Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-12-2015 Ran by Luana (administrator) on LUANA-PC (17-12-2015 13:16:55) Running from C:\Users\Luana\Downloads Loaded Profiles: Luana (Available Profiles: Luana) Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Inglês (Estados Unidos) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\ProgramData\WindowsMsg\osmsg.exe (Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe (Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe (Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files (x86)\WeatherTool\2.0.0.10998\WeatherService.exe (IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe (ShenZhen Enode Techology co,.Ltd) C:\Program Files (x86)\WeatherTool\2.0.0.10998\weather.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files (x86)\CalendarTool\2.0.0.11153\CalendarServ.exe () C:\Program Files (x86)\CalendarTool\2.0.0.11153\calendar.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111312 2015-11-06] (AVAST Software) HKLM-x32\...\Run: [HomePageHelper] => c:\programdata\homepage.exe HKLM-x32\...\Run: [LightGate] => c:\programdata\lightgate.exe [1081344 2015-12-04] () HKLM-x32\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast\setup\emupdate\a244e634-4707-4b38-9280-9b66900b3a24.exe [183232 2015-12-17] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3038396689-3654849643-3041127529-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd) HKU\S-1-5-21-3038396689-3654849643-3041127529-1000\...\Run: [osmsg] => C:\ProgramData\WindowsMsg\osmsg.exe [2920448 2015-12-02] () HKU\S-1-5-21-3038396689-3654849643-3041127529-1000\...\Run: [-] => c:\programdata\carssc.exe [1876992 2015-12-17] () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-23] (AVAST Software) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Mediatek Wireless Utility.lnk [2015-12-17] ShortcutTarget: Mediatek Wireless Utility.lnk -> C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe (Mediatek Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2015-11-28] ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.) CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:52833;https=127.0.0.1:52833 Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{3629970D-27CB-48AA-A79E-AD415CAD0CF9}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{3FC5A369-BD82-43B4-927C-745CC6BC3B58}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{7F0235B1-572F-49E9-9F00-E03071206900}: [NameServer] 8.8.8.8,208.67.220.220 Tcpip\..\Interfaces\{E4EAF070-0A73-4B83-A7AE-537ACE2B7199}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{F4562D61-89A0-41C6-9994-CDBE2E287D81}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKU\S-1-5-21-3038396689-3654849643-3041127529-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yeabests.cc/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1404768562&from=bxk&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yeabests.cc/ HKU\S-1-5-21-3038396689-3654849643-3041127529-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yeabests.cc/ HKU\S-1-5-21-3038396689-3654849643-3041127529-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ir_14_38_ie&cd=2XzuyEtN2Y1L1Qzu0F0Czz0F0CyEtDyBtB0B0B0EyBtA0EyDtN0D0Tzu0SzyzzzztN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StBtAtB0ByEzytB0BtGyE0D0D0DtGtAyD0A0DtG0DtCyCyCtGyB0AtA0A0AyBzztD0DtAtC0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0C0A0F0FyE0E0BtG0EyCtCyEtGyEzzyDtDtGzyzyyD0AtG0CzyyD0DzztDyDtCtC0AtAyE2Q&cr=834752587&ir= SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1404768562&from=bxk&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891&q={searchTerms} SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.default-search.net/search?sid=492&aid=246&itype=n&ver=13467&tm=460&src=ds&p={searchTerms} SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = hxxp://www.default-search.net/search?sid=498&aid=161&itype=r&ver=13892&tm=464&src=ds&p={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1404768562&from=bxk&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891&q={searchTerms} SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.default-search.net/search?sid=492&aid=246&itype=n&ver=13467&tm=460&src=ds&p={searchTerms} SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = hxxp://www.default-search.net/search?sid=498&aid=161&itype=r&ver=13892&tm=464&src=ds&p={searchTerms} SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> Web URL = hxxp://br.yhs4.search.yahoo.com/yhs/search?hspart=baixaki&hsimp=yhs-baixaki_br_solimba_01&p={searchTerms} SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_cmi_14_37_ie&cd=2XzuyEtN2Y1L1Qzu0F0Czz0F0CyEtDyBtB0B0B0EyBtA0EyDtN0D0Tzu0SzyyByBtN1L2XzutAtFtBtFtCtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StBtAtB0ByEzytB0BtGyE0D0D0DtGtAyD0A0DtG0DtCyCyCtGyB0AtA0A0AyBzztD0DtAtC0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0C0A0F0FyE0E0BtG0EyCtCyEtGyEzzyDtDtGzyzyyD0AtG0CzyyD0DzztDyDtCtC0AtAyE2Q&cr=1296903121&ir= SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> {231737BA-CFC9-484A-8D04-8584DE5343D1} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10843 SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ir_14_38_ie&cd=2XzuyEtN2Y1L1Qzu0F0Czz0F0CyEtDyBtB0B0B0EyBtA0EyDtN0D0Tzu0SzyzzzztN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StBtAtB0ByEzytB0BtGyE0D0D0DtGtAyD0A0DtG0DtCyCyCtGyB0AtA0A0AyBzztD0DtAtC0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0C0A0F0FyE0E0BtG0EyCtCyEtGyEzzyDtDtGzyzyyD0AtG0CzyyD0DzztDyDtCtC0AtAyE2Q&cr=834752587&ir= SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1404768562&from=bxk&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891&q={searchTerms} SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> {5AF0BFD6-C77D-4426-8810-F22E20F71E2C} URL = hxxp://search.findwide.com/serp?guid={55ADA6B2-CD49-48B3-A62B-221E24A747CD}&action=default_search&serpv=22&k={searchTerms} SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.default-search.net/search?sid=492&aid=246&itype=n&ver=13467&tm=460&src=ds&p={searchTerms} SearchScopes: HKU\S-1-5-21-3038396689-3654849643-3041127529-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-09-21] (IObit) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-23] (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2014-07-16] (Sun Microsystems, Inc.) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-23] (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2014-07-16] (Sun Microsystems, Inc.) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1441762220&z=fd27e06c1302e681a638294g7z0zeg8m1qfo4e7tfo&from=cornl&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891 FireFox: ======== FF ProfilePath: C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default FF NewTab: hxxp://www.istartsurf.com/newtab/?type=nt&ts=1441762220&z=fd27e06c1302e681a638294g7z0zeg8m1qfo4e7tfo&from=cornl&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891 FF DefaultSearchUrl: hxxps://www.google.com/search FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: hxxp://www.istartsurf.com/?type=hp&ts=1441762220&z=fd27e06c1302e681a638294g7z0zeg8m1qfo4e7tfo&from=cornl&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891 FF Keyword.URL: hxxps://www.google.com/search FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-28] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [No File] FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-28] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_45 -> C:\Windows\SysWOW64\npdeployJava1.dll [2014-07-16] (Sun Microsystems, Inc.) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2014-07-16] (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2013-08-20] (Nero AG) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2014-09-03] (globalUpdate) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2014-09-03] (globalUpdate) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [No File] FF SearchPlugin: C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default\searchplugins\Astromenda.xml [2014-09-24] FF SearchPlugin: C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default\searchplugins\default-search.xml [2014-09-07] FF SearchPlugin: C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default\searchplugins\trovi-search.xml [2014-09-03] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml [2014-09-07] FF Extension: compare for fun - C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default\extensions\plDql15Cl@gmail.com [2015-04-01] [not signed] FF Extension: TheTorntv V10 - C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default\extensions\a338c5448f724f94af2f11@cc4cdd6788a64e7ca7d83cb2cd.com [2014-10-03] [not signed] FF Extension: Default SearchProtected - C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default\extensions\defsearchp@gmail.com [2015-09-08] [not signed] FF Extension: deskCut - C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default\Extensions\deskCutv2@gmail.com [2015-09-08] [not signed] FF Extension: linkalertconlanaddonsmozillacom - C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default\Extensions\linkalert.conlan@addons.mozilla.com [2014-09-07] [not signed] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-10] FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Luana\AppData\Roaming\Mozilla\Firefox\Profiles\73qc3hy0.default\extensions\defsearchp@gmail.com FF HKU\S-1-5-21-3038396689-3654849643-3041127529-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] [not signed] FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\my-prefs.js [2015-03-25] <==== ATTENTION (Points to *.cfg file) FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\my.cfg [2015-03-25] <==== ATTENTION Chrome: ======= CHR HomePage: Default -> hxxp://www.istartsurf.com/?type=hp&ts=1441762220&z=fd27e06c1302e681a638294g7z0zeg8m1qfo4e7tfo&from=cornl&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891 CHR StartupUrls: Default -> "hxxp://www.istartsurf.com/?type=hp&ts=1441762220&z=fd27e06c1302e681a638294g7z0zeg8m1qfo4e7tfo&from=cornl&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891" CHR Profile: C:\Users\Luana\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Video Downloader professional) - C:\Users\Luana\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2015-08-05] CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Luana\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2015-11-16] CHR Extension: (AdBlock) - C:\Users\Luana\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-12-03] CHR Extension: (vGet Extension (Video Downloader, DLNA)) - C:\Users\Luana\AppData\Local\Google\Chrome\User Data\Default\Extensions\hniladkejehjfchadikcbjmgjaogciic [2015-08-05] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Luana\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-12-03] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Luana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-23] CHR Extension: (Baixar videos com FVD Video Downloader) - C:\Users\Luana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nocpfkkbaekckhcoekockfbidpcjgkbd [2015-08-05] CHR HKLM\...\Chrome\Extension: [pfkfdlcdbajamklbneflfbcmfgddmpae] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3038396689-3654849643-3041127529-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pfkfdlcdbajamklbneflfbcmfgddmpae] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-19] CHR HKLM-x32\...\Chrome\Extension: [pfkfdlcdbajamklbneflfbcmfgddmpae] - hxxps://clients2.google.com/service/update2/crx StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.istartsurf.com/?type=sc&ts=1441762220&z=fd27e06c1302e681a638294g7z0zeg8m1qfo4e7tfo&from=cornl&uid=SAMSUNGXHD501LJ_S12ZJ1NPC03891 ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-23] (AVAST Software) S2 GoogleChromeUpService; C:\ProgramData\upgsvr.exe [1762304 2015-11-16] (TODO: <公司名>) [File not signed] S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2934048 2015-10-09] (IObit) S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 MediatekRegistryWriter; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe [405136 2014-12-04] (Mediatek Inc.) R2 MediatekRegistryWriter64; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe [454288 2014-12-04] (Mediatek Inc.) S4 RealtekWlanU; C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtlService.exe [48856 2014-05-19] (Realtek) S4 RTLDHCPService; C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe [262360 2014-04-23] (Realtek) S4 RunSwUSB; C:\Windows\runSW.exe [36864 2014-04-15] () [File not signed] R2 TheCalendarService; C:\Program Files (x86)\CalendarTool\2.0.0.11153\CalendarServ.exe [153224 2015-12-10] () R2 TheDesktopWeatherService; C:\Program Files (x86)\WeatherTool\2.0.0.10998\WeatherService.exe [152008 2015-11-01] () R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [X] S4 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [X] S4 ss_conn_service; "C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe" [X] S4 SwitchBoard; "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [X] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-23] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-23] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-23] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-23] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-06] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-23] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-23] (AVAST Software) S3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [305920 2011-10-24] (AVEO) R1 crfilterdrv; C:\Windows\System32\drivers\crfilterdrv.sys [51528 2015-02-26] (Windows (R) Win 7 DDK provider) S3 DroidCam; C:\Windows\System32\DRIVERS\droidcam.sys [33080 2014-12-31] (Dev47Apps) S3 DroidCamVideo; C:\Windows\System32\DRIVERS\droidcamvideo.sys [228408 2014-12-31] (Dev47Apps) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 netr28ux; C:\Windows\System32\DRIVERS\netr28ux.sys [2245456 2015-10-14] (MediaTek Inc.) S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [748648 2010-06-15] (Realtek Semiconductor Corporation ) S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3591384 2014-10-13] (Realtek Semiconductor Corporation ) S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation) S1 Bfilter; \??\C:\Windows\System32\drivers\Bfilter.sys [X] S1 Bfmon; \??\C:\Windows\System32\drivers\Bfmon.sys [X] S1 Bnbase; System32\drivers\bnbasex64.sys [X] S1 Bndef; \??\C:\Windows\System32\drivers\bndef64.sys [X] S1 Bprotect; \??\C:\Windows\System32\drivers\Bprotect.sys [X] S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 PCFApiUtil; \??\C:\Program Files (x86)\Baidu Security\PC Faster\4.0.0.0\PCFApiUtil64.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-17 13:16 - 2015-12-17 13:17 - 00026405 _____ C:\Users\Luana\Downloads\FRST.txt 2015-12-17 13:16 - 2015-12-17 13:16 - 00000000 ____D C:\FRST 2015-12-17 13:15 - 2015-12-17 13:16 - 02370048 _____ (Farbar) C:\Users\Luana\Downloads\FRST64.exe 2015-12-17 13:15 - 2015-12-17 13:15 - 01721344 _____ (Farbar) C:\Users\Luana\Downloads\FRST.exe 2015-12-17 12:59 - 2015-12-17 12:59 - 00000000 ____D C:\Program Files (x86)\CalendarTool 2015-12-17 12:52 - 2015-12-17 14:31 - 02245032 _____ (UpAurora.COM) C:\ProgramData\UpAurora_1.0.0.3034__101br.exe 2015-12-17 12:32 - 2015-12-17 12:32 - 00000000 ____D C:\Users\Luana\AppData\Roaming\Adobe 2015-12-17 06:51 - 2015-12-17 06:51 - 00009856 _____ C:\Users\Luana\Downloads\DXTour.kmz 2015-12-17 06:44 - 2015-12-17 06:45 - 36333331 _____ C:\Users\Luana\Downloads\Google Play Services 6.5.87 (1599771-010)_6587010.apk 2015-12-17 06:16 - 2015-12-17 06:16 - 00563465 _____ C:\Users\Luana\Downloads\Leonardo da Vinci - Sophie Chauveau.epub 2015-12-17 06:10 - 2015-12-17 16:08 - 01876992 _____ C:\ProgramData\carssc.exe 2015-12-17 01:36 - 2015-12-17 01:36 - 00319207 _____ C:\Users\Luana\Desktop\ftancyscu.wlmp 2015-12-16 23:07 - 2015-12-16 23:18 - 00000000 ____D C:\Users\Luana\Downloads\Gilza clipe 2015-12-16 20:17 - 2015-12-16 20:18 - 00000000 ____D C:\Users\Luana\AppData\Local\{64996F5D-838A-4603-A0CC-F7426CD24D24} 2015-12-16 18:34 - 2015-12-17 06:24 - 00000000 ____D C:\Users\Luana\AppData\Roaming\CalendarTool 2015-12-16 07:17 - 2015-12-16 07:17 - 00000000 ____D C:\Program Files (x86)\WeatherTool 2015-12-15 23:33 - 2015-12-15 23:34 - 00004132 _____ C:\Users\Luana\Downloads\NFe_XML_15122015233357.zip 2015-12-14 17:51 - 2015-12-14 17:51 - 00004132 _____ C:\Users\Luana\Downloads\NFe_XML_14122015175148.zip 2015-12-14 17:51 - 2015-12-14 17:51 - 00004132 _____ C:\Users\Luana\Downloads\NFe_XML_14122015175145.zip 2015-12-11 09:57 - 2015-12-10 15:43 - 00600312 _____ C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe 2015-12-10 00:13 - 2015-12-10 00:13 - 00386822 _____ C:\Users\Luana\Downloads\Edital 01 2013 Credenciamento de Musicos OSUFBA-1.pdf 2015-12-09 09:23 - 2015-11-05 17:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2015-12-09 09:23 - 2015-11-05 17:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2015-12-09 09:22 - 2015-11-20 16:54 - 03170304 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-12-09 09:22 - 2015-11-20 16:54 - 02609152 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-12-09 09:22 - 2015-11-20 16:54 - 00709632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-12-09 09:22 - 2015-11-20 16:54 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-12-09 09:22 - 2015-11-20 16:54 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-12-09 09:22 - 2015-11-20 16:54 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-12-09 09:22 - 2015-11-20 16:54 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-12-09 09:22 - 2015-11-20 16:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-12-09 09:22 - 2015-11-20 16:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-12-09 09:22 - 2015-11-20 16:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-12-09 09:22 - 2015-11-20 16:54 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-12-09 09:22 - 2015-11-20 16:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-12-09 09:22 - 2015-11-20 16:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-12-09 09:22 - 2015-11-20 16:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-12-09 09:22 - 2015-11-20 16:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-12-09 09:22 - 2015-11-20 16:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-12-09 09:22 - 2015-11-10 16:55 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-12-09 09:22 - 2015-11-10 16:55 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-12-09 09:22 - 2015-11-10 16:55 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2015-12-09 09:22 - 2015-11-10 16:39 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2015-12-09 09:22 - 2015-11-10 16:37 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2015-12-09 09:22 - 2015-11-10 15:47 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-12-09 09:22 - 2015-11-03 17:04 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2015-12-09 09:22 - 2015-11-03 16:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2015-12-09 09:22 - 2015-10-08 21:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll 2015-12-09 09:22 - 2015-10-08 21:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL 2015-12-09 09:22 - 2015-10-08 21:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll 2015-12-09 09:22 - 2015-10-08 21:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL 2015-12-09 09:22 - 2015-10-08 21:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL 2015-12-09 09:22 - 2015-10-08 21:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll 2015-12-09 09:22 - 2015-10-08 21:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL 2015-12-09 09:22 - 2015-10-08 21:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll 2015-12-09 09:22 - 2015-10-08 17:13 - 00419928 _____ C:\Windows\SysWOW64\locale.nls 2015-12-09 09:22 - 2015-10-08 16:52 - 00419928 _____ C:\Windows\system32\locale.nls 2015-12-09 09:21 - 2015-11-11 19:12 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-12-09 09:21 - 2015-11-11 18:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-12-09 09:21 - 2015-11-11 16:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-12-09 09:21 - 2015-11-11 16:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2015-12-09 09:21 - 2015-11-11 16:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll 2015-12-09 09:21 - 2015-11-11 16:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll 2015-12-09 09:21 - 2015-11-11 14:21 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-12-09 09:21 - 2015-11-11 14:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-12-09 09:21 - 2015-11-11 13:44 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-12-09 09:21 - 2015-11-11 13:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-12-09 09:21 - 2015-11-11 13:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-12-09 09:21 - 2015-11-11 13:12 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-12-09 09:21 - 2015-11-11 12:57 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-12-09 09:21 - 2015-11-09 22:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-12-09 09:21 - 2015-11-09 22:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-12-09 09:21 - 2015-11-09 22:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-12-09 09:21 - 2015-11-09 22:12 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-12-09 09:21 - 2015-11-09 22:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-12-09 09:21 - 2015-11-09 22:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-12-09 09:21 - 2015-11-09 22:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-12-09 09:21 - 2015-11-09 22:06 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-12-09 09:21 - 2015-11-09 22:06 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-12-09 09:21 - 2015-11-09 22:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-12-09 09:21 - 2015-11-09 22:03 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-12-09 09:21 - 2015-11-09 22:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-12-09 09:21 - 2015-11-09 22:02 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-12-09 09:21 - 2015-11-09 21:50 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-12-09 09:21 - 2015-11-09 21:47 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-12-09 09:21 - 2015-11-09 21:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-12-09 09:21 - 2015-11-09 21:44 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2015-12-09 09:21 - 2015-11-09 21:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-12-09 09:21 - 2015-11-09 21:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-12-09 09:21 - 2015-11-09 21:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-12-09 09:21 - 2015-11-09 21:35 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-12-09 09:21 - 2015-11-09 21:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-12-09 09:21 - 2015-11-09 21:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-12-09 09:21 - 2015-11-09 21:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-12-09 09:21 - 2015-11-08 20:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-12-09 09:21 - 2015-11-08 20:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-12-09 09:21 - 2015-11-08 20:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-12-09 09:21 - 2015-11-08 20:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-12-09 09:21 - 2015-11-08 20:15 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-12-09 09:21 - 2015-11-08 20:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-12-09 09:21 - 2015-11-08 20:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-12-09 09:21 - 2015-11-08 20:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-12-09 09:21 - 2015-11-08 20:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-12-09 09:21 - 2015-11-08 20:06 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-12-09 09:21 - 2015-11-08 20:04 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-12-09 09:21 - 2015-11-08 20:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-12-09 09:21 - 2015-11-08 20:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-12-09 09:21 - 2015-11-08 20:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-12-09 09:21 - 2015-11-08 20:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-12-09 09:21 - 2015-11-08 20:01 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-12-09 09:21 - 2015-11-08 19:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-12-09 09:21 - 2015-11-08 19:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-12-09 09:21 - 2015-11-08 19:40 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-12-09 09:21 - 2015-11-08 19:35 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-12-09 09:21 - 2015-11-08 19:32 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-12-09 09:21 - 2015-11-08 19:29 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2015-12-09 09:21 - 2015-11-08 19:18 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-12-09 09:21 - 2015-11-08 19:15 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-12-09 09:21 - 2015-11-08 19:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-12-09 09:21 - 2015-11-08 19:14 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-12-09 09:21 - 2015-11-08 19:14 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-12-09 09:21 - 2015-11-08 19:13 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-12-09 09:21 - 2015-11-08 18:53 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-12-09 09:21 - 2015-11-08 18:41 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-12-09 09:21 - 2015-11-08 18:30 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-12-09 09:21 - 2015-11-05 17:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll 2015-12-09 09:21 - 2015-11-05 17:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll 2015-12-09 09:21 - 2015-11-05 07:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-12-09 09:20 - 2015-11-03 17:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll 2015-12-09 09:20 - 2015-11-03 16:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll 2015-12-08 09:18 - 2015-12-11 16:38 - 01314158 _____ ( ) C:\ProgramData\carssb.exe 2015-12-08 00:23 - 2015-12-07 16:37 - 01435648 _____ C:\ProgramData\test.exe 2015-12-07 16:06 - 2015-12-08 22:17 - 00000000 ____D C:\Users\Luana\Documents\3x4 2015-12-04 07:44 - 2015-12-04 13:14 - 01081344 _____ C:\ProgramData\LightGate.exe 2015-12-03 23:30 - 2015-12-03 23:30 - 00315773 _____ C:\Users\Luana\Desktop\alemir e rosana.wlmp 2015-12-03 21:06 - 2015-12-03 21:06 - 00000000 ____D C:\Users\Luana\AppData\Local\{000846A1-766E-428A-9D43-AF00DDCEB257} 2015-12-03 14:49 - 2015-12-03 15:37 - 149576007 _____ C:\Users\Luana\Downloads\GTH11LEGENDADO.rmvb 2015-12-03 13:37 - 2015-12-03 13:37 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2015-12-03 01:56 - 2015-12-17 12:31 - 00000000 ____D C:\ProgramData\WindowsMsg 2015-12-03 01:56 - 2015-12-17 06:11 - 00000000 ____D C:\Program Files (x86)\osTip 2015-12-03 01:55 - 2015-12-02 15:40 - 01308162 _____ ( ) C:\ProgramData\carss---.exe 2015-12-02 15:46 - 2015-12-02 15:46 - 00002790 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-12-02 15:46 - 2015-12-02 15:46 - 00000000 ____D C:\Program Files\CCleaner 2015-12-02 11:28 - 2015-12-02 11:29 - 06801752 _____ (Piriform Ltd) C:\Users\Luana\Downloads\ccsetup512.exe 2015-12-02 10:51 - 2015-12-02 12:30 - 00000000 ____D C:\@Filmagens 2015-12-01 10:32 - 2015-12-01 10:33 - 00000000 ____D C:\Users\Luana\Documents\videos Luana 2015-12-01 08:31 - 2015-12-01 07:09 - 00154947 _____ C:\Users\Luana\Documents\casameta Cla ra e Márcio.txt 2015-12-01 01:25 - 2015-12-03 20:17 - 00000000 ____D C:\Users\Luana\Documents\Renata 2015-12-01 00:55 - 2015-12-01 00:55 - 00138303 _____ C:\Users\Luana\Downloads\Convidados.zip 2015-12-01 00:41 - 2015-12-03 23:59 - 00000000 ____D C:\Users\Luana\AppData\Roaming\dvdcss 2015-11-30 13:09 - 2015-12-07 23:37 - 00000000 ____D C:\Users\Luana\Documents\NeroVideo 2015-11-30 12:55 - 2015-11-30 13:09 - 00000000 ____D C:\Users\Luana\AppData\Local\Nero 2015-11-30 12:55 - 2015-11-30 12:55 - 00000000 ____D C:\Users\Luana\AppData\Local\Nero_AG 2015-11-30 12:53 - 2015-12-01 00:41 - 00000000 ____D C:\Users\Luana\AppData\Roaming\Nero 2015-11-30 12:41 - 2015-11-30 12:41 - 00000000 ____D C:\Windows\System32\Tasks\Nero 2015-11-30 12:39 - 2015-11-30 12:39 - 00002913 _____ C:\Users\Public\Desktop\Nero 2014.lnk 2015-11-30 12:33 - 2015-11-30 13:09 - 00000000 ____D C:\ProgramData\Nero 2015-11-30 12:33 - 2015-11-30 12:39 - 00000000 ____D C:\Program Files (x86)\Nero 2015-11-30 12:33 - 2015-11-30 12:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 2015-11-30 12:27 - 2015-11-30 12:27 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2015-11-30 12:26 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2015-11-30 12:26 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2015-11-30 12:26 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2015-11-30 12:25 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2015-11-30 12:25 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2015-11-30 12:11 - 2015-11-30 12:11 - 00000000 ____D C:\Users\Luana\Downloads\Nero 2014 Platinum 15.0.02200 Final (Patch Kindly) [ChingLiu] 2015-11-30 12:09 - 2015-11-30 12:09 - 00000000 ____D C:\Users\Luana\AppData\LocalLow\uTorrent 2015-11-30 12:08 - 2015-11-30 12:09 - 02026520 _____ (BitTorrent Inc.) C:\Users\Luana\Downloads\uTorrent.exe 2015-11-30 12:08 - 2015-11-30 12:08 - 02026520 _____ (BitTorrent Inc.) C:\Users\Luana\Downloads\Unconfirmed 957580.crdownload 2015-11-30 10:24 - 2015-11-30 10:25 - 00000000 ____D C:\Users\Luana\AppData\Local\{94FD7A2D-9140-4DF6-94DB-03E270C993C9} 2015-11-29 18:25 - 2015-11-29 18:26 - 00000000 ____D C:\Users\Luana\Downloads\nero 2015 2015-11-29 18:11 - 2015-11-29 18:11 - 258994863 _____ C:\Users\Luana\Downloads\nero 2015.rar 2015-11-29 18:04 - 2015-11-29 18:24 - 803581360 _____ (Nero AG) C:\Users\Luana\Downloads\Unconfirmed 993980.crdownload 2015-11-29 16:06 - 2015-11-29 16:06 - 00000000 ____D C:\Users\Luana\AppData\Local\{C5394D54-FA44-4BB1-A39A-D4FBFDE1E30F} 2015-11-29 14:23 - 2015-11-29 14:25 - 108568588 _____ C:\Users\Luana\Downloads\001 - Pro Motion menu Kit 05.zip 2015-11-29 13:57 - 2015-12-17 08:45 - 149565886 _____ C:\Users\Luana\Downloads\Photoshop CS6 Portable com 3D By - MangPlay.rar 2015-11-29 09:10 - 2015-11-29 09:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mediatek Wireless 2015-11-29 09:10 - 2015-11-29 09:10 - 00000000 ____D C:\ProgramData\Mediatek 2015-11-29 09:09 - 2015-11-29 09:09 - 00000000 ____D C:\Windows\system32\RaLanguages 2015-11-29 09:09 - 2015-11-29 09:09 - 00000000 ____D C:\ProgramData\Mediatek Driver 2015-11-29 09:09 - 2015-11-29 09:09 - 00000000 ____D C:\Program Files (x86)\MediatekWiFi 2015-11-29 09:09 - 2015-10-14 07:14 - 02245456 _____ (MediaTek Inc.) C:\Windows\system32\Drivers\netr28ux.sys 2015-11-29 09:09 - 2015-10-14 07:14 - 00343704 _____ (Mediatek Inc.) C:\Windows\system32\RaCoInstx.dll 2015-11-29 09:09 - 2015-10-14 06:57 - 00079216 _____ C:\Windows\SysWOW64\Drivers\FW_7662.bin 2015-11-29 09:09 - 2015-10-14 06:57 - 00079216 _____ C:\Windows\system32\Drivers\FW_7662.bin 2015-11-29 09:09 - 2015-10-14 06:57 - 00020626 _____ C:\Windows\SysWOW64\Drivers\Patch_7662.bin 2015-11-29 09:09 - 2015-10-14 06:57 - 00020626 _____ C:\Windows\system32\Drivers\Patch_7662.bin 2015-11-29 09:09 - 2015-10-14 06:57 - 00016389 _____ C:\Windows\SysWOW64\RaCoInst.dat 2015-11-29 09:09 - 2015-10-14 06:57 - 00016389 _____ C:\Windows\system32\RaCoInst.dat 2015-11-29 09:09 - 2012-08-01 16:46 - 01115648 _____ (Ralink Technology, Corp.) C:\Windows\SysWOW64\RAIHV.dll 2015-11-29 09:09 - 2012-08-01 16:46 - 01115648 _____ (Ralink Technology, Corp.) C:\Windows\system32\RAIHV.dll 2015-11-29 09:09 - 2012-01-10 11:39 - 00127488 _____ (Ralink Technology, Corp.) C:\Windows\SysWOW64\RAEXTUI.dll 2015-11-29 09:09 - 2012-01-10 11:39 - 00127488 _____ (Ralink Technology, Corp.) C:\Windows\system32\RAEXTUI.dll 2015-11-29 09:09 - 2011-05-04 13:57 - 02403392 _____ (Ralink Technology, Corp.) C:\Windows\system32\RaCertMgr.dll 2015-11-29 09:09 - 2011-05-04 13:56 - 01608768 _____ (Ralink Technology, Corp.) C:\Windows\SysWOW64\RaCertMgr.dll 2015-11-29 09:09 - 2010-06-29 10:35 - 00792416 _____ C:\Windows\SysWOW64\DiagFunc.dll 2015-11-29 09:09 - 2010-06-29 10:35 - 00792416 _____ C:\Windows\system32\DiagFunc.dll 2015-11-29 09:09 - 2010-01-27 12:47 - 00000451 _____ C:\Windows\system32\DiagFunc.ini 2015-11-29 09:09 - 2010-01-27 11:54 - 00000451 _____ C:\Windows\SysWOW64\DiagFunc.ini 2015-11-29 08:44 - 2015-11-29 08:44 - 00000000 ____D C:\Program Files\Broadcom 2015-11-29 08:44 - 2015-11-29 08:44 - 00000000 ____D C:\Program Files (x86)\Cisco 2015-11-29 08:44 - 2015-11-29 08:43 - 00006656 _____ C:\Windows\system32\bcmwlrc.dll 2015-11-29 08:43 - 2015-11-29 08:43 - 00000000 ____D C:\Windows\system32\nn-NO 2015-11-29 08:43 - 2015-11-29 08:43 - 00000000 ____D C:\Program Files (x86)\Atheros 2015-11-29 08:43 - 2011-04-27 18:01 - 00443040 _____ (Atheros) C:\Windows\system32\athihvs.dll 2015-11-29 08:43 - 2011-04-27 18:01 - 00063648 _____ (Atheros) C:\Windows\system32\athihvui.dll 2015-11-29 08:42 - 2015-11-29 08:42 - 00000000 ____D C:\ProgramData\Atheros 2015-11-28 20:32 - 2015-11-28 20:32 - 00000000 ____D C:\Users\Luana\AppData\Local\Nico Mak Computing 2015-11-28 20:31 - 2015-11-28 20:31 - 00002294 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk 2015-11-28 20:31 - 2015-11-28 20:31 - 00002288 _____ C:\Users\Public\Desktop\WinZip.lnk 2015-11-28 20:31 - 2015-11-28 20:31 - 00000000 ____D C:\Users\Luana\AppData\Local\WinZip 2015-11-28 20:31 - 2015-11-28 20:31 - 00000000 ____D C:\ProgramData\WinZip 2015-11-28 20:31 - 2015-11-28 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2015-11-28 20:31 - 2015-11-28 20:31 - 00000000 ____D C:\Program Files\WinZip 2015-11-28 20:20 - 2015-11-29 08:54 - 00002904 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Luana 2015-11-28 20:02 - 2015-11-29 13:56 - 00000000 ____D C:\Users\Luana\Downloads\Progamas para edição 2015-11-28 19:59 - 2015-11-28 19:59 - 00000116 _____ C:\Users\Luana\Adobe Encore_AME.pref 2015-11-28 01:54 - 2015-11-28 01:54 - 00000000 ____D C:\Users\Luana\AppData\Local\Spoon 2015-11-27 14:44 - 2015-11-27 14:44 - 00000000 ____D C:\Users\Luana\AppData\Roaming\ProductData 2015-11-27 14:43 - 2015-12-12 07:18 - 00000000 ____D C:\ProgramData\ProductData 2015-11-27 14:43 - 2015-11-28 23:39 - 00000000 ____D C:\ProgramData\IObit 2015-11-27 14:43 - 2015-11-27 14:44 - 00000000 ____D C:\Users\Luana\AppData\Roaming\IObit 2015-11-27 14:43 - 2015-11-27 14:43 - 00001377 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk 2015-11-27 14:43 - 2015-11-27 14:43 - 00001365 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2015-11-27 14:43 - 2015-11-27 14:43 - 00000000 ____D C:\Users\Luana\AppData\LocalLow\IObit 2015-11-27 14:43 - 2015-11-27 14:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller 2015-11-27 14:43 - 2015-11-27 14:43 - 00000000 ____D C:\Program Files (x86)\IObit 2015-11-27 12:10 - 2015-02-07 14:52 - 00000430 _____ C:\Users\Luana\Downloads\LEIA IMPORTANTE!.vbs 2015-11-27 12:09 - 2013-03-17 20:50 - 00000000 ____D C:\Users\Luana\Desktop\Photoshop CS6 Portable com 3D 2015-11-27 10:29 - 2015-11-27 10:29 - 00000000 ____D C:\Users\Luana\AppData\Local\{19834DDC-F1A7-47C5-B96B-3E1817CCCE62} 2015-11-27 09:23 - 2015-11-26 07:58 - 04127064 _____ C:\ProgramData\ch_dl_url 2015-11-25 21:44 - 2015-11-25 21:44 - 00000000 ____D C:\Users\Luana\AppData\Local\{95348650-9E9F-485D-98A9-3C7D52A460FB} 2015-11-25 18:13 - 2015-11-25 15:31 - 01100288 _____ C:\Users\Luana\AppData\Roaming\HomePage.exe 2015-11-25 08:22 - 2015-11-25 08:22 - 00000161 _____ C:\Users\Luana\AppData\Roaming\xcgui_debug.txt 2015-11-24 23:24 - 2015-11-30 00:04 - 00001610 _____ C:\ProgramData\xcgui_debug.txt 2015-11-24 22:50 - 2012-06-02 06:32 - 06431744 _____ C:\Users\Luana\Desktop\PSCS6.exe 2015-11-24 16:37 - 2015-11-24 16:37 - 00000000 ____D C:\Users\Luana\AppData\Local\Yeaplayer 2015-11-24 16:37 - 2015-11-16 08:01 - 01762304 _____ (TODO: <公司名>) C:\Users\Luana\AppData\Roaming\upgsvr.exe 2015-11-24 16:37 - 2015-11-16 08:01 - 01762304 _____ (TODO: <公司名>) C:\ProgramData\upgsvr.exe 2015-11-24 16:37 - 2015-11-14 21:08 - 02496403 _____ ( ) C:\Users\Luana\AppData\Roaming\yeaplayer_51472.exe 2015-11-24 16:36 - 2015-11-24 16:36 - 00004593 _____ C:\Users\Luana\AppData\Roaming\webad.xml 2015-11-24 16:36 - 2015-11-23 15:11 - 01919488 _____ C:\Users\Luana\AppData\Roaming\carss.exe 2015-11-24 16:35 - 2015-11-24 16:36 - 00000000 ____D C:\Program Files (x86)\03000200-1448390159-0500-0006-000700080009 2015-11-24 15:48 - 2015-11-24 15:48 - 00000000 ____D C:\PhSp_CS2_UE_Ret 2015-11-24 11:42 - 2015-11-24 11:42 - 00000040 ____H C:\CCBB6CD8F6F4 2015-11-24 11:41 - 2015-11-24 11:42 - 00000000 ____D C:\Program Files\Common Files\Adobe 2015-11-22 13:23 - 2015-11-22 13:23 - 00000268 _____ C:\Users\Luana\Documents\556.txt 2015-11-19 22:27 - 2015-11-20 22:02 - 00000691 _____ C:\Users\Luana\AppData\Roaming\Página de Amostra II.xml 2015-11-17 21:47 - 2015-11-17 21:47 - 00000000 ____D C:\Users\Luana\AppData\Local\{233AA1E2-6556-4641-8C1D-D807EAAC7CB7} ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-17 13:16 - 2009-07-14 01:20 - 00000000 ____D C:\Windows 2015-12-17 12:40 - 2009-07-14 02:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-12-17 12:40 - 2009-07-14 02:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-12-17 12:30 - 2009-07-14 03:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-17 09:28 - 2015-04-10 00:11 - 00000000 ____D C:\Users\Luana\AppData\Roaming\vlc 2015-12-17 07:45 - 2015-06-14 09:00 - 00000000 ____D C:\Users\Luana\AppData\Roaming\WeatherTool 2015-12-17 01:01 - 2013-02-12 02:34 - 00000000 ____D C:\Dg Foto Art Trial 2015-12-15 07:50 - 2014-06-26 02:19 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2015-12-10 21:45 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\rescache 2015-12-10 07:23 - 2009-07-14 02:45 - 05030368 _____ C:\Windows\system32\FNTCACHE.DAT 2015-12-10 07:22 - 2015-05-13 15:14 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-12-10 07:22 - 2015-05-13 15:14 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2015-12-10 07:20 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\inf 2015-12-10 06:38 - 2015-05-13 15:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-12-10 06:36 - 2014-07-31 20:33 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-12-03 13:37 - 2015-06-25 21:31 - 00000000 ____D C:\Program Files\Common Files\AV 2015-12-02 16:29 - 2014-07-27 08:27 - 00000000 ____D C:\Users\Luana\AppData\Roaming\uTorrent 2015-12-02 16:29 - 2014-06-26 20:08 - 00000000 ____D C:\Windows\Minidump 2015-12-02 13:18 - 2010-11-21 01:27 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-12-02 10:53 - 2014-06-26 02:30 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-12-02 01:31 - 2015-08-05 19:31 - 00000000 ____D C:\Users\Luana\AppData\Roaming\Anvsoft 2015-11-30 23:20 - 2015-09-01 03:38 - 00000000 ____D C:\Users\Luana\AppData\Local\Apps\Windows 7 USB DVD Download Tool 2015-11-30 12:41 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\Cursors 2015-11-29 09:09 - 2014-06-25 22:39 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2015-11-29 08:52 - 2014-06-25 22:48 - 00076120 _____ C:\Users\Luana\AppData\Local\GDIPFONTCACHEV1.DAT 2015-11-29 08:49 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\system32\NDF 2015-11-29 08:44 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\system32\lv-LV 2015-11-29 08:44 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\system32\lt-LT 2015-11-29 08:44 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\system32\et-EE 2015-11-28 21:17 - 2014-08-23 01:17 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-11-28 20:34 - 2014-08-23 01:17 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-11-28 20:34 - 2014-08-23 01:17 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-11-28 20:34 - 2014-08-23 01:17 - 00003770 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-11-28 20:32 - 2014-10-30 00:45 - 00000000 ____D C:\Users\Luana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-11-28 20:32 - 2014-10-30 00:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-11-28 20:32 - 2014-10-30 00:44 - 00000000 ____D C:\Program Files (x86)\WinRAR 2015-11-28 19:59 - 2014-06-25 22:24 - 00000000 ____D C:\Users\Luana 2015-11-27 23:55 - 2015-03-03 23:39 - 00000132 _____ C:\Users\Luana\AppData\Roaming\Preferências do Formato BMP do Adobe CS6 2015-11-27 14:45 - 2014-08-18 21:06 - 00000000 ____D C:\Users\Luana\AppData\Local\Facebook 2015-11-27 14:28 - 2015-10-05 19:11 - 00001541 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk 2015-11-27 14:10 - 2014-06-26 02:33 - 00000000 ____D C:\Program Files\Adobe 2015-11-24 22:49 - 2015-06-18 04:04 - 00000000 ____D C:\Users\Luana\AppData\Local\SkypePlugin 2015-11-24 22:48 - 2014-10-02 02:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-11-24 22:47 - 2015-08-13 18:58 - 00000000 ____D C:\ProgramData\Skype 2015-11-24 22:46 - 2015-08-13 18:58 - 00000000 ____D C:\Users\Luana\AppData\Roaming\Skype 2015-11-24 22:42 - 2009-07-14 03:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2015-11-24 17:26 - 2015-03-31 06:14 - 00000385 _____ C:\Users\Luana\AppData\Roaming\lTS3MxdZ96H8BdBcD7NBVhbY1 2015-11-24 17:15 - 2015-09-08 23:33 - 00000000 ____D C:\ProgramData\UWdsManProU 2015-11-24 17:05 - 2014-09-03 22:14 - 00000000 ____D C:\Program Files (x86)\TheTorntv V10 2015-11-17 03:37 - 2014-06-26 02:50 - 00000000 ____D C:\Windows\Panther 2015-11-17 03:32 - 2015-10-30 07:42 - 00000000 ___HD C:\$WINDOWS.~BT ==================== Files in the root of some directories ======= 2014-09-03 23:38 - 2014-09-03 23:38 - 0000322 _____ () C:\Users\Luana\AppData\Roaming\aps.uninstall.scan.results 2015-11-24 16:36 - 2015-11-23 15:11 - 1919488 _____ () C:\Users\Luana\AppData\Roaming\carss.exe 2015-11-19 22:27 - 2015-11-20 22:36 - 0120402 _____ () C:\Users\Luana\AppData\Roaming\ContactSheetII.log 2015-11-25 18:13 - 2015-11-25 15:31 - 1100288 _____ () C:\Users\Luana\AppData\Roaming\HomePage.exe 2015-03-31 06:14 - 2015-03-31 06:14 - 0004387 _____ () C:\Users\Luana\AppData\Roaming\LPyGSFtejnNx0f7 2015-03-31 06:14 - 2015-11-24 17:26 - 0000385 _____ () C:\Users\Luana\AppData\Roaming\lTS3MxdZ96H8BdBcD7NBVhbY1 2014-11-28 01:17 - 2014-11-28 01:17 - 0000461 _____ () C:\Users\Luana\AppData\Roaming\Poladroid prefs.plist 2015-03-03 23:39 - 2015-11-27 23:55 - 0000132 _____ () C:\Users\Luana\AppData\Roaming\Preferências do Formato BMP do Adobe CS6 2014-07-23 11:06 - 2015-02-14 23:12 - 0000132 _____ () C:\Users\Luana\AppData\Roaming\Preferências do Formato GIF do Adobe CS6 2014-08-18 15:17 - 2014-10-04 20:34 - 0000132 _____ () C:\Users\Luana\AppData\Roaming\Preferências do Formato PNG do Adobe CS6 2014-09-18 00:16 - 2014-09-18 00:16 - 0000132 _____ () C:\Users\Luana\AppData\Roaming\Preferências do Formato Targa do Adobe CS6 2015-11-19 22:27 - 2015-11-20 22:02 - 0000691 _____ () C:\Users\Luana\AppData\Roaming\Página de Amostra II.xml 2015-11-24 16:37 - 2015-11-16 08:01 - 1762304 _____ (TODO: <公司名>) C:\Users\Luana\AppData\Roaming\upgsvr.exe 2014-09-04 00:35 - 2014-09-19 08:57 - 0000067 _____ () C:\Users\Luana\AppData\Roaming\WB.CFG 2015-11-24 16:36 - 2015-11-24 16:36 - 0004593 _____ () C:\Users\Luana\AppData\Roaming\webad.xml 2015-11-25 08:22 - 2015-11-25 08:22 - 0000161 _____ () C:\Users\Luana\AppData\Roaming\xcgui_debug.txt 2015-11-24 16:37 - 2015-11-14 21:08 - 2496403 _____ ( ) C:\Users\Luana\AppData\Roaming\yeaplayer_51472.exe 2015-03-31 06:14 - 2015-03-31 06:14 - 0004387 _____ () C:\Users\Luana\AppData\Roaming\yQ71wQ0da 2015-04-06 23:32 - 2015-04-06 23:32 - 0001456 _____ () C:\Users\Luana\AppData\Local\Adobe Salvar para Web 13.0 Prefs 2015-12-03 01:55 - 2015-12-02 15:40 - 1308162 _____ ( ) C:\ProgramData\carss---.exe 2015-12-08 09:18 - 2015-12-11 16:38 - 1314158 _____ ( ) C:\ProgramData\carssb.exe 2015-12-17 06:10 - 2015-12-17 16:08 - 1876992 _____ () C:\ProgramData\carssc.exe 2015-11-27 09:23 - 2015-11-26 07:58 - 4127064 _____ () C:\ProgramData\ch_dl_url 2014-12-31 01:25 - 2014-12-31 03:43 - 0000036 _____ () C:\ProgramData\droidcam-settings 2015-12-04 07:44 - 2015-12-04 13:14 - 1081344 _____ () C:\ProgramData\LightGate.exe 2014-08-25 23:42 - 2014-08-25 23:42 - 0004978 _____ () C:\ProgramData\mtbjfghn.xbe 2015-12-08 00:23 - 2015-12-07 16:37 - 1435648 _____ () C:\ProgramData\test.exe 2015-12-17 12:52 - 2015-12-17 14:31 - 2245032 _____ (UpAurora.COM) C:\ProgramData\UpAurora_1.0.0.3034__101br.exe 2015-11-24 16:37 - 2015-11-16 08:01 - 1762304 _____ (TODO: <公司名>) C:\ProgramData\upgsvr.exe 2015-11-24 23:24 - 2015-11-30 00:04 - 0001610 _____ () C:\ProgramData\xcgui_debug.txt 2015-12-11 09:57 - 2015-12-10 15:43 - 0600312 _____ () C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe 2015-09-08 23:33 - 2015-09-08 23:33 - 0000102 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Files to move or delete: ==================== C:\ProgramData\carss---.exe C:\ProgramData\carssb.exe C:\ProgramData\carssc.exe C:\ProgramData\LightGate.exe C:\ProgramData\test.exe C:\ProgramData\UpAurora_1.0.0.3034__101br.exe C:\ProgramData\upgsvr.exe C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-12-10 01:14 ==================== End of FRST.txt ============================