Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:06-08-2015 Ran by Casa (administrator) on CASA-PC (04-05-2016 18:06:23) Running from C:\Users\Casa\Downloads Loaded Profiles: Casa (Available Profiles: Casa & paulo) Platform: Windows 7 Ultimate (X64) Language: Português (Brasil) Internet Explorer Version 8 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Navigation Co., Ltd.) C:\Users\Casa\AppData\Roaming\ntsvc\ntsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Greenwichers) C:\Program Files\Common Files\Clocker\Clocker.exe () C:\ProgramData\CloudPrinter\CloudPrinter.exe (QNT) C:\Windows\SysWOW64\NetService\netservice.exe () C:\Program Files\PopService\PopService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (iSkySoft) C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Logixoft) C:\ProgramData\rvlkl\rvlkl.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Devolver Digital ) E:\setup.exe () C:\Users\Casa\AppData\Local\Temp\is-QUR3O.tmp\setup.tmp (Devolver Digital ) E:\setup.exe () C:\Users\Casa\AppData\Local\Temp\is-6V3BE.tmp\setup.tmp ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation) HKLM-x32\...\Run: [mbot_br_469] => [X] HKLM-x32\...\Run: [gmsd_br_280] => [X] HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [uTorrent] => C:\Users\Casa\AppData\Roaming\uTorrent\uTorrent.exe [1959424 2016-04-06] (BitTorrent Inc.) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-03-31] (Valve Corporation) HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\...\Run: [C] => C:\Windows\system32\GroupPolicy\Machine\Registry.pol [750 2016-02-18] () IFEO\avcenter.exe: [Debugger] nsjw.exe IFEO\avguard.exe: [Debugger] nsjw.exe IFEO\avp.exe: [Debugger] nsjw.exe IFEO\bdagent.exe: [Debugger] nsjw.exe IFEO\ccuac.exe: [Debugger] nsjw.exe IFEO\ComboFix.exe: [Debugger] nsjw.exe IFEO\egui.exe: [Debugger] nsjw.exe IFEO\hijackthis.exe: [Debugger] nsjw.exe IFEO\keyscrambler.exe: [Debugger] nsjw.exe IFEO\mbam.exe: [Debugger] nsjw.exe IFEO\NisSrv.exe: [Debugger] nsjw.exe IFEO\spybotsd.exe: [Debugger] nsjw.exe IFEO\wireshark.exe: [Debugger] nsjw.exe IFEO\zlclient.exe: [Debugger] nsjw.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\rvlkl.lnk [2015-11-17] ShortcutTarget: rvlkl.lnk -> C:\ProgramData\rvlkl\rvlkl.exe (Logixoft) Startup: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk [2015-03-02] ShortcutTarget: crossbrowse.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (No File) InternetURL: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google.com.url -> C:\ProgramData\318983520.exe Startup: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-04-01] ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{9946e5c7-112b-5773-9946-6e5c7112971c}\hqghumeaylnlf.exe (PC Utilities Software Limited) Startup: C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recorte de tela e Iniciador do OneNote 2007.lnk [2015-05-12] ShortcutTarget: Recorte de tela e Iniciador do OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] () ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] () ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] () ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => No File ShellIconOverlayIdentifiers: [ExplorerEx] -> {E056AFDD-03E9-4D73-8D33-8FCCBCA73438} => C:\Users\Casa\AppData\Roaming\Macwebtoise\explorerEx64.dll [2015-01-22] () ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] () ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] () ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Casa\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:65477;https=127.0.0.1:65477; HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID=617911&ResetID=130918373917078690&GUID=68F1EA47-E93E-495D-B174-A3E2733827C8 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.searchult.com/?bd=ds&oem=cds&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&version=2.3.0.9239&pid=414031160&tid=554&q={searchTerms} HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKapPZK_Te_JFfpX42ANEwDOSw1XbdrKiKZaTe809gi9uFlS2Oh7xBgLF6Ea9K9ef0oz26JMGtPy_i9B8BFpXEu5PV-KQ, HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.baixaki.com.br/portal/?utm_source=sol&utm_medium=ppi&utm_campaign=portal HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://smartsputnik.ru/?ri=1&uid=d9cfb0b813ebeec68658cdd4fabaf04f&q={searchTerms} HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} URLSearchHook: HKLM-x32 - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} URLSearchHook: [S-1-5-21-3029540503-3706228234-1220206705-1000] ATTENTION ==> Default URLSearchHook is missing SearchScopes: HKLM -> DefaultScope {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> OldSearch URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_bxi01_15_04_ch&cd=2XzuyEtN2Y1L1QzutDzzyCtDyC0EyDyCtDyD0ByE0EyDtDyBtN0D0Tzu0StCtCtBtDtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyEtCtCzy0AyDtDzytG0E0D0DtCtGzz0CzztCtGzzyD0DyDtGtAzz0A0CtAzy0ByB0E0D0B0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtC0A0A0CtB0F0AtGtA0Ezy0CtGyE0AtA0AtGzyzy0C0AtG0AyDtByCtDtB0CyDyD0FyDyC2Q&cr=452709962&ir= SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid=320&itype=a&ver=15005&tm=603&src=ds&p={searchTerms} SearchScopes: HKLM -> {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = SearchScopes: HKLM-x32 -> ielnksrch URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid=320&itype=a&ver=15005&tm=603&src=ds&p={searchTerms} SearchScopes: HKLM-x32 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.thesearchpage.info/?l=1&q={searchTerms}&pid=2457&r=2015/01/15&hid=10016137845286072043&lg=EN&cc=BR&unqvl=74 SearchScopes: HKLM-x32 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM-x32 -> {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> DefaultScope {ielnksrch} URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> OldSearch URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3C} URL = http://smartsputnik.ru/?ri=1&uid=d9cfb0b813ebeec68658cdd4fabaf04f&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3D} URL = http://smartsputnik.ru/?ri=1&uid=d9cfb0b813ebeec68658cdd4fabaf04f&q= SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {B9A0191A-DF8A-47B4-B8F6-9937EF2702DE} URL = http://br.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ir_15_15¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDzzyCtDyC0EyDyCtDyD0ByE0EyDtDyBtN0D0Tzu0StCtCzzyEtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyE0F0BtDtAyE0DtG0F0AtD0DtG0CzytA0DtGyCzyzyzztGyD0B0B0D0ByEzztB0ByB0CyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtC0A0A0CtB0F0AtGtA0Ezy0CtGyE0AtA0AtGzyzy0C0AtG0AyDtByCtDtB0CyDyD0FyDyC2QtN0A0LzutB%26cr%3D1734649387%26a%3Dwny_ir_15_15%26os%3DWindows 7 Ultimate&p={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {BE8EBFCD-B0E2-415E-AB48-B6F5EFE6494B} URL = http://www.search.ask.com/web?tpid=ATU4SP-MED&o=APN11391&pf=V7&p2=^BAY^YYYYYY^YY^BR&gct=sb&itbv=12.28.1.1226&apn_uid=D646F06B-8F0F-409F-A544-A26A5033C0C9&apn_ptnrs=^BAY&apn_dtid=^YYYYYY^YY^BR&apn_dbr=cr_42.0.2311.152&doi=2015-05-17&trgb=CR&q={searchTerms}&psv=&pt=tb SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {E4E012DC-1925-48E9-8010-2D195574642A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST3750640NS_5QD1KWTQXXXX5QD1KWTQ&ts=1426537096&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> {ielnksrch} URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP24eo9kfZX0nx5RMmRzsFGKeNSjntU1m5dTo8zmFXS4pfSAVng0s9J0KJ0PjZC0j_6YUq_6j08_XisDBNGw-Tu0EuQmRKZr9XUwRbGl0g_oVoaBTlKEENoeZiU77MOuaXtEkM7yxST6bhqBP3aDtgxXIzwmFAyWnXAC3iemWvamPCttHYEE-TsD0,&q={searchTerms} BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) Toolbar: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> No Name - {41545534-2D53-5000-76A7-7A786E7484D7} - No File Toolbar: HKU\S-1-5-21-3029540503-3706228234-1220206705-1000 -> No Name - {41545534-5350-2D4D-4544-7A786E7484D7} - No File Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) Handler: WSISVCUchrome - No CLSID Value Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-12-21] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-12-21] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-12-21] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-12-21] (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{51902F85-692E-4225-B885-C62B9E8245F4}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{51902F85-692E-4225-B885-C62B9E8245F4}: [DhcpNameServer] 192.168.1.1 StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default FF NewTab: C:\\ProgramData\\Sailitys\\ff.NT FF DefaultSearchEngine: findit FF DefaultSearchEngine,S: WebSearch FF DefaultSearchUrl: hxxp://websearch.hotsearches.info/?pid=23765&r=2015/07/02&hid=10016137845286072043&lg=EN&cc=BR&unqvl=90&l=1&q= FF SearchEngineOrder.1: WebSearch FF SearchEngineOrder.1,S: WebSearch FF SelectedSearchEngine: Default FF SelectedSearchEngine,S: WebSearch FF Homepage: C:\\ProgramData\\Sailitys\\ff.HP FF Keyword.URL: hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgPUQgVFwZCbQELUQ5cFQdCdxRaWFoSDFcXI1tcVloSQAYWeB9aFQQTR0cFME0FB18EURNNfWpdBGsUUkBPNEpwFFs=&q={searchTerms} FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-12-17] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-12-17] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2015-11-18] (Adobe Systems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Casa\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-05-27] (Raidcall) FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Casa\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File] FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-19] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-19] (Google Inc.) FF Plugin HKU\S-1-5-21-3029540503-3706228234-1220206705-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Casa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-09-10] (Unity Technologies ApS) FF user.js: detected! => C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\user.js [2015-10-29] FF SearchPlugin: C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\searchplugins\findit.xml [2016-02-18] FF SearchPlugin: C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\searchplugins\WebSearch.xml [2015-07-07] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\findit.xml [2016-02-18] FF Extension: Yellow AdBlocker - C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\Extensions\gdodupagpoubevx@_iuymmxdcefubaho.net [2015-08-21] FF Extension: GreatSAvve4U - C:\Users\Casa\AppData\Roaming\Mozilla\Firefox\Profiles\r5nqm5ni.default\Extensions\NJCJol@vakvs.edu [2015-08-21] FF HKLM\...\Firefox\Extensions: [{5081D2D4-1637-404c-B74F-50526718257D}] - C:\Program Files\shopperz\Firefox FF HKLM-x32\...\Firefox\Extensions: [{5081D2D4-1637-404c-B74F-50526718257D}] - C:\Program Files\shopperz\Firefox FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found] Chrome: ======= CHR Profile: C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-08] CHR Extension: (YouTube) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-08] CHR Extension: (Google Search) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-08] CHR Extension: (Gmail) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-08] CHR Profile: C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Drive) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-12] CHR Extension: (Video Game Truck Advertising) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\befkjchdmahejikgbnefikmbeahhippp [2016-05-04] CHR Extension: (YouTube) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-19] CHR Extension: (Google Search) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-12] CHR Extension: (Chrome Web Store Payments) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-19] CHR Extension: (Gmail) - C:\Users\Casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-19] CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - http://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3029540503-3706228234-1220206705-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fgbcffenncokfocljomejddmgcpppjom] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - http://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08] CHR HKLM-x32\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) R2 ClockerService; C:\Program Files\Common Files\Clocker\Clocker.exe [77824 2015-01-28] (Greenwichers) [File not signed] R2 CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe [667136 2016-02-18] () [File not signed] R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation) R2 MyLocalService; C:\Windows\SysWOW64\NetService\netservice.exe [226888 2015-01-20] (QNT) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [275752 2008-01-22] (Nero AG) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1286896 2016-04-05] (Overwolf LTD) R2 PopService; C:\Program Files\PopService\PopService.exe [38464 2015-05-22] () R2 Sed; C:\Users\Casa\AppData\Roaming\ntsvc\ntsvc.exe [388072 2015-05-21] (Navigation Co., Ltd.) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 crfilterdrv; C:\Windows\System32\drivers\crfilterdrv.sys [51528 2015-02-25] (Windows (R) Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-12-28] (Disc Soft Ltd) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation) R1 pofilterdrv; C:\Windows\System32\drivers\pofilterdrv.sys [60736 2015-01-19] (NetFilterSDK.com) S1 bmekvmlw; \??\C:\Windows\system32\drivers\bmekvmlw.sys [X] S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X] S1 ccnfd_1_10_0_5; system32\drivers\ccnfd_1_10_0_5.sys [X] S1 cherimoya; system32\drivers\cherimoya.sys [X] S3 PCFApiUtil; \??\C:\Program Files (x86)\Baidu Security\PC Faster\5.0.0.0\PCFApiUtil64.sys [X] S1 wsfd_1_10_0_17; system32\drivers\wsfd_1_10_0_17.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Three Months Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-05-04 17:53 - 2016-05-04 17:59 - 00043855 _____ C:\Users\Casa\Downloads\Addition.txt 2016-05-04 17:53 - 2016-05-04 17:54 - 00000000 ____D C:\Program Files (x86)\Shadow Warrior 2016-05-04 17:52 - 2016-05-04 18:11 - 00029143 _____ C:\Users\Casa\Downloads\FRST.txt 2016-05-04 17:52 - 2016-05-04 18:06 - 00000000 ____D C:\FRST 2016-05-04 17:51 - 2016-05-04 17:51 - 02170368 _____ (Farbar) C:\Users\Casa\Downloads\frst64.exe 2016-05-04 17:50 - 2016-05-04 17:50 - 01728000 _____ (Farbar) C:\Users\Casa\Downloads\FRST.exe 2016-05-04 17:25 - 2016-05-04 17:25 - 15870928 _____ C:\Users\Casa\Downloads\Cemu 1.4.2b Fixed.rar 2016-05-04 17:20 - 2016-05-04 17:20 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync 2016-05-04 17:20 - 2016-05-04 17:20 - 00000000 ____D C:\Users\Casa\AppData\Local\Mega Limited 2016-05-04 17:19 - 2016-05-04 17:20 - 00000000 ____D C:\Users\Casa\AppData\Local\MEGAsync 2016-05-04 17:18 - 2016-05-04 17:19 - 11944801 _____ C:\Users\Casa\Downloads\citra-latest-windows-amd64.7z 2016-05-04 17:14 - 2016-05-04 17:16 - 10629936 _____ (MEGA Limited) C:\Users\Casa\Downloads\MEGAsyncSetup.exe 2016-05-04 17:13 - 2016-05-04 17:15 - 14572000 _____ (Microsoft Corporation) C:\Users\Casa\Downloads\vc_redist.x64.exe 2016-05-03 19:39 - 2016-05-03 19:39 - 03750018 _____ C:\Users\Casa\Downloads\content.rar 2016-05-03 19:18 - 2016-05-03 19:18 - 01735558 _____ C:\Users\Casa\Downloads\cemu_1.4.0 (2).zip 2016-05-03 18:44 - 2016-05-03 18:44 - 00000000 ____D C:\Users\Casa\Desktop\Emulador de Controle Tomb Raider - x360ce - Cópia 2016-05-03 18:04 - 2016-05-03 18:04 - 00000000 ____D C:\Users\Casa\Desktop\CemuMod Fusion Ver 1.0 2016-05-03 18:03 - 2016-05-03 18:03 - 00001015 _____ C:\Users\Casa\Downloads\Cemu 1.4.0 Fix Version 1.0 Luigui U por Inmortalgames (1).txt 2016-05-03 18:02 - 2016-05-03 18:03 - 10414123 _____ C:\Users\Casa\Downloads\CemuMod Fusion Ver 1.0.rar 2016-05-03 06:32 - 2016-05-03 06:32 - 00083796 _____ C:\Users\Casa\Downloads\Super.Mario.3D.World.USA.WiiU-PoWeRUp-7z.torrent 2016-05-02 16:32 - 2016-05-02 16:32 - 01735558 _____ C:\Users\Casa\Downloads\cemu_1.4.0.zip 2016-05-02 16:22 - 2016-05-02 16:21 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2016-05-01 17:52 - 2016-05-01 17:52 - 07496523 _____ C:\Users\Casa\Downloads\58759762316322 (1).rar 2016-05-01 17:51 - 2016-05-01 18:15 - 00000000 ____D C:\Users\Casa\Downloads\New Super Mario Bros U [USA] Loadiine READY2PLAY 2016-05-01 17:51 - 2016-05-01 17:51 - 00024461 _____ C:\Users\Casa\Downloads\New Super Mario Bros U [USA] Loadiine READY2PLAY.torrent 2016-05-01 17:30 - 2016-05-01 17:30 - 00001015 _____ C:\Users\Casa\Downloads\Cemu 1.4.0 Fix Version 1.0 Luigui U por Inmortalgames.txt 2016-05-01 17:30 - 2016-05-01 17:30 - 00001008 _____ C:\Users\Casa\Downloads\Cemu 1.4.2 Version Oficial por Inmortalgames.txt 2016-04-30 17:31 - 2016-05-03 06:44 - 00000000 ____D C:\Users\Casa\Downloads\Shadow_Warrior-FLT 2016-04-30 17:19 - 2016-04-30 17:19 - 00023086 _____ C:\Users\Casa\Downloads\shadow-warrior-special-edition-multi11pcdvdprophet.torrent 2016-04-29 18:02 - 2016-04-29 18:35 - 00000000 ____D C:\Users\Casa\Downloads\Costume.Quest.v1.0.11.MacOSX.READNFO-EZGAME.www.GamesTorrents.com 2016-04-29 18:01 - 2016-04-29 18:01 - 00012048 _____ C:\Users\Casa\Downloads\costumequestv1011macosxreadnfo-ezgame[www.gamestorrent.biz] (1).torrent 2016-04-28 19:27 - 2016-04-28 19:27 - 00072851 _____ C:\Users\Casa\Downloads\COSTUME.QUEST.2.V1.0.ALL.RITUEL.NODVD.ZIP 2016-04-28 19:25 - 2016-04-28 19:26 - 00918688 _____ C:\Users\Casa\Downloads\d3dx9.zip 2016-04-28 18:15 - 2016-04-28 18:15 - 00012048 _____ C:\Users\Casa\Downloads\costumequestv1011macosxreadnfo-ezgame[www.gamestorrent.biz].torrent 2016-04-28 06:55 - 2016-04-28 06:55 - 00000000 ____D C:\Users\Casa\Downloads\Alan.Wake-SKIDROW 2016-04-27 19:14 - 2016-04-27 19:14 - 00000000 _____ C:\Users\Casa\Desktop\Novo Documento de Texto (5).txt 2016-04-27 18:58 - 2016-04-27 18:58 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Doublefine 2016-04-27 17:46 - 2016-04-27 17:46 - 00000593 _____ C:\Users\Casa\Desktop\Cemu - Atalho.lnk 2016-04-27 17:40 - 2016-04-27 17:40 - 07496523 _____ C:\Users\Casa\Downloads\new super mario bros u fix.rar 2016-04-27 10:53 - 2016-04-27 10:53 - 00001724 _____ C:\Users\Casa\Downloads\Castlevania Lords Of Shadow 2 [MULTI6][PCDVD][Repack BlackBox][WwW.GamesTorrents.CoM] - Atalho.lnk 2016-04-27 10:53 - 2016-04-27 10:53 - 00001409 _____ C:\Users\Casa\Downloads\New Super Luigi U [EUR] MULTi8 Loadiine READY2PLAY - Atalho.lnk 2016-04-27 10:53 - 2016-04-27 10:53 - 00001391 _____ C:\Users\Casa\Downloads\New Super Mario Bros U [USA] Loadiine READY2PLAY - Atalho.lnk 2016-04-26 19:14 - 2016-04-27 18:51 - 980795931 ____R (Игры на Cat-A-Cat.NET ) C:\Users\Casa\Downloads\Costume Quest 2.exe 2016-04-26 16:39 - 2016-04-26 17:49 - 00000000 ____D C:\Users\Casa\Downloads\State.of.Decay-WaLMaRT 2016-04-26 06:45 - 2016-04-26 07:12 - 00000000 ____D C:\Users\Casa\Downloads\The Big Bang Theory 3 Temporada - The Pirate Filmes 2016-04-26 06:45 - 2016-04-26 07:03 - 00000000 ____D C:\Users\Casa\Downloads\The Big Bang Theory 2 Temporada - The Pirate Filmes 2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\Users\Todos os Usuários\.mono 2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\Users\Casa\AppData\Roaming\.mono 2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\ProgramData\.mono 2016-04-25 19:16 - 2016-04-25 19:16 - 00017483 _____ C:\Windows\DirectX.log 2016-04-25 18:37 - 2016-05-02 00:50 - 00000910 _____ C:\Users\Casa\Desktop\Novo Documento de Texto.txt 2016-04-25 05:34 - 2016-04-25 05:34 - 00039324 _____ C:\Users\Casa\Desktop\doença.htm 2016-04-24 18:40 - 2016-04-25 18:42 - 00000000 ____D C:\Program Files (x86)\Remedy Entertainment 2016-04-24 17:32 - 2016-04-24 17:33 - 00000000 ____D C:\Users\Casa\Desktop\Uma familia da pesada 2016-04-23 11:27 - 2016-04-23 11:27 - 00000000 ____D C:\Users\Casa\Documents\League of Legends 2016-04-23 08:38 - 2016-04-23 08:38 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-04-23 08:38 - 2016-04-23 08:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewFeature1 2016-04-23 08:37 - 2016-04-23 08:37 - 00000000 ____D C:\Users\Casa\Desktop\League of Legends 2016-04-22 19:45 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2016-04-22 19:45 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2016-04-22 19:45 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2016-04-22 19:44 - 2016-04-22 19:44 - 00000000 ____D C:\Riot Games 2016-04-22 16:18 - 2016-04-22 16:18 - 00000000 ____D C:\Users\Casa\Downloads\The.Walking.Dead.S06E01.PROPER.720p.HDTV.x264-KILLERS[rarbg] 2016-04-20 01:54 - 2016-04-20 02:10 - 00000000 ____D C:\Users\Casa\Downloads\Inatividade Paranormal (www.thePirateFilmes.com) 2016-04-19 06:54 - 2016-04-21 19:23 - 00000000 ____D C:\Users\Casa\Desktop\beelzebub 2016-04-19 06:43 - 2016-04-19 06:46 - 00000000 ____D C:\Users\Casa\Downloads\Inatividade Paranormal 2.(2014).Dublado.1080p.By.Luan.Harper 2016-04-16 18:29 - 2016-04-21 23:08 - 00000000 ____D C:\Users\Casa\Downloads\The Big Bang Theory 1 Temporada - The Pirate Filmes 2016-04-16 13:39 - 2016-04-16 13:39 - 00000408 _____ C:\Windows\Tasks\Overwolf Updater Task.job 2016-04-16 13:39 - 2016-04-16 13:39 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2016-04-16 13:39 - 2016-04-16 13:39 - 00000000 ____D C:\Program Files (x86)\Overwolf 2016-04-16 13:38 - 2016-04-16 13:39 - 00000000 ____D C:\Users\Todos os Usuários\Overwolf 2016-04-16 13:38 - 2016-04-16 13:39 - 00000000 ____D C:\ProgramData\Overwolf 2016-04-16 13:37 - 2016-04-30 09:13 - 00000000 ____D C:\Users\Casa\AppData\Roaming\TS3Client 2016-04-16 13:37 - 2016-04-16 13:44 - 00000000 ____D C:\Users\Casa\AppData\Local\Overwolf 2016-04-16 13:37 - 2016-04-16 13:37 - 00000967 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2016-04-16 13:37 - 2016-04-16 13:37 - 00000929 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk 2016-04-16 13:37 - 2016-04-16 13:37 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2016-04-15 09:59 - 2016-04-16 13:27 - 00000000 ____D C:\Program Files (x86)\TeamSpeak 3 Client 2016-04-14 19:29 - 2016-04-22 16:22 - 00000000 ____D C:\Users\Casa\Downloads\Uma.Aventura.Animal.na.Terra.do.Vento.2015.HDRip.XviD.Dublado-OSR 2016-04-14 12:10 - 2016-05-01 18:07 - 00000000 ____D C:\Users\Casa\Desktop\cemu_1.4.1 2016-04-14 12:10 - 2016-04-14 12:10 - 01742620 _____ C:\Users\Casa\Downloads\cemu_1.4.1.zip 2016-04-09 02:14 - 2016-04-09 02:37 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural - 10ª Temporada (2015) BluRay BDrip 720p Dual Áudio - HipnosTPF 2016-04-06 20:01 - 2016-04-24 19:18 - 00000000 ____D C:\Program Files (x86)\Dishonored 2016-03-29 20:06 - 2016-04-27 17:41 - 00000000 ____D C:\Users\Casa\Desktop\fairy tail 2016-03-29 05:04 - 2016-05-04 04:59 - 00012798 _____ C:\Windows\setupact.log 2016-03-29 05:04 - 2016-03-29 05:04 - 00000000 _____ C:\Windows\setuperr.log 2016-03-27 22:52 - 2016-03-30 06:01 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural - 8º Temporada (2012) BDRip 720p Dublado - Douglasvip 2016-03-23 19:00 - 2016-04-15 14:29 - 00000310 _____ C:\Users\Casa\Desktop\Novo Documento de Texto (4).txt 2016-03-22 19:15 - 2016-03-22 19:15 - 00000000 ____D C:\Users\Casa\Documents\CAPCOM 2016-03-21 20:06 - 2016-03-21 20:06 - 00000000 ____D C:\Users\Casa\Downloads\Resident Evil 6 Complete Pack (Capcom) (MULTi8 l ENG l RUS) [L] - PROPHET 2016-03-19 00:02 - 2016-03-19 03:10 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural - 7ª Temporada (2011) DUBLADO 720p_Douglasvip 2016-03-18 17:56 - 2016-03-29 09:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Titans Of Wow - Pandaria 5.4.8 2016-03-13 22:25 - 2016-03-16 16:15 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural 6 Temporada - The Pirate Filmes 2016-03-13 17:49 - 2016-05-03 18:15 - 00000000 ____D C:\Users\Casa\Downloads\Super.Mario.3D.World.USA.WiiU-PoWeRUp-7z 2016-03-13 02:02 - 2016-03-13 02:02 - 00000000 ____D C:\5412e79ae2ce9173f016fef024 2016-03-12 18:19 - 2016-03-12 19:02 - 00000000 ____D C:\Users\Casa\Downloads\New Super Luigi U [EUR] MULTi8 Loadiine READY2PLAY 2016-03-09 06:51 - 2016-03-14 20:31 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural 5 Temporada - The Pirate Filmes 2016-03-08 18:21 - 2016-03-08 18:21 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameVicio 2016-03-08 18:21 - 2016-03-08 18:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameVicio 2016-03-08 18:21 - 2016-03-08 18:21 - 00000000 ____D C:\Program Files (x86)\GameVicio 2016-03-08 17:17 - 2016-03-08 17:39 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft Games 2016-03-08 14:46 - 2016-03-08 14:46 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Gears of War 2016-03-07 17:23 - 2016-03-07 17:23 - 00000000 ____D C:\Users\paulo.Casa-PC\Documents\My Games 2016-03-07 17:23 - 2016-03-07 17:23 - 00000000 ____D C:\Users\paulo.Casa-PC\AppData\Local\SKIDROW 2016-03-07 17:21 - 2016-04-28 14:39 - 00000000 ____D C:\Users\paulo.Casa-PC 2016-03-07 17:21 - 2016-03-07 17:22 - 00002374 _____ C:\Users\paulo.Casa-PC\Desktop\Google Chrome.lnk 2016-03-07 17:21 - 2016-03-07 17:22 - 00000000 ____D C:\Users\paulo.Casa-PC\AppData\Local\VirtualStore 2016-03-07 17:21 - 2016-03-07 17:21 - 00108840 _____ C:\Users\paulo.Casa-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2016-03-07 17:21 - 2016-03-07 17:21 - 00001423 _____ C:\Users\paulo.Casa-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-03-07 17:21 - 2016-03-07 17:21 - 00001389 _____ C:\Users\paulo.Casa-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2016-03-07 17:21 - 2016-03-07 17:21 - 00000020 ___SH C:\Users\paulo.Casa-PC\ntuser.ini 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Modelos 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Meus documentos 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Menu Iniciar 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Documents\Minhas músicas 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Documents\Minhas imagens 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Documents\Meus vídeos 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Dados de aplicativos 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Configurações locais 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\AppData\Local\Histórico 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\AppData\Local\Dados de aplicativos 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Ambiente de rede 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 _SHDL C:\Users\paulo.Casa-PC\Ambiente de impressão 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 ____D C:\Users\paulo.Casa-PC\AppData\Local\iSkysoft 2016-03-07 17:21 - 2016-03-07 17:21 - 00000000 ____D C:\Users\paulo.Casa-PC\AppData\Local\Google 2016-03-07 17:21 - 2014-12-30 02:03 - 00000000 ____D C:\Users\paulo.Casa-PC\AppData\Local\Microsoft Help 2016-03-07 17:21 - 2009-07-14 01:54 - 00000000 ___RD C:\Users\paulo.Casa-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2016-03-07 17:21 - 2009-07-14 01:49 - 00000000 ___RD C:\Users\paulo.Casa-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2016-03-07 12:19 - 2016-03-07 12:25 - 00000000 ____D C:\Users\Casa\Desktop\fotos de mateus 2016-03-07 12:14 - 2016-03-07 12:17 - 00000000 ____D C:\Users\Casa\Desktop\musicas de mateus 2016-03-07 12:11 - 2016-03-16 14:30 - 00000000 ____D C:\Users\Casa\Desktop\video de mateus 2016-03-06 02:00 - 2016-03-06 02:47 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural 4 Temporada - The Pirate Filmes 2016-03-05 07:48 - 2016-03-07 17:21 - 00000000 ____D C:\Users\paulo 2016-03-05 07:48 - 2016-03-05 07:48 - 00002257 _____ C:\Users\paulo\Desktop\Google Chrome.lnk 2016-03-05 07:48 - 2016-03-05 07:48 - 00000020 ___SH C:\Users\paulo\ntuser.ini 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Modelos 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Meus documentos 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Menu Iniciar 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Documents\Minhas músicas 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Documents\Minhas imagens 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Documents\Meus vídeos 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Dados de aplicativos 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Configurações locais 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\AppData\Local\Histórico 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\AppData\Local\Dados de aplicativos 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Ambiente de rede 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 _SHDL C:\Users\paulo\Ambiente de impressão 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 ____D C:\Users\paulo\AppData\Local\VirtualStore 2016-03-05 07:48 - 2016-03-05 07:48 - 00000000 ____D C:\Users\paulo\AppData\Local\Google 2016-03-05 07:48 - 2014-12-30 02:03 - 00000000 ____D C:\Users\paulo\AppData\Local\Microsoft Help 2016-03-05 07:48 - 2009-07-14 01:54 - 00000000 ___RD C:\Users\paulo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2016-03-05 07:48 - 2009-07-14 01:49 - 00000000 ___RD C:\Users\paulo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2016-03-04 23:16 - 2016-03-04 23:16 - 00015360 ___SH C:\Users\Casa\Downloads\Thumbs.db 2016-03-04 18:10 - 2016-03-04 18:12 - 00000188 _____ C:\Windows\SysWOW64\PATCH.ERR 2016-03-04 16:38 - 2016-03-04 16:44 - 00000000 ____D C:\Titans Of Wow 2016-03-04 16:38 - 2016-03-04 16:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Titans Of Wow 2016-03-03 18:59 - 2016-03-22 19:12 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Bioshock 2016-03-03 18:59 - 2016-03-03 19:09 - 00000000 ____D C:\Users\Casa\Documents\Bioshock 2016-03-03 18:59 - 2016-03-03 18:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tribo Gamer 2016-03-03 18:59 - 2016-03-03 18:59 - 00000000 ____D C:\Program Files (x86)\Tribo Gamer 2016-03-03 18:40 - 2016-03-06 17:34 - 00001819 _____ C:\Users\Casa\Desktop\Play BioShock.lnk 2016-03-03 18:12 - 2016-03-03 18:12 - 00000000 ____D C:\Users\Casa\AppData\Roaming\MMFApplications 2016-03-03 18:09 - 2016-03-03 18:09 - 00000000 ____D C:\Users\Casa\Documents\The Escapists 2016-03-01 19:16 - 2016-03-01 19:16 - 00000000 ____D C:\Users\Casa\Documents\FLiNGTrainer 2016-03-01 19:13 - 2016-03-01 19:13 - 00000000 ____D C:\Program Files (x86)\Rainy Night Creations 2016-03-01 18:03 - 2016-03-01 18:03 - 00000000 ____D C:\Users\Casa\Documents\Battlefield 3 2016-02-29 18:58 - 2016-02-29 18:58 - 00000000 ____D C:\Users\Casa\Documents\My Cheat Tables 2016-02-28 18:30 - 2016-03-04 15:10 - 00000083 _____ C:\Users\Casa\Desktop\Novo Documento de Texto (2).txt 2016-02-27 19:14 - 2016-02-27 19:14 - 00000000 ____D C:\Users\Casa\AppData\Local\Bluestacks 2016-02-27 09:49 - 2016-03-04 13:45 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural 3 Temporada - The Pirate Filmes 2016-02-26 11:27 - 2016-02-26 11:27 - 00000286 ____H C:\Windows\Tasks\User_Feed_Synchronization-{0373942C-C445-4530-B8E9-96DDA48E3F67}.job 2016-02-25 19:52 - 2016-02-25 19:50 - 00196608 _____ C:\Windows\B3104CC2-071F-45C3-BE66-487CF59C2A03.Diagnose.0.etl 2016-02-25 19:52 - 2016-02-25 19:50 - 00002978 _____ C:\Windows\ipconfig.all.txt 2016-02-25 14:49 - 2016-02-27 02:20 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural 2 Temporada - The Pirate Filmes 2016-02-25 03:00 - 2016-02-25 03:01 - 00000000 ____D C:\Windows\Temp5A9E4FA0-2B31-BB10-2768-77C476CB2FC1-Signatures 2016-02-24 17:33 - 2016-02-24 17:50 - 00000000 ____D C:\Users\Casa\Downloads\Sobrenatural 1 Temporada - The Pirate Filmes 2016-02-24 12:38 - 2014-05-16 14:04 - 00254240 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys 2016-02-24 03:00 - 2016-02-24 03:00 - 00000000 ____D C:\Windows\Temp868E13B4-6B54-77F7-CB8C-DAAF7B282C49-Signatures 2016-02-23 18:38 - 2016-04-24 19:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics 2016-02-23 18:26 - 2016-04-24 19:17 - 00000000 ____D C:\Program Files (x86)\R.G. Mechanics 2016-02-22 22:43 - 2016-02-22 22:43 - 00000312 _____ C:\Windows\Tasks\Chrome Cleanup Tool post reboot run.job 2016-02-22 22:42 - 2016-02-23 00:39 - 00000342 _____ C:\Windows\Tasks\Chrome Cleanup Tool logs upload retry.job 2016-02-20 18:39 - 2016-02-21 18:13 - 00000000 ____D C:\Users\Casa\AppData\Local\Fallout3 2016-02-20 18:21 - 2016-02-20 18:21 - 00000000 ____D C:\Windows\SysWOW64\xlive 2016-02-19 19:58 - 2016-02-19 19:58 - 00000000 ____D C:\Users\Todos os Usuários\levelup downloader 2016-02-19 19:58 - 2016-02-19 19:58 - 00000000 ____D C:\Users\Casa\AppData\Local\IsolatedStorage 2016-02-19 19:58 - 2016-02-19 19:58 - 00000000 ____D C:\ProgramData\levelup downloader 2016-02-19 18:24 - 2016-05-02 16:21 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-02-19 18:12 - 2016-02-19 18:12 - 00001060 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d16b5a365bb7ea.job 2016-02-18 18:53 - 2016-02-18 18:53 - 00000000 ____D C:\Users\Todos os Usuários\Sailitys 2016-02-18 18:53 - 2016-02-18 18:53 - 00000000 ____D C:\ProgramData\Sailitys 2016-02-18 18:52 - 2016-02-18 18:52 - 07951360 _____ C:\Users\Casa\AppData\Roaming\agent.dat 2016-02-18 18:52 - 2016-02-18 18:52 - 01882213 _____ C:\Users\Casa\AppData\Roaming\Over-La.tst 2016-02-18 18:52 - 2016-02-18 18:52 - 00188584 _____ () C:\Users\Casa\AppData\Roaming\U-lux.bin 2016-02-18 18:52 - 2016-02-18 18:52 - 00126464 _____ C:\Users\Casa\AppData\Roaming\noah.dat 2016-02-18 18:52 - 2016-02-18 18:52 - 00126464 _____ C:\Users\Casa\AppData\Roaming\lobby.dat 2016-02-18 18:52 - 2016-02-18 18:52 - 00072777 _____ C:\Users\Casa\AppData\Roaming\TranKeylax.tst 2016-02-18 18:52 - 2016-02-18 18:52 - 00063696 _____ C:\Users\Casa\AppData\Roaming\Config.xml 2016-02-18 18:52 - 2016-02-18 18:52 - 00054272 _____ C:\Users\Casa\AppData\Roaming\ApplicationHosting.dat 2016-02-18 18:52 - 2016-02-18 18:52 - 00018432 _____ C:\Users\Casa\AppData\Roaming\Main.dat 2016-02-18 18:52 - 2016-02-18 18:52 - 00005568 _____ C:\Users\Casa\AppData\Roaming\md.xml 2016-02-18 18:52 - 2016-02-18 18:52 - 00000000 ____D C:\Users\Todos os Usuários\CloudPrinter 2016-02-18 18:52 - 2016-02-18 18:52 - 00000000 ____D C:\ProgramData\CloudPrinter 2016-02-18 18:52 - 2016-02-18 18:49 - 00667136 _____ C:\Users\Casa\AppData\Roaming\TranKeylax.exe 2016-02-18 18:52 - 2016-02-18 18:49 - 00667136 _____ C:\Users\Casa\AppData\Roaming\Over-La.exe 2016-02-18 18:51 - 2016-02-18 18:51 - 00848437 _____ C:\Users\Casa\AppData\Roaming\Trustron.bin 2016-02-18 18:51 - 2016-02-18 18:51 - 00000163 _____ C:\Windows\SysWOW64\L 2016-02-18 18:50 - 2016-02-18 18:50 - 00001001 _____ C:\Windows\SysWOW64\${LOGFILE} 2016-02-18 18:49 - 2016-02-19 12:09 - 00000000 ____D C:\Users\Casa\AppData\Roaming\WTools 2016-02-18 18:49 - 2016-02-18 19:06 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Store 2016-02-18 18:49 - 2016-02-18 18:50 - 00016992 _____ C:\Users\Casa\AppData\Roaming\InstallationConfiguration.xml 2016-02-18 18:49 - 2016-02-18 18:49 - 00126976 _____ C:\Users\Casa\AppData\Roaming\Installer.dat 2016-02-18 18:49 - 2016-02-18 18:49 - 00000078 _____ C:\Users\Casa\AppData\Roaming\Selection Tools.installation.log 2016-02-18 18:48 - 2016-02-18 18:50 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Nosibay 2016-02-18 18:48 - 2016-02-18 18:49 - 00001344 _____ C:\Users\Casa\AppData\Roaming\Bubble Dock.boostrap.log 2016-02-18 18:48 - 2016-02-18 18:49 - 00000078 _____ C:\Users\Casa\AppData\Roaming\WindApp.installation.log 2016-02-18 18:48 - 2016-02-18 18:48 - 00005707 _____ C:\Users\Casa\AppData\Roaming\Bubble Dock.installation.log 2016-02-18 18:48 - 2016-02-18 18:48 - 00000097 _____ C:\Users\Casa\AppData\Roaming\WindApp.boostrap.log 2016-02-18 18:47 - 2016-02-18 18:47 - 00828928 _____ C:\Windows\SysWOW64\SearchProtectService.exe 2016-02-18 10:18 - 2016-02-18 10:19 - 00000000 ____D C:\Users\Todos os Usuários\Battle.net 2016-02-18 10:18 - 2016-02-18 10:19 - 00000000 ____D C:\ProgramData\Battle.net 2016-02-17 15:05 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2016-02-17 15:05 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2016-02-17 15:05 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2016-02-17 15:05 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2016-02-17 15:05 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2016-02-17 15:05 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2016-02-17 15:05 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2016-02-17 15:05 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2016-02-17 15:05 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2016-02-17 15:05 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2016-02-17 15:05 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2016-02-17 15:05 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2016-02-17 15:05 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2016-02-17 15:05 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2016-02-17 15:05 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2016-02-17 15:05 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2016-02-17 15:05 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2016-02-17 15:04 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2016-02-17 15:04 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2016-02-17 15:04 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2016-02-17 15:04 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2016-02-17 15:04 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2016-02-17 15:04 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2016-02-17 15:04 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2016-02-17 15:04 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2016-02-17 15:04 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2016-02-17 15:04 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2016-02-17 15:04 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2016-02-17 15:04 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2016-02-17 15:04 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2016-02-17 15:04 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2016-02-17 15:04 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2016-02-17 15:04 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2016-02-17 15:04 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2016-02-17 15:04 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2016-02-17 15:04 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2016-02-17 15:04 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2016-02-17 15:04 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2016-02-17 15:04 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2016-02-17 15:04 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2016-02-17 15:04 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2016-02-17 15:04 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2016-02-17 15:03 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2016-02-17 15:03 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2016-02-17 15:03 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2016-02-17 15:03 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2016-02-17 15:03 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2016-02-17 15:03 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2016-02-17 15:03 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2016-02-17 15:03 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2016-02-17 15:03 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2016-02-17 15:03 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2016-02-17 15:03 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2016-02-17 15:03 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2016-02-17 15:03 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2016-02-17 15:03 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2016-02-17 15:03 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2016-02-17 15:03 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2016-02-17 15:03 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2016-02-17 15:03 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2016-02-17 15:03 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2016-02-17 15:02 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2016-02-17 15:02 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2016-02-17 15:02 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2016-02-17 15:02 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2016-02-17 15:02 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2016-02-17 15:02 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2016-02-17 15:02 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2016-02-17 15:02 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2016-02-17 15:02 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2016-02-17 15:02 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2016-02-17 15:02 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2016-02-17 15:01 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2016-02-17 15:01 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2016-02-17 15:01 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2016-02-17 15:01 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2016-02-17 15:01 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2016-02-17 15:01 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2016-02-17 15:01 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2016-02-17 15:01 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2016-02-17 15:01 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2016-02-17 14:59 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2016-02-17 14:59 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2016-02-17 14:59 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2016-02-17 14:59 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2016-02-17 14:59 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2016-02-17 14:59 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2016-02-17 14:59 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2016-02-17 14:58 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2016-02-17 14:58 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2016-02-17 14:58 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2016-02-17 14:58 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2016-02-17 14:58 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2016-02-17 14:58 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2016-02-15 19:32 - 2016-02-15 19:32 - 00000000 ____D C:\Users\Casa\AppData\Roaming\The Bureau - XCOM Declassified 2016-02-15 14:58 - 2016-03-25 21:51 - 00000000 ____D C:\Users\Casa\Desktop\World of Warcraft - 3.3.5a (12340) - enUS (No Install) 2016-02-08 23:28 - 2016-02-08 23:28 - 00000000 ____D C:\Users\Todos os Usuários\X360CE 2016-02-08 23:28 - 2016-02-08 23:28 - 00000000 ____D C:\ProgramData\X360CE 2016-02-08 19:41 - 2016-02-08 19:41 - 00000000 ____D C:\Users\Casa\AppData\Local\ali213GameLauncher ==================== Three Months Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-05-04 17:53 - 2015-03-03 10:40 - 01382453 _____ C:\Windows\WindowsUpdate.log 2016-05-04 17:17 - 2016-01-29 05:21 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache 2016-05-04 17:17 - 2016-01-29 05:21 - 00000000 ____D C:\ProgramData\Package Cache 2016-05-04 17:17 - 2014-12-28 11:12 - 00000000 ____D C:\Users\Casa\AppData\Roaming\uTorrent 2016-05-04 07:21 - 2015-01-28 09:28 - 00000000 ____D C:\Users\Todos os Usuários\rvlkl 2016-05-04 07:21 - 2015-01-28 09:28 - 00000000 ____D C:\ProgramData\rvlkl 2016-05-04 06:45 - 2015-11-12 05:33 - 00000000 ____D C:\Program Files (x86)\Steam 2016-05-04 05:07 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-05-04 05:07 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-05-04 05:02 - 2015-03-22 16:22 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Skype 2016-05-02 22:43 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\system32\NDF 2016-05-01 22:35 - 2015-07-04 10:42 - 00000684 _____ C:\Users\Casa\Desktop\997027960.txt 2016-04-30 19:12 - 2015-11-25 03:22 - 00000000 ____D C:\Games 2016-04-30 18:51 - 2009-07-14 14:55 - 00709738 _____ C:\Windows\system32\prfh0416.dat 2016-04-30 18:51 - 2009-07-14 14:55 - 00149354 _____ C:\Windows\system32\prfc0416.dat 2016-04-30 18:51 - 2009-07-14 02:13 - 01647490 _____ C:\Windows\system32\PerfStringBackup.INI 2016-04-28 14:41 - 2014-12-27 17:11 - 00000000 ____D C:\Users\Casa 2016-04-28 14:39 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\registration 2016-04-25 19:43 - 2015-01-13 16:43 - 00000000 ____D C:\Users\Casa\Desktop\anderson freire 2016-04-25 19:31 - 2015-07-30 00:54 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2016-04-24 19:17 - 2015-09-30 18:02 - 00000000 ____D C:\Users\Casa\Documents\My Games 2016-04-24 19:17 - 2015-01-19 10:53 - 00000000 ____D C:\Users\Casa\AppData\Local\SKIDROW 2016-04-23 11:07 - 2015-07-31 14:07 - 00000000 ____D C:\Users\Casa\AppData\Roaming\LolClient 2016-04-22 19:46 - 2015-07-31 02:26 - 00000000 ____D C:\Users\Casa\AppData\Roaming\Riot Games 2016-04-22 04:57 - 2014-12-28 10:24 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-04-11 21:42 - 2015-09-22 19:25 - 00001954 _____ C:\Users\Casa\Desktop\RCGamebox.lnk 2016-04-05 19:09 - 2014-12-28 18:16 - 00000000 ____D C:\Users\Casa\AppData\Roaming\DAEMON Tools Lite ==================== Files in the root of some directories ======= 2015-06-06 09:47 - 2015-06-06 09:53 - 0000183 _____ () C:\Program Files\Common Files\Novo Documento de Texto.txt 2015-05-18 16:32 - 2015-05-21 23:09 - 0000109 _____ () C:\Program Files (x86)\Common Files\Novo Documento de Texto.txt 2016-02-18 18:52 - 2016-02-18 18:52 - 7951360 _____ () C:\Users\Casa\AppData\Roaming\agent.dat 2015-06-16 01:16 - 2015-08-21 12:56 - 0000024 _____ () C:\Users\Casa\AppData\Roaming\appdataFr25.bin 2015-02-26 18:16 - 2015-05-14 23:36 - 0000020 _____ () C:\Users\Casa\AppData\Roaming\appdataFr3.bin 2016-02-18 18:52 - 2016-02-18 18:52 - 0054272 _____ () C:\Users\Casa\AppData\Roaming\ApplicationHosting.dat 2016-02-18 18:48 - 2016-02-18 18:49 - 0001344 _____ () C:\Users\Casa\AppData\Roaming\Bubble Dock.boostrap.log 2016-02-18 18:48 - 2016-02-18 18:48 - 0005707 _____ () C:\Users\Casa\AppData\Roaming\Bubble Dock.installation.log 2015-05-10 09:00 - 2015-05-10 09:00 - 0154283 ____H () C:\Users\Casa\AppData\Roaming\Casa-wchelper.dll 2016-02-18 18:52 - 2016-02-18 18:52 - 0063696 _____ () C:\Users\Casa\AppData\Roaming\Config.xml 2015-07-11 08:20 - 2016-02-24 12:38 - 0002725 _____ () C:\Users\Casa\AppData\Roaming\droid4xinstaller.log 2015-06-14 17:29 - 2015-06-14 17:29 - 1322672 _____ () C:\Users\Casa\AppData\Roaming\GameHouse-Installer_am-cuttherope_gamehouse_.exe 2016-02-18 18:49 - 2016-02-18 18:50 - 0016992 _____ () C:\Users\Casa\AppData\Roaming\InstallationConfiguration.xml 2016-02-18 18:49 - 2016-02-18 18:49 - 0126976 _____ () C:\Users\Casa\AppData\Roaming\Installer.dat 2015-04-14 13:28 - 2015-04-14 13:28 - 0001171 _____ () C:\Users\Casa\AppData\Roaming\Kx7lf0Ji0oXH 2015-04-20 11:05 - 2015-04-20 11:05 - 1246720 _____ () C:\Users\Casa\AppData\Roaming\Kx7lf0Ji0oXH.exe 2016-02-18 18:52 - 2016-02-18 18:52 - 0126464 _____ () C:\Users\Casa\AppData\Roaming\lobby.dat 2016-02-18 18:52 - 2016-02-18 18:52 - 0018432 _____ () C:\Users\Casa\AppData\Roaming\Main.dat 2016-02-18 18:52 - 2016-02-18 18:52 - 0005568 _____ () C:\Users\Casa\AppData\Roaming\md.xml 2015-06-14 17:30 - 2015-10-26 05:53 - 0400728 _____ () C:\Users\Casa\AppData\Roaming\msconfig.ini 2016-02-18 18:52 - 2016-02-18 18:52 - 0126464 _____ () C:\Users\Casa\AppData\Roaming\noah.dat 2016-02-18 18:52 - 2016-02-18 18:49 - 0667136 _____ () C:\Users\Casa\AppData\Roaming\Over-La.exe 2016-02-18 18:52 - 2016-02-18 18:52 - 1882213 _____ () C:\Users\Casa\AppData\Roaming\Over-La.tst 2016-02-18 18:49 - 2016-02-18 18:49 - 0000078 _____ () C:\Users\Casa\AppData\Roaming\Selection Tools.installation.log 2016-01-08 08:10 - 2016-01-08 08:10 - 0000001 _____ () C:\Users\Casa\AppData\Roaming\smw_inst 2016-02-18 18:52 - 2016-02-18 18:49 - 0667136 _____ () C:\Users\Casa\AppData\Roaming\TranKeylax.exe 2016-02-18 18:52 - 2016-02-18 18:52 - 0072777 _____ () C:\Users\Casa\AppData\Roaming\TranKeylax.tst 2016-02-18 18:51 - 2016-02-18 18:51 - 0848437 _____ () C:\Users\Casa\AppData\Roaming\Trustron.bin 2016-02-18 18:52 - 2016-02-18 18:52 - 0188584 _____ () C:\Users\Casa\AppData\Roaming\U-lux.bin 2016-02-18 18:53 - 2016-02-18 18:53 - 0032038 _____ () C:\Users\Casa\AppData\Roaming\uninstall_temp.ico 2015-03-30 10:25 - 2015-03-31 00:25 - 0000069 _____ () C:\Users\Casa\AppData\Roaming\WB.CFG 2016-02-18 18:48 - 2016-02-18 18:48 - 0000097 _____ () C:\Users\Casa\AppData\Roaming\WindApp.boostrap.log 2016-02-18 18:48 - 2016-02-18 18:49 - 0000078 _____ () C:\Users\Casa\AppData\Roaming\WindApp.installation.log 2015-01-18 09:07 - 2015-01-18 09:07 - 0000000 ___SH () C:\Users\Casa\AppData\Local\LumaEmu 2015-12-24 18:38 - 2015-12-24 18:38 - 0000017 _____ () C:\Users\Casa\AppData\Local\resmon.resmoncfg 2015-03-19 16:07 - 2015-04-22 08:17 - 0011662 _____ () C:\Users\Casa\AppData\Local\Temp-log.txt 2015-02-19 20:59 - 2015-02-19 20:59 - 0000227 _____ () C:\ProgramData\bc.ini Files to move or delete: ==================== C:\Users\Casa\AppData\Roaming\msconfig.ini C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job C:\Windows\Tasks\{38AE8803-5DFC-46DC-B239-E31F33E05F68}.job C:\Windows\Tasks\{DE2ABF7F-8BAB-4F89-BF73-1F181918DB64}.job Some files in TEMP: ==================== C:\Users\Casa\AppData\Local\Temp\ICReinstall_American_McGee_s_Grimm_GOG_PC_FullDownGames.exe C:\Users\Casa\AppData\Local\Temp\utils.dll C:\Users\Casa\AppData\Local\Temp\ytd_sysmenu_setup.exe Some zero byte size files/folders: ========================== C:\Windows\SysWOW64\ahstock2a.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-13 03:20 ==================== End of log ============================