This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Needing help removing a Virus! PGCC-MARKET-ADV. [Closed]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Some years ago i downloaded a program and my Google Chrome seems to became infected by some source of Virus which makes pages to load with advertisement. This is very stressfull specially when im working. "pgcc.market-adsvisor.net" Its the page which loads and after some spanish advertisement .

Im totally new to this forum but hope somebody can help me!

 

 

Hello Casevel and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt
Addition.txt


Thanks

Satchfan

 

Hi

It has been a couple of days since I replied to your request for help with your computer problems.

Please let me know if you are having problems and still need help.

Thanks

Satchfan

Has i posted before, some years ago i downloaded a program and my Google Chrome seems to became infected by some source of Virus which makes pages to load with advertisement. This is very stressfull specially when im working. "pgcc.market-adsvisor.net" Its the page which loads and after some spanish advertisement .

I'll follow the recomendations @Satchfan gave me for now.

 

ps: Sorry about the late reply, i didnt have much free time this week 'coz of university. Eitherway ill process as you told me @Satchafn

ill try to het this done right now!

 

# AdwCleaner v3.211 - Report created 01/12/2015 at 05:21:31
# Updated 26/05/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Toshiba - TOSHIBA-TOSH
# Running from : C:\Users\Toshiba\Downloads\adwcleaner_3.211.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.18098
 
 
-\\ Mozilla Firefox v38.0.1 (x86 pt-PT)
 
[ File : C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js ]
 
 
[ File : C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\yb2m6y23.default\prefs.js ]
 
 
-\\ Google Chrome v46.0.2490.86
 
[ File : C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [25765 octets] - [28/05/2014 02:07:04]
AdwCleaner[R1].txt - [1111 octets] - [28/05/2014 12:41:44]
AdwCleaner[R2].txt - [1512 octets] - [03/06/2014 16:18:39]
AdwCleaner[R3].txt - [2271 octets] - [03/06/2014 19:05:31]
AdwCleaner[R4].txt - [3001 octets] - [07/06/2014 00:19:58]
AdwCleaner[R5].txt - [1765 octets] - [16/06/2014 13:34:27]
AdwCleaner[R6].txt - [1938 octets] - [26/06/2015 18:09:29]
AdwCleaner[R7].txt - [2133 octets] - [22/11/2015 21:18:31]
AdwCleaner[R8].txt - [1910 octets] - [01/12/2015 05:20:14]
AdwCleaner[S0].txt - [20019 octets] - [28/05/2014 02:12:35]
AdwCleaner[S1].txt - [1882 octets] - [28/05/2014 12:46:11]
AdwCleaner[S2].txt - [2346 octets] - [03/06/2014 19:07:28]
AdwCleaner[S3].txt - [2844 octets] - [07/06/2014 00:38:34]
AdwCleaner[S4].txt - [1828 octets] - [16/06/2014 13:37:44]
AdwCleaner[S5].txt - [2003 octets] - [26/06/2015 18:10:50]
AdwCleaner[S6].txt - [2159 octets] - [22/11/2015 21:21:28]
AdwCleaner[S7].txt - [1831 octets] - [01/12/2015 05:21:31]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S7].txt - [1891 octets] ##########
 
 
/
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.1 (11.24.2015)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on 01-12-2015 at  5:29:29,18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 2 
 
Successfully deleted: C:\Users\Toshiba\AppData\Local\{D72ADD82-4E15-404B-870C-83D522BCD0E6} (Empty Folder)
Successfully deleted: C:\Users\Toshiba\AppData\Local\nico mak computing (Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01-12-2015 at  5:37:16,55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

This logs are huge btw

 

1o one:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:30-11-2015
Ran by [removed] (administrator) on TOSHIBA-TOSH (01-12-2015 05:43:51)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Português (Portugal)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Qihu Software Co. Limited) C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Qihu 360 Software Co., Ltd.) C:\Program Files (x86)\360\Total Security\safemon\chrome\360webshield.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2010-12-13] (TOSHIBA Corporation)
HKLM\…\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation)
HKLM\…\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH)
HKLM\…\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [571304 2010-12-09] (TOSHIBA Corporation)
HKLM\…\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [296824 2010-09-25] (TOSHIBA Corporation)
HKLM\…\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [973176 2010-12-15] (TOSHIBA Corporation)
HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-03] (Synaptics Incorporated)
HKLM\…\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1519016 2010-12-08] (TOSHIBA Corporation)
HKLM\…\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710040 2010-12-08] (TOSHIBA Corporation)
HKLM\…\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [711576 2010-12-20] (TOSHIBA Corporation)
HKLM\…\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\…\Run: [Toshiba Registration] => C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [150992 2011-03-03] (Toshiba Europe GmbH)
HKLM\…\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\…\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [ITSecMng] => %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
HKLM-x32\…\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [252792 2010-06-04] (TOSHIBA)
HKLM-x32\…\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2475384 2011-01-16] (TOSHIBA CORPORATION.)
HKLM-x32\…\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295072 2013-02-03] (RealNetworks, Inc.)
HKLM-x32\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM-x32\…\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [69632 2012-03-20] (Vodafone)
HKLM-x32\…\Run: [QHSafeTray] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe [1032312 2015-09-21] ()
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKU\S-1-5-19\…\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
HKU\S-1-5-20\…\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Run: [ISUSPM] => C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe [222128 2007-03-29] (Macrovision Corporation)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [912480 2015-09-02] (Microsoft Corporation)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Run: [Octoshape Streaming Services] => C:\Users\Toshiba\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800 2011-03-24] (Octoshape ApS)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Run: [pgcchelper] => C:\Users\Toshiba\AppData\Local\pgcchelper\pgcchelper.exe [465920 2013-08-21] ()
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: F - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: G - G:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {2091109a-ec9b-11e2-81bf-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {209110a1-ec9b-11e2-81bf-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {3354c7d3-b65f-11e1-85c4-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {3354c7da-b65f-11e1-85c4-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {555db868-c42c-11e1-986e-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {555db87a-c42c-11e1-986e-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {6d39009a-89cd-11e3-81a6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {7dff1801-042d-11e3-99f7-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {7ee67c48-ab5d-11e1-9c37-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {814e09fc-06a0-11e3-bfb8-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {839edb36-bef0-11e1-a7f6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d65fc-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d660c-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d660f-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d661e-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6634-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6647-be0d-11e1-a6d5-001e101f6c04} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6654-be0d-11e1-a6d5-001e101f6c04} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {98b68ef4-8cf3-11e4-a1d6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b1170f08-b665-11e1-aaae-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b128d9d0-79a3-11e1-ad2b-e89a8f044043} - G:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b128d9d7-79a3-11e1-ad2b-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b4e4fd6e-06b5-11e3-bc4e-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd4f-4c49-11e2-845e-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd60-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd95-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbda6-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {c905ad93-7dc4-11e1-9435-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {c905ada5-7dc4-11e1-9435-e89a8f044043} - G:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {d1598edb-052f-11e3-9b91-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {e5eb2800-7dd1-11e1-ba79-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaa6-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaa9-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaab-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {fed48f45-b0e5-11e1-bdfc-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-18\…\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
AppInit_DLLs: C:\Windows\Jaksta\AC\x64\jaudcap.dll => C:\Windows\Jaksta\AC\x64\jaudcap.dll [311584 2013-10-31] (Jaksta Technologies Pty Ltd)
AppInit_DLLs-x32: c:\windows\jaksta\ac\x86\jaudcap.dll => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll [2013-05-25] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2015-10-28]
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk [2015-10-28]
ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2015-10-28]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2011-03-03]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2011-03-03]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{29C379EB-15F5-4442-AA43-EB5BBACB5BAD}: [NameServer] 87.103.113.145 87.103.113.209
Tcpip\..\Interfaces\{38C84661-4E79-4615-80AF-39A9CC15597A}: [DhcpNameServer] 10.4.0.1
Tcpip\..\Interfaces\{55E724F6-2238-4EB4-8837-A7F77724710C}: [DhcpNameServer] 192.168.9.1 192.168.9.1
Tcpip\..\Interfaces\{68286DD8-2390-4CC7-89AA-0E467F732497}: [DhcpNameServer] 192.168.1.254 192.168.1.254
Tcpip\..\Interfaces\{8FE9971E-EE68-4FEB-99F3-97886FB827C8}: [DhcpNameServer] 10.4.0.1
Tcpip\..\Interfaces\{BE796E17-B658-4766-850E-2A2DC603FD09}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{E033A2D6-B0C3-4FC5-9A5D-7BA019A686D1}: [NameServer] 87.103.113.145 87.103.113.209
Tcpip\..\Interfaces\{E033A2D6-B0C3-4FC5-9A5D-7BA019A686D1}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{F1AC4D32-119C-4B55-889E-5D6285A6420A}: [NameServer] 87.103.113.145 87.103.113.209
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {F11F3195-DB15-4386-AC80-13C6FE576B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=TSHMDF&pc;=MATM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {6F601FA8-C974-4DA2-BE97-D0382BB0B5AD} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=TSHMDF&pc;=MATM&src;=IE-SearchBox
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: AllCHeApPrice -> {A26C1ADD-E1BD-E1E3-22F8-2342C59EF108} -> C:\ProgramData\AllCHeApPrice\ALdqClzjI.x64.dll => No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll [2015-09-21] (Qihu 360 Software Co., Ltd.)
BHO: GreAatsaveR -> {F8F6BED2-3F26-FA29-32C4-4F4312546BF4} -> C:\Program Files (x86)\GreAatsaveR\WAcF.x64.dll => No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-20] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon.dll [2015-08-14] (Qihu 360 Software Co., Ltd.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-20] (Oracle Corporation)
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\yb2m6y23.default
FF Homepage: hxxps://www.google.pt/
FF Session Restore: -> is enabled.
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll [2014-07-09] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll [2014-07-09] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-20] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2011-01-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2011-01-16] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @real.com/nppl3260;version=16.0.0.282 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2013-02-03] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.5.109 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-07-24] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.5.109 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-07-24] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.0.282 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2013-02-03] (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2012-11-29] (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2013-04-10] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2217298813-2927578935-920386982-1000: @octoshape.com/Octoshape Streaming Services,version=1.0 -> C:\Users\Toshiba\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1312180-0-npoctoshape.dll [2013-12-18] (Octoshape ApS)
FF Plugin HKU\S-1-5-21-2217298813-2927578935-920386982-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Toshiba\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin ProgramFiles/Appdata: C:\Users\Toshiba\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2014-05-22] (Octoshape ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priberam.xml [2014-10-15]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sapo.xml [2014-10-15]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-ptpt.xml [2015-04-05]
FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox [2013-02-03] [not signed]
FF Extension: 360 Internet Protection - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [2015-11-09] [not signed]
FF Extension: SNT - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\yb2m6y23.default\Extensions\[removed] [2014-01-21] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-02-03] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox
 
Chrome: 
=======
CHR NewTab: Default -> "chrome-extension://cbmbfafhdccfgdgnbkgogehiklmemkoh/index.html"
CHR Profile: C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05]
CHR Extension: (Google Drive) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (X New Tab Page) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmbfafhdccfgdgnbkgogehiklmemkoh [2015-03-21]
CHR Extension: (Adblock Plus) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-11-25]
CHR Extension: (Google Search) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Block site) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2015-07-18]
CHR Extension: (Documentos do Google offline) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Proteção de Internet do 360) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\glcimepnljoholdmjchkloafkggfoijh [2015-11-09]
CHR Extension: (RealDownloader) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-05-28]
CHR Extension: (Adblock Super) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\knebimhcckndhiglamoabbnifdkijidd [2015-09-15]
CHR Extension: (StayFocusd) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2014-11-06]
CHR Extension: (Ajudante de Download de vídeo) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnkioblodjcgkdailhejgcocjkkoochj [2015-04-26]
CHR Extension: (Pagamentos via Chrome Web Store) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-25]
CHR Extension: (Gmail) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR HKLM-x32\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2012-11-29]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 QHActiveDefense; C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe [858744 2015-09-21] (QIHU 360 SOFTWARE CO. LIMITED)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
R2 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2012-03-20] (Vodafone) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [137296 2015-08-14] (360.cn)
R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [77904 2015-09-21] (360.cn)
R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [319568 2015-09-21] (360.cn)
R1 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [40520 2015-07-09] (360.cn)
R1 360FsFlt; C:\Windows\System32\DRIVERS\360FsFlt.sys [363088 2015-08-14] (360.cn)
R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [178768 2015-08-14] (360.cn)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [243200 2009-10-21] (Huawei Technologies Co., Ltd.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [227840 2012-03-16] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-27] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 Tosrfcom; no ImagePath
S3 WsAudioDevice_383S(1); C:\Windows\System32\drivers\WsAudioDevice_383S(1).sys [29288 2013-05-30] (Wondershare)
S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-01 05:43 - 2015-12-01 05:44 - 00033524 _____ C:\Users\Toshiba\Downloads\FRST.txt
2015-12-01 05:43 - 2015-12-01 05:43 - 02350080 _____ (Farbar) C:\Users\Toshiba\Downloads\FRST64.exe
2015-12-01 05:43 - 2015-12-01 05:43 - 00000000 ____D C:\FRST
2015-12-01 05:37 - 2015-12-01 05:37 - 00000747 _____ C:\Users\Toshiba\Desktop\JRT.txt
2015-12-01 05:29 - 2015-12-01 05:29 - 00000000 ____D C:\Users\Toshiba\Desktop\JRT_NewerVersion
2015-12-01 05:09 - 2015-12-01 05:09 - 00010607 _____ C:\Users\Toshiba\Downloads\Entrega do TP4_listagem de alunos (2).xlsx
2015-12-01 05:08 - 2015-12-01 05:08 - 00010918 _____ C:\Users\Toshiba\Downloads\TP2_alunos selecionados (2).xlsx
2015-12-01 05:08 - 2015-12-01 05:08 - 00010802 _____ C:\Users\Toshiba\Downloads\Listagem de alunos slecionados para a entrega da Resolução do TRabalho Prático nº 3 (2).xlsx
2015-11-30 22:08 - 2015-11-30 22:52 - 00015355 _____ C:\Users\Toshiba\Downloads\TP 5_dados.xlsx
2015-11-27 23:27 - 2015-11-27 23:27 - 00008524 _____ C:\Users\Toshiba\Downloads\Notificação_20151127191836.PDF
2015-11-27 23:27 - 2015-11-27 23:27 - 00002104 _____ C:\Users\Toshiba\Downloads\NotificacaoDocumentosEmFalta_20151120140804 (1).PDF
2015-11-26 21:16 - 2015-11-30 23:24 - 00003504 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Toshiba
2015-11-26 21:16 - 2015-11-29 22:09 - 00003510 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Toshiba
2015-11-26 21:16 - 2015-11-26 21:16 - 00003628 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Toshiba
2015-11-26 21:16 - 2015-11-26 21:16 - 00003226 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Toshiba
2015-11-25 09:06 - 2015-11-25 09:06 - 00252648 _____ C:\Users\Toshiba\Downloads\Mod_III_Planeamento_Politicas_Indicadores_RH (1).pptx
2015-11-25 07:03 - 2015-11-25 07:03 - 00843349 _____ C:\Users\Toshiba\Downloads\Mod_II_Recrutamento_Selecao.pptx
2015-11-25 07:02 - 2015-11-25 07:02 - 00252648 _____ C:\Users\Toshiba\Downloads\Mod_III_Planeamento_Politicas_Indicadores_RH.pptx
2015-11-25 06:58 - 2015-11-25 06:58 - 00217479 _____ C:\Users\Toshiba\Downloads\1000204143520_DOCF815819TS073039069.pdf
2015-11-25 06:21 - 2015-11-25 06:21 - 01590358 _____ C:\Users\Toshiba\Downloads\Caso 2_CS.pdf
2015-11-25 05:49 - 2015-11-25 05:50 - 00010607 _____ C:\Users\Toshiba\Downloads\Entrega do TP4_listagem de alunos (1).xlsx
2015-11-24 19:53 - 2015-11-24 19:53 - 00107532 _____ C:\Users\Toshiba\Documents\comprovativo_204479007.pdf
2015-11-24 19:25 - 2015-11-24 19:25 - 00217479 _____ C:\Users\Toshiba\Downloads\SS.pdf
2015-11-24 19:25 - 2015-11-24 19:25 - 00176534 _____ C:\Users\Toshiba\Downloads\CC.pdf
2015-11-24 03:40 - 2015-11-24 03:40 - 03358661 _____ C:\Users\Toshiba\Downloads\J M C Ferreira et al_1996_Abordagens Contingenciais e Teorias Recentes_excerto.pdf
2015-11-23 20:16 - 2015-11-23 20:16 - 00322259 _____ C:\Users\Toshiba\Downloads\Ponto_6.pdf
2015-11-23 20:16 - 2015-11-23 20:16 - 00208125 _____ C:\Users\Toshiba\Downloads\Ponto_7 (1).pdf
2015-11-23 20:15 - 2015-11-23 20:16 - 00453755 _____ C:\Users\Toshiba\Downloads\Ponto_5.pdf
2015-11-23 04:48 - 2015-11-23 04:49 - 03384218 _____ C:\Users\Toshiba\Downloads\Gay+Jizz+Orgy+Major+Leagu (1).ace
2015-11-23 04:47 - 2015-11-23 04:48 - 03448982 _____ C:\Users\Toshiba\Downloads\Gay+Jizz+Orgy+Major+Leagu.ace
2015-11-22 21:25 - 2015-11-22 21:26 - 01599080 _____ (Malwarebytes) C:\Users\Toshiba\Downloads\JRT.exe
2015-11-22 21:19 - 2015-11-22 21:19 - 00000046 _____ C:\Users\Toshiba\Documents\service.txt
2015-11-21 18:06 - 2015-11-21 18:07 - 00010607 _____ C:\Users\Toshiba\Downloads\Entrega do TP4_listagem de alunos.xlsx
2015-11-20 20:48 - 2015-11-20 20:48 - 00053744 _____ C:\Users\Toshiba\Downloads\1000203820402_BOLETIM_C815819.pdf
2015-11-20 20:32 - 2015-11-20 20:32 - 00002104 _____ C:\Users\Toshiba\Downloads\NotificacaoDocumentosEmFalta_20151120140804.PDF
2015-11-19 04:54 - 2015-11-20 10:44 - 00000556 _____ C:\Users\Toshiba\Documents\ref bibli.txt
2015-11-16 12:39 - 2015-11-16 12:39 - 00009590 _____ C:\Users\Toshiba\Documents\LISTA DE TEMAS.txt
2015-11-16 12:31 - 2015-11-16 12:31 - 00365208 _____ C:\Users\Toshiba\Documents\LISTA DE TEMAS.pdf
2015-11-16 02:28 - 2015-11-17 05:00 - 00002680 _____ C:\Users\Toshiba\Documents\Fundadores.txt
2015-11-14 04:34 - 2015-11-14 04:35 - 03139397 _____ C:\Users\Toshiba\Downloads\10.ogg
2015-11-12 09:53 - 2015-11-03 17:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-11 13:09 - 2015-11-11 13:09 - 00010802 _____ C:\Users\Toshiba\Downloads\Listagem de alunos slecionados para a entrega da Resolução do TRabalho Prático nº 3 (1).xlsx
2015-11-11 13:07 - 2015-11-11 13:07 - 00010802 _____ C:\Users\Toshiba\Downloads\Listagem de alunos slecionados para a entrega da Resolução do TRabalho Prático nº 3.xlsx
2015-11-11 12:34 - 2015-10-20 18:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-11-11 12:34 - 2015-10-20 18:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-11 12:34 - 2015-10-20 18:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-11-11 12:34 - 2015-10-20 18:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-11 12:34 - 2015-10-20 18:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-11-11 12:34 - 2015-10-20 17:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-11 12:34 - 2015-10-20 17:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-11 12:34 - 2015-10-20 17:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-11 12:34 - 2015-10-20 17:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-11-11 12:34 - 2015-10-20 17:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-11 12:33 - 2015-11-03 21:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-11-11 12:33 - 2015-10-30 23:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-11 12:33 - 2015-10-30 23:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-11-11 12:33 - 2015-10-30 23:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-11-11 12:33 - 2015-10-30 23:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-11-11 12:33 - 2015-10-30 22:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-11-11 12:33 - 2015-10-30 22:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-11-11 12:33 - 2015-10-30 22:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-11 12:33 - 2015-10-30 22:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-11-11 12:33 - 2015-10-30 22:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-11-11 12:33 - 2015-10-30 21:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-11 12:32 - 2015-11-03 22:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-11-11 12:32 - 2015-10-30 23:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-11 12:32 - 2015-10-30 23:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-11-11 12:32 - 2015-10-30 23:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-11 12:32 - 2015-10-30 23:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-11 12:32 - 2015-10-30 23:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-11-11 12:32 - 2015-10-30 23:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-11 12:32 - 2015-10-30 23:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-11-11 12:32 - 2015-10-30 23:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-11 12:32 - 2015-10-30 23:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-11 12:32 - 2015-10-30 23:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-11 12:32 - 2015-10-30 23:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-11 12:32 - 2015-10-30 23:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-11 12:32 - 2015-10-30 23:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-11-11 12:32 - 2015-10-30 23:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-11 12:32 - 2015-10-30 23:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-11 12:32 - 2015-10-30 22:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-11-11 12:32 - 2015-10-30 22:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 12:32 - 2015-10-30 22:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-11 12:32 - 2015-10-30 22:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-11-11 12:32 - 2015-10-30 22:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-11 12:32 - 2015-10-30 22:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-11 12:32 - 2015-10-30 22:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-11 12:32 - 2015-10-30 22:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-11-11 12:32 - 2015-10-30 22:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-11-11 12:32 - 2015-10-30 22:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-11-11 12:32 - 2015-10-30 22:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-11 12:32 - 2015-10-30 22:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-11-11 12:32 - 2015-10-30 22:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-11-11 12:32 - 2015-10-30 22:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-11-11 12:32 - 2015-10-30 22:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-11 12:32 - 2015-10-30 22:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-11-11 12:32 - 2015-10-30 22:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-11-11 12:32 - 2015-10-30 22:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-11-11 12:32 - 2015-10-30 22:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-11 12:32 - 2015-10-30 22:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-11 12:32 - 2015-10-30 22:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-11-11 12:32 - 2015-10-30 22:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-11-11 12:32 - 2015-10-30 22:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-11 12:32 - 2015-10-30 22:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-11 12:32 - 2015-10-30 22:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-11-11 12:32 - 2015-10-30 22:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-11-11 12:32 - 2015-10-30 22:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-11 12:32 - 2015-10-30 22:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-11 12:32 - 2015-10-30 22:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-11-11 12:32 - 2015-10-30 22:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-11 12:32 - 2015-10-30 22:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-11 12:32 - 2015-10-30 22:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-11-11 12:32 - 2015-10-30 22:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-11-11 12:32 - 2015-10-30 22:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-11 12:32 - 2015-10-30 21:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-11 12:32 - 2015-10-30 21:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-11 12:32 - 2015-10-30 21:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-11 12:30 - 2015-10-20 01:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-11 12:30 - 2015-10-20 01:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-11 12:30 - 2015-10-20 01:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-11 12:30 - 2015-10-20 01:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-11 12:30 - 2015-10-20 01:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-11-11 12:30 - 2015-10-20 01:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-11-11 12:30 - 2015-10-20 01:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-11-11 12:30 - 2015-10-20 01:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-11-11 12:30 - 2015-10-20 01:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-11-11 12:30 - 2015-10-20 01:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-11-11 12:30 - 2015-10-20 01:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-11-11 12:30 - 2015-10-20 01:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-11-11 12:30 - 2015-10-20 01:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-11-11 12:30 - 2015-10-20 01:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-11-11 12:30 - 2015-10-20 00:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-11-11 12:30 - 2015-10-20 00:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-11-11 12:30 - 2015-10-20 00:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-11-11 12:30 - 2015-10-20 00:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-11-11 12:30 - 2015-10-20 00:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-11-11 12:30 - 2015-10-20 00:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-11-11 12:30 - 2015-10-20 00:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 12:30 - 2015-10-19 23:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-11 12:30 - 2015-10-19 23:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-11-11 12:30 - 2015-10-19 23:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-11 12:30 - 2015-10-19 23:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-11-11 12:30 - 2015-10-19 23:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-11-11 12:30 - 2015-10-19 23:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 12:30 - 2015-10-19 23:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 12:30 - 2015-10-19 23:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 12:30 - 2015-10-19 23:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 12:30 - 2015-09-23 13:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-11 12:30 - 2015-09-23 13:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-11 12:30 - 2015-09-23 13:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2015-11-11 12:28 - 2015-10-29 17:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-11-11 12:28 - 2015-10-29 17:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-11-11 12:28 - 2015-10-29 17:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-11-11 12:28 - 2015-10-29 17:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-11-11 12:28 - 2015-10-29 17:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-11-11 12:28 - 2015-10-29 17:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-11-11 12:28 - 2015-10-29 17:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-11-11 12:28 - 2015-10-13 16:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-11 12:28 - 2015-10-13 16:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-11 12:28 - 2015-10-13 04:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-11 12:28 - 2015-10-01 18:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-11-11 12:28 - 2015-10-01 18:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-11-11 12:28 - 2015-10-01 17:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0.00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (5).00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (4).00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (3).00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (2).00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (1).00_jpg_srz
2015-11-09 14:47 - 2015-11-09 14:48 - 29489272 _____ C:\Users\Toshiba\Downloads\360TSE_Setup_7.2.0.1021.exe
2015-11-06 23:42 - 2015-11-11 02:25 - 00001240 _____ C:\Users\Toshiba\Documents\Max Weber.txt
2015-11-05 15:20 - 2015-11-05 15:20 - 02247087 _____ C:\Users\Toshiba\Downloads\Karl Weick (1).pdf
2015-11-05 15:04 - 2015-11-05 15:04 - 00208125 _____ C:\Users\Toshiba\Downloads\Ponto_7.pdf
2015-11-04 22:38 - 2015-11-04 22:48 - 47082118 _____ C:\Users\Toshiba\Downloads\grims.rar
2015-11-03 23:49 - 2015-11-03 23:50 - 00036854 _____ C:\Users\Toshiba\Downloads\H36-Grupo520-Ordenação.pdf
2015-11-02 18:09 - 2015-11-02 23:10 - 00000000 ____D C:\Users\Toshiba\Documents\VirtualDJ
2015-11-02 18:09 - 2015-11-02 18:09 - 00000921 _____ C:\Users\Toshiba\Desktop\VirtualDJ 8.lnk
2015-11-02 18:09 - 2015-11-02 18:09 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2015-11-02 18:09 - 2015-11-02 18:09 - 00000000 ____D C:\Program Files (x86)\VirtualDJ
2015-11-02 18:05 - 2015-11-02 18:07 - 38793216 _____ C:\Users\Toshiba\Downloads\install_virtualdj_pc_v8.0.2483.msi
2015-11-02 18:01 - 2015-11-02 18:02 - 09989712 _____ (MEGA Limited) C:\Users\Toshiba\Downloads\MEGAsyncSetup.exe
2015-11-01 22:21 - 2015-11-01 22:21 - 00010918 _____ C:\Users\Toshiba\Downloads\TP2_alunos selecionados (1).xlsx
2015-11-01 22:19 - 2015-11-01 22:19 - 00010918 _____ C:\Users\Toshiba\Downloads\TP2_alunos selecionados.xlsx
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-01 05:45 - 2015-07-25 12:30 - 00000000 ____D C:\Users\Toshiba\AppData\LocalLow\360WD
2015-12-01 05:43 - 2009-07-14 03:20 - 00000000 ____D C:\Windows
2015-12-01 05:32 - 2009-07-14 04:45 - 00019248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-01 05:32 - 2009-07-14 04:45 - 00019248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-01 05:30 - 2013-11-15 15:00 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-01 05:29 - 2014-05-28 19:51 - 00001008 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-01 05:24 - 2014-05-28 19:51 - 00001004 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-01 05:24 - 2012-03-09 16:38 - 00000000 ____D C:\ProgramData\NVIDIA
2015-12-01 05:23 - 2013-12-13 01:12 - 00000448 ____H C:\Windows\Tasks\SK.Enabler-S-1495795506.job
2015-12-01 05:23 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-01 05:21 - 2014-05-28 02:06 - 00000000 ____D C:\AdwCleaner
2015-12-01 05:19 - 2012-03-29 14:30 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\Skype
2015-12-01 04:56 - 2013-02-04 22:51 - 00000936 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000UA.job
2015-11-30 22:56 - 2013-02-04 22:51 - 00000914 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000Core.job
2015-11-30 04:12 - 2012-03-31 11:57 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\Audacity
2015-11-29 20:15 - 2010-11-08 09:01 - 00724104 _____ C:\Windows\system32\prfh0816.dat
2015-11-29 20:15 - 2010-11-08 09:01 - 00153996 _____ C:\Windows\system32\prfc0816.dat
2015-11-29 20:15 - 2009-07-14 05:13 - 01664338 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-29 20:15 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\inf
2015-11-28 22:13 - 2012-08-30 11:25 - 00000000 ____D C:\Users\Toshiba\Desktop\V.v
2015-11-23 04:48 - 2015-10-19 11:21 - 00000000 __SHD C:\ProgramData\360Quarant
2015-11-23 04:48 - 2015-10-19 11:21 - 00000000 __SHD C:\$360Section
2015-11-22 21:40 - 2015-10-28 16:08 - 00000000 ____D C:\Users\Toshiba\Desktop\hh
2015-11-20 00:59 - 2011-03-03 12:41 - 00000000 ____D C:\ProgramData\Skype
2015-11-12 14:22 - 2014-01-21 14:05 - 00411920 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-11 16:36 - 2013-07-31 02:01 - 00000000 ____D C:\Windows\system32\MRT
2015-11-11 16:22 - 2013-05-02 23:53 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-11 16:18 - 2012-11-27 21:13 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-11 15:52 - 2012-05-04 17:57 - 01630198 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-11-11 15:47 - 2009-07-14 07:45 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 10:56 - 2014-05-28 19:52 - 00002146 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-11-09 16:37 - 2012-09-07 15:05 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\Nero
2015-11-09 15:39 - 2013-11-04 14:56 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player
2015-11-09 15:39 - 2013-05-02 21:13 - 00000000 ___RD C:\Users\Toshiba\Desktop\Utilitários
2015-11-09 15:37 - 2015-07-24 17:13 - 00000000 ____D C:\ProgramData\360TotalSecurity
2015-11-09 14:51 - 2014-06-05 14:53 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\360safe
2015-11-09 14:51 - 2009-07-14 03:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-11-09 14:51 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2015-11-09 14:50 - 2015-07-24 17:13 - 00001116 _____ C:\Users\Public\Desktop\360 Total Security.lnk
2015-11-09 14:50 - 2015-07-24 17:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center
2015-11-04 22:49 - 2015-10-28 16:06 - 00000000 ____D C:\Users\Toshiba\AppData\Local\WinZip
2015-11-02 22:14 - 2014-01-21 14:05 - 00110536 _____ C:\Users\Toshiba\AppData\Local\GDIPFONTCACHEV1.DAT
 
==================== Files in the root of some directories =======
 
2012-08-30 18:55 - 2012-08-30 18:55 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\0AZ2B6673Windows.bat
2012-08-30 18:50 - 2012-08-30 18:50 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\33KM2IMTW2Windows.bat
2012-08-08 10:27 - 2012-08-08 10:27 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\9ZTCUM5SCSVACLhehe.exe
2013-12-22 06:31 - 2013-12-22 06:31 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\bitlord_log.txt
2012-08-07 16:41 - 2013-05-02 18:00 - 15875330 _____ () C:\Users\Toshiba\AppData\Roaming\Eldoqt's Keylog
2012-09-15 13:41 - 2012-09-15 13:41 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\L1QHUAXhehe.exe
2014-02-06 17:12 - 2014-02-06 17:12 - 0000050 _____ () C:\Users\Toshiba\AppData\Roaming\mbam.context.scan
2012-08-07 16:41 - 2010-11-04 17:57 - 0032072 _____ (Microsoft Corporation) C:\Users\Toshiba\AppData\Roaming\YUPVRTMT77.exe
2012-08-30 18:44 - 2012-08-30 18:44 - 0000638 _____ () C:\Users\Toshiba\AppData\Roaming\ZFKOXZ6DODAWindows.bat
2012-09-30 20:26 - 2012-10-03 18:54 - 0004608 _____ () C:\Users\Toshiba\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-07-21 18:56 - 2013-07-21 18:56 - 0000017 _____ () C:\Users\Toshiba\AppData\Local\resmon.resmoncfg
2012-03-16 14:55 - 2012-03-16 14:55 - 0286678 ____R () C:\ProgramData\DeviceManager.xml.rc4
2012-03-29 14:31 - 2012-03-29 14:31 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
 
Some files in TEMP:
====================
C:\Users\Toshiba\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Toshiba\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Toshiba\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Toshiba\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\Toshiba\AppData\Local\Temp\Quarantine.exe
C:\Users\Toshiba\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Toshiba\AppData\Local\Temp\stubhelper.dll
C:\Users\Toshiba\AppData\Local\Temp\swt-win32-3740.dll
C:\Users\Toshiba\AppData\Local\Temp\{3CC7CDA1-51B3-4D59-87CF-EF76109A212C}-42.0.2311.90_41.0.2272.118_chrome_updater.exe
C:\Users\Toshiba\AppData\Local\Temp\{5B312002-9617-46A7-8B31-53337E079C2C}-41.0.2272.89_40.0.2214.115_chrome_updater.exe
C:\Users\Toshiba\AppData\Local\Temp\{694DE23C-2511-4F9C-841F-19C0054DC42A}-40.0.2214.115_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{8BDA707E-0BEA-46F0-8339-C016E4EA3C5F}-39.0.2171.95_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{903CA3B2-3591-4D28-A8A2-E774059B7BD3}-40.0.2214.115_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{E4D00499-5580-4A1B-85D1-50CB0D137A40}-42.0.2311.90_41.0.2272.118_chrome_updater.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-11-29 20:24
 
==================== End of FRST.txt ============================
 
2nd one:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:30-11-2015
Ran by [removed] (2015-12-01 05:45:34)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2012-03-12 10:27:01)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrador (S-1-5-21-2217298813-2927578935-920386982-500 - Administrator - Disabled)
Convidado (S-1-5-21-2217298813-2927578935-920386982-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2217298813-2927578935-920386982-1003 - Limited - Enabled)
Toshiba (S-1-5-21-2217298813-2927578935-920386982-1000 - Administrator - Enabled) => C:\Users\Toshiba
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: 360 Total Security (Enabled - Up to date) {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D}
AS: 360 Total Security (Enabled - Up to date) {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKLM-x32\…\uTorrent) (Version: 3.2.0 - BitTorrent Inc.)
µTorrent (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\uTorrent) (Version: 3.3.2.30303 - BitTorrent Inc.)
360 Total Security (HKLM-x32\…\360TotalSecurity) (Version: 7.2.0.1021 - 360 Security Center)
3DS saveEditor2 (HKLM-x32\…\{7349108B-BC63-4ED7-9989-ECCA0DD0F14F}) (Version: 1.0.0.0 - CYBER Gadget)
Adobe Flash Player 14 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader X (10.1.9) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.9 - Adobe Systems Incorporated)
ASIO4ALL (HKLM-x32\…\ASIO4ALL) (Version: 2.11 Beta1 - Michael Tippach)
Atheros Bluetooth Filter Driver Package (HKLM\…\{65486209-5C54-439C-8383-8AC9BBE25932}) (Version: 1.00.0004 - Atheros Communications)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.36 - Atheros Communications Inc.)
Atheros Driver Installation Program (HKLM-x32\…\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros)
aTube Catcher versão 3.8 (HKLM-x32\…\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Audacity 2.0 (HKLM-x32\…\Audacity_is1) (Version:  - Audacity Team)
AudioConverter Studio 6.2 (HKLM-x32\…\AudioConverter Studio_is1) (Version:  - ManiacTools.com)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bejeweled 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
Bluetooth Stack for Windows by Toshiba (HKLM\…\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v8.00.04(T) - TOSHIBA CORPORATION)
CCleaner (HKLM\…\CCleaner) (Version: 4.01 - Piriform)
Chicken Invaders 3 - Revenge of the Yolk (x32 Version: 2.2.0.95 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Complément Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Complemento Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.51.1.0 - Conexant)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\…\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\…\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
Dropbox (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Dropbox) (Version: 2.0.22 - Dropbox, Inc.)
Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
FL Studio 10 (HKLM-x32\…\FL Studio 10) (Version:  - Image-Line)
FL Studio 11 (HKLM-x32\…\FL Studio 11) (Version:  - Image-Line)
FlowStone FL 3.0 (HKLM-x32\…\FlowStone) (Version:  - )
FLV and Media Player (3.2.0.3) (HKLM-x32\…\FLV and Media Player) (Version: 3.2.0.3 - Applian Technologies)
Free M4a to MP3 Converter 7.1 (HKLM-x32\…\Free M4a to MP3 Converter_is1) (Version:  - ManiacTools.com)
Free Video Converter V 3.1 (HKLM-x32\…\Free Video Converter_is1) (Version: 3.1.0.0 - Koyote Soft)
Free WAV to MP3 Converter (HKLM-x32\…\Free WAV to MP3 Converter) (Version: 1.0 - Polaris-Software.com)
Freemake Video Converter versão 3.2.1 (HKLM-x32\…\Freemake Video Converter_is1) (Version: 3.2.1 - Ellora Assets Corporation)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 46.0.2490.86 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
High-Definition Video Playback (x32 Version: 7.1.13900.47.0 - Nero AG) Hidden
IL Download Manager (HKLM-x32\…\IL Download Manager) (Version:  - Image-Line)
IL Shared Libraries (HKLM-x32\…\IL Shared Libraries) (Version:  - Image-Line)
Insaniquarium Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)
Java 8 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
JavaFX 2.1.0 (HKLM-x32\…\{1111706F-666A-4037-7777-210328764D10}) (Version: 2.1.0 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
League of Legends (HKLM-x32\…\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games)
Mahjongg Artifacts (x32 Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware versão 2.0.2.1012 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Português) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 2070) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\…\{2C303EE0-A595-3543-A71A-931C7AC40EDE}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mixxx 1.11.0 (64-bit) (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Mixxx (1.11.0)) (Version: 1.11.0 - The Mixxx Development Team)
MK LOL (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MK LOL) (Version:  - )
MKLOL (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MKLOL) (Version:  - )
Mozilla Firefox 38.0.1 (x86 pt-PT) (HKLM-x32\…\Mozilla Firefox 38.0.1 (x86 pt-PT)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MP3 Rocket (HKLM-x32\…\MP3 Rocket) (Version:  - )
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero BackItUp 10 (HKLM-x32\…\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.6.11500.16.100 - Nero AG)
Nero BurnRights 10 (HKLM-x32\…\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10500.1.102 - Nero AG)
Nero Express 10 (HKLM-x32\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12000.21.100 - Nero AG)
Nero InfoTool 10 (HKLM-x32\…\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.2.10400.5.100 - Nero AG)
Nero MediaHub 10 (HKLM-x32\…\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.2.13300.36.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{0FF68F26-416C-4954-ACA5-6AD5F9DE99C1}) (Version: 10.5.14800 - Nero AG)
Nero RescueAgent 10 (HKLM-x32\…\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.2.10800.9.100 - Nero AG)
Nero StartSmart 10 (HKLM-x32\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.10300.25.0 - Nero AG)
NVIDIA Controlador gráfico 266.69 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 266.69 - NVIDIA Corporation)
NVIDIA O controlador de 3D Vision 266.69 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 266.69 - NVIDIA Corporation)
NVIDIA O software do sistema PhysX 9.10.0514 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation)
Octoshape Streaming Services (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Octoshape Streaming Services) (Version:  - Octoshape ApS)
Painel de controlo da NVIDIA 266.69 (Version: 266.69 - NVIDIA Corporation) Hidden
Pando Media Booster (HKLM-x32\…\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.9 - Pando Networks Inc.)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
pgcchelper (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\pgcchelper) (Version:  - ) <==== ATTENTION
Photo Service - powered by myphotobook (HKLM-x32\…\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1) (Version: 1.2.0-545 - myphotobook GmbH)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants Vs. Zombies (HKLM-x32\…\{B5790265-B654-4377-9EF0-085A6AB6FA8E}) (Version: 1.2.0.1065 - PopCap)
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Popcorn4TV version 1.0 (HKLM-x32\…\{FA0CD53E-825A-48F4-9AAC-D3E6B718EAC8}_is1) (Version: 1.0 - Popcorn4TV)
RealDownloader (x32 Version: 1.3.0 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\…\RealPlayer 16.0) (Version: 16.0.0 - RealNetworks)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7512 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Reader Driver (HKLM-x32\…\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 1.0.0.12 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Replay Media Catcher 5 (5.0.1.19) (HKLM-x32\…\Replay Media Catcher 5) (Version: 5.0.1.19 - Applian Technologies)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\…\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version:  - Microsoft) Hidden
Skype™ 7.14 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.14.106 - Skype Technologies S.A.)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
software tmn (HKLM-x32\…\software tmn) (Version: 11.300.05.07.84 - Huawei Technologies Co.,Ltd)
SPORE™ (HKLM-x32\…\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.00.0000 - Electronic Arts)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.2.11.1 - Synaptics Incorporated)
TOSHIBA Assist (HKLM-x32\…\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.02.02 - TOSHIBA CORPORATION)
TOSHIBA Bulletin Board (HKLM-x32\…\InstallShield_{229C190B-7690-40B7-8680-42530179F3E9}) (Version: 2.0.16.64 - TOSHIBA Corporation)
TOSHIBA ConfigFree (HKLM-x32\…\{F52618B2-A995-4F8D-A6C8-9E235A470C68}) (Version: 8.0.36 - TOSHIBA CORPORATION)
TOSHIBA Disc Creator (HKLM\…\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.6 for x64 - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM-x32\…\InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}) (Version: 1.2.23.64 - TOSHIBA Corporation)
TOSHIBA Face Recognition (HKLM-x32\…\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.8.64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\…\InstallShield_{C4FFA951-9678-4D51-84B4-AFD15D3C45AD}) (Version: 4.08.06.00 - )
TOSHIBA HDD/SSD Alert (HKLM-x32\…\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.7 - TOSHIBA Corporation)
Toshiba Manuals (HKLM-x32\…\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.02 - TOSHIBA)
TOSHIBA Online Product Information (HKLM-x32\…\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 4.00.0008 - TOSHIBA)
TOSHIBA PC Health Monitor (HKLM\…\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.7.4.64 - TOSHIBA Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\…\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.3.10010 - TOSHIBA CORPORATION)
TOSHIBA Recovery Media Creator Reminder (HKLM-x32\…\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA)
TOSHIBA ReelTime (HKLM-x32\…\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}) (Version: 1.7.17.64 - TOSHIBA Corporation)
TOSHIBA Service Station (HKLM-x32\…\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.1.52 - TOSHIBA)
TOSHIBA Sleep Utility (HKLM-x32\…\{654F7484-88C5-46DC-AB32-C66BCB0E2102}) (Version: 1.4.2.7 - TOSHIBA Corporation)
TOSHIBA Supervisor Password (HKLM-x32\…\InstallShield_{CBD6B23D-41D5-4A46-8019-6208516C9712}) (Version: 4.08.06.00 - )
TOSHIBA TEMPRO (HKLM-x32\…\{F082CB11-4794-4259-99A1-D91BA762AD15}) (Version: 3.35 - Toshiba Europe GmbH)
TOSHIBA Value Added Package (HKLM-x32\…\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.5.1.64 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM-x32\…\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: 1.1.6.3 - TOSHIBA Corporation)
TRORMCLauncher (HKLM-x32\…\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version:  - )
TRORMCLauncher (Version: 1.0.0.10 - TOSHIBA) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM-x32\…\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version: 15.4.5722.2 - Microsoft Corporation)
VirtualDJ 8 (HKLM-x32\…\{24F8CB37-888B-41E6-B119-CDC3F5075F57}) (Version: 8.0.2483.0 - Atomix Productions)
Vodafone Mobile Broadband (HKLM-x32\…\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.3.203.38322 - Vodafone)
VPNium  (HKLM-x32\…\VPNium) (Version:  - )
Wedding Dash 2 - Rings Around the World (x32 Version: 2.2.0.95 - WildTangent) Hidden
WildTangent Games (HKLM-x32\…\WildTangent toshiba Master Uninstall) (Version: 1.0.2.5 - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.10.15 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.21 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinZip 20.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EF}) (Version: 20.0.11659 - WinZip Computing, S.L. )
WTFast 3.5 (HKLM-x32\…\{12B4121D-5221-4AFC-9EDC-63B0CA139856}_is1) (Version: 3.5.9.511 - Initex & AAA Internet Publishing)
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\…\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation)
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.dll ()
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
27-11-2015 23:26:05 Windows Update
01-12-2015 05:29:32 JRT Pre-Junkware Removal
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 02:34 - 2014-05-28 13:52 - 00001120 ____A C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0986D771-5561-4047-95C7-9D49EF73BEA1} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2217298813-2927578935-920386982-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {0BE694B7-1711-41E4-B5C7-D3E6DD8B256F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {1294239E-66AE-4D62-83A3-1EFD249B8DE9} - System32\Tasks\RNUpgradeHelperLogonPrompt_Toshiba => C:\Users\Toshiba\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-26] (RealNetworks, Inc.)
Task: {21AD92AC-60AF-4828-B182-47DDB5C40051} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000UA => C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-04] (Facebook Inc.)
Task: {239D8043-CAC0-4668-AA96-6D4F2A87C0A2} - System32\Tasks\{D9EF8992-5C27-4196-979E-420DFB6BB443} => pcalua.exe -a C:\Users\Toshiba\Downloads\Spore-RELOADED\Support\SPORE(TM)_code.exe -d C:\Users\Toshiba\Downloads\Spore-RELOADED\Support
Task: {353A78B3-B166-41F6-A0E0-1909BD7E1096} - System32\Tasks\{750601F8-6B96-4AA8-B860-9FFEEE60C34B} => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2012-03-20] (Vodafone)
Task: {3BD7D9CA-9C9C-4B83-A12D-F47D7173CD50} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {42FF1FBF-AAE5-448B-9C7D-1EE6B4D25800} - System32\Tasks\ReclaimerUpdateFiles_Toshiba => C:\Users\Toshiba\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-26] (RealNetworks, Inc.)
Task: {4A442F34-2C83-4E56-8AAA-9F89FC28C45B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-04-23] (Piriform Ltd)
Task: {541FCD98-4E89-4CB2-939C-C9029F48E717} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2217298813-2927578935-920386982-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {567A2C4E-ABD5-4225-9477-BB0890B6C1EE} - System32\Tasks\{E67D9C62-3F46-4CC2-B533-DC0AEF61A542} => pcalua.exe -a F:\setup_vmb_lite.exe -d F:\ -c /checkApplicationPresence
Task: {637F330E-44E1-45EB-B011-064A02FAF6BC} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2217298813-2927578935-920386982-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {694D4CDA-6395-45EF-89CB-D346C2D8650E} - System32\Tasks\ReclaimerUpdateXML_Toshiba => C:\Users\Toshiba\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-26] (RealNetworks, Inc.)
Task: {79FD3D47-2CD3-4653-B6C0-0B28D334CA37} - System32\Tasks\{3922DAC0-2546-4927-BF57-69BFB73538A0} => pcalua.exe -a C:\Users\Toshiba\Desktop\DISK1\setup.exe -d C:\Users\Toshiba\Desktop\DISK1
Task: {7ACD3B90-4819-49AB-B7F9-9F4F08D8D535} - System32\Tasks\{5012F6F2-9110-4EB0-8633-07CB2A965BC1} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe"
Task: {7CF50F43-DE14-473A-9155-A860D9C5C245} - System32\Tasks\SK.Enabler-S-1495795506 => c:\programdata\quickset\sk.enabler\SK.Enabler.exe <==== ATTENTION
Task: {9346C268-CD96-4219-8C67-49FBCEAB905C} - \Advanced System Protector -> No File <==== ATTENTION
Task: {9B3310F2-D7F4-46F4-A512-0DCD5104F759} - \SomotoUpdateCheckerAutoStart -> No File <==== ATTENTION
Task: {A516172D-55DE-4439-A484-EEABF838FAA1} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000Core => C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-04] (Facebook Inc.)
Task: {B274EF48-A02C-47B2-8F9C-281F51C462C5} - System32\Tasks\{78C2B097-249D-4597-99F7-535A2B57AE85} => pcalua.exe -a E:\Setup.EXE -d E:\
Task: {B662769C-3123-45A4-9674-B6224C19F9D2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10] (Adobe Systems Incorporated)
Task: {B71BF007-3FAF-4916-B13A-ACB10CBA2B0A} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2010-12-03] (TOSHIBA CORPORATION)
Task: {D4A5356B-4E4C-494D-8696-AF4AA0B80757} - System32\Tasks\RNUpgradeHelperResumePrompt_Toshiba => C:\Users\Toshiba\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-26] (RealNetworks, Inc.)
Task: {E6FAC7B6-2217-4DDE-AFBE-7173CCF1C606} - \AutoKMS -> No File <==== ATTENTION
Task: {F65B81F8-EAB0-4F9A-AE10-309C5A978567} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2217298813-2927578935-920386982-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000Core.job => C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000UA.job => C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SK.Enabler-S-1495795506.job => c:\programdata\quickset\sk.enabler\SK.Enabler.exeG/schedule /profile c:\programdata\quickset\sk.enabler\1495795506.iniToshibaSK.Ena <==== ATTENTION
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-11-18 16:18 - 2010-11-18 16:18 - 11190784 _____ () C:\Program Files\Toshiba\FlashCards\BlackPng.dll
2015-07-24 17:13 - 2015-09-21 05:29 - 01032312 _____ () C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
2012-11-29 20:31 - 2012-11-29 20:31 - 00038608 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2010-12-08 14:55 - 2010-12-08 14:55 - 00592312 _____ () C:\Program Files\TOSHIBA\TECO\TecoPower.dll
2015-07-24 17:13 - 2015-09-21 05:29 - 00087672 _____ () C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll
2015-07-24 17:13 - 2015-09-21 05:29 - 00559224 _____ () C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-11-11 10:56 - 2015-11-07 04:36 - 01532744 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libglesv2.dll
2015-11-11 10:56 - 2015-11-07 04:36 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^Users^Toshiba^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Facebook Update => "C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: Google Update => "C:\Users\Toshiba\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: NBAgent => "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: uTorrent => "C:\Program Files (x86)\uTorrent\uTorrent.exe"  /MINIMIZED
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{E4B835F9-97A8-420C-B4CB-4E3E3DD0CE12}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{6630CD62-1F5C-4179-A965-F41AFB73726F}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{78A2A81D-4FDA-402A-97AD-C3F6B06DD7E5}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{CB3033A9-1BA0-4795-B19B-BE5C501E90BD}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{0CC488C1-893A-4428-89FC-212558E8BC5B}] => (Allow) LPort=2869
FirewallRules: [{D5987659-7889-461B-8084-C95A811D09DF}] => (Allow) LPort=1900
FirewallRules: [{A84FABB1-F4F4-4E56-8B6E-A4A9EAE50EB2}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{90EB44D0-8807-4AB8-813B-B22D5B3BDFBC}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{7AC109EB-F74C-4BA5-80A3-B836A830217B}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.exe
FirewallRules: [{F079C75A-DA93-4832-A544-44B679C320C0}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.exe
FirewallRules: [{FA374334-FA74-43F6-BC2E-C8C61AD2996E}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.patch.exe
FirewallRules: [{56E0D77B-5E5F-411C-A2A5-E7332FE3DB3D}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.patch.exe
FirewallRules: [TCP Query User{38F6D9A2-CE4C-46B2-A499-08113283FB65}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{37CCD958-FF84-4CC6-8232-E2E9ED329674}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{926B7186-91BB-4B4D-8A16-A2EBD2653B54}] => (Allow) C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{D578C435-4A13-4C2A-859B-E5B123913E17}] => (Allow) C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{95AB5361-25DB-4309-A133-A04AAF97A500}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{D95D58B6-1C05-42A0-9D16-60BE980B2CC2}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{82B13C37-0E33-415E-8D0C-21595D285FE7}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{7DECAFF3-5D7D-468A-8176-049AF015F99F}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{8D54D461-90A6-4A97-919B-8AE3C7227D4F}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{4B06F689-2984-4D26-95B2-228BFA616B30}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{21FF7A6C-AD3A-4B78-BFBE-A47CA00B528D}C:\program files (x86)\world of warcraft\launcher.patch.exe] => (Block) C:\program files (x86)\world of warcraft\launcher.patch.exe
FirewallRules: [UDP Query User{3D8BBE54-D17D-430C-95F3-AEA9DC23C03A}C:\program files (x86)\world of warcraft\launcher.patch.exe] => (Block) C:\program files (x86)\world of warcraft\launcher.patch.exe
FirewallRules: [TCP Query User{0A980D26-E7A6-4AB3-95A0-42F0C2889334}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{2D19EB68-9D96-44F3-B62E-8378FBADD90D}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [TCP Query User{879BD1AD-3140-4E73-8C80-C30CB81857A7}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe
FirewallRules: [UDP Query User{90092A81-FFCE-497E-AB80-E2712CCD9ACB}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe
FirewallRules: [{CE57C971-27FC-4739-883E-E2268AFC0330}] => (Allow) C:\Program Files (x86)\Movies Toolbar\SafetyNut\SRTOOL~1\IE\dtUser.exe
FirewallRules: [{8B30292C-FD2E-441C-A010-40DCF364C21E}] => (Allow) C:\Program Files (x86)\Movies Toolbar\SafetyNut\SRTOOL~1\IE\dtUser.exe
FirewallRules: [{A2E8D0D6-227F-4C9C-9CCC-1F21A3D869C3}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Media Catcher 5\aria2c.exe
FirewallRules: [{6D585C6F-0ADD-4EA0-94CB-1D57DE58447B}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Media Catcher 5\aria2c.exe
FirewallRules: [{B425E63C-621A-49F5-8F52-DB15F69149FF}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Media Catcher 5\qtCopy.exe
FirewallRules: [{15EE142D-6456-418A-B56A-593C7C1FB15D}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Media Catcher 5\qtCopy.exe
FirewallRules: [TCP Query User{0C6A7119-446C-456A-B838-DC77324E67A9}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{64B4CD22-AD18-42AA-99D0-687FE0155501}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{2F249B5F-838D-4E2C-851A-87B11B5E65F0}] => (Allow) C:\Users\Toshiba\AppData\Local\iLivid\iLivid.exe
FirewallRules: [{01D02FD0-5539-4CFE-A53B-731C88D880C2}] => (Allow) C:\Users\Toshiba\AppData\Local\iLivid\iLivid.exe
FirewallRules: [{0953B0C3-891E-4B6C-A354-1043B9A09CCF}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{D8FE5899-54B4-4D87-9197-DB63F890B9B8}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{A79857CB-DC6C-48E9-8C9F-7D0826AF659E}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{D6F4E693-D20B-417C-AA5F-CE518A4A2D20}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{FD18CDD4-450A-4751-8AB5-BD33BB980A30}] => (Allow) C:\Users\Toshiba\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [TCP Query User{2E121153-D06C-474F-88B5-B59A62B69FF4}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{666FA564-FDF9-4930-8B5E-C0E216E05476}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{240E81E7-EBD5-42B4-B7CC-A67E5E61764F}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{F8861256-9BF0-4F16-9F4E-8A2F564718E4}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [{971C47A2-4FE9-4E04-B122-E04C21DF2F21}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FD6FCF90-9595-4AF5-BE56-D351797838C4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C4DA9577-36D9-4637-AC8F-1259D6054646}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{CAC4893D-5E3F-4DFE-A921-D32292604BDD}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{362FB02C-BD8C-4C10-95EB-8C2A1CDE6F61}C:\program files\360\360 internet security\360sdupd.exe] => (Block) C:\program files\360\360 internet security\360sdupd.exe
FirewallRules: [UDP Query User{D6932836-012D-4413-A3D4-3F814234C16C}C:\program files\360\360 internet security\360sdupd.exe] => (Block) C:\program files\360\360 internet security\360sdupd.exe
FirewallRules: [{73A5BCB0-0F35-48F5-83B6-D728B899E017}] => (Allow) C:\Program Files\360\360 Internet Security\UpTip.exe
FirewallRules: [{D94AC79C-2BAE-4084-8452-B286D758DAEC}] => (Allow) C:\Program Files\360\360 Internet Security\UpTip.exe
FirewallRules: [{B3F69BA1-0C36-4477-8521-6AD9741B356F}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{9F8055D7-257C-4F84-B66F-A8973A10C453}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{C621FD83-9521-4059-B088-F0C8C77287D5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{7641D096-2485-48CD-854D-8B0B0C0EED24}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{2B0054D1-D133-45CF-BDD8-FFDED904102A}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{0EC73F4C-E509-4C8C-A736-32737BE2041A}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{FE7214A9-D1F2-4B0D-9E60-4C5CF379C286}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/01/2015 05:24:35 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Nome do módulo com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Código de excepção: 0x40000015
Desvio de falha: 0x0007da8a
ID do processo com falha: 0xec8
Data/hora de início da aplicação com falha: 0xmbamservice.exe0
Caminho da aplicação com falha: mbamservice.exe1
Caminho do módulo com falha: mbamservice.exe2
ID do Relatório: mbamservice.exe3
 
Error: (12/01/2015 05:24:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamscheduler.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5339cec3
Nome do módulo com falha: MSVCR100.dll, versão: 10.0.40219.325, carimbo de data/hora: 0x4df2be1e
Código de excepção: 0x40000015
Desvio de falha: 0x0008d6fd
ID do processo com falha: 0x904
Data/hora de início da aplicação com falha: 0xmbamscheduler.exe0
Caminho da aplicação com falha: mbamscheduler.exe1
Caminho do módulo com falha: mbamscheduler.exe2
ID do Relatório: mbamscheduler.exe3
 
Error: (11/30/2015 09:43:58 PM) (Source: Google Update) (EventID: 20) (User: Toshiba-TOSH)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http s
 
Error: (11/30/2015 00:50:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Nome do módulo com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Código de excepção: 0x40000015
Desvio de falha: 0x0007da8a
ID do processo com falha: 0xf40
Data/hora de início da aplicação com falha: 0xmbamservice.exe0
Caminho da aplicação com falha: mbamservice.exe1
Caminho do módulo com falha: mbamservice.exe2
ID do Relatório: mbamservice.exe3
 
Error: (11/30/2015 00:50:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamscheduler.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5339cec3
Nome do módulo com falha: MSVCR100.dll, versão: 10.0.40219.325, carimbo de data/hora: 0x4df2be1e
Código de excepção: 0x40000015
Desvio de falha: 0x0008d6fd
ID do processo com falha: 0x8ec
Data/hora de início da aplicação com falha: 0xmbamscheduler.exe0
Caminho da aplicação com falha: mbamscheduler.exe1
Caminho do módulo com falha: mbamscheduler.exe2
ID do Relatório: mbamscheduler.exe3
 
Error: (11/29/2015 09:37:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Nome do módulo com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Código de excepção: 0x40000015
Desvio de falha: 0x0007da8a
ID do processo com falha: 0xfa8
Data/hora de início da aplicação com falha: 0xmbamservice.exe0
Caminho da aplicação com falha: mbamservice.exe1
Caminho do módulo com falha: mbamservice.exe2
ID do Relatório: mbamservice.exe3
 
Error: (11/29/2015 09:37:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamscheduler.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5339cec3
Nome do módulo com falha: MSVCR100.dll, versão: 10.0.40219.325, carimbo de data/hora: 0x4df2be1e
Código de excepção: 0x40000015
Desvio de falha: 0x0008d6fd
ID do processo com falha: 0xb14
Data/hora de início da aplicação com falha: 0xmbamscheduler.exe0
Caminho da aplicação com falha: mbamscheduler.exe1
Caminho do módulo com falha: mbamscheduler.exe2
ID do Relatório: mbamscheduler.exe3
 
Error: (11/29/2015 07:59:13 PM) (Source: Google Update) (EventID: 20) (User: Toshiba-TOSH)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http s
 
Error: (11/28/2015 10:11:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: wmprph.exe, versão: 12.0.7600.16385, carimbo de data/hora: 0x4a5bd018
Nome do módulo com falha: ntdll.dll, versão: 6.1.7601.19045, carimbo de data/hora: 0x56259295
Código de excepção: 0xc0000005
Desvio de falha: 0x000000000004ac04
ID do processo com falha: 0x1f10
Data/hora de início da aplicação com falha: 0xwmprph.exe0
Caminho da aplicação com falha: wmprph.exe1
Caminho do módulo com falha: wmprph.exe2
ID do Relatório: wmprph.exe3
 
Error: (11/28/2015 08:53:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Nome do módulo com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Código de excepção: 0x40000015
Desvio de falha: 0x0007da8a
ID do processo com falha: 0xf30
Data/hora de início da aplicação com falha: 0xmbamservice.exe0
Caminho da aplicação com falha: mbamservice.exe1
Caminho do módulo com falha: mbamservice.exe2
ID do Relatório: mbamservice.exe3
 
 
System errors:
=============
Error: (12/01/2015 05:30:46 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: O serviço NVIDIA Driver Helper Service terminou inesperadamente. Isto aconteceu 1 vez(es).
 
Error: (12/01/2015 05:24:35 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: O serviço MBAMService terminou inesperadamente. Isto aconteceu 1 vez(es).
 
Error: (12/01/2015 05:24:14 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: O serviço MBAMScheduler falhou o arranque devido ao seguinte erro: 
%%1053
 
Error: (12/01/2015 05:24:14 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Foi atingido o tempo limite (30000 milissegundos) ao aguardar pela ligação do serviço MBAMScheduler.
 
Error: (11/30/2015 00:50:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: O serviço MBAMService terminou inesperadamente. Isto aconteceu 1 vez(es).
 
Error: (11/30/2015 00:50:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: O serviço MBAMScheduler falhou o arranque devido ao seguinte erro: 
%%1053
 
Error: (11/30/2015 00:50:35 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Foi atingido o tempo limite (30000 milissegundos) ao aguardar pela ligação do serviço MBAMScheduler.
 
Error: (11/30/2015 06:25:38 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
 
Error: (11/30/2015 03:15:26 AM) (Source: Modem) (EventID: 1) (User: )
Description: \000000a2
 
Error: (11/29/2015 09:46:14 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: A chamada ScRegSetValueExW falhou por FailureCommand com o seguinte erro: 
%%5
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz
Percentage of memory in use: 53%
Total physical RAM: 4077.86 MB
Available physical RAM: 1915.9 MB
Total Virtual: 8153.93 MB
Available Virtual: 5548.56 MB
 
==================== Drives ================================
 
Drive c: (WINDOWS) (Fixed) (Total:149.41 GB) (Free:15.05 GB) NTFS
Drive d: (Data) (Fixed) (Total:148.28 GB) (Free:106.28 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: FCC1188A)
Partition 1: (Active) - (Size=400 MB) - (Type=27)
Partition 2: (Not Active) - (Size=149.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=148.3 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

P2P - I see you have P2P software, (uTorrent ), installed on your machine.

We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection.

You have some nasty stuff on your computer and it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

Please see this topic for more information:

P2P File Sharing Risks.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Download/run Rkill:

Please download Rkill from one of the following links and save to your Desktop:

Please download Rkill from one of the following links and save to your Desktop:

 

Link One
Link Two
Link Three
Link Four

  • on Windows XP double-click on the Rkill desktop icon to run the tool
  • on Windows Vista/Windows 7 or 8, right-click on the Rkill desktop icon and select Run As Administrator
  • a black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully
  • if not, delete the file, then download and use the one provided in Link 2
  • if it does not work, repeat the process and attempt to use one of the remaining links until the tool runs
  • if the tool does not run from any of the links provided, please let me know
  • do not reboot the computer or you will need to run the application again
  • please leave Rkill on the Desktop until otherwise advised.

Note: If your security software warns about Rkill, please ignore and allow the download to continue.

================================================

Uninstall programs

Please uninstall these programs:

360 Total Security
pgcchelper

  • click Start, Control Panel, Programs and Features
  • click on 360 Total Security and then Uninstall
  • repeat this for pgcchelper.

If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

================================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:

  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scan” tab, select Threat Scan, then click Scan.
  • when the scan is complete, if no malicious items are found you can close the program
  • if malicious items are found be sure that everything is checked and click Quarantine
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.

NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

================================================

When you’ve done the above, please run FRST again and make sure there is a checkmark next to "Addition.txt" before you hit “Scan”.

Logs to include with the next post:

Mbam.txt
New Frst.txt
New Addition.txt


Satchfan

 

Unnistaled: uTorrent, 360 Total Security and pgcchelper

 

Runned Rkill

 

Mbam log.txt:

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Data da Verificação: 04-12-2015
Hora da Verificação: 03:18
Ficheiro de Relatório: Malwarebytes Anti Malware.txt
Administrador: Sim
 
Versão: 2.2.0.1024
Base de Dados de Malware: v2015.12.03.06
Base de dados de Rootkits: v2015.11.26.01
Licença: Grátis
Proteção contra Malware: Desativado
Proteção contra Websites Maliciosos: Desativado
Autoproteção: Desativado
 
SO: Windows 7 Service Pack 1
CPU: x64
Sistema de Ficheiros: NTFS
Utilizador: Toshiba
 
Tipo de Verificação: Verificação de Ameaças
Resultado: Concluída
Objetos Verificados: 518410
Tempo Decorrido: 1 h, 12 min, 25 s
 
Memória: Ativado
Arranque: Ativado
Sistema de Ficheiros: Ativado
Arquivos: Ativado
Rootkits: Desativado
Heurísticos: Ativado
PPI: Avisar
MPI: Ativado
 
Processos: 0
(Nenhum item malicioso detetado)
 
Módulos: 0
(Nenhum item malicioso detetado)
 
Chaves de Registo: 11
PUP.Optional.AdvancedSystemProtector, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Advanced System Protector, Apagar ao Reiniciar, [238fb2ee682345f1967f264fbf44ce32], 
PUP.Optional.OpenCandy, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OpenCandyHelperRunAsStandardUser, Apagar ao Reiniciar, [7042b0f0008bd95dc8f9eab28281d62a], 
PUP.Optional.OpenCandy, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OpenCandyHelperRunAsStandardUserD5C8C5F5C62F445384F8C780A93D054D, Apagar ao Reiniciar, [6d45613f5635d165ffc22676649f33cd], 
PUP.Optional.OpenCandy, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OpenCandyHelperRunOnce, Apagar ao Reiniciar, [357d920eb8d33ff75c650f8d2fd4a957], 
PUP.Optional.OpenCandy, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OpenCandyHelperRunOnce647E88A251DB4A5787E04198D2B6F7E7, Apagar ao Reiniciar, [9c163c64810aee48bb06cbd18e7513ed], 
PUP.Optional.Enabler, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\SK.Enabler-S-1495795506, Apagar ao Reiniciar, [a0124957d2b97eb8dd65cfb8f01352ae], 
PUP.Optional.Somoto, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\SomotoUpdateCheckerAutoStart, Apagar ao Reiniciar, [2092bde34f3cc5718c0a4a5f80831fe1], 
PUM.Optional.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, Movido para Quarentena, [9c165b450685e74fde2916d6fd0609f7], 
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110011341191}, Movido para Quarentena, [545e613f3b5092a47afbff8458ab26da], 
PUM.Optional.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, Movido para Quarentena, [f3bf712f8506082ee225c72544bfd030], 
PUP.Optional.CrossRider, HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F80120C0-E381-4274-8E7F-26F6A95CD5F8}, Movido para Quarentena, [4e649b059bf0e74fef67f093a06343bd], 
 
Valores de Registo: 5
PUM.Optional.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, Movido para Quarentena, [9c165b450685e74fde2916d6fd0609f7]
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110011341191}|AppName, Vid-Saver-bg.exe, Movido para Quarentena, [545e613f3b5092a47afbff8458ab26da]
PUP.Optional.FreeMakeConverter, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|[removed], C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\, Movido para Quarentena, [2b873769335847ef0c2a24668c77dd23]
PUM.Optional.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, Movido para Quarentena, [f3bf712f8506082ee225c72544bfd030]
PUP.Optional.CrossRider, HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F80120C0-E381-4274-8E7F-26F6A95CD5F8}|AppName, The weDownload Manager-enabler.exe-codedownloader.exe, Movido para Quarentena, [4e649b059bf0e74fef67f093a06343bd]
 
Dados de Registo: 0
(Nenhum item malicioso detetado)
 
Pastas: 79
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1, Movido para Quarentena, [c3efdcc40b8025119dafccd2f40ed030], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig, Movido para Quarentena, [c3efdcc40b8025119dafccd2f40ed030], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [931f861a7318f73fb399138b1ee4d52b], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [931f861a7318f73fb399138b1ee4d52b], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [0aa8b4ec3d4e5fd71e2e811daa581ae6], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [0aa8b4ec3d4e5fd71e2e811daa581ae6], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7, Movido para Quarentena, [b7fb9b05f19afa3cfc501e800002916f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk, Movido para Quarentena, [b7fb9b05f19afa3cfc501e800002916f], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1, Movido para Quarentena, [d8da049cc1ca72c43e0eafef8979669a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig, Movido para Quarentena, [d8da049cc1ca72c43e0eafef8979669a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [3a780c94f299063053f9c7d723df6d93], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [3a780c94f299063053f9c7d723df6d93], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [a1111c84f19a45f1f25ab4ea0ef46b95], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [a1111c84f19a45f1f25ab4ea0ef46b95], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7, Movido para Quarentena, [179be9b7d2b9b77ffb51564807fb16ea], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk, Movido para Quarentena, [179be9b7d2b9b77ffb51564807fb16ea], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1, Movido para Quarentena, [a30fd7c9bdce8caa3913a4fa39c9f30d], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig, Movido para Quarentena, [a30fd7c9bdce8caa3913a4fa39c9f30d], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [169c1d83018a77bf85c7b5e943bf956b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [169c1d83018a77bf85c7b5e943bf956b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [654dcbd5ff8ceb4b39132f6f0af89868], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [654dcbd5ff8ceb4b39132f6f0af89868], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7, Movido para Quarentena, [4c66f2aed8b323133f0d584624defe02], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk, Movido para Quarentena, [4c66f2aed8b323133f0d584624defe02], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1, Movido para Quarentena, [0fa3623efd8e46f0d6769a04877b9e62], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig, Movido para Quarentena, [0fa3623efd8e46f0d6769a04877b9e62], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [e3cf138d19720d29ed5fc2dc10f229d7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [e3cf138d19720d29ed5fc2dc10f229d7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [9e145b45b8d3fd39e8644d5114eeaf51], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [9e145b45b8d3fd39e8644d5114eeaf51], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7, Movido para Quarentena, [cfe359477615b87efe4ed3cb4db55fa1], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk, Movido para Quarentena, [cfe359477615b87efe4ed3cb4db55fa1], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1, Movido para Quarentena, [a50da6fa78130d2966e7c2dc9969f907], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig, Movido para Quarentena, [a50da6fa78130d2966e7c2dc9969f907], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [e2d0e1bf96f5eb4bc08dc2dccd3553ad], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [e2d0e1bf96f5eb4bc08dc2dccd3553ad], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [0da5168a0c7f4fe7da736a34a35f7b85], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [0da5168a0c7f4fe7da736a34a35f7b85], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7, Movido para Quarentena, [dfd38b158209f442a3aa0a940200b14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk, Movido para Quarentena, [dfd38b158209f442a3aa0a940200b14f], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1, Movido para Quarentena, [e9c96f317c0fc37307462678f21031cf], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig, Movido para Quarentena, [e9c96f317c0fc37307462678f21031cf], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [3e74acf48407c96dd17c2678679b6a96], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [3e74acf48407c96dd17c2678679b6a96], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [04ae5947f89350e6d974dfbf03ff39c7], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [04ae5947f89350e6d974dfbf03ff39c7], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7, Movido para Quarentena, [753d0f91315a82b41b324955828020e0], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk, Movido para Quarentena, [753d0f91315a82b41b324955828020e0], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1, Movido para Quarentena, [931f019f32595ed8e568e6b858aa0cf4], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig, Movido para Quarentena, [931f019f32595ed8e568e6b858aa0cf4], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [dad82b75a3e8082ea8a5910d7c865aa6], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [dad82b75a3e8082ea8a5910d7c865aa6], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [5e549b05c2c97eb8da73b4eaae549c64], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [5e549b05c2c97eb8da73b4eaae549c64], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7, Movido para Quarentena, [9f13b1ef45464fe70d40c4dacc36e41c], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk, Movido para Quarentena, [9f13b1ef45464fe70d40c4dacc36e41c], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1, Movido para Quarentena, [5e543769cac1fd3976d78c1211f1bf41], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig, Movido para Quarentena, [5e543769cac1fd3976d78c1211f1bf41], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [634f5b45c9c2ae88212cb1edd42e23dd], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [634f5b45c9c2ae88212cb1edd42e23dd], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [e7cb4e52a1ea39fde06d504ea75b39c7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [e7cb4e52a1ea39fde06d504ea75b39c7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7, Movido para Quarentena, [7e34e0c0513ab97df35a158952b08d73], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk, Movido para Quarentena, [7e34e0c0513ab97df35a158952b08d73], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [f8ba8e12305b48ee469afa9fd72cb14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [f8ba8e12305b48ee469afa9fd72cb14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [773b87191e6d181e459b970245bea957], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [773b87191e6d181e459b970245bea957], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [03af712fd7b480b60cd46f2a3fc414ec], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [03af712fd7b480b60cd46f2a3fc414ec], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [4072366af99263d30bd56e2b1ce7e61a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [4072366af99263d30bd56e2b1ce7e61a], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1, Movido para Quarentena, [fab8ddc3ccbfc571934d6039c53e758b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf, Movido para Quarentena, [fab8ddc3ccbfc571934d6039c53e758b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104, Movido para Quarentena, [753de0c0ed9e1b1b5b857f1a20e318e8], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp, Movido para Quarentena, [753de0c0ed9e1b1b5b857f1a20e318e8], 
PUP.Optional.Pedka, C:\Users\Toshiba\AppData\Local\pgcchelper, Movido para Quarentena, [c4eeecb4b6d5d75f5b81f494a0621be5], 
PUP.Optional.ASK.Gen, C:\Users\Toshiba\AppData\Local\Temp\APN-Stub, Movido para Quarentena, [c3efa8f8820976c0cf422574ab578779], 
PUP.Optional.ASK.Gen, C:\Users\Toshiba\AppData\Local\Temp\APN-Stub\Unknown, Movido para Quarentena, [c3efa8f8820976c0cf422574ab578779], 
 
Ficheiros: 183
PUP.Optional.APNToolBar, C:\Users\Toshiba\AppData\Local\Temp\is-BALLB.tmp\Offercast33_ATU3_.exe, Movido para Quarentena, [af03821e8209082e70f0b7728b7607f9], 
PUP.Optional.Amonetize, C:\Users\Toshiba\Downloads\Gay+Jizz+Orgy+Major+Leagu (1).ace, Movido para Quarentena, [5e54d7c9a0eb072f33706246c8391ee2], 
PUP.Optional.Amonetize, C:\Users\Toshiba\Downloads\Gay+Jizz+Orgy+Major+Leagu.ace, Movido para Quarentena, [41711d83484338fe782b674133ce8779], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\lsdb.js, Movido para Quarentena, [c3efdcc40b8025119dafccd2f40ed030], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\background.html, Movido para Quarentena, [c3efdcc40b8025119dafccd2f40ed030], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\content.js, Movido para Quarentena, [c3efdcc40b8025119dafccd2f40ed030], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\icon48.png, Movido para Quarentena, [c3efdcc40b8025119dafccd2f40ed030], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\manifest.json, Movido para Quarentena, [c3efdcc40b8025119dafccd2f40ed030], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [931f861a7318f73fb399138b1ee4d52b], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [931f861a7318f73fb399138b1ee4d52b], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [931f861a7318f73fb399138b1ee4d52b], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [931f861a7318f73fb399138b1ee4d52b], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [931f861a7318f73fb399138b1ee4d52b], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [0aa8b4ec3d4e5fd71e2e811daa581ae6], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [0aa8b4ec3d4e5fd71e2e811daa581ae6], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [0aa8b4ec3d4e5fd71e2e811daa581ae6], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [0aa8b4ec3d4e5fd71e2e811daa581ae6], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\lsdb.js, Movido para Quarentena, [b7fb9b05f19afa3cfc501e800002916f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\background.html, Movido para Quarentena, [b7fb9b05f19afa3cfc501e800002916f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\content.js, Movido para Quarentena, [b7fb9b05f19afa3cfc501e800002916f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\manifest.json, Movido para Quarentena, [b7fb9b05f19afa3cfc501e800002916f], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\lsdb.js, Movido para Quarentena, [d8da049cc1ca72c43e0eafef8979669a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\background.html, Movido para Quarentena, [d8da049cc1ca72c43e0eafef8979669a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\content.js, Movido para Quarentena, [d8da049cc1ca72c43e0eafef8979669a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\icon48.png, Movido para Quarentena, [d8da049cc1ca72c43e0eafef8979669a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\manifest.json, Movido para Quarentena, [d8da049cc1ca72c43e0eafef8979669a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [3a780c94f299063053f9c7d723df6d93], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [3a780c94f299063053f9c7d723df6d93], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [3a780c94f299063053f9c7d723df6d93], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [3a780c94f299063053f9c7d723df6d93], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [3a780c94f299063053f9c7d723df6d93], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [a1111c84f19a45f1f25ab4ea0ef46b95], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [a1111c84f19a45f1f25ab4ea0ef46b95], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [a1111c84f19a45f1f25ab4ea0ef46b95], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [a1111c84f19a45f1f25ab4ea0ef46b95], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\lsdb.js, Movido para Quarentena, [179be9b7d2b9b77ffb51564807fb16ea], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\background.html, Movido para Quarentena, [179be9b7d2b9b77ffb51564807fb16ea], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\content.js, Movido para Quarentena, [179be9b7d2b9b77ffb51564807fb16ea], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\manifest.json, Movido para Quarentena, [179be9b7d2b9b77ffb51564807fb16ea], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\lsdb.js, Movido para Quarentena, [a30fd7c9bdce8caa3913a4fa39c9f30d], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\background.html, Movido para Quarentena, [a30fd7c9bdce8caa3913a4fa39c9f30d], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\content.js, Movido para Quarentena, [a30fd7c9bdce8caa3913a4fa39c9f30d], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\icon48.png, Movido para Quarentena, [a30fd7c9bdce8caa3913a4fa39c9f30d], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\manifest.json, Movido para Quarentena, [a30fd7c9bdce8caa3913a4fa39c9f30d], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [169c1d83018a77bf85c7b5e943bf956b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [169c1d83018a77bf85c7b5e943bf956b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [169c1d83018a77bf85c7b5e943bf956b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [169c1d83018a77bf85c7b5e943bf956b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [169c1d83018a77bf85c7b5e943bf956b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [654dcbd5ff8ceb4b39132f6f0af89868], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [654dcbd5ff8ceb4b39132f6f0af89868], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [654dcbd5ff8ceb4b39132f6f0af89868], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [654dcbd5ff8ceb4b39132f6f0af89868], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\lsdb.js, Movido para Quarentena, [4c66f2aed8b323133f0d584624defe02], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\background.html, Movido para Quarentena, [4c66f2aed8b323133f0d584624defe02], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\content.js, Movido para Quarentena, [4c66f2aed8b323133f0d584624defe02], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\manifest.json, Movido para Quarentena, [4c66f2aed8b323133f0d584624defe02], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\lsdb.js, Movido para Quarentena, [0fa3623efd8e46f0d6769a04877b9e62], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\background.html, Movido para Quarentena, [0fa3623efd8e46f0d6769a04877b9e62], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\content.js, Movido para Quarentena, [0fa3623efd8e46f0d6769a04877b9e62], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\icon48.png, Movido para Quarentena, [0fa3623efd8e46f0d6769a04877b9e62], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\manifest.json, Movido para Quarentena, [0fa3623efd8e46f0d6769a04877b9e62], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [e3cf138d19720d29ed5fc2dc10f229d7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [e3cf138d19720d29ed5fc2dc10f229d7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [e3cf138d19720d29ed5fc2dc10f229d7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [e3cf138d19720d29ed5fc2dc10f229d7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [e3cf138d19720d29ed5fc2dc10f229d7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [9e145b45b8d3fd39e8644d5114eeaf51], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [9e145b45b8d3fd39e8644d5114eeaf51], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [9e145b45b8d3fd39e8644d5114eeaf51], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [9e145b45b8d3fd39e8644d5114eeaf51], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\lsdb.js, Movido para Quarentena, [cfe359477615b87efe4ed3cb4db55fa1], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\background.html, Movido para Quarentena, [cfe359477615b87efe4ed3cb4db55fa1], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\content.js, Movido para Quarentena, [cfe359477615b87efe4ed3cb4db55fa1], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\manifest.json, Movido para Quarentena, [cfe359477615b87efe4ed3cb4db55fa1], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\lsdb.js, Movido para Quarentena, [a50da6fa78130d2966e7c2dc9969f907], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\background.html, Movido para Quarentena, [a50da6fa78130d2966e7c2dc9969f907], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\content.js, Movido para Quarentena, [a50da6fa78130d2966e7c2dc9969f907], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\icon48.png, Movido para Quarentena, [a50da6fa78130d2966e7c2dc9969f907], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\manifest.json, Movido para Quarentena, [a50da6fa78130d2966e7c2dc9969f907], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [e2d0e1bf96f5eb4bc08dc2dccd3553ad], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [e2d0e1bf96f5eb4bc08dc2dccd3553ad], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [e2d0e1bf96f5eb4bc08dc2dccd3553ad], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [e2d0e1bf96f5eb4bc08dc2dccd3553ad], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [e2d0e1bf96f5eb4bc08dc2dccd3553ad], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [0da5168a0c7f4fe7da736a34a35f7b85], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [0da5168a0c7f4fe7da736a34a35f7b85], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [0da5168a0c7f4fe7da736a34a35f7b85], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [0da5168a0c7f4fe7da736a34a35f7b85], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\lsdb.js, Movido para Quarentena, [dfd38b158209f442a3aa0a940200b14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\background.html, Movido para Quarentena, [dfd38b158209f442a3aa0a940200b14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\content.js, Movido para Quarentena, [dfd38b158209f442a3aa0a940200b14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\manifest.json, Movido para Quarentena, [dfd38b158209f442a3aa0a940200b14f], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\lsdb.js, Movido para Quarentena, [e9c96f317c0fc37307462678f21031cf], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\background.html, Movido para Quarentena, [e9c96f317c0fc37307462678f21031cf], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\content.js, Movido para Quarentena, [e9c96f317c0fc37307462678f21031cf], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\icon48.png, Movido para Quarentena, [e9c96f317c0fc37307462678f21031cf], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\manifest.json, Movido para Quarentena, [e9c96f317c0fc37307462678f21031cf], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [3e74acf48407c96dd17c2678679b6a96], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [3e74acf48407c96dd17c2678679b6a96], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [3e74acf48407c96dd17c2678679b6a96], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [3e74acf48407c96dd17c2678679b6a96], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [3e74acf48407c96dd17c2678679b6a96], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [04ae5947f89350e6d974dfbf03ff39c7], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [04ae5947f89350e6d974dfbf03ff39c7], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [04ae5947f89350e6d974dfbf03ff39c7], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [04ae5947f89350e6d974dfbf03ff39c7], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\lsdb.js, Movido para Quarentena, [753d0f91315a82b41b324955828020e0], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\background.html, Movido para Quarentena, [753d0f91315a82b41b324955828020e0], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\content.js, Movido para Quarentena, [753d0f91315a82b41b324955828020e0], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\manifest.json, Movido para Quarentena, [753d0f91315a82b41b324955828020e0], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\lsdb.js, Movido para Quarentena, [931f019f32595ed8e568e6b858aa0cf4], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\background.html, Movido para Quarentena, [931f019f32595ed8e568e6b858aa0cf4], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\content.js, Movido para Quarentena, [931f019f32595ed8e568e6b858aa0cf4], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\icon48.png, Movido para Quarentena, [931f019f32595ed8e568e6b858aa0cf4], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\manifest.json, Movido para Quarentena, [931f019f32595ed8e568e6b858aa0cf4], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [dad82b75a3e8082ea8a5910d7c865aa6], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [dad82b75a3e8082ea8a5910d7c865aa6], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [dad82b75a3e8082ea8a5910d7c865aa6], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [dad82b75a3e8082ea8a5910d7c865aa6], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [dad82b75a3e8082ea8a5910d7c865aa6], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [5e549b05c2c97eb8da73b4eaae549c64], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [5e549b05c2c97eb8da73b4eaae549c64], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [5e549b05c2c97eb8da73b4eaae549c64], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [5e549b05c2c97eb8da73b4eaae549c64], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\lsdb.js, Movido para Quarentena, [9f13b1ef45464fe70d40c4dacc36e41c], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\background.html, Movido para Quarentena, [9f13b1ef45464fe70d40c4dacc36e41c], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\content.js, Movido para Quarentena, [9f13b1ef45464fe70d40c4dacc36e41c], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\manifest.json, Movido para Quarentena, [9f13b1ef45464fe70d40c4dacc36e41c], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\lsdb.js, Movido para Quarentena, [5e543769cac1fd3976d78c1211f1bf41], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\background.html, Movido para Quarentena, [5e543769cac1fd3976d78c1211f1bf41], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\content.js, Movido para Quarentena, [5e543769cac1fd3976d78c1211f1bf41], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\icon48.png, Movido para Quarentena, [5e543769cac1fd3976d78c1211f1bf41], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfnmilbmajnbldkbonmbbdofiaobjpig\1.1\manifest.json, Movido para Quarentena, [5e543769cac1fd3976d78c1211f1bf41], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [634f5b45c9c2ae88212cb1edd42e23dd], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [634f5b45c9c2ae88212cb1edd42e23dd], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [634f5b45c9c2ae88212cb1edd42e23dd], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [634f5b45c9c2ae88212cb1edd42e23dd], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [634f5b45c9c2ae88212cb1edd42e23dd], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [e7cb4e52a1ea39fde06d504ea75b39c7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [e7cb4e52a1ea39fde06d504ea75b39c7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [e7cb4e52a1ea39fde06d504ea75b39c7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [e7cb4e52a1ea39fde06d504ea75b39c7], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\lsdb.js, Movido para Quarentena, [7e34e0c0513ab97df35a158952b08d73], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\background.html, Movido para Quarentena, [7e34e0c0513ab97df35a158952b08d73], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\content.js, Movido para Quarentena, [7e34e0c0513ab97df35a158952b08d73], 
PUP.Optional.MultiPlug, C:\Users\Toshiba\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\liabipegcpgffnknmdhangpphpapholk\2.7\manifest.json, Movido para Quarentena, [7e34e0c0513ab97df35a158952b08d73], 
PUP.Optional.Enabler, C:\Windows\Tasks\SK.Enabler-S-1495795506.job, Movido para Quarentena, [f0c27c246c1f96a0fc44612648bbc937], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [f8ba8e12305b48ee469afa9fd72cb14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [f8ba8e12305b48ee469afa9fd72cb14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [f8ba8e12305b48ee469afa9fd72cb14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [f8ba8e12305b48ee469afa9fd72cb14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [f8ba8e12305b48ee469afa9fd72cb14f], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [773b87191e6d181e459b970245bea957], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [773b87191e6d181e459b970245bea957], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [773b87191e6d181e459b970245bea957], 
PUP.Optional.MultiPlug, C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [773b87191e6d181e459b970245bea957], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [03af712fd7b480b60cd46f2a3fc414ec], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [03af712fd7b480b60cd46f2a3fc414ec], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [03af712fd7b480b60cd46f2a3fc414ec], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [03af712fd7b480b60cd46f2a3fc414ec], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [03af712fd7b480b60cd46f2a3fc414ec], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [4072366af99263d30bd56e2b1ce7e61a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [4072366af99263d30bd56e2b1ce7e61a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [4072366af99263d30bd56e2b1ce7e61a], 
PUP.Optional.MultiPlug, C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [4072366af99263d30bd56e2b1ce7e61a], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\lsdb.js, Movido para Quarentena, [fab8ddc3ccbfc571934d6039c53e758b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\background.html, Movido para Quarentena, [fab8ddc3ccbfc571934d6039c53e758b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\content.js, Movido para Quarentena, [fab8ddc3ccbfc571934d6039c53e758b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\manifest.json, Movido para Quarentena, [fab8ddc3ccbfc571934d6039c53e758b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbdkochhjlohgipfideljcbgckcfnhf\2.1\newtab.html, Movido para Quarentena, [fab8ddc3ccbfc571934d6039c53e758b], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\lsdb.js, Movido para Quarentena, [753de0c0ed9e1b1b5b857f1a20e318e8], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\background.html, Movido para Quarentena, [753de0c0ed9e1b1b5b857f1a20e318e8], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\content.js, Movido para Quarentena, [753de0c0ed9e1b1b5b857f1a20e318e8], 
PUP.Optional.MultiPlug, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\igapgnpnmadafimalefljcfplikonjpp\104\manifest.json, Movido para Quarentena, [753de0c0ed9e1b1b5b857f1a20e318e8], 
PUP.Optional.PricePeep, C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage, Movido para Quarentena, [139f4d536e1d0036e87e7729b3507789], 
PUP.Optional.PricePeep, C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal, Movido para Quarentena, [c0f2534dc4c71b1bed799e02db287b85], 
PUP.Optional.ReMarkit.PrxySvrRST, C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage, Movido para Quarentena, [ffb300a0c8c3181e9f253a8561a28a76], 
PUP.Optional.ReMarkit.PrxySvrRST, C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage-journal, Movido para Quarentena, [5f539f013952290d3f85e9d68c77936d], 
PUP.Optional.ReMarkit.PrxySvrRST, C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markit00.re-markit.co_0.localstorage, Movido para Quarentena, [a2106b3523681f17e6de853a9a69c13f], 
PUP.Optional.ReMarkit.PrxySvrRST, C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markit00.re-markit.co_0.localstorage-journal, Movido para Quarentena, [4d65f6aa75167db9bd075e61fc078b75], 
PUP.Optional.Pedka, C:\Users\Toshiba\AppData\Local\pgcchelper\pgcchelper_uninstaller.exe, Movido para Quarentena, [c4eeecb4b6d5d75f5b81f494a0621be5], 
PUP.Optional.ASK.Gen, C:\Users\Toshiba\AppData\Local\Temp\APN-Stub\Unknown\Stbd4bff06d-f55e-4c48-bcda-dbe85efb0736.log, Movido para Quarentena, [c3efa8f8820976c0cf422574ab578779], 
 
Sectores Físicos: 0
(Nenhum item malicioso detetado)
 
 
(end)

 

New Frst.txt:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:30-11-2015
Ran by [removed] (administrator) on TOSHIBA-TOSH (04-12-2015 04:48:46)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Português (Portugal)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoService.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\Teco.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
(Macrovision Corporation) C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Octoshape ApS) C:\Users\Toshiba\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
(Nico Mak Computing) C:\Program Files\WinZip\FAHWindow64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
(Nico Mak Computing) C:\Program Files\WinZip\WZUpdateNotifier.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Flexera Software, Inc.) C:\ProgramData\FLEXnet\Connect\11\agent.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2010-12-13] (TOSHIBA Corporation)
HKLM\…\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation)
HKLM\…\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH)
HKLM\…\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [571304 2010-12-09] (TOSHIBA Corporation)
HKLM\…\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [296824 2010-09-25] (TOSHIBA Corporation)
HKLM\…\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [973176 2010-12-15] (TOSHIBA Corporation)
HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-03] (Synaptics Incorporated)
HKLM\…\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1519016 2010-12-08] (TOSHIBA Corporation)
HKLM\…\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710040 2010-12-08] (TOSHIBA Corporation)
HKLM\…\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [711576 2010-12-20] (TOSHIBA Corporation)
HKLM\…\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\…\Run: [Toshiba Registration] => C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [150992 2011-03-03] (Toshiba Europe GmbH)
HKLM\…\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\…\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [ITSecMng] => %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
HKLM-x32\…\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [252792 2010-06-04] (TOSHIBA)
HKLM-x32\…\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2475384 2011-01-16] (TOSHIBA CORPORATION.)
HKLM-x32\…\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295072 2013-02-03] (RealNetworks, Inc.)
HKLM-x32\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM-x32\…\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [69632 2012-03-20] (Vodafone)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKU\S-1-5-19\…\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
HKU\S-1-5-20\…\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Run: [ISUSPM] => C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe [222128 2007-03-29] (Macrovision Corporation)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [912480 2015-09-02] (Microsoft Corporation)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Run: [Octoshape Streaming Services] => C:\Users\Toshiba\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800 2011-03-24] (Octoshape ApS)
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: F - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: G - G:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {2091109a-ec9b-11e2-81bf-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {209110a1-ec9b-11e2-81bf-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {3354c7d3-b65f-11e1-85c4-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {3354c7da-b65f-11e1-85c4-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {555db868-c42c-11e1-986e-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {555db87a-c42c-11e1-986e-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {6d39009a-89cd-11e3-81a6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {7dff1801-042d-11e3-99f7-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {7ee67c48-ab5d-11e1-9c37-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {814e09fc-06a0-11e3-bfb8-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {839edb36-bef0-11e1-a7f6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d65fc-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d660c-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d660f-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d661e-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6634-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6647-be0d-11e1-a6d5-001e101f6c04} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6654-be0d-11e1-a6d5-001e101f6c04} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {98b68ef4-8cf3-11e4-a1d6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b1170f08-b665-11e1-aaae-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b128d9d0-79a3-11e1-ad2b-e89a8f044043} - G:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b128d9d7-79a3-11e1-ad2b-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b4e4fd6e-06b5-11e3-bc4e-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd4f-4c49-11e2-845e-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd60-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd95-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbda6-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {c905ad93-7dc4-11e1-9435-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {c905ada5-7dc4-11e1-9435-e89a8f044043} - G:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {d1598edb-052f-11e3-9b91-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {e5eb2800-7dd1-11e1-ba79-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaa6-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaa9-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaab-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {fed48f45-b0e5-11e1-bdfc-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-18\…\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
AppInit_DLLs: C:\Windows\Jaksta\AC\x64\jaudcap.dll => C:\Windows\Jaksta\AC\x64\jaudcap.dll [311584 2013-10-31] (Jaksta Technologies Pty Ltd)
AppInit_DLLs-x32: c:\windows\jaksta\ac\x86\jaudcap.dll => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll [2013-05-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll [2013-05-25] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2015-10-28]
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk [2015-10-28]
ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2015-10-28]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2011-03-03]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2011-03-03]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{29C379EB-15F5-4442-AA43-EB5BBACB5BAD}: [NameServer] 87.103.113.145 87.103.113.209
Tcpip\..\Interfaces\{38C84661-4E79-4615-80AF-39A9CC15597A}: [DhcpNameServer] 10.4.0.1
Tcpip\..\Interfaces\{55E724F6-2238-4EB4-8837-A7F77724710C}: [DhcpNameServer] 192.168.9.1 192.168.9.1
Tcpip\..\Interfaces\{68286DD8-2390-4CC7-89AA-0E467F732497}: [DhcpNameServer] 192.168.1.254 192.168.1.254
Tcpip\..\Interfaces\{8FE9971E-EE68-4FEB-99F3-97886FB827C8}: [DhcpNameServer] 10.4.0.1
Tcpip\..\Interfaces\{BE796E17-B658-4766-850E-2A2DC603FD09}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{E033A2D6-B0C3-4FC5-9A5D-7BA019A686D1}: [NameServer] 87.103.113.145 87.103.113.209
Tcpip\..\Interfaces\{E033A2D6-B0C3-4FC5-9A5D-7BA019A686D1}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{F1AC4D32-119C-4B55-889E-5D6285A6420A}: [NameServer] 87.103.113.145 87.103.113.209
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {F11F3195-DB15-4386-AC80-13C6FE576B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=TSHMDF&pc;=MATM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {6F601FA8-C974-4DA2-BE97-D0382BB0B5AD} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=TSHMDF&pc;=MATM&src;=IE-SearchBox
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: AllCHeApPrice -> {A26C1ADD-E1BD-E1E3-22F8-2342C59EF108} -> C:\ProgramData\AllCHeApPrice\ALdqClzjI.x64.dll => No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: GreAatsaveR -> {F8F6BED2-3F26-FA29-32C4-4F4312546BF4} -> C:\Program Files (x86)\GreAatsaveR\WAcF.x64.dll => No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-20] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: No Name -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-20] (Oracle Corporation)
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\yb2m6y23.default
FF Homepage: hxxps://www.google.pt/
FF Session Restore: -> is enabled.
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll [2014-07-09] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll [2014-07-09] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-20] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2011-01-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2011-01-16] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @real.com/nppl3260;version=16.0.0.282 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2013-02-03] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.5.109 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-07-24] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.5.109 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-07-24] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.0.282 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2013-02-03] (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2012-11-29] (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2013-04-10] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2217298813-2927578935-920386982-1000: @octoshape.com/Octoshape Streaming Services,version=1.0 -> C:\Users\Toshiba\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1312180-0-npoctoshape.dll [2013-12-18] (Octoshape ApS)
FF Plugin HKU\S-1-5-21-2217298813-2927578935-920386982-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Toshiba\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin ProgramFiles/Appdata: C:\Users\Toshiba\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2014-05-22] (Octoshape ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priberam.xml [2014-10-15]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sapo.xml [2014-10-15]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-ptpt.xml [2015-04-05]
FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox [2013-02-03] [not signed]
FF Extension: No Name - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [not found]
FF Extension: SNT - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\yb2m6y23.default\Extensions\[removed] [2014-01-21] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-02-03] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
 
Chrome: 
=======
CHR NewTab: Default -> "chrome-extension://cbmbfafhdccfgdgnbkgogehiklmemkoh/index.html"
CHR Profile: C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05]
CHR Extension: (Google Drive) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (X New Tab Page) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmbfafhdccfgdgnbkgogehiklmemkoh [2015-03-21]
CHR Extension: (Adblock Plus) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-11-25]
CHR Extension: (Google Search) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Block site) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2015-07-18]
CHR Extension: (Documentos do Google offline) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Proteção de Internet do 360) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\glcimepnljoholdmjchkloafkggfoijh [2015-11-09]
CHR Extension: (RealDownloader) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-05-28]
CHR Extension: (Adblock Super) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\knebimhcckndhiglamoabbnifdkijidd [2015-09-15]
CHR Extension: (StayFocusd) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2014-11-06]
CHR Extension: (Ajudante de Download de vídeo) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnkioblodjcgkdailhejgcocjkkoochj [2015-04-26]
CHR Extension: (Pagamentos via Chrome Web Store) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-25]
CHR Extension: (Gmail) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR HKLM-x32\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2012-11-29]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
R2 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2012-03-20] (Vodafone) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [243200 2009-10-21] (Huawei Technologies Co., Ltd.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [227840 2012-03-16] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-04] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 Tosrfcom; no ImagePath
S3 WsAudioDevice_383S(1); C:\Windows\System32\drivers\WsAudioDevice_383S(1).sys [29288 2013-05-30] (Wondershare)
S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-04 03:15 - 2015-12-04 03:15 - 22908888 _____ (Malwarebytes ) C:\Users\Toshiba\Downloads\mbam-setup-2.2.0.1024.exe
2015-12-04 03:10 - 2015-12-04 03:10 - 02032072 _____ (Bleeping Computer, LLC) C:\Users\Toshiba\Downloads\rkill.com
2015-12-04 03:04 - 2015-12-04 03:13 - 00002668 _____ C:\Users\Toshiba\Desktop\Rkill.txt
2015-12-04 03:04 - 2015-12-04 03:04 - 02032072 _____ (Bleeping Computer, LLC) C:\Users\Toshiba\Downloads\rkill.exe
2015-12-04 03:04 - 2015-12-04 03:04 - 01107912 _____ (Bleeping Computer, LLC) C:\Users\Toshiba\Downloads\rkill64.exe
2015-12-03 04:11 - 2015-12-03 04:11 - 00208125 _____ C:\Users\Toshiba\Downloads\Ponto_7 (3).pdf
2015-12-03 00:19 - 2015-12-03 00:19 - 02247087 _____ C:\Users\Toshiba\Downloads\Karl Weick (3).pdf
2015-12-02 19:32 - 2015-12-02 19:32 - 00061616 _____ C:\Users\Toshiba\Documents\so.pptx
2015-12-02 11:01 - 2015-12-02 11:01 - 02247087 _____ C:\Users\Toshiba\Downloads\Karl Weick (2).pdf
2015-12-02 09:56 - 2015-12-02 09:56 - 00010607 _____ C:\Users\Toshiba\Downloads\Entrega do TP4_listagem de alunos (3).xlsx
2015-12-02 09:55 - 2015-12-02 09:56 - 00010802 _____ C:\Users\Toshiba\Downloads\Listagem de alunos slecionados para a entrega da Resolução do TRabalho Prático nº 3 (3).xlsx
2015-12-02 09:55 - 2015-12-02 09:55 - 00014733 _____ C:\Users\Toshiba\Downloads\TP1_alunos selecionados (2).xlsx
2015-12-02 09:55 - 2015-12-02 09:55 - 00010918 _____ C:\Users\Toshiba\Downloads\TP2_alunos selecionados (3).xlsx
2015-12-02 08:19 - 2015-12-02 09:49 - 00126113 _____ C:\Users\Toshiba\Downloads\TP6_dados (1).xlsx
2015-12-02 08:16 - 2015-12-02 08:16 - 00125483 _____ C:\Users\Toshiba\Downloads\TP6_dados.xlsx
2015-12-01 21:59 - 2015-12-01 21:59 - 00000000 ____D C:\Users\Toshiba\AppData\Local\Nico Mak Computing
2015-12-01 10:32 - 2015-12-01 10:32 - 10530323 _____ C:\Users\Toshiba\Downloads\Pontos_1_e_2.pdf
2015-12-01 10:23 - 2015-12-01 10:23 - 00208125 _____ C:\Users\Toshiba\Downloads\Ponto_7 (2).pdf
2015-12-01 10:20 - 2015-12-01 10:20 - 00453755 _____ C:\Users\Toshiba\Downloads\Ponto_5 (1).pdf
2015-12-01 10:20 - 2015-12-01 10:20 - 00322259 _____ C:\Users\Toshiba\Downloads\Ponto_6 (1).pdf
2015-12-01 05:45 - 2015-12-01 05:46 - 00050612 _____ C:\Users\Toshiba\Downloads\Addition.txt
2015-12-01 05:43 - 2015-12-04 04:48 - 00033421 _____ C:\Users\Toshiba\Downloads\FRST.txt
2015-12-01 05:43 - 2015-12-04 04:48 - 00000000 ____D C:\FRST
2015-12-01 05:43 - 2015-12-01 05:43 - 02350080 _____ (Farbar) C:\Users\Toshiba\Downloads\FRST64.exe
2015-12-01 05:37 - 2015-12-01 05:37 - 00000747 _____ C:\Users\Toshiba\Desktop\JRT.txt
2015-12-01 05:29 - 2015-12-01 05:29 - 00000000 ____D C:\Users\Toshiba\Desktop\JRT_NewerVersion
2015-12-01 05:09 - 2015-12-01 05:09 - 00010607 _____ C:\Users\Toshiba\Downloads\Entrega do TP4_listagem de alunos (2).xlsx
2015-12-01 05:08 - 2015-12-01 05:08 - 00010918 _____ C:\Users\Toshiba\Downloads\TP2_alunos selecionados (2).xlsx
2015-12-01 05:08 - 2015-12-01 05:08 - 00010802 _____ C:\Users\Toshiba\Downloads\Listagem de alunos slecionados para a entrega da Resolução do TRabalho Prático nº 3 (2).xlsx
2015-11-30 22:08 - 2015-11-30 22:52 - 00015355 _____ C:\Users\Toshiba\Downloads\TP 5_dados.xlsx
2015-11-27 23:27 - 2015-11-27 23:27 - 00008524 _____ C:\Users\Toshiba\Downloads\Notificação_20151127191836.PDF
2015-11-27 23:27 - 2015-11-27 23:27 - 00002104 _____ C:\Users\Toshiba\Downloads\NotificacaoDocumentosEmFalta_20151120140804 (1).PDF
2015-11-26 21:16 - 2015-12-04 04:44 - 00003510 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Toshiba
2015-11-26 21:16 - 2015-12-04 04:44 - 00003504 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Toshiba
2015-11-26 21:16 - 2015-11-26 21:16 - 00003628 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Toshiba
2015-11-26 21:16 - 2015-11-26 21:16 - 00003226 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Toshiba
2015-11-25 09:06 - 2015-11-25 09:06 - 00252648 _____ C:\Users\Toshiba\Downloads\Mod_III_Planeamento_Politicas_Indicadores_RH (1).pptx
2015-11-25 07:03 - 2015-11-25 07:03 - 00843349 _____ C:\Users\Toshiba\Downloads\Mod_II_Recrutamento_Selecao.pptx
2015-11-25 07:02 - 2015-11-25 07:02 - 00252648 _____ C:\Users\Toshiba\Downloads\Mod_III_Planeamento_Politicas_Indicadores_RH.pptx
2015-11-25 06:58 - 2015-11-25 06:58 - 00217479 _____ C:\Users\Toshiba\Downloads\1000204143520_DOCF815819TS073039069.pdf
2015-11-25 06:21 - 2015-11-25 06:21 - 01590358 _____ C:\Users\Toshiba\Downloads\Caso 2_CS.pdf
2015-11-25 05:49 - 2015-11-25 05:50 - 00010607 _____ C:\Users\Toshiba\Downloads\Entrega do TP4_listagem de alunos (1).xlsx
2015-11-24 19:53 - 2015-11-24 19:53 - 00107532 _____ C:\Users\Toshiba\Documents\comprovativo_204479007.pdf
2015-11-24 19:25 - 2015-11-24 19:25 - 00217479 _____ C:\Users\Toshiba\Downloads\SS.pdf
2015-11-24 19:25 - 2015-11-24 19:25 - 00176534 _____ C:\Users\Toshiba\Downloads\CC.pdf
2015-11-24 03:40 - 2015-11-24 03:40 - 03358661 _____ C:\Users\Toshiba\Downloads\J M C Ferreira et al_1996_Abordagens Contingenciais e Teorias Recentes_excerto.pdf
2015-11-23 20:16 - 2015-11-23 20:16 - 00322259 _____ C:\Users\Toshiba\Downloads\Ponto_6.pdf
2015-11-23 20:16 - 2015-11-23 20:16 - 00208125 _____ C:\Users\Toshiba\Downloads\Ponto_7 (1).pdf
2015-11-23 20:15 - 2015-11-23 20:16 - 00453755 _____ C:\Users\Toshiba\Downloads\Ponto_5.pdf
2015-11-22 21:25 - 2015-11-22 21:26 - 01599080 _____ (Malwarebytes) C:\Users\Toshiba\Downloads\JRT.exe
2015-11-22 21:19 - 2015-11-22 21:19 - 00000046 _____ C:\Users\Toshiba\Documents\service.txt
2015-11-21 18:06 - 2015-11-21 18:07 - 00010607 _____ C:\Users\Toshiba\Downloads\Entrega do TP4_listagem de alunos.xlsx
2015-11-20 20:48 - 2015-11-20 20:48 - 00053744 _____ C:\Users\Toshiba\Downloads\1000203820402_BOLETIM_C815819.pdf
2015-11-20 20:32 - 2015-11-20 20:32 - 00002104 _____ C:\Users\Toshiba\Downloads\NotificacaoDocumentosEmFalta_20151120140804.PDF
2015-11-19 04:54 - 2015-11-20 10:44 - 00000556 _____ C:\Users\Toshiba\Documents\ref bibli.txt
2015-11-16 12:39 - 2015-11-16 12:39 - 00009590 _____ C:\Users\Toshiba\Documents\LISTA DE TEMAS.txt
2015-11-16 12:31 - 2015-11-16 12:31 - 00365208 _____ C:\Users\Toshiba\Documents\LISTA DE TEMAS.pdf
2015-11-16 02:28 - 2015-11-17 05:00 - 00002680 _____ C:\Users\Toshiba\Documents\Fundadores.txt
2015-11-14 04:34 - 2015-11-14 04:35 - 03139397 _____ C:\Users\Toshiba\Downloads\10.ogg
2015-11-12 09:53 - 2015-11-03 17:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-11 13:09 - 2015-11-11 13:09 - 00010802 _____ C:\Users\Toshiba\Downloads\Listagem de alunos slecionados para a entrega da Resolução do TRabalho Prático nº 3 (1).xlsx
2015-11-11 13:07 - 2015-11-11 13:07 - 00010802 _____ C:\Users\Toshiba\Downloads\Listagem de alunos slecionados para a entrega da Resolução do TRabalho Prático nº 3.xlsx
2015-11-11 12:34 - 2015-10-20 18:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-11-11 12:34 - 2015-10-20 18:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-11-11 12:34 - 2015-10-20 18:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-11 12:34 - 2015-10-20 18:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-11-11 12:34 - 2015-10-20 18:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-11 12:34 - 2015-10-20 18:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-11-11 12:34 - 2015-10-20 17:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-11 12:34 - 2015-10-20 17:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-11 12:34 - 2015-10-20 17:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-11 12:34 - 2015-10-20 17:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-11-11 12:34 - 2015-10-20 17:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-11 12:33 - 2015-11-03 21:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-11-11 12:33 - 2015-10-30 23:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-11 12:33 - 2015-10-30 23:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-11-11 12:33 - 2015-10-30 23:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-11-11 12:33 - 2015-10-30 23:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-11-11 12:33 - 2015-10-30 22:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-11-11 12:33 - 2015-10-30 22:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-11-11 12:33 - 2015-10-30 22:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-11 12:33 - 2015-10-30 22:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-11-11 12:33 - 2015-10-30 22:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-11-11 12:33 - 2015-10-30 21:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-11 12:32 - 2015-11-03 22:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-11-11 12:32 - 2015-10-30 23:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-11 12:32 - 2015-10-30 23:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-11-11 12:32 - 2015-10-30 23:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-11 12:32 - 2015-10-30 23:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-11 12:32 - 2015-10-30 23:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-11-11 12:32 - 2015-10-30 23:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-11 12:32 - 2015-10-30 23:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-11-11 12:32 - 2015-10-30 23:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-11 12:32 - 2015-10-30 23:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-11 12:32 - 2015-10-30 23:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-11 12:32 - 2015-10-30 23:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-11 12:32 - 2015-10-30 23:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-11 12:32 - 2015-10-30 23:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-11-11 12:32 - 2015-10-30 23:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-11 12:32 - 2015-10-30 23:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-11 12:32 - 2015-10-30 22:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-11-11 12:32 - 2015-10-30 22:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 12:32 - 2015-10-30 22:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-11 12:32 - 2015-10-30 22:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-11-11 12:32 - 2015-10-30 22:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-11 12:32 - 2015-10-30 22:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-11 12:32 - 2015-10-30 22:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-11 12:32 - 2015-10-30 22:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-11-11 12:32 - 2015-10-30 22:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-11-11 12:32 - 2015-10-30 22:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-11-11 12:32 - 2015-10-30 22:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-11 12:32 - 2015-10-30 22:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-11-11 12:32 - 2015-10-30 22:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-11-11 12:32 - 2015-10-30 22:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-11-11 12:32 - 2015-10-30 22:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-11 12:32 - 2015-10-30 22:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-11-11 12:32 - 2015-10-30 22:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-11-11 12:32 - 2015-10-30 22:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-11-11 12:32 - 2015-10-30 22:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-11 12:32 - 2015-10-30 22:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-11 12:32 - 2015-10-30 22:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-11-11 12:32 - 2015-10-30 22:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-11-11 12:32 - 2015-10-30 22:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-11 12:32 - 2015-10-30 22:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-11 12:32 - 2015-10-30 22:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-11-11 12:32 - 2015-10-30 22:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-11-11 12:32 - 2015-10-30 22:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-11 12:32 - 2015-10-30 22:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-11 12:32 - 2015-10-30 22:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-11-11 12:32 - 2015-10-30 22:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-11 12:32 - 2015-10-30 22:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-11 12:32 - 2015-10-30 22:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-11-11 12:32 - 2015-10-30 22:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-11-11 12:32 - 2015-10-30 22:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-11 12:32 - 2015-10-30 21:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-11 12:32 - 2015-10-30 21:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-11 12:32 - 2015-10-30 21:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-11 12:30 - 2015-10-20 01:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-11 12:30 - 2015-10-20 01:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-11 12:30 - 2015-10-20 01:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-11 12:30 - 2015-10-20 01:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-11 12:30 - 2015-10-20 01:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-11-11 12:30 - 2015-10-20 01:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-11-11 12:30 - 2015-10-20 01:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-11-11 12:30 - 2015-10-20 01:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-11-11 12:30 - 2015-10-20 01:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-11-11 12:30 - 2015-10-20 01:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-11-11 12:30 - 2015-10-20 01:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-11-11 12:30 - 2015-10-20 01:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-11-11 12:30 - 2015-10-20 01:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-11-11 12:30 - 2015-10-20 01:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-11-11 12:30 - 2015-10-20 01:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-11-11 12:30 - 2015-10-20 00:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-11-11 12:30 - 2015-10-20 00:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-11-11 12:30 - 2015-10-20 00:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-11-11 12:30 - 2015-10-20 00:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-11-11 12:30 - 2015-10-20 00:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-11-11 12:30 - 2015-10-20 00:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-11-11 12:30 - 2015-10-20 00:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-11-11 12:30 - 2015-10-20 00:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-11-11 12:30 - 2015-10-20 00:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 12:30 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 12:30 - 2015-10-19 23:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-11 12:30 - 2015-10-19 23:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-11-11 12:30 - 2015-10-19 23:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-11 12:30 - 2015-10-19 23:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-11-11 12:30 - 2015-10-19 23:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-11-11 12:30 - 2015-10-19 23:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 12:30 - 2015-10-19 23:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 12:30 - 2015-10-19 23:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 12:30 - 2015-10-19 23:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 12:30 - 2015-09-23 13:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-11 12:30 - 2015-09-23 13:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-11 12:30 - 2015-09-23 13:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2015-11-11 12:28 - 2015-10-29 17:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-11-11 12:28 - 2015-10-29 17:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-11-11 12:28 - 2015-10-29 17:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-11-11 12:28 - 2015-10-29 17:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-11-11 12:28 - 2015-10-29 17:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-11-11 12:28 - 2015-10-29 17:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-11-11 12:28 - 2015-10-29 17:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-11-11 12:28 - 2015-10-13 16:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-11 12:28 - 2015-10-13 16:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-11 12:28 - 2015-10-13 04:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-11 12:28 - 2015-10-01 18:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-11-11 12:28 - 2015-10-01 18:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-11-11 12:28 - 2015-10-01 17:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0.00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (5).00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (4).00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (3).00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (2).00_jpg_srz
2015-11-10 19:45 - 2015-11-10 19:45 - 00617818 _____ C:\Users\Toshiba\Downloads\3449ee_ec8ff2df77064793f8f5913857e08baf.jpg_srz_1143_1601_85_22_0.50_1.20_0 (1).00_jpg_srz
2015-11-09 14:47 - 2015-11-09 14:48 - 29489272 _____ C:\Users\Toshiba\Downloads\360TSE_Setup_7.2.0.1021.exe
2015-11-06 23:42 - 2015-11-11 02:25 - 00001240 _____ C:\Users\Toshiba\Documents\Max Weber.txt
2015-11-05 15:20 - 2015-11-05 15:20 - 02247087 _____ C:\Users\Toshiba\Downloads\Karl Weick (1).pdf
2015-11-05 15:04 - 2015-11-05 15:04 - 00208125 _____ C:\Users\Toshiba\Downloads\Ponto_7.pdf
2015-11-04 22:38 - 2015-11-04 22:48 - 47082118 _____ C:\Users\Toshiba\Downloads\grims.rar
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-04 04:44 - 2009-07-14 04:45 - 00019248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-04 04:44 - 2009-07-14 04:45 - 00019248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-04 04:39 - 2014-05-28 01:00 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-04 04:35 - 2015-07-24 17:12 - 00000000 ____D C:\Program Files (x86)\360
2015-12-04 04:34 - 2014-05-28 19:51 - 00001004 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-04 04:34 - 2012-03-09 16:38 - 00000000 ____D C:\ProgramData\NVIDIA
2015-12-04 04:34 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-04 04:33 - 2014-05-28 00:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-04 04:33 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\registration
2015-12-04 04:30 - 2013-11-15 15:00 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-04 04:29 - 2014-05-28 19:51 - 00001008 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-04 04:25 - 2012-03-29 14:30 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\Skype
2015-12-04 03:16 - 2014-05-28 00:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-04 03:02 - 2012-11-22 09:51 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\uTorrent
2015-12-03 16:56 - 2013-02-04 22:51 - 00000936 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000UA.job
2015-12-03 14:24 - 2012-03-31 11:57 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\Audacity
2015-12-03 09:07 - 2010-11-08 09:01 - 00724104 _____ C:\Windows\system32\prfh0816.dat
2015-12-03 09:07 - 2010-11-08 09:01 - 00153996 _____ C:\Windows\system32\prfc0816.dat
2015-12-03 09:07 - 2009-07-14 05:13 - 01664338 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-03 09:07 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\inf
2015-12-02 23:31 - 2014-05-28 19:52 - 00002146 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-01 22:56 - 2013-02-04 22:51 - 00000914 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000Core.job
2015-12-01 05:46 - 2015-10-19 11:21 - 00000000 __SHD C:\ProgramData\360Quarant
2015-12-01 05:46 - 2015-10-19 11:21 - 00000000 __SHD C:\$360Section
2015-12-01 05:46 - 2009-07-14 03:20 - 00000000 ____D C:\Windows
2015-12-01 05:21 - 2014-05-28 02:06 - 00000000 ____D C:\AdwCleaner
2015-11-28 22:13 - 2012-08-30 11:25 - 00000000 ____D C:\Users\Toshiba\Desktop\V.v
2015-11-22 21:40 - 2015-10-28 16:08 - 00000000 ____D C:\Users\Toshiba\Desktop\hh
2015-11-20 00:59 - 2011-03-03 12:41 - 00000000 ____D C:\ProgramData\Skype
2015-11-12 14:22 - 2014-01-21 14:05 - 00411920 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-11 16:36 - 2013-07-31 02:01 - 00000000 ____D C:\Windows\system32\MRT
2015-11-11 16:22 - 2013-05-02 23:53 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-11 16:18 - 2012-11-27 21:13 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-11 15:52 - 2012-05-04 17:57 - 01630198 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-11-11 15:47 - 2009-07-14 07:45 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-09 16:37 - 2012-09-07 15:05 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\Nero
2015-11-09 15:39 - 2013-11-04 14:56 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player
2015-11-09 15:39 - 2013-05-02 21:13 - 00000000 ___RD C:\Users\Toshiba\Desktop\Utilitários
2015-11-09 14:51 - 2009-07-14 03:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-11-09 14:51 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2015-11-04 22:49 - 2015-10-28 16:06 - 00000000 ____D C:\Users\Toshiba\AppData\Local\WinZip
 
==================== Files in the root of some directories =======
 
2012-08-30 18:55 - 2012-08-30 18:55 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\0AZ2B6673Windows.bat
2012-08-30 18:50 - 2012-08-30 18:50 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\33KM2IMTW2Windows.bat
2012-08-08 10:27 - 2012-08-08 10:27 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\9ZTCUM5SCSVACLhehe.exe
2013-12-22 06:31 - 2013-12-22 06:31 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\bitlord_log.txt
2012-08-07 16:41 - 2013-05-02 18:00 - 15875330 _____ () C:\Users\Toshiba\AppData\Roaming\Eldoqt's Keylog
2012-09-15 13:41 - 2012-09-15 13:41 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\L1QHUAXhehe.exe
2014-02-06 17:12 - 2014-02-06 17:12 - 0000050 _____ () C:\Users\Toshiba\AppData\Roaming\mbam.context.scan
2012-08-07 16:41 - 2010-11-04 17:57 - 0032072 _____ (Microsoft Corporation) C:\Users\Toshiba\AppData\Roaming\YUPVRTMT77.exe
2012-08-30 18:44 - 2012-08-30 18:44 - 0000638 _____ () C:\Users\Toshiba\AppData\Roaming\ZFKOXZ6DODAWindows.bat
2012-09-30 20:26 - 2012-10-03 18:54 - 0004608 _____ () C:\Users\Toshiba\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-07-21 18:56 - 2013-07-21 18:56 - 0000017 _____ () C:\Users\Toshiba\AppData\Local\resmon.resmoncfg
2012-03-16 14:55 - 2012-03-16 14:55 - 0286678 ____R () C:\ProgramData\DeviceManager.xml.rc4
2012-03-29 14:31 - 2012-03-29 14:31 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
 
Some files in TEMP:
====================
C:\Users\Toshiba\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Toshiba\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Toshiba\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Toshiba\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\Toshiba\AppData\Local\Temp\Quarantine.exe
C:\Users\Toshiba\AppData\Local\Temp\rnsetup0.exe
C:\Users\Toshiba\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Toshiba\AppData\Local\Temp\stubhelper.dll
C:\Users\Toshiba\AppData\Local\Temp\swt-win32-3740.dll
C:\Users\Toshiba\AppData\Local\Temp\{3CC7CDA1-51B3-4D59-87CF-EF76109A212C}-42.0.2311.90_41.0.2272.118_chrome_updater.exe
C:\Users\Toshiba\AppData\Local\Temp\{5B312002-9617-46A7-8B31-53337E079C2C}-41.0.2272.89_40.0.2214.115_chrome_updater.exe
C:\Users\Toshiba\AppData\Local\Temp\{694DE23C-2511-4F9C-841F-19C0054DC42A}-40.0.2214.115_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{8BDA707E-0BEA-46F0-8339-C016E4EA3C5F}-39.0.2171.95_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{903CA3B2-3591-4D28-A8A2-E774059B7BD3}-40.0.2214.115_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{E4D00499-5580-4A1B-85D1-50CB0D137A40}-42.0.2311.90_41.0.2272.118_chrome_updater.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-11-29 20:24
 
==================== End of FRST.txt ============================
 
New Addiction.txt:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:30-11-2015
Ran by [removed] (2015-12-04 04:49:42)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2012-03-12 10:27:01)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrador (S-1-5-21-2217298813-2927578935-920386982-500 - Administrator - Disabled)
Convidado (S-1-5-21-2217298813-2927578935-920386982-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2217298813-2927578935-920386982-1003 - Limited - Enabled)
Toshiba (S-1-5-21-2217298813-2927578935-920386982-1000 - Administrator - Enabled) => C:\Users\Toshiba
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\uTorrent) (Version: 3.3.2.30303 - BitTorrent Inc.)
3DS saveEditor2 (HKLM-x32\…\{7349108B-BC63-4ED7-9989-ECCA0DD0F14F}) (Version: 1.0.0.0 - CYBER Gadget)
Adobe Flash Player 14 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader X (10.1.9) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.9 - Adobe Systems Incorporated)
ASIO4ALL (HKLM-x32\…\ASIO4ALL) (Version: 2.11 Beta1 - Michael Tippach)
Atheros Bluetooth Filter Driver Package (HKLM\…\{65486209-5C54-439C-8383-8AC9BBE25932}) (Version: 1.00.0004 - Atheros Communications)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.36 - Atheros Communications Inc.)
Atheros Driver Installation Program (HKLM-x32\…\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros)
aTube Catcher versão 3.8 (HKLM-x32\…\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Audacity 2.0 (HKLM-x32\…\Audacity_is1) (Version:  - Audacity Team)
AudioConverter Studio 6.2 (HKLM-x32\…\AudioConverter Studio_is1) (Version:  - ManiacTools.com)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bejeweled 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
Bluetooth Stack for Windows by Toshiba (HKLM\…\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v8.00.04(T) - TOSHIBA CORPORATION)
CCleaner (HKLM\…\CCleaner) (Version: 4.01 - Piriform)
Chicken Invaders 3 - Revenge of the Yolk (x32 Version: 2.2.0.95 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Complément Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Complemento Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.51.1.0 - Conexant)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\…\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\…\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
Dropbox (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Dropbox) (Version: 2.0.22 - Dropbox, Inc.)
Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
FL Studio 10 (HKLM-x32\…\FL Studio 10) (Version:  - Image-Line)
FL Studio 11 (HKLM-x32\…\FL Studio 11) (Version:  - Image-Line)
FlowStone FL 3.0 (HKLM-x32\…\FlowStone) (Version:  - )
FLV and Media Player (3.2.0.3) (HKLM-x32\…\FLV and Media Player) (Version: 3.2.0.3 - Applian Technologies)
Free M4a to MP3 Converter 7.1 (HKLM-x32\…\Free M4a to MP3 Converter_is1) (Version:  - ManiacTools.com)
Free Video Converter V 3.1 (HKLM-x32\…\Free Video Converter_is1) (Version: 3.1.0.0 - Koyote Soft)
Free WAV to MP3 Converter (HKLM-x32\…\Free WAV to MP3 Converter) (Version: 1.0 - Polaris-Software.com)
Freemake Video Converter versão 3.2.1 (HKLM-x32\…\Freemake Video Converter_is1) (Version: 3.2.1 - Ellora Assets Corporation)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 47.0.2526.73 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
High-Definition Video Playback (x32 Version: 7.1.13900.47.0 - Nero AG) Hidden
IL Download Manager (HKLM-x32\…\IL Download Manager) (Version:  - Image-Line)
IL Shared Libraries (HKLM-x32\…\IL Shared Libraries) (Version:  - Image-Line)
Insaniquarium Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)
Java 8 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
JavaFX 2.1.0 (HKLM-x32\…\{1111706F-666A-4037-7777-210328764D10}) (Version: 2.1.0 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
League of Legends (HKLM-x32\…\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games)
Mahjongg Artifacts (x32 Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware versão 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Português) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 2070) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\…\{2C303EE0-A595-3543-A71A-931C7AC40EDE}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mixxx 1.11.0 (64-bit) (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Mixxx (1.11.0)) (Version: 1.11.0 - The Mixxx Development Team)
MK LOL (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MK LOL) (Version:  - )
MKLOL (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MKLOL) (Version:  - )
Mozilla Firefox 38.0.1 (x86 pt-PT) (HKLM-x32\…\Mozilla Firefox 38.0.1 (x86 pt-PT)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MP3 Rocket (HKLM-x32\…\MP3 Rocket) (Version:  - )
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero BackItUp 10 (HKLM-x32\…\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.6.11500.16.100 - Nero AG)
Nero BurnRights 10 (HKLM-x32\…\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10500.1.102 - Nero AG)
Nero Express 10 (HKLM-x32\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12000.21.100 - Nero AG)
Nero InfoTool 10 (HKLM-x32\…\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.2.10400.5.100 - Nero AG)
Nero MediaHub 10 (HKLM-x32\…\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.2.13300.36.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{0FF68F26-416C-4954-ACA5-6AD5F9DE99C1}) (Version: 10.5.14800 - Nero AG)
Nero RescueAgent 10 (HKLM-x32\…\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.2.10800.9.100 - Nero AG)
Nero StartSmart 10 (HKLM-x32\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.10300.25.0 - Nero AG)
NVIDIA Controlador gráfico 266.69 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 266.69 - NVIDIA Corporation)
NVIDIA O controlador de 3D Vision 266.69 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 266.69 - NVIDIA Corporation)
NVIDIA O software do sistema PhysX 9.10.0514 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation)
Octoshape Streaming Services (HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\Octoshape Streaming Services) (Version:  - Octoshape ApS)
Painel de controlo da NVIDIA 266.69 (Version: 266.69 - NVIDIA Corporation) Hidden
Pando Media Booster (HKLM-x32\…\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.9 - Pando Networks Inc.)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Photo Service - powered by myphotobook (HKLM-x32\…\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1) (Version: 1.2.0-545 - myphotobook GmbH)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants Vs. Zombies (HKLM-x32\…\{B5790265-B654-4377-9EF0-085A6AB6FA8E}) (Version: 1.2.0.1065 - PopCap)
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Popcorn4TV version 1.0 (HKLM-x32\…\{FA0CD53E-825A-48F4-9AAC-D3E6B718EAC8}_is1) (Version: 1.0 - Popcorn4TV)
RealDownloader (x32 Version: 1.3.0 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\…\RealPlayer 16.0) (Version: 16.0.0 - RealNetworks)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7512 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Reader Driver (HKLM-x32\…\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 1.0.0.12 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Replay Media Catcher 5 (5.0.1.19) (HKLM-x32\…\Replay Media Catcher 5) (Version: 5.0.1.19 - Applian Technologies)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\…\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version:  - Microsoft) Hidden
Skype™ 7.14 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.14.106 - Skype Technologies S.A.)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
software tmn (HKLM-x32\…\software tmn) (Version: 11.300.05.07.84 - Huawei Technologies Co.,Ltd)
SPORE™ (HKLM-x32\…\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.00.0000 - Electronic Arts)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.2.11.1 - Synaptics Incorporated)
TOSHIBA Assist (HKLM-x32\…\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.02.02 - TOSHIBA CORPORATION)
TOSHIBA Bulletin Board (HKLM-x32\…\InstallShield_{229C190B-7690-40B7-8680-42530179F3E9}) (Version: 2.0.16.64 - TOSHIBA Corporation)
TOSHIBA ConfigFree (HKLM-x32\…\{F52618B2-A995-4F8D-A6C8-9E235A470C68}) (Version: 8.0.36 - TOSHIBA CORPORATION)
TOSHIBA Disc Creator (HKLM\…\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.6 for x64 - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM-x32\…\InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}) (Version: 1.2.23.64 - TOSHIBA Corporation)
TOSHIBA Face Recognition (HKLM-x32\…\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.8.64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\…\InstallShield_{C4FFA951-9678-4D51-84B4-AFD15D3C45AD}) (Version: 4.08.06.00 - )
TOSHIBA HDD/SSD Alert (HKLM-x32\…\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.7 - TOSHIBA Corporation)
Toshiba Manuals (HKLM-x32\…\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.02 - TOSHIBA)
TOSHIBA Online Product Information (HKLM-x32\…\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 4.00.0008 - TOSHIBA)
TOSHIBA PC Health Monitor (HKLM\…\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.7.4.64 - TOSHIBA Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\…\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.3.10010 - TOSHIBA CORPORATION)
TOSHIBA Recovery Media Creator Reminder (HKLM-x32\…\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA)
TOSHIBA ReelTime (HKLM-x32\…\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}) (Version: 1.7.17.64 - TOSHIBA Corporation)
TOSHIBA Service Station (HKLM-x32\…\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.1.52 - TOSHIBA)
TOSHIBA Sleep Utility (HKLM-x32\…\{654F7484-88C5-46DC-AB32-C66BCB0E2102}) (Version: 1.4.2.7 - TOSHIBA Corporation)
TOSHIBA Supervisor Password (HKLM-x32\…\InstallShield_{CBD6B23D-41D5-4A46-8019-6208516C9712}) (Version: 4.08.06.00 - )
TOSHIBA TEMPRO (HKLM-x32\…\{F082CB11-4794-4259-99A1-D91BA762AD15}) (Version: 3.35 - Toshiba Europe GmbH)
TOSHIBA Value Added Package (HKLM-x32\…\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.5.1.64 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM-x32\…\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: 1.1.6.3 - TOSHIBA Corporation)
TRORMCLauncher (HKLM-x32\…\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version:  - )
TRORMCLauncher (Version: 1.0.0.10 - TOSHIBA) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM-x32\…\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version: 15.4.5722.2 - Microsoft Corporation)
VirtualDJ 8 (HKLM-x32\…\{24F8CB37-888B-41E6-B119-CDC3F5075F57}) (Version: 8.0.2483.0 - Atomix Productions)
Vodafone Mobile Broadband (HKLM-x32\…\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.3.203.38322 - Vodafone)
VPNium  (HKLM-x32\…\VPNium) (Version:  - )
Wedding Dash 2 - Rings Around the World (x32 Version: 2.2.0.95 - WildTangent) Hidden
WildTangent Games (HKLM-x32\…\WildTangent toshiba Master Uninstall) (Version: 1.0.2.5 - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.10.15 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.21 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinZip 20.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EF}) (Version: 20.0.11659 - WinZip Computing, S.L. )
WTFast 3.5 (HKLM-x32\…\{12B4121D-5221-4AFC-9EDC-63B0CA139856}_is1) (Version: 3.5.9.511 - Initex & AAA Internet Publishing)
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\…\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation)
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.dll ()
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2217298813-2927578935-920386982-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
01-12-2015 05:29:32 JRT Pre-Junkware Removal
01-12-2015 22:11:04 Windows Update
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 02:34 - 2014-05-28 13:52 - 00001120 ____A C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0986D771-5561-4047-95C7-9D49EF73BEA1} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2217298813-2927578935-920386982-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {0BE694B7-1711-41E4-B5C7-D3E6DD8B256F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {1294239E-66AE-4D62-83A3-1EFD249B8DE9} - System32\Tasks\RNUpgradeHelperLogonPrompt_Toshiba => C:\Users\Toshiba\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-26] (RealNetworks, Inc.)
Task: {21AD92AC-60AF-4828-B182-47DDB5C40051} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000UA => C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-04] (Facebook Inc.)
Task: {239D8043-CAC0-4668-AA96-6D4F2A87C0A2} - System32\Tasks\{D9EF8992-5C27-4196-979E-420DFB6BB443} => pcalua.exe -a C:\Users\Toshiba\Downloads\Spore-RELOADED\Support\SPORE(TM)_code.exe -d C:\Users\Toshiba\Downloads\Spore-RELOADED\Support
Task: {353A78B3-B166-41F6-A0E0-1909BD7E1096} - System32\Tasks\{750601F8-6B96-4AA8-B860-9FFEEE60C34B} => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2012-03-20] (Vodafone)
Task: {3BD7D9CA-9C9C-4B83-A12D-F47D7173CD50} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4A442F34-2C83-4E56-8AAA-9F89FC28C45B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-04-23] (Piriform Ltd)
Task: {541FCD98-4E89-4CB2-939C-C9029F48E717} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2217298813-2927578935-920386982-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {567A2C4E-ABD5-4225-9477-BB0890B6C1EE} - System32\Tasks\{E67D9C62-3F46-4CC2-B533-DC0AEF61A542} => pcalua.exe -a F:\setup_vmb_lite.exe -d F:\ -c /checkApplicationPresence
Task: {637F330E-44E1-45EB-B011-064A02FAF6BC} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2217298813-2927578935-920386982-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {79FD3D47-2CD3-4653-B6C0-0B28D334CA37} - System32\Tasks\{3922DAC0-2546-4927-BF57-69BFB73538A0} => pcalua.exe -a C:\Users\Toshiba\Desktop\DISK1\setup.exe -d C:\Users\Toshiba\Desktop\DISK1
Task: {7ACD3B90-4819-49AB-B7F9-9F4F08D8D535} - System32\Tasks\{5012F6F2-9110-4EB0-8633-07CB2A965BC1} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe"
Task: {9346C268-CD96-4219-8C67-49FBCEAB905C} - \Advanced System Protector -> No File <==== ATTENTION
Task: {9B3310F2-D7F4-46F4-A512-0DCD5104F759} - \SomotoUpdateCheckerAutoStart -> No File <==== ATTENTION
Task: {A516172D-55DE-4439-A484-EEABF838FAA1} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000Core => C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-04] (Facebook Inc.)
Task: {B274EF48-A02C-47B2-8F9C-281F51C462C5} - System32\Tasks\{78C2B097-249D-4597-99F7-535A2B57AE85} => pcalua.exe -a E:\Setup.EXE -d E:\
Task: {B662769C-3123-45A4-9674-B6224C19F9D2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10] (Adobe Systems Incorporated)
Task: {B71BF007-3FAF-4916-B13A-ACB10CBA2B0A} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2010-12-03] (TOSHIBA CORPORATION)
Task: {D4A5356B-4E4C-494D-8696-AF4AA0B80757} - System32\Tasks\RNUpgradeHelperResumePrompt_Toshiba => C:\Users\Toshiba\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-26] (RealNetworks, Inc.)
Task: {E033F324-D3C5-41CE-9D18-AE8BAC70520A} - System32\Tasks\ReclaimerUpdateXML_Toshiba => C:\Users\Toshiba\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-26] (RealNetworks, Inc.)
Task: {E6FAC7B6-2217-4DDE-AFBE-7173CCF1C606} - \AutoKMS -> No File <==== ATTENTION
Task: {EF0CDE51-6339-4CEC-86F2-206F9D96CA37} - System32\Tasks\ReclaimerUpdateFiles_Toshiba => C:\Users\Toshiba\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-26] (RealNetworks, Inc.)
Task: {F65B81F8-EAB0-4F9A-AE10-309C5A978567} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2217298813-2927578935-920386982-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000Core.job => C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2217298813-2927578935-920386982-1000UA.job => C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2012-11-29 20:31 - 2012-11-29 20:31 - 00038608 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2010-12-08 14:55 - 2010-12-08 14:55 - 00592312 _____ () C:\Program Files\TOSHIBA\TECO\TecoPower.dll
2010-12-13 16:32 - 2010-12-13 16:32 - 03420584 _____ () C:\Program Files\Toshiba\BulletinBoard\TosNcUi.dll
2010-11-18 16:18 - 2010-11-18 16:18 - 11190784 _____ () C:\Program Files\Toshiba\FlashCards\BlackPng.dll
2010-12-08 14:55 - 2010-12-08 14:55 - 00592312 _____ () C:\Program Files\Toshiba\TECO\TecoPower.dll
2010-12-15 14:19 - 2010-12-15 14:19 - 00124320 _____ () C:\Program Files\Toshiba\TECO\MUIHelp.dll
2011-03-03 12:41 - 2011-02-22 09:01 - 00559104 _____ () C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\pt\Humphrey.resources.dll
2010-12-08 14:42 - 2010-12-08 14:42 - 00079264 _____ () C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
2012-03-20 13:08 - 2012-03-20 13:08 - 00396800 _____ () C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\Vodafone.View.Taskbar.dll
2009-07-13 21:03 - 2009-07-14 01:15 - 00364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll
2015-11-10 14:23 - 2014-02-10 12:44 - 04592128 _____ () C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2015-11-10 14:23 - 2014-02-10 12:44 - 00112128 _____ () C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^Users^Toshiba^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Facebook Update => "C:\Users\Toshiba\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: Google Update => "C:\Users\Toshiba\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: NBAgent => "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: uTorrent => "C:\Program Files (x86)\uTorrent\uTorrent.exe"  /MINIMIZED
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{E4B835F9-97A8-420C-B4CB-4E3E3DD0CE12}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{6630CD62-1F5C-4179-A965-F41AFB73726F}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{78A2A81D-4FDA-402A-97AD-C3F6B06DD7E5}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{CB3033A9-1BA0-4795-B19B-BE5C501E90BD}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{0CC488C1-893A-4428-89FC-212558E8BC5B}] => (Allow) LPort=2869
FirewallRules: [{D5987659-7889-461B-8084-C95A811D09DF}] => (Allow) LPort=1900
FirewallRules: [{A84FABB1-F4F4-4E56-8B6E-A4A9EAE50EB2}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{90EB44D0-8807-4AB8-813B-B22D5B3BDFBC}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{7AC109EB-F74C-4BA5-80A3-B836A830217B}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.exe
FirewallRules: [{F079C75A-DA93-4832-A544-44B679C320C0}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.exe
FirewallRules: [{FA374334-FA74-43F6-BC2E-C8C61AD2996E}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.patch.exe
FirewallRules: [{56E0D77B-5E5F-411C-A2A5-E7332FE3DB3D}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.patch.exe
FirewallRules: [TCP Query User{38F6D9A2-CE4C-46B2-A499-08113283FB65}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{37CCD958-FF84-4CC6-8232-E2E9ED329674}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{926B7186-91BB-4B4D-8A16-A2EBD2653B54}] => (Allow) C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{D578C435-4A13-4C2A-859B-E5B123913E17}] => (Allow) C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{95AB5361-25DB-4309-A133-A04AAF97A500}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{D95D58B6-1C05-42A0-9D16-60BE980B2CC2}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{8D54D461-90A6-4A97-919B-8AE3C7227D4F}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{4B06F689-2984-4D26-95B2-228BFA616B30}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{21FF7A6C-AD3A-4B78-BFBE-A47CA00B528D}C:\program files (x86)\world of warcraft\launcher.patch.exe] => (Block) C:\program files (x86)\world of warcraft\launcher.patch.exe
FirewallRules: [UDP Query User{3D8BBE54-D17D-430C-95F3-AEA9DC23C03A}C:\program files (x86)\world of warcraft\launcher.patch.exe] => (Block) C:\program files (x86)\world of warcraft\launcher.patch.exe
FirewallRules: [TCP Query User{0A980D26-E7A6-4AB3-95A0-42F0C2889334}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{2D19EB68-9D96-44F3-B62E-8378FBADD90D}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [TCP Query User{879BD1AD-3140-4E73-8C80-C30CB81857A7}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe
FirewallRules: [UDP Query User{90092A81-FFCE-497E-AB80-E2712CCD9ACB}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe
FirewallRules: [{CE57C971-27FC-4739-883E-E2268AFC0330}] => (Allow) C:\Program Files (x86)\Movies Toolbar\SafetyNut\SRTOOL~1\IE\dtUser.exe
FirewallRules: [{8B30292C-FD2E-441C-A010-40DCF364C21E}] => (Allow) C:\Program Files (x86)\Movies Toolbar\SafetyNut\SRTOOL~1\IE\dtUser.exe
FirewallRules: [{A2E8D0D6-227F-4C9C-9CCC-1F21A3D869C3}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Media Catcher 5\aria2c.exe
FirewallRules: [{6D585C6F-0ADD-4EA0-94CB-1D57DE58447B}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Media Catcher 5\aria2c.exe
FirewallRules: [{B425E63C-621A-49F5-8F52-DB15F69149FF}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Media Catcher 5\qtCopy.exe
FirewallRules: [{15EE142D-6456-418A-B56A-593C7C1FB15D}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Media Catcher 5\qtCopy.exe
FirewallRules: [TCP Query User{0C6A7119-446C-456A-B838-DC77324E67A9}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{64B4CD22-AD18-42AA-99D0-687FE0155501}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{2F249B5F-838D-4E2C-851A-87B11B5E65F0}] => (Allow) C:\Users\Toshiba\AppData\Local\iLivid\iLivid.exe
FirewallRules: [{01D02FD0-5539-4CFE-A53B-731C88D880C2}] => (Allow) C:\Users\Toshiba\AppData\Local\iLivid\iLivid.exe
FirewallRules: [{0953B0C3-891E-4B6C-A354-1043B9A09CCF}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{D8FE5899-54B4-4D87-9197-DB63F890B9B8}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{A79857CB-DC6C-48E9-8C9F-7D0826AF659E}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{D6F4E693-D20B-417C-AA5F-CE518A4A2D20}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{FD18CDD4-450A-4751-8AB5-BD33BB980A30}] => (Allow) C:\Users\Toshiba\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [TCP Query User{2E121153-D06C-474F-88B5-B59A62B69FF4}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{666FA564-FDF9-4930-8B5E-C0E216E05476}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{240E81E7-EBD5-42B4-B7CC-A67E5E61764F}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{F8861256-9BF0-4F16-9F4E-8A2F564718E4}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [{971C47A2-4FE9-4E04-B122-E04C21DF2F21}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FD6FCF90-9595-4AF5-BE56-D351797838C4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C4DA9577-36D9-4637-AC8F-1259D6054646}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{CAC4893D-5E3F-4DFE-A921-D32292604BDD}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{362FB02C-BD8C-4C10-95EB-8C2A1CDE6F61}C:\program files\360\360 internet security\360sdupd.exe] => (Block) C:\program files\360\360 internet security\360sdupd.exe
FirewallRules: [UDP Query User{D6932836-012D-4413-A3D4-3F814234C16C}C:\program files\360\360 internet security\360sdupd.exe] => (Block) C:\program files\360\360 internet security\360sdupd.exe
FirewallRules: [{73A5BCB0-0F35-48F5-83B6-D728B899E017}] => (Allow) C:\Program Files\360\360 Internet Security\UpTip.exe
FirewallRules: [{D94AC79C-2BAE-4084-8452-B286D758DAEC}] => (Allow) C:\Program Files\360\360 Internet Security\UpTip.exe
FirewallRules: [{AEDC6E83-5974-4B33-8EF7-41A352A5D7FA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{82B04690-14F7-41A9-BDD3-B6B04B0D6640}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{2D18A4BA-DBDE-4B8B-BF06-C8B10AD9A84F}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/04/2015 02:21:47 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: Skype.exe, versão: 7.14.73.106, carimbo de data/hora: 0x564b2877
Nome do módulo com falha: KERNELBASE.dll, versão: 6.1.7601.19045, carimbo de data/hora: 0x56258f05
Código de excepção: 0xe0fafb28
Desvio de falha: 0x0000c42d
ID do processo com falha: 0x19a4
Data/hora de início da aplicação com falha: 0xSkype.exe0
Caminho da aplicação com falha: Skype.exe1
Caminho do módulo com falha: Skype.exe2
ID do Relatório: Skype.exe3
 
Error: (12/04/2015 02:14:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Nome do módulo com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Código de excepção: 0x40000015
Desvio de falha: 0x0007da8a
ID do processo com falha: 0xf5c
Data/hora de início da aplicação com falha: 0xmbamservice.exe0
Caminho da aplicação com falha: mbamservice.exe1
Caminho do módulo com falha: mbamservice.exe2
ID do Relatório: mbamservice.exe3
 
Error: (12/04/2015 02:14:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamscheduler.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5339cec3
Nome do módulo com falha: MSVCR100.dll, versão: 10.0.40219.325, carimbo de data/hora: 0x4df2be1e
Código de excepção: 0x40000015
Desvio de falha: 0x0008d6fd
ID do processo com falha: 0x8e0
Data/hora de início da aplicação com falha: 0xmbamscheduler.exe0
Caminho da aplicação com falha: mbamscheduler.exe1
Caminho do módulo com falha: mbamscheduler.exe2
ID do Relatório: mbamscheduler.exe3
 
Error: (12/03/2015 00:32:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Nome do módulo com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Código de excepção: 0x40000015
Desvio de falha: 0x0007da8a
ID do processo com falha: 0xe44
Data/hora de início da aplicação com falha: 0xmbamservice.exe0
Caminho da aplicação com falha: mbamservice.exe1
Caminho do módulo com falha: mbamservice.exe2
ID do Relatório: mbamservice.exe3
 
Error: (12/03/2015 00:31:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamscheduler.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5339cec3
Nome do módulo com falha: MSVCR100.dll, versão: 10.0.40219.325, carimbo de data/hora: 0x4df2be1e
Código de excepção: 0x40000015
Desvio de falha: 0x0008d6fd
ID do processo com falha: 0x83c
Data/hora de início da aplicação com falha: 0xmbamscheduler.exe0
Caminho da aplicação com falha: mbamscheduler.exe1
Caminho do módulo com falha: mbamscheduler.exe2
ID do Relatório: mbamscheduler.exe3
 
Error: (12/02/2015 11:09:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Nome do módulo com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Código de excepção: 0x40000015
Desvio de falha: 0x0007da8a
ID do processo com falha: 0xed4
Data/hora de início da aplicação com falha: 0xmbamservice.exe0
Caminho da aplicação com falha: mbamservice.exe1
Caminho do módulo com falha: mbamservice.exe2
ID do Relatório: mbamservice.exe3
 
Error: (12/02/2015 11:09:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamscheduler.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5339cec3
Nome do módulo com falha: MSVCR100.dll, versão: 10.0.40219.325, carimbo de data/hora: 0x4df2be1e
Código de excepção: 0x40000015
Desvio de falha: 0x0008d6fd
ID do processo com falha: 0x8a8
Data/hora de início da aplicação com falha: 0xmbamscheduler.exe0
Caminho da aplicação com falha: mbamscheduler.exe1
Caminho do módulo com falha: mbamscheduler.exe2
ID do Relatório: mbamscheduler.exe3
 
Error: (12/02/2015 05:48:45 PM) (Source: Google Update) (EventID: 20) (User: Toshiba-TOSH)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http s
 
Error: (12/02/2015 10:56:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Nome do módulo com falha: mbamservice.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5318d363
Código de excepção: 0x40000015
Desvio de falha: 0x0007da8a
ID do processo com falha: 0xdd0
Data/hora de início da aplicação com falha: 0xmbamservice.exe0
Caminho da aplicação com falha: mbamservice.exe1
Caminho do módulo com falha: mbamservice.exe2
ID do Relatório: mbamservice.exe3
 
Error: (12/02/2015 10:56:04 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome da aplicação com falha: mbamscheduler.exe, versão: 3.0.2.0, carimbo de data/hora: 0x5339cec3
Nome do módulo com falha: MSVCR100.dll, versão: 10.0.40219.325, carimbo de data/hora: 0x4df2be1e
Código de excepção: 0x40000015
Desvio de falha: 0x0008d6fd
ID do processo com falha: 0x860
Data/hora de início da aplicação com falha: 0xmbamscheduler.exe0
Caminho da aplicação com falha: mbamscheduler.exe1
Caminho do módulo com falha: mbamscheduler.exe2
ID do Relatório: mbamscheduler.exe3
 
 
System errors:
=============
Error: (12/04/2015 02:19:50 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: O serviço Windows Update desligou-se ao iniciar.
 
Error: (12/04/2015 02:14:56 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: O serviço MBAMService terminou inesperadamente. Isto aconteceu 1 vez(es).
 
Error: (12/04/2015 02:14:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: O serviço MBAMScheduler falhou o arranque devido ao seguinte erro: 
%%1053
 
Error: (12/04/2015 02:14:38 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Foi atingido o tempo limite (30000 milissegundos) ao aguardar pela ligação do serviço MBAMScheduler.
 
Error: (12/03/2015 06:00:19 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
 
Error: (12/03/2015 01:44:19 PM) (Source: Modem) (EventID: 1) (User: )
Description: \00000099
 
Error: (12/03/2015 00:38:49 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: O serviço Intel(R) Management and Security Application User Notification Service desligou-se ao iniciar.
 
Error: (12/03/2015 00:36:49 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: O serviço Windows Update desligou-se ao iniciar.
 
Error: (12/03/2015 00:32:02 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: O serviço MBAMService terminou inesperadamente. Isto aconteceu 1 vez(es).
 
Error: (12/03/2015 00:31:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: O serviço MBAMScheduler falhou o arranque devido ao seguinte erro: 
%%1053
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz
Percentage of memory in use: 53%
Total physical RAM: 4077.86 MB
Available physical RAM: 1915.83 MB
Total Virtual: 8153.93 MB
Available Virtual: 5545.55 MB
 
==================== Drives ================================
 
Drive c: (WINDOWS) (Fixed) (Total:149.41 GB) (Free:14.71 GB) NTFS
Drive d: (Data) (Fixed) (Total:148.28 GB) (Free:106.28 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: FCC1188A)
Partition 1: (Active) - (Size=400 MB) - (Type=27)
Partition 2: (Not Active) - (Size=149.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=148.3 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

Unnistaled: uTorrent, 360 Total Security and pgcchelper

According to you last log, uTorrent is still installed.


There is evidence that there was illegal software on your system, (AutoKMS), and, if this had not been deleted, helping you would be in direct breach of forum rules. However, as it appears that it has been deleted we’ll carry on.


You need to move Farbar Recovery Scan Tool to your desktop otherwise fixes will not work.

  • go to your Downloads folder and locate Farbar Recovery Scan Tool
  • right click and select Cut
  • go to an empty spot on your desktop, right click and select Paste

Farbar Recovery Scan Tool should now be on your desktop.

================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: F - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: G - G:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {2091109a-ec9b-11e2-81bf-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {209110a1-ec9b-11e2-81bf-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {3354c7d3-b65f-11e1-85c4-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {3354c7da-b65f-11e1-85c4-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {555db868-c42c-11e1-986e-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {555db87a-c42c-11e1-986e-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {6d39009a-89cd-11e3-81a6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {7dff1801-042d-11e3-99f7-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {7ee67c48-ab5d-11e1-9c37-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {814e09fc-06a0-11e3-bfb8-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {839edb36-bef0-11e1-a7f6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d65fc-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d660c-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d660f-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d661e-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6634-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6647-be0d-11e1-a6d5-001e101f6c04} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6654-be0d-11e1-a6d5-001e101f6c04} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {98b68ef4-8cf3-11e4-a1d6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b1170f08-b665-11e1-aaae-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b128d9d0-79a3-11e1-ad2b-e89a8f044043} - G:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b128d9d7-79a3-11e1-ad2b-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b4e4fd6e-06b5-11e3-bc4e-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd4f-4c49-11e2-845e-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd60-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd95-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbda6-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {c905ad93-7dc4-11e1-9435-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {c905ada5-7dc4-11e1-9435-e89a8f044043} - G:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {d1598edb-052f-11e3-9b91-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {e5eb2800-7dd1-11e1-ba79-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaa6-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaa9-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaab-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {fed48f45-b0e5-11e1-bdfc-e89a8f044043} - F:\StartVMCLite.exe
AppInit_DLLs-x32: c:\windows\jaksta\ac\x86\jaudcap.dll => No File
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {F11F3195-DB15-4386-AC80-13C6FE576B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {6F601FA8-C974-4DA2-BE97-D0382BB0B5AD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
BHO: AllCHeApPrice -> {A26C1ADD-E1BD-E1E3-22F8-2342C59EF108} -> C:\ProgramData\AllCHeApPrice\ALdqClzjI.x64.dll => No File
BHO: GreAatsaveR -> {F8F6BED2-3F26-FA29-32C4-4F4312546BF4} -> C:\Program Files (x86)\GreAatsaveR\WAcF.x64.dll => No File
BHO-x32: No Name -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Extension: No Name - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [not found]
FF Extension: SNT - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\yb2m6y23.default\Extensions\[removed] [2014-01-21] [not signed]
CHR Extension: (Proteção de Internet do 360) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\glcimepnljoholdmjchkloafkggfoijh [2015-11-09]
S3 Tosrfcom; no ImagePath
S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [X]
2015-12-01 21:59 - 2015-12-01 21:59 - 00000000 ____D C:\Users\Toshiba\AppData\Local\Nico Mak Computing
2015-11-09 14:47 - 2015-11-09 14:48 - 29489272 _____ C:\Users\Toshiba\Downloads\360TSE_Setup_7.2.0.1021.exe
2015-12-04 04:35 - 2015-07-24 17:12 - 00000000 ____D C:\Program Files (x86)\360
2015-12-04 03:02 - 2012-11-22 09:51 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\uTorrent
2015-12-01 05:46 - 2015-10-19 11:21 - 00000000 __SHD C:\ProgramData\360Quarant
2015-12-01 05:46 - 2015-10-19 11:21 - 00000000 __SHD C:\$360Section
Task: {9346C268-CD96-4219-8C67-49FBCEAB905C} - \Advanced System Protector -> No File <==== ATTENTION
Task: {9B3310F2-D7F4-46F4-A512-0DCD5104F759} - \SomotoUpdateCheckerAutoStart -> No File <==== ATTENTION
Task: {E6FAC7B6-2217-4DDE-AFBE-7173CCF1C606} - \AutoKMS -> No File <==== ATTENTION
FirewallRules: [TCP Query User{38F6D9A2-CE4C-46B2-A499-08113283FB65}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{37CCD958-FF84-4CC6-8232-E2E9ED329674}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{95AB5361-25DB-4309-A133-A04AAF97A500}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{D95D58B6-1C05-42A0-9D16-60BE980B2CC2}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{0A980D26-E7A6-4AB3-95A0-42F0C2889334}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{2D19EB68-9D96-44F3-B62E-8378FBADD90D}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [{2F249B5F-838D-4E2C-851A-87B11B5E65F0}] => (Allow) C:\Users\Toshiba\AppData\Local\iLivid\iLivid.exe
FirewallRules: [{01D02FD0-5539-4CFE-A53B-731C88D880C2}] => (Allow) C:\Users\Toshiba\AppData\Local\iLivid\iLivid.exe
FirewallRules: [{0953B0C3-891E-4B6C-A354-1043B9A09CCF}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{D8FE5899-54B4-4D87-9197-DB63F890B9B8}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{A79857CB-DC6C-48E9-8C9F-7D0826AF659E}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{D6F4E693-D20B-417C-AA5F-CE518A4A2D20}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{73A5BCB0-0F35-48F5-83B6-D728B899E017}] => (Allow) C:\Program Files\360\360 Internet Security\UpTip.exe
FirewallRules: [{D94AC79C-2BAE-4084-8452-B286D758DAEC}] => (Allow) C:\Program Files\360\360 Internet Security\UpTip.exe
FirewallRules: [{82B04690-14F7-41A9-BDD3-B6B04B0D6640}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{2D18A4BA-DBDE-4B8B-BF06-C8B10AD9A84F}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
C:\Users\Toshiba\AppData\Roaming\0AZ2B6673Windows.bat
C:\Users\Toshiba\AppData\Roaming\33KM2IMTW2Windows.bat
C:\Users\Toshiba\AppData\Roaming\9ZTCUM5SCSVACLhehe.exe
C:\Users\Toshiba\AppData\Roaming\bitlord_log.txt
C:\Users\Toshiba\AppData\Roaming\L1QHUAXhehe.exe
C:\Users\Toshiba\AppData\Roaming\ZFKOXZ6DODAWindows.bat
C:\Users\Toshiba\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Toshiba\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Toshiba\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Toshiba\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\Toshiba\AppData\Local\Temp\Quarantine.exe
C:\Users\Toshiba\AppData\Local\Temp\rnsetup0.exe
C:\Users\Toshiba\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Toshiba\AppData\Local\Temp\stubhelper.dll
C:\Users\Toshiba\AppData\Local\Temp\swt-win32-3740.dll
C:\Users\Toshiba\AppData\Local\Temp\{3CC7CDA1-51B3-4D59-87CF-EF76109A212C}-42.0.2311.90_41.0.2272.118_chrome_updater.exe
C:\Users\Toshiba\AppData\Local\Temp\{5B312002-9617-46A7-8B31-53337E079C2C}-41.0.2272.89_40.0.2214.115_chrome_updater.exe
C:\Users\Toshiba\AppData\Local\Temp\{694DE23C-2511-4F9C-841F-19C0054DC42A}-40.0.2214.115_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{8BDA707E-0BEA-46F0-8339-C016E4EA3C5F}-39.0.2171.95_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{903CA3B2-3591-4D28-A8A2-E774059B7BD3}-40.0.2214.115_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{E4D00499-5580-4A1B-85D1-50CB0D137A40}-42.0.2311.90_41.0.2272.118_chrome_updater.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\windows\kmsemulator.exe
C:\Users\Toshiba\AppData\Local\iLivid
C:\Program Files\360
EmptyTemp:
CMD: ipconfig /flushdns

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

Logs to include with next post:

Fixlog.txt

Can you tell me if there are any remaining problems.

Thanks

Satchfan

I re-check the the said program status and in fact it is deleted.
 
Fix result of Farbar Recovery Scan Tool (x64) Version:30-11-2015
Ran by [removed] (2015-12-04 12:51:36) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: F - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: G - G:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {2091109a-ec9b-11e2-81bf-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {209110a1-ec9b-11e2-81bf-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {3354c7d3-b65f-11e1-85c4-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {3354c7da-b65f-11e1-85c4-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {555db868-c42c-11e1-986e-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {555db87a-c42c-11e1-986e-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {6d39009a-89cd-11e3-81a6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {7dff1801-042d-11e3-99f7-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {7ee67c48-ab5d-11e1-9c37-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {814e09fc-06a0-11e3-bfb8-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {839edb36-bef0-11e1-a7f6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d65fc-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d660c-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d660f-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d661e-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6634-be0d-11e1-a6d5-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6647-be0d-11e1-a6d5-001e101f6c04} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {870d6654-be0d-11e1-a6d5-001e101f6c04} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {98b68ef4-8cf3-11e4-a1d6-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b1170f08-b665-11e1-aaae-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b128d9d0-79a3-11e1-ad2b-e89a8f044043} - G:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b128d9d7-79a3-11e1-ad2b-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b4e4fd6e-06b5-11e3-bc4e-e89a8f044043} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd4f-4c49-11e2-845e-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd60-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbd95-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {b75cbda6-4c49-11e2-845e-001e101f859f} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {c905ad93-7dc4-11e1-9435-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {c905ada5-7dc4-11e1-9435-e89a8f044043} - G:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {d1598edb-052f-11e3-9b91-e89a8f044043} - F:\AutoRun.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {e5eb2800-7dd1-11e1-ba79-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaa6-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaa9-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {f61ffaab-b6cc-11e1-8026-e89a8f044043} - F:\StartVMCLite.exe
HKU\S-1-5-21-2217298813-2927578935-920386982-1000\…\MountPoints2: {fed48f45-b0e5-11e1-bdfc-e89a8f044043} - F:\StartVMCLite.exe
AppInit_DLLs-x32: c:\windows\jaksta\ac\x86\jaudcap.dll => No File
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {F11F3195-DB15-4386-AC80-13C6FE576B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {6F601FA8-C974-4DA2-BE97-D0382BB0B5AD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
BHO: AllCHeApPrice -> {A26C1ADD-E1BD-E1E3-22F8-2342C59EF108} -> C:\ProgramData\AllCHeApPrice\ALdqClzjI.x64.dll => No File
BHO: GreAatsaveR -> {F8F6BED2-3F26-FA29-32C4-4F4312546BF4} -> C:\Program Files (x86)\GreAatsaveR\WAcF.x64.dll => No File
BHO-x32: No Name -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Extension: No Name - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [not found]
FF Extension: SNT - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\yb2m6y23.default\Extensions\[removed] [2014-01-21] [not signed]
CHR Extension: (Proteção de Internet do 360) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\glcimepnljoholdmjchkloafkggfoijh [2015-11-09]
S3 Tosrfcom; no ImagePath
S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [X]
2015-12-01 21:59 - 2015-12-01 21:59 - 00000000 ____D C:\Users\Toshiba\AppData\Local\Nico Mak Computing
2015-11-09 14:47 - 2015-11-09 14:48 - 29489272 _____ C:\Users\Toshiba\Downloads\360TSE_Setup_7.2.0.1021.exe
2015-12-04 04:35 - 2015-07-24 17:12 - 00000000 ____D C:\Program Files (x86)\360
2015-12-04 03:02 - 2012-11-22 09:51 - 00000000 ____D C:\Users\Toshiba\AppData\Roaming\uTorrent
2015-12-01 05:46 - 2015-10-19 11:21 - 00000000 __SHD C:\ProgramData\360Quarant
2015-12-01 05:46 - 2015-10-19 11:21 - 00000000 __SHD C:\$360Section
Task: {9346C268-CD96-4219-8C67-49FBCEAB905C} - \Advanced System Protector -> No File <==== ATTENTION
Task: {9B3310F2-D7F4-46F4-A512-0DCD5104F759} - \SomotoUpdateCheckerAutoStart -> No File <==== ATTENTION
Task: {E6FAC7B6-2217-4DDE-AFBE-7173CCF1C606} - \AutoKMS -> No File <==== ATTENTION
FirewallRules: [TCP Query User{38F6D9A2-CE4C-46B2-A499-08113283FB65}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{37CCD958-FF84-4CC6-8232-E2E9ED329674}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{95AB5361-25DB-4309-A133-A04AAF97A500}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{D95D58B6-1C05-42A0-9D16-60BE980B2CC2}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{0A980D26-E7A6-4AB3-95A0-42F0C2889334}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{2D19EB68-9D96-44F3-B62E-8378FBADD90D}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [{2F249B5F-838D-4E2C-851A-87B11B5E65F0}] => (Allow) C:\Users\Toshiba\AppData\Local\iLivid\iLivid.exe
FirewallRules: [{01D02FD0-5539-4CFE-A53B-731C88D880C2}] => (Allow) C:\Users\Toshiba\AppData\Local\iLivid\iLivid.exe
FirewallRules: [{0953B0C3-891E-4B6C-A354-1043B9A09CCF}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{D8FE5899-54B4-4D87-9197-DB63F890B9B8}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{A79857CB-DC6C-48E9-8C9F-7D0826AF659E}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{D6F4E693-D20B-417C-AA5F-CE518A4A2D20}] => (Allow) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
FirewallRules: [{73A5BCB0-0F35-48F5-83B6-D728B899E017}] => (Allow) C:\Program Files\360\360 Internet Security\UpTip.exe
FirewallRules: [{D94AC79C-2BAE-4084-8452-B286D758DAEC}] => (Allow) C:\Program Files\360\360 Internet Security\UpTip.exe
FirewallRules: [{82B04690-14F7-41A9-BDD3-B6B04B0D6640}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{2D18A4BA-DBDE-4B8B-BF06-C8B10AD9A84F}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
C:\Users\Toshiba\AppData\Roaming\0AZ2B6673Windows.bat
C:\Users\Toshiba\AppData\Roaming\33KM2IMTW2Windows.bat
C:\Users\Toshiba\AppData\Roaming\9ZTCUM5SCSVACLhehe.exe
C:\Users\Toshiba\AppData\Roaming\bitlord_log.txt
C:\Users\Toshiba\AppData\Roaming\L1QHUAXhehe.exe
C:\Users\Toshiba\AppData\Roaming\ZFKOXZ6DODAWindows.bat
C:\Users\Toshiba\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Toshiba\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Toshiba\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Toshiba\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\Toshiba\AppData\Local\Temp\Quarantine.exe
C:\Users\Toshiba\AppData\Local\Temp\rnsetup0.exe
C:\Users\Toshiba\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Toshiba\AppData\Local\Temp\stubhelper.dll
C:\Users\Toshiba\AppData\Local\Temp\swt-win32-3740.dll
C:\Users\Toshiba\AppData\Local\Temp\{3CC7CDA1-51B3-4D59-87CF-EF76109A212C}-42.0.2311.90_41.0.2272.118_chrome_updater.exe
C:\Users\Toshiba\AppData\Local\Temp\{5B312002-9617-46A7-8B31-53337E079C2C}-41.0.2272.89_40.0.2214.115_chrome_updater.exe
C:\Users\Toshiba\AppData\Local\Temp\{694DE23C-2511-4F9C-841F-19C0054DC42A}-40.0.2214.115_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{8BDA707E-0BEA-46F0-8339-C016E4EA3C5F}-39.0.2171.95_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{903CA3B2-3591-4D28-A8A2-E774059B7BD3}-40.0.2214.115_chrome_installer.exe
C:\Users\Toshiba\AppData\Local\Temp\{E4D00499-5580-4A1B-85D1-50CB0D137A40}-42.0.2311.90_41.0.2272.118_chrome_updater.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\windows\kmsemulator.exe
C:\Users\Toshiba\AppData\Local\iLivid
C:\Program Files\360
EmptyTemp:
CMD: ipconfig /flushdns
*****************
 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F" => key removed successfully
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G" => key removed successfully
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2091109a-ec9b-11e2-81bf-e89a8f044043}" => key removed successfully
HKCR\CLSID\{2091109a-ec9b-11e2-81bf-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{209110a1-ec9b-11e2-81bf-e89a8f044043}" => key removed successfully
HKCR\CLSID\{209110a1-ec9b-11e2-81bf-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3354c7d3-b65f-11e1-85c4-e89a8f044043}" => key removed successfully
HKCR\CLSID\{3354c7d3-b65f-11e1-85c4-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3354c7da-b65f-11e1-85c4-e89a8f044043}" => key removed successfully
HKCR\CLSID\{3354c7da-b65f-11e1-85c4-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{555db868-c42c-11e1-986e-e89a8f044043}" => key removed successfully
HKCR\CLSID\{555db868-c42c-11e1-986e-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{555db87a-c42c-11e1-986e-e89a8f044043}" => key removed successfully
HKCR\CLSID\{555db87a-c42c-11e1-986e-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6d39009a-89cd-11e3-81a6-e89a8f044043}" => key removed successfully
HKCR\CLSID\{6d39009a-89cd-11e3-81a6-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7dff1801-042d-11e3-99f7-e89a8f044043}" => key removed successfully
HKCR\CLSID\{7dff1801-042d-11e3-99f7-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7ee67c48-ab5d-11e1-9c37-e89a8f044043}" => key removed successfully
HKCR\CLSID\{7ee67c48-ab5d-11e1-9c37-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{814e09fc-06a0-11e3-bfb8-e89a8f044043}" => key removed successfully
HKCR\CLSID\{814e09fc-06a0-11e3-bfb8-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{839edb36-bef0-11e1-a7f6-e89a8f044043}" => key removed successfully
HKCR\CLSID\{839edb36-bef0-11e1-a7f6-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{870d65fc-be0d-11e1-a6d5-e89a8f044043}" => key removed successfully
HKCR\CLSID\{870d65fc-be0d-11e1-a6d5-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{870d660c-be0d-11e1-a6d5-e89a8f044043}" => key removed successfully
HKCR\CLSID\{870d660c-be0d-11e1-a6d5-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{870d660f-be0d-11e1-a6d5-e89a8f044043}" => key removed successfully
HKCR\CLSID\{870d660f-be0d-11e1-a6d5-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{870d661e-be0d-11e1-a6d5-e89a8f044043}" => key removed successfully
HKCR\CLSID\{870d661e-be0d-11e1-a6d5-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{870d6634-be0d-11e1-a6d5-e89a8f044043}" => key removed successfully
HKCR\CLSID\{870d6634-be0d-11e1-a6d5-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{870d6647-be0d-11e1-a6d5-001e101f6c04}" => key removed successfully
HKCR\CLSID\{870d6647-be0d-11e1-a6d5-001e101f6c04} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{870d6654-be0d-11e1-a6d5-001e101f6c04}" => key removed successfully
HKCR\CLSID\{870d6654-be0d-11e1-a6d5-001e101f6c04} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{98b68ef4-8cf3-11e4-a1d6-e89a8f044043}" => key removed successfully
HKCR\CLSID\{98b68ef4-8cf3-11e4-a1d6-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1170f08-b665-11e1-aaae-e89a8f044043}" => key removed successfully
HKCR\CLSID\{b1170f08-b665-11e1-aaae-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b128d9d0-79a3-11e1-ad2b-e89a8f044043}" => key removed successfully
HKCR\CLSID\{b128d9d0-79a3-11e1-ad2b-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b128d9d7-79a3-11e1-ad2b-e89a8f044043}" => key removed successfully
HKCR\CLSID\{b128d9d7-79a3-11e1-ad2b-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b4e4fd6e-06b5-11e3-bc4e-e89a8f044043}" => key removed successfully
HKCR\CLSID\{b4e4fd6e-06b5-11e3-bc4e-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b75cbd4f-4c49-11e2-845e-e89a8f044043}" => key removed successfully
HKCR\CLSID\{b75cbd4f-4c49-11e2-845e-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b75cbd60-4c49-11e2-845e-001e101f859f}" => key removed successfully
HKCR\CLSID\{b75cbd60-4c49-11e2-845e-001e101f859f} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b75cbd95-4c49-11e2-845e-001e101f859f}" => key removed successfully
HKCR\CLSID\{b75cbd95-4c49-11e2-845e-001e101f859f} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b75cbda6-4c49-11e2-845e-001e101f859f}" => key removed successfully
HKCR\CLSID\{b75cbda6-4c49-11e2-845e-001e101f859f} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c905ad93-7dc4-11e1-9435-e89a8f044043}" => key removed successfully
HKCR\CLSID\{c905ad93-7dc4-11e1-9435-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c905ada5-7dc4-11e1-9435-e89a8f044043}" => key removed successfully
HKCR\CLSID\{c905ada5-7dc4-11e1-9435-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d1598edb-052f-11e3-9b91-e89a8f044043}" => key removed successfully
HKCR\CLSID\{d1598edb-052f-11e3-9b91-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e5eb2800-7dd1-11e1-ba79-e89a8f044043}" => key removed successfully
HKCR\CLSID\{e5eb2800-7dd1-11e1-ba79-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f61ffaa6-b6cc-11e1-8026-e89a8f044043}" => key removed successfully
HKCR\CLSID\{f61ffaa6-b6cc-11e1-8026-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f61ffaa9-b6cc-11e1-8026-e89a8f044043}" => key removed successfully
HKCR\CLSID\{f61ffaa9-b6cc-11e1-8026-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f61ffaab-b6cc-11e1-8026-e89a8f044043}" => key removed successfully
HKCR\CLSID\{f61ffaab-b6cc-11e1-8026-e89a8f044043} => key not found. 
"HKU\S-1-5-21-2217298813-2927578935-920386982-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fed48f45-b0e5-11e1-bdfc-e89a8f044043}" => key removed successfully
HKCR\CLSID\{fed48f45-b0e5-11e1-bdfc-e89a8f044043} => key not found. 
"c:\windows\jaksta\ac\x86\jaudcap.dll" => Value data removed successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F11F3195-DB15-4386-AC80-13C6FE576B53}" => key removed successfully
HKCR\CLSID\{F11F3195-DB15-4386-AC80-13C6FE576B53} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{6F601FA8-C974-4DA2-BE97-D0382BB0B5AD}" => key removed successfully
HKCR\Wow6432Node\CLSID\{6F601FA8-C974-4DA2-BE97-D0382BB0B5AD} => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A26C1ADD-E1BD-E1E3-22F8-2342C59EF108}" => key removed successfully
"HKCR\CLSID\{A26C1ADD-E1BD-E1E3-22F8-2342C59EF108}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F8F6BED2-3F26-FA29-32C4-4F4312546BF4}" => key removed successfully
"HKCR\CLSID\{F8F6BED2-3F26-FA29-32C4-4F4312546BF4}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B69F34DD-F0F9-42DC-9EDD-957187DA688D}" => key removed successfully
HKCR\Wow6432Node\CLSID\{B69F34DD-F0F9-42DC-9EDD-957187DA688D} => key not found. 
"HKCR\PROTOCOLS\Handler\livecall" => key removed successfully
HKCR\CLSID\{828030A1-22C1-4009-854F-8E305202313F} => key not found. 
"HKCR\PROTOCOLS\Handler\msnim" => key removed successfully
HKCR\CLSID\{828030A1-22C1-4009-854F-8E305202313F} => key not found. 
"HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin" => key removed successfully
C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox => path removed successfully
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\yb2m6y23.default\Extensions\[removed] => moved successfully
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\glcimepnljoholdmjchkloafkggfoijh => moved successfully
Tosrfcom => service removed successfully
hwusbfake => service removed successfully
C:\Users\Toshiba\AppData\Local\Nico Mak Computing => moved successfully
C:\Users\Toshiba\Downloads\360TSE_Setup_7.2.0.1021.exe => moved successfully
C:\Program Files (x86)\360 => moved successfully
C:\Users\Toshiba\AppData\Roaming\uTorrent => moved successfully
C:\ProgramData\360Quarant => moved successfully
C:\$360Section => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9346C268-CD96-4219-8C67-49FBCEAB905C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9346C268-CD96-4219-8C67-49FBCEAB905C}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advanced System Protector => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9B3310F2-D7F4-46F4-A512-0DCD5104F759}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B3310F2-D7F4-46F4-A512-0DCD5104F759}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SomotoUpdateCheckerAutoStart => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E6FAC7B6-2217-4DDE-AFBE-7173CCF1C606}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6FAC7B6-2217-4DDE-AFBE-7173CCF1C606}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => key removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{38F6D9A2-CE4C-46B2-A499-08113283FB65}C:\program files (x86)\java\jre7\bin\javaw.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{37CCD958-FF84-4CC6-8232-E2E9ED329674}C:\program files (x86)\java\jre7\bin\javaw.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{95AB5361-25DB-4309-A133-A04AAF97A500}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D95D58B6-1C05-42A0-9D16-60BE980B2CC2}C:\users\toshiba\appdata\roaming\dropbox\bin\dropbox.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0A980D26-E7A6-4AB3-95A0-42F0C2889334}C:\windows\kmsemulator.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2D19EB68-9D96-44F3-B62E-8378FBADD90D}C:\windows\kmsemulator.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2F249B5F-838D-4E2C-851A-87B11B5E65F0} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{01D02FD0-5539-4CFE-A53B-731C88D880C2} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0953B0C3-891E-4B6C-A354-1043B9A09CCF} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D8FE5899-54B4-4D87-9197-DB63F890B9B8} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A79857CB-DC6C-48E9-8C9F-7D0826AF659E} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D6F4E693-D20B-417C-AA5F-CE518A4A2D20} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{73A5BCB0-0F35-48F5-83B6-D728B899E017} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D94AC79C-2BAE-4084-8452-B286D758DAEC} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{82B04690-14F7-41A9-BDD3-B6B04B0D6640} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2D18A4BA-DBDE-4B8B-BF06-C8B10AD9A84F} => value removed successfully
C:\Users\Toshiba\AppData\Roaming\0AZ2B6673Windows.bat => moved successfully
C:\Users\Toshiba\AppData\Roaming\33KM2IMTW2Windows.bat => moved successfully
C:\Users\Toshiba\AppData\Roaming\9ZTCUM5SCSVACLhehe.exe => moved successfully
C:\Users\Toshiba\AppData\Roaming\bitlord_log.txt => moved successfully
C:\Users\Toshiba\AppData\Roaming\L1QHUAXhehe.exe => moved successfully
C:\Users\Toshiba\AppData\Roaming\ZFKOXZ6DODAWindows.bat => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\drm_dyndata_7370014.dll => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\jre-8u60-windows-au.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\jre-8u65-windows-au.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\Quarantine.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\rnsetup0.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\SkypeSetup.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\stubhelper.dll => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\swt-win32-3740.dll => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\{3CC7CDA1-51B3-4D59-87CF-EF76109A212C}-42.0.2311.90_41.0.2272.118_chrome_updater.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\{5B312002-9617-46A7-8B31-53337E079C2C}-41.0.2272.89_40.0.2214.115_chrome_updater.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\{694DE23C-2511-4F9C-841F-19C0054DC42A}-40.0.2214.115_chrome_installer.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\{8BDA707E-0BEA-46F0-8339-C016E4EA3C5F}-39.0.2171.95_chrome_installer.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\{903CA3B2-3591-4D28-A8A2-E774059B7BD3}-40.0.2214.115_chrome_installer.exe => moved successfully
C:\Users\Toshiba\AppData\Local\Temp\{E4D00499-5580-4A1B-85D1-50CB0D137A40}-42.0.2311.90_41.0.2272.118_chrome_updater.exe => moved successfully
"C:\Program Files (x86)\uTorrent\uTorrent.exe" => not found.
"C:\windows\kmsemulator.exe" => not found.
"C:\Users\Toshiba\AppData\Local\iLivid" => not found.
C:\Program Files\360 => moved successfully
 
=========  ipconfig /flushdns =========
 
 
Configura��o IP do Windows
 
Cache de resolu��o DNS limpa com �xito.
 
========= End of CMD: =========
 
EmptyTemp: => 10.8 GB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 13:03:04 ====
 
So far my computer seems pretty healthy after following your advice!

Well done on following the instructions so well.

Let’s run an online scan to be sure nothing is left and if that’s clear I’ll send instructions to tidy up.


Run ESET Online Scan

Note: This may take a long time so please be patient.

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use Internet Explorer, FireFox or  Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan

  • click the Run Eset online Scanner button
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o    click on esetinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    o    double click on the Eset installer icon on your desktop.
     

  • check Yes, I accept the Terms of Use
  • click the Start button
  • accept any security warnings from your browser
  • check Enable detection of potentially unwanted applications
  • click Advanced settings and select the following:


    o    scan archives
    o    scan for potentially unsafe applications
    o    enable Anti-Stealth technology


    Note: Do not check Remove found threats
     

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • when the scan completes, push List of found threats
  • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


    Note - if ESET doesn't find any threats, no report will be created.
     

  • push the back button.
  • push Finish

When the scan is complete:

If no threats were found:


o    put a checkmark in "Uninstall application on close"
o    close program
o    report to me that nothing was found.
 

If threats were found:


o    click on "list of threats found"
o    click on "export to text file" and save it as ESET results and save to the desktop
o    click on back
o    put a checkmark in "Uninstall application on close"
o    click on finish
o    close program
o    copy and paste the report here.
 

Thanks

Satchfan

 

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI