start CloseProcesses: (Elex do Brasil Participações Ltda) C:\Programas\iSafe\iSafeSvc.exe (Elex do Brasil Participações Ltda) C:\Programas\iSafe\iSafeSvc2.exe (Elex do Brasil Participações Ltda) C:\Programas\iSafe\iSafeTray.exe () C:\Programas\iSafe\ipcdl.exe C:\Programas\iSafe HKLM\...\Run: [] => [X] HKLM\...99B7938DA9E4}\LocalServer32: [Default-wmiprvse]  <==== ATTENTION! HKU\S-1-5-21-1060284298-764733703-725345543-1008\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1060284298-764733703-725345543-1008\...\MountPoints2: {3410e954-5816-11dd-9cab-001d601032bd} - F:\Menu.exe HKU\S-1-5-21-1060284298-764733703-725345543-1008\...\MountPoints2: {5ea9ab0e-7236-11dd-9cd6-001d601032bd} - F:\.\RECYCLER\S-1-5-21-861567501-1801674531-839528404-232 HKU\S-1-5-21-1060284298-764733703-725345543-1008\...\MountPoints2: {c866feaf-0c13-11e4-a703-001d601032bd} - F:\Startme.exe HKU\S-1-5-21-1060284298-764733703-725345543-1008\...\MountPoints2: {f007bd32-7a06-11de-9f7e-001d601032bd} - F:\setup.exe AUTORUN=1 URLSearchHook: HKLM - Default Value = {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} URLSearchHook: HKLM - (No Name) - {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} -  No File SearchScopes: HKLM - {AD174941-7758-4410-8113-8C8C3D166F1A} URL = http://u-search.net/...q={searchTerms} SearchScopes: HKCU - {AD174941-7758-4410-8113-8C8C3D166F1A} URL = BHO: No Name -> {9030D464-4C02-4ABF-8ECC-5164760863C6} ->  No File Toolbar: HKLM - No Name - {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} -  No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File FF Extension: Website Counselor - C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\mfw8iwaf.default\Extensions\{cc6cc772-f121-49e0-b1f0-c26583cb0c5e} [2014-09-10] C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\mfw8iwaf.default\Extensions\{cc6cc772-f121-49e0-b1f0-c26583cb0c5e} R2 iSafeService; C:\Programas\iSafe\iSafeSvc.exe [118048 2014-08-08] (Elex do Brasil Participações Ltda) C:\Programas\iSafe\iSafeSvc.exe R1 iSafeKrnl; C:\Programas\iSafe\iSafeKrnl.sys [214592 2014-08-08] (Elex do Brasil Participações Ltda) S3 iSafeKrnlBoot; C:\WINDOWS\System32\DRIVERS\iSafeKrnlBoot.sys [40768 2014-08-08] (Elex do Brasil Participações Ltda) R1 iSafeKrnlKit; C:\Programas\iSafe\iSafeKrnlKit.sys [68288 2014-08-08] (Elex do Brasil Participações Ltda) R1 iSafeKrnlR3; C:\Programas\iSafe\iSafeKrnlR3.sys [37696 2014-08-08] (Elex do Brasil Participações Ltda) R1 iSafeNetFilter; C:\Programas\iSafe\iSafeNetFilter.sys [55464 2014-08-06] (Elex do Brasil Participações Ltda) C:\Programas\iSafe S1 mferkdk; \??\C:\Programas\McAfee\VirusScan Enterprise\mferkdk.sys [X] U1 WS2IFSL; No ImagePath 2014-09-16 10:30 - 2014-08-08 07:24 - 00040768 _____ (Elex do Brasil Participações Ltda) C:\WINDOWS\system32\Drivers\iSafeKrnlBoot.sys 2014-09-16 10:29 - 2014-09-16 10:34 - 00000000 ____D () C:\Documents and Settings\Daniel\Application Data\iSafe 2014-09-16 10:30 - 2014-08-08 07:17 - 00065696 _____ () C:\Programas\iSafe\zlib1.dll 2014-09-16 10:30 - 2014-08-08 07:17 - 00092320 _____ () C:\Programas\iSafe\curlpp.dll 2014-09-16 10:30 - 2014-08-08 07:17 - 00427168 _____ () C:\Programas\iSafe\ipcproxy.dll 2014-09-16 10:29 - 2014-07-09 13:48 - 00176976 _____ () C:\Programas\iSafe\tws\unrar.dll 2014-09-16 10:29 - 2014-07-09 13:48 - 00068432 _____ () C:\Programas\iSafe\tws\zlib1.dll 2014-09-16 10:29 - 2014-07-09 13:48 - 00087744 _____ () C:\Programas\iSafe\tws\unacev2.dll 2014-09-16 10:30 - 2014-08-08 07:17 - 00185640 _____ () C:\Programas\iSafe\libpng.dll 2014-09-16 10:30 - 2014-08-08 07:17 - 02228896 _____ () C:\Programas\iSafe\ipcdl.exe AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:63238B95 EmptyTemp: end