Additional scan result of Farbar Recovery Scan Tool (x64) Version:06-06-2015 Ran by CarlosEduardo at 2015-06-06 19:53:13 Running from C:\Users\CarlosEduardo\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3030160730-3914295730-2292402835-500 - Administrator - Disabled) CarlosEduardo (S-1-5-21-3030160730-3914295730-2292402835-1002 - Administrator - Enabled) => C:\Users\CarlosEduardo Guest (S-1-5-21-3030160730-3914295730-2292402835-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3030160730-3914295730-2292402835-1004 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Bitdefender Antivírus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Bitdefender Antispyware (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) Atualizações da NVIDIA 2.4.5.28 (Version: 2.4.5.28 - NVIDIA Corporation) Hidden Bitdefender Total Security 2015 (HKLM\...\Bitdefender) (Version: 18.21.0.1497 - Bitdefender) CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform) Central de Mouse e Teclado da Microsoft (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Central de Mouse e Teclado da Microsoft (Version: 2.3.188.0 - Microsoft Corporation) Hidden Driver Booster 2.3 (HKLM-x32\...\Driver Booster_is1) (Version: 2.3 - IObit) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.81 - Google Inc.) Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden K-Lite Mega Codec Pack 11.2.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.2.0 - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) NVIDIA Driver de áudio HD 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation) NVIDIA Driver de gráficos 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.06 - NVIDIA Corporation) NVIDIA Driver do 3D Vision 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.06 - NVIDIA Corporation) NVIDIA GeForce Experience 2.4.5.28 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.28 - NVIDIA Corporation) NVIDIA Software do sistema PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Painel de controle da NVIDIA 353.06 (Version: 353.06 - NVIDIA Corporation) Hidden Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7512 - Realtek Semiconductor Corp.) SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.5.28 - NVIDIA Corporation) Hidden Viber (HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\...\Viber) (Version: 5.1.1.15 - Viber Media Inc) Warsaw 1.5.2.9896 64 bits (HKLM\...\{20E60725-16C8-4FB9-8BC2-AF92C5F8D06D}_is1) (Version: 1.5.2.9896 - GAS Tecnologia) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 05-06-2015 18:46:45 Windows Modules Installer 05-06-2015 19:13:33 Driver Booster : HID Keyboard Device ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 10:25 - 2015-06-06 19:30 - 00000822 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {04F24453-4C69-4C88-BEA7-BBB17BD599CD} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2015-04-07] (IObit) Task: {41B31809-251C-4291-A66A-A11D7168CC04} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {656ED234-B9D6-40CA-A1CF-734056F8EE97} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-05] (Realtek Semiconductor) Task: {B06D8D05-8BD6-4286-9B9A-8941E8FEAF45} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2015-05-14] (IObit) Task: {B2D17952-FC53-4785-9B39-7BECE9DF225F} - System32\Tasks\Driver Booster SkipUAC (CarlosEduardo) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-05-14] (IObit) Task: {BC8B295D-85EA-4B57-912E-6DB306A75509} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {BDEECDED-4C89-495A-8A08-5DEA9DFAA81D} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {C31293FC-D1D4-4CFA-B8DB-A4BD7A134807} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-05] (Google Inc.) Task: {CD31CAD2-A621-4F7B-B86C-3A10CD655C59} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {D35D1A67-0E6D-4F41-B566-46121618EA9D} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-05] (Realtek Semiconductor) Task: {D3EF74B1-5351-47DC-824D-61DEBCFAF6BD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd) Task: {DB29B46C-7463-45ED-91BF-373C8F30B144} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2015-05-31] () Task: {E9C2E294-EB85-41C6-9585-40B51425D371} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {F81606D5-D2C7-478C-ACCF-5D99DE35A921} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-05] (Google Inc.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-06-05 20:58 - 2014-08-27 16:31 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\txmlutil.dll 2015-06-05 20:58 - 2013-09-03 14:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdmetrics.dll 2015-06-05 20:58 - 2015-03-23 17:57 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\UI\accessl.ui 2015-06-05 20:58 - 2012-10-29 14:22 - 00152816 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdfwcore.dll 2015-06-05 21:04 - 2015-06-05 21:04 - 00790368 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00350_002\ashttpbr.mdl 2015-06-05 21:04 - 2015-06-05 21:04 - 00711064 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00350_002\ashttpdsp.mdl 2015-06-05 21:04 - 2015-06-05 21:04 - 02683520 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00350_002\ashttpph.mdl 2015-06-05 21:04 - 2015-06-05 21:04 - 01326504 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00350_002\ashttprbl.mdl 2015-06-05 18:55 - 2015-05-28 01:15 - 00116368 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-06-06 11:10 - 2015-05-25 11:39 - 80036560 _____ () C:\Users\CarlosEduardo\AppData\Local\Viber\Viber.exe 2015-06-05 20:27 - 2015-05-28 04:04 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-06-06 11:10 - 2015-02-25 04:21 - 01507328 _____ () C:\Users\CarlosEduardo\AppData\Local\Viber\libGLESv2.dll 2015-06-06 11:10 - 2015-05-25 11:03 - 00100864 _____ () C:\Users\CarlosEduardo\AppData\Local\Viber\qfacebook.dll 2015-06-06 11:10 - 2015-05-25 11:02 - 00171008 _____ () C:\Users\CarlosEduardo\AppData\Local\Viber\exif.dll 2015-06-06 11:10 - 2015-02-25 04:21 - 00063488 _____ () C:\Users\CarlosEduardo\AppData\Local\Viber\libEGL.dll 2015-06-06 11:10 - 2015-02-25 04:36 - 00010240 _____ () C:\Users\CarlosEduardo\AppData\Local\Viber\QtQuick.2\qtquick2plugin.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\CarlosEduardo\OneDrive:ms-properties AlternateDataStreams: C:\Users\CarlosEduardo\Desktop\FRST64.exe:BDU AlternateDataStreams: C:\Users\CarlosEduardo\Downloads\AdwCleaner.exe:BDU AlternateDataStreams: C:\Users\CarlosEduardo\Downloads\K-Lite_Codec_Pack_1120_Mega.exe:BDU AlternateDataStreams: C:\Users\CarlosEduardo\Downloads\OTL.exe:BDU AlternateDataStreams: C:\Users\CarlosEduardo\Downloads\ViberSetup.exe:BDU ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\...\google.com -> www.google.com IE trusted site: HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\...\google.com.br -> www.google.com.br IE trusted site: HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\...\itau.b.br -> www.itau.b.br IE trusted site: HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\...\itau.com.br -> hxxps://bankline.itau.com.br IE trusted site: HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\...\itau.com.br -> bankline.itau.com.br IE trusted site: HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\...\itaupersonnalite.com.br -> www.itaupersonnalite.com.br IE trusted site: HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\...\itaupersonnalite.com.br -> hxxp://www.itaupersonnalite.com.br ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3030160730-3914295730-2292402835-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\CarlosEduardo\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\twilight edited.jpg DNS Servers: 80.82.64.136 - 8.8.8.8 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{3BB941DB-2FA5-4751-8C7A-0D17AF2536E0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{20BD506D-B2D1-43CE-96CB-F433C9DCC775}] => (Allow) C:\Users\CarlosEduardo\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{DCDA163E-D218-4C89-A079-F22B0911C3B2}] => (Allow) C:\Users\CarlosEduardo\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{E2BDF630-005C-40E0-86D1-ECE9A1B27484}] => (Allow) C:\Program Files\Diebold\Warsaw\core.exe FirewallRules: [{13C02A0C-1858-454F-A489-56F71B1BF103}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{105B41C3-5424-4707-B930-C987645FAB96}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{D50AFDCE-1853-432D-BDC4-4B78699057AE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{FA798708-7DEE-429F-BA83-D876B66F11C5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{6159762E-D800-4A84-9431-9270A660C56E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{7853382B-D6E2-4B40-AE02-F936BF2721EB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (06/06/2015 07:29:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: O serviço Superfetch terminou com o erro: %%1062 Error: (06/06/2015 07:28:55 PM) (Source: DCOM) (EventID: 10010) (User: KDU) Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} Error: (06/06/2015 03:30:42 PM) (Source: disk) (EventID: 11) (User: ) Description: O driver detectou um erro de controlador em \Device\Harddisk2\DR2. Microsoft Office: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4700HQ CPU @ 2.40GHz Percentage of memory in use: 16% Total physical RAM: 16333.46 MB Available physical RAM: 13643.06 MB Total Pagefile: 19277.46 MB Available Pagefile: 16475.01 MB Total Virtual: 131072 MB Available Virtual: 131071.78 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:238.14 GB) (Free:197.98 GB) NTFS Drive d: (Storage Kdu) (Fixed) (Total:931.51 GB) (Free:272.22 GB) NTFS Drive e: (W81_X64_ESD_OEM_en-US_Mar2015) (Removable) (Total:7.4 GB) (Free:3.02 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 1EC820E8) Partition: GPT Partition Type. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 238.5 GB) (Disk ID: B9F841C8) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=238.1 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 7.4 GB) (Disk ID: 006534C0) Partition 1: (Active) - (Size=7.4 GB) - (Type=07 NTFS) ==================== End of log ============================