Now will add JRT and AdWCleaner. Tomorrow, due to time, will do the ESET scan
# AdwCleaner v5.028 - Relatório criado 05/01/2016 às 16:22:51
# Atualizado 04/01/2016 por Xplode
# Banco de dados : 2016-01-04.2 [Servidor]
# Sistema operacional : Windows 7 Ultimate Service Pack 1 (x64)
# Usuário : Usuario - USUARIO-PC
# Executando de : C:\Users\Usuario\Downloads\AdwCleaner.exe
# Opção : Verificar
***** [ Serviços ] *****
***** [ Pastas ] *****
Pasta Encontrado : C:\Program Files\AdTrustMedia
Pasta Encontrado : C:\Program Files (x86)\simplitec
Pasta Encontrado : C:\Program Files (x86)\AdTrustMedia
Pasta Encontrado : C:\ProgramData\simplitec
Pasta Encontrado : C:\ProgramData\AdTrustMedia
Pasta Encontrado : C:\Users\Usuario\AppData\Local\PackageAware
Pasta Encontrado : C:\Users\Usuario\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
Pasta Encontrado : C:\Users\Usuario\AppData\Roaming\ASPackage
Pasta Encontrado : C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage
***** [ Arquivos ] *****
Arquivo Encontrado : C:\Users\Usuario\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_cmaiofennmphjldldcpphcechfnnohja_0.localstorage
Arquivo Encontrado : C:\Users\Usuario\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_cmaiofennmphjldldcpphcechfnnohja_0.localstorage-journal
Arquivo Encontrado : C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.metrolyrics.com_0.localstorage
Arquivo Encontrado : C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.metrolyrics.com_0.localstorage-journal
Arquivo Encontrado : C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_en.anisearch.com_0.localstorage
Arquivo Encontrado : C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_en.anisearch.com_0.localstorage-journal
Arquivo Encontrado : C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
Arquivo Encontrado : C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
***** [ DLL ] *****
***** [ Atalhos ] *****
***** [ Tarefas agendadas ] *****
***** [ Registro ] *****
Chave Encontrada : HKCU\Software\Mozilla\Extends
Valor Encontrada : HKCU\Software\Mozilla\Firefox\Extensions [{b64d9b05-48e1-4ceb-bf58-e0643994e900}]
Chave Encontrada : HKCU\Software\APN PIP
Chave Encontrada : HKCU\Software\Mozilla\Extends
Chave Encontrada : HKLM\SOFTWARE\Conduit
Chave Encontrada : HKLM\SOFTWARE\simplitec
Chave Encontrada : HKU\S-1-5-21-419499787-849242958-3298517021-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\APN PIP
Chave Encontrada : HKU\S-1-5-21-419499787-849242958-3298517021-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Mozilla\Extends
***** [ Navegadores ] *****
[C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\uqcyog4w.default\prefs.js] [Preference] Encontrada : user_pref("extensions.savesense.channel", "pcdealply");
[C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\uqcyog4w.default\prefs.js] [Preference] Encontrada : user_pref("network.hxxp.request.max-start-delay", 0);
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrado : anidb.net
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrado : br.ask.com
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrado : en.anisearch.com
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrado : veoh.com
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrado : mais.uol.com.br
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrado : rfactor.softonic.com.br
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrado : kemulator.softonic.com.br
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Encontrada : gkcefkcdkepgkpbgncjchhbjgoanleod
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Encontrada : nfengeggddojhakldhlpjdlddgkkjkdd
[C:\Users\Usuario\AppData\Local\Comodo\Dragon\User Data\Default\Web data] [Search Provider] Encontrado : br.ask.com
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4584 bytes] ##########
# AdwCleaner v5.116 - Relatório criado 11/05/2016 às 19:33:49
# Atualizado 09/05/2016 por Xplode
# Banco de dados : 2016-05-09.1 [Servidor]
# Sistema operacional : Windows 7 Ultimate Service Pack 1 (X64)
# Usuário : Usuario - USUARIO-PC
# Executando de : C:\Users\Usuario\Desktop\AdwCleaner.exe
# Opção : Verificar
***** [ Serviços ] *****
Serviço Encontrado : ba3ba5636768c7ae2a9c1f6ef71ffe51
***** [ Pastas ] *****
Pasta Encontrado : C:\ProgramData\AdTrustMedia
Pasta Encontrado : C:\ProgramData\Application Data\AdTrustMedia
Pasta Encontrado : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Social2Sea
Pasta Encontrado : C:\Users\Public\Documents\Guid
Pasta Encontrado : C:\Program Files (x86)\03DE0294-1462993516-05D9-3A06-3A0700080009
Pasta Encontrado : C:\Users\Usuario\AppData\Local\PackageAware
Pasta Encontrado : C:\Program Files\AdTrustMedia
***** [ Arquivos ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Atalhos ] *****
***** [ Tarefas agendadas ] *****
***** [ Registro ] *****
Valor Encontrada : HKCU\Software\Mozilla\Firefox\Extensions [{b64d9b05-48e1-4ceb-bf58-e0643994e900}]
Chave Encontrada : HKLM\SOFTWARE\Classes\CLSID\{8BF0126F-A5B7-4720-ABB2-2414A0AF5474}
Chave Encontrada : HKCU\Software\APN PIP
Chave Encontrada : HKCU\Software\Conduit
Chave Encontrada : HKCU\Software\Mozilla\Extends
Chave Encontrada : HKLM\SOFTWARE\Social2Sea
Chave Encontrada : [x64] HKLM\SOFTWARE\Social2Sea
Chave Encontrada : HKU\S-1-5-21-419499787-849242958-3298517021-1000\Software\APN PIP
Chave Encontrada : HKU\S-1-5-21-419499787-849242958-3298517021-1000\Software\Conduit
Chave Encontrada : HKU\S-1-5-21-419499787-849242958-3298517021-1000\Software\Mozilla\Extends
Valor Encontrada : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{0A3900A9-C2DD-4B6B-9321-DA94A6DC52EB}]
Valor Encontrada : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{50C83A51-A8A2-4543-914D-9F26A62487A5}]
Valor Encontrada : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{4128B613-601E-46E2-975E-E7F7E7711E03}]
Valor Encontrada : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{7809ADCB-A618-49F1-92EB-C20A6C408741}]
Valor Encontrada : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{EE294111-98B0-421D-A25E-4483F3CAB8E3}]
Valor Encontrada : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{06E251A3-99F2-4CC5-AA4F-4FCED1B8E7CA}]
Valor Encontrada : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [TCP Query User{ADE6D9F5-44DF-4509-9B5C-A32F2036331C}C:\program files (x86)\simplitec\kmpfaster\serviceprovider.exe]
Valor Encontrada : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [UDP Query User{52198C39-E862-4157-91A2-1B0FCE1767DD}C:\program files (x86)\simplitec\kmpfaster\serviceprovider.exe]
***** [ Navegadores ] *****
[C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\uqcyog4w.default\prefs.js] Encontrada : user_pref("extensions.savesense.channel", "pcdealply");
[C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\uqcyog4w.default\prefs.js] Encontrada : user_pref("network.hxxp.request.max-start-delay", 0);
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrado : br.ask.com
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Encontrada : gkcefkcdkepgkpbgncjchhbjgoanleod
[C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Encontrada : nfengeggddojhakldhlpjdlddgkkjkdd
[C:\Users\Usuario\AppData\Local\Comodo\Dragon\User Data\Default\Web data] [Search Provider] Encontrado : br.ask.com
[C:\Users\Usuario\AppData\Local\Comodo\Dragon\User Data\Default\Web data] [Search Provider] Encontrado : br.yahoo.com
*************************
C:\AdwCleaner\AdwCleaner[S1].txt - [8838 bytes] - [05/01/2016 15:22:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [8911 bytes] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 7 Ultimate x64
Ran by Usuario (Administrator) on 11/05/2016 at 19:51:54,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 22
Failed to delete: C:\Users\Usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0SV87797 (Temporary Internet Files Folder)
Failed to delete: C:\Users\Usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CT5JTH93 (Temporary Internet Files Folder)
Failed to delete: C:\Users\Usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D7JY3P3W (Temporary Internet Files Folder)
Failed to delete: C:\Users\Usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FOK01LR5 (Temporary Internet Files Folder)
Failed to delete: C:\Users\Usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U2TG90E0 (Temporary Internet Files Folder)
Successfully deleted: C:\ProgramData\update~1 (Folder)
Successfully deleted: C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg (Folder)
Successfully deleted: C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_klbibkeccnjlkjkiokjodocebajanakg_0.localstorage (File)
Successfully deleted: C:\Users\Usuario\AppData\Roaming\productdata (Folder)
Successfully deleted: C:\Users\Usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HP506WPM (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UV13MMTJ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXD9FFUU (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\prefetch\ANTILOGGER FREE.EXE-8827C9B1.pf (File)
Successfully deleted: C:\Windows\system32\REN8D32.tmp (File)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0SV87797 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CT5JTH93 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D7JY3P3W (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FOK01LR5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HP506WPM (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U2TG90E0 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UV13MMTJ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXD9FFUU (Temporary Internet Files Folder)
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11/05/2016 at 19:58:22,15
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~