Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Win64/Sathurbot.A trojan or something similar (Win 8 user) [Solved]

Sathurbot trojan help

  • This topic is locked This topic is locked

#16
ALXS

ALXS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Hi Naat sorry about that here is the log

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-08-2014
Ran by Alex (administrator) on ALEX on 27-08-2014 17:04:17
Running from C:\Users\Alex\Desktop
Platform: Windows 8.1 Single Language (X64) OS Language: Português (Brasil)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Windows ® Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Spotify Ltd) C:\Users\Alex\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Dropbox, Inc.) C:\Users\Alex\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe\livecomm.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [Everything] => C:\Program Files (x86)\Everything\Everything.exe [1048576 2014-08-05] ()
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5187088 2014-08-11] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications))
HKU\S-1-5-21-85189985-2318871348-3638756338-1001\...\Run: [Spotify Web Helper] => C:\Users\Alex\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-08-25] (Spotify Ltd)
HKU\S-1-5-21-85189985-2318871348-3638756338-1001\...\Policies\Explorer: [Run] "C:\Users\Alex\AppData\Roaming\Microsoft\Windows\IEUpdate\poqexec.exe"
Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Alex\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Alex\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Alex\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Alex\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Alex\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Alex\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Alex\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Alex\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Alex\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: EldosIconOverlay -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: EldosIconOverlay -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer13.msn.com/?pc=ACJB
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com/?pc=ACJB
SearchScopes: HKLM - DefaultScope {02E50DD2-AF67-45A2-B3F0-FF2966062B6C} URL = http://www.bing.com/...=IE10TR&pc=ACJB
SearchScopes: HKLM - {02E50DD2-AF67-45A2-B3F0-FF2966062B6C} URL = http://www.bing.com/...=IE10TR&pc=ACJB
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://uk.yhs4.searc...p={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {02E50DD2-AF67-45A2-B3F0-FF2966062B6C} URL = http://www.bing.com/...=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 - {02E50DD2-AF67-45A2-B3F0-FF2966062B6C} URL = http://www.bing.com/...=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://uk.yhs4.searc...p={searchTerms}
SearchScopes: HKCU - DefaultScope {02E50DD2-AF67-45A2-B3F0-FF2966062B6C} URL = 
SearchScopes: HKCU - {02E50DD2-AF67-45A2-B3F0-FF2966062B6C} URL = 
SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://uk.yhs4.searc...p={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://iyell/
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-21]
CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-21]
CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-21]
CHR Extension: (Adblock Plus) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-21]
CHR Extension: (Google Search) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-21]
CHR Extension: (Screen Capture (by Google)) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpngackimfmofbokmjmljamhdncknpmg [2014-07-21]
CHR Extension: (Google Calendar) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2014-07-21]
CHR Extension: (AdBlock) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-07-21]
CHR Extension: (Hola Better Internet) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-07-21]
CHR Extension: (Super Auto Refresh) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkhjakkgopekjlempoplnjclgedabddk [2014-08-22]
CHR Extension: (Google Maps) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-07-21]
CHR Extension: (Google Wallet) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-21]
CHR Extension: (Gmail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-21]
CHR Extension: (Space Planet) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppcocpoeoiajndepaaimnnglicichmbb [2014-07-21]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows ® Win 7 DDK provider)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3244048 2014-08-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-11] (AVG Technologies CZ, s.r.o.)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-23] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-23] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [242968 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [270104 2014-06-30] (AVG Technologies CZ, s.r.o.)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 cbfs3; C:\Windows\System32\drivers\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
S3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation)
S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
S3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-28] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-23] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-27 15:51 - 2014-08-27 15:51 - 00000127 _____ () C:\Users\Alex\Desktop\ckfiles.txt
2014-08-27 03:52 - 2014-08-27 03:52 - 00828425 _____ () C:\Users\Alex\Desktop\ckfiles111.txt
2014-08-27 03:46 - 2014-08-27 03:46 - 00468480 _____ () C:\Users\Alex\Desktop\CKScanner.exe
2014-08-27 03:36 - 2014-08-27 03:36 - 00468480 _____ () C:\Users\Alex\Downloads\CKScanner.exe
2014-08-27 03:09 - 2014-08-27 03:10 - 00049697 _____ () C:\Users\Alex\Desktop\Addition.txt
2014-08-27 03:07 - 2014-08-27 17:04 - 00020794 _____ () C:\Users\Alex\Desktop\FRST.txt
2014-08-27 03:06 - 2014-08-27 17:04 - 00000000 ____D () C:\FRST
2014-08-27 03:05 - 2014-08-27 03:05 - 02103296 _____ (Farbar) C:\Users\Alex\Downloads\FRST64.exe
2014-08-27 03:05 - 2014-08-27 03:05 - 02103296 _____ (Farbar) C:\Users\Alex\Desktop\FRST64.exe
2014-08-26 21:51 - 2014-08-26 21:51 - 00211128 _____ () C:\Users\Alex\Downloads\OTLtuesday.txt
2014-08-26 21:46 - 2014-08-26 21:46 - 00095922 _____ () C:\Users\Alex\Downloads\Extras.Txt
2014-08-26 21:45 - 2014-08-26 21:45 - 00211128 _____ () C:\Users\Alex\Downloads\OTL.Txt
2014-08-26 21:20 - 2014-08-26 21:24 - 00602112 _____ (OldTimer Tools) C:\Users\Alex\Downloads\OTL.exe
2014-08-26 18:46 - 2014-08-26 18:47 - 101616092 _____ () C:\Users\Alex\Downloads\Unknown-Artists--Bass--Original-Mix-.wav
2014-08-26 17:15 - 2014-08-26 17:15 - 00000644 _____ () C:\Users\Alex\Desktop\virus.txt
2014-08-26 13:59 - 2014-08-27 12:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-08-26 13:57 - 2014-08-26 13:57 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-08-26 13:51 - 2014-08-26 13:54 - 00000000 ____D () C:\Users\Alex\Downloads\AVG Antivirus 2014 x64 374 Days
2014-08-26 13:46 - 2014-08-26 13:46 - 00001450 _____ () C:\Users\Alex\Desktop\Everything - Atalho.lnk
2014-08-26 13:41 - 2014-08-26 13:41 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything
2014-08-26 13:35 - 2014-08-26 22:22 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Everything
2014-08-26 13:34 - 2014-08-26 13:41 - 00000000 ____D () C:\Program Files (x86)\Everything
2014-08-26 13:33 - 2014-08-26 13:34 - 00473291 _____ () C:\Users\Alex\Downloads\Everything-1.3.4.686.x86-Setup.exe
2014-08-25 23:45 - 2014-08-25 23:45 - 00000000 ____D () C:\Windows\System32\Tasks\GenericSettingsHandler
2014-08-25 15:40 - 2014-08-25 15:40 - 00517120 _____ (Microsoft Corporation) C:\Users\Alex\Downloads\settingsynchost.exe
2014-08-25 15:05 - 2014-08-25 15:05 - 00000000 ____D () C:\Users\Alex\AppData\Local\BMExplorer
2014-08-23 20:40 - 2014-08-27 16:49 - 00000000 ____D () C:\Users\Alex\Desktop\Tunes
2014-08-23 14:40 - 2014-08-27 15:00 - 00000000 ____D () C:\Users\Alex\AppData\Local\Extion
2014-08-23 14:40 - 2014-08-27 14:41 - 00000000 ____D () C:\Users\Alex\AppData\Local\Ipsoft
2014-08-23 14:40 - 2014-08-23 14:40 - 00000000 __SHD () C:\Users\Alex\AppData\Local\EmieUserList
2014-08-23 14:40 - 2014-08-23 14:40 - 00000000 __SHD () C:\Users\Alex\AppData\Local\EmieSiteList
2014-08-23 14:17 - 2014-08-25 17:11 - 00000000 ____D () C:\Program Files (x86)\iExplorer
2014-08-23 13:18 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\AppData\Local\Macroplant_LLC
2014-08-23 13:17 - 2012-04-09 16:27 - 00223760 _____ (EldoS Corporation) C:\Windows\SysWOW64\CbFsNetRdr3.dll
2014-08-23 13:17 - 2012-04-09 16:27 - 00190480 _____ (EldoS Corporation) C:\Windows\system32\CbFsMntNtf3.dll
2014-08-23 13:17 - 2012-04-09 16:27 - 00158224 _____ (EldoS Corporation) C:\Windows\SysWOW64\CbFsMntNtf3.dll
2014-08-23 13:17 - 2012-04-09 16:27 - 00141328 _____ (EldoS Corporation) C:\Windows\system32\CbFsNetRdr3.dll
2014-08-23 13:16 - 2012-04-09 16:27 - 00352144 _____ (EldoS Corporation) C:\Windows\system32\Drivers\cbfs3.sys
2014-08-23 13:14 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\Downloads\Fracture (2007) [1080p]
2014-08-23 12:13 - 2014-08-25 17:10 - 00000000 __HDC () C:\Users\Todos os Usuários\{ACF12395-778E-44F0-A811-C99F334A83F5}
2014-08-23 12:13 - 2014-08-25 17:10 - 00000000 __HDC () C:\ProgramData\{ACF12395-778E-44F0-A811-C99F334A83F5}
2014-08-23 12:08 - 2014-08-25 17:10 - 00000000 __HDC () C:\Users\Todos os Usuários\{BD26D777-CA21-4BDD-A581-6BCFE4F0F941}
2014-08-23 12:08 - 2014-08-25 17:10 - 00000000 __HDC () C:\ProgramData\{BD26D777-CA21-4BDD-A581-6BCFE4F0F941}
2014-08-23 12:08 - 2014-08-23 12:08 - 00001114 _____ () C:\Users\Public\Desktop\Controller Editor.lnk
2014-08-23 12:07 - 2014-08-25 17:10 - 00000000 __HDC () C:\Users\Todos os Usuários\{C6A355F5-168B-4EEC-AB7C-75594F783EDB}
2014-08-23 12:07 - 2014-08-25 17:10 - 00000000 __HDC () C:\ProgramData\{C6A355F5-168B-4EEC-AB7C-75594F783EDB}
2014-08-23 11:22 - 2014-08-23 11:22 - 00000000 ____D () C:\Users\Alex\AppData\Local\Spoon
2014-08-23 06:05 - 2014-08-23 12:07 - 00001079 _____ () C:\Users\Public\Desktop\Service Center.lnk
2014-08-23 05:51 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\Downloads\Native Instruments Traktor Pro 2 v2.6.8 Incl. Patch-Tracer [deepstatus][h33t][1337x][flashtorrents]
2014-08-23 01:27 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-08-23 01:27 - 2014-08-25 17:10 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-08-23 00:09 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\Downloads\Angel.Heart.1987.720p.BRRip.x264-x0r
2014-08-22 08:03 - 2014-08-23 11:34 - 31922338 ____T () C:\Users\Alex\Desktop\Bomb.wav
2014-08-22 06:17 - 2014-08-22 06:21 - 11064240 _____ () C:\Users\Alex\Downloads\Bomb Decent Project.rar
2014-08-22 05:56 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Synapse Audio
2014-08-22 05:56 - 2014-08-22 05:56 - 00000000 ____D () C:\Program Files (x86)\Steinberg
2014-08-22 02:59 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2014-08-22 02:59 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-08-22 02:57 - 2014-08-25 17:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
2014-08-22 02:57 - 2014-08-22 02:57 - 00000000 ____D () C:\Windows\PCHEALTH
2014-08-22 02:57 - 2014-08-22 02:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Sync Framework
2014-08-22 02:57 - 2014-08-22 02:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-08-22 02:56 - 2014-08-25 17:09 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-08-22 02:55 - 2014-08-25 17:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-08-22 02:54 - 2014-08-22 02:54 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-08-22 02:53 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Todos os Usuários\Microsoft Help
2014-08-22 02:53 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-22 02:53 - 2014-08-22 02:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-08-22 02:53 - 2014-08-22 02:53 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services
2014-08-22 02:52 - 2014-08-22 02:52 - 00000000 __RHD () C:\MSOCache
2014-08-22 02:09 - 2014-08-22 02:18 - 81604866 _____ () C:\Users\Alex\Downloads\Alex Carroll - Only Happy When It Rains_[MASTERED].wav
2014-08-22 00:55 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\Downloads\Microsoft Office 2010 Professional Plus x86
2014-08-22 00:14 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\AppData\Local\Microsoft Help
2014-08-21 23:31 - 2014-08-21 23:31 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2014-08-21 23:31 - 2014-08-21 23:31 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-08-21 23:21 - 2014-08-21 23:27 - 15038405 _____ () C:\Users\Alex\Downloads\Synapse.Audio.DUNE.VSTi.v1.4.0.x86.x64.WORKiNG-ASSiGN.rar
2014-08-20 16:48 - 2012-11-21 16:33 - 00000000 ____D () C:\Users\Alex\Downloads\Inception - Audio Spray (2012)
2014-08-20 06:20 - 2014-08-20 06:21 - 87297164 _____ () C:\Users\Alex\Downloads\12_Henix-R - Melodic Sensation_MASTER.wav
2014-08-20 06:20 - 2014-08-20 06:21 - 81145856 _____ () C:\Users\Alex\Downloads\14_CupCake - Slowing Down_MASTER.wav
2014-08-20 06:19 - 2014-08-20 06:20 - 90031782 _____ () C:\Users\Alex\Downloads\10.Mahruna - Facelift - WAV.wav
2014-08-20 06:19 - 2014-08-20 06:20 - 85765488 _____ () C:\Users\Alex\Downloads\09-D_Vision -  Forget The Rules(mastering by Tim Schult).wav
2014-08-20 06:15 - 2014-08-20 06:16 - 67741696 _____ () C:\Users\Alex\Downloads\02_Toxic Universe - Wild Orchid 2_MASTER.wav
2014-08-20 06:12 - 2014-08-20 06:13 - 117739184 _____ () C:\Users\Alex\Downloads\Ranji - Speed of sound Master.wav
2014-08-20 06:11 - 2014-08-20 06:12 - 61691768 _____ () C:\Users\Alex\Downloads\Old_Friend_Master_16bit_44.1khz.wav
2014-08-20 05:57 - 2014-08-20 06:15 - 56743186 _____ () C:\Users\Alex\Downloads\Inception - Audio Spray (2012).rar
2014-08-18 19:02 - 2014-08-18 19:02 - 00000000 ____D () C:\Users\Alex\AppData\Local\Adobe
2014-08-18 04:04 - 2014-08-18 04:04 - 00001814 _____ () C:\Users\Alex\Desktop\Surgeon Simulator 2013 Steam Edition Game Two.lnk
2014-08-18 04:02 - 2014-08-18 04:02 - 00000000 ____D () C:\Games
2014-08-18 02:13 - 2014-08-18 02:28 - 403326231 _____ (Cat-A-Cat ) C:\Users\Alex\Downloads\Surgeon_Simulator_2013_Steam_Edition_ENG.exe
2014-08-18 01:45 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\AppData\Local\Intel_Corporation
2014-08-18 01:26 - 2014-08-18 01:26 - 00000000 ____D () C:\Users\Alex\AppData\Local\Ubisoft
2014-08-18 01:17 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Todos os Usuários\McAfee Security Scan
2014-08-18 01:17 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-08-18 01:17 - 2014-08-23 01:27 - 00001951 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-08-14 20:27 - 2014-08-01 21:17 - 00704480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-14 20:27 - 2014-08-01 21:17 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-14 18:01 - 2014-07-25 11:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-14 18:01 - 2014-07-25 10:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-14 18:01 - 2014-07-25 10:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-14 18:01 - 2014-07-25 09:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-14 18:01 - 2014-07-25 09:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-14 18:01 - 2014-07-25 09:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-14 18:01 - 2014-07-25 09:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 18:01 - 2014-07-25 09:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-14 18:01 - 2014-07-25 09:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-14 18:01 - 2014-07-25 09:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-14 18:01 - 2014-07-25 09:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-14 18:01 - 2014-07-25 09:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-14 18:01 - 2014-07-25 08:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-14 18:01 - 2014-07-25 08:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-14 18:01 - 2014-07-25 08:43 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-14 18:01 - 2014-07-25 08:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-14 18:01 - 2014-07-25 08:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-14 18:01 - 2014-07-25 08:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-14 18:01 - 2014-07-25 08:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-14 18:01 - 2014-07-25 08:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-14 18:01 - 2014-07-25 08:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-14 18:01 - 2014-07-25 08:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-14 18:01 - 2014-07-25 08:09 - 00291840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-14 18:01 - 2014-07-25 08:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-14 18:01 - 2014-07-25 08:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-14 18:01 - 2014-07-25 07:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-14 18:01 - 2014-07-25 07:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-14 18:01 - 2014-07-25 07:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-14 18:01 - 2014-07-25 07:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-14 18:01 - 2014-07-25 07:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-14 18:01 - 2014-07-25 07:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-14 18:00 - 2014-07-25 10:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-14 18:00 - 2014-07-25 10:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-14 18:00 - 2014-07-25 09:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-14 18:00 - 2014-07-25 09:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-14 17:59 - 2014-06-19 22:48 - 01273184 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-14 17:59 - 2014-06-19 20:52 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-14 17:57 - 2014-08-06 23:12 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-14 17:57 - 2014-08-06 19:39 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-14 17:57 - 2014-08-06 19:38 - 00697856 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-14 17:57 - 2014-08-02 02:44 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-14 17:57 - 2014-08-02 00:56 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-14 17:57 - 2014-08-02 00:11 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-08-14 17:57 - 2014-07-15 15:16 - 03048880 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2014-08-14 17:57 - 2014-07-15 05:29 - 03118080 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-08-14 17:57 - 2014-07-15 05:22 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2014-08-14 17:57 - 2014-07-15 05:03 - 02344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-08-14 17:57 - 2014-07-12 01:17 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe
2014-08-14 17:57 - 2014-07-10 01:16 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
2014-08-14 17:57 - 2014-07-10 01:03 - 04756992 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
2014-08-14 17:57 - 2014-07-10 00:33 - 01120256 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
2014-08-14 17:57 - 2014-06-12 22:15 - 00517528 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-08-14 17:57 - 2014-06-12 22:14 - 01557848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-14 17:57 - 2014-06-12 21:10 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-08-14 17:57 - 2014-06-09 19:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 17:57 - 2014-06-09 19:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-14 17:57 - 2014-06-06 08:34 - 02133504 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-08-14 17:57 - 2014-06-04 06:27 - 00114520 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-14 17:57 - 2014-06-04 02:31 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-14 17:57 - 2014-06-04 02:22 - 02790912 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-14 17:57 - 2014-06-04 01:43 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-14 17:57 - 2014-06-04 01:38 - 03304448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-14 17:57 - 2014-06-03 23:15 - 02642944 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-14 17:57 - 2014-06-03 23:14 - 02318336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-14 17:57 - 2014-05-31 03:27 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-08-14 17:56 - 2014-06-05 11:13 - 00216368 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll
2014-08-14 17:56 - 2014-06-05 10:14 - 00189016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2014-08-14 17:56 - 2014-06-01 23:10 - 00423768 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-08-14 17:56 - 2014-05-31 07:07 - 00467800 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2014-08-14 17:56 - 2014-05-31 07:07 - 00440664 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-08-14 17:56 - 2014-05-31 07:07 - 00419672 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-08-14 17:56 - 2014-05-31 07:07 - 00089944 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-08-14 17:56 - 2014-05-31 07:07 - 00027480 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-08-14 17:56 - 2014-05-31 03:30 - 00037376 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-08-14 17:56 - 2014-05-31 03:27 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-08-14 17:56 - 2014-05-31 03:26 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-08-14 17:56 - 2014-05-31 01:01 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-08-14 17:56 - 2014-05-31 01:01 - 00209408 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-08-14 17:56 - 2014-05-31 01:01 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-08-14 17:56 - 2014-05-27 12:53 - 02518360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-08-14 17:56 - 2014-05-27 06:56 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\DaOtpCredentialProvider.dll
2014-08-14 17:56 - 2014-05-27 06:53 - 00270848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DaOtpCredentialProvider.dll
2014-08-14 17:56 - 2014-05-17 01:59 - 16871936 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2014-08-14 17:56 - 2014-05-17 01:13 - 12711424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2014-08-14 17:56 - 2014-05-13 04:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\BulkOperationHost.exe
2014-08-14 17:56 - 2014-05-13 02:07 - 02844160 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-08-14 17:56 - 2014-05-13 01:41 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll
2014-08-14 17:56 - 2014-05-13 01:26 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll
2014-08-14 17:56 - 2014-05-13 00:59 - 01035264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-08-14 17:56 - 2014-05-13 00:31 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll
2014-08-14 17:56 - 2014-05-03 08:29 - 01726224 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-08-14 17:56 - 2014-05-03 06:20 - 01473080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-08-14 17:56 - 2014-05-03 02:36 - 00997888 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2014-08-14 17:56 - 2014-05-03 02:19 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\ncobjapi.dll
2014-08-14 17:56 - 2014-05-03 02:08 - 00301056 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2014-08-14 17:56 - 2014-05-03 02:07 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2014-08-14 17:56 - 2014-05-03 01:46 - 00052736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncobjapi.dll
2014-08-14 17:56 - 2014-05-03 01:37 - 00235008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedynos.dll
2014-08-14 17:56 - 2014-05-03 01:37 - 00207360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedyn.dll
2014-08-14 17:56 - 2014-05-02 20:26 - 00050745 _____ () C:\Windows\system32\srms.dat
2014-08-14 17:56 - 2014-05-01 02:44 - 01025536 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-08-14 17:56 - 2014-04-30 03:43 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vwififlt.sys
2014-08-14 17:56 - 2014-04-30 03:41 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-08-14 17:56 - 2014-04-30 03:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\agilevpn.sys
2014-08-14 17:56 - 2014-04-30 03:41 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vwifimp.sys
2014-08-14 17:56 - 2014-04-30 02:45 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe
2014-08-14 17:56 - 2014-04-30 01:48 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2014-08-14 17:56 - 2014-04-30 01:24 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-08-14 17:56 - 2014-04-30 01:23 - 00353280 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2014-08-14 17:56 - 2014-04-30 01:23 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-08-14 17:56 - 2014-04-30 01:23 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll
2014-08-14 17:56 - 2014-04-30 01:14 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2014-08-14 17:56 - 2014-04-30 00:59 - 01063424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-08-14 17:56 - 2014-04-30 00:46 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2014-08-14 17:56 - 2014-04-30 00:46 - 00229888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-08-14 17:56 - 2014-04-30 00:46 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-08-14 17:56 - 2014-04-30 00:45 - 00062976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc.dll
2014-08-14 17:56 - 2014-04-30 00:42 - 00403968 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2014-08-14 17:56 - 2014-04-28 19:40 - 00721408 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2014-08-14 17:56 - 2014-04-26 19:03 - 02140888 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2014-08-14 17:56 - 2014-04-26 17:14 - 02144984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2014-08-14 17:56 - 2014-04-26 13:39 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll
2014-08-14 17:56 - 2014-04-14 06:37 - 02125344 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2014-08-14 17:56 - 2014-04-14 05:08 - 01797896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2014-08-14 17:56 - 2014-04-14 02:18 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d8thk.dll
2014-08-14 17:56 - 2014-04-09 03:11 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-08-14 17:56 - 2014-04-09 02:20 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-08-14 11:42 - 2014-08-14 11:42 - 00000000 ____D () C:\Users\Usuário Padrão\AppData\Roaming\TuneUp Software
2014-08-14 11:42 - 2014-08-14 11:42 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software
2014-08-14 11:42 - 2014-08-14 11:42 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software
2014-08-13 19:12 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\Documents\My Games
2014-08-13 19:12 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2014-08-13 19:12 - 2014-08-13 19:12 - 00001290 _____ () C:\Users\Alex\Desktop\Sid Meier's Civilization 5.lnk
2014-08-13 19:12 - 2014-08-13 19:12 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Sid Meier's Civilization 5
2014-08-13 18:35 - 2014-08-13 18:44 - 00000000 ____D () C:\Program Files (x86)\R.G. Mechanics
2014-08-13 17:29 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\Downloads\[R.G. Mechanics] Civilization 5 GOTY
2014-08-13 03:54 - 2014-08-13 03:55 - 77719596 _____ () C:\Users\Alex\Downloads\10 - Minimal Criminal - Mary Poppin'  Pills.wav
2014-08-13 03:26 - 2014-08-13 03:26 - 00271541 _____ () C:\Users\Alex\Downloads\154884-vlt_deepdark.vlt
2014-08-12 21:24 - 2014-08-12 21:28 - 90194132 _____ () C:\Users\Alex\Downloads\A.L.X.S. - Dragon Fly (Monu remix)_UNMASTERED.wav
2014-08-12 20:57 - 2014-08-12 20:57 - 00000000 ____D () C:\Users\Alex\Documents\Command & Conquer 3 Tiberium Wars
2014-08-12 20:54 - 2014-08-12 20:56 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Command & Conquer 3 Tiberium Wars
2014-08-12 20:45 - 2014-08-12 20:45 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-08-12 05:28 - 2014-08-12 05:28 - 00000448 _____ () C:\Users\Alex\Desktop\My Computer - Atalho.lnk
2014-08-12 04:58 - 2014-08-12 04:58 - 00000000 ____D () C:\Users\Alex\Desktop\Muic
2014-08-12 04:57 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\AppData\Local\Macroplant,_LLC
2014-08-12 04:55 - 2014-08-12 05:08 - 00000000 ____D () C:\Users\Alex\AppData\Local\clear.fi
2014-08-12 04:55 - 2014-08-12 04:55 - 00000000 ____D () C:\Users\Alex\AppData\Local\Acer
2014-08-12 04:10 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-08-12 04:09 - 2014-08-25 17:10 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-08-12 04:08 - 2014-08-26 13:39 - 00000000 ____D () C:\Program Files (x86)\Sharepod
2014-08-11 16:31 - 2014-08-11 16:31 - 00000000 ____D () C:\Users\Alex\Documents\theHunter
2014-08-11 16:30 - 2014-08-11 16:30 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\theHunter
2014-08-11 16:30 - 2014-08-11 16:30 - 00000000 ____D () C:\Users\Alex\AppData\Local\theHunter
2014-08-11 16:26 - 2014-08-11 16:26 - 00000097 _____ () C:\Users\Alex\AppData\Roaming\LauncherSettings_live.cfg
2014-08-11 16:23 - 2014-08-11 16:23 - 00000000 ____D () C:\Users\Todos os Usuários\Hunter
2014-08-11 16:23 - 2014-08-11 16:23 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\theHunterSteam
2014-08-11 16:23 - 2014-08-11 16:23 - 00000000 ____D () C:\ProgramData\Hunter
2014-08-11 16:23 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2014-08-11 16:23 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2014-08-11 16:23 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2014-08-11 16:23 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2014-08-11 16:23 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2014-08-11 16:23 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2014-08-11 16:23 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2014-08-11 16:23 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2014-08-11 16:23 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2014-08-11 16:23 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2014-08-11 16:23 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2014-08-11 16:23 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2014-08-11 16:23 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2014-08-11 16:23 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2014-08-11 16:23 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2014-08-11 16:23 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2014-08-11 16:23 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2014-08-11 16:23 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2014-08-11 16:23 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2014-08-11 16:23 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2014-08-11 16:23 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2014-08-11 16:23 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2014-08-11 16:23 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2014-08-11 16:23 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2014-08-11 16:23 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2014-08-11 16:23 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2014-08-11 16:23 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2014-08-11 16:23 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2014-08-11 16:23 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2014-08-11 16:23 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2014-08-11 16:23 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2014-08-11 16:23 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2014-08-11 16:23 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2014-08-11 16:23 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2014-08-11 16:23 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2014-08-11 16:23 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2014-08-11 16:23 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2014-08-11 16:23 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2014-08-11 16:23 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2014-08-11 16:23 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2014-08-11 16:23 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2014-08-11 16:23 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2014-08-11 16:23 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2014-08-11 16:23 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2014-08-11 16:23 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2014-08-11 16:23 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2014-08-11 16:23 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2014-08-11 16:23 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2014-08-11 16:23 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2014-08-11 16:23 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2014-08-11 16:23 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2014-08-11 16:23 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2014-08-11 16:23 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2014-08-11 16:23 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2014-08-11 16:23 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2014-08-11 16:23 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2014-08-11 16:23 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2014-08-11 16:23 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2014-08-11 16:23 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2014-08-11 16:23 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2014-08-11 16:23 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2014-08-11 16:23 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2014-08-11 16:23 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2014-08-11 16:23 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2014-08-11 16:23 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2014-08-11 16:23 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2014-08-11 16:23 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2014-08-11 16:23 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2014-08-11 16:23 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2014-08-11 16:23 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2014-08-11 16:23 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2014-08-11 16:23 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2014-08-11 16:23 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2014-08-11 16:23 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2014-08-11 16:23 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2014-08-11 16:23 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2014-08-11 16:23 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2014-08-11 16:23 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2014-08-11 16:23 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2014-08-11 16:23 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2014-08-11 16:23 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2014-08-11 16:23 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2014-08-11 16:23 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2014-08-11 16:23 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2014-08-11 16:23 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2014-08-11 16:23 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2014-08-11 16:23 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2014-08-11 16:23 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2014-08-11 16:23 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2014-08-11 16:23 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2014-08-11 16:23 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2014-08-11 16:23 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2014-08-11 16:23 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2014-08-11 16:23 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2014-08-11 16:23 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2014-08-11 16:23 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2014-08-11 16:23 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2014-08-11 16:23 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2014-08-11 16:23 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2014-08-11 16:23 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2014-08-11 16:23 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2014-08-11 16:23 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2014-08-11 16:23 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2014-08-11 16:23 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2014-08-11 16:23 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2014-08-11 16:23 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2014-08-11 16:23 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2014-08-11 16:23 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2014-08-11 16:23 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2014-08-11 16:23 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2014-08-11 16:23 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2014-08-11 16:23 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2014-08-11 16:23 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2014-08-11 16:23 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2014-08-11 16:23 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2014-08-11 16:23 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2014-08-11 16:23 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2014-08-11 16:23 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2014-08-11 16:23 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2014-08-11 16:23 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2014-08-11 16:23 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2014-08-11 16:23 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2014-08-11 16:23 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2014-08-11 16:23 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2014-08-11 16:23 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2014-08-11 16:23 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2014-08-11 16:23 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2014-08-11 16:23 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2014-08-11 16:23 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2014-08-11 16:23 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2014-08-11 16:23 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2014-08-11 16:23 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2014-08-11 16:23 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2014-08-11 16:23 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2014-08-11 16:23 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2014-08-11 16:23 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2014-08-11 16:23 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2014-08-11 16:23 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2014-08-11 16:23 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2014-08-11 16:23 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2014-08-11 16:23 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2014-08-11 16:23 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2014-08-11 16:23 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2014-08-11 16:23 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2014-08-11 16:23 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2014-08-11 16:23 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2014-08-11 16:23 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2014-08-11 16:23 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2014-08-11 16:23 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2014-08-11 16:23 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2014-08-11 16:22 - 2014-08-12 20:51 - 00042250 _____ () C:\Windows\DirectX.log
2014-08-11 16:22 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2014-08-11 16:22 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2014-08-11 16:22 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2014-08-11 16:22 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2014-08-11 16:22 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2014-08-11 16:22 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2014-08-11 16:22 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2014-08-11 16:22 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2014-08-11 16:22 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2014-08-11 16:22 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2014-08-11 16:22 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2014-08-11 16:22 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2014-08-11 16:22 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2014-08-11 16:22 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2014-08-11 16:22 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2014-08-11 16:22 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2014-08-11 16:22 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2014-08-11 16:22 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2014-08-10 16:52 - 2014-08-10 16:52 - 00000000 ____D () C:\Users\Alex\Documents\Bluetooth Folder
2014-08-10 12:19 - 2014-08-25 17:09 - 00000000 ____D () C:\Windows\Minidump
2014-08-10 12:19 - 2014-08-10 12:19 - 339680009 _____ () C:\Windows\MEMORY.DMP
2014-08-10 12:19 - 2014-08-10 12:19 - 00286256 _____ () C:\Windows\Minidump\081014-42078-01.dmp
2014-08-10 02:33 - 2014-08-10 02:38 - 00000000 ____D () C:\Users\Alex\Desktop\VSTs
2014-08-10 02:24 - 2014-08-27 04:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
2014-08-10 02:24 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Todos os Usuários\Native Instruments
2014-08-10 02:24 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Native Instruments
2014-08-09 22:29 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Todos os Usuários\Avg_Update_0614a
2014-08-09 22:29 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Avg_Update_0614a
2014-08-09 22:29 - 2014-08-09 22:29 - 00000332 _____ () C:\Windows\Tasks\0614aUpdateInfo.job
2014-08-09 18:52 - 2014-08-09 18:57 - 00013893 ____H () C:\Users\Alex\Documents\~WRL3332.tmp
2014-08-09 04:54 - 2014-08-22 06:36 - 00000000 ____D () C:\Users\Alex\Desktop\Ableton
2014-08-09 03:01 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smith Micro
2014-08-09 03:01 - 2014-08-09 03:01 - 00000000 ____D () C:\Program Files (x86)\Smith Micro
2014-08-09 02:48 - 2014-08-09 02:48 - 00001107 _____ () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Downloads.lnk
2014-08-09 02:39 - 2014-08-23 11:25 - 00000000 ____D () C:\Users\Alex\Documents\Native Instruments
2014-08-09 02:39 - 2014-08-09 02:39 - 00000000 ____D () C:\Users\Alex\AppData\Local\Native Instruments
2014-08-09 02:31 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\Desktop\Program
2014-08-09 02:25 - 2014-08-13 17:17 - 00000000 ____D () C:\Users\Alex\Desktop\Samples
2014-08-09 02:24 - 2014-08-27 04:25 - 00000000 ____D () C:\Program Files\Native Instruments
2014-08-09 02:24 - 2014-08-25 17:10 - 00000000 ____D () C:\Program Files\Common Files\Native Instruments
2014-08-09 02:22 - 2014-08-12 03:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicDisc
2014-08-09 02:15 - 2014-08-23 11:55 - 81018074 _____ () C:\Users\Alex\Downloads\psycid.wav
2014-08-09 02:12 - 2014-08-09 02:12 - 48561932 _____ () C:\Users\Alex\Downloads\Gimme Shelter.wav
2014-08-09 02:03 - 2014-08-09 02:06 - 87433088 _____ () C:\Users\Alex\Downloads\Bad Mother .wav
2014-08-09 01:57 - 2014-08-09 01:58 - 72817964 _____ () C:\Users\Alex\Downloads\ALXS - Evil Dead Update Wednesday.wav
2014-08-09 01:50 - 2014-08-09 01:50 - 89652752 _____ () C:\Users\Alex\Downloads\Minimal Techno (1).wav
2014-08-09 01:40 - 2014-08-23 11:49 - 72441962 _____ () C:\Users\Alex\Downloads\Dragonfly.wav
2014-08-09 01:15 - 2014-08-09 01:15 - 00000000 ____D () C:\Users\Todos os Usuários\Ableton
2014-08-09 01:15 - 2014-08-09 01:15 - 00000000 ____D () C:\ProgramData\Ableton
2014-08-09 01:14 - 2014-08-09 01:15 - 00000000 ____D () C:\Users\Alex\Documents\Ableton
2014-08-09 01:14 - 2014-08-09 01:14 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Ableton
2014-08-08 18:47 - 2014-08-08 18:51 - 00000000 ____D () C:\Users\Alex\Desktop\Massive Presets
2014-08-08 18:45 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-08-08 18:45 - 2014-08-25 17:10 - 00000000 ____D () C:\Program Files\7-Zip
2014-08-08 17:58 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2014-08-08 17:58 - 2014-08-08 17:58 - 00000000 ____D () C:\Program Files (x86)\Elaborate Bytes
2014-08-08 17:56 - 2014-08-08 17:58 - 05629238 _____ () C:\Users\Alex\Downloads\Massive - 11.500 Presets [.nmsv Massive 1.3+][packet-dada].7z
2014-08-08 17:43 - 2014-08-08 21:54 - 00000000 ____D () C:\Users\Alex\Downloads\Vengeance Sounds Pack
2014-08-08 16:26 - 2014-08-27 16:26 - 00000902 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-08 16:26 - 2014-08-18 01:17 - 00003790 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-08 16:12 - 2014-08-27 02:19 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-08 16:12 - 2014-08-25 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-08 15:23 - 2014-08-08 15:23 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\AVG2014
2014-08-08 15:20 - 2014-08-08 15:20 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\TuneUp Software
2014-08-08 15:17 - 2014-08-26 14:00 - 00000000 ____D () C:\Users\Todos os Usuários\AVG2014
2014-08-08 15:17 - 2014-08-26 14:00 - 00000000 ____D () C:\ProgramData\AVG2014
2014-08-08 15:17 - 2014-08-26 13:58 - 00000000 ___HD () C:\$AVG
2014-08-08 15:08 - 2014-08-27 15:28 - 00000000 ____D () C:\Users\Todos os Usuários\MFAData
2014-08-08 15:08 - 2014-08-27 15:28 - 00000000 ____D () C:\ProgramData\MFAData
2014-08-08 15:08 - 2014-08-25 16:28 - 00000000 ____D () C:\Users\Alex\AppData\Local\Avg2014
2014-08-08 15:08 - 2014-08-08 15:08 - 00000000 ____D () C:\Users\Alex\AppData\Local\MFAData
2014-08-08 15:06 - 2014-08-08 15:06 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\WildTangent
2014-08-08 06:00 - 2014-01-19 04:38 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-07 14:15 - 2014-08-07 14:15 - 00013517 ____H () C:\Users\Alex\Documents\~WRL1525.tmp
2014-08-07 09:17 - 2014-08-27 01:42 - 00000000 ____D () C:\Users\Alex\Documents\PDFs
2014-08-06 16:29 - 2014-08-06 16:29 - 00000900 _____ () C:\Users\Alex\Desktop\Photos.lnk
2014-08-04 05:59 - 2014-08-04 05:59 - 00009204 _____ () C:\Users\Alex\Downloads\Kingsway Upholstery.odt
2014-08-03 20:08 - 2014-08-03 20:08 - 84213450 _____ () C:\Users\Alex\Downloads\DONT SAY SORRY MASTER (1).wav
2014-08-01 13:16 - 2014-08-01 13:16 - 89652752 _____ () C:\Users\Alex\Downloads\Minimal Techno.wav
2014-08-01 13:09 - 2014-08-23 11:48 - 82543728 _____ () C:\Users\Alex\Downloads\Ibogaine.wav
2014-08-01 11:17 - 2014-08-01 11:17 - 00000911 _____ () C:\Users\Alex\Desktop\Documents.lnk
2014-07-30 16:43 - 2014-08-23 01:11 - 00241152 ___SH () C:\Users\Alex\Downloads\Thumbs.db
2014-07-30 16:03 - 2014-08-27 16:50 - 00000000 ___RD () C:\Users\Alex\Dropbox
2014-07-30 16:03 - 2014-08-14 20:43 - 00001064 _____ () C:\Users\Alex\Desktop\Dropbox.lnk
2014-07-30 16:02 - 2014-08-25 17:10 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-07-30 15:30 - 2014-07-30 15:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-30 15:28 - 2012-08-21 14:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2014-07-30 15:27 - 2014-07-30 15:28 - 00000000 ____D () C:\Users\Todos os Usuários\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-07-30 15:27 - 2014-07-30 15:28 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-07-30 15:27 - 2014-07-30 15:28 - 00000000 ____D () C:\Program Files\iTunes
2014-07-30 15:27 - 2014-07-30 15:27 - 00000000 ____D () C:\Program Files\iPod
2014-07-30 14:00 - 2014-07-30 14:00 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-07-30 14:00 - 2014-07-30 14:00 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-07-30 13:59 - 2014-07-31 09:00 - 00000000 ____D () C:\Users\Todos os Usuários\Adobe
2014-07-30 13:59 - 2014-07-31 09:00 - 00000000 ____D () C:\ProgramData\Adobe
2014-07-30 12:33 - 2014-07-30 12:44 - 00000259 _____ () C:\Users\Alex\Desktop\meta data.txt
2014-07-30 12:16 - 2014-07-30 15:35 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Apple Computer
2014-07-30 12:16 - 2014-07-30 12:16 - 00000000 ____D () C:\Users\Alex\AppData\Local\Apple Computer
2014-07-30 12:15 - 2014-08-25 17:11 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-07-30 12:15 - 2014-07-30 12:15 - 00002535 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\Users\Todos os Usuários\Apple Computer
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\Users\Alex\AppData\Local\Apple
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-07-30 12:13 - 2014-07-30 12:13 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-07-30 12:12 - 2014-08-25 17:10 - 00000000 ____D () C:\Program Files\Bonjour
2014-07-30 12:12 - 2014-07-30 12:15 - 00000000 ____D () C:\Users\Todos os Usuários\Apple
2014-07-30 12:12 - 2014-07-30 12:15 - 00000000 ____D () C:\ProgramData\Apple
2014-07-30 12:12 - 2014-07-30 12:13 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-07-29 13:02 - 2014-07-30 14:25 - 00000000 ___RD () C:\Users\Alex\Dropbox (Old)
2014-07-29 12:56 - 2014-08-27 16:50 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Dropbox
2014-07-29 02:07 - 2014-07-29 02:27 - 733593600 _____ () C:\Users\Alex\Downloads\Don't.Look.Now.[1973].DVDrip[Eng].avi
2014-07-28 19:24 - 2014-08-25 17:09 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-28 17:38 - 2014-07-28 17:38 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-07-28 15:40 - 2014-08-05 14:50 - 00128512 ___SH () C:\Users\Alex\Desktop\Thumbs.db
2014-07-28 12:32 - 2014-07-28 12:32 - 00711251 _____ () C:\Users\Alex\Downloads\alexsims1989 bank statement 2.jpeg
2014-07-28 12:31 - 2014-07-28 12:31 - 00850450 _____ () C:\Users\Alex\Downloads\alexsims1989 counterpart licence.jpeg
2014-07-28 00:55 - 2014-08-27 04:47 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\vlc
2014-07-28 00:53 - 2014-07-28 00:53 - 00001086 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-07-28 00:53 - 2014-07-28 00:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-07-28 00:53 - 2014-07-28 00:53 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2021-10-21 10:36 - 2014-01-08 17:33 - 00000852 _____ () C:\Windows\system32\Drivers\RTKHDRC.dat
2021-10-04 04:34 - 2014-01-08 17:33 - 00000712 _____ () C:\Windows\system32\Drivers\RTMICEQ0.dat
2014-08-27 17:04 - 2014-08-27 03:07 - 00020794 _____ () C:\Users\Alex\Desktop\FRST.txt
2014-08-27 17:04 - 2014-08-27 03:06 - 00000000 ____D () C:\FRST
2014-08-27 17:00 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\sru
2014-08-27 16:57 - 2014-07-21 11:52 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-27 16:54 - 2014-07-21 11:52 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-85189985-2318871348-3638756338-1001
2014-08-27 16:50 - 2014-07-30 16:03 - 00000000 ___RD () C:\Users\Alex\Dropbox
2014-08-27 16:50 - 2014-07-29 12:56 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Dropbox
2014-08-27 16:49 - 2014-08-23 20:40 - 00000000 ____D () C:\Users\Alex\Desktop\Tunes
2014-08-27 16:49 - 2014-07-21 11:50 - 00000000 ___DO () C:\Users\Alex\SkyDrive
2014-08-27 16:48 - 2014-07-21 11:52 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-27 16:45 - 2013-08-22 11:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-27 16:45 - 2013-08-22 11:44 - 00477224 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 16:44 - 2013-09-09 07:17 - 00106250 _____ () C:\Windows\PFRO.log
2014-08-27 16:43 - 2013-08-22 10:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-08-27 16:26 - 2014-08-08 16:26 - 00000902 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-27 15:51 - 2014-08-27 15:51 - 00000127 _____ () C:\Users\Alex\Desktop\ckfiles.txt
2014-08-27 15:28 - 2014-08-08 15:08 - 00000000 ____D () C:\Users\Todos os Usuários\MFAData
2014-08-27 15:28 - 2014-08-08 15:08 - 00000000 ____D () C:\ProgramData\MFAData
2014-08-27 15:00 - 2014-08-23 14:40 - 00000000 ____D () C:\Users\Alex\AppData\Local\Extion
2014-08-27 14:47 - 2014-07-21 11:51 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{D39C622B-1408-4D71-B205-685E3723D306}
2014-08-27 14:41 - 2014-08-23 14:40 - 00000000 ____D () C:\Users\Alex\AppData\Local\Ipsoft
2014-08-27 13:56 - 2014-01-08 17:15 - 01971311 _____ () C:\Windows\WindowsUpdate.log
2014-08-27 12:39 - 2014-08-26 13:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-08-27 04:47 - 2014-07-28 00:55 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\vlc
2014-08-27 04:25 - 2014-08-10 02:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
2014-08-27 04:25 - 2014-08-09 02:24 - 00000000 ____D () C:\Program Files\Native Instruments
2014-08-27 03:52 - 2014-08-27 03:52 - 00828425 _____ () C:\Users\Alex\Desktop\ckfiles111.txt
2014-08-27 03:46 - 2014-08-27 03:46 - 00468480 _____ () C:\Users\Alex\Desktop\CKScanner.exe
2014-08-27 03:36 - 2014-08-27 03:36 - 00468480 _____ () C:\Users\Alex\Downloads\CKScanner.exe
2014-08-27 03:10 - 2014-08-27 03:09 - 00049697 _____ () C:\Users\Alex\Desktop\Addition.txt
2014-08-27 03:05 - 2014-08-27 03:05 - 02103296 _____ (Farbar) C:\Users\Alex\Downloads\FRST64.exe
2014-08-27 03:05 - 2014-08-27 03:05 - 02103296 _____ (Farbar) C:\Users\Alex\Desktop\FRST64.exe
2014-08-27 02:19 - 2014-08-08 16:12 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-27 01:42 - 2014-08-07 09:17 - 00000000 ____D () C:\Users\Alex\Documents\PDFs
2014-08-26 22:32 - 2014-07-21 16:01 - 00000000 ____D () C:\Users\Alex\AppData\Local\Deployment
2014-08-26 22:22 - 2014-08-26 13:35 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Everything
2014-08-26 21:51 - 2014-08-26 21:51 - 00211128 _____ () C:\Users\Alex\Downloads\OTLtuesday.txt
2014-08-26 21:46 - 2014-08-26 21:46 - 00095922 _____ () C:\Users\Alex\Downloads\Extras.Txt
2014-08-26 21:45 - 2014-08-26 21:45 - 00211128 _____ () C:\Users\Alex\Downloads\OTL.Txt
2014-08-26 21:24 - 2014-08-26 21:20 - 00602112 _____ (OldTimer Tools) C:\Users\Alex\Downloads\OTL.exe
2014-08-26 18:47 - 2014-08-26 18:46 - 101616092 _____ () C:\Users\Alex\Downloads\Unknown-Artists--Bass--Original-Mix-.wav
2014-08-26 17:15 - 2014-08-26 17:15 - 00000644 _____ () C:\Users\Alex\Desktop\virus.txt
2014-08-26 14:11 - 2013-08-22 10:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-08-26 14:01 - 2014-07-21 14:47 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\uTorrent
2014-08-26 14:00 - 2014-08-08 15:17 - 00000000 ____D () C:\Users\Todos os Usuários\AVG2014
2014-08-26 14:00 - 2014-08-08 15:17 - 00000000 ____D () C:\ProgramData\AVG2014
2014-08-26 13:59 - 2013-08-22 12:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-08-26 13:58 - 2014-08-08 15:17 - 00000000 ___HD () C:\$AVG
2014-08-26 13:57 - 2014-08-26 13:57 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-08-26 13:54 - 2014-08-26 13:51 - 00000000 ____D () C:\Users\Alex\Downloads\AVG Antivirus 2014 x64 374 Days
2014-08-26 13:46 - 2014-08-26 13:46 - 00001450 _____ () C:\Users\Alex\Desktop\Everything - Atalho.lnk
2014-08-26 13:41 - 2014-08-26 13:41 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything
2014-08-26 13:41 - 2014-08-26 13:34 - 00000000 ____D () C:\Program Files (x86)\Everything
2014-08-26 13:39 - 2014-08-12 04:08 - 00000000 ____D () C:\Program Files (x86)\Sharepod
2014-08-26 13:34 - 2014-08-26 13:33 - 00473291 _____ () C:\Users\Alex\Downloads\Everything-1.3.4.686.x86-Setup.exe
2014-08-26 01:37 - 2014-07-22 13:17 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Spotify
2014-08-25 23:45 - 2014-08-25 23:45 - 00000000 ____D () C:\Windows\System32\Tasks\GenericSettingsHandler
2014-08-25 21:53 - 2014-07-22 13:18 - 00000000 ____D () C:\Users\Alex\AppData\Local\Spotify
2014-08-25 19:27 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-25 17:11 - 2014-08-23 14:17 - 00000000 ____D () C:\Program Files (x86)\iExplorer
2014-08-25 17:11 - 2014-07-30 12:15 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-08-25 17:11 - 2013-09-09 07:36 - 00000000 ____D () C:\Program Files (x86)\Acer
2014-08-25 17:10 - 2014-08-23 13:18 - 00000000 ____D () C:\Users\Alex\AppData\Local\Macroplant_LLC
2014-08-25 17:10 - 2014-08-23 13:14 - 00000000 ____D () C:\Users\Alex\Downloads\Fracture (2007) [1080p]
2014-08-25 17:10 - 2014-08-23 12:13 - 00000000 __HDC () C:\Users\Todos os Usuários\{ACF12395-778E-44F0-A811-C99F334A83F5}
2014-08-25 17:10 - 2014-08-23 12:13 - 00000000 __HDC () C:\ProgramData\{ACF12395-778E-44F0-A811-C99F334A83F5}
2014-08-25 17:10 - 2014-08-23 12:08 - 00000000 __HDC () C:\Users\Todos os Usuários\{BD26D777-CA21-4BDD-A581-6BCFE4F0F941}
2014-08-25 17:10 - 2014-08-23 12:08 - 00000000 __HDC () C:\ProgramData\{BD26D777-CA21-4BDD-A581-6BCFE4F0F941}
2014-08-25 17:10 - 2014-08-23 12:07 - 00000000 __HDC () C:\Users\Todos os Usuários\{C6A355F5-168B-4EEC-AB7C-75594F783EDB}
2014-08-25 17:10 - 2014-08-23 12:07 - 00000000 __HDC () C:\ProgramData\{C6A355F5-168B-4EEC-AB7C-75594F783EDB}
2014-08-25 17:10 - 2014-08-23 05:51 - 00000000 ____D () C:\Users\Alex\Downloads\Native Instruments Traktor Pro 2 v2.6.8 Incl. Patch-Tracer [deepstatus][h33t][1337x][flashtorrents]
2014-08-25 17:10 - 2014-08-23 01:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-08-25 17:10 - 2014-08-23 01:27 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-08-25 17:10 - 2014-08-23 00:09 - 00000000 ____D () C:\Users\Alex\Downloads\Angel.Heart.1987.720p.BRRip.x264-x0r
2014-08-25 17:10 - 2014-08-22 05:56 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Synapse Audio
2014-08-25 17:10 - 2014-08-22 02:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2014-08-25 17:10 - 2014-08-22 02:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-08-25 17:10 - 2014-08-22 02:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
2014-08-25 17:10 - 2014-08-22 02:55 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-08-25 17:10 - 2014-08-22 02:53 - 00000000 ____D () C:\Users\Todos os Usuários\Microsoft Help
2014-08-25 17:10 - 2014-08-22 02:53 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-25 17:10 - 2014-08-22 00:55 - 00000000 ____D () C:\Users\Alex\Downloads\Microsoft Office 2010 Professional Plus x86
2014-08-25 17:10 - 2014-08-22 00:14 - 00000000 ____D () C:\Users\Alex\AppData\Local\Microsoft Help
2014-08-25 17:10 - 2014-08-18 01:45 - 00000000 ____D () C:\Users\Alex\AppData\Local\Intel_Corporation
2014-08-25 17:10 - 2014-08-18 01:17 - 00000000 ____D () C:\Users\Todos os Usuários\McAfee Security Scan
2014-08-25 17:10 - 2014-08-18 01:17 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-08-25 17:10 - 2014-08-13 19:12 - 00000000 ____D () C:\Users\Alex\Documents\My Games
2014-08-25 17:10 - 2014-08-13 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2014-08-25 17:10 - 2014-08-13 17:29 - 00000000 ____D () C:\Users\Alex\Downloads\[R.G. Mechanics] Civilization 5 GOTY
2014-08-25 17:10 - 2014-08-12 04:57 - 00000000 ____D () C:\Users\Alex\AppData\Local\Macroplant,_LLC
2014-08-25 17:10 - 2014-08-12 04:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-08-25 17:10 - 2014-08-12 04:09 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-08-25 17:10 - 2014-08-10 02:24 - 00000000 ____D () C:\Users\Todos os Usuários\Native Instruments
2014-08-25 17:10 - 2014-08-10 02:24 - 00000000 ____D () C:\ProgramData\Native Instruments
2014-08-25 17:10 - 2014-08-09 22:29 - 00000000 ____D () C:\Users\Todos os Usuários\Avg_Update_0614a
2014-08-25 17:10 - 2014-08-09 22:29 - 00000000 ____D () C:\ProgramData\Avg_Update_0614a
2014-08-25 17:10 - 2014-08-09 03:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smith Micro
2014-08-25 17:10 - 2014-08-09 02:31 - 00000000 ____D () C:\Users\Alex\Desktop\Program
2014-08-25 17:10 - 2014-08-09 02:24 - 00000000 ____D () C:\Program Files\Common Files\Native Instruments
2014-08-25 17:10 - 2014-08-08 18:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-08-25 17:10 - 2014-08-08 18:45 - 00000000 ____D () C:\Program Files\7-Zip
2014-08-25 17:10 - 2014-08-08 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2014-08-25 17:10 - 2014-08-08 16:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-25 17:10 - 2014-07-30 16:02 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-25 17:10 - 2014-07-30 12:12 - 00000000 ____D () C:\Program Files\Bonjour
2014-08-25 17:10 - 2014-07-21 14:30 - 00000000 ___RD () C:\Users\Alex\Documents\Portuguese
2014-08-25 17:10 - 2014-07-21 11:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-25 17:10 - 2014-01-08 17:52 - 00000000 ____D () C:\Users\Todos os Usuários\Norton
2014-08-25 17:10 - 2014-01-08 17:52 - 00000000 ____D () C:\ProgramData\Norton
2014-08-25 17:10 - 2013-09-09 07:28 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-25 17:10 - 2013-09-09 07:22 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-08-25 17:10 - 2013-08-22 12:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-08-25 17:10 - 2013-08-22 12:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-08-25 17:09 - 2014-08-22 02:56 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-08-25 17:09 - 2014-08-10 12:19 - 00000000 ____D () C:\Windows\Minidump
2014-08-25 17:09 - 2014-07-28 19:24 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-25 17:09 - 2014-01-08 22:58 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2014-08-25 17:09 - 2013-08-22 16:12 - 00000000 ____D () C:\Windows\ShellNew
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 __RSD () C:\Windows\Media
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ___RD () C:\Windows\ToastData
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\SystemResources
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\WinMetadata
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\WindowsInternal.Inbox.Shared
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\WindowsInternal.Inbox.Media.Shared
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\MUI
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\rescache
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\MediaViewer
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\Globalization
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\FileManager
2014-08-25 17:09 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\Camera
2014-08-25 17:09 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\Sysprep
2014-08-25 17:09 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\servicing
2014-08-25 16:53 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\registration
2014-08-25 16:28 - 2014-08-08 15:08 - 00000000 ____D () C:\Users\Alex\AppData\Local\Avg2014
2014-08-25 15:40 - 2014-08-25 15:40 - 00517120 _____ (Microsoft Corporation) C:\Users\Alex\Downloads\settingsynchost.exe
2014-08-25 15:05 - 2014-08-25 15:05 - 00000000 ____D () C:\Users\Alex\AppData\Local\BMExplorer
2014-08-23 14:40 - 2014-08-23 14:40 - 00000000 __SHD () C:\Users\Alex\AppData\Local\EmieUserList
2014-08-23 14:40 - 2014-08-23 14:40 - 00000000 __SHD () C:\Users\Alex\AppData\Local\EmieSiteList
2014-08-23 13:27 - 2014-07-21 11:45 - 00000000 ____D () C:\Users\Alex
2014-08-23 12:08 - 2014-08-23 12:08 - 00001114 _____ () C:\Users\Public\Desktop\Controller Editor.lnk
2014-08-23 12:07 - 2014-08-23 06:05 - 00001079 _____ () C:\Users\Public\Desktop\Service Center.lnk
2014-08-23 11:55 - 2014-08-09 02:15 - 81018074 _____ () C:\Users\Alex\Downloads\psycid.wav
2014-08-23 11:49 - 2014-08-09 01:40 - 72441962 _____ () C:\Users\Alex\Downloads\Dragonfly.wav
2014-08-23 11:48 - 2014-08-01 13:09 - 82543728 _____ () C:\Users\Alex\Downloads\Ibogaine.wav
2014-08-23 11:34 - 2014-08-22 08:03 - 31922338 ____T () C:\Users\Alex\Desktop\Bomb.wav
2014-08-23 11:25 - 2014-08-09 02:39 - 00000000 ____D () C:\Users\Alex\Documents\Native Instruments
2014-08-23 11:22 - 2014-08-23 11:22 - 00000000 ____D () C:\Users\Alex\AppData\Local\Spoon
2014-08-23 01:27 - 2014-08-18 01:17 - 00001951 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-08-23 01:11 - 2014-07-30 16:43 - 00241152 ___SH () C:\Users\Alex\Downloads\Thumbs.db
2014-08-22 06:36 - 2014-08-09 04:54 - 00000000 ____D () C:\Users\Alex\Desktop\Ableton
2014-08-22 06:21 - 2014-08-22 06:17 - 11064240 _____ () C:\Users\Alex\Downloads\Bomb Decent Project.rar
2014-08-22 05:56 - 2014-08-22 05:56 - 00000000 ____D () C:\Program Files (x86)\Steinberg
2014-08-22 02:57 - 2014-08-22 02:57 - 00000000 ____D () C:\Windows\PCHEALTH
2014-08-22 02:57 - 2014-08-22 02:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Sync Framework
2014-08-22 02:57 - 2014-08-22 02:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-08-22 02:57 - 2014-08-22 02:53 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-08-22 02:54 - 2014-08-22 02:54 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-08-22 02:54 - 2013-08-22 10:25 - 00000199 _____ () C:\Windows\win.ini
2014-08-22 02:53 - 2014-08-22 02:53 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services
2014-08-22 02:52 - 2014-08-22 02:52 - 00000000 __RHD () C:\MSOCache
2014-08-22 02:18 - 2014-08-22 02:09 - 81604866 _____ () C:\Users\Alex\Downloads\Alex Carroll - Only Happy When It Rains_[MASTERED].wav
2014-08-22 00:50 - 2014-07-22 09:50 - 00004952 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for ALEX-Alex Alex
2014-08-21 23:31 - 2014-08-21 23:31 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2014-08-21 23:31 - 2014-08-21 23:31 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-08-21 23:27 - 2014-08-21 23:21 - 15038405 _____ () C:\Users\Alex\Downloads\Synapse.Audio.DUNE.VSTi.v1.4.0.x86.x64.WORKiNG-ASSiGN.rar
2014-08-20 06:21 - 2014-08-20 06:20 - 87297164 _____ () C:\Users\Alex\Downloads\12_Henix-R - Melodic Sensation_MASTER.wav
2014-08-20 06:21 - 2014-08-20 06:20 - 81145856 _____ () C:\Users\Alex\Downloads\14_CupCake - Slowing Down_MASTER.wav
2014-08-20 06:20 - 2014-08-20 06:19 - 90031782 _____ () C:\Users\Alex\Downloads\10.Mahruna - Facelift - WAV.wav
2014-08-20 06:20 - 2014-08-20 06:19 - 85765488 _____ () C:\Users\Alex\Downloads\09-D_Vision -  Forget The Rules(mastering by Tim Schult).wav
2014-08-20 06:16 - 2014-08-20 06:15 - 67741696 _____ () C:\Users\Alex\Downloads\02_Toxic Universe - Wild Orchid 2_MASTER.wav
2014-08-20 06:15 - 2014-08-20 05:57 - 56743186 _____ () C:\Users\Alex\Downloads\Inception - Audio Spray (2012).rar
2014-08-20 06:13 - 2014-08-20 06:12 - 117739184 _____ () C:\Users\Alex\Downloads\Ranji - Speed of sound Master.wav
2014-08-20 06:12 - 2014-08-20 06:11 - 61691768 _____ () C:\Users\Alex\Downloads\Old_Friend_Master_16bit_44.1khz.wav
2014-08-18 19:02 - 2014-08-18 19:02 - 00000000 ____D () C:\Users\Alex\AppData\Local\Adobe
2014-08-18 04:04 - 2014-08-18 04:04 - 00001814 _____ () C:\Users\Alex\Desktop\Surgeon Simulator 2013 Steam Edition Game Two.lnk
2014-08-18 04:02 - 2014-08-18 04:02 - 00000000 ____D () C:\Games
2014-08-18 02:28 - 2014-08-18 02:13 - 403326231 _____ (Cat-A-Cat ) C:\Users\Alex\Downloads\Surgeon_Simulator_2013_Steam_Edition_ENG.exe
2014-08-18 01:47 - 2014-01-08 22:59 - 00789532 _____ () C:\Windows\system32\prfh0416.dat
2014-08-18 01:47 - 2014-01-08 22:59 - 00163076 _____ () C:\Windows\system32\prfc0416.dat
2014-08-18 01:47 - 2013-09-09 07:24 - 01797166 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-18 01:26 - 2014-08-18 01:26 - 00000000 ____D () C:\Users\Alex\AppData\Local\Ubisoft
2014-08-18 01:17 - 2014-08-08 16:26 - 00003790 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-18 01:17 - 2013-09-09 07:36 - 00000000 ____D () C:\Users\Todos os Usuários\McAfee
2014-08-18 01:17 - 2013-09-09 07:36 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-15 13:54 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-08-15 13:54 - 2013-08-22 12:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-14 20:43 - 2014-07-30 16:03 - 00001064 _____ () C:\Users\Alex\Desktop\Dropbox.lnk
2014-08-14 20:22 - 2014-07-21 22:38 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 20:18 - 2014-07-21 22:38 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-14 17:53 - 2014-07-21 21:48 - 00233912 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-08-14 17:33 - 2013-08-22 01:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-14 17:33 - 2013-08-22 00:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-14 17:33 - 2013-08-22 00:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-14 17:32 - 2014-07-23 12:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-14 17:32 - 2014-07-23 12:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-14 17:32 - 2014-07-21 21:52 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-14 17:32 - 2013-08-22 08:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-14 17:32 - 2013-08-22 08:44 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 17:32 - 2013-08-22 08:22 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-14 17:32 - 2013-08-22 08:21 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-14 17:32 - 2013-08-22 08:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-14 17:32 - 2013-08-22 08:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-14 17:32 - 2013-08-22 07:32 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-14 17:32 - 2013-08-22 00:55 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-14 17:32 - 2013-08-22 00:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-14 17:32 - 2013-08-22 00:40 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-14 17:28 - 2014-07-24 08:52 - 00428888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-08-14 11:42 - 2014-08-14 11:42 - 00000000 ____D () C:\Users\Usuário Padrão\AppData\Roaming\TuneUp Software
2014-08-14 11:42 - 2014-08-14 11:42 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software
2014-08-14 11:42 - 2014-08-14 11:42 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software
2014-08-13 19:12 - 2014-08-13 19:12 - 00001290 _____ () C:\Users\Alex\Desktop\Sid Meier's Civilization 5.lnk
2014-08-13 19:12 - 2014-08-13 19:12 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Sid Meier's Civilization 5
2014-08-13 18:44 - 2014-08-13 18:35 - 00000000 ____D () C:\Program Files (x86)\R.G. Mechanics
2014-08-13 17:17 - 2014-08-09 02:25 - 00000000 ____D () C:\Users\Alex\Desktop\Samples
2014-08-13 16:20 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-08-13 03:55 - 2014-08-13 03:54 - 77719596 _____ () C:\Users\Alex\Downloads\10 - Minimal Criminal - Mary Poppin'  Pills.wav
2014-08-13 03:26 - 2014-08-13 03:26 - 00271541 _____ () C:\Users\Alex\Downloads\154884-vlt_deepdark.vlt
2014-08-12 21:28 - 2014-08-12 21:24 - 90194132 _____ () C:\Users\Alex\Downloads\A.L.X.S. - Dragon Fly (Monu remix)_UNMASTERED.wav
2014-08-12 20:57 - 2014-08-12 20:57 - 00000000 ____D () C:\Users\Alex\Documents\Command & Conquer 3 Tiberium Wars
2014-08-12 20:56 - 2014-08-12 20:54 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Command & Conquer 3 Tiberium Wars
2014-08-12 20:51 - 2014-08-11 16:22 - 00042250 _____ () C:\Windows\DirectX.log
2014-08-12 20:45 - 2014-08-12 20:45 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-08-12 05:28 - 2014-08-12 05:28 - 00000448 _____ () C:\Users\Alex\Desktop\My Computer - Atalho.lnk
2014-08-12 05:08 - 2014-08-12 04:55 - 00000000 ____D () C:\Users\Alex\AppData\Local\clear.fi
2014-08-12 04:58 - 2014-08-12 04:58 - 00000000 ____D () C:\Users\Alex\Desktop\Muic
2014-08-12 04:57 - 2014-01-08 17:52 - 00000000 ____D () C:\Users\Todos os Usuários\boost_interprocess
2014-08-12 04:57 - 2014-01-08 17:52 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-08-12 04:55 - 2014-08-12 04:55 - 00000000 ____D () C:\Users\Alex\AppData\Local\Acer
2014-08-12 04:55 - 2013-09-09 07:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2014-08-12 04:55 - 2013-09-09 07:36 - 00000000 ____D () C:\Program Files\Acer
2014-08-12 04:54 - 2014-07-23 22:44 - 00000000 ____D () C:\Users\Public\OEM
2014-08-12 03:46 - 2014-08-09 02:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicDisc
2014-08-11 16:31 - 2014-08-11 16:31 - 00000000 ____D () C:\Users\Alex\Documents\theHunter
2014-08-11 16:30 - 2014-08-11 16:30 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\theHunter
2014-08-11 16:30 - 2014-08-11 16:30 - 00000000 ____D () C:\Users\Alex\AppData\Local\theHunter
2014-08-11 16:26 - 2014-08-11 16:26 - 00000097 _____ () C:\Users\Alex\AppData\Roaming\LauncherSettings_live.cfg
2014-08-11 16:23 - 2014-08-11 16:23 - 00000000 ____D () C:\Users\Todos os Usuários\Hunter
2014-08-11 16:23 - 2014-08-11 16:23 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\theHunterSteam
2014-08-11 16:23 - 2014-08-11 16:23 - 00000000 ____D () C:\ProgramData\Hunter
2014-08-10 16:52 - 2014-08-10 16:52 - 00000000 ____D () C:\Users\Alex\Documents\Bluetooth Folder
2014-08-10 16:52 - 2014-01-08 17:41 - 00000000 ____D () C:\Users\Todos os Usuários\Atheros
2014-08-10 16:52 - 2014-01-08 17:41 - 00000000 ____D () C:\ProgramData\Atheros
2014-08-10 16:46 - 2013-08-22 11:46 - 00025135 _____ () C:\Windows\setupact.log
2014-08-10 12:19 - 2014-08-10 12:19 - 339680009 _____ () C:\Windows\MEMORY.DMP
2014-08-10 12:19 - 2014-08-10 12:19 - 00286256 _____ () C:\Windows\Minidump\081014-42078-01.dmp
2014-08-10 02:38 - 2014-08-10 02:33 - 00000000 ____D () C:\Users\Alex\Desktop\VSTs
2014-08-09 22:29 - 2014-08-09 22:29 - 00000332 _____ () C:\Windows\Tasks\0614aUpdateInfo.job
2014-08-09 18:57 - 2014-08-09 18:52 - 00013893 ____H () C:\Users\Alex\Documents\~WRL3332.tmp
2014-08-09 03:01 - 2014-08-09 03:01 - 00000000 ____D () C:\Program Files (x86)\Smith Micro
2014-08-09 02:48 - 2014-08-09 02:48 - 00001107 _____ () C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Downloads.lnk
2014-08-09 02:39 - 2014-08-09 02:39 - 00000000 ____D () C:\Users\Alex\AppData\Local\Native Instruments
2014-08-09 02:12 - 2014-08-09 02:12 - 48561932 _____ () C:\Users\Alex\Downloads\Gimme Shelter.wav
2014-08-09 02:06 - 2014-08-09 02:03 - 87433088 _____ () C:\Users\Alex\Downloads\Bad Mother .wav
2014-08-09 01:58 - 2014-08-09 01:57 - 72817964 _____ () C:\Users\Alex\Downloads\ALXS - Evil Dead Update Wednesday.wav
2014-08-09 01:50 - 2014-08-09 01:50 - 89652752 _____ () C:\Users\Alex\Downloads\Minimal Techno (1).wav
2014-08-09 01:15 - 2014-08-09 01:15 - 00000000 ____D () C:\Users\Todos os Usuários\Ableton
2014-08-09 01:15 - 2014-08-09 01:15 - 00000000 ____D () C:\ProgramData\Ableton
2014-08-09 01:15 - 2014-08-09 01:14 - 00000000 ____D () C:\Users\Alex\Documents\Ableton
2014-08-09 01:14 - 2014-08-09 01:14 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Ableton
2014-08-08 21:54 - 2014-08-08 17:43 - 00000000 ____D () C:\Users\Alex\Downloads\Vengeance Sounds Pack
2014-08-08 18:51 - 2014-08-08 18:47 - 00000000 ____D () C:\Users\Alex\Desktop\Massive Presets
2014-08-08 17:58 - 2014-08-08 17:58 - 00000000 ____D () C:\Program Files (x86)\Elaborate Bytes
2014-08-08 17:58 - 2014-08-08 17:56 - 05629238 _____ () C:\Users\Alex\Downloads\Massive - 11.500 Presets [.nmsv Massive 1.3+][packet-dada].7z
2014-08-08 15:40 - 2013-09-09 07:36 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-08-08 15:40 - 2013-09-09 07:36 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-08-08 15:23 - 2014-08-08 15:23 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\AVG2014
2014-08-08 15:20 - 2014-08-08 15:20 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\TuneUp Software
2014-08-08 15:08 - 2014-08-08 15:08 - 00000000 ____D () C:\Users\Alex\AppData\Local\MFAData
2014-08-08 15:06 - 2014-08-08 15:06 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\WildTangent
2014-08-08 15:06 - 2013-09-09 07:28 - 00000000 ____D () C:\Users\Todos os Usuários\WildTangent
2014-08-08 15:06 - 2013-09-09 07:28 - 00000000 ____D () C:\ProgramData\WildTangent
2014-08-08 15:06 - 2013-09-09 07:28 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2014-08-08 15:04 - 2013-09-09 07:40 - 00000000 ____D () C:\Windows\oem
2014-08-08 05:56 - 2013-09-09 07:36 - 00000000 ____D () C:\Users\Todos os Usuários\Acer
2014-08-08 05:56 - 2013-09-09 07:36 - 00000000 ____D () C:\ProgramData\Acer
2014-08-07 14:15 - 2014-08-07 14:15 - 00013517 ____H () C:\Users\Alex\Documents\~WRL1525.tmp
2014-08-06 23:12 - 2014-08-14 17:57 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-06 19:39 - 2014-08-14 17:57 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-06 19:38 - 2014-08-14 17:57 - 00697856 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-06 16:29 - 2014-08-06 16:29 - 00000900 _____ () C:\Users\Alex\Desktop\Photos.lnk
2014-08-05 14:50 - 2014-07-28 15:40 - 00128512 ___SH () C:\Users\Alex\Desktop\Thumbs.db
2014-08-04 06:00 - 2014-07-21 11:45 - 00000000 ____D () C:\Users\Alex\AppData\Local\Packages
2014-08-04 05:59 - 2014-08-04 05:59 - 00009204 _____ () C:\Users\Alex\Downloads\Kingsway Upholstery.odt
2014-08-03 20:08 - 2014-08-03 20:08 - 84213450 _____ () C:\Users\Alex\Downloads\DONT SAY SORRY MASTER (1).wav
2014-08-02 02:44 - 2014-08-14 17:57 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-02 00:56 - 2014-08-14 17:57 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-02 00:11 - 2014-08-14 17:57 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-08-01 21:17 - 2014-08-14 20:27 - 00704480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-01 21:17 - 2014-08-14 20:27 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-01 13:16 - 2014-08-01 13:16 - 89652752 _____ () C:\Users\Alex\Downloads\Minimal Techno.wav
2014-08-01 11:17 - 2014-08-01 11:17 - 00000911 _____ () C:\Users\Alex\Desktop\Documents.lnk
2014-07-31 10:45 - 2014-07-21 11:45 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Adobe
2014-07-31 09:00 - 2014-07-30 13:59 - 00000000 ____D () C:\Users\Todos os Usuários\Adobe
2014-07-31 09:00 - 2014-07-30 13:59 - 00000000 ____D () C:\ProgramData\Adobe
2014-07-30 15:35 - 2014-07-30 12:16 - 00000000 ____D () C:\Users\Alex\AppData\Roaming\Apple Computer
2014-07-30 15:30 - 2014-07-30 15:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-30 15:28 - 2014-07-30 15:27 - 00000000 ____D () C:\Users\Todos os Usuários\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-07-30 15:28 - 2014-07-30 15:27 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-07-30 15:28 - 2014-07-30 15:27 - 00000000 ____D () C:\Program Files\iTunes
2014-07-30 15:27 - 2014-07-30 15:27 - 00000000 ____D () C:\Program Files\iPod
2014-07-30 14:25 - 2014-07-29 13:02 - 00000000 ___RD () C:\Users\Alex\Dropbox (Old)
2014-07-30 14:00 - 2014-07-30 14:00 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-07-30 14:00 - 2014-07-30 14:00 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-07-30 12:44 - 2014-07-30 12:33 - 00000259 _____ () C:\Users\Alex\Desktop\meta data.txt
2014-07-30 12:16 - 2014-07-30 12:16 - 00000000 ____D () C:\Users\Alex\AppData\Local\Apple Computer
2014-07-30 12:15 - 2014-07-30 12:15 - 00002535 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\Users\Todos os Usuários\Apple Computer
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\Users\Alex\AppData\Local\Apple
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-07-30 12:15 - 2014-07-30 12:15 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-07-30 12:15 - 2014-07-30 12:12 - 00000000 ____D () C:\Users\Todos os Usuários\Apple
2014-07-30 12:15 - 2014-07-30 12:12 - 00000000 ____D () C:\ProgramData\Apple
2014-07-30 12:13 - 2014-07-30 12:13 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-07-30 12:13 - 2014-07-30 12:12 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-07-29 02:27 - 2014-07-29 02:07 - 733593600 _____ () C:\Users\Alex\Downloads\Don't.Look.Now.[1973].DVDrip[Eng].avi
2014-07-28 19:24 - 2013-08-22 16:12 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ___RD () C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ___RD () C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\WinStore
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-07-28 19:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-07-28 19:24 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\oobe
2014-07-28 17:39 - 2013-09-09 08:08 - 00000000 ___HD () C:\OEM
2014-07-28 17:38 - 2014-07-28 17:38 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-07-28 12:32 - 2014-07-28 12:32 - 00711251 _____ () C:\Users\Alex\Downloads\alexsims1989 bank statement 2.jpeg
2014-07-28 12:31 - 2014-07-28 12:31 - 00850450 _____ () C:\Users\Alex\Downloads\alexsims1989 counterpart licence.jpeg
2014-07-28 00:53 - 2014-07-28 00:53 - 00001086 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-07-28 00:53 - 2014-07-28 00:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-07-28 00:53 - 2014-07-28 00:53 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\uk-UA
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\th-TH
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\SystemResetPlatform
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\sl-SI
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\sk-SK
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\setup
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\ro-RO
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\migwiz
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\lv-LV
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\lt-LT
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\hr-HR
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\he-IL
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\et-EE
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\en-GB
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\bg-BG
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Windows\system32\ar-SA
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2014-07-28 00:24 - 2013-08-22 12:36 - 00000000 ____D () C:\Program Files (x86)\Windows Multimedia Platform
2014-07-28 00:24 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\SysWOW64\oobe
2014-07-28 00:24 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-28 00:24 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\Dism
 
Some content of TEMP:
====================
C:\Users\Alex\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp6qi2ho.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-08-26 17:35
 
==================== End Of Log ============================

  • 0

Advertisements


#17
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Is the Sathurbot still detected?



51a46ae42d560-malwarebytes_anti_malware. Scan with Malwarebytes' Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.

  • Install the progam and select update.
  • Once updated, click the Settings tab, in the left panel choose Detctions & protection and tick Scan for rootkits.
  • Click the Scan tab, choose Threat Scan is checked and click Scan Now.
  • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the Scan Log.
  • At the bottom click Export and choose Text file.

Save the file to your desktop and include its content in your next reply.


ESETOnline.png Scan with ESET Online Scanner

This step can only be done using Internet Explorer, Google Chrome or Mozilla Firefox.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
Please visit ESET Online Scanner website.
Click there Run ESET Online Scanner.

If using Internet Explorer:

  • Accept the Terms of Use and click Start.
  • Allow the running of add-on.

If using Mozilla Firefox or Google Chrome:

  • Download esetsmartinstaller_enu.exe that you'll be given link to.
  • Double click esetsmartinstaller_enu.exe.
  • Allow the Terms of Use and click Start.

To perform the scan:

  • Make sure that Enable detecion of potentially unwanted applications is checked.
  • In the Advanced Settings dropdown menu:
    • Make sure that Remove found threats is unchecked.
    • Scan archives is checked.
    • Scan for potentially unsafe applications and Enable Anti-Stealth technology are checked.
    • Use custom proxy settings is unchecked.
  • Click Start
  • The program will begin to download it's virus database. The speed may vary depending on your Internet connection.
  • When completed, the program will begin to scan. This may take several hours. Please, be patient.
  • Do not do anything on your machine as it may interrupt the scan.
  • When the scan is done, click Finish.
  • A logfile will be created at C:\Program Files (x86)\ESET\ESET Online Scanner. Open it using Notepad.

Please include this logfile in your next reply.
Don't forget to re-enable previously switched-off protection software!


  • 0

#18
ALXS

ALXS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Hi Naat,

 

The Malwarebytes log is:

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 27/08/2014
Scan Time: 17:43:17
Logfile: Malwarebytes Anti-Malware log.txt
Administrator: Yes
 
Version: 2.00.2.1012
Malware Database: v2014.08.27.07
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Alex
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 349327
Time Elapsed: 39 min, 45 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 1
Spyware.Zbot.ED, C:\Users\Alex\AppData\Local\Ipsoft\tmp3474.exe, Quarantined, [d3c67f4aa0dbdb5b9fe9908270952dd3], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

  • 0

#19
ALXS

ALXS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

and the ESET log is

 

 

[email protected] as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=10e1dff8264ab74084417403c4b3bec2
# engine=19873
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-08-27 11:18:13
# local_time=2014-08-27 08:18:13 (-0300, Hora Padrão da Bahia)
# country="United Kingdom"
# lang=1033
# osver=6.2.9200 NT 
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 0 12639814 0 0
# scanned=273246
# found=2
# cleaned=0
# scan_time=5884
sh=81746F3E7487D80E7A97964EA1934A469716F9CA ft=1 fh=c71c00119e355a2b vn="a variant of Win64/Sathurbot.D trojan" ac=I fn="C:\FRST\Quarantine\C\ProgramData\Microsoft\Crypto\RSA64\CryptoProvider.dll.xBAD"
sh=6ADAB0D96E65123180089A1949C57F0254BA2682 ft=1 fh=c71c001162b7b66f vn="a variant of Win64/Sathurbot.A trojan" ac=I fn="C:\FRST\Quarantine\C\ProgramData\Microsoft\Crypto\RSA64\rsa64.dll.xBAD"
 

  • 0

#20
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Is the Sathurbot still detected?


  • 0

#21
ALXS

ALXS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Yes. :( but my computer no longer is experiencing the screen flash which makes the folders close... So you have definitely done something amazing already :)


  • 0

#22
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Can you generate a report or a screenshot where it is detected?


  • 0

#23
ALXS

ALXS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Do i need to run the scan again on ESET to see?


  • 0

#24
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

No, but sfter the removals alerts should cease.

 

If they are still occuring, I need to see where are they detected. Is your AV complaining about it?


  • 0

#25
ALXS

ALXS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

The Sathurbot was only visible on ESET. Which is what i discovered it with before i posted on this forum. It was coming up on AVG as a trojan but it seemed to have nothing do with a Sathurbot. I deleted AVG and decided to go with the Windows anti virus and firewall instead.

 

The first time i tied ESET it said the files where here:

C:\Users\All Users\Microsoft\Crypto\RSA64\rsa64.dll a variant of Win64/Sathurbot.A trojan
C:\Users\Todos os Usuários\Microsoft\Crypto\RSA64\rsa64.dll a variant of Win64/Sathurbot.A trojan
 

When i ran the last ESET it the last time you asked me to it detected two Sathurbots:

 

sh=81746F3E7487D80E7A97964EA1934A469716F9CA ft=1 fh=c71c00119e355a2b vn="a variant of Win64/Sathurbot.D trojan" ac=I fn="C:\FRST\Quarantine\C\ProgramData\Microsoft\Crypto\RSA64\CryptoProvider.dll.xBAD"
sh=6ADAB0D96E65123180089A1949C57F0254BA2682 ft=1 fh=c71c001162b7b66f vn="a variant of Win64/Sathurbot.A trojan" ac=I fn="C:\FRST\Quarantine\C\ProgramData\Microsoft\Crypto\RSA64\rsa64.dll.xBAD"

  • 0

Advertisements


#26
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

OK, let's make sure about that.

EXEfile7.png Scan with SystemLook

Download SystemLook x64 by jpshortstuff and save it to your desktop.

  • Right-click on EXEfile7.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • In the main box please paste the following script:
    :dir
    "C:\Users\All Users\Microsoft\Crypto" /s
    "C:\Users\Todos os Usuários\Microsoft\Crypto" /s
    
  • click Look.
  • When finished a logfile SystemLook.txt will open (will be also saved to your desktop)
  • Click Exit to close the tool.

Please include the content of SystemLook in your next reply.


  • 0

#27
ALXS

ALXS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Hi Naat,

 

This is the log text.

 

SystemLook 30.07.11 by jpshortstuff
Log created at 09:23 on 28/08/2014 by Alex
Administrator - Elevation successful
 
========== dir ==========
 
"C:\Users\All Users\Microsoft\Crypto" - Unable to find folder.
 
"C:\Users\Todos os Usuários\Microsoft\Crypto" - Unable to find folder.
 
-= EOF =-

  • 0

#28
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

I'd like you to do these two for me in the order mentioned.



FRST.gif Fix with Farbar Recovery Scan Tool
 

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif
icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif


Press the WindowsKey.png + R on your keyboard at the same time. Type Notepad and click OK.

  • Copy the entire content of the codebox below and paste into the Notepad document:
    start
    DeleteQuarantine:
    end
  • Click File, Save As and type fixlist.txt as the File Name.

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    > XP users click run after receipt of Windows Security Warning - Open File.
    > 8 users will be prompted about Windows SmartScreen protection - click More information and Run.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please include it in your reply.



panda-av.jpg Scan with Panda Cloud Cleaner

This type of scan often produces false positives. In any case do not remove on your own any of its findings! Removal will be made after the careful analysis of the scan results.

Please download Panda Cloud Cleaner and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Install the scanner by right-click on panda-av.jpg icon and select RunAsAdmin.jpg Run as Administrator.
  • It should start itself automaticaly after the installation.
  • In the main console click Accept and Scan.
  • This scan won't take long, about several minutes (depending on your system specs). Let it run uninterrupted.
  • At the last stage you will see a couple of messages about veryfying & analyzing results. Wait patiently.
  • Upon completion you will see detections window. Enter one of them and click there View Report at the bottom right side.
  • A notepad window named PCloudCleaner.log will open. Save it to your desktop.

Please include the contents of that file in your next reply.
Don't forget to re-enable your switched-off protection software!
After that you may uninstall Panda Cloud Cleaner from your machine, if you wish to.


  • 0

#29
ALXS

ALXS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Here are the logs Naat:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-08-2014
Ran by Alex at 2014-08-28 12:13:36 Run:2
Running from C:\Users\Alex\Desktop
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
start
DeleteQuarantine:
end
*****************
 
"C:\FRST\Quarantine" => removed successfully.
 
==== End of Fixlog ====
 
Panda log
 
Broken Link. FILE: File not found:C:\PROGRAM FILES\MICROSOFT OFFICE 15\ROOT\OFFICE15\MSOSYNC.EXE to be deleted.
 
Broken Link. TASK: Task\[Microsoft Office 15 Sync Maintenance for ALEX-Alex Alex]. Task to be deleted.
 
Suspicious Policy. POLICY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED[HIDEFILEEXT] to be changed to: 0
 
Suspicious Policy. POLICY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED[HIDEFILEEXT] to be changed to: 0
 

 


  • 0

#30
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Good :)



51a5ce45263de-delfix.png Clean with DelFix

Please download DelFix by Xplode and save it to your desktop.

  • Right-click on 51a5ce45263de-delfix.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Ensure that Remove disinfection tools, Purge system restore and Reset system settings are checked.
  • Push Run.
  • When finished, it will display a notepad report.

Include it for my review.
Please also manually reboot your machine after posting your logfile.


  • 0






Similar Topics


Also tagged with one or more of these keywords: Sathurbot, trojan, help

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP