Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Backdoor.Win32.ZAcess.oun


  • This topic is locked This topic is locked
31 replies to this topic

#1 ultrafire

ultrafire

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 05 June 2012 - 06:56 PM

Hello,

I'm currently pestered by this backdoor application on my desktop and noticed how hard it was to remove it just today.

First I had Microsoft Security Essentials telling me a few days ago that some trojan were removed initially were referred as Win32.Sireref.AB but when I restarted my PC they were still there.

So, I tried Kasperksy AV 2012 to see if was more effective. I did not only not remove the trojans but they started to affect my PC. When I logged, after several reboots, all my desktop icons no longer led to anything and if I tried to go into the folder running the .exes directly they did nothing as well.

Google didn't help me much as were loads of website with pre-formatted answers and asking me to download some magical software that was going to remove it. Seeing that were 4 or 5 of these website with identical layouts I refrained to do so.

The silver lining was that I ended in this forum that from what I have seen has suceeded in helping some other members with an identical problem to mine.

I saw that they posted some logs detailing their PC information but I do not know how to produce them.


Thanks in advance for all your replies,
Ultra.

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,331 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:33 PM

Posted 05 June 2012 - 07:11 PM

Please go here....Preparation Guide ,do steps 6-9.

Create a DDS log and post it in this topic,thanks.
If GMER won't run (it may not on a 64 bit system) skip it and move on.

Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 ultrafire

ultrafire
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 05 June 2012 - 07:56 PM

Hi,

Thanks for the fast reply and I'm sorry I didn't see your guide before starting the topic.

Here I'll post the DDS logs only because as you said GMER didn't work on my Windows 7 64-bit OS.



Thanks for your replies,
Ultra.

Attached Files



#4 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:07:33 PM

Posted 08 June 2012 - 01:30 PM

:welcome: to Bleeping Computer.

My name is Jason and I'll be helping you with your computer problems. You can call me by my screename jntkwx or Jason is fine.

Some things to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • Please do not attach logs or put logs in code boxes (unless explicitly asked to)
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can also help.
  • Do not run anything while running a fix.
  • If you don't understand a step, please ask for clarification before continuing with any future steps.

Click on the Watch Topic button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

 

Posted Image One or more of the identified infections is a backdoor trojan and password stealer.

This type of infection allows hackers to access and remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable.
It would also be wise to contact those same financial institutions to appraise them of your situation.


I highly suggest you take a look at the two links provided below:
1. How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?
2. When should I re-format? How should I reinstall?

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you decide to go through with the cleanup, please proceed with the following steps.


:step1: Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If you do not know how to do this you can find out >here< or >here<
3. Double click on combofix.exe & follow the prompts.

Important:
  • Do not mouseclick combofix's window while it's running. That may cause it to stall.
  • If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer


:step2: Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:

    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


In your next reply, please include:
  • Combofix log
  • FSS log
  • How's your computer running now? Please be descriptive as possible

Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#5 ultrafire

ultrafire
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 08 June 2012 - 02:12 PM

Hi, Jason

First of all, thanks for getting back to me.

Also while researching on the Web I found that the trojan that is affecting my PC is a password stealer and so I promptly changed all my emails and social media passwords. My bank uses a virtual keyboard for logging purposes. Should I also change it ?

Second, I'm using my infected PC on Safe Mode as the normal mode, like I stated before, gives me no acess to programs/shortcuts and pretty much everything else. I hope this mode does not contaminate in any way the logs you get.

Lastly, ComboFix seems to not have run properly. I checked your guide on how to do it and after extracting itself it does nothing. No blue screen appears. Tried it three times. That was the main reason I mentioned I was running Windows on Safe Mode.


FSS worked fine and I will post the log in this post now.

Let me know if you need anything else.


Thanks again.


--

Farbar Service Scanner Version: 05-06-2012
Ran by Ultra (administrator) on 08-06-2012 at 19:54:25
Running from "C:\Users\Ultra\Desktop"
Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Nerwork
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Attempt to access Google.com returned error: Other errors
Yahoo IP is accessible.
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to retrieve start type of MpsSvc. The value does not exist.
Checking ImagePath: ATTENTION!=====> Unable to retrieve ImagePath of MpsSvc. The value does not exist.
Unable to retrieve ServiceDll of MpsSvc. The value does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.


Firewall Disabled Policy:
==================


System Restore:
============
SDRSVC Service is not running. Checking service configuration:
The start type of SDRSVC service is OK.
The ImagePath of SDRSVC service is OK.
The ServiceDll of SDRSVC service is OK.

VSS Service is not running. Checking service configuration:
The start type of VSS service is OK.
The ImagePath of VSS service is OK.


System Restore Disabled Policy:
========================


Action Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.

winmgmt Service is not running. Checking service configuration:
The start type of winmgmt service is OK.
The ImagePath of winmgmt: "%systemroot%\system32\svchost.exe -k netsvcs".
The ServiceDll of winmgmt service is OK.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.

BITS Service is not running. Checking service configuration:
The start type of BITS service is OK.
The ImagePath of BITS service is OK.
The ServiceDll of BITS service is OK.

EventSystem Service is not running. Checking service configuration:
The start type of EventSystem service is OK.
The ImagePath of EventSystem service is OK.
The ServiceDll of EventSystem service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is OK.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend: "%ProgramFiles(x86)%\Windows Defender\mpsvc.dll".


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

#6 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:07:33 PM

Posted 08 June 2012 - 02:21 PM

Yes, just to be safe, I would recommend changing your banking password as well.

:step1: Please download RestoreBFE from: http://download.bleepingcomputer.com/sUBs/MiniFixes/RestoreBFE.exe
Double click on the downloaded file. It should only take a few seconds to run.
When complete, it will say .. "Done! Please check if BFE service is running now"

:step2: Rerun FSS, as we've done previously.

:step3: Try to run Combofix again. If it still doesn't run, let me know and we can try another tool.
Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#7 ultrafire

ultrafire
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 08 June 2012 - 02:39 PM

Hi Jason,

I installed the program you asked, re-did the FSS scan and rebooted and started my PC on normal mode.

I was able to run ComboFix and it's as we speak running it's scan (i'm on a clean pc).

Infortunately, I have to step out for a couple of hours. I'll get you both logs in the next post.


I apologise for the inconvience.

#8 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:07:33 PM

Posted 08 June 2012 - 02:40 PM

Sounds good. :thumbup2:

No problem, reply whenever you can.
Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#9 ultrafire

ultrafire
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 08 June 2012 - 07:33 PM

Hello,

Took longer than I expected but here are the logs of ComboFix and FSS (after BFE was installed)


--

ComboFix 12-06-08.02 - Ultra 08-06-2012 20:36:44.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.351.2070.18.8167.6345 [GMT 1:00]
Executando de: c:\users\Ultra\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Criado um novo ponto de restauração
.
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2012-05-08 to 2012-06-08 ))))))))))))))))))))))))))))
.
.
2012-06-08 19:42 . 2012-06-08 19:42 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-06-08 19:42 . 2012-06-08 19:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-05 21:59 . 2012-06-05 21:59 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2012-06-05 21:59 . 2012-06-08 19:43 -------- d-----w- c:\programdata\Kaspersky Lab
2012-06-05 21:37 . 2012-06-05 21:37 -------- d-----w- c:\users\Ultra\AppData\Roaming\Curiolab
2012-06-02 07:41 . 2012-06-02 07:41 -------- d-----w- c:\programdata\RELOADED
2012-05-28 17:46 . 2012-05-28 17:46 -------- d-----w- c:\programdata\Nexon
2012-05-28 17:43 . 2012-05-28 17:43 -------- d-----w- c:\program files (x86)\BandiMPEG1
2012-05-28 16:30 . 2012-05-28 16:30 235 ----a-w- c:\windows\SysWow64\nxEuUninstall.bat
2012-05-28 16:30 . 2012-05-28 16:30 -------- d-----w- C:\Nexon
2012-05-28 16:30 . 2012-05-28 16:30 446464 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
2012-05-24 20:32 . 2012-05-24 20:32 -------- d-----w- c:\users\Ultra\AppData\Roaming\LolClient2
2012-05-22 08:54 . 2012-05-22 09:10 -------- d-----w- c:\users\Ultra\AppData\Local\Nokia
2012-05-22 08:54 . 2012-05-22 08:54 -------- d-----w- c:\users\Ultra\AppData\Roaming\PC Suite
2012-05-22 08:54 . 2012-05-22 08:54 -------- d-----w- c:\programdata\PC Suite
2012-05-22 08:53 . 2012-05-22 08:54 -------- d-----w- c:\programdata\Nokia
2012-05-22 08:53 . 2012-05-22 08:53 -------- d-----w- c:\program files (x86)\Common Files\Nokia
2012-05-22 08:53 . 2012-05-22 08:53 -------- d-----w- c:\program files\DIFX
2012-05-22 08:53 . 2012-04-22 12:51 25600 ----a-w- c:\windows\system32\drivers\pccsmcfdx64.sys
2012-05-22 08:53 . 2012-05-22 08:53 -------- dc----w- c:\windows\system32\DRVSTORE
2012-05-22 08:53 . 2012-05-22 08:53 -------- d-----w- c:\program files (x86)\PC Connectivity Solution
2012-05-22 08:50 . 2012-05-22 08:53 -------- d-----w- c:\program files (x86)\Nokia
2012-05-19 15:09 . 2012-05-19 15:10 -------- d-----w- c:\users\Ultra\AppData\Roaming\fretsonfire
2012-05-11 20:03 . 2012-05-11 20:03 -------- d-----w- c:\program files\Microsoft Silverlight
2012-05-11 20:03 . 2012-05-11 20:03 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
.
.
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-28 17:01 . 2012-01-28 16:53 5216304 ----a-w- c:\windows\PE_Rom.dll
2012-05-05 11:33 . 2012-04-02 19:29 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-05 11:33 . 2012-01-28 23:08 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 11:33 . 2012-04-02 19:33 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-05 12:40 . 2012-04-05 12:40 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-04-05 12:40 . 2012-04-05 12:40 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-04-05 12:40 . 2012-04-05 12:40 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-04-05 12:40 . 2012-04-05 12:40 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-04-05 12:40 . 2012-04-05 12:40 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-04-05 12:40 . 2012-04-05 12:40 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-04-05 12:40 . 2012-04-05 12:40 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-04-05 12:40 . 2012-04-05 12:40 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-04-05 12:40 . 2012-04-05 12:40 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-04-05 12:40 . 2012-04-05 12:40 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-04-05 12:40 . 2012-04-05 12:40 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-04-05 12:40 . 2012-04-05 12:40 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-04-05 12:40 . 2012-04-05 12:40 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-04-05 12:40 . 2012-04-05 12:40 448512 ----a-w- c:\windows\system32\html.iec
2012-04-05 12:40 . 2012-04-05 12:40 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-04-05 12:40 . 2012-04-05 12:40 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-04-05 12:40 . 2012-04-05 12:40 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-04-05 12:40 . 2012-04-05 12:40 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-04-05 12:40 . 2012-04-05 12:40 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-04-05 12:40 . 2012-04-05 12:40 222208 ----a-w- c:\windows\system32\msls31.dll
2012-04-05 12:40 . 2012-04-05 12:40 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-04-05 12:40 . 2012-04-05 12:40 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-04-05 12:40 . 2012-04-05 12:40 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-04-05 12:40 . 2012-04-05 12:40 160256 ----a-w- c:\windows\system32\wextract.exe
2012-04-05 12:40 . 2012-04-05 12:40 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-04-05 12:40 . 2012-04-05 12:40 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-04-05 12:40 . 2012-04-05 12:40 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-04-05 12:40 . 2012-04-05 12:40 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-04-05 12:40 . 2012-04-05 12:40 12288 ----a-w- c:\windows\system32\mshta.exe
2012-04-05 12:40 . 2012-04-05 12:40 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-04-05 12:40 . 2012-04-05 12:40 114176 ----a-w- c:\windows\system32\admparse.dll
2012-04-05 12:40 . 2012-04-05 12:40 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-04-05 12:40 . 2012-04-05 12:40 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-04-05 12:40 . 2012-04-05 12:40 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-03-31 06:05 . 2012-05-09 19:05 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-31 04:39 . 2012-05-09 19:05 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39 . 2012-05-09 19:05 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10 . 2012-05-09 19:05 3146240 ----a-w- c:\windows\system32\win32k.sys
2012-03-30 11:35 . 2012-05-09 19:04 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-17 07:58 . 2012-05-09 19:05 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-03-11 11:28 . 2012-01-28 16:00 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-07-14 . 24ACB7E5BE595468E3B9AA488B9B4FCB . 328704 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[-] 2009-07-14 . 50BEA589F7D7958BDD2528A8F69D05CC . 329216 . . [6.1.7600.16385] .. c:\windows\system32\services.exe
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\Ultra\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\Ultra\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\Ultra\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-05-11 880496]
"Steam"="d:\programas\Steam\steam.exe" [2012-01-28 1242448]
"NokiaSuite.exe"="c:\program files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" [2012-05-16 1084840]
"KPeerNexonEU"="c:\nexon\NEXON_EU_Downloader\nxEULauncher.exe" [2012-05-28 438272]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-05-20 284440]
"ASUS ShellProcess Execute"="c:\program files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe" [2010-11-25 252544]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe" [2011-04-24 202296]
.
c:\users\Ultra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Ultra\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
Transfer Utility Camera Monitor.lnk - d:\programas\PIXELA\Transfer Utility\CameraMonitor.exe [2012-4-5 537968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R1 cpmlezqs;cpmlezqs;c:\windows\system32\drivers\cpmlezqs.sys [x]
R1 heocfhew;heocfhew;c:\windows\system32\drivers\heocfhew.sys [x]
R1 swjqyjod;swjqyjod;c:\windows\system32\drivers\swjqyjod.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Serviço Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-28 136176]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
R3 AIDA64Driver;FinalWire AIDA64 Kernel Driver;d:\programas\AIDA64 Extreme Edition\kerneld.amd64 [2010-10-05 27296]
R3 EagleX64;EagleX64;c:\users\Ultra\AppData\Local\Temp\EagleX64.sys [x]
R3 ENTECH64;ENTECH64;c:\windows\system32\DRIVERS\ENTECH64.sys [x]
R3 gupdatem;Serviço Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-28 136176]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\DRIVERS\RTL8192su.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Serviço de Tecnologias de Activação do Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 X6va005;X6va005;c:\users\Ultra\AppData\Local\Temp\005B4BC.tmp [x]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [2011-06-13 922240]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-05-20 13592]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-09 382272]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [x]
S3 ASUSFILTER;ASUSFILTER;SysWow64\drivers\ASUSFILTER.sys [x]
S3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2012-06-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 11:33]
.
2012-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-28 15:46]
.
2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-28 15:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Ultra\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Ultra\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Ultra\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Ultra\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-19 11613288]
"WheelMouse"="d:\programas\a4tech\Amoumain.exe" [2012-02-01 196608]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Scan Suplementar -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportar para o Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
LSP: mswsock.dll
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Ultra\AppData\Roaming\Mozilla\Firefox\Profiles\0wp73s6z.default\
.
- - - - ORFÃOS REMOVIDOS - - - -
.
AddRemove-{1AA94747-3BF6-4237-9E1A-7B3067738FE1} - c:\program files (x86)\InstallShield Installation Information\{1AA94747-3BF6-4237-9E1A-7B3067738FE1}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AIDA64Driver]
"ImagePath"="\??\d:\programas\AIDA64 Extreme Edition\kerneld.amd64"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc]
"ImagePath"="."
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\Ultra\AppData\Local\Temp\005B4BC.tmp"
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Outros Processos em Execução ------------------------
.
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
c:\program files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
c:\program files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\pnSvc.exe
c:\program files (x86)\ASUS\AI Suite II\AI Suite II.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleCrashHandler.exe
.
**************************************************************************
.
Tempo para conclusão: 2012-06-08 20:47:55 - Máquina reiniciou
ComboFix-quarantined-files.txt 2012-06-08 19:47
.
Pré-execução: 713.596.928 bytes livres
Pós execução: 1.921.171.456 bytes livres
.
- - End Of File - - E1F46D1AE6042E6EA055D1708F189457

--

Farbar Service Scanner Version: 05-06-2012
Ran by Ultra (administrator) on 09-06-2012 at 01:28:10
Running from "C:\Users\Ultra\Desktop"
Microsoft Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Google IP is accessible.
Attempt to access Google.com returned error: Other errors
Yahoo IP is accessible.
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is set to Demand. The default start type is Auto.
The ImagePath of MpsSvc: ".".
Unable to retrieve ServiceDll of MpsSvc. The value does not exist.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is OK.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

#10 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:07:33 PM

Posted 08 June 2012 - 08:28 PM

ultrafire,

Looking good! :thumbup2:

:step1: Please open notepad and copy/paste the text in the quotebox below into it:

http://www.bleepingcomputer.com/forums/topic456001.html

Suspect::[138]
c:\windows\system32\drivers\cpmlezqs.sys
c:\windows\system32\drivers\heocfhew.sys
c:\windows\system32\drivers\swjqyjod.sys
c:\users\Ultra\AppData\Local\Temp\005B4BC.tmp
c:\users\Ultra\AppData\Local\Temp\EagleX64.sys

FCopy::
c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe | c:\windows\system32\services.exe

Save this as CFScript.txt


Posted Image


Refering to the picture above, drag CFScript.txt into ComboFix.exe

If prompted to update Combofix, please allow it to update.

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
Ensure you are connected to the internet and click OK on the message box.

:step2: Please download this file, and save it to your desktop. Double click it to run it, and when prompted, allow it to merge the file into the registry.
Mpssvc.reg

:step3: Rerun FSS, following my previous instructions.


In your next reply, please include:
  • Latest Combofix log
  • FSS log
  • How's your computer running now? Please be as descriptive as possible

Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#11 ultrafire

ultrafire
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 08 June 2012 - 09:09 PM

Hi Jason,

I'm sorry but I can't seem to make ComboFix do anything with the method you described. :(

It just extracts and does nothing like before. I tried couple of times and even uninstalled Kaspesrsky.



The PC behaviour is the same. When I arrived at home, clicking on shortcuts would make appear a message that that registry was marked for deletion.

Also, KAV still picked up on ZAcess.oun trojan present on my PC.


I added MpsSvc.reg as you requested.

#12 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:07:33 PM

Posted 08 June 2012 - 09:12 PM

ultrafire,

That's odd. I haven't heard of Combofix doing that before.

Please download Farbar Recovery Scan Tool 64-Bit and save it to a flashdrive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

- OR -

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[*]Select Command Prompt
[*]In the command window type in notepad and press Enter.
[*]The notepad opens. Under File menu select Open.
[*]Select "Computer" and find your flash drive letter and close the notepad.
[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.
[*]When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.[/list]
Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#13 ultrafire

ultrafire
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 08 June 2012 - 09:26 PM

Hi Jason,

Here goes the log of Farbar


--

Scan result of Farbar Recovery Scan Tool Version: 09-06-2012
Ran by SYSTEM at 09-06-2012 03:24:01
Running from G:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11613288 2010-11-19] (Realtek Semiconductor)
HKLM\...\Run: [WheelMouse] d:\Programas\a4tech\Amoumain.exe [x]
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe [43632 2010-01-18] ()
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [ASUS ShellProcess Execute] C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe [252544 2010-11-24] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [465536 2010-11-08] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKU\Ultra\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [880496 2012-05-11] (BitTorrent, Inc.)
HKU\Ultra\...\Run: [Steam] "D:\Programas\Steam\steam.exe" -silent [x]
HKU\Ultra\...\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray [1084840 2012-05-16] (Nokia)
HKU\Ultra\...\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe [438272 2012-05-28] (NEXON Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Transfer Utility Camera Monitor.lnk
ShortcutTarget: Transfer Utility Camera Monitor.lnk -> C:\Programas\PIXELA\Transfer Utility\CameraMonitor.exe (No File)

==================== Services (Whitelisted) ======

2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [922240 2011-06-13] ()
2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [915584 2010-12-01] ()
2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [586880 2010-10-21] ()
3 npggsvc; C:\Windows\SysWow64\GameMon.des -service [4676512 2012-01-29] (INCA Internet Co., Ltd.)
2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2012-02-09] ()
3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]
2 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [x]

========================== Drivers (Whitelisted) =============

0 AiChargerPlus; C:\Windows\System32\Drivers\AiChargerPlus.sys [14464 2010-11-08] (ASUSTek Computer Inc.)
1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2012-02-01] ((Standard mouse types))
3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2012-02-01] (A4Tech Co.,Ltd.)
1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [13440 2010-08-23] ()
1 AsUpIO; C:\Windows\SysWow64\Drivers\AsUpIO.sys [14464 2010-08-02] ()
3 ASUSFILTER; C:\Windows\SysWow64\Drivers\ASUSFILTER.sys [46152 2011-09-19] (MCCI Corporation)
2 cpuz135; \??\C:\Windows\system32\drivers\cpuz135_x64.sys [21992 2011-09-21] (CPUID)
3 Dot4Print; C:\Windows\System32\DRIVERS\Dot4Prt.sys [19968 2010-11-20] (Microsoft Corporation)
3 ENTECH64; C:\Windows\System32\Drivers\ENTECH64.sys [12744 2007-08-20] (EnTech Taiwan)
0 JRAID; C:\Windows\System32\Drivers\JRAID.sys [120920 2010-08-10] (JMicron Technology Corp.)
3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltjx64.sys [9216 2012-01-09] (Nokia)
3 AIDA64Driver; \??\D:\Programas\AIDA64 Extreme Edition\kerneld.amd64 [x]
3 catchme; [x]
1 cpmlezqs; \??\C:\Windows\system32\drivers\cpmlezqs.sys [x]
3 EagleX64; \??\C:\Users\Ultra\AppData\Local\Temp\EagleX64.sys [x]
1 heocfhew; \??\C:\Windows\system32\drivers\heocfhew.sys [x]
1 swjqyjod; \??\C:\Windows\system32\drivers\swjqyjod.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
3 X6va005; \??\C:\Users\Ultra\AppData\Local\Temp\005B4BC.tmp [x]

========================== NetSvcs (Whitelisted) ===========


============ One Month Created Files and Folders ==============

2012-06-09 03:23 - 2012-06-09 03:24 - 00000000 ____D C:\FRST
2012-06-08 17:39 - 2012-06-08 17:39 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{f06303e1-a68a-11e1-8aaa-5404a64b4a3d}.TxR.blf
2012-06-08 17:36 - 2012-06-08 18:19 - 00000000 ___SD C:\32788R22FWJFW
2012-06-08 17:36 - 2012-06-08 17:32 - 00006396 ____A C:\Users\Ultra\Desktop\MpsSvc.reg
2012-06-08 17:36 - 2012-06-08 17:32 - 00000473 ____A C:\Users\Ultra\Desktop\CFScript.txt
2012-06-08 11:47 - 2012-06-08 11:47 - 00023582 ____A C:\ComboFix.txt
2012-06-08 11:34 - 2012-06-08 11:47 - 00000000 ____D C:\Qoobox
2012-06-08 11:34 - 2012-06-08 11:46 - 00000000 ____D C:\Windows\ERDNT
2012-06-08 11:34 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-06-08 11:34 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-06-08 11:34 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-06-08 11:34 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-06-08 11:34 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-06-08 11:34 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-06-08 11:34 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-06-08 11:34 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-06-08 11:33 - 2012-06-08 11:33 - 00000000 ____D C:\Users\Ultra\AppData\Local\{99442FBA-06B8-48B4-BF89-A5AA0C5E0058}
2012-06-08 11:28 - 2012-06-08 11:27 - 00027648 ____A C:\Users\Ultra\Desktop\RestoreBFE.exe
2012-06-08 10:54 - 2012-06-08 16:28 - 00002644 ____A C:\Users\Ultra\Desktop\FSS.txt
2012-06-08 10:53 - 2012-06-08 10:50 - 00338059 ____A C:\Users\Ultra\Desktop\FSS.exe
2012-06-05 16:55 - 2012-06-05 16:55 - 00009543 ____A C:\Users\Ultra\Desktop\DDS logs.7z
2012-06-05 16:39 - 2012-06-05 16:51 - 00000000 ____D C:\Users\Ultra\Desktop\gmer
2012-06-05 16:39 - 2012-06-05 16:39 - 00294216 ____A C:\Users\Ultra\Desktop\gmer.zip
2012-06-05 16:38 - 2012-06-05 16:38 - 00027838 ____A C:\Users\Ultra\Desktop\DDS.txt
2012-06-05 16:38 - 2012-06-05 16:38 - 00007824 ____A C:\Users\Ultra\Desktop\Attach.txt
2012-06-05 16:29 - 2012-06-05 16:29 - 00607260 ____R (Swearware) C:\Users\Ultra\Desktop\dds.scr
2012-06-05 16:25 - 2012-06-05 16:25 - 00050477 ____A C:\Users\Ultra\Downloads\Defogger.exe
2012-06-05 16:25 - 2012-06-05 16:25 - 00000472 ____A C:\Users\Ultra\Downloads\defogger_disable.log
2012-06-05 16:25 - 2012-06-05 16:25 - 00000000 ____A C:\Users\Ultra\defogger_reenable
2012-06-05 16:18 - 2012-06-05 16:18 - 00000620 ____A C:\Users\Public\Desktop\DriveImage XML.lnk
2012-06-05 16:17 - 2012-06-05 16:17 - 02013115 ____A C:\Users\Ultra\Downloads\dixmlsetup.exe
2012-06-05 16:15 - 2012-06-05 16:16 - 74030592 ____A (Microsoft Corporation) C:\Users\Ultra\Downloads\msert.exe
2012-06-05 16:03 - 2012-06-05 16:03 - 00338059 ____A C:\Users\Ultra\Downloads\FSS.exe
2012-06-05 15:23 - 2012-06-08 10:48 - 04538510 ____R (Swearware) C:\Users\Ultra\Desktop\ComboFix.exe
2012-06-05 15:09 - 2012-06-08 17:43 - 00186276 ____A C:\Windows\ntbtlog.txt
2012-06-05 14:02 - 2012-06-05 14:02 - 00017408 ____A C:\Users\Ultra\AppData\Local\WebpageIcons.db
2012-06-05 13:37 - 2012-06-05 13:37 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\Curiolab
2012-06-05 13:17 - 2012-06-05 13:17 - 04589838 ____A (Curio Lab) C:\Users\Ultra\Downloads\ExterminateItSetup.exe
2012-06-05 09:35 - 2012-06-05 09:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{9FAFA1A0-6DBE-48C9-9261-0AC7B3B047C9}
2012-06-05 09:35 - 2012-06-05 09:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{65A31834-2FB4-46DE-B20E-6960F76ABC65}
2012-06-05 07:02 - 2012-06-05 07:02 - 00000656 ____A C:\Users\Public\Desktop\Max Payne 3.lnk
2012-06-05 04:48 - 2012-06-05 04:48 - 00012243 ____A C:\Users\Ultra\Downloads\E043DA5ADCDE9B0E903636BFB3A0E6B51BDD4C9F.torrent
2012-06-05 04:44 - 2012-06-05 04:44 - 00043236 ____A C:\Users\Ultra\Downloads\083E3B3D13FF63DD167EDA1B20907DEDC6D2F0A6.torrent
2012-06-05 04:35 - 2012-06-05 04:35 - 01376768 ____A C:\Users\Ultra\Downloads\7z920-x64 (1).msi
2012-06-05 04:33 - 2012-06-05 04:33 - 00290830 ____A C:\Users\Ultra\Downloads\Max.Payne.3-RELOADED.torrent
2012-06-04 21:35 - 2012-06-04 21:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{DAF65D90-89EA-4107-B438-A2DF04330B95}
2012-06-04 21:35 - 2012-06-04 21:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{27E01C33-4FBF-426A-9271-2E177652C265}
2012-06-04 17:07 - 2012-06-04 17:07 - 00029192 ____A C:\Users\Ultra\Downloads\Max.Payne.3-Black.Box.torrent
2012-06-04 15:59 - 2012-06-04 15:59 - 00022901 ____A C:\Users\Ultra\Downloads\2991983a1a578c7adbf1c0f76d53fa748245ea45.zip
2012-06-04 14:06 - 2012-06-04 14:06 - 00317861 ____A C:\Users\Ultra\Downloads\OriginalHoverEffects.zip
2012-06-04 11:59 - 2012-06-04 11:59 - 02102899 ____A C:\Users\Ultra\Desktop\Projecto.7z
2012-06-04 09:45 - 2012-06-04 09:45 - 00026430 ____A C:\Users\Ultra\Downloads\580814.zip
2012-06-04 09:35 - 2012-06-04 09:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C6DF2717-BF26-47CF-9BF9-025D181B3D8B}
2012-06-04 09:34 - 2012-06-04 09:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0AF86232-E02C-4312-9D3F-00A6DAF8BD37}
2012-06-03 18:23 - 2012-06-03 18:23 - 00092160 ____A C:\Users\Ultra\Downloads\CVTemplate_pt_PT.doc
2012-06-03 14:43 - 2012-06-03 14:44 - 00000000 ____D C:\Users\Ultra\AppData\Local\{F911B6B8-0D61-4388-A0A1-8B38AC6D0279}
2012-06-03 14:43 - 2012-06-03 14:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{EF8EE191-2460-4867-B7F7-45A01C4D305E}
2012-06-03 07:04 - 2012-06-03 07:04 - 00003584 ____A C:\Users\Ultra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-03 02:43 - 2012-06-03 02:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A4FCA90C-4D83-4641-96A4-EF175BDBCAD8}
2012-06-03 02:43 - 2012-06-03 02:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{24115564-E0D0-41A7-992C-75D613C64883}
2012-06-02 17:31 - 2012-06-02 17:31 - 00000022 ____A C:\Users\Ultra\Downloads\9cc1ab12fdd993709c501f852099158a819bf1fd.zip
2012-06-02 17:21 - 2012-06-02 17:21 - 00023208 ____A C:\Users\Ultra\Downloads\68b0deadae459825376840c8e21630e831ed4ab8.zip
2012-06-02 10:46 - 2012-06-02 10:47 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E3650004-7026-4549-AD46-D32C813E4162}
2012-06-02 10:46 - 2012-06-02 10:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5A606F6A-C010-4E77-9E72-752A1BF4C5AA}
2012-06-02 08:54 - 2012-06-02 08:55 - 12633984 ____A (Microsoft Corporation) C:\Users\Ultra\Downloads\mseinstall (1).exe
2012-06-01 23:41 - 2012-06-01 23:41 - 00000000 ____D C:\Users\All Users\RELOADED
2012-06-01 23:38 - 2012-06-01 23:38 - 00000465 ____A C:\Users\Public\Desktop\Ys Origin.lnk
2012-06-01 22:46 - 2012-06-01 22:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D1B5AA92-5A57-4DE5-8A58-395D8304E2C9}
2012-06-01 22:46 - 2012-06-01 22:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{7387F4DD-0F28-440B-AF44-FB827C335E6A}
2012-06-01 19:31 - 2012-06-01 19:31 - 00029855 ____A C:\Users\Ultra\Downloads\c81cc55670b3ffbefae3bfa1c1a406df5313bfa2.zip
2012-06-01 13:35 - 2012-06-01 13:35 - 03675950 ____A C:\Users\Ultra\Downloads\3AIPCT9R-YMCE-YTB1-JJZT-6X13HP0HNDVP.mp3
2012-06-01 10:46 - 2012-06-01 10:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3452BC41-19C9-44C3-9AD9-D1E2763C3C3F}
2012-06-01 10:45 - 2012-06-01 10:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1BFD8FC6-896A-454F-A931-CFFA86144F62}
2012-05-31 14:23 - 2012-05-31 14:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C98A2A30-0D3F-4016-B322-1D2BB26F71C2}
2012-05-31 14:23 - 2012-05-31 14:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{BD41BE88-08EA-4776-BDE4-58325A4D3632}
2012-05-31 13:56 - 2012-05-31 13:56 - 00042621 ____A C:\Users\Ultra\Downloads\Notas_Trabalhos_Grupo_Casos_Empresa_2012_Jose_Seruya.pdf
2012-05-31 11:45 - 2012-05-31 11:45 - 00025101 ____A C:\Users\Ultra\Downloads\AARAO_REISb79447077b4a3844196557e0f5035825.rar
2012-05-31 02:23 - 2012-05-31 02:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{86EC41D0-570D-4FCC-B968-69B5F9CF8C71}
2012-05-31 02:22 - 2012-05-31 02:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2712B372-7649-4A74-A836-9335F5AC7F88}
2012-05-30 12:54 - 2012-05-30 12:54 - 00000000 ____D C:\Users\Ultra\AppData\Local\{81D996E1-982A-4198-9A37-9ECCC795228C}
2012-05-30 12:53 - 2012-05-30 12:54 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C609F247-90EF-4404-B5A4-9328DC27EAD5}
2012-05-30 12:03 - 2012-05-30 12:03 - 00024456 ____A C:\Users\Ultra\Downloads\The.Finder.S01E01.720p.HDTV.DIMENSION.en_1.zip
2012-05-30 08:10 - 2012-05-30 08:10 - 00030489 ____A C:\Users\Ultra\Downloads\Sociologia - Terrorismo (1).docx
2012-05-30 07:52 - 2012-05-30 07:52 - 00027136 ____A C:\Users\Ultra\Downloads\unrealinfo.doc
2012-05-30 00:53 - 2012-05-30 00:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{91CF110E-1857-4E46-B3C9-324510BC1831}
2012-05-30 00:53 - 2012-05-30 00:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{251B2F34-18DB-4FC7-8A32-DCACF700C773}
2012-05-29 13:51 - 2012-05-29 13:51 - 00004545 ____A C:\Users\Ultra\Downloads\background.gif
2012-05-29 13:49 - 2012-05-29 13:49 - 00002155 ____A C:\Users\Ultra\Downloads\white-background.jpg
2012-05-29 13:14 - 2012-05-29 13:14 - 00030489 ____A C:\Users\Ultra\Downloads\Sociologia - Terrorismo.docx
2012-05-29 09:30 - 2012-05-29 09:30 - 00020403 ____A C:\Users\Ultra\Downloads\583293.zip
2012-05-29 09:27 - 2012-05-29 09:27 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B9AF1D98-1C79-4180-93C6-8EE09D75ED96}
2012-05-29 09:26 - 2012-05-29 09:27 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5320EE8F-4694-47E8-8B54-E5B2E7CA2B60}
2012-05-28 09:46 - 2012-05-28 09:46 - 00000000 ____D C:\Users\All Users\Nexon
2012-05-28 09:44 - 2012-05-28 09:44 - 00000000 ____D C:\Users\Ultra\Documents\Vindictus EU
2012-05-28 09:43 - 2012-05-28 09:43 - 00000193 ____A C:\Users\Public\Desktop\Vindictus EU.url
2012-05-28 09:43 - 2012-05-28 09:43 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
2012-05-28 09:40 - 2012-05-28 09:44 - 00000000 ____D C:\Users\All Users\NexonEU
2012-05-28 08:35 - 2012-05-28 08:37 - 168454136 ____A (NVIDIA Corporation) C:\Users\Ultra\Downloads\301.42-desktop-win7-winvista-64bit-english-whql.exe
2012-05-28 08:34 - 2012-05-28 08:34 - 00227741 ____A C:\Users\Ultra\Downloads\Vindictus_Downloader.exe.zip
2012-05-28 08:30 - 2012-05-28 08:30 - 00536576 ____A (Nexon) C:\Users\Ultra\Downloads\Vindictus_Downloader.exe
2012-05-28 08:30 - 2012-05-28 08:30 - 00536576 ____A (Nexon) C:\Users\Ultra\Downloads\Vindictus_Downloader (1).exe
2012-05-28 08:30 - 2012-05-28 08:30 - 00446464 ____A (NEXON Inc.) C:\Windows\NEXON_EU_DownloaderUpdater.exe
2012-05-28 08:30 - 2012-05-28 08:30 - 00000235 ____A C:\Windows\SysWOW64\nxEuUninstall.bat
2012-05-28 08:30 - 2012-05-28 08:30 - 00000000 ____D C:\Nexon
2012-05-28 08:29 - 2012-05-28 08:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{ED6753E8-BAAE-4D9C-8600-3FC5CEE5AB14}
2012-05-28 08:29 - 2012-05-28 08:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{CE719AC7-7F96-4074-8FAE-009CBAED3116}
2012-05-27 17:50 - 2012-05-27 17:50 - 00047872 ____A C:\Users\Ultra\Downloads\We.Bought.A.Zoo.2011.BluRay.720p.DTS.x264-CHD._www.ENGSUB.NET.zip
2012-05-27 17:49 - 2012-05-27 17:49 - 00019050 ____A C:\Users\Ultra\Downloads\[kat.ph]partyofthree.chloe.taylor.scarlett.rose.wet.pussies.torrent
2012-05-27 17:49 - 2012-05-27 17:49 - 00001502 ____A C:\Users\Ultra\Downloads\[kat.ph]cassie.cruz.scarlett.rose.i.got.a.special.surprise.for.my.girl.bangtryouts.bangbros.08.25.2011.torrent
2012-05-27 13:16 - 2012-05-27 13:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{BDDB38CA-69B5-4FAE-A10A-CAB1F29114E4}
2012-05-27 13:16 - 2012-05-27 13:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3A84A1FB-4891-42DB-8742-A21A550E7B54}
2012-05-27 12:38 - 2012-05-27 12:38 - 00034100 ____A C:\Users\Ultra\Downloads\Relatorio Sociologia.docx
2012-05-27 11:38 - 2012-05-27 11:38 - 00057087 ____A C:\Users\Ultra\Downloads\zach-galifianakis-and-gq-magazine-profile-e1338005796189.jpg
2012-05-27 01:16 - 2012-05-27 01:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C6E19E4A-F66B-4BAE-91AC-1475702E047B}
2012-05-27 01:16 - 2012-05-27 01:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4BB1D6FB-040C-4EBF-9007-5962766F3FF3}
2012-05-26 17:35 - 2012-05-26 17:35 - 00046592 ____A C:\Users\Ultra\Downloads\506253.zip
2012-05-26 13:16 - 2012-05-26 13:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{71D54793-BD96-4736-A048-9988AF7384C4}
2012-05-26 13:15 - 2012-05-26 13:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{91109A78-0B68-4227-9B17-664A66E5AF00}
2012-05-26 03:35 - 2012-05-26 03:35 - 03196928 ____A C:\Users\Ultra\Downloads\videosz-pissing-hour-13.mpg
2012-05-26 03:35 - 2012-05-26 03:35 - 03192832 ____A C:\Users\Ultra\Downloads\videosz-pissing-hour-11.mpg
2012-05-26 03:34 - 2012-05-26 03:34 - 00583095 ____A C:\Users\Ultra\Downloads\0250_02_tgp2.wmv
2012-05-26 01:39 - 2012-05-26 01:39 - 00126402 ____A C:\Users\Ultra\Downloads\ORAL_Presentation_Scores_T5_Michelle_Wells (1).pdf
2012-05-26 01:15 - 2012-05-26 01:15 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3DF5D975-431C-4D6A-8C53-9088F928BC48}
2012-05-26 01:15 - 2012-05-26 01:15 - 00000000 ____D C:\Users\Ultra\AppData\Local\{29008124-0E12-4A09-8679-3778066DD54A}
2012-05-25 11:04 - 2012-05-25 11:04 - 01058767 ____A C:\Users\Ultra\Desktop\www_22032012_Marcos.7z
2012-05-25 09:23 - 2012-05-25 09:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{40D070CC-BE61-48F1-A929-B5BAF1EFEF85}
2012-05-25 09:22 - 2012-05-25 09:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{04BCCDD9-8C31-4FC6-AD7B-BA07B93C33B1}
2012-05-24 21:22 - 2012-05-24 21:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{46AE7AA2-FDE6-4484-8ACC-9651C4D2A666}
2012-05-24 21:22 - 2012-05-24 21:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{34EF7328-6B3C-4DD7-A1DE-6775108567B5}
2012-05-24 16:45 - 2012-05-24 16:45 - 00019933 ____A C:\Users\Ultra\Downloads\578137.zip
2012-05-24 16:03 - 2012-05-24 16:03 - 00000597 ____A C:\Users\Ultra\Downloads\Hot_And_Fire_Girls-Aamy_Spears.xspf
2012-05-24 12:32 - 2012-05-24 12:32 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\LolClient2
2012-05-24 12:14 - 2012-05-24 12:14 - 00126402 ____A C:\Users\Ultra\Downloads\ORAL_Presentation_Scores_T5_Michelle_Wells.pdf
2012-05-24 11:05 - 2012-05-24 12:32 - 00000116 ____A C:\Users\Ultra\Documents\layout.css
2012-05-24 11:05 - 2012-05-24 11:07 - 00000395 ____A C:\Users\Ultra\Documents\index.html
2012-05-24 09:22 - 2012-05-24 09:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E18D100C-B27A-43BB-85D0-25A18BA0A377}
2012-05-24 09:22 - 2012-05-24 09:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{43DC0A1D-A93A-4A08-8F46-1A806357B8F5}
2012-05-23 13:58 - 2012-05-23 13:58 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D5E98A58-9415-42B7-BDBD-D180FAD95FC8}
2012-05-23 13:58 - 2012-05-23 13:58 - 00000000 ____D C:\Users\Ultra\AppData\Local\{6AC72E01-BD43-4E5A-8B50-B81B095B38D8}
2012-05-23 10:02 - 2012-05-23 10:02 - 00000543 ____A C:\Users\Ultra\Downloads\site_descrição (1).txt
2012-05-23 09:57 - 2012-05-23 09:57 - 00167424 ____A C:\Users\Ultra\Downloads\Sociologia - resumos (2).doc
2012-05-23 09:57 - 2012-05-23 09:57 - 00167424 ____A C:\Users\Ultra\Downloads\Sociologia - resumos (1) (1).doc
2012-05-23 09:56 - 2012-05-23 09:56 - 00167424 ____A C:\Users\Ultra\Downloads\Sociologia - resumos (1).doc
2012-05-23 09:56 - 2012-05-23 09:56 - 00000543 ____A C:\Users\Ultra\Downloads\site_descrição.txt
2012-05-23 08:32 - 2012-05-23 08:32 - 00167424 ____A C:\Users\Ultra\Downloads\Sociologia - resumos.doc
2012-05-23 08:31 - 2012-05-23 08:31 - 00027928 ____A C:\Users\Ultra\Downloads\REGULAMENTO DA OFERTA DE BOLSAS DE ESTUDO ITALIANAS A ESTUDANTES PORTUGUESES.docx
2012-05-23 01:57 - 2012-05-23 01:57 - 00000000 ____D C:\Users\Ultra\AppData\Local\{631C1988-A21A-47D1-AC84-846768B06A1D}
2012-05-23 01:57 - 2012-05-23 01:57 - 00000000 ____D C:\Users\Ultra\AppData\Local\{396004BA-EEC2-4FC8-A376-38312EC2F481}
2012-05-22 14:29 - 2012-05-22 14:29 - 00217666 ____A C:\Users\Ultra\Downloads\PT-Subs57e44bf3a84db771e2912e509e42e7d7.rar
2012-05-22 14:28 - 2012-05-22 14:28 - 00317420 ____A C:\Users\Ultra\Downloads\snypaz3251841a338130e703f355f45f0f7c00.rar
2012-05-22 14:23 - 2012-05-22 14:23 - 00303800 ____A C:\Users\Ultra\Downloads\healerbe11dc945159ef0f61915482c967a8ba.rar
2012-05-22 14:20 - 2012-05-22 14:20 - 00422520 ____A (Opensubtitles.org ) C:\Users\Ultra\Downloads\the.wire.the.target.(2002).scc.1cd.(4038327).exe
2012-05-22 14:20 - 2012-05-22 14:20 - 00027829 ____A C:\Users\Ultra\Downloads\the.wire.the.target.(2002).scc.1cd.(4038327).zip
2012-05-22 14:19 - 2012-05-22 14:19 - 00315908 ____A C:\Users\Ultra\Downloads\eaf7ea275138f232dce23b60f4e030b0cd07215c.zip
2012-05-22 12:29 - 2012-05-22 12:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B0FDC97C-01A7-49B8-B249-3CDB3CA88AB6}
2012-05-22 12:29 - 2012-05-22 12:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2DD60F6F-C792-4890-B8AE-926D94DCD44D}
2012-05-22 11:49 - 2012-05-22 11:49 - 00019839 ____A C:\Users\Ultra\Downloads\580795.zip
2012-05-22 01:10 - 2012-05-22 01:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\NokiaAccount
2012-05-22 00:54 - 2012-05-22 01:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\Nokia
2012-05-22 00:54 - 2012-05-22 00:54 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\PC Suite
2012-05-22 00:54 - 2012-05-22 00:54 - 00000000 ____D C:\Users\All Users\PC Suite
2012-05-22 00:53 - 2012-05-22 00:54 - 00002089 ____A C:\Users\Public\Desktop\Nokia Suite.lnk
2012-05-22 00:53 - 2012-05-22 00:54 - 00000000 ____D C:\Users\All Users\Nokia
2012-05-22 00:53 - 2012-05-22 00:53 - 00000000 ____D C:\Program Files\DIFX
2012-05-22 00:53 - 2012-05-22 00:53 - 00000000 ____D C:\Program Files (x86)\PC Connectivity Solution
2012-05-22 00:53 - 2012-04-22 04:51 - 00025600 ____A (Nokia) C:\Windows\System32\Drivers\pccsmcfdx64.sys
2012-05-22 00:50 - 2012-05-22 00:53 - 00000000 ____D C:\Program Files (x86)\Nokia
2012-05-22 00:50 - 2012-05-22 00:50 - 00000000 ____D C:\Users\All Users\NokiaInstallerCache
2012-05-22 00:31 - 2012-05-22 00:31 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_ccdcmbx64_01009.Wdf
2012-05-22 00:28 - 2012-05-22 00:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5354C84D-F91F-4942-BF6A-9634C85710C5}
2012-05-22 00:28 - 2012-05-22 00:28 - 00000000 ____D C:\Users\Ultra\AppData\Local\{45E58DC3-C836-4B37-8614-3E3E91BA71F8}
2012-05-21 16:25 - 2012-05-21 16:25 - 00025911 ____A C:\Users\Ultra\Downloads\bc4b3ec3b04d11d57df9ca4f862cb2f138839277.zip
2012-05-21 13:43 - 2012-05-21 13:43 - 00013675 ____A C:\Users\Ultra\Downloads\[kat.ph]hot.and.fire.girls.aamy.spears.torrent
2012-05-21 13:42 - 2012-05-21 13:42 - 00028390 ____A C:\Users\Ultra\Downloads\[kat.ph]day.with.a.pornstar.xxx.charisma.cappelli.new.july.24.torrent
2012-05-21 13:42 - 2012-05-21 13:42 - 00011633 ____A C:\Users\Ultra\Downloads\[kat.ph]bleepdungeon.charisma.cappelli.2011.torrent
2012-05-21 13:42 - 2012-05-21 13:42 - 00011164 ____A C:\Users\Ultra\Downloads\[kat.ph]dont.tell.my.wife.i.buttfooked.her.best.friend.charisma.cappelli.torrent
2012-05-21 13:42 - 2012-05-21 13:42 - 00008451 ____A C:\Users\Ultra\Downloads\[kat.ph]charisma.cappelli.and.lisa.lipps.2.chicks.same.time.torrent
2012-05-21 13:41 - 2012-05-21 13:41 - 00016558 ____A C:\Users\Ultra\Downloads\[kat.ph]pornfidelity.charisma.cappelli.torrent
2012-05-21 13:38 - 2012-05-21 13:45 - 121270768 ____A C:\Users\Ultra\Downloads\Aimee High Preview (1).wmv
2012-05-21 13:38 - 2012-05-21 13:40 - 28574839 ____A C:\Users\Ultra\Downloads\Sarah V reg 640 Preview (1).wmv
2012-05-21 13:38 - 2012-05-21 13:39 - 25254759 ____A C:\Users\Ultra\Downloads\Rayna reg 640 Preview.wmv
2012-05-21 10:32 - 2012-05-21 06:20 - 07960562 ____N C:\Users\Ultra\Desktop\21052012039.mp4
2012-05-21 09:18 - 2012-05-21 09:18 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0D1C80C6-6752-4759-9565-ED7B40C533AC}
2012-05-21 09:18 - 2012-05-21 09:18 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0390B189-A75E-4336-91BD-9662A1F9E00C}
2012-05-20 16:20 - 2012-05-20 16:20 - 00000022 ____A C:\Users\Ultra\Downloads\577104.zip
2012-05-20 14:50 - 2012-05-20 14:50 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D2105118-EEE5-4F9E-B8DF-14A079D75693}
2012-05-20 14:50 - 2012-05-20 14:50 - 00000000 ____D C:\Users\Ultra\AppData\Local\{37F47588-7889-4DC5-9595-F8A103965061}
2012-05-20 14:39 - 2012-05-20 14:39 - 00036352 ____A C:\Users\Ultra\Downloads\Museus- Educação ou Divertimento.doc
2012-05-20 11:08 - 2012-05-20 11:08 - 00088425 ____A C:\Users\Ultra\Downloads\Apontamentos de Comunicação Televisiva (1).docx
2012-05-20 07:26 - 2012-05-20 07:26 - 03677947 ____A C:\Users\Ultra\Documents\Ronaldo_Workout_pt_PT.pdf
2012-05-20 02:50 - 2012-05-20 02:50 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D838C7C6-76A0-4607-BF30-F2C23A42AC4E}
2012-05-20 02:49 - 2012-05-20 02:50 - 00000000 ____D C:\Users\Ultra\AppData\Local\{554C04D5-A6AA-4BD1-AF73-F390EA9319E2}
2012-05-19 17:05 - 2012-05-19 17:05 - 00018117 ____A C:\Users\Ultra\Downloads\578378.zip
2012-05-19 13:13 - 2012-05-19 13:13 - 00021753 ____A C:\Users\Ultra\Downloads\FacebookIPO2.jpg
2012-05-19 12:42 - 2012-05-19 12:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{93FA97CC-306D-42F1-A983-1A3D4460815C}
2012-05-19 12:42 - 2012-05-19 12:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{41648D25-81C8-45B2-8AE4-A2E6F6DF6649}
2012-05-19 07:18 - 2012-05-19 07:18 - 31523862 ____A C:\Users\Ultra\Downloads\Frets_on_Fire_Songs_-_Anv1.zip
2012-05-19 07:18 - 2012-05-19 07:18 - 00037235 ____A C:\Users\Ultra\Downloads\Frets_on_Fire_Song_Pack_#3_(311_songs).torrent
2012-05-19 07:09 - 2012-05-19 07:10 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\fretsonfire
2012-05-19 07:09 - 2012-05-19 07:09 - 00000696 ____A C:\Users\UpdatusUser\Desktop\Frets on Fire.lnk
2012-05-19 07:08 - 2012-05-19 07:09 - 34874776 ____A C:\Users\Ultra\Downloads\FretsOnFire-1.3.110-win32.exe
2012-05-19 03:19 - 2012-05-19 03:19 - 03175683 ____A C:\Users\Ultra\Downloads\zzhpreview.wmv
2012-05-19 01:26 - 2012-05-19 01:26 - 19337401 ____A C:\Users\Ultra\Downloads\Pos_Producao_Zettl_Jose_Araujo_Jose_Araujo.pdf
2012-05-19 01:26 - 2012-05-19 01:26 - 18024727 ____A C:\Users\Ultra\Downloads\Hitchcock_Explains_About_Cutting_Copia_Jose_Araujo_Jose_Araujo.mp4
2012-05-19 00:42 - 2012-05-19 00:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{F5193CDA-C337-4753-A3CA-BC9B1EDE7C3A}
2012-05-19 00:42 - 2012-05-19 00:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3D13DC09-1D76-492F-B9B7-ABF49AB6A398}
2012-05-18 17:26 - 2012-05-18 17:26 - 00023755 ____A C:\Users\Ultra\Downloads\411405.zip
2012-05-18 16:24 - 2012-05-18 16:24 - 00103407 ____A C:\Users\Ultra\Downloads\Notas_Trabalhos_Sociologia_Comunicacao_Rita_Figueiras.pdf
2012-05-18 15:53 - 2012-05-18 15:53 - 00019486 ____A C:\Users\Ultra\Downloads\[kat.ph]teen.bleep.club.kandi.milan.torrent
2012-05-18 15:53 - 2012-05-18 15:53 - 00017617 ____A C:\Users\Ultra\Downloads\[kat.ph]devilsfilm.kandi.milan.tight.indian.pussy.torrent
2012-05-18 15:53 - 2012-05-18 15:53 - 00011286 ____A C:\Users\Ultra\Downloads\[kat.ph]girlshuntinggirls.ally.ann.kandi.milan.and.tory.lane.torrent
2012-05-18 12:41 - 2012-05-18 12:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{8EBB868F-0D7E-410F-9226-34404EECF240}
2012-05-18 12:41 - 2012-05-18 12:41 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1A6B91E2-C02C-451B-B39E-4D38CC0CE4BC}
2012-05-18 00:41 - 2012-05-18 00:41 - 00000000 ____D C:\Users\Ultra\AppData\Local\{FAB67C2B-0740-4437-B9EC-2D85875337DC}
2012-05-18 00:41 - 2012-05-18 00:41 - 00000000 ____D C:\Users\Ultra\AppData\Local\{634D8E93-6810-497F-A986-0694953C980D}
2012-05-17 13:17 - 2012-05-17 13:17 - 00178478 ____A C:\Users\Ultra\Downloads\gs_CSS_Goncalo_Silva (1).pdf
2012-05-17 13:17 - 2012-05-17 13:17 - 00171841 ____A C:\Users\Ultra\Downloads\gs_HTML_Goncalo_Silva.pdf
2012-05-17 12:29 - 2012-05-17 12:29 - 00024782 ____A C:\Users\Ultra\Downloads\B5550964EFACFAEBAA46BAEBD7AD578774F1B7CE.torrent
2012-05-17 11:29 - 2012-05-17 11:29 - 00386039 ____A C:\Users\Ultra\Downloads\tumblr_lpjwgvrBA01qb82q8o2_250.gif
2012-05-17 11:22 - 2012-05-17 11:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3483B2A9-DB49-41D2-8637-2343392B6792}
2012-05-17 11:21 - 2012-05-17 11:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{AED4EA71-F32B-4CBE-BEDD-7C7606F20749}
2012-05-16 23:21 - 2012-05-16 23:21 - 00000000 ____D C:\Users\Ultra\AppData\Local\{AEE4ED56-F767-444D-8020-15268E018100}
2012-05-16 23:21 - 2012-05-16 23:21 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1917766F-6A11-42FA-92A8-488CB49015E0}
2012-05-16 17:00 - 2012-05-16 17:00 - 00138700 ____A C:\Users\Ultra\Downloads\Guião Italiano.pdf
2012-05-16 14:23 - 2012-05-16 14:23 - 00025204 ____A C:\Users\Ultra\Downloads\b4dec57ae54dbb315e5926cda13a8978157138d4.zip
2012-05-16 13:47 - 2012-05-16 14:32 - 00003042 ____A C:\Users\Ultra\Desktop\layout.css
2012-05-16 13:47 - 2012-05-16 14:28 - 00004857 ____A C:\Users\Ultra\Desktop\index.html
2012-05-16 13:47 - 2012-05-14 07:35 - 00007065 ____A C:\Users\Ultra\Desktop\tratada.jpg
2012-05-16 11:50 - 2012-05-16 11:50 - 04909628 ____A C:\Users\Ultra\Downloads\Turno5_Goncalo_Silva.zip
2012-05-16 11:50 - 2012-05-16 11:50 - 04419192 ____A (Krzysztof Kowalczyk) C:\Users\Ultra\Downloads\SumatraPDF-2.1.1-install.exe
2012-05-16 11:50 - 2012-05-16 11:50 - 00576069 ____A C:\Users\Ultra\Downloads\Html_Cheat_Sheet_V1_Goncalo_Silva_3.pdf
2012-05-16 11:50 - 2012-05-16 11:50 - 00178478 ____A C:\Users\Ultra\Downloads\gs_CSS_Goncalo_Silva.pdf
2012-05-16 09:59 - 2012-05-16 09:59 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C9589BFA-4994-46C1-8C11-6F6718944E0F}
2012-05-16 09:59 - 2012-05-16 09:59 - 00000000 ____D C:\Users\Ultra\AppData\Local\{89D62C28-6808-4491-8C9F-FA173D3D39D8}
2012-05-15 16:14 - 2012-05-15 16:14 - 00020440 ____A C:\Users\Ultra\Downloads\8d57ac7e5628280aedcda2daee85dac7d71a2b8e.zip
2012-05-15 13:46 - 2012-05-15 13:46 - 00010097 ____A C:\Users\Ultra\Downloads\[kat.ph]hawaii.five.0.2010.s02e23.720p.hdtv.x264.2hd.publichd.torrent
2012-05-15 13:45 - 2012-05-15 13:45 - 00008752 ____A C:\Users\Ultra\Downloads\[isoHunt] b5888a87213031398847f57b56d40e9fcfc5fd6d.torrent
2012-05-15 13:44 - 2012-05-15 13:44 - 00007545 ____A C:\Users\Ultra\Downloads\[isoHunt] House.S08E21.720p.WEB-DL.DD5.1.H.264-POD [PublicHD].torrent
2012-05-15 11:36 - 2012-05-15 11:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B40A570B-6ED6-42B4-8EAA-AE0F63398ACC}
2012-05-15 11:35 - 2012-05-15 11:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{F6CEF80B-F14C-49C8-9FD4-020C7183825F}
2012-05-14 15:30 - 2012-05-14 15:30 - 00020742 ____A C:\Users\Ultra\Downloads\575246.zip
2012-05-14 14:56 - 2012-05-14 14:56 - 00000000 ____D C:\Users\Ultra\AppData\Local\{991A722E-1C02-40E8-8EE4-19298CD23823}
2012-05-14 14:56 - 2012-05-14 14:56 - 00000000 ____D C:\Users\Ultra\AppData\Local\{462A7163-FA36-409C-B1EA-FD0EBFDA1A40}
2012-05-14 14:10 - 2012-05-14 14:10 - 00027770 ____A C:\Users\Ultra\Downloads\horatio-caine-csi.jpg
2012-05-14 07:35 - 2012-05-14 07:35 - 00211949 ____A C:\Users\Ultra\Downloads\www_22032012.zip
2012-05-14 04:25 - 2012-05-14 04:25 - 00020161 ____A C:\Users\Ultra\Downloads\572087.zip
2012-05-14 03:35 - 2012-05-14 03:35 - 00021440 ____A C:\Users\Ultra\Downloads\Person.of.Interest.S01E20.720p.HDTV.X264-DIMENSION._www.ENGSUB.NET.zip
2012-05-14 03:15 - 2012-05-14 03:15 - 00000000 ____D C:\Users\Ultra\Documents\DS Wood Backup
2012-05-14 03:14 - 2012-04-20 12:06 - 00000000 ____D C:\Users\Ultra\Desktop\__rpg
2012-05-14 03:14 - 2012-04-20 03:07 - 00001098 ____A C:\Users\Ultra\Desktop\changelog.txt
2012-05-14 03:14 - 2012-04-19 20:44 - 00397376 ____A C:\Users\Ultra\Desktop\_DS_MENU.DAT
2012-05-14 03:14 - 2012-02-02 21:20 - 00011896 ____A C:\Users\Ultra\Desktop\readme.txt
2012-05-14 03:11 - 2012-05-14 03:11 - 01629727 ____A C:\Users\Ultra\Downloads\Wood_R4_v1.47.rar
2012-05-14 02:55 - 2012-05-14 02:56 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B651CD4C-1BB7-4B73-A384-CEF4C04A8534}
2012-05-14 02:55 - 2012-05-14 02:55 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1FA356C4-4AD6-4BA8-BE2E-68C13460C4F7}
2012-05-13 16:11 - 2012-05-13 16:11 - 00017193 ____A C:\Users\Ultra\Downloads\575209.zip
2012-05-13 16:11 - 2012-05-13 16:11 - 00017193 ____A C:\Users\Ultra\Downloads\575209 (1).zip
2012-05-13 15:51 - 2012-05-13 15:51 - 00025524 ____A C:\Users\Ultra\Downloads\3e9f9de423983e8d2e3774272bb01b4bfc8b9f54.zip
2012-05-13 15:50 - 2012-05-13 15:50 - 00026919 ____A C:\Users\Ultra\Downloads\477c19a61e38c16dfac31fd05e98fcdad70db47c.zip
2012-05-13 15:49 - 2012-05-13 15:49 - 00025229 ____A C:\Users\Ultra\Downloads\caaa8fb5be80ebee80a8228a72f1100d976654ca.zip
2012-05-13 15:49 - 2012-05-13 15:49 - 00024490 ____A C:\Users\Ultra\Downloads\68fbbb06fb8a5b8e6015a36bf1e6efe078a39913.zip
2012-05-13 15:48 - 2012-05-13 15:48 - 00025954 ____A C:\Users\Ultra\Downloads\dbb26cb8501aeb604c448291f514d64193aebcd1.zip
2012-05-13 12:21 - 2012-05-13 12:21 - 00021001 ____A C:\Users\Ultra\Downloads\E18938ECED029432584752BA641376F1CA9CFCB5.torrent
2012-05-13 12:18 - 2012-05-13 12:18 - 00270228 ____A C:\Users\Ultra\Downloads\Inazuma 11.rar
2012-05-13 10:36 - 2012-05-13 10:37 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1F1262BE-CE4B-4731-A24C-4E891BABEE94}
2012-05-13 10:36 - 2012-05-13 10:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{19B1B3A1-4B5E-40CA-A4F3-740B1E474356}
2012-05-13 03:36 - 2012-05-13 03:36 - 00071196 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.abby.one.night.stand.720p.may.02.2012.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00052971 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.pretty.back.door.baby.linsay.720p.wmv.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00036261 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.slow.motion.erica.1080p.mov.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00035974 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.perfect.blonde.mary.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00034499 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.introducing.diana.1080p.mov.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00020178 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.gabriella.siempre.en.mi.corazon.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00019553 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.ivy.lunchtime.fantasy.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00014118 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.caprice.bleep.perfection.torrent
2012-05-13 03:30 - 2012-05-13 03:30 - 01951383 ____A C:\Users\Ultra\Downloads\jimmycanon-bree.wmv
2012-05-13 03:18 - 2012-05-13 03:22 - 48858842 ____A C:\Users\Ultra\Downloads\Cherry Poppins Deep Throated free9000info.avi
2012-05-12 22:36 - 2012-05-12 22:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E820D5B4-C0AD-4B43-BF6C-5770B9351499}
2012-05-12 22:36 - 2012-05-12 22:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5303A074-0CFD-4F28-95E4-490EC691E277}
2012-05-12 10:47 - 2012-05-12 10:47 - 00020483 ____A C:\Users\Ultra\Downloads\9cc31dfc101a6099ec8f8a3c1f723fab795ee6ba.zip
2012-05-12 10:36 - 2012-05-12 10:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A4C127FE-72C5-4C7B-8157-9ECC0558CE18}
2012-05-12 10:36 - 2012-05-12 10:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{533EB4A8-1C60-40A8-BB73-0557C25BF3F3}
2012-05-11 22:35 - 2012-05-11 22:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C67DEDF2-90D6-42F7-8D5E-EFEBDCC5F3FC}
2012-05-11 22:35 - 2012-05-11 22:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B7EBFBA8-5380-4A79-8484-C3CF892FED6E}
2012-05-11 19:12 - 2012-05-11 19:48 - 332702746 ____A C:\Users\Ultra\Downloads\Christy Mack - Titty Attack.avi
2012-05-11 18:51 - 2012-05-11 18:51 - 00227928 ____A C:\Users\Ultra\Downloads\KarupsHA.12.01.12.Aamy.Spears.Solo.1.XXX.720p.MP4-KTR.exe
2012-05-11 18:51 - 2012-05-11 18:51 - 00027275 ____A C:\Users\Ultra\Downloads\2547591314767065089275E181DB07CA70E0A47D.torrent
2012-05-11 18:51 - 2012-05-11 18:51 - 00023918 ____A C:\Users\Ultra\Downloads\E99C222D891AFF1B9615E4DE92FBB2F9915349A7.torrent
2012-05-11 12:39 - 2012-05-11 12:39 - 00014321 ____A C:\Users\Ultra\Downloads\[isoHunt] BigNaturals_-_Jen_Capone_(Best_Breast)_-_great_big_tits.5106497.TPB.torrent
2012-05-11 12:30 - 2012-05-11 12:30 - 00019172 ____A C:\Users\Ultra\Downloads\RealityKings-HotBush_-_Jen_Capone.5635829.TPB.torrent
2012-05-11 12:03 - 2012-05-11 12:03 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-11 12:03 - 2012-05-11 12:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-11 10:35 - 2012-05-11 10:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{8BCB1FDB-4BF9-4E32-BD89-CF8351CE3481}
2012-05-11 10:35 - 2012-05-11 10:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{7D52B79F-1FB2-4821-826E-1E0C365D259E}
2012-05-10 22:34 - 2012-05-10 22:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E8AC6FD9-CEC2-45B0-8855-D08E128B7928}
2012-05-10 22:34 - 2012-05-10 22:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4D873341-111F-48AA-BC72-0975027AC1B1}
2012-05-10 13:13 - 2012-05-10 13:13 - 00000000 ____D C:\Users\Ultra\Documents\Dreamweaver
2012-05-10 10:45 - 2012-05-10 10:45 - 00149532 ____A C:\Users\Ultra\Downloads\Eldermana335dd3a05fdb3142f5873352474407b.zip
2012-05-10 10:34 - 2012-05-10 10:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A77C31C8-A2C3-4C8A-A171-E66858FBDF2E}
2012-05-10 10:34 - 2012-05-10 10:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{281EFAA9-F503-4693-B43F-6014EB402864}

============ 3 Months Modified Files and Folders =============

2012-06-08 18:19 - 2012-06-08 17:36 - 00000000 ___SD C:\32788R22FWJFW
2012-06-08 18:19 - 2012-01-28 08:12 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\uTorrent
2012-06-08 18:19 - 2009-07-13 21:08 - 00032538 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-08 18:18 - 2012-02-22 13:26 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\Dropbox
2012-06-08 18:18 - 2012-01-28 12:54 - 00000000 ____D C:\Users\All Users\NVIDIA
2012-06-08 18:18 - 2012-01-28 07:46 - 00001006 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-08 18:18 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-08 18:18 - 2009-07-13 20:51 - 00037573 ____A C:\Windows\setupact.log
2012-06-08 18:17 - 2012-01-28 07:31 - 02040539 ____A C:\Windows\WindowsUpdate.log
2012-06-08 18:09 - 2009-08-15 09:10 - 00688664 ____A C:\Windows\System32\prfh0816.dat
2012-06-08 18:09 - 2009-08-15 09:10 - 00138606 ____A C:\Windows\System32\prfc0816.dat
2012-06-08 18:09 - 2009-07-13 21:13 - 01566356 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-08 18:08 - 2009-07-13 20:45 - 00010800 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-08 18:08 - 2009-07-13 20:45 - 00010800 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-08 18:02 - 2012-02-22 13:27 - 00000000 ___RD C:\Users\Ultra\Dropbox
2012-06-08 17:43 - 2012-06-05 15:09 - 00186276 ____A C:\Windows\ntbtlog.txt
2012-06-08 17:39 - 2012-06-08 17:39 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{f06303e1-a68a-11e1-8aaa-5404a64b4a3d}.TxR.blf
2012-06-08 17:33 - 2012-01-28 07:52 - 00025718 ____A C:\Windows\PFRO.log
2012-06-08 17:32 - 2012-06-08 17:36 - 00006396 ____A C:\Users\Ultra\Desktop\MpsSvc.reg
2012-06-08 17:32 - 2012-06-08 17:36 - 00000473 ____A C:\Users\Ultra\Desktop\CFScript.txt
2012-06-08 16:33 - 2012-04-02 11:29 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-08 16:28 - 2012-06-08 10:54 - 00002644 ____A C:\Users\Ultra\Desktop\FSS.txt
2012-06-08 16:24 - 2012-01-28 07:46 - 00001010 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-08 11:47 - 2012-06-08 11:47 - 00023582 ____A C:\ComboFix.txt
2012-06-08 11:47 - 2012-06-08 11:34 - 00000000 ____D C:\Qoobox
2012-06-08 11:47 - 2009-07-13 19:20 - 00000000 __RHD C:\users\Default
2012-06-08 11:46 - 2012-06-08 11:34 - 00000000 ____D C:\Windows\ERDNT
2012-06-08 11:43 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini
2012-06-08 11:43 - 2009-07-13 18:34 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts
2012-06-08 11:33 - 2012-06-08 11:33 - 00000000 ____D C:\Users\Ultra\AppData\Local\{99442FBA-06B8-48B4-BF89-A5AA0C5E0058}
2012-06-08 11:32 - 2012-01-28 10:25 - 00000000 ____D C:\Users\Ultra\Tracing
2012-06-08 11:27 - 2012-06-08 11:28 - 00027648 ____A C:\Users\Ultra\Desktop\RestoreBFE.exe
2012-06-08 10:50 - 2012-06-08 10:53 - 00338059 ____A C:\Users\Ultra\Desktop\FSS.exe
2012-06-08 10:48 - 2012-06-05 15:23 - 04538510 ____R (Swearware) C:\Users\Ultra\Desktop\ComboFix.exe
2012-06-05 16:55 - 2012-06-05 16:55 - 00009543 ____A C:\Users\Ultra\Desktop\DDS logs.7z
2012-06-05 16:51 - 2012-06-05 16:39 - 00000000 ____D C:\Users\Ultra\Desktop\gmer
2012-06-05 16:39 - 2012-06-05 16:39 - 00294216 ____A C:\Users\Ultra\Desktop\gmer.zip
2012-06-05 16:38 - 2012-06-05 16:38 - 00027838 ____A C:\Users\Ultra\Desktop\DDS.txt
2012-06-05 16:38 - 2012-06-05 16:38 - 00007824 ____A C:\Users\Ultra\Desktop\Attach.txt
2012-06-05 16:29 - 2012-06-05 16:29 - 00607260 ____R (Swearware) C:\Users\Ultra\Desktop\dds.scr
2012-06-05 16:25 - 2012-06-05 16:25 - 00050477 ____A C:\Users\Ultra\Downloads\Defogger.exe
2012-06-05 16:25 - 2012-06-05 16:25 - 00000472 ____A C:\Users\Ultra\Downloads\defogger_disable.log
2012-06-05 16:25 - 2012-06-05 16:25 - 00000000 ____A C:\Users\Ultra\defogger_reenable
2012-06-05 16:25 - 2012-01-28 07:34 - 00000000 ____D C:\users\Ultra
2012-06-05 16:18 - 2012-06-05 16:18 - 00000620 ____A C:\Users\Public\Desktop\DriveImage XML.lnk
2012-06-05 16:17 - 2012-06-05 16:17 - 02013115 ____A C:\Users\Ultra\Downloads\dixmlsetup.exe
2012-06-05 16:16 - 2012-06-05 16:15 - 74030592 ____A (Microsoft Corporation) C:\Users\Ultra\Downloads\msert.exe
2012-06-05 16:03 - 2012-06-05 16:03 - 00338059 ____A C:\Users\Ultra\Downloads\FSS.exe
2012-06-05 14:27 - 2012-01-28 14:25 - 00000000 ____D C:\Windows\Minidump
2012-06-05 14:02 - 2012-06-05 14:02 - 00017408 ____A C:\Users\Ultra\AppData\Local\WebpageIcons.db
2012-06-05 13:58 - 2012-01-28 08:08 - 00001912 ____A C:\Windows\epplauncher.mif
2012-06-05 13:37 - 2012-06-05 13:37 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\Curiolab
2012-06-05 13:17 - 2012-06-05 13:17 - 04589838 ____A (Curio Lab) C:\Users\Ultra\Downloads\ExterminateItSetup.exe
2012-06-05 12:59 - 2012-01-28 07:54 - 00110776 ____A C:\Users\Ultra\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-05 12:58 - 2009-07-13 20:45 - 04981560 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-05 12:57 - 2012-01-28 10:12 - 00000000 ____D C:\Program Files (x86)\Pando Networks
2012-06-05 09:35 - 2012-06-05 09:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{9FAFA1A0-6DBE-48C9-9261-0AC7B3B047C9}
2012-06-05 09:35 - 2012-06-05 09:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{65A31834-2FB4-46DE-B20E-6960F76ABC65}
2012-06-05 09:35 - 2012-01-28 10:19 - 00000000 ____D C:\Users\Ultra\AppData\Local\Windows Live
2012-06-05 07:09 - 2012-01-28 13:01 - 00000000 ____D C:\Users\Ultra\Documents\Rockstar Games
2012-06-05 07:02 - 2012-06-05 07:02 - 00000656 ____A C:\Users\Public\Desktop\Max Payne 3.lnk
2012-06-05 07:02 - 2012-01-28 09:55 - 00000000 ____D C:\Windows\SysWOW64\directx
2012-06-05 04:48 - 2012-06-05 04:48 - 00012243 ____A C:\Users\Ultra\Downloads\E043DA5ADCDE9B0E903636BFB3A0E6B51BDD4C9F.torrent
2012-06-05 04:44 - 2012-06-05 04:44 - 00043236 ____A C:\Users\Ultra\Downloads\083E3B3D13FF63DD167EDA1B20907DEDC6D2F0A6.torrent
2012-06-05 04:35 - 2012-06-05 04:35 - 01376768 ____A C:\Users\Ultra\Downloads\7z920-x64 (1).msi
2012-06-05 04:33 - 2012-06-05 04:33 - 00290830 ____A C:\Users\Ultra\Downloads\Max.Payne.3-RELOADED.torrent
2012-06-05 03:49 - 2012-03-14 13:11 - 00001390 ____A C:\Users\All Users\hpzinstall.log
2012-06-04 21:35 - 2012-06-04 21:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{DAF65D90-89EA-4107-B438-A2DF04330B95}
2012-06-04 21:35 - 2012-06-04 21:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{27E01C33-4FBF-426A-9271-2E177652C265}
2012-06-04 17:07 - 2012-06-04 17:07 - 00029192 ____A C:\Users\Ultra\Downloads\Max.Payne.3-Black.Box.torrent
2012-06-04 15:59 - 2012-06-04 15:59 - 00022901 ____A C:\Users\Ultra\Downloads\2991983a1a578c7adbf1c0f76d53fa748245ea45.zip
2012-06-04 15:29 - 2012-01-28 15:16 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\Skype
2012-06-04 14:06 - 2012-06-04 14:06 - 00317861 ____A C:\Users\Ultra\Downloads\OriginalHoverEffects.zip
2012-06-04 11:59 - 2012-06-04 11:59 - 02102899 ____A C:\Users\Ultra\Desktop\Projecto.7z
2012-06-04 09:45 - 2012-06-04 09:45 - 00026430 ____A C:\Users\Ultra\Downloads\580814.zip
2012-06-04 09:35 - 2012-06-04 09:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C6DF2717-BF26-47CF-9BF9-025D181B3D8B}
2012-06-04 09:35 - 2012-06-04 09:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0AF86232-E02C-4312-9D3F-00A6DAF8BD37}
2012-06-03 18:23 - 2012-06-03 18:23 - 00092160 ____A C:\Users\Ultra\Downloads\CVTemplate_pt_PT.doc
2012-06-03 14:44 - 2012-06-03 14:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{F911B6B8-0D61-4388-A0A1-8B38AC6D0279}
2012-06-03 14:43 - 2012-06-03 14:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{EF8EE191-2460-4867-B7F7-45A01C4D305E}
2012-06-03 07:04 - 2012-06-03 07:04 - 00003584 ____A C:\Users\Ultra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-03 07:01 - 2012-02-22 13:27 - 00001017 ____A C:\Users\Ultra\Desktop\Dropbox.lnk
2012-06-03 02:43 - 2012-06-03 02:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A4FCA90C-4D83-4641-96A4-EF175BDBCAD8}
2012-06-03 02:43 - 2012-06-03 02:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{24115564-E0D0-41A7-992C-75D613C64883}
2012-06-02 17:31 - 2012-06-02 17:31 - 00000022 ____A C:\Users\Ultra\Downloads\9cc1ab12fdd993709c501f852099158a819bf1fd.zip
2012-06-02 17:21 - 2012-06-02 17:21 - 00023208 ____A C:\Users\Ultra\Downloads\68b0deadae459825376840c8e21630e831ed4ab8.zip
2012-06-02 10:47 - 2012-06-02 10:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E3650004-7026-4549-AD46-D32C813E4162}
2012-06-02 10:46 - 2012-06-02 10:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5A606F6A-C010-4E77-9E72-752A1BF4C5AA}
2012-06-02 09:08 - 2012-01-28 08:08 - 01583842 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-02 08:55 - 2012-06-02 08:54 - 12633984 ____A (Microsoft Corporation) C:\Users\Ultra\Downloads\mseinstall (1).exe
2012-06-01 23:41 - 2012-06-01 23:41 - 00000000 ____D C:\Users\All Users\RELOADED
2012-06-01 23:38 - 2012-06-01 23:38 - 00000465 ____A C:\Users\Public\Desktop\Ys Origin.lnk
2012-06-01 22:46 - 2012-06-01 22:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D1B5AA92-5A57-4DE5-8A58-395D8304E2C9}
2012-06-01 22:46 - 2012-06-01 22:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{7387F4DD-0F28-440B-AF44-FB827C335E6A}
2012-06-01 19:31 - 2012-06-01 19:31 - 00029855 ____A C:\Users\Ultra\Downloads\c81cc55670b3ffbefae3bfa1c1a406df5313bfa2.zip
2012-06-01 13:35 - 2012-06-01 13:35 - 03675950 ____A C:\Users\Ultra\Downloads\3AIPCT9R-YMCE-YTB1-JJZT-6X13HP0HNDVP.mp3
2012-06-01 10:46 - 2012-06-01 10:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3452BC41-19C9-44C3-9AD9-D1E2763C3C3F}
2012-06-01 10:46 - 2012-06-01 10:45 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1BFD8FC6-896A-454F-A931-CFFA86144F62}
2012-05-31 16:08 - 2012-01-30 11:10 - 00000000 ____D C:\Users\Ultra\Documents\Os meus ficheiros recebidos
2012-05-31 14:23 - 2012-05-31 14:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C98A2A30-0D3F-4016-B322-1D2BB26F71C2}
2012-05-31 14:23 - 2012-05-31 14:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{BD41BE88-08EA-4776-BDE4-58325A4D3632}
2012-05-31 13:56 - 2012-05-31 13:56 - 00042621 ____A C:\Users\Ultra\Downloads\Notas_Trabalhos_Grupo_Casos_Empresa_2012_Jose_Seruya.pdf
2012-05-31 11:52 - 2012-04-18 15:52 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\HpUpdate
2012-05-31 11:45 - 2012-05-31 11:45 - 00025101 ____A C:\Users\Ultra\Downloads\AARAO_REISb79447077b4a3844196557e0f5035825.rar
2012-05-31 08:47 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-05-31 02:23 - 2012-05-31 02:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{86EC41D0-570D-4FCC-B968-69B5F9CF8C71}
2012-05-31 02:23 - 2012-05-31 02:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2712B372-7649-4A74-A836-9335F5AC7F88}
2012-05-30 12:54 - 2012-05-30 12:54 - 00000000 ____D C:\Users\Ultra\AppData\Local\{81D996E1-982A-4198-9A37-9ECCC795228C}
2012-05-30 12:54 - 2012-05-30 12:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C609F247-90EF-4404-B5A4-9328DC27EAD5}
2012-05-30 12:03 - 2012-05-30 12:03 - 00024456 ____A C:\Users\Ultra\Downloads\The.Finder.S01E01.720p.HDTV.DIMENSION.en_1.zip
2012-05-30 08:10 - 2012-05-30 08:10 - 00030489 ____A C:\Users\Ultra\Downloads\Sociologia - Terrorismo (1).docx
2012-05-30 07:52 - 2012-05-30 07:52 - 00027136 ____A C:\Users\Ultra\Downloads\unrealinfo.doc
2012-05-30 00:53 - 2012-05-30 00:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{91CF110E-1857-4E46-B3C9-324510BC1831}
2012-05-30 00:53 - 2012-05-30 00:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{251B2F34-18DB-4FC7-8A32-DCACF700C773}
2012-05-29 13:51 - 2012-05-29 13:51 - 00004545 ____A C:\Users\Ultra\Downloads\background.gif
2012-05-29 13:49 - 2012-05-29 13:49 - 00002155 ____A C:\Users\Ultra\Downloads\white-background.jpg
2012-05-29 13:14 - 2012-05-29 13:14 - 00030489 ____A C:\Users\Ultra\Downloads\Sociologia - Terrorismo.docx
2012-05-29 11:51 - 2012-01-28 07:34 - 00000000 ____D C:\Users\Ultra\AppData\LocalLow
2012-05-29 09:30 - 2012-05-29 09:30 - 00020403 ____A C:\Users\Ultra\Downloads\583293.zip
2012-05-29 09:27 - 2012-05-29 09:27 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B9AF1D98-1C79-4180-93C6-8EE09D75ED96}
2012-05-29 09:27 - 2012-05-29 09:26 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5320EE8F-4694-47E8-8B54-E5B2E7CA2B60}
2012-05-28 09:46 - 2012-05-28 09:46 - 00000000 ____D C:\Users\All Users\Nexon
2012-05-28 09:44 - 2012-05-28 09:44 - 00000000 ____D C:\Users\Ultra\Documents\Vindictus EU
2012-05-28 09:44 - 2012-05-28 09:40 - 00000000 ____D C:\Users\All Users\NexonEU
2012-05-28 09:43 - 2012-05-28 09:43 - 00000193 ____A C:\Users\Public\Desktop\Vindictus EU.url
2012-05-28 09:43 - 2012-05-28 09:43 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
2012-05-28 09:24 - 2012-05-01 12:19 - 00000000 ____D C:\Users\Ultra\AppData\Local\Facebook
2012-05-28 09:01 - 2012-01-28 08:53 - 05216304 ____A C:\Windows\PE_Rom.dll
2012-05-28 08:37 - 2012-05-28 08:35 - 168454136 ____A (NVIDIA Corporation) C:\Users\Ultra\Downloads\301.42-desktop-win7-winvista-64bit-english-whql.exe
2012-05-28 08:34 - 2012-05-28 08:34 - 00227741 ____A C:\Users\Ultra\Downloads\Vindictus_Downloader.exe.zip
2012-05-28 08:31 - 2012-02-07 03:22 - 00000000 ____D C:\Windows\System32\appmgmt
2012-05-28 08:30 - 2012-05-28 08:30 - 00536576 ____A (Nexon) C:\Users\Ultra\Downloads\Vindictus_Downloader.exe
2012-05-28 08:30 - 2012-05-28 08:30 - 00536576 ____A (Nexon) C:\Users\Ultra\Downloads\Vindictus_Downloader (1).exe
2012-05-28 08:30 - 2012-05-28 08:30 - 00446464 ____A (NEXON Inc.) C:\Windows\NEXON_EU_DownloaderUpdater.exe
2012-05-28 08:30 - 2012-05-28 08:30 - 00000235 ____A C:\Windows\SysWOW64\nxEuUninstall.bat
2012-05-28 08:30 - 2012-05-28 08:30 - 00000000 ____D C:\Nexon
2012-05-28 08:29 - 2012-05-28 08:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{ED6753E8-BAAE-4D9C-8600-3FC5CEE5AB14}
2012-05-28 08:29 - 2012-05-28 08:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{CE719AC7-7F96-4074-8FAE-009CBAED3116}
2012-05-27 17:50 - 2012-05-27 17:50 - 00047872 ____A C:\Users\Ultra\Downloads\We.Bought.A.Zoo.2011.BluRay.720p.DTS.x264-CHD._www.ENGSUB.NET.zip
2012-05-27 17:49 - 2012-05-27 17:49 - 00019050 ____A C:\Users\Ultra\Downloads\[kat.ph]partyofthree.chloe.taylor.scarlett.rose.wet.pussies.torrent
2012-05-27 17:49 - 2012-05-27 17:49 - 00001502 ____A C:\Users\Ultra\Downloads\[kat.ph]cassie.cruz.scarlett.rose.i.got.a.special.surprise.for.my.girl.bangtryouts.bangbros.08.25.2011.torrent
2012-05-27 13:16 - 2012-05-27 13:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{BDDB38CA-69B5-4FAE-A10A-CAB1F29114E4}
2012-05-27 13:16 - 2012-05-27 13:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3A84A1FB-4891-42DB-8742-A21A550E7B54}
2012-05-27 12:38 - 2012-05-27 12:38 - 00034100 ____A C:\Users\Ultra\Downloads\Relatorio Sociologia.docx
2012-05-27 11:38 - 2012-05-27 11:38 - 00057087 ____A C:\Users\Ultra\Downloads\zach-galifianakis-and-gq-magazine-profile-e1338005796189.jpg
2012-05-27 01:16 - 2012-05-27 01:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C6E19E4A-F66B-4BAE-91AC-1475702E047B}
2012-05-27 01:16 - 2012-05-27 01:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4BB1D6FB-040C-4EBF-9007-5962766F3FF3}
2012-05-26 17:35 - 2012-05-26 17:35 - 00046592 ____A C:\Users\Ultra\Downloads\506253.zip
2012-05-26 13:16 - 2012-05-26 13:16 - 00000000 ____D C:\Users\Ultra\AppData\Local\{71D54793-BD96-4736-A048-9988AF7384C4}
2012-05-26 13:16 - 2012-05-26 13:15 - 00000000 ____D C:\Users\Ultra\AppData\Local\{91109A78-0B68-4227-9B17-664A66E5AF00}
2012-05-26 03:35 - 2012-05-26 03:35 - 03196928 ____A C:\Users\Ultra\Downloads\videosz-pissing-hour-13.mpg
2012-05-26 03:35 - 2012-05-26 03:35 - 03192832 ____A C:\Users\Ultra\Downloads\videosz-pissing-hour-11.mpg
2012-05-26 03:34 - 2012-05-26 03:34 - 00583095 ____A C:\Users\Ultra\Downloads\0250_02_tgp2.wmv
2012-05-26 01:39 - 2012-05-26 01:39 - 00126402 ____A C:\Users\Ultra\Downloads\ORAL_Presentation_Scores_T5_Michelle_Wells (1).pdf
2012-05-26 01:15 - 2012-05-26 01:15 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3DF5D975-431C-4D6A-8C53-9088F928BC48}
2012-05-26 01:15 - 2012-05-26 01:15 - 00000000 ____D C:\Users\Ultra\AppData\Local\{29008124-0E12-4A09-8679-3778066DD54A}
2012-05-25 11:04 - 2012-05-25 11:04 - 01058767 ____A C:\Users\Ultra\Desktop\www_22032012_Marcos.7z
2012-05-25 09:23 - 2012-05-25 09:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{40D070CC-BE61-48F1-A929-B5BAF1EFEF85}
2012-05-25 09:23 - 2012-05-25 09:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{04BCCDD9-8C31-4FC6-AD7B-BA07B93C33B1}
2012-05-24 21:22 - 2012-05-24 21:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{46AE7AA2-FDE6-4484-8ACC-9651C4D2A666}
2012-05-24 21:22 - 2012-05-24 21:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{34EF7328-6B3C-4DD7-A1DE-6775108567B5}
2012-05-24 16:45 - 2012-05-24 16:45 - 00019933 ____A C:\Users\Ultra\Downloads\578137.zip
2012-05-24 16:03 - 2012-05-24 16:03 - 00000597 ____A C:\Users\Ultra\Downloads\Hot_And_Fire_Girls-Aamy_Spears.xspf
2012-05-24 12:32 - 2012-05-24 12:32 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\LolClient2
2012-05-24 12:32 - 2012-05-24 11:05 - 00000116 ____A C:\Users\Ultra\Documents\layout.css
2012-05-24 12:14 - 2012-05-24 12:14 - 00126402 ____A C:\Users\Ultra\Downloads\ORAL_Presentation_Scores_T5_Michelle_Wells.pdf
2012-05-24 11:07 - 2012-05-24 11:05 - 00000395 ____A C:\Users\Ultra\Documents\index.html
2012-05-24 09:22 - 2012-05-24 09:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E18D100C-B27A-43BB-85D0-25A18BA0A377}
2012-05-24 09:22 - 2012-05-24 09:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{43DC0A1D-A93A-4A08-8F46-1A806357B8F5}
2012-05-23 13:58 - 2012-05-23 13:58 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D5E98A58-9415-42B7-BDBD-D180FAD95FC8}
2012-05-23 13:58 - 2012-05-23 13:58 - 00000000 ____D C:\Users\Ultra\AppData\Local\{6AC72E01-BD43-4E5A-8B50-B81B095B38D8}
2012-05-23 10:02 - 2012-05-23 10:02 - 00000543 ____A C:\Users\Ultra\Downloads\site_descrição (1).txt
2012-05-23 09:57 - 2012-05-23 09:57 - 00167424 ____A C:\Users\Ultra\Downloads\Sociologia - resumos (2).doc
2012-05-23 09:57 - 2012-05-23 09:57 - 00167424 ____A C:\Users\Ultra\Downloads\Sociologia - resumos (1) (1).doc
2012-05-23 09:56 - 2012-05-23 09:56 - 00167424 ____A C:\Users\Ultra\Downloads\Sociologia - resumos (1).doc
2012-05-23 09:56 - 2012-05-23 09:56 - 00000543 ____A C:\Users\Ultra\Downloads\site_descrição.txt
2012-05-23 08:32 - 2012-05-23 08:32 - 00167424 ____A C:\Users\Ultra\Downloads\Sociologia - resumos.doc
2012-05-23 08:31 - 2012-05-23 08:31 - 00027928 ____A C:\Users\Ultra\Downloads\REGULAMENTO DA OFERTA DE BOLSAS DE ESTUDO ITALIANAS A ESTUDANTES PORTUGUESES.docx
2012-05-23 01:57 - 2012-05-23 01:57 - 00000000 ____D C:\Users\Ultra\AppData\Local\{631C1988-A21A-47D1-AC84-846768B06A1D}
2012-05-23 01:57 - 2012-05-23 01:57 - 00000000 ____D C:\Users\Ultra\AppData\Local\{396004BA-EEC2-4FC8-A376-38312EC2F481}
2012-05-22 14:29 - 2012-05-22 14:29 - 00217666 ____A C:\Users\Ultra\Downloads\PT-Subs57e44bf3a84db771e2912e509e42e7d7.rar
2012-05-22 14:28 - 2012-05-22 14:28 - 00317420 ____A C:\Users\Ultra\Downloads\snypaz3251841a338130e703f355f45f0f7c00.rar
2012-05-22 14:23 - 2012-05-22 14:23 - 00303800 ____A C:\Users\Ultra\Downloads\healerbe11dc945159ef0f61915482c967a8ba.rar
2012-05-22 14:20 - 2012-05-22 14:20 - 00422520 ____A (Opensubtitles.org ) C:\Users\Ultra\Downloads\the.wire.the.target.(2002).scc.1cd.(4038327).exe
2012-05-22 14:20 - 2012-05-22 14:20 - 00027829 ____A C:\Users\Ultra\Downloads\the.wire.the.target.(2002).scc.1cd.(4038327).zip
2012-05-22 14:19 - 2012-05-22 14:19 - 00315908 ____A C:\Users\Ultra\Downloads\eaf7ea275138f232dce23b60f4e030b0cd07215c.zip
2012-05-22 12:29 - 2012-05-22 12:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B0FDC97C-01A7-49B8-B249-3CDB3CA88AB6}
2012-05-22 12:29 - 2012-05-22 12:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2DD60F6F-C792-4890-B8AE-926D94DCD44D}
2012-05-22 11:49 - 2012-05-22 11:49 - 00019839 ____A C:\Users\Ultra\Downloads\580795.zip
2012-05-22 01:10 - 2012-05-22 01:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\NokiaAccount
2012-05-22 01:10 - 2012-05-22 00:54 - 00000000 ____D C:\Users\Ultra\AppData\Local\Nokia
2012-05-22 00:54 - 2012-05-22 00:54 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\PC Suite
2012-05-22 00:54 - 2012-05-22 00:54 - 00000000 ____D C:\Users\All Users\PC Suite
2012-05-22 00:54 - 2012-05-22 00:53 - 00002089 ____A C:\Users\Public\Desktop\Nokia Suite.lnk
2012-05-22 00:54 - 2012-05-22 00:53 - 00000000 ____D C:\Users\All Users\Nokia
2012-05-22 00:53 - 2012-05-22 00:53 - 00000000 ____D C:\Program Files\DIFX
2012-05-22 00:53 - 2012-05-22 00:53 - 00000000 ____D C:\Program Files (x86)\PC Connectivity Solution
2012-05-22 00:53 - 2012-05-22 00:50 - 00000000 ____D C:\Program Files (x86)\Nokia
2012-05-22 00:53 - 2012-01-28 07:44 - 00018528 ____A C:\Windows\DPINST.LOG
2012-05-22 00:50 - 2012-05-22 00:50 - 00000000 ____D C:\Users\All Users\NokiaInstallerCache
2012-05-22 00:31 - 2012-05-22 00:31 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_ccdcmbx64_01009.Wdf
2012-05-22 00:29 - 2012-05-22 00:28 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5354C84D-F91F-4942-BF6A-9634C85710C5}
2012-05-22 00:28 - 2012-05-22 00:28 - 00000000 ____D C:\Users\Ultra\AppData\Local\{45E58DC3-C836-4B37-8614-3E3E91BA71F8}
2012-05-21 16:25 - 2012-05-21 16:25 - 00025911 ____A C:\Users\Ultra\Downloads\bc4b3ec3b04d11d57df9ca4f862cb2f138839277.zip
2012-05-21 13:45 - 2012-05-21 13:38 - 121270768 ____A C:\Users\Ultra\Downloads\Aimee High Preview (1).wmv
2012-05-21 13:43 - 2012-05-21 13:43 - 00013675 ____A C:\Users\Ultra\Downloads\[kat.ph]hot.and.fire.girls.aamy.spears.torrent
2012-05-21 13:42 - 2012-05-21 13:42 - 00028390 ____A C:\Users\Ultra\Downloads\[kat.ph]day.with.a.pornstar.xxx.charisma.cappelli.new.july.24.torrent
2012-05-21 13:42 - 2012-05-21 13:42 - 00011633 ____A C:\Users\Ultra\Downloads\[kat.ph]bleepdungeon.charisma.cappelli.2011.torrent
2012-05-21 13:42 - 2012-05-21 13:42 - 00011164 ____A C:\Users\Ultra\Downloads\[kat.ph]dont.tell.my.wife.i.buttfooked.her.best.friend.charisma.cappelli.torrent
2012-05-21 13:42 - 2012-05-21 13:42 - 00008451 ____A C:\Users\Ultra\Downloads\[kat.ph]charisma.cappelli.and.lisa.lipps.2.chicks.same.time.torrent
2012-05-21 13:41 - 2012-05-21 13:41 - 00016558 ____A C:\Users\Ultra\Downloads\[kat.ph]pornfidelity.charisma.cappelli.torrent
2012-05-21 13:40 - 2012-05-21 13:38 - 28574839 ____A C:\Users\Ultra\Downloads\Sarah V reg 640 Preview (1).wmv
2012-05-21 13:39 - 2012-05-21 13:38 - 25254759 ____A C:\Users\Ultra\Downloads\Rayna reg 640 Preview.wmv
2012-05-21 09:18 - 2012-05-21 09:18 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0D1C80C6-6752-4759-9565-ED7B40C533AC}
2012-05-21 09:18 - 2012-05-21 09:18 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0390B189-A75E-4336-91BD-9662A1F9E00C}
2012-05-21 06:20 - 2012-05-21 10:32 - 07960562 ____N C:\Users\Ultra\Desktop\21052012039.mp4
2012-05-20 16:20 - 2012-05-20 16:20 - 00000022 ____A C:\Users\Ultra\Downloads\577104.zip
2012-05-20 14:50 - 2012-05-20 14:50 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D2105118-EEE5-4F9E-B8DF-14A079D75693}
2012-05-20 14:50 - 2012-05-20 14:50 - 00000000 ____D C:\Users\Ultra\AppData\Local\{37F47588-7889-4DC5-9595-F8A103965061}
2012-05-20 14:39 - 2012-05-20 14:39 - 00036352 ____A C:\Users\Ultra\Downloads\Museus- Educação ou Divertimento.doc
2012-05-20 11:08 - 2012-05-20 11:08 - 00088425 ____A C:\Users\Ultra\Downloads\Apontamentos de Comunicação Televisiva (1).docx
2012-05-20 07:26 - 2012-05-20 07:26 - 03677947 ____A C:\Users\Ultra\Documents\Ronaldo_Workout_pt_PT.pdf
2012-05-20 02:50 - 2012-05-20 02:50 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D838C7C6-76A0-4607-BF30-F2C23A42AC4E}
2012-05-20 02:50 - 2012-05-20 02:49 - 00000000 ____D C:\Users\Ultra\AppData\Local\{554C04D5-A6AA-4BD1-AF73-F390EA9319E2}
2012-05-19 17:05 - 2012-05-19 17:05 - 00018117 ____A C:\Users\Ultra\Downloads\578378.zip
2012-05-19 13:13 - 2012-05-19 13:13 - 00021753 ____A C:\Users\Ultra\Downloads\FacebookIPO2.jpg
2012-05-19 12:42 - 2012-05-19 12:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{93FA97CC-306D-42F1-A983-1A3D4460815C}
2012-05-19 12:42 - 2012-05-19 12:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{41648D25-81C8-45B2-8AE4-A2E6F6DF6649}
2012-05-19 07:18 - 2012-05-19 07:18 - 31523862 ____A C:\Users\Ultra\Downloads\Frets_on_Fire_Songs_-_Anv1.zip
2012-05-19 07:18 - 2012-05-19 07:18 - 00037235 ____A C:\Users\Ultra\Downloads\Frets_on_Fire_Song_Pack_#3_(311_songs).torrent
2012-05-19 07:10 - 2012-05-19 07:09 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\fretsonfire
2012-05-19 07:09 - 2012-05-19 07:09 - 00000696 ____A C:\Users\UpdatusUser\Desktop\Frets on Fire.lnk
2012-05-19 07:09 - 2012-05-19 07:08 - 34874776 ____A C:\Users\Ultra\Downloads\FretsOnFire-1.3.110-win32.exe
2012-05-19 03:19 - 2012-05-19 03:19 - 03175683 ____A C:\Users\Ultra\Downloads\zzhpreview.wmv
2012-05-19 01:26 - 2012-05-19 01:26 - 19337401 ____A C:\Users\Ultra\Downloads\Pos_Producao_Zettl_Jose_Araujo_Jose_Araujo.pdf
2012-05-19 01:26 - 2012-05-19 01:26 - 18024727 ____A C:\Users\Ultra\Downloads\Hitchcock_Explains_About_Cutting_Copia_Jose_Araujo_Jose_Araujo.mp4
2012-05-19 00:42 - 2012-05-19 00:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{F5193CDA-C337-4753-A3CA-BC9B1EDE7C3A}
2012-05-19 00:42 - 2012-05-19 00:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3D13DC09-1D76-492F-B9B7-ABF49AB6A398}
2012-05-18 17:26 - 2012-05-18 17:26 - 00023755 ____A C:\Users\Ultra\Downloads\411405.zip
2012-05-18 16:24 - 2012-05-18 16:24 - 00103407 ____A C:\Users\Ultra\Downloads\Notas_Trabalhos_Sociologia_Comunicacao_Rita_Figueiras.pdf
2012-05-18 15:53 - 2012-05-18 15:53 - 00019486 ____A C:\Users\Ultra\Downloads\[kat.ph]teen.bleep.club.kandi.milan.torrent
2012-05-18 15:53 - 2012-05-18 15:53 - 00017617 ____A C:\Users\Ultra\Downloads\[kat.ph]devilsfilm.kandi.milan.tight.indian.pussy.torrent
2012-05-18 15:53 - 2012-05-18 15:53 - 00011286 ____A C:\Users\Ultra\Downloads\[kat.ph]girlshuntinggirls.ally.ann.kandi.milan.and.tory.lane.torrent
2012-05-18 12:42 - 2012-05-18 12:41 - 00000000 ____D C:\Users\Ultra\AppData\Local\{8EBB868F-0D7E-410F-9226-34404EECF240}
2012-05-18 12:41 - 2012-05-18 12:41 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1A6B91E2-C02C-451B-B39E-4D38CC0CE4BC}
2012-05-18 00:41 - 2012-05-18 00:41 - 00000000 ____D C:\Users\Ultra\AppData\Local\{FAB67C2B-0740-4437-B9EC-2D85875337DC}
2012-05-18 00:41 - 2012-05-18 00:41 - 00000000 ____D C:\Users\Ultra\AppData\Local\{634D8E93-6810-497F-A986-0694953C980D}
2012-05-17 13:17 - 2012-05-17 13:17 - 00178478 ____A C:\Users\Ultra\Downloads\gs_CSS_Goncalo_Silva (1).pdf
2012-05-17 13:17 - 2012-05-17 13:17 - 00171841 ____A C:\Users\Ultra\Downloads\gs_HTML_Goncalo_Silva.pdf
2012-05-17 12:29 - 2012-05-17 12:29 - 00024782 ____A C:\Users\Ultra\Downloads\B5550964EFACFAEBAA46BAEBD7AD578774F1B7CE.torrent
2012-05-17 11:29 - 2012-05-17 11:29 - 00386039 ____A C:\Users\Ultra\Downloads\tumblr_lpjwgvrBA01qb82q8o2_250.gif
2012-05-17 11:22 - 2012-05-17 11:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3483B2A9-DB49-41D2-8637-2343392B6792}
2012-05-17 11:22 - 2012-05-17 11:21 - 00000000 ____D C:\Users\Ultra\AppData\Local\{AED4EA71-F32B-4CBE-BEDD-7C7606F20749}
2012-05-16 23:21 - 2012-05-16 23:21 - 00000000 ____D C:\Users\Ultra\AppData\Local\{AEE4ED56-F767-444D-8020-15268E018100}
2012-05-16 23:21 - 2012-05-16 23:21 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1917766F-6A11-42FA-92A8-488CB49015E0}
2012-05-16 17:00 - 2012-05-16 17:00 - 00138700 ____A C:\Users\Ultra\Downloads\Guião Italiano.pdf
2012-05-16 14:32 - 2012-05-16 13:47 - 00003042 ____A C:\Users\Ultra\Desktop\layout.css
2012-05-16 14:28 - 2012-05-16 13:47 - 00004857 ____A C:\Users\Ultra\Desktop\index.html
2012-05-16 14:23 - 2012-05-16 14:23 - 00025204 ____A C:\Users\Ultra\Downloads\b4dec57ae54dbb315e5926cda13a8978157138d4.zip
2012-05-16 14:15 - 2011-12-11 14:20 - 00044544 ____A C:\Users\Ultra\Desktop\EDM_12_12_11_Turno5.doc
2012-05-16 11:50 - 2012-05-16 11:50 - 04909628 ____A C:\Users\Ultra\Downloads\Turno5_Goncalo_Silva.zip
2012-05-16 11:50 - 2012-05-16 11:50 - 04419192 ____A (Krzysztof Kowalczyk) C:\Users\Ultra\Downloads\SumatraPDF-2.1.1-install.exe
2012-05-16 11:50 - 2012-05-16 11:50 - 00576069 ____A C:\Users\Ultra\Downloads\Html_Cheat_Sheet_V1_Goncalo_Silva_3.pdf
2012-05-16 11:50 - 2012-05-16 11:50 - 00178478 ____A C:\Users\Ultra\Downloads\gs_CSS_Goncalo_Silva.pdf
2012-05-16 09:59 - 2012-05-16 09:59 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C9589BFA-4994-46C1-8C11-6F6718944E0F}
2012-05-16 09:59 - 2012-05-16 09:59 - 00000000 ____D C:\Users\Ultra\AppData\Local\{89D62C28-6808-4491-8C9F-FA173D3D39D8}
2012-05-15 16:14 - 2012-05-15 16:14 - 00020440 ____A C:\Users\Ultra\Downloads\8d57ac7e5628280aedcda2daee85dac7d71a2b8e.zip
2012-05-15 13:46 - 2012-05-15 13:46 - 00010097 ____A C:\Users\Ultra\Downloads\[kat.ph]hawaii.five.0.2010.s02e23.720p.hdtv.x264.2hd.publichd.torrent
2012-05-15 13:45 - 2012-05-15 13:45 - 00008752 ____A C:\Users\Ultra\Downloads\[isoHunt] b5888a87213031398847f57b56d40e9fcfc5fd6d.torrent
2012-05-15 13:44 - 2012-05-15 13:44 - 00007545 ____A C:\Users\Ultra\Downloads\[isoHunt] House.S08E21.720p.WEB-DL.DD5.1.H.264-POD [PublicHD].torrent
2012-05-15 11:36 - 2012-05-15 11:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B40A570B-6ED6-42B4-8EAA-AE0F63398ACC}
2012-05-15 11:36 - 2012-05-15 11:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{F6CEF80B-F14C-49C8-9FD4-020C7183825F}
2012-05-14 15:30 - 2012-05-14 15:30 - 00020742 ____A C:\Users\Ultra\Downloads\575246.zip
2012-05-14 14:56 - 2012-05-14 14:56 - 00000000 ____D C:\Users\Ultra\AppData\Local\{991A722E-1C02-40E8-8EE4-19298CD23823}
2012-05-14 14:56 - 2012-05-14 14:56 - 00000000 ____D C:\Users\Ultra\AppData\Local\{462A7163-FA36-409C-B1EA-FD0EBFDA1A40}
2012-05-14 14:10 - 2012-05-14 14:10 - 00027770 ____A C:\Users\Ultra\Downloads\horatio-caine-csi.jpg
2012-05-14 07:35 - 2012-05-16 13:47 - 00007065 ____A C:\Users\Ultra\Desktop\tratada.jpg
2012-05-14 07:35 - 2012-05-14 07:35 - 00211949 ____A C:\Users\Ultra\Downloads\www_22032012.zip
2012-05-14 04:25 - 2012-05-14 04:25 - 00020161 ____A C:\Users\Ultra\Downloads\572087.zip
2012-05-14 03:35 - 2012-05-14 03:35 - 00021440 ____A C:\Users\Ultra\Downloads\Person.of.Interest.S01E20.720p.HDTV.X264-DIMENSION._www.ENGSUB.NET.zip
2012-05-14 03:15 - 2012-05-14 03:15 - 00000000 ____D C:\Users\Ultra\Documents\DS Wood Backup
2012-05-14 03:11 - 2012-05-14 03:11 - 01629727 ____A C:\Users\Ultra\Downloads\Wood_R4_v1.47.rar
2012-05-14 02:56 - 2012-05-14 02:55 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B651CD4C-1BB7-4B73-A384-CEF4C04A8534}
2012-05-14 02:55 - 2012-05-14 02:55 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1FA356C4-4AD6-4BA8-BE2E-68C13460C4F7}
2012-05-14 02:54 - 2012-01-28 08:13 - 00000000 ____D C:\Program Files (x86)\uTorrent
2012-05-13 16:11 - 2012-05-13 16:11 - 00017193 ____A C:\Users\Ultra\Downloads\575209.zip
2012-05-13 16:11 - 2012-05-13 16:11 - 00017193 ____A C:\Users\Ultra\Downloads\575209 (1).zip
2012-05-13 15:51 - 2012-05-13 15:51 - 00025524 ____A C:\Users\Ultra\Downloads\3e9f9de423983e8d2e3774272bb01b4bfc8b9f54.zip
2012-05-13 15:50 - 2012-05-13 15:50 - 00026919 ____A C:\Users\Ultra\Downloads\477c19a61e38c16dfac31fd05e98fcdad70db47c.zip
2012-05-13 15:49 - 2012-05-13 15:49 - 00025229 ____A C:\Users\Ultra\Downloads\caaa8fb5be80ebee80a8228a72f1100d976654ca.zip
2012-05-13 15:49 - 2012-05-13 15:49 - 00024490 ____A C:\Users\Ultra\Downloads\68fbbb06fb8a5b8e6015a36bf1e6efe078a39913.zip
2012-05-13 15:48 - 2012-05-13 15:48 - 00025954 ____A C:\Users\Ultra\Downloads\dbb26cb8501aeb604c448291f514d64193aebcd1.zip
2012-05-13 12:21 - 2012-05-13 12:21 - 00021001 ____A C:\Users\Ultra\Downloads\E18938ECED029432584752BA641376F1CA9CFCB5.torrent
2012-05-13 12:18 - 2012-05-13 12:18 - 00270228 ____A C:\Users\Ultra\Downloads\Inazuma 11.rar
2012-05-13 10:37 - 2012-05-13 10:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1F1262BE-CE4B-4731-A24C-4E891BABEE94}
2012-05-13 10:36 - 2012-05-13 10:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{19B1B3A1-4B5E-40CA-A4F3-740B1E474356}
2012-05-13 05:18 - 2012-01-28 07:43 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2012-05-13 03:36 - 2012-05-13 03:36 - 00071196 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.abby.one.night.stand.720p.may.02.2012.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00052971 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.pretty.back.door.baby.linsay.720p.wmv.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00036261 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.slow.motion.erica.1080p.mov.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00035974 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.perfect.blonde.mary.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00034499 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.introducing.diana.1080p.mov.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00020178 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.gabriella.siempre.en.mi.corazon.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00019553 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.ivy.lunchtime.fantasy.torrent
2012-05-13 03:36 - 2012-05-13 03:36 - 00014118 ____A C:\Users\Ultra\Downloads\[kat.ph]x.art.caprice.bleep.perfection.torrent
2012-05-13 03:30 - 2012-05-13 03:30 - 01951383 ____A C:\Users\Ultra\Downloads\jimmycanon-bree.wmv
2012-05-13 03:22 - 2012-05-13 03:18 - 48858842 ____A C:\Users\Ultra\Downloads\Cherry Poppins Deep Throated free9000info.avi
2012-05-12 22:36 - 2012-05-12 22:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E820D5B4-C0AD-4B43-BF6C-5770B9351499}
2012-05-12 22:36 - 2012-05-12 22:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5303A074-0CFD-4F28-95E4-490EC691E277}
2012-05-12 10:47 - 2012-05-12 10:47 - 00020483 ____A C:\Users\Ultra\Downloads\9cc31dfc101a6099ec8f8a3c1f723fab795ee6ba.zip
2012-05-12 10:36 - 2012-05-12 10:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A4C127FE-72C5-4C7B-8157-9ECC0558CE18}
2012-05-12 10:36 - 2012-05-12 10:36 - 00000000 ____D C:\Users\Ultra\AppData\Local\{533EB4A8-1C60-40A8-BB73-0557C25BF3F3}
2012-05-11 22:36 - 2012-05-11 22:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C67DEDF2-90D6-42F7-8D5E-EFEBDCC5F3FC}
2012-05-11 22:35 - 2012-05-11 22:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B7EBFBA8-5380-4A79-8484-C3CF892FED6E}
2012-05-11 19:48 - 2012-05-11 19:12 - 332702746 ____A C:\Users\Ultra\Downloads\Christy Mack - Titty Attack.avi
2012-05-11 18:51 - 2012-05-11 18:51 - 00227928 ____A C:\Users\Ultra\Downloads\KarupsHA.12.01.12.Aamy.Spears.Solo.1.XXX.720p.MP4-KTR.exe
2012-05-11 18:51 - 2012-05-11 18:51 - 00027275 ____A C:\Users\Ultra\Downloads\2547591314767065089275E181DB07CA70E0A47D.torrent
2012-05-11 18:51 - 2012-05-11 18:51 - 00023918 ____A C:\Users\Ultra\Downloads\E99C222D891AFF1B9615E4DE92FBB2F9915349A7.torrent
2012-05-11 12:39 - 2012-05-11 12:39 - 00014321 ____A C:\Users\Ultra\Downloads\[isoHunt] BigNaturals_-_Jen_Capone_(Best_Breast)_-_great_big_tits.5106497.TPB.torrent
2012-05-11 12:30 - 2012-05-11 12:30 - 00019172 ____A C:\Users\Ultra\Downloads\RealityKings-HotBush_-_Jen_Capone.5635829.TPB.torrent
2012-05-11 12:03 - 2012-05-11 12:03 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-11 12:03 - 2012-05-11 12:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-11 10:35 - 2012-05-11 10:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{8BCB1FDB-4BF9-4E32-BD89-CF8351CE3481}
2012-05-11 10:35 - 2012-05-11 10:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{7D52B79F-1FB2-4821-826E-1E0C365D259E}
2012-05-10 22:35 - 2012-05-10 22:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E8AC6FD9-CEC2-45B0-8855-D08E128B7928}
2012-05-10 22:34 - 2012-05-10 22:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4D873341-111F-48AA-BC72-0975027AC1B1}
2012-05-10 13:13 - 2012-05-10 13:13 - 00000000 ____D C:\Users\Ultra\Documents\Dreamweaver
2012-05-10 10:45 - 2012-05-10 10:45 - 00149532 ____A C:\Users\Ultra\Downloads\Eldermana335dd3a05fdb3142f5873352474407b.zip
2012-05-10 10:34 - 2012-05-10 10:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A77C31C8-A2C3-4C8A-A171-E66858FBDF2E}
2012-05-10 10:34 - 2012-05-10 10:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{281EFAA9-F503-4693-B43F-6014EB402864}
2012-05-09 17:05 - 2012-05-09 17:05 - 00518029 ____A C:\Users\Ultra\Downloads\smart-news-free-version (1).zip
2012-05-09 17:03 - 2012-05-09 17:03 - 00518029 ____A C:\Users\Ultra\Downloads\smart-news-free-version.zip
2012-05-09 15:20 - 2012-05-09 15:20 - 00022866 ____A C:\Users\Ultra\Downloads\e56f7dcdec819076f5c63e9fb223b36421cfbf09.zip
2012-05-09 12:56 - 2012-05-09 12:56 - 00304640 ____A C:\Users\Ultra\Downloads\form_refunding_cinema_2012.xls
2012-05-09 11:11 - 2012-02-01 07:11 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-09 11:11 - 2012-01-31 20:10 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-09 11:05 - 2009-07-13 23:46 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-09 10:58 - 2012-05-09 10:58 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A5320AA0-91EF-4C1E-BB25-D0E8BD37296E}
2012-05-09 10:58 - 2012-05-09 10:58 - 00000000 ____D C:\Users\Ultra\AppData\Local\{627CA57A-6A0C-41D3-BED9-01688556A069}
2012-05-08 11:27 - 2012-05-08 11:27 - 00000000 ____D C:\Users\Ultra\AppData\Local\{27BC5644-AA6B-4C55-8BB4-DECA291D482D}
2012-05-08 11:27 - 2012-05-08 11:27 - 00000000 ____D C:\Users\Ultra\AppData\Local\{24370B51-E4B2-4B7C-A623-FC9764F3F25B}
2012-05-07 17:39 - 2012-04-24 13:11 - 00000000 ____D C:\Users\Ultra\AppData\Local\Adobe
2012-05-07 17:31 - 2012-04-24 13:22 - 00000000 ____D C:\Users\All Users\regid.1986-12.com.adobe
2012-05-07 17:31 - 2012-01-28 07:57 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\Adobe
2012-05-07 17:30 - 2012-04-24 13:14 - 00000000 ____D C:\Program Files (x86)\Adobe
2012-05-07 14:47 - 2012-05-07 14:47 - 00000000 ____D C:\Users\Ultra\AppData\Local\{06BEB408-72B1-493E-87FE-361E2480370A}
2012-05-07 14:47 - 2012-05-07 14:47 - 00000000 ____D C:\Users\Ultra\AppData\Local\{004D55DA-3BFA-4FC4-940A-3BAAB7BEF803}
2012-05-07 02:47 - 2012-05-07 02:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1BB128B1-21EE-4236-A5FF-224F49A57F30}
2012-05-07 02:46 - 2012-05-07 02:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{59A077A3-3E70-4B34-B1B9-2FA6AB6E9D2F}
2012-05-06 14:46 - 2012-05-06 14:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3D38FB87-5D87-4C9C-89E9-CB7DFB221BE0}
2012-05-06 14:46 - 2012-05-06 14:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\{11892B8C-65CC-4169-88FB-C927C2FA7B3C}
2012-05-06 07:57 - 2012-05-06 07:49 - 203736686 ____A C:\Users\Ultra\Downloads\Vampire Hunter D OST.zip
2012-05-06 02:45 - 2012-05-06 02:45 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A30C985B-F6BA-49C1-9C2F-3B8B2842C130}
2012-05-06 02:45 - 2012-05-06 02:45 - 00000000 ____D C:\Users\Ultra\AppData\Local\{35C83B9B-5EA7-4470-8C12-BB39532CB326}
2012-05-05 13:10 - 2012-05-05 13:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\{9138A30F-CD25-4754-98A7-FA685A13CB2F}
2012-05-05 13:10 - 2012-05-05 13:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\{633F9468-382A-418D-8411-FE3516D7102E}
2012-05-05 03:33 - 2012-04-02 11:33 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-05 03:33 - 2012-04-02 11:29 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-05 03:33 - 2012-01-28 15:08 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-05-05 01:10 - 2012-05-05 01:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\{ADBD048E-AA0A-4012-92A2-3E8C67535C5E}
2012-05-05 01:10 - 2012-05-05 01:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\{9DA6D023-F522-4588-8303-6F1BF025DA31}
2012-05-04 13:09 - 2012-05-04 13:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C6CA1CF1-D949-4730-A7AD-7144A6130D7A}
2012-05-04 13:09 - 2012-05-04 13:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B2E26283-BF40-4E40-AE91-A67AD46DFDAD}
2012-05-04 04:37 - 2012-05-04 05:39 - 00509862 ____A C:\Users\Ultra\Desktop\uncharted3_leilão.jpg
2012-05-04 01:10 - 2012-05-04 01:10 - 00000947 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-05-04 01:09 - 2012-05-04 01:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1158603A-5D02-4993-9CB3-D1835C8421D0}
2012-05-04 01:09 - 2012-05-04 01:08 - 00000000 ____D C:\Users\Ultra\AppData\Local\{57ABA3C3-09B4-41D8-BF1B-6AA7270B279E}
2012-05-02 16:02 - 2012-05-02 16:02 - 00021930 ____A C:\Users\Ultra\Downloads\Anexo.PDF
2012-05-02 16:02 - 2012-05-02 16:02 - 00021930 ____A C:\Users\Ultra\Downloads\Anexo (3).PDF
2012-05-02 16:02 - 2012-05-02 16:02 - 00021930 ____A C:\Users\Ultra\Downloads\Anexo (2).PDF
2012-05-02 16:02 - 2012-05-02 16:02 - 00021930 ____A C:\Users\Ultra\Downloads\Anexo (1).PDF
2012-05-02 15:26 - 2012-05-02 15:26 - 00042729 ____A C:\Users\Ultra\Desktop\ucp-logo.jpg
2012-05-02 13:34 - 2012-05-02 13:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4B53C227-57FD-4695-A55E-364D10CC55C1}
2012-05-02 13:34 - 2012-05-02 13:33 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C2E571F6-4FE0-4353-9549-A0BDBF982D3F}
2012-05-02 01:33 - 2012-05-02 01:33 - 00000000 ____D C:\Users\Ultra\AppData\Local\{646A309F-82F4-47E9-B3EB-C0770E8BB939}
2012-05-02 01:33 - 2012-05-02 01:33 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1E740C36-B73F-49B1-82BD-AC852430CC7C}
2012-05-01 12:44 - 2012-05-01 12:42 - 00091402 ____A C:\Users\Ultra\Downloads\we_are_watching_you.png
2012-05-01 12:18 - 2012-05-01 12:18 - 00493520 ____A (Facebook Inc.) C:\Users\Ultra\Downloads\FacebookVideoCallSetup_v1.2.203.0.exe
2012-05-01 11:10 - 2012-05-01 11:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4AE88AF2-8876-4E42-B992-D3303264D21F}
2012-05-01 11:10 - 2012-05-01 11:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D3FBC416-1FAE-40C4-9650-792354100298}
2012-04-30 23:09 - 2012-04-30 23:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A0A6AAFB-C977-42A2-A4AA-C30BFA2EC00F}
2012-04-30 23:09 - 2012-04-30 23:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{6A0C1CCA-73D3-4091-B1B5-C124B01291BF}
2012-04-30 11:09 - 2012-04-30 11:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D70B4066-9F30-4D83-92B1-9558002D1916}
2012-04-30 11:09 - 2012-04-30 11:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{7BB45200-11B5-45D4-9C42-65656650BA44}
2012-04-29 15:08 - 2012-04-29 15:08 - 00000000 ____D C:\Users\Ultra\AppData\Local\{89A24166-334D-4338-A752-AA44AB9C9CE2}
2012-04-29 15:08 - 2012-04-29 15:08 - 00000000 ____D C:\Users\Ultra\AppData\Local\{59455A43-2D1D-4560-9AF6-0B5512510952}
2012-04-29 03:08 - 2012-04-29 03:08 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E553A6FF-9109-47A7-9864-101A158BCC98}
2012-04-29 03:08 - 2012-04-29 03:08 - 00000000 ____D C:\Users\Ultra\AppData\Local\{78FAF7CF-315F-450E-848C-39CE702D1123}
2012-04-28 11:01 - 2012-04-28 11:01 - 00000000 ____D C:\Users\Ultra\AppData\Local\{CE80A5EB-4298-4DB4-B572-49C015F9F96C}
2012-04-28 11:01 - 2012-04-28 11:01 - 00000000 ____D C:\Users\Ultra\AppData\Local\{72276188-8B58-4F82-8590-8FDA521E37CF}
2012-04-28 06:38 - 2012-02-01 07:11 - 00000000 ____D C:\Users\Ultra\AppData\Local\Microsoft Help
2012-04-28 02:30 - 2012-04-28 02:30 - 00016303 ____A C:\Users\Ultra\Downloads\English_IV_Portfolio_Guidelines_1112_Michelle_Wells.docx
2012-04-28 02:30 - 2012-04-28 02:30 - 00013504 ____A C:\Users\Ultra\Downloads\Vocabulary_Extension_Work_Plan_Eng_IV_Michelle_Wells_1.docx
2012-04-27 23:01 - 2012-04-27 23:01 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D502E3EB-3E12-443E-920B-52D48FBB2D73}
2012-04-27 23:01 - 2012-04-27 23:01 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3991D2E2-AAAC-49AA-9036-08CAB2505541}
2012-04-27 18:23 - 2012-04-27 18:23 - 00028101 ____A C:\Users\Ultra\Downloads\448653.zip
2012-04-27 14:12 - 2012-04-27 14:12 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\Mozilla
2012-04-27 14:12 - 2012-04-27 14:12 - 00000000 ____D C:\Users\Ultra\AppData\Local\Mozilla
2012-04-27 14:12 - 2012-04-27 14:12 - 00000000 ____D C:\Users\All Users\Mozilla
2012-04-27 14:12 - 2012-04-27 14:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-04-27 14:12 - 2012-04-27 14:11 - 16339280 ____A (Mozilla) C:\Users\Ultra\Downloads\Firefox Setup 12.0.exe
2012-04-27 13:50 - 2012-04-27 13:50 - 00033170 ____A C:\Users\Ultra\Downloads\exe_html_1_Goncalo_Silva.zip
2012-04-27 13:31 - 2012-04-27 13:31 - 00534325 ____A C:\Users\Ultra\Downloads\html_exe2_Goncalo_Silva.zip
2012-04-27 11:01 - 2012-04-27 11:01 - 00000000 ____D C:\Users\Ultra\AppData\Local\{6C8FE1AF-5BFD-4D33-A621-A069E34461E3}
2012-04-27 11:01 - 2012-04-27 11:00 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4C8B7315-C1C9-4E4D-9969-64AC5EF0CFAF}
2012-04-27 01:53 - 2012-04-27 01:53 - 00164546 ____A C:\Users\Ultra\Downloads\GG14_numerorecibo_7100345997_numeroapolice_7000129206_8265707 (1).pdf
2012-04-27 01:53 - 2012-04-27 01:52 - 00145310 ____A C:\Users\Ultra\Downloads\G500_numeroapolice_7000129206_8265706 (1).pdf
2012-04-26 23:00 - 2012-04-26 23:00 - 00000000 ____D C:\Users\Ultra\AppData\Local\{F0585882-A7A0-4FAC-81BC-1F2ABAF809C2}
2012-04-26 23:00 - 2012-04-26 23:00 - 00000000 ____D C:\Users\Ultra\AppData\Local\{8206E82A-51D9-4557-BFE9-FD125320CB41}
2012-04-26 16:34 - 2012-04-26 16:34 - 00022979 ____A C:\Users\Ultra\Downloads\568014.zip
2012-04-26 16:34 - 2012-04-26 16:34 - 00020329 ____A C:\Users\Ultra\Downloads\568570.zip
2012-04-26 12:53 - 2012-04-26 12:53 - 02748756 ____A C:\Users\Ultra\Downloads\The Americanization of Japan.pptx
2012-04-26 11:07 - 2012-04-26 11:07 - 00057614 ____A C:\Users\Ultra\Downloads\MKT2571R7473843.PDF
2012-04-26 11:00 - 2012-04-26 11:00 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C5ACAF2B-BBF3-4756-ADB2-07C89C5E4231}
2012-04-26 11:00 - 2012-04-26 11:00 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B5A0859C-18E4-4ABA-8B07-B8506C2CE8CB}
2012-04-25 13:56 - 2012-04-25 13:56 - 00020595 ____A C:\Users\Ultra\Downloads\geekgirlsex.com.Britney.Brooks.Renna.Ryann.XXX.[SiteRip][GoldenP.4913079.TPB.torrent
2012-04-25 13:55 - 2012-04-25 13:55 - 00016138 ____A C:\Users\Ultra\Downloads\MollysLife_-_Renna_Ryann_(__What_A_Catch_).5101936.TPB.torrent
2012-04-25 13:00 - 2012-04-25 13:00 - 00023883 ____A C:\Users\Ultra\Downloads\4045a3c07dba045e0f25babb52e537a3af06c2a3 (1).zip
2012-04-25 11:47 - 2012-04-25 11:47 - 00015893 ____A C:\Users\Ultra\Downloads\8f04557ce7d77b00cdf67da6e7b0bc6c54da60d7 (1).zip
2012-04-25 11:29 - 2012-04-25 11:29 - 00015893 ____A C:\Users\Ultra\Downloads\8f04557ce7d77b00cdf67da6e7b0bc6c54da60d7.zip
2012-04-25 10:58 - 2012-04-25 10:58 - 00016700 ____A C:\Users\Ultra\Downloads\4bf1b1032b9cd5c71c66432cb407285a8b04b1ff.zip
2012-04-25 10:02 - 2012-04-25 10:02 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D2BC9D50-4EB2-48B4-96DA-DA68AA471B53}
2012-04-25 10:02 - 2012-04-25 10:02 - 00000000 ____D C:\Users\Ultra\AppData\Local\{02FC5661-23D7-4CF0-A37E-B26167619BC7}
2012-04-24 18:39 - 2012-04-24 18:39 - 00038533 ____A C:\Users\Ultra\Downloads\Modern.Family.S03E16.720p.HDTV.X264-DIMENSION.srt
2012-04-24 18:38 - 2012-04-24 18:38 - 00015523 ____A C:\Users\Ultra\Downloads\3124e7ee5caae3c1542e5e37740b2b25daf2b1b5 (1).zip
2012-04-24 18:37 - 2012-04-24 18:37 - 00015523 ____A C:\Users\Ultra\Downloads\3124e7ee5caae3c1542e5e37740b2b25daf2b1b5.zip
2012-04-24 18:33 - 2012-04-24 18:33 - 00016292 ____A C:\Users\Ultra\Downloads\AARAO_REIS8e20b1e9e042325c45b00c0a2b392521.rar
2012-04-24 18:33 - 2012-04-24 18:33 - 00016292 ____A C:\Users\Ultra\Downloads\AARAO_REIS8e20b1e9e042325c45b00c0a2b392521 (1).rar
2012-04-24 18:09 - 2012-04-24 18:09 - 00017746 ____A C:\Users\Ultra\Downloads\AARAO_REIS3614141bcf641fd94d68e05c3a7ebf3a.rar
2012-04-24 17:48 - 2012-04-24 17:48 - 00011567 ____A C:\Users\Ultra\Downloads\34f4eb74fd4dab92cbed4750f33748bce604a178.zip
2012-04-24 17:18 - 2012-04-24 17:18 - 00015806 ____A C:\Users\Ultra\Downloads\447b6465aab16606916245eb01fb2f57d939d279.zip
2012-04-24 17:00 - 2012-04-24 13:13 - 00000000 ____D C:\Users\All Users\Adobe
2012-04-24 16:54 - 2012-04-24 16:54 - 00013650 ____A C:\Users\Ultra\Downloads\4ad7d1a25be415a4ecb7036b95892cd12b8f4320.zip
2012-04-24 16:48 - 2012-04-24 16:48 - 00023883 ____A C:\Users\Ultra\Downloads\4045a3c07dba045e0f25babb52e537a3af06c2a3.zip
2012-04-24 16:22 - 2012-04-24 16:22 - 00017022 ____A C:\Users\Ultra\Downloads\AARAO_REIS142b6b807cd7a0333ade9d1348e13825.rar
2012-04-24 15:58 - 2012-04-24 15:58 - 00017476 ____A C:\Users\Ultra\Downloads\AARAO_REIS4fb04a602f43391ce38aa18706aed5cc.rar
2012-04-24 14:53 - 2012-04-12 04:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\TERA-Diagnostic
2012-04-24 13:57 - 2012-04-24 13:57 - 00000737 ____A C:\Users\Ultra\.imagineer_log.txt
2012-04-24 13:22 - 2012-04-24 13:22 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2012-04-24 13:17 - 2012-04-24 13:17 - 00000000 ____D C:\Program Files\Adobe
2012-04-24 13:16 - 2012-04-24 13:14 - 00000000 ____D C:\Program Files\Common Files\Adobe
2012-04-24 13:15 - 2012-04-24 13:15 - 00000000 ____D C:\Program Files (x86)\Adobe Story
2012-04-24 13:14 - 2012-04-24 13:14 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2012-04-24 13:14 - 2012-04-24 13:14 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2012-04-24 13:07 - 2012-04-24 13:07 - 00001251 ____A C:\Users\Ultra\Documents\hosts.txt
2012-04-24 12:14 - 2012-04-24 12:14 - 00000000 ____D C:\Users\Ultra\AppData\Local\{BF4CA9D7-FABD-4A5D-B9C4-BF7BCFC89DE2}
2012-04-24 12:14 - 2012-04-24 12:13 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4ED12895-7906-4C43-997F-A6A13F64828F}
2012-04-24 00:36 - 2012-04-24 00:28 - 01129120 ____A C:\Users\Ultra\Downloads\C.O final.pptx
2012-04-24 00:13 - 2012-04-24 00:13 - 00000000 ____D C:\Users\Ultra\AppData\Local\{DB7A540F-ED49-4194-B1FB-774CC576851E}
2012-04-24 00:13 - 2012-04-24 00:13 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A375D9A1-9F0E-493F-A8E7-EEFEDD924F5C}
2012-04-23 14:00 - 2012-04-23 14:00 - 00060215 ____A C:\Users\Ultra\Downloads\Aula_Pratica_SWOT_Jose_Seruya (1).pdf
2012-04-23 13:59 - 2012-04-23 13:59 - 00787393 ____A C:\Users\Ultra\Downloads\4teorica_05_Mar_2012_Jose_Seruya (3).pdf
2012-04-23 13:59 - 2012-04-23 13:59 - 00056554 ____A C:\Users\Ultra\Downloads\3aula_Pratica_28_Fev_2012_Jose_Seruya (2).pdf
2012-04-23 13:55 - 2012-04-23 13:55 - 00872281 ____A C:\Users\Ultra\Downloads\6teorica_19_Mar_2012_Jose_Seruya.pdf
2012-04-23 13:42 - 2012-04-23 13:42 - 03092176 ____A C:\Users\Ultra\Downloads\Caso_Igfss_paula_Pedro_26_Marco_2012_Jose_Seruya.pdf
2012-04-23 13:42 - 2012-04-23 13:42 - 00115693 ____A C:\Users\Ultra\Downloads\8teorica_16_Abr_2012_Jose_Seruya (2).pdf
2012-04-23 13:42 - 2012-04-23 13:42 - 00115693 ____A C:\Users\Ultra\Downloads\8teorica_16_Abr_2012_Jose_Seruya (1).pdf
2012-04-23 13:28 - 2012-04-23 13:28 - 00082107 ____A C:\Users\Ultra\Downloads\Caso_Fabimage_Jose_Seruya (2).pdf
2012-04-23 12:03 - 2012-04-23 12:03 - 00787393 ____A C:\Users\Ultra\Downloads\4teorica_05_Mar_2012_Jose_Seruya (2).pdf
2012-04-23 12:03 - 2012-04-23 12:03 - 00056554 ____A C:\Users\Ultra\Downloads\3aula_Pratica_28_Fev_2012_Jose_Seruya (1).pdf
2012-04-23 12:00 - 2012-04-23 12:00 - 00787393 ____A C:\Users\Ultra\Downloads\4teorica_05_Mar_2012_Jose_Seruya (1).pdf
2012-04-23 11:37 - 2012-04-23 11:37 - 00015809 ____A C:\Users\Ultra\Downloads\AARAO_REIS83b526114b8c6320f02d1020d10c6b41 (1).rar
2012-04-23 11:01 - 2012-04-23 11:01 - 00701010 ____A C:\Users\Ultra\Downloads\4_Aula_Pratica_06_Marco_2012_Jose_Seruya.pdf
2012-04-23 10:12 - 2012-04-23 10:11 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C65537B0-55FF-41A3-BFCA-DBD62005EBBD}
2012-04-23 10:11 - 2012-04-23 10:11 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C9B1902E-315F-44D9-830C-449627614CAD}
2012-04-22 21:35 - 2012-04-22 21:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{AABD559B-4352-465D-9226-899237A31709}
2012-04-22 21:35 - 2012-04-22 21:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{934AF4C0-A6F8-48CB-B7CB-5A81F38F4EC0}
2012-04-22 17:35 - 2012-04-22 17:35 - 00016122 ____A C:\Users\Ultra\Downloads\AARAO_REISf8d51f281bcf0167acd2aa1ad73d0469.rar
2012-04-22 17:28 - 2012-04-22 17:28 - 00384172 ____A C:\Users\Ultra\Downloads\5teorica_12_Mar_2012_Jose_Seruya.pdf
2012-04-22 17:27 - 2012-04-22 14:35 - 00502120 ____A C:\Users\Ultra\Downloads\Comunicação Organizacional (2).pptx
2012-04-22 15:30 - 2012-04-22 15:30 - 00524050 ____A C:\Users\Ultra\Downloads\3teorica_27_Fev_2012_Jose_Seruya (2).pdf
2012-04-22 14:57 - 2012-04-22 14:57 - 00084133 ____A C:\Users\Ultra\Desktop\joker_nick.jpg
2012-04-22 14:51 - 2012-04-22 14:51 - 00524050 ____A C:\Users\Ultra\Downloads\3teorica_27_Fev_2012_Jose_Seruya (1).pdf
2012-04-22 14:51 - 2012-04-22 14:51 - 00043794 ____A C:\Users\Ultra\Downloads\Caso_Tvprime_Jose_Seruya (1).pdf
2012-04-22 14:27 - 2012-04-22 14:27 - 00817615 ____A C:\Users\Ultra\Downloads\2teorica_13_Fev_2012_Incl_TMN_Jose_Seruya (2).pdf
2012-04-22 14:27 - 2012-04-22 14:27 - 00060215 ____A C:\Users\Ultra\Downloads\Aula_Pratica_SWOT_Jose_Seruya.pdf
2012-04-22 11:32 - 2012-04-22 11:32 - 00015754 ____A C:\Users\Ultra\Downloads\AARAO_REISd46274c02b480d9f2fc83776b8c3b096.rar
2012-04-22 10:59 - 2012-04-22 10:59 - 00034324 ____A C:\Users\Ultra\Downloads\AARAO_REISfa21761bcf2fa9e440ba0c506ab1ee35.rar
2012-04-22 10:36 - 2012-04-22 10:36 - 00016128 ____A C:\Users\Ultra\Downloads\AARAO_REIS25daf13a34cc17d123bbf021931d58ae.rar
2012-04-22 10:35 - 2012-04-22 10:35 - 00015809 ____A C:\Users\Ultra\Downloads\AARAO_REIS83b526114b8c6320f02d1020d10c6b41.rar
2012-04-22 10:06 - 2012-04-22 10:06 - 00017166 ____A C:\Users\Ultra\Downloads\AARAO_REISb3b54f64cda53ee2ac4a15142b59b5cc.rar
2012-04-22 09:42 - 2012-04-22 09:42 - 00013896 ____A C:\Users\Ultra\Downloads\AARAO_REIS2c612decb2c7a61398e833a7ec16c62f.rar
2012-04-22 09:35 - 2012-04-22 09:35 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5448571E-F3DE-41A2-9B16-0C1BBF867B6C}
2012-04-22 09:34 - 2012-04-22 09:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{632ABA02-82D9-400F-AB94-23C53AF037D0}
2012-04-22 09:17 - 2012-04-22 09:17 - 00017029 ____A C:\Users\Ultra\Downloads\AARAO_REIS449d44f169bd5156a7fa20eadd585314.rar
2012-04-22 08:11 - 2012-04-22 08:11 - 00012372 ____A C:\Users\Ultra\Downloads\Programa_Comorg_2011_12_Jose_Seruya.pdf
2012-04-22 08:09 - 2012-04-22 08:09 - 00817615 ____A C:\Users\Ultra\Downloads\2teorica_13_Fev_2012_Incl_TMN_Jose_Seruya (1).pdf
2012-04-22 08:04 - 2012-04-22 08:04 - 00027205 ____A C:\Users\Ultra\Downloads\1aula_Pratica_7_Fev_2012_Jose_Seruya (2).pdf
2012-04-22 07:57 - 2012-04-22 07:57 - 00084337 ____A C:\Users\Ultra\Downloads\Comunicação Organizacional (1).pptx
2012-04-22 07:31 - 2012-04-22 07:31 - 00063315 ____A C:\Users\Ultra\Downloads\[kat.ph]bleepedhard18.ginger.lee.480p.wmv.torrent
2012-04-22 07:31 - 2012-04-22 07:31 - 00031692 ____A C:\Users\Ultra\Downloads\[kat.ph]bleepedhard18.ginger.lee.wmv.torrent
2012-04-22 07:31 - 2012-04-22 07:31 - 00017556 ____A C:\Users\Ultra\Downloads\[kat.ph]naughty.bookworms.alexa.jordan.ginger.lee.xxx.torrent
2012-04-22 07:31 - 2012-04-22 07:31 - 00017104 ____A C:\Users\Ultra\Downloads\[kat.ph]massage.girls.18.com.ginger.lee.torrent
2012-04-22 07:02 - 2012-04-22 07:02 - 00743390 ____A C:\Users\Ultra\Downloads\1teorica_06_Fev_2012_Jose_Seruya (2).pdf
2012-04-22 06:34 - 2012-04-22 06:34 - 00084337 ____A C:\Users\Ultra\Downloads\Comunicação Organizacional.pptx
2012-04-22 04:51 - 2012-05-22 00:53 - 00025600 ____A (Nokia) C:\Windows\System32\Drivers\pccsmcfdx64.sys
2012-04-22 03:12 - 2012-04-22 03:12 - 00000000 ____D C:\Users\Ultra\Documents\Diablo III
2012-04-22 03:12 - 2012-04-21 13:43 - 00000000 ____D C:\Users\All Users\Blizzard Entertainment
2012-04-21 21:34 - 2012-04-21 21:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E49EC1C7-8275-42F9-96B7-205734A198EA}
2012-04-21 21:34 - 2012-04-21 21:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E2E2A909-ACF7-4553-9492-279B808051B4}
2012-04-21 18:33 - 2012-04-21 18:33 - 00015879 ____A C:\Users\Ultra\Downloads\AARAO_REIS678ab226e6d9b8871454acdcf571b07c.rar
2012-04-21 14:26 - 2012-04-21 14:26 - 00249374 ____A C:\Users\Ultra\Desktop\patuscada2.jpg
2012-04-21 13:44 - 2012-04-21 13:44 - 46267680 ____A (Blizzard Entertainment) C:\Users\Ultra\Downloads\Diablo III Beta enGB Setup.exe
2012-04-21 13:44 - 2012-04-21 13:44 - 00000000 ____D C:\Users\All Users\Battle.net
2012-04-21 13:28 - 2012-04-21 13:28 - 32448800 ____A C:\Users\Ultra\Downloads\WoW-4.0.0-WOW-enGB-Installer.exe
2012-04-21 09:34 - 2012-04-21 09:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A3170EFB-C55C-4866-A26C-08BD9B4CEE5B}
2012-04-21 09:34 - 2012-04-21 09:34 - 00000000 ____D C:\Users\Ultra\AppData\Local\{142714F7-4C9A-47CE-982B-E793E23A96E6}
2012-04-21 07:02 - 2012-04-20 17:45 - 00000000 ____D C:\Users\Ultra\Documents\BattleForge
2012-04-21 01:42 - 2012-04-21 01:42 - 00015452 ____A C:\Users\Ultra\Downloads\[kat.ph]realcouples.kat.kenny.buster.torrent
2012-04-21 01:32 - 2012-04-21 01:32 - 00025690 ____A C:\Users\Ultra\Downloads\[kat.ph]realcouples.uk.birdie.james.torrent
2012-04-21 01:32 - 2012-04-21 01:32 - 00015670 ____A C:\Users\Ultra\Downloads\[kat.ph]realcouples.elle.ian.dbbians.freeforums.org.torrent
2012-04-21 01:32 - 2012-04-21 01:32 - 00015249 ____A C:\Users\Ultra\Downloads\[kat.ph]realcouples.emma.rich.dbbians.freeforums.org.torrent
2012-04-21 01:29 - 2012-04-21 01:29 - 00000000 ____D C:\Users\All Users\Premium
2012-04-21 01:29 - 2012-04-21 01:28 - 00000000 ____D C:\Users\All Users\InstallMate
2012-04-21 01:28 - 2012-04-21 01:28 - 00289408 ____A (Premium) C:\Users\Ultra\Downloads\FastDownload.exe
2012-04-21 01:25 - 2012-04-21 01:25 - 00016672 ____A C:\Users\Ultra\Downloads\2D57D7CAD97BDCA2585F51E1280DFC3EC7D05D55.torrent
2012-04-20 21:34 - 2012-04-20 21:33 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4ABC5344-1C47-49E2-8151-CF3383C6EC82}
2012-04-20 21:33 - 2012-04-20 21:33 - 00000000 ____D C:\Users\Ultra\AppData\Local\{349C3B50-D73D-4B73-A384-279E09A5CF3F}
2012-04-20 17:34 - 2012-04-20 17:33 - 84167392 ____A C:\Users\Ultra\Downloads\BattleForgeInstall.exe
2012-04-20 12:06 - 2012-05-14 03:14 - 00000000 ____D C:\Users\Ultra\Desktop\__rpg
2012-04-20 10:43 - 2012-04-20 10:43 - 00018926 ____A C:\Users\Ultra\Downloads\AARAO_REIS063ceab26a255397b8a9d250f99bd14e.rar
2012-04-20 09:33 - 2012-04-20 09:33 - 00000000 ____D C:\Users\Ultra\AppData\Local\{80597962-D263-46AE-BC13-BABA311E2619}
2012-04-20 09:33 - 2012-04-20 09:33 - 00000000 ____D C:\Users\Ultra\AppData\Local\{37C8AB0E-7A35-44AB-A808-910E2D413172}
2012-04-20 03:07 - 2012-05-14 03:14 - 00001098 ____A C:\Users\Ultra\Desktop\changelog.txt
2012-04-19 21:33 - 2012-04-19 21:32 - 00000000 ____D C:\Users\Ultra\AppData\Local\{ABA08008-F4F7-4011-A4DF-CC6B2EECD052}
2012-04-19 21:32 - 2012-04-19 21:32 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0227EB71-0503-4207-A2C4-F10858083411}
2012-04-19 20:44 - 2012-05-14 03:14 - 00397376 ____A C:\Users\Ultra\Desktop\_DS_MENU.DAT
2012-04-19 11:23 - 2012-04-19 11:23 - 00016672 ____A C:\Users\Ultra\Downloads\[isoHunt] Malloy Martini - Divine Vision.torrent
2012-04-19 11:20 - 2012-04-19 11:20 - 00023280 ____A C:\Users\Ultra\Downloads\[kat.ph]bratsluts.12.02.05.cate.harrington.varsity.girl.torrent
2012-04-19 11:20 - 2012-04-19 11:20 - 00019135 ____A C:\Users\Ultra\Downloads\[kat.ph]dailyse.21sextury.com.cate.harrington.torrent
2012-04-19 11:20 - 2012-04-19 11:20 - 00016662 ____A C:\Users\Ultra\Downloads\[kat.ph]realcouples.cate.harrington.scott.torrent
2012-04-19 11:15 - 2012-01-28 11:35 - 00000000 ____D C:\Users\Ultra\riotsGamesLogs
2012-04-19 10:02 - 2012-04-19 10:02 - 00068930 ____A C:\Users\Ultra\Downloads\Goodfellas.1990.720p.BluRay.x264-WiKi.5094628.TPB.torrent
2012-04-19 09:32 - 2012-04-19 09:32 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A0B09CCE-FA8C-42F6-B210-429CC5FA4E76}
2012-04-19 09:32 - 2012-04-19 09:32 - 00000000 ____D C:\Users\Ultra\AppData\Local\{01C549E2-8414-4153-BF0F-5349B196CB38}
2012-04-18 15:52 - 2012-04-18 15:52 - 00953482 ____A C:\HpuInstall.log
2012-04-18 15:52 - 2012-04-18 15:52 - 00000000 ____D C:\Windows\Hewlett-Packard
2012-04-18 15:52 - 2012-03-14 13:11 - 00000000 ____D C:\Program Files (x86)\HP
2012-04-18 15:00 - 2012-04-18 14:53 - 121270768 ____A C:\Users\Ultra\Downloads\Aimee High Preview.wmv
2012-04-18 15:00 - 2012-04-18 14:53 - 115454724 ____A C:\Users\Ultra\Downloads\Jenna High Preview.wmv
2012-04-18 14:59 - 2012-04-18 14:52 - 116990802 ____A C:\Users\Ultra\Downloads\Kristina High Preview.wmv
2012-04-18 14:56 - 2012-04-18 14:56 - 00016053 ____A C:\Users\Ultra\Downloads\F3C850E0D5C8680322EFD7E0DA4276E759583487.torrent
2012-04-18 14:55 - 2012-04-18 14:52 - 47646909 ____A C:\Users\Ultra\Downloads\Heather Taylor High Preview.wmv
2012-04-18 10:06 - 2012-04-18 10:06 - 01509522 ____A C:\Users\Ultra\Downloads\Fotos dos Planos.zip
2012-04-18 09:56 - 2012-04-18 09:56 - 00115693 ____A C:\Users\Ultra\Downloads\8teorica_16_Abr_2012_Jose_Seruya.pdf
2012-04-18 09:56 - 2012-04-18 09:56 - 00082107 ____A C:\Users\Ultra\Downloads\Caso_Fabimage_Jose_Seruya.pdf
2012-04-18 08:48 - 2012-04-18 08:47 - 00000000 ____D C:\Users\Ultra\AppData\Local\{03E1A090-367F-4D6C-ACD4-AE191011CF3A}
2012-04-18 08:47 - 2012-04-18 08:47 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2A9C0078-392E-453B-B3E7-6F016355B71B}
2012-04-17 17:18 - 2012-04-17 13:21 - 00301866 ____A C:\Users\Ultra\Downloads\SociologiadaComunicação (1).pptx
2012-04-17 16:34 - 2012-04-17 16:34 - 00154408 ____A C:\Users\Ultra\Downloads\Eldermanf093ad7abc78b6425693b16d72bdf901.zip
2012-04-17 16:33 - 2012-04-17 16:33 - 00022417 ____A C:\Users\Ultra\Downloads\565774.zip
2012-04-17 12:00 - 2012-04-17 12:00 - 00000000 ____D C:\Users\Ultra\AppData\Local\{CF1348FD-A9B0-4339-B5A5-64FF26739BCF}
2012-04-17 12:00 - 2012-04-17 12:00 - 00000000 ____D C:\Users\Ultra\AppData\Local\{8F1D055B-B144-4963-8951-E716074FFE30}
2012-04-16 15:29 - 2012-04-16 15:29 - 00020937 ____A C:\Users\Ultra\Downloads\54594ef49e4aa5128cd7a56f9ad12e36c4b377fd.zip
2012-04-16 14:43 - 2012-04-16 14:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{DE98676B-C365-4B01-B229-CE8D4D99CA12}
2012-04-16 14:43 - 2012-04-16 14:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2EAD263B-EEED-43B6-BC0C-22D5C54323C5}
2012-04-16 12:25 - 2012-04-16 12:25 - 00072771 ____A C:\Users\Ultra\Downloads\[isoHunt] 2037585.torrent
2012-04-16 10:21 - 2012-04-16 10:21 - 00044966 ____A C:\Users\Ultra\Downloads\Calendario_Grupos_Casos_Empresa_2012_3_Jose_Seruya_2.pdf
2012-04-16 10:21 - 2012-04-16 10:21 - 00044966 ____A C:\Users\Ultra\Downloads\Calendario_Grupos_Casos_Empresa_2012_3_Jose_Seruya_2 (1).pdf
2012-04-16 10:21 - 2012-04-16 10:21 - 00044948 ____A C:\Users\Ultra\Downloads\Calendario_Grupos_Casos_Empresa_2012_3_Jose_Seruya.pdf
2012-04-16 03:04 - 2012-04-16 03:04 - 04364800 ____A (Krzysztof Kowalczyk) C:\Users\Ultra\Downloads\SumatraPDF-2.0.1-install.exe
2012-04-16 03:04 - 2012-04-16 03:04 - 00164546 ____A C:\Users\Ultra\Downloads\GG14_numerorecibo_7100345997_numeroapolice_7000129206_8265707.pdf
2012-04-16 03:04 - 2012-04-16 03:04 - 00145310 ____A C:\Users\Ultra\Downloads\G500_numeroapolice_7000129206_8265706.pdf
2012-04-16 03:01 - 2012-04-16 02:53 - 00000000 ____D C:\Program Files (x86)\Tibia
2012-04-16 02:53 - 2012-04-16 02:52 - 30678149 ____A (CipSoft GmbH ) C:\Users\Ultra\Downloads\tibia952.exe
2012-04-16 02:43 - 2012-04-16 02:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3715B257-8D2C-49F8-9E33-983F887A8A35}
2012-04-16 02:43 - 2012-04-16 02:42 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1DA0C3A5-9028-4B3E-8A0C-8DC63E861FBC}
2012-04-15 17:14 - 2012-04-15 17:14 - 00024858 ____A C:\Users\Ultra\Downloads\Gossip.Girl.S05E03.720p.HDTV.x264-IMMERSE.english.subtitlesource.zip
2012-04-15 17:13 - 2012-04-15 17:13 - 00024836 ____A C:\Users\Ultra\Downloads\a8ea3ffe10483ab1df73436bdd419b56dd7fe60a (1).zip
2012-04-15 17:13 - 2012-04-15 17:13 - 00024343 ____A C:\Users\Ultra\Downloads\b22b7ae369524eb0e2f62fe410875d4aa3b3f682.zip
2012-04-15 17:12 - 2012-04-15 17:12 - 00024836 ____A C:\Users\Ultra\Downloads\a8ea3ffe10483ab1df73436bdd419b56dd7fe60a.zip
2012-04-15 05:45 - 2012-04-15 05:44 - 00000000 ____D C:\Users\Ultra\AppData\Local\{FA9A25D0-1C81-4985-B70E-BC0925131042}
2012-04-15 05:44 - 2012-04-15 05:44 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E20A651F-0D3F-46C7-80B9-5C9E4500CEFE}
2012-04-14 17:44 - 2012-04-14 17:44 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A6ABD8C9-884B-4AD2-9622-E4F42680CD53}
2012-04-14 17:44 - 2012-04-14 17:44 - 00000000 ____D C:\Users\Ultra\AppData\Local\{86563547-A026-4F5C-A767-C8310DC3F146}
2012-04-14 05:44 - 2012-04-14 05:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{BF76C399-3B81-452F-9BA5-03CAA5408759}
2012-04-14 05:43 - 2012-04-14 05:43 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4FF0AD61-A25E-4A01-A493-E70A25ABCC04}
2012-04-13 17:02 - 2012-04-13 17:02 - 00036326 ____A C:\Users\Ultra\Downloads\guilmm455ccba68b15e136fae670d20b0517d0.rar
2012-04-13 16:31 - 2012-04-13 16:31 - 00000000 ____D C:\Users\Ultra\AppData\Local\{489CAC14-03AD-490C-B776-3FD93D8D5A96}
2012-04-13 16:31 - 2012-04-13 16:31 - 00000000 ____D C:\Users\Ultra\AppData\Local\{043A9BC5-E8AE-4F27-BF7E-7E791120A7DA}
2012-04-13 09:25 - 2012-04-13 09:25 - 00000000 ____D C:\Users\Ultra\Documents\Almost Human
2012-04-13 09:24 - 2012-04-13 09:24 - 00002119 ____A C:\Users\Public\Desktop\Legend of Grimrock.lnk
2012-04-13 09:24 - 2012-04-13 09:24 - 00000000 ____D C:\Program Files (x86)\GOG.com
2012-04-13 05:06 - 2012-04-13 05:06 - 00041837 ____A C:\Users\Ultra\Downloads\[kat.ph]the.phantom.of.the.opera.2004.720p.bluray.dtsx264.ctrlhd.torrent
2012-04-13 05:05 - 2012-04-13 05:05 - 00195136 ____A C:\Users\Ultra\Downloads\The_Phantom_Of_The_Opera_2004_720p_BluRay_x264-MySiLU.exe
2012-04-13 04:50 - 2012-04-13 04:50 - 00067903 ____A C:\Users\Ultra\Downloads\Assassins.Creed.II-SKIDROW.torrent
2012-04-13 04:31 - 2012-04-13 04:31 - 00000000 ____D C:\Users\Ultra\AppData\Local\{674BD194-6F40-41F4-9B47-16A202839E91}
2012-04-13 04:31 - 2012-04-13 04:30 - 00000000 ____D C:\Users\Ultra\AppData\Local\{520239B1-2C0C-4FDA-A23F-22E5AA566CC4}
2012-04-13 04:30 - 2012-01-28 10:24 - 00000000 ____D C:\Program Files (x86)\Windows Live
2012-04-13 03:29 - 2012-04-13 03:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{6494E83D-86B9-4FE6-84F5-51887F2466BF}
2012-04-13 03:13 - 2012-04-13 03:13 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0F9564F3-C055-498D-AB16-E72FA776CDCC}
2012-04-13 03:13 - 2012-04-13 03:12 - 00000000 ____D C:\Users\Ultra\AppData\Local\{83A51A0D-F9AF-4768-AFCC-04D2F9AAC0FA}
2012-04-12 19:09 - 2012-04-12 19:09 - 00026049 ____A C:\Users\Ultra\Downloads\f96090a3792877f783ec5ed1813d26204d7429d9.zip
2012-04-12 19:08 - 2012-04-12 19:08 - 00051309 ____A C:\Users\Ultra\Downloads\AARAO_REISea241ff69af4ac54e8dc2d9050504ba1.rar
2012-04-12 19:07 - 2012-04-12 19:07 - 00024742 ____A C:\Users\Ultra\Downloads\AARAO_REISa1b8c963f221f1a03eb767d95816b862.rar
2012-04-12 17:26 - 2012-04-12 17:26 - 00120322 ____A C:\Users\Ultra\Downloads\EM_2_SEM_PROG_11_12_Goncalo_Silva.pdf
2012-04-12 15:12 - 2012-04-12 15:12 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2B9BC01D-C9F0-4287-B739-CA9543A06AD1}
2012-04-12 11:32 - 2012-04-12 11:32 - 00014632 ____A C:\Users\Ultra\Downloads\[isoHunt] 2105074.torrent
2012-04-12 06:39 - 2012-04-12 06:39 - 10940755 ____A C:\Users\Ultra\Downloads\YearOfTheDragon.themepack
2012-04-12 06:39 - 2012-04-12 06:39 - 05330765 ____A C:\Users\Ultra\Downloads\Masquerade.themepack
2012-04-12 06:31 - 2012-04-12 06:31 - 13766774 ____A C:\Users\Ultra\Downloads\FractalArtCameronBashaw.themepack
2012-04-12 06:31 - 2012-04-12 06:31 - 10875782 ____A C:\Users\Ultra\Downloads\GhostTownTracyHymas.themepack
2012-04-12 06:31 - 2012-04-12 06:31 - 08402527 ____A C:\Users\Ultra\Downloads\DarkSkiesTracyHymas.themepack
2012-04-12 04:57 - 2012-04-12 04:57 - 00158522 ____A C:\Users\Ultra\Downloads\SociologiadaComunicação.pptx
2012-04-12 04:48 - 2012-04-12 04:48 - 00014532 ____A C:\Users\Ultra\Downloads\E1DD62E8672EB00480BCB06DF82E9166E661D5E2.torrent
2012-04-12 04:20 - 2012-01-28 08:36 - 00486709 ____A C:\Windows\DirectX.log
2012-04-12 04:17 - 2012-04-12 04:16 - 96234888 ____A (En Masse Entertainment) C:\Users\Ultra\Downloads\TERA-Setup.exe
2012-04-12 03:12 - 2012-04-12 03:12 - 00000000 ____D C:\Users\Ultra\AppData\Local\{77ACE924-4DE3-4336-AAE8-150445126306}
2012-04-11 14:29 - 2012-04-11 14:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A5133E6B-982F-4D9E-AF74-8FA9082207B9}
2012-04-11 10:15 - 2012-04-11 10:15 - 00143430 ____A C:\Users\Ultra\Downloads\Eldermanfe025d3232b65245336c443d1014bf82.zip
2012-04-11 07:43 - 2012-04-11 07:42 - 198732944 ____A C:\Users\Ultra\Downloads\PS3UPDAT.PUP
2012-04-11 02:29 - 2012-04-11 02:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{EDBF1CEE-8277-4A8A-BBC3-04C35B674F84}
2012-04-10 14:29 - 2012-04-10 14:29 - 00000000 ____D C:\Users\Ultra\AppData\Local\{CC1174DC-C76E-4DE1-B5D7-4AB441BC1960}
2012-04-10 12:09 - 2012-04-10 12:09 - 00022325 ____A C:\Users\Ultra\Downloads\561069.zip
2012-04-10 10:53 - 2012-04-10 10:48 - 00000000 ____D C:\Users\Ultra\Windows Marketplace
2012-04-10 10:50 - 2012-04-10 10:50 - 00642712 ____A (Microsoft Corporation) C:\Users\Ultra\Downloads\gfwlivesetup_4d530fa3e0000001.exe
2012-04-10 10:38 - 2012-04-10 10:38 - 00000000 ____D C:\Users\Ultra\Documents\Games for Windows - LIVE Demos
2012-04-10 10:36 - 2012-04-10 10:36 - 00000000 ____D C:\Users\Ultra\Documents\Spartan
2012-04-10 10:35 - 2012-04-10 10:35 - 00000000 ____D C:\Windows\SysWOW64\xlive
2012-04-10 10:35 - 2012-04-10 10:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2012-04-10 08:58 - 2012-04-10 08:58 - 00043189 ____A C:\Users\Ultra\Downloads\AARAO_REIS4b77e572f14efba2716dd87eb93f98a6.rar
2012-04-10 08:57 - 2012-04-10 08:57 - 00143237 ____A C:\Users\Ultra\Downloads\Elderman7521011ad3468aa83dde9a1bf84e1e55.zip
2012-04-10 02:29 - 2012-04-10 02:28 - 00000000 ____D C:\Users\Ultra\AppData\Local\{32862DA4-15A0-4E75-8588-ADB7EEC3E2D7}
2012-04-10 01:50 - 2012-04-10 01:50 - 00016295 ____A C:\Users\Ultra\Downloads\[kat.ph]true.justice.season.1.2011.brrip.hotice.torrent
2012-04-09 18:09 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2012-04-09 16:33 - 2012-04-09 16:33 - 00018975 ____A C:\Users\Ultra\Downloads\c4de96aa7dee63db127bf7a08a9fad6f2d761dea.zip
2012-04-09 16:29 - 2012-04-09 16:29 - 00147795 ____A C:\Users\Ultra\Downloads\Eldermanb4b2602ef46681dd9a94ee5a94fbe58f.zip
2012-04-09 14:28 - 2012-04-09 14:28 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4D1B3945-50C3-4177-AD6C-754FA2C0B36B}
2012-04-09 09:38 - 2012-03-25 09:47 - 00000000 ____D C:\Users\Ultra\AppData\Local\dxhr
2012-04-09 02:28 - 2012-04-09 02:28 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C377BEC4-EDE6-460C-ABFD-637ACA75AE58}
2012-04-08 16:35 - 2012-04-08 16:35 - 00044375 ____A C:\Users\Ultra\Downloads\Limitless.2011.Unrated.Extended.Cut.720p.BluRay.x264.DTS-HDChina._www.ENGSUB.NET.zip
2012-04-08 16:35 - 2012-04-08 16:35 - 00038161 ____A C:\Users\Ultra\Downloads\Limitless.UNRATED.720p.Bluray.x264-MHD._www.ENGSUB.NET.zip
2012-04-08 16:34 - 2012-04-08 16:34 - 00037938 ____A C:\Users\Ultra\Downloads\6fb0ada99fd0e61a40a00bbbea8ab94155a1ebd7.zip
2012-04-08 14:24 - 2012-04-08 14:24 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2D3A86F3-CAB3-4F10-AD1D-FDC9273C5576}
2012-04-08 02:24 - 2012-04-08 02:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{906E2B0B-D3BD-488A-A44B-BD2376D9C0BD}
2012-04-08 01:28 - 2012-04-08 01:28 - 00018112 ____A C:\Users\Ultra\Downloads\AARAO_REIS904ec649bb00d2827c7361f06e281976.rar
2012-04-07 17:14 - 2012-04-07 17:14 - 00014723 ____A C:\Users\Ultra\Downloads\AARAO_REIS790ce93b4479bd3b289693ae91f5b9c1.rar
2012-04-07 17:05 - 2012-04-07 17:05 - 00011367 ____A C:\Users\Ultra\Downloads\F11926F08FD90C62B95EAE3AEDC854849784C773.torrent
2012-04-07 14:23 - 2012-04-07 14:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{88836488-1138-4F67-B5A6-2E8219F52B79}
2012-04-07 01:57 - 2012-04-07 01:57 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B2F4592F-068C-49B4-8211-8E55AB767C16}
2012-04-07 01:56 - 2012-04-07 01:56 - 00033670 ____A C:\Users\Ultra\Downloads\AARAO_REIS7e4cb2b242d3f5872688e4c7ba54840e (1).rar
2012-04-07 01:55 - 2012-04-07 01:55 - 00033670 ____A C:\Users\Ultra\Downloads\AARAO_REIS7e4cb2b242d3f5872688e4c7ba54840e.rar
2012-04-06 13:57 - 2012-04-06 13:57 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5E6EC0DA-6453-428E-9680-21FF80E1F7D8}
2012-04-06 13:11 - 2012-02-25 13:28 - 00000000 ____D C:\Program Files (x86)\Overwolf
2012-04-06 12:59 - 2012-02-25 13:28 - 00000000 ____D C:\Users\Ultra\AppData\Local\Overwolf
2012-04-06 02:31 - 2012-04-06 02:31 - 00019287 ____A C:\Users\Ultra\Downloads\[kat.ph]bleep.team.five.brittany.harper.callie.cobra.and.missi.daniels.torrent
2012-04-06 02:30 - 2012-04-06 02:30 - 00014201 ____A C:\Users\Ultra\Downloads\[kat.ph]cumfiesta.brittany.harper.sexy.lil.thing.torrent
2012-04-06 02:15 - 2012-04-06 02:15 - 00017558 ____A C:\Users\Ultra\Downloads\HouseOfTaboo.-.Kelley.Scarlett.5835013.TPB.torrent
2012-04-06 02:15 - 2012-04-06 02:15 - 00015892 ____A C:\Users\Ultra\Downloads\7C4C93BAE6DD829251B0F536501B0823A71FE69C.torrent
2012-04-06 02:14 - 2012-04-06 02:14 - 00000000 ____D C:\Users\Public\Documents\Canon MyCameraFiles
2012-04-06 02:14 - 2012-04-06 02:13 - 00000000 ____D C:\Program Files (x86)\Canon
2012-04-06 02:13 - 2012-04-06 02:13 - 00000000 ____D C:\Users\All Users\ZoomBrowser
2012-04-06 01:57 - 2012-04-06 01:57 - 00000000 ____D C:\Users\Ultra\AppData\Local\{50C6C320-AC37-42BD-973C-52A744FBF649}
2012-04-05 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\pt-PT
2012-04-05 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\pt-PT
2012-04-05 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2012-04-05 16:50 - 2012-04-05 16:50 - 00046990 ____A C:\Users\Ultra\Downloads\AARAO_REIScd65ceedb896e329b0de991123794757.rar
2012-04-05 13:56 - 2012-04-05 13:56 - 00000000 ____D C:\Users\Ultra\AppData\Local\{ED071913-AC11-4992-B156-67150C748F81}
2012-04-05 08:53 - 2012-04-05 08:53 - 00154462 ____A C:\Users\Ultra\Downloads\Elderman7d491e33b6efd7f4092040cd388aa752.zip
2012-04-05 07:53 - 2012-04-05 07:53 - 00028790 ____A C:\Users\Ultra\Downloads\30_Rock_s06e10_Alexis_Goodlooking_and_the_Case_of_the_Missing_Whiskey_2HD-[]www.Demonoid.me[].torrent
2012-04-05 07:53 - 2012-04-05 07:53 - 00028646 ____A C:\Users\Ultra\Downloads\30_Rock_s06e11_Standards_and_Practices_FQM-(www.Demonoid.me).torrent
2012-04-05 04:42 - 2012-01-31 20:11 - 00006750 ____A C:\Windows\IE9_main.log
2012-04-05 04:41 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\servicing
2012-04-05 04:40 - 2012-04-05 04:40 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2012-04-05 04:40 - 2012-04-05 04:40 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-04-05 04:40 - 2012-04-05 04:40 - 00697344 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00603648 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-04-05 04:40 - 2012-04-05 04:40 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-04-05 04:40 - 2012-04-05 04:40 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-04-05 04:40 - 2012-04-05 04:40 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00072822 ____A C:\Windows\SysWOW64\ieuinit.inf
2012-04-05 04:40 - 2012-04-05 04:40 - 00072822 ____A C:\Windows\System32\ieuinit.inf
2012-04-05 04:40 - 2012-04-05 04:40 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2012-04-05 04:40 - 2012-04-05 04:40 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-04-05 04:40 - 2012-04-05 04:40 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-04-05 04:40 - 2012-04-05 04:40 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-04-05 04:38 - 2012-04-05 04:38 - 00543024 ____A (Microsoft Corporation) C:\Users\Ultra\Downloads\IE9-Windows7-x64-enu.exe
2012-04-05 04:25 - 2012-04-05 04:25 - 24241050 ____A (InstallShield Software Corporation) C:\Users\Ultra\Downloads\metalfatigue.exe
2012-04-05 03:01 - 2012-04-05 03:01 - 00047155 ____A C:\Users\Ultra\Downloads\[kat.ph]2.chicks.same.time.gracie.glam.danni.cole.torrent
2012-04-05 03:01 - 2012-04-05 03:01 - 00033495 ____A C:\Users\Ultra\Downloads\[kat.ph]danni.cole.oily.wet.and.horny.torrent
2012-04-05 03:01 - 2012-04-05 03:01 - 00020218 ____A C:\Users\Ultra\Downloads\[kat.ph]earlmiller.09.12.31.danni.cole.and.mikey.xxx.wmv.ohrly.torrent
2012-04-05 03:01 - 2012-04-05 03:01 - 00016228 ____A C:\Users\Ultra\Downloads\[kat.ph]big.tit.cream.pie.danni.cole.creampies.and.motorcycles.torrent
2012-04-05 03:01 - 2012-04-05 03:01 - 00014035 ____A C:\Users\Ultra\Downloads\[kat.ph]real.slut.party.danni.cole.allison.banks.lingerie.sexy.party.torrent
2012-04-05 03:01 - 2012-04-05 03:01 - 00012617 ____A C:\Users\Ultra\Downloads\[kat.ph]massagecreep.danni.cole.torrent
2012-04-05 01:56 - 2012-04-05 01:56 - 00263804 ____A C:\Users\Ultra\Downloads\467913_329894673739966_100001583086481_947595_2120231619_o.jpg
2012-04-05 01:56 - 2012-04-05 01:56 - 00000000 ____D C:\Users\Ultra\AppData\Local\{ECBF7757-61CE-4675-A036-B8123D6A571C}
2012-04-04 16:03 - 2012-04-04 16:03 - 00023228 ____A C:\Users\Ultra\Downloads\[kat.ph]jtbp.sasha.grey.ii.from.all.star.celebrity.sasha.grey.torrent
2012-04-04 16:03 - 2012-04-04 16:03 - 00014310 ____A C:\Users\Ultra\Downloads\[kat.ph]18yearsold.presents.sasha.grey.young.anal.slut.november.26.2006.torrent
2012-04-04 13:56 - 2012-04-04 13:56 - 00000000 ____D C:\Users\Ultra\AppData\Local\{10957733-82DD-4A13-A9AC-340397379C2D}
2012-04-03 17:30 - 2012-04-03 17:30 - 00331933 ____A C:\Users\Ultra\Downloads\466897_329429793786454_100001583086481_946747_1405515368_o.jpg
2012-04-03 16:37 - 2012-04-03 16:37 - 00032460 ____A C:\Users\Ultra\Downloads\AARAO_REISd43321e86c9c4a132220dca7d9589077.rar
2012-04-03 11:19 - 2012-04-03 11:19 - 00000000 ____D C:\Users\Ultra\AppData\Local\{97511515-56E3-44BC-B1FB-636D94001970}
2012-04-02 16:26 - 2012-04-02 16:26 - 00144928 ____A C:\Users\Ultra\Downloads\Elderman991ac360e33a4053fb8777cad22b2399.zip
2012-04-02 13:20 - 2012-04-02 13:20 - 17604163 ____A C:\Users\Ultra\Downloads\A4DRK.mp4
2012-04-02 11:28 - 2012-04-02 11:27 - 00000000 ____D C:\Users\Ultra\AppData\Local\{12FDDA19-C5D1-483F-8B03-4AA187752A34}
2012-04-01 13:09 - 2012-04-01 13:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{FF2B6FE6-6AC9-4806-972C-36770B08E3FC}
2012-04-01 01:09 - 2012-04-01 01:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5656F75B-E73D-4BBF-A4DF-3AC89EA0E2BC}
2012-03-31 13:09 - 2012-03-31 13:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{17960DD5-5F0F-4751-83F0-112173B5B47A}
2012-03-31 11:50 - 2012-03-31 11:50 - 00019700 ____A C:\Users\Ultra\Downloads\558325.zip
2012-03-31 11:37 - 2012-03-31 11:37 - 00038790 ____A C:\Users\Ultra\Downloads\AARAO_REISc598b58e2ddf5151def96169a049bbc0 (1).rar
2012-03-31 10:16 - 2012-03-31 10:16 - 00020074 ____A C:\Users\Ultra\Downloads\AARAO_REIS12ff85ad01446590bc37a5c270d0f2fd.rar
2012-03-31 10:14 - 2012-03-31 10:14 - 00038790 ____A C:\Users\Ultra\Downloads\AARAO_REISc598b58e2ddf5151def96169a049bbc0.rar
2012-03-31 01:09 - 2012-03-31 01:09 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A5C3A65D-449B-47F1-ACAF-AEA0B20C85E6}
2012-03-30 22:05 - 2012-05-09 11:05 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 20:39 - 2012-05-09 11:05 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-03-30 20:39 - 2012-05-09 11:05 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-03-30 19:10 - 2012-05-09 11:05 - 03146240 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-30 16:22 - 2012-03-30 16:22 - 00037751 ____A C:\Users\Ultra\Downloads\gitobeto6452601199bd8b00f3617969a9aac5d8.rar
2012-03-30 16:21 - 2012-03-30 16:21 - 00018959 ____A C:\Users\Ultra\Downloads\57ac5b8bd802b5a21dd37ea6a25e96921eb115f9.zip
2012-03-30 13:08 - 2012-03-30 13:08 - 00000000 ____D C:\Users\Ultra\AppData\Local\{CCC2CB2B-BC69-44D8-BF5F-507CDDC64A60}
2012-03-30 09:30 - 2012-03-30 09:30 - 00029999 ____A C:\Users\Ultra\Downloads\AARAO_REIS0557555a25e4cb093e17cd353576ba89.rar
2012-03-30 03:35 - 2012-05-09 11:04 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-30 01:46 - 2012-03-29 13:00 - 00115332 ____A C:\Users\Ultra\Downloads\capa.docx
2012-03-30 01:28 - 2012-03-30 01:21 - 00046717 ____A C:\Users\Ultra\Downloads\REST_PA.docx
2012-03-30 01:08 - 2012-03-30 01:08 - 00000000 ____D C:\Users\Ultra\AppData\Local\{BB480D5F-4780-4FC7-BC58-840BF5CE4EF3}
2012-03-29 14:42 - 2012-03-29 14:42 - 00166121 ____A C:\Users\Ultra\Downloads\Elderman49f5be9efd6bf3ecf38e1ee459e07bd4.zip
2012-03-29 13:23 - 2012-03-29 13:23 - 00031281 ____A C:\Users\Ultra\Downloads\pateodascomidas_logo1.png
2012-03-29 12:10 - 2012-03-29 12:10 - 00037338 ____A C:\Users\Ultra\Downloads\AARAO_REISb5b19cb76ba2960a25af1548df6105af (1).rar
2012-03-29 12:09 - 2012-03-29 12:09 - 00037338 ____A C:\Users\Ultra\Downloads\AARAO_REISb5b19cb76ba2960a25af1548df6105af.rar
2012-03-29 11:10 - 2012-03-29 11:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\{57C6512F-75E3-4B5A-9569-A3E714CE885A}
2012-03-28 23:10 - 2012-03-28 23:10 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3A2493D9-0AD1-49AB-BC14-133C7AB4DC19}
2012-03-28 10:36 - 2012-03-28 10:36 - 00036504 ____A C:\Users\Ultra\Downloads\000001527 - Março de 2012 - Folha de Remun Principal.pdf
2012-03-28 10:32 - 2012-03-28 10:32 - 00036979 ____A C:\Users\Ultra\Downloads\000001527 - Fevereiro de 2010 - Remun Principal.pdf
2012-03-28 10:11 - 2012-03-28 10:11 - 00000000 ____D C:\Users\Ultra\AppData\Local\{46B39C41-79F9-4136-860D-27DA156CEA54}
2012-03-28 10:11 - 2012-03-28 10:11 - 00000000 ____D C:\Users\Ultra\AppData\Local\{10B93354-3D67-4CB6-B814-BC5E272B6C0C}
2012-03-27 08:14 - 2012-03-27 08:14 - 00018178 ____A C:\Users\Ultra\Downloads\556573.zip
2012-03-27 08:13 - 2012-03-27 08:13 - 00036824 ____A C:\Users\Ultra\Downloads\AARAO_REIS15f484fa44f8676750ba769c294a4a26.rar
2012-03-27 08:04 - 2012-03-27 07:21 - 266268095 ____A C:\Users\Ultra\Downloads\da_blake_rose_by_XxTRUCOxX.rar
2012-03-27 04:11 - 2012-03-27 04:11 - 00000000 ____D C:\Users\Ultra\AppData\Local\{285EFBAE-68E2-46A1-8C3A-BA2B36EDE2EC}
2012-03-27 04:11 - 2012-03-27 04:11 - 00000000 ____D C:\Users\Ultra\AppData\Local\{15A948AC-3FB6-4183-BA21-A932D08B4CF4}
2012-03-26 11:59 - 2012-03-26 11:59 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D64E7690-0DA9-4F89-A08C-D6918FD0539E}
2012-03-26 11:59 - 2012-03-26 11:59 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0C478173-18AE-42B7-8FB9-A0CE9ABA2C4E}
2012-03-25 15:41 - 2012-03-25 15:40 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5A1E6AAE-1CE1-4752-91CF-60207E6D69A2}
2012-03-25 15:40 - 2012-03-25 15:40 - 00000000 ____D C:\Users\Ultra\AppData\Local\{C5872EF2-5C86-42B6-9FB6-907356A8037D}
2012-03-25 09:46 - 2012-03-25 09:46 - 00000000 ____D C:\Users\Ultra\Documents\ALI213
2012-03-25 09:46 - 2012-03-25 09:46 - 00000000 ____D C:\Users\Ultra\AppData\Local\28050
2012-03-25 08:18 - 2012-03-25 08:18 - 00129480 ____A C:\Users\Ultra\Downloads\Deus.Ex.Human.Revolution-bleepROW.torrent
2012-03-25 03:40 - 2012-03-25 03:40 - 00000000 ____D C:\Users\Ultra\AppData\Local\{A070EA48-EFEC-48D3-ACA3-01825D618241}
2012-03-25 03:40 - 2012-03-25 03:40 - 00000000 ____D C:\Users\Ultra\AppData\Local\{382B3747-CF6C-444F-A403-ECA66E954D07}
2012-03-25 02:48 - 2012-03-25 02:48 - 00055822 ____A C:\Users\Ultra\Downloads\Casotoys_Intl_Jose_Seruya.pdf
2012-03-24 17:23 - 2012-03-24 17:23 - 00041712 ____A C:\Users\Ultra\Downloads\519553.zip
2012-03-24 15:40 - 2012-03-24 15:40 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D309819C-2F84-4966-B423-C50B878133CE}
2012-03-24 15:40 - 2012-03-24 15:40 - 00000000 ____D C:\Users\Ultra\AppData\Local\{AC7813AD-81F7-4437-ADCF-D7935AC1DE9B}
2012-03-24 14:50 - 2012-01-28 15:16 - 00000000 ___RD C:\Program Files (x86)\Skype
2012-03-24 14:50 - 2012-01-28 15:16 - 00000000 ____D C:\Users\All Users\Skype
2012-03-24 14:21 - 2012-03-24 14:21 - 00046601 ____A C:\Users\Ultra\Downloads\Nikita.S02E17.720p.HDTV.X264-DIMENSION.srt
2012-03-24 12:26 - 2012-03-24 12:26 - 00037068 ____A C:\Users\Ultra\Downloads\AARAO_REIS4c8c7e0bad8d7842221e5cb48b152a7b.rar
2012-03-24 03:46 - 2012-03-24 03:46 - 00019327 ____A C:\Users\Ultra\Downloads\AARAO_REISb32223fe60646cf5d152acb23e697cd2.rar
2012-03-24 03:39 - 2012-03-24 03:39 - 00000000 ____D C:\Users\Ultra\AppData\Local\{E25FE121-E5A9-4DBB-B62E-F5871410DDAA}
2012-03-24 03:39 - 2012-03-24 03:39 - 00000000 ____D C:\Users\Ultra\AppData\Local\{305F9FB5-AB8F-4726-A174-F81E8CF37C13}
2012-03-23 17:07 - 2012-03-23 17:07 - 00036087 ____A C:\Users\Ultra\Downloads\AARAO_REIS99cd229d2e14462ef6e3490514cae01b.rar
2012-03-23 09:49 - 2012-03-23 09:49 - 00000000 ____D C:\Users\Ultra\AppData\Local\{59E7CF82-EA68-44B1-8C29-CD3FE1B04E0C}
2012-03-23 09:49 - 2012-03-23 09:48 - 00000000 ____D C:\Users\Ultra\AppData\Local\{FF8C4463-0E51-4397-BE65-7BD54E3F7FF2}
2012-03-22 17:08 - 2012-03-22 17:08 - 00019489 ____A C:\Users\Ultra\Downloads\AARAO_REIScc91c2c4d85f79921df7b0034f1c44b7.rar
2012-03-22 16:53 - 2012-03-22 16:53 - 00430121 ____A C:\Users\Ultra\Downloads\Fotos Casa Joana.zip
2012-03-22 16:53 - 2012-03-22 16:53 - 00158808 ____A C:\Users\Ultra\Downloads\3.jpg
2012-03-22 12:22 - 2012-03-22 12:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B40B58F2-F07B-4B04-A48E-D3C4D24E6A72}
2012-03-22 12:22 - 2012-03-22 12:22 - 00000000 ____D C:\Users\Ultra\AppData\Local\{ABD2C4E0-F197-482E-8F3C-161413A97067}
2012-03-21 16:19 - 2012-03-21 16:19 - 00016787 ____A C:\Users\Ultra\Downloads\215269.zip
2012-03-21 15:00 - 2012-03-21 15:00 - 00143124 ____A C:\Users\Ultra\Downloads\Europass-CV-120322-Sousa.pdf
2012-03-21 13:05 - 2012-03-21 13:05 - 00018290 ____A C:\Users\Ultra\Downloads\738a30da04c0439a5576ba8312a2d53db164c015.zip
2012-03-21 11:50 - 2012-03-21 11:50 - 10806030 ____A C:\Users\Ultra\Downloads\MOV_0005 (1).mp4
2012-03-21 10:26 - 2012-03-21 10:26 - 00000000 ____D C:\Users\Ultra\AppData\Local\{ECF3FE7F-9A10-400D-9B87-DBE7E54A67F2}
2012-03-21 10:26 - 2012-03-21 10:26 - 00000000 ____D C:\Users\Ultra\AppData\Local\{1844E0C9-6CA9-4814-B050-177844C21334}
2012-03-20 16:23 - 2012-03-20 16:23 - 00035662 ____A C:\Users\Ultra\Downloads\AARAO_REIS29e497d74c2ff0225a9db869731688c5.rar
2012-03-20 15:56 - 2012-03-20 15:55 - 00006063 ____A C:\Users\Ultra\Documents\That convo !.txt
2012-03-20 15:27 - 2012-03-20 15:27 - 00000000 ____D C:\Users\Ultra\AppData\Local\{B0A0A063-DF18-4C69-A07B-BBF8F54C9969}
2012-03-20 15:27 - 2012-03-20 15:27 - 00000000 ____D C:\Users\Ultra\AppData\Local\{027521D4-DB32-4D77-9D5B-A995563CBA5B}
2012-03-20 03:27 - 2012-03-20 03:26 - 00000000 ____D C:\Users\Ultra\AppData\Local\{20F536C6-853E-4477-AAE8-FCB97D6528B2}
2012-03-20 03:26 - 2012-03-20 03:26 - 00000000 ____D C:\Users\Ultra\AppData\Local\{BBB86160-FF59-4232-B39A-6E504074A1E4}
2012-03-19 15:26 - 2012-03-19 15:26 - 00000000 ____D C:\Users\Ultra\AppData\Local\{60210C15-D328-4EE6-968A-65A28F5B2A6D}
2012-03-19 15:26 - 2012-03-19 15:26 - 00000000 ____D C:\Users\Ultra\AppData\Local\{4A24D2FB-579B-4CAF-8A2B-B331CBF94CD9}
2012-03-18 16:48 - 2012-03-18 16:48 - 00013443 ____A C:\Users\Ultra\Downloads\4D5B78998E0E2E8C65BC32037BAFBB9470DA3E3D.torrent
2012-03-18 16:37 - 2012-03-18 16:37 - 00014883 ____A C:\Users\Ultra\Downloads\E9DF998B25FDFE281FA74DB97D8A4FA2F5CEF05D.torrent
2012-03-18 16:31 - 2012-03-18 16:31 - 00010111 ____A C:\Users\Ultra\Downloads\8E476E2715E4EDD1680F634F22EB1100E7CAF816.torrent
2012-03-18 16:28 - 2012-03-18 16:24 - 02322860 ____A C:\Users\Ultra\Downloads\ls9788_1500_NaBlog.org.mp4
2012-03-18 14:54 - 2012-03-18 14:54 - 00000000 ____D C:\Users\Ultra\AppData\Local\{009E4DD7-A3FB-4A1E-88DC-5295E7039FB5}
2012-03-18 14:54 - 2012-03-18 14:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{27C16116-C7C0-4502-AB24-4422BAE88B01}
2012-03-18 11:41 - 2012-03-18 11:41 - 00043632 ____A C:\Users\Ultra\Downloads\valfadinha9b44d40b35a3d22cc19ce5aced6c65e1.rar
2012-03-18 11:39 - 2012-03-18 11:38 - 00283226 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-03-18 02:53 - 2012-03-18 02:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{ACE20498-61E0-474E-8FCE-3ECC3323BBA1}
2012-03-18 02:53 - 2012-03-18 02:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{25FFE894-8649-451B-ABE3-DE0CAF2B19D5}
2012-03-17 14:53 - 2012-03-17 14:52 - 00000000 ____D C:\Users\Ultra\AppData\Local\{5659B6C3-2753-41C8-B59E-B9D4EA7D5171}
2012-03-17 14:52 - 2012-03-17 14:52 - 00000000 ____D C:\Users\Ultra\AppData\Local\{D26E2ADB-5D3A-4219-8D37-1F5668324F35}
2012-03-17 13:42 - 2012-03-17 13:42 - 00026346 ____A C:\Users\Ultra\Downloads\123e0817165521183343fd6c3b3e77d393a673a4.zip
2012-03-17 12:51 - 2012-03-17 12:51 - 00683222 ____A C:\Users\Ultra\Downloads\fractal_white_text.eps
2012-03-17 12:51 - 2012-03-17 12:51 - 00683222 ____A C:\Users\Ultra\Downloads\fractal_white_text (1).eps
2012-03-17 12:51 - 2012-03-17 12:51 - 00590334 ____A C:\Users\Ultra\Downloads\fractal_black_text.eps
2012-03-17 10:40 - 2012-03-17 10:40 - 00290116 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-03-17 10:40 - 2012-03-17 10:40 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2012-03-17 02:52 - 2012-03-17 02:52 - 00000000 ____D C:\Users\Ultra\AppData\Local\{F2FFB442-2E48-4CDA-A48B-2742A93EA5D2}
2012-03-17 02:52 - 2012-03-17 02:52 - 00000000 ____D C:\Users\Ultra\AppData\Local\{F1A1B053-6249-4996-8BA7-4B8E34A81BA2}
2012-03-16 23:58 - 2012-05-09 11:05 - 00075120 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2012-03-16 13:53 - 2012-03-16 13:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{94F230AC-62B9-4284-81FA-9A49759EED1E}
2012-03-16 13:53 - 2012-03-16 13:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{18F6B9D8-6FF5-4CA4-BA28-03E6B9D4B15A}
2012-03-16 10:41 - 2012-03-16 10:41 - 00021096 ____A C:\Users\Ultra\Downloads\552220.zip
2012-03-16 10:38 - 2012-03-16 10:38 - 00065024 ____A C:\Users\Ultra\Downloads\Oferta Estágio_Livraria UCP 2012.doc
2012-03-16 06:00 - 2012-02-07 17:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\ElevatedDiagnostics
2012-03-16 01:53 - 2012-03-16 01:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{85842710-DCEC-457F-A136-985A5B65C494}
2012-03-16 01:53 - 2012-03-16 01:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2B85EF1C-8936-4ED0-89E8-8ABAD4A38293}
2012-03-15 17:11 - 2012-03-15 17:11 - 00018789 ____A C:\Users\Ultra\Downloads\gitobetoeefae443414f97dc383f3e378115ade5.rar
2012-03-15 12:53 - 2012-03-15 12:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{7ED46CB4-36D2-45EE-925C-7C6B938A3298}
2012-03-15 12:53 - 2012-03-15 12:53 - 00000000 ____D C:\Users\Ultra\AppData\Local\{68682A13-6C1B-4C04-84D1-FE268FDD95AA}
2012-03-14 13:14 - 2012-03-14 13:14 - 00000000 ____D C:\Users\Ultra\AppData\Local\HP
2012-03-14 13:14 - 2012-03-14 13:13 - 00000000 ____D C:\Users\Ultra\AppData\Roaming\HP
2012-03-14 13:13 - 2012-03-14 13:13 - 00000000 ____D C:\Users\All Users\WEBREG
2012-03-14 13:13 - 2012-03-14 13:11 - 00171745 ____A C:\Windows\hpoins13.dat
2012-03-14 13:13 - 2012-03-14 13:11 - 00000000 ____D C:\Users\All Users\HP
2012-03-14 13:13 - 2009-07-13 18:34 - 00000438 ____A C:\Windows\win.ini
2012-03-14 13:12 - 2012-03-14 13:12 - 00000000 ____D C:\Users\All Users\HP Product Assistant
2012-03-14 13:09 - 2012-03-14 13:03 - 219873664 ____A C:\Users\Ultra\Downloads\PS_AIO_C4200_NonNet_Full_Win_WW_130_140.exe
2012-03-14 12:41 - 2012-03-14 12:41 - 00000000 ____D C:\Users\Ultra\AppData\Local\{52FF8B08-04C0-44AA-AB08-3CC9A5312867}
2012-03-14 12:41 - 2012-03-14 12:41 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3659C76B-65AD-475C-82AA-F395C77DE061}
2012-03-13 17:25 - 2012-03-13 17:24 - 07551191 ____A C:\Users\Ultra\Downloads\(C76) [Momoiro Rip] Gyakuten ranbu (Gyakuten Saiban).rar
2012-03-13 15:17 - 2012-03-13 15:17 - 05030185 ____A C:\Users\Ultra\Downloads\%5BDoujinshi%5D%5BCursor%5D%5BPhoenix+Wright+Ace+Attorney+-+Psychedelic%5D%5B18+files%5D%5BEng%5D.rar
2012-03-13 13:23 - 2012-03-13 13:23 - 04512306 ____A C:\Users\Ultra\Downloads\Ficha_MAT_2ºp (1).docx
2012-03-13 13:22 - 2012-03-13 13:22 - 04512306 ____A C:\Users\Ultra\Downloads\Ficha_MAT_2ºp.docx
2012-03-13 13:22 - 2012-03-13 13:22 - 00082865 ____A C:\Users\Ultra\Downloads\Ficha_LP_2ºp.docx
2012-03-13 13:21 - 2012-03-13 13:21 - 00143204 ____A C:\Users\Ultra\Downloads\Matriz_MAT_2ºperíodo.docx
2012-03-13 13:04 - 2012-03-13 13:04 - 00000000 ____D C:\Users\Ultra\AppData\Local\{7C59300E-ECD4-467B-BA55-A2F85C054110}
2012-03-13 13:04 - 2012-03-13 13:04 - 00000000 ____D C:\Users\Ultra\AppData\Local\{2DE9D652-FA55-4B3C-84E3-CB300138E911}
2012-03-13 02:29 - 2012-03-13 02:29 - 00043794 ____A C:\Users\Ultra\Downloads\Caso_Tvprime_Jose_Seruya.pdf
2012-03-12 17:00 - 2012-03-12 17:00 - 00016116 ____A C:\Users\Ultra\Downloads\550801.zip
2012-03-12 16:37 - 2012-03-12 16:37 - 00033328 ____A C:\Users\Ultra\Downloads\AARAO_REIS5e852cf75b32b458fbd6f4773ab3daa5.rar
2012-03-12 15:24 - 2012-03-12 15:24 - 00000000 ____D C:\Users\Ultra\AppData\Local\{64C92FB1-0F49-4465-9F41-BF355551DEBD}
2012-03-12 15:24 - 2012-03-12 15:24 - 00000000 ____D C:\Users\Ultra\AppData\Local\{24DF14FB-8EEE-40A4-8630-639A3F960A0C}
2012-03-12 13:39 - 2012-03-12 13:39 - 00016759 ____A C:\Users\Ultra\Downloads\550795.zip
2012-03-12 13:04 - 2012-03-12 13:04 - 00034500 ____A C:\Users\Ultra\Downloads\AARAO_REIS7ca7443929bed1566915c72fb0b8a402.rar
2012-03-12 05:56 - 2012-03-12 05:55 - 00787393 ____A C:\Users\Ultra\Downloads\4teorica_05_Mar_2012_Jose_Seruya.pdf
2012-03-12 05:55 - 2012-03-12 05:55 - 00524050 ____A C:\Users\Ultra\Downloads\3teorica_27_Fev_2012_Jose_Seruya.pdf
2012-03-12 05:55 - 2012-03-12 05:55 - 00056554 ____A C:\Users\Ultra\Downloads\3aula_Pratica_28_Fev_2012_Jose_Seruya.pdf
2012-03-12 05:51 - 2012-03-12 05:51 - 00817615 ____A C:\Users\Ultra\Downloads\2teorica_13_Fev_2012_Incl_TMN_Jose_Seruya.pdf
2012-03-12 05:50 - 2012-03-12 05:50 - 00027205 ____A C:\Users\Ultra\Downloads\1aula_Pratica_7_Fev_2012_Jose_Seruya (1).pdf
2012-03-12 05:49 - 2012-03-12 05:49 - 00743390 ____A C:\Users\Ultra\Downloads\1teorica_06_Fev_2012_Jose_Seruya (1).pdf
2012-03-12 05:48 - 2012-03-12 05:48 - 00024351 ____A C:\Users\Ultra\Downloads\Caso_Foodautocare_Orientacoes_Jose_Seruya_4.pdf
2012-03-12 03:24 - 2012-03-12 03:24 - 00000000 ____D C:\Users\Ultra\AppData\Local\{3A19BDF5-3273-41AE-93A5-D8208DCD729C}
2012-03-12 03:24 - 2012-03-12 03:23 - 00000000 ____D C:\Users\Ultra\AppData\Local\{0E4333FB-9F9C-432A-AB60-CE44E56E7636}
2012-03-12 03:23 - 2012-03-12 03:23 - 00000000 ____D C:\Users\All Users\Overwolf


ZeroAccess:
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\@
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\L
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\U
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\L\00000004.@
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\L\00000008.@
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\U\00000004.@
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\U\00000008.@
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\U\000000cb.@
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\U\80000000.@
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\U\80000032.@
C:\Windows\Installer\{7b02821e-4874-9814-0827-df42bba46481}\U\80000064.@

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0329216 ____A (Microsoft Corporation) 50BEA589F7D7958BDD2528A8F69D05CC

C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2012-01-28 07:40] - [2011-02-24 22:25] - 0296320 ____A (Microsoft Corporation) DF8126BD41180351A093A3AD2FC8903B


==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

========================= Memory info ======================

Percentage of memory in use: 9%
Total physical RAM: 8167.13 MB
Available physical RAM: 7375.22 MB
Total Pagefile: 8165.27 MB
Available Pagefile: 7369.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

======================= Partitions =========================

1 Drive c: () (Fixed) (Total:48.73 GB) (Free:2.18 GB) NTFS
2 Drive e: () (Fixed) (Total:249.26 GB) (Free:10.88 GB) NTFS
4 Drive g: (KINGSTON) (Removable) (Total:7.45 GB) (Free:7.45 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (Sistema Reservado) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 7640 MB 0 B

Partitions of Disk 0:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 48 GB 101 MB
Partition 3 Primary 249 GB 48 GB

======================================================================================================

Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y Sistema Res NTFS Partition 100 MB Healthy

======================================================================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 48 GB Healthy

======================================================================================================

Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E NTFS Partition 249 GB Healthy

======================================================================================================

Partitions of Disk 1:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7636 MB 4032 KB

======================================================================================================

Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G KINGSTON FAT32 Removable 7636 MB Healthy

======================================================================================================

==========================================================

Last Boot: 2012-06-08 12:05

======================= End Of Log ==========================

#14 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:07:33 PM

Posted 09 June 2012 - 07:46 AM

ultrafire,

Boot to System Recovery Options as we did previously, and run FRST.
Type the following in the edit box after "Search:"

services.exe;volsnap.sys

Note: The file names should be separated by semicolon (;)

It then should look like:

Search: services.exe;volsnap.sys

Click Search button and post the log (Search.txt) it makes to your reply.
Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#15 ultrafire

ultrafire
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 09 June 2012 - 09:18 AM

Jason,

As you requested the Search log from Farbar follows


--

Farbar Recovery Scan Tool Version: 09-06-2012
Ran by SYSTEM at 2012-06-09 15:15:48
Running from G:\

================== Search: "services.exe;volsnap.sys" ===================

C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7601.21668_none_74344b472bf715e9\volsnap.sys
[2012-01-28 07:40] - [2011-02-24 22:28] - 0296320 ____A (Microsoft Corporation) 879CE6AEA3FE874AD4C500B6B6198EB0

C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7601.17567_none_73a9ae3212da5cc8\volsnap.sys
[2012-01-28 07:40] - [2011-02-24 22:25] - 0296320 ____A (Microsoft Corporation) DF8126BD41180351A093A3AD2FC8903B

C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7601.17514_none_73dcbcf012b4850e\volsnap.sys
[2012-01-29 04:38] - [2010-11-20 05:34] - 0295808 ____A (Microsoft Corporation) 0D08D2F3B3FF84E433346669B5E0F639

C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7600.20909_none_728fcff92e9f18d5\volsnap.sys
[2012-01-28 07:40] - [2011-02-24 22:33] - 0295808 ____A (Microsoft Corporation) 2BAFD52623B3DF4133051F6FB7D3D844

C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7600.16767_none_71c3512c15b3f0dc\volsnap.sys
[2012-01-28 07:40] - [2011-02-24 22:36] - 0295296 ____A (Microsoft Corporation) C9D0EAF58D6BA71E128E715EA43AD87D

C:\Windows\winsxs\amd64_volume.inf_31bf3856ad364e35_6.1.7600.16385_none_71aba92815c60174\volsnap.sys
[2009-07-13 15:20] - [2009-07-13 17:45] - 0294992 ____A (Microsoft Corporation) 58F82EED8CA24B461441F9C3E4F0BF5C

C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0329216 ____A (Microsoft Corporation) 50BEA589F7D7958BDD2528A8F69D05CC

C:\Windows\System32\DriverStore\FileRepository\volume.inf_amd64_neutral_e7c4cd5b40e03494\volsnap.sys
[2012-01-28 07:40] - [2011-02-24 22:25] - 0296320 ____A (Microsoft Corporation) DF8126BD41180351A093A3AD2FC8903B

C:\Windows\System32\DriverStore\FileRepository\volume.inf_amd64_neutral_df8bea40ac96ca21\volsnap.sys
[2012-01-29 04:38] - [2010-11-20 05:34] - 0295808 ____A (Microsoft Corporation) 0D08D2F3B3FF84E433346669B5E0F639

C:\Windows\System32\drivers\volsnap.sys
[2012-01-28 07:40] - [2011-02-24 22:25] - 0296320 ____A (Microsoft Corporation) DF8126BD41180351A093A3AD2FC8903B

====== End Of Search ======




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users