Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis log, infected with adware.


  • This topic is locked This topic is locked
8 replies to this topic

#1 askorin

askorin

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:35 PM

Posted 10 January 2016 - 05:35 PM

Hello

 

I have been infected with an adware that does not appear in my google chrome extensions, I cannot uninstall it as it does not appear in my control panel... After trying various malware removal tools (Malwarebytes, Adwcleaner, Spybot S&D, etc) I decided to use Hijackthis, I will post the logs:

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 19:32:39, on 10-01-2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16384)
 
FIREFOX: 43.0.4 (x86 es-CL)
Boot mode: Normal
 
Running processes:
C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\José Arcos\Downloads\HijackThis.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts file is located at: C:\Windows\System32\drivers\etc\hosts
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\José Arcos\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\José Arcos\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
O8 - Extra context menu item: &Enviar a OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\AJRouter.dll,-2 (AJRouter) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ACP User Service (amdacpusrsvc) - Advanced Micro Devices - C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @appmgmts.dll,-3250 (AppMgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\AppReadiness.dll,-1000 (AppReadiness) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\appxdeploymentserver.dll,-1 (AppXSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%windir%\system32\bisrv.dll,-100 (BrokerInfrastructure) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\BthHFSrv.dll,-103 (BthHFSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cdpsvc.dll,-100 (CDPSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ClipSVC.dll,-103 (ClipSVC) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\coremessaging.dll,-1 (CoreMessagingRegistrar) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\cscsvc.dll,-200 (CscService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @combase.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dcpsvc.dll,-3001 (DcpSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\das.dll,-100 (DeviceAssociationService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (DeviceInstall) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\DevQueryBroker.dll,-100 (DevQueryBroker) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\diagtrack.dll,-3001 (DiagTrack) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%systemroot%\system32\Windows.Internal.Management.dll,-100 (DmEnrollmentSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dmwappushsvc.dll,-200 (dmwappushservice) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dosvc.dll,-100 (DoSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\DeviceSetupManager.dll,-1000 (DsmSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dssvc.dll,-10003 (DsSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (Eaphost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%SystemRoot%\system32\embeddedmodesvc.dll,-200 (embeddedmode) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @EnterpriseAppMgmtSvc.dll,-1 (EntAppSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (EventLog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fhsvc.dll,-101 (fhsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Google Update Servicio (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Servicio (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\tetheringservice.dll,-4097 (icssvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\lfsvc.dll,-1 (lfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\licensemanagersvc.dll,-200 (LicenseManager) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%windir%\system32\lsm.dll,-1001 (LSM) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\moshost.dll,-100 (MapsBroker) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%SystemRoot%\system32\ncasvc.dll,-3009 (NcaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ncbservice.dll,-500 (NcbService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\NcdAutoSetup.dll,-100 (NcdAutoSetup) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprofmsvc.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\NetSetupSvc.dll,-3 (NetSetupSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\NgcCtnrSvc.dll,-1 (NgcCtnrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\APHostRes.dll,-10002 (OneSyncSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Sincronizar host_Session1 (OneSyncSvc_Session1) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\peerdistsvc.dll,-9000 (PeerDistSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe
O23 - Service: @%SystemRoot%\system32\UserDataAccessRes.dll,-15001 (PimIndexMaintenanceSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Datos de contactos_Session1 (PimIndexMaintenanceSvc_Session1) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-200 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll,-1 (PrintNotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\RDXService.dll,-256 (RetailDemo) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @combase.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ScDeviceEnum.dll,-100 (ScDeviceEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\sensorservice.dll,-1000 (SensorService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ipnathlp.dll,-106 (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\System32\smphost.dll,-102 (smphost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SmsRouterSvc.dll,-10001 (SmsRouter) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\windows.staterepository.dll,-1 (StateRepository) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\StorSvc.dll,-100 (StorSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\svsvc.dll,-101 (svsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\system32\SystemEventsBrokerServer.dll,-1001 (SystemEventsBroker) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tileobjserver.dll,-1 (tiledatamodelsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\system32\TimeBrokerServer.dll,-1001 (TimeBroker) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\umrdp.dll,-1000 (UmRdpService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\UserDataAccessRes.dll,-10003 (UnistoreSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Almacenamiento de datos de usuarios_Session1 (UnistoreSvc_Session1) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\UserDataAccessRes.dll,-14001 (UserDataSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Acceso a datos de usuarios_Session1 (UserDataSvc_Session1) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\usermgr.dll,-100 (UserManager) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\usocore.dll,-102 (UsoSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\icsvc.dll,-801 (vmicguestinterface) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-101 (vmicheartbeat) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-201 (vmickvpexchange) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-601 (vmicrdv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-301 (vmicshutdown) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-401 (vmictimesync) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-901 (vmicvmsession) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\icsvc.dll,-501 (vmicvss) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\WalletService.dll,-1000 (WalletService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wcmsvc.dll,-4097 (Wcmsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wephostsvc.dll,-100 (WEPHOSTSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wiarpc.dll,-2 (WiaRpc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (WlanSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wlidsvc.dll,-100 (wlidsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\workfolderssvc.dll,-102 (workfolderssvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpnservice.dll,-1 (WpnService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
O23 - Service: @%SystemRoot%\system32\WSService.dll,-103 (WSService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\XblAuthManager.dll,-100 (XblAuthManager) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\XblGameSave.dll,-100 (XblGameSave) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\XboxNetApiSvc.dll,-100 (XboxNetApiSvc) - Unknown owner - C:\Windows\system32\svchost.exe
 
--
End of file - 29751 bytes


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 39,541 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:12:35 PM

Posted 12 January 2016 - 11:45 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
attachlogs.png

Attach the file.
Select the "Choose a File" navigate to the location of the File.
Click the file you wish to Attach.

Click the Add reply button.
===

Wait for further instructions.

#3 askorin

askorin
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:35 PM

Posted 12 January 2016 - 04:43 PM

Hello, nasdaq.

Thank you for answering, I will post the results.

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-01-2015 01
Ran by José Arcos (administrator) on AMD (12-01-2016 18:37:20)
Running from C:\Users\José Arcos\Desktop\Farbar
Loaded Profiles: José Arcos (Available Profiles: José Arcos)
Platform: Windows 10 Pro (X64) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices) C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
(Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe
() C:\Windows\System32\PnkBstrA.exe
(AMD) C:\Windows\System32\atieclxx.exe
(MSI) C:\Windows\SysWOW64\muachost.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(VIA Technologies, Inc.) C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cnext.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-07-07] (Realtek Semiconductor)
HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\cnext.exe [4867784 2015-12-04] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-2794140196-700506298-3970498116-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
HKU\S-1-5-21-2794140196-700506298-3970498116-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50378880 2015-12-17] (Skype Technologies S.A.)
HKU\S-1-5-21-2794140196-700506298-3970498116-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4179288 2015-11-30] (Disc Soft Ltd)
HKU\S-1-5-21-2794140196-700506298-3970498116-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-2794140196-700506298-3970498116-1001\...\RunOnce: [Uninstall C:\Users\Jos� Arcos\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\José Arcos\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
HKU\S-1-5-21-2794140196-700506298-3970498116-1001\...\MountPoints2: {3fae79c1-ab56-11e5-9bcc-fcaa14943432} - "E:\setup.exe" 
HKU\S-1-5-21-2794140196-700506298-3970498116-1001\...\MountPoints2: {3fae7f66-ab56-11e5-9bcc-fcaa14943432} - "F:\setup.exe" 
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  No File
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 200.75.0.4 200.75.25.224 192.168.1.1
Tcpip\..\Interfaces\{a4acb44c-3b59-41ee-b99a-2682ce7d0679}: [DhcpNameServer] 200.75.0.4 200.75.25.224 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-2794140196-700506298-3970498116-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-21] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-01-23] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\José Arcos\AppData\Roaming\Mozilla\Firefox\Profiles\4qcoqoqv.default
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-19] (Google Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\José Arcos\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\José Arcos\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Drive) - C:\Users\José Arcos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-09]
CHR Extension: (YouTube) - C:\Users\José Arcos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-09]
CHR Extension: (Búsqueda de Google) - C:\Users\José Arcos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-09]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\José Arcos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-09]
CHR Extension: (Gmail) - C:\Users\José Arcos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-09]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2015-12-04] (Advanced Micro Devices) [File not signed]
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1368408 2015-11-30] (Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2505472 2015-10-09] (ESET)
R2 GamingApp_Service; C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe [36008 2015-11-04] (Micro-Star Int'l Co., Ltd.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2015-12-23] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2015-12-24] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-12-24] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [305392 2015-12-16] (Advanced Micro Devices)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [40720 2015-07-28] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-09-17] (Advanced Micro Devices)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-12-25] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [46392 2015-12-25] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [264040 2015-09-23] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [14976 2015-09-23] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [186784 2015-09-23] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [142976 2015-10-07] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [206312 2015-09-23] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [52872 2015-09-23] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [69840 2015-09-23] (ESET)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-01-06] ()
S3 ExterminateIt; C:\Windows\SysWOW64\drivers\extit.sys [39936 2016-01-08] (CurioLab S.M.B.A.) [File not signed]
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-06-22] (Realtek                                            )
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [30848 2016-01-09] ()
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R3 VUSB3HUB; C:\Windows\System32\drivers\ViaHub3.sys [227840 2014-10-31] (VIA Technologies, Inc.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
R3 xhcdrv; C:\Windows\System32\drivers\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.)
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-01-12 18:36 - 2016-01-12 18:37 - 00000000 ____D C:\FRST
2016-01-12 18:35 - 2016-01-12 18:37 - 00000000 ____D C:\Users\José Arcos\Desktop\Farbar
2016-01-12 18:34 - 2016-01-12 18:34 - 00016148 _____ C:\Windows\system32\AMD_José Arcos_HistoryPrediction.bin
2016-01-10 19:14 - 2016-01-10 19:14 - 00067950 _____ C:\Users\José Arcos\Downloads\startuplist.txt
2016-01-10 19:13 - 2016-01-10 19:13 - 00000000 ____D C:\Users\José Arcos\AppData\LocalLow\Temp
2016-01-10 19:06 - 2016-01-10 19:06 - 00000000 ____D C:\Users\José Arcos\Downloads\backups
2016-01-10 18:58 - 2016-01-10 18:58 - 00388608 _____ (Trend Micro Inc.) C:\Users\José Arcos\Downloads\HijackThis.exe
2016-01-10 18:48 - 2016-01-10 18:48 - 00000085 _____ C:\Windows\wininit.ini
2016-01-10 18:04 - 2016-01-11 18:59 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-01-10 18:02 - 2016-01-10 18:29 - 00000000 ____D C:\Users\José Arcos\Desktop\mbar
2016-01-10 18:01 - 2016-01-10 18:02 - 16563352 _____ (Malwarebytes Corp.) C:\Users\José Arcos\Downloads\mbar-1.09.3.1001.exe
2016-01-10 15:46 - 2016-01-10 15:46 - 00002100 _____ C:\Users\Public\Desktop\ESET Protección de banca y pagos en linea.lnk
2016-01-10 15:46 - 2016-01-10 15:46 - 00000000 ____D C:\Users\José Arcos\AppData\Local\ESET
2016-01-10 15:46 - 2016-01-10 15:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2016-01-10 15:46 - 2016-01-10 15:46 - 00000000 ____D C:\ProgramData\ESET
2016-01-10 15:45 - 2016-01-10 15:45 - 00000000 ____D C:\Program Files\ESET
2016-01-10 15:40 - 2016-01-10 15:42 - 96897224 _____ (ESET) C:\Users\José Arcos\Downloads\ess_nt64_esl.exe
2016-01-09 23:38 - 2016-01-09 23:38 - 00000000 ___RD C:\Users\José Arcos\3D Objects
2016-01-09 23:32 - 2016-01-09 23:32 - 00000000 ____D C:\Program Files (x86)\ESET
2016-01-09 23:31 - 2016-01-09 23:32 - 02870984 _____ (ESET) C:\Users\José Arcos\Downloads\esetsmartinstaller_esn.exe
2016-01-09 23:28 - 2016-01-09 23:29 - 01600184 _____ (Malwarebytes) C:\Users\José Arcos\Downloads\JRT.exe
2016-01-09 02:57 - 2016-01-09 02:57 - 00030848 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-01-09 02:56 - 2016-01-09 03:40 - 00000000 ____D C:\ProgramData\RogueKiller
2016-01-09 02:53 - 2016-01-09 02:56 - 20835400 _____ C:\Users\José Arcos\Downloads\RogueKiller.exe
2016-01-09 02:49 - 2016-01-09 02:49 - 00034328 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\Drivers\PROCEXP152.SYS
2016-01-09 02:18 - 2016-01-09 02:18 - 00000000 ____D C:\Users\José Arcos\Desktop\PE
2016-01-09 02:10 - 2016-01-09 02:10 - 00002290 _____ C:\Users\José Arcos\Desktop\Google Chrome.lnk
2016-01-09 00:15 - 2016-01-09 00:15 - 00164618 _____ C:\Windows\ntbtlog.txt
2016-01-09 00:15 - 2016-01-09 00:15 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2016-01-08 23:35 - 2016-01-08 23:35 - 01749504 _____ C:\Users\José Arcos\Downloads\adwcleaner_5.028 (1).exe
2016-01-08 23:23 - 2016-01-08 23:24 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Mozilla
2016-01-08 23:23 - 2016-01-08 23:23 - 00001188 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-01-08 23:23 - 2016-01-08 23:23 - 00001176 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-01-08 23:23 - 2016-01-08 23:23 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Mozilla
2016-01-08 23:23 - 2016-01-08 23:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-01-08 23:23 - 2016-01-08 23:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-01-08 23:22 - 2016-01-08 23:22 - 00248720 _____ C:\Users\José Arcos\Downloads\Firefox Setup Stub 43.0.4.exe
2016-01-08 23:14 - 2016-01-08 23:14 - 02953520 _____ (AVAST Software) C:\Users\José Arcos\Downloads\avast-browser-cleanup.exe
2016-01-08 23:06 - 2016-01-08 23:13 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\FreeFixer
2016-01-08 23:06 - 2016-01-08 23:11 - 00000000 ____D C:\Users\José Arcos\AppData\Local\FreeFixer
2016-01-08 23:05 - 2016-01-08 23:05 - 02687418 _____ (Kephyr) C:\Users\José Arcos\Downloads\freefixersetup.exe
2016-01-08 21:33 - 2016-01-08 21:39 - 00000000 ____D C:\Users\Public\Documents\Stronghold AntiMalware
2016-01-08 21:32 - 2016-01-08 21:32 - 07566832 _____ (Security Stronghold ) C:\Users\José Arcos\Downloads\StrongholdAntiMalware.exe
2016-01-08 20:45 - 2016-01-08 20:46 - 02012464 _____ C:\Users\José Arcos\Downloads\Adaware_Installer.exe
2016-01-08 19:32 - 2016-01-08 19:47 - 00039936 _____ (CurioLab S.M.B.A.) C:\Windows\SysWOW64\Drivers\extit.sys
2016-01-07 21:35 - 2016-01-07 21:35 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Curiolab
2016-01-07 21:28 - 2016-01-07 21:34 - 157313688 _____ (CURIOLAB S.M.B.A.) C:\Users\José Arcos\Downloads\ExterminateItSetup.exe
2016-01-07 20:10 - 2016-01-07 20:11 - 48831832 _____ C:\Users\José Arcos\Downloads\BDPUARLauncher.exe
2016-01-07 20:04 - 2016-01-07 20:07 - 01749504 _____ C:\Users\José Arcos\Desktop\adwcleaner_5.028.exe
2016-01-07 19:49 - 2016-01-07 19:51 - 00002002 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2016-01-07 19:49 - 2016-01-07 19:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2016-01-07 19:49 - 2016-01-07 19:49 - 00000000 ____D C:\Program Files\HitmanPro
2016-01-07 19:48 - 2016-01-07 19:49 - 11337112 _____ (SurfRight B.V.) C:\Users\José Arcos\Downloads\HitmanPro_x64 (1).exe
2016-01-06 23:23 - 2016-01-06 23:23 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2016-01-06 23:13 - 2016-01-06 23:24 - 00000000 ____D C:\ProgramData\HitmanPro
2016-01-06 23:12 - 2016-01-06 23:13 - 11323704 _____ (SurfRight B.V.) C:\Users\José Arcos\Downloads\HitmanPro_x64.exe
2016-01-06 22:06 - 2016-01-06 22:06 - 00000000 _____ C:\autoexec.bat
2016-01-06 22:05 - 2016-01-06 22:05 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys
2016-01-06 21:59 - 2016-01-06 22:01 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\José Arcos\Downloads\SpyHunter-Installer.exe
2016-01-05 13:19 - 2016-01-05 13:19 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Blizzard
2016-01-05 13:17 - 2016-01-05 13:17 - 00001210 _____ C:\Users\Public\Desktop\Hearthstone.lnk
2016-01-05 13:17 - 2016-01-05 13:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2016-01-05 13:11 - 2016-01-09 01:58 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2016-01-05 13:11 - 2016-01-05 13:11 - 00000000 ____D C:\Data
2016-01-05 13:06 - 2016-01-11 13:49 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Battle.net
2016-01-05 13:06 - 2016-01-05 13:06 - 00001173 _____ C:\Users\Public\Desktop\Battle.net.lnk
2016-01-05 13:06 - 2016-01-05 13:06 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Battle.net
2016-01-05 13:06 - 2016-01-05 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2016-01-05 13:05 - 2016-01-11 13:09 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-01-05 13:04 - 2016-01-05 13:05 - 00000000 ____D C:\ProgramData\Battle.net
2016-01-05 13:04 - 2016-01-05 13:04 - 03142712 _____ (Blizzard Entertainment) C:\Users\José Arcos\Downloads\Hearthstone-Setup.exe
2015-12-29 17:16 - 2015-12-29 17:16 - 00000000 ____D C:\Program Files\Common Files\AV
2015-12-29 17:16 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2015-12-29 17:08 - 2015-12-29 17:08 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2015-12-29 17:07 - 2016-01-11 18:59 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-12-29 17:07 - 2016-01-10 18:48 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-12-29 17:05 - 2015-12-29 17:05 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\José Arcos\Downloads\spybot-2.4.exe
2015-12-28 22:47 - 2015-12-28 22:47 - 11230592 _____ (Enigma Software Group USA, LLC.) C:\Users\José Arcos\Downloads\RegHunter-Installer.exe
2015-12-28 21:43 - 2015-12-28 21:43 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Tera_Awesomium
2015-12-28 21:42 - 2016-01-11 19:00 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-28 21:41 - 2016-01-10 18:02 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-12-28 21:41 - 2015-12-28 21:41 - 00001131 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-28 21:41 - 2015-12-28 21:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-28 21:41 - 2015-12-28 21:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-28 21:41 - 2015-12-28 21:41 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-28 21:41 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-12-28 21:41 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-12-28 21:34 - 2015-12-28 21:37 - 22908888 _____ (Malwarebytes ) C:\Users\José Arcos\Downloads\mbam-setup-org-2.2.0.1024.exe
2015-12-28 20:53 - 2015-12-28 21:24 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-12-28 20:53 - 2015-12-28 20:53 - 00000000 ____D C:\Users\José Arcos\AppData\Local\TERA
2015-12-27 13:06 - 2015-12-27 13:38 - 00000000 ____D C:\Users\José Arcos\Documents\Flight Simulator X Files
2015-12-27 13:03 - 2015-12-27 13:03 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2015-12-27 12:42 - 2015-12-27 12:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2015-12-27 12:30 - 2015-12-27 12:32 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\TS3Client
2015-12-27 12:30 - 2015-12-27 12:30 - 00001191 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2015-12-27 12:30 - 2015-12-27 12:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2015-12-27 12:30 - 2015-12-27 12:30 - 00000000 ____D C:\Program Files (x86)\TeamSpeak 3 Client
2015-12-27 12:29 - 2015-12-27 12:30 - 29057448 _____ (TeamSpeak Systems GmbH) C:\Users\José Arcos\Downloads\TeamSpeak3-Client-win32-3.0.18.2.exe
2015-12-27 12:02 - 2015-12-27 12:13 - 00000000 ____D C:\Users\José Arcos\Desktop\Microsoft Flight Simulator X deluxe
2015-12-27 11:54 - 2015-12-27 11:54 - 00022551 _____ C:\Users\José Arcos\Downloads\Microsoft.Flight.Simulator.X.deluxe.torrent
2015-12-27 11:52 - 2015-12-27 11:52 - 00000000 ____D C:\Users\José Arcos\AppData\LocalLow\uTorrent
2015-12-26 21:30 - 2016-01-07 20:23 - 00000000 ____D C:\Program Files (x86)\Fallout 4
2015-12-26 21:10 - 2015-12-26 21:10 - 00000000 ____D C:\Program Files (x86)\FSX
2015-12-25 20:27 - 2016-01-11 21:30 - 00000000 ____D C:\Users\José Arcos\Documents\The Witcher 3
2015-12-25 20:20 - 2015-12-25 20:20 - 00001795 _____ C:\Users\Public\Desktop\The Witcher 3 - Wild Hunt.lnk
2015-12-25 20:20 - 2015-12-25 20:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 3 Wild Hunt
2015-12-25 18:47 - 2015-12-25 19:42 - 00000000 ____D C:\Users\José Arcos\Documents\MEGAsync Downloads
2015-12-25 18:46 - 2016-01-09 02:06 - 00000000 ___RD C:\Users\José Arcos\Documents\MEGA
2015-12-25 18:45 - 2015-12-25 18:45 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Mega Limited
2015-12-25 18:41 - 2015-12-25 18:45 - 10152576 _____ (MEGA Limited) C:\Users\José Arcos\Downloads\MEGAsyncSetup.exe
2015-12-25 17:26 - 2016-01-10 17:55 - 00000000 ____D C:\AdwCleaner
2015-12-25 17:25 - 2015-12-25 17:26 - 01743360 _____ C:\Users\José Arcos\Downloads\AdwCleaner.exe
2015-12-25 02:32 - 2015-12-25 02:32 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\TuneUp Software
2015-12-25 02:32 - 2015-12-25 02:32 - 00000000 ____D C:\Users\José Arcos\AppData\Local\TuneUp Software
2015-12-25 02:31 - 2015-12-25 02:31 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2015-12-25 02:31 - 2015-12-25 02:31 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Disc_Soft_Ltd
2015-12-25 02:30 - 2015-12-25 19:53 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\DAEMON Tools Lite
2015-12-25 02:30 - 2015-12-25 02:32 - 00000000 ____D C:\ProgramData\TuneUp Software
2015-12-25 02:30 - 2015-12-25 02:30 - 00046392 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtliteusbbus.sys
2015-12-25 02:30 - 2015-12-25 02:30 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2015-12-25 02:30 - 2015-12-25 02:30 - 00001814 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2015-12-25 02:30 - 2015-12-25 02:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2015-12-25 02:29 - 2015-12-25 02:30 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2015-12-25 02:24 - 2015-12-25 19:50 - 00000000 ____D C:\Program Files (x86)\The Witcher 3
2015-12-25 02:04 - 2015-12-25 02:04 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-25 01:57 - 2015-12-25 01:57 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2015-12-25 01:53 - 2015-12-25 01:54 - 01709792 _____ (Disc Soft Ltd.) C:\Users\José Arcos\Downloads\DTLiteInstaller.exe
2015-12-25 01:53 - 2015-12-25 01:53 - 01005568 _____ (Microsoft Corporation) C:\Users\José Arcos\Downloads\dotNetFx45_Full_setup.exe
2015-12-25 01:49 - 2015-12-25 01:52 - 14572000 _____ (Microsoft Corporation) C:\Users\José Arcos\Downloads\vc_redist.x64.exe
2015-12-24 20:58 - 2015-12-24 20:58 - 05111240 _____ (Piriform Ltd) C:\Users\José Arcos\Downloads\spsetup129.exe
2015-12-24 20:58 - 2015-12-24 20:58 - 00000837 _____ C:\Users\Public\Desktop\Speccy.lnk
2015-12-24 20:58 - 2015-12-24 20:58 - 00000000 ____D C:\Program Files\Speccy
2015-12-24 20:48 - 2015-12-24 20:49 - 04947168 _____ (Advanced Micro Devices, Inc.) C:\Users\José Arcos\Downloads\autodetectutility.exe
2015-12-24 20:47 - 2015-12-24 20:47 - 02165485 _____ C:\Users\José Arcos\Desktop\double_driver_4.1.0_portable.zip
2015-12-24 19:47 - 2015-12-24 19:47 - 00000000 ____D C:\Users\José Arcos\Documents\Amnesia
2015-12-24 19:47 - 2015-12-24 19:47 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\fltk.org
2015-12-24 19:47 - 2015-12-24 19:47 - 00000000 ____D C:\ProgramData\fltk.org
2015-12-24 19:41 - 2015-12-24 19:41 - 00000221 _____ C:\Users\José Arcos\Desktop\Amnesia The Dark Descent.url
2015-12-24 19:31 - 2015-12-24 19:31 - 00000000 ____D C:\Users\José Arcos\AppData\Local\PAYDAY
2015-12-24 19:01 - 2015-12-24 19:01 - 00076152 _____ C:\Windows\system32\PnkBstrA.exe
2015-12-24 18:51 - 2015-12-24 18:51 - 00000000 ____D C:\Users\José Arcos\AppData\Local\PunkBuster
2015-12-24 16:50 - 2015-12-24 16:50 - 00000219 _____ C:\Users\José Arcos\Desktop\Counter-Strike Global Offensive.url
2015-12-24 16:17 - 2016-01-10 17:57 - 00000000 ____D C:\ProgramData\AVAST Software
2015-12-24 16:17 - 2015-12-24 16:17 - 05037264 _____ (AVAST Software) C:\Users\José Arcos\Downloads\avast_premier_antivirus_setup_online.exe
2015-12-24 13:53 - 2015-12-24 13:54 - 00000000 ____D C:\Users\José Arcos\Documents\Battlefield 4
2015-12-24 13:49 - 2015-12-24 13:49 - 00001269 _____ C:\Users\Public\Desktop\Battlefield 4.lnk
2015-12-24 13:49 - 2015-12-24 13:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 4
2015-12-24 13:49 - 2015-12-24 13:49 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2015-12-24 13:48 - 2015-12-25 11:40 - 00226168 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2015-12-24 13:48 - 2015-12-25 11:40 - 00226168 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2015-12-24 13:48 - 2015-12-24 13:48 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2015-12-24 12:46 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2015-12-24 12:46 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2015-12-24 12:46 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2015-12-24 12:46 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2015-12-24 12:46 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2015-12-24 12:46 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2015-12-23 23:30 - 2015-12-23 23:30 - 01199856 _____ ( ) C:\Users\José Arcos\Downloads\hwmonitor_1.28.exe
2015-12-23 23:30 - 2015-12-23 23:30 - 00000975 _____ C:\Users\Public\Desktop\CPUID HWMonitor.lnk
2015-12-23 23:23 - 2015-12-23 23:24 - 00000000 ____D C:\Program Files\RealTemp
2015-12-23 23:13 - 2015-12-23 23:13 - 00000219 _____ C:\Users\José Arcos\Desktop\Counter-Strike Source.url
2015-12-23 22:22 - 2015-12-28 22:18 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-12-23 22:22 - 2015-12-23 22:22 - 00000220 _____ C:\Users\José Arcos\Desktop\Garry's Mod.url
2015-12-23 22:18 - 2015-12-23 22:18 - 00000000 ____D C:\Users\José Arcos\Tracing
2015-12-23 22:17 - 2016-01-12 18:36 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Skype
2015-12-23 22:17 - 2015-12-23 22:17 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
2015-12-23 22:17 - 2015-12-23 22:17 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-12-23 22:17 - 2015-12-23 22:17 - 00000000 ____D C:\ProgramData\Skype
2015-12-23 22:17 - 2015-12-23 22:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-12-23 22:16 - 2015-12-23 22:16 - 01503872 _____ (Skype Technologies S.A.) C:\Users\José Arcos\Downloads\SkypeSetup.exe
2015-12-23 22:16 - 2015-12-23 22:16 - 01503872 _____ (Skype Technologies S.A.) C:\Users\José Arcos\Downloads\SkypeSetup (1).exe
2015-12-23 22:11 - 2015-12-23 22:11 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\LolClient
2015-12-23 21:24 - 2015-12-23 21:24 - 05271256 _____ (Husdawg, LLC) C:\Users\José Arcos\Downloads\Detection.exe
2015-12-23 21:01 - 2015-12-23 21:01 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2015-12-23 21:01 - 2015-12-23 21:01 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-12-23 21:01 - 2015-12-23 21:01 - 00000000 ____D C:\Program Files\MSBuild
2015-12-23 21:01 - 2015-12-23 21:01 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-12-23 21:01 - 2015-12-23 21:01 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-12-23 21:00 - 2015-12-23 21:00 - 00000000 ____D C:\ProgramData\Riot Games
2015-12-23 20:59 - 2015-06-17 18:10 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2015-12-23 20:59 - 2015-06-17 18:10 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-12-23 20:59 - 2015-06-17 18:10 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2015-12-23 20:59 - 2015-05-29 21:07 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2015-12-23 20:59 - 2015-05-29 21:07 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-12-23 20:59 - 2015-05-29 21:07 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2015-12-23 20:58 - 2016-01-05 13:02 - 00000000 ____D C:\Users\José Arcos\Desktop\Importante
2015-12-23 20:58 - 2015-12-23 20:58 - 00001585 _____ C:\Users\Public\Desktop\League of Legends.lnk
2015-12-23 20:58 - 2015-12-23 20:58 - 00000000 ____D C:\Riot Games
2015-12-23 20:58 - 2015-12-23 20:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2015-12-23 20:58 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2015-12-23 20:58 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2015-12-23 20:58 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2015-12-23 20:56 - 2015-12-23 20:56 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Riot Games
2015-12-23 20:55 - 2015-12-23 20:56 - 27874912 _____ (Riot Games) C:\Users\José Arcos\Downloads\LeagueofLegends_LA2_Installer_9_15_2014.exe
2015-12-23 14:21 - 2016-01-12 18:34 - 00000000 ____D C:\Program Files (x86)\Steam
2015-12-23 14:21 - 2015-12-23 14:21 - 01476720 _____ C:\Users\José Arcos\Downloads\SteamSetup.exe
2015-12-23 14:21 - 2015-12-23 14:21 - 00000992 _____ C:\Users\Public\Desktop\Steam.lnk
2015-12-23 14:21 - 2015-12-23 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2015-12-23 13:42 - 2015-12-24 12:42 - 00000000 ____D C:\Program Files (x86)\Origin Games
2015-12-23 13:41 - 2015-12-24 13:53 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Origin
2015-12-23 13:41 - 2015-12-23 14:19 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Origin
2015-12-23 04:16 - 2015-12-23 04:16 - 00000000 ____D C:\ProgramData\Steam
2015-12-23 04:11 - 2015-12-23 04:11 - 00001239 _____ C:\Users\José Arcos\Desktop\Metal Gear Solid V Ground Zeroes.lnk
2015-12-23 04:11 - 2015-12-23 04:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metal Gear Solid V Ground Zeroes
2015-12-23 04:10 - 2016-01-10 00:23 - 00000000 ____D C:\Program Files (x86)\Metal Gear Solid V Ground Zeroes
2015-12-23 04:00 - 2015-12-23 04:00 - 00000926 _____ C:\Users\Public\Desktop\Outlast Whistleblower.lnk
2015-12-23 03:50 - 2015-12-23 04:00 - 00000000 ____D C:\Program Files (x86)\Outlast Whistleblower
2015-12-23 03:08 - 2015-12-23 03:08 - 00000000 ____D C:\Users\José Arcos\AppData\Local\CAPCOM
2015-12-23 02:59 - 2015-12-23 02:59 - 00001162 _____ C:\Users\José Arcos\Desktop\Resident Evil HD Remaster.lnk
2015-12-23 02:28 - 2012-08-28 15:35 - 15453832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xlive.dll
2015-12-23 02:27 - 2015-12-23 02:59 - 00000000 ____D C:\Program Files (x86)\Resident Evil HD Remaster
2015-12-23 02:20 - 2015-12-23 02:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound
2015-12-23 02:20 - 2015-12-23 02:20 - 00000000 ____D C:\Program Files (x86)\BRS
2015-12-23 02:20 - 2011-03-19 15:16 - 01417216 _____ (Blue Ripple Sound Limited) C:\Windows\SysWOW64\rapture3d_oal.dll
2015-12-23 02:20 - 2010-09-22 13:12 - 19087360 _____ (Intel Corporation / Blue Ripple Sound Limited) C:\Windows\SysWOW64\mkl_blueripple.dll
2015-12-23 02:20 - 2010-03-01 19:51 - 00109080 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2015-12-23 02:01 - 2015-12-23 02:01 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Blizzard Entertainment
2015-12-23 01:55 - 2016-01-12 18:35 - 00005270 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for AMD-José Arcos AMD
2015-12-23 01:52 - 2015-12-23 01:52 - 00016148 _____ C:\Windows\system32\JOSE_José Arcos_HistoryPrediction.bin
2015-12-22 23:12 - 2015-12-22 23:12 - 00000000 ____D C:\Windows\system32\SleepStudy
2015-12-22 22:34 - 2015-12-22 22:34 - 00466728 _____ (Microsoft Corporation) C:\Windows\system32\coin99ip.dll
2015-12-22 22:29 - 2015-12-22 22:33 - 00000000 ____D C:\Windows\system32\MRT
2015-12-22 22:29 - 2015-11-23 19:10 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-22 22:16 - 2015-12-25 11:35 - 00000000 ____D C:\ProgramData\Origin
2015-12-22 22:16 - 2015-12-24 13:54 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-12-22 22:16 - 2015-12-22 22:16 - 00001008 _____ C:\Users\Public\Desktop\Origin.lnk
2015-12-22 22:16 - 2015-12-22 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-12-22 22:15 - 2015-12-23 13:41 - 00000000 ____D C:\Program Files (x86)\Origin
2015-12-20 17:45 - 2015-12-20 17:45 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-12-20 01:01 - 2015-12-20 01:01 - 00000599 _____ C:\Users\Public\Desktop\Fraps.lnk
2015-12-20 01:01 - 2015-12-20 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2015-12-20 01:01 - 2015-12-20 01:01 - 00000000 ____D C:\Fraps
2015-12-20 00:45 - 2015-12-20 00:45 - 00016148 _____ C:\Windows\system32\DESKTOP-V93OD72_José Arcos_HistoryPrediction.bin
2015-12-20 00:43 - 2015-12-20 00:43 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Steam
2015-12-20 00:43 - 2015-12-20 00:43 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Fallout4
2015-12-20 00:41 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2015-12-20 00:41 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2015-12-20 00:41 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2015-12-20 00:41 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2015-12-20 00:41 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2015-12-20 00:41 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2015-12-20 00:41 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2015-12-20 00:41 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2015-12-20 00:41 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2015-12-20 00:41 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2015-12-20 00:41 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2015-12-20 00:41 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2015-12-20 00:41 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2015-12-20 00:41 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2015-12-20 00:41 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2015-12-20 00:41 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2015-12-20 00:41 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2015-12-20 00:41 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2015-12-20 00:41 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2015-12-20 00:41 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2015-12-20 00:41 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2015-12-20 00:41 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2015-12-20 00:41 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2015-12-20 00:40 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2015-12-20 00:40 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2015-12-20 00:40 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2015-12-20 00:40 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2015-12-20 00:40 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2015-12-20 00:40 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2015-12-20 00:40 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2015-12-20 00:40 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2015-12-20 00:40 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2015-12-20 00:40 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2015-12-20 00:40 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2015-12-20 00:40 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2015-12-20 00:40 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2015-12-20 00:40 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2015-12-20 00:40 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2015-12-20 00:40 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2015-12-20 00:40 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2015-12-20 00:40 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2015-12-20 00:40 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2015-12-20 00:40 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2015-12-20 00:40 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2015-12-20 00:40 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2015-12-20 00:40 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2015-12-20 00:40 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2015-12-20 00:40 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2015-12-20 00:40 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2015-12-20 00:40 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2015-12-20 00:40 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2015-12-20 00:40 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2015-12-20 00:40 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2015-12-20 00:40 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2015-12-20 00:40 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2015-12-20 00:40 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2015-12-20 00:40 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2015-12-20 00:40 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2015-12-20 00:40 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2015-12-20 00:40 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2015-12-20 00:40 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2015-12-20 00:40 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2015-12-20 00:40 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2015-12-20 00:40 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2015-12-20 00:40 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2015-12-20 00:40 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2015-12-20 00:40 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2015-12-20 00:40 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2015-12-20 00:40 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2015-12-20 00:40 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2015-12-20 00:40 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2015-12-20 00:40 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2015-12-20 00:40 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2015-12-20 00:40 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2015-12-20 00:40 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2015-12-20 00:40 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2015-12-20 00:40 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2015-12-20 00:40 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2015-12-20 00:40 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2015-12-20 00:40 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2015-12-20 00:40 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2015-12-20 00:40 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2015-12-20 00:40 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2015-12-20 00:40 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2015-12-20 00:40 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2015-12-20 00:40 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2015-12-20 00:40 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2015-12-20 00:40 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2015-12-20 00:40 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2015-12-20 00:40 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2015-12-20 00:40 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2015-12-20 00:40 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2015-12-20 00:40 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2015-12-20 00:40 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2015-12-20 00:40 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2015-12-20 00:40 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2015-12-20 00:40 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2015-12-20 00:40 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2015-12-20 00:40 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2015-12-20 00:40 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2015-12-20 00:40 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2015-12-20 00:40 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2015-12-20 00:40 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2015-12-20 00:40 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2015-12-20 00:40 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2015-12-20 00:40 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2015-12-20 00:40 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2015-12-20 00:40 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2015-12-20 00:40 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2015-12-20 00:40 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2015-12-20 00:40 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2015-12-20 00:40 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2015-12-20 00:39 - 2015-12-20 00:41 - 00000000 ____D C:\Windows\SysWOW64\directx
2015-12-20 00:39 - 2015-12-20 00:40 - 00000000 ___HD C:\Windows\msdownld.tmp
2015-12-20 00:38 - 2015-12-20 00:38 - 00001115 _____ C:\Users\José Arcos\Desktop\MSI Afterburner.lnk
2015-12-20 00:38 - 2015-12-20 00:38 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2015-12-20 00:37 - 2015-12-26 17:58 - 00000000 ____D C:\MSI
2015-12-20 00:37 - 2015-12-20 00:38 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner
2015-12-20 00:37 - 2015-12-20 00:37 - 00003058 _____ C:\Windows\System32\Tasks\MSISW_Host
2015-12-20 00:37 - 2015-12-20 00:37 - 00001182 _____ C:\Users\Public\Desktop\MSI Gaming APP.lnk
2015-12-20 00:37 - 2015-12-20 00:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-12-20 00:37 - 2015-12-20 00:37 - 00000000 ____D C:\Program Files (x86)\MSI
2015-12-20 00:37 - 2015-08-18 09:51 - 01692840 _____ (MSI) C:\Windows\SysWOW64\muachost.exe
2015-12-20 00:26 - 2015-12-20 00:29 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Comms
2015-12-20 00:05 - 2015-12-20 00:08 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo
2015-12-20 00:05 - 2015-12-20 00:08 - 00000000 ____D C:\Program Files (x86)\Lenovo
2015-12-20 00:05 - 2015-12-20 00:05 - 00000000 ____D C:\Windows\Downloaded Installations
2015-12-20 00:05 - 2015-12-20 00:05 - 00000000 ____D C:\Users\José Arcos\REACHit
2015-12-20 00:05 - 2015-12-20 00:05 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Lenovo
2015-12-20 00:05 - 2015-12-20 00:05 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Downloaded Installations
2015-12-19 23:53 - 2015-12-20 00:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-12-19 23:53 - 2015-12-19 23:53 - 00000000 ____D C:\Windows\PCHEALTH
2015-12-19 23:53 - 2015-12-19 23:53 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2015-12-19 23:53 - 2015-12-19 23:53 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2015-12-19 23:53 - 2015-12-19 23:53 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2015-12-19 23:52 - 2015-12-19 23:52 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Microsoft Help
2015-12-19 23:52 - 2015-12-19 23:52 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2015-12-19 23:52 - 2015-12-19 23:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-12-19 23:52 - 2015-12-19 23:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2015-12-19 23:51 - 2015-12-19 23:53 - 00000000 ____D C:\Program Files\Microsoft Office
2015-12-19 23:51 - 2015-12-19 23:51 - 00000000 __RHD C:\MSOCache
2015-12-19 23:50 - 2015-12-19 23:50 - 00002880 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-12-19 23:50 - 2015-12-19 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-12-19 23:50 - 2015-12-19 23:50 - 00000000 ____D C:\Program Files\CCleaner
2015-12-19 23:49 - 2015-12-19 23:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
2015-12-19 23:49 - 2015-12-19 23:49 - 00000000 ____D C:\ProgramData\Auslogics
2015-12-19 23:49 - 2015-12-19 23:49 - 00000000 ____D C:\Program Files (x86)\Auslogics
2015-12-19 23:39 - 2015-12-19 23:39 - 00000022 _____ C:\Windows\GPU-Z.INI
2015-12-19 23:38 - 2015-12-19 23:38 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Futuremark
2015-12-19 23:35 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2015-12-19 23:35 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2015-12-19 23:35 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2015-12-19 23:35 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2015-12-19 23:35 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2015-12-19 23:35 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2015-12-19 23:35 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2015-12-19 23:34 - 2015-12-19 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2015-12-19 23:34 - 2015-12-19 23:34 - 00000000 ____D C:\Program Files\CPUID
2015-12-19 22:53 - 2015-12-19 22:53 - 00001240 _____ C:\Users\Public\Desktop\Soulstorm.lnk
2015-12-19 22:53 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2015-12-19 22:53 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2015-12-19 22:53 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2015-12-19 22:53 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2015-12-19 22:53 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2015-12-19 22:53 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2015-12-19 22:53 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2015-12-19 22:53 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2015-12-19 22:53 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2015-12-19 22:53 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2015-12-19 22:53 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2015-12-19 22:53 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2015-12-19 22:53 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2015-12-19 22:53 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2015-12-19 22:53 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2015-12-19 22:53 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2015-12-19 22:53 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2015-12-19 22:53 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2015-12-19 22:53 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2015-12-19 22:53 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2015-12-19 22:53 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2015-12-19 22:53 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2015-12-19 22:53 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2015-12-19 22:53 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2015-12-19 22:53 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2015-12-19 22:53 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2015-12-19 22:53 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2015-12-19 22:53 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2015-12-19 22:52 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2015-12-19 22:52 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2015-12-19 22:52 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2015-12-19 22:52 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2015-12-19 22:52 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2015-12-19 22:52 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2015-12-19 22:52 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2015-12-19 22:52 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2015-12-19 22:49 - 2015-12-19 22:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ
2015-12-19 22:49 - 2015-12-19 22:49 - 00000000 ____D C:\Program Files (x86)\THQ
2015-12-19 22:47 - 2015-12-23 04:16 - 00000000 ____D C:\Users\José Arcos\Documents\My Games
2015-12-19 22:38 - 2015-12-19 22:38 - 00001711 _____ C:\Users\Public\Desktop\Starcraft II.lnk
2015-12-19 22:38 - 2015-12-19 22:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Starcraft II
2015-12-19 22:37 - 2015-12-23 01:59 - 00000000 ____D C:\Users\José Arcos\Documents\Starcraft II
2015-12-19 22:37 - 2015-12-23 01:59 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2015-12-19 22:21 - 2015-12-19 22:21 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Steam
2015-12-19 22:21 - 2015-12-19 22:21 - 00000000 ____D C:\Users\José Arcos\AppData\Local\CEF
2015-12-19 22:07 - 2015-12-19 22:13 - 00000000 ____D C:\Games
2015-12-19 21:48 - 2015-12-23 01:55 - 00000000 ___RD C:\Users\José Arcos\Dropbox
2015-12-19 21:46 - 2015-12-19 21:46 - 00000000 ____D C:\Users\José Arcos\AppData\Local\PeerDistRepub
2015-12-19 21:45 - 2015-12-19 21:45 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Dropbox
2015-12-19 21:44 - 2015-12-23 13:52 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-12-19 21:44 - 2015-12-23 01:56 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Dropbox
2015-12-19 21:44 - 2015-12-19 21:44 - 00000000 ____D C:\ProgramData\Dropbox
2015-12-19 21:40 - 2015-12-19 21:40 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\ATI
2015-12-19 21:40 - 2015-12-19 21:40 - 00000000 ____D C:\Users\José Arcos\AppData\Local\ATI
2015-12-19 21:40 - 2015-12-19 21:40 - 00000000 ____D C:\ProgramData\ATI
2015-12-19 21:39 - 2015-12-19 21:39 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\library_dir
2015-12-19 21:38 - 2015-12-23 22:13 - 00000000 ____D C:\Users\José Arcos\AppData\Local\AMD
2015-12-19 21:38 - 2015-12-20 00:51 - 00000000 ____D C:\Program Files (x86)\Raptr
2015-12-19 21:38 - 2015-12-19 21:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2015-12-19 21:37 - 2015-12-19 21:37 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2015-12-19 21:37 - 2015-12-19 21:37 - 00000000 ____D C:\Program Files (x86)\AMD
2015-12-19 21:37 - 2015-12-19 21:37 - 00000000 _____ C:\Windows\ativpsrm.bin
2015-12-19 21:32 - 2015-12-19 21:32 - 00004296 _____ C:\Windows\System32\Tasks\AMD Updater
2015-12-19 21:31 - 2015-12-19 21:31 - 00000000 ____D C:\Program Files\VIA XHCI UASP Utility
2015-12-19 21:31 - 2014-10-31 10:43 - 00227840 _____ (VIA Technologies, Inc.) C:\Windows\system32\Drivers\ViaHub3.sys
2015-12-19 21:31 - 2013-01-18 03:11 - 00086064 _____ (VIA Technologies, Inc.) C:\Windows\system32\Drivers\vusbstor.sys
2015-12-19 21:30 - 2015-12-19 21:30 - 00000000 ____D C:\Program Files (x86)\VIA
2015-12-19 21:30 - 2014-10-31 10:43 - 00305664 _____ (VIA Technologies, Inc.) C:\Windows\system32\Drivers\xhcdrv.sys
2015-12-19 21:30 - 2012-08-17 10:57 - 01795952 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2015-12-19 21:16 - 2015-12-19 21:16 - 00001047 _____ C:\Users\José Arcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Funciones opcionales.lnk
2015-12-19 20:59 - 2015-12-09 00:39 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-12-19 20:57 - 2015-12-25 11:45 - 00000000 ____D C:\AMD
2015-12-19 20:54 - 2015-12-19 20:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-19 20:53 - 2016-01-12 18:38 - 00004228 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{400D9272-2951-4734-B13D-0DC23A3BA9EC}
2015-12-19 20:53 - 2016-01-12 18:34 - 00001136 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-19 20:53 - 2016-01-11 22:58 - 00001140 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-19 20:53 - 2016-01-07 20:31 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Google
2015-12-19 20:53 - 2015-12-19 20:54 - 00000000 ____D C:\Program Files (x86)\Google
2015-12-19 20:53 - 2015-12-19 20:53 - 00004198 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-19 20:53 - 2015-12-19 20:53 - 00003966 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-19 20:51 - 2015-12-19 20:51 - 00001243 _____ C:\Users\José Arcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CNext.lnk
2015-12-19 20:50 - 2015-12-19 20:50 - 00469776 _____ (Microsoft Corporation) C:\Windows\system32\coin98ip.dll
2015-12-19 20:46 - 2016-01-11 18:59 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2015-12-19 20:45 - 2015-12-19 21:38 - 00000000 ____D C:\Program Files\AMD
2015-12-19 20:43 - 2015-12-19 20:43 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-12-19 20:42 - 2015-12-27 13:03 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-12-19 20:42 - 2015-12-19 20:43 - 00000000 ___HD C:\Program Files (x86)\Temp
2015-12-19 20:42 - 2015-12-19 20:42 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2015-12-19 20:42 - 2015-12-19 20:42 - 00000000 ____D C:\Program Files\Realtek
2015-12-19 20:42 - 2015-12-19 20:42 - 00000000 ____D C:\Program Files (x86)\Realtek
2015-12-19 20:42 - 2015-07-07 08:13 - 04514008 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2015-12-19 20:42 - 2015-07-07 04:54 - 35222128 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-12-19 20:42 - 2015-07-06 05:05 - 02930904 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2015-12-19 20:42 - 2015-07-01 07:18 - 01749208 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2015-12-19 20:42 - 2015-06-30 05:04 - 00184688 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2015-12-19 20:42 - 2015-06-26 09:10 - 01310936 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2015-12-19 20:42 - 2015-06-22 23:37 - 00895256 _____ (Realtek ) C:\Windows\system32\Drivers\rt640x64.sys
2015-12-19 20:42 - 2015-06-22 23:37 - 00091272 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2015-12-19 20:42 - 2015-06-22 03:43 - 02702552 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2015-12-19 20:42 - 2015-06-17 03:45 - 03234520 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2015-12-19 20:42 - 2015-06-08 05:13 - 02825944 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
2015-12-19 20:42 - 2015-05-15 08:27 - 02918104 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2015-12-19 20:42 - 2015-01-19 07:10 - 72113152 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2015-12-19 20:42 - 2014-11-11 02:44 - 00631000 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2015-12-19 20:42 - 2014-09-24 00:31 - 07087448 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2015-12-19 20:42 - 2014-09-24 00:31 - 01939800 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2015-12-19 20:42 - 2014-09-24 00:31 - 00315736 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2015-12-19 20:42 - 2014-09-24 00:31 - 00261464 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2015-12-19 20:42 - 2014-05-22 05:24 - 00096568 _____ C:\Windows\system32\audioLibVc.dll
2015-12-19 20:42 - 2013-06-21 00:01 - 00109848 _____ C:\Windows\system32\AcpiServiceVnA64.dll
2015-12-19 20:42 - 2012-08-31 08:18 - 07164176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2015-12-19 20:42 - 2012-08-31 08:17 - 00434960 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2015-12-19 20:42 - 2012-08-31 08:17 - 00141584 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2015-12-19 20:42 - 2012-08-31 08:17 - 00124176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2015-12-19 20:42 - 2012-08-31 08:17 - 00075024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2015-12-19 20:42 - 2011-12-20 04:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2015-12-19 20:42 - 2011-11-22 05:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2015-12-19 20:42 - 2011-05-30 22:42 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2015-12-19 20:39 - 2015-12-25 20:21 - 00000000 ____D C:\ProgramData\Package Cache
2015-12-19 20:39 - 2015-12-19 20:39 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\WinRAR
2015-12-19 20:39 - 2015-12-19 20:39 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-12-19 20:39 - 2015-12-19 20:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-12-19 20:38 - 2015-12-19 20:39 - 00000000 ____D C:\Program Files\WinRAR
2015-12-19 20:37 - 2015-12-28 21:28 - 01840872 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-19 20:35 - 2015-12-19 20:35 - 00002410 _____ C:\Users\José Arcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-12-19 20:35 - 2015-12-19 20:35 - 00000000 ___RD C:\Users\José Arcos\OneDrive
2015-12-19 20:35 - 2015-12-19 20:35 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-12-19 20:35 - 2015-12-19 20:35 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Macromedia
2015-12-19 20:35 - 2015-12-19 20:35 - 00000000 ____D C:\Users\José Arcos\AppData\Local\MicrosoftEdge
2015-12-19 20:34 - 2015-12-19 20:34 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-12-19 20:33 - 2015-12-19 20:33 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Publishers
2015-12-19 20:32 - 2016-01-10 18:59 - 00000000 ____D C:\Users\José Arcos\AppData\Local\VirtualStore
2015-12-19 20:32 - 2016-01-09 23:38 - 00000000 ____D C:\Users\José Arcos
2015-12-19 20:32 - 2015-12-27 12:41 - 00000000 __RHD C:\Users\Public\AccountPictures
2015-12-19 20:32 - 2015-12-20 00:27 - 00000000 ____D C:\Users\José Arcos\AppData\Local\Packages
2015-12-19 20:32 - 2015-12-19 20:32 - 00016148 _____ C:\Windows\system32\DESKTOP-V93OD72_defaultuser0_HistoryPrediction.bin
2015-12-19 20:32 - 2015-12-19 20:32 - 00000020 ___SH C:\Users\José Arcos\ntuser.ini
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Reciente
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Plantillas
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Mis documentos
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Menú Inicio
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Impresoras
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Entorno de red
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Documents\Mis vídeos
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Documents\Mis imágenes
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Documents\Mi música
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Datos de programa
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\Configuración local
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\AppData\Local\Historial
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\AppData\Local\Datos de programa
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 _SHDL C:\Users\José Arcos\AppData\Local\Archivos temporales de Internet
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 ____D C:\Users\José Arcos\AppData\Roaming\Adobe
2015-12-19 20:32 - 2015-12-19 20:32 - 00000000 ____D C:\Users\José Arcos\AppData\Local\TileDataLayer
2015-12-19 20:29 - 2015-12-01 04:01 - 02115936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2015-12-19 20:29 - 2015-11-18 03:36 - 04532304 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-12-19 20:29 - 2015-11-18 02:56 - 04047280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2015-12-19 20:29 - 2015-08-19 01:50 - 00609592 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-12-19 20:28 - 2015-07-22 00:52 - 00988672 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Public\Documents\Mis vídeos
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Public\Documents\Mis imágenes
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Public\Documents\Mi música
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Reciente
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Plantillas
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Mis documentos
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Menú Inicio
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Impresoras
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Entorno de red
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Documents\Mis vídeos
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Documents\Mis imágenes
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Documents\Mi música
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Datos de programa
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\Configuración local
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\AppData\Local\Historial
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\AppData\Local\Datos de programa
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default\AppData\Local\Archivos temporales de Internet
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default User\Documents\Mis vídeos
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default User\Documents\Mis imágenes
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default User\Documents\Mi música
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Historial
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Datos de programa
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Archivos temporales de Internet
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\ProgramData\Plantillas
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programas
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\ProgramData\Menú Inicio
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\ProgramData\Escritorio
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\ProgramData\Documentos
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\ProgramData\Datos de programa
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Program Files\Archivos comunes
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 _SHDL C:\Archivos de programa
2015-12-19 20:25 - 2015-12-19 20:25 - 00000000 ____D C:\Windows\CSC
2015-12-19 20:23 - 2015-07-10 07:59 - 02718208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2015-12-19 16:20 - 2016-01-08 15:44 - 00000000 ____D C:\Windows\Panther
2015-12-16 16:45 - 2015-12-16 16:45 - 10919104 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll
2015-12-16 16:45 - 2015-12-16 16:45 - 09158496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2015-12-16 16:45 - 2015-12-16 16:45 - 09105552 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll
2015-12-16 16:45 - 2015-12-16 16:45 - 08168856 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2015-12-16 16:45 - 2015-12-16 16:45 - 00162784 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll
2015-12-16 16:45 - 2015-12-16 16:45 - 00143080 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2015-12-16 16:45 - 2015-12-16 16:45 - 00112392 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 13313544 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 11011560 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 08426376 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdxc32.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 01519232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 01249664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 00471344 _____ C:\Windows\system32\amdmiracast.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 00130616 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 00088032 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 00088032 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 00081200 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2015-12-16 16:44 - 2015-12-16 16:44 - 00081200 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2015-12-16 16:43 - 2015-12-16 16:43 - 00151968 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll
2015-12-16 16:43 - 2015-12-16 16:43 - 00138416 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll
2015-12-16 16:43 - 2015-12-16 16:43 - 00128568 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll
2015-12-16 16:43 - 2015-12-16 16:43 - 00120200 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll
2015-12-16 16:41 - 2015-12-16 16:41 - 00874000 _____ (AMD) C:\Windows\system32\coinst_15.30.dll
2015-12-16 16:41 - 2015-12-16 16:41 - 00243728 _____ C:\Windows\system32\clinfo.exe
2015-12-16 16:41 - 2015-12-16 16:41 - 00232464 _____ C:\Windows\system32\dgtrayicon.exe
2015-12-16 16:41 - 2015-12-16 16:41 - 00203792 _____ C:\Windows\system32\hsa-thunk64.dll
2015-12-16 16:41 - 2015-12-16 16:41 - 00183312 _____ C:\Windows\SysWOW64\hsa-thunk.dll
2015-12-16 16:41 - 2015-12-16 16:41 - 00136208 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll
2015-12-16 16:41 - 2015-12-16 16:41 - 00122384 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll
2015-12-16 16:41 - 2015-12-16 16:41 - 00104976 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll
2015-12-16 16:41 - 2015-12-16 16:41 - 00097808 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll
2015-12-16 16:41 - 2015-12-16 16:41 - 00012816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\detoured.dll
2015-12-16 16:41 - 2015-12-16 16:41 - 00012816 _____ (Microsoft Corporation) C:\Windows\system32\detoured.dll
2015-12-16 16:37 - 2015-12-16 16:37 - 25848848 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2015-12-16 16:37 - 2015-12-16 16:37 - 00199696 _____ (AMD) C:\Windows\system32\atitmm64.dll
2015-12-16 16:37 - 2015-12-16 16:37 - 00097808 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll
2015-12-16 16:37 - 2015-12-16 16:37 - 00089616 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll
2015-12-16 16:35 - 2015-12-16 16:35 - 00341520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODE.exe
2015-12-16 16:34 - 2015-12-16 16:34 - 31385616 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll
2015-12-16 16:34 - 2015-12-16 16:34 - 00059920 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODCLI.exe
2015-12-16 16:32 - 2015-12-16 16:32 - 00040464 _____ (AMD) C:\Windows\system32\atimuixx.dll
2015-12-16 16:31 - 2015-12-16 16:31 - 23969808 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2015-12-16 16:31 - 2015-12-16 16:31 - 00679952 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2015-12-16 16:29 - 2015-12-16 16:29 - 00561168 _____ (AMD) C:\Windows\system32\atieclxx.exe
2015-12-16 16:29 - 2015-12-16 16:29 - 00254992 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2015-12-16 16:29 - 2015-12-16 16:29 - 00166416 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll
2015-12-16 16:29 - 2015-12-16 16:29 - 00151056 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2015-12-16 16:29 - 2015-12-16 16:29 - 00084504 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll
2015-12-16 16:29 - 2015-12-16 16:29 - 00078864 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2015-12-16 16:29 - 2015-12-16 16:29 - 00078864 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2015-12-16 16:28 - 2015-12-16 16:28 - 00451088 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2015-12-16 16:28 - 2015-12-16 16:28 - 00171032 _____ C:\Windows\system32\atieah64.exe
2015-12-16 16:28 - 2015-12-16 16:28 - 00154128 _____ C:\Windows\SysWOW64\atieah32.exe
2015-12-16 16:28 - 2015-12-16 16:28 - 00071184 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll
2015-12-16 16:28 - 2015-12-16 16:28 - 00060944 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2015-12-16 16:27 - 2015-12-16 16:27 - 15720464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll
2015-12-16 16:27 - 2015-12-16 16:27 - 14310928 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2015-12-16 16:26 - 2015-12-16 16:26 - 00375824 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2015-12-16 16:26 - 2015-12-16 16:26 - 00064528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll
2015-12-16 16:26 - 2015-12-16 16:26 - 00057872 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2015-12-16 16:25 - 2015-12-16 16:25 - 49992720 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2015-12-16 16:25 - 2015-12-16 16:25 - 01281552 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2015-12-16 16:25 - 2015-12-16 16:25 - 00950288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2015-12-16 16:25 - 2015-12-16 16:25 - 00950288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxx.dll
2015-12-16 16:25 - 2015-12-16 16:25 - 00052240 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2015-12-16 16:22 - 2015-12-16 16:22 - 27605008 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl12cl64.dll
2015-12-16 16:21 - 2015-12-16 16:21 - 22357008 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl12cl.dll
2015-12-16 16:20 - 2015-12-16 16:20 - 41519120 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2015-12-16 16:19 - 2015-12-16 16:19 - 00059408 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2015-12-16 16:19 - 2015-12-16 16:19 - 00048144 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll
2015-12-16 16:17 - 2015-12-16 16:17 - 06651920 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll
2015-12-16 16:16 - 2015-12-16 16:16 - 05232656 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll
2015-12-16 16:15 - 2015-12-16 16:15 - 00686608 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdlvr64.dll
2015-12-16 16:15 - 2015-12-16 16:15 - 00571408 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdlvr32.dll
2015-12-16 16:13 - 2015-12-16 16:13 - 00305392 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys
2015-12-16 16:13 - 2015-12-16 16:13 - 00213520 _____ C:\Windows\system32\amdgfxinfo64.dll
2015-12-16 16:13 - 2015-12-16 16:13 - 00198672 _____ C:\Windows\SysWOW64\amdgfxinfo32.dll
2015-12-16 16:13 - 2015-12-16 16:13 - 00143376 _____ C:\Windows\system32\amdhdl64.dll
2015-12-16 16:13 - 2015-12-16 16:13 - 00132112 _____ C:\Windows\SysWOW64\amdhdl32.dll
2015-12-16 16:13 - 2015-12-16 16:13 - 00073744 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-12-16 16:13 - 2015-12-16 16:13 - 00068112 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-12-16 15:07 - 2015-12-16 15:07 - 10339016 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdxc64.dll
2015-12-16 06:11 - 2015-12-16 06:11 - 03471376 _____ C:\Windows\SysWOW64\atiumdva.cap
2015-12-16 06:11 - 2015-12-16 06:11 - 03437632 _____ C:\Windows\system32\atiumd6a.cap
2015-12-16 06:11 - 2015-12-16 06:11 - 00323588 _____ C:\Windows\system32\ativvaxy_el.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00322740 _____ C:\Windows\system32\ativvaxy_vi.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00321072 _____ C:\Windows\system32\ativvaxy_vi_nd.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00320992 _____ C:\Windows\system32\ativvaxy_el_nd.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00261920 _____ C:\Windows\system32\ativvaxy_stn_nd.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00258464 _____ C:\Windows\system32\ativvaxy_cz_nd.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00252628 _____ C:\Windows\system32\ativvaxy_FJ.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00249680 _____ C:\Windows\system32\ativvaxy_FJ_nd.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00234292 _____ C:\Windows\system32\ativvaxy_cik.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00232624 _____ C:\Windows\system32\ativvaxy_cik_nd.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00204952 _____ C:\Windows\system32\ativvsvl.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00177344 _____ C:\Windows\system32\ativce03.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00157144 _____ C:\Windows\system32\ativvsva.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00140240 _____ C:\Windows\system32\samu_krnl_ci.sbin
2015-12-16 06:11 - 2015-12-16 06:11 - 00138832 _____ C:\Windows\system32\samu_krnl_isv_ci.sbin
2015-12-16 06:11 - 2015-12-16 06:11 - 00100832 _____ C:\Windows\system32\ativce02.dat
2015-12-16 06:11 - 2015-12-16 06:11 - 00047664 _____ C:\Windows\system32\kapp_ci.sbin
2015-12-16 06:11 - 2015-12-16 06:11 - 00043536 _____ C:\Windows\system32\kapp_si.sbin
2015-12-16 06:10 - 2015-12-16 06:10 - 00737410 _____ C:\Windows\system32\atiicdxx.dat
2015-12-16 06:09 - 2015-12-16 06:09 - 00843639 _____ C:\Windows\system32\amdicdxx.dat
2015-12-16 06:09 - 2015-12-16 06:09 - 00683968 _____ C:\Windows\SysWOW64\atiapfxx.blb
2015-12-16 06:09 - 2015-12-16 06:09 - 00683968 _____ C:\Windows\system32\atiapfxx.blb
2015-12-16 06:09 - 2015-12-16 06:09 - 00175648 _____ C:\Windows\system32\amde31a.dat
2015-12-16 06:09 - 2015-12-16 06:09 - 00166560 _____ C:\Windows\system32\amde34a.dat
2015-12-16 06:09 - 2015-12-16 06:09 - 00007112 _____ C:\Windows\system32\AMDKernelEvents.man
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-01-12 18:36 - 2015-07-10 06:05 - 00000000 ____D C:\Windows
2016-01-11 19:23 - 2015-07-10 07:55 - 00000000 ____D C:\Windows\CbsTemp
2016-01-11 19:18 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\AppReadiness
2016-01-11 19:00 - 2015-07-10 09:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-11 18:59 - 2015-07-10 06:05 - 00131072 ___SH C:\Windows\system32\config\BBI
2016-01-11 13:50 - 2015-07-10 08:04 - 00000000 ___HD C:\Program Files\WindowsApps
2016-01-10 15:46 - 2015-07-10 08:04 - 00000000 ___HD C:\Windows\ELAMBKUP
2016-01-10 15:46 - 2015-07-10 08:02 - 00000000 ____D C:\Windows\INF
2016-01-08 22:06 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\ModemLogs
2016-01-08 15:41 - 2015-10-30 16:23 - 00000000 ___HD C:\$WINDOWS.~BT
2016-01-02 22:40 - 2015-07-10 08:06 - 00826872 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-02 22:40 - 2015-07-10 08:06 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-28 23:01 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-12-28 21:28 - 2015-07-10 13:26 - 00816300 _____ C:\Windows\system32\perfh00A.dat
2015-12-28 21:28 - 2015-07-10 13:26 - 00159748 _____ C:\Windows\system32\perfc00A.dat
2015-12-28 21:21 - 2015-07-10 09:20 - 00345048 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-27 00:00 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\rescache
2015-12-23 21:01 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\SysWOW64\MUI
2015-12-23 21:01 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\MUI
2015-12-20 17:43 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\appcompat
2015-12-20 00:01 - 2015-07-10 08:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-12-20 00:01 - 2015-07-10 08:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-12-19 23:58 - 2015-07-10 13:35 - 00000000 ____D C:\Windows\ShellNew
2015-12-19 23:52 - 2015-07-10 08:04 - 00000167 _____ C:\Windows\win.ini
2015-12-19 23:52 - 2015-07-10 08:04 - 00000000 ____D C:\Program Files\Common Files\System
2015-12-19 22:02 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\LiveKernelReports
2015-12-19 21:16 - 2015-07-10 13:26 - 00000000 ____D C:\Windows\OCR
2015-12-19 20:52 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2015-12-19 20:49 - 2015-07-10 08:04 - 00000000 ___RD C:\Windows\DevicesFlow
2015-12-19 20:33 - 2015-07-10 08:04 - 00000000 ___RD C:\Windows\PurchaseDialog
2015-12-19 20:33 - 2015-07-10 08:04 - 00000000 ___RD C:\Windows\PrintDialog
2015-12-19 20:33 - 2015-07-10 08:04 - 00000000 ___RD C:\Windows\MiracastView
2015-12-19 20:33 - 2015-07-10 08:04 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2015-12-19 20:30 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\oobe
2015-12-19 20:27 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\spool
2015-12-19 20:26 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-12-19 20:25 - 2015-07-10 08:04 - 00000000 ____D C:\Program Files\Windows NT
2015-12-19 20:23 - 2015-07-10 06:05 - 00000000 ____D C:\Windows\system32\Sysprep
2015-12-19 16:19 - 2015-07-10 08:04 - 00028672 _____ C:\Windows\system32\config\BCD-Template
 
==================== Files in the root of some directories =======
 
2015-12-19 20:43 - 2015-12-19 20:43 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\José Arcos\AppData\Local\Temp\130950542015793129.exe
C:\Users\José Arcos\AppData\Local\Temp\AMDCleanupUtility.exe
C:\Users\José Arcos\AppData\Local\Temp\Cleanup.dll
C:\Users\José Arcos\AppData\Local\Temp\ddu.exe
C:\Users\José Arcos\AppData\Local\Temp\difxapi.dll
C:\Users\José Arcos\AppData\Local\Temp\dllnt_dump.dll
C:\Users\José Arcos\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\José Arcos\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\José Arcos\AppData\Local\Temp\msvcm80.dll
C:\Users\José Arcos\AppData\Local\Temp\msvcp80.dll
C:\Users\José Arcos\AppData\Local\Temp\msvcr80.dll
C:\Users\José Arcos\AppData\Local\Temp\proxy_vole2014474577154815514.dll
C:\Users\José Arcos\AppData\Local\Temp\raptrpatch.exe
C:\Users\José Arcos\AppData\Local\Temp\raptr_stub.exe
C:\Users\José Arcos\AppData\Local\Temp\rldfw64_s614.dll
C:\Users\José Arcos\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\José Arcos\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\José Arcos\AppData\Local\Temp\sonarinst.exe
C:\Users\José Arcos\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-01-05 14:34
 
==================== End of FRST.txt ============================

Attached Files



#4 nasdaq

nasdaq

  • Malware Response Team
  • 39,541 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:12:35 PM

Posted 13 January 2016 - 09:15 AM




Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.


start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  No File
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
C:\Users\José Arcos\AppData\Local\Temp\130950542015793129.exe
C:\Users\José Arcos\AppData\Local\Temp\AMDCleanupUtility.exe
C:\Users\José Arcos\AppData\Local\Temp\Cleanup.dll
C:\Users\José Arcos\AppData\Local\Temp\ddu.exe
C:\Users\José Arcos\AppData\Local\Temp\difxapi.dll
C:\Users\José Arcos\AppData\Local\Temp\dllnt_dump.dll
C:\Users\José Arcos\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\José Arcos\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\José Arcos\AppData\Local\Temp\msvcm80.dll
C:\Users\José Arcos\AppData\Local\Temp\msvcp80.dll
C:\Users\José Arcos\AppData\Local\Temp\msvcr80.dll
C:\Users\José Arcos\AppData\Local\Temp\proxy_vole2014474577154815514.dll
C:\Users\José Arcos\AppData\Local\Temp\raptrpatch.exe
C:\Users\José Arcos\AppData\Local\Temp\raptr_stub.exe
C:\Users\José Arcos\AppData\Local\Temp\rldfw64_s614.dll
C:\Users\José Arcos\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\José Arcos\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\José Arcos\AppData\Local\Temp\sonarinst.exe
C:\Users\José Arcos\AppData\Local\Temp\sqlite3.dll

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Reset Chrome...
Open Google Chrome, click on menu icon google-chrome-setting-icon.png which is located right side top of the google chrome.
 
Click "Settings" then "Show advanced settings" at the bottom of the screen.
 
Click "Reset browser settings" button.
 
Clear your cache and cookies
https://support.google.com/chromebook/answer/183083?hl=en
Select "From the beginning of time"

Restart Chrome.
===

If the problem persists please let me know the details so I can investigate further.

#5 askorin

askorin
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:35 PM

Posted 13 January 2016 - 12:19 PM

Sadly, the problem persists, I have popups all over my screen and I get redirected to other websites.The source of the ads seems to be something called "Constant Fun", but I cannot find it in my programs list or browser extensions. I will post the fixlog below:

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version:10-01-2015 01

Ran by José Arcos (2016-01-13 14:09:34) Run:1
Running from C:\Users\José Arcos\Desktop\Farbar
Loaded Profiles: José Arcos (Available Profiles: José Arcos)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
 
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
 
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  No File
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  No File
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
C:\Users\José Arcos\AppData\Local\Temp\130950542015793129.exe
C:\Users\José Arcos\AppData\Local\Temp\AMDCleanupUtility.exe
C:\Users\José Arcos\AppData\Local\Temp\Cleanup.dll
C:\Users\José Arcos\AppData\Local\Temp\ddu.exe
C:\Users\José Arcos\AppData\Local\Temp\difxapi.dll
C:\Users\José Arcos\AppData\Local\Temp\dllnt_dump.dll
C:\Users\José Arcos\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\José Arcos\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\José Arcos\AppData\Local\Temp\msvcm80.dll
C:\Users\José Arcos\AppData\Local\Temp\msvcp80.dll
C:\Users\José Arcos\AppData\Local\Temp\msvcr80.dll
C:\Users\José Arcos\AppData\Local\Temp\proxy_vole2014474577154815514.dll
C:\Users\José Arcos\AppData\Local\Temp\raptrpatch.exe
C:\Users\José Arcos\AppData\Local\Temp\raptr_stub.exe
C:\Users\José Arcos\AppData\Local\Temp\rldfw64_s614.dll
C:\Users\José Arcos\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\José Arcos\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\José Arcos\AppData\Local\Temp\sonarinst.exe
C:\Users\José Arcos\AppData\Local\Temp\sqlite3.dll
 
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending" => key removed successfully
HKCR\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => key not found. 
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced" => key removed successfully
HKCR\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => key not found. 
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing" => key removed successfully
HKCR\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => key not found. 
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. 
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending" => key removed successfully
HKCR\Wow6432Node\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => key not found. 
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced" => key removed successfully
HKCR\Wow6432Node\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => key not found. 
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing" => key removed successfully
HKCR\Wow6432Node\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => key not found. 
GPUZ => service removed successfully
wfpcapture => service removed successfully


#6 nasdaq

nasdaq

  • Malware Response Team
  • 39,541 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:12:35 PM

Posted 14 January 2016 - 07:40 AM

Remove Chrome using the the instructions on this page.
https://support.google.com/chrome/answer/95319?hl=en

Before you do Export your Bookmarks
Chrome will export your bookmarks as a HTML file, which you can then import into another browser.

If you want to save your passwords as well see here: http://www.intowindows.com/how-to-backup-saved-passwords-in-google-chrome-browser/

Re-install Chrome and the Bookmarks.
<<<>>>

If the problem persists please run this tool.

Lets check further.

You will need to temporarily disable your AV program so it does not interfere.
Info on how to disable your security applications How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides.

Download Zeok tool from here

When the download appears, save to the Desktop.
On the Desktop, right-click the Zoek.exe file and select: Run as Administrator
(Give it a few seconds to appear.)

Click the Options in bold the following options are available to you.
Select only the check boxes for the options in bold.
 

Running Processes
Installed Programs
Startup Information
FireFox look
Chrome Look
Recently created
Auto Clean


Do a Quick Scan
HijackThis log
Uninstall list
Shortcut Fix
Do a Deep Scan
Installer List
IE Default
Silent Runner
System Restore Info
Symlink Check
Reset Chrome
System Specs
Recently created
Empty Temp
Auto Clean



Now...
Close any open Browsers.
Click the Run script button, and wait. It takes a few minutes to run all the script.

When the tool finishes, the zoek-results.log is opened in Notepad.
The log is also found on the systemdrive, normally C:\
If a reboot is needed, the log is opened after the reboot.
Do
Please attach the zoek-results.log in your reply. It's probably too long to post.

How to:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
attachlogs.png

Attach the file.
Select the "Choose a File" navigate to the location of the File.
Click the file you wish to Attach.

Click the Add reply button.

Make sure you Enable your AV Program.

#7 askorin

askorin
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:35 PM

Posted 14 January 2016 - 12:27 PM

Reinstalling chrome seems to have fixed the problem! Thank you very much for your help!



#8 nasdaq

nasdaq

  • Malware Response Team
  • 39,541 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:12:35 PM

Posted 15 January 2016 - 08:37 AM

Glad we could help.


If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/
===

#9 nasdaq

nasdaq

  • Malware Response Team
  • 39,541 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:12:35 PM

Posted 21 January 2016 - 10:27 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users