What I was doing was looking over the CK scan log and copy and pasting all the lines that said crack on them to the small search bar in the bottom that appears when you push on "Start" and the files would show up and I would delete them. I honestly have no idea where the files themselves might be in my computer as I never had a specific folder for downloads.
SystemLook 30.07.11 by jpshortstuff
Log created at 12:20 on 06/02/2014 by Z
Administrator - Elevation successful
========== filefind ==========
Searching for "AutoKMS*"
C:\Windows\System32\Tasks\AutoKMS --a---- 2426 bytes [17:46 31/01/2013] [13:55 14/01/2014] B2BC231CDE08697786871C0846C08FB5
C:\_OTL\MovedFiles\02052014_140032\C_Windows\AutoKMS.ini --a---- 135 bytes [17:46 31/01/2013] [17:46 31/01/2013] 48A77273E8C545DCB70EEE3866CD2123
C:\_OTL\MovedFiles\02052014_140032\C_Windows\Tasks\AutoKMS.job --a---- 192 bytes [17:46 31/01/2013] [09:21 15/01/2014] 2C6E1DBBE76805DE040F2E1A3EF1BB35
Searching for "*crack*"
C:\Users\Z\AppData\Roaming\Microsoft\Windows\Recent\mIRC v7.22 + Crack-Serials [ChattChitto RG].lnk --a---- 1155 bytes [18:19 06/02/2014] [18:19 06/02/2014] 4F70A18E8BAD5BBEFF72CBFD397D5987
========== regfind ==========
Searching for "AutoKMS"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A99D13A-16E4-46A5-8EBE-F27CFA950FD7}]
"Path"="\AutoKMS"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS]
Searching for "crack"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1ae1b8d2_0]
@="{0.0.0.00000000}.{c8ee149c-82f5-465b-9a1f-c8d172aee503}|\Device\HarddiskVolume2\Users\Z\Downloads\flstudio_10.0_crack.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"a"="c:\program files (x86)\image-line\fl studio 10\plugins\fruity\effects\hardcore\presets\i cracked my tube!.hdprg\1"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"b"="c:\users\z\mirc v7.27 cracked-eat\mirc727.exe\1"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"c"="C:\Users\Z\MIRC v7.27 Cracked-EAT\Crack\1"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"d"="C:\Users\Z\AppData\Roaming\Microsoft\Windows\Recent\Crack.lnk\1"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"e"="C:\Users\Z\AppData\Roaming\uTorrent\mIRC v7.22 + Crack-Serials [ChattChitto RG].torrent\1"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\best-cracks.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crack-land.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crack-serial-keygen-online.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackloader.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cracks-keygens.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cracks-keygens.net]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cracks.me.uk]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cracks4u.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackszilla.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackundeground.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackweb.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackz.ws]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-crack.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\gotocrack.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\newcracks.com]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\newcracks.net]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.5\CRACK]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Help"="3 The System performance object consists of counters that apply to more than one instance of a component processors on the computer. 5 The Memory performance object consists of counters that describe the behavior of physical and virtual memory on the computer. Physical memory is the amount of random access memory on the computer. Virtual memory consists of the space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory. Excessive paging, a symptom of a memory shortage, can cause delays which interfere with all system processes. 7 % Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processor has an idle thread tha
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\CurrentLanguage]
"Help"="3 The System performance object consists of counters that apply to more than one instance of a component processors on the computer. 5 The Memory performance object consists of counters that describe the behavior of physical and virtual memory on the computer. Physical memory is the amount of random access memory on the computer. Virtual memory consists of the space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory. Excessive paging, a symptom of a memory shortage, can cause delays which interfere with all system processes. 7 % Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processor has an idl
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Help"="3 The System performance object consists of counters that apply to more than one instance of a component processors on the computer. 5 The Memory performance object consists of counters that describe the behavior of physical and virtual memory on the computer. Physical memory is the amount of random access memory on the computer. Virtual memory consists of the space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory. Excessive paging, a symptom of a memory shortage, can cause delays which interfere with all system processes. 7 % Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processor has an idl
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Perflib\CurrentLanguage]
"Help"="3 The System performance object consists of counters that apply to more than one instance of a component processors on the computer. 5 The Memory performance object consists of counters that describe the behavior of physical and virtual memory on the computer. Physical memory is the amount of random access memory on the computer. Virtual memory consists of the space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory. Excessive paging, a symptom of a memory shortage, can cause delays which interfere with all system processes. 7 % Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processo
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1ae1b8d2_0]
@="{0.0.0.00000000}.{c8ee149c-82f5-465b-9a1f-c8d172aee503}|\Device\HarddiskVolume2\Users\Z\Downloads\flstudio_10.0_crack.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"a"="c:\program files (x86)\image-line\fl studio 10\plugins\fruity\effects\hardcore\presets\i cracked my tube!.hdprg\1"
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"b"="c:\users\z\mirc v7.27 cracked-eat\mirc727.exe\1"
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"c"="C:\Users\Z\MIRC v7.27 Cracked-EAT\Crack\1"
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"d"="C:\Users\Z\AppData\Roaming\Microsoft\Windows\Recent\Crack.lnk\1"
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"e"="C:\Users\Z\AppData\Roaming\uTorrent\mIRC v7.22 + Crack-Serials [ChattChitto RG].torrent\1"
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\best-cracks.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crack-land.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crack-serial-keygen-online.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackloader.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cracks-keygens.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cracks-keygens.net]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cracks.me.uk]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cracks4u.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackszilla.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackundeground.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackweb.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crackz.ws]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-crack.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\gotocrack.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\newcracks.com]
[HKEY_USERS\S-1-5-21-893635891-571939354-3906648824-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\newcracks.net]
-= EOF =-
CKScanner 2.4 - Additional Security Risks - These are not necessarily bad
scanner sequence 3.MN.11.OFABT0
----- EOF -----
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2014
Ran by Z (administrator) on Z-PC on 06-02-2014 12:11:31
Running from C:\Users\Z\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisDSService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\Aqualab\namehelp\nssm.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\pcCMService.exe
() C:\Program Files (x86)\Aqualab\namehelp\namehelp.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtLED\RtLEDService.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtLED\RtLED.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
() C:\Users\Z\Downloads\SystemLook_x64.exe
() C:\Users\Z\Downloads\CKScanner.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [2598280 2010-03-29] (ELAN Microelectronics Corp.)
HKLM\...\Run: [UpdatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [111640 2009-09-30] ()
HKLM-x32\...\Run: [332BigDog] - C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [VitaKeyTSR] - C:\Program Files (x86)\EgisTec BioExcess\EgisTSR.exe [376176 2010-05-27] (Egis Technology Inc. )
HKLM-x32\...\Run: [VeriFaceManager] - C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [3122528 2011-03-14] (Lenovo)
HKLM-x32\...\Run: [UCam_Menu] - C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-03-02] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PrivitizeVPN] - C:\Program Files (x86)\PrivitizeVPN\PrivitizeVPN.exe [196784 2013-02-08] (OOO Industry)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [337432 2013-10-23] (Power Software Ltd)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-893635891-571939354-3906648824-1000\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-06] (SUPERAntiSpyware)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {B2F2CD68-F538-42E9-9456-6FA113ABB119} URL = http://search.yahoo....p={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: IEPwdBankBHO Class - {56CBB761-DA41-4E31-B270-B13B4B0A61D0} - C:\Program Files (x86)\EgisTec BioExcess\EgisIEPwdBank.dll (Egis Technology Inc. )
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF ProfilePath: C:\Users\Z\AppData\Roaming\Mozilla\Firefox\Profiles\3hutvwbm.default
FF NewTab: GOOGLE.COM
FF Homepage: hxxp://www.google.com/
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 - C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll No File
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 - C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\Z\AppData\Roaming\Mozilla\Firefox\Profiles\3hutvwbm.default\Extensions\staged [2014-02-05]
FF Extension: YouTube to MP3 Button - C:\Users\Z\AppData\Roaming\Mozilla\Firefox\Profiles\3hutvwbm.default\Extensions\flvto@hotger.com.xpi [2012-08-03]
FF Extension: Turn Off the Lights - C:\Users\Z\AppData\Roaming\Mozilla\Firefox\Profiles\3hutvwbm.default\Extensions\stefanvandamme@stefanvd.net.xpi [2013-11-18]
FF Extension: Adblock Plus - C:\Users\Z\AppData\Roaming\Mozilla\Firefox\Profiles\3hutvwbm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-07-22]
FF Extension: Tab Mix Plus - C:\Users\Z\AppData\Roaming\Mozilla\Firefox\Profiles\3hutvwbm.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2012-07-22]
FF Extension: DownThemAll! - C:\Users\Z\AppData\Roaming\Mozilla\Firefox\Profiles\3hutvwbm.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2013-02-13]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR Extension: (Google Docs) - C:\Users\Z\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-02]
CHR Extension: (Google Drive) - C:\Users\Z\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-02]
CHR Extension: (YouTube) - C:\Users\Z\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-02]
CHR Extension: (Google Search) - C:\Users\Z\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-02]
CHR Extension: (Google Wallet) - C:\Users\Z\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-02]
CHR Extension: (Gmail) - C:\Users\Z\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-02]
==================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2013-12-20] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2013-12-20] (BlueStack Systems, Inc.)
R2 EgisTec Data Security Service; C:\Program Files (x86)\EgisTec BioExcess\EgisDSService.exe [314736 2010-05-27] (Egis Technology Inc. )
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 namehelp; C:\Program Files (x86)\Aqualab\namehelp\nssm.exe [156672 2012-10-08] ()
R2 pcCMService64; C:\Program Files\Common Files\Motive\pcCMService.exe [460288 2012-11-15] (Alcatel-Lucent)
R2 RtLedService; C:\Program Files\Realtek\RtLED\RtLEDService.exe [311296 2010-02-05] (Realtek Semiconductor Corp.)
==================== Drivers (Whitelisted) ====================
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [114448 2013-12-20] (BlueStack Systems)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MREMP50; \??\C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MRESP50; \??\C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-06 12:06 - 2014-02-06 12:09 - 00026330 _____ () C:\Users\Z\Downloads\Addition.txt
2014-02-06 12:04 - 2014-02-06 12:11 - 00014720 _____ () C:\Users\Z\Downloads\FRST.txt
2014-02-06 12:00 - 2014-02-06 12:11 - 00000000 ____D () C:\FRST
2014-02-06 11:59 - 2014-02-06 11:59 - 02082304 _____ (Farbar) C:\Users\Z\Downloads\FRST64.exe
2014-02-06 09:12 - 2014-02-06 12:09 - 00000127 _____ () C:\Users\Z\Downloads\ckfiles.txt
2014-02-06 09:07 - 2014-02-06 12:11 - 00000356 _____ () C:\Users\Z\Downloads\SystemLook.txt
2014-02-06 08:10 - 2014-02-06 08:10 - 00468480 _____ () C:\Users\Z\Downloads\CKScanner.exe
2014-02-05 16:51 - 2014-02-05 16:51 - 00023701 _____ () C:\ComboFix.txt
2014-02-05 15:44 - 2014-02-05 16:51 - 00000000 ____D () C:\Qoobox
2014-02-05 15:44 - 2011-06-26 00:45 - 00256000 _____ () C:\windows\PEV.exe
2014-02-05 15:44 - 2010-11-07 11:20 - 00208896 _____ () C:\windows\MBR.exe
2014-02-05 15:44 - 2009-04-19 22:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-02-05 15:44 - 2000-08-30 18:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-02-05 15:44 - 2000-08-30 18:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-02-05 15:44 - 2000-08-30 18:00 - 00098816 _____ () C:\windows\sed.exe
2014-02-05 15:44 - 2000-08-30 18:00 - 00080412 _____ () C:\windows\grep.exe
2014-02-05 15:44 - 2000-08-30 18:00 - 00068096 _____ () C:\windows\zip.exe
2014-02-05 15:43 - 2014-02-05 16:48 - 00000000 ____D () C:\windows\erdnt
2014-02-05 15:40 - 2014-02-05 15:40 - 05180173 ____R (Swearware) C:\Users\Z\Downloads\ComboFix.exe
2014-02-05 14:19 - 2014-02-05 15:06 - 42248830 _____ () C:\Users\Z\Desktop\SystemLook.txt
2014-02-05 14:17 - 2014-02-05 14:17 - 00165376 _____ () C:\Users\Z\Downloads\SystemLook_x64.exe
2014-02-05 14:00 - 2014-02-05 14:00 - 00000000 ____D () C:\_OTL
2014-02-04 22:32 - 2014-02-04 22:32 - 00001295 _____ () C:\Users\Z\Desktop\JRT.txt
2014-02-04 22:21 - 2014-02-04 22:21 - 00000000 ____D () C:\windows\ERUNT
2014-02-04 22:20 - 2014-02-04 22:20 - 01037530 _____ (Thisisu) C:\Users\Z\Downloads\JRT.exe
2014-02-04 15:48 - 2014-02-04 16:12 - 00000000 ____D () C:\AdwCleaner
2014-02-04 15:47 - 2014-02-04 15:47 - 01166132 _____ () C:\Users\Z\Downloads\AdwCleaner.exe
2014-02-04 14:22 - 2014-02-04 14:22 - 00061482 _____ () C:\Users\Z\Downloads\Extras.Txt
2014-02-04 14:20 - 2014-02-05 14:44 - 00074838 _____ () C:\Users\Z\Downloads\OTL.Txt
2014-02-04 13:26 - 2014-02-04 13:53 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-02-04 13:26 - 2014-02-04 13:26 - 00119000 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-02-04 13:24 - 2014-02-04 13:53 - 00000000 ____D () C:\Users\Z\Desktop\mbar
2014-02-04 13:24 - 2014-02-04 13:24 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-02-04 13:23 - 2014-02-04 13:23 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Z\Downloads\mbar-1.07.0.1009.exe
2014-02-04 13:23 - 2014-02-04 13:23 - 00602112 _____ (OldTimer Tools) C:\Users\Z\Downloads\OTL.exe
2014-02-04 13:21 - 2014-02-04 13:22 - 00987425 _____ () C:\Users\Z\Downloads\SecurityCheck.exe
2014-02-02 16:11 - 2014-02-02 16:11 - 00625664 _____ () C:\Users\Z\Downloads\dds(1).scr
2014-02-02 16:10 - 2014-02-02 16:10 - 00625664 _____ () C:\Users\Z\Downloads\dds.scr
2014-02-02 15:23 - 2014-02-03 17:50 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-02 15:20 - 2014-02-06 11:41 - 00000888 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-02 15:20 - 2014-02-06 07:45 - 00000502 _____ () C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 87e12a3c-de15-40b6-a694-38fb9f0dbc8a.job
2014-02-02 15:20 - 2014-02-06 07:45 - 00000502 _____ () C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 43c95507-6eb6-4e1f-bdfe-ee76624bd54c.job
2014-02-02 15:20 - 2014-02-05 16:46 - 00000884 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-02 15:20 - 2014-02-02 15:36 - 00003884 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-02 15:20 - 2014-02-02 15:36 - 00003632 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-02 15:20 - 2014-02-02 15:24 - 00000000 ____D () C:\Users\Z\AppData\Local\Google
2014-02-02 15:20 - 2014-02-02 15:24 - 00000000 ____D () C:\Program Files (x86)\Google
2014-02-02 15:20 - 2014-02-02 15:20 - 00003560 _____ () C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 43c95507-6eb6-4e1f-bdfe-ee76624bd54c
2014-02-02 15:20 - 2014-02-02 15:20 - 00003486 _____ () C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 87e12a3c-de15-40b6-a694-38fb9f0dbc8a
2014-02-02 15:20 - 2014-02-02 15:20 - 00001808 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2014-02-02 15:20 - 2014-02-02 15:20 - 00000000 ____D () C:\Users\Z\AppData\Roaming\SUPERAntiSpyware.com
2014-02-02 15:20 - 2014-02-02 15:20 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-02-02 15:20 - 2014-02-02 15:20 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-02-02 15:17 - 2014-02-02 15:19 - 17939320 _____ (SUPERAntiSpyware) C:\Users\Z\Downloads\SUPERAntiSpywarePro.exe
2014-02-01 16:09 - 2014-02-01 16:09 - 00002571 _____ () C:\Users\Z\Desktop\Rosetta Stone Version 3.lnk
2014-02-01 16:08 - 2014-02-03 20:07 - 00000000 ____D () C:\ProgramData\Rosetta Stone
2014-02-01 16:08 - 2014-02-01 16:08 - 00000000 ____D () C:\Program Files (x86)\Rosetta Stone
2014-02-01 16:05 - 2014-02-01 16:05 - 00000000 ____D () C:\Users\Z\AppData\Roaming\PowerISO
2014-02-01 16:01 - 2014-02-01 16:01 - 00001007 _____ () C:\Users\Public\Desktop\PowerISO.lnk
2014-02-01 16:00 - 2014-02-01 16:01 - 00000000 ____D () C:\Program Files (x86)\PowerISO
2014-02-01 16:00 - 2013-10-23 08:11 - 00129944 _____ (Power Software Ltd) C:\windows\system32\Drivers\scdemu.sys
2014-01-26 20:44 - 2014-01-26 20:46 - 00000000 ____D () C:\Users\Z\Downloads\Megadeth
2014-01-26 20:41 - 2014-01-26 20:42 - 00000000 ____D () C:\Users\Z\Downloads\Metallica
2014-01-26 20:39 - 2014-01-26 20:39 - 00000000 ____D () C:\Users\Z\Downloads\Iron Maiden-Greatest Hits[www.lokotorrents.com][mp3]
2014-01-21 22:26 - 2014-01-21 22:27 - 00279016 _____ () C:\windows\Minidump\012114-25053-01.dmp
2014-01-21 22:26 - 2014-01-21 22:26 - 266548433 _____ () C:\windows\MEMORY.DMP
2014-01-21 22:26 - 2014-01-21 22:26 - 00000000 ____D () C:\windows\Minidump
2014-01-17 12:57 - 2014-02-01 16:50 - 00000000 ____D () C:\Users\Z\Downloads\Rosetta Stone V3 - English (American)
2014-01-15 17:41 - 2014-01-15 17:41 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-01-15 17:40 - 2014-01-15 17:41 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-15 17:40 - 2014-01-15 17:41 - 00000000 ____D () C:\Program Files\iTunes
2014-01-15 17:40 - 2014-01-15 17:41 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-01-15 17:40 - 2014-01-15 17:40 - 00000000 ____D () C:\Program Files\iPod
2014-01-15 17:05 - 2014-01-15 17:05 - 00000000 ____D () C:\windows\System32\Tasks\Apple
2014-01-15 17:05 - 2014-01-15 17:05 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-01-15 17:04 - 2014-01-15 17:04 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-01-15 17:04 - 2014-01-15 17:04 - 00000000 ____D () C:\Program Files\Bonjour
2014-01-15 17:04 - 2014-01-15 17:04 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-01-15 17:00 - 2014-01-15 17:00 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Malwarebytes
2014-01-15 16:59 - 2014-01-15 17:01 - 79225752 _____ (Apple Inc.) C:\Users\Aris 2\Downloads\iTunes64Setup.exe
2014-01-15 03:21 - 2014-02-05 16:02 - 00404990 _____ () C:\windows\PFRO.log
2014-01-15 03:21 - 2014-02-05 16:02 - 00001624 _____ () C:\windows\setupact.log
2014-01-15 03:21 - 2014-01-15 03:21 - 00000000 _____ () C:\windows\setuperr.log
2014-01-15 03:01 - 2014-02-06 07:48 - 00089517 _____ () C:\windows\IE11_main.log
2014-01-15 02:19 - 2013-11-26 19:41 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2014-01-15 02:19 - 2013-11-26 19:41 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2014-01-15 02:19 - 2013-11-26 19:41 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2014-01-15 02:19 - 2013-11-26 19:41 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2014-01-15 02:19 - 2013-11-26 19:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2014-01-15 02:19 - 2013-11-26 19:41 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2014-01-15 02:19 - 2013-11-26 19:41 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2014-01-15 02:19 - 2013-11-26 05:40 - 00376768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2014-01-15 02:19 - 2013-11-26 04:32 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-01-14 17:24 - 2014-01-14 17:24 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Best Buy pc app
2014-01-14 15:07 - 2014-01-14 15:07 - 00001354 _____ () C:\Users\Z\Desktop\CopyTrans Control Center.lnk
2014-01-14 15:07 - 2014-01-14 15:07 - 00000000 ____D () C:\Users\Z\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Suite
2014-01-14 15:05 - 2014-01-14 15:15 - 00000000 ____D () C:\Users\Z\AppData\Roaming\WindSolutions
2014-01-14 15:05 - 2014-01-14 15:10 - 00000000 ____D () C:\ProgramData\WindSolutions
2014-01-14 15:05 - 2014-01-14 15:05 - 04473792 _____ (WindSolutions) C:\Users\Z\Downloads\Install_CopyTrans_Suite.exe
2014-01-14 14:08 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\windows\system32\Drivers\GEARAspiWDM.sys
2014-01-14 09:15 - 2014-01-14 09:17 - 100400976 _____ (Apple Inc.) C:\Users\Z\Downloads\iTunes64Setup(1).exe
2014-01-14 08:07 - 2014-01-14 08:07 - 00000000 ____D () C:\Users\Z\Documents\Freemake
2014-01-14 07:54 - 2014-01-14 07:55 - 00000000 ____D () C:\windows\pss
2014-01-13 20:38 - 2014-01-13 20:38 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Macromedia
2014-01-13 20:38 - 2014-01-13 20:38 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Macromedia
2014-01-13 20:27 - 2012-07-25 12:03 - 00016896 _____ () C:\windows\system32\sasnative64.exe
2014-01-13 20:25 - 2014-01-13 20:25 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Alerts
2014-01-13 20:14 - 2014-01-13 20:14 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Mozilla
2014-01-13 20:14 - 2014-01-13 20:14 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Mozilla
2014-01-13 20:05 - 2014-01-13 20:05 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Apple
2014-01-13 19:52 - 2014-01-15 17:42 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Apple Computer
2014-01-13 19:52 - 2014-01-13 19:52 - 00112872 _____ () C:\Users\Aris 2\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-13 19:52 - 2014-01-13 19:52 - 00000398 _____ () C:\Users\Aris 2\Desktop\pc app.appref-ms
2014-01-13 19:52 - 2014-01-13 19:52 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy
2014-01-13 19:52 - 2014-01-13 19:52 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Intel Corporation
2014-01-13 19:52 - 2014-01-13 19:52 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Apple Computer
2014-01-13 19:51 - 2014-01-20 18:57 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Deployment
2014-01-13 19:51 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\DAEMON Tools Pro
2014-01-13 19:51 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\EgisTec IPS
2014-01-13 19:51 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\BioExcess
2014-01-13 19:51 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Apps\2.0
2014-01-13 19:49 - 2014-01-13 19:49 - 00001413 _____ () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-13 19:49 - 2014-01-13 19:49 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Adobe
2014-01-13 19:48 - 2014-01-13 19:50 - 00000000 ___RD () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-13 19:47 - 2014-01-13 19:47 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\VirtualStore
2014-01-13 19:46 - 2014-02-04 16:12 - 00000000 ___RD () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-13 19:46 - 2014-01-13 19:51 - 00002425 _____ () C:\Users\Aris 2\Desktop\CyberLink YouCam.lnk
2014-01-13 19:46 - 2014-01-13 19:51 - 00002086 _____ () C:\Users\Aris 2\Desktop\OneKey Recovery.lnk
2014-01-13 19:46 - 2014-01-13 19:51 - 00001118 _____ () C:\Users\Aris 2\Desktop\Cyberlink Power2Go.lnk
2014-01-13 19:46 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-01-13 19:46 - 2014-01-13 19:48 - 00000000 ____D () C:\Users\Aris 2
2014-01-13 19:46 - 2014-01-13 19:46 - 00000020 ___SH () C:\Users\Aris 2\ntuser.ini
2014-01-13 19:46 - 2013-03-19 07:03 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\TuneUp Software
2014-01-13 19:46 - 2009-07-13 22:54 - 00000000 ___RD () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-01-13 19:46 - 2009-07-13 22:49 - 00000000 ___RD () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-01-12 22:14 - 2014-01-12 22:14 - 00000000 ____D () C:\Users\Z\Downloads\The Very Best Of Rammstein - krazykc
2014-01-12 19:24 - 2014-01-12 19:25 - 00000000 ____D () C:\Users\Z\Desktop\965TOGQJ
2014-01-10 10:20 - 2014-01-14 08:00 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-01-10 10:20 - 2014-01-10 10:20 - 16600426 _____ () C:\Users\Z\Downloads\Instagram_(7labsOfficial.com).apk
2014-01-10 10:19 - 2014-01-10 10:25 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-01-10 10:19 - 2014-01-10 10:20 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-01-10 10:15 - 2014-01-10 10:15 - 10245808 _____ (BlueStack Systems Inc.) C:\Users\Z\Downloads\BlueStacks-SplitInstaller_native.exe
2014-01-07 09:22 - 2014-01-07 09:22 - 00000000 ____D () C:\Users\Z\Downloads\Legend of Zelda, The - Ocarina of Time (USA)
2014-01-07 09:21 - 2014-01-07 09:21 - 26999427 _____ () C:\Users\Z\Downloads\Legend of Zelda, The - Ocarina of Time (USA).zip
2014-01-07 09:19 - 2014-01-07 09:19 - 00001067 _____ () C:\Users\Z\Desktop\Project 64.lnk
==================== One Month Modified Files and Folders =======
2014-02-06 12:12 - 2014-02-06 12:04 - 00014720 _____ () C:\Users\Z\Downloads\FRST.txt
2014-02-06 12:11 - 2014-02-06 12:00 - 00000000 ____D () C:\FRST
2014-02-06 12:11 - 2014-02-06 09:07 - 00000356 _____ () C:\Users\Z\Downloads\SystemLook.txt
2014-02-06 12:09 - 2014-02-06 12:06 - 00026330 _____ () C:\Users\Z\Downloads\Addition.txt
2014-02-06 12:09 - 2014-02-06 09:12 - 00000127 _____ () C:\Users\Z\Downloads\ckfiles.txt
2014-02-06 12:08 - 2011-03-14 12:26 - 01871315 _____ () C:\windows\WindowsUpdate.log
2014-02-06 12:05 - 2009-07-13 22:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-06 12:05 - 2009-07-13 22:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-06 11:59 - 2014-02-06 11:59 - 02082304 _____ (Farbar) C:\Users\Z\Downloads\FRST64.exe
2014-02-06 11:41 - 2014-02-02 15:20 - 00000888 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-06 11:21 - 2012-07-22 20:34 - 00000000 ____D () C:\Users\Z\AppData\Local\Apps\2.0
2014-02-06 11:19 - 2012-07-22 20:33 - 00000000 ____D () C:\Users\Z
2014-02-06 10:41 - 2011-03-14 13:24 - 04130720 _____ () C:\FaceProv.log
2014-02-06 09:58 - 2009-07-13 21:20 - 00000000 ____D () C:\windows\tracing
2014-02-06 08:10 - 2014-02-06 08:10 - 00468480 _____ () C:\Users\Z\Downloads\CKScanner.exe
2014-02-06 07:48 - 2014-01-15 03:01 - 00089517 _____ () C:\windows\IE11_main.log
2014-02-06 07:45 - 2014-02-02 15:20 - 00000502 _____ () C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 87e12a3c-de15-40b6-a694-38fb9f0dbc8a.job
2014-02-06 07:45 - 2014-02-02 15:20 - 00000502 _____ () C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 43c95507-6eb6-4e1f-bdfe-ee76624bd54c.job
2014-02-05 16:51 - 2014-02-05 16:51 - 00023701 _____ () C:\ComboFix.txt
2014-02-05 16:51 - 2014-02-05 15:44 - 00000000 ____D () C:\Qoobox
2014-02-05 16:51 - 2009-07-13 21:20 - 00000000 __RHD () C:\Users\Default
2014-02-05 16:48 - 2014-02-05 15:43 - 00000000 ____D () C:\windows\erdnt
2014-02-05 16:46 - 2014-02-02 15:20 - 00000884 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-05 16:46 - 2009-07-13 20:34 - 00000215 _____ () C:\windows\system.ini
2014-02-05 16:02 - 2014-01-15 03:21 - 00404990 _____ () C:\windows\PFRO.log
2014-02-05 16:02 - 2014-01-15 03:21 - 00001624 _____ () C:\windows\setupact.log
2014-02-05 16:02 - 2012-12-17 16:08 - 00065536 _____ () C:\windows\system32\Ikeext.etl
2014-02-05 16:02 - 2009-07-13 23:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-02-05 16:01 - 2009-07-13 20:34 - 74973184 _____ () C:\windows\system32\config\SOFTWARE.bak
2014-02-05 16:01 - 2009-07-13 20:34 - 16515072 _____ () C:\windows\system32\config\SYSTEM.bak
2014-02-05 16:01 - 2009-07-13 20:34 - 00262144 _____ () C:\windows\system32\config\SECURITY.bak
2014-02-05 16:01 - 2009-07-13 20:34 - 00262144 _____ () C:\windows\system32\config\SAM.bak
2014-02-05 16:01 - 2009-07-13 20:34 - 00262144 _____ () C:\windows\system32\config\DEFAULT.bak
2014-02-05 15:40 - 2014-02-05 15:40 - 05180173 ____R (Swearware) C:\Users\Z\Downloads\ComboFix.exe
2014-02-05 15:06 - 2014-02-05 14:19 - 42248830 _____ () C:\Users\Z\Desktop\SystemLook.txt
2014-02-05 14:44 - 2014-02-04 14:20 - 00074838 _____ () C:\Users\Z\Downloads\OTL.Txt
2014-02-05 14:17 - 2014-02-05 14:17 - 00165376 _____ () C:\Users\Z\Downloads\SystemLook_x64.exe
2014-02-05 14:13 - 2011-03-14 13:14 - 00000000 ____D () C:\ProgramData\VeriFace
2014-02-05 14:08 - 2013-12-19 22:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-05 14:00 - 2014-02-05 14:00 - 00000000 ____D () C:\_OTL
2014-02-04 22:32 - 2014-02-04 22:32 - 00001295 _____ () C:\Users\Z\Desktop\JRT.txt
2014-02-04 22:24 - 2011-03-14 13:15 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-04 22:24 - 2011-03-14 13:15 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-04 22:21 - 2014-02-04 22:21 - 00000000 ____D () C:\windows\ERUNT
2014-02-04 22:20 - 2014-02-04 22:20 - 01037530 _____ (Thisisu) C:\Users\Z\Downloads\JRT.exe
2014-02-04 16:12 - 2014-02-04 15:48 - 00000000 ____D () C:\AdwCleaner
2014-02-04 16:12 - 2014-01-13 19:46 - 00000000 ___RD () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-04 15:47 - 2014-02-04 15:47 - 01166132 _____ () C:\Users\Z\Downloads\AdwCleaner.exe
2014-02-04 14:22 - 2014-02-04 14:22 - 00061482 _____ () C:\Users\Z\Downloads\Extras.Txt
2014-02-04 14:02 - 2012-09-17 15:01 - 00000000 ____D () C:\Users\Z\AppData\Roaming\foobar2000
2014-02-04 13:53 - 2014-02-04 13:26 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-02-04 13:53 - 2014-02-04 13:24 - 00000000 ____D () C:\Users\Z\Desktop\mbar
2014-02-04 13:26 - 2014-02-04 13:26 - 00119000 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-02-04 13:24 - 2014-02-04 13:24 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-02-04 13:23 - 2014-02-04 13:23 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Z\Downloads\mbar-1.07.0.1009.exe
2014-02-04 13:23 - 2014-02-04 13:23 - 00602112 _____ (OldTimer Tools) C:\Users\Z\Downloads\OTL.exe
2014-02-04 13:22 - 2014-02-04 13:21 - 00987425 _____ () C:\Users\Z\Downloads\SecurityCheck.exe
2014-02-03 22:13 - 2012-07-22 22:37 - 00000000 ____D () C:\Users\Z\AppData\Roaming\mIRC
2014-02-03 20:07 - 2014-02-01 16:08 - 00000000 ____D () C:\ProgramData\Rosetta Stone
2014-02-03 17:50 - 2014-02-02 15:23 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-02 16:11 - 2014-02-02 16:11 - 00625664 _____ () C:\Users\Z\Downloads\dds(1).scr
2014-02-02 16:10 - 2014-02-02 16:10 - 00625664 _____ () C:\Users\Z\Downloads\dds.scr
2014-02-02 15:36 - 2014-02-02 15:20 - 00003884 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-02 15:36 - 2014-02-02 15:20 - 00003632 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-02 15:24 - 2014-02-02 15:20 - 00000000 ____D () C:\Users\Z\AppData\Local\Google
2014-02-02 15:24 - 2014-02-02 15:20 - 00000000 ____D () C:\Program Files (x86)\Google
2014-02-02 15:20 - 2014-02-02 15:20 - 00003560 _____ () C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 43c95507-6eb6-4e1f-bdfe-ee76624bd54c
2014-02-02 15:20 - 2014-02-02 15:20 - 00003486 _____ () C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 87e12a3c-de15-40b6-a694-38fb9f0dbc8a
2014-02-02 15:20 - 2014-02-02 15:20 - 00001808 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2014-02-02 15:20 - 2014-02-02 15:20 - 00000000 ____D () C:\Users\Z\AppData\Roaming\SUPERAntiSpyware.com
2014-02-02 15:20 - 2014-02-02 15:20 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-02-02 15:20 - 2014-02-02 15:20 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-02-02 15:19 - 2014-02-02 15:17 - 17939320 _____ (SUPERAntiSpyware) C:\Users\Z\Downloads\SUPERAntiSpywarePro.exe
2014-02-01 16:50 - 2014-01-17 12:57 - 00000000 ____D () C:\Users\Z\Downloads\Rosetta Stone V3 - English (American)
2014-02-01 16:26 - 2012-07-27 20:07 - 00000000 ____D () C:\Users\Z\AppData\Roaming\uTorrent
2014-02-01 16:09 - 2014-02-01 16:09 - 00002571 _____ () C:\Users\Z\Desktop\Rosetta Stone Version 3.lnk
2014-02-01 16:08 - 2014-02-01 16:08 - 00000000 ____D () C:\Program Files (x86)\Rosetta Stone
2014-02-01 16:05 - 2014-02-01 16:05 - 00000000 ____D () C:\Users\Z\AppData\Roaming\PowerISO
2014-02-01 16:01 - 2014-02-01 16:01 - 00001007 _____ () C:\Users\Public\Desktop\PowerISO.lnk
2014-02-01 16:01 - 2014-02-01 16:00 - 00000000 ____D () C:\Program Files (x86)\PowerISO
2014-01-28 18:14 - 2009-07-13 23:13 - 00726444 _____ () C:\windows\system32\PerfStringBackup.INI
2014-01-26 20:46 - 2014-01-26 20:44 - 00000000 ____D () C:\Users\Z\Downloads\Megadeth
2014-01-26 20:42 - 2014-01-26 20:41 - 00000000 ____D () C:\Users\Z\Downloads\Metallica
2014-01-26 20:39 - 2014-01-26 20:39 - 00000000 ____D () C:\Users\Z\Downloads\Iron Maiden-Greatest Hits[www.lokotorrents.com][mp3]
2014-01-21 22:27 - 2014-01-21 22:26 - 00279016 _____ () C:\windows\Minidump\012114-25053-01.dmp
2014-01-21 22:26 - 2014-01-21 22:26 - 266548433 _____ () C:\windows\MEMORY.DMP
2014-01-21 22:26 - 2014-01-21 22:26 - 00000000 ____D () C:\windows\Minidump
2014-01-20 18:57 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Deployment
2014-01-15 17:42 - 2014-01-13 19:52 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Apple Computer
2014-01-15 17:41 - 2014-01-15 17:41 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-01-15 17:41 - 2014-01-15 17:40 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-15 17:41 - 2014-01-15 17:40 - 00000000 ____D () C:\Program Files\iTunes
2014-01-15 17:41 - 2014-01-15 17:40 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-01-15 17:40 - 2014-01-15 17:40 - 00000000 ____D () C:\Program Files\iPod
2014-01-15 17:05 - 2014-01-15 17:05 - 00000000 ____D () C:\windows\System32\Tasks\Apple
2014-01-15 17:05 - 2014-01-15 17:05 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-01-15 17:04 - 2014-01-15 17:04 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-01-15 17:04 - 2014-01-15 17:04 - 00000000 ____D () C:\Program Files\Bonjour
2014-01-15 17:04 - 2014-01-15 17:04 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-01-15 17:01 - 2014-01-15 16:59 - 79225752 _____ (Apple Inc.) C:\Users\Aris 2\Downloads\iTunes64Setup.exe
2014-01-15 17:00 - 2014-01-15 17:00 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Malwarebytes
2014-01-15 03:21 - 2014-01-15 03:21 - 00000000 _____ () C:\windows\setuperr.log
2014-01-15 03:21 - 2012-07-22 22:40 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-01-15 03:21 - 2009-07-13 22:45 - 00430560 _____ () C:\windows\system32\FNTCACHE.DAT
2014-01-14 17:24 - 2014-01-14 17:24 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Best Buy pc app
2014-01-14 15:15 - 2014-01-14 15:05 - 00000000 ____D () C:\Users\Z\AppData\Roaming\WindSolutions
2014-01-14 15:10 - 2014-01-14 15:05 - 00000000 ____D () C:\ProgramData\WindSolutions
2014-01-14 15:07 - 2014-01-14 15:07 - 00001354 _____ () C:\Users\Z\Desktop\CopyTrans Control Center.lnk
2014-01-14 15:07 - 2014-01-14 15:07 - 00000000 ____D () C:\Users\Z\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Suite
2014-01-14 15:05 - 2014-01-14 15:05 - 04473792 _____ (WindSolutions) C:\Users\Z\Downloads\Install_CopyTrans_Suite.exe
2014-01-14 09:17 - 2014-01-14 09:15 - 100400976 _____ (Apple Inc.) C:\Users\Z\Downloads\iTunes64Setup(1).exe
2014-01-14 08:18 - 2009-07-29 01:00 - 00000000 ____D () C:\windows\Panther
2014-01-14 08:15 - 2012-08-26 21:24 - 00000000 ____D () C:\Users\Z\AppData\Roaming\Skype
2014-01-14 08:15 - 2012-08-26 21:05 - 00000000 ____D () C:\ProgramData\Skype
2014-01-14 08:09 - 2012-10-07 18:53 - 00000000 ____D () C:\Users\Z\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2014-01-14 08:09 - 2012-10-07 18:50 - 00000000 ____D () C:\Program Files (x86)\Image-Line
2014-01-14 08:08 - 2012-07-27 20:31 - 00000000 ____D () C:\ProgramData\ImTOO
2014-01-14 08:07 - 2014-01-14 08:07 - 00000000 ____D () C:\Users\Z\Documents\Freemake
2014-01-14 08:07 - 2013-03-18 19:33 - 00000000 ____D () C:\ProgramData\Freemake
2014-01-14 08:07 - 2013-03-18 19:32 - 00000000 ____D () C:\Program Files (x86)\Freemake
2014-01-14 08:01 - 2013-01-31 08:47 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Pro
2014-01-14 08:00 - 2014-01-10 10:20 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-01-14 07:58 - 2011-03-14 13:09 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-01-14 07:55 - 2014-01-14 07:54 - 00000000 ____D () C:\windows\pss
2014-01-14 07:55 - 2013-05-22 14:19 - 00002766 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC
2014-01-14 07:55 - 2013-01-31 11:46 - 00002426 _____ () C:\windows\System32\Tasks\AutoKMS
2014-01-14 07:55 - 2012-08-26 21:16 - 00003158 _____ () C:\windows\System32\Tasks\{E3E2BE91-13D0-4651-9B98-CD47424E0C5C}
2014-01-14 07:55 - 2012-08-26 21:08 - 00003158 _____ () C:\windows\System32\Tasks\{70DA2957-F89B-4D22-AD67-FE0213EB0683}
2014-01-14 07:55 - 2012-07-22 22:40 - 00003770 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-01-13 20:38 - 2014-01-13 20:38 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Macromedia
2014-01-13 20:38 - 2014-01-13 20:38 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Macromedia
2014-01-13 20:25 - 2014-01-13 20:25 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Alerts
2014-01-13 20:14 - 2014-01-13 20:14 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Mozilla
2014-01-13 20:14 - 2014-01-13 20:14 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Mozilla
2014-01-13 20:05 - 2014-01-13 20:05 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Apple
2014-01-13 19:52 - 2014-01-13 19:52 - 00112872 _____ () C:\Users\Aris 2\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-13 19:52 - 2014-01-13 19:52 - 00000398 _____ () C:\Users\Aris 2\Desktop\pc app.appref-ms
2014-01-13 19:52 - 2014-01-13 19:52 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy
2014-01-13 19:52 - 2014-01-13 19:52 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Intel Corporation
2014-01-13 19:52 - 2014-01-13 19:52 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Apple Computer
2014-01-13 19:51 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\DAEMON Tools Pro
2014-01-13 19:51 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\EgisTec IPS
2014-01-13 19:51 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\BioExcess
2014-01-13 19:51 - 2014-01-13 19:51 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\Apps\2.0
2014-01-13 19:51 - 2014-01-13 19:46 - 00002425 _____ () C:\Users\Aris 2\Desktop\CyberLink YouCam.lnk
2014-01-13 19:51 - 2014-01-13 19:46 - 00002086 _____ () C:\Users\Aris 2\Desktop\OneKey Recovery.lnk
2014-01-13 19:51 - 2014-01-13 19:46 - 00001118 _____ () C:\Users\Aris 2\Desktop\Cyberlink Power2Go.lnk
2014-01-13 19:51 - 2014-01-13 19:46 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-01-13 19:50 - 2014-01-13 19:48 - 00000000 ___RD () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-13 19:49 - 2014-01-13 19:49 - 00001413 _____ () C:\Users\Aris 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-13 19:49 - 2014-01-13 19:49 - 00000000 ____D () C:\Users\Aris 2\AppData\Roaming\Adobe
2014-01-13 19:48 - 2014-01-13 19:46 - 00000000 ____D () C:\Users\Aris 2
2014-01-13 19:47 - 2014-01-13 19:47 - 00000000 ____D () C:\Users\Aris 2\AppData\Local\VirtualStore
2014-01-13 19:46 - 2014-01-13 19:46 - 00000020 ___SH () C:\Users\Aris 2\ntuser.ini
2014-01-12 22:14 - 2014-01-12 22:14 - 00000000 ____D () C:\Users\Z\Downloads\The Very Best Of Rammstein - krazykc
2014-01-12 19:25 - 2014-01-12 19:24 - 00000000 ____D () C:\Users\Z\Desktop\965TOGQJ
2014-01-12 19:17 - 2012-07-25 08:57 - 00000000 ____D () C:\Users\Z\AppData\Local\Apple Computer
2014-01-10 10:25 - 2014-01-10 10:19 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-01-10 10:20 - 2014-01-10 10:20 - 16600426 _____ () C:\Users\Z\Downloads\Instagram_(7labsOfficial.com).apk
2014-01-10 10:20 - 2014-01-10 10:19 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-01-10 10:20 - 2009-07-13 21:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-01-10 10:15 - 2014-01-10 10:15 - 10245808 _____ (BlueStack Systems Inc.) C:\Users\Z\Downloads\BlueStacks-SplitInstaller_native.exe
2014-01-07 09:23 - 2014-01-01 14:48 - 00000000 ____D () C:\Users\Z\Downloads\Legend of Zelda, The - Majora's Mask (USA)
2014-01-07 09:22 - 2014-01-07 09:22 - 00000000 ____D () C:\Users\Z\Downloads\Legend of Zelda, The - Ocarina of Time (USA)
2014-01-07 09:21 - 2014-01-07 09:21 - 26999427 _____ () C:\Users\Z\Downloads\Legend of Zelda, The - Ocarina of Time (USA).zip
2014-01-07 09:19 - 2014-01-07 09:19 - 00001067 _____ () C:\Users\Z\Desktop\Project 64.lnk
2014-01-07 09:19 - 2012-07-27 20:43 - 00000000 ____D () C:\Users\Z\Desktop\dad
Files to move or delete:
====================
C:\Users\Z\Setup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-29 00:38
==================== End Of Log ============================