Zoek.exe v5.0.0.0 Updated 26-11-2014
Tool run by abdullah on Thu 11/27/2014 at 6:10:37.85.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\abdullah\Desktop\zoek.com [Scan all users] [Checkboxes used]
==== Older Logs ======================
C:\zoek-results2014-11-25-114409.log 4263 bytes
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Running Processes ======================
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Windows\system32\ntvdm.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe
c:\ProgramData\SolidWorks Electrical\MSSQL11.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\remotesolverdispatcherservice.exe
C:\Program Files\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\dispatcher.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe
C:\Program Files\Common Files\Research In Motion\nginx\nginx.exe
C:\Program Files\Common Files\Research In Motion\nginx\nginx.exe
C:\Windows\system32\conhost.exe
C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
==== Deleting Services ======================
==== System Specs ======================
Windows: Windows XP Professional Service Pack 2 (Build 2600)
Memory (RAM): 2039 MB
CPU Info: Intel(R) Pentium(R) M processor 1.73GHz
CPU Speed: 1740.1 MHz
Sound Card: Speakers (Realtek High Definiti |
Realtek Digital Output (Realtek |
Display Adapters: Standard VGA Graphics Adapter | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver
Monitors: 1x; Generic PnP Monitor |
Screen Resolution: 1024 X 768 - 32 bit
Network: Network Present
Network Adapters: BlackBerry Virtual Private Network | Intel(R) PRO/Wireless 2200BG Network Connection | Realtek RTL8139/810x Family Fast Ethernet NIC
CD / DVD Drives: 1x (E: | ) E: PIONEER DVD-RW DVR-K16RA
Ports: COM3 LPT Port NOT Present.
Mouse: 2 Button Mouse Present
Hard Disks: C: 31.5GB | D: 24.4GB
Hard Disks - Free: C: 1.2GB | D: 11.5GB
Manufacturer *: Acer
BIOS Info: AT/AT COMPATIBLE | 09/03/05 | ACRSYS - 6040000
Time Zone: Arab Standard Time
Motherboard *: Acer, Inc. LuganoII
Country: United States
Language: ENU
==== System Specs (Software) ======================
Anti-Virus: avast! Antivirus On-access scanning disabled (Outdated)
Anti-Spyware: Windows Defender disabled (Outdated)
Anti-Spyware: avast! Antivirus disabled (Outdated)
Firewall: avast! Antivirus disabled
Default Browser: Firefox 33.1
Internet Explorer version: 8.0.7601.17514
Mozilla Firefox version: 33.1 (x86 en-US)
Google Chrome version: 39.0.2171.71
Flash Player version: 15.0.0.223
==== Files Recently Created / Modified ======================
====== C:\Windows ====
2014-11-13 05:19:03 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Windows\eDrawingOfficeAutomator.INI
2014-11-12 06:59:34 B59EF013D567E5746F1DEE2565F747ED 43152 ----a-w- C:\Windows\avastSS.scr
2014-11-11 17:17:23 CE87062E62094A1788F155968C6C11B7 1698408 ----a-w- C:\Windows\RtlExUpd.dll
2014-11-11 04:24:35 8AA1EEA748FD13559209CAD05C2FEC0D 1078 ----a-w- C:\Windows\HELP.ICO
2014-11-11 04:24:34 B32AFABA92BD361DB7FC6FF2CD21EBAC 874 ----a-w- C:\Windows\WINHELP.INI
2014-11-11 04:24:34 52ABCED54E43B884E337564171BB464B 85 ----a-w- C:\Windows\TDW.INI
2014-11-11 04:24:34 430C0B509EA1B4B862FBEEF26044591C 499 ----a-w- C:\Windows\BDE.INI
2014-11-11 04:24:34 0445A34E84EF3AE55AB46A57ED7D1C4B 113 ----a-w- C:\Windows\BCW5.INI
2014-11-11 04:24:33 E17C2D2BE9A43014BEE9C0B35AC9B8D9 91136 ----a-w- C:\Windows\BC5RMV.EXE
2014-11-11 04:24:33 A7F6AA2196E2ED4C4E1496FBFF8B474B 586 ----a-w- C:\Windows\owl.ini
2014-11-11 03:17:35 163A95975E1D8819E653AA3E961371CA 51200 ----a-w- C:\Windows\twain_32.dll
2014-11-11 03:17:01 40D777B7A95E00593EB1568C68514493 2616320 ----a-w- C:\Windows\explorer.exe
2014-11-11 03:16:18 DBD14D0DB0382DFE96D7B5007DDD5ABE 65024 ----a-w- C:\Windows\bfsvc.exe
====== C:\Users\abdullah\AppData\Local\Temp ====
2014-11-24 16:26:23 BD6C3071F98A563989F99AC61BDDC925 10284408 ----a-w- C:\Users\abdullah\AppData\Local\Temp\HitmanPro.exe
====== Java Cache =====
====== C:\Windows\system32 =====
2014-11-24 05:02:15 39D7CCC6EAA06A59961124EB41BDF398 4226 ----a-w- C:\Windows\System32\.crusader
====== C:\Windows\system32\drivers =====
2014-11-23 13:20:22 8E2E9CCD873ABF180F48BCAEEEBE347D 114904 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-11-23 13:19:15 E89B115E1DD297DCB694B22CFA90BF61 75480 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-11-23 13:19:15 D2DED3C333A5D9CB3F4C244B0F0DD877 23256 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-11-23 13:19:15 7A6526C8BD114DB7CA8930AB22D52A0B 51928 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-11-21 09:52:19 70DBEF6B5667CC01E9DB737F0E447078 43688 ----a-w- C:\Windows\System32\drivers\iSafeNetFilter.sys
2014-11-21 09:52:17 0B1E9BD9C4CB00F956C63B3CBEDEF18D 40744 ----a-w- C:\Windows\System32\drivers\iSafeKrnlBoot.sys
2014-11-12 14:47:31 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\System32\drivers\Msft_Kernel_RimSerial_01007.Wdf
2014-11-12 14:47:13 C4F4FCD5AE48BDD31648981DDF8EF993 35840 ----a-w- C:\Windows\System32\drivers\RimSerial.sys
2014-11-12 13:21:09 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\System32\drivers\Msft_Kernel_RimUsb_01007.Wdf
2014-11-12 06:59:59 401E663D9CBAFB580FF37A1A44AC84D9 91496 ----a-w- C:\Windows\System32\drivers\aswStm.sys
2014-11-12 06:59:58 1624D5AD126B8AFE2B2E85E5B8364EB6 423784 ----a-w- C:\Windows\System32\drivers\aswsp.sys
2014-11-12 06:59:58 0EFBC2962B156E8AC267F96D4D93EF06 206248 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-11-12 06:59:57 9D23DE88C3B18BA87CD4587177CA6CEA 24184 ----a-w- C:\Windows\System32\drivers\aswHwid.sys
2014-11-12 06:59:57 73A9014A9C4B19AA093DA05ED4246E27 70384 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-11-12 06:59:57 6544697080421E62E97AAFBD0A8AA391 49944 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2014-11-12 06:59:56 DE8D7912469E4BC5FAED78D9D1076888 81768 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2014-11-12 06:59:54 E73CBE3420ECFA8FF7D0467E170E335D 787800 ----a-w- C:\Windows\System32\drivers\aswsnx.sys
2014-11-12 06:59:54 5ED92794EB7D63160A4ACFA5ADF6BCF1 787800 ----a-w- C:\Windows\System32\drivers\aswsnx.sys.1416985232101
2014-11-12 06:59:53 D1AD7B24E80D34280B9D0463C881CF93 26136 ----a-w- C:\Windows\System32\drivers\aswKbd.sys
2014-11-12 06:58:50 D3586ED440E451BC779BB09196F8070B 271288 ----a-w- C:\Windows\System32\drivers\aswNdisFlt.sys
2014-11-12 06:21:32 BE125797A510CD7E9E77D0D79CB989EF 47456 ----a-w- C:\Windows\System32\drivers\Bhbase.sys
2014-11-11 17:17:47 637602DCEA2333202468A7C24CF9E72A 3656872 ----a-w- C:\Windows\System32\drivers\RTKVHDA.sys
2014-11-11 05:36:49 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-11-11 03:17:52 FC8771F45ECCCFD89684E38842539B9B 78208 ----a-w- C:\Windows\System32\drivers\mountmgr.sys
2014-11-11 03:17:52 E0ABDB5ED7E199E242A7D028E76C1D3A 96768 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2014-11-11 03:17:52 CEB46AB7C01C9F825F8CC6BABC18166A 115712 ----a-w- C:\Windows\System32\drivers\mrxdav.sys
2014-11-11 03:17:52 A4BDC541E69674FBFF1A8FF00BE913F2 48640 ----a-w- C:\Windows\System32\drivers\ndproxy.sys
2014-11-11 03:17:52 5DCEF0C32BE0F33277326586FA503689 190976 ----a-w- C:\Windows\System32\drivers\ks.sys
2014-11-11 03:17:52 2899EF7AEEF6913ED4FCB0E8A7A04F46 240000 ----a-w- C:\Windows\System32\drivers\netio.sys
2014-11-11 03:17:49 012C5F4E9349E711E11E0F19A8589F0A 28032 ----a-w- C:\Windows\System32\drivers\msahci.sys
2014-11-11 03:17:43 CEA80C80BED809AA0DA6FEBC04733349 274304 ----a-w- C:\Windows\System32\drivers\acpi.sys
2014-11-11 03:17:43 1B133875B8AA8AC48969BD3458AFE9F5 164864 ----a-w- C:\Windows\System32\drivers\1394ohci.sys
2014-11-11 03:17:42 4B55C9F9A93B3BFD01ED7366EB0B9D2E 132992 ----a-w- C:\Windows\System32\drivers\ataport.sys
2014-11-11 03:17:41 4BD7134618C1D2A27466A099062547BF 65536 ----a-w- C:\Windows\System32\drivers\IPMIDrv.sys
2014-11-11 03:17:36 CCA24162E055C3714CE5A88B100C64ED 35328 ----a-w- C:\Windows\System32\drivers\tcpipreg.sys
2014-11-11 03:17:35 FD1D6C73E6333BE727CBCC6054247654 52224 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2014-11-11 03:17:32 B40CCEC755DC3FBAE95E568C7849405E 148864 ----a-w- C:\Windows\System32\drivers\storport.sys
2014-11-11 03:17:28 BF63EBFC6979FEFB2BC03DF7989A0C1A 76288 ----a-w- C:\Windows\System32\drivers\USBSTOR.SYS
2014-11-11 03:17:28 7FA7F2E249A5DCBB7970630E15E1F482 5632 ----a-w- C:\Windows\System32\drivers\vms3cap.sys
2014-11-11 03:17:28 3C3C78515F5AB448B022BDF5B8FFDD2E 63488 ----a-w- C:\Windows\System32\drivers\wanarp.sys
2014-11-11 03:17:26 68A0387F58E226DEEE23D9715955572A 15872 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys
2014-11-11 03:17:26 518395321DC96FE2C9F0E96AC743B656 173440 ----a-w- C:\Windows\System32\drivers\rdyboost.sys
2014-11-11 03:17:23 6D4CCAEDC018F1CF52866BBBAA235982 12800 ----a-w- C:\Windows\System32\drivers\sffp_sd.sys
2014-11-11 03:17:23 05D860DA1040F111503AC416CCEF2BCA 85376 ----a-w- C:\Windows\System32\drivers\sbp2port.sys
2014-11-11 03:17:16 33C3093D09017CFE2E219F2472BFF6EB 1211264 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-11-11 03:17:15 AF2EEC9580C1D32FB7EAF105D9784061 117120 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2014-11-11 03:17:15 9283C58EBAA2618F93482EB5DABCEC82 143744 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2014-11-11 03:17:12 BF8F6AF06DA75B336F07E23AEF97D93B 56192 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2014-11-11 03:17:08 E7C54812A2AAF43316EB6930C1FFA108 712576 ----a-w- C:\Windows\System32\drivers\ndis.sys
2014-11-11 03:17:08 38FBE267E7E6983311179230FACB1017 118784 ----a-w- C:\Windows\System32\drivers\ndiswan.sys
2014-11-11 03:17:02 56E5C9B62BAD9EC85BC76940D28B6C11 187776 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2014-11-11 03:17:02 43B3206DD654E783AA7E4EAD340A43B8 60416 ----a-w- C:\Windows\System32\drivers\BTHUSB.SYS
2014-11-11 03:17:02 195C41CC67E9E1CEDD960CCB74925920 393216 ----a-w- C:\Windows\System32\drivers\bthport.sys
2014-11-11 03:16:58 37E8FA3779668837CA9E2C36D2415949 1290112 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2014-11-11 03:16:51 E5DD784A4EE5EBC72A86C677C988FCDB 309248 ----a-w- C:\Windows\System32\drivers\srv2.sys
2014-11-11 03:16:42 E714A1C0354636837E20CCBF00888EE7 92672 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2014-11-11 03:16:42 1A078C3FE1C1F9C8561CD600C69AD300 26112 ----a-w- C:\Windows\System32\drivers\usbrpm.sys
2014-11-11 03:16:42 1023EE888C9B47178C5293ED5336AB69 132224 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2014-11-11 03:16:41 FD82D2B38C465A55C527E339BA1201B1 25856 ----a-w- C:\Windows\System32\drivers\USBCAMD.sys
2014-11-11 03:16:41 E071E5BE621FEC4590117C488A78AE32 25856 ----a-w- C:\Windows\System32\drivers\USBCAMD2.sys
2014-11-11 03:16:39 F497F67932C6FA693D7DE2780631CFE7 245632 ----a-w- C:\Windows\System32\drivers\volsnap.sys
2014-11-11 03:16:39 23DAE03F29D253AE74C44F99E515F9A1 6656 ----a-w- C:\Windows\System32\drivers\RDPCDD.sys
2014-11-11 03:16:33 0693B5EC673E34DC147E195779A4DCF6 26624 ----a-w- C:\Windows\System32\drivers\scfilter.sys
2014-11-11 03:16:30 9AC33EF26C8A3AD0F117D00EB7301D03 223232 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2014-11-11 03:16:30 412CEA1AA78CC02A447F5C9E62B32FF1 67456 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2014-11-11 03:16:30 2D699FB6E89CE0D8DA14ECC03B3EDFE0 130432 ----a-w- C:\Windows\System32\drivers\mpio.sys
2014-11-11 03:16:29 9E3CED91863E6EE98C24794D05E27A71 28160 ----a-w- C:\Windows\System32\drivers\kbdhid.sys
2014-11-11 03:16:25 D528BC58A489409BA40334EBF96A311B 242688 ----a-w- C:\Windows\System32\drivers\rdbss.sys
2014-11-11 03:16:21 D8A65DAFB3EB41CBB622745676FCD072 46080 ----a-w- C:\Windows\System32\drivers\ndisuio.sys
2014-11-11 03:16:21 CB7A9ABB12B8415BCE5D74994C7BA3AE 233344 ----a-w- C:\Windows\System32\drivers\msiscsi.sys
2014-11-11 03:16:21 55055F8AD8BE27A64C831322A780A228 116096 ----a-w- C:\Windows\System32\drivers\msdsm.sys
2014-11-11 03:16:20 F024449C97EC1E464AAFFDA18593DB88 78336 ----a-w- C:\Windows\System32\drivers\dfsc.sys
2014-11-11 03:16:18 AEA177F783E20150ACE5383EE368DA19 50176 ----a-w- C:\Windows\System32\drivers\appid.sys
2014-11-11 03:16:17 871917B07A141BFF43D76D8844D48106 513536 ----a-w- C:\Windows\System32\drivers\http.sys
2014-11-11 03:16:17 0C4E035C7F105F1299258C90886C64C5 14208 ----a-w- C:\Windows\System32\drivers\hwpolicy.sys
2014-11-11 03:16:16 A5EF29D5315111C80A5C1ABAD14C8972 304128 ----a-w- C:\Windows\System32\drivers\HdAudio.sys
2014-11-11 03:16:16 8A73E79089B282100B9393B644CB853B 194800 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2014-11-11 03:16:15 23F5D28378A160352BA8F817BD8C71CB 728448 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2014-11-11 03:16:14 1893ACD253854AC385042DB594FA23FF 211968 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2014-11-11 03:16:12 D295BED4B898F0FD999FCFA9B32B071B 39936 ----a-w- C:\Windows\System32\drivers\umbus.sys
2014-11-11 03:16:10 254BB140EEE3C59D6114C1A86B636877 31232 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
2014-11-11 03:16:09 9D22AAD9AC6A07C691A1113E5F860868 258560 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2014-11-11 03:16:09 7E72E7D7E0757D59481D530FD2B0BFAE 75776 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2014-11-11 03:16:04 B459575348C20E8121D6039DA063C704 74752 ----a-w- C:\Windows\System32\drivers\tdx.sys
2014-11-11 03:16:03 2F885864D5BC8A16C86BEE595969A48A 21504 ----a-w- C:\Windows\System32\drivers\tdi.sys
2014-11-11 03:15:59 472AF0311073DCECEAA8FA18BA2BDF89 40704 ----a-w- C:\Windows\System32\drivers\vmstorfl.sys
2014-11-11 03:15:57 099972E1FAF4950D3994FBAB9DD21253 140160 ----a-w- C:\Windows\System32\drivers\scsiport.sys
2014-11-11 03:15:56 DCAFFD62259E0BDB433DD67B5BB37619 28032 ----a-w- C:\Windows\System32\drivers\storvsc.sys
2014-11-11 03:15:55 CDBE627E16CC9E98F343D73F8E81D258 114176 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2014-11-11 03:15:52 B973FCFC50DC1434E1970A146F7E3885 133632 ----a-w- C:\Windows\System32\drivers\rdpdr.sys
2014-11-11 03:15:52 906DCFC5EBF4EC0433F8D4FFFB0BA334 117760 ----a-w- C:\Windows\System32\drivers\rmcast.sys
2014-11-11 03:15:52 288B06960D78428FF89E811632684E20 183808 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2014-11-11 03:15:50 B272B4C3E085EA860C12F2E4FAF2FFA2 123904 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2014-11-11 03:15:49 673E55C3498EB970088E812EA820AA8F 153984 ----a-w- C:\Windows\System32\drivers\pci.sys
2014-11-11 03:15:47 280122DDCF04B378EDD1AD54D71C1E54 187904 ----a-w- C:\Windows\System32\drivers\netbt.sys
2014-11-11 03:15:46 D4D77455211E204F370D08F4963063CE 17920 ----a-w- C:\Windows\System32\drivers\VMBusHID.sys
2014-11-11 03:15:46 C2F2911156FDC7817C52829C86DA494E 175360 ----a-w- C:\Windows\System32\drivers\vmbus.sys
2014-11-11 03:15:46 5461686CCA2FDA57B024547733AB42E3 160128 ----a-w- C:\Windows\System32\drivers\vhdmp.sys
2014-11-11 03:15:46 4C63E00F2F4B5F86AB48A58CD990F212 53120 ----a-w- C:\Windows\System32\drivers\volmgr.sys
2014-11-11 03:15:45 EE43346C7E4B5E63E54F927BABBB32FF 246784 ----a-w- C:\Windows\System32\drivers\udfs.sys
2014-11-11 03:15:45 B2FA25D9B17A68BB93D58B0556E8C90D 108544 ----a-w- C:\Windows\System32\drivers\tunnel.sys
2014-11-11 03:15:43 62BA4FDCA65BDB69695E0D1157C57717 43392 ----a-w- C:\Windows\System32\drivers\winhv.sys
2014-11-11 03:15:38 112127C3B2E64D7680CC39CD0A39DD7E 311296 ----a-w- C:\Windows\System32\drivers\srv.sys
2014-11-11 03:15:30 2C10395BAA4847F83042813C515CC289 24576 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2014-11-11 03:15:30 1CB91B2BD8F6DD367DFC2EF26FD751B2 18432 ----a-w- C:\Windows\System32\drivers\tdpipe.sys
2014-11-11 03:15:30 04DBF4B01EA4BF25A9A3E84AFFAC9B20 53120 ----a-w- C:\Windows\System32\drivers\termdd.sys
2014-11-11 03:15:26 A3CAE5D281DB4CFF7CFF8233507EE5AD 332160 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2014-11-11 03:15:26 10C19F8290891AF023EAEC0832E1EB4D 24064 ----a-w- C:\Windows\System32\drivers\hidusb.sys
2014-11-11 03:15:25 931A1DF1520ABC6E84BA4A75E6957025 55808 ----a-w- C:\Windows\System32\drivers\hidclass.sys
2014-11-11 03:15:24 9036377B8A6C15DC2EEC53E489D159B5 108544 ----a-w- C:\Windows\System32\drivers\hdaudbus.sys
2014-11-11 03:15:14 BE167ED0FDB9C1FA1133953C18D5A6C9 108544 ----a-w- C:\Windows\System32\drivers\cdrom.sys
2014-11-11 03:15:13 1EFBC664ABFF416D1D07DB115DCB264F 10240 ----a-w- C:\Windows\System32\drivers\acpipmi.sys
2014-11-11 03:15:12 E7F4D42D8076EC60E21715CD11743A0D 80256 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2014-11-11 03:15:12 81773BE2B369F54EDE42AE62B59BB895 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-11-11 03:15:12 146459D2B08BFDCBFA856D9947043C81 22400 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2014-11-11 03:15:12 1151FD4FB0216CFED887BFDE29EBD516 338944 ----a-w- C:\Windows\System32\drivers\afd.sys
2014-11-11 03:15:09 3C2177A897B4CA2788C6FB0C3FD81D4B 388096 ----a-w- C:\Windows\System32\drivers\csc.sys
2014-11-11 03:15:08 CBE8C58A8579CFE5FCCF809E6F114E89 31232 ----a-w- C:\Windows\System32\drivers\CompositeBus.sys
====== C:\Windows\Tasks ======
2014-11-24 05:04:20 FBFBEE1146F05BAECDAA4E7FDECAD1DD 3830 ----a-w- C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2014-11-24 05:04:20 54C5F9BA83459007CA4C47F33CFCF99D 834 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-24 05:04:10 3038DA690DF01934F311648100E5CD38 3578 ----a-w- C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2014-11-24 05:04:09 71979AEDFDCD7491BDB107BFA02DC93E 830 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-20 11:20:51 8CA594E290ED80F69A3DEBED17CDADF6 3132 ----a-w- C:\Windows\system32\Tasks\{5C052D30-F617-4FEA-850E-0DE8079C77C6}
2014-11-20 03:42:38 CFD62261B64F544BA286A5AE6118D49D 266 ----a-w- C:\Windows\Tasks\AutoKMS.job
2014-11-20 03:42:38 9ACF031A065F250BB610063E39818A67 2896 ----a-w- C:\Windows\system32\Tasks\AutoKMS
2014-11-19 02:52:25 -------- d-----w- C:\Windows\system32\Tasks\OfficeSoftwareProtectionPlatform
2014-11-15 16:23:43 246E7B0052F761E05C8B4FD04AFE7FC7 3250 ----a-w- C:\Windows\system32\Tasks\9A5A8340-6B15
2014-11-15 16:23:38 8396269959DDD051BBC9247D6FF8EDE1 3266 ----a-w- C:\Windows\system32\Tasks\Java Update
2014-11-12 07:00:21 DF111910114835E952332A64D25C5B2A 4182 ----a-w- C:\Windows\system32\Tasks\avast! Emergency Update
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-11-24 05:04:00 -------- d-----w- C:\Program Files\Google
2014-11-21 09:52:07 -------- d-----w- C:\Program Files\Elex-tech
2014-11-19 02:44:47 -------- d-----w- C:\Program Files\Microsoft Synchronization Services
2014-11-19 02:44:44 -------- d-----w- C:\Program Files\Common Files\DESIGNER
2014-11-19 02:43:15 -------- d-----w- C:\Program Files\Microsoft SQL Server Compact Edition
2014-11-19 02:37:34 -------- d-----w- C:\Program Files\Microsoft Analysis Services
2014-11-15 16:23:29 -------- d-----w- C:\Program Files\Office
2014-11-13 04:45:01 -------- d-----w- C:\Program Files\NVIDIA Corporation
2014-11-13 04:40:02 -------- d-----w- C:\Program Files\Microsoft Visual Studio 8
2014-11-13 04:38:42 -------- d-----w- C:\Program Files\Microsoft Office
2014-11-13 04:27:26 -------- d-----w- C:\Program Files\Common Files\SolidWorks Installation Manager
2014-11-12 13:12:16 -------- d-----w- C:\Program Files\Research In Motion
2014-11-12 13:12:16 -------- d-----w- C:\Program Files\Common Files\XCPCSync.OEM
2014-11-12 13:12:16 -------- d-----w- C:\Program Files\Common Files\Research In Motion
2014-11-12 12:18:59 -------- d-----w- C:\Program Files\Enigma Software Group
2014-11-12 12:17:54 -------- d-----w- C:\Program Files\Common Files\Wise Installation Wizard
2014-11-12 10:05:46 -------- d-----w- C:\Program Files\VideoLAN
2014-11-12 04:09:19 -------- d-----w- C:\Program Files\Microsoft Visual Studio 10.0
2014-11-12 04:01:58 -------- d-----w- C:\Program Files\Microsoft SQL Server
2014-11-12 03:57:25 -------- d-----w- C:\Program Files\MSECache
2014-11-12 03:56:21 -------- d-----w- C:\Program Files\Common Files\SolidWorks Shared
2014-11-12 03:56:19 -------- d-----w- C:\Program Files\Common Files\Macrovision Shared
2014-11-11 17:17:45 -------- d--h--w- C:\Program Files\InstallShield Installation Information
2014-11-11 17:17:45 -------- d-----w- C:\Program Files\Realtek
2014-11-11 17:17:24 -------- d--h--w- C:\Program Files\Temp
2014-11-11 17:17:06 -------- d-----w- C:\Program Files\Common Files\InstallShield
2014-11-11 13:08:30 -------- d-----w- C:\Program Files\SolidWorks Corp
2014-11-11 12:59:10 -------- d-----w- C:\Program Files\Microsoft.NET
2014-11-11 04:24:31 -------- d-----w- C:\Program Files\BORLAND
2014-11-11 03:45:52 -------- d-----w- C:\Program Files\Your Uninstaller! 7
2014-11-10 19:41:29 -------- d-----w- C:\Program Files\Mozilla Maintenance Service
2014-11-10 18:59:04 -------- d-----w- C:\Program Files\WinRAR
======= C: =====
2014-11-11 04:25:23 D41D8CD98F00B204E9800998ECF8427E 0 --sha-r- C:\MSDOS.SYS
2014-11-11 04:25:23 D41D8CD98F00B204E9800998ECF8427E 0 --sha-r- C:\IO.SYS
2014-11-11 03:46:36 A23CB25C63259C95CC678574EA40DC4F 11876 ----a-w- C:\missing.ini
====== C:\Users\abdullah\AppData\Roaming ======
2014-11-24 05:03:29 -------- d-----w- C:\Users\abdullah\AppData\Local\Google
2014-11-21 09:50:49 -------- d-----w- C:\Users\abdullah\AppData\Roaming\Elex-tech
2014-11-19 10:44:41 -------- d-----w- C:\Users\abdullah\AppData\Roaming\VolIE
2014-11-19 03:45:46 -------- d-----w- C:\Users\abdullah\AppData\Roaming\Runscanner.net
2014-11-18 16:12:32 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp
2014-11-18 16:12:32 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp
2014-11-18 16:12:32 -------- d-----w- C:\Users\Default\AppData\Local\Temp
2014-11-18 16:12:32 -------- d-----w- C:\Users\Default User\AppData\Local\Temp
2014-11-18 16:12:31 -------- d-----w- C:\Users\abdullah\AppData\Local\Temp
2014-11-17 15:11:51 E4F2DFCCCF23865CDD714AEDFEFB9109 1810472 ----a-w- C:\Windows\serviceprofiles\Localservice\AppData\Local\FontCache3.0.0.0.dat
2014-11-13 06:24:27 -------- d-----w- C:\Users\abdullah\AppData\Local\TempSWBackupDirectory
2014-11-13 06:19:16 -------- d-----w- C:\Users\abdullah\AppData\Local\SolidWorks
2014-11-12 13:47:54 -------- d-----w- C:\Users\abdullah\AppData\Local\Downloaded Installations
2014-11-12 13:16:27 -------- d-----w- C:\Users\abdullah\AppData\Local\Programs
2014-11-12 13:15:09 -------- d-----w- C:\Users\abdullah\AppData\Roaming\Research In Motion
2014-11-12 13:14:48 -------- d-----w- C:\Users\abdullah\AppData\Local\Research In Motion
2014-11-12 10:08:37 -------- d-----w- C:\Users\abdullah\AppData\Roaming\Adobe
2014-11-12 10:06:57 -------- d-----w- C:\Users\abdullah\AppData\Roaming\vlc
2014-11-12 09:46:42 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Roaming\PeerNetworking
2014-11-12 06:31:43 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster
2014-11-12 06:10:51 -------- d-----w- C:\Users\abdullah\AppData\Roaming\uTorrent
2014-11-12 03:58:52 -------- d-----w- C:\Users\abdullah\AppData\Local\Microsoft Help
2014-11-11 04:24:34 -------- d-----w- C:\Users\abdullah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Borland C++ 5.02
2014-11-11 03:49:26 09F08AEED33428A5FCC329FFC487FB3E 121272 ----a-w- C:\Users\abdullah\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-11 03:46:13 -------- d-----w- C:\Users\abdullah\AppData\Roaming\URSoft
2014-11-11 03:44:38 -------- d-----w- C:\Users\abdullah\AppData\Roaming\WinRAR
2014-11-10 20:02:15 -------- d-----w- C:\Users\abdullah\AppData\Roaming\SolidWorks
2014-11-10 19:41:50 -------- d-----w- C:\Users\abdullah\AppData\Roaming\Mozilla
2014-11-10 19:41:50 -------- d-----w- C:\Users\abdullah\AppData\Local\Mozilla
2014-11-10 19:31:23 -------- d-sh--w- C:\Users\abdullah\AppData\Locallow\Microsoft
2014-11-10 19:01:13 -------- d-----w- C:\Users\abdullah\AppData\Local\Adobe
2014-11-10 18:59:08 -------- d-----w- C:\Users\abdullah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-11-10 18:55:55 -------- d-----r- C:\Users\abdullah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-11-10 18:55:55 -------- d-----r- C:\Users\abdullah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-11-10 18:55:10 -------- d-----w- C:\Users\abdullah\AppData\Roaming\Identities
2014-11-10 18:54:16 -------- d-----w- C:\Users\abdullah\AppData\Local\VirtualStore
2014-11-10 18:54:08 -------- d-s---w- C:\Users\abdullah\AppData\Roaming\Microsoft
2014-11-10 18:54:08 -------- d-----w- C:\Users\abdullah\AppData\Roaming\Media Center Programs
2014-11-10 18:54:08 -------- d-----w- C:\Users\abdullah\AppData\Local\Microsoft
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
====== C:\Users\abdullah ======
2014-11-24 05:42:05 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-11-24 05:38:09 3DE4CD6718136B9D5123112C7A4A2CAD 880784 ----a-w- C:\Users\abdullah\Downloads\ChromeSetup(1).exe
2014-11-24 05:02:33 FAFDDF0EE9B533DE6CC525C01C0F311E 880784 ----a-w- C:\Users\abdullah\Downloads\ChromeSetup.exe
2014-11-24 04:36:59 -------- d-----w- C:\ProgramData\HitmanPro
2014-11-24 04:25:43 BD6C3071F98A563989F99AC61BDDC925 10284408 ----a-w- C:\Users\abdullah\Downloads\HitmanPro.exe
2014-11-23 13:14:40 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\abdullah\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-11-23 13:00:07 FCCD0F6A733248E8F624B9FE813F0324 1944824 ----a-w- C:\Users\abdullah\Downloads\rkill.com
2014-11-21 09:47:05 CC65D4EFBF70F21579A3D2270DBF19E3 15281584 ----a-w- C:\Users\abdullah\Downloads\yet_another_cleaner_sk.exe
2014-11-19 10:41:04 FCD9B946149250801353C80447BE2929 896554 ----a-w- C:\Users\abdullah\Downloads\anycleaner_1.05_x86_setup.exe
2014-11-19 03:41:37 3E5710600931E322F62B0DAA598C0AA5 2248504 ----a-w- C:\Users\abdullah\Downloads\runscanner.exe
2014-11-19 02:48:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2014-11-19 02:48:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-11-18 16:33:02 8573E3C2603DD23E1A8DE3177D146D18 1707532 ----a-w- C:\Users\abdullah\Downloads\JRT.exe
2014-11-18 14:35:39 6504113C2218667814D4F54847BA046A 2140160 ----a-w- C:\Users\abdullah\Downloads\adwcleaner_4.101.exe
2014-11-17 20:43:03 F2950B0376EBFFB13E6A2A1EA119488A 109829936 ----a-w- C:\Users\abdullah\Downloads\iTunesSetup.exe
2014-11-15 15:36:14 -------- d-----w- C:\ProgramData\Microsoft Toolkit
2014-11-13 05:23:51 -------- d-----w- C:\ProgramData\COSMOS Applications
2014-11-13 05:22:34 -------- d-----w- C:\ProgramData\SolidWorks Flow Simulation
2014-11-13 04:54:12 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2014
2014-11-13 04:45:00 -------- d-----w- C:\ProgramData\SolidWorks
2014-11-13 04:41:26 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
2014-11-13 04:27:37 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks Installation Manager
2014-11-12 13:13:56 -------- d-----w- C:\ProgramData\Research In Motion
2014-11-12 13:13:27 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry
2014-11-12 10:06:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-11-12 04:07:14 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008
2014-11-12 04:04:24 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2012
2014-11-12 04:00:27 -------- d-----w- C:\ProgramData\Apple
2014-11-12 03:58:15 -------- d-----w- C:\ProgramData\Microsoft Help
2014-11-12 03:56:32 -------- d-----w- C:\ProgramData\SolidWorks Electrical
2014-11-11 13:34:41 -------- d-----w- C:\ProgramData\DassaultSystemes
2014-11-11 13:33:53 -------- d-----w- C:\ProgramData\FLEXnet
2014-11-11 04:24:35 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Borland C++ 5.02
2014-11-11 03:46:11 -------- d---a-w- C:\ProgramData\TEMP
2014-11-11 03:45:55 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Uninstaller! 7
2014-11-10 19:41:30 -------- d-----w- C:\ProgramData\Mozilla
2014-11-10 18:59:08 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-11-10 18:55:55 -------- d-----r- C:\Users\abdullah\Searches
2014-11-10 18:54:59 -------- d-----r- C:\Users\abdullah\Contacts
2014-11-10 18:54:10 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\abdullah\ntuser.ini
2014-11-10 18:54:08 -------- d--h--w- C:\Users\abdullah\AppData
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\Videos
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\Saved Games
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\Pictures
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\Music
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\Links
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\Favorites
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\Downloads
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\Documents
2014-11-10 18:54:08 -------- d-----r- C:\Users\abdullah\Desktop
====== C: exe-files ==
=== C: other files ==
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-1455536248-4251957604-2131250355-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"BlackBerryLink.exe"="C:\Program Files\Research In Motion\BlackBerry Link\BlackBerryLink.exe /minimize"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-21-1455536248-4251957604-2131250355-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="C:\Windows\system32\Macromed\Flash\FlashUtil32_15_0_0_223_Plugin.exe -update plugin"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"RIMBBLaunchAgent.exe"="C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe"
"RIM PeerManager"="C:\Program Files\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BlackBerryLink.exe"="C:\Program Files\Research In Motion\BlackBerry Link\BlackBerryLink.exe /minimize"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="C:\Windows\system32\Macromed\Flash\FlashUtil32_15_0_0_223_Plugin.exe -update plugin"
==== Startup Folders ======================
2014-11-13 04:54:13 2753 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks 2014 Fast Start.lnk
2014-11-13 04:27:37 1304 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks Background Downloader.lnk
==== Task Scheduler Jobs ======================
C:\Windows\tasks\AutoKMS.job --a------ C:\Windows\AutoKMS\AutoKMS.exe []
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [Undetermined Task]
==== Other Scheduled Tasks ======================
"C:\Windows\system32\tasks\9A5A8340-6B15" ["C:\Users\abdullah\AppData\Roaming\ARHome\Updater.exe"]
"C:\Windows\system32\tasks\AutoKMS" [C:\Windows\AutoKMS\AutoKMS.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\Java Update" ["C:\Program Files\Java\Java.exe"]
"C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"
wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [11/12/2014 09:59 AM]
==== Firefox Extensions ======================
ProfilePath: C:\Users\abdullah\AppData\Roaming\Mozilla\Firefox\Profiles\xf3rtzuv.default-1415791883588
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\abdullah\AppData\Roaming\Mozilla\Firefox\Profiles\xf3rtzuv.default-1415791883588
D2377C9458EFEB094E38B8C874AA214C - C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll - Google Update
67D325B5AEB28E381B84E8DE1A90C7A8 - C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll - Shockwave Flash
0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
EED1D8EB9B68CC8060660549D0364042 - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll - RIM Handheld Application Loader
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[11/12/2014 09:59 AM]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[11/12/2014 09:59 AM]
Google Slides - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Google Docs - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Avast SafePrice - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Google Sheets - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Avast Online Security - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki
Google Wallet - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="
"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="
"
"Search Page"="
"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="
"
"Search Page"="
"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
"
==== Reset Google Chrome ======================
C:\Users\abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Preferences was reset successfully
C:\Users\abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Web Data was reset successfully
==== HijackThis Entries ======================
F3 - REG:win.ini: load=C:\BC5\PIPELINE\remind.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM\..\Run: [RIM PeerManager] "C:\Program Files\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKCU\..\Run: [BlackBerryLink.exe] "C:\Program Files\Research In Motion\BlackBerry Link\BlackBerryLink.exe" /minimize
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil32_15_0_0_223_Plugin.exe -update plugin
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: SolidWorks 2014 Fast Start.lnk = ?
O4 - Global Startup: SolidWorks Background Downloader.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: BlackBerry Device Manager - BlackBerry Limited - C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systèmes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Remote Solver for Flow Simulation 2014 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: RIM MDNS - Apple Inc. - C:\Program Files\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe
O23 - Service: BlackBerry Link Communication Manager (RIM Tunnel Service) - Research In Motion Limited - C:\Program Files\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
==== Empty IE Cache ======================
C:\Users\abdullah\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\abdullah\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\abdullah\AppData\Local\Mozilla\Firefox\Profiles\xf3rtzuv.default-1415791883588\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\abdullah\AppData\Local\Google\Chrome\User Data\Profile 2\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache is not empty, a reboot is needed
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=72 folders=2 13612111 bytes)
==== Empty Temp Folders ======================
C:\Users\abdullah\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\abdullah\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\abdullah\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Users\abdullah\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K5N5RLYF\
" not found
==== EOF on Thu 11/27/2014 at 7:05:59.57 ======================