Internet Explorer: 11.0.9600.17344 BrowserJavaVersion: 10.71.2
Run by R.W.Solema at 11:34:11 on 2014-11-07
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8157.6120 [GMT -8:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\system32\taskeng.exe
C:\windows\Explorer.EXE
C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Greenshot\Greenshot.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler64.exe
C:\Program Files\Start Menu X\StartMenuX.exe
C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe
C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe
C:\Program Files (x86)\Lenovo\FanSpeedControl\LenovoFSC.exe
C:\Program Files (x86)\jmesoft\hotkey.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\windows\system32\wbem\unsecapp.exe
C:\windows\System32\svchost.exe -k swprv
C:\windows\system32\vssvc.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://
www.yahoo.com/?fr=hp-avast&type=odc179
uSearch Bar = hxxps://
www.yahoo.com/?fr=hp-avast&type=odc179
uSearch Page = hxxps://search.yahoo.com/yhs/search?type=odc179&hspart=avast&hsimp=yhs-001&p={searchTerms}
mStart Page = hxxps://
www.yahoo.com/?fr=hp-avast&type=odc179
mSearch Bar = hxxps://
www.yahoo.com/?fr=hp-avast&type=odc179
mSearch Page = hxxps://search.yahoo.com/yhs/search?type=odc179&hspart=avast&hsimp=yhs-001&p={searchTerms}
uProxyServer = hxxp=127.0.0.1:49293;https=127.0.0.1:49293
uProxyOverride = <-loopback>;<local>
mWinlogon: Userinit = userinit.exe,
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [StartMenuX57] "C:\Program Files\Start Menu X\StartMenuX.exe"
mRun: [LenovoFSC] C:\Program Files (x86)\Lenovo\FanSpeedControl\LenovoFSC.exe
mRun: [jmekey] C:\Program Files (x86)\jmesoft\hotkey.exe
mRun: [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [Malwarebytes Anti-Exploit] C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mRun: [ZALFree] "C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe" /MINIMIZED
mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
dRunOnce: [WLStart] "C:\Program Files (x86)\Windows Live\Installer\wlstart.exe" /nosearch /nohomepage
dRunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\REALPL~1.LNK - C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe
uPolicies-Explorer: NoResolveTrack = dword:1
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{08118354-E1AC-4114-B126-EF807A27983C} : DHCPNameServer = 209.18.47.61 209.18.47.62
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page =
www.google.com
x64-BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [Unattend0000000001{BFA3D12B-66DD-4617-923A-E864BC7D20B5}] C:\Windows\test.bat
x64-Run: [IgfxTray] C:\windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\windows\System32\igfxpers.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [Greenshot] C:\Program Files\Greenshot\Greenshot.exe
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Notify: igfxcui - igfxdev.dll
x64-Notify: WB - C:\Program Files (x86)\Stardock\WindowBlinds\fast64.dll
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1
www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\R.W.Solema\AppData\Roaming\Mozilla\Firefox\Profiles\mxbcgzf7.default\
FF - prefs.js: browser.search.defaulturl - hxxps://search.yahoo.com/yhs/search
FF - prefs.js: browser.search.selectedEngine - Yahoo! (Avast)
FF - prefs.js: browser.startup.homepage - hxxps://
www.yahoo.com/?fr=hp-avast&type=odc179
FF - prefs.js: keyword.URL - hxxps://search.yahoo.com/yhs/search
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\windows\System32\drivers\aswRvrt.sys [2014-3-6 65776]
R0 aswVmm;avast! VM Monitor;C:\windows\System32\drivers\aswVmm.sys [2014-3-6 267632]
R0 SCMNdisP;General NDIS Protocol Driver;C:\windows\System32\drivers\SCMNdisP.sys [2014-3-6 25312]
R1 aswSnx;aswSnx;C:\windows\System32\drivers\aswsnx.sys [2014-3-6 1050432]
R1 aswSP;aswSP;C:\windows\System32\drivers\aswsp.sys [2014-3-6 436624]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit;C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [2014-6-26 63000]
R1 JSWPSLWF;JumpStart Wireless Filter Driver;C:\windows\System32\drivers\jswpslwfx.sys [2014-3-6 26624]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2014-7-22 172344]
R2 aswHwid;avast! HardwareID;C:\windows\System32\drivers\aswHwid.sys [2014-5-4 29208]
R2 aswMonFlt;aswMonFlt;C:\windows\System32\drivers\aswMonFlt.sys [2014-3-6 83280]
R2 aswStm;aswStm;C:\windows\System32\drivers\aswstm.sys [2014-3-6 116728]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-7 50344]
R2 FoxitCloudUpdateService;Foxit Cloud Safe Update Service;C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [2014-10-1 242912]
R2 MbaeSvc;Malwarebytes Anti-Exploit Service;C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [2014-6-26 441144]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2014-7-30 39568]
R2 RealPlayer Cloud Service;RealPlayer Cloud Service;C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [2014-5-27 1141848]
R2 RealPlayerUpdateSvc;RealPlayer Update Service;C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [2014-7-30 23552]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-7-6 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-7-6 171928]
R2 TeamViewer9;TeamViewer 9;C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-9-16 4799760]
R2 VBoxAswDrv;VBoxAsw Support Driver;C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-11-7 271752]
R2 WSWNA1100;WSWNA1100;C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe [2014-3-6 278528]
R3 athur;Atheros AR9271 Wireless Network Adapter Service;C:\windows\System32\drivers\athurx.sys [2014-3-6 1827328]
R3 AvastVBoxSvc;AvastVBox COM Service;C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-11-7 4012248]
R3 fwndis;Emsisoft Firewall NDIS driver;C:\windows\System32\drivers\fwndis64.sys [2014-8-14 35336]
R3 keycrypt;keycrypt;C:\windows\System32\drivers\KeyCrypt64.sys [2014-8-6 25568]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\windows\System32\drivers\nx6000.sys [2010-12-2 31744]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\System32\drivers\RtsUStor.sys [2014-10-19 272600]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2014-10-19 941784]
R3 SuperIO;Lenovo ASD HWM Driver;C:\windows\System32\drivers\spio.sys [2009-6-5 11848]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-7-6 1738168]
S3 DrvAgent64;DrvAgent64;C:\Windows\SysWOW64\drivers\DrvAgent64.SYS [2014-7-20 21712]
S3 fssfltr;fssfltr;C:\windows\System32\drivers\fssfltr.sys [2014-10-2 58056]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2014-3-31 1512640]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\windows\System32\ieetwcollector.exe [2014-10-14 111616]
S3 jswpsapi;JumpStart Wi-Fi Protected Setup;C:\Program Files (x86)\NETGEAR\WNA1100\jswpsapi.exe [2014-3-6 954368]
S3 LEqdUsb;Logicool SetPoint Unifying KMDF USB Filter;C:\windows\System32\drivers\LEqdUsb.sys [2013-5-22 77592]
S3 LHidEqd;Logicool SetPoint Unifying KMDF HID Filter;C:\windows\System32\drivers\LHidEqd.sys [2013-5-22 13080]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\windows\System32\drivers\rdpvideominiport.sys [2014-3-8 19456]
S3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver;C:\windows\System32\drivers\Rtnic64.sys [2009-6-10 51712]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3\RpcAgentSrv.exe [2014-8-26 73712]
S3 ssmirrdr;ssmirrdr;C:\windows\System32\drivers\ssmirrdr.sys [2011-3-14 10112]
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2014-3-8 56832]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2014-3-6 1255736]
S3 wsvd;wsvd;C:\windows\System32\drivers\wsvd.sys [2009-7-21 121840]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
S4 mkvtccivnf64;mkvtccivnf64;C:\Program Files\010\mkvtccivnf64.exe run options=01100010100000000000000000000000 sourceguid=92B36EB2-53CA-4C72-9832-65CCF55DEDB1 --> C:\Program Files\010\mkvtccivnf64.exe run options=01100010100000000000000000000000 sourceguid=92B36EB2-53CA-4C72-9832-65CCF55DEDB1 [?]
.
=============== Created Last 30 ================
.
2014-11-07 19:00:57 75888 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C2839E53-29DB-42B8-BDC2-F8D5127BB795}\offreg.dll
2014-11-07 18:58:49 -------- d-----w- C:\ProgramData\Sophos
2014-11-07 18:58:30 73728 ----a-r- C:\Users\R.W.Solema\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2014-11-07 18:58:30 73728 ----a-r- C:\Users\R.W.Solema\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2014-11-07 18:58:30 73728 ----a-r- C:\Users\R.W.Solema\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe
2014-11-07 18:58:26 -------- d-----w- C:\Program Files (x86)\Sophos
2014-11-07 18:45:28 -------- d-----w- C:\Users\R.W.Solema\AppData\Roaming\Dropbox
2014-11-07 18:40:58 -------- d-----w- C:\windows\SysWow64\vbox
2014-11-07 18:40:58 -------- d-----w- C:\windows\System32\vbox
2014-11-07 18:29:34 43152 ----a-w- C:\windows\avastSS.scr
2014-11-07 18:01:49 -------- d-----w- C:\Users\R.W.Solema\AppData\Roaming\rmi
2014-11-07 12:16:40 11627712 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C2839E53-29DB-42B8-BDC2-F8D5127BB795}\mpengine.dll
2014-11-05 20:24:06 -------- d-----w- C:\Program Files (x86)\DCoder Image Source
2014-11-05 20:24:00 -------- d-----w- C:\Program Files (x86)\DirectVobSub
2014-11-05 20:23:33 -------- d-----w- C:\Program Files (x86)\MadVR
2014-11-05 20:23:18 -------- d-----w- C:\Program Files (x86)\LAV Filters
2014-11-05 20:23:04 -------- d-----w- C:\Program Files (x86)\Bass Audio Decoder
2014-11-05 20:22:58 112640 ----a-w- C:\windows\SysWow64\ff_vfw.dll
2014-11-05 20:22:57 -------- d-----w- C:\Program Files (x86)\ffdshow
2014-11-05 20:21:09 -------- d-----w- C:\ProgramData\Zoom Player
2014-11-05 20:21:09 -------- d-----w- C:\Program Files (x86)\Zoom Player
2014-11-04 21:44:41 -------- d-----w- C:\Program Files (x86)\Quintessential Media Player
2014-11-03 02:33:23 -------- d-----w- C:\Program Files (x86)\ConvertHelper
2014-10-30 20:48:18 -------- d-----w- C:\Program Files\Reason
2014-10-28 00:40:11 -------- d-----w- C:\Users\R.W.Solema\AppData\Roaming\IcoFX2X
2014-10-28 00:39:42 -------- d-----w- C:\ProgramData\IcoFX2X
2014-10-28 00:39:39 -------- d-----w- C:\Program Files (x86)\IcoFX 2
2014-10-22 19:13:26 -------- d-----w- C:\Users\R.W.Solema\AppData\Local\CrashDumps
2014-10-20 01:38:37 941784 ----a-w- C:\windows\System32\drivers\Rt64win7.sys
2014-10-20 01:38:37 73800 ----a-w- C:\windows\System32\RtNicProp64.dll
2014-10-20 01:38:21 272600 ----a-w- C:\windows\System32\drivers\RtsUStor.sys
2014-10-20 01:38:18 9890008 ----a-w- C:\windows\SysWow64\RsCRIcon.dll
2014-10-20 01:35:47 -------- d-----w- C:\ProgramData\ProductData
2014-10-20 01:35:38 -------- d-----w- C:\Program Files (x86)\IObit
2014-10-19 01:35:57 -------- d-----w- C:\Users\R.W.Solema\AppData\Roaming\COWON
2014-10-19 01:26:05 -------- d-----w- C:\Program Files (x86)\Common Files\COWON
2014-10-19 01:26:04 -------- d-----w- C:\Program Files (x86)\JetAudio
2014-10-19 01:22:51 -------- d-----w- C:\Users\R.W.Solema\AppData\Roaming\0F1L1I1P0H1L1E1E1F
2014-10-18 21:30:25 56496 ----a-w- C:\windows\SysWow64\wbhelp2.dll
2014-10-18 21:30:25 544768 ----a-w- C:\windows\SysWow64\wbocx.ocx
2014-10-18 21:30:25 258352 ----a-w- C:\windows\SysWow64\unicows.dll
2014-10-18 21:30:24 4608 ----a-w- C:\windows\SysWow64\W95INF32.DLL
2014-10-18 21:30:24 33968 ----a-w- C:\windows\SysWow64\anim.dll
2014-10-18 21:30:24 2272 ----a-w- C:\windows\SysWow64\W95INF16.DLL
2014-10-18 21:30:24 1706800 ----a-w- C:\windows\SysWow64\gdiplus.dll
2014-10-14 22:26:36 98216 ----a-w- C:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-10-14 22:18:53 507392 ----a-w- C:\windows\System32\aepdu.dll
2014-10-14 22:17:56 3179520 ----a-w- C:\windows\System32\rdpcorets.dll
2014-10-13 01:31:57 -------- d-----w- C:\Users\R.W.Solema\AppData\Local\Eraser 6
2014-10-12 00:25:53 -------- d-----w- C:\Program Files\MPC-HC
2014-10-09 09:02:23 -------- d-----w- C:\Program Files (x86)\Ruiware
.
==================== Find3M ====================
.
2014-11-07 18:29:35 65776 ----a-w- C:\windows\System32\drivers\aswRvrt.sys
2014-11-07 18:29:35 267632 ----a-w- C:\windows\System32\drivers\aswVmm.sys
2014-11-07 18:29:35 116728 ----a-w- C:\windows\System32\drivers\aswstm.sys
2014-11-07 18:29:34 93568 ----a-w- C:\windows\System32\drivers\aswRdr2.sys
2014-11-07 18:29:34 83280 ----a-w- C:\windows\System32\drivers\aswMonFlt.sys
2014-11-07 18:29:34 29208 ----a-w- C:\windows\System32\drivers\aswHwid.sys
2014-11-07 18:29:24 1050432 ----a-w- C:\windows\System32\drivers\aswsnx.sys
2014-11-07 17:37:21 129752 ----a-w- C:\windows\System32\drivers\MBAMSwissArmy.sys
2014-10-28 13:34:58 275080 ------w- C:\windows\System32\MpSigStub.exe
2014-10-20 01:39:42 71344 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-10-20 01:39:42 701104 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2014-10-20 01:38:37 107552 ----a-w- C:\windows\System32\RTNUninst64.dll
2014-10-10 02:05:59 276480 ----a-w- C:\windows\System32\generaltel.dll
2014-10-10 02:00:38 424448 ----a-w- C:\windows\System32\aeinv.dll
2014-10-01 18:11:26 63704 ----a-w- C:\windows\System32\drivers\mwac.sys
2014-10-01 18:11:16 93400 ----a-w- C:\windows\System32\drivers\mbamchameleon.sys
2014-10-01 18:11:12 25816 ----a-w- C:\windows\System32\drivers\mbam.sys
2014-09-29 00:58:48 3198976 ----a-w- C:\windows\System32\win32k.sys
2014-09-25 22:32:04 2017280 ----a-w- C:\windows\SysWow64\inetcpl.cpl
2014-09-25 22:31:02 2108416 ----a-w- C:\windows\System32\inetcpl.cpl
2014-09-25 02:08:38 371712 ----a-w- C:\windows\System32\qdvd.dll
2014-09-25 01:40:50 519680 ----a-w- C:\windows\SysWow64\qdvd.dll
2014-09-19 07:36:08 505416 ----a-w- C:\windows\SysWow64\msvcp71.dll
2014-09-19 07:36:08 353864 ----a-w- C:\windows\SysWow64\msvcr71.dll
2014-09-19 01:56:02 2724864 ----a-w- C:\windows\System32\mshtml.tlb
2014-09-19 01:55:49 4096 ----a-w- C:\windows\System32\ieetwcollectorres.dll
2014-09-19 01:40:43 66048 ----a-w- C:\windows\System32\iesetup.dll
2014-09-19 01:40:03 547328 ----a-w- C:\windows\System32\vbscript.dll
2014-09-19 01:39:58 48640 ----a-w- C:\windows\System32\ieetwproxystub.dll
2014-09-19 01:38:27 83968 ----a-w- C:\windows\System32\MshtmlDac.dll
2014-09-19 01:36:57 5829632 ----a-w- C:\windows\System32\jscript9.dll
2014-09-19 01:26:00 139264 ----a-w- C:\windows\System32\ieUnatt.exe
2014-09-19 01:25:49 111616 ----a-w- C:\windows\System32\ieetwcollector.exe
2014-09-19 01:25:12 4201472 ----a-w- C:\windows\SysWow64\jscript9.dll
2014-09-19 01:25:09 758272 ----a-w- C:\windows\System32\jscript9diag.dll
2014-09-19 01:18:02 940032 ----a-w- C:\windows\System32\MsSpellCheckingFacility.exe
2014-09-19 01:14:57 2724864 ----a-w- C:\windows\SysWow64\mshtml.tlb
2014-09-19 01:06:47 72704 ----a-w- C:\windows\System32\JavaScriptCollectionAgent.dll
2014-09-19 01:02:07 454656 ----a-w- C:\windows\SysWow64\vbscript.dll
2014-09-19 01:01:47 61952 ----a-w- C:\windows\SysWow64\iesetup.dll
2014-09-19 01:01:03 51200 ----a-w- C:\windows\SysWow64\ieetwproxystub.dll
2014-09-19 00:59:40 61952 ----a-w- C:\windows\SysWow64\MshtmlDac.dll
2014-09-19 00:50:16 112128 ----a-w- C:\windows\SysWow64\ieUnatt.exe
2014-09-19 00:49:31 597504 ----a-w- C:\windows\SysWow64\jscript9diag.dll
2014-09-19 00:40:12 1249280 ----a-w- C:\windows\System32\mshtmlmedia.dll
2014-09-19 00:36:23 60416 ----a-w- C:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-09-19 00:33:18 2309632 ----a-w- C:\windows\System32\wininet.dll
2014-09-19 00:18:55 1068032 ----a-w- C:\windows\SysWow64\mshtmlmedia.dll
2014-09-18 23:59:11 1810944 ----a-w- C:\windows\SysWow64\wininet.dll
2014-09-18 02:00:42 3241472 ----a-w- C:\windows\System32\msi.dll
2014-09-18 01:32:52 2363904 ----a-w- C:\windows\SysWow64\msi.dll
2014-09-13 01:58:18 77312 ----a-w- C:\windows\System32\packager.dll
2014-09-13 01:40:05 67072 ----a-w- C:\windows\SysWow64\packager.dll
2014-09-09 22:11:04 2048 ----a-w- C:\windows\System32\tzres.dll
2014-09-09 21:47:10 2048 ----a-w- C:\windows\SysWow64\tzres.dll
2014-09-05 02:11:09 6584320 ----a-w- C:\windows\System32\mstscax.dll
2014-09-05 01:52:41 5703168 ----a-w- C:\windows\SysWow64\mstscax.dll
2014-09-04 05:23:20 424448 ----a-w- C:\windows\System32\rastls.dll
2014-09-04 05:04:15 372736 ----a-w- C:\windows\SysWow64\rastls.dll
2014-08-29 01:18:30 25568 ----a-w- C:\windows\System32\drivers\KeyCrypt64.sys
2014-08-23 02:07:00 404480 ----a-w- C:\windows\System32\gdi32.dll
2014-08-23 01:45:55 311808 ----a-w- C:\windows\SysWow64\gdi32.dll
2014-08-19 03:11:28 693176 ----a-w- C:\windows\System32\winload.efi
2014-08-19 03:10:10 616352 ----a-w- C:\windows\System32\winresume.efi
2014-08-19 03:08:04 503808 ----a-w- C:\windows\System32\srcore.dll
2014-08-19 03:08:04 50176 ----a-w- C:\windows\System32\srclient.dll
2014-08-19 03:08:03 63488 ----a-w- C:\windows\System32\setbcdlocale.dll
2014-08-19 03:07:51 58880 ----a-w- C:\windows\System32\appidapi.dll
2014-08-19 03:07:51 32256 ----a-w- C:\windows\System32\appidsvc.dll
2014-08-19 03:07:33 296960 ----a-w- C:\windows\System32\rstrui.exe
2014-08-19 03:07:11 17920 ----a-w- C:\windows\System32\appidcertstorecheck.exe
2014-08-19 03:07:11 146944 ----a-w- C:\windows\System32\appidpolicyconverter.exe
2014-08-19 02:41:39 43008 ----a-w- C:\windows\SysWow64\srclient.dll
2014-08-19 02:41:22 50688 ----a-w- C:\windows\SysWow64\appidapi.dll
2014-08-19 02:06:56 61440 ----a-w- C:\windows\System32\drivers\appid.sys
.
============= FINISH: 11:34:46.06 ===============