Zoek.exe v5.0.0.0 Updated 08-September-2015 Tool run by User1 on zo 13/09/2015 at 14:38:53,91. Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\User1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\652P0G67\zoek[1].exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2015-09-11-060336.log 502 bytes C:\zoek-results2015-09-11-074626.log 25687 bytes ==== Empty Folders Check ====================== C:\Users\User1\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Folders Found ====================== 2014-10-07 19:13:39 2015-08-27 18:04:14 -------- d-----w- C:\ProgramData\Microsoft\Microsoft Security Client 2014-10-07 19:13:39 2015-08-27 18:04:14 -------- d-----w- C:\Users\All Users\Microsoft\Microsoft Security Client 2015-09-11 07:29:32 2015-09-11 07:29:32 -------- d---a-w- C:\zoek_backup\C_Program Files (x86)_Microsoft Security Client 2015-09-08 06:27:39 2015-09-08 06:27:39 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_00e6e752 2015-08-29 08:06:45 2015-08-29 08:06:45 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_039ea69a 2015-08-28 09:40:40 2015-08-28 09:40:40 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_043ab183 2015-09-01 16:07:58 2015-09-01 16:07:58 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_048105ab 2015-08-31 10:08:25 2015-08-31 10:08:25 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0490f2c7 2015-09-02 15:13:24 2015-09-02 15:13:24 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0490fc29 2015-09-01 04:55:27 2015-09-01 04:55:27 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0498ce75 2015-09-02 11:05:34 2015-09-02 11:05:34 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_049d0962 2015-09-08 05:16:24 2015-09-08 05:16:24 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a1054d 2015-08-29 11:10:28 2015-08-29 11:10:28 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a4ce46 2015-09-08 10:33:22 2015-09-08 10:33:22 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a508f5 2015-09-07 09:25:12 2015-09-07 09:25:12 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a8d883 2015-08-31 14:10:20 2015-08-31 14:10:20 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a8e149 2015-09-05 05:54:06 2015-09-05 05:54:06 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b0bedb 2015-09-05 05:54:11 2015-09-05 05:54:11 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b0d22c 2015-09-04 07:47:07 2015-09-04 07:47:07 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b16c68 2015-09-04 07:47:12 2015-09-04 07:47:12 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b17fd9 2015-09-04 07:47:17 2015-09-04 07:47:17 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b19349 2015-09-04 07:47:22 2015-09-04 07:47:22 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b1a69a 2015-09-04 07:47:39 2015-09-04 07:47:39 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b1e8f7 2015-09-04 07:47:44 2015-09-04 07:47:44 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b1fc77 2015-08-30 10:17:20 2015-08-30 10:17:20 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b4c995 2015-09-06 10:51:44 2015-09-06 10:51:44 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04bce2ef 2015-08-28 05:49:05 2015-08-28 05:49:05 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04c49e22 2015-09-07 17:38:36 2015-09-07 17:38:36 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04c4c8ba 2015-09-05 09:34:47 2015-09-05 09:34:47 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04c8e8d8 2015-08-29 05:21:25 2015-08-29 05:21:25 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_05769ebe 2015-08-29 04:45:13 2015-08-29 04:45:13 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0586a2e3 2015-08-29 05:37:51 2015-08-29 05:37:51 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_059696c2 2015-09-05 07:13:31 2015-09-05 07:13:31 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_05ae952d 2015-08-29 06:28:26 2015-08-29 06:28:27 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_061aba0b 2015-08-27 18:34:32 2015-08-27 18:34:32 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_07226759 2015-09-08 05:36:55 2015-09-08 05:36:55 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0786d077 2015-08-31 10:17:04 2015-08-31 10:17:04 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_08a68e1b 2015-09-05 06:43:16 2015-09-05 06:43:16 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_08be7b95 2015-09-01 07:57:04 2015-09-01 07:57:04 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_08c6a553 2015-08-27 18:16:25 2015-08-27 18:16:25 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_08dab7ba 2015-09-02 04:51:47 2015-09-02 04:51:47 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_09baae19 2015-09-08 06:17:35 2015-09-08 06:17:35 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0ab2aabf 2015-09-03 09:38:22 2015-09-03 09:38:22 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0b6295d8 2015-08-29 06:13:32 2015-08-29 06:13:32 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0b728ee6 2015-08-29 10:59:16 2015-08-29 10:59:16 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0b828ae0 2015-08-30 11:09:44 2015-08-30 11:09:44 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0bc2a736 2015-08-29 07:00:27 2015-08-29 07:00:27 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0be6ba68 2015-08-29 12:32:53 2015-08-29 12:32:53 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0c2eae67 2015-08-29 05:49:07 2015-08-29 05:49:07 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0c46c541 2015-09-05 06:18:18 2015-09-05 06:18:18 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0cea90aa 2015-09-03 13:48:31 2015-09-03 13:48:31 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0db28d31 2015-08-29 06:03:22 2015-08-29 06:03:22 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0e06ce55 2015-08-30 10:40:51 2015-08-30 10:40:51 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0e269194 2015-09-02 06:04:42 2015-09-02 06:04:42 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0e82a7c3 2015-08-28 09:27:42 2015-08-28 09:27:42 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0e8e9b64 2015-09-01 06:09:38 2015-09-01 06:09:38 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0ea69819 2015-09-05 06:10:13 2015-09-05 06:10:13 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0f768545 2015-08-28 10:38:54 2015-08-28 10:38:54 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0fa29d19 2015-08-28 05:38:16 2015-08-28 05:38:16 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0fd2b691 2015-09-03 04:28:20 2015-09-03 04:28:20 -------- dc----w- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0fdf09ee 2015-09-08 06:27:39 2015-09-08 06:27:39 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_00e6e752 2015-08-29 08:06:45 2015-08-29 08:06:45 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_039ea69a 2015-08-28 09:40:40 2015-08-28 09:40:40 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_043ab183 2015-09-01 16:07:58 2015-09-01 16:07:58 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_048105ab 2015-08-31 10:08:25 2015-08-31 10:08:25 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0490f2c7 2015-09-02 15:13:24 2015-09-02 15:13:24 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0490fc29 2015-09-01 04:55:27 2015-09-01 04:55:27 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0498ce75 2015-09-02 11:05:34 2015-09-02 11:05:34 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_049d0962 2015-09-08 05:16:24 2015-09-08 05:16:24 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a1054d 2015-08-29 11:10:28 2015-08-29 11:10:28 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a4ce46 2015-09-08 10:33:22 2015-09-08 10:33:22 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a508f5 2015-09-07 09:25:12 2015-09-07 09:25:12 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a8d883 2015-08-31 14:10:20 2015-08-31 14:10:20 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04a8e149 2015-09-05 05:54:06 2015-09-05 05:54:06 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b0bedb 2015-09-05 05:54:11 2015-09-05 05:54:11 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b0d22c 2015-09-04 07:47:07 2015-09-04 07:47:07 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b16c68 2015-09-04 07:47:12 2015-09-04 07:47:12 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b17fd9 2015-09-04 07:47:17 2015-09-04 07:47:17 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b19349 2015-09-04 07:47:22 2015-09-04 07:47:22 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b1a69a 2015-09-04 07:47:39 2015-09-04 07:47:39 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b1e8f7 2015-09-04 07:47:44 2015-09-04 07:47:44 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b1fc77 2015-08-30 10:17:20 2015-08-30 10:17:20 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04b4c995 2015-09-06 10:51:44 2015-09-06 10:51:44 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04bce2ef 2015-08-28 05:49:05 2015-08-28 05:49:05 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04c49e22 2015-09-07 17:38:36 2015-09-07 17:38:36 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04c4c8ba 2015-09-05 09:34:47 2015-09-05 09:34:47 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_04c8e8d8 2015-08-29 05:21:25 2015-08-29 05:21:25 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_05769ebe 2015-08-29 04:45:13 2015-08-29 04:45:13 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0586a2e3 2015-08-29 05:37:51 2015-08-29 05:37:51 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_059696c2 2015-09-05 07:13:31 2015-09-05 07:13:31 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_05ae952d 2015-08-29 06:28:26 2015-08-29 06:28:27 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_061aba0b 2015-08-27 18:34:32 2015-08-27 18:34:32 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_07226759 2015-09-08 05:36:55 2015-09-08 05:36:55 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0786d077 2015-08-31 10:17:04 2015-08-31 10:17:04 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_08a68e1b 2015-09-05 06:43:16 2015-09-05 06:43:16 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_08be7b95 2015-09-01 07:57:04 2015-09-01 07:57:04 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_08c6a553 2015-08-27 18:16:25 2015-08-27 18:16:25 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_08dab7ba 2015-09-02 04:51:47 2015-09-02 04:51:47 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_09baae19 2015-09-08 06:17:35 2015-09-08 06:17:35 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0ab2aabf 2015-09-03 09:38:22 2015-09-03 09:38:22 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0b6295d8 2015-08-29 06:13:32 2015-08-29 06:13:32 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0b728ee6 2015-08-29 10:59:16 2015-08-29 10:59:16 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0b828ae0 2015-08-30 11:09:44 2015-08-30 11:09:44 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0bc2a736 2015-08-29 07:00:27 2015-08-29 07:00:27 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0be6ba68 2015-08-29 12:32:53 2015-08-29 12:32:53 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0c2eae67 2015-08-29 05:49:07 2015-08-29 05:49:07 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0c46c541 2015-09-05 06:18:18 2015-09-05 06:18:18 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0cea90aa 2015-09-03 13:48:31 2015-09-03 13:48:31 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0db28d31 2015-08-29 06:03:22 2015-08-29 06:03:22 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0e06ce55 2015-08-30 10:40:51 2015-08-30 10:40:51 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0e269194 2015-09-02 06:04:42 2015-09-02 06:04:42 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0e82a7c3 2015-08-28 09:27:42 2015-08-28 09:27:42 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0e8e9b64 2015-09-01 06:09:38 2015-09-01 06:09:38 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0ea69819 2015-09-05 06:10:13 2015-09-05 06:10:13 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0f768545 2015-08-28 10:38:54 2015-08-28 10:38:54 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0fa29d19 2015-08-28 05:38:16 2015-08-28 05:38:16 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0fd2b691 2015-09-03 04:28:20 2015-09-03 04:28:20 -------- dc----w- C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppHang_MBAMService_8c848a11c5173ff33b32a03e617e2bd9fceec85_0fdf09ee ==== Files Found ====================== --- C:\Users\User1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.avast.com_0.localstorage-journal --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 3608 Created time: 2015-01-24 08:19:10 Modified time: 2015-01-24 08:19:11 MD5: 542F54146E1E9320725B1D5A3680DF80 SHA1: BDDC539324B3C7F7B9F363F36A854D1B554F62CB --- C:\Users\User1\Downloads\avast_premier_antivirus_setup_online.exe --- Company: AVAST Software File Description: avast! Antivirus Installer File Version: 10.0.2208.712 Product Name: Avast Antivirus Copyright: Copyright (c) 2014 AVAST Software Original Filename: SfxInst.exe File type: ----a-w- File size: 4978536 Created time: 2015-01-24 08:23:41 Modified time: 2015-01-24 08:24:08 MD5: DDCCF75551DA2D1A6E598AA2416A2135 SHA1: 8E30CA195762D47ABFAFA7F1294381553A3FC0A9 --- C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-2015-08-23 (21-12-31).xml --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 3234 Created time: 2015-08-23 19:25:55 Modified time: 2015-08-23 19:25:55 MD5: D54C4C8DE06FC87C466447CFC789E2C1 SHA1: 4AA8955AF2C529EC1BDDD3B702424A24F7378BF5 --- C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-2015-08-26 (13-06-26).xml --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 2494 Created time: 2015-08-26 11:20:14 Modified time: 2015-08-26 11:20:14 MD5: 5A5B85835198D7D0E9DB4C5C4248A821 SHA1: 2B2B2CF4D1C76C0A9BEC2C0A51FC21285D2FF91A --- C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-2015-08-26 (19-34-06).xml --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 2494 Created time: 2015-08-26 17:43:49 Modified time: 2015-08-26 17:43:49 MD5: 54D6BA33A04584411A38A12F352AEB37 SHA1: B483CE3C9E16C2DA90E7FD72F8CBEFF25B7F398D --- C:\Users\All Users\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-2015-08-23 (21-12-31).xml --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 3234 Created time: 2015-08-23 19:25:55 Modified time: 2015-08-23 19:25:55 MD5: D54C4C8DE06FC87C466447CFC789E2C1 SHA1: 4AA8955AF2C529EC1BDDD3B702424A24F7378BF5 --- C:\Users\All Users\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-2015-08-26 (13-06-26).xml --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 2494 Created time: 2015-08-26 11:20:14 Modified time: 2015-08-26 11:20:14 MD5: 5A5B85835198D7D0E9DB4C5C4248A821 SHA1: 2B2B2CF4D1C76C0A9BEC2C0A51FC21285D2FF91A --- C:\Users\All Users\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-2015-08-26 (19-34-06).xml --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 2494 Created time: 2015-08-26 17:43:49 Modified time: 2015-08-26 17:43:49 MD5: 54D6BA33A04584411A38A12F352AEB37 SHA1: B483CE3C9E16C2DA90E7FD72F8CBEFF25B7F398D --- C:\Users\User1\Downloads\mbam-setup-2.1.8.1057.exe --- Company: Malwarebytes Corporation File Description: Malwarebytes Anti-Malware File Version: 2.1.8.1057 Product Name: Malwarebytes Anti-Malware Copyright: (c) Malwarebytes Corporation. All rights reserved. Original Filename: File type: ----a-w- File size: 24345872 Created time: 2015-08-23 19:08:10 Modified time: 2015-08-23 19:08:26 MD5: D3B6FA14CB7E12B7FBC0B3AA26235898 SHA1: 7783C2A681393DBAE743E830C255420483A38F7D --- C:\Windows\Prefetch\MBAM.EXE-2FB6D924.pf --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 114752 Created time: 2015-09-07 17:41:26 Modified time: 2015-09-08 10:37:43 MD5: A70BF20F9767E4EAF1085C34D39E733D SHA1: 87CC0C5167D8A3DDEC0AF834F4624B22DEF0DB28 --- C:\Windows\Prefetch\MBAMSCHEDULER.EXE-E854CD0F.pf --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 40886 Created time: 2015-09-07 17:26:34 Modified time: 2015-09-08 06:31:54 MD5: B467006C53B475AAA6E840398CBAD233 SHA1: 1759CF5ACA53ADA9ED6435B29C9F90D93DEB5E6F --- C:\Windows\Prefetch\MBAMSERVICE.EXE-351A0DC9.pf --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 44036 Created time: 2015-09-07 09:13:06 Modified time: 2015-09-08 10:20:55 MD5: 886F8C6A4D7DF9A9759009FAF22EB8CE SHA1: DF38B45CA1F9784E5EE8887C3B24D9FB09ACEC99