Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

I have no idea how to get rid of this trojan-backdoor-windhcpsvc, also


  • Please log in to reply

#1
TiffanyLCox

TiffanyLCox

    New Member

  • Member
  • Pip
  • 2 posts
I have a Dell Inspiron 5010 running Windows 7 Home Professional which I use for school/music purposes. I use Webroot with spy sweeper which automatically runs scans daily. Three times now my Webroot has detected this trojan-backdoor-windhcpsvc. Twice since then Webroot has detected Keylogger for Chrome. I don't even have Chrome installed on my computer. I have tried and tried to get rid of these things and I have no idea what I can do. Please help me and I will love you forever...thank you in advance.
  • 0

Advertisements


#2
TiffanyLCox

TiffanyLCox

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
OTL logfile created on: 4/17/2011 4:00:09 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Owner\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory | 16.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 42.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 58.59 Gb Total Space | 31.03 Gb Free Space | 52.96% Space Free | Partition Type: NTFS
Drive D: | 229.63 Gb Total Space | 36.05 Gb Free Space | 15.70% Space Free | Partition Type: NTFS

Computer Name: PINKY | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/17 03:58:36 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Downloads\OTL.exe
PRC - [2011/04/10 02:49:09 | 001,416,848 | ---- | M] (IObit) -- C:\Users\Owner\Downloads\iobit_toolbox\Tools\Toolbox.exe
PRC - [2011/04/10 02:48:52 | 002,276,696 | ---- | M] (IObit) -- C:\Users\Owner\Downloads\iobit_toolbox\Tools\Suo12_StartupManager.exe
PRC - [2011/03/19 03:32:22 | 003,251,928 | ---- | M] (Webroot Software, Inc. ) -- C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe
PRC - [2011/03/19 03:32:18 | 001,373,208 | ---- | M] (Webroot Software, Inc. ) -- C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe
PRC - [2011/03/18 12:53:06 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/03/02 15:48:42 | 003,899,008 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe
PRC - [2011/03/02 15:48:34 | 000,158,048 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\SSU.exe
PRC - [2010/11/20 07:17:26 | 000,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\net1.exe
PRC - [2010/11/20 07:17:00 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
PRC - [2009/07/13 20:14:27 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\net.exe
PRC - [2009/06/09 09:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2009/05/05 07:39:18 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe


========== Modules (SafeList) ==========

MOD - [2011/04/17 03:58:36 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Downloads\OTL.exe
MOD - [2010/11/20 06:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/11/25 22:03:12 | 000,354,304 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2010/06/17 05:23:36 | 000,194,496 | ---- | M] (Advanced Micro Devices) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 20:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CISVC.EXE -- (CISVC)
SRV:64bit: - [2009/06/09 09:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV:64bit: - [1999/12/31 19:00:00 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011/03/19 03:32:22 | 003,251,928 | ---- | M] (Webroot Software, Inc. ) [Auto | Running] -- C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe -- (WRConsumerService)
SRV - [2011/03/02 15:48:42 | 003,899,008 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) [Auto | Running] -- C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe -- (WebrootSpySweeperService)
SRV - [2010/05/14 04:35:09 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/05/05 07:39:18 | 000,206,064 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe -- (sprtsvc_DellComms) SupportSoft Sprocket Service (DellComms)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/01/21 07:36:02 | 000,413,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/17 19:34:58 | 000,025,072 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Running] -- c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms -- (PCDSRVC{1E208CE0-FB7451FF-06020101}_0)
DRV:64bit: - [2010/10/12 16:57:14 | 000,137,248 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ssidrv.sys -- (ssidrv)
DRV:64bit: - [2010/10/12 16:57:12 | 000,055,360 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\ssfmonm.sys -- (ssfmonm)
DRV:64bit: - [2010/09/24 04:46:32 | 000,116,752 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010/03/31 19:52:24 | 000,033,792 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lgandmodem64.sys -- (ANDModem)
DRV:64bit: - [2010/03/31 19:52:22 | 000,027,136 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lgandgps64.sys -- (AndGps)
DRV:64bit: - [2010/03/31 19:52:20 | 000,027,648 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lganddiag64.sys -- (AndDiag)
DRV:64bit: - [2010/03/31 19:52:18 | 000,019,456 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lgandbus64.sys -- (Andbus)
DRV:64bit: - [2010/03/17 00:44:45 | 000,301,104 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/03/09 09:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010/02/18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009/12/17 00:16:18 | 000,020,984 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcmvwl64.sys -- (BcmVWL)
DRV:64bit: - [2009/12/17 00:16:14 | 003,053,560 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/15 15:06:42 | 000,172,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 15:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 15:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2006/11/01 13:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [1999/12/31 19:00:00 | 007,883,264 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [1999/12/31 19:00:00 | 000,285,696 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [1999/12/31 19:00:00 | 000,073,784 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [1999/12/31 19:00:00 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [1999/12/31 19:00:00 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV - [2010/11/17 19:35:04 | 000,026,192 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWow64\drivers\PcdrNdisuio.sys -- (PcdrNdisuio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = file://c:\windows\syswow64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = file://c:\windows\syswow64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 1A DD B5 B9 F8 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://ws.infospace...._id=62781&qkw="


FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/11 22:09:00 | 000,000,000 | ---D | M]

[2010/10/22 02:32:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\mozilla\Extensions
[2011/04/11 09:59:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\vjgi6jym.default\extensions
[2011/03/03 12:03:13 | 000,004,855 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\vjgi6jym.default\searchplugins\google-images.xml
[2011/03/03 12:06:27 | 000,002,152 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\vjgi6jym.default\searchplugins\qrobeit.xml
[2011/04/02 10:12:30 | 000,001,742 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\vjgi6jym.default\searchplugins\search-the-web.xml
[2011/03/03 11:26:05 | 000,001,679 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\vjgi6jym.default\searchplugins\thepiratebayorg.xml
[2011/03/03 12:08:34 | 000,001,224 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\vjgi6jym.default\searchplugins\yahoo-answers.xml
[2011/04/11 22:09:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) --
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJGI6JYM.DEFAULT\EXTENSIONS\{AFE43E80-0ABC-4DF2-81A0-3FE44B74ABE8}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VJGI6JYM.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
[2011/03/18 12:53:24 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/04/16 01:47:03 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No CLSID value found.
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe (Dell Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [WebrootTrayApp] C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/im...r/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell....r/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.196.64.53 68.113.206.10 24.178.162.3
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Authentication Packages - (ows\w) - File not found
O30 - LSA: Authentication Packages - (ows\w) - File not found
O30:64bit: - LSA: Security Packages - (ce.exe) - File not found
O30:64bit: - LSA: Security Packages - (.0\) - File not found
O30:64bit: - LSA: Security Packages - (\) - \ File not found
O30:64bit: - LSA: Security Packages - (7\) - File not found
O30:64bit: - LSA: Security Packages - (rdconv .exe) - File not found
O30:64bit: - LSA: Security Packages - (ns\wordconv .ex) - File not found
O30 - LSA: Security Packages - (ce.exe) - File not found
O30 - LSA: Security Packages - (.0\) - File not found
O30 - LSA: Security Packages - (\) - \ File not found
O30 - LSA: Security Packages - (7\) - File not found
O30 - LSA: Security Packages - (rdconv .exe) - File not found
O30 - LSA: Security Packages - (ns\wordconv .ex) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/17 03:31:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2011/04/16 05:54:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LGMobile Support Tool
[2011/04/16 05:53:49 | 000,000,000 | ---D | C] -- C:\ProgramData\LGMOBILEAX
[2011/04/16 03:46:27 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\uTorrent
[2011/04/11 22:08:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011/04/11 18:27:23 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Malwarebytes
[2011/04/11 18:27:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/04/11 18:26:57 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/04/09 22:33:36 | 000,000,000 | ---D | C] -- C:\Windows\Internet Logs
[2011/04/09 14:31:10 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\CheckPoint
[2011/04/09 14:29:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2011/04/09 14:25:18 | 000,000,000 | ---D | C] -- C:\ProgramData\CheckPoint
[2011/04/09 14:16:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/04/09 14:16:50 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/04/08 11:57:14 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\VirtualStore
[2011/04/08 11:16:42 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\MediaMonkey
[2011/04/08 01:51:44 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Mozilla
[2011/04/06 20:18:35 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell Inc
[2011/04/06 19:56:41 | 000,026,192 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\SysWow64\drivers\PcdrNdisuio.sys
[2011/04/06 18:07:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/04/06 18:06:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2011/04/06 18:06:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011/04/06 18:05:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2011/04/06 18:05:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2011/04/06 13:42:55 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\TweakNow PowerPack 2011
[2011/04/06 13:37:19 | 000,000,000 | ---D | C] -- C:\Windows\uninstall
[2011/04/06 09:49:21 | 000,000,000 | R--D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp
[2011/04/04 16:56:53 | 000,334,848 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO3064.dll
[2011/04/04 16:53:47 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2011/04/04 16:53:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011/04/04 16:52:05 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2011/04/04 16:52:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2011/04/04 15:08:57 | 000,462,336 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2011/04/04 15:08:57 | 000,203,264 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2011/04/04 15:08:53 | 000,120,320 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2011/04/04 15:08:52 | 000,012,288 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2011/04/04 14:51:29 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\SlimWare Utilities Inc
[2011/04/04 14:45:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
[2011/04/04 07:32:23 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Apple Computer
[2011/04/04 05:56:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Stardock
[2011/04/04 04:14:51 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/04/02 10:49:54 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\AMD
[2011/04/02 10:49:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2011/04/02 10:49:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2011/04/02 10:49:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2011/04/02 10:48:45 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2011/04/02 10:43:18 | 000,000,000 | ---D | C] -- C:\ATI
[2011/04/02 10:42:15 | 000,000,000 | ---D | C] -- C:\AMD
[2011/04/02 05:24:58 | 000,544,768 | ---- | C] (Stardock Corporation) -- C:\Windows\SysWow64\wbocx.ocx
[2011/04/02 05:24:58 | 000,056,496 | ---- | C] (Stardock.Net, Inc) -- C:\Windows\SysWow64\wbhelp2.dll
[2011/04/02 05:24:58 | 000,033,968 | ---- | C] (Neil Banfield) -- C:\Windows\SysWow64\anim.dll
[2011/03/28 16:31:17 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\lnk_disabled
[2011/03/28 16:31:17 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\ExpertScan
[2011/03/24 21:17:22 | 000,000,000 | ---D | C] -- C:\Users\Owner\SecurityScans
[2011/03/24 19:51:28 | 000,000,000 | ---D | C] -- C:\Users\Owner\New folder
[2011/03/24 17:24:05 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\FixCleaner
[2011/03/21 23:00:52 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\catroot2
[2011/03/21 22:17:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows Genuine Advantage
[2011/03/21 19:56:10 | 000,053,760 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/03/21 19:56:06 | 000,051,712 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/03/19 10:02:50 | 000,131,072 | ---- | C] (Dell, Inc.) -- C:\Windows\SysWow64\DellSPMsg.dll
[2011/03/19 08:19:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Citrix
[2011/03/19 08:18:32 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Citrix
[2011/03/18 06:46:23 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{7BE3606C-110E-4B37-B1DD-B689AE992454}
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/17 04:06:31 | 000,000,422 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2011/04/17 02:37:51 | 000,007,606 | ---- | M] () -- C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2011/04/17 01:32:16 | 000,002,411 | ---- | M] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2011/04/16 13:13:17 | 000,165,018 | ---- | M] () -- C:\Users\Owner\Desktop\accessController.pdf
[2011/04/16 13:11:51 | 000,005,129 | ---- | M] () -- C:\Users\Owner\Desktop\documentTrackingSheet.gif
[2011/04/16 05:59:20 | 000,730,966 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/04/16 05:59:20 | 000,626,688 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/04/16 05:59:20 | 000,107,792 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/04/16 05:52:09 | 000,013,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/16 05:52:09 | 000,013,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/16 03:47:12 | 000,000,267 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/04/16 03:47:12 | 000,000,267 | ---- | M] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/04/16 02:10:41 | 000,003,472 | ---- | M] () -- C:\Users\Owner\Documents\cc_20110416_021028.reg
[2011/04/16 01:45:34 | 000,379,128 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/04/16 01:45:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/04/16 01:45:18 | 1406,087,168 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/12 10:26:35 | 000,000,366 | ---- | M] () -- C:\Users\Owner\Documents\cc_20110412_102628.reg
[2011/04/11 22:09:02 | 000,001,136 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/04/11 22:09:01 | 000,002,010 | ---- | M] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/11 21:59:07 | 000,001,124 | ---- | M] () -- C:\Users\Owner\Documents\cc_20110411_215858.reg
[2011/04/11 20:46:13 | 000,032,648 | ---- | M] () -- C:\Users\Owner\Documents\cc_20110411_204605.reg
[2011/04/11 20:45:47 | 000,074,384 | ---- | M] () -- C:\Users\Owner\Documents\cc_20110411_204405.reg
[2011/04/11 20:31:03 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/04/11 12:08:32 | 000,146,223 | ---- | M] () -- C:\Users\Owner\Desktop\bookmarks.html
[2011/04/11 12:08:09 | 000,165,174 | ---- | M] () -- C:\Users\Owner\Desktop\bookmarks-2011-04-11.json
[2011/04/10 05:35:12 | 000,012,326 | ---- | M] () -- C:\Users\Owner\Desktop\Toolbox - Shortcut.lnk
[2011/04/09 14:20:40 | 000,185,732 | ---- | M] () -- C:\Users\Owner\Documents\cc_20110409_142011.reg
[2011/04/08 02:51:43 | 000,001,019 | ---- | M] () -- C:\Users\Owner\windows-kb890830-x64-v3.17 - Shortcut.lnk
[2011/04/07 10:21:49 | 000,000,979 | ---- | M] () -- C:\Users\Owner\Desktop\PC Checkup.lnk
[2011/04/06 20:19:58 | 015,388,232 | ---- | M] () -- C:\Users\Owner\Documents\DELL_SYSTEM-SOFTWARE_A01_R260746.exe
[2011/04/06 19:40:18 | 000,070,446 | ---- | M] () -- C:\Users\Owner\Documents\Test Event Logs - Full System Test.html
[2011/04/06 18:07:26 | 000,001,807 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/06 08:46:46 | 000,000,046 | ---- | M] () -- C:\Windows\SysWow64\_WKERNEL.FRE
[2011/04/02 11:17:38 | 000,707,378 | ---- | M] () -- C:\Windows\SysNative\oem113.inf
[2011/03/25 03:48:20 | 000,022,752 | ---- | M] () -- C:\Windows\hpqins15.dat
[2011/03/22 00:42:39 | 000,001,399 | ---- | M] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/03/21 22:25:17 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/03/21 22:25:13 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2011/03/21 19:56:26 | 000,061,952 | ---- | M] () -- C:\Windows\SysNative\OVDecode64.dll
[2011/03/21 19:56:22 | 000,059,904 | ---- | M] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/03/21 19:56:10 | 000,053,760 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/03/21 19:56:06 | 000,051,712 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/03/19 08:36:28 | 002,003,392 | ---- | M] () -- C:\Users\Owner\Documents\M5010A09.EXE
[2011/03/19 08:18:31 | 000,103,784 | ---- | M] () -- C:\Users\Owner\GoToAssistDownloadHelper.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/16 13:13:15 | 000,165,018 | ---- | C] () -- C:\Users\Owner\Desktop\accessController.pdf
[2011/04/16 13:11:42 | 000,005,129 | ---- | C] () -- C:\Users\Owner\Desktop\documentTrackingSheet.gif
[2011/04/16 03:47:12 | 000,000,267 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/04/16 03:47:12 | 000,000,267 | ---- | C] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/04/16 02:10:31 | 000,003,472 | ---- | C] () -- C:\Users\Owner\Documents\cc_20110416_021028.reg
[2011/04/12 10:26:30 | 000,000,366 | ---- | C] () -- C:\Users\Owner\Documents\cc_20110412_102628.reg
[2011/04/11 22:09:02 | 000,001,148 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/04/11 22:09:02 | 000,001,136 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/04/11 21:59:00 | 000,001,124 | ---- | C] () -- C:\Users\Owner\Documents\cc_20110411_215858.reg
[2011/04/11 20:46:06 | 000,032,648 | ---- | C] () -- C:\Users\Owner\Documents\cc_20110411_204605.reg
[2011/04/11 20:44:07 | 000,074,384 | ---- | C] () -- C:\Users\Owner\Documents\cc_20110411_204405.reg
[2011/04/11 12:08:32 | 000,146,223 | ---- | C] () -- C:\Users\Owner\Desktop\bookmarks.html
[2011/04/11 12:08:02 | 000,165,174 | ---- | C] () -- C:\Users\Owner\Desktop\bookmarks-2011-04-11.json
[2011/04/10 05:35:12 | 000,012,326 | ---- | C] () -- C:\Users\Owner\Desktop\Toolbox - Shortcut.lnk
[2011/04/09 14:20:14 | 000,185,732 | ---- | C] () -- C:\Users\Owner\Documents\cc_20110409_142011.reg
[2011/04/08 02:51:43 | 000,001,019 | ---- | C] () -- C:\Users\Owner\windows-kb890830-x64-v3.17 - Shortcut.lnk
[2011/04/07 10:21:49 | 000,000,979 | ---- | C] () -- C:\Users\Owner\Desktop\PC Checkup.lnk
[2011/04/06 20:19:44 | 015,388,232 | ---- | C] () -- C:\Users\Owner\Documents\DELL_SYSTEM-SOFTWARE_A01_R260746.exe
[2011/04/06 19:40:17 | 000,070,446 | ---- | C] () -- C:\Users\Owner\Documents\Test Event Logs - Full System Test.html
[2011/04/06 18:07:26 | 000,001,807 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/06 18:05:33 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/04/04 15:08:52 | 000,614,400 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2011/04/04 15:08:52 | 000,614,400 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2011/04/04 15:08:52 | 000,224,342 | ---- | C] () -- C:\Windows\SysNative\atiicdxx.dat
[2011/04/04 15:08:52 | 000,002,857 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/04/04 15:08:52 | 000,002,857 | ---- | C] () -- C:\Windows\SysNative\atipblag.dat
[2011/04/04 15:08:51 | 000,078,832 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2011/04/04 15:08:43 | 000,022,190 | ---- | C] () -- C:\Windows\atiogl.xml
[2011/04/02 11:17:55 | 000,707,378 | ---- | C] () -- C:\Windows\SysNative\oem113.inf
[2011/04/02 05:25:20 | 000,000,046 | ---- | C] () -- C:\Windows\SysWow64\_WKERNEL.FRE
[2011/04/02 05:24:57 | 000,000,439 | ---- | C] () -- C:\Windows\SysWow64\shfolder.inf
[2011/03/25 03:48:18 | 000,022,752 | ---- | C] () -- C:\Windows\hpqins15.dat
[2011/03/24 19:51:45 | 000,000,439 | ---- | C] () -- C:\Users\Owner\d3dcsx_42_x64_xp.inf
[2011/03/24 19:51:42 | 000,075,776 | ---- | C] () -- C:\Users\Owner\infinst.exe
[2011/03/21 22:25:17 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/03/21 22:25:13 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011/03/21 19:56:26 | 000,061,952 | ---- | C] () -- C:\Windows\SysNative\OVDecode64.dll
[2011/03/21 19:56:22 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/03/19 08:36:22 | 002,003,392 | ---- | C] () -- C:\Users\Owner\Documents\M5010A09.EXE
[2011/03/19 08:18:30 | 000,103,784 | ---- | C] () -- C:\Users\Owner\GoToAssistDownloadHelper.exe
[2011/03/06 12:28:19 | 000,007,606 | ---- | C] () -- C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2011/02/14 13:06:54 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2011/02/14 13:06:54 | 000,002,411 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2010/12/12 05:39:41 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/12/09 17:50:24 | 000,023,693 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\UserTile.png
[2010/10/27 14:37:09 | 000,000,140 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2010/08/20 13:14:06 | 000,030,424 | ---- | C] () -- C:\Windows\SysWow64\wrLZMA.dll
[2010/05/14 04:31:09 | 000,000,080 | RHS- | C] () -- C:\Windows\CT4CET.bin
[2010/05/14 04:27:03 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/05/14 04:26:48 | 000,000,193 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2010/05/14 04:26:48 | 000,000,147 | ---- | C] () -- C:\Windows\WisPriority.ini
[2010/05/14 04:26:48 | 000,000,035 | ---- | C] () -- C:\Windows\DELL_LANGCODE.ini
[2010/05/14 04:26:48 | 000,000,033 | ---- | C] () -- C:\Windows\DELL_OSTYPE.ini
[2010/05/14 04:26:48 | 000,000,032 | ---- | C] () -- C:\Windows\WisHWDest.ini
[2010/05/14 04:26:48 | 000,000,028 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2010/05/14 04:26:48 | 000,000,023 | ---- | C] () -- C:\Windows\WisSysInfo.ini
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:59:36 | 000,982,196 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 16:59:36 | 000,139,824 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 16:59:36 | 000,097,448 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 16:59:35 | 000,417,344 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/04/09 14:31:10 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\CheckPoint
[2011/04/11 21:27:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\FixCleaner
[2011/04/10 04:24:28 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\IObit
[2011/03/03 09:49:48 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PCDr
[2010/10/27 14:37:13 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Template
[2011/04/08 02:59:39 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\TweakNow PowerPack 2011
[2011/04/17 01:57:20 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\uTorrent
[2011/04/11 20:31:03 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/03/29 10:45:15 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/04/17 04:06:31 | 000,000,422 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



< End of report >
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP