Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

trojan zbot trojan pws


  • Please log in to reply

#1
jamie829

jamie829

    Member

  • Member
  • PipPip
  • 18 posts
I am infected with a trojan. Mbam found trojan.zbot and trojan.pws after a recent scan, I attempted to have mbam remove them but I think the problem is still present. I am having the same symptoms as this post: http://www.geekstogo...ng-trojan-zbot/

OTL Quick scan found:

OTL logfile created on: 3/28/2012 5:22:22 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\eric\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.64 Gb Available Physical Memory | 42.49% Memory free
3.35 Gb Paging File | 2.70 Gb Available in Paging File | 80.63% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 24.52 Gb Free Space | 65.90% Space Free | Partition Type: NTFS
Drive F: | 1.00 Gb Total Space | 0.80 Gb Free Space | 79.70% Space Free | Partition Type: NTFS

Computer Name: ERIC-PC | User Name: eric | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/03/28 17:21:07 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\eric\My Documents\Downloads\OTL.exe
PRC - [2012/03/19 16:05:54 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Documents and Settings\eric\Local Settings\Application Data\Mozilla Firefox\firefox.exe
PRC - [2012/01/13 14:53:16 | 000,981,680 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2011/06/15 16:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 16:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/07/02 14:25:48 | 000,656,896 | ---- | M] (j2 Global Communications, Inc.) -- C:\Program Files\eFax Messenger 4.4\J2GTray.exe
PRC - [2010/07/02 14:24:07 | 000,095,744 | ---- | M] (j2 Global Communications, Inc.) -- C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/04/18 12:10:16 | 000,692,224 | ---- | M] (SHARP CORPORATION) -- C:\Program Files\Sharp\Sharpdesk\FTPServer.exe
PRC - [2006/04/18 12:08:02 | 000,544,768 | ---- | M] (SHARP CORPORATION) -- C:\Program Files\Sharp\Sharpdesk\nsapp.exe
PRC - [2006/04/17 02:16:14 | 000,032,768 | ---- | M] (SHARP CORPORATION) -- C:\Program Files\Sharp\Sharpdesk\SharpTray.exe


========== Modules (No Company Name) ==========

MOD - [2012/03/19 16:05:53 | 001,969,080 | ---- | M] () -- C:\Documents and Settings\eric\Local Settings\Application Data\Mozilla Firefox\mozjs.dll
MOD - [2012/03/05 10:17:30 | 008,527,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2011/04/27 16:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\ComboFix\mbr.sys -- (mbr)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\eric\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\aeaudio.sys -- (aeaudio)
DRV - [2012/03/28 17:15:27 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012/03/28 16:27:01 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1F0F91A9-7890-4DB1-AE19-ECE143FA2361}\MpKsl37091a06.sys -- (MpKsl37091a06)
DRV - [2004/09/17 10:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
DRV - [2003/06/30 19:11:52 | 000,043,136 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2001/08/17 08:11:38 | 000,128,000 | ---- | M] (Compaq Computer Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\n100325.sys -- (N100)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A6 EE 1A E7 E8 D9 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {AC5E78EB-5582-4DE9-9AE7-6248E47E4682}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{AC5E78EB-5582-4DE9-9AE7-6248E47E4682}: "URL" = http://www.google.co...age={startPage}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 192.168.1.*

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..keyword.URL: "http://www.google.co...ient&gfns=1&q="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Documents and Settings\eric\Local Settings\Application Data\Mozilla Firefox\components [2012/03/19 16:05:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Documents and Settings\eric\Local Settings\Application Data\Mozilla Firefox\plugins

[2011/12/21 12:38:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\eric\Application Data\Mozilla\Extensions
[2012/01/05 12:10:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\eric\Application Data\Mozilla\Firefox\Profiles\mx499vsp.default\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\ERIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\MX499VSP.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI

O1 HOSTS File: ([2012/03/28 16:41:21 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [FtpServer.exe] C:\Program Files\Sharp\Sharpdesk\FtpServer.exe (SHARP CORPORATION)
O4 - HKLM..\Run: [IndexTray] C:\Program Files\Sharp\Sharpdesk\IndexTray.exe (SHARP CORPORATION)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SharpTray] C:\Program Files\Sharp\Sharpdesk\SharpTray.exe (SHARP CORPORATION)
O4 - HKLM..\Run: [TypeRegChecker] C:\Program Files\Sharp\Sharpdesk\TypeRegChecker.exe (SHARP CORPORATION)
O4 - HKCU..\Run: [eFax 4.4] C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe (j2 Global Communications, Inc.)
O4 - HKCU..\Run: [Xyicmud] "C:\Documents and Settings\eric\Application Data\Iqahi\qevu.exe" File not found
O4 - Startup: C:\Documents and Settings\eric\Start Menu\Programs\Startup\eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe (j2 Global Communications, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O15 - HKCU\..Trusted Domains: dell.com ([]* in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.112.138 167.206.7.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = _______.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6FAD25E3-E688-4DF0-8935-358BB8210A9D}: DhcpNameServer = 167.206.112.138 167.206.7.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6FAD25E3-E688-4DF0-8935-358BB8210A9D}: NameServer = 192.168.1.2
O18 - Protocol\Handler\sds {79E0F14C-9C52-4218-89A7-7C4B0563D121} - C:\Program Files\Sharp\Sharpdesk\ExplorerExtensions.dll (SHARP CORPORATION)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\eric\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\eric\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/21 11:14:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/03/28 16:30:16 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/03/28 16:27:50 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/03/28 16:27:49 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/03/28 16:27:49 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/03/28 16:27:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/03/28 16:27:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/03/28 16:26:53 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/03/28 15:27:17 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/03/26 09:24:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\eric\Desktop\chernoff
[2012/03/20 09:30:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\eric\Local Settings\Application Data\Identities
[2012/03/20 09:30:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\eric\Application Data\Souru
[2012/03/19 13:07:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\eric\Desktop\ROTHMAN
[2012/03/12 13:20:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\eric\Desktop\BKE
[2012/03/08 18:07:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/28 17:15:27 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/03/28 16:41:21 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/28 16:30:28 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/03/28 16:19:29 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/03/28 16:15:13 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/03/28 16:14:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/26 10:01:42 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\eric\Desktop\Microsoft Office Word 2007.lnk
[2012/03/26 09:40:02 | 000,000,229 | ---- | M] () -- C:\WINDOWS\hpbafd.ini
[2012/03/20 15:50:54 | 000,066,722 | ---- | M] () -- C:\Documents and Settings\eric\Desktop\ACS 3-20.pdf
[2012/03/20 10:18:54 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/19 12:41:32 | 000,000,451 | ---- | M] () -- C:\Documents and Settings\eric\Desktop\Shortcut to Apps on Sbserver.lnk
[2012/03/16 15:32:41 | 000,230,205 | ---- | M] () -- C:\Documents and Settings\eric\Desktop\20110418_dkt_459_cia_contempt_motion_supplemental_oppn-1.pdf
[2012/03/15 09:20:10 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\eric\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/03/14 14:16:33 | 000,314,508 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/03/14 14:16:33 | 000,040,836 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/03/02 17:15:33 | 035,718,170 | ---- | M] () -- C:\Documents and Settings\eric\My Documents\___TRUST.rtf
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/28 16:30:27 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2012/03/28 16:30:22 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/03/28 16:27:50 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/03/28 16:27:49 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/03/28 16:27:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/03/28 16:27:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/03/28 16:27:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/03/20 15:50:54 | 000,066,722 | ---- | C] () -- C:\Documents and Settings\eric\Desktop\ACS 3-20.pdf
[2012/03/20 10:18:54 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/16 15:32:41 | 000,230,205 | ---- | C] () -- C:\Documents and Settings\eric\Desktop\20110418_dkt_459_cia_contempt_motion_supplemental_oppn-1.pdf
[2012/03/02 17:18:26 | 035,718,170 | ---- | C] () -- C:\Documents and Settings\eric\My Documents\JER TRUST.rtf
[2012/01/31 17:37:18 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/12/30 12:35:50 | 000,501,438 | ---- | C] () -- C:\Documents and Settings\eric\Application Data\fontlst2.opf
[2011/12/21 12:30:48 | 000,000,229 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2011/12/21 11:17:27 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/12/21 11:11:13 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/12/21 05:56:34 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/12/21 05:54:42 | 000,264,616 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2011/12/21 21:06:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.4 Output
[2011/12/30 12:32:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sharp
[2011/12/30 12:35:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sharpdesk
[2012/01/03 12:34:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\eric\Application Data\eFax Messenger
[2012/01/03 12:31:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\eric\Application Data\j2 Global
[2011/12/30 12:35:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\eric\Application Data\Sharpdesk
[2012/03/28 17:05:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\eric\Application Data\Souru
[2011/12/21 13:02:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\eric\Application Data\TeamViewer
[2011/12/21 14:42:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\eric\Application Data\UBitMenu
[2012/03/28 16:19:29 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP