This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Slowed PC Performance

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Leon Panokarren,

coz I guess you got me to do this so we remove any older java components that my careful self might have missed before …

Close. Sometimes, for unknown reasons, remnants are left. You get a partial uninstall. If it doesn't show in your add/remove list, there isn't any way for you to know that they're there. Javara will remove old installs including left over remnants.

Never fear. If Kaspersky doesn't want to run, it doesn't have to. We will use Eset instead.

I need you to run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.

Also please give me a new HijackThis log.
Leon Panokarren, That's one of the reasons that I have tried to get everything I could find prior to asking you to run an online scan. It's virtually impossible to guess how long it will take, there are too many variables. Could take around an hour up to many. I've see 5 hour online scans on dial-up on infected machines.
alrite tom … I guess its been 45 minutes and the scanner is not yet done 10% … i believe it is scanning all of the huge database client installables on my machine .. reminds me I should clean up my hard disks a little bit …. I will leaving this running … and update you with the results tomorrow evening … thanks a lot sir … you've been great help! Leon
Leon Panokarren, I'm going out of town tommorrow evening. Be back Sunday night. If I don't get back to you right away, no worries. I'll be back. B)
Leon Panokarren,

this thing ran for 24 hours

Well, you might have the new record for what I've seen. :)

I think we should dig a little deeper.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Tom K,

Thanks again … crazy couple of days at work …. got the Combofix.exe run and the log pasted below .. these programs scare me though …. I disabled the McAfee services and ran CF; yet it got alerts from the AV -

ComboFix 08-11-19.08 - leonp 2008-11-20 22:27:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1398 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Downloaded Program Files\MyWebEx
c:\windows\Downloaded Program Files\MyWebEx\319\Agent.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_PACKET
——-\Service_Packet


((((((((((((((((((((((((( Files Created from 2008-10-21 to 2008-11-21 )))))))))))))))))))))))))))))))
.

2008-11-13 23:31 . 2008-11-13 23:50 d——– c:\program files\EsetOnlineScanner
2008-11-12 23:27 . 2008-11-12 23:27 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-12 23:18 . 2008-11-12 23:18 d——– c:\program files\Java
2008-11-12 23:18 . 2008-11-12 23:18 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-12 23:18 . 2008-11-12 23:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-12 20:40 . 2008-11-12 20:41 d——– c:\windows\ERUNT
2008-11-12 20:35 . 2008-11-12 20:52 d——– C:\SDFix
2008-11-11 21:57 . 2008-11-11 21:58 d——– c:\program files\Quick3270
2008-11-10 20:29 . 2008-11-10 20:30 84,730,752 –a—— C:\Registry_20081109.reg
2008-11-10 18:23 . 2008-11-11 22:00 d——– c:\documents and settings\leonp\Application Data\webex
2008-11-03 19:36 . 2008-10-02 18:42 193,936 –a—— c:\windows\atagtctl.exe
2008-11-02 23:38 . 2008-11-02 23:38 d——– c:\documents and settings\Owner
2008-11-02 23:23 . 2008-11-02 23:23 d——– c:\windows\system32\vmm32
2008-10-27 20:28 . 2008-10-27 20:28 0 –a—— C:\test_1.out

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-21 03:35 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-19 00:56 ——— d—–w c:\program files\McAfee
2008-11-16 16:17 ——— d—–w c:\documents and settings\LocalService\Application Data\SACore
2008-11-15 05:56 ——— d—–w c:\documents and settings\leonp\Application Data\dvdcss
2008-11-10 23:50 ——— d—–w c:\program files\Common Files\Adobe
2008-11-07 07:08 ——— d—–w c:\program files\LimeWire
2008-11-06 02:56 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2008-11-04 00:08 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-22 21:10 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 21:10 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2008-10-20 04:43 ——— d—–w c:\program files\RarZilla Free Unrar
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-15 16:57 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-07 00:13 ——— d—–w c:\documents and settings\All Users\Application Data\Citrix
2008-10-06 23:47 ——— d—–w c:\documents and settings\leonp\Application Data\McAfee
2008-10-06 23:47 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2008-10-04 08:18 ——— d—–w c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-10-03 17:41 6,066,176 —-a-w c:\windows\system32\dllcache\ieframe.dll
2008-10-02 23:40 73,624 —-a-w c:\windows\system32\ataskernel.exe
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ——w c:\windows\system32\dllcache\msxml3.dll
2008-08-30 01:06 1,350,664 —-a-w c:\windows\system32\msxml6.dll
2008-08-28 10:04 333,056 ——w c:\windows\system32\dllcache\srv.sys
2008-08-27 08:24 3,593,216 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-08-25 08:38 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-08-25 08:37 70,656 —-a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-08-23 05:56 635,848 —-a-w c:\windows\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2003-10-01 23:04 121,856 –sha-w c:\windows\system32\cfpsys.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-20 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 851968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 823296]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 974848]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-03 1862144]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-03 582992]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-12 136600]
"nwiz"="nwiz.exe" [2007-06-06 c:\windows\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2007-06-06 c:\windows\system32\nvmctray.dll]
"SigmatelSysTrayApp"="stsystra.exe" [2007-06-06 c:\windows\stsystra.exe]
"Warning: do not remove it! (system)"="cfpsys.exe" [2003-10-01 c:\windows\system32\cfpsys.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 c:\windows\system32\narrator.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-05-17 568176]
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-12-03 7168]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-03 50688]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Informatica\\PowerCenter8.1.1\\client\\bin\\pmwflmgr.exe"=
"c:\\Informatica\\PowerCenter8.1.1\\client\\bin\\pmwfmntr.exe"=
"c:\\Informatica\\PowerCenter8.1.1\\client\\bin\\pmdesign.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R1 DLARTL_M;DLARTL_M;c:\windows\system32\Drivers\DLARTL_M.SYS [2007-12-03 28184]
R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\DRIVERS\datunidr.sys [2007-08-23 5376]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-10-03 203280]
S2 MetadataManagerScheduler;Informatica PowerCenter Metadata Manager Scheduler;c:\informatica\powercenter8.1.1\client\console\refreshsched.exe [2008-03-29 32768]
S3 PowerExchange_Listener;PowerExchange_Listener;c:\program files\Informatica\Informatica PowerExchange\dtllstnt.exe [2008-07-05 53248]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4bfb47b8-b252-11dc-8c47-001d09a40c0a}]
\Shell\AutoRun\command - setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f6f43b7-b1cb-11dc-8c46-001d09a40c0a}]
\Shell\AutoRun\command - E:\Autorun.exe /run
\Shell\Shell00\Command - E:\Autorun.exe /run
\Shell\Shell01\Command - E:\Autorun.exe /action
\Shell\Shell02\Command - E:\Autorun.exe /uninstall
.
Contents of the 'Scheduled Tasks' folder

2008-06-07 c:\windows\Tasks\Access.job
- c:\documents and settings\leonp\My Documents\Access.mdb [2008-06-06 19:06]

2008-02-18 c:\windows\Tasks\Command Prompt.job
- c:\windows\system32\cmd.exe [2004-08-04 06:00]

2008-11-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-10-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\leonp\Application Data\Mozilla\Firefox\Profiles\dgcdwoxx.default\
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-20 22:32:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: c:\windows\explorer.exe
-> c:\program files\McAfee\SiteAdvisor\saHook.dll
.
———————— Other Running Processes ————————
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\McAfee\MSK\msksrver.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\windows\system32\rundll32.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\program files\Common Files\logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2008-11-20 22:38:03 - machine was rebooted [leonp]
ComboFix-quarantined-files.txt 2008-11-21 03:37:58

Pre-Run: 98,299,904,000 bytes free
Post-Run: 98,307,952,640 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

237 — E O F — 2008-11-13 00:58:42
Leon Panokarren,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\test_1.out
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4bfb47b8-b252-11dc-8c47-001d09a40c0a}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f6f43b7-b1cb-11dc-8c46-001d09a40c0a}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

I'd also like to get a different look at what's happening.

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Tom, I will work to have the logs you requested of me .. meanwhile I am seeing the browser I am using keeps switching from https:// to http:// i.e. I believe from secure to unsecure mode - why is that? For instance, if I am logging on to yahoo, the login page opens up as secure, and then the actual mail box opens up as unsecure …. why is that? is there something wrong here? Leon
Leon Panokarren, I believe that what you are seeing is a function of the webpage, shouldn't change based on your computer. Per your example, the Yahoo home page is unsecure. Malibox is unsecure. The only page I know of that is secure is the login page. That is because, obviously, the login page is the one where you are providing "secure" information. (username and password). You don't provide information in your mailbox or on their homepage.
Tom K, Happy holidays! Thanks! Also, McAfee seems to keep raising alarms on the PrcViewer.exe software we installed. When I asked it to clean up the software since i thought we were done with the application, McAfee reports an unsuccessful attempt. Why is that? Why can't we remove this software? Leon
Leon Panokarren, That is a false positive from the SmitfradFix tool we used. Do worry about it. We'll take care of it when we clean up our tools once your clean. How are you coming with those logs? It's been over a week. It is usually best to get the computer cleaned up before using to much. This reduces reinfection risks.
Tom K,

Here you go - Let me know what you find out

——————————————————————————————————————————————-
Combofix log with the CFScript -
——————————————————————————————————————————————-


ComboFix 08-11-28.02 - leonp 2008-11-28 17:05:39.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1485 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\leonp\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\test_1.out
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\test_1.out

.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-28 )))))))))))))))))))))))))))))))
.

2008-11-13 23:31 . 2008-11-13 23:50 d——– c:\program files\EsetOnlineScanner
2008-11-12 23:27 . 2008-11-12 23:27 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-12 23:18 . 2008-11-12 23:18 d——– c:\program files\Java
2008-11-12 23:18 . 2008-11-12 23:18 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-12 23:18 . 2008-11-12 23:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-12 20:40 . 2008-11-12 20:41 d——– c:\windows\ERUNT
2008-11-12 20:35 . 2008-11-12 20:52 d——– C:\SDFix
2008-11-11 21:57 . 2008-11-11 21:58 d——– c:\program files\Quick3270
2008-11-10 20:29 . 2008-11-10 20:30 84,730,752 –a—— C:\Registry_20081109.reg
2008-11-10 18:23 . 2008-11-11 22:00 d——– c:\documents and settings\leonp\Application Data\webex
2008-11-03 19:36 . 2008-10-02 18:42 193,936 –a—— c:\windows\atagtctl.exe
2008-11-02 23:38 . 2008-11-02 23:38 d——– c:\documents and settings\Owner
2008-11-02 23:23 . 2008-11-02 23:23 d——– c:\windows\system32\vmm32

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-28 22:11 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-28 08:05 ——— d—–w c:\program files\McAfee
2008-11-26 19:49 ——— d—–w c:\documents and settings\LocalService\Application Data\SACore
2008-11-15 05:56 ——— d—–w c:\documents and settings\leonp\Application Data\dvdcss
2008-11-10 23:50 ——— d—–w c:\program files\Common Files\Adobe
2008-11-07 07:08 ——— d—–w c:\program files\LimeWire
2008-11-06 02:56 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2008-11-04 00:08 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-22 21:10 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 21:10 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2008-10-20 04:43 ——— d—–w c:\program files\RarZilla Free Unrar
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-15 16:57 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-07 00:13 ——— d—–w c:\documents and settings\All Users\Application Data\Citrix
2008-10-06 23:47 ——— d—–w c:\documents and settings\leonp\Application Data\McAfee
2008-10-06 23:47 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2008-10-04 08:18 ——— d—–w c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-10-03 17:41 6,066,176 —-a-w c:\windows\system32\dllcache\ieframe.dll
2008-10-02 23:40 73,624 —-a-w c:\windows\system32\ataskernel.exe
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ——w c:\windows\system32\dllcache\msxml3.dll
2008-08-30 01:06 1,350,664 —-a-w c:\windows\system32\msxml6.dll
2008-08-28 10:04 333,056 ——w c:\windows\system32\dllcache\srv.sys
2003-10-01 23:04 121,856 –sha-w c:\windows\system32\cfpsys.exe
.

((((((((((((((((((((((((((((( snapshot@2008-11-20_22.37.32.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-28 03:51:55 8,722 —-a-w c:\windows\hh.dat
+ 2008-11-24 02:20:18 8,722 —-a-w c:\windows\hh.dat
- 2008-11-21 02:59:56 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-28 21:21:02 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-21 02:59:56 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-28 21:21:02 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-28 21:21:02 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-28 22:07:42 16,384 —-atw c:\windows\temp\Perflib_Perfdata_198.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-20 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 851968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 823296]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 974848]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-03 1862144]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-03 582992]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-12 136600]
"nwiz"="nwiz.exe" [2007-06-06 c:\windows\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2007-06-06 c:\windows\system32\nvmctray.dll]
"SigmatelSysTrayApp"="stsystra.exe" [2007-06-06 c:\windows\stsystra.exe]
"Warning: do not remove it! (system)"="cfpsys.exe" [2003-10-01 c:\windows\system32\cfpsys.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 c:\windows\system32\narrator.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-05-17 568176]
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-12-03 7168]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-03 50688]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Informatica\\PowerCenter8.1.1\\client\\bin\\pmwflmgr.exe"=
"c:\\Informatica\\PowerCenter8.1.1\\client\\bin\\pmwfmntr.exe"=
"c:\\Informatica\\PowerCenter8.1.1\\client\\bin\\pmdesign.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R1 DLARTL_M;DLARTL_M;c:\windows\system32\Drivers\DLARTL_M.SYS [2007-12-03 28184]
R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\DRIVERS\datunidr.sys [2007-08-23 5376]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-10-03 203280]
S2 MetadataManagerScheduler;Informatica PowerCenter Metadata Manager Scheduler;c:\informatica\powercenter8.1.1\client\console\refreshsched.exe [2008-03-29 32768]
S3 PowerExchange_Listener;PowerExchange_Listener;c:\program files\Informatica\Informatica PowerExchange\dtllstnt.exe [2008-07-05 53248]
.
Contents of the 'Scheduled Tasks' folder

2008-06-07 c:\windows\Tasks\Access.job
- c:\documents and settings\leonp\My Documents\Access.mdb [2008-06-06 19:06]

2008-02-18 c:\windows\Tasks\Command Prompt.job
- c:\windows\system32\cmd.exe [2004-08-04 06:00]

2008-11-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-10-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-28 17:08:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(864)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
———————— Other Running Processes ————————
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\McAfee\MSK\msksrver.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\windows\system32\rundll32.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\program files\Common Files\logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2008-11-28 17:13:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-28 22:13:27
ComboFix2.txt 2008-11-28 21:56:57
ComboFix3.txt 2008-11-21 03:38:04

Pre-Run: 98,260,389,888 bytes free
Post-Run: 98,241,761,280 bytes free

214 — E O F — 2008-11-13 00:58:42

Lop S&D Log

——————–\\ Lop S&D 4.2.4-9c XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel® Core™2 Duo CPU T7250 @ 2.00GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A01
USER : leonp ( Administrator )
BOOT : Normal boot
Antivirus : McAfee VirusScan (Activated)
Firewall : McAfee Personal Firewall (Activated)
C:\ (Local Disk) - NTFS - Total:109 Go (Free:91 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Fri 11/28/2008|17:17 )

——————–\\ Listing folders in APPLIC~1

[12/03/2007|05:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\ GTek
[08/10/2004|02:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[12/03/2007|04:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\ InstallShield
[12/03/2007|04:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Intel
[08/10/2004|01:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[12/03/2007|05:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Roxio

[04/24/2008|08:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {02C45027-B817-41FE-A000-2799C43CEF41}
[06/01/2007|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {BCDF421A-66A6-4306-BBBF-C4511CB2A940}
[11/10/2008|06:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[09/07/2008|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AVS4YOU
[10/06/2008|07:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Citrix
[12/03/2007|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[12/03/2007|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Dell
[12/03/2007|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[12/03/2007|05:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Gtek
[12/03/2007|04:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[12/03/2007|04:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intel
[11/12/2008|11:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Kaspersky Lab Setup Files
[02/03/2008|11:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Logishrd
[02/03/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Logitech
[07/27/2008|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[10/06/2008|06:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee
[12/25/2007|04:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[01/06/2008|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[03/27/2008|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Quest Software
[03/27/2008|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Raize
[12/03/2007|05:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Roxio
[08/10/2004|02:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[05/30/2008|07:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SecTaskMan
[12/03/2007|05:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SingleClick Systems
[10/04/2008|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SiteAdvisor
[12/03/2007|05:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[07/27/2008|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com
[12/03/2007|05:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SupportSoft
[11/28/2008|05:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[02/03/2008|10:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[02/03/2008|11:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo!
[02/03/2008|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion

[12/03/2007|05:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ GTek
[08/10/2004|02:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[12/03/2007|04:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ InstallShield
[12/03/2007|04:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Intel
[08/10/2004|01:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[12/03/2007|05:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Roxio

[12/23/2007|09:48] C:\DOCUME~1\leonp\APPLIC~1\ Adobe
[09/16/2008|01:59] C:\DOCUME~1\leonp\APPLIC~1\ AVS4YOU
[01/05/2008|10:48] C:\DOCUME~1\leonp\APPLIC~1\ CyberLink
[12/20/2007|07:34] C:\DOCUME~1\leonp\APPLIC~1\ Dell
[11/15/2008|12:56] C:\DOCUME~1\leonp\APPLIC~1\ dvdcss
[12/20/2007|07:37] C:\DOCUME~1\leonp\APPLIC~1\ Google
[12/22/2007|08:48] C:\DOCUME~1\leonp\APPLIC~1\ GTek
[07/15/2008|10:25] C:\DOCUME~1\leonp\APPLIC~1\ Help
[08/10/2004|02:08] C:\DOCUME~1\leonp\APPLIC~1\ Identities
[12/03/2007|04:54] C:\DOCUME~1\leonp\APPLIC~1\ InstallShield
[12/03/2007|04:54] C:\DOCUME~1\leonp\APPLIC~1\ Intel
[05/10/2008|02:01] C:\DOCUME~1\leonp\APPLIC~1\ JGsoft
[09/11/2008|08:43] C:\DOCUME~1\leonp\APPLIC~1\ LimeWire
[12/20/2007|07:51] C:\DOCUME~1\leonp\APPLIC~1\ Macromedia
[07/27/2008|10:03] C:\DOCUME~1\leonp\APPLIC~1\ Malwarebytes
[10/06/2008|06:47] C:\DOCUME~1\leonp\APPLIC~1\ McAfee
[11/02/2008|11:23] C:\DOCUME~1\leonp\APPLIC~1\ Microsoft
[09/15/2008|06:18] C:\DOCUME~1\leonp\APPLIC~1\ Mozilla
[07/14/2008|10:32] C:\DOCUME~1\leonp\APPLIC~1\ Quest Software
[06/15/2008|12:53] C:\DOCUME~1\leonp\APPLIC~1\ Roxio
[04/24/2008|08:03] C:\DOCUME~1\leonp\APPLIC~1\ Seven Zip
[01/16/2008|09:43] C:\DOCUME~1\leonp\APPLIC~1\ Sun
[07/27/2008|09:59] C:\DOCUME~1\leonp\APPLIC~1\ SUPERAntiSpyware.com
[09/13/2008|04:06] C:\DOCUME~1\leonp\APPLIC~1\ TextPad
[05/18/2008|11:28] C:\DOCUME~1\leonp\APPLIC~1\ vlc
[11/11/2008|10:00] C:\DOCUME~1\leonp\APPLIC~1\ webex
[07/17/2008|10:38] C:\DOCUME~1\leonp\APPLIC~1\ WinRAR
[02/03/2008|11:50] C:\DOCUME~1\leonp\APPLIC~1\ Yahoo!

[12/03/2007|04:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Intel
[03/30/2008|08:44] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[12/03/2007|05:12] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Roxio
[11/26/2008|02:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\ SACore

[12/03/2007|04:54] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Intel
[08/10/2004|01:57] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft


——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[06/06/2008 08:44 PM][–a——] C:\WINDOWS\tasks\Access.job
[02/18/2008 02:03 PM][–a——] C:\WINDOWS\tasks\Command Prompt.job
[11/15/2008 01:00 AM][–a——] C:\WINDOWS\tasks\McDefragTask.job
[10/01/2008 12:00 AM][–a——] C:\WINDOWS\tasks\McQcTask.job
[11/28/2008 05:07 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 06:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[11/10/2008|06:49] C:\Program Files\ Adobe
[05/21/2008|10:30] C:\Program Files\ Altap Salamander 2.5
[09/16/2008|01:58] C:\Program Files\ AVS4YOU
[12/03/2007|04:55] C:\Program Files\ Broadcom
[11/28/2008|05:06] C:\Program Files\ Common Files
[08/10/2004|02:02] C:\Program Files\ ComPlus Applications
[12/03/2007|04:56] C:\Program Files\ CONEXANT
[12/03/2007|05:03] C:\Program Files\ CyberLink
[12/03/2007|05:03] C:\Program Files\ Dell
[12/03/2007|05:05] C:\Program Files\ Dell Network Assistant
[12/03/2007|05:09] C:\Program Files\ Dell Support Center
[12/03/2007|05:09] C:\Program Files\ DellAutomatedPCTuneUp
[12/03/2007|04:55] C:\Program Files\ Digital Line Detect
[08/04/2008|07:13] C:\Program Files\ Ericom Software
[11/13/2008|11:50] C:\Program Files\ EsetOnlineScanner
[12/21/2007|05:31] C:\Program Files\ Google
[07/05/2008|06:25] C:\Program Files\ Informatica
[11/03/2008|07:08] C:\Program Files\ InstallShield Installation Information
[12/03/2007|04:54] C:\Program Files\ Intel
[12/03/2007|04:54] C:\Program Files\ Intel, Inc
[10/15/2008|09:58] C:\Program Files\ Internet Explorer
[11/12/2008|11:18] C:\Program Files\ Java
[05/10/2008|02:01] C:\Program Files\ JGsoft
[11/07/2008|02:08] C:\Program Files\ LimeWire
[02/03/2008|11:14] C:\Program Files\ Logitech
[11/05/2008|09:56] C:\Program Files\ Malwarebytes' Anti-Malware
[11/28/2008|03:05] C:\Program Files\ McAfee
[12/03/2007|05:05] C:\Program Files\ McAfee.com
[08/13/2008|07:04] C:\Program Files\ Messenger
[12/25/2007|04:30] C:\Program Files\ Microsoft ActiveSync
[02/05/2008|09:08] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[08/10/2004|02:04] C:\Program Files\ microsoft frontpage
[12/25/2007|04:46] C:\Program Files\ Microsoft Office
[05/12/2008|06:16] C:\Program Files\ Microsoft SQL Server
[09/10/2008|06:52] C:\Program Files\ Microsoft Works
[12/25/2007|04:28] C:\Program Files\ Microsoft.NET
[12/03/2007|04:54] C:\Program Files\ Modem Diagnostic Tool
[08/10/2004|02:02] C:\Program Files\ Movie Maker
[08/10/2004|02:01] C:\Program Files\ MSN
[08/10/2004|02:01] C:\Program Files\ MSN Gaming Zone
[12/22/2007|08:49] C:\Program Files\ MSXML 4.0
[12/03/2007|04:49] C:\Program Files\ MSXML 6.0
[08/10/2004|02:02] C:\Program Files\ NetMeeting
[12/03/2007|04:55] C:\Program Files\ NetWaiting
[11/02/2008|11:29] C:\Program Files\ Online Services
[06/25/2008|06:25] C:\Program Files\ Oracle
[12/03/2007|04:49] C:\Program Files\ Outlook Express
[01/02/2008|11:22] C:\Program Files\ Password Protect
[04/24/2008|08:03] C:\Program Files\ PDF Annotator
[07/21/2008|10:32] C:\Program Files\ Quest Software
[11/11/2008|09:58] C:\Program Files\ Quick3270
[03/27/2008|09:52] C:\Program Files\ Raize
[10/19/2008|11:43] C:\Program Files\ RarZilla Free Unrar
[12/03/2007|05:03] C:\Program Files\ Roxio
[12/03/2007|04:58] C:\Program Files\ Sigmatel
[07/27/2008|09:59] C:\Program Files\ SUPERAntiSpyware
[12/03/2007|04:35] C:\Program Files\ Synaptics
[05/12/2008|06:16] C:\Program Files\ Uninstall Information
[07/17/2008|10:36] C:\Program Files\ Unrar
[05/18/2008|11:01] C:\Program Files\ VideoLAN
[12/03/2007|04:55] C:\Program Files\ WIDCOMM
[05/18/2008|10:59] C:\Program Files\ Windows Media Connect 2
[05/18/2008|10:59] C:\Program Files\ Windows Media Player
[11/02/2008|11:28] C:\Program Files\ Windows NT
[08/10/2004|02:02] C:\Program Files\ WindowsUpdate
[08/10/2004|02:04] C:\Program Files\ xerox
[09/20/2008|08:57] C:\Program Files\ Yahoo!
[03/29/2008|02:43] C:\Program Files\ Zero G Registry

——————–\\ Listing Folders in C:\Program Files\Common Files

[11/10/2008|06:50] C:\Program Files\Common Files\ Adobe
[09/16/2008|01:58] C:\Program Files\Common Files\ AVSMedia
[12/25/2007|04:29] C:\Program Files\Common Files\ DESIGNER
[07/05/2008|06:25] C:\Program Files\Common Files\ InstallShield
[02/03/2008|11:15] C:\Program Files\Common Files\ logishrd
[12/03/2007|05:06] C:\Program Files\Common Files\ McAfee
[09/07/2008|12:02] C:\Program Files\Common Files\ Microsoft Shared
[08/10/2004|02:02] C:\Program Files\Common Files\ MSSoap
[08/10/2004|01:57] C:\Program Files\Common Files\ ODBC
[12/03/2007|04:59] C:\Program Files\Common Files\ Roxio Shared
[09/20/2008|08:57] C:\Program Files\Common Files\ Scanner
[08/10/2004|02:02] C:\Program Files\Common Files\ Services
[12/03/2007|05:02] C:\Program Files\Common Files\ Sonic Shared
[08/10/2004|01:57] C:\Program Files\Common Files\ SpeechEngines
[12/03/2007|05:09] C:\Program Files\Common Files\ supportsoft
[12/03/2007|05:00] C:\Program Files\Common Files\ SureThing Shared
[12/25/2007|04:28] C:\Program Files\Common Files\ System
[07/27/2008|09:59] C:\Program Files\Common Files\ Wise Installation Wizard

——————–\\ Process

( 66 Processes )

iexplore.exe ~ [PID:9892]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\leonp\Cookies\leonp@advertising[1].txt

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-28 17:18:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections


No other infections found !

[F:3][D:1]-> C:\DOCUME~1\leonp\LOCALS~1\Temp
[F:25][D:0]-> C:\DOCUME~1\leonp\Cookies
[F:115][D:4]-> C:\DOCUME~1\leonp\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Fri 11/28/2008|17:19 - Option : [1]

——————–\\ Scan completed at 17:19:46

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI