Tom K,
Here you go - Let me know what you find out
——————————————————————————————————————————————-
Combofix log with the CFScript -
——————————————————————————————————————————————-
ComboFix 08-11-28.02 - leonp 2008-11-28 17:05:39.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1485 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\leonp\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\test_1.out
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\test_1.out
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-28 )))))))))))))))))))))))))))))))
.
2008-11-13 23:31 . 2008-11-13 23:50 d——– c:\program files\EsetOnlineScanner
2008-11-12 23:27 . 2008-11-12 23:27 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-12 23:18 . 2008-11-12 23:18 d——– c:\program files\Java
2008-11-12 23:18 . 2008-11-12 23:18 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-12 23:18 . 2008-11-12 23:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-12 20:40 . 2008-11-12 20:41 d——– c:\windows\ERUNT
2008-11-12 20:35 . 2008-11-12 20:52 d——– C:\SDFix
2008-11-11 21:57 . 2008-11-11 21:58 d——– c:\program files\Quick3270
2008-11-10 20:29 . 2008-11-10 20:30 84,730,752 –a—— C:\Registry_20081109.reg
2008-11-10 18:23 . 2008-11-11 22:00 d——– c:\documents and settings\leonp\Application Data\webex
2008-11-03 19:36 . 2008-10-02 18:42 193,936 –a—— c:\windows\atagtctl.exe
2008-11-02 23:38 . 2008-11-02 23:38 d——– c:\documents and settings\Owner
2008-11-02 23:23 . 2008-11-02 23:23 d——– c:\windows\system32\vmm32
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-28 22:11 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-28 08:05 ——— d—–w c:\program files\McAfee
2008-11-26 19:49 ——— d—–w c:\documents and settings\LocalService\Application Data\SACore
2008-11-15 05:56 ——— d—–w c:\documents and settings\leonp\Application Data\dvdcss
2008-11-10 23:50 ——— d—–w c:\program files\Common Files\Adobe
2008-11-07 07:08 ——— d—–w c:\program files\LimeWire
2008-11-06 02:56 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2008-11-04 00:08 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-22 21:10 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 21:10 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2008-10-20 04:43 ——— d—–w c:\program files\RarZilla Free Unrar
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-15 16:57 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-07 00:13 ——— d—–w c:\documents and settings\All Users\Application Data\Citrix
2008-10-06 23:47 ——— d—–w c:\documents and settings\leonp\Application Data\McAfee
2008-10-06 23:47 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2008-10-04 08:18 ——— d—–w c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-10-03 17:41 6,066,176 —-a-w c:\windows\system32\dllcache\ieframe.dll
2008-10-02 23:40 73,624 —-a-w c:\windows\system32\ataskernel.exe
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ——w c:\windows\system32\dllcache\msxml3.dll
2008-08-30 01:06 1,350,664 —-a-w c:\windows\system32\msxml6.dll
2008-08-28 10:04 333,056 ——w c:\windows\system32\dllcache\srv.sys
2003-10-01 23:04 121,856 –sha-w c:\windows\system32\cfpsys.exe
.
((((((((((((((((((((((((((((( snapshot@2008-11-20_22.37.32.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-28 03:51:55 8,722 —-a-w c:\windows\hh.dat
+ 2008-11-24 02:20:18 8,722 —-a-w c:\windows\hh.dat
- 2008-11-21 02:59:56 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-28 21:21:02 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-21 02:59:56 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-28 21:21:02 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-28 21:21:02 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-28 22:07:42 16,384 —-atw c:\windows\temp\Perflib_Perfdata_198.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-20 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 851968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 823296]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 974848]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-03 1862144]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-03 582992]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-12 136600]
"nwiz"="nwiz.exe" [2007-06-06 c:\windows\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2007-06-06 c:\windows\system32\nvmctray.dll]
"SigmatelSysTrayApp"="stsystra.exe" [2007-06-06 c:\windows\stsystra.exe]
"Warning: do not remove it! (system)"="cfpsys.exe" [2003-10-01 c:\windows\system32\cfpsys.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 c:\windows\system32\narrator.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-05-17 568176]
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-12-03 7168]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-03 50688]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Informatica\\PowerCenter8.1.1\\client\\bin\\pmwflmgr.exe"=
"c:\\Informatica\\PowerCenter8.1.1\\client\\bin\\pmwfmntr.exe"=
"c:\\Informatica\\PowerCenter8.1.1\\client\\bin\\pmdesign.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
R1 DLARTL_M;DLARTL_M;c:\windows\system32\Drivers\DLARTL_M.SYS [2007-12-03 28184]
R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\DRIVERS\datunidr.sys [2007-08-23 5376]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-10-03 203280]
S2 MetadataManagerScheduler;Informatica PowerCenter Metadata Manager Scheduler;c:\informatica\powercenter8.1.1\client\console\refreshsched.exe [2008-03-29 32768]
S3 PowerExchange_Listener;PowerExchange_Listener;c:\program files\Informatica\Informatica PowerExchange\dtllstnt.exe [2008-07-05 53248]
.
Contents of the 'Scheduled Tasks' folder
2008-06-07 c:\windows\Tasks\Access.job
- c:\documents and settings\leonp\My Documents\Access.mdb [2008-06-06 19:06]
2008-02-18 c:\windows\Tasks\Command Prompt.job
- c:\windows\system32\cmd.exe [2004-08-04 06:00]
2008-11-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-10-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-28 17:08:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(864)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
———————— Other Running Processes ————————
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\McAfee\MSK\msksrver.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\windows\system32\rundll32.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\program files\Common Files\logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2008-11-28 17:13:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-28 22:13:27
ComboFix2.txt 2008-11-28 21:56:57
ComboFix3.txt 2008-11-21 03:38:04
Pre-Run: 98,260,389,888 bytes free
Post-Run: 98,241,761,280 bytes free
214 — E O F — 2008-11-13 00:58:42
Lop S&D Log
——————–\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel® Core™2 Duo CPU T7250 @ 2.00GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A01
USER : leonp ( Administrator )
BOOT : Normal boot
Antivirus : McAfee VirusScan (Activated)
Firewall : McAfee Personal Firewall (Activated)
C:\ (Local Disk) - NTFS - Total:109 Go (Free:91 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Fri 11/28/2008|17:17 )
——————–\\ Listing folders in APPLIC~1
[12/03/2007|05:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\ GTek
[08/10/2004|02:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[12/03/2007|04:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\ InstallShield
[12/03/2007|04:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Intel
[08/10/2004|01:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[12/03/2007|05:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Roxio
[04/24/2008|08:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {02C45027-B817-41FE-A000-2799C43CEF41}
[06/01/2007|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {BCDF421A-66A6-4306-BBBF-C4511CB2A940}
[11/10/2008|06:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[09/07/2008|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AVS4YOU
[10/06/2008|07:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Citrix
[12/03/2007|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[12/03/2007|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Dell
[12/03/2007|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[12/03/2007|05:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Gtek
[12/03/2007|04:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[12/03/2007|04:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intel
[11/12/2008|11:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Kaspersky Lab Setup Files
[02/03/2008|11:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Logishrd
[02/03/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Logitech
[07/27/2008|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[10/06/2008|06:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee
[12/25/2007|04:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[01/06/2008|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[03/27/2008|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Quest Software
[03/27/2008|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Raize
[12/03/2007|05:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Roxio
[08/10/2004|02:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[05/30/2008|07:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SecTaskMan
[12/03/2007|05:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SingleClick Systems
[10/04/2008|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SiteAdvisor
[12/03/2007|05:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[07/27/2008|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com
[12/03/2007|05:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SupportSoft
[11/28/2008|05:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[02/03/2008|10:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[02/03/2008|11:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo!
[02/03/2008|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion
[12/03/2007|05:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ GTek
[08/10/2004|02:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[12/03/2007|04:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ InstallShield
[12/03/2007|04:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Intel
[08/10/2004|01:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[12/03/2007|05:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Roxio
[12/23/2007|09:48] C:\DOCUME~1\leonp\APPLIC~1\ Adobe
[09/16/2008|01:59] C:\DOCUME~1\leonp\APPLIC~1\ AVS4YOU
[01/05/2008|10:48] C:\DOCUME~1\leonp\APPLIC~1\ CyberLink
[12/20/2007|07:34] C:\DOCUME~1\leonp\APPLIC~1\ Dell
[11/15/2008|12:56] C:\DOCUME~1\leonp\APPLIC~1\ dvdcss
[12/20/2007|07:37] C:\DOCUME~1\leonp\APPLIC~1\ Google
[12/22/2007|08:48] C:\DOCUME~1\leonp\APPLIC~1\ GTek
[07/15/2008|10:25] C:\DOCUME~1\leonp\APPLIC~1\ Help
[08/10/2004|02:08] C:\DOCUME~1\leonp\APPLIC~1\ Identities
[12/03/2007|04:54] C:\DOCUME~1\leonp\APPLIC~1\ InstallShield
[12/03/2007|04:54] C:\DOCUME~1\leonp\APPLIC~1\ Intel
[05/10/2008|02:01] C:\DOCUME~1\leonp\APPLIC~1\ JGsoft
[09/11/2008|08:43] C:\DOCUME~1\leonp\APPLIC~1\ LimeWire
[12/20/2007|07:51] C:\DOCUME~1\leonp\APPLIC~1\ Macromedia
[07/27/2008|10:03] C:\DOCUME~1\leonp\APPLIC~1\ Malwarebytes
[10/06/2008|06:47] C:\DOCUME~1\leonp\APPLIC~1\ McAfee
[11/02/2008|11:23] C:\DOCUME~1\leonp\APPLIC~1\ Microsoft
[09/15/2008|06:18] C:\DOCUME~1\leonp\APPLIC~1\ Mozilla
[07/14/2008|10:32] C:\DOCUME~1\leonp\APPLIC~1\ Quest Software
[06/15/2008|12:53] C:\DOCUME~1\leonp\APPLIC~1\ Roxio
[04/24/2008|08:03] C:\DOCUME~1\leonp\APPLIC~1\ Seven Zip
[01/16/2008|09:43] C:\DOCUME~1\leonp\APPLIC~1\ Sun
[07/27/2008|09:59] C:\DOCUME~1\leonp\APPLIC~1\ SUPERAntiSpyware.com
[09/13/2008|04:06] C:\DOCUME~1\leonp\APPLIC~1\ TextPad
[05/18/2008|11:28] C:\DOCUME~1\leonp\APPLIC~1\ vlc
[11/11/2008|10:00] C:\DOCUME~1\leonp\APPLIC~1\ webex
[07/17/2008|10:38] C:\DOCUME~1\leonp\APPLIC~1\ WinRAR
[02/03/2008|11:50] C:\DOCUME~1\leonp\APPLIC~1\ Yahoo!
[12/03/2007|04:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Intel
[03/30/2008|08:44] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[12/03/2007|05:12] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Roxio
[11/26/2008|02:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\ SACore
[12/03/2007|04:54] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Intel
[08/10/2004|01:57] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft
——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[06/06/2008 08:44 PM][–a——] C:\WINDOWS\tasks\Access.job
[02/18/2008 02:03 PM][–a——] C:\WINDOWS\tasks\Command Prompt.job
[11/15/2008 01:00 AM][–a——] C:\WINDOWS\tasks\McDefragTask.job
[10/01/2008 12:00 AM][–a——] C:\WINDOWS\tasks\McQcTask.job
[11/28/2008 05:07 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 06:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini
——————–\\ Listing Folders in C:\Program Files
[11/10/2008|06:49] C:\Program Files\ Adobe
[05/21/2008|10:30] C:\Program Files\ Altap Salamander 2.5
[09/16/2008|01:58] C:\Program Files\ AVS4YOU
[12/03/2007|04:55] C:\Program Files\ Broadcom
[11/28/2008|05:06] C:\Program Files\ Common Files
[08/10/2004|02:02] C:\Program Files\ ComPlus Applications
[12/03/2007|04:56] C:\Program Files\ CONEXANT
[12/03/2007|05:03] C:\Program Files\ CyberLink
[12/03/2007|05:03] C:\Program Files\ Dell
[12/03/2007|05:05] C:\Program Files\ Dell Network Assistant
[12/03/2007|05:09] C:\Program Files\ Dell Support Center
[12/03/2007|05:09] C:\Program Files\ DellAutomatedPCTuneUp
[12/03/2007|04:55] C:\Program Files\ Digital Line Detect
[08/04/2008|07:13] C:\Program Files\ Ericom Software
[11/13/2008|11:50] C:\Program Files\ EsetOnlineScanner
[12/21/2007|05:31] C:\Program Files\ Google
[07/05/2008|06:25] C:\Program Files\ Informatica
[11/03/2008|07:08] C:\Program Files\ InstallShield Installation Information
[12/03/2007|04:54] C:\Program Files\ Intel
[12/03/2007|04:54] C:\Program Files\ Intel, Inc
[10/15/2008|09:58] C:\Program Files\ Internet Explorer
[11/12/2008|11:18] C:\Program Files\ Java
[05/10/2008|02:01] C:\Program Files\ JGsoft
[11/07/2008|02:08] C:\Program Files\ LimeWire
[02/03/2008|11:14] C:\Program Files\ Logitech
[11/05/2008|09:56] C:\Program Files\ Malwarebytes' Anti-Malware
[11/28/2008|03:05] C:\Program Files\ McAfee
[12/03/2007|05:05] C:\Program Files\ McAfee.com
[08/13/2008|07:04] C:\Program Files\ Messenger
[12/25/2007|04:30] C:\Program Files\ Microsoft ActiveSync
[02/05/2008|09:08] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[08/10/2004|02:04] C:\Program Files\ microsoft frontpage
[12/25/2007|04:46] C:\Program Files\ Microsoft Office
[05/12/2008|06:16] C:\Program Files\ Microsoft SQL Server
[09/10/2008|06:52] C:\Program Files\ Microsoft Works
[12/25/2007|04:28] C:\Program Files\ Microsoft.NET
[12/03/2007|04:54] C:\Program Files\ Modem Diagnostic Tool
[08/10/2004|02:02] C:\Program Files\ Movie Maker
[08/10/2004|02:01] C:\Program Files\ MSN
[08/10/2004|02:01] C:\Program Files\ MSN Gaming Zone
[12/22/2007|08:49] C:\Program Files\ MSXML 4.0
[12/03/2007|04:49] C:\Program Files\ MSXML 6.0
[08/10/2004|02:02] C:\Program Files\ NetMeeting
[12/03/2007|04:55] C:\Program Files\ NetWaiting
[11/02/2008|11:29] C:\Program Files\ Online Services
[06/25/2008|06:25] C:\Program Files\ Oracle
[12/03/2007|04:49] C:\Program Files\ Outlook Express
[01/02/2008|11:22] C:\Program Files\ Password Protect
[04/24/2008|08:03] C:\Program Files\ PDF Annotator
[07/21/2008|10:32] C:\Program Files\ Quest Software
[11/11/2008|09:58] C:\Program Files\ Quick3270
[03/27/2008|09:52] C:\Program Files\ Raize
[10/19/2008|11:43] C:\Program Files\ RarZilla Free Unrar
[12/03/2007|05:03] C:\Program Files\ Roxio
[12/03/2007|04:58] C:\Program Files\ Sigmatel
[07/27/2008|09:59] C:\Program Files\ SUPERAntiSpyware
[12/03/2007|04:35] C:\Program Files\ Synaptics
[05/12/2008|06:16] C:\Program Files\ Uninstall Information
[07/17/2008|10:36] C:\Program Files\ Unrar
[05/18/2008|11:01] C:\Program Files\ VideoLAN
[12/03/2007|04:55] C:\Program Files\ WIDCOMM
[05/18/2008|10:59] C:\Program Files\ Windows Media Connect 2
[05/18/2008|10:59] C:\Program Files\ Windows Media Player
[11/02/2008|11:28] C:\Program Files\ Windows NT
[08/10/2004|02:02] C:\Program Files\ WindowsUpdate
[08/10/2004|02:04] C:\Program Files\ xerox
[09/20/2008|08:57] C:\Program Files\ Yahoo!
[03/29/2008|02:43] C:\Program Files\ Zero G Registry
——————–\\ Listing Folders in C:\Program Files\Common Files
[11/10/2008|06:50] C:\Program Files\Common Files\ Adobe
[09/16/2008|01:58] C:\Program Files\Common Files\ AVSMedia
[12/25/2007|04:29] C:\Program Files\Common Files\ DESIGNER
[07/05/2008|06:25] C:\Program Files\Common Files\ InstallShield
[02/03/2008|11:15] C:\Program Files\Common Files\ logishrd
[12/03/2007|05:06] C:\Program Files\Common Files\ McAfee
[09/07/2008|12:02] C:\Program Files\Common Files\ Microsoft Shared
[08/10/2004|02:02] C:\Program Files\Common Files\ MSSoap
[08/10/2004|01:57] C:\Program Files\Common Files\ ODBC
[12/03/2007|04:59] C:\Program Files\Common Files\ Roxio Shared
[09/20/2008|08:57] C:\Program Files\Common Files\ Scanner
[08/10/2004|02:02] C:\Program Files\Common Files\ Services
[12/03/2007|05:02] C:\Program Files\Common Files\ Sonic Shared
[08/10/2004|01:57] C:\Program Files\Common Files\ SpeechEngines
[12/03/2007|05:09] C:\Program Files\Common Files\ supportsoft
[12/03/2007|05:00] C:\Program Files\Common Files\ SureThing Shared
[12/25/2007|04:28] C:\Program Files\Common Files\ System
[07/27/2008|09:59] C:\Program Files\Common Files\ Wise Installation Wizard
——————–\\ Process
( 66 Processes )
iexplore.exe ~ [PID:9892]
——————–\\ Searching with S_Lop
No Lop folder found !
——————–\\ Searching for Lop Files - Folders
C:\DOCUME~1\leonp\Cookies\leonp@advertising[1].txt
——————–\\ Searching within the Registry
….. OK !
——————–\\ Checking the Hosts file
Hosts file CLEAN
——————–\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-28 17:18:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0
——————–\\ Searching for other infections
No other infections found !
[F:3][D:1]-> C:\DOCUME~1\leonp\LOCALS~1\Temp
[F:25][D:0]-> C:\DOCUME~1\leonp\Cookies
[F:115][D:4]-> C:\DOCUME~1\leonp\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Fri 11/28/2008|17:19 - Option : [1]
——————–\\ Scan completed at 17:19:46