ok, heres combofix log followed by S&D log
ComboFix 08-12-28.01 - user 2008-12-28 18:59:55.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.632 [GMT -8:00]
Running from: c:\documents and settings\Yvonne Negron\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Yvonne Negron\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDMxMjM5NjF8_
c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDMxMjM5NjF8_\spl.ini
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.
2008-12-28 18:56 . 2008-12-28 18:58 <DIR> d-------- C:\Lop SD
2008-12-28 11:49 . 2008-12-28 11:49 578,560 --a------ c:\windows\SYSTEM32\DLLCACHE\user32.dll
2008-12-28 11:43 . 2008-12-28 11:43 <DIR> d-------- c:\windows\ERUNT
2008-12-28 11:33 . 2008-12-28 12:04 <DIR> d-------- C:\SDFix
2008-12-28 10:05 . 2008-12-28 12:37 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-12-27 22:49 . 2008-12-27 22:49 <DIR> d-------- c:\documents and settings\Yvonne Negron\Application Data\Malwarebytes
2008-12-27 22:48 . 2008-12-27 22:48 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-27 22:48 . 2008-12-27 22:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-27 22:48 . 2008-12-03 19:52 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-12-27 22:48 . 2008-12-03 19:52 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2008-12-27 22:19 . 2008-12-27 22:19 <DIR> d-------- c:\program files\Lavasoft
2008-12-27 22:19 . 2008-12-27 22:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-27 22:18 . 2008-12-27 22:18 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-19 10:18 . 2008-12-28 18:59 <DIR> d-------- c:\program files\Trillian
2008-12-17 08:54 . 2008-12-17 08:54 <DIR> d-------- c:\documents and settings\Yvonne Negron\Application Data\Printer Info Cache
2008-12-14 18:32 . 2008-12-14 18:32 <DIR> d-------- c:\program files\Costco
2008-12-14 18:32 . 2008-12-21 11:05 <DIR> d-------- c:\documents and settings\Yvonne Negron\Application Data\Costco Photo Organizer
2008-12-14 17:32 . 2008-12-15 09:23 <DIR> d-------- c:\documents and settings\Yvonne Negron\Application Data\Costco Photo Viewer US
2008-12-09 09:34 . 2008-12-09 09:34 7,680 --ahs---- c:\windows\Thumbs.db
2008-12-07 13:15 . 2008-12-07 13:15 <DIR> d-------- c:\program files\TextPad 5
2008-12-07 13:10 . 2008-12-07 13:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\WinZip
2008-12-07 13:03 . 2008-12-09 09:25 <DIR> d-------- C:\_marcus
2008-12-01 19:12 . 2008-12-01 19:13 <DIR> d-------- c:\program files\iTunes
2008-12-01 19:12 . 2008-12-01 19:12 <DIR> d-------- c:\program files\iPod
2008-12-01 19:12 . 2008-12-01 19:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 02:20 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-28 22:19 43,362 ----a-w c:\documents and settings\Yvonne Negron\Application Data\wklnhst.dat
2008-12-28 03:35 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-24 01:02 --------- d-----w c:\documents and settings\Yvonne Negron\Application Data\Apple Computer
2008-12-18 01:56 --------- d-----w c:\program files\Norton PC Checkup
2008-12-15 02:32 --------- d-----w c:\program files\Common Files\HP
2008-12-13 06:40 3,593,216 ----a-w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2008-12-08 18:22 --------- d-----w c:\program files\Yahoo!
2008-12-08 18:22 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-06 22:43 --------- d-----w c:\program files\Citrix
2008-12-05 09:43 --------- d--h--r c:\documents and settings\Yvonne Negron\Application Data\yahoo!
2008-12-02 03:08 --------- d-----w c:\program files\QuickTime
2008-12-02 03:07 --------- d-----w c:\program files\Common Files\Apple
2008-12-02 02:53 --------- d-----w c:\program files\Safari
2008-11-17 17:56 --------- d-----w c:\program files\Rhapsody
2008-10-24 11:21 455,296 ------w c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\SYSTEM32\DLLCACHE\gdi32.dll
2008-10-16 22:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 22:13 202,776 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuweb.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuaueng.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuapi.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\SYSTEM32\DLLCACHE\wucltui.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\SYSTEM32\DLLCACHE\cdm.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 22:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 22:09 51,224 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuauclt.exe
2008-10-16 22:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\SYSTEM32\DLLCACHE\wups.dll
2008-10-16 22:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 22:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
2008-10-16 13:11 70,656 ------w c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-10-16 13:11 13,824 ------w c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
2008-10-15 16:34 337,408 ------w c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-15 07:06 633,632 ----a-w c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
2008-10-15 07:04 161,792 ------w c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\SYSTEM32\strmdll.dll
2008-10-03 10:02 247,326 ------w c:\windows\SYSTEM32\DLLCACHE\strmdll.dll
2008-10-01 00:43 1,286,152 ----a-w c:\windows\SYSTEM32\msxml4.dll
2008-09-30 01:42 73,816 ----a-w c:\documents and settings\Yvonne Negron\Application Data\GDIPFONTCACHEV1.DAT
2008-02-08 05:46 13,624 ----a-w c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-02-08 05:46 87,360 ----a-w c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-02-08 05:46 91,448 ----a-w c:\program files\mozilla firefox\plugins\confmgr.dll
2008-02-08 05:46 21,824 ----a-w c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-02-08 05:46 206,136 ----a-w c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-02-08 05:46 31,544 ----a-w c:\program files\mozilla firefox\plugins\icafile.dll
2008-02-08 05:46 40,248 ----a-w c:\program files\mozilla firefox\plugins\icalogon.dll
2007-03-17 01:27 479,232 ----a-w c:\program files\mozilla firefox\plugins\msvcm80.dll
2007-03-17 01:27 548,864 ----a-w c:\program files\mozilla firefox\plugins\msvcp80.dll
2007-03-17 01:27 626,688 ----a-w c:\program files\mozilla firefox\plugins\msvcr80.dll
2007-07-20 20:47 981,170 ----a-w c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-02-08 05:46 24,384 ----a-w c:\program files\mozilla firefox\plugins\TcpPServ.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-28_12.58.50.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-28 20:22:22 16,384 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2008-12-29 02:25:19 16,384 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
- 2008-12-28 20:22:22 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-29 02:25:19 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-28 20:22:22 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-29 02:25:19 32,768 --sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-06-01 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-06 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-11-16 127035]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-05-21 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-06-01 217088]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-12-05 50688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-31 185896]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"basicsmssmenu"="c:\program files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe" [2007-10-09 169328]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-05-21 113664]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 233472]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-12 83360]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-09-10 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 16:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\mshta.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\SYSTEM32\\dla\\tfswctrl.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-03 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-03 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-03 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-08-03 76040]
R3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1);c:\windows\system32\DRIVERS\CamDrL20.sys [2007-04-22 245760]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\Drivers\ICDUSB2.sys [2008-09-27 39048]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-12-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-25 c:\windows\Tasks\Norton PC Checkup WeekDay Scanner.job
- c:\program files\norton pc checkup\PC_Checkup.exe [2008-12-17 17:56]
2008-12-28 c:\windows\Tasks\Norton PC Checkup Weekend Scanner.job
- c:\program files\norton pc checkup\PC_Checkup.exe [2008-12-17 17:56]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
FF - ProfilePath - c:\documents and settings\Yvonne Negron\Application Data\Mozilla\Firefox\Profiles\r53hbem1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Yvonne Negron\Application Data\Mozilla\Firefox\Profiles\r53hbem1.default\extensions\
[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npsnapfish.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
ATTENTION: FIREFOX POLICES IS IN FORCE c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("general.useragent.vendorComment", "ax");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.xpconnect.activex.global.hosting_flags", 9);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.classID.allowByDefault", false);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID22D6F312-B0F6-11D0-94AB-0080C74C7E95", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6BF52A52-394A-11D3-B153-00C04F79FAA6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA9FC132B-096D-460B-B7D5-1DB0FAE0C062", "AllAccess");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-28 19:01:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\seneka]
"imagepath"="\systemroot\system32\drivers\senekaotmhwjal.sys"
.
Completion time: 2008-12-28 19:01:47
ComboFix-quarantined-files.txt 2008-12-29 03:01:44
ComboFix2.txt 2008-12-29 02:28:04
ComboFix3.txt 2008-12-28 20:59:22
Pre-Run: 2,231,169,024 bytes free
Post-Run: 2,217,578,496 bytes free
225 --- E O F --- 2008-12-18 08:56:14
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 2.80GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A02
USER : Yvonne Negron ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.0 (Activated)
C:\ (Local Disk) - NTFS - Total:33 Go (Free:2 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
E:\ (Local Disk) - NTFS - Total:698 Go (Free:662 Go)
F:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Sun 12/28/2008|18:56 )
--------------------\\ Listing folders in APPLIC~1
[12/01/2008|07:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[02/22/2008|06:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[08/05/2008|05:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL
[05/01/2007|09:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL Downloads
[07/01/2007|09:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[03/14/2007|11:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[12/28/2008|06:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> avg8
[02/25/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Dell
[02/26/2008|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Downloaded Installations
[08/03/2008|12:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google
[03/01/2005|08:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> GTek
[11/17/2007|10:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> HP
[03/01/2005|08:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[12/02/2007|09:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Knowledge Adventure
[12/27/2008|10:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Lavasoft
[05/01/2007|09:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Macromedia
[12/27/2008|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
[09/10/2005|04:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com
[04/18/2005|06:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall
[10/23/2007|03:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[08/02/2005|08:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> MotiveSysIDs
[02/26/2008|11:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ParetoLogic
[05/21/2005|08:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Pure Networks
[03/01/2005|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> QuickTime
[03/01/2005|07:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SBSI
[08/03/2008|07:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Seagate
[05/27/2008|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
[08/03/2008|04:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy
[05/27/2008|08:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SupportSoft
[12/28/2008|12:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TEMP
[08/03/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Viewpoint
[09/10/2005|04:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[12/07/2008|01:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WinZip
[12/27/2006|08:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> yahoo!
[03/01/2005|07:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[03/01/2005|08:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Jasc Software Inc
[03/01/2005|08:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[03/01/2005|08:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Sonic
[03/01/2005|08:17] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Sun
[04/04/2005|01:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Macromedia
[03/18/2005|09:39] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> McAfee.com Personal Firewall
[12/28/2008|06:20] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[11/13/2007|07:59] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Mozilla
[11/13/2007|07:59] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Talkback
[09/06/2008|10:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Adobe
[09/06/2008|10:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Macromedia
[12/28/2008|06:20] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
[09/02/2006|07:40] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> acccore
[04/21/2008|05:56] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Adobe
[01/22/2007|06:36] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> AdobeUM
[08/05/2008|05:22] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> AOL
[12/23/2008|05:02] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Apple Computer
[04/12/2007|10:03] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Common Files
[12/21/2008|11:05] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Costco Photo Organizer
[12/15/2008|09:23] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Costco Photo Viewer US
[03/15/2007|12:00] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Creative
[11/24/2005|01:15] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> CyberLink
[04/08/2005|10:11] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Earthlink
[04/08/2005|08:03] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> EarthLink Toolbar
[04/22/2007|10:05] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> FotoWire
[10/01/2006|10:11] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Google
[04/10/2007|11:36] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Gtek
[07/17/2005|07:28] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Help
[11/17/2007|10:39] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> HP
[12/23/2006|03:27] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> ICAClient
[01/21/2006|08:44] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Identities
[08/03/2008|12:39] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> InstallShield
[03/01/2005|08:28] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Jasc Software Inc
[08/03/2008|12:28] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Lavasoft
[06/06/2005|01:14] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Leadertech
[01/01/2008|02:23] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> LimeWire
[11/23/2007|02:30] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Macromedia
[12/27/2008|10:49] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Malwarebytes
[03/25/2005|06:30] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> McAfee.com
[03/20/2005|10:47] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> McAfee.com Personal Firewall
[12/28/2008|06:20] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Microsoft
[08/14/2006|09:14] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Mozilla
[10/21/2007|03:38] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> MSNInstaller
[12/17/2008|08:54] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Printer Info Cache
[03/25/2008|03:04] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Real
[10/23/2007|12:35] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Skype
[04/12/2006|07:31] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Snapfish
[06/06/2005|01:15] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Sonic
[03/01/2005|08:17] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Sun
[07/25/2006|06:54] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Talkback
[08/20/2008|08:27] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> U3
[03/19/2008|07:15] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> Viewpoint
[12/05/2008|01:43] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> yahoo!
[05/21/2005|08:02] C:\DOCUME~1\YVONNE~1\APPLIC~1\<DIR> You've Got Pictures Screensaver
--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[12/27/2008 07:33 PM][--a------] C:\WINDOWS\tasks\Norton PC Checkup Weekend Scanner.job
[12/24/2008 06:58 PM][--a------] C:\WINDOWS\tasks\Norton PC Checkup WeekDay Scanner.job
[12/22/2008 01:30 PM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[12/28/2008 06:25 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 03:00 AM][-r-h-----] C:\WINDOWS\tasks\DESKTOP.INI
--------------------\\ Listing Folders in C:\Program Files
[07/14/2008|07:08] C:\Program Files\<DIR> Adobe
[03/01/2005|08:05] C:\Program Files\<DIR> Analog Devices
[09/14/2006|06:21] C:\Program Files\<DIR> AOD
[08/05/2008|05:25] C:\Program Files\<DIR> AOL
[09/06/2008|04:51] C:\Program Files\<DIR> Apple Software Update
[11/05/2007|11:13] C:\Program Files\<DIR> Audible
[08/03/2008|12:05] C:\Program Files\<DIR> AVG
[04/23/2005|08:56] C:\Program Files\<DIR> BigIdea
[09/22/2008|10:31] C:\Program Files\<DIR> Bonjour
[12/06/2008|02:43] C:\Program Files\<DIR> Citrix
[12/28/2008|06:23] C:\Program Files\<DIR> Common Files
[12/14/2008|06:32] C:\Program Files\<DIR> Costco
[05/10/2008|11:57] C:\Program Files\<DIR> Coupons
[05/10/2007|09:33] C:\Program Files\<DIR> Creative
[03/14/2007|10:46] C:\Program Files\<DIR> Creative Installation Information
[03/01/2005|08:19] C:\Program Files\<DIR> CyberLink
[10/21/2007|03:42] C:\Program Files\<DIR> Dell
[03/01/2005|08:29] C:\Program Files\<DIR> Dell Inc
[05/27/2008|08:07] C:\Program Files\<DIR> Dell Support Center
[04/10/2007|11:14] C:\Program Files\<DIR> DellSupport
[05/02/2006|05:49] C:\Program Files\<DIR> Disney Interactive
[08/03/2008|01:06] C:\Program Files\<DIR> Google
[08/03/2008|07:10] C:\Program Files\<DIR> Grisoft
[02/05/2007|09:30] C:\Program Files\<DIR> HP
[06/20/2006|09:19] C:\Program Files\<DIR> IncrediMail
[10/05/2005|05:56] C:\Program Files\<DIR> Infogrames Interactive
[09/27/2008|08:37] C:\Program Files\<DIR> InstallShield Installation Information
[05/23/2005|07:26] C:\Program Files\<DIR> Intel
[12/12/2008|07:21] C:\Program Files\<DIR> Internet Explorer
[12/01/2008|07:12] C:\Program Files\<DIR> iPod
[12/01/2008|07:13] C:\Program Files\<DIR> iTunes
[05/23/2005|07:35] C:\Program Files\<DIR> Jasc Software Inc
[07/14/2008|07:12] C:\Program Files\<DIR> Java
[12/27/2008|10:19] C:\Program Files\<DIR> Lavasoft
[01/01/2008|08:46] C:\Program Files\<DIR> LimeWire
[04/22/2007|10:05] C:\Program Files\<DIR> Logitech
[12/27/2008|10:48] C:\Program Files\<DIR> Malwarebytes' Anti-Malware
[09/29/2008|08:32] C:\Program Files\<DIR> Messenger
[03/01/2005|08:21] C:\Program Files\<DIR> Microsoft ActiveSync
[08/03/2008|10:01] C:\Program Files\<DIR> Microsoft CAPICOM 2.1.0.2
[03/01/2005|08:23] C:\Program Files\<DIR> Microsoft Encarta
[03/01/2005|07:41] C:\Program Files\<DIR> microsoft frontpage
[05/23/2005|07:02] C:\Program Files\<DIR> Microsoft Office
[03/01/2005|08:23] C:\Program Files\<DIR> Microsoft Picture It! 9
[03/01/2005|08:26] C:\Program Files\<DIR> Microsoft Plus! Digital Media Edition
[03/01/2005|08:21] C:\Program Files\<DIR> Microsoft Works
[03/01/2005|08:20] C:\Program Files\<DIR> Microsoft Works Suite 2004
[05/23/2005|07:26] C:\Program Files\<DIR> Modem Helper
[03/01/2005|08:18] C:\Program Files\<DIR> Modem On Hold
[09/29/2008|08:25] C:\Program Files\<DIR> Movie Maker
[12/28/2008|06:28] C:\Program Files\<DIR> Mozilla Firefox
[10/21/2007|03:38] C:\Program Files\<DIR> MSN
[03/01/2005|07:41] C:\Program Files\<DIR> MSN Gaming Zone
[11/17/2006|02:20] C:\Program Files\<DIR> MSXML 4.0
[08/03/2008|07:02] C:\Program Files\<DIR> MSXML 6.0
[05/06/2008|07:50] C:\Program Files\<DIR> MUSICMATCH
[09/29/2008|08:22] C:\Program Files\<DIR> NetMeeting
[12/17/2008|05:56] C:\Program Files\<DIR> Norton PC Checkup
[03/01/2005|07:41] C:\Program Files\<DIR> Online Services
[09/29/2008|08:21] C:\Program Files\<DIR> Outlook Express
[06/08/2007|07:12] C:\Program Files\<DIR> Overland
[08/03/2008|10:03] C:\Program Files\<DIR> Pure Networks
[12/01/2008|07:08] C:\Program Files\<DIR> QuickTime
[05/27/2008|11:05] C:\Program Files\<DIR> Real
[11/17/2008|09:56] C:\Program Files\<DIR> Rhapsody
[12/01/2008|06:53] C:\Program Files\<DIR> Safari
[08/03/2008|07:03] C:\Program Files\<DIR> Seagate
[05/27/2008|11:06] C:\Program Files\<DIR> Skype
[03/25/2005|10:39] C:\Program Files\<DIR> Sonic
[09/27/2008|08:39] C:\Program Files\<DIR> Sony
[12/08/2008|10:22] C:\Program Files\<DIR> Spybot - Search & Destroy
[06/30/2006|08:47] C:\Program Files\<DIR> Stentor
[05/27/2007|11:27] C:\Program Files\<DIR> Taomedic
[12/07/2008|01:15] C:\Program Files\<DIR> TextPad 5
[08/03/2008|01:01] C:\Program Files\<DIR> Trend Micro
[12/28/2008|10:23] C:\Program Files\<DIR> Trillian
[12/23/2006|04:47] C:\Program Files\<DIR> Uninstall Information
[08/03/2008|09:43] C:\Program Files\<DIR> Viewpoint
[12/21/2006|10:08] C:\Program Files\<DIR> Windows Media Connect 2
[09/29/2008|08:21] C:\Program Files\<DIR> Windows Media Player
[09/29/2008|08:21] C:\Program Files\<DIR> Windows NT
[07/07/2005|06:36] C:\Program Files\<DIR> WindowsUpdate
[12/07/2008|01:10] C:\Program Files\<DIR> WinZip
[03/01/2005|07:41] C:\Program Files\<DIR> XEROX
[12/08/2008|10:22] C:\Program Files\<DIR> Yahoo!
--------------------\\ Listing Folders in C:\Program Files\Common Files
[02/22/2008|06:46] C:\Program Files\Common Files\<DIR> Adobe
[08/05/2008|05:26] C:\Program Files\Common Files\<DIR> AOL
[05/06/2006|05:18] C:\Program Files\Common Files\<DIR> aolback
[12/01/2008|07:07] C:\Program Files\Common Files\<DIR> Apple
[03/01/2005|08:21] C:\Program Files\Common Files\<DIR> Designer
[04/22/2007|10:05] C:\Program Files\Common Files\<DIR> FotoWire
[02/05/2007|09:29] C:\Program Files\Common Files\<DIR> Hewlett-Packard
[12/14/2008|06:32] C:\Program Files\Common Files\<DIR> HP
[03/01/2005|08:28] C:\Program Files\Common Files\<DIR> InstallShield
[03/01/2005|08:17] C:\Program Files\Common Files\<DIR> Java
[06/20/2005|07:58] C:\Program Files\Common Files\<DIR> Knowledge Adventure
[04/22/2007|10:02] C:\Program Files\Common Files\<DIR> Logitech
[08/25/2008|11:37] C:\Program Files\Common Files\<DIR> Microsoft Shared
[03/01/2005|07:41] C:\Program Files\Common Files\<DIR> MSSoap
[05/25/2005|06:49] C:\Program Files\Common Files\<DIR> NSV
[03/01/2005|08:35] C:\Program Files\Common Files\<DIR> Nullsoft
[05/27/2005|07:44] C:\Program Files\Common Files\<DIR> ODBC
[03/31/2008|07:43] C:\Program Files\Common Files\<DIR> Real
[05/13/2007|06:59] C:\Program Files\Common Files\<DIR> Scanner
[03/01/2005|07:41] C:\Program Files\Common Files\<DIR> Services
[03/01/2005|08:27] C:\Program Files\Common Files\<DIR> Sonic
[03/01/2005|07:41] C:\Program Files\Common Files\<DIR> SpeechEngines
[12/27/2008|07:35] C:\Program Files\Common Files\<DIR> Symantec Shared
[09/29/2008|08:21] C:\Program Files\Common Files\<DIR> System
[12/27/2008|10:18] C:\Program Files\Common Files\<DIR> Wise Installation Wizard
[03/31/2008|07:44] C:\Program Files\Common Files\<DIR> xing shared
--------------------\\ Process
( 53 Processes )
... OK !
--------------------\\ Searching with S_Lop
No Lop folder found !
--------------------\\ Searching for Lop Files - Folders
C:\DOCUME~1\YVONNE~1\Cookies\
[email protected][2].txt
--------------------\\ Searching within the Registry
..... OK !
--------------------\\ Checking the Hosts file
Hosts file CLEAN
--------------------\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net Rootkit scan 2008-12-28 18:57:56
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
disk error: C:\WINDOWS\System32\
please note that you need administrator rights to perform deep scan
--------------------\\ Searching for other infections
No other infections found !
[F:2][D:1]-> C:\DOCUME~1\YVONNE~1\LOCALS~1\Temp
[F:333][D:0]-> C:\DOCUME~1\YVONNE~1\Cookies
[F:6][D:2]-> C:\DOCUME~1\YVONNE~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Sun 12/28/2008|18:58 - Option : [1]
--------------------\\ Scan completed at 18:58:41