——————–\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon™ XP 2600+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Johanna & Gera ( Administrator )
BOOT : Normal boot
Antivirus : McAfee VirusScan Enterprise 8.5.0.781 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:70 Go (Free:51 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
G:\ (USB)
H:\ (USB)
“C:\Lop SD” ( MAJ : 19-12-2008|23:40 )
Option : ( vr 15-01-2010|16:10 )
——————–\\ Beschrijving van mappen in APPLIC~1
C:\DOCUME~1\ALLUSE~1\APPLIC~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
C:\DOCUME~1\ALLUSE~1\APPLIC~1\flag ace stupid data
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Games
C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nokia
C:\DOCUME~1\ALLUSE~1\APPLIC~1\OD2
C:\DOCUME~1\ALLUSE~1\APPLIC~1\OviInstallerCache
C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Tools
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Postbank
C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Raxco
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Support.com
C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Vivendi Universal Games
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
C:\DOCUME~1\ALLUSE~1\APPLIC~1\bytes
C:\DOCUME~1\ALLUSE~1\APPLIC~1\bytes beschikbaar
C:\DOCUME~1\DEFAUL~1\APPLIC~1\Adobe
C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
C:\DOCUME~1\DEFAUL~1\APPLIC~1\InterTrust
C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
C:\DOCUME~1\DEFAUL~1\APPLIC~1\bytes
C:\DOCUME~1\DEFAUL~1\APPLIC~1\bytes beschikbaar
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Adobe
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Apple Computer
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Byte64coal
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Identities
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\InterTrust
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\LimeWire
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Macromedia
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Malwarebytes
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Microsoft
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Mozilla
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\MSN6
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\PC Suite
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\PC Tools
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Real
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\Sun
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\U3
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\bytes
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\bytes beschikbaar
C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
C:\DOCUME~1\LOCALS~1\APPLIC~1\Help
C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
C:\DOCUME~1\LOCALS~1\APPLIC~1\bytes
C:\DOCUME~1\LOCALS~1\APPLIC~1\bytes beschikbaar
C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
C:\DOCUME~1\NETWOR~1\APPLIC~1\bytes
C:\DOCUME~1\NETWOR~1\APPLIC~1\bytes beschikbaar
——————–\\ Geplande Taken gelocaliseerd in C:\WINDOWS\Tasks
C:\WINDOWS\tasks\AEC307729184B762.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Herinnering voor registratie 3.job
C:\WINDOWS\tasks\Herinnering voor registratie 2.job
C:\WINDOWS\tasks\Herinnering voor registratie 1.job
C:\WINDOWS\tasks\SA.DAT
C:\WINDOWS\tasks\desktop.ini
( AEC307729184B762.job )=( c:\docume~1\johann~1.sn0\applic~1\byte64~1\downloadbitswma.exe )
——————–\\ Beschrijving van mappen in C:\Program Files
C:\Program Files\Adobe
C:\Program Files\aod
C:\Program Files\Apple Software Update
C:\Program Files\Belastingdienst
C:\Program Files\Bonjour
C:\Program Files\Byte64coal
C:\Program Files\Circl Developement
C:\Program Files\Common Files
C:\Program Files\ComPlus Applications
C:\Program Files\CyberLink
C:\Program Files\DIFX
C:\Program Files\Digitalway
C:\Program Files\directx
C:\Program Files\Disney Interactive
C:\Program Files\Google
C:\Program Files\Grisoft
C:\Program Files\InstallShield Installation Information
C:\Program Files\Internet Explorer
C:\Program Files\iPod
C:\Program Files\iTunes
C:\Program Files\IVT Corporation
C:\Program Files\Java
C:\Program Files\Lexmark X5100 Series
C:\Program Files\LimeWire
C:\Program Files\LimeWire Plus
C:\Program Files\LimewirePlus
C:\Program Files\Macrogaming
C:\Program Files\Malwarebytes' Anti-Malware
C:\Program Files\Mattel Interactive
C:\Program Files\McAfee
C:\Program Files\Messenger
C:\Program Files\Messenger Plus! Live
C:\Program Files\Microsoft
C:\Program Files\microsoft frontpage
C:\Program Files\Microsoft Office
C:\Program Files\Microsoft Office Outlook Connector
C:\Program Files\Microsoft Silverlight
C:\Program Files\Microsoft SQL Server Compact Edition
C:\Program Files\Microsoft Sync Framework
C:\Program Files\Microsoft Visual Studio
C:\Program Files\Microsoft Works
C:\Program Files\Microsoft.NET
C:\Program Files\Movie Maker
C:\Program Files\MSBuild
C:\Program Files\MSECache
C:\Program Files\MSN
C:\Program Files\MSN Gaming Zone
C:\Program Files\MSXML 4.0
C:\Program Files\NetMeeting
C:\Program Files\Nokia
C:\Program Files\Online Services
C:\Program Files\Outlook Express
C:\Program Files\PC Connectivity Solution
C:\Program Files\PC Connectivity Solution(2)
C:\Program Files\Postbank
C:\Program Files\Q-TEC WEBCAM 100 USB
C:\Program Files\QuickTime
C:\Program Files\Raxco
C:\Program Files\Real
C:\Program Files\Reference Assemblies
C:\Program Files\Safari
C:\Program Files\Spyware Doctor
C:\Program Files\Spyware Stormer
C:\Program Files\support.com
C:\Program Files\Uninstall Information
C:\Program Files\Virtual CD v4 SDK
C:\Program Files\Windows Live
C:\Program Files\Windows Live SkyDrive
C:\Program Files\Windows Media Player
C:\Program Files\Windows NT
C:\Program Files\WindowsUpdate
C:\Program Files\xerox
C:\Program Files\Zylom Games
C:\Program Files\bytes
C:\Program Files\bytes beschikbaar
——————–\\ Beschrijving van mappen in C:\Program Files\Common Files
C:\Program Files\Common Files\Adobe
C:\Program Files\Common Files\Apple
C:\Program Files\Common Files\Barbie(TM)
C:\Program Files\Common Files\Cisco Systems
C:\Program Files\Common Files\DESIGNER
C:\Program Files\Common Files\InstallShield
C:\Program Files\Common Files\Java
C:\Program Files\Common Files\Knowledge Adventure
C:\Program Files\Common Files\McAfee
C:\Program Files\Common Files\Microsoft Shared
C:\Program Files\Common Files\MSSoap
C:\Program Files\Common Files\Nokia(2)
C:\Program Files\Common Files\ODBC
C:\Program Files\Common Files\PC Tools
C:\Program Files\Common Files\PCSuite
C:\Program Files\Common Files\Real
C:\Program Files\Common Files\Services
C:\Program Files\Common Files\SpeechEngines
C:\Program Files\Common Files\System
C:\Program Files\Common Files\Vivendi Universal Games
C:\Program Files\Common Files\Windows Live
C:\Program Files\Common Files\xing shared
C:\Program Files\Common Files\bytes
C:\Program Files\Common Files\bytes beschikbaar
——————–\\ Process
( 51 Processes )
iexplore.exe ~
IEXPLORE.EXE ~
IEXPLORE.EXE ~
——————–\\ Zoeken met S_Lop
Geen Lop mappen gevonden !
——————–\\ Zoeken naar Lop Bestanden - Mappen
C:\DOCUME~1\ALLUSE~1\APPLIC~1\flag ace stupid data
C:\DOCUME~1\ALLUSE~1\APPLIC~1\flag ace stupid data\hold road.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\flag ace stupid data\hold road.exe
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\byte64~1
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\byte64~1\downloadbitswma.exe
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\byte64~1\goiwpwco.exe
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\byte64~1\mzklrsux.exe
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\byte64~1\Rect2.exe
C:\DOCUME~1\JOHANN~1.SN0\APPLIC~1\byte64~1\Software okay eggs dash.exe
C:\Program Files\byte64~1
C:\WINDOWS\Tasks\AEC307729184B762.job
——————–\\ Zoeken doorheen het Register
“each part”=“C:\\DOCUME~1\\JOHANN~1.SN0\\APPLIC~1\\BYTE64~1\\Rect2.exe”
“Stupid Data Dart Wave”=“C:\\Documents and Settings\\All Users\\Application Data\\flag ace stupid data\\hold road.exe”
——————–\\ Nazicht van het Hosts bestand
Hosts bestand IN ORDE
——————–\\ Zoeken naar verborgen bestanden met Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-15 16:13:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0
——————–\\ Zoeken naar andere infecties
Geen andere infecties gevonden !
-> C:\DOCUME~1\JOHANN~1.SN0\Cookies
-> C:\DOCUME~1\JOHANN~1.SN0\LOCALS~1\TEMPOR~1\content.IE5
1 - “C:\Lop SD\LopR_1.txt” - vr 15-01-2010|16:14 - Option :
——————–\\ Scan voltooid om 16:14:34