The other day I caught internet explorer "explorer.exe" scanning my hard drive for *.* any Idea's why internet explorer needs to scan c:\*.* or c:\windows\desktop\*.* or c:\windows\system32\*.* then access classes and user.dat when the computer is supposedly idle with one internet explorer window open, with no page loaded, and network is released.....
Also there's some other file that only scans my drive and registry when I'm playing solitaire.... I'll have to track it down and post it later. something about a twain device and some kind of log file regarding spi?
Using some auditing tools and maybe I'll post some screen captures of the actions.. It's interesting.. I'm gonna find the root's of these scanning issues, and locate the logs the scanners are creating, then decide if they are windows system components or spyware. What I'm finding is that there are three or four applications that are "interacting" indirectly to scan, and list all the files into a specific log, or series of logs... then another application trying to compile that log into a paint file, then phone home, but that application has been denied access ot the internet.. but the network stack is now being given instructions to pad packets with info from buffers and conveniently the application is putting the paint file into the buffer area that is being polled for the packet padding data......


Reply With Quote



