Kalai
Topic Starter
Hi, today my brother got a email that said it was from my email address and had nothing in the subject bar and in the email had this link and nothing else–http://eurestransalp.com/oldtemp/ehhh.htm
All the people in my address book were sent this email from my email address and I did not send them.
Can you help me with this, am I infected with spyware? How do I stop the emails from being sent?
I did teh OTL scan and this is what it says–
OTL logfile created on: 8/10/2011 11:23:53 PM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\[removed]\Documents\My Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.78 Gb Available Physical Memory | 59.56% Memory free
6.20 Gb Paging File | 5.06 Gb Available in Paging File | 81.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 283.40 Gb Total Space | 224.46 Gb Free Space | 79.20% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 2.50 Gb Free Space | 17.08% Space Free | Partition Type: NTFS
Computer Name: KOAWOODHAWAI-PC | User Name: [removed] | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\[removed]\Documents\My Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MSN\MSNCoreFiles\msn.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\Core\mchost.exe (McAfee, Inc.)
PRC - C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe (Microsoft Corporation.)
PRC - C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\RtHDVCpl.exe (Realtek Semiconductor)
========== Modules (SafeList) ==========
MOD - C:\Users\[removed]\Documents\My Downloads\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (SftService) – File not found
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McOobeSv) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (GameConsoleService) – C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (mfefirek) – C:\WINDOWS\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\WINDOWS\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\WINDOWS\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\WINDOWS\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (e1express) Intel® – C:\WINDOWS\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/08/09 21:38:29 | 000,000,000 | —D | M]
O1 HOSTS File: ([2006/09/18 11:41:30 | 000,000,761 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20110717142037.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [dellsupportcenter] File not found
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msn in Local intranet)
O15 - HKCU\..Trusted Domains: //@signup.mar@/ ([]msn in Computer)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Forest.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Forest.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 11:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2004/04/30 11:01:00 | 000,000,053 | -HS- | M] () - D:\AUTORUN.INF – [ NTFS ]
O33 - MountPoints2\{663f744a-3f0d-11de-a456-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{663f744a-3f0d-11de-a456-806e6f6e6963}\Shell\AutoRun\command - "" = E:\langsel.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/08/10 19:57:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/07/28 21:01:11 | 000,000,000 | —D | C] – C:\ProgramData\MSNDynFiles
[2011/07/26 19:26:05 | 000,000,000 | —D | C] – C:\Users\[removed]\Documents\MSN Photo Show
[2011/07/25 12:02:42 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/07/25 12:00:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/07/25 12:00:44 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2011/07/24 18:14:08 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Malwarebytes
[2011/07/24 18:13:54 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/07/24 18:13:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/07/24 18:13:53 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/07/24 18:13:50 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/07/24 18:13:50 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/07/22 16:29:26 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\WildTangent
[2011/07/17 23:24:58 | 000,000,000 | —D | C] – C:\Users\[removed]\Documents\My Downloads
[2011/07/17 22:55:52 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\Adobe
[2011/07/17 20:18:22 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Macromedia
[2011/07/17 14:20:36 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeclnk.sys
[2011/07/17 14:20:13 | 000,312,616 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfefirek.sys
[2011/07/17 14:20:13 | 000,160,720 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfewfpk.sys
[2011/07/17 14:20:13 | 000,152,320 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeavfk.sys
[2011/07/17 14:20:13 | 000,083,496 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mferkdet.sys
[2011/07/17 14:20:13 | 000,064,304 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfenlfk.sys
[2011/07/17 14:20:13 | 000,055,456 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\cfwids.sys
[2011/07/17 14:20:13 | 000,051,688 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfebopk.sys
[2011/07/17 14:20:02 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2011/07/17 14:20:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2011/07/17 14:19:49 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2011/07/17 14:18:47 | 000,095,568 | R— | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeapfk.sys
[2011/07/17 14:18:37 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2011/07/17 13:39:48 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Adobe
[2011/07/17 13:14:58 | 000,000,000 | —D | C] – C:\Windows\System32\vmm32
[2011/07/17 11:47:45 | 000,000,000 | —D | C] – C:\Users\[removed]\Tracing
[2011/07/17 11:47:36 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\MSN6
[2011/07/17 10:54:55 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2011/07/17 10:54:54 | 002,421,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2011/07/17 10:54:31 | 000,035,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2011/07/17 10:54:30 | 000,575,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2011/07/17 10:54:30 | 000,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2011/07/17 10:54:24 | 000,171,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2011/07/17 10:54:24 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2011/07/17 04:49:35 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\MSNInstaller
[2011/07/17 04:49:32 | 000,000,000 | —D | C] – C:\Program Files\MSN
[2011/07/17 04:48:37 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\Stardock_Corporation
[2011/07/17 04:46:12 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\DataSafeOnline
[2011/07/17 04:46:01 | 000,000,000 | —D | C] – C:\Intel
[2011/07/17 04:45:52 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/07/17 04:45:48 | 000,000,000 | R–D | C] – C:\Users\[removed]\Searches
[2011/07/17 04:45:48 | 000,000,000 | R–D | C] – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/07/17 04:45:40 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Identities
[2011/07/17 04:45:38 | 000,000,000 | R–D | C] – C:\Users\[removed]\Contacts
[2011/07/17 04:45:36 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\VirtualStore
[2011/07/17 04:45:30 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2011/07/17 04:43:21 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Dell
[2011/07/17 04:43:06 | 000,000,000 | –SD | C] – C:\Users\[removed]\AppData\Roaming\Microsoft
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Videos
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Saved Games
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Pictures
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Music
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Links
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Favorites
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Downloads
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Documents
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Desktop
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\AppData\Local\Temporary Internet Files
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Templates
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Start Menu
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\SendTo
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Recent
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\PrintHood
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\NetHood
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Documents\My Videos
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Documents\My Pictures
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Documents\My Music
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\My Documents
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Local Settings
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\AppData\Local\History
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Cookies
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Application Data
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\AppData\Local\Application Data
[2011/07/17 04:43:06 | 000,000,000 | -H-D | C] – C:\Users\[removed]\AppData
[2011/07/17 04:43:06 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\Temp
[2011/07/17 04:43:06 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\SoftThinks
[2011/07/17 04:43:06 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\Microsoft
[2011/07/17 04:43:06 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Media Center Programs
[2011/07/17 04:39:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Templates
[2011/07/17 04:39:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Videos
[2011/07/17 04:39:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Pictures
[2011/07/17 04:39:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Music
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Start Menu
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Favorites
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Documents
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Desktop
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Application Data
========== Files - Modified Within 30 Days ==========
[2011/08/10 21:57:43 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/10 21:57:43 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/10 20:03:30 | 000,595,446 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/08/10 20:03:30 | 000,101,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/08/10 19:57:54 | 000,001,735 | —- | M] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2011/08/10 19:57:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/08/09 23:08:18 | 000,035,406 | —- | M] () – C:\Users\[removed]\Documents\ALLC 6-08-11.pdf
[2011/08/09 23:07:09 | 000,034,803 | —- | M] () – C:\Users\[removed]\Documents\ALLC KGS 6-10-11.pdf
[2011/08/05 00:15:06 | 001,572,864 | -HS- | M] () – C:\Users\[removed]\NTUSER.bak
[2011/08/02 15:01:34 | 000,003,584 | —- | M] () – C:\Users\[removed]\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/02 15:01:04 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2011/07/28 20:58:17 | 000,001,973 | —- | M] () – C:\Users\Public\Desktop\MSN.lnk
[2011/07/28 20:58:17 | 000,001,787 | —- | M] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\MSN.lnk
[2011/07/25 12:00:45 | 000,000,733 | —- | M] () – C:\Users\[removed]\Desktop\NTREGOPT.lnk
[2011/07/25 12:00:45 | 000,000,714 | —- | M] () – C:\Users\[removed]\Desktop\ERUNT.lnk
[2011/07/24 18:13:54 | 000,000,930 | —- | M] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/24 18:13:54 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/20 09:29:27 | 000,000,938 | —- | M] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/07/17 22:55:03 | 000,000,388 | —- | M] () – C:\Users\[removed]\Desktop\Documents - Shortcut.lnk
[2011/07/17 22:54:57 | 000,000,385 | —- | M] () – C:\Users\[removed]\Desktop\Pictures - Shortcut.lnk
[2011/07/17 11:30:51 | 000,230,120 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/07/17 05:25:19 | 000,000,943 | —- | M] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/17 04:37:39 | 000,047,092 | —- | M] () – C:\Windows\System32\license.rtf
========== Files Created - No Company Name ==========
[2011/08/09 23:08:18 | 000,035,406 | —- | C] () – C:\Users\[removed]\Documents\ALLC 6-08-11.pdf
[2011/08/09 23:07:09 | 000,034,803 | —- | C] () – C:\Users\[removed]\Documents\ALLC KGS 6-10-11.pdf
[2011/08/02 15:01:32 | 000,003,584 | —- | C] () – C:\Users\[removed]\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/02 15:01:04 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2011/07/25 12:00:45 | 000,000,733 | —- | C] () – C:\Users\[removed]\Desktop\NTREGOPT.lnk
[2011/07/25 12:00:45 | 000,000,714 | —- | C] () – C:\Users\[removed]\Desktop\ERUNT.lnk
[2011/07/24 18:13:54 | 000,000,930 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/24 18:13:54 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/20 09:29:27 | 000,000,938 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/07/17 22:55:03 | 000,000,388 | —- | C] () – C:\Users\[removed]\Desktop\Documents - Shortcut.lnk
[2011/07/17 22:54:57 | 000,000,385 | —- | C] () – C:\Users\[removed]\Desktop\Pictures - Shortcut.lnk
[2011/07/17 14:25:11 | 000,001,029 | —- | C] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSN Connection Center.lnk
[2011/07/17 14:24:21 | 000,001,735 | —- | C] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2011/07/17 10:54:52 | 000,001,973 | —- | C] () – C:\Users\Public\Desktop\MSN.lnk
[2011/07/17 10:54:52 | 000,001,787 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\MSN.lnk
[2011/07/17 05:25:19 | 000,000,943 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/17 04:45:50 | 000,000,949 | —- | C] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/07/17 04:45:48 | 000,000,944 | —- | C] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011/07/17 04:45:38 | 000,000,915 | —- | C] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2011/07/17 04:43:06 | 001,572,864 | -HS- | C] () – C:\Users\[removed]\NTUSER.bak
[2011/07/17 04:43:06 | 000,000,258 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2009/05/12 13:54:58 | 001,953,696 | —- | C] () – C:\Windows\System32\igklg400.dll
[2009/05/12 13:54:58 | 001,533,360 | —- | C] () – C:\Windows\System32\igklg450.dll
[2009/05/12 13:54:58 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2009/05/12 13:54:58 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2009/05/12 13:51:36 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/05/12 13:51:36 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/02/03 13:11:25 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 02:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 02:47:37 | 000,230,120 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 02:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:33:01 | 000,595,446 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 00:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 00:33:01 | 000,101,144 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 00:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 00:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 00:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/01 22:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/01 22:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/01 21:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/01 21:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2011/07/17 05:03:53 | 000,000,000 | —D | M] – C:\Users\[removed]\AppData\Roaming\MSNInstaller
[2011/07/22 16:29:26 | 000,000,000 | —D | M] – C:\Users\[removed]\AppData\Roaming\WildTangent
[2011/08/10 15:39:22 | 000,032,588 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 11:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 16:24:42 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/09/18 11:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/05/12 13:55:07 | 000,003,879 | RH– | M] () – C:\dell.sdr
[2011/08/10 19:57:39 | 3523,690,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 02:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 02:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 02:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 02:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 11:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/01/20 16:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 02:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/12/04 17:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 16:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 17:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 17:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 17:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 00:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 00:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/20 09:29:27 | 000,000,286 | -HS- | M] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-18 05:42:23
< End of report >
Any help or information onwhat is going on would be great, thanks and aloha.
Kalai
All the people in my address book were sent this email from my email address and I did not send them.
Can you help me with this, am I infected with spyware? How do I stop the emails from being sent?
I did teh OTL scan and this is what it says–
OTL logfile created on: 8/10/2011 11:23:53 PM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\[removed]\Documents\My Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.78 Gb Available Physical Memory | 59.56% Memory free
6.20 Gb Paging File | 5.06 Gb Available in Paging File | 81.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 283.40 Gb Total Space | 224.46 Gb Free Space | 79.20% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 2.50 Gb Free Space | 17.08% Space Free | Partition Type: NTFS
Computer Name: KOAWOODHAWAI-PC | User Name: [removed] | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\[removed]\Documents\My Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MSN\MSNCoreFiles\msn.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\Core\mchost.exe (McAfee, Inc.)
PRC - C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe (Microsoft Corporation.)
PRC - C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\RtHDVCpl.exe (Realtek Semiconductor)
========== Modules (SafeList) ==========
MOD - C:\Users\[removed]\Documents\My Downloads\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (SftService) – File not found
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McOobeSv) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (GameConsoleService) – C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (mfefirek) – C:\WINDOWS\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\WINDOWS\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\WINDOWS\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\WINDOWS\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (e1express) Intel® – C:\WINDOWS\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/08/09 21:38:29 | 000,000,000 | —D | M]
O1 HOSTS File: ([2006/09/18 11:41:30 | 000,000,761 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20110717142037.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [dellsupportcenter] File not found
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msn in Local intranet)
O15 - HKCU\..Trusted Domains: //@signup.mar@/ ([]msn in Computer)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Forest.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Forest.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 11:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2004/04/30 11:01:00 | 000,000,053 | -HS- | M] () - D:\AUTORUN.INF – [ NTFS ]
O33 - MountPoints2\{663f744a-3f0d-11de-a456-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{663f744a-3f0d-11de-a456-806e6f6e6963}\Shell\AutoRun\command - "" = E:\langsel.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/08/10 19:57:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/07/28 21:01:11 | 000,000,000 | —D | C] – C:\ProgramData\MSNDynFiles
[2011/07/26 19:26:05 | 000,000,000 | —D | C] – C:\Users\[removed]\Documents\MSN Photo Show
[2011/07/25 12:02:42 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/07/25 12:00:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/07/25 12:00:44 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2011/07/24 18:14:08 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Malwarebytes
[2011/07/24 18:13:54 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/07/24 18:13:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/07/24 18:13:53 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/07/24 18:13:50 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/07/24 18:13:50 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/07/22 16:29:26 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\WildTangent
[2011/07/17 23:24:58 | 000,000,000 | —D | C] – C:\Users\[removed]\Documents\My Downloads
[2011/07/17 22:55:52 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\Adobe
[2011/07/17 20:18:22 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Macromedia
[2011/07/17 14:20:36 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeclnk.sys
[2011/07/17 14:20:13 | 000,312,616 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfefirek.sys
[2011/07/17 14:20:13 | 000,160,720 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfewfpk.sys
[2011/07/17 14:20:13 | 000,152,320 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeavfk.sys
[2011/07/17 14:20:13 | 000,083,496 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mferkdet.sys
[2011/07/17 14:20:13 | 000,064,304 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfenlfk.sys
[2011/07/17 14:20:13 | 000,055,456 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\cfwids.sys
[2011/07/17 14:20:13 | 000,051,688 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfebopk.sys
[2011/07/17 14:20:02 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2011/07/17 14:20:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2011/07/17 14:19:49 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2011/07/17 14:18:47 | 000,095,568 | R— | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeapfk.sys
[2011/07/17 14:18:37 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2011/07/17 13:39:48 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Adobe
[2011/07/17 13:14:58 | 000,000,000 | —D | C] – C:\Windows\System32\vmm32
[2011/07/17 11:47:45 | 000,000,000 | —D | C] – C:\Users\[removed]\Tracing
[2011/07/17 11:47:36 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\MSN6
[2011/07/17 10:54:55 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2011/07/17 10:54:54 | 002,421,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2011/07/17 10:54:31 | 000,035,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2011/07/17 10:54:30 | 000,575,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2011/07/17 10:54:30 | 000,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2011/07/17 10:54:24 | 000,171,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2011/07/17 10:54:24 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2011/07/17 04:49:35 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\MSNInstaller
[2011/07/17 04:49:32 | 000,000,000 | —D | C] – C:\Program Files\MSN
[2011/07/17 04:48:37 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\Stardock_Corporation
[2011/07/17 04:46:12 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\DataSafeOnline
[2011/07/17 04:46:01 | 000,000,000 | —D | C] – C:\Intel
[2011/07/17 04:45:52 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/07/17 04:45:48 | 000,000,000 | R–D | C] – C:\Users\[removed]\Searches
[2011/07/17 04:45:48 | 000,000,000 | R–D | C] – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/07/17 04:45:40 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Identities
[2011/07/17 04:45:38 | 000,000,000 | R–D | C] – C:\Users\[removed]\Contacts
[2011/07/17 04:45:36 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\VirtualStore
[2011/07/17 04:45:30 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2011/07/17 04:43:21 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Dell
[2011/07/17 04:43:06 | 000,000,000 | –SD | C] – C:\Users\[removed]\AppData\Roaming\Microsoft
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Videos
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Saved Games
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Pictures
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Music
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Links
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Favorites
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Downloads
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Documents
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\Desktop
[2011/07/17 04:43:06 | 000,000,000 | R–D | C] – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\AppData\Local\Temporary Internet Files
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Templates
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Start Menu
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\SendTo
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Recent
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\PrintHood
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\NetHood
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Documents\My Videos
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Documents\My Pictures
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Documents\My Music
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\My Documents
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Local Settings
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\AppData\Local\History
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Cookies
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\Application Data
[2011/07/17 04:43:06 | 000,000,000 | -HSD | C] – C:\Users\[removed]\AppData\Local\Application Data
[2011/07/17 04:43:06 | 000,000,000 | -H-D | C] – C:\Users\[removed]\AppData
[2011/07/17 04:43:06 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\Temp
[2011/07/17 04:43:06 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\SoftThinks
[2011/07/17 04:43:06 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Local\Microsoft
[2011/07/17 04:43:06 | 000,000,000 | —D | C] – C:\Users\[removed]\AppData\Roaming\Media Center Programs
[2011/07/17 04:39:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Templates
[2011/07/17 04:39:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Videos
[2011/07/17 04:39:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Pictures
[2011/07/17 04:39:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Music
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Start Menu
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Favorites
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Documents
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Desktop
[2011/07/17 04:39:08 | 000,000,000 | -HSD | C] – C:\ProgramData\Application Data
========== Files - Modified Within 30 Days ==========
[2011/08/10 21:57:43 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/10 21:57:43 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/10 20:03:30 | 000,595,446 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/08/10 20:03:30 | 000,101,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/08/10 19:57:54 | 000,001,735 | —- | M] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2011/08/10 19:57:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/08/09 23:08:18 | 000,035,406 | —- | M] () – C:\Users\[removed]\Documents\ALLC 6-08-11.pdf
[2011/08/09 23:07:09 | 000,034,803 | —- | M] () – C:\Users\[removed]\Documents\ALLC KGS 6-10-11.pdf
[2011/08/05 00:15:06 | 001,572,864 | -HS- | M] () – C:\Users\[removed]\NTUSER.bak
[2011/08/02 15:01:34 | 000,003,584 | —- | M] () – C:\Users\[removed]\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/02 15:01:04 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2011/07/28 20:58:17 | 000,001,973 | —- | M] () – C:\Users\Public\Desktop\MSN.lnk
[2011/07/28 20:58:17 | 000,001,787 | —- | M] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\MSN.lnk
[2011/07/25 12:00:45 | 000,000,733 | —- | M] () – C:\Users\[removed]\Desktop\NTREGOPT.lnk
[2011/07/25 12:00:45 | 000,000,714 | —- | M] () – C:\Users\[removed]\Desktop\ERUNT.lnk
[2011/07/24 18:13:54 | 000,000,930 | —- | M] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/24 18:13:54 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/20 09:29:27 | 000,000,938 | —- | M] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/07/17 22:55:03 | 000,000,388 | —- | M] () – C:\Users\[removed]\Desktop\Documents - Shortcut.lnk
[2011/07/17 22:54:57 | 000,000,385 | —- | M] () – C:\Users\[removed]\Desktop\Pictures - Shortcut.lnk
[2011/07/17 11:30:51 | 000,230,120 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/07/17 05:25:19 | 000,000,943 | —- | M] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/17 04:37:39 | 000,047,092 | —- | M] () – C:\Windows\System32\license.rtf
========== Files Created - No Company Name ==========
[2011/08/09 23:08:18 | 000,035,406 | —- | C] () – C:\Users\[removed]\Documents\ALLC 6-08-11.pdf
[2011/08/09 23:07:09 | 000,034,803 | —- | C] () – C:\Users\[removed]\Documents\ALLC KGS 6-10-11.pdf
[2011/08/02 15:01:32 | 000,003,584 | —- | C] () – C:\Users\[removed]\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/02 15:01:04 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2011/07/25 12:00:45 | 000,000,733 | —- | C] () – C:\Users\[removed]\Desktop\NTREGOPT.lnk
[2011/07/25 12:00:45 | 000,000,714 | —- | C] () – C:\Users\[removed]\Desktop\ERUNT.lnk
[2011/07/24 18:13:54 | 000,000,930 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/24 18:13:54 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/20 09:29:27 | 000,000,938 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/07/17 22:55:03 | 000,000,388 | —- | C] () – C:\Users\[removed]\Desktop\Documents - Shortcut.lnk
[2011/07/17 22:54:57 | 000,000,385 | —- | C] () – C:\Users\[removed]\Desktop\Pictures - Shortcut.lnk
[2011/07/17 14:25:11 | 000,001,029 | —- | C] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSN Connection Center.lnk
[2011/07/17 14:24:21 | 000,001,735 | —- | C] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2011/07/17 10:54:52 | 000,001,973 | —- | C] () – C:\Users\Public\Desktop\MSN.lnk
[2011/07/17 10:54:52 | 000,001,787 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\MSN.lnk
[2011/07/17 05:25:19 | 000,000,943 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/17 04:45:50 | 000,000,949 | —- | C] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/07/17 04:45:48 | 000,000,944 | —- | C] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011/07/17 04:45:38 | 000,000,915 | —- | C] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2011/07/17 04:43:06 | 001,572,864 | -HS- | C] () – C:\Users\[removed]\NTUSER.bak
[2011/07/17 04:43:06 | 000,000,258 | —- | C] () – C:\Users\[removed]\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2009/05/12 13:54:58 | 001,953,696 | —- | C] () – C:\Windows\System32\igklg400.dll
[2009/05/12 13:54:58 | 001,533,360 | —- | C] () – C:\Windows\System32\igklg450.dll
[2009/05/12 13:54:58 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2009/05/12 13:54:58 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2009/05/12 13:51:36 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/05/12 13:51:36 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/02/03 13:11:25 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 02:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 02:47:37 | 000,230,120 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 02:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:33:01 | 000,595,446 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 00:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 00:33:01 | 000,101,144 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 00:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 00:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 00:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/01 22:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/01 22:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/01 21:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/01 21:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2011/07/17 05:03:53 | 000,000,000 | —D | M] – C:\Users\[removed]\AppData\Roaming\MSNInstaller
[2011/07/22 16:29:26 | 000,000,000 | —D | M] – C:\Users\[removed]\AppData\Roaming\WildTangent
[2011/08/10 15:39:22 | 000,032,588 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 11:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 16:24:42 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/09/18 11:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/05/12 13:55:07 | 000,003,879 | RH– | M] () – C:\dell.sdr
[2011/08/10 19:57:39 | 3523,690,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 02:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 02:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 02:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 02:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 11:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/01/20 16:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 02:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/12/04 17:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 16:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 17:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 17:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 17:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 00:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 00:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/20 09:29:27 | 000,000,286 | -HS- | M] () – C:\Users\[removed]\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-18 05:42:23
< End of report >
Any help or information onwhat is going on would be great, thanks and aloha.
Kalai