glosasso
Topic Starter
While deleting some programs using the control panel add/remove feature I got a pop from AVG that I had been infected by a trojan. I ran an online Kaspersky scan that confirmed the infection (Infected: Trojan-Downloader.Win32.Agent.dnxz). I ran the OTL scan, the results follow:
OTL logfile created on: 10/14/2010 3:09:15 PM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Glenn LoSasso\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 5.15 Gb Free Space | 5.52% Space Free | Partition Type: NTFS
Computer Name: LAPTOP | User Name: Glenn LoSasso | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
PRC - C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
MOD - C:\Program Files\AlienGUIse\wbhelp.dll (Stardock.Net, Inc)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (acssrv) – C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Driver Services (SafeList) ==========
DRV - (catchme) – C:\DOCUME~1\GLENNL~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (nhcDriverDevice) – C:\WINDOWS\system32\drivers\nhcDriver.sys (pBUS-167 Software - http://www.pbus-167.com)
DRV - (SandBox) – C:\WINDOWS\system32\drivers\SandBox.sys (Agnitum Ltd.)
DRV - (afw) – C:\WINDOWS\system32\drivers\afw.sys (Agnitum Ltd.)
DRV - (afwcore) – C:\WINDOWS\system32\drivers\afwcore.sys (Agnitum Ltd.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (DAdderFltr) – C:\WINDOWS\system32\drivers\dadder.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (vncdrv) – C:\WINDOWS\system32\drivers\vncdrv.sys (Microsoft Corporation)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
[2008/07/28 09:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions
[2008/07/28 09:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions\[removed]
[2008/04/29 11:56:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Firefox\Profiles\xw69a85n.default\extensions
O1 HOSTS File: ([2010/03/25 15:05:08 | 000,380,249 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13124 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1176123311500 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1 [removed] 4.2.2.2
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (c:\progra~1\agnitum\outpos~1\wl_hook.dll) - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
O20 - AppInit_DLLs: (c:\windows\system32\wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)
O24 - Desktop WallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/17 17:42:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell - "" = AutoRun
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (69819404975603712)
========== Files/Folders - Created Within 30 Days ==========
[2010/10/14 14:58:21 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2010/10/13 16:23:05 | 004,259,888 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\audiodriver.EXE
[2010/10/13 16:22:38 | 005,178,792 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\videodriver.EXE
[2010/10/13 14:08:26 | 002,944,016 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\chipset.exe
[2010/10/13 14:07:49 | 001,352,448 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\networkdriver.exe
[2010/10/13 08:03:10 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/10/13 08:03:09 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/10/13 08:02:46 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/10/05 08:45:57 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/10/05 08:45:53 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/10/05 08:42:27 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/10/05 08:40:53 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/14 15:11:15 | 000,442,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/14 15:11:15 | 000,071,910 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/14 15:07:00 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/14 15:05:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/14 15:05:34 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2010/10/14 14:58:21 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2010/10/14 14:55:21 | 000,003,643 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Desktop\scan.html
[2010/10/14 09:55:56 | 066,317,001 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/10/13 16:23:19 | 004,259,888 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\audiodriver.EXE
[2010/10/13 16:22:38 | 005,178,792 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\videodriver.EXE
[2010/10/13 14:22:17 | 000,000,799 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/10/13 14:08:38 | 002,944,016 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\chipset.exe
[2010/10/13 14:07:54 | 001,352,448 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\networkdriver.exe
[2010/10/13 09:52:42 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/10/13 09:28:46 | 000,138,848 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/13 09:21:42 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/18 12:23:26 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mfc42u.dll
[2010/09/18 12:23:26 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42u.dll
[2010/09/18 02:53:25 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mfc42.dll
[2010/09/18 02:53:25 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/09/18 02:53:25 | 000,954,368 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mfc40.dll
[2010/09/18 02:53:25 | 000,954,368 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2010/09/18 02:53:25 | 000,953,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mfc40u.dll
[2010/09/18 02:53:25 | 000,953,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/14 14:55:21 | 000,003,643 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Desktop\scan.html
[2010/10/05 08:47:00 | 000,002,137 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/12 17:03:36 | 000,082,568 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/04/02 11:26:02 | 000,000,120 | —- | C] () – C:\WINDOWS\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
[2009/02/05 20:07:40 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/11/11 08:22:31 | 000,001,400 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Application Data\default.cfg
[2008/07/23 12:50:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/07/23 12:46:38 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/07/10 08:53:59 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/10 08:53:59 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/10 08:53:59 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/03/17 14:17:32 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2008/01/03 12:54:19 | 000,000,136 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\fusioncache.dat
[2007/08/30 15:15:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/08/30 15:15:00 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/08/30 15:15:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/08/30 15:15:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/08/09 12:08:04 | 000,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/05/17 12:16:16 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/05/16 14:05:50 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/04/10 16:09:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/04/06 11:19:48 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2007/04/05 15:45:17 | 000,005,632 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/04/04 10:59:15 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/04/04 09:26:53 | 000,000,056 | —- | C] () – C:\WINDOWS\wb.ini
[2006/07/17 17:55:35 | 000,002,340 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/07/17 10:31:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/06/02 21:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56spn.dll
[2006/06/02 21:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56itl.dll
[2006/06/02 21:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56eng.dll
[2006/06/02 21:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56brz.dll
[2006/06/02 21:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56ger.dll
[2006/06/02 21:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56fra.dll
[2006/06/02 21:09:00 | 000,053,248 | —- | C] () – C:\WINDOWS\sm56jpn.dll
[2006/06/02 21:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56cht.dll
[2006/06/02 21:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56chs.dll
[2005/08/05 17:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[1996/04/03 15:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2010/09/09 08:01:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Agnitum
[2009/11/12 10:50:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/03/17 10:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2008/09/08 12:43:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CopyTransControlCenter
[2009/09/17 09:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/03/25 15:06:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/07/28 09:33:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/03/24 11:46:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/13 09:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/15 09:15:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/09 09:12:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/10/16 09:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Acreon
[2008/08/26 16:09:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Amazon
[2007/04/07 15:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyPod
[2008/09/08 13:03:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTrans
[2008/09/08 12:43:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransControlCenter
[2008/09/08 13:35:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransManager
[2009/09/17 09:12:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Leadertech
[2010/01/07 15:07:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Razer
[2010/10/14 10:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\runic games
[2008/09/08 12:20:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\SyncGuardian
[2007/11/08 16:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Thunderbird
[2008/07/28 09:33:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\TomTom
[2009/06/25 12:59:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WinPatrol
[2007/07/23 08:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WowAceUpdater
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/02/02 13:26:44 | 000,001,024 | —- | M] () – C:\.rnd
[2006/07/17 17:42:45 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/03/31 09:06:19 | 000,000,209 | —- | M] () – C:\Boot.bak
[2009/03/31 17:24:57 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/06/25 11:15:57 | 000,016,226 | —- | M] () – C:\ComboFix.txt
[2006/07/17 17:42:45 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/10/14 15:05:34 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2006/07/17 17:42:45 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/17 17:42:45 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/19 09:07:59 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/10/14 15:05:32 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/07/17 17:42:16 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/11/15 19:46:32 | 000,028,472 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2003/08/06 16:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware logo_slvr.jpg
[2003/08/06 16:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware_logo_slvr.jpg
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
[2006/04/06 11:00:20 | 000,000,138 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Alienware games download store.url
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/07/17 10:29:40 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/07/17 10:29:40 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/07/17 10:29:40 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/19 09:12:28 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/04/05 15:45:31 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/07/17 17:47:58 | 000,000,079 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/10/13 16:23:19 | 004,259,888 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\audiodriver.EXE
[2010/10/13 14:08:38 | 002,944,016 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\chipset.exe
[2010/10/13 14:07:54 | 001,352,448 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\networkdriver.exe
[2010/10/14 14:58:21 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2010/10/13 16:22:38 | 005,178,792 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\videodriver.EXE
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-13 13:21:57
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware_logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL Extras logfile created on: 10/14/2010 3:09:15 PM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Glenn LoSasso\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 5.15 Gb Free Space | 5.52% Space Free | Partition Type: NTFS
Computer Name: LAPTOP | User Name: Glenn LoSasso | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"135:TCP" = 135:TCP:*:Enabled:DCOM
"135:UDP" = 135:UDP:*:Enabled:DCOM2
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EagleSoft\Shared Files\esinetconnect.exe" = C:\Program Files\EagleSoft\Shared Files\esinetconnect.exe:*:Enabled:Patterson EagleSoft Internet Connection – (Patterson Dental Supply, Inc.)
"C:\Program Files\EagleSoft\Shared Files\ESTechUtil.exe" = C:\Program Files\EagleSoft\Shared Files\ESTechUtil.exe:*:Enabled:Patterson EagleSoft Technical Utility – (Patterson Dental Supply, Inc.)
"C:\Program Files\EagleSoft\Shared Files\EagleSoft.exe" = C:\Program Files\EagleSoft\Shared Files\EagleSoft.exe:*:Enabled:Patterson EagleSoft – (Patterson Dental Supply, Inc.)
"C:\Program Files\EagleSoft\Shared Files\techaid.exe" = C:\Program Files\EagleSoft\Shared Files\techaid.exe:*:Enabled:Patterson EagleSoft Technical Reference – ()
"C:\Program Files\EagleSoft\Shared Files\ESMessenger.exe" = C:\Program Files\EagleSoft\Shared Files\ESMessenger.exe:*:Enabled:Patterson EagleSoft Messenger Client – (Patterson Dental Supply, Inc.)
"C:\Program Files\EagleSoft\Shared Files\dbeng7.exe" = C:\Program Files\EagleSoft\Shared Files\dbeng7.exe:*:Enabled:Patterson EagleSoft ODBC Client – (Sybase, Inc.)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – ()
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – File not found
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – File not found
"C:\Program Files\Curse\CurseClient.exe" = C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client – File not found
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"{2A8E4833-F483-4074-B4DB-F295F7901A8D}" = MobileMe Control Panel
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon Camera WIA Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35260E0B-A8C2-4D25-97E2-448DE7275C85}" = Canon Camera WIA Driver
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{652C4ADF-0A29-4B02-9211-EE61675847DE}" = Canon Camera WIA Driver
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{72FA90DD-95D4-4B30-A6A4-9BCFFB4A1033}" = Nero 7 Essentials
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7E7658A2-CD3F-48A7-93EA-0882BCA4FD2A}" = LogMeIn
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{900A92BA-19EF-4A34-86CF-7B6C85BDD971}" = VC_MergeModuleToMSI
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9F7AF7CD-E3D0-4C68-A3BA-C76C359B3AA8}" = LightScribe 1.4.105.1
"{A0E27BA8-353A-4288-AB60-5DE8EDA18E16}" = Symantec Technical Support Web Controls
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B502B428-3386-40A9-98DB-079AAB72E64F}" = mEoU
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver
"{BBB8D142-6F80-42E1-9168-643A105DED1D}" = Patterson EagleSoft
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EB1B8449-CD8F-485B-ADB6-02FBCFE180D3}" = Razer DeathAdder™ Mouse
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"13860389BCE916343D6A5C65169C6F0C6BF6E3EA" = Windows Driver Package - Cypress (CyUsb) USB
"7BDD6421B73797179E9A97E5C7DE019FBC77147F" = Windows Driver Package - Razer (HidUsb) HIDClass (04/04/2009 1.0.5.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Agnitum Outpost Firewall_is1" = Outpost Firewall 2009
"AlienGUIse Theme Manager" = AlienGUIse Theme Manager
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AVG9Uninstall" = AVG Free 9.0
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"CopyPod Suite" = CopyPod Suite (remove only)
"CopyTrans Suite" = CopyTrans Suite Remove Only
"CSCLIB" = Canon Camera Support Core Library
"DA73216D935E3CBA996AFD6E6513ECC587E0C3C1" = Windows Driver Package - Razer (HidUsb) HIDClass (02/02/2007 1.0.5.0)
"EOS Utility" = Canon Utilities EOS Utility
"GoToAssist" = GoToAssist 8.0.0.480
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"InstallShield_{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon EOS Kiss_N REBEL_XT 350D WIA Driver
"InstallShield_{35260E0B-A8C2-4D25-97E2-448DE7275C85}" = Canon EOS-1D Mark II N WIA Driver
"InstallShield_{652C4ADF-0A29-4B02-9211-EE61675847DE}" = Canon EOS-1Ds Mark II WIA Driver
"InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notebook Hardware Control" = Notebook Hardware Control 2.0 Pre-Release-06
"NVIDIA Drivers" = NVIDIA Drivers
"ProInst" = Intel® PROSet/Wireless Software
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 12.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SMSERIAL" = Motorola SM56 Data Fax Modem
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"Theme Manager" = Theme Manager
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol 2009
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Move Media Player" = Move Media Player
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 228: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 240: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 412: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 424: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 436: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:35:24 PM | Computer Name = LAPTOP | Source = MsiInstaller | ID = 10005
Description = Product: Apple Application Support – A later version of Apple Application
Support is already installed on this computer.
Error - 9/21/2010 3:24:14 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 388: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/21/2010 3:24:14 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 228: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/21/2010 3:24:14 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 240: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/21/2010 3:24:14 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 412: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
[ System Events ]
Error - 10/13/2010 8:15:14 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
D4G2VP41 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C46-. The master browser is stopping or an election
is being forced.
Error - 10/13/2010 9:06:28 AM | Computer Name = LAPTOP | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{EE161A86-6F9F-4C46-A71B-C7EB978E103C}
because another computer on the network has the same name. The server could not
start.
Error - 10/13/2010 9:30:25 AM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep
Error - 10/13/2010 9:33:23 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
KARENMILLA that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C4. The master browser is stopping or an election is
being forced.
Error - 10/13/2010 9:39:10 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
D4G2VP41 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C46-. The master browser is stopping or an election
is being forced.
Error - 10/13/2010 9:57:22 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
KARENMILLA that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C4. The master browser is stopping or an election is
being forced.
Error - 10/13/2010 10:15:11 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
D4G2VP41 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C46-. The master browser is stopping or an election
is being forced.
Error - 10/13/2010 10:43:15 AM | Computer Name = LAPTOP | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{EE161A86-6F9F-4C46-A71B-C7EB978E103C}
because another computer on the network has the same name. The server could not
start.
Error - 10/14/2010 3:06:39 PM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep
Error - 10/14/2010 3:13:29 PM | Computer Name = LAPTOP | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{EE161A86-6F9F-4C46-A71B-C7EB978E103C}
because another computer on the network has the same name. The server could not
start.
< End of report >
OTL logfile created on: 10/14/2010 3:09:15 PM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Glenn LoSasso\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 5.15 Gb Free Space | 5.52% Space Free | Partition Type: NTFS
Computer Name: LAPTOP | User Name: Glenn LoSasso | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
PRC - C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
MOD - C:\Program Files\AlienGUIse\wbhelp.dll (Stardock.Net, Inc)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (acssrv) – C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Driver Services (SafeList) ==========
DRV - (catchme) – C:\DOCUME~1\GLENNL~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (nhcDriverDevice) – C:\WINDOWS\system32\drivers\nhcDriver.sys (pBUS-167 Software - http://www.pbus-167.com)
DRV - (SandBox) – C:\WINDOWS\system32\drivers\SandBox.sys (Agnitum Ltd.)
DRV - (afw) – C:\WINDOWS\system32\drivers\afw.sys (Agnitum Ltd.)
DRV - (afwcore) – C:\WINDOWS\system32\drivers\afwcore.sys (Agnitum Ltd.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (DAdderFltr) – C:\WINDOWS\system32\drivers\dadder.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (vncdrv) – C:\WINDOWS\system32\drivers\vncdrv.sys (Microsoft Corporation)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
[2008/07/28 09:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions
[2008/07/28 09:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions\[removed]
[2008/04/29 11:56:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Firefox\Profiles\xw69a85n.default\extensions
O1 HOSTS File: ([2010/03/25 15:05:08 | 000,380,249 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13124 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1176123311500 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1 [removed] 4.2.2.2
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (c:\progra~1\agnitum\outpos~1\wl_hook.dll) - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
O20 - AppInit_DLLs: (c:\windows\system32\wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)
O24 - Desktop WallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/17 17:42:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell - "" = AutoRun
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (69819404975603712)
========== Files/Folders - Created Within 30 Days ==========
[2010/10/14 14:58:21 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2010/10/13 16:23:05 | 004,259,888 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\audiodriver.EXE
[2010/10/13 16:22:38 | 005,178,792 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\videodriver.EXE
[2010/10/13 14:08:26 | 002,944,016 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\chipset.exe
[2010/10/13 14:07:49 | 001,352,448 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\networkdriver.exe
[2010/10/13 08:03:10 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/10/13 08:03:09 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/10/13 08:02:46 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/10/05 08:45:57 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/10/05 08:45:53 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/10/05 08:42:27 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/10/05 08:40:53 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/14 15:11:15 | 000,442,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/14 15:11:15 | 000,071,910 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/14 15:07:00 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/14 15:05:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/14 15:05:34 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2010/10/14 14:58:21 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2010/10/14 14:55:21 | 000,003,643 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Desktop\scan.html
[2010/10/14 09:55:56 | 066,317,001 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/10/13 16:23:19 | 004,259,888 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\audiodriver.EXE
[2010/10/13 16:22:38 | 005,178,792 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\videodriver.EXE
[2010/10/13 14:22:17 | 000,000,799 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/10/13 14:08:38 | 002,944,016 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\chipset.exe
[2010/10/13 14:07:54 | 001,352,448 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\networkdriver.exe
[2010/10/13 09:52:42 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/10/13 09:28:46 | 000,138,848 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/13 09:21:42 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/18 12:23:26 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mfc42u.dll
[2010/09/18 12:23:26 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42u.dll
[2010/09/18 02:53:25 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mfc42.dll
[2010/09/18 02:53:25 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/09/18 02:53:25 | 000,954,368 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mfc40.dll
[2010/09/18 02:53:25 | 000,954,368 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2010/09/18 02:53:25 | 000,953,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mfc40u.dll
[2010/09/18 02:53:25 | 000,953,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/14 14:55:21 | 000,003,643 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Desktop\scan.html
[2010/10/05 08:47:00 | 000,002,137 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/12 17:03:36 | 000,082,568 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/04/02 11:26:02 | 000,000,120 | —- | C] () – C:\WINDOWS\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
[2009/02/05 20:07:40 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/11/11 08:22:31 | 000,001,400 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Application Data\default.cfg
[2008/07/23 12:50:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/07/23 12:46:38 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/07/10 08:53:59 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/10 08:53:59 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/10 08:53:59 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/03/17 14:17:32 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2008/01/03 12:54:19 | 000,000,136 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\fusioncache.dat
[2007/08/30 15:15:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/08/30 15:15:00 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/08/30 15:15:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/08/30 15:15:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/08/09 12:08:04 | 000,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/05/17 12:16:16 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/05/16 14:05:50 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/04/10 16:09:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/04/06 11:19:48 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2007/04/05 15:45:17 | 000,005,632 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/04/04 10:59:15 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/04/04 09:26:53 | 000,000,056 | —- | C] () – C:\WINDOWS\wb.ini
[2006/07/17 17:55:35 | 000,002,340 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/07/17 10:31:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/06/02 21:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56spn.dll
[2006/06/02 21:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56itl.dll
[2006/06/02 21:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56eng.dll
[2006/06/02 21:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56brz.dll
[2006/06/02 21:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56ger.dll
[2006/06/02 21:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56fra.dll
[2006/06/02 21:09:00 | 000,053,248 | —- | C] () – C:\WINDOWS\sm56jpn.dll
[2006/06/02 21:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56cht.dll
[2006/06/02 21:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56chs.dll
[2005/08/05 17:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[1996/04/03 15:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2010/09/09 08:01:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Agnitum
[2009/11/12 10:50:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/03/17 10:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2008/09/08 12:43:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CopyTransControlCenter
[2009/09/17 09:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/03/25 15:06:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/07/28 09:33:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/03/24 11:46:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/13 09:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/15 09:15:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/09 09:12:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/10/16 09:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Acreon
[2008/08/26 16:09:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Amazon
[2007/04/07 15:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyPod
[2008/09/08 13:03:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTrans
[2008/09/08 12:43:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransControlCenter
[2008/09/08 13:35:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransManager
[2009/09/17 09:12:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Leadertech
[2010/01/07 15:07:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Razer
[2010/10/14 10:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\runic games
[2008/09/08 12:20:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\SyncGuardian
[2007/11/08 16:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Thunderbird
[2008/07/28 09:33:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\TomTom
[2009/06/25 12:59:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WinPatrol
[2007/07/23 08:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WowAceUpdater
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/02/02 13:26:44 | 000,001,024 | —- | M] () – C:\.rnd
[2006/07/17 17:42:45 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/03/31 09:06:19 | 000,000,209 | —- | M] () – C:\Boot.bak
[2009/03/31 17:24:57 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/06/25 11:15:57 | 000,016,226 | —- | M] () – C:\ComboFix.txt
[2006/07/17 17:42:45 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/10/14 15:05:34 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2006/07/17 17:42:45 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/17 17:42:45 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/19 09:07:59 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/10/14 15:05:32 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/07/17 17:42:16 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/11/15 19:46:32 | 000,028,472 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2003/08/06 16:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware logo_slvr.jpg
[2003/08/06 16:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware_logo_slvr.jpg
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
[2006/04/06 11:00:20 | 000,000,138 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Alienware games download store.url
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/07/17 10:29:40 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/07/17 10:29:40 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/07/17 10:29:40 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/19 09:12:28 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/04/05 15:45:31 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/07/17 17:47:58 | 000,000,079 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/10/13 16:23:19 | 004,259,888 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\audiodriver.EXE
[2010/10/13 14:08:38 | 002,944,016 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\chipset.exe
[2010/10/13 14:07:54 | 001,352,448 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\networkdriver.exe
[2010/10/14 14:58:21 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2010/10/13 16:22:38 | 005,178,792 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Glenn LoSasso\Desktop\videodriver.EXE
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-13 13:21:57
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware_logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL Extras logfile created on: 10/14/2010 3:09:15 PM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Glenn LoSasso\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 5.15 Gb Free Space | 5.52% Space Free | Partition Type: NTFS
Computer Name: LAPTOP | User Name: Glenn LoSasso | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"135:TCP" = 135:TCP:*:Enabled:DCOM
"135:UDP" = 135:UDP:*:Enabled:DCOM2
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EagleSoft\Shared Files\esinetconnect.exe" = C:\Program Files\EagleSoft\Shared Files\esinetconnect.exe:*:Enabled:Patterson EagleSoft Internet Connection – (Patterson Dental Supply, Inc.)
"C:\Program Files\EagleSoft\Shared Files\ESTechUtil.exe" = C:\Program Files\EagleSoft\Shared Files\ESTechUtil.exe:*:Enabled:Patterson EagleSoft Technical Utility – (Patterson Dental Supply, Inc.)
"C:\Program Files\EagleSoft\Shared Files\EagleSoft.exe" = C:\Program Files\EagleSoft\Shared Files\EagleSoft.exe:*:Enabled:Patterson EagleSoft – (Patterson Dental Supply, Inc.)
"C:\Program Files\EagleSoft\Shared Files\techaid.exe" = C:\Program Files\EagleSoft\Shared Files\techaid.exe:*:Enabled:Patterson EagleSoft Technical Reference – ()
"C:\Program Files\EagleSoft\Shared Files\ESMessenger.exe" = C:\Program Files\EagleSoft\Shared Files\ESMessenger.exe:*:Enabled:Patterson EagleSoft Messenger Client – (Patterson Dental Supply, Inc.)
"C:\Program Files\EagleSoft\Shared Files\dbeng7.exe" = C:\Program Files\EagleSoft\Shared Files\dbeng7.exe:*:Enabled:Patterson EagleSoft ODBC Client – (Sybase, Inc.)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – ()
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – File not found
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – File not found
"C:\Program Files\Curse\CurseClient.exe" = C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client – File not found
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"{2A8E4833-F483-4074-B4DB-F295F7901A8D}" = MobileMe Control Panel
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon Camera WIA Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35260E0B-A8C2-4D25-97E2-448DE7275C85}" = Canon Camera WIA Driver
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{652C4ADF-0A29-4B02-9211-EE61675847DE}" = Canon Camera WIA Driver
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{72FA90DD-95D4-4B30-A6A4-9BCFFB4A1033}" = Nero 7 Essentials
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7E7658A2-CD3F-48A7-93EA-0882BCA4FD2A}" = LogMeIn
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{900A92BA-19EF-4A34-86CF-7B6C85BDD971}" = VC_MergeModuleToMSI
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9F7AF7CD-E3D0-4C68-A3BA-C76C359B3AA8}" = LightScribe 1.4.105.1
"{A0E27BA8-353A-4288-AB60-5DE8EDA18E16}" = Symantec Technical Support Web Controls
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B502B428-3386-40A9-98DB-079AAB72E64F}" = mEoU
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver
"{BBB8D142-6F80-42E1-9168-643A105DED1D}" = Patterson EagleSoft
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EB1B8449-CD8F-485B-ADB6-02FBCFE180D3}" = Razer DeathAdder™ Mouse
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"13860389BCE916343D6A5C65169C6F0C6BF6E3EA" = Windows Driver Package - Cypress (CyUsb) USB
"7BDD6421B73797179E9A97E5C7DE019FBC77147F" = Windows Driver Package - Razer (HidUsb) HIDClass (04/04/2009 1.0.5.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Agnitum Outpost Firewall_is1" = Outpost Firewall 2009
"AlienGUIse Theme Manager" = AlienGUIse Theme Manager
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AVG9Uninstall" = AVG Free 9.0
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"CopyPod Suite" = CopyPod Suite (remove only)
"CopyTrans Suite" = CopyTrans Suite Remove Only
"CSCLIB" = Canon Camera Support Core Library
"DA73216D935E3CBA996AFD6E6513ECC587E0C3C1" = Windows Driver Package - Razer (HidUsb) HIDClass (02/02/2007 1.0.5.0)
"EOS Utility" = Canon Utilities EOS Utility
"GoToAssist" = GoToAssist 8.0.0.480
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"InstallShield_{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon EOS Kiss_N REBEL_XT 350D WIA Driver
"InstallShield_{35260E0B-A8C2-4D25-97E2-448DE7275C85}" = Canon EOS-1D Mark II N WIA Driver
"InstallShield_{652C4ADF-0A29-4B02-9211-EE61675847DE}" = Canon EOS-1Ds Mark II WIA Driver
"InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notebook Hardware Control" = Notebook Hardware Control 2.0 Pre-Release-06
"NVIDIA Drivers" = NVIDIA Drivers
"ProInst" = Intel® PROSet/Wireless Software
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 12.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SMSERIAL" = Motorola SM56 Data Fax Modem
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"Theme Manager" = Theme Manager
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol 2009
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Move Media Player" = Move Media Player
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 228: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 240: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 412: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 424: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:24:50 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 436: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/14/2010 2:35:24 PM | Computer Name = LAPTOP | Source = MsiInstaller | ID = 10005
Description = Product: Apple Application Support – A later version of Apple Application
Support is already installed on this computer.
Error - 9/21/2010 3:24:14 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 388: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/21/2010 3:24:14 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 228: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/21/2010 3:24:14 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 240: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 9/21/2010 3:24:14 PM | Computer Name = LAPTOP | Source = Bonjour Service | ID = 100
Description = 412: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
[ System Events ]
Error - 10/13/2010 8:15:14 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
D4G2VP41 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C46-. The master browser is stopping or an election
is being forced.
Error - 10/13/2010 9:06:28 AM | Computer Name = LAPTOP | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{EE161A86-6F9F-4C46-A71B-C7EB978E103C}
because another computer on the network has the same name. The server could not
start.
Error - 10/13/2010 9:30:25 AM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep
Error - 10/13/2010 9:33:23 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
KARENMILLA that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C4. The master browser is stopping or an election is
being forced.
Error - 10/13/2010 9:39:10 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
D4G2VP41 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C46-. The master browser is stopping or an election
is being forced.
Error - 10/13/2010 9:57:22 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
KARENMILLA that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C4. The master browser is stopping or an election is
being forced.
Error - 10/13/2010 10:15:11 AM | Computer Name = LAPTOP | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
D4G2VP41 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{EE161A86-6F9F-4C46-. The master browser is stopping or an election
is being forced.
Error - 10/13/2010 10:43:15 AM | Computer Name = LAPTOP | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{EE161A86-6F9F-4C46-A71B-C7EB978E103C}
because another computer on the network has the same name. The server could not
start.
Error - 10/14/2010 3:06:39 PM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep
Error - 10/14/2010 3:13:29 PM | Computer Name = LAPTOP | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{EE161A86-6F9F-4C46-A71B-C7EB978E103C}
because another computer on the network has the same name. The server could not
start.
< End of report >