glosasso
Topic Starter
My computer is flashing on and off, stalling, and won't allow a complete scan using Microsoft Security Essentials. OTL logs below:
OTL logfile created on: 3/7/2011 12:54:29 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Glenn LoSasso\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 6.00 Gb Free Space | 6.44% Space Free | Partition Type: NTFS
Computer Name: LAPTOP | User Name: Glenn LoSasso | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
PRC - C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
MOD - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
MOD - C:\Program Files\AlienGUIse\wbhelp.dll (Stardock.Net, Inc)
========== Win32 Services (SafeList) ==========
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (acssrv) – C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Driver Services (SafeList) ==========
DRV - (MpKsl9a809de3) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AE1F7106-71EE-4CEC-BDA0-108CA634945A}\MpKsl9a809de3.sys (Microsoft Corporation)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (nhcDriverDevice) – C:\WINDOWS\system32\drivers\nhcDriver.sys (pBUS-167 Software - http://www.pbus-167.com)
DRV - (SandBox) – C:\WINDOWS\system32\drivers\SandBox.sys (Agnitum Ltd.)
DRV - (afw) – C:\WINDOWS\system32\drivers\afw.sys (Agnitum Ltd.)
DRV - (afwcore) – C:\WINDOWS\system32\drivers\afwcore.sys (Agnitum Ltd.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (DAdderFltr) – C:\WINDOWS\system32\drivers\dadder.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (vncdrv) – C:\WINDOWS\system32\drivers\vncdrv.sys (Microsoft Corporation)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
[2008/07/28 08:33:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions
[2008/07/28 08:33:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions\[removed]
[2008/04/29 10:56:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Firefox\Profiles\xw69a85n.default\extensions
O1 HOSTS File: ([2010/03/25 14:05:08 | 000,380,249 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13124 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1176123311500 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - AppInit_DLLs: (c:\progra~1\agnitum\outpos~1\wl_hook.dll) - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
O20 - AppInit_DLLs: (c:\windows\system32\wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)
O24 - Desktop WallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/17 16:42:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell - "" = AutoRun
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (69819404975603712)
========== Files/Folders - Created Within 30 Days ==========
[2011/03/07 12:53:16 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2011/03/07 11:07:12 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2011/02/15 09:21:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/02/15 09:19:47 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/02/15 09:19:43 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/02/15 09:11:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/02/15 09:11:20 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/02/10 10:57:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Glenn LoSasso\Desktop\lloydpick-gathererdb_wowhead-b997b1f
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/03/07 13:06:01 | 000,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-788183689-2980432082-2600853406-1005UA.job
[2011/03/07 12:52:36 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2011/03/07 12:48:35 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/03/07 12:44:44 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/07 12:43:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/07 12:43:10 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2011/03/07 10:06:03 | 000,000,958 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-788183689-2980432082-2600853406-1005Core.job
[2011/03/02 15:24:24 | 000,000,799 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2011/02/15 09:21:07 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/15 08:30:49 | 000,442,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/15 08:30:49 | 000,071,910 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/14 08:06:50 | 000,002,344 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Desktop\Google Chrome.lnk
[2011/02/14 08:06:50 | 000,002,322 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/02/09 13:21:52 | 000,138,848 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/09 13:04:56 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/03/07 12:43:10 | 2145,570,816 | -HS- | C] () – C:\hiberfil.sys
[2011/02/15 09:21:07 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/20 13:49:48 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\sysogg.dll
[2010/12/20 13:47:46 | 000,233,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2010/07/12 16:03:36 | 000,082,568 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/01/11 09:01:16 | 000,696,832 | —- | C] () – C:\WINDOWS\is-P8SGB.exe
[2010/01/04 09:00:54 | 000,696,832 | —- | C] () – C:\WINDOWS\is-4QG3R.exe
[2009/09/15 08:54:19 | 000,024,048 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/04/02 10:26:02 | 000,000,120 | —- | C] () – C:\WINDOWS\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
[2009/04/02 09:11:59 | 000,002,560 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2009/02/05 19:07:40 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/11/11 07:22:31 | 000,001,400 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Application Data\default.cfg
[2008/07/23 11:50:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/07/23 11:46:38 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/07/10 07:53:59 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/10 07:53:59 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/10 07:53:59 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/03/17 13:17:32 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2008/01/03 11:54:19 | 000,000,136 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\fusioncache.dat
[2007/12/14 11:32:52 | 000,012,632 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2007/11/08 15:05:18 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/08/30 14:15:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/08/30 14:15:00 | 001,626,112 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2007/08/30 14:15:00 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/08/30 14:15:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2007/08/30 14:15:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/08/30 14:15:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/08/30 14:15:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2007/08/30 14:15:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2007/08/09 11:08:04 | 000,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/05/17 11:16:16 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/05/16 13:05:50 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/04/10 15:09:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/04/10 08:27:03 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2007/04/06 10:19:48 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2007/04/05 14:45:17 | 000,011,264 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/04/04 09:59:15 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/04/04 08:26:53 | 000,000,056 | —- | C] () – C:\WINDOWS\wb.ini
[2006/07/17 16:55:35 | 000,002,340 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/07/17 16:46:17 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/07/17 16:38:34 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/07/17 09:31:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/07/17 09:30:20 | 000,138,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56spn.dll
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56itl.dll
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56eng.dll
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56brz.dll
[2006/06/02 20:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56ger.dll
[2006/06/02 20:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56fra.dll
[2006/06/02 20:09:00 | 000,053,248 | —- | C] () – C:\WINDOWS\sm56jpn.dll
[2006/06/02 20:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56cht.dll
[2006/06/02 20:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56chs.dll
[2005/08/05 16:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/08/10 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 07:00:00 | 000,442,140 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 07:00:00 | 000,071,910 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/10 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/02/07 09:29:46 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/02/07 09:27:14 | 000,004,742 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[1996/04/03 14:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2010/09/09 07:01:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Agnitum
[2010/10/20 09:57:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/20 09:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/03/17 09:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/10/20 09:12:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/09/08 11:43:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CopyTransControlCenter
[2011/03/07 11:05:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kJbLe06301
[2010/10/20 09:04:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/09/17 08:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/03/25 14:06:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/07/28 08:33:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/03/24 10:46:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/13 08:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/15 08:15:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/09 08:12:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/10/16 08:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Acreon
[2008/08/26 15:09:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Amazon
[2010/10/20 09:12:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\AVG10
[2007/04/07 14:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyPod
[2008/09/08 12:03:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTrans
[2008/09/08 11:43:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransControlCenter
[2008/09/08 12:35:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransManager
[2009/09/17 08:12:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Leadertech
[2011/01/10 12:08:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Notepad++
[2010/01/07 14:07:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Razer
[2010/10/14 09:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\runic games
[2008/09/08 11:20:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\SyncGuardian
[2007/11/08 15:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Thunderbird
[2008/07/28 08:33:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\TomTom
[2009/06/25 11:59:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WinPatrol
[2007/07/23 07:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WowAceUpdater
[2011/03/07 12:48:35 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/02/02 12:26:44 | 000,001,024 | —- | M] () – C:\.rnd
[2006/07/17 16:42:45 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/03/31 08:06:19 | 000,000,209 | —- | M] () – C:\Boot.bak
[2009/03/31 16:24:57 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/06/25 10:15:57 | 000,016,226 | —- | M] () – C:\ComboFix.txt
[2006/07/17 16:42:45 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/03/07 12:43:10 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2006/07/17 16:42:45 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/17 16:42:45 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/19 08:07:59 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/07 12:43:05 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/07/17 16:42:16 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/11/15 18:46:32 | 000,028,472 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2003/08/06 15:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware logo_slvr.jpg
[2003/08/06 15:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware_logo_slvr.jpg
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
[2006/04/06 10:00:20 | 000,000,138 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Alienware games download store.url
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/07/17 09:29:40 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/07/17 09:29:40 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/07/17 09:29:40 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/19 08:12:28 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/04/05 14:45:31 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/07/17 16:47:58 | 000,000,079 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/03/07 12:52:36 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-09 18:05:38
========== Alternate Data Streams ==========
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware_logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL logfile created on: 3/7/2011 12:54:29 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Glenn LoSasso\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 6.00 Gb Free Space | 6.44% Space Free | Partition Type: NTFS
Computer Name: LAPTOP | User Name: Glenn LoSasso | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
PRC - C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
MOD - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
MOD - C:\Program Files\AlienGUIse\wbhelp.dll (Stardock.Net, Inc)
========== Win32 Services (SafeList) ==========
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (acssrv) – C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Driver Services (SafeList) ==========
DRV - (MpKsl9a809de3) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AE1F7106-71EE-4CEC-BDA0-108CA634945A}\MpKsl9a809de3.sys (Microsoft Corporation)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (nhcDriverDevice) – C:\WINDOWS\system32\drivers\nhcDriver.sys (pBUS-167 Software - http://www.pbus-167.com)
DRV - (SandBox) – C:\WINDOWS\system32\drivers\SandBox.sys (Agnitum Ltd.)
DRV - (afw) – C:\WINDOWS\system32\drivers\afw.sys (Agnitum Ltd.)
DRV - (afwcore) – C:\WINDOWS\system32\drivers\afwcore.sys (Agnitum Ltd.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (DAdderFltr) – C:\WINDOWS\system32\drivers\dadder.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (vncdrv) – C:\WINDOWS\system32\drivers\vncdrv.sys (Microsoft Corporation)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
[2008/07/28 08:33:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions
[2008/07/28 08:33:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions\[removed]
[2008/04/29 10:56:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Firefox\Profiles\xw69a85n.default\extensions
O1 HOSTS File: ([2010/03/25 14:05:08 | 000,380,249 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13124 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1176123311500 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - AppInit_DLLs: (c:\progra~1\agnitum\outpos~1\wl_hook.dll) - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
O20 - AppInit_DLLs: (c:\windows\system32\wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)
O24 - Desktop WallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/17 16:42:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell - "" = AutoRun
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (69819404975603712)
========== Files/Folders - Created Within 30 Days ==========
[2011/03/07 12:53:16 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2011/03/07 11:07:12 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2011/02/15 09:21:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/02/15 09:19:47 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/02/15 09:19:43 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/02/15 09:11:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/02/15 09:11:20 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/02/10 10:57:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Glenn LoSasso\Desktop\lloydpick-gathererdb_wowhead-b997b1f
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/03/07 13:06:01 | 000,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-788183689-2980432082-2600853406-1005UA.job
[2011/03/07 12:52:36 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2011/03/07 12:48:35 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/03/07 12:44:44 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/07 12:43:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/07 12:43:10 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2011/03/07 10:06:03 | 000,000,958 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-788183689-2980432082-2600853406-1005Core.job
[2011/03/02 15:24:24 | 000,000,799 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2011/02/15 09:21:07 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/15 08:30:49 | 000,442,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/15 08:30:49 | 000,071,910 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/14 08:06:50 | 000,002,344 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Desktop\Google Chrome.lnk
[2011/02/14 08:06:50 | 000,002,322 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/02/09 13:21:52 | 000,138,848 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/09 13:04:56 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/03/07 12:43:10 | 2145,570,816 | -HS- | C] () – C:\hiberfil.sys
[2011/02/15 09:21:07 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/20 13:49:48 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\sysogg.dll
[2010/12/20 13:47:46 | 000,233,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2010/07/12 16:03:36 | 000,082,568 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/01/11 09:01:16 | 000,696,832 | —- | C] () – C:\WINDOWS\is-P8SGB.exe
[2010/01/04 09:00:54 | 000,696,832 | —- | C] () – C:\WINDOWS\is-4QG3R.exe
[2009/09/15 08:54:19 | 000,024,048 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/04/02 10:26:02 | 000,000,120 | —- | C] () – C:\WINDOWS\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
[2009/04/02 09:11:59 | 000,002,560 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2009/02/05 19:07:40 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/11/11 07:22:31 | 000,001,400 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Application Data\default.cfg
[2008/07/23 11:50:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/07/23 11:46:38 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/07/10 07:53:59 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/10 07:53:59 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/10 07:53:59 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/03/17 13:17:32 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2008/01/03 11:54:19 | 000,000,136 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\fusioncache.dat
[2007/12/14 11:32:52 | 000,012,632 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2007/11/08 15:05:18 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/08/30 14:15:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/08/30 14:15:00 | 001,626,112 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2007/08/30 14:15:00 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/08/30 14:15:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2007/08/30 14:15:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/08/30 14:15:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/08/30 14:15:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2007/08/30 14:15:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2007/08/09 11:08:04 | 000,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/05/17 11:16:16 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/05/16 13:05:50 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/04/10 15:09:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/04/10 08:27:03 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2007/04/06 10:19:48 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2007/04/05 14:45:17 | 000,011,264 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/04/04 09:59:15 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/04/04 08:26:53 | 000,000,056 | —- | C] () – C:\WINDOWS\wb.ini
[2006/07/17 16:55:35 | 000,002,340 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/07/17 16:46:17 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/07/17 16:38:34 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/07/17 09:31:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/07/17 09:30:20 | 000,138,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56spn.dll
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56itl.dll
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56eng.dll
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56brz.dll
[2006/06/02 20:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56ger.dll
[2006/06/02 20:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56fra.dll
[2006/06/02 20:09:00 | 000,053,248 | —- | C] () – C:\WINDOWS\sm56jpn.dll
[2006/06/02 20:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56cht.dll
[2006/06/02 20:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56chs.dll
[2005/08/05 16:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/08/10 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 07:00:00 | 000,442,140 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 07:00:00 | 000,071,910 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/10 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/02/07 09:29:46 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/02/07 09:27:14 | 000,004,742 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[1996/04/03 14:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2010/09/09 07:01:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Agnitum
[2010/10/20 09:57:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/20 09:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/03/17 09:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/10/20 09:12:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/09/08 11:43:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CopyTransControlCenter
[2011/03/07 11:05:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kJbLe06301
[2010/10/20 09:04:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/09/17 08:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/03/25 14:06:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/07/28 08:33:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/03/24 10:46:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/13 08:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/15 08:15:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/09 08:12:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/10/16 08:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Acreon
[2008/08/26 15:09:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Amazon
[2010/10/20 09:12:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\AVG10
[2007/04/07 14:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyPod
[2008/09/08 12:03:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTrans
[2008/09/08 11:43:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransControlCenter
[2008/09/08 12:35:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransManager
[2009/09/17 08:12:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Leadertech
[2011/01/10 12:08:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Notepad++
[2010/01/07 14:07:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Razer
[2010/10/14 09:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\runic games
[2008/09/08 11:20:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\SyncGuardian
[2007/11/08 15:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Thunderbird
[2008/07/28 08:33:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\TomTom
[2009/06/25 11:59:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WinPatrol
[2007/07/23 07:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WowAceUpdater
[2011/03/07 12:48:35 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/02/02 12:26:44 | 000,001,024 | —- | M] () – C:\.rnd
[2006/07/17 16:42:45 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/03/31 08:06:19 | 000,000,209 | —- | M] () – C:\Boot.bak
[2009/03/31 16:24:57 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/06/25 10:15:57 | 000,016,226 | —- | M] () – C:\ComboFix.txt
[2006/07/17 16:42:45 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/03/07 12:43:10 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2006/07/17 16:42:45 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/17 16:42:45 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/19 08:07:59 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/07 12:43:05 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/07/17 16:42:16 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/11/15 18:46:32 | 000,028,472 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2003/08/06 15:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware logo_slvr.jpg
[2003/08/06 15:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware_logo_slvr.jpg
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
[2006/04/06 10:00:20 | 000,000,138 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Alienware games download store.url
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/07/17 09:29:40 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/07/17 09:29:40 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/07/17 09:29:40 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/19 08:12:28 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/04/05 14:45:31 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/07/17 16:47:58 | 000,000,079 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/03/07 12:52:36 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-09 18:05:38
========== Alternate Data Streams ==========
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware_logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >