This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is flashing on and off, stalling, and won't allow a complete scan using Microsoft Security Essentials. OTL logs below:


OTL logfile created on: 3/7/2011 12:54:29 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Glenn LoSasso\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 6.00 Gb Free Space | 6.44% Space Free | Partition Type: NTFS

Computer Name: LAPTOP | User Name: Glenn LoSasso | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
PRC - C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
MOD - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
MOD - C:\Program Files\AlienGUIse\wbhelp.dll (Stardock.Net, Inc)


========== Win32 Services (SafeList) ==========

SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (acssrv) – C:\Program Files\Agnitum\Outpost Firewall\acs.exe (Agnitum Ltd.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (MpKsl9a809de3) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AE1F7106-71EE-4CEC-BDA0-108CA634945A}\MpKsl9a809de3.sys (Microsoft Corporation)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (nhcDriverDevice) – C:\WINDOWS\system32\drivers\nhcDriver.sys (pBUS-167 Software - http://www.pbus-167.com)
DRV - (SandBox) – C:\WINDOWS\system32\drivers\SandBox.sys (Agnitum Ltd.)
DRV - (afw) – C:\WINDOWS\system32\drivers\afw.sys (Agnitum Ltd.)
DRV - (afwcore) – C:\WINDOWS\system32\drivers\afwcore.sys (Agnitum Ltd.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (DAdderFltr) – C:\WINDOWS\system32\drivers\dadder.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (vncdrv) – C:\WINDOWS\system32\drivers\vncdrv.sys (Microsoft Corporation)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"


[2008/07/28 08:33:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions
[2008/07/28 08:33:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Extensions\[removed]
[2008/04/29 10:56:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Glenn LoSasso\Application Data\Mozilla\Firefox\Profiles\xw69a85n.default\extensions

O1 HOSTS File: ([2010/03/25 14:05:08 | 000,380,249 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13124 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1176123311500 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - AppInit_DLLs: (c:\progra~1\agnitum\outpos~1\wl_hook.dll) - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
O20 - AppInit_DLLs: (c:\windows\system32\wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)
O24 - Desktop WallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/17 16:42:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell - "" = AutoRun
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{22a6a234-9c6e-11de-9699-00030d4fc396}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (69819404975603712)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/07 12:53:16 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2011/03/07 11:07:12 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2011/02/15 09:21:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/02/15 09:19:47 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/02/15 09:19:43 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/02/15 09:11:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/02/15 09:11:20 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/02/10 10:57:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Glenn LoSasso\Desktop\lloydpick-gathererdb_wowhead-b997b1f
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/07 13:06:01 | 000,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-788183689-2980432082-2600853406-1005UA.job
[2011/03/07 12:52:36 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe
[2011/03/07 12:48:35 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/03/07 12:44:44 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/07 12:43:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/07 12:43:10 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2011/03/07 10:06:03 | 000,000,958 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-788183689-2980432082-2600853406-1005Core.job
[2011/03/02 15:24:24 | 000,000,799 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2011/02/15 09:21:07 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/15 08:30:49 | 000,442,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/15 08:30:49 | 000,071,910 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/14 08:06:50 | 000,002,344 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Desktop\Google Chrome.lnk
[2011/02/14 08:06:50 | 000,002,322 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/02/09 13:21:52 | 000,138,848 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/09 13:04:56 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/07 12:43:10 | 2145,570,816 | -HS- | C] () – C:\hiberfil.sys
[2011/02/15 09:21:07 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/20 13:49:48 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\sysogg.dll
[2010/12/20 13:47:46 | 000,233,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2010/07/12 16:03:36 | 000,082,568 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/01/11 09:01:16 | 000,696,832 | —- | C] () – C:\WINDOWS\is-P8SGB.exe
[2010/01/04 09:00:54 | 000,696,832 | —- | C] () – C:\WINDOWS\is-4QG3R.exe
[2009/09/15 08:54:19 | 000,024,048 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/04/02 10:26:02 | 000,000,120 | —- | C] () – C:\WINDOWS\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
[2009/04/02 09:11:59 | 000,002,560 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2009/02/05 19:07:40 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/11/11 07:22:31 | 000,001,400 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Application Data\default.cfg
[2008/07/23 11:50:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/07/23 11:46:38 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/07/10 07:53:59 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/10 07:53:59 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/10 07:53:59 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/03/17 13:17:32 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2008/01/03 11:54:19 | 000,000,136 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\fusioncache.dat
[2007/12/14 11:32:52 | 000,012,632 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2007/11/08 15:05:18 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/08/30 14:15:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/08/30 14:15:00 | 001,626,112 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2007/08/30 14:15:00 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/08/30 14:15:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2007/08/30 14:15:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/08/30 14:15:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/08/30 14:15:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2007/08/30 14:15:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2007/08/09 11:08:04 | 000,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/05/17 11:16:16 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/05/16 13:05:50 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/04/10 15:09:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/04/10 08:27:03 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2007/04/06 10:19:48 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2007/04/05 14:45:17 | 000,011,264 | —- | C] () – C:\Documents and Settings\Glenn LoSasso\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/04/04 09:59:15 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/04/04 08:26:53 | 000,000,056 | —- | C] () – C:\WINDOWS\wb.ini
[2006/07/17 16:55:35 | 000,002,340 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/07/17 16:46:17 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/07/17 16:38:34 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/07/17 09:31:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/07/17 09:30:20 | 000,138,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56spn.dll
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56itl.dll
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56eng.dll
[2006/06/02 20:09:00 | 000,069,632 | —- | C] () – C:\WINDOWS\sm56brz.dll
[2006/06/02 20:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56ger.dll
[2006/06/02 20:09:00 | 000,061,440 | —- | C] () – C:\WINDOWS\sm56fra.dll
[2006/06/02 20:09:00 | 000,053,248 | —- | C] () – C:\WINDOWS\sm56jpn.dll
[2006/06/02 20:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56cht.dll
[2006/06/02 20:09:00 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56chs.dll
[2005/08/05 16:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/08/10 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 07:00:00 | 000,442,140 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 07:00:00 | 000,071,910 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/10 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/02/07 09:29:46 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/02/07 09:27:14 | 000,004,742 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[1996/04/03 14:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010/09/09 07:01:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Agnitum
[2010/10/20 09:57:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/20 09:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/03/17 09:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/10/20 09:12:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/09/08 11:43:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CopyTransControlCenter
[2011/03/07 11:05:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kJbLe06301
[2010/10/20 09:04:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/09/17 08:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/03/25 14:06:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/07/28 08:33:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/03/24 10:46:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/13 08:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/15 08:15:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/09 08:12:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/10/16 08:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Acreon
[2008/08/26 15:09:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Amazon
[2010/10/20 09:12:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\AVG10
[2007/04/07 14:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyPod
[2008/09/08 12:03:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTrans
[2008/09/08 11:43:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransControlCenter
[2008/09/08 12:35:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\CopyTransManager
[2009/09/17 08:12:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Leadertech
[2011/01/10 12:08:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Notepad++
[2010/01/07 14:07:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Razer
[2010/10/14 09:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\runic games
[2008/09/08 11:20:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\SyncGuardian
[2007/11/08 15:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\Thunderbird
[2008/07/28 08:33:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\TomTom
[2009/06/25 11:59:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WinPatrol
[2007/07/23 07:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Glenn LoSasso\Application Data\WowAceUpdater
[2011/03/07 12:48:35 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/02/02 12:26:44 | 000,001,024 | —- | M] () – C:\.rnd
[2006/07/17 16:42:45 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/03/31 08:06:19 | 000,000,209 | —- | M] () – C:\Boot.bak
[2009/03/31 16:24:57 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/06/25 10:15:57 | 000,016,226 | —- | M] () – C:\ComboFix.txt
[2006/07/17 16:42:45 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/03/07 12:43:10 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2006/07/17 16:42:45 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/17 16:42:45 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/19 08:07:59 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/07 12:43:05 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/07/17 16:42:16 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/11/15 18:46:32 | 000,028,472 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >
[2003/08/06 15:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware logo_slvr.jpg
[2003/08/06 15:08:19 | 000,081,676 | —- | M] () – C:\WINDOWS\alienware_logo_slvr.jpg
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2006/04/06 10:00:20 | 000,000,138 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Alienware games download store.url

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/07/17 09:29:40 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/07/17 09:29:40 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/07/17 09:29:40 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/19 08:12:28 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/04/05 14:45:31 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/07/17 16:47:58 | 000,000,079 | —- | M] () – C:\Documents and Settings\Glenn LoSasso\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/03/07 12:52:36 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Glenn LoSasso\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-09 18:05:38

========== Alternate Data Streams ==========

@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware_logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 3552 bytes -> C:\WINDOWS\alienware logo_slvr.jpg:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
Hi glosasso,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Nothing is jumping out at me as bad in your log.

Will your Malwarebytes' run?

Is there anything more you can tell me about your situation?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI