Hi! I've got an odd problem going on, and was informed that this section of the forums may be better able to assist. My original thread is here: click to view and goes into minute detail about the situation.
The relevant information is that I installed the retail version (CD-ROM) of Activision/Troika game Vampire the Masquerade: Bloodlines. I applied the official patch, downloaded through a rather well-known modding comunity, and installed it before actually playing the game. Also, during installation of the main part, I declined installing Direct X 9, as I was rather positive I had a more-recent version installed and these game discs were fairly old/outdated anyway. While playing the game for 6+ hours, I also had a download of a player-created mod (Clan Quest Mod) downloading. My internet's slow due to being rural broadband; the file itself was under 1gb in size.
After the dowload (performed through Firefox 29, Portable Edition) finished, my internet disconneted itself. It wasn't a normal disconnect like when my ISP has issues or the router hiccups. In this case, it went all the way back to the 'disconnected; nertworks available' animation and forced me to manually reconnect. This occurred several times, a few minutes apart, to the point I began to worry I'd somehow 'worn out' my network card.
There were some odd events in the event viewer, but none of which I could make heads or tails of. They just seemed kind of bothersome/worrisome to me. So, fearing I'd contracted a virus or malware, I updated and ran MBAM. In the process of scanning, it hung on a .dll (can't remember which) and the entire system became unusable. In a panic, I held down the power button to 'reset' the system.
Fifteen minutes or so later, I went to safe mode (as I feared a virus caused the hang) and ran MBAM that way. The scan said 8 were detected, but they were all Gimp extensions and google turned up nothing about the type of infection they were supposed to be so I ignored them. While I was there, I ran Defraggler, but it started hanging and I aborted, narrowed the file selection, and tried agian-- rise, repeat a few times.
I attempted to reboot my system, but it took ages and the desktop which loaded was totally glitched out. I couldn't use my mouse or do anything; it only parially loaded the general aesthetic of the dashboard before deciding it didn't feel like trying. The only option to shut it back down was to hold the power button again. The second attempt at rebooting was worse, and only turned up a black screen with the cursor in the middle.
Now, the only boot mode I can get into is safe boot-- thankfully the option with networking does work, as that's how I'm posting this right now. I've also noticed that, while my drive should only have ~24gb free space, here in safe mode it claims to have 47.7gb free space.
Thanks in advance, and I sure hope that we can figure out what's going on and how to fix my laptop! Also, my apologies if anything doesn't make sense; I'm literally falling asleep on myself right now, but wanted to get this posted before I left.
Below is the OTL readout:
OTL logfile created on: 8/8/2014 6:03:30 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Me\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.75 Gb Total Physical Memory | 2.12 Gb Available Physical Memory | 77.28% Memory free
5.75 Gb Paging File | 5.27 Gb Available in Paging File | 91.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.38 Gb Total Space | 47.74 Gb Free Space | 34.25% Space Free | Partition Type: NTFS
Drive D: | 9.67 Gb Total Space | 1.71 Gb Free Space | 17.72% Space Free | Partition Type: NTFS
Computer Name: SPIEGEL | User Name: Me | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/08/08 17:33:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Me\Desktop\OTL.exe
PRC - [2008/01/20 21:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2007/04/30 19:43:54 | 003,450,608 | ---- | M] (Stardock) -- C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
========== Modules (No Company Name) ==========
MOD - [2008/02/04 15:29:02 | 000,688,128 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
MOD - [2007/04/30 19:18:50 | 000,112,400 | ---- | M] () -- C:\Program Files\Stardock\ObjectDock\DockShellHook.dll
MOD - [2007/04/23 00:19:28 | 000,026,392 | ---- | M] () -- C:\Program Files\Stardock\ObjectDock\Docklets\Calendar\Calendar.dll
MOD - [2007/04/21 13:47:52 | 000,059,592 | ---- | M] () -- C:\Program Files\Stardock\ObjectDock\zlib.dll
MOD - [2007/04/19 14:23:48 | 000,095,944 | ---- | M] () -- C:\Program Files\Stardock\ObjectDock\CrashRpt.dll
MOD - [2005/10/07 15:05:32 | 000,125,440 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2002/11/19 14:11:40 | 000,139,264 | ---- | M] () -- C:\Program Files\Common Files\Stardock\ODimg.dll
MOD - [2002/03/13 19:46:32 | 000,118,784 | ---- | M] () -- C:\Program Files\Stardock\ObjectDock\ODimg.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/09/27 14:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008/08/24 02:46:25 | 000,049,664 | ---- | M] (GRISOFT, s.r.o.) [Auto | Stopped] -- C:\Program Files\Grisoft\AVG7\avgupsvc.exe -- (Avg7UpdSvc)
SRV - [2008/08/24 02:46:23 | 000,418,816 | ---- | M] (GRISOFT, s.r.o.) [Auto | Stopped] -- C:\Program Files\Grisoft\AVG7\avgamsvr.exe -- (Avg7Alrt)
SRV - [2008/08/24 02:46:23 | 000,192,512 | ---- | M] (GRISOFT, s.r.o.) [Auto | Stopped] -- C:\Program Files\Grisoft\AVG7\avgrssvc.exe -- (AvgCoreSvc)
SRV - [2008/04/28 00:26:44 | 000,599,344 | ---- | M] (Validity Sensors, Inc.) [Auto | Stopped] -- C:\Windows\System32\vfsFPService.exe -- (vfsFPService)
SRV - [2008/04/15 13:18:38 | 000,221,239 | ---- | M] (IDT, Inc.) [Auto | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_9a642328\stacsv.exe -- (STacSV)
SRV - [2008/03/26 17:26:56 | 000,341,328 | ---- | M] () [Auto | Stopped] -- C:\Windows\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/03/12 21:24:52 | 000,302,144 | ---- | M] (DigitalPersona, Inc.) [Auto | Stopped] -- C:\Program Files\DigitalPersona\Bin\DpHostW.exe -- (DpHost)
SRV - [2008/02/12 15:05:54 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_9a642328\AEstSrv.exe -- (AESTFilters)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/11 13:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Stopped] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\muvee Technologies\muvee autoProducer 6.1 -- (NTIDrvr)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2011/09/02 01:31:28 | 000,039,192 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2011/09/02 01:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2011/09/02 01:31:10 | 000,042,648 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LEqdUsb.sys -- (LEqdUsb)
DRV - [2011/09/02 01:31:10 | 000,012,184 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidEqd.sys -- (LHidEqd)
DRV - [2009/07/13 18:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2008/08/24 02:55:30 | 000,010,760 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgclean.sys -- (AvgClean)
DRV - [2008/08/24 02:55:26 | 000,026,952 | ---- | M] (GRISOFT, s.r.o.) [File_System | System | Stopped] -- C:\Windows\System32\drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2008/05/08 20:01:42 | 003,552,256 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008/04/28 04:26:42 | 000,014,352 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie)
DRV - [2008/04/28 00:27:10 | 000,040,752 | ---- | M] (Validity Sensors, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vfs101x.sys -- (vfs101x)
DRV - [2008/04/27 13:07:44 | 000,909,824 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008/04/15 13:19:54 | 000,378,368 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2008/04/11 12:55:04 | 000,084,240 | ---- | M] (JMicron Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\jmcr.sys -- (JMCR)
DRV - [2008/03/27 14:12:12 | 000,024,424 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hpdskflt.sys -- (hpdskflt)
DRV - [2008/03/27 14:11:34 | 000,034,664 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2008/02/29 15:39:54 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Users\Me\AppData\Local\Temp\ewdmaudn.sys -- (ewdmaudn)
DRV - [2008/02/14 09:56:02 | 000,118,784 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/01/24 08:23:12 | 000,052,736 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\enecir.sys -- (enecir)
DRV - [2008/01/07 18:54:50 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2007/06/18 19:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2006/11/02 02:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)
DRV - [2005/05/25 09:39:06 | 000,004,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\RMClock\RTCore32.sys -- (RTCore32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...avilion&pf=cnnb
IE - HKLM\..\SearchScopes,DefaultScope = {88C464C8-3E96-4A23-8D0A-E94467635565}
IE - HKLM\..\SearchScopes\{88C464C8-3E96-4A23-8D0A-E94467635565}: "URL" = http://search.yahoo....ing}&fr=hp-pvnb
IE - HKLM\..\SearchScopes\{EFD512E0-600A-48B5-BFAC-B970AD1E5D2A}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...avilion&pf=cnnb
IE - HKCU\..\SearchScopes,DefaultScope = {88C464C8-3E96-4A23-8D0A-E94467635565}
IE - HKCU\..\SearchScopes\{88C464C8-3E96-4A23-8D0A-E94467635565}: "URL" = http://search.yahoo....ing}&fr=hp-pvnb
IE - HKCU\..\SearchScopes\{EFD512E0-600A-48B5-BFAC-B970AD1E5D2A}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpl
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "The Free Dictionary"
FF - prefs.js..browser.search.selectedEngine: "The Free Dictionary"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: en-GB%40dictionaries.addons.mozilla.org:1.19.1
FF - prefs.js..extensions.enabledAddons: %7B46551EC9-40F0-4e47-8E18-8E5CF550CFB8%7D:1.4.3
FF - prefs.js..extensions.enabledAddons: %7B58c64034-c5f3-4179-85f5-81642f42b6d5%7D:2.22.1
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.8.33
FF - prefs.js..extensions.enabledAddons: %7B1dbc4a33-ea62-4330-966c-7bdad3455322%7D:1.0.6.10
FF - prefs.js..extensions.enabledAddons: %7Bdc572301-7619-498c-a57d-39143191b318%7D:0.4.1.4
FF - prefs.js..extensions.enabledAddons: %7BEDA7B1D7-F793-4e03-B074-E6F303317FB0%7D:1.2.7
FF - prefs.js..extensions.enabledAddons: %7Bad4ee9e5-49c7-4589-acf3-db9fa76a95c9%7D:2.2.1
FF - prefs.js..extensions.enabledAddons: %7Bcd617375-6743-4ee8-bac4-fbf10f35729e%7D:2.9.5
FF - prefs.js..extensions.enabledAddons: %7B0e91bc50-5f71-11e0-80e3-0800200c9a66%7D:0.2
FF - prefs.js..extensions.enabledAddons: ClassicThemeRestorer%40ArisT2Noia4dev:1.2.2
FF - prefs.js..extensions.enabledAddons: personasexpression%40eddiescorpse.private:2.1.3
FF - prefs.js..extensions.enabledAddons: personas%40christopher.beard:1.7.3
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.17
FF - prefs.js..extensions.enabledAddons: anticontainer%40downthemall.net:1.3
FF - prefs.js..extensions.enabledAddons: %7B0538E3E3-7E9B-4d49-8831-A227C80A7AD3%7D:2.2.4
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.15
FF - prefs.js..extensions.enabledAddons: ffe_ffix%40game-point.net:2.0.0
FF - prefs.js..extensions.enabledAddons: xkit%40studioxenix.com:7.4.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2008/06/12 10:06:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2014/07/21 16:10:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Extensions
[2014/08/07 15:06:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions
[2014/07/08 19:34:40 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2014/07/08 17:12:31 | 000,000,000 | ---D | M] (Remove It Permanently) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{1dbc4a33-ea62-4330-966c-7bdad3455322}
[2008/08/24 00:53:19 | 000,000,000 | ---D | M] (Abstract Classic) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{2fbc1200-ad13-11db-abbd-0800200c9a66}
[2014/07/08 17:11:47 | 000,000,000 | ---D | M] (Fingerfox (SE)) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{58c64034-c5f3-4179-85f5-81642f42b6d5}
[2009/04/02 02:10:04 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}(52)
[2014/07/08 17:11:19 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 19:31:20 | 000,098,595 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 18:08:16 | 000,344,276 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 18:07:25 | 000,458,672 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\CSTBB@NArisT2_Noia4dev.xpi
[2014/07/08 17:45:44 | 000,126,171 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 20:00:36 | 000,088,745 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 19:46:00 | 001,225,715 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 18:06:32 | 000,007,863 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 18:04:16 | 000,052,857 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/09 00:46:53 | 000,349,810 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 18:05:09 | 000,065,623 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 19:24:08 | 000,085,563 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 19:12:29 | 000,348,260 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 19:12:29 | 000,049,239 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 21:22:52 | 000,088,767 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\[email protected]
[2014/07/08 18:08:16 | 000,008,682 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{0e91bc50-5f71-11e0-80e3-0800200c9a66}.xpi
[2014/07/08 17:11:31 | 000,293,729 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2014/07/08 17:11:59 | 000,538,443 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2014/07/08 19:30:18 | 000,014,793 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{a7213cf2-fa1e-4373-88ff-255d0abd3020}.xpi
[2014/07/08 17:12:54 | 000,025,991 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{ad4ee9e5-49c7-4589-acf3-db9fa76a95c9}.xpi
[2014/07/08 18:08:16 | 000,065,849 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi
[2014/07/08 17:44:50 | 000,967,387 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014/07/08 17:12:49 | 000,788,466 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
[2014/07/08 19:31:20 | 000,731,942 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2014/07/08 20:00:36 | 000,287,566 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2014/07/08 17:12:53 | 000,091,556 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}.xpi
[2008/08/24 00:53:19 | 001,148,079 | ---- | M] () (No name found) -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\extensions\{2fbc1200-ad13-11db-abbd-0800200c9a66}\chrome\tmp.xpi
[2008/09/12 04:21:23 | 000,000,437 | ---- | M] () -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\searchplugins\dream-journal.xml
[2014/07/08 18:04:16 | 000,000,364 | ---- | M] () -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\searchplugins\duckduckgo.xml
[2010/10/21 04:48:36 | 000,002,043 | ---- | M] () -- C:\Users\Me\AppData\Roaming\Mozilla\Firefox\Profiles\xue1rgkd.default\searchplugins\the-free-dictionary.xml
[2014/07/08 17:09:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/07/08 17:09:24 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2014/07/11 17:40:02 | 000,000,081 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 download.skype.com
O1 - Hosts: 127.0.0.1 ui.skype.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [AVG7_CC] C:\Program Files\Grisoft\AVG7\avgcc.exe (GRISOFT, s.r.o.)
O4 - HKLM..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Aim6] File not found
O4 - Startup: C:\Users\Me\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bit...m/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 10.10.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{03F18E8A-CA29-4E65-A728-D0BB73517000}: DhcpNameServer = 100.100.0.205
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8167A2A5-D88B-46DC-8378-09EFF5DB2CA1}: DhcpNameServer = 208.67.222.222 208.67.220.220 10.10.10.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgwlntf: DllName - (avgwlntf.dll) - C:\Windows\System32\avgwlntf.dll (GRISOFT, s.r.o.)
O24 - Desktop WallPaper: C:\Users\Me\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Me\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/12 08:36:39 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/08/08 17:33:20 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Me\Desktop\OTL.exe
[2014/08/08 11:56:15 | 000,000,000 | ---D | C] -- C:\Users\Me\Desktop\Saved
[2014/08/07 16:48:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vampire - The Masquerade Bloodlines
[2014/08/07 16:30:50 | 000,000,000 | ---D | C] -- C:\Program Files\Activision
[2014/08/05 04:53:39 | 000,000,000 | ---D | C] -- C:\Users\Me\Documents\GoogleChromePortableBeta
[2014/07/11 17:30:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014/07/11 17:30:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/08/08 17:33:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Me\Desktop\OTL.exe
[2014/08/08 16:58:48 | 000,001,356 | ---- | M] () -- C:\Users\Me\AppData\Local\d3d9caps.dat
[2014/08/08 12:43:36 | 000,057,344 | ---- | M] () -- C:\Users\Me\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/08/08 11:46:07 | 000,594,698 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/08/08 11:46:06 | 000,100,766 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/08/08 11:40:35 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2014/08/08 11:40:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/08/08 11:37:43 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/08/08 11:37:42 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/08/08 11:37:39 | 000,000,412 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{D77409A7-A3A2-4033-9A35-852519C12020}.job
[2014/08/07 17:15:48 | 000,001,725 | ---- | M] () -- C:\Users\Public\Desktop\Vampire - The Masquerade Bloodlines.lnk
[2014/08/07 16:48:19 | 000,000,285 | ---- | M] () -- C:\Windows\vtmb.ini
[2014/08/06 14:29:08 | 000,005,813 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2014/07/31 04:20:20 | 000,023,696 | ---- | M] () -- C:\Users\Me\.recently-used.xbel
[2014/07/11 23:22:36 | 000,043,520 | ---- | M] () -- C:\Windows\System32\CmdLineExt03.dll
[2014/07/11 17:05:01 | 000,786,432 | ---- | M] () -- C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2014/07/11 17:05:01 | 000,196,608 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2014/07/11 17:05:01 | 000,065,536 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/08/07 16:48:22 | 000,001,725 | ---- | C] () -- C:\Users\Public\Desktop\Vampire - The Masquerade Bloodlines.lnk
[2014/08/07 16:48:19 | 000,000,285 | ---- | C] () -- C:\Windows\vtmb.ini
[2014/07/31 04:20:20 | 000,023,696 | ---- | C] () -- C:\Users\Me\.recently-used.xbel
[2014/07/11 17:04:50 | 000,196,608 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2014/07/11 17:04:50 | 000,065,536 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2014/07/11 17:04:49 | 000,786,432 | ---- | C] () -- C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2013/08/08 01:53:32 | 000,000,000 | ---- | C] () -- C:\Users\Me\nslookup
[2009/07/12 05:29:44 | 000,000,000 | ---- | C] () -- C:\Users\Me\.gtk-bookmarks
[2008/12/07 14:10:30 | 000,001,356 | ---- | C] () -- C:\Users\Me\AppData\Local\d3d9caps.dat
[2008/09/23 08:35:21 | 000,000,000 | ---- | C] () -- C:\Users\Me\AppData\Roaming\wklnhst.dat
[2008/08/30 05:02:45 | 000,031,007 | ---- | C] () -- C:\Users\Me\AppData\Roaming\UserTile.png
[2008/08/24 05:38:52 | 000,057,344 | ---- | C] () -- C:\Users\Me\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2008/01/20 21:23:46 | 011,580,416 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2008/01/20 21:24:24 | 000,614,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/01/20 21:24:03 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/02/09 01:14:23 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\.purple
[2008/08/23 23:51:53 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\acccore
[2014/03/27 19:07:59 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Atari
[2013/07/30 04:04:05 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Audacity
[2013/05/03 18:33:42 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\AVG7
[2008/08/22 20:39:31 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\DigitalPersona
[2009/09/27 03:51:42 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\FileZilla
[2008/08/30 00:59:48 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Fingerfox (SE)
[2009/01/19 17:57:32 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\funkitron
[2014/07/31 04:20:20 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\gtk-2.0
[2009/01/21 08:47:39 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\iWin
[2008/09/21 13:46:40 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Leadertech
[2009/01/21 13:30:54 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Legends of pirates
[2014/05/02 20:16:12 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Moonchild Productions
[2008/08/26 02:45:54 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Mp3tag
[2009/12/28 12:24:18 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\muvee Technologies
[2008/08/30 05:02:45 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\PeerNetworking
[2008/09/04 11:36:42 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\PlayFirst
[2013/11/06 05:00:24 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\QuickScan
[2008/08/28 05:32:57 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Super-Cow
[2008/09/01 14:09:01 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Tenebril
[2012/09/29 18:47:43 | 000,000,000 | ---D | M] -- C:\Users\Me\AppData\Roaming\Trillian
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 64 bytes -> C:\Users\Me\Documents\Souleater's Remorse.wav:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Me\Documents\Once Upon a December.mp3:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Me\Documents\Cowboy Bebop - Bang Bang.mpg:TOC.WMV
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:206E2596
< End of report >