This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow computer in different way - TERRY

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is running slow again. I takes forever to open a website. A screen will just go gray and you can't do anything with it until it decides to go blue again.

OTL logfile created on: 12/30/2012 11:31:12 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Patty\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 63.52% Memory free
5.93 Gb Paging File | 4.13 Gb Available in Paging File | 69.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297.99 Gb Total Space | 182.21 Gb Free Space | 61.15% Space Free | Partition Type: NTFS

Computer Name: PATTI-PC | User Name: Patty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
PRC - [2012/12/11 17:26:19 | 001,807,800 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
PRC - [2012/09/29 18:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () – C:\Program Files\Macrium\Reflect\ReflectService.exe
PRC - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/12 16:19:44 | 000,947,176 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/13 19:17:11 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) – C:\Program Files\ShadowExplorer\sesvc.exe
PRC - [2010/11/20 07:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe


========== Modules (No Company Name) ==========

MOD - [2012/12/11 17:26:17 | 014,586,296 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_135.dll
MOD - [2012/07/13 19:17:14 | 002,003,424 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/03/16 23:11:16 | 004,297,568 | —- | M] () – C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 14:45:26 | 008,801,120 | —- | M] () – C:\Program Files\Microsoft Office2010\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV - [2012/12/11 17:26:22 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () [Auto | Running] – C:\Program Files\Macrium\Reflect\ReflectService.exe – (ReflectService.exe)
SRV - [2012/09/20 13:28:48 | 030,785,672 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Office2010\Office14\GROOVE.EXE – (Microsoft SharePoint Workspace Audit Service)
SRV - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 19:17:12 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/02/10 23:45:21 | 001,343,400 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) [Auto | Running] – C:\Program Files\ShadowExplorer\sesvc.exe – (sesvc)
SRV - [2009/07/13 20:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/13 20:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\Users\Patty\AppData\Local\Temp\catchme.sys – (catchme)
DRV - [2012/12/30 02:17:07 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60889A6B-745E-424C-84C3-FB2E0A798C4E}\MpKsl2c3e85da.sys – (MpKsl2c3e85da)
DRV - [2012/09/29 18:54:26 | 000,022,856 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\mbam.sys – (MBAMProtector)
DRV - [2012/09/25 08:06:55 | 000,012,992 | —- | M] (Paramount Software UK Ltd) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\PSVolAcc.sys – (PSVolAcc)
DRV - [2012/09/25 08:06:28 | 000,016,064 | —- | M] (Macrium Software) [Kernel | Boot | Running] – C:\Windows\System32\drivers\pssnap.sys – (pssnap)
DRV - [2012/09/25 08:05:31 | 000,054,464 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounterex.sys – (PSMounterEx)
DRV - [2012/08/30 21:03:50 | 000,099,272 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2012/08/20 22:33:19 | 000,053,952 | —- | M] (Macrium Software) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounter.sys – (PSMounter)
DRV - [2010/11/20 05:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 04:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/11 00:11:46 | 000,132,424 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdm.sys – (sscdmdm)
DRV - [2010/11/11 00:11:46 | 000,110,280 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdserd.sys – (sscdserd)
DRV - [2010/11/11 00:11:46 | 000,104,648 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdbus.sys – (sscdbus)
DRV - [2010/11/11 00:11:46 | 000,014,920 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdfl.sys – (sscdmdfl)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8&fr=mkg029
IE - HKLM\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKLM\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://us.mg5.mail.yahoo.com/neo/launch?.rand=ed87695mvk0e5"
FF - prefs.js..extensions.enabledAddons: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.4.8.20120412011105


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Patty\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Patty\AppData\Roaming\Mozilla\Firefox\Profiles/5erqatan.default\extensions\[removed]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.2.565.25\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension

[2012/08/04 12:51:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions
[2012/02/10 22:22:37 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/08/14 12:00:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/12/27 20:10:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions
[2012/11/30 12:30:24 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\7z2enokc.default-1346048094184\extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\m1mj1ash.default-1341883794977\extensions
[2012/08/14 17:42:25 | 000,553,785 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{003e1c8f-ebd6-f074-7551-4b31c0f547ec}.xpi
[2012/08/17 21:10:41 | 000,552,897 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{806215f3-1fe9-5c04-f5dd-1617f7bae315}.xpi
[2012/12/27 20:10:01 | 000,533,036 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012/09/30 18:28:20 | 000,093,926 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{ba243cb0-b824-4a26-9418-73ee795d9b9d}.xpi
[2012/11/24 00:01:29 | 000,804,627 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/07/13 19:16:36 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68
CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68

O1 HOSTS File: ([2012/09/30 17:37:46 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office2010\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3E4F083-98BF-476A-B54A-CA975B5E2AAD}: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/30 23:28:44 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/22 03:00:44 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/22 03:00:42 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/21 18:10:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/12/21 18:10:10 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2012/12/13 10:56:01 | 002,345,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/12/13 10:55:57 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2012/12/13 10:55:57 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/12/13 10:55:56 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012/12/13 10:55:55 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012/12/13 10:55:44 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2012/12/13 10:55:36 | 000,627,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/12/13 10:55:36 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/12/13 10:55:33 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/12/13 10:55:33 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/12/13 10:55:32 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/12/13 10:55:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2012/10/12 12:25:08 | 000,347,424 | —- | C] (Microsoft Corporation) – C:\Program Files\MicrosoftFixit.WinFileFolder.MATSKB.Run.exe
[2011/11/28 15:40:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Program Files\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/30 23:22:42 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/30 23:22:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:08:34 | 2388,381,696 | -HS- | M] () – C:\hiberfil.sys
[2012/12/27 20:02:28 | 001,500,026 | —- | M] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:33:45 | 001,548,705 | —- | M] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:15 | 001,326,183 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:37 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:10 | 000,114,033 | —- | M] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/22 03:17:29 | 000,493,792 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/12/20 20:22:14 | 025,304,641 | —- | M] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:40 | 002,818,519 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:30 | 025,304,695 | —- | M] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 17:38:09 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/16 09:13:28 | 000,295,424 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/16 09:13:20 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/11 17:26:18 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/12/11 17:26:18 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/12/04 17:38:31 | 000,042,783 | —- | M] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:43 | 000,057,326 | —- | M] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 18:41:28 | 002,159,251 | —- | M] () – C:\Users\Patty\Desktop\Untitled.hmk

========== Files Created - No Company Name ==========

[2012/12/27 12:30:35 | 001,500,026 | —- | C] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:30:31 | 001,548,705 | —- | C] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:14 | 001,326,183 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:35 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:09 | 000,114,033 | —- | C] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/20 23:47:39 | 000,039,651 | —- | C] () – C:\Users\Patty\Desktop\xmas tree.jpg
[2012/12/20 20:22:13 | 025,304,641 | —- | C] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:39 | 002,818,519 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:28 | 025,304,695 | —- | C] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 20:10:58 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/20 17:38:08 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:14 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/04 17:38:30 | 000,042,783 | —- | C] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:39 | 000,057,326 | —- | C] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 16:16:38 | 002,159,251 | —- | C] () – C:\Users\Patty\Desktop\Untitled.hmk
[2012/12/02 14:07:07 | 000,045,022 | —- | C] () – C:\Users\Patty\Desktop\270105_477742762263912_289450700_n.jpg
[2012/09/25 09:31:50 | 000,054,464 | —- | C] () – C:\Windows\System32\drivers\psmounterex.sys
[2012/09/24 16:33:30 | 000,015,420 | —- | C] () – C:\Users\Patty\Desktop.sla
[2012/09/24 13:06:29 | 000,001,019 | —- | C] () – C:\Program Files\Scribus 1.4.1.lnk
[2012/07/20 13:27:03 | 000,027,520 | —- | C] () – C:\Users\Patty\AppData\Local\dt.dat
[2012/03/16 23:25:18 | 000,000,017 | —- | C] () – C:\Users\Patty\AppData\Local\resmon.resmoncfg
[2012/02/10 22:29:32 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2011/09/26 10:00:27 | 000,000,117 | —- | C] () – C:\Windows\restore.INI
[2011/06/10 05:34:52 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2011/04/17 18:19:47 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2011/02/11 17:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll

========== ZeroAccess Check ==========

[2009/07/13 23:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 20:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\erdnt\cache\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\erdnt\cache\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/10/28 01:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 00:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/07/13 20:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD3200AAKS-75L9A0 ATA Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Canon MP500Storage USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: TEAC USB HS-CF Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: TEAC USB HS-xD/SM USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: TEAC USB HS-MS Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 -
Interface type: USB
Media Type:
Model: TEAC USB HS-SD Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 298.00GB
Starting Offset: 105906176
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
OTL Extras logfile created on: 12/30/2012 11:31:12 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Patty\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 63.52% Memory free
5.93 Gb Paging File | 4.13 Gb Available in Paging File | 69.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297.99 Gb Total Space | 182.21 Gb Free Space | 61.15% Space Free | Partition Type: NTFS

Computer Name: PATTI-PC | User Name: Patty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

[HKEY_USERS\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office2010\Office14\msohtmed.exe" %1 (Microsoft Corporation)
https [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [TakeOwnership] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UpdatesDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0732D58D-2ED7-4223-B83F-174CD9F7D0B9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0D976E33-6A8F-44F3-ADDE-D1DB31471B63}" = lport=137 | protocol=17 | dir=in | app=system |
"{0FB989FF-174D-426D-BD71-5096FF9B2635}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office2010\office14\outlook.exe |
"{18FDF09B-8AC7-4B59-AAE0-D4994FF524C5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5B1E76FE-4A5E-4B7E-8ED3-0E9660BD608E}" = rport=10243 | protocol=6 | dir=out | app=system |
"{711C3FAD-5DED-4A57-9B8F-F9F87EE93D4F}" = rport=137 | protocol=17 | dir=out | app=system |
"{794F9695-6474-4D92-811C-57DF8C1A4862}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7AFBC966-6ADB-4965-8B45-8D6B084C28A8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8FB63360-429B-4877-A878-F7DD4F3DAC4C}" = rport=445 | protocol=6 | dir=out | app=system |
"{9100EDB8-2F99-4256-9B7E-12F60B15903D}" = rport=139 | protocol=6 | dir=out | app=system |
"{914D4354-7A6D-4B3C-AD71-65B6316AB6D7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{936F2561-3127-4B15-B85A-148A307F37BA}" = lport=10243 | protocol=6 | dir=in | app=system |
"{994579BE-92D7-45F0-BDCB-CCA85B5A23D4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9AA310FF-9015-4088-B341-4B8484557B0C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9B61881B-8EE8-47F9-88B5-6F2B83F1A7C6}" = lport=138 | protocol=17 | dir=in | app=system |
"{AAC278BA-0795-475B-B35D-B7D7CDF33315}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{AD8A67E7-FC03-41F5-BA0F-C0C5E87730C3}" = rport=138 | protocol=17 | dir=out | app=system |
"{BF7F3787-0558-4B3D-B19F-0FBA95FF9864}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C9B5E501-2D48-45B8-8878-FB76AE7B2B0A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D147EC32-EE41-4504-898C-9176530A2AC7}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E0028CFB-163E-401A-89AB-9FD236FE7C29}" = lport=139 | protocol=6 | dir=in | app=system |
"{F008BC21-0F5A-4122-8F2B-C8D6874F6F17}" = lport=445 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{13FB84A7-7DAF-42BD-9A36-245008AB42F3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{175948C1-6278-4B06-B974-48619D0D6ED3}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3953394A-DE40-4745-931B-B07F3264ABC9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5C2DE8EC-AB85-43DD-9E14-04562DFB9386}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5FD78384-E337-4E24-9BF3-D8D3B537E403}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{71F170AC-DF47-4F3B-80EF-80149262168F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8D89D13C-C7B1-487C-8C1B-A4249EFDBE39}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{92102493-7716-419D-B79C-E8304C5A614A}" = protocol=17 | dir=in | app=c:\program files\microsoft office2010\office14\onenote.exe |
"{9D046A5E-1470-478C-9588-CBB27A83C104}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A0421DC1-1578-4747-B9E4-EE64464F56A1}" = protocol=6 | dir=in | app=c:\program files\microsoft office2010\office14\groove.exe |
"{A24DFA97-ADF4-4502-9AFE-71634943FC31}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B6807204-6815-492F-BDE5-70A138FE5F47}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{BD14476E-DC27-4372-B1E8-AF2BAE8C2478}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C51BC0AB-BDBC-4631-8940-E50A053CB9C9}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{EC294D04-A938-427A-94F3-45140667B5DE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EC571D02-EE1C-4C73-9304-27C4B51E8704}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F2DAE1FA-803E-4FEC-9873-784D2DFEC23F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F7C733F0-DB1D-4057-AD5A-C6B944680969}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FA58F22D-7498-4333-9A01-026EC185D85B}" = protocol=6 | dir=in | app=c:\program files\microsoft office2010\office14\onenote.exe |
"{FA6EAFE0-A10B-45AF-AF9D-8DB0FC24DF22}" = protocol=17 | dir=in | app=c:\program files\microsoft office2010\office14\groove.exe |
"{FE5C1A61-BC3E-4E2B-B4C1-3386D94E70F3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FEBC7F1E-72B7-4D83-B9E2-C339D36A4535}" = protocol=6 | dir=out | app=system |
"TCP Query User{493FADA3-572D-45BF-8FAE-97B77613AF77}C:\program files\microsoft office2010\office14\groove.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office2010\office14\groove.exe |
"UDP Query User{20D05909-C2EC-498C-B0F4-B9E014D21CAC}C:\program files\microsoft office2010\office14\groove.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office2010\office14\groove.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{028BB5A9-6385-4CF6-A6FF-D512D5015DBA}" = Garmin Lifetime Updater
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java™ 7 Update 5
"{2DDCB109-F81F-4307-9A2E-351BF0EC721D}" = 2010 Hallmark Registration Bonus Pack
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{601BE80D-247B-4084-94C7-7A54369DB7A2}" = Hallmark Card Studio 2010 Deluxe
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1" = Auslogics Duplicate File Finder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8777089A-4CF4-44BA-910B-9A4580669DED}" = Hallmark Card Studio 2012 Deluxe
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{94055A4F-6F4D-4F6D-85DB-893070B0BE7F}" = Verizon Wireless Software Upgrade Assistant - Samsung
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98EABC7F-B1A1-43A5-B505-5B4EC3908DCD}" = Microsoft Security Client
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B1D8A61F-F1F8-4C50-B0A9-C3C39517AA64}" = Macrium Reflect Free Edition
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{BA4DF4C3-196E-4128-969A-00996B5A46F8}" = Canon MP500
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F42F3704-4CA7-4D28-9F5B-FDBF2E589EB2}" = Verizon Wireless Software Upgrade Assistant - SAMSUNG (TL-PC)
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop Elements 2.0" = Adobe Photoshop Elements 2.0
"CCleaner" = CCleaner
"Cisco Connect" = Cisco Connect
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator 2.0" = Canon MP Navigator 2.0
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Picasa 3" = Picasa 3
"Revo Uninstaller" = Revo Uninstaller 1.93
"Scribus 1.4.1" = Scribus 1.4.1
"ShadowExplorer_is1" = ShadowExplorer 0.8
"SpywareBlaster_is1" = SpywareBlaster 4.6
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 11/22/2012 8:02:48 PM | Computer Name = Patti-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 14.0.1.4577 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: b34 Start
Time: 01cdc6b0df6f8137 Termination Time: 136 Application Path: C:\Program Files\Mozilla
Firefox\firefox.exe Report Id: 19ced353-3501-11e2-956e-002564d80f68

Error - 11/24/2012 5:02:58 PM | Computer Name = Patti-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 14.0.1.4577 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 75c Start
Time: 01cdc999e481789d Termination Time: 79 Application Path: C:\Program Files\Mozilla
Firefox\firefox.exe Report Id: 4d1b13c2-367a-11e2-956e-002564d80f68

Error - 12/2/2012 4:00:09 AM | Computer Name = Patti-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary MpKsl55bf4999. System Error: The system cannot find the file specified.
.

Error - 12/2/2012 4:03:02 AM | Computer Name = Patti-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary MpKsl55bf4999. System Error: The system cannot find the file specified.
.

Error - 12/3/2012 7:40:59 PM | Computer Name = Patti-PC | Source = Application Error | ID = 1000
Description = Faulting application name: HCS.exe, version: 2.0.1.0, time stamp:
0x4e98a6d9 Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp:
0x4ec49b60 Exception code: 0xc0000374 Fault offset: 0x000c380b Faulting process id:
0xbc4 Faulting application start time: 0x01cdd199e50c195a Faulting application path:
C:\Program Files\Creative Home\Hallmark Card Studio 2012 Deluxe\HCS.exe Faulting
module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: e38ea696-3da2-11e2-87a0-002564d80f68

Error - 12/3/2012 7:42:43 PM | Computer Name = Patti-PC | Source = Application Error | ID = 1000
Description = Faulting application name: HCS.exe, version: 2.0.1.0, time stamp:
0x4e98a6d9 Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp:
0x4ec49b60 Exception code: 0xc0000374 Fault offset: 0x000c380b Faulting process id:
0xc44 Faulting application start time: 0x01cdd1afaa03d8ca Faulting application path:
C:\Program Files\Creative Home\Hallmark Card Studio 2012 Deluxe\HCS.exe Faulting
module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 217bc2c7-3da3-11e2-87a0-002564d80f68

Error - 12/4/2012 12:48:37 PM | Computer Name = Patti-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary MpKsl55bf4999. System Error: The system cannot find the file specified.
.

Error - 12/23/2012 4:00:02 AM | Computer Name = Patti-PC | Source = Windows Backup | ID = 4103
Description =

Error - 12/26/2012 7:58:16 PM | Computer Name = Patti-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 14.0.1.4577 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 948 Start
Time: 01cde3991bf652e5 Termination Time: 109 Application Path: C:\Program Files\Mozilla
Firefox\firefox.exe Report Id: 004ec28b-4fb8-11e2-9535-002564d80f68

Error - 12/30/2012 2:14:48 PM | Computer Name = Patti-PC | Source = Windows Backup | ID = 4103
Description =

[ System Events ]
Error - 12/22/2012 3:12:10 PM | Computer Name = Patti-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.

Error - 12/22/2012 3:12:10 PM | Computer Name = Patti-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.

Error - 12/22/2012 3:12:10 PM | Computer Name = Patti-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.

Error - 12/22/2012 3:12:10 PM | Computer Name = Patti-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.

Error - 12/22/2012 3:12:10 PM | Computer Name = Patti-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.

Error - 12/22/2012 3:13:25 PM | Computer Name = Patti-PC | Source = Microsoft-Windows-Eventlog | ID = 22
Description = The event logging service encountered an error while initializing
publishing resources for channel DebugChannel. If channel type is Analytic or Debug,
then this could mean there was an error initializing logging resources as well.

Error - 12/26/2012 7:26:15 PM | Computer Name = Patti-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Netman service.

Error - 12/27/2012 9:03:30 PM | Computer Name = Patti-PC | Source = Microsoft-Windows-Eventlog | ID = 22
Description = The event logging service encountered an error while initializing
publishing resources for channel DebugChannel. If channel type is Analytic or Debug,
then this could mean there was an error initializing logging resources as well.

Error - 12/28/2012 12:08:42 PM | Computer Name = Patti-PC | Source = Microsoft-Windows-Eventlog | ID = 22
Description = The event logging service encountered an error while initializing
publishing resources for channel DebugChannel. If channel type is Analytic or Debug,
then this could mean there was an error initializing logging resources as well.

Error - 12/28/2012 5:07:43 PM | Computer Name = Patti-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.


< End of report >
My computer is running slow again. I takes forever to open a website. A screen will just go gray and you can't do anything with it until it decides to go blue again.

OTL logfile created on: 12/30/2012 11:31:12 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Patty\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 63.52% Memory free
5.93 Gb Paging File | 4.13 Gb Available in Paging File | 69.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297.99 Gb Total Space | 182.21 Gb Free Space | 61.15% Space Free | Partition Type: NTFS

Computer Name: PATTI-PC | User Name: Patty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
PRC - [2012/12/11 17:26:19 | 001,807,800 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
PRC - [2012/09/29 18:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () – C:\Program Files\Macrium\Reflect\ReflectService.exe
PRC - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/12 16:19:44 | 000,947,176 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/13 19:17:11 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) – C:\Program Files\ShadowExplorer\sesvc.exe
PRC - [2010/11/20 07:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe


========== Modules (No Company Name) ==========

MOD - [2012/12/11 17:26:17 | 014,586,296 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_135.dll
MOD - [2012/07/13 19:17:14 | 002,003,424 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/03/16 23:11:16 | 004,297,568 | —- | M] () – C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 14:45:26 | 008,801,120 | —- | M] () – C:\Program Files\Microsoft Office2010\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV - [2012/12/11 17:26:22 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () [Auto | Running] – C:\Program Files\Macrium\Reflect\ReflectService.exe – (ReflectService.exe)
SRV - [2012/09/20 13:28:48 | 030,785,672 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Office2010\Office14\GROOVE.EXE – (Microsoft SharePoint Workspace Audit Service)
SRV - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 19:17:12 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/02/10 23:45:21 | 001,343,400 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) [Auto | Running] – C:\Program Files\ShadowExplorer\sesvc.exe – (sesvc)
SRV - [2009/07/13 20:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/13 20:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\Users\Patty\AppData\Local\Temp\catchme.sys – (catchme)
DRV - [2012/12/30 02:17:07 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60889A6B-745E-424C-84C3-FB2E0A798C4E}\MpKsl2c3e85da.sys – (MpKsl2c3e85da)
DRV - [2012/09/29 18:54:26 | 000,022,856 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\mbam.sys – (MBAMProtector)
DRV - [2012/09/25 08:06:55 | 000,012,992 | —- | M] (Paramount Software UK Ltd) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\PSVolAcc.sys – (PSVolAcc)
DRV - [2012/09/25 08:06:28 | 000,016,064 | —- | M] (Macrium Software) [Kernel | Boot | Running] – C:\Windows\System32\drivers\pssnap.sys – (pssnap)
DRV - [2012/09/25 08:05:31 | 000,054,464 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounterex.sys – (PSMounterEx)
DRV - [2012/08/30 21:03:50 | 000,099,272 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2012/08/20 22:33:19 | 000,053,952 | —- | M] (Macrium Software) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounter.sys – (PSMounter)
DRV - [2010/11/20 05:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 04:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/11 00:11:46 | 000,132,424 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdm.sys – (sscdmdm)
DRV - [2010/11/11 00:11:46 | 000,110,280 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdserd.sys – (sscdserd)
DRV - [2010/11/11 00:11:46 | 000,104,648 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdbus.sys – (sscdbus)
DRV - [2010/11/11 00:11:46 | 000,014,920 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdfl.sys – (sscdmdfl)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8&fr=mkg029
IE - HKLM\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKLM\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://us.mg5.mail.yahoo.com/neo/launch?.rand=ed87695mvk0e5"
FF - prefs.js..extensions.enabledAddons: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.4.8.20120412011105


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Patty\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Patty\AppData\Roaming\Mozilla\Firefox\Profiles/5erqatan.default\extensions\[removed]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.2.565.25\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension

[2012/08/04 12:51:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions
[2012/02/10 22:22:37 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/08/14 12:00:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/12/27 20:10:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions
[2012/11/30 12:30:24 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\7z2enokc.default-1346048094184\extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\m1mj1ash.default-1341883794977\extensions
[2012/08/14 17:42:25 | 000,553,785 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{003e1c8f-ebd6-f074-7551-4b31c0f547ec}.xpi
[2012/08/17 21:10:41 | 000,552,897 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{806215f3-1fe9-5c04-f5dd-1617f7bae315}.xpi
[2012/12/27 20:10:01 | 000,533,036 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012/09/30 18:28:20 | 000,093,926 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{ba243cb0-b824-4a26-9418-73ee795d9b9d}.xpi
[2012/11/24 00:01:29 | 000,804,627 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/07/13 19:16:36 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68
CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68

O1 HOSTS File: ([2012/09/30 17:37:46 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office2010\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3E4F083-98BF-476A-B54A-CA975B5E2AAD}: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/30 23:28:44 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/22 03:00:44 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/22 03:00:42 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/21 18:10:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/12/21 18:10:10 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2012/12/13 10:56:01 | 002,345,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/12/13 10:55:57 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2012/12/13 10:55:57 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/12/13 10:55:56 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012/12/13 10:55:55 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012/12/13 10:55:44 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2012/12/13 10:55:36 | 000,627,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/12/13 10:55:36 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/12/13 10:55:33 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/12/13 10:55:33 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/12/13 10:55:32 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/12/13 10:55:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2012/10/12 12:25:08 | 000,347,424 | —- | C] (Microsoft Corporation) – C:\Program Files\MicrosoftFixit.WinFileFolder.MATSKB.Run.exe
[2011/11/28 15:40:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Program Files\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/30 23:22:42 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/30 23:22:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:08:34 | 2388,381,696 | -HS- | M] () – C:\hiberfil.sys
[2012/12/27 20:02:28 | 001,500,026 | —- | M] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:33:45 | 001,548,705 | —- | M] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:15 | 001,326,183 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:37 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:10 | 000,114,033 | —- | M] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/22 03:17:29 | 000,493,792 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/12/20 20:22:14 | 025,304,641 | —- | M] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:40 | 002,818,519 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:30 | 025,304,695 | —- | M] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 17:38:09 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/16 09:13:28 | 000,295,424 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/16 09:13:20 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/11 17:26:18 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/12/11 17:26:18 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/12/04 17:38:31 | 000,042,783 | —- | M] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:43 | 000,057,326 | —- | M] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 18:41:28 | 002,159,251 | —- | M] () – C:\Users\Patty\Desktop\Untitled.hmk

========== Files Created - No Company Name ==========

[2012/12/27 12:30:35 | 001,500,026 | —- | C] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:30:31 | 001,548,705 | —- | C] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:14 | 001,326,183 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:35 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:09 | 000,114,033 | —- | C] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/20 23:47:39 | 000,039,651 | —- | C] () – C:\Users\Patty\Desktop\xmas tree.jpg
[2012/12/20 20:22:13 | 025,304,641 | —- | C] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:39 | 002,818,519 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:28 | 025,304,695 | —- | C] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 20:10:58 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/20 17:38:08 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:14 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/04 17:38:30 | 000,042,783 | —- | C] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:39 | 000,057,326 | —- | C] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 16:16:38 | 002,159,251 | —- | C] () – C:\Users\Patty\Desktop\Untitled.hmk
[2012/12/02 14:07:07 | 000,045,022 | —- | C] () – C:\Users\Patty\Desktop\270105_477742762263912_289450700_n.jpg
[2012/09/25 09:31:50 | 000,054,464 | —- | C] () – C:\Windows\System32\drivers\psmounterex.sys
[2012/09/24 16:33:30 | 000,015,420 | —- | C] () – C:\Users\Patty\Desktop.sla
[2012/09/24 13:06:29 | 000,001,019 | —- | C] () – C:\Program Files\Scribus 1.4.1.lnk
[2012/07/20 13:27:03 | 000,027,520 | —- | C] () – C:\Users\Patty\AppData\Local\dt.dat
[2012/03/16 23:25:18 | 000,000,017 | —- | C] () – C:\Users\Patty\AppData\Local\resmon.resmoncfg
[2012/02/10 22:29:32 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2011/09/26 10:00:27 | 000,000,117 | —- | C] () – C:\Windows\restore.INI
[2011/06/10 05:34:52 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2011/04/17 18:19:47 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2011/02/11 17:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll

========== ZeroAccess Check ==========

[2009/07/13 23:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 20:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\erdnt\cache\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\erdnt\cache\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/10/28 01:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 00:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/07/13 20:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD3200AAKS-75L9A0 ATA Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Canon MP500Storage USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: TEAC USB HS-CF Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: TEAC USB HS-xD/SM USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: TEAC USB HS-MS Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 -
Interface type: USB
Media Type:
Model: TEAC USB HS-SD Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 298.00GB
Starting Offset: 105906176
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
My computer is running slow again. I takes forever to open a website. A screen will just go gray and you can't do anything with it until it decides to go blue again.. Here are some reports I thought would be helpful!!!!!

OTL logfile created on: 12/30/2012 11:31:12 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Patty\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 63.52% Memory free
5.93 Gb Paging File | 4.13 Gb Available in Paging File | 69.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297.99 Gb Total Space | 182.21 Gb Free Space | 61.15% Space Free | Partition Type: NTFS

Computer Name: PATTI-PC | User Name: Patty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
PRC - [2012/12/11 17:26:19 | 001,807,800 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
PRC - [2012/09/29 18:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () – C:\Program Files\Macrium\Reflect\ReflectService.exe
PRC - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/12 16:19:44 | 000,947,176 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/13 19:17:11 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) – C:\Program Files\ShadowExplorer\sesvc.exe
PRC - [2010/11/20 07:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe


========== Modules (No Company Name) ==========

MOD - [2012/12/11 17:26:17 | 014,586,296 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_135.dll
MOD - [2012/07/13 19:17:14 | 002,003,424 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/03/16 23:11:16 | 004,297,568 | —- | M] () – C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 14:45:26 | 008,801,120 | —- | M] () – C:\Program Files\Microsoft Office2010\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV - [2012/12/11 17:26:22 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () [Auto | Running] – C:\Program Files\Macrium\Reflect\ReflectService.exe – (ReflectService.exe)
SRV - [2012/09/20 13:28:48 | 030,785,672 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Office2010\Office14\GROOVE.EXE – (Microsoft SharePoint Workspace Audit Service)
SRV - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 19:17:12 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/02/10 23:45:21 | 001,343,400 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) [Auto | Running] – C:\Program Files\ShadowExplorer\sesvc.exe – (sesvc)
SRV - [2009/07/13 20:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/13 20:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\Users\Patty\AppData\Local\Temp\catchme.sys – (catchme)
DRV - [2012/12/30 02:17:07 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60889A6B-745E-424C-84C3-FB2E0A798C4E}\MpKsl2c3e85da.sys – (MpKsl2c3e85da)
DRV - [2012/09/29 18:54:26 | 000,022,856 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\mbam.sys – (MBAMProtector)
DRV - [2012/09/25 08:06:55 | 000,012,992 | —- | M] (Paramount Software UK Ltd) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\PSVolAcc.sys – (PSVolAcc)
DRV - [2012/09/25 08:06:28 | 000,016,064 | —- | M] (Macrium Software) [Kernel | Boot | Running] – C:\Windows\System32\drivers\pssnap.sys – (pssnap)
DRV - [2012/09/25 08:05:31 | 000,054,464 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounterex.sys – (PSMounterEx)
DRV - [2012/08/30 21:03:50 | 000,099,272 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2012/08/20 22:33:19 | 000,053,952 | —- | M] (Macrium Software) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounter.sys – (PSMounter)
DRV - [2010/11/20 05:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 04:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/11 00:11:46 | 000,132,424 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdm.sys – (sscdmdm)
DRV - [2010/11/11 00:11:46 | 000,110,280 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdserd.sys – (sscdserd)
DRV - [2010/11/11 00:11:46 | 000,104,648 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdbus.sys – (sscdbus)
DRV - [2010/11/11 00:11:46 | 000,014,920 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdfl.sys – (sscdmdfl)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8&fr=mkg029
IE - HKLM\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKLM\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://us.mg5.mail.yahoo.com/neo/launch?.rand=ed87695mvk0e5"
FF - prefs.js..extensions.enabledAddons: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.4.8.20120412011105


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Patty\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Patty\AppData\Roaming\Mozilla\Firefox\Profiles/5erqatan.default\extensions\[removed]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.2.565.25\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension

[2012/08/04 12:51:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions
[2012/02/10 22:22:37 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/08/14 12:00:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/12/27 20:10:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions
[2012/11/30 12:30:24 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\7z2enokc.default-1346048094184\extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\m1mj1ash.default-1341883794977\extensions
[2012/08/14 17:42:25 | 000,553,785 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{003e1c8f-ebd6-f074-7551-4b31c0f547ec}.xpi
[2012/08/17 21:10:41 | 000,552,897 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{806215f3-1fe9-5c04-f5dd-1617f7bae315}.xpi
[2012/12/27 20:10:01 | 000,533,036 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012/09/30 18:28:20 | 000,093,926 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{ba243cb0-b824-4a26-9418-73ee795d9b9d}.xpi
[2012/11/24 00:01:29 | 000,804,627 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/07/13 19:16:36 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68
CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68

O1 HOSTS File: ([2012/09/30 17:37:46 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office2010\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3E4F083-98BF-476A-B54A-CA975B5E2AAD}: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/30 23:28:44 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/22 03:00:44 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/22 03:00:42 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/21 18:10:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/12/21 18:10:10 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2012/12/13 10:56:01 | 002,345,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/12/13 10:55:57 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2012/12/13 10:55:57 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/12/13 10:55:56 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012/12/13 10:55:55 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012/12/13 10:55:44 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2012/12/13 10:55:36 | 000,627,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/12/13 10:55:36 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/12/13 10:55:33 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/12/13 10:55:33 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/12/13 10:55:32 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/12/13 10:55:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2012/10/12 12:25:08 | 000,347,424 | —- | C] (Microsoft Corporation) – C:\Program Files\MicrosoftFixit.WinFileFolder.MATSKB.Run.exe
[2011/11/28 15:40:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Program Files\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/30 23:22:42 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/30 23:22:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:08:34 | 2388,381,696 | -HS- | M] () – C:\hiberfil.sys
[2012/12/27 20:02:28 | 001,500,026 | —- | M] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:33:45 | 001,548,705 | —- | M] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:15 | 001,326,183 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:37 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:10 | 000,114,033 | —- | M] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/22 03:17:29 | 000,493,792 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/12/20 20:22:14 | 025,304,641 | —- | M] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:40 | 002,818,519 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:30 | 025,304,695 | —- | M] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 17:38:09 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/16 09:13:28 | 000,295,424 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/16 09:13:20 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/11 17:26:18 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/12/11 17:26:18 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/12/04 17:38:31 | 000,042,783 | —- | M] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:43 | 000,057,326 | —- | M] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 18:41:28 | 002,159,251 | —- | M] () – C:\Users\Patty\Desktop\Untitled.hmk

========== Files Created - No Company Name ==========

[2012/12/27 12:30:35 | 001,500,026 | —- | C] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:30:31 | 001,548,705 | —- | C] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:14 | 001,326,183 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:35 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:09 | 000,114,033 | —- | C] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/20 23:47:39 | 000,039,651 | —- | C] () – C:\Users\Patty\Desktop\xmas tree.jpg
[2012/12/20 20:22:13 | 025,304,641 | —- | C] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:39 | 002,818,519 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:28 | 025,304,695 | —- | C] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 20:10:58 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/20 17:38:08 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:14 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/04 17:38:30 | 000,042,783 | —- | C] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:39 | 000,057,326 | —- | C] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 16:16:38 | 002,159,251 | —- | C] () – C:\Users\Patty\Desktop\Untitled.hmk
[2012/12/02 14:07:07 | 000,045,022 | —- | C] () – C:\Users\Patty\Desktop\270105_477742762263912_289450700_n.jpg
[2012/09/25 09:31:50 | 000,054,464 | —- | C] () – C:\Windows\System32\drivers\psmounterex.sys
[2012/09/24 16:33:30 | 000,015,420 | —- | C] () – C:\Users\Patty\Desktop.sla
[2012/09/24 13:06:29 | 000,001,019 | —- | C] () – C:\Program Files\Scribus 1.4.1.lnk
[2012/07/20 13:27:03 | 000,027,520 | —- | C] () – C:\Users\Patty\AppData\Local\dt.dat
[2012/03/16 23:25:18 | 000,000,017 | —- | C] () – C:\Users\Patty\AppData\Local\resmon.resmoncfg
[2012/02/10 22:29:32 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2011/09/26 10:00:27 | 000,000,117 | —- | C] () – C:\Windows\restore.INI
[2011/06/10 05:34:52 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2011/04/17 18:19:47 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2011/02/11 17:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll

========== ZeroAccess Check ==========

[2009/07/13 23:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 20:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\erdnt\cache\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\erdnt\cache\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/10/28 01:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 00:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/07/13 20:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD3200AAKS-75L9A0 ATA Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Canon MP500Storage USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: TEAC USB HS-CF Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: TEAC USB HS-xD/SM USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: TEAC USB HS-MS Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 -
Interface type: USB
Media Type:
Model: TEAC USB HS-SD Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 298.00GB
Starting Offset: 105906176
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
My computer is running slow again. I takes forever to open a website. A screen will just go gray and you can't do anything with it until it decides to go blue again.. Here are some reports I thought would be helpful!!!!!

OTL logfile created on: 12/30/2012 11:31:12 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Patty\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 63.52% Memory free
5.93 Gb Paging File | 4.13 Gb Available in Paging File | 69.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297.99 Gb Total Space | 182.21 Gb Free Space | 61.15% Space Free | Partition Type: NTFS

Computer Name: PATTI-PC | User Name: Patty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
PRC - [2012/12/11 17:26:19 | 001,807,800 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
PRC - [2012/09/29 18:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () – C:\Program Files\Macrium\Reflect\ReflectService.exe
PRC - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/12 16:19:44 | 000,947,176 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/13 19:17:11 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) – C:\Program Files\ShadowExplorer\sesvc.exe
PRC - [2010/11/20 07:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe


========== Modules (No Company Name) ==========

MOD - [2012/12/11 17:26:17 | 014,586,296 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_135.dll
MOD - [2012/07/13 19:17:14 | 002,003,424 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/03/16 23:11:16 | 004,297,568 | —- | M] () – C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 14:45:26 | 008,801,120 | —- | M] () – C:\Program Files\Microsoft Office2010\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV - [2012/12/11 17:26:22 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () [Auto | Running] – C:\Program Files\Macrium\Reflect\ReflectService.exe – (ReflectService.exe)
SRV - [2012/09/20 13:28:48 | 030,785,672 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Office2010\Office14\GROOVE.EXE – (Microsoft SharePoint Workspace Audit Service)
SRV - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 19:17:12 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/02/10 23:45:21 | 001,343,400 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) [Auto | Running] – C:\Program Files\ShadowExplorer\sesvc.exe – (sesvc)
SRV - [2009/07/13 20:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/13 20:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\Users\Patty\AppData\Local\Temp\catchme.sys – (catchme)
DRV - [2012/12/30 02:17:07 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60889A6B-745E-424C-84C3-FB2E0A798C4E}\MpKsl2c3e85da.sys – (MpKsl2c3e85da)
DRV - [2012/09/29 18:54:26 | 000,022,856 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\mbam.sys – (MBAMProtector)
DRV - [2012/09/25 08:06:55 | 000,012,992 | —- | M] (Paramount Software UK Ltd) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\PSVolAcc.sys – (PSVolAcc)
DRV - [2012/09/25 08:06:28 | 000,016,064 | —- | M] (Macrium Software) [Kernel | Boot | Running] – C:\Windows\System32\drivers\pssnap.sys – (pssnap)
DRV - [2012/09/25 08:05:31 | 000,054,464 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounterex.sys – (PSMounterEx)
DRV - [2012/08/30 21:03:50 | 000,099,272 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2012/08/20 22:33:19 | 000,053,952 | —- | M] (Macrium Software) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounter.sys – (PSMounter)
DRV - [2010/11/20 05:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 04:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/11 00:11:46 | 000,132,424 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdm.sys – (sscdmdm)
DRV - [2010/11/11 00:11:46 | 000,110,280 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdserd.sys – (sscdserd)
DRV - [2010/11/11 00:11:46 | 000,104,648 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdbus.sys – (sscdbus)
DRV - [2010/11/11 00:11:46 | 000,014,920 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdfl.sys – (sscdmdfl)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8&fr=mkg029
IE - HKLM\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKLM\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://us.mg5.mail.yahoo.com/neo/launch?.rand=ed87695mvk0e5"
FF - prefs.js..extensions.enabledAddons: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.4.8.20120412011105


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Patty\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Patty\AppData\Roaming\Mozilla\Firefox\Profiles/5erqatan.default\extensions\[removed]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.2.565.25\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension

[2012/08/04 12:51:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions
[2012/02/10 22:22:37 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/08/14 12:00:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/12/27 20:10:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions
[2012/11/30 12:30:24 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\7z2enokc.default-1346048094184\extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\m1mj1ash.default-1341883794977\extensions
[2012/08/14 17:42:25 | 000,553,785 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{003e1c8f-ebd6-f074-7551-4b31c0f547ec}.xpi
[2012/08/17 21:10:41 | 000,552,897 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{806215f3-1fe9-5c04-f5dd-1617f7bae315}.xpi
[2012/12/27 20:10:01 | 000,533,036 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012/09/30 18:28:20 | 000,093,926 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{ba243cb0-b824-4a26-9418-73ee795d9b9d}.xpi
[2012/11/24 00:01:29 | 000,804,627 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/07/13 19:16:36 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68
CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68

O1 HOSTS File: ([2012/09/30 17:37:46 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office2010\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3E4F083-98BF-476A-B54A-CA975B5E2AAD}: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/30 23:28:44 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/22 03:00:44 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/22 03:00:42 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/21 18:10:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/12/21 18:10:10 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2012/12/13 10:56:01 | 002,345,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/12/13 10:55:57 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2012/12/13 10:55:57 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/12/13 10:55:56 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012/12/13 10:55:55 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012/12/13 10:55:44 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2012/12/13 10:55:36 | 000,627,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/12/13 10:55:36 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/12/13 10:55:33 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/12/13 10:55:33 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/12/13 10:55:32 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/12/13 10:55:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2012/10/12 12:25:08 | 000,347,424 | —- | C] (Microsoft Corporation) – C:\Program Files\MicrosoftFixit.WinFileFolder.MATSKB.Run.exe
[2011/11/28 15:40:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Program Files\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/30 23:22:42 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/30 23:22:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:08:34 | 2388,381,696 | -HS- | M] () – C:\hiberfil.sys
[2012/12/27 20:02:28 | 001,500,026 | —- | M] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:33:45 | 001,548,705 | —- | M] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:15 | 001,326,183 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:37 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:10 | 000,114,033 | —- | M] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/22 03:17:29 | 000,493,792 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/12/20 20:22:14 | 025,304,641 | —- | M] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:40 | 002,818,519 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:30 | 025,304,695 | —- | M] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 17:38:09 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/16 09:13:28 | 000,295,424 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/16 09:13:20 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/11 17:26:18 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/12/11 17:26:18 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/12/04 17:38:31 | 000,042,783 | —- | M] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:43 | 000,057,326 | —- | M] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 18:41:28 | 002,159,251 | —- | M] () – C:\Users\Patty\Desktop\Untitled.hmk

========== Files Created - No Company Name ==========

[2012/12/27 12:30:35 | 001,500,026 | —- | C] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:30:31 | 001,548,705 | —- | C] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:14 | 001,326,183 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:35 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:09 | 000,114,033 | —- | C] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/20 23:47:39 | 000,039,651 | —- | C] () – C:\Users\Patty\Desktop\xmas tree.jpg
[2012/12/20 20:22:13 | 025,304,641 | —- | C] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:39 | 002,818,519 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:28 | 025,304,695 | —- | C] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 20:10:58 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/20 17:38:08 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:14 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/04 17:38:30 | 000,042,783 | —- | C] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:39 | 000,057,326 | —- | C] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 16:16:38 | 002,159,251 | —- | C] () – C:\Users\Patty\Desktop\Untitled.hmk
[2012/12/02 14:07:07 | 000,045,022 | —- | C] () – C:\Users\Patty\Desktop\270105_477742762263912_289450700_n.jpg
[2012/09/25 09:31:50 | 000,054,464 | —- | C] () – C:\Windows\System32\drivers\psmounterex.sys
[2012/09/24 16:33:30 | 000,015,420 | —- | C] () – C:\Users\Patty\Desktop.sla
[2012/09/24 13:06:29 | 000,001,019 | —- | C] () – C:\Program Files\Scribus 1.4.1.lnk
[2012/07/20 13:27:03 | 000,027,520 | —- | C] () – C:\Users\Patty\AppData\Local\dt.dat
[2012/03/16 23:25:18 | 000,000,017 | —- | C] () – C:\Users\Patty\AppData\Local\resmon.resmoncfg
[2012/02/10 22:29:32 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2011/09/26 10:00:27 | 000,000,117 | —- | C] () – C:\Windows\restore.INI
[2011/06/10 05:34:52 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2011/04/17 18:19:47 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2011/02/11 17:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll

========== ZeroAccess Check ==========

[2009/07/13 23:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 20:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\erdnt\cache\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\erdnt\cache\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/10/28 01:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 00:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/07/13 20:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD3200AAKS-75L9A0 ATA Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Canon MP500Storage USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: TEAC USB HS-CF Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: TEAC USB HS-xD/SM USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: TEAC USB HS-MS Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 -
Interface type: USB
Media Type:
Model: TEAC USB HS-SD Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 298.00GB
Starting Offset: 105906176
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
My computer is running slow again. I takes forever to open a website. A screen will just go gray and you can't do anything with it until it decides to go blue again.. Here are some reports I thought would be helpful!!!!!

OTL logfile created on: 12/30/2012 11:31:12 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Patty\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.97 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 63.52% Memory free
5.93 Gb Paging File | 4.13 Gb Available in Paging File | 69.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297.99 Gb Total Space | 182.21 Gb Free Space | 61.15% Space Free | Partition Type: NTFS

Computer Name: PATTI-PC | User Name: Patty | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
PRC - [2012/12/11 17:26:19 | 001,807,800 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
PRC - [2012/09/29 18:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () – C:\Program Files\Macrium\Reflect\ReflectService.exe
PRC - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/12 16:19:44 | 000,947,176 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/13 19:17:11 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) – C:\Program Files\ShadowExplorer\sesvc.exe
PRC - [2010/11/20 07:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe


========== Modules (No Company Name) ==========

MOD - [2012/12/11 17:26:17 | 014,586,296 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_135.dll
MOD - [2012/07/13 19:17:14 | 002,003,424 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/03/16 23:11:16 | 004,297,568 | —- | M] () – C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 14:45:26 | 008,801,120 | —- | M] () – C:\Program Files\Microsoft Office2010\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV - [2012/12/11 17:26:22 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 18:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/09/29 18:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/09/25 08:05:09 | 000,224,960 | —- | M] () [Auto | Running] – C:\Program Files\Macrium\Reflect\ReflectService.exe – (ReflectService.exe)
SRV - [2012/09/20 13:28:48 | 030,785,672 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Office2010\Office14\GROOVE.EXE – (Microsoft SharePoint Workspace Audit Service)
SRV - [2012/09/12 16:25:24 | 000,287,824 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/09/12 16:25:22 | 000,020,472 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 19:17:12 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/02/10 23:45:21 | 001,343,400 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2011/01/02 20:29:50 | 000,009,216 | —- | M] (www.shadowexplorer.com) [Auto | Running] – C:\Program Files\ShadowExplorer\sesvc.exe – (sesvc)
SRV - [2009/07/13 20:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/13 20:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\Users\Patty\AppData\Local\Temp\catchme.sys – (catchme)
DRV - [2012/12/30 02:17:07 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60889A6B-745E-424C-84C3-FB2E0A798C4E}\MpKsl2c3e85da.sys – (MpKsl2c3e85da)
DRV - [2012/09/29 18:54:26 | 000,022,856 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\mbam.sys – (MBAMProtector)
DRV - [2012/09/25 08:06:55 | 000,012,992 | —- | M] (Paramount Software UK Ltd) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\PSVolAcc.sys – (PSVolAcc)
DRV - [2012/09/25 08:06:28 | 000,016,064 | —- | M] (Macrium Software) [Kernel | Boot | Running] – C:\Windows\System32\drivers\pssnap.sys – (pssnap)
DRV - [2012/09/25 08:05:31 | 000,054,464 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounterex.sys – (PSMounterEx)
DRV - [2012/08/30 21:03:50 | 000,099,272 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2012/08/20 22:33:19 | 000,053,952 | —- | M] (Macrium Software) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\psmounter.sys – (PSMounter)
DRV - [2010/11/20 05:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 04:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/11 00:11:46 | 000,132,424 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdm.sys – (sscdmdm)
DRV - [2010/11/11 00:11:46 | 000,110,280 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdserd.sys – (sscdserd)
DRV - [2010/11/11 00:11:46 | 000,104,648 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdbus.sys – (sscdbus)
DRV - [2010/11/11 00:11:46 | 000,014,920 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\sscdmdfl.sys – (sscdmdfl)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8&fr=mkg029
IE - HKLM\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKLM\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes,DefaultScope = {36668FFD-7809-43FB-A609-999C5A7AB5FE}
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\..\SearchScopes\{36668FFD-7809-43FB-A609-999C5A7AB5FE}: "URL" = http://search.foxtab.com/?q={searchTerms}&…mp;cr=344294484
IE - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://us.mg5.mail.yahoo.com/neo/launch?.rand=ed87695mvk0e5"
FF - prefs.js..extensions.enabledAddons: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.4.8.20120412011105


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI4066~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Patty\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Patty\AppData\Roaming\Mozilla\Firefox\Profiles/5erqatan.default\extensions\[removed]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.2.565.25\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension

[2012/08/04 12:51:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions
[2012/02/10 22:22:37 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/08/14 12:00:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\5erqatan.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/12/27 20:10:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions
[2012/11/30 12:30:24 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\791mcddo.default-1346059307542\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\7z2enokc.default-1346048094184\extensions
[2012/09/30 04:17:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\Firefox\Profiles\m1mj1ash.default-1341883794977\extensions
[2012/08/14 17:42:25 | 000,553,785 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{003e1c8f-ebd6-f074-7551-4b31c0f547ec}.xpi
[2012/08/17 21:10:41 | 000,552,897 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\5erqatan.default\extensions\{806215f3-1fe9-5c04-f5dd-1617f7bae315}.xpi
[2012/12/27 20:10:01 | 000,533,036 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012/09/30 18:28:20 | 000,093,926 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{ba243cb0-b824-4a26-9418-73ee795d9b9d}.xpi
[2012/11/24 00:01:29 | 000,804,627 | —- | M] () (No name found) – C:\Users\Patty\AppData\Roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/07/13 19:16:36 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68
CHR - homepage: http://search.babylon.com/?affID=110795&am…000002564d80f68

O1 HOSTS File: ([2012/09/30 17:37:46 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office2010\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1020532669-3928529439-608603026-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3E4F083-98BF-476A-B54A-CA975B5E2AAD}: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/30 23:28:44 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/22 03:00:44 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/22 03:00:42 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/21 18:10:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/12/21 18:10:10 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2012/12/13 10:56:01 | 002,345,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/12/13 10:55:57 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2012/12/13 10:55:57 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/12/13 10:55:56 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012/12/13 10:55:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/13 10:55:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012/12/13 10:55:55 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/13 10:55:55 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/13 10:55:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012/12/13 10:55:44 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2012/12/13 10:55:36 | 000,627,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/12/13 10:55:36 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/12/13 10:55:33 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/12/13 10:55:33 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/12/13 10:55:32 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/12/13 10:55:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2012/10/12 12:25:08 | 000,347,424 | —- | C] (Microsoft Corporation) – C:\Program Files\MicrosoftFixit.WinFileFolder.MATSKB.Run.exe
[2011/11/28 15:40:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Program Files\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/12/30 23:28:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Patty\Desktop\OTL.exe
[2012/12/30 23:22:42 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/30 23:22:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:16:03 | 000,015,152 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/28 11:08:34 | 2388,381,696 | -HS- | M] () – C:\hiberfil.sys
[2012/12/27 20:02:28 | 001,500,026 | —- | M] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:33:45 | 001,548,705 | —- | M] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:15 | 001,326,183 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:37 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:10 | 000,114,033 | —- | M] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/22 03:17:29 | 000,493,792 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/12/20 20:22:14 | 025,304,641 | —- | M] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:40 | 002,818,519 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:30 | 025,304,695 | —- | M] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 17:38:09 | 000,055,838 | —- | M] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/16 17:48:16 | 000,043,348 | —- | M] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/16 09:13:28 | 000,295,424 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/12/16 09:13:20 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/12/11 17:26:18 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/12/11 17:26:18 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/12/04 17:38:31 | 000,042,783 | —- | M] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:43 | 000,057,326 | —- | M] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 18:41:28 | 002,159,251 | —- | M] () – C:\Users\Patty\Desktop\Untitled.hmk

========== Files Created - No Company Name ==========

[2012/12/27 12:30:35 | 001,500,026 | —- | C] () – C:\Users\Patty\Desktop\P1020817.JPG
[2012/12/27 12:30:31 | 001,548,705 | —- | C] () – C:\Users\Patty\Desktop\P1020816.JPG
[2012/12/24 13:03:14 | 001,326,183 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.psd
[2012/12/24 12:21:35 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard new one.jpg
[2012/12/23 20:11:09 | 000,114,033 | —- | C] () – C:\Users\Patty\Desktop\547471_4414392155775_1461270197_n.jpg
[2012/12/20 23:47:39 | 000,039,651 | —- | C] () – C:\Users\Patty\Desktop\xmas tree.jpg
[2012/12/20 20:22:13 | 025,304,641 | —- | C] () – C:\Users\Patty\Desktop\Meijer - Jesus.psd
[2012/12/20 20:20:39 | 002,818,519 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.psd
[2012/12/20 20:20:28 | 025,304,695 | —- | C] () – C:\Users\Patty\Desktop\Jesus.psd
[2012/12/20 20:10:58 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n - Copy.jpg
[2012/12/20 17:38:08 | 000,055,838 | —- | C] () – C:\Users\Patty\Desktop\barnyard 2.jpg
[2012/12/16 17:48:14 | 000,043,348 | —- | C] () – C:\Users\Patty\Desktop\522720_442345169152921_1608320880_n.jpg
[2012/12/04 17:38:30 | 000,042,783 | —- | C] () – C:\Users\Patty\Desktop\205121_1016409768339_8587_n.jpg
[2012/12/04 17:36:39 | 000,057,326 | —- | C] () – C:\Users\Patty\Desktop\155500_10151225841494710_1105715689_n.jpg
[2012/12/03 16:16:38 | 002,159,251 | —- | C] () – C:\Users\Patty\Desktop\Untitled.hmk
[2012/12/02 14:07:07 | 000,045,022 | —- | C] () – C:\Users\Patty\Desktop\270105_477742762263912_289450700_n.jpg
[2012/09/25 09:31:50 | 000,054,464 | —- | C] () – C:\Windows\System32\drivers\psmounterex.sys
[2012/09/24 16:33:30 | 000,015,420 | —- | C] () – C:\Users\Patty\Desktop.sla
[2012/09/24 13:06:29 | 000,001,019 | —- | C] () – C:\Program Files\Scribus 1.4.1.lnk
[2012/07/20 13:27:03 | 000,027,520 | —- | C] () – C:\Users\Patty\AppData\Local\dt.dat
[2012/03/16 23:25:18 | 000,000,017 | —- | C] () – C:\Users\Patty\AppData\Local\resmon.resmoncfg
[2012/02/10 22:29:32 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2011/09/26 10:00:27 | 000,000,117 | —- | C] () – C:\Windows\restore.INI
[2011/06/10 05:34:52 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2011/04/17 18:19:47 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2011/02/11 17:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll

========== ZeroAccess Check ==========

[2009/07/13 23:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 20:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\erdnt\cache\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\erdnt\cache\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 20:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/10/28 01:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 00:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 07:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/07/13 20:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD3200AAKS-75L9A0 ATA Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Canon MP500Storage USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: TEAC USB HS-CF Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: TEAC USB HS-xD/SM USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: TEAC USB HS-MS Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 -
Interface type: USB
Media Type:
Model: TEAC USB HS-SD Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 298.00GB
Starting Offset: 105906176
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
My computer is running slow again, but in a different way. The page will turn gray and won't let me do anything, I have to do cntl del. It takes forever to open a website. I do have a router installed, but it did this before the router, but maybe not this often. This is why I hate routers, this is my third and I stick to my guns, still hate them. I had already run all those reports before I realized the post was closed, so they are in the post before this one.
Hi PattiChati,

No need to post the same log multiple times. We look for threads with zero replies so replying to your own thread before a helper has responded will lengthen the time it takes for us to respond.

Can you elaborate on the problem you are having? From what I understand you are browsing the web using a web browser - perhaps Internet Explorer? The page will turn gray while browsing, which sounds like your browser is freezing. Then you must press control+alt+delete to use task manager to close Internet Explorer?

I highly doubt your router is causing this problem. Routers are good devices and their built in firewalls help protect you from certain threats so don't get rid of it! :)

Since this subforum is specifically for dealing with malware infections, I need you to run a few scans to determine if malware is indeed causing your problems.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2012-12-30 23:44:42 —————————– 23:44:42.692 OS Version: Windows 6.1.7601 Service Pack 1 23:44:42.692 Number of processors: 2 586 0x170A 23:44:42.692 ComputerName: PATTI-PC UserName: Patty 23:44:44.081 Initialize success 23:45:37.178 AVAST engine defs: 12123001 23:46:02.013 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 23:46:02.029 Disk 0 Vendor: WDC_WD3200AAKS-75L9A0 01.03E01 Size: 305245MB BusType: 11 23:46:02.045 Disk 0 MBR read successfully 23:46:02.045 Disk 0 MBR scan 23:46:02.060 Disk 0 Windows 7 default MBR code 23:46:02.060 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 23:46:02.107 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 305143 MB offset 206848 23:46:02.138 Disk 0 scanning sectors +625139712 23:46:02.263 Disk 0 scanning C:\Windows\system32\drivers 23:46:15.788 Service scanning 23:46:28.861 Service MpKsl2c3e85da C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60889A6B-745E-424C-84C3-FB2E0A798C4E}\MpKsl2c3e85da.sys **LOCKED** 32 23:46:43.572 Modules scanning 23:46:50.670 Disk 0 trace - called modules: 23:46:50.701 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS PCIIDEX.SYS msahci.sys 23:46:50.717 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x865a5648] 23:46:50.717 3 CLASSPNP.SYS[8b7ba59e] -> nt!IofCallDriver -> [0x860ba918] 23:46:50.732 5 ACPI.sys[8b29f3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x86084908] 23:46:51.887 AVAST engine scan C:\Windows 23:46:53.883 AVAST engine scan C:\Windows\system32 23:50:09.523 AVAST engine scan C:\Windows\system32\drivers 23:50:24.936 AVAST engine scan C:\Users\Patty 23:51:18.897 Disk 0 MBR has been saved successfully to "C:\Users\Patty\Desktop\MBR.dat" 23:51:18.912 The log file has been saved successfully to "C:\Users\Patty\Desktop\aswMBR.txt"
You have most of what my computer isdoing. It goes gray on any screen, just did on my inbox screen. I use Firefox and have never had it go gray before or freeze up for that matter.
Hi Patti, DDS should have generated another log called DDS.txt. Would you please paste its contents in your next reply? If you cannot locate it, run DDS again, then paste the contents of the DDS.txt log. When your screen goes gray and Firefox freezes up, are you still able to use other programs?
Is this what you need because whenever it says there are two reports I only ever see one. When my screen goes gray nothing moves except the round circle. I was not able to copy and paste, so hopefully this will work for you. 📎dds.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI