(thank you again for all this help)
MSE reinstalled, updated
MBAM surprisingly clean
OTL Extras is NOT clean
------------------------------------------------------------------------------------------
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.02.01
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Kelley :: KELLEY-PC [administrator]
8/1/2012 9:47:10 PM
mbam-log-2012-08-01 (21-47-10).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 193543
Time elapsed: 10 minute(s), 46 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
-------------------------------------------------------------------------------------------------------------
OTL.txt
------------------------------------------------------------------------------------------------------------
OTL logfile created on: 8/1/2012 10:05:10 PM - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Kelley\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.67 Gb Available Physical Memory | 55.99% Memory free
6.17 Gb Paging File | 4.78 Gb Available in Paging File | 77.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.58 Gb Total Space | 114.74 Gb Free Space | 52.02% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 4.13 Gb Free Space | 42.26% Space Free | Partition Type: NTFS
Computer Name: KELLEY-PC | User Name: Kelley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/08/01 21:49:53 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Kelley\Desktop\OTL.exe
PRC - [2012/07/30 22:22:30 | 000,686,792 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_3_300_268_ActiveX.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/02/28 21:14:46 | 000,307,824 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2009/10/07 12:36:20 | 000,263,520 | ---- | M] (AT&T) -- C:\Program Files\AT&T Network Client\NetClientSvc.exe
PRC - [2009/10/07 12:36:18 | 000,619,872 | ---- | M] (AT&T) -- C:\Program Files\AT&T Network Client\netcfgsvr.exe
PRC - [2009/09/26 00:32:18 | 000,189,736 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/02/18 21:57:47 | 000,266,240 | ---- | M] () -- C:\Windows\System32\CSHelper.exe
PRC - [2008/08/14 01:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/03/04 01:05:24 | 000,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\OEM02Mon.exe
PRC - [2008/02/15 18:25:34 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe
PRC - [2008/01/28 18:45:58 | 000,081,920 | ---- | M] (Primax Electronics Ltd.) -- C:\Windows\System32\ico.exe
PRC - [2007/11/12 07:07:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEstSrv.exe
PRC - [2007/03/21 15:00:04 | 000,355,096 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/03/21 15:00:00 | 000,174,872 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/02/09 16:00:54 | 000,262,144 | ---- | M] (LITE-ON TECHNOLOGY CORP.) -- C:\Program Files\Lenovo\Productivity Keyboard\Skdaemon.exe
========== Modules (No Company Name) ==========
MOD - [2012/06/17 21:59:56 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012/05/10 15:16:23 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/10 14:52:48 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/10 14:52:35 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2008/07/03 09:42:04 | 000,055,808 | ---- | M] () -- C:\Windows\System32\bcmwlrmt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe -- (SessionLauncher)
SRV - [2012/07/03 13:19:28 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2009/10/07 12:36:20 | 000,263,520 | ---- | M] (AT&T) [Auto | Running] -- C:\Program Files\AT&T Network Client\NetClientSvc.exe -- (NetClientSvc)
SRV - [2009/10/07 12:36:18 | 000,619,872 | ---- | M] (AT&T) [Auto | Running] -- C:\Program Files\AT&T Network Client\netcfgsvr.exe -- (NetCfgSvr)
SRV - [2009/09/26 00:32:18 | 000,189,736 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service)
SRV - [2009/02/18 21:57:47 | 000,266,240 | ---- | M] () [Auto | Running] -- C:\Windows\System32\CSHelper.exe -- (CSHelper)
SRV - [2008/08/14 01:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2008/05/14 12:32:18 | 000,309,744 | ---- | M] (Sonic Solutions) [Disabled | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe -- (RoxLiveShare10)
SRV - [2008/05/14 12:32:10 | 000,166,384 | ---- | M] (Sonic Solutions) [Disabled | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe -- (RoxWatch10)
SRV - [2008/05/14 12:31:38 | 001,120,752 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
SRV - [2008/02/15 18:25:34 | 000,102,400 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe -- (STacSV)
SRV - [2008/01/20 22:25:27 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lpdsvc.dll -- (LPDSVC)
SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/12 07:07:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEstSrv.exe -- (AESTFilters)
SRV - [2007/05/31 10:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 10:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2007/03/21 15:00:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2012/03/20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2009/10/07 12:40:44 | 000,219,776 | R--- | M] (AT&T) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agnfilt.sys -- (agnfilt)
DRV - [2008/12/09 12:13:08 | 000,011,392 | ---- | M] (AT&T) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avpnnic.sys -- (avpnnic)
DRV - [2008/07/03 09:41:54 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY)
DRV - [2008/06/23 08:45:44 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2008/05/04 05:25:24 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008/03/06 03:58:44 | 000,111,616 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV - [2008/03/04 01:05:34 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Vfx.sys -- (OEM02Vfx)
DRV - [2008/03/04 01:05:18 | 000,235,648 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Dev.sys -- (OEM02Dev)
DRV - [2008/02/15 18:27:02 | 000,330,752 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2008/01/20 22:23:25 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2008/01/20 22:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2007/09/06 12:35:16 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/09/06 12:35:14 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/09/06 12:35:12 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/02 03:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006/10/23 14:56:56 | 000,016,192 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PELUSBLF.SYS -- (pelusblf)
DRV - [2006/10/23 14:55:26 | 000,023,360 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PELMOUSE.SYS -- (pelmouse)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={sea...&oe={outputEncoding}&sourceid=ie7&rlz=1I7DMUS
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2075852643-1379254224-2315044420-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://my.yahoo.com/
IE - HKU\S-1-5-21-2075852643-1379254224-2315044420-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2075852643-1379254224-2315044420-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-2075852643-1379254224-2315044420-1000\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" =
http://127.0.0.1:4664/search&s=d9InZprGHecCXNHmXC_cpvj4K5o?q={searchTerms}
IE - HKU\S-1-5-21-2075852643-1379254224-2315044420-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/07/01 09:19:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2011/08/18 20:17:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kelley\AppData\Roaming\Mozilla\Extensions
[2010/06/21 18:54:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kelley\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/01/02 12:21:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kelley\AppData\Roaming\Mozilla\Sunbird\Profiles\2w1w70u5.default\extensions
[2011/08/18 20:17:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009/01/02 13:14:34 | 000,000,000 | ---D | M] (No name found) -- C:\PROGRAM FILES\MOZILLA SUNBIRD\EXTENSIONS\{E2FDA1A4-762B-4020-B5AD-A41DF1933103}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA SUNBIRD\EXTENSIONS\
CALENDAR-TIMEZONES@MOZILLA.ORG
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA SUNBIRD\EXTENSIONS\
TALKBACK@MOZILLA.ORG
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage:
http://my.myway.com/
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Kelley\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Kelley\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Facebook = C:\Users\Kelley\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm\1_0\
CHR - Extension: Google Search = C:\Users\Kelley\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Nice Translator = C:\Users\Kelley\AppData\Local\Google\Chrome\User Data\Default\Extensions\echdnikijbegadnenjfmhfjflclkjcbp\3_0\
CHR - Extension: AdBlock = C:\Users\Kelley\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.22_0\
CHR - Extension: Google Calendar (by Google) = C:\Users\Kelley\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich\0.7_0\
CHR - Extension: Google Mail Checker = C:\Users\Kelley\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\3.2_0\
CHR - Extension: Gmail = C:\Users\Kelley\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/31 22:10:47 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [Password Keychain] C:\Program Files\Password Keychain\Passkeychain.exe (NFX Technologies)
O4 - HKLM..\Run: [SKDaemon.exe] C:\Program Files\Lenovo\Productivity Keyboard\Skdaemon.exe (LITE-ON TECHNOLOGY CORP.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2075852643-1379254224-2315044420-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2075852643-1379254224-2315044420-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O15 - HKU\S-1-5-21-2075852643-1379254224-2315044420-1000\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {A6616B31-4860-41E2-98E3-CA7649AF172F}
file:///E:/launch.ocx (Launch Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.251.129 167.206.251.130 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6455F280-B22C-40DA-BE2E-BEF3680BBCA5}: NameServer = 9.0.2.1,9.0.3.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9528A93C-3D6E-4198-B32E-06D0E5985BF3}: DhcpNameServer = 167.206.251.129 167.206.251.130 192.168.1.1
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Kelley\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Kelley\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/08/01 21:49:40 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Users\Kelley\Desktop\OTL.exe
[2012/08/01 21:46:22 | 000,000,000 | ---D | C] -- C:\Users\Kelley\AppData\Roaming\Malwarebytes
[2012/08/01 21:45:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/01 21:45:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/01 21:45:35 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/08/01 21:45:35 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/08/01 21:39:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/08/01 21:32:46 | 010,652,120 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Kelley\Desktop\mbam-setup-1.62.0.1300.exe
[2012/07/31 23:27:48 | 000,000,000 | ---D | C] -- C:\FRST
[2012/07/31 22:20:07 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/07/31 22:20:07 | 000,000,000 | ---D | C] -- C:\Users\Kelley\AppData\Local\temp
[2012/07/31 22:11:02 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/07/31 22:01:01 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/07/31 22:01:01 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/07/31 22:01:01 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/07/31 22:00:58 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/07/31 22:00:55 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/31 22:00:47 | 000,000,000 | R--D | C] -- C:\Users\Kelley\Videos
[2012/07/31 22:00:36 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/07/31 21:57:39 | 004,721,982 | R--- | C] (Swearware) -- C:\Users\Kelley\Desktop\ComboFix.exe
[2012/07/30 22:43:36 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2012/07/30 22:42:19 | 000,000,000 | ---D | C] -- C:\Users\Kelley\AppData\Roaming\xsecva
[2012/07/19 20:41:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Cisco Systems
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/01 21:49:53 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Kelley\Desktop\OTL.exe
[2012/08/01 21:39:41 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/08/01 21:39:30 | 000,606,880 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/08/01 21:39:30 | 000,105,448 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/08/01 21:33:04 | 010,652,120 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Kelley\Desktop\mbam-setup-1.62.0.1300.exe
[2012/08/01 21:27:12 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/01 21:27:12 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/01 21:26:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/31 22:52:25 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/07/31 22:47:54 | 000,000,161 | ---- | M] () -- C:\Users\Kelley\Desktop\YAS (yet another sirefef).url
[2012/07/31 22:10:47 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/07/31 21:57:33 | 004,721,982 | R--- | M] (Swearware) -- C:\Users\Kelley\Desktop\ComboFix.exe
[2012/07/29 22:42:14 | 000,069,163 | ---- | M] () -- C:\Users\Kelley\Documents\HCRA submission.pdf
[2012/07/28 21:38:34 | 000,004,597 | ---- | M] () -- C:\Users\Kelley\Documents\Greg's Credit card charges.pdf
[2012/07/28 20:59:34 | 000,152,059 | ---- | M] () -- C:\Users\Kelley\Documents\Optimum bill.pdf
[2012/07/18 22:00:11 | 000,086,070 | ---- | M] () -- C:\Users\Kelley\Documents\Panera.pdf
[2012/07/17 22:34:51 | 000,002,193 | ---- | M] () -- C:\Users\Kelley\Documents\Jake dental.pdf
[2012/07/17 22:33:10 | 000,334,154 | ---- | M] () -- C:\Users\Kelley\Documents\Greg dental.pdf
[2012/07/17 19:41:42 | 000,002,401 | ---- | M] () -- C:\Users\Kelley\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2012/07/13 22:28:15 | 000,002,377 | ---- | M] () -- C:\Users\Kelley\Desktop\Skype.lnk
[2012/07/11 22:21:10 | 000,436,152 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/07/03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/08/01 21:39:33 | 000,001,828 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/07/31 22:47:54 | 000,000,161 | ---- | C] () -- C:\Users\Kelley\Desktop\YAS (yet another sirefef).url
[2012/07/31 22:01:01 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/07/31 22:01:01 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/07/31 22:01:01 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/07/31 22:01:01 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/07/31 22:01:01 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/07/29 22:42:12 | 000,069,163 | ---- | C] () -- C:\Users\Kelley\Documents\HCRA submission.pdf
[2012/07/28 21:38:33 | 000,004,597 | ---- | C] () -- C:\Users\Kelley\Documents\Greg's Credit card charges.pdf
[2012/07/28 20:59:28 | 000,152,059 | ---- | C] () -- C:\Users\Kelley\Documents\Optimum bill.pdf
[2012/07/18 22:00:10 | 000,086,070 | ---- | C] () -- C:\Users\Kelley\Documents\Panera.pdf
[2012/07/17 22:34:28 | 000,002,193 | ---- | C] () -- C:\Users\Kelley\Documents\Jake dental.pdf
[2012/07/17 22:32:54 | 000,334,154 | ---- | C] () -- C:\Users\Kelley\Documents\Greg dental.pdf
[2011/08/18 20:21:29 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2010/11/10 21:31:58 | 000,000,127 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2010/06/21 19:17:23 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/05/31 11:06:28 | 000,430,256 | ---- | C] () -- C:\Users\Kelley\AppData\Local\rx_image32.Cache
[2010/05/31 11:06:27 | 000,012,648 | ---- | C] () -- C:\Users\Kelley\AppData\Local\rx_audio.Cache
[2009/10/07 12:05:00 | 000,144,236 | ---- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2009/07/04 13:07:06 | 000,024,206 | ---- | C] () -- C:\Users\Kelley\AppData\Roaming\UserTile.png
[2009/02/19 20:16:12 | 000,000,680 | ---- | C] () -- C:\Users\Kelley\AppData\Local\d3d9caps.dat
[2008/12/28 13:47:10 | 000,413,696 | ---- | C] () -- C:\Users\Kelley\AppData\Local\filesync.metadata
[2008/12/11 21:24:50 | 000,044,544 | ---- | C] () -- C:\Users\Kelley\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== LOP Check ==========
[2009/02/06 23:17:00 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\.purple
[2009/01/01 16:24:49 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\acccore
[2011/08/18 19:32:27 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\Canon
[2010/01/18 23:59:17 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\enchant
[2009/10/08 21:10:29 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\iolo
[2009/02/19 23:54:29 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\LAIM
[2010/01/23 13:35:17 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\Leadertech
[2008/12/12 01:20:53 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\OpenOffice.org
[2009/04/09 00:15:28 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\Opera
[2009/07/04 13:07:06 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\PeerNetworking
[2008/12/12 15:04:21 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\PlayFirst
[2010/11/13 23:20:49 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\Saore
[2010/02/10 17:47:08 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\Sierra Wireless
[2012/03/10 21:24:28 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\TaxCut
[2010/06/21 18:54:57 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\Thunderbird
[2010/08/10 23:41:15 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\WeatherWatcher
[2012/07/30 23:35:36 | 000,000,000 | ---D | M] -- C:\Users\Kelley\AppData\Roaming\xsecva
[2012/07/31 22:52:25 | 000,032,622 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >