All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk moved successfully.
C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_11959207.lnk moved successfully.
C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_61472742.lnk moved successfully.
C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_84347022.lnk moved successfully.
C:\Users\Sarah\AppData\Local\458v73p75ekmqk3f8msv2l moved successfully.
C:\ProgramData\458v73p75ekmqk3f8msv2l moved successfully.
C:\Users\Sarah\AppData\Local\sev68fq41yk1qbmnnfrx803860r6kgy265y01qxpow6 moved successfully.
C:\ProgramData\sev68fq41yk1qbmnnfrx803860r6kgy265y01qxpow6 moved successfully.
C:\Users\Sarah\AppData\Local\33tc3173v44sqee43uclq23c54s20c2j moved successfully.
C:\ProgramData\33tc3173v44sqee43uclq23c54s20c2j moved successfully.
C:\Windows\0711449drv.spi moved successfully.
C:\Users\Sarah\AppData\Roaming\78CD6 folder moved successfully.
C:\Users\Sarah\AppData\Roaming\bpppnGG5aQH6W7 folder moved successfully.
C:\Users\Sarah\AppData\Roaming\BTXXXqjYCekIVzN folder moved successfully.
C:\Users\Sarah\AppData\Roaming\CG4aQH6sKE9ZYwI folder moved successfully.
C:\Users\Sarah\AppData\Roaming\crzONxA0ciDp folder moved successfully.
C:\Users\Sarah\AppData\Roaming\D6E65 folder moved successfully.
C:\Users\Sarah\AppData\Roaming\DA1ivD2on4m folder moved successfully.
C:\Users\Sarah\AppData\Roaming\DAZ 3D\Studio4\Updater folder moved successfully.
C:\Users\Sarah\AppData\Roaming\DAZ 3D\Studio4\temp\textureConvert folder moved successfully.
C:\Users\Sarah\AppData\Roaming\DAZ 3D\Studio4\temp folder moved successfully.
C:\Users\Sarah\AppData\Roaming\DAZ 3D\Studio4\RunOnce\RunFirst folder moved successfully.
C:\Users\Sarah\AppData\Roaming\DAZ 3D\Studio4\RunOnce\MetaData folder moved successfully.
C:\Users\Sarah\AppData\Roaming\DAZ 3D\Studio4\RunOnce folder moved successfully.
C:\Users\Sarah\AppData\Roaming\DAZ 3D\Studio4 folder moved successfully.
C:\Users\Sarah\AppData\Roaming\DAZ 3D folder moved successfully.
C:\Users\Sarah\AppData\Roaming\delOBtzP0ciDoFp folder moved successfully.
C:\Users\Sarah\AppData\Roaming\gH5sQJ7dE8R9YjV folder moved successfully.
C:\Users\Sarah\AppData\Roaming\GxA0uvSib3n5Q6W folder moved successfully.
C:\Users\Sarah\AppData\Roaming\HUelIBty2F5ERXj folder moved successfully.
C:\Users\Sarah\AppData\Roaming\i0ucS2ibDpaHW7T folder moved successfully.
C:\Users\Sarah\AppData\Roaming\ksQJdEK8g9YwUlB folder moved successfully.
C:\Users\Sarah\AppData\Roaming\rKfRL9hTXjCkBzN folder moved successfully.
C:\Users\Sarah\AppData\Roaming\sddWWK77fR9 folder moved successfully.
C:\Users\Sarah\AppData\Roaming\twwjjUVVel folder moved successfully.
C:\Users\Sarah\AppData\Roaming\vRL9gTXqjCkVzNx folder moved successfully.
C:\Users\Sarah\AppData\Roaming\VTXqYCekIrOt folder moved successfully.
C:\Users\Sarah\AppData\Roaming\vVrlOBtxPySiDoF folder moved successfully.
C:\Users\Sarah\AppData\Roaming\yrzNyxASbpaJ8R9 folder moved successfully.
C:\Users\Sarah\AppData\Roaming\zjCeekIBrzOyxAv folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administer
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 87177 bytes
->Flash cache emptied: 56504 bytes
User: Administrator
->Temp folder emptied: 0 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
User: Sarah
->Temp folder emptied: 403396 bytes
->Temporary Internet Files folder emptied: 1813626 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 59450415 bytes
->Flash cache emptied: 21356 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6183156 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 65.00 mb
[EMPTYJAVA]
User: Administer
User: Administrator
User: All Users
User: Default
User: Default User
User: Public
User: Sarah
->Java cache emptied: 0 bytes
Total Java Files Cleaned = 0.00 mb
[EMPTYFLASH]
User: Administer
->Flash cache emptied: 0 bytes
User: Administrator
User: All Users
User: Default
User: Default User
User: Public
User: Sarah
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 01122012_161907
Files\Folders moved on Reboot...
File move failed. C:\windows\temp\dsiwmis.log scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Farbar Service Scanner
Ran by Sarah (administrator) on 12-01-2012 at 16:29:36
Microsoft Windows 7 Home Premium (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.
Windows Firewall:
=============
MpsSvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist.
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.
Firewall Disabled Policy:
==================
System Restore:
============
SDRSVC Service is not running. Checking service configuration:
The start type of SDRSVC service is OK.
The ImagePath of SDRSVC service is OK.
The ServiceDll of SDRSVC service is OK.
VSS Service is not running. Checking service configuration:
The start type of VSS service is OK.
The ImagePath of VSS service is OK.
System Restore Disabled Policy:
========================
Security Center:
============
Windows Update:
===========
File Check:
========
C:\windows\system32\nsisvc.dll => MD5 is legit
C:\windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\windows\system32\dhcpcore.dll => MD5 is legit
C:\windows\system32\Drivers\afd.sys => MD5 is legit
C:\windows\system32\Drivers\tdx.sys => MD5 is legit
C:\windows\system32\Drivers\tcpip.sys
[2012-01-02 14:38] - [2011-09-29 09:43] - 1285488 ____A (Microsoft Corporation) 56C198AC82EFA622DD93E9E43575F79C
C:\windows\system32\dnsrslvr.dll
[2012-01-02 14:37] - [2011-03-02 23:29] - 0132608 ____A (Microsoft Corporation) B15BE77A2BACF9C3177D27518AFE26A9
C:\windows\system32\mpssvc.dll
[2009-07-13 17:53] - [2009-07-13 19:15] - 0565760 ____A (Microsoft Corporation) 5CD996CECF45CBC3E8D109C86B82D69E
C:\windows\system32\bfe.dll
[2009-07-13 17:54] - [2009-07-13 19:14] - 0493568 ____A (Microsoft Corporation) 85AC71C045CEB054ED48A7841AAE0C11
C:\windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\windows\system32\SDRSVC.dll
[2009-07-13 17:23] - [2009-07-13 19:16] - 0125952 ____A (Microsoft Corporation) 5FD90ABDBFAEE85986802622CBB03446
C:\windows\system32\vssvc.exe
[2009-07-13 17:24] - [2009-07-13 19:14] - 1025536 ____A (Microsoft Corporation) 7EA2BCD94D9CFAF4C556F5CC94532A6C
C:\windows\system32\wscsvc.dll
[2012-01-02 14:26] - [2010-12-20 23:38] - 0073728 ____A (Microsoft Corporation) A661A76333057B383A06E65F0073222F
C:\windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\windows\system32\wuaueng.dll
[2009-07-13 18:15] - [2009-07-13 19:16] - 1912832 ____A (Microsoft Corporation) A33408CC036F9C08142B11BE5E93F0A1
C:\windows\system32\qmgr.dll
[2009-07-13 17:30] - [2009-07-13 19:16] - 0589312 ____A (Microsoft Corporation) 53F476476F55A27F580661BDE09C4EC4
C:\windows\system32\es.dll => MD5 is legit
C:\windows\system32\cryptsvc.dll
[2009-07-13 17:33] - [2009-07-13 19:15] - 0135680 ____A (Microsoft Corporation) 9C231178CE4FB385F4B54B0A9080B8A4
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
**** End of log ****
Farbar Service Scanner
Ran by Sarah (administrator) on 13-01-2012 at 16:13:21
Microsoft Windows 7 Home Premium (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
SDRSVC Service is not running. Checking service configuration:
The start type of SDRSVC service is OK.
The ImagePath of SDRSVC service is OK.
The ServiceDll of SDRSVC service is OK.
VSS Service is not running. Checking service configuration:
The start type of VSS service is OK.
The ImagePath of VSS service is OK.
System Restore Disabled Policy:
========================
Security Center:
============
Windows Update:
===========
File Check:
========
C:\windows\system32\nsisvc.dll => MD5 is legit
C:\windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\windows\system32\dhcpcore.dll => MD5 is legit
C:\windows\system32\Drivers\afd.sys => MD5 is legit
C:\windows\system32\Drivers\tdx.sys => MD5 is legit
C:\windows\system32\Drivers\tcpip.sys
[2012-01-02 14:38] - [2011-09-29 09:43] - 1285488 ____A (Microsoft Corporation) 56C198AC82EFA622DD93E9E43575F79C
C:\windows\system32\dnsrslvr.dll
[2012-01-02 14:37] - [2011-03-02 23:29] - 0132608 ____A (Microsoft Corporation) B15BE77A2BACF9C3177D27518AFE26A9
C:\windows\system32\mpssvc.dll
[2009-07-13 17:53] - [2009-07-13 19:15] - 0565760 ____A (Microsoft Corporation) 5CD996CECF45CBC3E8D109C86B82D69E
C:\windows\system32\bfe.dll
[2009-07-13 17:54] - [2009-07-13 19:14] - 0493568 ____A (Microsoft Corporation) 85AC71C045CEB054ED48A7841AAE0C11
C:\windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\windows\system32\SDRSVC.dll
[2009-07-13 17:23] - [2009-07-13 19:16] - 0125952 ____A (Microsoft Corporation) 5FD90ABDBFAEE85986802622CBB03446
C:\windows\system32\vssvc.exe
[2009-07-13 17:24] - [2009-07-13 19:14] - 1025536 ____A (Microsoft Corporation) 7EA2BCD94D9CFAF4C556F5CC94532A6C
C:\windows\system32\wscsvc.dll
[2012-01-02 14:26] - [2010-12-20 23:38] - 0073728 ____A (Microsoft Corporation) A661A76333057B383A06E65F0073222F
C:\windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\windows\system32\wuaueng.dll
[2009-07-13 18:15] - [2009-07-13 19:16] - 1912832 ____A (Microsoft Corporation) A33408CC036F9C08142B11BE5E93F0A1
C:\windows\system32\qmgr.dll
[2009-07-13 17:30] - [2009-07-13 19:16] - 0589312 ____A (Microsoft Corporation) 53F476476F55A27F580661BDE09C4EC4
C:\windows\system32\es.dll => MD5 is legit
C:\windows\system32\cryptsvc.dll
[2009-07-13 17:33] - [2009-07-13 19:15] - 0135680 ____A (Microsoft Corporation) 9C231178CE4FB385F4B54B0A9080B8A4
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
**** End of log ****
:OTL
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[emptyjava]
[CLEARALLRESTOREPOINTS]
[Reboot]
All processes killed
========== OTL ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: Administer
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Administrator
->Temp folder emptied: 0 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
User: Sarah
->Temp folder emptied: 285407 bytes
->Temporary Internet Files folder emptied: 5619132 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 49995418 bytes
->Flash cache emptied: 456 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 32456183 bytes
RecycleBin emptied: 4548 bytes
Total Files Cleaned = 84.00 mb
[EMPTYFLASH]
User: Administer
->Flash cache emptied: 0 bytes
User: Administrator
User: All Users
User: Default
User: Default User
User: Public
User: Sarah
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0.00 mb
[EMPTYJAVA]
User: Administer
User: Administrator
User: All Users
User: Default
User: Default User
User: Public
User: Sarah
->Java cache emptied: 0 bytes
Total Java Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 01132012_220310
Files\Folders moved on Reboot...
File move failed. C:\windows\temp\dsiwmis.log scheduled to be moved on reboot.
Registry entries deleted on Reboot...