This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot play any media [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Michael, At the start I couldn't get media to work on either Firefox or IE and, as we've been talking to each other, I've only been checking on Firefox - as it's my default browser. Your last post prompted me to try IE again…..and media is now working!! Out of curiosity, I've just downloaded Google Chrome and that's working too. I'm happy enough with that, tbh! Thank you thank you thank you Fiona x.
Good to hear. Let's see if we can get it working in Firefox.

  • Launch RealPlayer
  • Click the RealPlayer icon in the upper left corner of the window and choose Preferences.
  • Choose Download & Recording from the left hand panel
  • Uncheck "Enable Web Download & Recording for these installed browsers"
  • Click OK and close RealPlayer
  • Restart Firefox
Here's the OTL log…

OTL logfile created on: 17/09/2012 17:00:56 - Run 4
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\Dougie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.80 Gb Total Physical Memory | 2.36 Gb Available Physical Memory | 62.11% Memory free
7.60 Gb Paging File | 5.77 Gb Available in Paging File | 75.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.01 Gb Total Space | 165.10 Gb Free Space | 36.61% Space Free | Partition Type: NTFS

Computer Name: DOUGIE-PC | User Name: Dougie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/10 00:22:46 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\Dougie\Desktop\OTL(3).exe
PRC - [2012/07/27 21:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/05/30 09:46:49 | 000,296,056 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\real\realplayer\Update\realsched.exe
PRC - [2012/02/23 13:30:40 | 000,059,240 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
PRC - [2011/09/06 18:29:20 | 004,259,648 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
PRC - [2011/08/18 16:05:54 | 002,751,808 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
PRC - [2011/08/18 16:05:46 | 001,692,480 | —- | M] (SoftThinks SAS) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2011/08/01 18:56:48 | 000,460,096 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2011/07/29 00:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/04/28 13:48:00 | 000,079,872 | —- | M] (SanDisk Corporation) – C:\Users\Dougie\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2011/02/25 11:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2010/03/17 22:37:16 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/17 22:34:12 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/12/23 23:39:04 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2009/12/23 23:39:02 | 000,284,696 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2009/10/15 09:10:28 | 000,498,160 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2009/06/24 22:21:38 | 000,409,744 | —- | M] (Creative Technology Ltd) – C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
PRC - [2009/06/09 15:11:14 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/16 07:53:21 | 014,340,608 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
MOD - [2012/06/16 07:52:01 | 012,436,480 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012/06/16 07:51:27 | 001,591,808 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012/06/16 07:51:08 | 012,237,824 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012/05/11 08:59:09 | 002,297,856 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
MOD - [2012/05/10 21:47:47 | 000,368,128 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
MOD - [2012/05/10 21:46:40 | 000,771,584 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/10 21:43:26 | 003,347,968 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012/05/10 21:43:03 | 005,452,800 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/05/10 21:42:47 | 000,971,264 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/05/10 21:42:44 | 007,967,232 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/05/10 21:42:20 | 011,492,864 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2011/08/18 16:05:54 | 002,751,808 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
MOD - [2011/08/01 18:55:50 | 000,079,168 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
MOD - [2011/08/01 18:55:18 | 000,132,416 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
MOD - [2011/08/01 18:54:46 | 001,123,648 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll
MOD - [2011/07/29 00:09:42 | 000,096,112 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/29 00:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/06/24 22:56:36 | 000,087,328 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/10/15 09:10:28 | 000,498,160 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe


========== Services (SafeList) ==========

SRV:64bit: - [2012/08/24 23:46:28 | 000,383,608 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV:64bit: - [2012/06/22 07:38:04 | 000,177,144 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Windows\SysNative\mfevtps.exe – (mfevtp)
SRV:64bit: - [2012/06/22 07:34:52 | 000,218,320 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe – (mfefire)
SRV:64bit: - [2012/06/22 07:33:12 | 000,237,920 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McProxy)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McNASvc)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/03/17 22:29:08 | 000,089,600 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_58afa5ca50c7b5e7\AESTSr64.exe – (AESTFilters)
SRV:64bit: - [2010/03/17 22:27:52 | 000,244,736 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_58afa5ca50c7b5e7\stacsv64.exe – (STacSV)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/06/09 15:11:14 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2012/09/14 09:26:49 | 000,250,568 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/09 22:54:40 | 000,114,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/07/27 21:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/08/18 16:05:46 | 001,692,480 | —- | M] (SoftThinks SAS) [Auto | Running] – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe – (SftService)
SRV - [2011/02/28 19:44:14 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 11:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2010/09/30 22:44:46 | 000,246,520 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [2010/04/13 20:11:18 | 000,231,224 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe – (MOBKbackup)
SRV - [2010/03/18 14:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/17 22:37:16 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS)
SRV - [2010/03/17 22:34:12 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS)
SRV - [2010/03/17 22:29:08 | 000,089,600 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_58afa5ca50c7b5e7\AESTSr64.exe – (AESTFilters)
SRV - [2010/03/17 22:27:52 | 000,244,736 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_58afa5ca50c7b5e7\STacSV64.exe – (STacSV)
SRV - [2009/12/23 23:39:04 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc)
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/06/22 07:40:58 | 000,069,672 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\cfwids.sys – (cfwids)
DRV:64bit: - [2012/06/22 07:38:16 | 000,335,784 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfewfpk.sys – (mfewfpk)
DRV:64bit: - [2012/06/22 07:36:54 | 000,106,112 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mferkdet.sys – (mferkdet)
DRV:64bit: - [2012/06/22 07:36:12 | 000,752,672 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfehidk.sys – (mfehidk)
DRV:64bit: - [2012/06/22 07:35:02 | 000,513,456 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfefirek.sys – (mfefirek)
DRV:64bit: - [2012/06/22 07:34:22 | 000,300,392 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeavfk.sys – (mfeavfk)
DRV:64bit: - [2012/06/22 07:34:00 | 000,169,320 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfeapfk.sys – (mfeapfk)
DRV:64bit: - [2012/06/15 12:04:12 | 000,073,096 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\McPvDrv.sys – (McPvDrv)
DRV:64bit: - [2012/04/20 16:40:58 | 000,196,440 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HipShieldK.sys – (HipShieldK)
DRV:64bit: - [2012/03/08 18:40:52 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/15 12:01:50 | 000,052,736 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/01/10 23:28:18 | 012,311,904 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2011/11/29 03:28:28 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/04/13 20:10:24 | 000,066,040 | —- | M] (Mozy, Inc.) [File_System | System | Running] – C:\Windows\SysNative\drivers\MOBK.sys – (MOBKFilter)
DRV:64bit: - [2010/03/17 22:44:44 | 000,301,104 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2010/03/17 22:41:48 | 000,325,152 | —- | M] (Realtek ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010/03/17 22:33:06 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64)
DRV:64bit: - [2010/03/17 22:29:52 | 000,232,480 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2010/03/17 22:27:14 | 000,505,856 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\stwrt64.sys – (STHDA)
DRV:64bit: - [2010/02/27 01:32:12 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2010/02/03 15:38:30 | 000,271,872 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2010/02/03 07:13:08 | 000,020,984 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\bcmvwl64.sys – (BcmVWL)
DRV:64bit: - [2010/02/03 07:13:06 | 003,058,168 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2009/12/17 16:42:08 | 000,538,136 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/15 19:06:42 | 000,172,704 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CtClsFlt.sys – (CtClsFlt)
DRV:64bit: - [2009/06/10 21:35:33 | 000,389,120 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 23:17:08 | 000,034,152 | R— | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2007/08/08 12:10:24 | 000,112,512 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ewusbmdm.sys – (hwdatacard)
DRV:64bit: - [2006/11/01 17:51:00 | 000,151,656 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\WimFltr.sys – (WimFltr)
DRV - [2009/07/14 02:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000\..\SearchScopes,DefaultScope = {A257890B-F366-4F14-BF9E-A6ED13FCBCDC}
IE - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000\..\SearchScopes\{A257890B-F366-4F14-BF9E-A6ED13FCBCDC}: "URL" = http://www.google.com/search?q={searchTerms}
IE - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=WLETDF&PC;=WLEM&q;="
FF - prefs.js..browser.search.order.2: ""
FF - prefs.js..browser.search.param.yahoo-fr: "w3i&type;=W3i_DS,157,0_0,Search,20110418,17042,0,16,0"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://uk.search.yahoo.com/?fr=w3i&type;=W3i_SP,205,0_0,StartPage,20110418,17045,0,16,0"
FF - prefs.js..extensions.enabledAddons: {4ED1F68A-5463-4931-9384-8FFF5ED91D92}:3.4.1.195
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.20.00
FF - prefs.js..extensions.enabledItems: {E4E6BF2A-1667-11DF-A01F-1F9655D89593}:4.0
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=mcafee&p;="
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/07/08 12:17:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/09/15 12:56:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/15 17:19:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/14 09:24:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\McAfee\MSK [2012/09/15 12:46:19 | 000,000,000 | —D | M]

[2010/09/24 20:23:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Dougie\AppData\Roaming\Mozilla\Extensions
[2012/09/13 10:54:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions
[2012/07/08 12:19:31 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/07/08 12:19:32 | 000,000,000 | —D | M] (Simppull Toolbar) – C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}
[2011/04/15 18:14:00 | 000,001,832 | —- | M] () – C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\searchplugins\bing.xml
[2012/09/15 17:19:02 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/07/10 01:03:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/15 12:56:00 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2012/09/06 02:27:05 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009/11/06 16:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2009/11/06 16:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/05/30 09:47:24 | 000,129,144 | —- | M] (RealPlayer) – C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
[2012/09/06 02:26:22 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/15 17:57:44 | 000,002,027 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/09/06 02:26:22 | 000,002,253 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.89\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.230.5 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U23 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.51204.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Dougie\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Dougie\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Dougie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\

O1 HOSTS File: ([2012/09/12 22:40:57 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Simppull Toolbar) - {627af46b-2076-42ae-a2fd-8428734d3e74} - C:\Program Files (x86)\simppulltoolbar\simppulldx.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Updater For Simppull Toolbar) - {C4B8BAB4-1667-11DF-A242-BA9455D89593} - C:\Program Files (x86)\simppulltoolbar\auxi\simppulltoolbAu.dll File not found
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Simppull Toolbar) - {627af46b-2076-42ae-a2fd-8428734d3e74} - C:\Program Files (x86)\simppulltoolbar\simppulldx.dll File not found
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000..\Run: [SansaDispatch] C:\Users\Dougie\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Dougie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk = File not found
O4 - Startup: C:\Users\Dougie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1272418825-2152305279-3347187607-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.22.22 192.168.22.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6EF6AB61-581E-4C8B-B495-6D1E4D0316F6}: DhcpNameServer = 192.168.22.22 192.168.22.23
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/17 12:26:46 | 000,000,000 | —D | C] – C:\Users\Dougie\Documents\leftover 2nd lects
[2012/09/15 12:46:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfeeMOBK
[2012/09/15 12:46:40 | 000,000,000 | –SD | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Online Backup
[2012/09/15 12:46:39 | 000,066,040 | —- | C] (Mozy, Inc.) – C:\windows\SysNative\drivers\MOBK.sys
[2012/09/15 12:46:37 | 000,196,440 | —- | C] (McAfee, Inc.) – C:\windows\SysNative\drivers\HipShieldK.sys
[2012/09/15 12:46:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee Online Backup
[2012/09/15 12:46:25 | 000,073,096 | —- | C] (McAfee, Inc.) – C:\windows\SysNative\drivers\McPvDrv.sys
[2012/09/15 12:46:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/09/15 12:46:09 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\McAfee Anti-Theft
[2012/09/15 12:45:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee.com
[2012/09/15 12:45:07 | 000,010,288 | —- | C] (McAfee, Inc.) – C:\windows\SysNative\drivers\mfeclnk.sys
[2012/09/15 12:45:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\McAfee
[2012/09/15 12:45:00 | 000,513,456 | —- | C] (McAfee, Inc.) – C:\windows\SysNative\drivers\mfefirek.sys
[2012/09/15 12:45:00 | 000,300,392 | —- | C] (McAfee, Inc.) – C:\windows\SysNative\drivers\mfeavfk.sys
[2012/09/15 12:45:00 | 000,106,112 | —- | C] (McAfee, Inc.) – C:\windows\SysNative\drivers\mferkdet.sys
[2012/09/15 12:45:00 | 000,069,672 | —- | C] (McAfee, Inc.) – C:\windows\SysNative\drivers\cfwids.sys
[2012/09/15 12:44:49 | 000,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2012/09/15 12:44:39 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2012/09/15 12:44:38 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2012/09/15 12:44:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee
[2012/09/15 12:28:55 | 000,177,144 | —- | C] (McAfee, Inc.) – C:\windows\SysNative\mfevtps.exe
[2012/09/15 12:24:26 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/09/15 11:35:59 | 003,178,400 | —- | C] (McAfee, Inc.) – C:\Users\Dougie\Desktop\MCPR.exe
[2012/09/14 09:49:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/09/12 22:56:34 | 000,000,000 | —D | C] – C:\windows\temp
[2012/09/12 22:41:07 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/09/12 22:04:33 | 000,518,144 | —- | C] (SteelWerX) – C:\windows\SWREG.exe
[2012/09/12 22:04:33 | 000,406,528 | —- | C] (SteelWerX) – C:\windows\SWSC.exe
[2012/09/12 22:04:33 | 000,060,416 | —- | C] (NirSoft) – C:\windows\NIRCMD.exe
[2012/09/12 22:04:18 | 000,000,000 | —D | C] – C:\ComboFix
[2012/09/12 21:54:24 | 000,000,000 | —D | C] – C:\Qoobox
[2012/09/12 21:53:39 | 000,000,000 | —D | C] – C:\windows\erdnt
[2012/09/12 19:55:26 | 004,749,988 | R— | C] (Swearware) – C:\Users\Dougie\Desktop\ComboFix.exe
[2012/09/12 19:48:06 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{E8EAFED6-57FD-4E6D-85F2-8BA7B9232862}
[2012/09/11 14:17:35 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{FA6823D5-4BF1-4B7D-8DAA-C7E56620D940}
[2012/09/10 22:06:26 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{4D9FA01B-2A07-4253-B215-2C08597E8958}
[2012/09/10 00:22:35 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Users\Dougie\Desktop\OTL(3).exe
[2012/09/10 00:19:12 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{0BF98022-D00D-4E17-87A6-AED1E36FF6A4}
[2012/09/10 00:07:41 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Dougie\Desktop\aswMBR(1).exe
[2012/09/09 00:10:24 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{346A4771-D13B-4ABD-8031-863626C82740}
[2012/08/22 14:05:33 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{9D882526-22AD-4272-846D-5230DC32ED9F}

========== Files - Modified Within 30 Days ==========

[2012/09/17 17:31:04 | 000,000,898 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/17 17:31:01 | 000,000,506 | —- | M] () – C:\windows\tasks\SystemToolsDailyTest.job
[2012/09/17 16:59:19 | 000,013,872 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/17 16:59:19 | 000,013,872 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/17 16:57:09 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/09/17 16:56:59 | 000,001,830 | —- | M] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2012/09/17 16:51:43 | 000,000,894 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/17 16:51:12 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/09/17 16:51:01 | 3062,804,480 | -HS- | M] () – C:\hiberfil.sys
[2012/09/17 16:37:53 | 000,726,444 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2012/09/17 16:37:53 | 000,628,874 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2012/09/17 16:37:53 | 000,111,026 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2012/09/15 17:42:45 | 000,002,346 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/09/15 17:42:45 | 000,002,245 | —- | M] () – C:\Users\Dougie\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/09/15 17:19:13 | 000,001,136 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/09/15 17:19:12 | 000,002,050 | —- | M] () – C:\Users\Dougie\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/09/15 11:36:04 | 003,178,400 | —- | M] (McAfee, Inc.) – C:\Users\Dougie\Desktop\MCPR.exe
[2012/09/13 10:52:32 | 000,512,399 | —- | M] () – C:\Users\Dougie\Desktop\adwcleaner.exe
[2012/09/12 22:40:57 | 000,000,027 | —- | M] () – C:\windows\SysNative\drivers\etc\hosts
[2012/09/12 19:55:47 | 004,749,988 | R— | M] (Swearware) – C:\Users\Dougie\Desktop\ComboFix.exe
[2012/09/11 08:08:20 | 000,000,574 | —- | M] () – C:\Users\Dougie\Desktop\MBR.zip
[2012/09/11 07:59:31 | 000,000,512 | —- | M] () – C:\Users\Dougie\Desktop\MBR.dat
[2012/09/11 03:30:53 | 514,563,466 | —- | M] () – C:\windows\MEMORY.DMP
[2012/09/10 00:22:46 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\Dougie\Desktop\OTL(3).exe
[2012/09/10 00:07:58 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Dougie\Desktop\aswMBR(1).exe
[2012/09/09 01:53:01 | 000,000,564 | —- | M] () – C:\windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2012/09/09 00:29:39 | 000,000,564 | —- | M] () – C:\windows\tasks\PCDoctorBackgroundMonitorTask.job

========== Files Created - No Company Name ==========

[2012/09/15 12:47:33 | 000,001,830 | —- | C] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2012/09/13 10:51:45 | 000,512,399 | —- | C] () – C:\Users\Dougie\Desktop\adwcleaner.exe
[2012/09/12 22:04:33 | 000,256,000 | —- | C] () – C:\windows\PEV.exe
[2012/09/12 22:04:33 | 000,208,896 | —- | C] () – C:\windows\MBR.exe
[2012/09/12 22:04:33 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2012/09/12 22:04:33 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2012/09/12 22:04:33 | 000,068,096 | —- | C] () – C:\windows\zip.exe
[2012/09/11 08:08:20 | 000,000,574 | —- | C] () – C:\Users\Dougie\Desktop\MBR.zip
[2012/09/11 07:59:31 | 000,000,512 | —- | C] () – C:\Users\Dougie\Desktop\MBR.dat
[2012/09/09 00:23:10 | 000,000,564 | —- | C] () – C:\windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2012/07/07 09:57:19 | 000,000,005 | —- | C] () – C:\Users\Dougie\AppData\Roaming\mbam.context.scan
[2012/01/10 23:27:26 | 000,867,020 | —- | C] () – C:\windows\SysWow64\igkrng575.bin
[2012/01/10 23:27:26 | 000,128,204 | —- | C] () – C:\windows\SysWow64\igcompkrng575.bin
[2012/01/10 23:27:26 | 000,105,608 | —- | C] () – C:\windows\SysWow64\igfcg575m.bin
[2012/01/10 22:29:54 | 013,904,384 | —- | C] () – C:\windows\SysWow64\ig4icd32.dll
[2011/05/18 21:58:07 | 000,001,940 | —- | C] () – C:\Users\Dougie\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/11/02 18:47:47 | 000,000,615 | —- | C] () – C:\Users\Dougie\wuredir.xml
[2010/10/29 02:34:32 | 000,000,086 | —- | C] () – C:\Users\Dougie\AppData\Roaming\wklnhst.dat

========== LOP Check ==========

[2012/07/08 12:19:29 | 000,000,000 | —D | M] – C:\Users\Dougie\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2012/01/21 17:13:18 | 000,000,000 | —D | M] – C:\Users\Dougie\AppData\Roaming\PCDr
[2011/04/30 08:57:39 | 000,000,000 | —D | M] – C:\Users\Dougie\AppData\Roaming\RegistryKeys
[2012/07/08 12:19:35 | 000,000,000 | —D | M] – C:\Users\Dougie\AppData\Roaming\SanDisk
[2010/10/29 02:34:36 | 000,000,000 | —D | M] – C:\Users\Dougie\AppData\Roaming\Template
[2011/11/04 23:24:41 | 000,000,000 | —D | M] – C:\Users\Dougie\AppData\Roaming\uTorrent
[2010/09/24 20:06:25 | 000,000,000 | —D | M] – C:\Users\Dougie\AppData\Roaming\WildTangent
[2011/11/22 00:42:31 | 000,000,000 | —D | M] – C:\Users\Dougie\AppData\Roaming\Windows Live Writer
[2012/09/09 01:53:01 | 000,000,564 | —- | M] () – C:\windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2012/09/09 00:29:39 | 000,000,564 | —- | M] () – C:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012/06/04 02:50:30 | 000,032,620 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT
[2012/09/17 17:31:01 | 000,000,506 | —- | M] () – C:\windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2010/06/17 17:03:33 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/02/26 07:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010/06/17 17:36:23 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 07:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 13:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/06/17 17:03:33 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2010/06/17 16:59:44 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/06/17 17:36:23 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/06/17 16:59:44 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 14:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010/06/17 17:36:23 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/06/17 16:59:44 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 02:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010/06/17 17:36:23 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2010/06/17 17:03:33 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/02/26 07:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/06/17 16:59:44 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2010/06/17 17:03:33 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache86\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\erdnt\cache64\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\windows\SysNative\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 13:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache86\userinit.exe
[2010/11/20 13:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 13:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\erdnt\cache64\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\windows\SysNative\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 14:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 14:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\windows\SysNative\winlogon.exe
[2010/11/20 14:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 02:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010/06/17 17:36:23 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010/06/17 17:36:23 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD5000BEVT-75A0RT0
Partitions: 3
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 15.00GB
Starting Offset: 105906176
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 451.00GB
Starting Offset: 15834546176
Hidden sectors: 0


< End of report >
  • OTL

    Run OTL.exe.

  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :OTL
    FF - prefs.js..extensions.enabledItems: {E4E6BF2A-1667-11DF-A01F-1F9655D89593}:4.0
    FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
    FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.3.3.2
    [2012/07/08 12:19:32 | 000,000,000 | —D | M] (Simppull Toolbar) – C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}
    O2 - BHO: (Simppull Toolbar) - {627af46b-2076-42ae-a2fd-8428734d3e74} - C:\Program Files (x86)\simppulltoolbar\simppulldx.dll File not found
    O2 - BHO: (Updater For Simppull Toolbar) - {C4B8BAB4-1667-11DF-A242-BA9455D89593} - C:\Program Files (x86)\simppulltoolbar\auxi\simppulltoolbAu.dll File not found
    O2 - BHO: (no name) - {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Simppull Toolbar) - {627af46b-2076-42ae-a2fd-8428734d3e74} - C:\Program Files (x86)\simppulltoolbar\simppulldx.dll File not found
    [2012/09/12 19:48:06 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{E8EAFED6-57FD-4E6D-85F2-8BA7B9232862}
    [2012/09/11 14:17:35 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{FA6823D5-4BF1-4B7D-8DAA-C7E56620D940}
    [2012/09/10 22:06:26 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{4D9FA01B-2A07-4253-B215-2C08597E8958}
    [2012/09/10 00:19:12 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{0BF98022-D00D-4E17-87A6-AED1E36FF6A4}
    [2012/09/09 00:10:24 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{346A4771-D13B-4ABD-8031-863626C82740}
    [2012/08/22 14:05:33 | 000,000,000 | —D | C] – C:\Users\Dougie\AppData\Local\{9D882526-22AD-4272-846D-5230DC32ED9F}
    [2011/05/18 21:58:07 | 000,001,940 | —- | C] () – C:\Users\Dougie\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
    
    :Commands
    [createrestorepoint]
    [purity]
    [resethosts]
    [emptytemp]

  • Click the Run Fix button.
  • OTL will now process the instructions.
  • When finished a box will open asking you to open the fix log, click OK.
  • The fix log will open.
  • Copy/Paste the log in your next reply please.

Note: If necessary, OTL may reboot your computer, or request that you do so. If it does, please go ahead and reboot your machine. After rebooting, open up Windows Explorer (Windows Key +E) and navigate to C:\_OTL\MovedFiles. Within, you should find a .log file with the format mmddyyyy_hhmmss, which represents the date and time the fix was run. Please copy and paste the contents of that file, making sure Word Wrap is off beforehand, if necessary.
All processes killed ========== OTL ========== Prefs.js: {E4E6BF2A-1667-11DF-A01F-1F9655D89593}:4.0 removed from extensions.enabledItems Prefs.js: [removed]:3.3.3.2 removed from extensions.enabledItems Prefs.js: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.3.3.2 removed from extensions.enabledItems C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\components folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\searchbar folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\options folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\weatherbutton\panels folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\weatherbutton\icons folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\weatherbutton folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\uwa folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\panels\images folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\panels\css folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\panels folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\data\search folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\data\rss folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\data\dynamicElements folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\data folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\widgets\net.vmn.www.3.YouTube.1217 folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\widgets\net.vmn.www.3.Twitter.1255 folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\widgets folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\newtab\images folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\newtab folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\modules folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\lib folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593} folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{627af46b-2076-42ae-a2fd-8428734d3e74}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627af46b-2076-42ae-a2fd-8428734d3e74}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C4B8BAB4-1667-11DF-A242-BA9455D89593}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4B8BAB4-1667-11DF-A242-BA9455D89593}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{627af46b-2076-42ae-a2fd-8428734d3e74} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627af46b-2076-42ae-a2fd-8428734d3e74}\ not found. C:\Users\Dougie\AppData\Local\{E8EAFED6-57FD-4E6D-85F2-8BA7B9232862} folder moved successfully. C:\Users\Dougie\AppData\Local\{FA6823D5-4BF1-4B7D-8DAA-C7E56620D940} folder moved successfully. C:\Users\Dougie\AppData\Local\{4D9FA01B-2A07-4253-B215-2C08597E8958} folder moved successfully. C:\Users\Dougie\AppData\Local\{0BF98022-D00D-4E17-87A6-AED1E36FF6A4} folder moved successfully. C:\Users\Dougie\AppData\Local\{346A4771-D13B-4ABD-8031-863626C82740} folder moved successfully. C:\Users\Dougie\AppData\Local\{9D882526-22AD-4272-846D-5230DC32ED9F} folder moved successfully. C:\Users\Dougie\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point C:\windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Dougie ->Temp folder emptied: 122494013 bytes ->Temporary Internet Files folder emptied: 100435472 bytes ->Java cache emptied: 1 bytes ->FireFox cache emptied: 55098621 bytes ->Google Chrome cache emptied: 65121735 bytes ->Flash cache emptied: 58484 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 120672 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 102023 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 328.00 mb OTL by OldTimer - Version 3.2.61.3 log created on 09192012_155840 Files\Folders moved on Reboot… C:\Users\Dougie\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot…
Sorry, didn't see the last part of your post. I got a log text straight away on start up. Here it is again this way. Pretty sure it's exactly the same. Fiona. All processes killed ========== OTL ========== Prefs.js: {E4E6BF2A-1667-11DF-A01F-1F9655D89593}:4.0 removed from extensions.enabledItems Prefs.js: [removed]:3.3.3.2 removed from extensions.enabledItems Prefs.js: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.3.3.2 removed from extensions.enabledItems C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\components folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\searchbar folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\options folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\weatherbutton\panels folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\weatherbutton\icons folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\weatherbutton folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\uwa folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\panels\images folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\panels\css folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib\panels folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin\lib folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\skin folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\data\search folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\data\rss folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\data\dynamicElements folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\data folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\widgets\net.vmn.www.3.YouTube.1217 folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\widgets\net.vmn.www.3.Twitter.1255 folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\widgets folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\newtab\images folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\newtab folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\modules folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content\lib folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome\content folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\chrome folder moved successfully. C:\Users\Dougie\AppData\Roaming\Mozilla\Firefox\Profiles\s591wzpi.default\extensions\{E4E6BF2A-1667-11DF-A01F-1F9655D89593} folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{627af46b-2076-42ae-a2fd-8428734d3e74}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627af46b-2076-42ae-a2fd-8428734d3e74}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C4B8BAB4-1667-11DF-A242-BA9455D89593}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4B8BAB4-1667-11DF-A242-BA9455D89593}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E4E6BF2A-1667-11DF-A01F-1F9655D89593}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{627af46b-2076-42ae-a2fd-8428734d3e74} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627af46b-2076-42ae-a2fd-8428734d3e74}\ not found. C:\Users\Dougie\AppData\Local\{E8EAFED6-57FD-4E6D-85F2-8BA7B9232862} folder moved successfully. C:\Users\Dougie\AppData\Local\{FA6823D5-4BF1-4B7D-8DAA-C7E56620D940} folder moved successfully. C:\Users\Dougie\AppData\Local\{4D9FA01B-2A07-4253-B215-2C08597E8958} folder moved successfully. C:\Users\Dougie\AppData\Local\{0BF98022-D00D-4E17-87A6-AED1E36FF6A4} folder moved successfully. C:\Users\Dougie\AppData\Local\{346A4771-D13B-4ABD-8031-863626C82740} folder moved successfully. C:\Users\Dougie\AppData\Local\{9D882526-22AD-4272-846D-5230DC32ED9F} folder moved successfully. C:\Users\Dougie\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point C:\windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Dougie ->Temp folder emptied: 122494013 bytes ->Temporary Internet Files folder emptied: 100435472 bytes ->Java cache emptied: 1 bytes ->FireFox cache emptied: 55098621 bytes ->Google Chrome cache emptied: 65121735 bytes ->Flash cache emptied: 58484 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 120672 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 102023 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 328.00 mb OTL by OldTimer - Version 3.2.61.3 log created on 09192012_155840 Files\Folders moved on Reboot… C:\Users\Dougie\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot…
Your logs appear to indicate that your system is clean. :thumbup: Please temporarily disable your real-time security programs before carrying out the following cleanup procedure. Be sure to re-enable them after the process is complete.

Also, before leaving, please post one last reply confirming your machine is in proper working order so that we may close the thread.

  • Uninstalling ComboFix

    • Click Start > Run (or WindowsKey + R)
    • In the Run box, type combofix /uninstall and then click OK.
    • A window should pop up shortly after saying that ComboFix has been uninstalled.
  • OTL Cleanup

    • Start OTL.exe.
    • Close all other programs apart from OTL as this step will require a reboot.
    • On the OTL main screen, press the CLEANUP button.
    • Click Yes at the prompt and then allow the program to reboot your computer.
  • Other information you should know before you leave:

    SpywareBlaster
    • If you ever use Internet Explorer, SpywareBlaster provides excellent additional protection.
    • SpywareBlaster prevents the installation of ActiveX-based spyware and other potentially unwanted programs.
    • Download it for free here.
    Web of Trust
    • WOT is a browsing tool that helps you determine the safety of unknown websites.
    • It places color-coded symbols next to URLs.
    • Green - Go
    • Yellow - Caution
    • Red - Stop
  • You can download it here.
Secunia Online Software Inspector
  • This is a nice little Java applet that will determine if any software on your computer is out of date.
  • Check it out here.
Other tips
  • Please go here for more valuable security tips.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI