This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu toolbar removal

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi! i stupidly downloaded an add on for savevid and it included a searchqu toolbar. i have tried going into add/removal programs and deleting all the bandoo and searchqu files however whenever I open chrome/firefox/ie, it makes searchqu my homepage. i tried the system restore with no luck, could you please help? thanks very much.
Hello oilandwater and Welcome to WhatTheTech Forums

My name is BlackPegasus.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for
    further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to
    get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out
    the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to
    ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.

Hello oilandwater


  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
=================
NEXT


Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

In your next reply please let me know how your system is running and post the logs to:
OTL
aswMBR
Hi BlackPegasus, thanks for your responses.

OTL.txt:

OTL logfile created on: 20/05/2011 2:36:33 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Hello\Desktop
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 282.94 Gb Total Space | 189.46 Gb Free Space | 66.96% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 8.72 Gb Free Space | 58.12% Space Free | Partition Type: NTFS

Computer Name: LAPTOP | User Name: Hello | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Hello\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Dell Remote Access\ezi_ra.exe (Dell Inc.)
PRC - c:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
PRC - C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Fingerprint Sensor\AtService.exe (AuthenTec, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Hello\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcr80.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcp80.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)


========== Win32 Services (SafeList) ==========

SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (vsmon) – C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Sound Blaster X-Fi MB Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Creative Labs)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (hnmsvc) – c:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (ATService) – C:\Program Files\Fingerprint Sensor\AtService.exe (AuthenTec, Inc.)
SRV - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (Vsdatant) – C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (Packet) – C:\Windows\System32\drivers\packet.sys (SingleClick Systems)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OA001Vid) – C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (OA001Ufd) – C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (CtClsFlt) – C:\Windows\System32\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (ATSwpWDF) – C:\Windows\System32\drivers\ATSwpWDF.sys (AuthenTec, Inc.)
DRV - (k57nd60x) Broadcom NetLink ™ – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.jp.msn.com/USCON/19
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/405
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/405"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {241aae70-0022-11de-87af-0800200c9a66}:3.6.30.01.10
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=405&q;="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\DigitalPersona\Bin\FirefoxExt\ [2009/11/13 14:04:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/08 09:44:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/31 16:43:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/31 16:43:56 | 000,000,000 | —D | M]

[2011/05/20 12:04:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Hello\AppData\Roaming\Mozilla\Extensions
[2010/09/29 15:31:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Hello\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/01/25 20:46:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Hello\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/05/20 12:38:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Hello\AppData\Roaming\Mozilla\Firefox\Profiles\hf4o1ii0.default\extensions
[2010/12/01 12:50:56 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Hello\AppData\Roaming\Mozilla\Firefox\Profiles\hf4o1ii0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/26 19:22:22 | 000,000,000 | —D | M] (Blue Fox) – C:\Users\Hello\AppData\Roaming\Mozilla\Firefox\Profiles\hf4o1ii0.default\extensions\{241aae70-0022-11de-87af-0800200c9a66}
[2010/12/10 01:17:40 | 000,005,529 | —- | M] () – C:\Users\Hello\AppData\Roaming\Mozilla\Firefox\Profiles\hf4o1ii0.default\searchplugins\SearchquWebSearch.xml
[2011/05/20 12:04:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/09/14 10:04:31 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/05/02 22:00:49 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/02/08 09:44:00 | 000,000,000 | —D | M] (ZoneAlarm Security Engine) – C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/10 01:17:40 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

O1 HOSTS File: ([2006/09/19 07:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RunDLLEntry] C:\Windows\System32\AmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKLM..\RunOnce: [removeSearchqudatamngr] File not found
O4 - HKLM..\RunOnce: [removeSearchqutoolbar] File not found
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} http://zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab (ZPA_WheelOfFortune Object)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 07:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{62a26a1c-db93-11de-b1e5-701a041e10e5}\Shell - "" = AutoRun
O33 - MountPoints2\{62a26a1c-db93-11de-b1e5-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{65b3bbd6-e14b-11de-8ac6-701a041e10e5}\Shell - "" = AutoRun
O33 - MountPoints2\{65b3bbd6-e14b-11de-8ac6-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{65b3bbd7-e14b-11de-8ac6-701a041e10e5}\Shell - "" = AutoRun
O33 - MountPoints2\{65b3bbd7-e14b-11de-8ac6-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{6abd6f25-de10-11de-b3b5-701a041e10e5}\Shell - "" = AutoRun
O33 - MountPoints2\{6abd6f25-de10-11de-b3b5-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{7501859e-d992-11de-a10a-701a041e10e5}\Shell - "" = AutoRun
O33 - MountPoints2\{7501859e-d992-11de-a10a-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{750185a0-d992-11de-a10a-701a041e10e5}\Shell - "" = AutoRun
O33 - MountPoints2\{750185a0-d992-11de-a10a-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{c5b9b433-d97b-11de-b9ba-701a041e10e5}\Shell - "" = AutoRun
O33 - MountPoints2\{c5b9b433-d97b-11de-b9ba-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{c5b9b44c-d97b-11de-b9ba-701a041e10e5}\Shell - "" = AutoRun
O33 - MountPoints2\{c5b9b44c-d97b-11de-b9ba-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/20 14:34:44 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Hello\Desktop\OTL.exe
[2011/05/20 12:31:00 | 000,000,000 | —D | C] – C:\Windows\System32\appmgmt
[2011/05/20 12:30:59 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/05/20 12:24:14 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/05/20 11:47:22 | 000,000,000 | —D | C] – C:\Program Files\Windows Savevid Toolbar
[2011/05/20 11:47:21 | 000,000,000 | -H-D | C] – C:\ProgramData\~0
[2011/05/20 11:47:03 | 000,000,000 | —D | C] – C:\Users\Hello\AppData\Local\PackageAware
[2011/05/02 22:01:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/05/02 22:00:47 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/05/02 22:00:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/05/02 22:00:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/28 18:34:01 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/04/28 18:34:01 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll

========== Files - Modified Within 30 Days ==========

[2011/05/20 14:35:21 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Hello\Desktop\OTL.exe
[2011/05/20 14:24:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2737727076-3544799952-3247842620-1000UA.job
[2011/05/20 14:10:32 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 14:10:32 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 12:24:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2737727076-3544799952-3247842620-1000Core.job
[2011/05/20 12:10:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/20 12:10:25 | 3213,803,520 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 20:14:01 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/05/14 15:25:22 | 000,609,196 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/14 15:25:22 | 000,108,672 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/14 15:24:54 | 000,002,044 | —- | M] () – C:\Users\Hello\Desktop\Google Chrome.lnk
[2011/05/14 15:24:54 | 000,002,006 | —- | M] () – C:\Users\Hello\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

========== Files Created - No Company Name ==========

[2011/03/05 23:00:54 | 000,001,048 | —- | C] () – C:\Windows\disney.ini
[2010/05/25 20:03:08 | 000,005,120 | —- | C] () – C:\Users\Hello\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/19 10:40:52 | 000,007,052 | —- | C] () – C:\Users\Hello\AppData\Local\d3d9caps.dat
[2009/11/14 05:23:44 | 000,181,944 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2009/11/14 05:23:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2009/11/14 05:23:44 | 000,081,920 | —- | C] () – C:\Windows\System32\ATIODE.exe
[2009/11/14 05:23:44 | 000,045,056 | —- | C] () – C:\Windows\System32\ATIODCLI.exe
[2009/11/13 21:31:57 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/11/13 14:20:15 | 000,000,075 | RHS- | C] () – C:\Windows\CT4CET.bin
[2009/11/13 14:14:54 | 000,005,051 | —- | C] () – C:\Windows\System32\cfgfx.ini
[2009/11/13 14:14:54 | 000,001,438 | —- | C] () – C:\Windows\FF08_not_Spk_Hp.ini
[2009/11/13 14:14:54 | 000,001,379 | —- | C] () – C:\Windows\FF08_Render_Spk_Hp.ini
[2009/11/13 14:14:53 | 000,146,432 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2009/11/13 14:14:53 | 000,072,704 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2009/11/13 13:56:50 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2009/04/12 01:13:37 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/04/12 01:13:37 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/01/21 12:23:41 | 000,081,158 | —- | C] () – C:\Windows\System32\manage-bde.ini.en
[2008/01/21 12:23:38 | 000,062,976 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2007/04/16 05:24:16 | 000,023,752 | —- | C] () – C:\Windows\System32\providers.bin
[2006/11/02 22:55:52 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 22:46:27 | 000,270,552 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 22:34:20 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 20:33:01 | 000,609,196 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 20:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 20:33:01 | 000,108,672 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 20:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 20:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 18:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 18:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 17:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 17:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/11/14 15:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2011/03/14 23:01:41 | 000,000,000 | —D | M] – C:\Users\Hello\AppData\Roaming\Atari
[2010/10/15 00:52:26 | 000,000,000 | —D | M] – C:\Users\Hello\AppData\Roaming\CheckPoint
[2009/11/25 11:33:01 | 000,000,000 | —D | M] – C:\Users\Hello\AppData\Roaming\DigitalPersona
[2011/03/05 23:07:07 | 000,000,000 | —D | M] – C:\Users\Hello\AppData\Roaming\GetRightToGo
[2010/09/29 16:43:31 | 000,000,000 | —D | M] – C:\Users\Hello\AppData\Roaming\IMVU
[2010/09/29 15:31:33 | 000,000,000 | —D | M] – C:\Users\Hello\AppData\Roaming\IMVUClient
[2010/10/18 19:00:50 | 000,000,000 | —D | M] – C:\Users\Hello\AppData\Roaming\SystemRequirementsLab
[2010/09/29 15:34:32 | 000,000,000 | —D | M] – C:\Users\Hello\AppData\Roaming\Vivox
[2011/05/19 20:14:01 | 000,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >

Extras.txt:

OTL Extras logfile created on: 20/05/2011 2:36:33 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Hello\Desktop
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 282.94 Gb Total Space | 189.46 Gb Free Space | 66.96% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 8.72 Gb Free Space | 58.12% Space Free | Partition Type: NTFS

Computer Name: LAPTOP | User Name: Hello | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{D28EB506-CC2C-41B9-A268-5A7EE5ADB327}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E07C43EE-66B9-4906-A9FC-1F4BF0AE1D2A}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{086147E5-7B91-419D-9AB1-6B1E2D74F1D2}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{09EC2826-DB75-40BA-8C61-6ED545341AA5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{150831CC-FFD6-4971-B745-12C3697F2F41}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{170EF621-0F6F-4A07-A1BA-4290EF01B46F}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{18F8572A-D7DC-4260-AB52-1B90455C2389}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{1CBE1099-E966-4C1B-B57C-6A154F277FFB}" = protocol=6 | dir=in | app=c:\program files\common files\dell\vlc\vlc.exe |
"{335D5695-BF64-431E-B250-2CFEA3B15067}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{4570AC6A-3A9D-40A8-A42A-2A607F6BB09E}" = protocol=6 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{532B8512-BADF-4EB2-BDD3-C4F773F807BC}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.patch.exe |
"{5778A3A6-CEA7-4C88-89C3-BF2346168D9C}" = protocol=6 | dir=in | app=c:\windows\system32\zonelabs\vsmon.exe |
"{5A1EF74D-6533-4B64-8833-8DDA8987F5E7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{714C438F-6D50-4DC4-BE2B-D3D9B072ABFD}" = protocol=17 | dir=in | app=c:\windows\system32\zonelabs\vsmon.exe |
"{7B47B744-6919-4BB6-8CF6-11210B38B970}" = protocol=6 | dir=in | app=c:\program files\common files\dell\advanced networking service\hnm_svc.exe |
"{96FFE797-4C06-4904-B173-22E5D6EF6832}" = protocol=17 | dir=in | app=c:\program files\dell remote access\ezi_ra.exe |
"{984A0009-A7A6-4F5C-989D-2561CC36C098}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"{9ECF4B56-A449-41E9-A177-317D4B8118FF}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{A1805E59-FD44-4DB0-9118-FA31A604EF49}" = protocol=17 | dir=in | app=c:\program files\common files\dell\vlc\vlc.exe |
"{A298D930-EBA2-41E5-9672-8FB21BFAB651}" = protocol=17 | dir=in | app=c:\program files\common files\dell\advanced networking service\hnm_svc.exe |
"{A3E47305-C12E-4757-B27D-6CDD2DABC565}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"{A56AFACA-472F-444C-A947-1E1CBC0D41D1}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.patch.exe |
"{A8DE2CDD-B231-4D8E-B725-37747802A120}" = protocol=6 | dir=in | app=c:\program files\dell remote access\ezi_ra.exe |
"{C188E398-CFF4-40B9-8BC5-73786A9A53FE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D119FDE1-C699-453D-921D-9D33CE40EF6F}" = protocol=17 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{E9F7E12B-203A-45C0-BF19-61BC57F261D2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F666E61A-EF40-4578-B948-8C989F424E44}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"TCP Query User{27E49ABE-9980-4203-B91A-57912C4EF5D1}C:\program files\world of warcraft\blizzard downloader.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\blizzard downloader.exe |
"UDP Query User{C6723183-91D9-42DD-93E1-15C1627C0CB4}C:\program files\world of warcraft\blizzard downloader.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\blizzard downloader.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.1.0.4402
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{0904ED3B-0FCD-A153-2F80-F7F5AB0329BA}" = Catalyst Control Center Graphics Previews Vista
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0F090069-6450-9559-72BD-2437FF935EEC}" = CCC Help Swedish
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1882D3BE-8B8F-4EA3-9414-EB06CD5B9CD8}" = Modem Diagnostics Tool
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{34386C65-FD55-CEBD-AF7F-5126751BAA98}" = Catalyst Control Center InstallProxy
"{35EAF162-26F1-4DD2-8349-297F5CE31FD5}" = DigitalPersona Personal 3.1.0
"{3643D422-9AFF-81D6-252C-14A8A3AD88D3}" = CCC Help Korean
"{3889CA7B-A8FC-09CB-C6D4-B134A2336DD9}" = CCC Help Portuguese
"{394B918B-47B0-D281-6AB8-E58871B54C91}" = Catalyst Control Center Core Implementation
"{3B7E26A8-4B67-D878-3AE3-0079686C52B6}" = CCC Help Spanish
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{433A39B0-380C-4634-93FE-12A812954F5B}" = BigPond Broadband ADSL
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51B6CDCD-8802-B41A-61E4-FC6A65FF217B}" = CCC Help French
"{531DDC1D-6563-8796-764A-A9C4E83C23E0}" = CCC Help English
"{56F4CA69-B3BC-81E6-304A-E650F3BB93A8}" = Catalyst Control Center Graphics Previews Common
"{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
"{61D9B6B3-B72E-C642-F0B0-8659EADB4CAA}" = Skins
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6FB141D8-1543-6588-623A-7D95969CB330}" = Catalyst Control Center Localization All
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{75CE8AF5-0A5E-4A42-BC67-F83591DA9A7D}" = Sound Blaster X-Fi MB
"{791A4569-E893-CA1F-664D-1DE63A5600A1}" = ccc-utility
"{7C0AEF0E-BB23-5C44-4933-88F6AE1057D8}" = Catalyst Control Center Graphics Full New
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{80052E79-4A36-69BA-F44F-882A2E321116}" = CCC Help German
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87460EB7-E62D-C963-4DDB-D2146478F59F}" = CCC Help Finnish
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8BD8412A-40FB-9114-A8AE-CFB94C24C078}" = CCC Help Norwegian
"{8C2522F0-8B10-139C-3379-3620EA6A254D}" = CCC Help Dutch
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FCE7358-DA6B-789A-44AB-E52256ACB330}" = CCC Help Chinese Traditional
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{958DF0E4-CC0D-BDD5-28D1-A1B961E48A85}" = ccc-core-static
"{990036E7-D647-45A4-8F7F-1CB277EF0ABD}" = RollerCoaster Tycoon 3 Demo
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A8E83877-671C-A1A3-F4D3-C3D74E5AE8B9}" = CCC Help Chinese Standard
"{AB49B509-8FCA-45E6-9FB9-9E4AEEB8F148}" = System Requirements Lab CYRI
"{ADB4809A-3857-F18D-153F-391EB1D37C59}" = Catalyst Control Center Graphics Full Existing
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B354E49B-DBDC-442D-5615-BD07B3A0B932}" = Catalyst Control Center Graphics Light
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B787CD67-506B-4C9A-8A99-D2C4460D055F}" = Catalyst Control Center - Branding
"{B96C8D6D-B0E5-CD7B-BC5D-739D5051E911}" = CCC Help Japanese
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C1E11C46-E6EB-4BD2-9ADF-2A98ACBEB216}" = iTunes
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{CB72877A-D2BF-6F18-2D0A-52C4036E2DF6}" = CCC Help Russian
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D809E781-A654-3530-2B92-91FF959C507A}" = CCC Help Danish
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F2393654-7D1F-48B3-9E4C-4007D120ABB8}" = AuthenTec Fingerprint Software
"{F31D838B-E7F3-1E70-F54F-B009CD9219EE}" = CCC Help Italian
"{F66A31D9-7831-4FBA-BA02-C411C0047CC5}" = Dell Remote Access
"{F6BB6248-C507-46FE-8A35-1B16F35E0441}" = ITECIR
"3B7076EB3C51070DE9D6902E9696507D9B471345" = Windows Driver Package - NETGEAR Inc. (RTLWUSB) Net (03/27/2006 5.1213.06.0327)
"94703D1C50646DF5FB8D0FB50EB2216330EB89C9" = Windows Driver Package - Atheros Communications Inc. (arusb_lh) Net (09/25/2008 3.1.0.101)
"A4680BD43717441189C52EBF2C4FD6B182EE1101" = Windows Driver Package - AuthenTec Inc. (ATSwpWDF) Biometric (10/02/2008 8.1.2.37)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CCleaner" = CCleaner
"Creative OA001" = Integrated Webcam Driver (1.06.03.0309)
"Dell Video Chat" = Dell Video Chat
"Dell Webcam Central" = Dell Webcam Central
"GoToAssist" = GoToAssist 8.0.0.514
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Optus Wireless Broadband" = Optus Wireless Broadband
"TarzanAG Demo" = Disney's Tarzan Action Game Demo
"VLC media player" = VLC media player 1.1.0
"WinLiveSuite_Wave3" = Windows Live Essentials
"World of Warcraft" = World of Warcraft
"ZoneAlarm" = ZoneAlarm
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"IMVU Avatar chat client software BETA" = IMVU Avatar Chat Software

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 31/03/2011 7:30:10 PM | Computer Name = Laptop | Source = WinMgmt | ID = 10
Description =

Error - 31/03/2011 10:03:24 PM | Computer Name = Laptop | Source = WinMgmt | ID = 10
Description =

Error - 31/03/2011 10:25:41 PM | Computer Name = Laptop | Source = EventSystem | ID = 4621
Description =

Error - 1/04/2011 8:18:46 AM | Computer Name = Laptop | Source = WinMgmt | ID = 10
Description =

Error - 1/04/2011 11:27:26 AM | Computer Name = Laptop | Source = EventSystem | ID = 4621
Description =

Error - 2/04/2011 12:33:11 AM | Computer Name = Laptop | Source = WinMgmt | ID = 10
Description =

Error - 2/04/2011 12:37:52 AM | Computer Name = Laptop | Source = VSS | ID = 8193
Description =

Error - 2/04/2011 3:55:46 AM | Computer Name = Laptop | Source = WinMgmt | ID = 10
Description =

Error - 2/04/2011 8:18:45 AM | Computer Name = Laptop | Source = WinMgmt | ID = 10
Description =

Error - 3/04/2011 12:58:26 AM | Computer Name = Laptop | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 19/05/2011 10:54:46 PM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.

Error - 19/05/2011 11:05:02 PM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.

Error - 19/05/2011 11:15:33 PM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.

Error - 19/05/2011 11:25:52 PM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.

Error - 19/05/2011 11:46:31 PM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.

Error - 19/05/2011 11:56:30 PM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.

Error - 20/05/2011 12:06:27 AM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.

Error - 20/05/2011 12:16:41 AM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.

Error - 20/05/2011 12:26:49 AM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.

Error - 20/05/2011 12:35:57 AM | Computer Name = Laptop | Source = netbt | ID = 4321
Description = The name "JULIE-PC :0" could not be registered on the interface
with IP address 10.0.0.24. The computer with the IP address 10.0.0.3 did not allow
the name to be claimed by this computer.


< End of report >
and here is the aswMBR.exe save log: aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-20 14:43:23 —————————– 14:43:23.126 OS Version: Windows 6.0.6001 Service Pack 1 14:43:23.126 Number of processors: 2 586 0x170A 14:43:23.126 ComputerName: LAPTOP UserName: Hello 14:43:26.148 Initialize success 14:43:36.358 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 14:43:36.360 Disk 0 Vendor: ST9320423ASG 0003SDM1 Size: 305245MB BusType: 3 14:43:38.383 Disk 0 MBR read successfully 14:43:38.388 Disk 0 MBR scan 14:43:38.393 Disk 0 unknown MBR code 14:43:40.408 Disk 0 scanning sectors +625139712 14:43:40.471 Disk 0 scanning C:\Windows\system32\drivers 14:43:45.848 Service scanning 14:43:47.330 Disk 0 trace - called modules: 14:43:47.364 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll PCIIDEX.SYS msahci.sys 14:43:47.368 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86528ac8] 14:43:47.371 3 CLASSPNP.SYS[8adc1745] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85d2cba0] 14:43:47.374 Scan finished successfully 14:44:14.480 Disk 0 MBR has been saved successfully to "C:\Users\Hello\Desktop\MBR.dat" 14:44:14.484 The log file has been saved successfully to "C:\Users\Hello\Desktop\aswMBR.txt"
Hello oilandwater, thank you for the logs.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/405
    FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/405"
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
    FF - prefs.js..browser.search.selectedEngine: "Web Search"
    FF - prefs.js..browser.search.defaultenginename: "Web Search"
    FF - prefs.js..browser.search.order.1: "Web Search"
    FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=405&q="
    [2010/12/10 01:17:40 | 000,005,529 | —- | M] () – C:\Users\Hello\AppData\Roaming\Mozilla\Firefox\Profiles\hf4o1ii0.default\searchplugins\SearchquWebSearch.xml
    [2010/09/14 10:04:31 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    [2010/12/10 01:17:40 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O4 - HKLM..\RunOnce: [removeSearchqudatamngr] File not found
    O4 - HKLM..\RunOnce: [removeSearchqutoolbar] File not found
    O33 - MountPoints2\{62a26a1c-db93-11de-b1e5-701a041e10e5}\Shell - "" = AutoRun
    O33 - MountPoints2\{62a26a1c-db93-11de-b1e5-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{65b3bbd6-e14b-11de-8ac6-701a041e10e5}\Shell - "" = AutoRun
    O33 - MountPoints2\{65b3bbd6-e14b-11de-8ac6-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{65b3bbd7-e14b-11de-8ac6-701a041e10e5}\Shell - "" = AutoRun
    O33 - MountPoints2\{65b3bbd7-e14b-11de-8ac6-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{6abd6f25-de10-11de-b3b5-701a041e10e5}\Shell - "" = AutoRun
    O33 - MountPoints2\{6abd6f25-de10-11de-b3b5-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{7501859e-d992-11de-a10a-701a041e10e5}\Shell - "" = AutoRun
    O33 - MountPoints2\{7501859e-d992-11de-a10a-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{750185a0-d992-11de-a10a-701a041e10e5}\Shell - "" = AutoRun
    O33 - MountPoints2\{750185a0-d992-11de-a10a-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{c5b9b433-d97b-11de-b9ba-701a041e10e5}\Shell - "" = AutoRun
    O33 - MountPoints2\{c5b9b433-d97b-11de-b9ba-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{c5b9b44c-d97b-11de-b9ba-701a041e10e5}\Shell - "" = AutoRun
    O33 - MountPoints2\{c5b9b44c-d97b-11de-b9ba-701a041e10e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\F\Shell - "" = AutoRun
    O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe
    [2011/05/20 11:47:22 | 000,000,000 | —D | C] – C:\Program Files\Windows Savevid Toolbar
    
    :Commands
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

====================
Next

  • Right click on OTL.exe and click "Run as administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    C:\ProgramData\~0\*.* /s
    C:\Users\Hello\AppData\Local\PackageAware\*.* /s

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt


=============================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL fix log
3. New OTL log
4. How is the computer behaving?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI