This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu Help!

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

. DDS (Ver_2011-06-03.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 18:39:34 on 2011-06-07 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2038.905 [GMT -4:00] . AV: BitDefender Antivirus *Enabled/Outdated* {50909708-FF80-02AF-F814-B28405891E92} SP: BitDefender Antispyware *Enabled/Outdated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\system32\taskeng.exe C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Apoint2K\Apoint.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\System32\igfxpers.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Apoint2K\ApMsgFwd.exe C:\Program Files\Apoint2K\Apntex.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Users\jaye\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jaye\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jaye\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\conime.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . mStart Page = about:blank uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll uURLSearchHooks: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll mURLSearchHooks: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_02\bin\ssv.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.0\CoIEPlg.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2011\IEToolbar.dll TB: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll uRun: [Google Update] "c:\users\jaye\appdata\local\google\update\GoogleUpdate.exe" /c mRun: [Apoint] c:\program files\apoint2k\Apoint.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_02\bin\jusched.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2011\ieshow.exe" mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2011\bdagent.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\lolrec~1.lnk - c:\program files\lolreplay\LOLRecorder.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_02\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab TCP: DhcpNameServer = 208.67.222.222 208.67.220.220 TCP: Interfaces\{04386B13-D920-4216-8861-7F3031A10A5F} : DhcpNameServer = 208.67.222.222 208.67.220.220 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll AppInit_DLLs: mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ============= SERVICES / DRIVERS =============== . R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-4-6 21504] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-6-7 366640] R2 Updatesrv;BitDefender Desktop Update Service;c:\program files\bitdefender\bitdefender 2011\updatesrv.exe [2011-2-11 43936] R3 BDFM;BDFM;c:\windows\system32\drivers\bdfm.sys [2010-5-13 152528] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-6-7 22712] S1 BdRawPr;BdRawPr;c:\windows\system32\drivers\bdrawpr.sys [2011-3-29 12960] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon –> c:\program files\common files\symantec shared\ccSvcHst.exe [?] S3 avc3;avc3;c:\windows\system32\drivers\avc3.sys [2010-11-29 535824] S3 avckf;avckf;c:\windows\system32\drivers\avckf.sys [2010-11-29 1066232] S3 Update Server;BitDefender Update Server v2;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2010-11-30 307544] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-06-07 21:28:42 388096 —-a-r- c:\users\jaye\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-06-07 21:28:40 ——– d—–w- c:\program files\Trend Micro 2011-06-07 20:32:46 ——– d—–w- c:\users\jaye\appdata\roaming\Malwarebytes 2011-06-07 20:32:33 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-06-07 20:32:32 ——– d—–w- c:\programdata\Malwarebytes 2011-06-07 20:32:29 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-06-07 20:32:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-06-07 17:36:28 ——– d—–w- c:\programdata\boost_interprocess 2011-06-07 06:49:07 ——– d—–w- c:\program files\Microsoft 2011-06-07 06:45:33 ——– d–h–w- c:\windows\msdownld.tmp 2011-06-07 06:45:27 ——– d—–w- c:\windows\system32\directx 2011-06-06 20:05:58 ——– d—–w- c:\program files\LOLReplay 2011-06-06 18:45:29 ——– d—–w- c:\users\jaye\appdata\local\Ilivid Player 2011-06-06 18:43:52 ——– d—–w- c:\users\jaye\appdata\local\PackageAware 2011-05-24 01:33:13 ——– d-sh–w- C:\found.000 2011-05-18 02:17:07 ——– d—–w- c:\programdata\LightScribe 2011-05-13 00:44:59 ——– d—–w- c:\programdata\Skype Extras 2011-05-13 00:43:32 ——– d—–r- c:\program files\Skype 2011-05-11 21:00:09 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat . ==================== Find3M ==================== . 2011-04-13 15:36:59 101888 —-a-w- c:\windows\system32\ifxcardm.dll 2011-04-13 15:36:54 82432 —-a-w- c:\windows\system32\axaltocm.dll 2011-04-05 07:04:50 61440 —-a-w- c:\windows\system32\winipsec.dll 2011-04-05 07:04:50 272896 —-a-w- c:\windows\system32\polstore.dll 2011-04-05 07:04:25 9728 —-a-w- c:\windows\system32\TCPSVCS.EXE 2011-04-05 07:04:25 8704 —-a-w- c:\windows\system32\HOSTNAME.EXE 2011-04-05 07:04:25 27136 —-a-w- c:\windows\system32\NETSTAT.EXE 2011-04-05 07:04:25 19968 —-a-w- c:\windows\system32\ARP.EXE 2011-04-05 07:04:25 17920 —-a-w- c:\windows\system32\ROUTE.EXE 2011-04-05 07:04:25 11264 —-a-w- c:\windows\system32\MRINFO.EXE 2011-04-05 07:04:25 105984 —-a-w- c:\windows\system32\netiohlp.dll 2011-04-05 07:04:25 10240 —-a-w- c:\windows\system32\finger.exe 2011-04-05 07:03:46 68096 —-a-w- c:\windows\system32\wlanhlp.dll 2011-04-05 07:03:46 65024 —-a-w- c:\windows\system32\wlanapi.dll 2011-04-05 07:03:46 127488 —-a-w- c:\windows\system32\L2SecHC.dll 2011-04-05 07:03:45 513536 —-a-w- c:\windows\system32\wlansvc.dll 2011-04-05 07:03:45 302592 —-a-w- c:\windows\system32\wlansec.dll 2011-04-05 07:03:45 293376 —-a-w- c:\windows\system32\wlanmsm.dll 2011-04-05 07:03:42 15181 —-a-w- c:\windows\system32\gatherWirelessInfo.vbs 2011-04-05 07:03:22 218624 —-a-w- c:\windows\system32\msv1_0.dll 2011-04-05 07:00:39 160256 —-a-w- c:\windows\system32\wkssvc.dll 2011-04-05 06:59:34 623616 —-a-w- c:\windows\system32\localspl.dll 2011-04-05 06:59:06 172032 —-a-w- c:\windows\system32\wintrust.dll 2011-04-05 06:56:59 6014976 —-a-w- c:\windows\system32\NlsLexicons001a.dll 2011-04-05 06:54:56 6656 —-a-w- c:\windows\system32\kbd106n.dll 2011-04-05 06:53:32 98304 —-a-w- c:\windows\system32\cabview.dll 2011-04-05 06:53:01 313344 —-a-w- c:\windows\system32\wmpdxm.dll 2011-04-05 06:53:01 18432 —-a-w- c:\windows\system32\amcompat.tlb 2011-04-05 06:53:00 43520 —-a-w- c:\windows\system32\msdxm.tlb 2011-04-05 06:52:58 7680 —-a-w- c:\windows\system32\spwmp.dll 2011-04-05 06:52:58 4096 —-a-w- c:\windows\system32\msdxm.ocx 2011-04-05 06:52:58 4096 —-a-w- c:\windows\system32\dxmasf.dll 2011-04-04 15:23:14 1401856 —-a-w- c:\windows\system32\msxml6.dll 2011-04-04 15:23:11 2048 —-a-w- c:\windows\system32\msxml3r.dll 2011-04-04 15:23:10 2048 —-a-w- c:\windows\system32\msxml6r.dll 2011-04-04 15:18:16 71680 —-a-w- c:\windows\system32\atl.dll 2011-04-04 15:11:55 499712 —-a-w- c:\windows\system32\kerberos.dll 2011-04-04 15:11:55 175104 —-a-w- c:\windows\system32\wdigest.dll 2011-04-04 15:11:53 9728 —-a-w- c:\windows\system32\lsass.exe 2011-04-04 15:11:53 72704 —-a-w- c:\windows\system32\secur32.dll 2011-04-04 15:11:53 439864 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2011-04-04 15:11:52 1259008 —-a-w- c:\windows\system32\lsasrv.dll 2011-04-04 14:45:30 60928 —-a-w- c:\windows\system32\msasn1.dll 2011-04-04 14:45:16 784896 —-a-w- c:\windows\system32\rpcrt4.dll 2011-04-04 14:44:49 243712 —-a-w- c:\windows\system32\rastls.dll 2011-04-04 14:44:32 355328 —-a-w- c:\windows\system32\WSDApi.dll 2011-04-04 10:13:35 23552 —-a-w- c:\windows\system32\lpk.dll 2011-04-04 10:13:35 10240 —-a-w- c:\windows\system32\dciman32.dll 2011-04-04 10:11:31 53248 —-a-w- c:\windows\system32\rrinstaller.exe 2011-04-04 10:11:31 24576 —-a-w- c:\windows\system32\mfpmp.exe 2011-04-04 10:11:31 2048 —-a-w- c:\windows\system32\mferror.dll 2011-04-04 10:10:39 714240 —-a-w- c:\windows\system32\timedate.cpl 2011-04-04 10:09:13 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax 2011-04-04 10:04:53 62464 —-a-w- c:\windows\system32\l3codeca.acm 2011-04-04 10:04:53 220672 —-a-w- c:\windows\system32\l3codecp.acm 2011-04-04 10:04:08 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys 2011-04-04 10:04:08 200704 —-a-w- c:\windows\system32\iphlpsvc.dll 2011-04-04 10:04:07 30720 —-a-w- c:\windows\system32\drivers\tcpipreg.sys 2011-04-04 10:04:07 15360 —-a-w- c:\windows\system32\drivers\TUNMP.SYS 2011-04-04 10:03:06 37888 —-a-w- c:\windows\system32\printcom.dll 2011-04-04 10:02:47 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe 2011-04-04 10:02:47 332288 —-a-w- c:\windows\system32\msdrm.dll 2011-04-04 10:02:47 152064 —-a-w- c:\windows\system32\secproc_ssp.dll 2011-04-04 10:02:46 518144 —-a-w- c:\windows\system32\RMActivate.exe 2011-04-04 10:02:46 471552 —-a-w- c:\windows\system32\secproc.dll 2011-04-04 10:02:46 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2011-04-04 10:02:46 152576 —-a-w- c:\windows\system32\secproc_ssp_isv.dll 2011-04-04 10:02:45 526336 —-a-w- c:\windows\system32\RMActivate_isv.exe 2011-04-04 10:02:45 471552 —-a-w- c:\windows\system32\secproc_isv.dll 2011-04-04 10:02:05 2560 —-a-w- c:\windows\apppatch\AcRes.dll 2011-04-04 10:01:07 84480 —-a-w- c:\windows\system32\INETRES.dll 2011-04-04 09:59:34 91136 —-a-w- c:\windows\system32\avifil32.dll 2011-04-04 09:59:34 82944 —-a-w- c:\windows\system32\mciavi32.dll 2011-04-04 09:59:34 65024 —-a-w- c:\windows\system32\avicap32.dll 2011-04-04 09:59:34 31744 —-a-w- c:\windows\system32\msvidc32.dll 2011-04-04 09:59:34 13312 —-a-w- c:\windows\system32\msrle32.dll 2011-04-04 09:59:34 123904 —-a-w- c:\windows\system32\msvfw32.dll 2011-04-04 09:59:33 22528 —-a-w- c:\windows\system32\msyuv.dll 2011-04-04 09:59:33 1314816 —-a-w- c:\windows\system32\quartz.dll 2011-04-04 09:59:32 50176 —-a-w- c:\windows\system32\iyuv_32.dll 2011-04-04 09:59:32 12288 —-a-w- c:\windows\system32\tsbyuv.dll 2011-04-04 09:59:00 310784 —-a-w- c:\windows\system32\unregmp2.exe 2011-04-04 09:14:11 297808 —-a-w- c:\windows\system32\mscoree.dll 2011-04-04 09:14:11 1130824 —-a-w- c:\windows\system32\dfshim.dll 2011-04-04 09:14:10 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll 2011-04-04 09:14:10 49472 —-a-w- c:\windows\system32\netfxperf.dll 2011-04-04 09:14:10 295264 —-a-w- c:\windows\system32\PresentationHost.exe 2011-04-04 07:16:52 53248 —-a-w- c:\windows\system32\tsgqec.dll 2011-04-04 07:16:52 136192 —-a-w- c:\windows\system32\aaclient.dll 2011-04-04 07:15:51 14848 —-a-w- c:\windows\system32\wshrm.dll 2011-04-04 07:15:12 411648 —-a-w- c:\windows\system32\drivers\http.sys 2011-04-04 07:15:12 30720 —-a-w- c:\windows\system32\httpapi.dll 2011-04-04 07:15:12 24064 —-a-w- c:\windows\system32\nshhttp.dll 2011-04-04 07:01:20 604672 —-a-w- c:\windows\system32\WMSPDMOD.DLL 2011-04-01 14:51:57 353096 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys 2011-04-01 14:51:47 308296 —-a-w- c:\windows\system32\drivers\trufos.sys 2011-04-01 14:51:29 105808 —-a-w- c:\windows\system32\drivers\bdhv.sys 2011-03-30 03:24:34 2421760 —-a-w- c:\windows\system32\wucltux.dll 2011-03-30 03:23:56 87552 —-a-w- c:\windows\system32\wudriver.dll 2011-03-30 03:23:24 33792 —-a-w- c:\windows\system32\wuapp.exe . ============= FINISH: 18:42:21.80 ===============
Hi cjayc,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

As we work through your logs. Please remember to run any tools by Right-clicking on the icon and selecting Run As Administrator….

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    
    :Files
    c:\users\jaye\appdata\local\Ilivid Player
    c:\users\jaye\appdata\local\PackageAware
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Then

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI