This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu malware

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I have searchqu infecting my machine, please help me remove it!!
It appeared around the same time as I installed Bandoo / iLivid so I suspect it's come from there.
It's no longer appearing in program files after a system restore but continues to become the default search engine / home page when I reboot.

Please find the following OTL log…


OTL logfile created on: 19/06/2011 20:17:43 - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Alun\Downloads
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.99 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 49.53% Memory free
6.19 Gb Paging File | 4.61 Gb Available in Paging File | 74.58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 283.40 Gb Total Space | 82.07 Gb Free Space | 28.96% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 9.57 Gb Free Space | 65.37% Space Free | Partition Type: NTFS

Computer Name: ALUNLAPTOP | User Name: Alun | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Alun\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ec3a90dd\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ec3a90dd\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Windows\System32\drivers\o2flash.exe (O2Micro International)
PRC - C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - c:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - C:\Users\Alun\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ec3a90dd\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ec3a90dd\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (O2FLASH) – C:\Windows\System32\drivers\o2flash.exe (O2Micro International)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (RapportCerberus_26762) – C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\26762\RapportCerberus_26762.sys (Trusteer Ltd.)
DRV - (RapportEI) – C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\Windows\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (O2SDGRDR) – C:\Windows\System32\drivers\o2sdg.sys (O2Micro )
DRV - (O2MDGRDR) – C:\Windows\System32\drivers\o2mdg.sys (O2Micro )
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (OEM13Vid) – C:\Windows\System32\drivers\OEM13Vid.sys (Creative Technology Ltd.)
DRV - (OEM13Vfx) – C:\Windows\System32\drivers\OEM13Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USSMB/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 B6 7A 9A 04 C3 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\DigitalPersona\Bin\FirefoxExt\ [2010/07/28 22:49:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/06/02 21:45:47 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (DigitalPersona Fingerprint Software Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\dellwall1.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\dellwall1.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/21 13:31:39 | 000,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{51c31cfd-be39-11de-a87e-0c607698b79a}\Shell - "" = AutoRun
O33 - MountPoints2\{51c31cfd-be39-11de-a87e-0c607698b79a}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{67ee0cfd-8587-11e0-9f11-0c607698b79a}\Shell - "" = AutoRun
O33 - MountPoints2\{67ee0cfd-8587-11e0-9f11-0c607698b79a}\Shell\AutoRun\command - "" = F:\unlock.exe autoplay=true
O33 - MountPoints2\{e107d711-0a55-11e0-a654-0c607698b79a}\Shell - "" = AutoRun
O33 - MountPoints2\{e107d711-0a55-11e0-a654-0c607698b79a}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/06/19 18:26:04 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{3567E40C-6A2A-4F6D-B0EC-762483ABB9D3}
[2011/06/18 21:19:37 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{87653691-0DF6-4072-B87C-34C330FD9000}
[2011/06/17 21:43:24 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{131F72FD-E466-473E-9F1E-15BAC1949921}
[2011/06/16 22:53:08 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/06/16 22:53:05 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/06/16 22:53:04 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/06/16 22:53:04 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/06/16 22:53:04 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/06/16 22:53:04 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/06/16 22:53:04 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/06/16 22:53:04 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/06/16 22:53:04 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/06/16 22:53:04 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/06/16 22:53:03 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/06/16 22:53:03 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/06/16 22:53:03 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/06/16 22:53:03 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/06/16 22:53:03 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/06/16 22:53:03 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/06/16 22:53:03 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/06/16 22:43:00 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{B7F8B3D9-D2BA-4403-8FAA-9467B6780C26}
[2011/06/15 18:52:35 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{A1E2D7F0-E910-4FE3-966E-033729818E29}
[2011/06/14 22:36:25 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{CF48AB26-CC03-4591-B0A7-8F918B5797B6}
[2011/06/13 18:27:37 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{A69DF137-17D0-4047-B38B-958C333AECC7}
[2011/06/12 23:47:55 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{E1AF7EAD-4325-45A1-AEE0-91F96A5C0F44}
[2011/06/12 11:47:16 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{81097046-4011-4A57-BCE2-7BF6B15349D2}
[2011/06/10 21:16:13 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{1DAF52BB-3590-40CB-B0BB-A0C33038C799}
[2011/06/09 01:56:43 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{F918C413-7BF8-444A-96A6-0E52B9648E2F}
[2011/06/07 20:44:34 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{CBDA6273-5D48-4DAF-999E-045795972ABF}
[2011/06/06 17:46:02 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{32C83AAD-4FB1-41A2-AFB1-3197310D6B0D}
[2011/06/05 19:15:34 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{A26FEEF1-E8CF-46AE-BCDB-5B06E314B62E}
[2011/06/04 22:08:17 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{0F246D31-C389-4734-BAB0-8474127C4C01}
[2011/06/03 19:08:09 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{A74CD983-9D6D-4437-8B8A-AE5604131436}
[2011/06/01 18:42:20 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{B3C128A3-C15D-46E2-8D2C-462C1F1C12F9}
[2011/05/31 21:04:09 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{B24A9156-FD3E-4D56-BE45-8777C261B588}
[2011/05/30 22:20:03 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{4FC0E872-7579-4242-9389-A98A821DCF57}
[2011/05/30 10:19:39 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{13928B43-E24F-4EA5-8538-97375F759AAA}
[2011/05/29 21:23:26 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{8B0C0B18-9866-4E3C-A964-22748EF399B2}
[2011/05/28 23:18:26 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{CCE35CDC-AD8E-42D8-86E8-78DD0095C308}
[2011/05/28 22:57:24 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Roaming\Malwarebytes
[2011/05/28 22:57:09 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/28 22:57:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/28 22:57:09 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/28 22:57:06 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/05/28 22:57:06 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/28 22:54:22 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\Alun\Desktop\mbam-setup.exe
[2011/05/28 11:18:05 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{6726919A-C288-4714-86AE-C3774A928A61}
[2011/05/27 22:01:30 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{58596604-1C38-4F01-9BD5-C785C3BF4EFA}
[2011/05/26 22:26:32 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{F3D0E4AC-BB28-4A13-84AC-43A677FFED8F}
[2011/05/24 19:38:09 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{42017AF5-C749-459E-8FC2-7B531B768A07}
[2011/05/23 22:46:14 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\{A6528A4C-5837-4FBE-86C4-CE10A63C65B3}
[2011/05/23 21:29:16 | 000,000,000 | —D | C] – C:\ProgramData\Western Digital
[2011/05/23 21:27:58 | 000,000,000 | —D | C] – C:\Program Files\Western Digital
[2011/05/23 21:26:09 | 000,000,000 | —D | C] – C:\Users\Alun\AppData\Local\Western Digital

========== Files - Modified Within 30 Days ==========

[2011/06/19 20:01:17 | 000,167,912 | —- | M] () – C:\ProgramData\nvModes.001
[2011/06/19 20:00:12 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/19 19:54:44 | 000,609,196 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/06/19 19:54:44 | 000,108,672 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/06/19 19:50:18 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/19 19:50:17 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/19 19:50:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/19 19:49:44 | 3213,881,344 | -HS- | M] () – C:\hiberfil.sys
[2011/06/19 19:48:19 | 000,002,140 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/06/19 19:23:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4284807790-2166530176-3820547900-1000UA.job
[2011/06/19 18:32:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/19 18:29:31 | 119,179,087 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2011/06/18 22:23:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4284807790-2166530176-3820547900-1000Core.job
[2011/06/17 21:43:47 | 000,167,912 | —- | M] () – C:\ProgramData\nvModes.dat
[2011/06/15 22:38:39 | 000,000,000 | —- | M] () – C:\Windows\System32\null
[2011/06/14 22:37:41 | 000,002,039 | —- | M] () – C:\Users\Alun\Desktop\Google Chrome.lnk
[2011/06/14 22:37:41 | 000,002,001 | —- | M] () – C:\Users\Alun\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/06/02 21:45:48 | 000,000,832 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2011/05/31 22:20:43 | 000,067,584 | —- | M] () – C:\Users\Alun\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/28 22:57:09 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/28 22:56:46 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Alun\Desktop\mbam-setup.exe
[2011/05/28 17:58:23 | 000,009,728 | —- | M] () – C:\Users\Alun\Documents\For Sale - Scenic.wps
[2011/05/28 17:58:23 | 000,001,970 | —- | M] () – C:\Users\Alun\AppData\Roaming\wklnhst.dat
[2011/05/28 07:05:27 | 000,611,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/05/28 07:04:56 | 000,602,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/28 07:04:56 | 000,055,296 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/28 07:04:30 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/28 07:04:22 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/28 07:04:17 | 001,469,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/28 07:04:03 | 000,164,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/28 07:04:03 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/28 07:04:03 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/28 07:04:02 | 000,184,320 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/28 07:04:02 | 000,055,808 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/28 07:03:58 | 000,387,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/28 06:10:26 | 000,385,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/28 05:33:03 | 000,133,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/28 05:32:51 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/28 05:32:15 | 000,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/28 05:31:44 | 001,638,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/23 22:48:03 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk

========== Files Created - No Company Name ==========

[2011/05/28 22:57:09 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/28 17:58:23 | 000,009,728 | —- | C] () – C:\Users\Alun\Documents\For Sale - Scenic.wps
[2010/02/01 23:07:54 | 000,178,176 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/01/19 12:49:54 | 000,466,944 | —- | C] () – C:\Windows\System32\RemoveDevice.dll
[2009/11/28 02:51:12 | 000,067,584 | —- | C] () – C:\Users\Alun\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/31 15:53:35 | 000,000,680 | —- | C] () – C:\Users\Alun\AppData\Local\d3d9caps.dat
[2009/10/26 20:49:35 | 000,001,970 | —- | C] () – C:\Users\Alun\AppData\Roaming\wklnhst.dat
[2009/10/24 23:06:54 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/10/21 21:23:32 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/10/21 21:23:31 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/10/21 21:23:11 | 000,062,976 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/10/21 14:14:01 | 000,167,912 | —- | C] () – C:\ProgramData\nvModes.001
[2009/10/21 14:13:47 | 000,167,912 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/10/15 15:53:38 | 000,055,808 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2009/10/15 15:53:37 | 000,024,064 | —- | C] () – C:\Windows\System32\WLTRYSVC.EXE
[2009/10/15 15:53:23 | 000,000,075 | RHS- | C] () – C:\Windows\CT4CET.bin
[2009/10/15 10:37:22 | 000,002,140 | —- | C] () – C:\Windows\bthservsdp.dat
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/04/11 17:42:42 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/04/11 15:48:25 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/03 23:25:56 | 000,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006/11/02 13:56:48 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:43 | 000,354,952 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 11:33:01 | 000,609,196 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,108,672 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 11:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/11/14 18:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2009/11/20 13:25:20 | 000,000,000 | —D | M] – C:\Users\Alun\AppData\Roaming\Autodesk
[2011/02/13 10:56:23 | 000,000,000 | —D | M] – C:\Users\Alun\AppData\Roaming\AVG10
[2011/06/17 03:20:41 | 000,000,000 | —D | M] – C:\Users\Alun\AppData\Roaming\BitTorrent
[2009/10/21 13:17:47 | 000,000,000 | —D | M] – C:\Users\Alun\AppData\Roaming\DigitalPersona
[2009/10/26 20:49:37 | 000,000,000 | —D | M] – C:\Users\Alun\AppData\Roaming\Template
[2009/10/21 21:55:43 | 000,000,000 | —D | M] – C:\Users\Alun\AppData\Roaming\tmp
[2011/04/27 10:17:15 | 000,000,000 | —D | M] – C:\Users\Alun\AppData\Roaming\Trusteer
[2011/06/19 19:48:22 | 000,032,638 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/12/29 01:15:38 | 000,008,702 | —- | M] () – C:\debug.txt
[2009/10/15 18:31:38 | 000,003,568 | RH– | M] () – C:\dell.sdr
[2011/06/19 19:49:44 | 3213,881,344 | -HS- | M] () – C:\hiberfil.sys
[2011/06/19 19:49:40 | 3529,539,584 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:19 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:19 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:19 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/26 12:57:19 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 13:36:30 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 03:43:58 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 04:20:25 | 017,223,680 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04:20:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04:20:25 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/04 00:17:10 | 000,000,574 | -HS- | M] () – C:\Users\Alun\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/05/28 22:56:46 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Alun\Desktop\mbam-setup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-18 02:01:29

< End of report >



Hoping you can help.

Thanks,
Al
:welcome:


OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [RESETHOSTS] 
    [purity]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
New log… All processes killed ========== OTL ========== HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Alun ->Flash cache emptied: 129281 bytes User: Default User: Default User User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Alun ->Temp folder emptied: 739902749 bytes ->Temporary Internet Files folder emptied: 249739283 bytes ->Java cache emptied: 147279111 bytes ->Google Chrome cache emptied: 435156894 bytes ->Flash cache emptied: 0 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33184 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 230421834 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 59718 bytes %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 741 bytes RecycleBin emptied: 1314784938 bytes Total Files Cleaned = 2,973.00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.24.1 log created on 06192011_214943 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI