Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information…
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: SetIEInstalledDate.exe
Submission date: 2011-10-22 19:47:49 (UTC)
Current status: finished
Result: 0/ 43 (0.0%)
VT Community
not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.10.22.00 2011.10.22 -
AntiVir 7.11.16.106 2011.10.21 -
Antiy-AVL 2.0.3.7 2011.10.22 -
Avast 6.0.1289.0 2011.10.22 -
AVG 10.0.0.1190 2011.10.22 -
BitDefender 7.2 2011.10.22 -
ByteHero 1.0.0.1 2011.09.23 -
CAT-QuickHeal 11.00 2011.10.21 -
ClamAV 0.97.0.0 2011.10.22 -
Commtouch 5.3.2.6 2011.10.22 -
Comodo 10529 2011.10.22 -
DrWeb 5.0.2.03300 2011.10.22 -
Emsisoft 5.1.0.11 2011.10.22 -
eSafe 7.0.17.0 2011.10.17 -
eTrust-Vet 36.1.8633 2011.10.21 -
F-Prot 4.6.5.141 2011.10.21 -
F-Secure 9.0.16440.0 2011.10.22 -
Fortinet 4.3.370.0 2011.10.22 -
GData 22 2011.10.22 -
Ikarus T3.1.1.107.0 2011.10.22 -
Jiangmin 13.0.900 2011.10.22 -
K7AntiVirus 9.116.5326 2011.10.22 -
Kaspersky 9.0.0.837 2011.10.22 -
McAfee 5.400.0.1158 2011.10.22 -
McAfee-GW-Edition 2010.1D 2011.10.22 -
Microsoft 1.7801 2011.10.22 -
NOD32 6566 2011.10.22 -
Norman 6.07.13 2011.10.22 -
nProtect 2011-10-22.01 2011.10.22 -
Panda 10.0.3.5 2011.10.22 -
PCTools 8.0.0.5 2011.10.22 -
Prevx 3.0 2011.10.22 -
Rising 23.80.04.02 2011.10.21 -
Sophos 4.70.0 2011.10.22 -
SUPERAntiSpyware 4.40.0.1006 2011.10.22 -
Symantec 20111.2.0.82 2011.10.22 -
TheHacker 6.7.0.1.327 2011.10.19 -
TrendMicro 9.500.0.1008 2011.10.22 -
TrendMicro-HouseCall 9.500.0.1008 2011.10.22 -
VBA32 3.12.16.4 2011.10.21 -
VIPRE 10841 2011.10.22 -
ViRobot 2011.10.22.4733 2011.10.22 -
VirusBuster 14.1.25.0 2011.10.22 -
Additional informationShow all
MD5 : 736d1b28224f9df8008be8b0dedfc9ef
SHA1 : 1d36b4dd18b65b5f2006d21f450ef6da17cc53d3
SHA256: d1bdeb73fe2112574d97414088b23e8be010e166a2ab47be18bec7cd14f031bc
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: IEAdvpack.dll
Submission date: 2011-10-22 20:04:35 (UTC)
Current status: finished
Result: 0/ 43 (0.0%)
VT Community
not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.10.22.00 2011.10.22 -
AntiVir 7.11.16.106 2011.10.21 -
Antiy-AVL 2.0.3.7 2011.10.22 -
Avast 6.0.1289.0 2011.10.22 -
AVG 10.0.0.1190 2011.10.22 -
BitDefender 7.2 2011.10.22 -
ByteHero 1.0.0.1 2011.09.23 -
CAT-QuickHeal 11.00 2011.10.21 -
ClamAV 0.97.0.0 2011.10.22 -
Commtouch 5.3.2.6 2011.10.22 -
Comodo 10529 2011.10.22 -
DrWeb 5.0.2.03300 2011.10.22 -
Emsisoft 5.1.0.11 2011.10.22 -
eSafe 7.0.17.0 2011.10.17 -
eTrust-Vet 36.1.8633 2011.10.21 -
F-Prot 4.6.5.141 2011.10.21 -
F-Secure 9.0.16440.0 2011.10.22 -
Fortinet 4.3.370.0 2011.10.22 -
GData 22 2011.10.22 -
Ikarus T3.1.1.107.0 2011.10.22 -
Jiangmin 13.0.900 2011.10.22 -
K7AntiVirus 9.116.5326 2011.10.22 -
Kaspersky 9.0.0.837 2011.10.22 -
McAfee 5.400.0.1158 2011.10.22 -
McAfee-GW-Edition 2010.1D 2011.10.22 -
Microsoft 1.7801 2011.10.22 -
NOD32 6566 2011.10.22 -
Norman 6.07.13 2011.10.22 -
nProtect 2011-10-22.01 2011.10.22 -
Panda 10.0.3.5 2011.10.22 -
PCTools 8.0.0.5 2011.10.22 -
Prevx 3.0 2011.10.22 -
Rising 23.80.04.02 2011.10.21 -
Sophos 4.70.0 2011.10.22 -
SUPERAntiSpyware 4.40.0.1006 2011.10.22 -
Symantec 20111.2.0.82 2011.10.22 -
TheHacker 6.7.0.1.327 2011.10.19 -
TrendMicro 9.500.0.1008 2011.10.22 -
TrendMicro-HouseCall 9.500.0.1008 2011.10.22 -
VBA32 3.12.16.4 2011.10.21 -
VIPRE 10841 2011.10.22 -
ViRobot 2011.10.22.4733 2011.10.22 -
VirusBuster 14.1.25.0 2011.10.22 -
Additional informationShow all
MD5 : ed6f6fbbcdec95483b7351e23f4fcdf6
SHA1 : f1be16ebff456033a5795b55ccb3d7ad6c30887f
SHA256: b5664313e8f937ea6de7ec38cfd0ad45f75d743472a8ff22921232eeb080b974
This is the ComboFix log -
ComboFix 11-10-21.06 - Aprilbaby 23/10/2011 8:01.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3933.2133 [GMT 11:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\Aprilbaby\Downloads\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\SearchCore for Browsers
.
.
((((((((((((((((((((((((( Files Created from 2011-09-22 to 2011-10-22 )))))))))))))))))))))))))))))))
.
.
2011-10-22 21:17 . 2011-10-22 21:17 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-10-21 10:51 . 2011-10-21 10:51 ——– d—–w- c:\program files (x86)\Common Files\Java
2011-10-20 21:24 . 2011-09-20 22:00 9049936 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F2E1C5ED-EF2E-4B9A-BB8D-F03EFF6B2C4F}\mpengine.dll
2011-10-20 20:02 . 2011-10-20 20:02 ——– d—–w- C:\_OTL
2011-10-19 12:34 . 2011-09-06 19:38 301912 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-10-19 12:34 . 2011-09-06 19:36 24408 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-10-19 12:34 . 2011-09-06 19:36 42328 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-10-19 12:34 . 2011-09-06 19:36 58200 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-10-19 12:34 . 2011-09-06 19:38 601944 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-10-19 12:34 . 2011-09-06 19:45 254400 —-a-w- c:\windows\system32\aswBoot.exe
2011-10-19 12:34 . 2011-09-06 19:36 65368 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-10-19 12:34 . 2011-09-06 19:45 41184 —-a-w- c:\windows\avastSS.scr
2011-10-19 12:34 . 2011-09-06 19:45 199304 —-a-w- c:\windows\SysWow64\aswBoot.exe
2011-10-19 12:34 . 2011-10-19 12:34 ——– d—–w- c:\programdata\AVAST Software
2011-10-19 12:34 . 2011-10-19 12:34 ——– d—–w- c:\program files\AVAST Software
2011-10-19 11:57 . 2011-10-19 11:57 ——– d—–w- c:\windows\system32\Macromed
2011-10-18 22:28 . 2011-10-18 22:28 ——– d—–w- c:\program files (x86)\Safari
2011-10-18 22:26 . 2011-10-18 22:27 ——– d—–w- c:\program files\iTunes
2011-10-18 22:26 . 2011-10-18 22:27 ——– d—–w- c:\program files (x86)\iTunes
2011-10-18 22:26 . 2011-10-18 22:26 ——– d—–w- c:\program files\iPod
2011-10-18 22:20 . 2011-10-18 22:20 ——– d—–w- c:\program files\Bonjour
2011-10-18 22:20 . 2011-10-18 22:20 ——– d—–w- c:\program files (x86)\Bonjour
2011-10-17 20:22 . 2011-10-17 20:22 ——– d—–w- c:\program files (x86)\Common Files\AVG Secure Search
2011-10-17 20:22 . 2011-10-17 20:22 ——– d—–w- c:\program files (x86)\AVG Secure Search
2011-10-17 20:20 . 2011-10-17 20:20 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\AVG2012
2011-10-17 20:19 . 2011-10-17 20:38 ——– d—–w- c:\programdata\AVG2012
2011-10-13 04:45 . 2011-09-06 03:03 3138048 —-a-w- c:\windows\system32\win32k.sys
2011-10-13 04:43 . 2011-08-17 05:26 613888 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-13 04:43 . 2011-08-17 05:25 108032 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-13 04:43 . 2011-08-17 04:24 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll
2011-10-13 04:43 . 2011-08-17 04:19 75776 —-a-w- c:\windows\SysWow64\psisrndr.ax
2011-10-13 04:43 . 2011-08-27 05:37 861696 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-13 04:43 . 2011-08-27 05:37 331776 —-a-w- c:\windows\system32\oleacc.dll
2011-10-13 04:43 . 2011-08-27 04:26 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-13 04:43 . 2011-08-27 04:26 233472 —-a-w- c:\windows\SysWow64\oleacc.dll
2011-10-10 19:34 . 2011-10-10 19:34 ——– d—–w- c:\programdata\boost_interprocess
2011-10-10 00:13 . 2011-10-10 00:14 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\vlc
2011-10-10 00:06 . 2011-10-10 00:06 ——– d—–w- c:\users\Aprilbaby\AppData\Local\PackageAware
2011-10-04 21:13 . 2011-10-04 21:13 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\DivoGames
2011-10-04 20:47 . 2011-10-04 20:54 ——– d—–w- c:\users\Aprilbaby\Jack of all Tribes
2011-09-26 01:48 . 2011-09-26 01:48 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\Unity
2011-09-26 01:40 . 2011-09-26 20:34 ——– d—–w- c:\users\Aprilbaby\AppData\Local\Unity
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-15 21:26 . 2011-06-03 22:42 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-02 18:06 . 2010-07-27 08:06 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2011-09-12 19:30 . 2011-09-12 19:30 37456 —-a-w- c:\windows\system32\drivers\avgrkx64.sys
2011-08-31 07:00 . 2011-03-15 13:25 25416 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-30 12:05 . 2011-08-30 12:05 96104 —-a-w- c:\windows\system32\dns-sd.exe
2011-08-30 12:05 . 2011-08-30 12:05 85864 —-a-w- c:\windows\system32\dnssd.dll
2011-08-30 12:05 . 2011-08-30 12:05 61288 —-a-w- c:\windows\system32\jdns_sd.dll
2011-08-30 12:05 . 2011-08-30 12:05 212840 —-a-w- c:\windows\system32\dnssdX.dll
2011-08-30 12:05 . 2011-08-30 12:05 83816 —-a-w- c:\windows\SysWow64\dns-sd.exe
2011-08-30 12:05 . 2011-08-30 12:05 73064 —-a-w- c:\windows\SysWow64\dnssd.dll
2011-08-30 12:05 . 2011-08-30 12:05 50536 —-a-w- c:\windows\SysWow64\jdns_sd.dll
2011-08-30 12:05 . 2011-08-30 12:05 178536 —-a-w- c:\windows\SysWow64\dnssdX.dll
2011-08-15 09:23 . 2011-08-15 09:23 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-07 19:08 . 2011-08-07 19:08 46672 —-a-w- c:\windows\system32\drivers\avgmfx64.sys
2011-08-02 06:38 . 2011-08-02 06:38 51712 —-a-w- c:\windows\system32\drivers\usbaapl64.sys
2011-08-02 06:38 . 2011-08-02 06:38 4517664 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-07-29 13:23 . 2011-07-29 13:23 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-07-29 13:23 . 2011-07-29 13:23 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-07-29 13:23 . 2011-07-29 13:23 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll
2011-07-29 13:23 . 2011-07-29 13:23 161792 —-a-w- c:\windows\SysWow64\msls31.dll
2011-07-29 13:23 . 2011-07-29 13:23 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-07-29 13:23 . 2011-07-29 13:23 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll
2011-07-29 13:23 . 2011-07-29 13:23 74752 —-a-w- c:\windows\SysWow64\iesetup.dll
2011-07-29 13:23 . 2011-07-29 13:23 63488 —-a-w- c:\windows\SysWow64\tdc.ocx
2011-07-29 13:23 . 2011-07-29 13:23 367104 —-a-w- c:\windows\SysWow64\html.iec
2011-07-29 13:23 . 2011-07-29 13:23 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll
2011-07-29 13:23 . 2011-07-29 13:23 152064 —-a-w- c:\windows\SysWow64\wextract.exe
2011-07-29 13:23 . 2011-07-29 13:23 150528 —-a-w- c:\windows\SysWow64\iexpress.exe
2011-07-29 13:23 . 2011-07-29 13:23 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2011-07-29 13:23 . 2011-07-29 13:23 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-07-29 13:23 . 2011-07-29 13:23 420864 —-a-w- c:\windows\SysWow64\vbscript.dll
2011-07-29 13:23 . 2011-07-29 13:23 35840 —-a-w- c:\windows\SysWow64\imgutil.dll
2011-07-29 13:23 . 2011-07-29 13:23 222208 —-a-w- c:\windows\system32\msls31.dll
2011-07-29 13:23 . 2011-07-29 13:23 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2011-07-29 13:23 . 2011-07-29 13:23 11776 —-a-w- c:\windows\SysWow64\mshta.exe
2011-07-29 13:23 . 2011-07-29 13:23 101888 —-a-w- c:\windows\SysWow64\admparse.dll
2011-07-29 13:23 . 2011-07-29 13:23 49664 —-a-w- c:\windows\system32\imgutil.dll
2011-07-29 13:23 . 2011-07-29 13:23 173056 —-a-w- c:\windows\system32\ieUnatt.exe
2011-07-29 13:23 . 2011-07-29 13:23 12288 —-a-w- c:\windows\system32\mshta.exe
2011-07-29 13:23 . 2011-07-29 13:23 114176 —-a-w- c:\windows\system32\admparse.dll
2011-07-29 13:23 . 2011-07-29 13:23 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-07-29 13:23 . 2011-07-29 13:23 85504 —-a-w- c:\windows\system32\iesetup.dll
2011-07-29 13:23 . 2011-07-29 13:23 76800 —-a-w- c:\windows\system32\tdc.ocx
2011-07-29 13:23 . 2011-07-29 13:23 48640 —-a-w- c:\windows\system32\mshtmler.dll
2011-07-29 13:23 . 2011-07-29 13:23 448512 —-a-w- c:\windows\system32\html.iec
2011-07-29 13:23 . 2011-07-29 13:23 30720 —-a-w- c:\windows\system32\licmgr10.dll
2011-07-29 13:23 . 2011-07-29 13:23 160256 —-a-w- c:\windows\system32\wextract.exe
2011-07-29 13:23 . 2011-07-29 13:23 1492992 —-a-w- c:\windows\system32\inetcpl.cpl
2011-07-29 13:23 . 2011-07-29 13:23 135168 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-07-29 13:23 . 2011-07-29 13:23 111616 —-a-w- c:\windows\system32\iesysprep.dll
2011-07-29 13:23 . 2011-07-29 13:23 603648 —-a-w- c:\windows\system32\vbscript.dll
2011-07-29 13:23 . 2011-07-29 13:23 165888 —-a-w- c:\windows\system32\iexpress.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-21_06.46.23 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-05-12 22:43 . 2011-10-20 20:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2011-05-12 22:43 . 2011-10-21 19:53 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 04:54 . 2011-10-21 06:45 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-10-22 21:20 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-10-21 06:45 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-10-22 21:20 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-10-21 06:45 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-10-22 21:20 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 05:10 . 2011-10-22 21:21 55658 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-11-22 06:40 . 2011-10-22 21:21 23572 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1601795646-3932628227-3861186438-1005_UserData.bin
+ 2009-11-22 21:29 . 2011-10-21 19:57 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-22 21:29 . 2011-10-18 04:49 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-10-21 07:27 . 2011-10-21 19:57 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-10-21 19:57 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-10-18 04:49 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-01 06:41 . 2011-10-21 06:42 3210 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2009-12-01 06:41 . 2011-10-22 10:47 3210 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2011-10-22 21:19 . 2011-10-22 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-10-21 06:43 . 2011-10-21 06:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-10-21 06:43 . 2011-10-21 06:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-10-22 21:19 . 2011-10-22 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-10-21 10:50 . 2011-10-02 18:06 157472 c:\windows\SysWOW64\javaws.exe
- 2011-06-17 23:19 . 2011-05-03 18:52 157472 c:\windows\SysWOW64\javaws.exe
- 2011-06-17 23:19 . 2011-05-03 18:52 145184 c:\windows\SysWOW64\javaw.exe
+ 2011-10-21 10:50 . 2011-10-02 18:06 145184 c:\windows\SysWOW64\javaw.exe
+ 2011-10-21 10:50 . 2011-10-02 18:06 145184 c:\windows\SysWOW64\java.exe
- 2011-06-17 23:19 . 2011-05-03 18:52 145184 c:\windows\SysWOW64\java.exe
+ 2009-11-23 06:10 . 2011-10-22 09:40 268788 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 02:36 . 2011-10-22 18:27 727720 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-10-21 03:26 727720 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-10-22 18:27 149422 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-10-21 03:26 149422 c:\windows\system32\perfc009.dat
- 2009-07-14 05:01 . 2011-10-21 06:42 463204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-10-22 21:18 463204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-10-21 10:50 . 2011-10-21 10:50 207360 c:\windows\Installer\1956fd.msi
- 2010-10-22 10:16 . 2011-10-21 06:42 3786516 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1601795646-3932628227-3861186438-1005-8192.dat
+ 2010-10-22 10:16 . 2011-10-22 21:18 3786516 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1601795646-3932628227-3861186438-1005-8192.dat
+ 2011-06-08 12:34 . 2011-10-21 10:20 2357891 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1601795646-3932628227-3861186438-1005-12288.dat
+ 2011-06-02 14:02 . 2011-10-22 21:18 26470100 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1601795646-3932628227-3861186438-1005-4096.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-08-31 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-08-31 23:16 2532680 —-a-w- c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-08-31 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-22 39408]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-06-15 15141768]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-07-01 1295224]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-07-10 352256]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-01-14 34088]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 423936]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2011-09-22 2404704]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-26 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\users\Aprilbaby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
[BU]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 ABP_InstallCheckerService;ABP_InstallCheckerService;c:\users\APRILB~1\AppData\Local\Temp\ABP_InstallChecker.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-08-31 1025352]
R3 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-09-11 5265248]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-14 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x]
R4 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-07-18 181616]
R4 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-15 42368]
R4 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
R4 RSELSVC;TOSHIBA Modem region select service;c:\program files\TOSHIBA\rselect\RSelSvc.exe [2009-07-07 65904]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R4 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-07-01 51576]
R4 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-10 258928]
R4 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 137560]
R4 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-04 826224]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-01 192776]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S2 vToolbarUpdater;vToolbarUpdater;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [2011-10-17 246600]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
2010-11-20 12:17 302592 —-a-w- c:\windows\System32\cmd.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 04:00]
.
2011-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 04:00]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 19:45 134384 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU]
"TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 709976]
"TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU]
"TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU]
"Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU]
"SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-24 11780712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 365592]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 165912]
"HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 387608]
"00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://googlechrome.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSAU&bmod=TSAU
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.2.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000009
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
.
**************************************************************************
.
Completion time: 2011-10-23 14:05:09 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-23 03:04
ComboFix2.txt 2011-10-21 07:21
.
Pre-Run: 310,935,330,816 bytes free
Post-Run: 310,513,479,680 bytes free
.
- - End Of File - - C62683BF5DBE5AE7E018C8F5E6F638B9
Hi Gail
Forgot to mention…. IE is still not working and Searchqu is still there. I am also, still getting the message that IE is using large amounts of memory .
Hello Julie A,
Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.
Before continuing on, please completely uninstall one of the programs.
=================
NEXT
Back Up registry with ERUNT
Please use the following link and download ERUNT to your desktop. HERE Click on the erunt-setup.exe Follow the prompts to install ERUNT Choose language A set up window will pop up. It will ask: Create ERUNT entry in to the Start up folder , answer NO
[external image: Posted Image]
Backup your registry to the default location
Note: To restore your registry (if needed), go to the folder and start
ERDNT.exe
=================
NEXT
Run
OTL.exe
=======================
NEXT
Please Run
SystemLook again that's on your
Desktop .
Note: The log can also be found on your Desktop entitled
SystemLook.txt
=====================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. SystemLook.txt
4.How is the computer behaving?
All processes killed
Error: Unable to interpret in the current context!
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASAPI32\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASMANCS\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupDataMngr_searchqu_RASAPI32\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupDataMngr_searchqu_RASMANCS\ deleted successfully.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: All Users
User: Aprilbaby
->Temp folder emptied: 156813 bytes
->Temporary Internet Files folder emptied: 54804646 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 25508601 bytes
->Apple Safari cache emptied: 873472 bytes
->Flash cache emptied: 1813 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 45341 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 78.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 10242011_111216
Files\Folders moved on Reboot…
C:\Users\Aprilbaby\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot…
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
SystemLook 30.07.11 by jpshortstuff
Log created at 11:21 on 24/10/2011 by Aprilbaby
Administrator - Elevation successful
========== filefind ==========
Searching for "searchqu"
No files found.
Searching for "iLivid"
No files found.
========== folderfind ==========
Searching for "searchqu"
No folders found.
Searching for "iLivid"
C:\_OTL\MovedFiles\10212011_070211\C_Program Files (x86)\iLivid d—— [00:07 10/10/2011]
========== regfind ==========
Searching for "searchqu"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
@="ISearchQueryHelper"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
@="ISearchQueryHelper"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
"URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
"SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
@="ISearchQueryHelper"
Searching for "iLivid"
[HKEY_CURRENT_USER\Software\ilivid]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0]
@="{0.0.0.00000000}.{38b1c540-f82e-4210-9543-172dc1be7f76}|\Device\HarddiskVolume2\Program Files (x86)\iLivid\VLC\vlc.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid]
[HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetupV1.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASAPI32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASMANCS]
[HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\ilivid]
[HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0]
@="{0.0.0.00000000}.{38b1c540-f82e-4210-9543-172dc1be7f76}|\Device\HarddiskVolume2\Program Files (x86)\iLivid\VLC\vlc.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid]
[HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid]
-= EOF =-
No change in my computer.
Hello Julie A,
Your doing a great job.
Just hang in there we will beat this.
Run
OTL.exe
=======================
NEXT
Please Run
SystemLook again that's on your
Desktop .
Double-click SystemLook.exe to run it. Copy the content of the following codebox into the main textfield:
:regfind
searchqu
iLivid Click the Look button to start the scan. When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. Note: The log can also be found on your Desktop entitled
SystemLook.txt
=====================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. SystemLook.txt
4.How is the computer behaving?
All processes killed
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry key HKEY_CURRENT_USER\Software\ilivid\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetupV1.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASAPI32\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASMANCS\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\ilivid\ not found.
Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0\ not found.
Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid\ not found.
Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid\ not found.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: All Users
User: Aprilbaby
->Temp folder emptied: 4852 bytes
->Temporary Internet Files folder emptied: 49267610 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 8280038 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 1236 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 38838 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 55.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 10252011_093838
Files\Folders moved on Reboot…
C:\Users\Aprilbaby\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot…
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
SystemLook 30.07.11 by jpshortstuff
Log created at 09:47 on 25/10/2011 by Aprilbaby
Administrator - Elevation successful
========== regfind ==========
Searching for "searchqu"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
@="ISearchQueryHelper"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
@="ISearchQueryHelper"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
"URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
"SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
@="ISearchQueryHelper"
Searching for "iLivid"
No data found.
-= EOF =-
No change in my computer, Gail
Hello Julie A,
Open IE and go to Tools > Internet Options > Advanced Tab > Reset Internet Explorer Settings > Reset………takes a few seconds ……Close IE and then reopen it and see how it runs now
Lets try OTL again, see if we can finally get rid of searchqu.
Run
OTL.exe
=======================
NEXT
Please Run
SystemLook again that's on your
Desktop .
Double-click SystemLook.exe to run it. Copy the content of the following codebox into the main textfield:
:regfind
searchqu
iLivid Click the Look button to start the scan. When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. Note: The log can also be found on your Desktop entitled
SystemLook.txt
=====================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. SystemLook.txt
4.How is the computer behaving?
All processes killed
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: All Users
User: Aprilbaby
->Temp folder emptied: 7558 bytes
->Temporary Internet Files folder emptied: 17755730 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 26512745 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 470 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 44441 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 42.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 10262011_101525
Files\Folders moved on Reboot…
C:\Users\Aprilbaby\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot…
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
SystemLook 30.07.11 by jpshortstuff
Log created at 10:22 on 26/10/2011 by Aprilbaby
Administrator - Elevation successful
========== regfind ==========
Searching for "searchqu"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
@="ISearchQueryHelper"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
@="ISearchQueryHelper"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
"URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
"SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
@="ISearchQueryHelper"
Searching for "iLivid"
No data found.
-= EOF =-
Internet Explorer is not working. I followed your instructions and nothing happened. I am still getting the message 'cannot find server'