This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information… 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: SetIEInstalledDate.exe Submission date: 2011-10-22 19:47:49 (UTC) Current status: finished Result: 0/ 43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.10.22.00 2011.10.22 - AntiVir 7.11.16.106 2011.10.21 - Antiy-AVL 2.0.3.7 2011.10.22 - Avast 6.0.1289.0 2011.10.22 - AVG 10.0.0.1190 2011.10.22 - BitDefender 7.2 2011.10.22 - ByteHero 1.0.0.1 2011.09.23 - CAT-QuickHeal 11.00 2011.10.21 - ClamAV 0.97.0.0 2011.10.22 - Commtouch 5.3.2.6 2011.10.22 - Comodo 10529 2011.10.22 - DrWeb 5.0.2.03300 2011.10.22 - Emsisoft 5.1.0.11 2011.10.22 - eSafe 7.0.17.0 2011.10.17 - eTrust-Vet 36.1.8633 2011.10.21 - F-Prot 4.6.5.141 2011.10.21 - F-Secure 9.0.16440.0 2011.10.22 - Fortinet 4.3.370.0 2011.10.22 - GData 22 2011.10.22 - Ikarus T3.1.1.107.0 2011.10.22 - Jiangmin 13.0.900 2011.10.22 - K7AntiVirus 9.116.5326 2011.10.22 - Kaspersky 9.0.0.837 2011.10.22 - McAfee 5.400.0.1158 2011.10.22 - McAfee-GW-Edition 2010.1D 2011.10.22 - Microsoft 1.7801 2011.10.22 - NOD32 6566 2011.10.22 - Norman 6.07.13 2011.10.22 - nProtect 2011-10-22.01 2011.10.22 - Panda 10.0.3.5 2011.10.22 - PCTools 8.0.0.5 2011.10.22 - Prevx 3.0 2011.10.22 - Rising 23.80.04.02 2011.10.21 - Sophos 4.70.0 2011.10.22 - SUPERAntiSpyware 4.40.0.1006 2011.10.22 - Symantec 20111.2.0.82 2011.10.22 - TheHacker 6.7.0.1.327 2011.10.19 - TrendMicro 9.500.0.1008 2011.10.22 - TrendMicro-HouseCall 9.500.0.1008 2011.10.22 - VBA32 3.12.16.4 2011.10.21 - VIPRE 10841 2011.10.22 - ViRobot 2011.10.22.4733 2011.10.22 - VirusBuster 14.1.25.0 2011.10.22 - Additional informationShow all MD5 : 736d1b28224f9df8008be8b0dedfc9ef SHA1 : 1d36b4dd18b65b5f2006d21f450ef6da17cc53d3 SHA256: d1bdeb73fe2112574d97414088b23e8be010e166a2ab47be18bec7cd14f031bc
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: IEAdvpack.dll Submission date: 2011-10-22 20:04:35 (UTC) Current status: finished Result: 0/ 43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.10.22.00 2011.10.22 - AntiVir 7.11.16.106 2011.10.21 - Antiy-AVL 2.0.3.7 2011.10.22 - Avast 6.0.1289.0 2011.10.22 - AVG 10.0.0.1190 2011.10.22 - BitDefender 7.2 2011.10.22 - ByteHero 1.0.0.1 2011.09.23 - CAT-QuickHeal 11.00 2011.10.21 - ClamAV 0.97.0.0 2011.10.22 - Commtouch 5.3.2.6 2011.10.22 - Comodo 10529 2011.10.22 - DrWeb 5.0.2.03300 2011.10.22 - Emsisoft 5.1.0.11 2011.10.22 - eSafe 7.0.17.0 2011.10.17 - eTrust-Vet 36.1.8633 2011.10.21 - F-Prot 4.6.5.141 2011.10.21 - F-Secure 9.0.16440.0 2011.10.22 - Fortinet 4.3.370.0 2011.10.22 - GData 22 2011.10.22 - Ikarus T3.1.1.107.0 2011.10.22 - Jiangmin 13.0.900 2011.10.22 - K7AntiVirus 9.116.5326 2011.10.22 - Kaspersky 9.0.0.837 2011.10.22 - McAfee 5.400.0.1158 2011.10.22 - McAfee-GW-Edition 2010.1D 2011.10.22 - Microsoft 1.7801 2011.10.22 - NOD32 6566 2011.10.22 - Norman 6.07.13 2011.10.22 - nProtect 2011-10-22.01 2011.10.22 - Panda 10.0.3.5 2011.10.22 - PCTools 8.0.0.5 2011.10.22 - Prevx 3.0 2011.10.22 - Rising 23.80.04.02 2011.10.21 - Sophos 4.70.0 2011.10.22 - SUPERAntiSpyware 4.40.0.1006 2011.10.22 - Symantec 20111.2.0.82 2011.10.22 - TheHacker 6.7.0.1.327 2011.10.19 - TrendMicro 9.500.0.1008 2011.10.22 - TrendMicro-HouseCall 9.500.0.1008 2011.10.22 - VBA32 3.12.16.4 2011.10.21 - VIPRE 10841 2011.10.22 - ViRobot 2011.10.22.4733 2011.10.22 - VirusBuster 14.1.25.0 2011.10.22 - Additional informationShow all MD5 : ed6f6fbbcdec95483b7351e23f4fcdf6 SHA1 : f1be16ebff456033a5795b55ccb3d7ad6c30887f SHA256: b5664313e8f937ea6de7ec38cfd0ad45f75d743472a8ff22921232eeb080b974
This is the ComboFix log - ComboFix 11-10-21.06 - Aprilbaby 23/10/2011 8:01.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3933.2133 [GMT 11:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe Command switches used :: c:\users\Aprilbaby\Downloads\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\SearchCore for Browsers . . ((((((((((((((((((((((((( Files Created from 2011-09-22 to 2011-10-22 ))))))))))))))))))))))))))))))) . . 2011-10-22 21:17 . 2011-10-22 21:17 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-10-21 10:51 . 2011-10-21 10:51 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-10-20 21:24 . 2011-09-20 22:00 9049936 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F2E1C5ED-EF2E-4B9A-BB8D-F03EFF6B2C4F}\mpengine.dll 2011-10-20 20:02 . 2011-10-20 20:02 ——– d—–w- C:\_OTL 2011-10-19 12:34 . 2011-09-06 19:38 301912 —-a-w- c:\windows\system32\drivers\aswSP.sys 2011-10-19 12:34 . 2011-09-06 19:36 24408 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-10-19 12:34 . 2011-09-06 19:36 42328 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2011-10-19 12:34 . 2011-09-06 19:36 58200 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2011-10-19 12:34 . 2011-09-06 19:38 601944 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-10-19 12:34 . 2011-09-06 19:45 254400 —-a-w- c:\windows\system32\aswBoot.exe 2011-10-19 12:34 . 2011-09-06 19:36 65368 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-10-19 12:34 . 2011-09-06 19:45 41184 —-a-w- c:\windows\avastSS.scr 2011-10-19 12:34 . 2011-09-06 19:45 199304 —-a-w- c:\windows\SysWow64\aswBoot.exe 2011-10-19 12:34 . 2011-10-19 12:34 ——– d—–w- c:\programdata\AVAST Software 2011-10-19 12:34 . 2011-10-19 12:34 ——– d—–w- c:\program files\AVAST Software 2011-10-19 11:57 . 2011-10-19 11:57 ——– d—–w- c:\windows\system32\Macromed 2011-10-18 22:28 . 2011-10-18 22:28 ——– d—–w- c:\program files (x86)\Safari 2011-10-18 22:26 . 2011-10-18 22:27 ——– d—–w- c:\program files\iTunes 2011-10-18 22:26 . 2011-10-18 22:27 ——– d—–w- c:\program files (x86)\iTunes 2011-10-18 22:26 . 2011-10-18 22:26 ——– d—–w- c:\program files\iPod 2011-10-18 22:20 . 2011-10-18 22:20 ——– d—–w- c:\program files\Bonjour 2011-10-18 22:20 . 2011-10-18 22:20 ——– d—–w- c:\program files (x86)\Bonjour 2011-10-17 20:22 . 2011-10-17 20:22 ——– d—–w- c:\program files (x86)\Common Files\AVG Secure Search 2011-10-17 20:22 . 2011-10-17 20:22 ——– d—–w- c:\program files (x86)\AVG Secure Search 2011-10-17 20:20 . 2011-10-17 20:20 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\AVG2012 2011-10-17 20:19 . 2011-10-17 20:38 ——– d—–w- c:\programdata\AVG2012 2011-10-13 04:45 . 2011-09-06 03:03 3138048 —-a-w- c:\windows\system32\win32k.sys 2011-10-13 04:43 . 2011-08-17 05:26 613888 —-a-w- c:\windows\system32\psisdecd.dll 2011-10-13 04:43 . 2011-08-17 05:25 108032 —-a-w- c:\windows\system32\psisrndr.ax 2011-10-13 04:43 . 2011-08-17 04:24 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll 2011-10-13 04:43 . 2011-08-17 04:19 75776 —-a-w- c:\windows\SysWow64\psisrndr.ax 2011-10-13 04:43 . 2011-08-27 05:37 861696 —-a-w- c:\windows\system32\oleaut32.dll 2011-10-13 04:43 . 2011-08-27 05:37 331776 —-a-w- c:\windows\system32\oleacc.dll 2011-10-13 04:43 . 2011-08-27 04:26 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-10-13 04:43 . 2011-08-27 04:26 233472 —-a-w- c:\windows\SysWow64\oleacc.dll 2011-10-10 19:34 . 2011-10-10 19:34 ——– d—–w- c:\programdata\boost_interprocess 2011-10-10 00:13 . 2011-10-10 00:14 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\vlc 2011-10-10 00:06 . 2011-10-10 00:06 ——– d—–w- c:\users\Aprilbaby\AppData\Local\PackageAware 2011-10-04 21:13 . 2011-10-04 21:13 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\DivoGames 2011-10-04 20:47 . 2011-10-04 20:54 ——– d—–w- c:\users\Aprilbaby\Jack of all Tribes 2011-09-26 01:48 . 2011-09-26 01:48 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\Unity 2011-09-26 01:40 . 2011-09-26 20:34 ——– d—–w- c:\users\Aprilbaby\AppData\Local\Unity . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-15 21:26 . 2011-06-03 22:42 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-10-02 18:06 . 2010-07-27 08:06 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-09-12 19:30 . 2011-09-12 19:30 37456 —-a-w- c:\windows\system32\drivers\avgrkx64.sys 2011-08-31 07:00 . 2011-03-15 13:25 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-30 12:05 . 2011-08-30 12:05 96104 —-a-w- c:\windows\system32\dns-sd.exe 2011-08-30 12:05 . 2011-08-30 12:05 85864 —-a-w- c:\windows\system32\dnssd.dll 2011-08-30 12:05 . 2011-08-30 12:05 61288 —-a-w- c:\windows\system32\jdns_sd.dll 2011-08-30 12:05 . 2011-08-30 12:05 212840 —-a-w- c:\windows\system32\dnssdX.dll 2011-08-30 12:05 . 2011-08-30 12:05 83816 —-a-w- c:\windows\SysWow64\dns-sd.exe 2011-08-30 12:05 . 2011-08-30 12:05 73064 —-a-w- c:\windows\SysWow64\dnssd.dll 2011-08-30 12:05 . 2011-08-30 12:05 50536 —-a-w- c:\windows\SysWow64\jdns_sd.dll 2011-08-30 12:05 . 2011-08-30 12:05 178536 —-a-w- c:\windows\SysWow64\dnssdX.dll 2011-08-15 09:23 . 2011-08-15 09:23 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-08-07 19:08 . 2011-08-07 19:08 46672 —-a-w- c:\windows\system32\drivers\avgmfx64.sys 2011-08-02 06:38 . 2011-08-02 06:38 51712 —-a-w- c:\windows\system32\drivers\usbaapl64.sys 2011-08-02 06:38 . 2011-08-02 06:38 4517664 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-07-29 13:23 . 2011-07-29 13:23 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2011-07-29 13:23 . 2011-07-29 13:23 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2011-07-29 13:23 . 2011-07-29 13:23 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2011-07-29 13:23 . 2011-07-29 13:23 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2011-07-29 13:23 . 2011-07-29 13:23 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2011-07-29 13:23 . 2011-07-29 13:23 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2011-07-29 13:23 . 2011-07-29 13:23 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2011-07-29 13:23 . 2011-07-29 13:23 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2011-07-29 13:23 . 2011-07-29 13:23 367104 —-a-w- c:\windows\SysWow64\html.iec 2011-07-29 13:23 . 2011-07-29 13:23 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2011-07-29 13:23 . 2011-07-29 13:23 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2011-07-29 13:23 . 2011-07-29 13:23 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2011-07-29 13:23 . 2011-07-29 13:23 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2011-07-29 13:23 . 2011-07-29 13:23 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-07-29 13:23 . 2011-07-29 13:23 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2011-07-29 13:23 . 2011-07-29 13:23 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2011-07-29 13:23 . 2011-07-29 13:23 222208 —-a-w- c:\windows\system32\msls31.dll 2011-07-29 13:23 . 2011-07-29 13:23 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2011-07-29 13:23 . 2011-07-29 13:23 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2011-07-29 13:23 . 2011-07-29 13:23 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2011-07-29 13:23 . 2011-07-29 13:23 49664 —-a-w- c:\windows\system32\imgutil.dll 2011-07-29 13:23 . 2011-07-29 13:23 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2011-07-29 13:23 . 2011-07-29 13:23 12288 —-a-w- c:\windows\system32\mshta.exe 2011-07-29 13:23 . 2011-07-29 13:23 114176 —-a-w- c:\windows\system32\admparse.dll 2011-07-29 13:23 . 2011-07-29 13:23 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-07-29 13:23 . 2011-07-29 13:23 85504 —-a-w- c:\windows\system32\iesetup.dll 2011-07-29 13:23 . 2011-07-29 13:23 76800 —-a-w- c:\windows\system32\tdc.ocx 2011-07-29 13:23 . 2011-07-29 13:23 48640 —-a-w- c:\windows\system32\mshtmler.dll 2011-07-29 13:23 . 2011-07-29 13:23 448512 —-a-w- c:\windows\system32\html.iec 2011-07-29 13:23 . 2011-07-29 13:23 30720 —-a-w- c:\windows\system32\licmgr10.dll 2011-07-29 13:23 . 2011-07-29 13:23 160256 —-a-w- c:\windows\system32\wextract.exe 2011-07-29 13:23 . 2011-07-29 13:23 1492992 —-a-w- c:\windows\system32\inetcpl.cpl 2011-07-29 13:23 . 2011-07-29 13:23 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2011-07-29 13:23 . 2011-07-29 13:23 111616 —-a-w- c:\windows\system32\iesysprep.dll 2011-07-29 13:23 . 2011-07-29 13:23 603648 —-a-w- c:\windows\system32\vbscript.dll 2011-07-29 13:23 . 2011-07-29 13:23 165888 —-a-w- c:\windows\system32\iexpress.exe . . ((((((((((((((((((((((((((((( SnapShot@2011-10-21_06.46.23 ))))))))))))))))))))))))))))))))))))))))) . - 2011-05-12 22:43 . 2011-10-20 20:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2011-05-12 22:43 . 2011-10-21 19:53 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat - 2009-07-14 04:54 . 2011-10-21 06:45 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2011-10-22 21:20 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-10-21 06:45 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-10-22 21:20 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-10-21 06:45 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-10-22 21:20 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 05:10 . 2011-10-22 21:21 55658 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2009-11-22 06:40 . 2011-10-22 21:21 23572 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1601795646-3932628227-3861186438-1005_UserData.bin + 2009-11-22 21:29 . 2011-10-21 19:57 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-11-22 21:29 . 2011-10-18 04:49 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-10-21 07:27 . 2011-10-21 19:57 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-10-21 19:57 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2011-10-18 04:49 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-12-01 06:41 . 2011-10-21 06:42 3210 c:\windows\system32\wdi\ERCQueuedResolutions.dat + 2009-12-01 06:41 . 2011-10-22 10:47 3210 c:\windows\system32\wdi\ERCQueuedResolutions.dat + 2011-10-22 21:19 . 2011-10-22 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-10-21 06:43 . 2011-10-21 06:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-10-21 06:43 . 2011-10-21 06:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-10-22 21:19 . 2011-10-22 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-10-21 10:50 . 2011-10-02 18:06 157472 c:\windows\SysWOW64\javaws.exe - 2011-06-17 23:19 . 2011-05-03 18:52 157472 c:\windows\SysWOW64\javaws.exe - 2011-06-17 23:19 . 2011-05-03 18:52 145184 c:\windows\SysWOW64\javaw.exe + 2011-10-21 10:50 . 2011-10-02 18:06 145184 c:\windows\SysWOW64\javaw.exe + 2011-10-21 10:50 . 2011-10-02 18:06 145184 c:\windows\SysWOW64\java.exe - 2011-06-17 23:19 . 2011-05-03 18:52 145184 c:\windows\SysWOW64\java.exe + 2009-11-23 06:10 . 2011-10-22 09:40 268788 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2009-07-14 02:36 . 2011-10-22 18:27 727720 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2011-10-21 03:26 727720 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-10-22 18:27 149422 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2011-10-21 03:26 149422 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2011-10-21 06:42 463204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2011-10-22 21:18 463204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-10-21 10:50 . 2011-10-21 10:50 207360 c:\windows\Installer\1956fd.msi - 2010-10-22 10:16 . 2011-10-21 06:42 3786516 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1601795646-3932628227-3861186438-1005-8192.dat + 2010-10-22 10:16 . 2011-10-22 21:18 3786516 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1601795646-3932628227-3861186438-1005-8192.dat + 2011-06-08 12:34 . 2011-10-21 10:20 2357891 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1601795646-3932628227-3861186438-1005-12288.dat + 2011-06-02 14:02 . 2011-10-22 21:18 26470100 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1601795646-3932628227-3861186438-1005-4096.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-08-31 2532680] . [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}] 2011-08-31 23:16 2532680 —-a-w- c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-08-31 2532680] . [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-22 39408] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-06-15 15141768] "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-07-01 1295224] "SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-07-10 352256] "KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-01-14 34088] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 423936] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2011-09-22 2404704] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-26 59240] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] . c:\users\Aprilbaby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui] [BU] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 ABP_InstallCheckerService;ABP_InstallCheckerService;c:\users\APRILB~1\AppData\Local\Temp\ABP_InstallChecker.exe [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664] R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-08-31 1025352] R3 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-09-11 5265248] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-14 183560] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x] R4 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-07-18 181616] R4 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-15 42368] R4 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448] R4 RSELSVC;TOSHIBA Modem region select service;c:\program files\TOSHIBA\rselect\RSelSvc.exe [2009-07-07 65904] R4 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] R4 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-07-01 51576] R4 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-10 258928] R4 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 137560] R4 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-04 826224] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-01 192776] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 vToolbarUpdater;vToolbarUpdater;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [2011-10-17 246600] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}] 2010-11-20 12:17 302592 —-a-w- c:\windows\System32\cmd.exe . Contents of the 'Scheduled Tasks' folder . 2011-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 04:00] . 2011-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 04:00] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 19:45 134384 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU] "TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 709976] "TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU] "TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU] "Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU] "SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-24 11780712] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 365592] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 165912] "HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 387608] "00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://googlechrome.com/ mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSAU&bmod=TSAU mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.2.1 Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll . - - - - ORPHANS REMOVED - - - - . WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:00000009 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe . ************************************************************************** . Completion time: 2011-10-23 14:05:09 - machine was rebooted ComboFix-quarantined-files.txt 2011-10-23 03:04 ComboFix2.txt 2011-10-21 07:21 . Pre-Run: 310,935,330,816 bytes free Post-Run: 310,513,479,680 bytes free . - - End Of File - - C62683BF5DBE5AE7E018C8F5E6F638B9
Hi Gail Forgot to mention…. IE is still not working and Searchqu is still there. I am also, still getting the message that IE is using large amounts of memory .
Hello Julie A,



Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.
Before continuing on, please completely uninstall one of the programs.
=================
NEXT

Back Up registry with ERUNT

  • Please use the following link and download ERUNT to your desktop. HERE
  • Click on the erunt-setup.exe
  • Follow the prompts to install ERUNT
  • Choose language
  • A set up window will pop up. It will ask: Create ERUNT entry in to the Start up folder, answer NO

    [external image: Posted Image]
  • Backup your registry to the default location

Note: To restore your registry (if needed), go to the folder and start ERDNT.exe
=================
NEXT

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    :Services
    
    :Reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASMANCS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupDataMngr_searchqu_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupDataMngr_searchqu_RASMANCS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
    [-HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=======================
NEXT

Please Run SystemLook again that's on your Desktop.
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    searchqu
    iLivid
    :folderfind
    searchqu
    iLivid
    :regfind
    searchqu
    iLivid
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
=====================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. SystemLook.txt
4.How is the computer behaving?
All processes killed Error: Unable to interpret in the current context! ========== OTL ========== ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASAPI32\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASMANCS\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupDataMngr_searchqu_RASAPI32\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupDataMngr_searchqu_RASMANCS\ deleted successfully. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Aprilbaby ->Temp folder emptied: 156813 bytes ->Temporary Internet Files folder emptied: 54804646 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 25508601 bytes ->Apple Safari cache emptied: 873472 bytes ->Flash cache emptied: 1813 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 45341 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 78.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 10242011_111216 Files\Folders moved on Reboot… C:\Users\Aprilbaby\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
SystemLook 30.07.11 by jpshortstuff Log created at 11:21 on 24/10/2011 by Aprilbaby Administrator - Elevation successful ========== filefind ========== Searching for "searchqu" No files found. Searching for "iLivid" No files found. ========== folderfind ========== Searching for "searchqu" No folders found. Searching for "iLivid" C:\_OTL\MovedFiles\10212011_070211\C_Program Files (x86)\iLivid d—— [00:07 10/10/2011] ========== regfind ========== Searching for "searchqu" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" Searching for "iLivid" [HKEY_CURRENT_USER\Software\ilivid] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0] @="{0.0.0.00000000}.{38b1c540-f82e-4210-9543-172dc1be7f76}|\Device\HarddiskVolume2\Program Files (x86)\iLivid\VLC\vlc.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetupV1.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASMANCS] [HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\ilivid] [HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0] @="{0.0.0.00000000}.{38b1c540-f82e-4210-9543-172dc1be7f76}|\Device\HarddiskVolume2\Program Files (x86)\iLivid\VLC\vlc.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid] [HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid] -= EOF =-
Hello Julie A,


Your doing a great job. :thumbup: Just hang in there we will beat this. :)

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL. Don't include the word Code.

    :OTL
    :Services
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
    [-HKEY_CURRENT_USER\Software\ilivid]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0]
    [-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid]
    [-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetupV1.exe]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASMANCS]
    [-HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\ilivid]
    [-HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0]
    [-HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid]
    [-HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid]
    
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=======================
NEXT

Please Run SystemLook again that's on your Desktop.
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :regfind
    searchqu
    iLivid
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
=====================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. SystemLook.txt
4.How is the computer behaving?
All processes killed ========== OTL ========== ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry key HKEY_CURRENT_USER\Software\ilivid\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetupV1.exe\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASAPI32\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividSetupV1_RASMANCS\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\ilivid\ not found. Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f479a412_0\ not found. Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid\ not found. Registry key HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid\ not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Aprilbaby ->Temp folder emptied: 4852 bytes ->Temporary Internet Files folder emptied: 49267610 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 8280038 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 1236 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 38838 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 55.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 10252011_093838 Files\Folders moved on Reboot… C:\Users\Aprilbaby\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
SystemLook 30.07.11 by jpshortstuff Log created at 09:47 on 25/10/2011 by Aprilbaby Administrator - Elevation successful ========== regfind ========== Searching for "searchqu" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" Searching for "iLivid" No data found. -= EOF =-
Hello Julie A,



Open IE and go to Tools > Internet Options > Advanced Tab > Reset Internet Explorer Settings > Reset………takes a few seconds ……Close IE and then reopen it and see how it runs now


Lets try OTL again, see if we can finally get rid of searchqu.


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL. Don't include the word Code.

    :OTL
    :Services
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=======================
NEXT

Please Run SystemLook again that's on your Desktop.
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :regfind
    searchqu
    iLivid
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
=====================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. SystemLook.txt
4.How is the computer behaving?
All processes killed ========== OTL ========== ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Aprilbaby ->Temp folder emptied: 7558 bytes ->Temporary Internet Files folder emptied: 17755730 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 26512745 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 470 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 44441 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 42.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 10262011_101525 Files\Folders moved on Reboot… C:\Users\Aprilbaby\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}\ not found.
SystemLook 30.07.11 by jpshortstuff Log created at 10:22 on 26/10/2011 by Aprilbaby Administrator - Elevation successful ========== regfind ========== Searching for "searchqu" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" Searching for "iLivid" No data found. -= EOF =- Internet Explorer is not working. I followed your instructions and nothing happened. I am still getting the message 'cannot find server'

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI