This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow running pc, web browser jumps to a serch engine. [Solved]

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Help please!!! My pc is running slow when tring to run programs and at start up. Also when on an internet site and you click on a link it redirects to a search engine. Below is my HiJackThis log.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:27:13 PM, on 1/5/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\mfevtps.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Verizon\VSP\ServicepointService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Yvette\My Documents\Downloads\HiJackThis.exe
C:\WINDOWS\system32\HPZinw12.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://oc-startpage.aol.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
R3 - URLSearchHook: MapQuest Toolbar Search Class - {2558d83c-097c-4cf1-9163-ce5ecc36ace2} - C:\Program Files\MapQuest Toolbar\mapquesttb.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110910172925.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O2 - BHO: MapQuest Toolbar Loader - {bd3fd433-147a-482e-a192-614f26e2310c} - C:\Program Files\MapQuest Toolbar\mapquesttb.dll
O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\2.0.1.82\oberontb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\NetAssistant\NetAssistant.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Yontoo Layer (Drop Down Deals)s - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Runtime\YontooIEClient_2.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\2.0.1.82\oberontb.dll
O3 - Toolbar: MapQuest Toolbar - {9302e698-7e00-43ab-b867-c6e759bc2ada} - C:\Program Files\MapQuest Toolbar\mapquesttb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] "C:\Program Files\Verizon\McciTrayApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig.exe -c Direct -p DOT4_001 -pn "hp LaserJet 1010 Series Driver" -n 0 -l 1033 -sl 120000
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: ActivClient Agent.lnk = C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\2.0.1.82\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\2.0.1.82\oberontb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.navy.mil
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1266028557531
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ackpbsc - C:\Program Files\ActivIdentity\ActivClient\ackpbsc.dll
O20 - Winlogon Notify: acunlock - C:\Program Files\ActivIdentity\ActivClient\acunlock.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: GSService - Unknown owner - C:\WINDOWS\system32\GSService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IHA_MessageCenter - Verizon - C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\system32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: ServicepointService - Radialpoint Inc. - C:\Program Files\Verizon\VSP\ServicepointService.exe
O23 - Service: SMServer - SMServer - C:\WINDOWS\system32\snmvtsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 15140 bytes
Hello and Welcome to WhatTheTech Forums

My name is BlackPegasus and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

=============
To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • Uninstall List :
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
=============
NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.


Summary of the logs I need from you in your next post:
OTS log
aswMBR log
Hello tazuki,

You have a lot of P2P programs and some questionable toolbars installed if you don't want to remove these which I think you should
please let me know before running the OTS fix and I will remove them from the fix.


P2P Warning!
IMPORTANT There are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

BearShare
FrostWire 5
LimePro
LimeWire
Azureus


Please note whenever you use any form of P2P networking to download files you can anticipate infestations of malware to occur.
P2P file sharing used to be fairly safe. This is no longer true…continue to use P2P sharing …at your own risk! Keep in mind that this practice may be the source of your current malware infestation.

I strongly recommend that you uninstall:

BearShare
FrostWire 5
LimePro
LimeWire
Azureus


You can do so using the Control Panel >> Add or Remove Programs function…however, that choice is up to you.

If you choose not to remove them, please do not use them until this computer is clean.

References… siting the risk factors, of using P2P programs:
Malware: Help prevent the Infection
IM And P2P Malware Threats Nearly Triple
How to Prevent the Online Invasion of Spyware and Adware
=====================
Optional Removal:

MapQuest Toolbar
http://www.systemlookup.com/CLSID/59477-mapquesttb_dll.html

Yontoo Layers (Drop Down Deals)
http://www.systemlookup.com/CLSID/56875-Yo…ient_2_dll.html

GamesBar
http://www.systemlookup.com/search.php?lis…E24B23A5&s;=

Please go to Start>Control Panel>Add Remove Programs. On the list you should find an entry for
MapQuest Toolbar
Freeze.com NetAssistant
Yontoo Layers (Drop Down Deals)
GamesBar
Click Remove and allow Windows to completely remove each one in turn.Then reboot your computer to complete this part of the process.
======================
NEXT

Start OTS Copy/Paste the information inside the codebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill All Processes]
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> 
YY -> HKEY_LOCAL_MACHINE\: URLSearchHooks\\"{2558d83c-097c-4cf1-9163-ce5ecc36ace2}" [HKLM] -> C:\Program Files\MapQuest Toolbar\mapquesttb.dll [MapQuest Toolbar Search Class]
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
YY -> HKLM\software\mozilla\Firefox\extensions\\[removed] -> C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN
< FireFox Extensions [User Folders] > -> 
YY -> MapQuest Toolbar   -> C:\Documents and Settings\Yvette\Application Data\Mozilla\Firefox\Profiles\gjm7r763.default\extensions\{4D1E692F-D179-413b-A987-EEEAAD85DDB3}
< FireFox SearchPlugins [User Folders] > -> 
YY ->  askcom.xml -> C:\Documents and Settings\Yvette\Application Data\Mozilla\FireFox\Profiles\gjm7r763.default\searchplugins\askcom.xml
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YY -> {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} [HKLM] -> C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll [UrlHelper Class]
YN -> {99079a25-328f-4bd4-be04-00955acaa0a7} [HKLM] -> [Searchqu Toolbar]
YY -> {bd3fd433-147a-482e-a192-614f26e2310c} [HKLM] -> C:\Program Files\MapQuest Toolbar\mapquesttb.dll [MapQuest Toolbar Loader]
YY -> {CB0D163C-E9F4-4236-9496-0597E24B23A5} [HKLM] -> C:\Program Files\GamesBar\2.0.1.82\oberontb.dll [GamesBarBHO Class]
YY -> {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} [HKLM] -> C:\Program Files\Freeze.com\NetAssistant\NetAssistant.dll [NetAssistantBHO Class]
YY -> {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} [HKLM] -> C:\Program Files\Yontoo Layers Runtime\YontooIEClient_2.dll [Yontoo Layers (Drop Down Deals)]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YY -> "{6F282B65-56BF-4BD1-A8B2-A4449A05863D}" [HKLM] -> C:\Program Files\GamesBar\2.0.1.82\oberontb.dll [GamesBar]
YY -> "{9302e698-7e00-43ab-b867-c6e759bc2ada}" [HKLM] -> C:\Program Files\MapQuest Toolbar\mapquesttb.dll [MapQuest Toolbar]
YN -> "{99079a25-328f-4bd4-be04-00955acaa0a7}" [HKLM] -> [Searchqu Toolbar]
YN -> "10" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1177238915-1965331169-682003330-1004\] > -> HKEY_USERS\S-1-5-21-1177238915-1965331169-682003330-1004\Software\Microsoft\Internet Explorer\Toolbar\
YY -> WebBrowser\\"{9302E698-7E00-43AB-B867-C6E759BC2ADA}" [HKLM] -> C:\Program Files\MapQuest Toolbar\mapquesttb.dll [MapQuest Toolbar]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "" -> []
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
YN -> {1A93C934-025B-4c3a-B38E-9654A7003239}:Reg Error: Value error. [HKLM] -> Reg Error: Value error. [Menu: GamesBar]
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List
YY -> "C:\Program Files\BearShare Applications\BearShare\BearShare.exe" -> C:\Program Files\BearShare Applications\BearShare\BearShare.exe [C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YY -> "C:\Program Files\BearShare Applications\BearShare\BearShare.exe" -> C:\Program Files\BearShare Applications\BearShare\BearShare.exe [C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare]
YN -> "C:\Program Files\FrostWire 5\FrostWire.exe" -> [C:\Program Files\FrostWire 5\FrostWire.exe:*:Enabled:FrostWire]
YN -> "C:\Program Files\Lime PRO\LimePro.exe" -> [C:\Program Files\Lime PRO\LimePro.exe:*:Enabled:Lime PRO p2p for windows]
YN -> "C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe" -> [C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe:*:Enabled:DTX broker]
YN -> "E:\My Music\FrostWire 5\FrostWire.exe" -> [E:\My Music\FrostWire 5\FrostWire.exe:*:Enabled:FrostWire]
YY -> "E:\My Music\FrostWire\FrostWire.exe" -> E:\My Music\FrostWire\FrostWire.exe [E:\My Music\FrostWire\FrostWire.exe:*:Enabled:FrostWire]
YN -> "E:\Program Files\LimeWire\LimeWire.exe" -> [E:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire]
[Registry - Additional Scans - Safe List]
< Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
YN -> {5F624839-947D-46EA-BD63-FD847C1AC6F1} -> BearShare
YN -> {889DF117-14D1-44EE-9F31-C5FB5D47F68B} -> Yontoo Layers Runtime (Drop Down Deals) 1.10.01
[Files/Folders - Created Within 30 Days]
NY ->  7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY ->  5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY ->  2 C:\Documents and Settings\Yvette\My Documents\*.tmp files -> C:\Documents and Settings\Yvette\My Documents\*.tmp
NY ->  1 C:\*.tmp files -> C:\*.tmp
[Files/Folders - Modified Within 30 Days]
NY ->  7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY ->  5 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp
NY ->  5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY ->  2 C:\Documents and Settings\Yvette\My Documents\*.tmp files -> C:\Documents and Settings\Yvette\My Documents\*.tmp
NY ->  182 C:\Documents and Settings\Yvette\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Yvette\Local Settings\Temp\*.tmp
NY ->  182 C:\Documents and Settings\Yvette\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Yvette\Local Settings\Temp\*.tmp
NY ->  182 C:\Documents and Settings\Yvette\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Yvette\Local Settings\Temp\*.tmp
NY ->  1 C:\*.tmp files -> C:\*.tmp
[File - Lop Check]
NY ->  Azureus -> C:\Documents and Settings\All Users\Application Data\Azureus
NY ->  BearShare -> C:\Documents and Settings\All Users\Application Data\BearShare
NY ->  GamesBar -> C:\Documents and Settings\All Users\Application Data\GamesBar
NY ->  MapQuest Toolbar -> C:\Documents and Settings\All Users\Application Data\MapQuest Toolbar
NY ->  Oberon Media -> C:\Documents and Settings\All Users\Application Data\Oberon Media
NY ->  bearsharemediabartb -> C:\Documents and Settings\misshoopladi\Application Data\bearsharemediabartb
NY ->  Azureus -> C:\Documents and Settings\Yvette\Application Data\Azureus
NY ->  FrostWire -> C:\Documents and Settings\Yvette\Application Data\FrostWire
NY ->  Oberon Media -> C:\Documents and Settings\Yvette\Application Data\Oberon Media
NY ->  OpenCandy -> C:\Documents and Settings\Yvette\Application Data\OpenCandy
NY ->  searchquband -> C:\Documents and Settings\Yvette\Application Data\searchquband
NY ->  searchqutoolbar -> C:\Documents and Settings\Yvette\Application Data\searchqutoolbar
[Alternate Data Streams]
NY -> @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:33384BC0
NY -> @Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:91486201
NY -> @Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D2A5A561
NY -> @Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:06F77AFE
NY -> @Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4B244549
NY -> @Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:91730504
NY -> @Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:23FD8469
NY -> @Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:61AF91EC
NY -> @Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:30FD0CBD
[Empty Temp Folders]
[EmptyFlash]
[EmptyJava]
[CreateRestorePoint]
[Reboot]

The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.

Summary of the logs I need from you in your next post:
OTS log
How is your computer running now?
Sorry thought it uploaded here you go. It does not want to upload for some reason. So here it is. All Processes Killed [Registry - Safe List] Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\\{2558d83c-097c-4cf1-9163-ce5ecc36ace2} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2558d83c-097c-4cf1-9163-ce5ecc36ace2}\ not found. File C:\Program Files\MapQuest Toolbar\mapquesttb.dll not found. Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed] deleted successfully. File C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN not found. C:\Documents and Settings\Yvette\Application Data\Mozilla\Firefox\Profiles\gjm7r763.default\extensions\{4D1E692F-D179-413b-A987-EEEAAD85DDB3}\META-INF folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Mozilla\Firefox\Profiles\gjm7r763.default\extensions\{4D1E692F-D179-413b-A987-EEEAAD85DDB3}\components folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Mozilla\Firefox\Profiles\gjm7r763.default\extensions\{4D1E692F-D179-413b-A987-EEEAAD85DDB3}\chrome folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Mozilla\Firefox\Profiles\gjm7r763.default\extensions\{4D1E692F-D179-413b-A987-EEEAAD85DDB3} folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Mozilla\FireFox\Profiles\gjm7r763.default\searchplugins\askcom.xml moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}\ deleted successfully. LoadLibrary failed for C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bd3fd433-147a-482e-a192-614f26e2310c}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bd3fd433-147a-482e-a192-614f26e2310c}\ not found. File C:\Program Files\MapQuest Toolbar\mapquesttb.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CB0D163C-E9F4-4236-9496-0597E24B23A5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CB0D163C-E9F4-4236-9496-0597E24B23A5}\ not found. File C:\Program Files\GamesBar\2.0.1.82\oberontb.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}\ not found. File C:\Program Files\Freeze.com\NetAssistant\NetAssistant.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ not found. File C:\Program Files\Yontoo Layers Runtime\YontooIEClient_2.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{6F282B65-56BF-4BD1-A8B2-A4449A05863D} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}\ not found. File C:\Program Files\GamesBar\2.0.1.82\oberontb.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{9302e698-7e00-43ab-b867-c6e759bc2ada} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9302e698-7e00-43ab-b867-c6e759bc2ada}\ not found. File C:\Program Files\MapQuest Toolbar\mapquesttb.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\10 deleted successfully. Registry value HKEY_USERS\S-1-5-21-1177238915-1965331169-682003330-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9302E698-7E00-43AB-B867-C6E759BC2ADA} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9302E698-7E00-43AB-B867-C6E759BC2ADA}\ not found. File C:\Program Files\MapQuest Toolbar\mapquesttb.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{1A93C934-025B-4c3a-B38E-9654A7003239}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A93C934-025B-4c3a-B38E-9654A7003239}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A93C934-025B-4c3a-B38E-9654A7003239}:Reg Error: Value error.\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\BearShare Applications\BearShare\BearShare.exe deleted successfully. File C:\Program Files\BearShare Applications\BearShare\BearShare.exe not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\BearShare Applications\BearShare\BearShare.exe deleted successfully. File C:\Program Files\BearShare Applications\BearShare\BearShare.exe not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\FrostWire 5\FrostWire.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Lime PRO\LimePro.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\My Music\FrostWire 5\FrostWire.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\My Music\FrostWire\FrostWire.exe deleted successfully. E:\My Music\FrostWire\FrostWire.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\LimeWire\LimeWire.exe deleted successfully. [Registry - Additional Scans - Safe List] [Files/Folders - Created Within 30 Days] C:\WINDOWS\002044_.tmp deleted successfully. C:\WINDOWS\004842_.tmp deleted successfully. C:\WINDOWS\DUMP1bd5.tmp deleted successfully. C:\WINDOWS\DUMP22ca.tmp deleted successfully. C:\WINDOWS\SET14.tmp deleted successfully. C:\WINDOWS\SET3.tmp deleted successfully. C:\WINDOWS\SETA.tmp deleted successfully. C:\WINDOWS\System32\ConduitEngine.tmp deleted successfully. C:\WINDOWS\System32\CONFIG.TMP deleted successfully. C:\WINDOWS\System32\SET4D.tmp deleted successfully. C:\WINDOWS\System32\SET51.tmp deleted successfully. C:\WINDOWS\System32\SET59.tmp deleted successfully. C:\Documents and Settings\Yvette\My Documents\~WRL1096.tmp deleted successfully. C:\Documents and Settings\Yvette\My Documents\~WRL1891.tmp deleted successfully. C:\tmp63.tmp deleted successfully. [Files/Folders - Modified Within 30 Days] C:\WINDOWS\Temp\GUR26.tmp deleted successfully. C:\WINDOWS\Temp\GUR59.tmp deleted successfully. C:\WINDOWS\Temp\is250.tmp deleted successfully. C:\WINDOWS\Temp\is254.tmp deleted successfully. C:\WINDOWS\Temp\RAP2C4.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\139.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\21.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\5.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\7F4E393D.TMP deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\9zkB3.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\cdm78.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\cdm7A.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\cdm89.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\EE.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\eLiveAS0.tmp\eLiveASBroker32.exe deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\eLiveAS0.tmp\eLiveASBroker64.exe deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\eLiveAS0.tmp\eLiveASHooks32.dll deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\eLiveAS0.tmp\eLiveASHooks64.dll deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\eLiveAS0.tmp\eLiveASHost32.dll deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\eLiveAS0.tmp\eLiveASHost64.dll deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\eLiveAS0.tmp folder deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\F0.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\is-984SJ.tmp\DealRunnerSetup.exe deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\is-984SJ.tmp folder deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\jar_cache62553.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR10.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR11.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR12.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR13.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR14.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR15.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR16.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR17.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR18.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR19.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR1A.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR1B.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR1C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR1D.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR1E.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR1F.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR20.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR21.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR22.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR23.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR24.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR25.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR26.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR27.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR28.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR29.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR2A.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR2B.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR2C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR2D.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR2E.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR2F.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR30.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR31.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR32.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR33.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR34.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR35.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR36.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR37.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR38.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR39.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR6E.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR6F.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR8.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MAR9.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MARA.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MARB.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MARC.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MARD.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MARE.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MARF.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MEP3E.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MEP3F.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MEP44.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MEP63.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MEP64.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MEP67.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MEPB3.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MEPB4.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\MEPB5.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\nsm132.tmp\NSISpcre.dll deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\nsm132.tmp folder deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\q7gB2.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\RBX-4525D84C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\Set4C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS11.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS13.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS14.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS1B.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS1C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS1E.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS1F.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS21.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS26.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS29.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS2A.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS2B.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS2E.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS34.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS36.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS37.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS39.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS3B.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS3C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS41.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS4A.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS60.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS71.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STS8F.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STSE.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\STSF.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\vneAC.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~1F0.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF1338.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF1413.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF17CB.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF17DF.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF1F4.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF2A52.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF2A5C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF36BE.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF36CB.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF3860.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF3928.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF3A4A.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF3F41.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF401D.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF4204.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF4573.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF558A.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF6073.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF6CFD.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF6D05.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF6E0C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF6E5C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF73AA.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF7445.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF744E.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF77CF.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF77D9.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF7B4C.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF7BB7.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF7D97.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF7E57.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF8198.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF8726.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF872E.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF8886.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF8D47.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF8D5F.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF9194.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF91AA.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF9208.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF9210.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF92B3.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF9E45.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF9EB8.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFA286.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFADA6.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFADE3.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFB07A.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFC032.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFC05F.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFC414.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFC423.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFC950.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFCD0E.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFCE8A.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFD272.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFD4D9.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFDC63.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFEA44.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFEDA9.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFEDB1.tmp deleted successfully. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0C1.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0C9.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0DD.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0E5.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF157.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF15F.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF189.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF191.tmp scheduled to be deleted on reboot. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF7B3.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFFA87.tmp deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~nsu.tmp\Au_.exe deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~nsu.tmp\Bu_.exe deleted successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\~nsu.tmp folder deleted successfully. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF4204.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF558A.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0C1.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0C9.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0DD.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0E5.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF157.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF15F.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF189.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF191.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF4204.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DF558A.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0C1.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0C9.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0DD.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0E5.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF157.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF15F.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF189.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF191.tmp scheduled to be deleted on reboot. [File - Lop Check] C:\Documents and Settings\All Users\Application Data\Azureus folder moved successfully. File C:\Documents and Settings\All Users\Application Data\BearShare not found! File C:\Documents and Settings\All Users\Application Data\GamesBar not found! File C:\Documents and Settings\All Users\Application Data\MapQuest Toolbar not found! C:\Documents and Settings\All Users\Application Data\Oberon Media\Services\Search folder moved successfully. C:\Documents and Settings\All Users\Application Data\Oberon Media\Services folder moved successfully. C:\Documents and Settings\All Users\Application Data\Oberon Media\11008813 folder moved successfully. C:\Documents and Settings\All Users\Application Data\Oberon Media folder moved successfully. C:\Documents and Settings\misshoopladi\Application Data\bearsharemediabartb folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\updates folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\torrents folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\tmp folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\shares folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\rss folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\plugins\azupnpav folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\plugins folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\net folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\logs\save folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\logs folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\dht folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus\active folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Azureus folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\xml\data folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\xml folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\themes\frostwirePro_theme folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\themes folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\overlays folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\static.frostwire.com\images\overlays folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\static.frostwire.com\images\banners folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\static.frostwire.com\images folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\static.frostwire.com folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm6.static.flickr.com\5128 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm6.static.flickr.com\5047 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm6.static.flickr.com folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm5.static.flickr.com\4147 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm5.static.flickr.com\4089 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm5.static.flickr.com\4084 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm5.static.flickr.com\4055 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm5.static.flickr.com\4047 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm5.static.flickr.com\4028 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm5.static.flickr.com folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm2.static.flickr.com\1218 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm2.static.flickr.com\1207 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache\farm2.static.flickr.com folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\image_cache folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\azureus\torrents folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\azureus\tmp folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\azureus\plugins folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\azureus\net folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\azureus\logs\save folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\azureus\logs folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\azureus\dht folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\azureus\active folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\azureus folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\.NetworkShare\Incomplete folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\.NetworkShare folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire\.AppSpecialShare folder moved successfully. C:\Documents and Settings\Yvette\Application Data\FrostWire folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Oberon Media\11008813\510005489 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Oberon Media\11008813\116881683 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Oberon Media\11008813\112623650 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Oberon Media\11008813 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\Oberon Media folder moved successfully. C:\Documents and Settings\Yvette\Application Data\OpenCandy\OpenCandy_23D5E51E4A5C4E90A00916E58BE2E132 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\OpenCandy\23D5E51E4A5C4E90A00916E58BE2E132 folder moved successfully. C:\Documents and Settings\Yvette\Application Data\OpenCandy folder moved successfully. C:\Documents and Settings\Yvette\Application Data\searchquband folder moved successfully. C:\Documents and Settings\Yvette\Application Data\searchqutoolbar\weather folder moved successfully. C:\Documents and Settings\Yvette\Application Data\searchqutoolbar\coupons folder moved successfully. C:\Documents and Settings\Yvette\Application Data\searchqutoolbar folder moved successfully. [Alternate Data Streams] ADS C:\Documents and Settings\All Users\Application Data\TEMP:33384BC0 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:91486201 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:D2A5A561 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:06F77AFE deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:4B244549 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:91730504 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:23FD8469 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:61AF91EC deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:30FD0CBD deleted successfully. [Empty Temp Folders] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 416763 bytes ->Flash cache emptied: 41620 bytes User: All Users User: Arsenio User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 192818 bytes User: LogMeInRemoteUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41620 bytes User: misshoopladi ->Temp folder emptied: 2109465 bytes ->Temporary Internet Files folder emptied: 24493731 bytes ->Flash cache emptied: 678 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 39988441 bytes User: Yvette ->Temp folder emptied: 1331242945 bytes ->Temporary Internet Files folder emptied: 327268976 bytes ->Java cache emptied: 20934198 bytes ->FireFox cache emptied: 470676694 bytes ->Google Chrome cache emptied: 14372913 bytes ->Flash cache emptied: 2173462 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 30642646 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 130208868 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 3691755741 bytes Total Files Cleaned = 5,805.00 mb [EMPTYFLASH] User: Administrator ->Flash cache emptied: 0 bytes User: All Users User: Arsenio User: Default User ->Flash cache emptied: 0 bytes User: LocalService User: LogMeInRemoteUser ->Flash cache emptied: 0 bytes User: misshoopladi ->Flash cache emptied: 0 bytes User: NetworkService User: Yvette ->Flash cache emptied: 99 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYJAVA] User: Administrator User: All Users User: Arsenio User: Default User User: LocalService User: LogMeInRemoteUser User: misshoopladi User: NetworkService User: Yvette ->Java cache emptied: 0 bytes Total Java Files Cleaned = 0.00 mb Cannot create restore point. Unable to start SRService service! < End of fix log > OTS by OldTimer - Version 3.1.46.0 fix logfile created on 01072012_211559 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0C1.tmp not found! File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0C9.tmp not found! File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0DD.tmp not found! File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF0E5.tmp not found! File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF157.tmp not found! File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF15F.tmp not found! File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF189.tmp not found! File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DFF191.tmp not found! File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DF4204.tmp not found! File\Folder C:\Documents and Settings\Yvette\Local Settings\Temp\~DF558A.tmp not found! C:\Documents and Settings\Yvette\Local Settings\Temp\McAfeeLogs\UpdaterUI_SLAMMEDGV.log moved successfully. C:\Documents and Settings\Yvette\Local Settings\Temp\McAfeeLogs\UpdaterUI_SLAMMEDGV_error.log moved successfully. C:\Documents and Settings\Yvette\Local Settings\Temporary Internet Files\Content.IE5\FX7DSR0F\iframe[1].htm moved successfully. C:\Documents and Settings\Yvette\Local Settings\Temporary Internet Files\Content.IE5\92EW3R09\index[3].htm moved successfully. C:\Documents and Settings\Yvette\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Documents and Settings\Yvette\Local Settings\Temporary Internet Files\SuggestedSites.dat moved successfully. File\Folder C:\Documents and Settings\Yvette\Application Data\Macromedia\Flash Player\#SharedObjects\82FMNJK4\a.dolimg.com\media\en-US\dxd\code\dcom3_global_animation_code.swf\dcomFeatureAnimationCounterV1187474.sol not found! Registry entries deleted on Reboot… Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F624839-947D-46EA-BD63-FD847C1AC6F1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F624839-947D-46EA-BD63-FD847C1AC6F1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ not found.
Hello tazuki,

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=============
NEXT

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Summary of the logs I need from you in your next post:
Security Checklog
Combofix log
How is your computer running now?
Hello tazuki,


VirusTotal

We need to upload files to VirusTotal for inspection.

  • Please visit VirusTotal by clicking here.
  • Click the Browse… button and search for the following file:
    • C:\lj1010seriesprintsys
      c:\program files\1103201122153681.bat
  • Click Open.
  • Click Send File.
  • Please be patient while the file is scanned.
  • If VirusTotal tells you that the file has already been scanned, click "reanalyse now".
  • Once scanned, copy and paste the link to the results page in your next reply.
If you're having trouble loading VirusTotal, try VirSCAN or Jotti.
================
NEXT

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
================
NEXT


ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!


Summary of the logs I need from you in your next post:

VirusTotal results
Malwarebytes' log
ESET log
Hello tazuki,


C:\lj1010seriesprintsys is folder for my printer driver.

I had a feeling that's what it was but just wanted to make sure. :thumbup:

We need to upload files to VirusTotal and Jotti for inspection.

  • Please visit VirusTotal by clicking here.
    Jotti.
  • Click the Browse… button and search for the following file:
    • C:\Mcafee\UnInstX64.exe
  • Click Open.
  • Click Send File.
  • Please be patient while the file is scanned.
  • If VirusTotal tells you that the file has already been scanned, click "reanalyse now".
  • Once scanned, copy and paste the link to the results page in your next reply.

Summary of the logs I need from you in your next post:
VirusTotal results
Jotti results
Hello tazuki,

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Here is the log. CKScanner - Additional Security Risks - These are not necessarily bad c:\documents and settings\yvette\my documents\my music\unknown artist\crackradio.org\desktop.ini scanner sequence 3.NA.11.OWAPNC —– EOF —–

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI