Searchnu [Solved]
17 min read
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
- please follow all instructions in the order posted
- please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
- all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
- if you don't understand something, please don't hesitate to ask for clarification before proceeding
- the fixes are specific to your problem and should only be used for this issue on this machine.
- please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================
P2P
You say you have P2P software, (uTorrent, )installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.
Should you decide to keep it, please donโt use it until we have finished up here.
===================================================
Download and run OTL
- Download OTL to your desktop.
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, underneath Output at the top change it to Minimal Output.
- Check the boxes beside LOP Check and Purity Check.
- Under Custom Scan paste this in
netsvcs
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lรฎk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%PROGRAMFILES%\Internet Explorer\*.dat
%APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Deskuop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
%USERPROFILE%\..|smtmp;true;true;true /FP
%temp%\smtmp\*.* /s >
/md5start
iexplore.*
explorer.*
winlogon.*
dll
zx.dll
hlp.dat
/md5stop - Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
- You may need two posts to fit them both in.
Run aswMBR
- download aswMBR.exe to your desktop.
- double click the aswMBR.exe to run it
- if asked, accept the AVAST virus definition download
- click the "Scan" button to start scan
- on completion of the scan click Save log, save it to your desktop and post in your next reply
OTL.txt
Extras.txt
aswMBR log
Thanks
Satchfan
Thanks for the logs but you didn't send Extras.txt which you'll find in the same location as the OTL log you sent.
Please do not attach it or any other logs, just copy and paste them into the reply.
Thanks
Satchfan
I hope this works Regards catoOTL Extras logfile created on: 4/04/2012 12:52:01 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\cato\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.75 Gb Total Physical Memory | 1.96 Gb Available Physical Memory | 71.31% Memory free
5.71 Gb Paging File | 4.57 Gb Available in Paging File | 79.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.04 Gb Total Space | 70.91 Gb Free Space | 50.27% Space Free | Partition Type: NTFS
Drive D: | 141.04 Gb Total Space | 140.95 Gb Free Space | 99.93% Space Free | Partition Type: NTFS
Computer Name: CATO-PC | User Name: cato | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] โ C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] โ C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
.url [@ = InternetShortcut] โ rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] โ Reg Error: Key error. File not found
.html [@ = ChromeHTML] โ Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ "%1" %*
cmdfile [open] โ "%1" %*
comfile [open] โ "%1" %*
cplfile [cplopen] โ %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] โ "%1" %*
helpfile [open] โ Reg Error: Key error.
hlpfile [open] โ %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] โ "C:\Program Files\Google\Chrome\Application\chrome.exe" โ "%1" (Google Inc.)
https [open] โ "C:\Program Files\Google\Chrome\Application\chrome.exe" โ "%1" (Google Inc.)
inffile [install] โ %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] โ rundll32.exe ieframe.dll,OpenURL %l
piffile [open] โ "%1" %*
regfile [merge] โ Reg Error: Key error.
scrfile [config] โ "%1"
scrfile [install] โ rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] โ "%1" /S
txtfile โ Reg Error: Key error.
Unknown [openas] โ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] โ cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] โ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type โ File not found
"VistaSp2" = Reg Error: Unknown registry data type โ File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Telstra\Mobile Broadband Manager\SwiApiMuxX.exe" = C:\Program Files\Telstra\Mobile Broadband Manager\SwiApiMuxX.exe:*:Enabled:SwiApiMuxX
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{20C413AF-1C08-4D7D-933E-1B3F06CAC7D0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{4D717091-0CB3-4E2E-979A-D41E7D105374}" = lport=443 | protocol=6 | dir=in | name=oovoo tcp port 443 |
"{7F5933EC-1496-471F-B821-7DEA3FED0605}" = lport=37675 | protocol=17 | dir=in | name=oovoo udp port 37675 |
"{857807EC-81DE-41A1-9ABF-6DEDDCB344E8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C3A724BB-23D4-4E40-B1E8-4C00654EEA12}" = lport=443 | protocol=17 | dir=in | name=oovoo udp port 443 |
"{CDC6B5DE-C59C-40F2-9480-91B2A2385275}" = lport=37674 | protocol=6 | dir=in | name=oovoo tcp port 37674 |
"{E7E19190-3743-4E02-A0E7-F8CF44C99A78}" = lport=37674 | protocol=17 | dir=in | name=oovoo udp port 37674 |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E2543A4-E295-496C-B288-92E0532312AF}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{13B174F2-5B02-4ACB-A70B-BBCABC08ADA6}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{17BA009E-6436-4103-80EC-8ABC199F346A}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
"{40C881C2-A1E4-4413-AF10-1AFA322F3D0F}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{4DB33356-BC8A-4973-9F20-79DE83C25AFF}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{50F0C1F7-CD8E-472F-82B3-86B029B0135D}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
"{531910EB-02E8-4B5E-9A62-DAA5409571D8}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{55FFD04E-5F52-4F86-B8A3-865D99F424BD}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{58DCA4D3-E015-46DE-971E-203CBF0BAC08}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{5B9B1F8C-126C-4ED1-AD79-2472102BFF67}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{61EEBDFE-5BFF-42BF-A866-CA0DBCD5F9F5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{63FBF446-B080-4CB2-9B34-E8EAD116FA75}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6C1B139B-B83F-4AFD-9344-15F0CDE97C1F}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{810EC36B-2409-423A-B4AD-9C9803B56C3D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A3CC2DB9-A74E-4E1C-A272-480F76F0CFEE}" = dir=in | app=c:\program files\acer arcade deluxe\acer homemedia connect\homemedia connect.exe |
"{A3E4BF8A-6394-4CBA-93EE-9BC5798A2D1A}" = protocol=17 | dir=in | app=c:\program files\windows ilivid toolbar\datamngr\toolbar\dtuser.exe |
"{A568017F-A5BE-4B7D-8765-E0A529E9C148}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{B7276846-462D-416E-822D-1EEF65034D61}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{BB36E7B5-751D-4DDD-9909-292446444B99}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{BD0E01D9-C134-4DC2-B94E-A730EFDFD733}" = dir=in | app=c:\program files\acer arcade deluxe\acer homemedia connect\kernel\dms\clmsserver.exe |
"{C36ED1B1-181A-4ADC-8175-016C260FC62E}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C3BD6075-5459-4CCA-BFC0-3D6AA3981D58}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\pmvservice.exe |
"{CADEA39D-A879-4E31-81ED-F8BFB0A57657}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\playmovie.exe |
"{D3E0FA75-8363-4103-8607-19BDE523EE6E}" = protocol=6 | dir=in | app=c:\program files\windows ilivid toolbar\datamngr\toolbar\dtuser.exe |
"{DB438517-1B40-45EF-A745-6CAB54E9744F}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{E2458C1E-5208-4C94-96E7-19B296FE5EA6}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{E4E05FBD-8DDE-4267-A3F4-23F5B0854E37}" = dir=in | app=c:\program files\acer arcade deluxe\acer homemedia connect\kernel\dms\clmsservice.exe |
"{ED3E119B-F8A2-4A61-B14F-C87F783F665D}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{F7C7622E-9B70-491C-8DE1-ACBB1A0F7C02}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{F9A8C3CD-A21B-4845-9957-58D71DF0AE4E}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FCFA34AF-50FF-4473-A9E1-82EF4047BCAD}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP270_series" = Canon MP270 series MP Drivers
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Javaโข 6 Update 31
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6D172D0A-B9F1-4046-AFAB-8599288545BF}" = Safari
"{710BF966-43C8-4216-A8EC-BC4E169FF7C1}" = MobileMe Control Panel
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71A51A91-E7D3-11DB-A386-005056C00008}" = Vimicro USB2.0 UVC PC Camera
"{71C2828F-2678-4675-BDEC-895424861262}_is1" = C:\Program Files\Acer GameZone\GameConsole
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7A8FF745-BBC5-482B-88E4-18D3178249A9}" = ScanSoft PaperPort 11
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110082360}" = Alien Shooter
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}" = Chicken Invaders 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111940693}" = Bookworm Adventures
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}" = Heroes of Hellas
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114072167}" = Go-Go Gourmet
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11408540}" = Magic Match Adventures
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114717227}" = Magic Farm
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime (Drop Down Deals) 1.10.01
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91605026-DBBF-48FF-B703-F7719CE3F703}" = Reader for PC
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{93D34EE3-99B3-4DB1-8B0A-0A657466F90D}" = Telstra Turbo Connection Manager
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skypeโข 5.5
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0
"{B0E5D7E7-A106-458F-BA7B-2F8CAEA3BF16}" = PlayReady PC runtime
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C9CDE2FE-8AE6-469D-8789-6862DE2BB704}" = calibre
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DA7DF8E2-4B8F-4286-97FE-DE3FFFE9B728}" = iCloud
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F429ED71-4A8B-457A-85E4-F6398CE73E58}" = AV Input Selection
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FD022B2B-F1D9-4E27-851C-FFF260262E97}" = BIAS SoundSoap SE 2.1.1
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Audacity_is1" = Audacity 1.2.6
"Borders" = Borders
"CANONIJINBOXADDON100" = Canon Inkjet Printer Driver Add-On Module
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Defraggler" = Defraggler
"DivX Setup" = DivX Setup
"E2D312050E630E0CB2650D738A53820EE8BB1A95" = Windows Driver Package - 2Wire (2WIREPCP) Net (03/22/2007 2.0)
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 6.1
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.27)" = Mozilla Firefox (3.6.27)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MSC" = McAfee Internet Security Suite
"NVIDIA Drivers" = NVIDIA Drivers
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"WinLiveSuite_Wave3" = Windows Live Essentials
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 25/03/2012 9:23:55 PM | Computer Name = cato-PC | Source = WinMgmt | ID = 10
Description =
Error - 26/03/2012 7:09:58 PM | Computer Name = cato-PC | Source = WinMgmt | ID = 10
Description =
Error - 26/03/2012 11:22:22 PM | Computer Name = cato-PC | Source = WinMgmt | ID = 10
Description =
Error - 26/03/2012 11:54:12 PM | Computer Name = cato-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Sony\ReaderDesktop\UpdateChecker\UwcHelperApp.exe".
Dependent
Assembly Microsoft.VC80.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 28/03/2012 7:03:45 PM | Computer Name = cato-PC | Source = WinMgmt | ID = 10
Description =
Error - 28/03/2012 8:06:15 PM | Computer Name = cato-PC | Source = WinMgmt | ID = 10
Description =
Error - 29/03/2012 8:09:08 PM | Computer Name = cato-PC | Source = WinMgmt | ID = 10
Description =
Error - 30/03/2012 6:26:58 PM | Computer Name = cato-PC | Source = WinMgmt | ID = 10
Description =
Error - 30/03/2012 8:13:21 PM | Computer Name = cato-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 30/03/2012 8:13:21 PM | Computer Name = cato-PC | Source = Windows Search Service | ID = 3013
Description =
[ System Events ]
Error - 3/04/2012 9:53:24 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7009
Description =
Error - 3/04/2012 9:53:24 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 3/04/2012 9:53:41 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7009
Description =
Error - 3/04/2012 9:53:41 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 3/04/2012 9:54:04 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7009
Description =
Error - 3/04/2012 9:54:04 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 3/04/2012 9:54:35 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7009
Description =
Error - 3/04/2012 9:54:35 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 3/04/2012 9:54:56 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7009
Description =
Error - 3/04/2012 9:54:56 PM | Computer Name = cato-PC | Source = Service Control Manager | ID = 7000
Description =
< End of report >
Apologies for the delay - all sorted now.
Uninstall the following programs, if present:
Searchqu 406 MediaBar
1. Click Start, Control Panel, Programs, and then Programs and Features.2. Click on Searchqu 406 MediaBar and then Uninstall. Repeat for the other progrms
===================================================
Back Up Your Registry โข Go here and download ERUNT
(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
โข Install ERUNT by following the prompts
(use the default install settings but sayโ noโ to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
โข Start ERUNT by double clicking on the desktop icon
โข Choose a location for the backup (the default location is C:\WINDOWS\ERDNT
โข Make sure that at least the first two check boxes are ticked
โข Press OK
โข Press YES to create the folder.
===================================================
Run OTL
- Double click on the icon to run it.
- Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :OTL IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091 IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found IE - HKCU\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s=tdLgVWzwLlexZ8eqCu9nCi9duH8?q={searchTerms} IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms} IE - HKCU\..\SearchScopes\{9C5697CE-D305-49C8-94B5-BF99595ED6F8}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ACAW FF - prefs.js..browser.search.defaultenginename: "Search Results" FF - prefs.js..browser.search.defaultthis.engineName: "Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.order.1: "Search Results" FF - prefs.js..browser.search.selectedEngine: "Search Results" FF - prefs.js..browser.startup.homepage: "http://www.searchnu.com/406" FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2 FF - prefs.js..extensions.enabledItems: {38542454-dfb6-44f5-b052-d4e071a3d073}:[removed] FF - prefs.js..extensions.enabledItems: {b80f591e-fe9a-46cf-a13e-180377240586}:[removed] FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.3.3.2 FF - prefs.js..extensions.enabledItems: [removed]:1.20.00 FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found [2011/10/06 09:24:04 | 000,000,000 | โD | M] (Elf 1.12 Community Toolbar) โ C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\{38542454-dfb6-44f5-b052-d4e071a3d073} [2011/10/06 09:24:08 | 000,000,000 | โD | M] (Elf 1.13 Community Toolbar) โ C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\{b80f591e-fe9a-46cf-a13e-180377240586} [2011/04/27 22:51:45 | 000,000,000 | โD | M] (Vuze Remote Community Toolbar) โ C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc} [2011/03/29 07:59:02 | 000,000,000 | โD | M] (Conduit Engine) โ C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\[removed] [2011/11/08 07:30:25 | 000,000,000 | โD | M] (Yontoo Layers (Drop Down Deals)) โ C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\[removed] [2011/04/01 09:20:24 | 000,000,879 | โ- | M] () โ C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\searchplugins\conduit.xml [2011/08/15 00:20:02 | 000,002,506 | โ- | M] () โ O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc) O2 - BHO: (Yontoo Layers (Drop Down Deals)) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Runtime (Drop Down Deals)\YontooIEClient.dll (Yontoo LLC) O3 - HKLM\..\Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. [2012/04/02 19:47:24 | 000,000,000 | โD | C] โ C:\Users\cato\AppData\Local\Ilivid Player [2012/04/03 10:13:07 | 000,000,000 | โD | M] โ C:\Users\cato\AppData\Roaming\Azureus :Files C:\Users\cato\AppData\Local\Ilivid Player C:\Users\cato\AppData\Roaming\Azureus ipconfig /flushdns /c :Commands [resethosts] [emptyflash] [purity] [emptytemp] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Satchfan
Please can you post the OTL fix log.
The OTL fix log can be found at C:\_OTL\MovedFiles. The file name will consist of numbers that reflect the date and time the fix was run. It will be something like 05042012 _113025 .log
Please copy and paste the contents into your next reply, NOT attach it, (or any other future logs).
Also, can you tell me if there are any changes/problems remaining.
Thanks
Satchfan
Was unable to do the original file, could not find it properly so ran fix again and hope this is OK.
Regards cato
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{ba14329e-9550-4989-b3f2-9732e92d17cc} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70D46D94-BF1E-45ED-B567-48701376298E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9C5697CE-D305-49C8-94B5-BF99595ED6F8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C5697CE-D305-49C8-94B5-BF99595ED6F8}\ not found.
Prefs.js: "Search Results" removed from browser.search.defaultenginename
Prefs.js: "Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl
Prefs.js: "Search Results" removed from browser.search.order.1
Prefs.js: "Search Results" removed from browser.search.selectedEngine
Prefs.js: "http://www.searchnu.com/406" removed from browser.startup.homepage
Prefs.js: [removed]:3.3.3.2 removed from extensions.enabledItems
Prefs.js: {38542454-dfb6-44f5-b052-d4e071a3d073}:[removed] removed from extensions.enabledItems
Prefs.js: {b80f591e-fe9a-46cf-a13e-180377240586}:[removed] removed from extensions.enabledItems
Prefs.js: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.3.3.2 removed from extensions.enabledItems
Prefs.js: [removed]:1.20.00 removed from extensions.enabledItems
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ not found.
Folder C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\{38542454-dfb6-44f5-b052-d4e071a3d073}\ not found.
Folder C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\{b80f591e-fe9a-46cf-a13e-180377240586}\ not found.
Folder C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
Folder C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\[removed]\ not found.
Folder C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\extensions\[removed]\ not found.
File C:\Users\cato\AppData\Roaming\Mozilla\Firefox\Profiles\hial4b9k.default\searchplugins\conduit.xml not found.
File 11/08/15 00:20:02 | 000,002,506 | โ- | M] () โ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D717F81-9148-4f12-8568-69135F087DB0}\ not found.
File C:\Program Files\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ not found.
File C:\Program Files\Yontoo Layers Runtime (Drop Down Deals)\YontooIEClient.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 not found.
Folder C:\Users\cato\AppData\Local\Ilivid Player\ not found.
Folder C:\Users\cato\AppData\Roaming\Azureus\ not found.
========== FILES ==========
File\Folder C:\Users\cato\AppData\Local\Ilivid Player not found.
File\Folder C:\Users\cato\AppData\Roaming\Azureus not found.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
c:\users\cato\Downloads\cmd.bat deleted successfully.
c:\users\cato\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYFLASH]
User: All Users
User: cato
->Flash cache emptied: 343 bytes
User: Default
User: Default User
User: Public
Total Flash Files Cleaned = 0.00 mb
[EMPTYTEMP]
User: All Users
User: cato
->Temp folder emptied: 96923 bytes
->Temporary Internet Files folder emptied: 1851709 bytes
->Java cache emptied: 53836 bytes
->FireFox cache emptied: 56085358 bytes
->Google Chrome cache emptied: 10321881 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 53960 bytes
Total Files Cleaned = 65.00 mb
OTL by OldTimer - Version 3.2.39.2 log created on 04052012_215134
Files\Folders moved on Rebootโฆ
File move failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be moved on reboot.
Registry entries deleted on Rebootโฆ
Run OTL
- double click on the icon to run it.
- copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :OTL IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms} IE - HKCU\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091 [2011/08/15 00:20:02 | 000,002,506 | โ- | M] () โ C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml [2012/04/02 19:31:10 | 000,002,519 | โ- | M] () โ C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml :Reg [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}] [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}] :Files C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml :Commands [purity] [emptytemp] [Reboot]
- click the Run Fix button at the top
- let the program run unhindered, reboot when it is done
- post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Download Malwarebytes-Anti-Malware
Click here
- double-click mbam-setup.exe and follow the prompts to install the program.
- at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
- if an update is found, it will download and install the latest version.
- once the program has loaded, select Perform quick scan, then click Scan.
- when the scan is complete, click OK, then Show Results to view the results.
- be sure that everything is checked, and click Remove Selected.
- when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
- the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
- copy and paste the contents of that report in your next reply and exit MBAM.
Logs to include in the next post:
OTL fix log
New OTL log
Mbam.txt
Thanks
Satchfan
Download and run ComboFix
Download ComboFix from the following location:
Link
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
- Remember to re-enable them when we're done.
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt
Satchfan
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI