This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cant get rid of utorrent. [Solved]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When you say its back, what is it showing. Can you take a screenshot next time it pops up ?

 

I am going to have you run SystemLook, you will need the 64 bit version

 

 

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
64 Bit Version
 
  •  
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
:folderfind
uTorrent
:filefind
uTorrent
:regfind
uTorrent
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

 

 

The uTorrent program just springs up from nowhere and opens up on my screen a few days after I've deleted it. It's not a huge problem and my laptop seems to be running fine but it's a bit strange how I can't get rid of it. I've taken a screengrab but there doesnt seem to be an obvious way to attach it on this forum. Apologies if I'm being very dense (entirely possible!) but could you tell me how to post it on here? I've pasted the requested log below.

 

Jen x

 

SystemLook 30.07.11 by jpshortstuff
Log created at 23:25 on 01/11/2015 by Dougie
Administrator - Elevation successful
 
========== folderfind ==========
 
Searching for "uTorrent"
C:\FRST\Quarantine\C\Program Files (x86)\uTorrent d—— [19:35 30/04/2011]
C:\FRST\Quarantine\C\Users\Dougie\AppData\LocalLow\uTorrent d—— [14:19 23/10/2015]
C:\Users\Dougie\AppData\LocalLow\uTorrent d—— [11:46 30/10/2015]
C:\Users\Dougie\AppData\Roaming\uTorrent d—— [11:45 30/10/2015]
 
========== filefind ==========
 
Searching for "uTorrent"
No files found.
 
========== regfind ==========
 
Searching for "uTorrent"
[HKEY_CURRENT_USER\Software\BitTorrent\uTorrent]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41073\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File1"="C:\Users\Dougie\Pictures\uTorrent screenshot.png"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"DisplayIcon"=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe",0"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"UninstallString"=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" /UNINSTALL"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"InstallLocation"="C:\Users\Dougie\AppData\Roaming\uTorrent"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"URLInfoAbout"="http://www.utorrent.com"
[HKEY_CURRENT_USER\Software\Classes\.btapp]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btinstall]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btkey]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btsearch]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btskin]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\Applications\uTorrent.exe]
[HKEY_CURRENT_USER\Software\Classes\Applications\uTorrent.exe\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_CURRENT_USER\Software\Classes\bittorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_CURRENT_USER\Software\Classes\bittorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_CURRENT_USER\Software\Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_CURRENT_USER\Software\Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_CURRENT_USER\Software\Classes\uTorrent]
[HKEY_CURRENT_USER\Software\Classes\uTorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_CURRENT_USER\Software\Classes\uTorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\utorrent_RASAPI32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\utorrent_RASMANCS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (TCP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (UDP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (TCP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (UDP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (TCP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (UDP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\BitTorrent\uTorrent]
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41073\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File1"="C:\Users\Dougie\Pictures\uTorrent screenshot.png"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"DisplayIcon"=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe",0"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"UninstallString"=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" /UNINSTALL"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"InstallLocation"="C:\Users\Dougie\AppData\Roaming\uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]
"URLInfoAbout"="http://www.utorrent.com"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btapp]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btinstall]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btkey]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btsearch]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btskin]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Applications\uTorrent.exe]
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Applications\uTorrent.exe\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\uTorrent]
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\uTorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\uTorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btapp]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btinstall]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btkey]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btsearch]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btskin]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Applications\uTorrent.exe]
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Applications\uTorrent.exe\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\uTorrent]
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\uTorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\uTorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
-= EOF =-

Junkware Removal should have removed most of those entries, lets run it again

 

[external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
See if you can manually delete just the uTorrent file
 

C:\Users\Dougie\AppData\LocalLow\uTorrent
C:\Users\Dougie\AppData\Roaming\uTorrent
 
 
 
 

Backup the Registry:
 
Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.
 
  •  
  • Please download the installer for Registry Backup from here or here and save to your desktop.
  • Right-click on tweaking.com_registry_backup_setup.exe and select Run as Administrator >> Follow the prompts for a default installation
  • Ensure the option Open "Tweaking.com - Registry Backup"  When Install Completes is selected >> Next >  >> Finish
  • Once the GUI(graphical user interface) has appeared/loaded:-
 
[external image: TCRB-1.jpg]
 
  •  
  • Click on Backup Now >> once the process is complete the below will be displayed in the GUI:-
 
[external image: TBRB-2.jpg]
 
  •  
  • Close Tweaking.com - Registry Backup
 
Note: There will now be a folder at the root of the Hard-Drive named C:\RegBackup, do not delete this as it is the actual backup just created.
 
A tutorial for Registry Backup explaining the various features be viewed HERE
 
 
 
 
 
 

REGEDIT4
 
 
[-HKEY_CURRENT_USER\Software\BitTorrent\uTorrent]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=-
[-HKEY_CURRENT_USER\Software\Classes\Applications\uTorrent.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\utorrent_RASAPI32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\utorrent_RASMANCS]
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\shell\open\command]
"=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[-HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\uTorrent]
 

 

 
Copy the entire contents inside the Quote box and Paste it into Notepad ( this will only work with Notepad ) name the file Regfix.reg and in the drop down box, save it as All Files. Save it to your desktop. Then Rightclick on the Regfix.reg file and click on Merge, when it asks you to merge with the Registry, say yes.
 
If you saved the file correctly it should look like this [external image: reg.jpg]
 
 
 
 
The run System Look with the same commands as I posted earlier and post the new logs

2 new logs…

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on 02/11/2015 at 11:17:11.23
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ FireFox
 
Successfully deleted the following from C:\Users\Dougie\AppData\Roaming\mozilla\firefox\profiles\vgenv38d.default-1437762687621\prefs.js
 
user_pref(browser.search.defaultenginename, Secure Search);
 
 
 
~~~ Chrome
 
 
[C:\Users\Dougie\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Dougie\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\Dougie\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Dougie\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02/11/2015 at 11:25:34.05
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
 
 
 
 
 
SystemLook 30.07.11 by jpshortstuff
Log created at 11:48 on 02/11/2015 by Dougie
Administrator - Elevation successful
 
========== folderfind ==========
 
Searching for "uTorrent"
C:\FRST\Quarantine\C\Program Files (x86)\uTorrent d—— [19:35 30/04/2011]
C:\FRST\Quarantine\C\Users\Dougie\AppData\LocalLow\uTorrent d—— [14:19 23/10/2015]
 
========== filefind ==========
 
Searching for "uTorrent"
No files found.
 
========== regfind ==========
 
Searching for "uTorrent"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41073\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File1"="C:\Users\Dougie\Pictures\uTorrent screenshot.png"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths]
"url4"="C:\Users\Dougie\AppData\LocalLow\uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btapp]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btinstall]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btkey]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btsearch]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btskin]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\bittorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_CURRENT_USER\Software\Classes\bittorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_CURRENT_USER\Software\Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_CURRENT_USER\Software\Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (TCP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (UDP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (TCP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (UDP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (TCP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (UDP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41073\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File1"="C:\Users\Dougie\Pictures\uTorrent screenshot.png"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths]
"url4"="C:\Users\Dougie\AppData\LocalLow\uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btapp]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btinstall]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btkey]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btsearch]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btskin]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btapp]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btinstall]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btkey]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btsearch]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btskin]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
-= EOF =-

Lets try removing some more entries using FRST, post a new SystemLook log after the fix , just need to see the one for the registry, along with the Fixlog from FRST

 

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint: 
[-HKEY_CLASSES_ROOT\.btsearch]
[-HKEY_CLASSES_ROOT\.torrent]
[-HKEY_CLASSES_ROOT\uTorrent]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent1.0]
[-HKEY_CLASSES_ROOT\.btapp\DefaultIcon\]
[-HKEY_CLASSES_ROOT\.btapp\shell\open\command]
[-HKEY_CLASSES_ROOT\.btinstall\DefaultIcon\]
[-HKEY_CLASSES_ROOT\.btinstall\shell\open\command\]
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

 

SystemLook 30.07.11 by jpshortstuff
Log created at 13:49 on 02/11/2015 by Dougie
Administrator - Elevation successful
 
========== folderfind ==========
 
Searching for "uTorrent"
C:\FRST\Quarantine\C\Program Files (x86)\uTorrent d—— [19:35 30/04/2011]
C:\FRST\Quarantine\C\Users\Dougie\AppData\LocalLow\uTorrent d—— [14:19 23/10/2015]
 
========== filefind ==========
 
Searching for "uTorrent"
No files found.
 
========== regfind ==========
 
Searching for "uTorrent"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41073\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File1"="C:\Users\Dougie\Pictures\uTorrent screenshot.png"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths]
"url4"="C:\Users\Dougie\AppData\LocalLow\uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btapp]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btinstall]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btkey]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\.btskin]
@="uTorrent"
[HKEY_CURRENT_USER\Software\Classes\bittorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_CURRENT_USER\Software\Classes\bittorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_CURRENT_USER\Software\Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_CURRENT_USER\Software\Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (TCP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (UDP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (TCP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (UDP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (TCP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe|Name=μTorrent (UDP-In)|Desc=Allow μTorrent network traffic with Edge Traversal|Edge=TRUE|"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41073\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File1"="C:\Users\Dougie\Pictures\uTorrent screenshot.png"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths]
"url4"="C:\Users\Dougie\AppData\LocalLow\uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btapp]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btinstall]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btkey]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btskin]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btapp]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btinstall]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btkey]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btskin]
@="uTorrent"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
-= EOF =-
 
 
 
 
 
Fix result of Farbar Recovery Scan Tool (x64) Version:31-10-2015
Ran by [removed] (2015-11-02 13:16:17) Run:3
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint: 
[-HKEY_CLASSES_ROOT\.btsearch]
[-HKEY_CLASSES_ROOT\.torrent]
[-HKEY_CLASSES_ROOT\uTorrent]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent1.0]
[-HKEY_CLASSES_ROOT\.btapp\DefaultIcon\]
[-HKEY_CLASSES_ROOT\.btapp\shell\open\command]
[-HKEY_CLASSES_ROOT\.btinstall\DefaultIcon\]
[-HKEY_CLASSES_ROOT\.btinstall\shell\open\command\]
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
HKEY_CLASSES_ROOT\.btsearch => key removed successfully
HKEY_CLASSES_ROOT\.torrent => key removed successfully
HKEY_CLASSES_ROOT\uTorrent => key not found. 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent1.0 => key not found. 
HKEY_CLASSES_ROOT\.btapp\DefaultIcon => key not found. 
HKEY_CLASSES_ROOT\.btapp\shell\open\command => key not found. 
HKEY_CLASSES_ROOT\.btinstall\DefaultIcon => key not found. 
HKEY_CLASSES_ROOT\.btinstall\shell\open\command => key not found. 
EmptyTemp: => 678.3 MB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 13:18:18 ====

That's great, thanks. Again, really appreciate it. I've deleted uTorrent once more… just from 'Remove Programs' on the Control Panel. I suppose it's just a matter of time to see if it resurfaces again in about 5 days! 

 

Thanks a lot

 

Jen x

For the time being before I get back to you try using Revo Uninstaller, the free version is fine, see if it finds uTorrent and it it does have it remove all the registry entries

 

http://www.revouninstaller.com/revo_uninstaller_free_download.html

Lets do a few at a time and see if they work

 

REGEDIT4
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File1"=""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths]
"url4"=""
[-HKEY_CURRENT_USER\Software\Classes\.btapp]
[-HKEY_CURRENT_USER\Software\Classes\.btinstall]
[-HKEY_CURRENT_USER\Software\Classes\.btkey]
[-HKEY_CURRENT_USER\Software\Classes\.btskin]
[-HKEY_CURRENT_USER\Software\Classes\bittorrent]
[-HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent]
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=-
 

 

 
Copy the entire contents inside the Quote box and Paste it into Notepad ( this will only work with Notepad ) name the file Regfix.reg and in the drop down box, save it as All Files. Save it to your desktop. Then Rightclick on the Regfix.reg file and click on Merge, when it asks you to merge with the Registry, say yes.
 
If you saved the file correctly it should look like this [external image: reg.jpg]
 
Then reboot your system

Then lets fix these with FRST

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint: 
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List" /v "File1" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths" /v "url4" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\.btapp" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\.btinstall" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\.btkey" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\.btskin" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\bittorrent\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\bittorrent\shell\open\command" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\Magnet\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\Magnet\shell\open\command" /v "@" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List" /v "File1" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths" /v "url4" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btapp" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btinstall" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btkey" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btskin" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\shell\open\command" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\shell\open\command" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btapp" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btinstall" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btkey" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btskin" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\shell\open\command" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\shell\open\command" /v "@" /f
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
 
Post the Fixlog from FRST and Then reboot your system again and run System Look just the regfind
 

:regfind
uTorrent

Hello!

         Sorry about the delay. Please dont close this thread…I've had a very busy week. Will post the logs in the next 24 hours. I would do it now but I'm very very tired and working in 6 hours!

 

Thanks,

 

Jen x

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI