This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cant get rid of utorrent. [Solved]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok, sorry for the delay. Week from hell :)

 

 

Jen x

 

Fix result of Farbar Recovery Scan Tool (x64) Version:31-10-2015
Ran by [removed] (2015-11-02 16:35:00) Run:4
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint: 
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List" /v "File1" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths" /v "url4" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\.btapp" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\.btinstall" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\.btkey" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\.btskin" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\bittorrent\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\bittorrent\shell\open\command" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\Magnet\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_CURRENT_USER\Software\Classes\Magnet\shell\open\command" /v "@" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List" /v "File1" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths" /v "url4" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btapp" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btinstall" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btkey" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btskin" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\shell\open\command" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\shell\open\command" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btapp" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btinstall" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btkey" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btskin" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\shell\open\command" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\DefaultIcon" /v "@" /f
reg: reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\shell\open\command" /v "@" /f
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
 
========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List" /v "File1" /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths" /v "url4" /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Classes\.btapp" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Classes\.btinstall" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Classes\.btkey" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Classes\.btskin" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Classes\bittorrent\DefaultIcon" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Classes\bittorrent\shell\open\command" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Classes\Magnet\DefaultIcon" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_CURRENT_USER\Software\Classes\Magnet\shell\open\command" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f =========
 
ERROR: Access is denied.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f =========
 
ERROR: Access is denied.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f =========
 
ERROR: Access is denied.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f =========
 
ERROR: Access is denied.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}" /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}" /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}" /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}" /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0912ADC6-FEAA-4E01-B955-34D48B4C95C3}" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{A53C4AE2-56F8-4555-A76D-6CD7AF33666E}" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List" /v "File1" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths" /v "url4" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btapp" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btinstall" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btkey" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\.btskin" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\DefaultIcon" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\bittorrent\shell\open\command" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\DefaultIcon" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\shell\open\command" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btapp" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btinstall" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btkey" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\.btskin" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\DefaultIcon" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\bittorrent\shell\open\command" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\DefaultIcon" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\shell\open\command" /v "@" /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
EmptyTemp: => 117.9 MB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 16:36:14 ====
 
 
 
 
SystemLook 30.07.11 by jpshortstuff
Log created at 02:16 on 07/11/2015 by Dougie
Administrator - Elevation successful
 
========== regfind ==========
 
Searching for "uTorrent"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41073\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_CURRENT_USER\Software\Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41073\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@="{0.0.0.00000000}.{5035cdbc-70a3-4bd9-bb1b-bbd3d776a270}|\Device\HarddiskVolume3\Users\Dougie\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\DefaultIcon]
@="C:\Users\Dougie\AppData\Roaming\uTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\shell\open\command]
@=""C:\Users\Dougie\AppData\Roaming\uTorrent\uTorrent.exe" "%1" /SHELLASSOC"
 
-= EOF =-
 
 
 
 
 
 

Make sure you back up your registry first with the program I posted earlier in case of any problems you can restore it 

 

 

  • Click Start > Run type Notepad click OK.
  • This will open an empty Notepad file.
  • Copy/Paste the contents of the box below into Notepad.

 

 

 
Windows Registry Editor Version 5.00
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@=-
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@=-
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@=-
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@=-
 
[HKEY_CURRENT_USER\Software\Classes\Magnet\DefaultIcon]
@=-
 
[HKEY_CURRENT_USER\Software\Classes\Magnet\shell\open\command]
@=-
 
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=-
 
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=-
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=-
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=-
 
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\309eac14_0]
@=-
 
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bc2a19ba_0]
@=-
 
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c7592708_0]
@=-
 
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ee683ef9_0]
@="-
 
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\DefaultIcon]
@=-
 
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000\Software\Classes\Magnet\shell\open\command]
@=-
 
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\DefaultIcon]
@=-
 
[HKEY_USERS\S-1-5-21-1272418825-2152305279-3347187607-1000_Classes\Magnet\shell\open\command]
@=-
 
 
 
 
  • Click Format and ensure Wordwrap is unchecked.
  • Save as RegFix.reg
  • Save as file type All Files or it won't work.
  • Now double click on RegFix.reg to run it.
  • You will be prompted to allow it to merge with the Registry. Allow it please.

Ok, I've done that. uTorrent hasn't resurfaced again so far. I deleted it again at the start of the week so if it is going to pop up again it should be round about now. I'm guessing that that's probably it now. Sorry that it's been so much trouble and thank you for your expertise.

 

Jen x

SystemLook 30.07.11 by jpshortstuff
Log created at 13:40 on 08/11/2015 by Dougie
Administrator - Elevation successful
 
========== regfind ==========
 
Searching for "uTorrent"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates]
"u_utorrent__utorrent_4"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan]
"s_utorrent__utorrent_4"=""
 
-= EOF =-

Making a lot of headway, not sure why those four entries where not removed, they may be bundled with mcAfee and possibly cannot be removed, lets do this, post the fix log after the fix and also a new SystemLook log

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint: 
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-09 00:28:52) Run:5
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint: 
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
 
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f =========
 
ERROR: Access is denied.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f =========
 
ERROR: Access is denied.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\appupdates" /v "u_utorrent__utorrent_4" /f =========
 
ERROR: Access is denied.
 
 
 
========= End of Reg: =========
 
 
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\MSC\Telemetry\VUL\scan" /v "s_utorrent__utorrent_4" /f =========
 
ERROR: Access is denied.
 
 
 
========= End of Reg: =========
 
EmptyTemp: => 517 MB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 00:30:37 ====

Jen,

 

Those four entries are embedded into McAfee and the only way to remove them is to uninstall McAfee , fix them and then reinstall McAfee but I dont feel that is needed as there not pointing to uTorrent starting up. 

 

Use your computer for a few more days and post back and let me know how its going

Great, glad to hear that :)

 

 

 

Double click on AdwCleaner.exe to run the tool again.
  • Click on the Uninstall button.
  • Click Yes when asked are you sure you want to uninstall.
  • Both AdwCleaner.exe, its folder and all logs will be removed.
  •  
     
    ==========================================================
     
     
    Please download DelFix and save the file to your Desktop.
     
    [external image: DelFix_zps139e2ea1.jpg]
     
    • Windows XP Double Click DelFix.exe to run the program. 
    • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
    • Checkmark " Remove Disinfection Tools"
    • Click the Run button
    •  
      This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
       
       
       
       
      So How did I get infected in the first place <– Some reading for you to keep yourself safe online
       
       
      Safe Surfn
      Ken

      Ask AI

      AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

      Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI