All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-2957639889-2282880335-1771364558-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtection deleted successfully.
C:\Users\Randles\AppData\Roaming\Search Protection\SearchProtection.exe moved successfully.
Registry key HKEY_USERS\S-1-5-21-2957639889-2282880335-1771364558-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\dell.com\ deleted successfully.
Starting removal of ActiveX control {7530BFB8-7293-4D34-9923-61A11451AFC5}
C:\Windows\Downloaded Program Files\OnlineScanner.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
C:\Users\Randles\AppData\Roaming\Search Protection folder moved successfully.
========== FILES ==========
< dir C:\Users\Randles\AppData\Roaming\BACS.exe /C >
Volume in drive C has no label.
Volume Serial Number is 1639-3798
Directory of C:\Users\Randles\AppData\Roaming\BACS.exe
02/10/2013 09:04 <DIR> .
02/10/2013 09:04 <DIR> ..
04/10/2013 14:59 7,866 Bacs.appInfo
04/10/2013 14:59 1,425 BacsNB.config
04/10/2013 14:59 73,166 Persistence.config
3 File(s) 82,457 bytes
2 Dir(s) 412,293,373,952 bytes free
C:\Users\Randles\Desktop\cmd.bat deleted successfully.
C:\Users\Randles\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: Randles
->Temp folder emptied: 38695114 bytes
->Temporary Internet Files folder emptied: 18626552 bytes
->Google Chrome cache emptied: 407147344 bytes
->Flash cache emptied: 2126 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 34196138 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 1046504957 bytes
Total Files Cleaned = 1,474.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 12132013_090503
Files\Folders moved on Reboot...
C:\Users\Randles\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...