Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

audio virus, redirected web searches, false warnings [Closed] [Solved]


  • This topic is locked This topic is locked

#31
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Thank you for the log. :) How is the computer? Are the audio ads still playing?
  • 0

Advertisements


#32
audreymaye

audreymaye

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
I will use it today and see if the ads are still running.
  • 0

#33
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
:thumbsup: :)
  • 0

#34
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Hi, just wanted to check in and see if you had a chance to test out the machine. :)
  • 0

#35
audreymaye

audreymaye

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
I haven't had any more problems with the audio ads. How should we proceed from here?
  • 0

#36
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Good to hear! :thumbsup: I have a few more steps that will need approval and then we can proceed. :)
  • 0

#37
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Hi, let's run a sweep for remnants and check for out of date programs on your machine.

Please disable your antivirus for the duration of my instructions. Don't forget to re-enable them after you have completed the steps.


Step 1: Scan with Malwarebytes


Posted Image Please download Malwarebytes' Anti-Malware from Here.

  • Double Click mbam-setup.exe to install the application (Windows 7 users, right click and select Run as Administrator.)
  • Proceed through the setup
    • Choose your language
    • Accept the License Agreement
    • Select Destination Location
    • Select Start Menu Folder
    • Select Addtional Tasks
    • Click Install
    • In the Completeing the Malwarebytes Anti-Malware Setup Wizard Window
      • Uncheck Enable free trial of Malwarebytes Anti-Malware PRO
      • Keep the check mark beside Update Malwarebytes' Anti-Malware
      • Keep the check mark beside Launch Malwarebytes' Anti-Malware
    • Click Finish.
    • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan
  • Click Scan. The scan may take some time to finish,so please be patient.

    Posted Image
  • When the scan is complete, click OK, then Show Results to view the results.

    Posted Image
  • Make sure that everything is checked, and click Remove Selected.

    Posted Image
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply.




Step 2: Scan with ESET Online Scanner


Please note: You can use Internet Explorer or Firefox for this step. Either browser used will have to be ran in admin mode.

Right click on either the Internet Explorer icon or the Firefox icon in the Start Menu or Quick Launch Bar on the Task bar and select Run as Administrator from the menu.

If you use Firefox, you will be prompted to download esetsmartinstaller_enu.exe. Please do so, then double click it to install it.

Please click on this link and then click the ESET Online Scanner bar ---->Posted Image

  • Select the option YES, I accept the Terms of Use then click on Start
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked.
  • Make sure that the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
  • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology
  • Now click on Start
  • The virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • Now click on Finish
  • Use notepad to open the logfile located at C:\Program Files(x86)\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.


Step 3: SecurityCheck Scan


Download Security CheckPosted Image by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Things I need to see in your next post:

  • ESET Scan Log
  • MBAM Log
  • SecurityCheck Log

  • 0

#38
audreymaye

audreymaye

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
eOkay here's the MBAM log:

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2014.01.20.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Audrey :: AUDREYS-PC [administrator]

Protection: Enabled

1/20/2014 5:51:12 PM
mbam-log-2014-01-20 (17-51-12).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 244931
Time elapsed: 20 minute(s), 27 second(s)

Memory Processes Detected: 2
C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-ua.exe (PUP.Optional.Consumer.Input.A) -> 3716 -> Delete on reboot.
C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe (PUP.Optional.Consumer.Input.A) -> 3724 -> Delete on reboot.

Memory Modules Detected: 1
C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-api.dll (PUP.Optional.Consumer.Input.A) -> Delete on reboot.

Registry Keys Detected: 31
HKCR\AppID\{384997EE-E3BE-49C4-9ECA-C62B7C08128A} (PUP.Optional.DynConIE.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} (PUP.Optional.WebSteroids.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6} (PUP.Optional.DynConIE.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93DBF2BB-A2B3-4683-A92E-57E60751F346} (PUP.Optional.ValueApps.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.CoCreateAsync (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.CoCreateAsync.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.CoreClass (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.CoreClass.1 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.CoreMachineClass (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.CoreMachineClass.1 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.CredentialDialogMachine (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.CredentialDialogMachine.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.OnDemandCOMClassMachine (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.OnDemandCOMClassMachineFallback (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.OnDemandCOMClassSvc (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.ProcessLauncher (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.ProcessLauncher.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.Update3COMClassService (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.Update3COMClassService.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.Update3WebMachine (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.Update3WebMachine.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.Update3WebMachineFallback (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.Update3WebMachineFallback.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.Update3WebSvc (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCR\ConsumerInputUpdate.Update3WebSvc.1.0 (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
HKCU\Software\ilividmoviestoolbarha (PUP.Optional.MoviesToolBar.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Classes\AppID\DynConIE.DLL (PUP.Optional.DynConIE.A) -> Quarantined and deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\consumerinput_update (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 3
C:\Program Files (x86)\Consumer Input (PUP.Optional.Consumer.Input.A) -> Delete on reboot.
C:\Program Files (x86)\Consumer Input\InternetExplorer (PUP.Optional.Consumer.Input.A) -> Delete on reboot.
C:\Program Files (x86)\Consumer Input\Monitoring (PUP.Optional.Consumer.Input.A) -> Delete on reboot.

Files Detected: 9
C:\ProgramData\ReadOnlyInstaller.msi (PUP.Optional.WeCare.A) -> Quarantined and deleted successfully.
C:\Users\Audrey\AppData\Roaming\.minecraft\bin\secuity.rar (PUP.Optional.InstallIQ) -> Quarantined and deleted successfully.
C:\Users\Audrey\Downloads\iLividSetup-r394-n-bi.exe (PUP.Optional.Bandoo) -> Quarantined and deleted successfully.
C:\Users\Audrey\Downloads\superantispyware_setup(1).exe (PUP.Optional.InstallCore.A) -> Quarantined and deleted successfully.
C:\Users\Audrey\Downloads\superantispyware_setup.exe (PUP.Optional.InstallCore.A) -> Quarantined and deleted successfully.
C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job (PUP.Optional.Consumer.Input.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-api.dll (PUP.Optional.Consumer.Input.A) -> Delete on reboot.
C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-ua.exe (PUP.Optional.Consumer.Input.A) -> Delete on reboot.
C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe (PUP.Optional.Consumer.Input.A) -> Delete on reboot.

(end)
  • 0

#39
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Looks good! I know the ESET scan can take quite a while. Whenever it finishes and you can post it and the SecurityCheck log will be fine. :thumbsup:
  • 0

#40
audreymaye

audreymaye

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
I am working on it...sorry it's taking so long
  • 0

Advertisements


#41
audreymaye

audreymaye

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
When I ran firefox as administrator I wasn't prompted to install esetsmartinsteller. I tried to click the link but got this error message:


The page isn't redirecting properly

Firefox has detected that the server is redirecting the request for this address in a way that will never complete.
  • 0

#42
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts

I am working on it...sorry it's taking so long


No worries :) We'll do this on a schedule that works best for you. :thumbsup:


When I ran firefox as administrator I wasn't prompted to install esetsmartinsteller. I tried to click the link but got this error message:


The page isn't redirecting properly

Firefox has detected that the server is redirecting the request for this address in a way that will never complete.


Ok, click this link, and it should work for you this time. :)

http://www.eset.com/us/online-scanner/
  • 0

#43
audreymaye

audreymaye

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Sorry it took so long...

ESETSmartInstaller@High as downloader log:
Can not read file from internet.ESETSmartInstaller@High as downloader log:
Can not read file from internet.Can not open internetESETSmartInstaller@High as downloader log:
Can not open internet# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=f207fc0ed0cf6a45a3bdd0033b1f6891
# engine=16802
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-01-26 08:05:10
# local_time=2014-01-26 01:05:10 (-0700, Mountain Standard Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 77 1722513 2494677 0 0
# compatibility_mode=5893 16776573 100 94 354051 142310160 0 0
# scanned=162738
# found=30
# cleaned=0
# scan_time=14079
sh=93510E07EBD463BE51052EC8114EC16C5423103E ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Mozilla Firefox\browser\nsprotector.js.vir"
sh=77801D0E0DC02E8C50CDC73562F4D7F13FC1C18B ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\ffprotect\application.js.vir"
sh=170ACC25B35BA845064591DF61F2D52142823738 ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\ffprotect\nsprotector.js.vir"
sh=BB64EAB4A8D339B38E2C84ECCDC1EB9BCB508661 ft=1 fh=b9050071cbb9d4b1 vn="a variant of Win32/Toolbar.Conduit.P application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Audrey\AppData\LocalLow\SweetPacks\ldrtbSwee.dll.vir"
sh=41565A5C7C5DE65C949CC2C3566265E05A0BA782 ft=1 fh=95024ab9b65b3320 vn="a variant of Win32/Toolbar.Conduit.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Audrey\AppData\LocalLow\SweetPacks\tbSwee.dll.vir"
sh=B5C93DA0C608B26C9487ABC49CCB643C9A15ED33 ft=1 fh=75f1c65aa8a331ed vn="a variant of Win32/PriceGong.A application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Audrey\AppData\LocalLow\SweetPacks\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGongIE.dll.vir"
sh=D929C336498DADAB24159BCEBA2CB112FA61DB65 ft=1 fh=2085af9b58a3c710 vn="a variant of Win32/Toolbar.Perion.G application" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\SysWOW64\ARFC\wrtc.exe.vir"
sh=1A739914A874A42A4520CE05D8B8761A884ADFB7 ft=1 fh=de394184ef561da5 vn="a variant of Win32/Toolbar.Perion.G application" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\SysWOW64\WNLT\Installation\WSSetup.exe.vir"
sh=59F3FE64F197C62D93FC68A615A265E18A40FC3A ft=1 fh=0aae50be347bedc5 vn="a variant of Win32/ExFriendAlert.B application" ac=I fn="C:\ProgramData\Updater\Uninstall.exe"
sh=59F3FE64F197C62D93FC68A615A265E18A40FC3A ft=1 fh=0aae50be347bedc5 vn="a variant of Win32/ExFriendAlert.B application" ac=I fn="C:\Users\All Users\Updater\Uninstall.exe"
sh=990C19FFECC9CBFCAD5E95F90C5F88B8F595DFC9 ft=1 fh=2f22969017421b85 vn="Win32/Toolbar.SearchSuite application" ac=I fn="C:\Users\Audrey\Documents\Minecraft Launcher\iLividSetup.exe"
sh=990C19FFECC9CBFCAD5E95F90C5F88B8F595DFC9 ft=1 fh=2f22969017421b85 vn="Win32/Toolbar.SearchSuite application" ac=I fn="C:\Users\Audrey\Documents\Scanned Documents\iLividSetup.exe"
sh=5A57010EA3C1E61AE84AA45A2551DBBD9649D692 ft=1 fh=86b596c4c976ff4c vn="a variant of Win32/CNETInstaller.B application" ac=I fn="C:\Users\Audrey\Downloads\cbsidlm-cbsi5_4_0_104-Revo_Uninstaller-SEO-10687648.exe"
sh=2FEC2BB06C11B711B37E7D1BAC0004F8F25A4C7B ft=1 fh=9586b0754c97a9e0 vn="Win32/Bundled.Toolbar.Google.D application" ac=I fn="C:\Users\Audrey\Downloads\ccsetup401.exe"
sh=FB595AE8FDFBBAA259D84BE399F2959C218C2F60 ft=1 fh=d9b75d7f29ec9d02 vn="a variant of Win32/Bundled.Toolbar.Ask application" ac=I fn="C:\Users\Audrey\Downloads\disk-defrag-setup(1).exe"
sh=FB595AE8FDFBBAA259D84BE399F2959C218C2F60 ft=1 fh=d9b75d7f29ec9d02 vn="a variant of Win32/Bundled.Toolbar.Ask application" ac=I fn="C:\Users\Audrey\Downloads\disk-defrag-setup.exe"
sh=AA39A015EA89F4E5E12C9775DF3C0F2C6B254AAD ft=1 fh=06e0c432f75b3b8c vn="a variant of Win32/Bundled.Toolbar.Ask application" ac=I fn="C:\Users\Audrey\Downloads\registry-cleaner-setup.exe"
sh=B37B52285DE862B7CAEA96BB8EB99D9B10DE236F ft=1 fh=1dbf7062960066bb vn="Win32/Bundled.Toolbar.Google.D application" ac=I fn="C:\Users\Audrey\Downloads\Shockwave_Installer_Slim.exe"
sh=B5B41E946960F17050C00A4891CFF46B08486A4D ft=1 fh=79895fd74f1827db vn="Win32/Bundled.Toolbar.Google.D application" ac=I fn="C:\Windows\System32\Adobe\Shockwave 12\gt.exe"
sh=B5B41E946960F17050C00A4891CFF46B08486A4D ft=1 fh=79895fd74f1827db vn="Win32/Bundled.Toolbar.Google.D application" ac=I fn="C:\Windows\SysWOW64\Adobe\Shockwave 12\gt.exe"
sh=9A11FA4B4C65E4E337705716CF5E7729DCC845DD ft=1 fh=253d22f876c9faad vn="a variant of Win32/BrowseFox.G application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_Program Files (x86)\BuzzSearch\updateBuzzSearch.exe"
sh=9A11FA4B4C65E4E337705716CF5E7729DCC845DD ft=1 fh=253d22f876c9faad vn="a variant of Win32/BrowseFox.G application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_Program Files (x86)\BuzzSearch\bin\utilBuzzSearch.exe"
sh=F4687F26FB5F90F12B444867597F3C32F765B35F ft=1 fh=512b5a55375d865d vn="Win32/Toolbar.Conduit.T application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll"
sh=BB64EAB4A8D339B38E2C84ECCDC1EB9BCB508661 ft=1 fh=b9050071cbb9d4b1 vn="a variant of Win32/Toolbar.Conduit.P application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_Program Files (x86)\SweetPacks\ldrtbSwee.dll"
sh=41565A5C7C5DE65C949CC2C3566265E05A0BA782 ft=1 fh=95024ab9b65b3320 vn="a variant of Win32/Toolbar.Conduit.B application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_Program Files (x86)\SweetPacks\tbSwee.dll"
sh=AD3D0A70CE074EA07CE5B82736EA126626FE9666 ft=1 fh=5e539c57b6095e4d vn="a variant of Win32/ExFriendAlert.B application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_ProgramData\Websteroids\IE\common.dll"
sh=9F82BB5DC8D4EC6B8B2BB47CB6C329B8AF1C14CE ft=1 fh=c92ed1f3ca58c043 vn="Win32/InstallCore.AZ application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_Users\Audrey\AppData\Roaming\0S1F1O2Z0S2Y1H1T\ROM Manager Packages\uninstaller.exe"
sh=77801D0E0DC02E8C50CDC73562F4D7F13FC1C18B ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_Users\Audrey\AppData\Roaming\SearchProtect\ffprotect\application.js"
sh=170ACC25B35BA845064591DF61F2D52142823738 ft=0 fh=0000000000000000 vn="Win32/Conduit.SearchProtect.A application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_Users\Audrey\AppData\Roaming\SearchProtect\ffprotect\nsprotector.js"
sh=22365F58A842B4AB7B83A5514ABE69D1FCC88476 ft=1 fh=b07ef803493edc7c vn="a variant of Win32/InstallIQ.A application" ac=I fn="C:\_OTL\MovedFiles\01012014_150310\C_Users\Audrey\Desktop\secuity.exe"
  • 0

#44
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Looks good! Let's get rid of the remnants it found. :) When you complete this fix, please post the SecurityCheck log along with the OTL Fix log.



Let's run an OTL fix:

Warning: This fix is to be used on this system and this system ONLY. Using this fix on any other machine other than yours can seriously damage it.

Be advised that when the fix commences, it will shut down all running processes and you may lose the desktop and icons, they will return on reboot.

Run OTL by double clicking it (Windows Vista, Windows 7, and 8, right click and select "Run as Administrator)

  • Copy the text in the quote box below (do not copy the word "quote") and paste in the in the box marked Custom Scans/Fixes as shown in the graphic below.

Posted Image

:Commands
[createrestorepoint]

:Files
C:\ProgramData\Updater
C:\Users\Audrey\Documents\Minecraft Launcher\iLividSetup.exe
C:\Users\Audrey\Documents\Scanned Documents\iLividSetup.exe
C:\Users\Audrey\Downloads\cbsidlm-cbsi5_4_0_104-Revo_Uninstaller-SEO-10687648.exe
C:\Users\Audrey\Downloads\ccsetup401.exe
C:\Users\Audrey\Downloads\disk-defrag-setup(1).exe
C:\Users\Audrey\Downloads\disk-defrag-setup.exe
C:\Users\Audrey\Downloads\registry-cleaner-setup.exe
C:\Users\Audrey\Downloads\Shockwave_Installer_Slim.exe
C:\Windows\System32\Adobe\Shockwave 12\gt.exe
C:\Windows\SysWOW64\Adobe\Shockwave 12\gt.exe

:Commands
[reboot]





  • Click the Run Fix button at the top of the OTL control panel.
  • Let the program run until it's finished and then reboot the computer.
  • Once your machine has rebooted, a log will open. If for some reason the log doesn't open, you can find a copy of it here: C:\_OTL\MovedFiles . Please post that log in your next reply.

If you have any problems, questions, or need further explanation, please post a message in this thread and I will get back to you asap.


Things I need to see in your next post:

OTL Fix Log

SecurityCheck Log

  • 0

#45
audreymaye

audreymaye

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Service BackupStack stopped successfully!
Service BackupStack deleted successfully!
C:\Program Files (x86)\MyPC Backup\BackupStack.exe moved successfully.
Service IBUpdaterService stopped successfully!
Service IBUpdaterService deleted successfully!
C:\Windows\SysNative\dmwu.exe moved successfully.
Service InternetUpdater stopped successfully!
Service InternetUpdater deleted successfully!
C:\ProgramData\InternetUpdater\InternetUpdaterService.exe moved successfully.
Error: Unable to stop service Util BuzzSearch!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util BuzzSearch deleted successfully.
C:\Program Files (x86)\BuzzSearch\bin\utilBuzzSearch.exe moved successfully.
Service Update BuzzSearch stopped successfully!
Service Update BuzzSearch deleted successfully!
C:\Program Files (x86)\BuzzSearch\updateBuzzSearch.exe moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{7e8a1050-cf67-4575-92df-dcc60e7d952d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ deleted successfully.
C:\Program Files (x86)\SweetPacks\prxtbSwee.dll moved successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{539F76FD-084E-4858-86D5-62F02F54AE86} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}\ deleted successfully.
C:\Program Files (x86)\Minibar\Minibar.dll moved successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{7e8a1050-cf67-4575-92df-dcc60e7d952d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ not found.
File C:\Program Files (x86)\SweetPacks\prxtbSwee.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B584D2D2-4B8E-4D13-8CA3-F0662FA68EF7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B584D2D2-4B8E-4D13-8CA3-F0662FA68EF7}\ not found.
Prefs.js: "SweetPacks Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "http://search.condui...={searchTerms}" removed from browser.search.defaulturl
Prefs.js: false removed from browser.search.update
Prefs.js: support%40searchdonkeyapp.com:2.6.4962872 removed from extensions.enabledAddons
Prefs.js: support%40websteroidsapp.com:2.6.53 removed from extensions.enabledAddons
Prefs.js: "http://search.condui...010251&UM=2&q=" removed from keyword.URL
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{94cd2cc3-083f-49ba-a218-4cda4b4829fd}\META-INF folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{94cd2cc3-083f-49ba-a218-4cda4b4829fd}\components folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{94cd2cc3-083f-49ba-a218-4cda4b4829fd}\chrome\content folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{94cd2cc3-083f-49ba-a218-4cda4b4829fd}\chrome folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{94cd2cc3-083f-49ba-a218-4cda4b4829fd} folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\plugins folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\chrome\content\minibar folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\chrome\content\kango-ui\theme\bubble folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\chrome\content\kango-ui\theme folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\chrome\content\kango-ui folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\chrome\content\kango folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\chrome\content\icons folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\chrome\content folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\chrome folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF} folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\[email protected]\chrome\content folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\[email protected]\chrome folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\[email protected] folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\[email protected]\chrome\content folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\[email protected]\chrome folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\extensions\[email protected] folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\searchplugins\conduit.xml moved successfully.
C:\Users\Audrey\AppData\Roaming\Mozilla\Firefox\Profiles\7z6g35x0.default\searchplugins\MyStart Search.xml moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93DBF2BB-A2B3-4683-A92E-57E60751F346}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93DBF2BB-A2B3-4683-A92E-57E60751F346}\ deleted successfully.
C:\Program Files\Conduit\ValueApps\IE\ValueAppsLoader.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44ed99e2-16a6-4b89-80d6-5b21cf42e78b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44ed99e2-16a6-4b89-80d6-5b21cf42e78b}\ deleted successfully.
C:\ProgramData\Websteroids\IE\common.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ not found.
File C:\Program Files (x86)\SweetPacks\prxtbSwee.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93DBF2BB-A2B3-4683-A92E-57E60751F346}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93DBF2BB-A2B3-4683-A92E-57E60751F346}\ deleted successfully.
C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA74D58F-ACD0-450D-A85E-6C04B171C044}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA74D58F-ACD0-450D-A85E-6C04B171C044}\ deleted successfully.
File C:\Program Files (x86)\Minibar\Minibar.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}\ deleted successfully.
C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-bho.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7e8a1050-cf67-4575-92df-dcc60e7d952d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ not found.
File C:\Program Files (x86)\SweetPacks\prxtbSwee.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7E8A1050-CF67-4575-92DF-DCC60E7D952D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E8A1050-CF67-4575-92DF-DCC60E7D952D}\ not found.
File C:\Program Files (x86)\SweetPacks\prxtbSwee.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Updater deleted successfully.
C:\ProgramData\Updater\updater.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AppsHat deleted successfully.
C:\Users\Audrey\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ConduitFloatingPlugin_lcnnhcneegeeojhgpfijnlnocjdmlaon not found.
C:\Users\Audrey\AppData\Roaming\ValueApps\CH\TBVerifier.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\iLivid deleted successfully.
C:\Users\Audrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk moved successfully.
C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe moved successfully.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}\ deleted successfully.
File C:\Program Files (x86)\Minibar\Minibar.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\MOVIES~1\Datamngr\x64\mgrldr.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~2\movies~1\datamngr\mgrldr.dll deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe\ deleted successfully.
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe\ not found.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
File move failed. F:\AUTORUN.INF scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{82994bee-e343-11e1-bb27-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{82994bee-e343-11e1-bb27-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{82994bee-e343-11e1-bb27-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{82994bee-e343-11e1-bb27-806e6f6e6963}\ not found.
File move failed. F:\RISK.EXE scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{82994bee-e343-11e1-bb27-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{82994bee-e343-11e1-bb27-806e6f6e6963}\ not found.
File move failed. F:\SETUP.EXE scheduled to be moved on reboot.
C:\ProgramData\InternetUpdater folder moved successfully.
C:\Users\Audrey\AppData\Roaming\ValueApps\CH folder moved successfully.
C:\Users\Audrey\AppData\Roaming\ValueApps folder moved successfully.
C:\Program Files\Conduit\ValueApps\IE folder moved successfully.
C:\Program Files\Conduit\ValueApps folder moved successfully.
C:\Program Files\Conduit folder moved successfully.
C:\ProgramData\Websteroids\IE folder moved successfully.
C:\ProgramData\Websteroids\Firefox\chrome\content folder moved successfully.
C:\ProgramData\Websteroids\Firefox\chrome folder moved successfully.
C:\ProgramData\Websteroids\Firefox folder moved successfully.
C:\ProgramData\Websteroids\Chrome\unzip folder moved successfully.
C:\ProgramData\Websteroids\Chrome folder moved successfully.
C:\ProgramData\Websteroids folder moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WiseConvert folder moved successfully.
C:\Program Files (x86)\WiseConvert\WiseConvert\res folder moved successfully.
C:\Program Files (x86)\WiseConvert\WiseConvert folder moved successfully.
C:\ProgramData\PC Optimizer Pro\LOGS folder moved successfully.
C:\ProgramData\PC Optimizer Pro folder moved successfully.
Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Optimizer Pro\ not found.
C:\Program Files\PC Optimizer Pro folder moved successfully.
C:\ProgramData\SearchDonkey\Chrome folder moved successfully.
C:\ProgramData\SearchDonkey folder moved successfully.
C:\Users\Audrey\Desktop\secuity.exe moved successfully.
C:\Users\Audrey\Documents\Mobogenie folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\notice folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\download folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\connect folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\dialog folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\welcome folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\pb folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\vedio folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\ui folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\subject folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\image folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\driver folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\contact folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_ folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_ folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\page folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\test folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\views folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\bin folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\templating folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\css folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\sqldrivers folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\phonon_backend folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\log folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\imageformats folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\OldVersion folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\NewVersion folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version\CacheVersion folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Version folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\driver folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Download folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\device folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\Data folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie\backup folder moved successfully.
C:\Users\Audrey\AppData\Local\Mobogenie folder moved successfully.
C:\Program Files (x86)\BuzzSearch\bin\plugins folder moved successfully.
C:\Program Files (x86)\BuzzSearch\bin folder moved successfully.
C:\Program Files (x86)\BuzzSearch folder moved successfully.
C:\Program Files (x86)\Mobogenie folder moved successfully.
File C:\windows\tasks\PC Optimizer Pro64 startups.job not found.
C:\END moved successfully.
File C:\windows\tasks\PC Optimizer Pro64 Scan.job not found.
File C:\windows\tasks\PC Optimizer Pro Updates.job not found.
File C:\windows\tasks\PC Optimizer Pro Idle.job not found.
File C:\Users\Audrey\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Optimizer Pro.lnk not found.
File C:\Users\Public\Desktop\PC Optimizer Pro.lnk not found.
C:\Users\Audrey\AppData\Roaming\Leadertech\PowerRegister folder moved successfully.
C:\Users\Audrey\AppData\Roaming\Leadertech folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\Res folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\ffprotect\Dialogs folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\ffprotect folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\Dialogs\spsd\images folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\Dialogs\spsd folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\Dialogs\spbd\images folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\Dialogs\spbd folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\Dialogs\lib folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\Dialogs folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect\bin folder moved successfully.
C:\Users\Audrey\AppData\Roaming\SearchProtect folder moved successfully.
Folder C:\Users\Audrey\AppData\Roaming\ValueApps\ not found.
C:\Users\Audrey\AppData\Roaming\0S1F1O2Z0S2Y1H1T\ROM Manager Packages folder moved successfully.
C:\Users\Audrey\AppData\Roaming\0S1F1O2Z0S2Y1H1T folder moved successfully.
Unable to delete ADS C:\Users\Audrey\Documents\Mobogenie:Roxio EMC Stream .
========== FILES ==========
C:\Program Files (x86)\Minibar\minibar folder moved successfully.
C:\Program Files (x86)\Minibar\kango-ui\theme\bubble folder moved successfully.
C:\Program Files (x86)\Minibar\kango-ui\theme folder moved successfully.
C:\Program Files (x86)\Minibar\kango-ui folder moved successfully.
C:\Program Files (x86)\Minibar\kango folder moved successfully.
C:\Program Files (x86)\Minibar\icons folder moved successfully.
C:\Program Files (x86)\Minibar folder moved successfully.
C:\Program Files (x86)\SweetPacks folder moved successfully.
C:\Program Files (x86)\MyPC Backup\~updates folder moved successfully.
C:\Program Files (x86)\MyPC Backup\x86 folder moved successfully.
Folder move failed. C:\Program Files (x86)\MyPC Backup\x64 scheduled to be moved on reboot.
C:\Program Files (x86)\MyPC Backup\Resources\cache folder moved successfully.
C:\Program Files (x86)\MyPC Backup\Resources folder moved successfully.
C:\Program Files (x86)\MyPC Backup\log folder moved successfully.
Folder move failed. C:\Program Files (x86)\MyPC Backup\Database scheduled to be moved on reboot.
C:\Program Files (x86)\MyPC Backup\Config folder moved successfully.
Folder move failed. C:\Program Files (x86)\MyPC Backup scheduled to be moved on reboot.
File\Folder C:\Program Files (x86)\BuzzSearch not found.
File\Folder C:\ProgramData\InternetUpdater not found.
File\Folder C:\Windows\SysNative\dmwu.exe not found.
C:\Windows\SysWOW64\jmdp folder moved successfully.
< netsh advfirewall reset /c >
Ok.
C:\Users\Audrey\Downloads\cmd.bat deleted successfully.
C:\Users\Audrey\Downloads\cmd.txt deleted successfully.
< netsh advfirewall set allprofiles state on /c >
Ok.
C:\Users\Audrey\Downloads\cmd.bat deleted successfully.
C:\Users\Audrey\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Audrey
->Temp folder emptied: 376357799 bytes
->Temporary Internet Files folder emptied: 525285349 bytes
->Java cache emptied: 28404 bytes
->FireFox cache emptied: 26620642 bytes
->Google Chrome cache emptied: 7452068 bytes
->Flash cache emptied: 42829 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: kids
->Temp folder emptied: 1406344 bytes
->Temporary Internet Files folder emptied: 72080 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 2652738 bytes
->Flash cache emptied: 598 bytes

User: Public

User: wangzhisong

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 549501976 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 46335458 bytes
RecycleBin emptied: 11439793 bytes

Total Files Cleaned = 1,476.00 mb

C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 01012014_150310

Files\Folders moved on Reboot...
File move failed. C:\Windows\SysNative\tasklist.exe scheduled to be moved on reboot.
File move failed. C:\Windows\SysWOW64\tasklist.exe scheduled to be moved on reboot.
File move failed. F:\AUTORUN.INF scheduled to be moved on reboot.
File move failed. F:\RISK.EXE scheduled to be moved on reboot.
File move failed. F:\SETUP.EXE scheduled to be moved on reboot.
C:\Program Files (x86)\MyPC Backup\x64 folder moved successfully.
C:\Program Files (x86)\MyPC Backup\Database folder moved successfully.
C:\Program Files (x86)\MyPC Backup folder moved successfully.
C:\Users\Audrey\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Audrey\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
C:\windows\temp\JET4C89.tmp moved successfully.
C:\windows\temp\~ROMFN_000004CC moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP