
Ran OTM and Systemlook, logs follow:
*** OTM
All processes killed
========== FILES ==========
C:\FRST\Quarantine folder moved successfully.
C:\FRST\Logs folder moved successfully.
C:\FRST\Hives folder moved successfully.
C:\FRST folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56468 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Don
->Temp folder emptied: 2306949 bytes
->Temporary Internet Files folder emptied: 192673907 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 1451 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5505 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 84793 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 186.00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYJAVA]
User: All Users
User: Default
User: Default User
User: Don
->Java cache emptied: 0 bytes
User: Public
Total Java Files Cleaned = 0.00 mb
OTM by OldTimer - Version 3.1.21.0 log created on 03192013_184422
Files moved on Reboot...
C:\Users\Don\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot...
*** SystemLook
SystemLook 30.07.11 by jpshortstuff
Log created at 18:53 on 19/03/2013 by Don
Administrator - Elevation successful
========== regfind ==========
Searching for ""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\3XEfile\shell\open\command]
@=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\batfile\shell\open\command]
@=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\batfile\shell\runas\command]
@="%SystemRoot%\System32\cmd.exe /C "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cmdfile\shell\open\command]
@=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cmdfile\shell\runas\command]
@="%SystemRoot%\System32\cmd.exe /C "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\comfile\shell\open\command]
@=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
@=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
"IsolatedCommand"=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\runas\command]
@=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\runas\command]
"IsolatedCommand"=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htafile\Shell\Open\Command]
@="C:\Windows\SysWOW64\mshta.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\jarfile\shell\open\command]
@=""C:\Program Files (x86)\Java\jre6\bin\javaw.exe" -jar "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSEFile\Shell\Open\Command]
@="C:\Windows\System32\WScript.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSEFile\Shell\Open2\Command]
@="C:\Windows\System32\CScript.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSFile\Shell\Open\Command]
@="%SystemRoot%\System32\WScript.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSFile\Shell\Open2\Command]
@="C:\Windows\System32\CScript.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mscfile\shell\Author\command]
@="%SystemRoot%\system32\mmc.exe /a "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mscfile\shell\open\command]
@="%SystemRoot%\system32\mmc.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mscfile\shell\RunAs\command]
@="%SystemRoot%\system32\mmc.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Msi.Package\shell\Open\command]
@=""%SystemRoot%\System32\msiexec.exe" /i "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Msi.Package\shell\Repair\command]
@=""%SystemRoot%\System32\msiexec.exe" /f "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Msi.Package\shell\Uninstall\command]
@=""%SystemRoot%\System32\msiexec.exe" /x "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Msi.Patch\shell\Open\command]
@=""%SystemRoot%\System32\msiexec.exe" /p "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\piffile\shell\open\command]
@=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBEFile\Shell\Open\Command]
@="%SystemRoot%\System32\WScript.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBEFile\Shell\Open2\Command]
@=""%SystemRoot%\System32\CScript.exe" "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\Shell\Open\Command]
@="%SystemRoot%\System32\WScript.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\Shell\Open2\Command]
@=""%SystemRoot%\System32\CScript.exe" "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Windows.XamlDocument\shell\open\command]
@=""C:\Windows\System32\PresentationHost.exe" "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Windows.Xbap\shell\open\command]
@=""C:\Windows\System32\PresentationHost.exe" "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Windows.XPSReachViewer\shell\open\command]
@="%SystemRoot%\System32\xpsrchvw.exe "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WSFFile\Shell\Open\Command]
@=""%SystemRoot%\System32\WScript.exe" "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WSFFile\Shell\Open2\Command]
@=""%SystemRoot%\System32\CScript.exe" "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WSHFile\Shell\Open\Command]
@=""%SystemRoot%\System32\WScript.exe" "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WSHFile\Shell\Open2\Command]
@=""%SystemRoot%\System32\CScript.exe" "%1" %*"
-= EOF =-