This thread's last reply is from June 11, 2013, 8:32 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
mylittlepony
Hi deltalima
Computer seems to be running ok and I am about to run the OTL Script. When I have done that and posted the output can I install my new version of MS Office?
deltalima
Please wait until I give the "all clear" before installing anything.
mylittlepony
Hi deltalima
The computer seems to be running ok so can I install my new version of MS Office? The log from OTL is below
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== PROCESSES ==========
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BCF61B68-08FF-4B36-936E-B8AD31622187}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BCF61B68-08FF-4B36-936E-B8AD31622187}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_USERS\S-1-5-21-3528189516-2229878515-3528017422-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3528189516-2229878515-3528017422-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}\ not found.
Registry key HKEY_USERS\S-1-5-21-3528189516-2229878515-3528017422-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BCF61B68-08FF-4B36-936E-B8AD31622187}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BCF61B68-08FF-4B36-936E-B8AD31622187}\ not found.
Prefs.js: "Search Results" removed from browser.search.defaultenginename
Prefs.js: "Search Results" removed from browser.search.order.1
Prefs.js: "http://dts.search-results.com/sr?src=ffb&appid=1083&systemid=1&sr=0&q=" removed from keyword.URL
C:\Users\User_1\AppData\Roaming\Mozilla\Firefox\Profiles\l98v6n8k.default\extensions\{28387537-e3f9-4ed7-860c-11e69af4a8a0} folder moved successfully.
C:\Users\User_1\AppData\Roaming\Mozilla\Firefox\Profiles\l98v6n8k.default\extensions\{3697b17c-b572-4862-a5e6-7f922c0f3403}\defaults\preferences folder moved successfully.
C:\Users\User_1\AppData\Roaming\Mozilla\Firefox\Profiles\l98v6n8k.default\extensions\{3697b17c-b572-4862-a5e6-7f922c0f3403}\defaults folder moved successfully.
C:\Users\User_1\AppData\Roaming\Mozilla\Firefox\Profiles\l98v6n8k.default\extensions\{3697b17c-b572-4862-a5e6-7f922c0f3403}\chrome\content folder moved successfully.
C:\Users\User_1\AppData\Roaming\Mozilla\Firefox\Profiles\l98v6n8k.default\extensions\{3697b17c-b572-4862-a5e6-7f922c0f3403}\chrome folder moved successfully.
C:\Users\User_1\AppData\Roaming\Mozilla\Firefox\Profiles\l98v6n8k.default\extensions\{3697b17c-b572-4862-a5e6-7f922c0f3403} folder moved successfully.
C:\Users\User_1\AppData\Roaming\Mozilla\Firefox\Profiles\l98v6n8k.default\extensions\[removed] folder moved successfully.
C:\Users\User_1\AppData\Roaming\Mozilla\Firefox\Profiles\l98v6n8k.default\searchplugins\Search_Results.xml moved successfully.
File C:\Program Files\Mozilla Firefox 3.6 Beta 4\plugins\npvsharetvplg.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\!{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{28387537-e3f9-4ed7-860c-11e69af4a8a0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28387537-e3f9-4ed7-860c-11e69af4a8a0}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_USERS\S-1-5-21-3528189516-2229878515-3528017422-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Data Array
User: Default
->Temp folder emptied: 3632168 bytes
->Temporary Internet Files folder emptied: 200057860 bytes
->Java cache emptied: 256871 bytes
->FireFox cache emptied: 58305926 bytes
->Google Chrome cache emptied: 131458927 bytes
->Flash cache emptied: 501 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Prism Setup Folder
User: Public
User: User_1
->Temp folder emptied: 8096861 bytes
->Temporary Internet Files folder emptied: 44459657 bytes
->Java cache emptied: 256871 bytes
->FireFox cache emptied: 107838613 bytes
->Google Chrome cache emptied: 266834708 bytes
->Flash cache emptied: 9856567 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1073646 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 4137779240 bytes
Total Files Cleaned = 4,740.00 mb
[EMPTYFLASH]
User: All Users
User: Data Array
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: Prism Setup Folder
User: Public
User: User_1
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0.00 mb
[EMPTYJAVA]
User: All Users
User: Data Array
User: Default
->Java cache emptied: 0 bytes
User: Default User
->Java cache emptied: 0 bytes
User: Prism Setup Folder
User: Public
User: User_1
->Java cache emptied: 0 bytes
Total Java Files Cleaned = 0.00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.69.0 log created on 06112013_203957
Files\Folders moved on Reboot...
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\User_1\AppData\Local\Trusteer\Rapport\user\logs\gp_iexplore.5176.log moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\User_1\AppData\Local\Trusteer\Rapport\user\logs\koan.5176.log moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\User_1\AppData\Local\Trusteer\Rapport\user\logs\koanlight.5176.log moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S6L7WAZ8\ads[2].htm moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RI1XAJM1\DroidSans[1].woff moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RI1XAJM1\frame[2].htm moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RI1XAJM1\viewtopic[1].htm moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\J1PCBJR2\zrt_lookup[1].htm moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
C:\Users\User_1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\SuggestedSites.dat moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
mylittlepony
Sorry didn't see your post. Will wait to hear from you before installing anything.
mylittlepony
Hi deltalima
Many thanks for your help and for the forum which is a very valuable resource.
deltalima
As your problems appear to have been resolved,