Hello tdc2719,
Let continue...
Step 1.
OTL - Run Fix Script
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
Step 2.
Fresh OTL Scan
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
Step 3.
ESET NOD32 Online Scan
Please post each log separately to prevent it being cut off by the forum post size limiter.
Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections....
Please include in your next reply:
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed
I'm getting pretty excited my friend!!I am glad to read it, but we are not finished yet!I'm not seeing any pop ups or hyperlinks
Step 1.
OTL - Run Fix Script
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
- Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Underneath Output at the top, make sure Standard Output is selected.
- Highlight and copy the following entries: into the
text box.
(Do not include the words Code: Select all - instead of it please click the Select all button next to Code: to select the entire script.)
:Commands
[createrestorepoint]
:Files
C:\Users\Tracy\Downloads\iLividSetup-r1250-n-bf.exe
C:\Users\Tracy\Downloads\Download\iobit-uninstaller.exe
C:\Users\Tracy\Downloads\Download\iobit-uninstaller.exe.dat
C:\Users\Tracy\AppData\Local\Apple Computer\Safari\LocalStorage\https_secure.imvu.com_0.localstorage
C:\Users\Tracy\AppData\Local\Apple Computer\Safari\LocalStorage\http_www.imvu.com_0.localstorage
C:\Users\Tracy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.imvu.com_0.localstorage
C:\Users\Tracy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.imvu.com_0.localstorage-journal
C:\Users\Tracy\AppData\Local\Microsoft\Internet Explorer\DOMStore\SW2FR3YF\www.imvu[1].xml
C:\Users\Tracy\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\4L3856VO\secure.imvu[1].xml
C:\Users\Tracy\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\53ZJJVYH\www.imvu[1].xml
C:\Users\Tracy\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\ASDUXTYB\www.imvu[1].xml
C:\Users\Tracy\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\F5V9WD42\www.imvu[1].xml
C:\Users\Tracy\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\L2XQBUZ9\secure.imvu[1].xml
C:\ProgramData\IObit
C:\Users\All Users\IObit
C:\Temp\Iminent
C:\Users\Tracy\AppData\Local\Microsoft\Windows\WER\ReportArchive\Critical_IMVUClient.exe_fcd02ec2d3ea62d899abedd3a953dc6a6efc_12b5890c
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
"DllName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}]
"DllName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
"DllName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
"DllName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}]
"DllName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
"DllName"=-
[-HKEY_CURRENT_USER\Software\AppDataLow\conduit_CT2612669]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\B628E64EF4794EFAAFFBAABD1206B915]
"URL"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\B628E64EF4794EFAAFFBAABD1206B915]
"FaviconURL"=-
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\AppDataLow\conduit_CT2612669]
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\SearchScopes\B628E64EF4794EFAAFFBAABD1206B915]
"URL"=-
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\SearchScopes\B628E64EF4794EFAAFFBAABD1206B915]
"FaviconURL"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47F23182-AE7D-40C8-A32C-73BF8FFDE7FB}]
"Path"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Funmoods]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\Tracy\AppData\Local\iLivid]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\Tracy\AppData\Local\iLivid]
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\Tracy\Downloads\iLividSetup-r1250-n-bf.exe"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetup-r1250-n-bf.exe]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\Tracy\AppData\Local\iLivid]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\Tracy\AppData\Local\iLivid]
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\Tracy\Downloads\iLividSetup-r1250-n-bf.exe"=-
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\Tracy\Downloads\iLividSetup-r1250-n-bf.exe"=-
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Avast Software\WRC\RatingStorage\<|prefix|>http://10.10.0.1:9988/cgi-bin/login?msgtype=login&ssid=1&logintype=3&username=VpnNoAuthUser&password=*****&sessionid=%89%8c%83%95a%a1%97%a4%acy%bc%bb%be&ip_address=10.10.0.27&redirecturl=http://search.iminent.com/?appId=11111111]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Avast Software\WRC\RatingStorage\<|prefix|>http://search.iminent.com/?appId=11111111]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Avast Software\WRC\RatingStorage\<|prefix|>http://search.iminent.com/SearchTheWeb/v4/1033/homepage/Default.aspx]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Avast Software\WRC\RatingStorage\search.iminent.com]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\15452115_0]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\Iminent\"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375]
"00000000000000000000000000000000"=-
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Avast Software\WRC\RatingStorage\<|prefix|>http://10.10.0.1:9988/cgi-bin/login?msgtype=login&ssid=1&logintype=3&username=VpnNoAuthUser&password=*****&sessionid=%89%8c%83%95a%a1%97%a4%acy%bc%bb%be&ip_address=10.10.0.27&redirecturl=http://search.iminent.com/?appId=11111111]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Avast Software\WRC\RatingStorage\<|prefix|>http://search.iminent.com/?appId=11111111]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Avast Software\WRC\RatingStorage\<|prefix|>http://search.iminent.com/SearchTheWeb/v4/1033/homepage/Default.aspx]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Avast Software\WRC\RatingStorage\search.iminent.com]
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\15452115_0]
@=""
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\IMVU_Inc]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\IMVU_Inc_C]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\2886fdf8_0]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\304d8887_0]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\3feed500_0]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\408e2c21_0]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\6af819e8_0]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\94b2fb38_0]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\a3233f2_0]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ba3d0a1a_0]
@=""
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
"C:\Users\Tracy\AppData\Roaming\IMVUClient\IMVUClient.exe"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\IMVUClient.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
"C:\Users\Tracy\AppData\Roaming\IMVUClient\IMVUClient.exe"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IMVUClient_RASAPI32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IMVUClient_RASMANCS]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IMVU_IncAutoUpdateHelper_RASAPI32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IMVU_IncAutoUpdateHelper_RASMANCS]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IMVU_IncToolbarHelper_RASAPI32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IMVU_IncToolbarHelper_RASMANCS]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\IMVU_Inc]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2314919567-2811087668-141971273-1000\Software\IMVU_Inc_C]
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\2886fdf8_0]
@=""
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\304d8887_0]
@=""
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\3feed500_0]
@=""
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\408e2c21_0]
@=""
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\6af819e8_0]
@=""
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\94b2fb38_0]
@=""
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\a3233f2_0]
@=""
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ba3d0a1a_0]
@=""
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
"C:\Users\Tracy\AppData\Roaming\IMVUClient\IMVUClient.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467]
"00000000000000000000000000000000"=-
[-HKEY_CURRENT_USER\Software\Trolltech]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.5\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.6\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QTextCodecFactoryInterface:]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Trolltech]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.5\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.6\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QTextCodecFactoryInterface:]
[-HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\B628E64EF4794EFAAFFBAABD1206B915]
"DisplayName"=-
[HKEY_USERS\S-1-5-21-2314919567-2811087668-141971273-1000\Software\Microsoft\Internet Explorer\SearchScopes\B628E64EF4794EFAAFFBAABD1206B915]
"DisplayName"=-
:Commands
[emptytemp]
[emptyflash]
[emptyjava]
- Click under the Custom Scan/Fixes box and paste the copied text.
- Click the Run Fix button. If prompted... click OK.
- OTL may ask to reboot the machine. Please do so if asked.
- Let the program run unhindered and reboot the PC when it is done.
When the computer reboots, and you start your usual account, a Notepad text file will appear. - Copy the contents of that file and post it in your next reply. The log can also be found, based on the date/time it was created, as C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log
Step 2.
Fresh OTL Scan
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
- Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Under Output, ensure that Standard Output is selected.
- Check the boxes labeled:
- Include 64 bit scans
- Scan All Users
- Extra Registry > Use SafeList
- Click on Run Scan at the top left hand corner.
- When done, one Notepad file OTL.txt <-- Will be opened, maximized
- Please post the content of OTL.txt file ONLY in your next reply.
Step 3.
ESET NOD32 Online Scan
- Firstly please Disable any Antivirus you have active, as shown in This topic. If active, it could impact the online scan.
Do NOT use the computer while the scan is running!
Make sure all other programs and windows are closed! - You need to right-click on the Internet Explorer or Firefox icons on the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.
- Go to ESET Online Scanner - © ESET All Rights Reserved, to run an online scan.
- Click the dark blue Run ESET Online Scanner button:
- If you using Google Chrome or Mozilla Firefox you will need to download "esetsmartinstaller_enu.exe" when prompted. Then double click on it to install.
- If you using Internet Explorer please read the End User License Agreement and check the box: Yes, I accept the terms of use. Then click the green Start button.
- Accept any security warnings from your browser and allow the download/installation of any required files.
If your browser blocks or halts a download, please allow it to download any required files. - Under scan settings:
- Check "Scan archives"
- UNCHECK "Remove found threats"
- Click Advanced settings and select the following:
- Scan potentially unwanted applications
- Scan for potentially unsafe applications
- Enable Anti-Stealth technology
- Click the Start button.
ESET will install itself, download virus signature database updates and begin scanning your computer.
The scan will take a while so please be patient. Do NOT use the computer while the scan is running! - When the scan completes, please press the text:

- Press the text:
, then save the file to your desktop as ESETScan.txt. - Press the Back button, then press the Finish button.
- Copy and paste the contents of ESETScan.txt in your next reply.
Note: If no threats are found, there is no option to create a log. Just report back to me there was nothing found.
Please post each log separately to prevent it being cut off by the forum post size limiter.
Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections....
Please include in your next reply:
- Do you have any problems executing the instructions?
- Contents of the C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log log file after OTL FixScript run
- Contents of a OTL.txt log file after fresh OTL scan
- Contents of the ESETScan.txt log file
- Do you see any changes in computer behavior?
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed
.
