Hello gorf,
Very good results
but we are not finished yet...
Step 1.
OTL - Run Fix Script
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
Step 2.
ESET online scannner
Note: You can use either Internet Explorer or Mozilla FireFox for this scan.
Step 3.
Fresh OTL Scan
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
Step 4.
SystemLook
You should still have SystemLook.exe on your desktop.
Please include in your next reply:
Please do not hesitate to divide the post into multiple if it is too long...
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed
Very good results
Step 1.
OTL - Run Fix Script
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
- Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Underneath Output at the top, make sure Standard Output is selected.
- Copy and Paste the following code into the
text box. Do not include the word Code
:Files
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_bar.utorrent.com_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toolbar.utorrent.com_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toolbar.utorrent.com_0.localstorage-journal
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_utorrent.cz_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_utorrent.cz_0.localstorage-journal
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.utorrent.com_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.utorrent.com_0.localstorage-journal
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.utorrent.cz_0.localstorage
C:\Users\Libecek\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\PJGYPJ5I\bar.utorrent[1].xml
C:\Users\Libecek\AppData\Roaming\Microsoft\Windows\Recent\utorrent-setup (1).lnk
C:\Users\Libecek\AppData\Roaming\Microsoft\Windows\Recent\utorrent-setup.lnk
C:\Users\Libecek\Downloads\utorrent-setup.zip
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Battlefield 3™.lnk
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Battlefield 3
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\Battlefield 3™.lnk
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_battlelog.battlefield.com_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_battlelog.battlefield.com_0.localstorage-journal
C:\Users\Public\Desktop\Battlefield 3.lnk
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_battlelog.battlefield.com_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_battlelog.battlefield.com_0.localstorage-journal
C:\Users\Libecek\Downloads\battlelog-web-plugins-1.132.0-retail-prod.exe
C:\Program Files\Steam\steamapps\common\arma 2 operation arrowhead\Expansion\beta\setup_battleyearma2oa.exe
C:\Program Files\Steam\steamapps\common\arma 2 operation arrowhead\Expansion\beta\setup_battleyearma2rft.exe
C:\Program Files\Steam\steamapps\common\arma 2 operation arrowhead\Expansion\beta\.rsync\.pack\setup_battleyearma2oa.exe.gz
C:\Program Files\Steam\steamapps\common\arma 2 operation arrowhead\Expansion\beta\.rsync\.pack\setup_battleyearma2rft.exe.gz
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_apps.conduit.com_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage-journal
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_youtube.conduitapps.com_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_youtube.conduitapps.com_0.localstorage-journal
C:\Users\Libecek\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_1463702_1459356_CZ.xml
C:\Users\Libecek\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\FGSE5H6Z\youtube.conduitapps[1].xml
C:\Users\Libecek\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\NS24HMH5\facebook.conduitapps[1].xml
C:\Users\Libecek\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\chrome\CT3220468\content\ConduitAbstractionLayer.js
C:\Users\Libecek\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\chrome\CT3220468\content\tb\al\aboutBox\images\conduit-logo-OLD.png
C:\Users\Libecek\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\chrome\CT3220468\content\tb\al\aboutBox\images\conduit-logo.png
C:\Users\Libecek\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\chrome\CT3220468\skin\conduitToolBarStyle.css
C:\Users\Libecek\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\lib\log4conduit.jsm
C:\Windows\System32\Tasks\GadgetBox UpdaterUpdaterTask{15CEFCF4-3899-406F-89C8-6FF0534A62C1}
C:\Windows\Tasks\GadgetBox UpdaterUpdaterTask{15CEFCF4-3899-406F-89C8-6FF0534A62C1}.job
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.gboxapp.com_0.localstorage
C:\Users\Libecek\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.gboxapp.com_0.localstorage-journal
C:\Users\Libecek\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppHang_utorrent.exe_2e199c6b83d0beef206c8626cd88643d7c54d724_12d5b6a3
C:\Users\Libecek\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppHang_utorrent.exe_2e199c6b83d0beef206c8626cd88643d7c54d724_14ca4537
C:\Program Files\Common Files\EAInstaller\Battlefield 3
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
C:\ProgramData\Origin\LocalContent\Battlefield 3
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Battlefield 3
C:\Users\All Users\Origin\LocalContent\Battlefield 3
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive\ArmA 2\BattlEye
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive\Arma 2 Operation Arrowhead\BattlEye
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive\ArmA 2\BattlEye
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive\Arma 2 Operation Arrowhead\BattlEye
C:\Users\Libecek\AppData\Local\ArmA 2 OA\BattlEye
C:\Program Files\Conduit
C:\Users\Libecek\AppData\Local\Conduit
C:\Users\Libecek\AppData\LocalLow\Conduit
C:\Program Files\Windows Sidebar\Shared Gadgets\gadgetbox.gadget
C:\Users\Libecek\AppData\LocalLow\Incredibar.com
C:\Users\Libecek\AppData\LocalLow\Incredibar.com\incredibar
C:\Users\Libecek\AppData\Local\PunkBuster
C:\Windows\System32\LogFiles\PunkBuster
:Reg
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\utorrent.com]
[HKEY_CURRENT_USER\Software\WinRAR\ArcHistory]
"1"=-
[-HKEY_CURRENT_USER\Software\Classes\Applications\uTorrent.exe]
[HKEY_CURRENT_USER\Software\Classes\btdna\DefaultIcon]
@=-
[HKEY_CURRENT_USER\Software\Classes\btdna\shell\open\command]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Conduit\AppPaths\client]
"AppPath"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\utorrent_RASAPI32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\utorrent_RASMANCS]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\utorrent.com]
[HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\WinRAR\ArcHistory]
"1"=-
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Classes\Applications\uTorrent.exe]
[HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Classes\btdna\DefaultIcon]
@=-
[HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Classes\btdna\shell\open\command]
@=-
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001_Classes\Applications\uTorrent.exe]
[HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001_Classes\btdna\DefaultIcon]
@=-
[HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001_Classes\btdna\shell\open\command]
@=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\9ad7d59e_0]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{F92227AA-6DFB-482D-A820-74FB991FBBDF}]
"ConfigApplicationPath"=-
"ConfigGDFBinaryPath"=-
"AppExePath"=-
"Title"=-
"Description"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{64BFBE7A-886C-4CA2-A9B4-0C2B5A5942BC}]
"DisplayName"=-
"DisplayIcon"=-
"UninstallString"=-
"InstallLocation"=-
"HelpLink"=-
"Readme"=-
[HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\9ad7d59e_0]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AEFE841-DCA1-4A95-80CB-BE935D018400}\InprocServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AEFE841-DCA1-4A95-80CB-BE935D018400}\ToolboxBitmap32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D65F2511-B60B-4AA3-8563-E8DFD1303132}\InprocServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{33616ACD-BF93-4F0E-97EB-A2A8D3018400}\1.0\0\win32]
@=-
[-HKEY_CURRENT_USER\Software\Conduit]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Conduit]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Conduit]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CCA8F2AB-BE4E-41F0-A289-4D960CEA58EA}\1.0\0\win32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CCA8F2AB-BE4E-41F0-A289-4D960CEA58EA}\1.0\HELPDIR]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4D2CEBF-BBC4-4C63-96B8-D7ADBABC1A2B}]
"Path"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GadgetBox UpdaterUpdaterTask{15CEFCF4-3899-406F-89C8-6FF0534A62C1}]
[-HKEY_CURRENT_USER\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Incredibar.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Incredibar.com]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Incredibar.com\incredibar]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Incredibar.com\incredibar\Instl]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001_Classes\VirtualStore\MACHINE\SOFTWARE\Incredibar.com]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001_Classes\VirtualStore\MACHINE\SOFTWARE\Incredibar.com\incredibar]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001_Classes\VirtualStore\MACHINE\SOFTWARE\Incredibar.com\incredibar\Instl]
[-HKEY_CURRENT_USER\Software\Trolltech]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QTextCodecFactoryInterface:]
[-HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Trolltech]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QTextCodecFactoryInterface:]
[-HKEY_USERS\S-1-5-21-618347355-2767662451-920019664-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:]
:Commands
[EMPTYTEMP]
[CREATERESTOREPOINT]
- Click under the Custom Scan/Fixes box and paste the copied text.
- Click the Run Fix button. If prompted... click OK.
- OTL may ask to reboot the machine. Please do so if asked.
- Let the program run unhindered and reboot the PC when it is done.
When the computer reboots, and you start your usual account, a Notepad text file will appear. - Copy the contents of that file and post it in your next reply. The log can also be found, based on the date/time it was created, as C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log
Step 2.
ESET online scannner
Note: You can use either Internet Explorer or Mozilla FireFox for this scan.
- Firstly please Disable any Antivirus you have active, as shown in This topic.
- Note: Don't forget to re-enable it after the scan.
- Next please click on the following link to open a new window to ESET online scannner
- Then click on:

Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox. - Select the option YES, I accept the Terms of Use then click on:

- When prompted allow the Add-On/Active X to install.
- Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
- Now click on Advanced Settings and select the following:
- Scan for potentially unwanted applications
- Scan for potentially unsafe applications
- Enable Anti-Stealth Technology
- Now click on:

- The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
- When completed the Online Scan will begin automatically.
- Do not touch either the mouse or keyboard during the scan otherwise it may stall.
- When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
- Now click on:

- Use notepad to open the log file located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
- Copy and paste that log as a reply to this topic.
Step 3.
Fresh OTL Scan
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
- Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Under Output, ensure that Standard Output is selected.
- Check the boxes labeled:
- Scan All Users
- Extra Registry > Use SafeList
- Click on Run Scan at the top left hand corner.
- When done, one Notepad file OTL.txt <-- Will be opened, maximized
- Please post the content of OTL.txt file in your next reply.
Step 4.
SystemLook
You should still have SystemLook.exe on your desktop.
- Right click on SystemLook.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
If you receive an "Open file - security warning"... asking "Do you want to run this file?", press the Run button. - Highlight and copy the following entries into SystemLook's main text entry window:
:filefind
*uTorrent*
*Battlefield*
*Battlelog*
*BattlEye*
*Conduit*
*GadgetBox*
*gboxapp*
:folderfind
*uTorrent*
*Battlefield*
*BattlEye*
*Conduit*
*GadgetBox*
*Incredibar*
*PunkBuster*
:Regfind
uTorrent
Battlefield
Battlelog
Conduit
GadgetBox
Incredibar
trolltech
- Press the Look button to start the scan.
When finished, a Notepad window will open with the results of the scan.
A file will be created (on your Desktop) with the results of the scan, named SystemLook.txt - Please post the contents of the SystemLook.txt file in your next reply.
Please include in your next reply:
- Do you have any problems executing the instructions?
- Contents of the C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log log file after OTL FixScript run
- Contents of the C:\Program Files\ESET\EsetOnlineScanner\log.txt log file
- Contents of the most recent OTL.txt file after fresh OTL scan
- Contents of the SystemLook.txt log file
- Do you see any changes in computer behavior?
Please do not hesitate to divide the post into multiple if it is too long...
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed


.