Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.
[Unregister Dlls]
[Processes - Safe List]
YY -> svchost.exe -> C:\Windows\update.1\svchost.exe
[Registry - Safe List]
< FireFox Extensions [Program Folders] > ->
YY -> ClickPotatoLite Component -> C:\PROGRAM FILES (X86)\CLICKPOTATOLITE\BIN\10.0.668.0\FIREFOX\EXTENSIONS
YY -> cacaoweb -> C:\USERS\HUGENE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D6H71Q8R.DEFAULT\EXTENSIONS\CACAOWEB@CACAOWEB.ORG
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {258C9770-1713-4021-8D7E-1F184A2BD754} [HKLM] -> [ShoppingReport2]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-2517038744-3281405084-810221206-1000\] > -> HKEY_USERS\S-1-5-21-2517038744-3281405084-810221206-1000\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "tray_ico" -> []
YY -> "tray_ico0" -> C:\Windows\update.tray-7-0\svchost.exe [C:\Windows\update.tray-7-0\svchost.exe]
YN -> "tray_ico1" -> []
YN -> "tray_ico2" -> []
YN -> "tray_ico3" -> []
YN -> "tray_ico4" -> []
YY -> "wxpdrv" -> C:\Windows\services32.exe [C:\Windows\services32.exe]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
YN -> {B58926D6-CFB0-45d2-9C28-4B5A0F0368AE}:{7A3D6D17-9DD5-4C60-8076-D1784DABAF8C} [HKLM] -> [Button: ClickPotato]
YN -> {DB38E21A-0133-419d-92AD-ECDFD5244D6D}:{3E2DFD6A-4E20-4d4c-AA8B-E1F9DBEF3C80} [HKLM] -> [Button: ShopperReports - Compare product prices]
YN -> {EB620C54-E229-4942-87CE-E717109FC8C6}:{714E0876-FCEE-49ce-A429-B9AD8AEFCB56} [HKLM] -> [Button: ShopperReports - Compare travel rates]
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
YN -> "AlternateShell" -> services32.exe
[Files/Folders - Created Within 30 Days]
NY -> av_ico -> C:\Windows\av_ico
NY -> update.tray-7-0-lnk -> C:\Windows\update.tray-7-0-lnk
NY -> update.tray-7-0 -> C:\Windows\update.tray-7-0
NY -> {E68DEF08-A0C1-4393-8FF0-64CC9424759A} -> C:\Users\Hugene\AppData\Local\{E68DEF08-A0C1-4393-8FF0-64CC9424759A}
NY -> {806FFDF5-BA2E-4CA3-A03B-8EB3FCAFE7FD} -> C:\Users\Hugene\AppData\Local\{806FFDF5-BA2E-4CA3-A03B-8EB3FCAFE7FD}
NY -> {BCEDF458-9CC8-4072-A84D-067A23974127} -> C:\Users\Hugene\AppData\Local\{BCEDF458-9CC8-4072-A84D-067A23974127}
NY -> {CEC449F1-C6A0-4583-B3C1-67A5B7B850BB} -> C:\Users\Hugene\AppData\Local\{CEC449F1-C6A0-4583-B3C1-67A5B7B850BB}
NY -> {500D8C58-5C38-4D19-8464-5C44C6AFC17D} -> C:\Users\Hugene\AppData\Local\{500D8C58-5C38-4D19-8464-5C44C6AFC17D}
NY -> {CD2A02D4-1CBA-4956-BEF8-E4E7367D2C50} -> C:\Users\Hugene\AppData\Local\{CD2A02D4-1CBA-4956-BEF8-E4E7367D2C50}
NY -> {9936B6F3-F771-4521-9D72-DEC6A2A461FC} -> C:\Users\Hugene\AppData\Local\{9936B6F3-F771-4521-9D72-DEC6A2A461FC}
NY -> {64D67BCE-0166-48F0-AD74-3E34CD011788} -> C:\Users\Hugene\AppData\Local\{64D67BCE-0166-48F0-AD74-3E34CD011788}
NY -> {A39F8A9F-96EC-4181-AF4B-B06838F8AF54} -> C:\Users\Hugene\AppData\Local\{A39F8A9F-96EC-4181-AF4B-B06838F8AF54}
NY -> {3038FE97-FEC0-4384-AE3F-FA640327C8A5} -> C:\Users\Hugene\AppData\Local\{3038FE97-FEC0-4384-AE3F-FA640327C8A5}
NY -> {8BDB0D15-4CB3-4DFB-9CD6-032AA25EED74} -> C:\Users\Hugene\AppData\Local\{8BDB0D15-4CB3-4DFB-9CD6-032AA25EED74}
NY -> {905689B7-4ABA-4479-9BF8-A2B36C2CE948} -> C:\Users\Hugene\AppData\Local\{905689B7-4ABA-4479-9BF8-A2B36C2CE948}
NY -> {28273214-0979-4530-8DD5-DFFC51386563} -> C:\Users\Hugene\AppData\Local\{28273214-0979-4530-8DD5-DFFC51386563}
NY -> {3AB9CA84-F75E-4E06-ABC9-25E3986F0B49} -> C:\Users\Hugene\AppData\Local\{3AB9CA84-F75E-4E06-ABC9-25E3986F0B49}
NY -> {17DDCF70-2822-4A5B-B81F-EF094A859584} -> C:\Users\Hugene\AppData\Local\{17DDCF70-2822-4A5B-B81F-EF094A859584}
NY -> {6E12370D-9DA1-4316-95E5-2764BC0AD20B} -> C:\Users\Hugene\AppData\Local\{6E12370D-9DA1-4316-95E5-2764BC0AD20B}
NY -> {FF1ECC46-B1A9-4B9A-824F-97998B3BF400} -> C:\Users\Hugene\AppData\Local\{FF1ECC46-B1A9-4B9A-824F-97998B3BF400}
[Files/Folders - Modified Within 30 Days]
NY -> cacaoweb.exe -> C:\Users\Hugene\Desktop\cacaoweb.exe
[Files - No Company Name]
NY -> services32.exe -> C:\Windows\services32.exe
[File - Lop Check]
NY -> cacaoweb -> C:\Users\Hugene\AppData\Roaming\cacaoweb
NY -> ClickPotatoLite -> C:\Users\Hugene\AppData\Roaming\ClickPotatoLite
[Custom Scans]
YY -> svchost.exe : MD5=7A3BC4D258CBE30DFB0649EE863FAE25 -> C:\Windows\update.1\svchost.exe
YY -> svchost.exe : MD5=7A3BC4D258CBE30DFB0649EE863FAE25 -> C:\Windows\update.tray-7-0\svchost.exe
YY -> svchost.exe : MD5=7A3BC4D258CBE30DFB0649EE863FAE25 -> C:\Windows\update.tray-7-0-lnk\svchost.exe
[Custom Items]
:Files
ipconfig /flushdns /c
:end
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here
I will review the information when it comes back in.
Depending on what the fix contains, this process may take some time and your desktop icons might disappear or other uncommon behavior may occur.
This is no sign of malfunction, do not panic!