Ok, time for cleaning …
Re-run OTL.exe.
[*]Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
:PROCESSES
KillAllProcesses
:COMMANDS
[CREATERESTOREPOINT]
:OTL
IE:64bit: - HKLM..\SearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: “URL” = http://dts.search-results.com/sr?src=ieb&appid=421&systemid=406&sr=0&q={searchTerms}
IE - HKLM..\SearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: “URL” = http://dts.search-results.com/sr?src=ieb&appid=421&systemid=406&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-716910420-3724383651-1605890227-1000..\SearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: “URL” = http://dts.search-results.com/sr?src=ieb&appid=421&systemid=406&sr=0&q={searchTerms}
FF - HKCU\Software\MozillaPlugins\bebomedia.com/OfferMosquitoIEHelper: C:\Users\Kwikzy\AppData\Local\ext_offermosquito\npOfferMosquitoIEHelper.dll File not found
O2:64bit: - BHO: (Reg Error: Value error.) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - Reg Error: Value error. File not found
O2:64bit: - BHO: (Reg Error: Value error.) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - Reg Error: Value error. File not found
O2:64bit: - BHO: (Reg Error: Value error.) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - Reg Error: Value error. File not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O3:64bit: - HKLM..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3:64bit: - HKLM..\Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
3:64bit: - HKLM..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3 - HKLM..\Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O3 - HKLM..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-716910420-3724383651-1605890227-1000..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKU\S-1-5-21-716910420-3724383651-1605890227-1000…\Run: [DataMgr] C:\Users\Kwikzy\AppData\Roaming\DataMgr\DataMgr.exe (HTTO Group, Ltd.)
O4 - HKU\S-1-5-21-716910420-3724383651-1605890227-1000…\Run: [SSync] C:\Users\Kwikzy\AppData\Roaming\SSync\SSync.exe ()
O4 - HKU\S-1-5-21-716910420-3724383651-1605890227-1000…\Run: [Intermediate] C:\Users\Kwikzy\AppData\Roaming\Intermediate\Intermediate.exe ()
O4 - HKU\S-1-5-21-716910420-3724383651-1605890227-1000…\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O33 - MountPoints2{15d435d4-3192-11e1-91d7-1803739604fa}\Shell - “” = AutoRun
O33 - MountPoints2{15d435d4-3192-11e1-91d7-1803739604fa}\Shell\AutoRun\command - “” = E:\LaunchU3.exe -a
@Alternate Data Stream - 133 bytes → C:\ProgramData\Temp:0B4227B4
:FILES
ipconfig /flushdns /c
netsh int ip reset c:\resetlog.txt /c
ipconfig /release /c
ipconfig /renew /c
C:\Users\Kwikzy\AppData\Roaming\DataMgr
C:\Users\Kwikzy\AppData\Roaming\SSync
C:\Users\Kwikzy\AppData\Roaming\Intermediate
C:\Program Files (x86)\Pando Networks
:COMMANDS
[EMPTYTEMP]
[*]Then click the Run Fix button at the top.
[*]Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
If the log doesn’t appear, it can be found here:
c:_OTL\MovedFiles\mmddyyyy_hhmmss.log
========================================
Next …
Please download zoek.zip or zoek.rar by smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive…
[*]Close any open browsers
[*] Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.
[*]Double click on zoek.exe to run the tool .
Please wait while the tool does not start…
[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:
InstalledProgs;
EmptyCLSID;
Installer-List;
Uninstall-List;
EmptyFoldersCheck;Delete
AutoClean;
[*] Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)
[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log”
========================================
Re-check …
Re-run OTL, just hit the QuickScan button and post me fresh created OTL.txt logreport.