I reviewed the logs and OTL shows signs of crapware as well as the posible presence of malware …etc. There is a possibility that you have active malware that hides from the our primary tool as OTL does looks suspicious.
First …
Re-run OTL.exe.
[*]Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
IE - HKU\S-1-5-21-2628011366-3451951904-1772102454-1009\..\SearchScopes\{B930BB79-8B60-4936-BD43-3F098FE4F2AA}: "URL" = http://search.peoplepc.com/search?area=earthlink-peoplepc-wssynd&channel=eas&q={searchTerms}
FF - prefs.js..browser.startup.homepage: "https://startpage.com/"
FF - prefs.js..keyword.URL: "https://startpage.com/do/search?language=english&cat=web&query="
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.mypeoplepc.com/
CHR - Extension: No name found = C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\
CHR - Extension: No name found = C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\onomgjhiigbnmhkghhpgdojopdlhddbe\2_0\
O4 - Startup: C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O33 - MountPoints2\{1fa0fb66-d76e-11e1-a007-8d9e58ecab1d}\Shell - "" = AutoRun
O33 - MountPoints2\{1fa0fb66-d76e-11e1-a007-8d9e58ecab1d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1fa0fb66-d76e-11e1-a007-8d9e58ecab1d}\Shell\AutoRun\command - "" = K:\VZAccess_Manager.exe /z detect
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C07A6A6B
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D0467BDF
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:53384F1D
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1DD8718C
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:774C075A
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ABFEED8E
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\tkgohcc9.default\searchplugins\dogpile.xml
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\tkgohcc9.default\searchplugins\ixquick-https.xml
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\tkgohcc9.default\searchplugins\startpage-https.xml
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\onomgjhiigbnmhkghhpgdojopdlhddbe
C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\PowerReg Scheduler.exe
ipconfig /flushdns /c
autorun.inf /alldrives
autorun.exe /alldrives
AUTOEXEC.BAT /alldrives
[*]Then click the Run Fix button at the top.
[*]Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
If the log doesn’t appear, it can be found here:
Then the big guy…
Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.
Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this or this Instruction.
How to disable avast:
[*]Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
[*]In the window that opens on the top right corner, click Settings.
[*]In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.
[*]Right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
[*]In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.
Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
Click Yes to allow ComboFix to continue.
If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix’s window while it is running.
If you see a message like “Illegal operation attempted on a registry key that has been marked for deletion” just restart computer once more.
When the tool is finished, it will produce a log report for you. (typical location: C:[b]ComboFix.txt[/b] )
Attach log reports ( ComboFix.txt) back to topic.