    Hello again Ken and thanks for perservering.

    My default search engine is still Google - that was the first thing I checked, but when I search from the address bar it goes straight to

    I don't have firefox...

    Thanks again

    Lets see if we can find this nuisance

    Download and Run SystemLook

    You need to download from the first link which is 64 bit compatible with your system

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
    Okey doke, here goes (and I've realised how to save to the Desktop, yay!)

    SystemLook 04.09.10 by jpshortstuff
    Log created at 16:23 on 16/07/2011 by Stupid Pooter
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "gala"
    No files found.

    ========== folderfind ==========

    Searching for "gala"
    No folders found.

    ========== regfind ==========

    Searching for "gala"
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8772ABAB-6CD0-4460-8DEE-68EFC4535469}]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\]
    [HKEY_USERS\S-1-5-21-3658000817-3345655794-736020671-1000\Software\Microsoft\Internet Explorer\SearchScopes\{8772ABAB-6CD0-4460-8DEE-68EFC4535469}]
    [HKEY_USERS\S-1-5-21-3658000817-3345655794-736020671-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\]

    -= EOF =-

    Make sure you back up your registry IMPORTANT

    Backup Your Registry with ERUNT:
    • Download to your Desktop from here:
    • Right-click, select Extract All... and follow the prompts to extract ERUNT to a new folder on your Desktop
    • Inside the new folder, double-click ERUNT.exe to start the program
    • OK all the prompts to back up your registry to the default location.
    Note: to restore your registry, go to the backup folder and start ERDNT.exe

    Open OTL.exe
    • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

      [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8772ABAB-6CD0-4460-8DEE-68EFC4535469}]
      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History]
      [-HKEY_USERS\S-1-5-21-3658000817-3345655794-736020671-1000\Software\Microsoft\Internet Explorer\SearchScopes\{8772ABAB-6CD0-4460-8DEE-68EFC4535469}]
      [HKEY_USERS\S-1-5-21-3658000817-3345655794-736020671-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History]
      [start explorer]
    • Then click the Run Fix button at the top. <--Not run Scan
    • Let the program run unhindered, reboot when it is done
    • Then post the results of the log it produces.
    • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

    Post the log from the OTL fix and then run System Look again and post the new log
    After reboot and upon starting IE, a window came up saying a program has corrupted my default search and it's now been reset to AOL...

    All processes killed
    ========== PROCESSES ==========
    ========== OTL ==========
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8772ABAB-6CD0-4460-8DEE-68EFC4535469}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8772ABAB-6CD0-4460-8DEE-68EFC4535469}\ not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\19E3FA281E754574480D044AE64297BA\Features not found.
    Registry key HKEY_USERS\S-1-5-21-3658000817-3345655794-736020671-1000\Software\Microsoft\Internet Explorer\SearchScopes\{8772ABAB-6CD0-4460-8DEE-68EFC4535469}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8772ABAB-6CD0-4460-8DEE-68EFC4535469}\ not found.
    Registry value HKEY_USERS\S-1-5-21-3658000817-3345655794-736020671-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\\ not found.
    ========== FILES ==========
    ========== COMMANDS ==========
    C:\Windows\System32\drivers\etc\Hosts moved successfully.
    HOSTS file reset successfully


    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public

    User: Stupid Pooter
    ->Temp folder emptied: 3235091 bytes
    ->Temporary Internet Files folder emptied: 267034450 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 21536 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1914 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
    RecycleBin emptied: 280 bytes

    Total Files Cleaned = 258.00 mb

    OTL by OldTimer - Version log created on 07172011_103202

    Files\Folders moved on Reboot...
    C:\Users\Stupid Pooter\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Stupid Pooter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RWV0DS8S\newreply[1].htm moved successfully.
    C:\Users\Stupid Pooter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Stupid Pooter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

    Registry entries deleted on Reboot...

    Redirects still ?
    Nope, it's working a treat now - thank you! I just need to work out how to select Google as my default search provider.

    Any idea what this problem was and how I came by it in bthe first place? Just so I know what to avoid...

    Many thanks again


    Open IE and go to Tools > Manage Add Ons > Search Providers and make Google your default, if Google is not listed than on the bottom there is a option to search for more providers, you can do that an find Google and make it your default.

    Let me know how it went ?
    Thanks Ken - I was half-joking about resetting Google as my default search as in theory I *do* know how to do it - but for some obscure reason Google does NOT come up as one of the options. Don't worry about it, it's not important.

    Thanks very much for all your help with the REAL issue, much appreciated.

    Take care


  10. #20
    Hello Kate,

    Under manage search providers you need it to go out an look for Google.

    Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups

    Malwarebytes is the free version and yours to keep and will not be removed

    Keeping your Java updated is very important to the security of your system, info here on how to update

    Safe Surfn
