========== OTL ========== Registry value HKEY_USERS\S-1-5-21-4292775695-2403161838-718631559-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found. Registry value HKEY_USERS\S-1-5-21-4292775695-2403161838-718631559-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Oqjajo deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:aswBoot.exe /A:"*" /L:"1045" /KBD:2 /wow /dir:"C:\Program Files\AVAST Software\Avast" deleted successfully. C:\Windows\SysWOW64\aswBoot.exe moved successfully. File C:\Users\Public\Desktop\avast! Free Antivirus.lnk not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus folder moved successfully. C:\Windows\SysNative\drivers\aswSP.sys moved successfully. C:\Windows\SysNative\drivers\aswFsBlk.sys moved successfully. C:\Windows\SysNative\drivers\aswRdr.sys moved successfully. C:\Windows\SysNative\drivers\aswTdi.sys moved successfully. C:\Windows\SysNative\drivers\aswSnx.sys moved successfully. C:\Windows\SysNative\drivers\aswMonFlt.sys moved successfully. File C:\Windows\SysWow64\aswBoot.exe not found. C:\Windows\avastSS.scr moved successfully. C:\Windows\SysWOW64\drivers\avgntdd.sys moved successfully. C:\Windows\SysWOW64\drivers\avgntmgr.sys moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\AntiVir Desktop folder moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira folder moved successfully. C:\Windows\SysNative\drivers\avipbb.sys moved successfully. C:\Windows\SysNative\drivers\avgntflt.sys moved successfully. Error: Unable to stop service ShldFlt! Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShldFlt deleted successfully. File move failed. C:\Windows\SysNative\drivers\ShldFlt.sys scheduled to be moved on reboot. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\\"AlternateShell"|"cmd.exe" /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\\wrc@avast.com deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}\ not found. OTL by OldTimer - Version 3.2.26.1 log created on 07262011_150740 Files\Folders moved on Reboot... C:\Windows\SysNative\drivers\ShldFlt.sys moved successfully. Registry entries deleted on Reboot...