Problem with OptimumInstaller

Optimum Installer was found and in an attempt to remove it it caused a BSOD and a Reboot to Safe Mode

I am now back in Normal mode, but I have not found the problem yet


DDS (Ver_2012-11-20.01) - NTFS_x86

Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2

Run by John at 13:47:56 on 2012-12-17

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3062.1687 [GMT 11:00]


AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}

SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


============== Running Processes ================




c:\Program Files\Microsoft Security Client\MsMpEng.exe




C:\Program Files\SUPERAntiSpyware\SASCORE.EXE

C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files\LSI SoftModem\agrsmsvc.exe

C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe



C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe


c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe

C:\Program Files\Secunia\PSI\PSIA.exe



c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe

c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe


C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

C:\Program Files\TOSHIBA\TECO\TecoService.exe

C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe


C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe

c:\Program Files\Microsoft Security Client\NisSrv.exe





C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

C:\Program Files\TOSHIBA\Utilities\KeNotify.exe

C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe

C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe

C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe

C:\Program Files\TOSHIBA\TECO\Teco.exe

C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe

C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Program Files\Microsoft Security Client\msseces.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Secunia\PSI\psi_tray.exe



C:\Program Files\Windows Media Player\wmpnetwk.exe



C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe


C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe

C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe

C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe

C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe


C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe

C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe

C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe

C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe

C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe


C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe



C:\Program Files\Internet Explorer\iexplore.exe


c:\Program Files\Microsoft Security Client\MpCmdRun.exe




C:\windows\system32\svchost.exe -k DcomLaunch

C:\windows\system32\svchost.exe -k RPCSS

C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\windows\system32\svchost.exe -k netsvcs

C:\windows\system32\svchost.exe -k LocalService

C:\windows\system32\svchost.exe -k NetworkService

C:\windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\windows\system32\svchost.exe -k apphost

C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\windows\system32\svchost.exe -k ftpsvc

C:\windows\system32\svchost.exe -k imgsvc

C:\windows\system32\svchost.exe -k iissvcs

C:\windows\System32\svchost.exe -k LocalServicePeerNet

C:\windows\system32\svchost.exe -k SDRSVC


============== Pseudo HJT Report ===============


uStart Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com

uSearch Page = hxxp://www.google.com

mStart Page = hxxp://www.google.com

mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSAU&bmod=TSAU

uSearchAssistant = hxxp://www.google.com

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll

BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - c:\program files\wot\WOT.dll

BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll

TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: VideoDownloadConverter: {48586425-6BB7-4F51-8DC6-38C88E3EBB58} -

TB: WOT: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - c:\program files\wot\WOT.dll

TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: VideoDownloadConverter: {48586425-6bb7-4f51-8dc6-38c88e3ebb58} -

TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - c:\program files\wot\WOT.dll

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

mRun: [iAStorIcon] c:\program files\intel\intel® rapid storage technology\IAStorIcon.exe

mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s

mRun: [sVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL

mRun: [HWSetup] "c:\program files\toshiba\utilities\HWSetup.exe" hwSetUP

mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe

mRun: [TPwrMain] c:\program files\toshiba\power saver\TPwrMain.EXE

mRun: [HSON] c:\program files\toshiba\tbs\HSON.exe

mRun: [smoothView] c:\program files\toshiba\smoothview\SmoothView.exe

mRun: [00TCrdMain] c:\program files\toshiba\flashcards\TCrdMain.exe

mRun: [synTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe

mRun: [smartFaceVWatcher] c:\program files\toshiba\smartfacev\SmartFaceVWatcher.exe

mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe

mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60

mRun: [Teco] "c:\program files\toshiba\teco\Teco.exe" /r

mRun: [TosWaitSrv] c:\program files\toshiba\tphm\TosWaitSrv.exe

mRun: [TosNC] c:\program files\toshiba\bulletinboard\TosNcCore.exe

mRun: [TosReelTimeMonitor] c:\program files\toshiba\reeltime\TosReelTimeMonitor.exe

mRun: [TWebCamera] "c:\program files\toshiba\toshiba web camera application\TWebCamera.exe" autorun

mRun: [MsmqIntCert] regsvr32 /s mqrt.dll

mRun: [intelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"

mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe

mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

TCP: NameServer =

TCP: Interfaces\{379F2145-B3CA-4A8C-9214-E399A1260DA0} : NameServer =

TCP: Interfaces\{CBBA0E56-5139-4DCD-94DF-89921C4507C3} : DHCPNameServer =

TCP: Interfaces\{CBBA0E56-5139-4DCD-94DF-89921C4507C3}\24967605F6E646032364939373 : DHCPNameServer =

Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll

Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL

SSODL: WebCheck - <orphaned>

SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL


============= SERVICES / DRIVERS ===============


R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552]

R1 MpKslc7f4fcd0;MpKslc7f4fcd0;c:\programdata\microsoft\microsoft antimalware\definition updates\{721c4052-3252-42fa-a32b-1304fad6529e}\MpKslc7f4fcd0.sys [2012-12-17 29904]

R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-23 12880]

R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-13 67664]

R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2011-8-12 116608]

R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-9-20 172032]

R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-10-28 185712]

R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-11 46448]

R2 ftpsvc;Microsoft FTP Service;c:\windows\system32\svchost.exe -k ftpsvc [2009-7-14 20992]

R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\intel\intel® rapid storage technology\IAStorDataMgrSvc.exe [2011-9-20 13336]

R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 99272]

R2 RSELSVC;TOSHIBA Modem region select service;c:\program files\toshiba\rselect\RSelSvc.exe [2009-7-8 62832]

R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2012-2-17 1153368]

R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-10-14 994360]

R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-9-29 185712]

R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-20 12920]

R2 UNS;Intel® Management & Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2011-9-20 2314240]

R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-9-12 287824]

R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2011-9-19 24064]

R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]

R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-9-20 230912]

R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2010-4-26 1011232]

R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2011-9-20 51512]

R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-11-6 111960]

R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-10-31 677232]

S1 MpKsl29be9dca;MpKsl29be9dca;c:\programdata\microsoft\microsoft antimalware\definition updates\{721c4052-3252-42fa-a32b-1304fad6529e}\MpKsl29be9dca.sys [2012-12-17 29904]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-10-14 399416]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]

S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2011-9-30 180736]

S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2011-9-20 174592]

S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-9-20 52224]

S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-9-20 1343400]

S3 WMSVC;Web Management Service;c:\windows\system32\inetsrv\WMSvc.exe [2009-7-14 9728]


=============== Created Last 30 ================


2012-12-17 02:41:29 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{721c4052-3252-42fa-a32b-1304fad6529e}\MpKslc7f4fcd0.sys

2012-12-17 02:27:52 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{721c4052-3252-42fa-a32b-1304fad6529e}\MpKsl29be9dca.sys

2012-12-16 10:01:57 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{721c4052-3252-42fa-a32b-1304fad6529e}\mpengine.dll

2012-12-15 03:21:08 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll

2012-12-12 20:17:48 2345984 ----a-w- c:\windows\system32\win32k.sys

2012-11-29 01:00:48 740840 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{00c097e2-9308-4f30-b88c-5caa1a3d5303}\gapaengine.dll


==================== Find3M ====================


2012-12-12 20:26:17 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-12-12 20:26:17 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-11-14 02:09:22 1800704 ----a-w- c:\windows\system32\jscript9.dll

2012-11-14 01:58:15 1427968 ----a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 01:57:37 1129472 ----a-w- c:\windows\system32\wininet.dll

2012-11-14 01:49:25 142848 ----a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 01:48:27 420864 ----a-w- c:\windows\system32\vbscript.dll

2012-11-14 01:44:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-11-09 04:42:49 2048 ----a-w- c:\windows\system32\tzres.dll

2012-11-05 20:32:16 295424 ----a-w- c:\windows\system32\atmfd.dll

2012-11-05 20:32:09 34304 ----a-w- c:\windows\system32\atmlib.dll

2012-11-02 05:11:31 376832 ----a-w- c:\windows\system32\dpnet.dll

2012-10-16 07:39:52 561664 ----a-w- c:\windows\apppatch\AcLayers.dll

2012-10-09 17:40:31 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll

2012-10-09 17:40:31 193536 ----a-w- c:\windows\system32\dhcpcore6.dll

2012-10-04 16:47:18 169984 ----a-w- c:\windows\system32\winsrv.dll

2012-10-04 16:43:05 293376 ----a-w- c:\windows\system32\KernelBase.dll

2012-10-04 14:57:58 271360 ----a-w- c:\windows\system32\conhost.exe

2012-10-04 14:41:50 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll

2012-10-04 14:41:50 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll

2012-10-04 14:41:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll

2012-10-04 14:41:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll

2012-10-03 16:58:30 1293680 ----a-w- c:\windows\system32\drivers\tcpip.sys

2012-10-03 16:42:26 52224 ----a-w- c:\windows\system32\nlaapi.dll

2012-10-03 16:42:26 242176 ----a-w- c:\windows\system32\nlasvc.dll

2012-10-03 16:42:24 18944 ----a-w- c:\windows\system32\netevent.dll

2012-10-03 16:42:24 175104 ----a-w- c:\windows\system32\netcorehc.dll

2012-10-03 16:42:23 156672 ----a-w- c:\windows\system32\ncsi.dll

2012-10-03 16:40:35 499712 ----a-w- c:\windows\system32\iphlpsvc.dll

2012-10-03 15:21:38 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys

2012-09-29 08:54:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-09-25 22:47:43 78336 ----a-w- c:\windows\system32\synceng.dll

2012-09-24 12:16:36 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll


============= FINISH: 13:48:40.26 ===============





DDS (Ver_2012-11-20.01)


Microsoft Windows 7 Home Premium

Boot Device: \Device\HarddiskVolume1

Install Date: 19/09/2011 7:24:46 PM

System Uptime: 17/12/2012 1:40:44 PM (0 hours ago)


Motherboard: TOSHIBA | | NSWAA

Processor: Intel® Core™ i3 CPU M 330 @ 2.13GHz | CPU | 2133/133mhz


==== Disk Partitions =========================


C: is FIXED (NTFS) - 453 GiB total, 410.245 GiB free.

D: is CDROM ()


==== Disabled Device Manager Items =============


==== System Restore Points ===================


RP190: 12/11/2012 3:35:18 PM - Installed WOT for Internet Explorer

RP191: 13/11/2012 7:57:48 PM - Windows Update

RP192: 15/11/2012 8:46:43 PM - Windows Update

RP193: 19/11/2012 7:26:57 PM - Windows Update

RP194: 23/11/2012 11:21:06 AM - Windows Update

RP195: 26/11/2012 8:47:46 PM - Windows Update

RP196: 28/11/2012 12:43:31 PM - Windows Update

RP197: 30/11/2012 9:17:19 PM - Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

RP198: 1/12/2012 11:19:37 AM - Windows Backup

RP199: 1/12/2012 2:10:57 PM - Windows Update

RP200: 2/12/2012 1:49:38 PM - Windows Backup

RP201: 5/12/2012 10:18:12 AM - Windows Update

RP202: 9/12/2012 6:20:32 PM - Windows Update

RP203: 13/12/2012 7:20:01 AM - Windows Update

RP204: 13/12/2012 3:47:58 PM - Windows Update

RP205: 16/12/2012 9:01:31 PM - Windows Update


==== Installed Programs ======================


Update for Microsoft Office 2007 (KB2508958)

2007 Microsoft Office system

500 From Special K


Adobe AIR

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader XI

Adobe Shockwave Player 11.6

ATI Catalyst Install Manager

Auslogics Disk Defrag

Bejeweled 2 Deluxe 1.0

Blueline 1.1.1

BurnAware Free 5.1

Business Contact Manager for Outlook 2007 SP2

Catalyst Control Center - Branding

Catalyst Control Center Core Implementation

Catalyst Control Center Graphics Full Existing

Catalyst Control Center Graphics Full New

Catalyst Control Center Graphics Light

Catalyst Control Center Graphics Previews Common

Catalyst Control Center Graphics Previews Vista

Catalyst Control Center InstallProxy

Catalyst Control Center Localization All



CCC Help Chinese Standard

CCC Help Chinese Traditional

CCC Help Czech

CCC Help Danish

CCC Help Dutch

CCC Help English

CCC Help Finnish

CCC Help French

CCC Help German

CCC Help Greek

CCC Help Hungarian

CCC Help Italian

CCC Help Japanese

CCC Help Korean

CCC Help Norwegian

CCC Help Polish

CCC Help Portuguese

CCC Help Russian

CCC Help Spanish

CCC Help Swedish

CCC Help Thai

CCC Help Turkish




Direct DiscRecorder

DVD MovieFactory for TOSHIBA

ESET Online Scanner v3

Google Earth

Google Toolbar for Internet Explorer

Google Update Helper


Intel® Control Center

Intel® Management Engine Components

Intel® Rapid Storage Technology

Java 7 Update 9

Java Auto Updater

JavaFX 2.1.1

Junk Mail filter update

LSI V92 MOH Application

Malwarebytes Anti-Malware version

Masque Casino Game Pak II

Microsoft .NET Framework 4 Client Profile

Microsoft Application Error Reporting

Microsoft Choice Guard

Microsoft IntelliPoint 8.2

Microsoft Office 2003 Web Components

Microsoft Office 2007 Primary Interop Assemblies

Microsoft Office 2007 Service Pack 3 (SP3)

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office File Validation Add-In

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office Professional Hybrid 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Small Business Connectivity Components

Microsoft Office Suite Activation Assistant

Microsoft Office Word MUI (English) 2007

Microsoft Security Client

Microsoft Security Essentials

Microsoft Silverlight

Microsoft SQL Server 2005

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)

Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)

Microsoft SQL Server 2005 Tools Express Edition

Microsoft SQL Server Native Client

Microsoft SQL Server Setup Support Files (English)

Microsoft SQL Server VSS Writer

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219


Optus Wireless Broadband

Orca Browser

PlayReady PC Runtime x86


Realtek Ethernet Controller Driver For Windows Vista and Later

Realtek High Definition Audio Driver

Realtek USB 2.0 Card Reader

Realtek WLAN Driver

Reel Deal Slots - Nickels and More

Secunia PSI (

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596856) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition

Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition

Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition

Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition

Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition


SpeedFan (remove only)

Spelling Dictionaries Support For Adobe Reader 9

Spybot - Search & Destroy



Synaptics Pointing Device Driver


TOSHIBA Bulletin Board

TOSHIBA ConfigFree

TOSHIBA Disc Creator


TOSHIBA eco Utility

TOSHIBA Extended Tiles for Windows Mobility Center

TOSHIBA Face Recognition

TOSHIBA Flash Cards Support Utility

TOSHIBA Hardware Setup


TOSHIBA Internal Modem Region Select Utility

TOSHIBA PC Health Monitor

TOSHIBA Recovery Media Creator


TOSHIBA Service Station

TOSHIBA Software Modem

TOSHIBA Speech System Applications

TOSHIBA Speech System SR Engine(U.S.) Version1.0

TOSHIBA Speech System TTS Engine(U.S.) Version1.0

TOSHIBA Supervisor Password

TOSHIBA Value Added Package

TOSHIBA Web Camera Application

Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft Office 2007 Help for Common Features (KB963673)

Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition

Update for Microsoft Office Access 2007 Help (KB963663)

Update for Microsoft Office Excel 2007 Help (KB963678)

Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition

Update for Microsoft Office Outlook 2007 Help (KB963677)

Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760573) 32-Bit Edition

Update for Microsoft Office Powerpoint 2007 Help (KB963669)

Update for Microsoft Office Publisher 2007 Help (KB963667)

Update for Microsoft Office Script Editor Help (KB963671)

Update for Microsoft Office Word 2007 Help (KB963665)

Utility Common Driver

Windows Live Call

Windows Live Communications Platform

Windows Live Essentials

Windows Live Mail

Windows Live Messenger

Windows Live Movie Maker

Windows Live Photo Gallery

Windows Live Sign-in Assistant

Windows Live Sync

Windows Live Upload Tool

Windows Live Writer

WOT for Internet Explorer


==== Event Viewer Messages From Past Week ========


17/12/2012 1:41:07 PM, Error: SNMP [1500] - The SNMP Service encountered an error while accessing the registry key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.

17/12/2012 1:39:57 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}

17/12/2012 1:39:57 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}

17/12/2012 1:39:14 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.

17/12/2012 1:30:45 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.

17/12/2012 1:30:44 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

17/12/2012 1:30:44 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

17/12/2012 1:30:35 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

17/12/2012 1:30:04 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

17/12/2012 1:29:50 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache MpFilter SASDIFSV SASKUTIL spldr Wanarpv6

17/12/2012 1:29:47 PM, Error: Service Control Manager [7001] - The Net.Msmq Listener Adapter service depends on the Message Queuing service which failed to start because of the following error: The dependency service or group failed to start.

17/12/2012 1:29:47 PM, Error: Service Control Manager [7001] - The Message Queuing Triggers service depends on the Message Queuing service which failed to start because of the following error: The dependency service or group failed to start.

17/12/2012 1:29:46 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000008e (0xc0000005, 0x00000000, 0xa590fcb8, 0x00000000). A dump was saved in: C:\windows\MEMORY.DMP. Report Id: 121712-16426-01.

15/12/2012 9:27:35 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} and APPID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user Laptop\John SID (S-1-5-21-667125997-313001622-354392929-1005) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.

15/12/2012 9:27:35 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} and APPID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user Laptop\John SID (S-1-5-21-667125997-313001622-354392929-1005) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.


==== End Of File ===========================

AdwCleaner log

# AdwCleaner v2.005 - Logfile created 12/17/2012 at 13:26:15

# Updated 14/10/2012 by Xplode

# Operating system : Windows 7 Home Premium Service Pack 1 (32 bits)

# User : John - LAPTOP

# Boot Mode : Normal

# Running from : C:\Users\John\Downloads\adwcleaner.exe

# Option [Delete]

***** [services] *****

***** [Files / Folders] *****

***** [Registry] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

***** [internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Google Chrome v [unable to get version]

File : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.


AdwCleaner[s1].txt - [906 octets] - [29/08/2012 12:35:47]

AdwCleaner[s3].txt - [1419 octets] - [28/10/2012 20:14:22]

AdwCleaner[s4].txt - [1131 octets] - [28/10/2012 20:38:44]

AdwCleaner[s5].txt - [971 octets] - [10/11/2012 21:35:46]

AdwCleaner[s6].txt - [1030 octets] - [12/11/2012 10:36:35]

AdwCleaner[s7].txt - [1091 octets] - [13/11/2012 19:46:03]

AdwCleaner[s8].txt - [1261 octets] - [23/11/2012 11:13:20]

AdwCleaner[s9].txt - [1192 octets] - [17/12/2012 13:26:15]

########## EOF - C:\AdwCleaner[s9].txt - [1252 octets] ##########

MBAM log Just Updated and scanned

Malwarebytes Anti-Malware


Database version: v2012.12.16.11

Windows 7 Service Pack 1 x86 NTFS (Safe Mode/Networking)

Internet Explorer 9.0.8112.16421

John :: LAPTOP [administrator]

17/12/2012 1:34:29 PM

mbam-log-2012-12-17 (13-34-29).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 237548

Time elapsed: 2 minute(s), 1 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)



SUPERAntiSpyware Scan Log


Generated 12/17/2012 at 01:33 PM

Application Version : 5.6.1014

Core Rules Database Version : 9749

Trace Rules Database Version: 7561

Scan type : Quick Scan

Total Scan Time : 00:02:22

Operating System Information

Windows 7 Home Premium 32-bit, Service Pack 1 (Build 6.01.7601)

UAC Off - Administrator

Memory items scanned : 358

Memory threats detected : 0

Registry items scanned : 30999

Registry threats detected : 0

File items scanned : 7080

File threats detected : 0

Thank You -

  • Staff

Hello and welcome to Malwarebytes :lol: :lol: :lol:

Where did you see a sign of OptimumInstaller? How did you try to remove it?

Please download AdwCleaner by Xplode onto your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Rn].txt as well - n is the order number.

This seems to be the Spybot log (I think) -

--- Report generated: 2012-12-17 13:08 ---

OptimumInstaller: [sBI $0B5D7EDA] Data (File, nothing done)

C:\ProgramData\Google\Custom Buttons\toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.XML




Properties.filedatetext=2011-09-26 18:13:32

--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

Note the Spybot report says Nothing Done, but as I ticked it and went to Remove it, the problems started -

I also do not use Chrome Ever ??

New AdwCleaner log -

# AdwCleaner v2.101 - Logfile created 12/17/2012 at 15:44:37

# Updated 16/12/2012 by Xplode

# Operating system : Windows 7 Home Premium Service Pack 1 (32 bits)

# User : John - LAPTOP

# Boot Mode : Normal

# Running from : C:\Users\John\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QKHJL1FF\adwcleaner.exe

# Option [search]

***** [services] *****

***** [Files / Folders] *****

***** [Registry] *****

***** [internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Google Chrome v [unable to get version]

File : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.


AdwCleaner[R1].txt - [733 octets] - [17/12/2012 15:44:37]

AdwCleaner[s1].txt - [906 octets] - [29/08/2012 12:35:47]

AdwCleaner[s3].txt - [1419 octets] - [28/10/2012 20:14:22]

AdwCleaner[s4].txt - [1131 octets] - [28/10/2012 20:38:44]

AdwCleaner[s5].txt - [971 octets] - [10/11/2012 21:35:46]

AdwCleaner[s6].txt - [1030 octets] - [12/11/2012 10:36:35]

AdwCleaner[s7].txt - [1091 octets] - [13/11/2012 19:46:03]

AdwCleaner[s8].txt - [1261 octets] - [23/11/2012 11:13:20]

AdwCleaner[s9].txt - [1321 octets] - [17/12/2012 13:26:15]

########## EOF - C:\AdwCleaner[R1].txt - [1270 octets] ##########

"Unexpected error in fixing problems "Can not create file "C:\Windows\wininit.ini" Access is denied."

This above quote that I found is (I think) the same as I had when I ticked the item and clicked "Repair Problems" or the Spybot version.

At this time it caused the BSOD and "Shut Down to Protect the System". The reboot was then to Safe Mode, where I ran the basic scans I submitted.

After 5 minutes I restarted again in Normal mode and all seemed "reasonably OK" -

Hi Chris -

The item did not show in a fresh Spybot scan, but I had not used the program since first signs of a problem.

C:\ProgramData\Google\Custom Buttons was very hard to find as it took 2 manual searches and 2 searches in the "Search bar" at the start Orb. These were finally found and all seemed to be related

<?xml version="1.0" encoding="UTF-8"?>

-<custombuttons xmlns="http://toolbar.googl.../custombuttons/"> -<button>

<title>Button Gallery</title>

And also ...........



Along with ...............


They did "protest" at first as I went to remove them but they all ended up in Recycle bin.

I think I have got all of them, but I never use Chrome and only the normal Google home page.

I thought it may relate to some USB items as wife has Survivor TV program given to her on USB stick.

And This ( SSODL: WebCheck - <orphaned> ) was also unknown.

Do you want me to check further, or was that it ??

Thanks -

EXTRA - I have since been back to my Google home page and there seems to be no problems there.

  • Staff

Hi John,

Thanks for the update.

You don't have Chrome installed to the best of my knowledge. You do, however, have these installed:

Google Earth

Google Toolbar for Internet Explorer

Google Update Helper

( SSODL: WebCheck - <orphaned> )
No need to worry as it is orphaned. You can check if that Registry Key still exists. Open Regedit.exe and navigate to here:


Is there anything listed under the Key?

Just a finish note -

These items still turn up in a computer search for OptimumInstaller, but nothing shows in any scans or seems to cause any problems these days -

Both top links turn up with "Broken Links" or "cannot access" so it must be gone now :)

-<custombuttons xmlns="http://toolbar.googl.../custombuttons/">

<?xml version="1.0" encoding="UTF-8"?>

-<custombuttons xmlns="http://toolbar.googl.../custombuttons/"> -<button>

<title>Button Gallery</title>






Must just be isolated items as no "dramas" exist now -

Okay, the file you click on when you did that search: instead of left-clicking, right-click it and click Open File Location. What is the path to the file and what is it called

Path Location is Documents - Text Document

Result on opening text document is exactly as below ...............................

-<custombuttons xmlns="http://toolbar.googl.../custombuttons/">

<?xml version="1.0" encoding="UTF-8"?>

-<custombuttons xmlns="http://toolbar.googl.../custombuttons/"> -<button>

<title>Button Gallery</title>






Picture of location -


So far nothing has altered at this end. Most likely it was nothing, but I just posted due to the first reaction (as post #1)

I just did a Right Click / Delete, and it was gone. I still scan daily with all my tools and nothing has ever shown up.

I still do not know what it was, except for those Google extensions in the file -

This Page seems to be about the only description of OptimumInstaller that is listed.

I can only think that I picked it up while doing searches for other items, as I never installed it -

All other pages are What is it / do I want it / can I remove it - etc

EXTRA - I do not have any Torrent or TV installer on here, so that is why I mentioned anout my wife getting TV series Survivor on USB stick from someone else recently (we are about a month behind USA release) -

