Unable to uninstall Hola Search Toolbar from Programmes

Okay that looks like it was able to remove some items for us.


Please visit this site and reset IE


How to reset Internet Explorer settings



Now restart the computer now and see if you're able to download FRST now and let me know.

If so then please download it and run it as requested and post back the log

FRST loaded this time, though when prompted to update to the most recent I kept attempting to, only for it to return to the original page where it would ask me to run it which i would, to which it would prompt me and so forth. In the end i declined to update it to the most recent, dont know if that affects anything but thought it may be worth mentioning.


here is the frst log


additional log


Please download the attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST or FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system.

Run FRST or FRST64 and press the Fix button just once and wait.
If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach or post it to your next reply.

Note: If the tool warned you about an outdated version please download and run the updated version.


Thanks I have done that as instructed. here is the fixlog.


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 19-08-2013
Ran by Steve at 2013-08-19 05:22:01 Run:1
Running from C:\Users\Steve\Desktop
Boot Mode: Normal


Content of fixlist:
c:\Program Files\Microsoft Security Client
HKLM\...\Run: [sunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe
HKLM\...\Run: [pcreg] - C:\Program Files\wrapper_inst\service.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...er=6&ar=msnhome
SearchScopes: HKLM - DefaultScope value is missing.
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Task: {31C4BE4D-7713-41D9-887A-24990BB7E7A2} - System32\Tasks\PcRegistryShield_Start => C:\Program Files\PC Registry Shield\PcRegistryShield.exe No File
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {5AEA3352-DF9F-488D-A58F-7A36D0A5DF75} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2970680302-2301816736-3001710448-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe No File
Task: {6A0D34D8-73A5-455B-8770-839F8CA53513} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30] (Apple Inc.)
Task: {6A9DFD4C-2DC3-4018-A299-59AA01A3853D} - System32\Tasks\pcreg => C:\Program Files\wrapper_inst\service.exe [2013-08-17] ()
Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-21] (Microsoft Corporation)
Task: {B783C587-4B02-4901-8F44-7C1F5C27398B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-02] (Adobe Systems Incorporated)
Task: {D62E3111-761D-49D0-9041-F84FCB3B4146} - System32\Tasks\At1 => c:\Program Files\wrapper_inst\service.exe [2013-08-17] ()
Task: {FDCDCD79-CB8F-4BDC-A062-861373ECF31A} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2970680302-2301816736-3001710448-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe No File
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\At1.job => c:\Program Files\wrapper_inst\service.exe
Task: C:\Windows\Tasks\pcreg.job => C:\Program Files\wrapper_inst\service.exe


c:\Program Files\Microsoft Security Client => Will not be moved with FRST.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\pcreg => Value deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} => Value deleted successfully.
HKCR\CLSID\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully.
HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found.
HKCR\PROTOCOLS\Handler\dssrequest => Key deleted successfully.
HKCR\CLSID\{5513F07E-936B-4E52-9B00-067394E91CC5} => Key deleted successfully.
HKCR\PROTOCOLS\Handler\sacore => Key deleted successfully.
HKCR\CLSID\{5513F07E-936B-4E52-9B00-067394E91CC5} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{31C4BE4D-7713-41D9-887A-24990BB7E7A2} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{31C4BE4D-7713-41D9-887A-24990BB7E7A2} => Key deleted successfully.
C:\Windows\System32\Tasks\PcRegistryShield_Start => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PcRegistryShield_Start => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} => Key deleted successfully.
C:\Windows\System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Shell\CrawlStartPages => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5AEA3352-DF9F-488D-A58F-7A36D0A5DF75} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5AEA3352-DF9F-488D-A58F-7A36D0A5DF75} => Key deleted successfully.
C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2970680302-2301816736-3001710448-1000 => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealUpgradeLogonTaskS-1-5-21-2970680302-2301816736-3001710448-1000 => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A0D34D8-73A5-455B-8770-839F8CA53513} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A0D34D8-73A5-455B-8770-839F8CA53513} => Key deleted successfully.
C:\Windows\System32\Tasks\Apple\AppleSoftwareUpdate => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apple\AppleSoftwareUpdate => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6A9DFD4C-2DC3-4018-A299-59AA01A3853D} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A9DFD4C-2DC3-4018-A299-59AA01A3853D} => Key deleted successfully.
C:\Windows\System32\Tasks\pcreg => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pcreg => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A61555D3-7840-45C1-A5A9-0D49851DE37A} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A61555D3-7840-45C1-A5A9-0D49851DE37A} => Key deleted successfully.
C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B783C587-4B02-4901-8F44-7C1F5C27398B} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B783C587-4B02-4901-8F44-7C1F5C27398B} => Key deleted successfully.
C:\Windows\System32\Tasks\Adobe Flash Player Updater => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D62E3111-761D-49D0-9041-F84FCB3B4146} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D62E3111-761D-49D0-9041-F84FCB3B4146} => Key deleted successfully.
C:\Windows\System32\Tasks\At1 => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\At1 => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FDCDCD79-CB8F-4BDC-A062-861373ECF31A} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FDCDCD79-CB8F-4BDC-A062-861373ECF31A} => Key deleted successfully.
C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2970680302-2301816736-3001710448-1000 => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealUpgradeScheduledTaskS-1-5-21-2970680302-2301816736-3001710448-1000 => Key deleted successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\At1.job => Moved successfully.
C:\Windows\Tasks\pcreg.job => Moved successfully.

==== End of Fixlog ====

Please uninstall ALL versions of Java.

Please uninstall McAfee Security Scan Plus


How is the computer running now?  Are there still any signs of infection?


Please, download Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Hi, the system is running better now and to a layman like myself appears fine. One thing though, I noticed in that report that windows firewall was enabled. I didnt even know I had windows firewall, therefore this will have been on throughout the enitre process. Should I repeat the instructions you laid out in your first post just to be certain or am I ok? Thanks


Results of screen317's Security Check version 0.99.72 
 Windows Vista Service Pack 2 x86 (UAC is disabled!) 
 Internet Explorer 9 
 Internet Explorer 8 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled! 
Microsoft Security Essentials  
  (On Access scanning disabled!)
 Error obtaining update status for antivirus! 
`````````Anti-malware/Other Utilities Check:`````````
 McAfee SiteAdvisor   
 Malwarebytes Anti-Malware version 
 Adobe Flash Player  11.8.800.94 
 Adobe Reader 10.1.7 Adobe Reader out of Date! 
````````Process Check: objlist.exe by Laurent```````` 
 Microsoft Security Essentials MSMpEng.exe
 Microsoft Security Essentials msseces.exe
 Malwarebytes Anti-Malware mbamservice.exe 
 Malwarebytes Anti-Malware mbamgui.exe 
 Malwarebytes' Anti-Malware mbamscheduler.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 1 %
````````````````````End of Log``````````````````````

I have noticed however over the course of the day that Internet explorer is operating quite slowly but not sure if this was always the case as i only ever used to use google chrome or firefox. Also a new icon was created on my desktop at some point during the process since we started clearing things that appears with the explorer logo entitled 'the internet'. I havent installed anything so dont know how or why its there.

Link to post
Share on other sites

Well one thing that seems to possibly be wrong and may not be easy to fix is Microsoft Security Essentials. 


It should be in your task tray as a small green icon.  Please see if you can right click and open it or not and do a Quick Scan and let me know.


I'm assuming this is your main antivirus software ?

I ran a quick search, it scanned 26928 items and claimed that no threats were discovered during the scan.


It is my main one, the one I use to offer real time protection, I also have superantispyware which I use from time to time do scan but dont run in real time, I also have clamwin which I havent used for a long time

I do apologise I dont know how to take a screen shot. When I right click on it it only offers 6 options, open home page, start without add ons, create shortcut, delete, rename and properties. This differes from other shortcuts which when right clicked offer many more options.


Upon clicking on properties it says internet properties and there are 7 sub menus General, Security, Privacy, content, connections, programmes, advanced. The general menu contains hompepage, browsing history, search and tab options. This differes from other programmes and the launch internet explorer icon which has 5 sub menus General, shortcut, compatibilit, security and details and when on the general menu offers information such as when it was created. The internet icon does not have that information

That sounds like the normal Internet Explorer icon to me.  It should be safe.  If you double-click on it then it should launch your Internet Explorer web browser.   Its possible that with all the cleaning we've done it fixed that too and put it on your desktop where it does belong.

Yes it does load the explorer. So I have two explorer icons, one shortcut says launch internet explorer browser and the new one which just says the internet? You think this ok though?


If thats all fine is there anything else I need to do. As I said Ive had unwittingly had windows firewall on throughout this process, is that ok?


Another question I have, is there any reason why in programmes I could unistall firefox and chrome but there is no option to remove internet explorer?


Finally, what should I do next? Thank you

  • Root Admin

At this time there are no more signs of an infection on your system.
However if you are still seeing any signs of an infection please let me know.

Let's go ahead and remove the tools and logs we've used during this process.

Most of the tools used are potentially dangerous to use unsupervised or if ran at the wrong time.
They are often updated daily so if you went to use them again in the future they would be outdated anyways.

The following procedures will implement some cleanup procedures to remove these tools.
It will also reset your System Restore by flushing out previous restore points and create a new restore point.
It will also remove all the backups our tools may have created.

Uninstall ComboFix (if used):

  • Turn off all active protection software including your antivirus.
  • Push the "Windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • Please copy and past the following into the box ComboFix /Uninstall and click OK.
  • Note the space between the X and the /Uninstall, it needs to be there.


Remove the rest of the tools used:

Please download
and save it to your Desktop. This tool will remove all the tools we used to clean your pc.

  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not go ahead and delete it by yourself.
  • If asked to restart the computer, please do so


If you receive a warning from your firewall or other security programs regarding
attempting to contact the internet, please allow it to do so.

AdwCleaner Removal:
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Uninstall
  • Confirm with Yes

ESET antivirus Removal:
  • This tool can be uninstalled via the Control Panel, Programs, Uninstall

If there are any other left over Folders, Files, Logs then you can delete them on your own.

Please visit the following link to see how to delete old System Restore Points. Please delete all of them and create a new one at this time.
How to Delete System Protection Restore Points in Windows 7 and Windows 8

Remove all but the most recent Restore Point on Windows XP

As Java seems to get exploited on a regular basis I advise not using Java if possible but to at least disable java in your web browsers
How do I disable Java in my web browser? - Disable Java

Please read the following articles which will help you to better understand how the computer may have become infected as well as how to help prevent future infections. Nothing is 100% bulletproof but with a little bit of education you can certainly swing things in your favor.

If you're not currently using Malwarebytes PRO then you may want to consider purchasing the product which can also help greatly reduce the risk of a future infection.

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

