".... you did only copy the text and not the lines, and you did not have notepad format wordwrapped checked?" In that I was asking you what you did, not telling you; unchecked is the way to go because punctuation [line returns] will get added if there is wordwrapping, and that interferes.
Anyway.
"The second O2 is MyGlobalSearch toolbar... and should have been removed by running fixkey.reg." - when I posted that I was actually referring to the Panda scan entry which should have been removed, not the one in the hijackthis log [that is a different key]. I could have phrased it better...ok, properly :):-
Panda log:- Potentially unwanted tool:application/myglobalsearch Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37B85A21-692B-4205-9CAD-2626E4993404}
Hijack O2:- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37B85A29-692B-4205-9CAD-2626E4993404}
-you do not see that actual key in full in the HT log, but the above is it. Note the same CLSID, {37B85....}.
However what I have done is confuse the syntax of this registry editor with that of regedit.exe. I don't often do that. This new file will work.... I have added the extra keys to remove what you are seeing in the HT log also.
__________________________________________________________
Windows Registry Editor Version 5.00
[-HKEY_USER\S-1-5-21-436374069-1284227242-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37B85A21-692B-4205-9CAD-2626E4993404]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1426AC5-8CE5-4A00-B71E-011D35709AC6}]
[-HKEY_CLASSES_ROOT\clsid\{014DA6C9-189F-421a-88CD-07CFE51CFF10}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37B85A29-692B-4205-9CAD-2626E4993404}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
__________________________________________________________
Sigh... I have given you a bit of a run around the block. Too much to remember. Have I answered everything?
I ask for an ATF run because it cleans out cookies, which things I don't really need to see in a Panda scan because they are benign text objects. There are no rookits in your Panda log.. but it does look truncated. May I assume that the unwanted tool is actually SDFix, as in the previous log?