All processes killed ========== FILES ========== C:\autorun.inf moved successfully. D:\autorun.inf moved successfully. C:\wqesvxa.exe moved successfully. D:\wqesvxa.exe moved successfully. C:\WINDOWS\System32\EXPLORER.EXE moved successfully. C:\WINDOWS\System32\cvnmhg0.dll moved successfully. C:\WINDOWS\System32\cvnmhg1.dll moved successfully. C:\WINDOWS\System32\amvo.exe moved successfully. C:\WINDOWS\System32\drivers\anzrgyrw.dat moved successfully. [color=#A23BEC]< netsh firewall reset /C >[/color] Ok. C:\Documents and Settings\Wieclaw\Pulpit\testy\cmd.bat deleted successfully. C:\Documents and Settings\Wieclaw\Pulpit\testy\cmd.txt deleted successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RelevantKnowledge\ deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Userinit"|"C:\\WINDOWS\\system32\\userinit.exe," /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\\"CheckedValue"|dword:00000001 /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf\\""|"@SYS:DoesNotExist" /E : value set successfully! Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\amva deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\EXPLORER.EXE deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\wsctf.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\\EnableLUA deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableRegistryTools deleted successfully. Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr deleted successfully. Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableRegistryTools deleted successfully. Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr not found. Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableRegistryTools not found. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! ========== COMMANDS ========== [EMPTYFLASH] User: Default User User: All Users User: NetworkService User: LocalService User: Wieclaw ->Flash cache emptied: 211543 bytes User: dawid Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Wieclaw ->Temp folder emptied: 1729046579 bytes ->Temporary Internet Files folder emptied: 6197695 bytes ->FireFox cache emptied: 22167996 bytes ->Google Chrome cache emptied: 20619682 bytes ->Flash cache emptied: 0 bytes User: dawid ->Temp folder emptied: 199674 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2114584 bytes %systemroot%\System32 .tmp files removed: 105515 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 104225166 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1 797,00 mb OTL by OldTimer - Version 3.2.28.0 log created on 09162011_171209 Files\Folders moved on Reboot... C:\WINDOWS\temp\Perflib_Perfdata_aa0.dat moved successfully. Registry entries deleted on Reboot...