All processes killed ========== OTL ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\XZqIqa15281iwWR deleted successfully. C:\Users\Paulo\AppData\Roaming\aerga43ge4r.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-2225979431-1048592176-2657008964-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully. Registry value HKEY_USERS\S-1-5-21-2225979431-1048592176-2657008964-1001\Software\Microsoft\Windows\CurrentVersion\Run\\RGSC deleted successfully. Registry value HKEY_USERS\S-1-5-21-2225979431-1048592176-2657008964-1001\Software\Microsoft\Windows\CurrentVersion\Run\\XZqIqa15281iwWR deleted successfully. File C:\Users\Paulo\AppData\Roaming\aerga43ge4r.exe not found. Registry value HKEY_USERS\S-1-5-21-2225979431-1048592176-2657008964-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\B7E8586B000174330067D184B4EB2367 deleted successfully. C:\ProgramData\B7E8586B000174330067D184B4EB2367\B7E8586B000174330067D184B4EB2367.exe moved successfully. ========== FILES ========== C:\ProgramData\B7E8586B000174330067D184B4EB2367 folder moved successfully. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Userinit"|"C:\\WINDOWS\\system32\\userinit.exe," /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Shell"|"explorer.exe" /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-2225979431-1048592176-2657008964-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit deleted successfully. Registry value HKEY_USERS\S-1-5-21-2225979431-1048592176-2657008964-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56466 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Paulo ->Temp folder emptied: 1912970662 bytes ->Temporary Internet Files folder emptied: 8409193491 bytes ->Java cache emptied: 53428544 bytes ->Flash cache emptied: 57953 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56504 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 401408 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 579436228 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50534 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 10 448,00 mb OTL by OldTimer - Version 3.2.53.1 log created on 07082012_124548 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot...