All processes killed ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-1028587419-3669330845-735310777-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found. Prefs.js: "uTorrentControl2 Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl Prefs.js: "uTorrentControl2 Customized Web Search" removed from browser.search.selectedEngine Prefs.js: engine@conduit.com:3.2.5.2 removed from extensions.enabledItems Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=2&q=" removed from keyword.URL C:\Users\Kamil\AppData\Roaming\mozilla\Firefox\Profiles\p3liy92z.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\searchplugin folder moved successfully. C:\Users\Kamil\AppData\Roaming\mozilla\Firefox\Profiles\p3liy92z.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\Plugins folder moved successfully. C:\Users\Kamil\AppData\Roaming\mozilla\Firefox\Profiles\p3liy92z.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\modules folder moved successfully. C:\Users\Kamil\AppData\Roaming\mozilla\Firefox\Profiles\p3liy92z.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\META-INF folder moved successfully. C:\Users\Kamil\AppData\Roaming\mozilla\Firefox\Profiles\p3liy92z.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\defaults folder moved successfully. C:\Users\Kamil\AppData\Roaming\mozilla\Firefox\Profiles\p3liy92z.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\components folder moved successfully. C:\Users\Kamil\AppData\Roaming\mozilla\Firefox\Profiles\p3liy92z.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\chrome folder moved successfully. C:\Users\Kamil\AppData\Roaming\mozilla\Firefox\Profiles\p3liy92z.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03} folder moved successfully. C:\Users\Kamil\AppData\Roaming\Mozilla\Firefox\Profiles\p3liy92z.default\searchplugins\conduit.xml moved successfully. Registry value HKEY_USERS\S-1-5-21-1028587419-3669330845-735310777-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{687578B9-7132-4A7A-80E4-30EE31099E03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578B9-7132-4A7A-80E4-30EE31099E03}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A9007C0-4076-11D3-8789-0000F8105754}\ deleted successfully. File {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll File not found not found. ========== COMMANDS ========== [EMPTYTEMP] User: Agnieszka User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Kamil ->Temp folder emptied: 4461670 bytes ->Temporary Internet Files folder emptied: 287003 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 89755041 bytes ->Flash cache emptied: 878 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 13232 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes RecycleBin emptied: 4945977 bytes Total Files Cleaned = 95,00 mb OTL by OldTimer - Version 3.2.53.1 log created on 07092012_090830 Files\Folders moved on Reboot... C:\Users\Kamil\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZW82MU2I\api[1].htm moved successfully. C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZW82MU2I\api[2].htm moved successfully. C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OYNCJYWH\background_banner_7_pl[1].jpg moved successfully. C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CKCMOVDA\background-banner-right-v9[1].jpg moved successfully. C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CKCMOVDA\button-flex-blue2[1].png moved successfully. C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7KIECM53\background-banner-middle-v9[1].jpg moved successfully. C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7KIECM53\tick-blue[1].png moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files... File C:\Users\Kamil\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! File C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZW82MU2I\api[1].htm not found! File C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZW82MU2I\api[2].htm not found! File C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OYNCJYWH\background_banner_7_pl[1].jpg not found! File C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CKCMOVDA\background-banner-right-v9[1].jpg not found! File C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CKCMOVDA\button-flex-blue2[1].png not found! File C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7KIECM53\background-banner-middle-v9[1].jpg not found! File C:\Users\Kamil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7KIECM53\tick-blue[1].png not found! [2012-07-09 09:11:34 | 000,000,000 | ---- | M] () C:\Windows\temp\_avast_\Webshlock.txt : Unable to obtain MD5 Registry entries deleted on Reboot...