All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\TabbtnEx deleted successfully. C:\Users\Admin\AppData\Local\Microsoft\Windows\3565\TabbtnEx.exe moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7A8FE94-5D3A-48AF-AB8E-60439308E5DF}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7A8FE94-5D3A-48AF-AB8E-60439308E5DF}\ not found. ========== FILES ========== C:\Users\Admin\AppData\Local\Microsoft\Windows\3565 folder moved successfully. C:\Users\Admin\AppData\Roaming\hellomoto folder moved successfully. C:\Users\Admin\AppData\Local\SearchDial.crx moved successfully. C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml moved successfully. [color=#A23BEC]< rd /s /q "C:\Kaspersky Rescue Disk 10.0" /C >[/color] C:\Users\Admin\Desktop\cmd.bat deleted successfully. C:\Users\Admin\Desktop\cmd.txt deleted successfully. ========== REGISTRY ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Backup.Old.Start Page deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\Backup.Old.DefaultScope deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0FCFBDCA-6686-0419-88C9-021C78E8905C}" /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\Backup.Old.DefaultScope deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0FCFBDCA-6686-0419-88C9-021C78E8905C}" /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: Admin ->Temp folder emptied: 336934541 bytes ->Temporary Internet Files folder emptied: 566072912 bytes ->Java cache emptied: 72310 bytes ->Flash cache emptied: 23961959 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 236186757 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1 109,00 mb OTL by OldTimer - Version 3.2.53.1 log created on 07102012_182826 Files\Folders moved on Reboot... C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0MVTDPP\9858-ukash-zablokowany-laptop-jak-u-wielu-prosba-o-pomoc[1].htm moved successfully. C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S0FHGWMQ\fastbutton[1].htm moved successfully. C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. PendingFileRenameOperations files... File C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0MVTDPP\9858-ukash-zablokowany-laptop-jak-u-wielu-prosba-o-pomoc[1].htm not found! File C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S0FHGWMQ\fastbutton[1].htm not found! File C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat not found! Registry entries deleted on Reboot...