All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SiSUSBRG deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\6F63A5884B7C69B15C18DEC281CB3EF3 not found. C:\Documents and Settings\All Users\Dane aplikacji\6F63A5884B7C69B15C18DEC281CB3EF3\6F63A5884B7C69B15C18DEC281CB3EF3.exe moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype-ie-addon-data\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}\ deleted successfully. File {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\ deleted successfully. Service Hamachi2Svc stopped successfully! Service Hamachi2Svc deleted successfully! File D:\Program Files\LogMeIn Hamachi\hamachi-2.exe not found. Service aaudstum stopped successfully! Service aaudstum deleted successfully! File C:\DOCUME~1\PIOTRM~1.000\USTAWI~1\Temp\aaudstum.sys not found. Service WINFLASH stopped successfully! Service WINFLASH deleted successfully! File C:\Documents and Settings\piotrmati\Moje dokumenty\Pobieranie\WinFlash.sys not found. Service EverestDriver stopped successfully! Service EverestDriver deleted successfully! File D:\Programy\Everest Ultimate Edition 2007 4.20.1197 PL\kerneld.wnt not found. Service EagleNT stopped successfully! Service EagleNT deleted successfully! File C:\WINDOWS\system32\drivers\EagleNT.sys not found. Service hwusbdev stopped successfully! Service hwusbdev deleted successfully! File system32\DRIVERS\ewusbdev.sys not found. Service {95808DC4-FA4A-4c74-92FE-5B863F82066B} stopped successfully! Service {95808DC4-FA4A-4c74-92FE-5B863F82066B} deleted successfully! File D:\Program Files\CyberLink\PowerDVD\000.fcl not found. ========== FILES ========== C:\Documents and Settings\All Users\Dane aplikacji\6F63A5884B7C69B15C18DEC281CB3EF3 folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Babylon folder moved successfully. C:\Documents and Settings\piotrmati.XXXXXXX-23B8A50\Dane aplikacji\Babylon folder moved successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum\ deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 345906 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 3214428 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 50787 bytes User: piotrmati ->Temp folder emptied: 4304142 bytes ->Temporary Internet Files folder emptied: 10799841 bytes ->Java cache emptied: 13742916 bytes ->FireFox cache emptied: 50638186 bytes ->Google Chrome cache emptied: 28639600 bytes ->Flash cache emptied: 61547 bytes User: piotrmati.XXXXXXX-23B8A50 ->Temp folder emptied: 1877814705 bytes ->Temporary Internet Files folder emptied: 79190057 bytes ->Java cache emptied: 268980 bytes ->Google Chrome cache emptied: 33040275 bytes ->Flash cache emptied: 2389 bytes User: piotrmati.XXXXXXX-23B8A50.000 ->Temp folder emptied: 62570750 bytes ->Temporary Internet Files folder emptied: 754285 bytes ->Java cache emptied: 9952258 bytes ->FireFox cache emptied: 1156424 bytes ->Google Chrome cache emptied: 29804553 bytes ->Flash cache emptied: 1046 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2338953 bytes %systemroot%\System32 .tmp files removed: 4386676 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 23062297 bytes RecycleBin emptied: 150 bytes Total Files Cleaned = 2 133,00 mb OTL by OldTimer - Version 3.2.54.0 log created on 07272012_111632 Files\Folders moved on Reboot... File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files... [2012-07-27 11:19:10 | 000,000,000 | ---- | M] () C:\WINDOWS\temp\_avast_\Webshlock.txt : Unable to obtain MD5 Registry entries deleted on Reboot...