All processes killed ========== FILES ========== C:\et3ypes.exe moved successfully. D:\et3ypes.exe moved successfully. E:\et3ypes.exe moved successfully. C:\autorun.inf moved successfully. D:\autorun.inf moved successfully. E:\autorun.inf moved successfully. C:\WINDOWS\System32\mgking0.dll moved successfully. C:\WINDOWS\System32\mgking1.dll moved successfully. C:\WINDOWS\System32\mgking.exe moved successfully. C:\Program Files\VVSN\URL1 folder moved successfully. C:\Program Files\VVSN folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\BabylonToolbar\BabylonToolbar folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\BabylonToolbar folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\GabPath folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\searchplugin folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\META-INF folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\lib folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\defaults folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\components folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\chrome folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b} folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}\searchplugin folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}\META-INF folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}\lib folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}\defaults folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}\components folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}\chrome folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{e8de9422-3b2c-4243-bf6f-235da84d8ef8} folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{b12785f5-d8d0-4530-a3ea-5c4263b85bef}\searchplugin folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{b12785f5-d8d0-4530-a3ea-5c4263b85bef}\META-INF folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{b12785f5-d8d0-4530-a3ea-5c4263b85bef}\lib folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{b12785f5-d8d0-4530-a3ea-5c4263b85bef}\defaults folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{b12785f5-d8d0-4530-a3ea-5c4263b85bef}\components folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{b12785f5-d8d0-4530-a3ea-5c4263b85bef}\chrome folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{b12785f5-d8d0-4530-a3ea-5c4263b85bef} folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5}\searchplugin folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5}\META-INF folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5}\lib folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5}\defaults folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5}\components folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5}\chrome folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5} folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\engine@conduit.com\searchplugin folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\engine@conduit.com\META-INF folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\engine@conduit.com\lib folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\engine@conduit.com\DualPackage folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\engine@conduit.com\defaults folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\engine@conduit.com\components folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\engine@conduit.com\chrome folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\engine@conduit.com folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\ffxtlbr@babylon.com\defaults\preferences folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\ffxtlbr@babylon.com\defaults folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\ffxtlbr@babylon.com\content\imgs folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\ffxtlbr@babylon.com\content folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\ffxtlbr@babylon.com\components folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\ffxtlbr@babylon.com\chrome folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\extensions\ffxtlbr@babylon.com folder moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\searchplugins\conduit.xml moved successfully. C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\v2vncbtt.default\searchplugins\daemon-search.xml moved successfully. C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml moved successfully. C:\Program Files\Mozilla Firefox\components\gpff.dll moved successfully. C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\defaults\preferences folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\defaults folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997} folder moved successfully. C:\Program Files\Surfbar folder moved successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{016EA142-53A1-4DC7-A1F2-4348F0E8E10C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{016EA142-53A1-4DC7-A1F2-4348F0E8E10C}\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2\ deleted successfully. ========== OTL ========== HKU\S-1-5-21-1935655697-630328440-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Restore| /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{b12785f5-d8d0-4530-a3ea-5c4263b85bef} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b12785f5-d8d0-4530-a3ea-5c4263b85bef}\ not found. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{e8de9422-3b2c-4243-bf6f-235da84d8ef8} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}\ deleted successfully. Prefs.js: "Search the web (Babylon)" removed from browser.search.defaultenginename Prefs.js: "ToggleEN Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14676" removed from browser.search.defaulturl Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1 Prefs.js: {1A615EA8-4C56-49EE-BE83-F9A264B79997}:1.0 removed from extensions.enabledItems Prefs.js: {e8de9422-3b2c-4243-bf6f-235da84d8ef8}:2.5.6.0 removed from extensions.enabledItems Prefs.js: {038cb5c7-48ea-4af9-94e0-a1646542e62b}:2.7.2.0 removed from extensions.enabledItems Prefs.js: {b12785f5-d8d0-4530-a3ea-5c4263b85bef}:2.5.6.0 removed from extensions.enabledItems Prefs.js: {d3f4b70a-92e0-4393-a0f3-976d03b1ebf5}:3.1.0.12 removed from extensions.enabledItems Prefs.js: engine@conduit.com:3.1.0.12 removed from extensions.enabledItems Prefs.js: ffxtlbr@babylon.com:1.1.2 removed from extensions.enabledItems Prefs.js: "http://utils.babylon.com/abt/index.php?url=" removed from keyword.URL Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{016EA143-53A1-4DC7-A1F2-4348F0E8E10C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{016EA143-53A1-4DC7-A1F2-4348F0E8E10C}\ deleted successfully. C:\WINDOWS\system32\d778.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{016EA142-53A1-4DC7-A1F2-4348F0E8E10C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{016EA142-53A1-4DC7-A1F2-4348F0E8E10C}\ not found. File C:\WINDOWS\system32\d778.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{b12785f5-d8d0-4530-a3ea-5c4263b85bef} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b12785f5-d8d0-4530-a3ea-5c4263b85bef}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{e8de9422-3b2c-4243-bf6f-235da84d8ef8} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}\ not found. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{016EA142-53A1-4DC7-A1F2-4348F0E8E10C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{016EA142-53A1-4DC7-A1F2-4348F0E8E10C}\ not found. File C:\WINDOWS\system32\d778.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\BabylonToolbar deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\VVSN deleted successfully. File C:\Program Files\VVSN\VVSN.exe not found. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\GabPath deleted successfully. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\king_mg deleted successfully. File C:\WINDOWS\system32\mgking.exe not found. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Windows deleted successfully. C:\WINDOWS\system32\window.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\SfKg6wIPuSp deleted successfully. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\ALLUpdate deleted successfully. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\ares deleted successfully. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\EA Core deleted successfully. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\IVONA ControlCenter deleted successfully. Registry value HKEY_USERS\S-1-5-21-1935655697-630328440-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\RGSC deleted successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User ->Flash cache emptied: 0 bytes User: LocalService User: Mateusz ->Flash cache emptied: 4026 bytes User: NetworkService Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Mateusz ->Temp folder emptied: 11268701 bytes ->Temporary Internet Files folder emptied: 459140 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 97795949 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 262144 bytes RecycleBin emptied: 170282 bytes Total Files Cleaned = 105,00 mb OTL by OldTimer - Version 3.2.17.3 log created on 11162010_205528 Files\Folders moved on Reboot... Registry entries deleted on Reboot...