All processes killed ========== OTL ========== Service upperdev stopped successfully! Service upperdev deleted successfully! File system32\DRIVERS\usbser_lowerflt.sys not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}\ not found. Prefs.js: "Search the web (Babylon)" removed from Backup.old.browser.search.defaultenginename Prefs.js: "http://search.babylon.com/?AF=100480&babsrc=HP_ss&mntrId=b8852620000000000000001d7d9e873d" removed from browser.startup.homepage Prefs.js: "Searchya! Web Search" removed from browser.search.defaultenginename Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1 Prefs.js: "http://searchya.com/?s=0&chnl=tst-214&cd=2XzutAtN2Y1L1QzutDtDtC0DyB0Dzy0EzzyBtA0DtByCtBtDtN0D0TzutBtDtCtBtDyDtCyB&cr=725385200" removed from browser.startup.homepage Prefs.js: "http://search.babylon.com/?AF=100480&babsrc=adbartrp&mntrId=b8852620000000000000001d7d9e873d&q=" removed from keyword.URL Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011441179}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110011441179}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25927741-5E5B-4D27-8D8B-9188FE64373F}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25927741-5E5B-4D27-8D8B-9188FE64373F}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{33AA308B-B565-4376-AC66-59EE9B6AD13E} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33AA308B-B565-4376-AC66-59EE9B6AD13E}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\bcuulervbtbtnuv deleted successfully. C:\Documents and Settings\All Users\Dane aplikacji\bcuulerv.exe moved successfully. Folder move failed. C:\Documents and Settings\All Users\Dane aplikacji\ehgmxrzvbosiawe scheduled to be moved on reboot. C:\Documents and Settings\All Users\Dane aplikacji\jlelsobqddrrhdo moved successfully. C:\Documents and Settings\Paweł\ms.exe moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\skin folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\locale\en-US folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\locale folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\firefox-production\skin folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\firefox-production\locale\en-US folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\firefox-production\locale folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\firefox-production\defaults\preferences folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\firefox-production\defaults folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\firefox-production\chrome\content folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\firefox-production\chrome folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\firefox-production folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\defaults folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\chrome\content folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com\chrome folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\crossriderapp4479@crossrider.com folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\ffxtlbr@babylon.com\defaults\preferences folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\ffxtlbr@babylon.com\defaults folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\ffxtlbr@babylon.com\content\imgs folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\ffxtlbr@babylon.com\content folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\ffxtlbr@babylon.com\components folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\extensions\ffxtlbr@babylon.com folder moved successfully. C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\qu5t18i5.default\searchplugins\Searchya! Web Search.xml moved successfully. C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml moved successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Backup.Old.Start Page deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\Backup.Old.DefaultScope deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\Backup.Old.DefaultScope deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 404176 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Paweł ->Temp folder emptied: 1122869131 bytes ->Temporary Internet Files folder emptied: 16239652 bytes ->Java cache emptied: 3118189 bytes ->FireFox cache emptied: 201725301 bytes ->Flash cache emptied: 202021 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2352022 bytes %systemroot%\System32 .tmp files removed: 2596 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 117615620 bytes RecycleBin emptied: 70357842 bytes Total Files Cleaned = 1 464,00 mb OTL by OldTimer - Version 3.2.57.0 log created on 08162012_230513 Files\Folders moved on Reboot... Folder move failed. C:\Documents and Settings\All Users\Dane aplikacji\ehgmxrzvbosiawe scheduled to be moved on reboot. PendingFileRenameOperations files... File C:\Documents and Settings\All Users\Dane aplikacji\ehgmxrzvbosiawe not found! Registry entries deleted on Reboot...