All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\X3DAudio1_6 deleted successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\5\X3DAudio1_6.exe moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} D:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. ========== FILES ========== D:\Documents and Settings\dragan\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\5 folder moved successfully. D:\Documents and Settings\dragan\Dane aplikacji\hellomoto folder moved successfully. D:\Documents and Settings\dragan\Dane aplikacji\SendSpace folder moved successfully. D:\Documents and Settings\All Users\Dane aplikacji\Premium\Setup folder moved successfully. D:\Documents and Settings\All Users\Dane aplikacji\Premium folder moved successfully. D:\Documents and Settings\All Users\Dane aplikacji\InstallMate\{16782E9C-E344-47BD-A045-B9BA79870632}\5B8857340D7F8010 folder moved successfully. D:\Documents and Settings\All Users\Dane aplikacji\InstallMate\{16782E9C-E344-47BD-A045-B9BA79870632} folder moved successfully. D:\Documents and Settings\All Users\Dane aplikacji\InstallMate folder moved successfully. D:\user.js moved successfully. ========== REGISTRY ========== HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 356570 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56466 bytes User: dragan ->Temp folder emptied: 555772 bytes ->Temporary Internet Files folder emptied: 79640285 bytes ->Java cache emptied: 977424 bytes ->Flash cache emptied: 18004680 bytes User: LocalService ->Temporary Internet Files folder emptied: 33177 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 678985 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2508201 bytes %systemroot%\System32 .tmp files removed: 2596 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 36303936 bytes RecycleBin emptied: 3321725458 bytes Total Files Cleaned = 3 301,00 mb OTL by OldTimer - Version 3.2.58.1 log created on 08252012_152845 Files\Folders moved on Reboot... D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z8S193FS\ox_iframe[1].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z8S193FS\trojmiasto_pl[1].txt moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1RYZGDH\fastbutton[2].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1RYZGDH\ox_iframe[1].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1RYZGDH\ox_iframe[2].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1RYZGDH\ox_iframe[3].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1RYZGDH\ox_iframe[4].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1RYZGDH\search_incredibar_com[1].txt moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1RYZGDH\tv_wp_pl[1].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1RYZGDH\xd_arbiter[2].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\U1RYZGDH\xd_arbiter[3].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\TRZOYZL8\oauth[1].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\TRZOYZL8\ox_iframe[1].htm moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\R8QS3B1Q\12113-wirus-ucash-zakrywajacy-pulpit-po-starcie-systemu-raport-otl[1].txt moved successfully. D:\Documents and Settings\dragan\Ustawienia lokalne\Temporary Internet Files\Content.IE5\R8QS3B1Q\ox_iframe[1].htm moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot...