All processes killed ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-3155688213-1898257628-214738319-1004\Software\Microsoft\Windows\CurrentVersion\RunOnce\\036DFF6102E0BE37DED8EF172F3B707C deleted successfully. C:\ProgramData\036DFF6102E0BE37DED8EF172F3B707C\036DFF6102E0BE37DED8EF172F3B707C.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-3155688213-1898257628-214738319-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HideSCAHealth deleted successfully. ========== FILES ========== C:\ProgramData\036DFF6102E0BE37DED8EF172F3B707C folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Monika ->Temp folder emptied: 748634304 bytes ->Temporary Internet Files folder emptied: 111194932 bytes ->Java cache emptied: 69468 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 14266 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 6129526 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 83975 bytes %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 743 bytes RecycleBin emptied: 602707174 bytes Total Files Cleaned = 1 401,00 mb OTL by OldTimer - Version 3.2.59.1 log created on 08282012_103945 Files\Folders moved on Reboot... C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XCI58NGB\20120731_boxright[1].htm moved successfully. C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XCI58NGB\6788-tworzenie-logow-i-korzystanie-ze-skryptow-w-otl[2].htm moved successfully. File\Folder C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XCI58NGB\like[1].htm not found! File\Folder C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XCI58NGB\oauth[1].htm not found! C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XCI58NGB\xd_arbiter[1].htm moved successfully. File\Folder C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3N4BSB3V\poczta_onet_pl[1].htm not found! File\Folder C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\02XZA91P\12180-zaatakowal-mnie-wirus-security-platinum[1].htm not found! C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\02XZA91P\adtop[1].htm moved successfully. File\Folder C:\Users\Monika\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\02XZA91P\zegarki[1].htm not found! PendingFileRenameOperations files... Registry entries deleted on Reboot...