All processes killed ========== OTL ========== Service gupdatem stopped successfully! Service gupdatem deleted successfully! File C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc not found. Service gupdate stopped successfully! Service gupdate deleted successfully! File C:\Program Files\Google\Update\GoogleUpdate.exe /svc not found. Service Pcouffin stopped successfully! Service Pcouffin deleted successfully! File System32\Drivers\Pcouffin.sys not found. Service InCDRm stopped successfully! Service InCDRm deleted successfully! File system32\drivers\InCDRm.sys not found. Service InCDPass stopped successfully! Service InCDPass deleted successfully! File system32\drivers\InCDPass.sys not found. Service InCDFs stopped successfully! Service InCDFs deleted successfully! File system32\drivers\InCDFs.sys not found. Service hwusbfake stopped successfully! Service hwusbfake deleted successfully! File system32\DRIVERS\ewusbfake.sys not found. Service hwdatacard stopped successfully! Service hwdatacard deleted successfully! File system32\DRIVERS\ewusbmdm.sys not found. Service cpuz130 stopped successfully! Service cpuz130 deleted successfully! File C:\DOCUME~1\Agata\USTAWI~1\Temp\cpuz130\cpuz_x32.sys not found. Service catchme stopped successfully! Service catchme deleted successfully! File C:\ComboFix\catchme.sys not found. HKU\S-1-5-21-507921405-1275210071-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully! HKU\S-1-5-21-507921405-1275210071-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully! HKU\S-1-5-21-507921405-1275210071-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully! HKU\S-1-5-21-507921405-1275210071-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{259F616C-A300-44F5-B04A-ED001A26C85C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{259F616C-A300-44F5-B04A-ED001A26C85C}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-507921405-1275210071-1801674531-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_USERS\S-1-5-21-507921405-1275210071-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\META-INF folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\defaults\preferences folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\defaults folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\chrome\skin folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\fr-FR folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\es-ES folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\en-US folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\de-DE folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\chrome\locale folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\chrome\content folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org\chrome folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\cacaoweb@cacaoweb.org folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\crossriderapp4479@crossrider.com\skin folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\crossriderapp4479@crossrider.com\locale\en-US folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\crossriderapp4479@crossrider.com\locale folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\crossriderapp4479@crossrider.com\defaults\preferences folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\crossriderapp4479@crossrider.com\defaults folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\crossriderapp4479@crossrider.com\chrome\content folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\crossriderapp4479@crossrider.com\chrome folder moved successfully. C:\Documents and Settings\Agata\Dane aplikacji\Mozilla\Firefox\Profiles\4ios87jl.default\extensions\crossriderapp4479@crossrider.com folder moved successfully. C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Config.nt.bak moved successfully. C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Autoexec.nt.bak moved successfully. C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\hosts.bak moved successfully. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Administrator.DOM ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Agata ->Temp folder emptied: 1590058085 bytes ->Temporary Internet Files folder emptied: 16714576 bytes ->Java cache emptied: 24471217 bytes ->FireFox cache emptied: 104835836 bytes ->Google Chrome cache emptied: 7534377 bytes ->Opera cache emptied: 0 bytes ->Flash cache emptied: 2849603 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56478 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33111 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2352022 bytes %systemroot%\System32 .tmp files removed: 2832932 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 7892938280 bytes RecycleBin emptied: 1664983 bytes Total Files Cleaned = 9 200,00 mb OTL by OldTimer - Version 3.2.59.1 log created on 08292012_195427 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot...