All processes killed ========== FILES ========== Item C:\ is whitelisted and cannot be moved. File move failed. C:\Documents and Settings\X\Start Menu\Programs\Startup\igfxtray.exe scheduled to be moved on reboot. C:\Documents and Settings\X\Start Menu\Programs\Startup\AutorunsDisabled folder moved successfully. C:\Documents and Settings\X\Application Data\facemoods.com\facemoods folder moved successfully. C:\Documents and Settings\X\Application Data\facemoods.com folder moved successfully. ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-2154615204-4275496255-3731553294-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ not found. Registry value HKEY_USERS\S-1-5-21-2154615204-4275496255-3731553294-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found. Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\c:\program files not found. Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\c:\program files not found. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\File not found not found. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\File not found not found. Starting removal of ActiveX control {00000075-9980-0010-8000-00AA00389B71} C:\WINDOWS\Downloaded Program Files\voxacm.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000075-9980-0010-8000-00AA00389B71}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000075-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{00000075-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000075-9980-0010-8000-00AA00389B71}\ not found. Starting removal of ActiveX control {31435657-9980-0010-8000-00AA00389B71} C:\WINDOWS\Downloaded Program Files\wvc1dmo.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{31435657-9980-0010-8000-00AA00389B71}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. ========== COMMANDS ========== [EMPTYFLASH] User: Administrator User: All Users User: Default User ->Flash cache emptied: 0 bytes User: LocalService User: NetworkService User: Owner User: X ->Flash cache emptied: 45161 bytes Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32835 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Owner User: X ->Temp folder emptied: 418900 bytes ->Temporary Internet Files folder emptied: 59166773 bytes ->Java cache emptied: 4769637 bytes ->Opera cache emptied: 42528366 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 2673152 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 26521408 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 130,00 mb OTL by OldTimer - Version 3.2.22.3 log created on 03262011_103448 Files\Folders moved on Reboot... C:\Documents and Settings\X\Start Menu\Programs\Startup\igfxtray.exe moved successfully. File\Folder C:\Documents and Settings\X\Local Settings\Temp\fla12A8.tmp not found! C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\TG700NYB\0,0[1].htm moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\TEM4JLLA\CAWHEF4D.htm moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\TEM4JLLA\CAZ2EX7V.htm moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\SP2VGDY7\CASHC3OB.php moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\SP2VGDY7\like[5].php moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\RU8NRH8D\CFT0325_093648017FF[1].png moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\RU8NRH8D\search[2].htm moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\OLUF4T6Z\CFT0325_09281315F08[1].png moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\CXQ7W1U7\3417392778-widgets[1].js moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\CXQ7W1U7\CFT0325_092441324CC[1].png moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\CXQ7W1U7\CFT0325_092645111AF[1].png moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\C1ERSHI7\sh36[1].htm moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\9DNRQGI9\fan[1].php moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\9DNRQGI9\login_status[2].htm moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\9DNRQGI9\login_status[3].htm moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\9DNRQGI9\scriptaculous[1].js moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\4LYJGPIN\LikeIt[1].htm moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\456B4HQR\like[2].php moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\456B4HQR\like[3].php moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\456B4HQR\orbit_v2media[1].flv moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\456B4HQR\xd_proxy[1].htm moved successfully. C:\Documents and Settings\X\Local Settings\Temporary Internet Files\Content.IE5\3ZT7ZPSS\276151725-ieretrofit[1].js moved successfully. Registry entries deleted on Reboot...