All processes killed ========== FILES ========== C:\RECYCLER\S-1-5-21-1275210071-220523388-839522115-1003 folder moved successfully. C:\RECYCLER\2010-04-15 folder moved successfully. C:\RECYCLER\2010-04-14 folder moved successfully. C:\RECYCLER folder moved successfully. E:\RECYCLER\S-1-5-21-1275210071-220523388-839522115-1003 folder moved successfully. E:\RECYCLER folder moved successfully. F:\RECYCLER\S-1-5-21-1275210071-220523388-839522115-1003 folder moved successfully. F:\RECYCLER folder moved successfully. I:\RECYCLER\S-1-5-21-1275210071-220523388-839522115-1003 folder moved successfully. I:\RECYCLER folder moved successfully. w9.exe not found in C:\ E:\w9.exe moved successfully. F:\w9.exe moved successfully. I:\w9.exe moved successfully. yveqsh93.exe not found in C:\ E:\yveqsh93.exe moved successfully. F:\yveqsh93.exe moved successfully. I:\yveqsh93.exe moved successfully. i00dvoym.exe not found in C:\ E:\i00dvoym.exe moved successfully. F:\i00dvoym.exe moved successfully. I:\i00dvoym.exe moved successfully. et3ypes.exe not found in C:\ E:\et3ypes.exe moved successfully. F:\et3ypes.exe moved successfully. I:\et3ypes.exe moved successfully. awrkn3g0.exe not found in C:\ E:\awrkn3g0.exe moved successfully. F:\awrkn3g0.exe moved successfully. I:\awrkn3g0.exe moved successfully. bud3mkqr.exe not found in C:\ E:\bud3mkqr.exe moved successfully. F:\bud3mkqr.exe moved successfully. I:\bud3mkqr.exe moved successfully. cbbw88s.exe not found in C:\ E:\cbbw88s.exe moved successfully. F:\cbbw88s.exe moved successfully. I:\cbbw88s.exe moved successfully. dwh.exe not found in C:\ E:\dwh.exe moved successfully. F:\dwh.exe moved successfully. I:\dwh.exe moved successfully. egmjjb.exe not found in C:\ E:\egmjjb.exe moved successfully. F:\egmjjb.exe moved successfully. I:\egmjjb.exe moved successfully. l10.exe not found in C:\ E:\l10.exe moved successfully. F:\l10.exe moved successfully. I:\l10.exe moved successfully. 9keibj.exe not found in C:\ E:\9keibj.exe moved successfully. F:\9keibj.exe moved successfully. I:\9keibj.exe moved successfully. b9v.exe not found in C:\ E:\b9v.exe moved successfully. F:\b9v.exe moved successfully. I:\b9v.exe moved successfully. x2hjdx.exe not found in C:\ E:\x2hjdx.exe moved successfully. F:\x2hjdx.exe moved successfully. I:\x2hjdx.exe moved successfully. tscl.exe not found in C:\ E:\tscl.exe moved successfully. F:\tscl.exe moved successfully. I:\tscl.exe moved successfully. lpl.exe not found in C:\ E:\lpl.exe moved successfully. F:\lpl.exe moved successfully. I:\lpl.exe moved successfully. r3q63rok.exe not found in C:\ E:\r3q63rok.exe moved successfully. F:\r3q63rok.exe moved successfully. I:\r3q63rok.exe moved successfully. jofk1wf.exe not found in C:\ E:\jofk1wf.exe moved successfully. F:\jofk1wf.exe moved successfully. I:\jofk1wf.exe moved successfully. o1o.exe not found in C:\ E:\o1o.exe moved successfully. F:\o1o.exe moved successfully. I:\o1o.exe moved successfully. wq.exe not found in C:\ E:\wq.exe moved successfully. F:\wq.exe moved successfully. I:\wq.exe moved successfully. kyme.exe not found in C:\ E:\kyme.exe moved successfully. F:\kyme.exe moved successfully. I:\kyme.exe moved successfully. h3wp9.exe not found in C:\ E:\h3wp9.exe moved successfully. F:\h3wp9.exe moved successfully. I:\h3wp9.exe moved successfully. io3yalc.exe not found in C:\ E:\io3yalc.exe moved successfully. F:\io3yalc.exe moved successfully. I:\io3yalc.exe moved successfully. C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job moved successfully. C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job moved successfully. C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job moved successfully. C:\WINDOWS\tasks\rzdlvvmvlf.job moved successfully. C:\WINDOWS\System32\drivers\str.sys moved successfully. File\Folder C:\WINDOWS\System32\arking.exe not found. C:\WINDOWS\System32\arking1.dll moved successfully. File\Folder C:\WINDOWS\System32\arking0.dll not found. File\Folder C:\WINDOWS\System32\mgking1.dll not found. C:\WINDOWS\System32\mmcshext5.dll moved successfully. File\Folder C:\WINDOWS\System32\dll.dll not found. C:\WINDOWS\System32\secustat.dat moved successfully. C:\WINDOWS\System32\secushr.dat moved successfully. C:\WINDOWS\System32\crt.dat moved successfully. C:\Documents and Settings\Michał\Dane aplikacji\Mozilla\Firefox\Profiles\pzp7w9uj.default\searchplugins\daemon-search.xml moved successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet32\ deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Userinit"|"C:\\WINDOWS\\system32\\userinit.exe," /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\UserFaultCheck deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\dso32 deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\King_ar deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\\"SuperHidden"|dword:00000001 /E : value set successfully! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\\"Hidden"|dword:00000001 /E : value set successfully! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\\"ShowSuperHidden"|dword:00000001 /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\\"CheckedValue"|dword:00000001 /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden\ deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden\\@|"" /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\RECYCLER\services.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\system.exe deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! ========== OTL ========== Prefs.js: "Search the web (Babylon)" removed from browser.search.defaultenginename Prefs.js: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627" removed from browser.search.defaulturl Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1 Prefs.js: "http://search.babylon.com/?babsrc=adbartrp&AF=15627&q=" removed from keyword.URL File oft XML Parser for Java "file://C:\WINDOWS\Java\classes\xmldso.cab" not found. Starting removal of ActiveX control Microsoft XML Parser for Java " Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java "\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java "\ not found. ========== COMMANDS ========== [EMPTYFLASH] User: Administrator ->Flash cache emptied: 0 bytes User: All Users User: Default User ->Flash cache emptied: 0 bytes User: LocalService User: Micha User: Michał ->Flash cache emptied: 7046 bytes User: NetworkService Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 65984 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Micha ->Temp folder emptied: 0 bytes User: Michał ->Temp folder emptied: 1837605 bytes ->Temporary Internet Files folder emptied: 13780188 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 79573001 bytes ->Google Chrome cache emptied: 557424 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 91,00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04152011_204519 Files\Folders moved on Reboot... Registry entries deleted on Reboot...