All processes killed ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-1275210071-630328440-725345543-1003_Classes\exefile\shell\open\command\\'' updated successfully. File "C:\Documents and Settings\OEM\Ustawienia lokalne\Dane aplikacji\rpf.exe" -a "%1" %* not found. Registry key HKEY_USERS\S-1-5-21-1275210071-630328440-725345543-1003_Classes\.exe\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-1275210071-630328440-725345543-1003_Classes\exefile\ deleted successfully. HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully! C:\Documents and Settings\All Users\Dane aplikacji\kwtd246lfs3h331o70m8o0w3 moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0626A63-410B-45E2-99A1-3F2475B2D695}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F0626A63-410B-45E2-99A1-3F2475B2D695}\ deleted successfully. C:\Program Files\SGPSA\BHO.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ deleted successfully. C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\ deleted successfully. File C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll not found. Registry value HKEY_USERS\S-1-5-21-1275210071-630328440-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\ not found. File C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll not found. Registry value HKEY_USERS\S-1-5-21-1275210071-630328440-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\ not found. File C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\FBSearch deleted successfully. C:\Program Files\Search Guard Plus\SearchGuardPlus.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SGPUpdater deleted successfully. C:\Program Files\Search Guard PlusU\sgpUpdaters.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully. Registry value HKEY_USERS\S-1-5-21-1275210071-630328440-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Gadu-Gadu deleted successfully. Registry value HKEY_USERS\S-1-5-21-1275210071-630328440-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Komunikator deleted successfully. Registry value HKEY_USERS\S-1-5-21-1275210071-630328440-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Picasa Media Detector deleted successfully. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\4\ deleted successfully. File "http://s.ytimg.com/yt/jsbin/www-core-vfl135925.js" not found. C:\Documents and Settings\All Users\Dane aplikacji\2D33C folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Kazaa Lite\db folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Kazaa Lite folder moved successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2\ deleted successfully. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYFLASH] User: All Users User: Default User User: LocalService User: NetworkService User: OEM ->Flash cache emptied: 114711 bytes Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 82513 bytes ->Temporary Internet Files folder emptied: 32969 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: OEM ->Temp folder emptied: 939691534 bytes ->Temporary Internet Files folder emptied: 64821450 bytes ->Java cache emptied: 1185691 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 3233973 bytes %systemroot%\System32 .tmp files removed: 2596 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 20780279 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 982,00 mb OTL by OldTimer - Version 3.2.23.0 log created on 06212011_180225 Files\Folders moved on Reboot... File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot...