All processes killed ========== OTL ========== wgqmgxcju removed from NetSvcs value successfully! Service wgqmgxcju stopped successfully! Service wgqmgxcju deleted successfully! File move failed. C:\WINDOWS\system32\ucjplzy.dll scheduled to be moved on reboot. File move failed. C:\WINDOWS\system32\ucjplzy.dll scheduled to be moved on reboot. D:\AUTORUN.INF moved successfully. Service ATE_PROCMON stopped successfully! Service ATE_PROCMON deleted successfully! File C:\Program Files\Anti Trojan Elite\ATEPMon.sys not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Anti Trojan Elite deleted successfully. C:\Program Files\Anti Trojan Elite\TJEnder.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:MACHINE BootExecut deleted successfully. HKU\S-1-5-21-1454471165-1801674531-1606980848-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Prefs.js: "iMesh Web Search" removed from browser.search.defaultenginename Prefs.js: "iMesh Web Search" removed from browser.search.order.1 Prefs.js: "http://search.imesh.com/webResults.html?src=ffb&q=" removed from keyword.URL C:\Documents and Settings\Żaneta\Dane aplikacji\Mozilla\Firefox\Profiles\wbnfb2k3.default\searchplugins\iMeshWebSearch.xml moved successfully. C:\Program Files\Mozilla Firefox\searchplugins\iMeshWebSearch.xml moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Fighters\SLOW-PCfighter\LOGS folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Fighters\SLOW-PCfighter\Backup folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Fighters\SLOW-PCfighter folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Fighters folder moved successfully. C:\Documents and Settings\Żaneta\Dane aplikacji\Fighters\SWPRO folder moved successfully. C:\Documents and Settings\Żaneta\Dane aplikacji\Fighters folder moved successfully. C:\Documents and Settings\Żaneta\Dane aplikacji\Simply Super Software\Trojan Remover folder moved successfully. C:\Documents and Settings\Żaneta\Dane aplikacji\Simply Super Software folder moved successfully. C:\WINDOWS\Tasks\SLOW-PCfighter-Żaneta-Startup.job moved successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{474597C5-AB09-49d6-A4D5-2E8D7341384E}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\4921:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\iMesh Applications\iMesh\iMesh.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\BearShare Applications\BearShare\BearShare.exe deleted successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User User: LocalService User: NetworkService User: Żaneta ->Flash cache emptied: 24421 bytes Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 33850 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Żaneta ->Temp folder emptied: 459517162 bytes ->Temporary Internet Files folder emptied: 373903174 bytes ->FireFox cache emptied: 36562502 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2352022 bytes %systemroot%\System32 .tmp files removed: 2596 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 71472060 bytes RecycleBin emptied: 708222447 bytes Total Files Cleaned = 1 576,00 mb OTL by OldTimer - Version 3.2.9.1 log created on 08042010_131033 Files\Folders moved on Reboot... C:\WINDOWS\system32\ucjplzy.dll moved successfully. File\Folder C:\Documents and Settings\Żaneta\Ustawienia lokalne\Temp\~DF320B.tmp not found! File\Folder C:\Documents and Settings\Żaneta\Ustawienia lokalne\Temp\~DF3218.tmp not found! File\Folder C:\Documents and Settings\Żaneta\Ustawienia lokalne\Temp\~DF32A4.tmp not found! File\Folder C:\Documents and Settings\Żaneta\Ustawienia lokalne\Temp\~DF32B1.tmp not found! File\Folder C:\Documents and Settings\Żaneta\Ustawienia lokalne\Temp\~DF33B5.tmp not found! File\Folder C:\Documents and Settings\Żaneta\Ustawienia lokalne\Temp\~DF33C5.tmp not found! C:\Documents and Settings\Żaneta\Ustawienia lokalne\Temporary Internet Files\Content.IE5\X5BWQP5V\ads[1].htm moved successfully. C:\Documents and Settings\Żaneta\Ustawienia lokalne\Temporary Internet Files\Content.IE5\X5BWQP5V\index[2].htm moved successfully. C:\Documents and Settings\Żaneta\Ustawienia lokalne\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. Registry entries deleted on Reboot...