========== OTL ========== Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WDICA deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PDRFRAME deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PDRELI deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PDFRAME deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PDCOMP deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCIDump deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lbrtfdc deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i2omgmt deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Changer deleted successfully. Prefs.js: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825 removed from extensions.enabledItems Prefs.js: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6.1 removed from extensions.enabledItems Prefs.js: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102 removed from extensions.enabledItems Prefs.js: Zango@Zango.com:10.3.75.0 removed from extensions.enabledItems Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\Zango@Zango.com deleted successfully. C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions\plugins folder moved successfully. C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions\components folder moved successfully. C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{100EB1FD-D03E-47FD-81F3-EE91287F9465}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}\ deleted successfully. C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}\ not found. File C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll not found. Registry value HKEY_USERS\Administrator_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}\ not found. File C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CnxDslTaskBar deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\juquagoz deleted successfully. C:\WINDOWS\system32\koowe.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LanguageShortcut deleted successfully. C:\Program Files\CyberLink\PowerDVD\Language\Language.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Services deleted successfully. C:\WINDOWS\system32\System.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\userini deleted successfully. C:\WINDOWS\system32\userini.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Windows deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Firewall deleted successfully. C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\lsass.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ZangoOE deleted successfully. C:\Program Files\Zango\bin\10.3.75.0\OEAddOn.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ZangoSA deleted successfully. C:\Program Files\Zango\bin\10.3.75.0\ZangoSA.exe moved successfully. Registry value HKEY_USERS\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\userini deleted successfully. File C:\WINDOWS\system32\userini.exe not found. Registry value HKEY_USERS\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\WeatherDPA deleted successfully. C:\Program Files\Zango\bin\10.3.75.0\Weather.exe moved successfully. Registry value HKEY_USERS\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Firewall deleted successfully. File C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\lsass.exe not found. Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\nltide_2 deleted successfully. Registry value HKEY_USERS\LocalService_ON_C\Software\Microsoft\Windows\CurrentVersion\RunOnce\\nltide_2 deleted successfully. Registry value HKEY_USERS\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\RunOnce\\nltide_2 deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\userini deleted successfully. File C:\WINDOWS\system32\userini.exe not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5428486-50A0-4a02-9D20-520B59A9F9B2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5428486-50A0-4a02-9D20-520B59A9F9B3}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:rundll32.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:rrrc.yeo deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:upptdvf deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\TaskMan:C:\Documents and Settings\Administrator\Dane aplikacji\yjty.exe deleted successfully. C:\Documents and Settings\Administrator\Dane aplikacji\yjty.exe moved successfully. Registry value HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Administrator\msgvn.exe deleted successfully. Registry value HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Administrator\Dane aplikacji\yjty.exe deleted successfully. Registry value HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Administrator\Dane aplikacji\qmkin.exe deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent\ deleted successfully. File C:\WINDOWS\System32\ati2evxx.dll not found. C:\AUTOEXEC.BAT moved successfully. File move failed. X:\AUTORUN.INF scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{36882b20-e3f1-11dd-9042-0011d810ef84}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36882b20-e3f1-11dd-9042-0011d810ef84}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eeeb6462-5524-11de-9133-0011d810ef84}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{eeeb6462-5524-11de-9133-0011d810ef84}\ not found. File G:\setupSNK.exe not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully. ========== FILES ========== C:\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll moved successfully. C:\WINDOWS\System32\vynounno.exe moved successfully. C:\Documents and Settings\Administrator\msgvn.exe moved successfully. File\Folder C:\WINDOWS\System32\koowe.exe not found. C:\Documents and Settings\Administrator\startup.reg moved successfully. File\Folder C:\WINDOWS\System32\userini.exe not found. C:\Documents and Settings\Administrator\Dane aplikacji\.# folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\HostOI\static\2 folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\HostOI\static\1 folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\HostOI\static\DownLoad folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\HostOI\static folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\HostOI\dynamic folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\HostOI folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\HostOL\static folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\HostOL\dynamic folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\HostOL folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\Zango\dynamic\TooltipXML folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\Zango\dynamic\ustat folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\Zango\dynamic folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\Zango\static\2 folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\Zango\static\DownLoad folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\Zango\static\1 folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\Zango\static folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0\Zango folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\v3.0 folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango\IESkins folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Zango folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\ShoppingReport\cs\res1 folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\ShoppingReport\cs\db folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\ShoppingReport\cs\report folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\ShoppingReport\cs\dwld folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\ShoppingReport\cs folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\ShoppingReport folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\InterTrust\ReceiptRepository folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\InterTrust folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\foobar2000\playlists folder moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\foobar2000 folder moved successfully. OTLPE by OldTimer - Version 3.1.39.0 log created on 08182010_171249