All processes killed ========== OTL ========== Prefs.js: "Web Search" removed from browser.search.defaultengine Prefs.js: "Web Search" removed from browser.search.defaultenginename Prefs.js: "Web Search" removed from browser.search.order.1 Prefs.js: "Web Search" removed from browser.search.selectedEngine Prefs.js: "http://startsear.ch/?aff=1&cf=06bc2f2c-3af6-11e1-aabe-001c26da7d33" removed from browser.startup.homepage Prefs.js: "http://startsear.ch/?aff=1&src=sp&cf=4769afd2-0242-11e1-aab9-001c26da7d33&q=" removed from keyword.URL Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{637DAFAB-6E55-4875-9952-826E0F1A1512}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{637DAFAB-6E55-4875-9952-826E0F1A1512}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found. Registry key HKEY_USERS\S-1-5-21-1334700489-3378039773-1944074608-1005\Software\Microsoft\Internet Explorer\SearchScopes\{72CAF6C8-ECA3-4E58-BDDE-87804242141C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72CAF6C8-ECA3-4E58-BDDE-87804242141C}\ not found. Registry key HKEY_USERS\S-1-5-21-1334700489-3378039773-1944074608-1005\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\avast5 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ivrcxcmnqprwplg deleted successfully. C:\Documents and Settings\All Users\Dane aplikacji\ivrcxcmn.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UserFaultCheck deleted successfully. Registry value HKEY_USERS\S-1-5-21-1334700489-3378039773-1944074608-1005\Software\Microsoft\Windows\CurrentVersion\Run\\feedreader.exe deleted successfully. Registry value HKEY_USERS\S-1-5-21-1334700489-3378039773-1944074608-1005\Software\Microsoft\Windows\CurrentVersion\Run\\ivrcxcmnqprwplg deleted successfully. File C:\Documents and Settings\All Users\Dane aplikacji\ivrcxcmn.exe not found. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Service UIUSys stopped successfully! Service UIUSys deleted successfully! File system32\DRIVERS\UIUSYS.SYS not found. Service PID_0928 stopped successfully! Service PID_0928 deleted successfully! File system32\DRIVERS\LV561AV.SYS not found. Service LVUSBSta stopped successfully! Service LVUSBSta deleted successfully! File system32\drivers\lvusbsta.sys not found. Service hwdatacard stopped successfully! Service hwdatacard deleted successfully! File system32\DRIVERS\ewusbmdm.sys not found. ========== FILES ========== C:\Documents and Settings\All Users\Dane aplikacji\kehbyysaibpavin moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\hmlkftuvqkkzahf folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\ipbswhxh.exe moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\pdskigbl.exe moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\qngsyxvu.exe moved successfully. C:\Documents and Settings\lenovo\ms.exe moved successfully. C:\Documents and Settings\lenovo\Dane aplikacji\Mozilla\Firefox\Profiles\uks75mcn.default\searchplugins\startsear.xml moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Wru folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\spool\suspic folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\spool folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\SpamConf folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\sounds\1045 folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\sounds folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\report folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\moved folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\log folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\journal folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\integ folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\HtmlData folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\fw folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\chest folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\backup folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\arpot\TEMP folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5\arpot folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software\Avast5 folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\ESET\ESET Smart Security folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\ESET folder moved successfully. C:\Documents and Settings\Gość\Dane aplikacji\ESET\ESET Smart Security\Antispam folder moved successfully. C:\Documents and Settings\Gość\Dane aplikacji\ESET\ESET Smart Security folder moved successfully. C:\Documents and Settings\Gość\Dane aplikacji\ESET folder moved successfully. C:\Documents and Settings\lenovo\Dane aplikacji\ESET\ESET Smart Security\Antispam folder moved successfully. C:\Documents and Settings\lenovo\Dane aplikacji\ESET\ESET Smart Security folder moved successfully. C:\Documents and Settings\lenovo\Dane aplikacji\ESET folder moved successfully. C:\WINDOWS\Tasks\NSSstub.job moved successfully. ========== REGISTRY ========== HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully! Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Wru\Wru.exe deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 296537 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->FireFox cache emptied: 3433759 bytes User: All Users User: Default User ->Temp folder emptied: 294912 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: Gość ->Temp folder emptied: 317357 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->FireFox cache emptied: 9372752 bytes ->Flash cache emptied: 405 bytes User: lenovo ->Temp folder emptied: 2015316241 bytes ->Temporary Internet Files folder emptied: 1164366668 bytes ->Java cache emptied: 2721920 bytes ->FireFox cache emptied: 55572389 bytes ->Flash cache emptied: 3022349 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 690066 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 23993 bytes %systemroot%\System32 .tmp files removed: 2379676 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 74883760 bytes RecycleBin emptied: 41138789 bytes Total Files Cleaned = 3 218,00 mb OTL by OldTimer - Version 3.2.54.0 log created on 07162012_150630 Files\Folders moved on Reboot... File\Folder C:\WINDOWS\temp\TMP00000001E5F22F6F42E29ED6 not found! PendingFileRenameOperations files... File C:\WINDOWS\temp\TMP00000001E5F22F6F42E29ED6 not found! Registry entries deleted on Reboot...