All processes killed ========== OTL ========== Prefs.js: "Web Search" removed from browser.search.defaultengine Prefs.js: "Web Search" removed from browser.search.defaultenginename Prefs.js: "Web Search" removed from browser.search.order.1 Prefs.js: "megaup" removed from browser.search.param.yahoo-fr Prefs.js: "megaup" removed from browser.search.param.yahoo-fr-cjkt Prefs.js: {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.8.1.4690 removed from extensions.enabledItems Prefs.js: {7AB6D133-2A14-4C11-B3AD-35B1548D38F9}:1.0 removed from extensions.enabledItems Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-2000478354-1214440339-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry value HKEY_USERS\S-1-5-21-2000478354-1214440339-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F364306-AA45-47B5-9F9D-39A8B94E7EF1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F364306-AA45-47B5-9F9D-39A8B94E7EF1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-2000478354-1214440339-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ not found. Registry value HKEY_USERS\S-1-5-21-2000478354-1214440339-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\termmgr deleted successfully. C:\Documents and Settings\Dom\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\4958\termmgr.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KodakShareButtonApp deleted successfully. Registry value HKEY_USERS\S-1-5-21-2000478354-1214440339-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\AbyssWebServer deleted successfully. Registry value HKEY_USERS\S-1-5-21-2000478354-1214440339-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully. C:\Documents and Settings\Dom\Menu Start\Programy\Autostart\Rozmowa.lnk moved successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Download All by FlashGet\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Download by FlashGet\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ deleted successfully. File {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found. File {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File not found not found. Service mi-raysat_3dsmax2011_32 stopped successfully! Service mi-raysat_3dsmax2011_32 deleted successfully! File C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe not found. Service PEVSystemStart stopped successfully! Service PEVSystemStart deleted successfully! C:\ComboFix\pev.3XE moved successfully. Service XDva120 stopped successfully! Service XDva120 deleted successfully! File C:\WINDOWS\system32\XDva120.sys not found. Service st3mp28 stopped successfully! Service st3mp28 deleted successfully! File system32\DRIVERS\st3mp28.sys not found. Service rtl8139 stopped successfully! Service rtl8139 deleted successfully! File system32\DRIVERS\RTL8139.SYS not found. Service GMSIPCI stopped successfully! Service GMSIPCI deleted successfully! File F:\INSTALL\GMSIPCI.SYS not found. Service EagleNT stopped successfully! Service EagleNT deleted successfully! File C:\WINDOWS\system32\drivers\EagleNT.sys not found. Service autorun stopped successfully! Service autorun deleted successfully! File c:\huadio.tmp not found. Service ATE_PROCMON stopped successfully! Service ATE_PROCMON deleted successfully! File E:\Anti Trojan Elite\ATEPMon.sys not found. Service ASFWHide stopped successfully! Service ASFWHide deleted successfully! File C:\DOCUME~1\Dom\USTAWI~1\Temp\ASFWHide not found. Service Amps2prt stopped successfully! Service Amps2prt deleted successfully! File system32\DRIVERS\Amps2prt.sys not found. Service AKEProtect stopped successfully! Service AKEProtect deleted successfully! File D:\GryAdam\Anti Keylogger Elite\AKEProtect.sys not found. ========== FILES ========== C:\Documents and Settings\Dom\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\4958 folder moved successfully. C:\Documents and Settings\Dom\Dane aplikacji\hellomoto folder moved successfully. C:\Documents and Settings\Dom\Dane aplikacji\ErrorSmart\Log folder moved successfully. C:\Documents and Settings\Dom\Dane aplikacji\ErrorSmart folder moved successfully. C:\Documents and Settings\Dom\Dane aplikacji\OpenCandy\OpenCandy_B0E04949EDD441B595DC6857254DA9DB folder moved successfully. C:\Documents and Settings\Dom\Dane aplikacji\OpenCandy\OpenCandy_10719B1082A94A33976A2C50B6EC02F8 folder moved successfully. C:\Documents and Settings\Dom\Dane aplikacji\OpenCandy folder moved successfully. C:\Documents and Settings\Dom\Dane aplikacji\Mozilla\Firefox\Profiles\5p6djy37.default\searchplugins\startsear.xml moved successfully. C:\Program Files\Mozilla Firefox\extensions\{7AB6D133-2A14-4C11-B3AD-35B1548D38F9}\defaults\preferences folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{7AB6D133-2A14-4C11-B3AD-35B1548D38F9}\defaults folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{7AB6D133-2A14-4C11-B3AD-35B1548D38F9}\chrome folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{7AB6D133-2A14-4C11-B3AD-35B1548D38F9} folder moved successfully. C:\Program Files\Internet Saving Optimizer\3.8.1.4690\FF\components folder moved successfully. C:\Program Files\Internet Saving Optimizer\3.8.1.4690\FF\chrome\content folder moved successfully. C:\Program Files\Internet Saving Optimizer\3.8.1.4690\FF\chrome folder moved successfully. C:\Program Files\Internet Saving Optimizer\3.8.1.4690\FF folder moved successfully. C:\Program Files\Internet Saving Optimizer\3.8.1.4690\Data folder moved successfully. C:\Program Files\Internet Saving Optimizer\3.8.1.4690 folder moved successfully. C:\Program Files\Internet Saving Optimizer folder moved successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\components folder moved successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\chrome\content folder moved successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\chrome folder moved successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF folder moved successfully. C:\Program Files\Media Access Startup\2.0.0.1050\Data folder moved successfully. C:\Program Files\Media Access Startup\2.0.0.1050 folder moved successfully. C:\Program Files\Media Access Startup folder moved successfully. C:\WINDOWS\tasks\AF6BFF9991847121.job moved successfully. C:\FOUND.000 folder moved successfully. C:\FOUND.001 folder moved successfully. C:\FOUND.004 folder moved successfully. C:\FOUND.005 folder moved successfully. C:\FOUND.006 folder moved successfully. C:\FOUND.002 folder moved successfully. C:\FOUND.007 folder moved successfully. C:\FOUND.003 folder moved successfully. C:\FOUND.008 folder moved successfully. C:\FOUND.009 folder moved successfully. [color=#A23BEC]< netsh firewall reset /C >[/color] Ok. H:\2004 - Street's Disciple\cmd.bat deleted successfully. H:\2004 - Street's Disciple\cmd.txt deleted successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2\ deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{395AD2D6-DCA7-4906-AFF0-69ED094EF016}" /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{395AD2D6-DCA7-4906-AFF0-69ED094EF016}" /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\\{2224E955-00E9-4613-A844-CE69FCCAAE91} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2224E955-00E9-4613-A844-CE69FCCAAE91}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Dom ->Temp folder emptied: 236417 bytes ->Temporary Internet Files folder emptied: 34257 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 66682313 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 492 bytes User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 32768 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 64.00 mb OTL by OldTimer - Version 3.2.54.1 log created on 07262012_095022 Files\Folders moved on Reboot... C:\WINDOWS\temp\Perflib_Perfdata_670.dat moved successfully. PendingFileRenameOperations files... File C:\WINDOWS\temp\Perflib_Perfdata_670.dat not found! Registry entries deleted on Reboot...