All processes killed ========== OTL ========== Service ZDPNDIS5 stopped successfully! Service ZDPNDIS5 deleted successfully! File C:\WINDOWS\system32\ZDPNDIS5.SYS not found. Service ZDCndis5 stopped successfully! Service ZDCndis5 deleted successfully! File C:\WINDOWS\system32\ZDCndis5.SYS not found. Service videX32 stopped successfully! Service videX32 deleted successfully! File system32\DRIVERS\videX32.sys not found. Service viagfx stopped successfully! Service viagfx deleted successfully! File system32\DRIVERS\vtmini.sys not found. Service SenFiltService stopped successfully! Service SenFiltService deleted successfully! File system32\drivers\Senfilt.sys not found. Service PCANDIS5 stopped successfully! Service PCANDIS5 deleted successfully! File C:\WINDOWS\system32\PCANDIS5.SYS not found. Service AEAudioService stopped successfully! Service AEAudioService deleted successfully! File system32\drivers\AEAudio.sys not found. Service ADIHdAudAddService stopped successfully! Service ADIHdAudAddService deleted successfully! File system32\drivers\ADIHdAud.sys not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found. Registry key HKEY_USERS\S-1-5-21-2567241484-2555261958-2837169219-1005\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found. Registry key HKEY_USERS\S-1-5-21-2567241484-2555261958-2837169219-1005\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_USERS\S-1-5-21-2567241484-2555261958-2837169219-1005\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. Registry key HKEY_USERS\S-1-5-21-2567241484-2555261958-2837169219-1005\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found. Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1 Prefs.js: {EEE6C361-6118-11DC-9C72-001320C79847}:1.2.0.2 removed from extensions.enabledItems Prefs.js: ffxtlbr@babylon.com:1.2.0 removed from extensions.enabledItems Prefs.js: "http://search.babylon.com/?AF=100482&babsrc=adbartrp&mntrId=04d106970000000000000060b34d5512&q=" removed from keyword.URL Prefs.js: "http://start.funmoods.com/?f=1&a=nv1" removed from browser.startup.homepage Prefs.js: "Search" removed from browser.search.selectedEngine Prefs.js: "Search" removed from browser.search.defaultenginename C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b}\searchplugin folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b}\modules folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b}\META-INF folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b}\defaults folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b}\components folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b}\chrome folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b} folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\META-INF folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\components folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\skin folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\nl-NL folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\it-IT folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\fr-FR folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\es-ES folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\en-US folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale\de-DE folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\locale folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar\content folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome\sweetim-toolbar folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@babylon.com\defaults\preferences folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@babylon.com\defaults folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@babylon.com\content\imgs folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@babylon.com\content folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@babylon.com\components folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@babylon.com folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@funmoods.com\content\imgs folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@funmoods.com\content folder moved successfully. C:\Documents and Settings\Jozef\Application Data\mozilla\Firefox\Profiles\karxteyf.default\extensions\ffxtlbr@funmoods.com folder moved successfully. C:\Documents and Settings\Jozef\Application Data\Mozilla\Firefox\Profiles\karxteyf.default\searchplugins\funmoods.xml moved successfully. C:\Documents and Settings\Jozef\Application Data\Mozilla\Firefox\Profiles\karxteyf.default\searchplugins\SweetIM Search.xml moved successfully. C:\Documents and Settings\Jozef\Application Data\Mozilla\Firefox\Profiles\karxteyf.default\searchplugins\sweetim.xml moved successfully. C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml moved successfully. Registry value HKEY_USERS\S-1-5-21-2567241484-2555261958-2837169219-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_USERS\S-1-5-21-2567241484-2555261958-2837169219-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found. Registry value HKEY_USERS\S-1-5-21-2567241484-2555261958-2837169219-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f848be46-92a0-11df-9b96-0060b34d5512}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f848be46-92a0-11df-9b96-0060b34d5512}\ not found. File I:\wa.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f848be46-92a0-11df-9b96-0060b34d5512}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f848be46-92a0-11df-9b96-0060b34d5512}\ not found. File I:\wa.exe not found. ========== FILES ========== [color=#A23BEC]< attrib /d /s -s -h C:\WINDOWS\system32\drivers\etc\hosts /C >[/color] C:\Documents and Settings\Jozef\Desktop\cmd.bat deleted successfully. C:\Documents and Settings\Jozef\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Opera cache emptied: 25160 bytes ->Flash cache emptied: 348 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Flash cache emptied: 56852 bytes User: Guest ->Temp folder emptied: 0 bytes ->FireFox cache emptied: 3424339 bytes ->Google Chrome cache emptied: 856432 bytes ->Flash cache emptied: 56852 bytes User: Jozef ->Temp folder emptied: 2152 bytes ->Java cache emptied: 23268144 bytes ->FireFox cache emptied: 50926462 bytes ->Opera cache emptied: 45953410 bytes ->Flash cache emptied: 1904682 bytes User: LocalService ->Temp folder emptied: 66016 bytes User: NetworkService ->Temp folder emptied: 0 bytes User: s ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 68050915 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 177277973 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 35462 bytes RecycleBin emptied: 4285395912 bytes Total Files Cleaned = 4 442,00 mb OTL by OldTimer - Version 3.2.55.0 log created on 07312012_192815 Files\Folders moved on Reboot... File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files... [2012-07-31 19:33:58 | 000,000,000 | ---- | M] () C:\WINDOWS\temp\_avast_\Webshlock.txt : Unable to obtain MD5 Registry entries deleted on Reboot...