All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sniffer deleted successfully. C:\WINDOWS\Temp\_ex-08.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\RTHDBPL deleted successfully. C:\Documents and Settings\Eliza\Dane aplikacji\SystemProc\lsass.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:mcenspc.dll deleted successfully. Prefs.js: {9CE11043-9A15-4207-A565-0C94C42D590D}:2.0 removed from extensions.enabledItems C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D} folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{100EB1FD-D03E-47FD-81F3-EE91287F9465}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5428486-50A0-4a02-9D20-520B59A9F9B2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{C5428486-50A0-4a02-9D20-520B59A9F9B3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5428486-50A0-4a02-9D20-520B59A9F9B3}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\se-2011-download.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\se-2011-payment.com\ deleted successfully. Starting removal of ActiveX control {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.1.1.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CafeNews deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Onet.pl AutoUpdate deleted successfully. C:\Documents and Settings\Julek\Menu Start\Programy\Autostart\Registration .LNK moved successfully. C:\Documents and Settings\Julek\Menu Start\Programy\Autostart\Registration Open Season.LNK moved successfully. Service EagleNT stopped successfully! Service EagleNT deleted successfully! File C:\WINDOWS\System32\drivers\EagleNT.sys not found. ========== FILES ========== C:\autoexec.exe moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\PriceGong\Data folder moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\PriceGong folder moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\Security Essentials 2011 folder moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\SystemProc folder moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\ShoppingReport\cs\res2 folder moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\ShoppingReport\cs\report folder moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\ShoppingReport\cs\dwld folder moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\ShoppingReport\cs\db folder moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\ShoppingReport\cs folder moved successfully. C:\Documents and Settings\Eliza\Dane aplikacji\ShoppingReport folder moved successfully. C:\Documents and Settings\Julek\Dane aplikacji\ShoppingReport\cs\res1 folder moved successfully. C:\Documents and Settings\Julek\Dane aplikacji\ShoppingReport\cs\report folder moved successfully. C:\Documents and Settings\Julek\Dane aplikacji\ShoppingReport\cs\dwld folder moved successfully. C:\Documents and Settings\Julek\Dane aplikacji\ShoppingReport\cs\db folder moved successfully. C:\Documents and Settings\Julek\Dane aplikacji\ShoppingReport\cs folder moved successfully. C:\Documents and Settings\Julek\Dane aplikacji\ShoppingReport folder moved successfully. C:\Documents and Settings\Gość\Dane aplikacji\ShoppingReport\cs\dwld folder moved successfully. C:\Documents and Settings\Gość\Dane aplikacji\ShoppingReport\cs folder moved successfully. C:\Documents and Settings\Gość\Dane aplikacji\ShoppingReport folder moved successfully. C:\Documents and Settings\aaa\Dane aplikacji\ShoppingReport\cs\res1 folder moved successfully. C:\Documents and Settings\aaa\Dane aplikacji\ShoppingReport\cs\report folder moved successfully. C:\Documents and Settings\aaa\Dane aplikacji\ShoppingReport\cs\dwld folder moved successfully. C:\Documents and Settings\aaa\Dane aplikacji\ShoppingReport\cs folder moved successfully. C:\Documents and Settings\aaa\Dane aplikacji\ShoppingReport folder moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: aaa ->Flash cache emptied: 539 bytes User: Administrator User: All Users User: Default User User: Eliza ->Flash cache emptied: 7770 bytes User: Gość ->Flash cache emptied: 0 bytes User: Julek ->Flash cache emptied: 12379 bytes User: LocalService ->Flash cache emptied: 0 bytes User: NetworkService Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: aaa ->Temp folder emptied: 22325755 bytes ->Temporary Internet Files folder emptied: 16738666 bytes ->Flash cache emptied: 0 bytes User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->FireFox cache emptied: 3427142 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Eliza ->Temp folder emptied: 901603533 bytes ->Temporary Internet Files folder emptied: 381857647 bytes ->FireFox cache emptied: 44221458 bytes ->Flash cache emptied: 0 bytes User: Gość ->Temp folder emptied: 34240 bytes ->Temporary Internet Files folder emptied: 173581 bytes ->Flash cache emptied: 0 bytes User: Julek ->Temp folder emptied: 1625380786 bytes ->Temporary Internet Files folder emptied: 657561745 bytes ->FireFox cache emptied: 52964173 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 6483429 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2114584 bytes %systemroot%\System32 .tmp files removed: 2596 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 9419142 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 3 552,00 mb OTL by OldTimer - Version 3.2.17.3 log created on 11172010_231423 Files\Folders moved on Reboot... Registry entries deleted on Reboot...