All processes killed ========== OTL ========== Prefs.js: "4shared" removed from browser.search.defaultenginename Prefs.js: "uTorrentControl2 Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl Prefs.js: "4shared" removed from browser.search.order.1 Prefs.js: "http://websearch.4shared.com/results?q=" removed from browser.search.searchEnginesURL Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=2&q=" removed from keyword.URL Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. Registry key HKEY_USERS\S-1-5-21-3690817028-2233715112-3189557289-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_USERS\S-1-5-21-3690817028-2233715112-3189557289-1000\Software\Microsoft\Internet Explorer\SearchScopes\{12995981-2FD6-4BEE-9FB0-B1674E8E5E7E}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12995981-2FD6-4BEE-9FB0-B1674E8E5E7E}\ not found. Registry key HKEY_USERS\S-1-5-21-3690817028-2233715112-3189557289-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. Registry key HKEY_USERS\S-1-5-21-3690817028-2233715112-3189557289-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found. Registry value HKEY_USERS\S-1-5-21-3690817028-2233715112-3189557289-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found. Registry value HKEY_USERS\S-1-5-21-3690817028-2233715112-3189557289-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{6c97a91e-4524-4019-86af-2aa2d567bf5c} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6c97a91e-4524-4019-86af-2aa2d567bf5c}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95525BD9-6136-4A26-8263-9CEE295D442D}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95525BD9-6136-4A26-8263-9CEE295D442D}\ deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95080B13-AA71-4EE8-B951-7E98221E1ED5} deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95080B13-AA71-4EE8-B951-7E98221E1ED5}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{6c97a91e-4524-4019-86af-2aa2d567bf5c} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6c97a91e-4524-4019-86af-2aa2d567bf5c}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95080B13-AA71-4EE8-B951-7E98221E1ED5} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95080B13-AA71-4EE8-B951-7E98221E1ED5}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry value HKEY_USERS\S-1-5-21-3690817028-2233715112-3189557289-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{687578B9-7132-4A7A-80E4-30EE31099E03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578B9-7132-4A7A-80E4-30EE31099E03}\ not found. 64bit-Registry value HKEY_USERS\S-1-5-21-3690817028-2233715112-3189557289-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{95080B13-AA71-4EE8-B951-7E98221E1ED5} deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95080B13-AA71-4EE8-B951-7E98221E1ED5}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tvncontrol deleted successfully. Registry value HKEY_USERS\S-1-5-21-3690817028-2233715112-3189557289-1000\Software\Microsoft\Windows\CurrentVersion\Run\\MSConfig deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&4shared Search\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&4shared Search\ not found. ADS C:\Windows\Temp:temp deleted successfully. ADS C:\ProgramData:gs5sys deleted successfully. ADS C:\Users\Public\Documents\desktop.ini:gs5sys deleted successfully. ADS C:\Users\admin\Documents\desktop.ini:gs5sys deleted successfully. ADS C:\Users\admin\Desktop\desktop.ini:gs5sys deleted successfully. ========== FILES ========== C:\Program Files (x86)\Common Files\Comodo folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Temp folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\User StyleSheets folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\JumpListIcons folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Options folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\rssItem folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\popup folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\icons\useful_components folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\icons\urlGadget folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\icons folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\base64\searchBox folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\base64\rssItem folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\base64\ifarme folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\base64\icons folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\base64\dyamincMenu folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media\base64 folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Media folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\services\translation folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\services\alerts folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\services folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\popup\view folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\popup folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\model folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\lib folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\xmlMenu\view folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\xmlMenu folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\urlGadget\view folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\urlGadget folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\multiRssItem\view folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\multiRssItem folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\menuPanel\view folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\menuPanel folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\dynamicMenu\view folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\dynamicMenu folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\contextMenu\view folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\contextMenu folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\container folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\components\view\InjectScript folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\components\view folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\components folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items\about folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\items folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\css folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\controller folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\API\component\view folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\API\component folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js\API folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\js folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0\Css folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.7.1_0 folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jplinpmadfkdgipabgcdchbdikologlh\1.1_0\js folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jplinpmadfkdgipabgcdchbdikologlh\1.1_0\images folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jplinpmadfkdgipabgcdchbdikologlh\1.1_0\html folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jplinpmadfkdgipabgcdchbdikologlh\1.1_0\css folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jplinpmadfkdgipabgcdchbdikologlh\1.1_0 folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jplinpmadfkdgipabgcdchbdikologlh folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default\Cache folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data\Default folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon\User Data folder moved successfully. C:\Users\admin\AppData\Local\Comodo\Dragon folder moved successfully. C:\Users\admin\AppData\Local\Comodo folder moved successfully. C:\Users\admin\AppData\Roaming\TightVNC folder moved successfully. C:\Users\admin\AppData\Roaming\Babylon folder moved successfully. C:\Users\admin\AppData\Roaming\OpenCandy\OpenCandy_A05DF542BE0545FE84EE2D3828C5D031 folder moved successfully. C:\Users\admin\AppData\Roaming\OpenCandy\A05DF542BE0545FE84EE2D3828C5D031 folder moved successfully. C:\Users\admin\AppData\Roaming\OpenCandy folder moved successfully. File\Folder C:\Users\admin\giycir.exe not found. File\Folder C:\Users\Public\Desktop\GeekBuddy.lnk not found. File\Folder C:\Users\Public\Desktop\AntiError.lnk not found. File\Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk not found. C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\lbd86po6.default\searchplugins\conduit.xml moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\4shared.xml moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml moved successfully. C:\Program Files (x86)\Common Files\ApnToolbarInstaller.exe moved successfully. C:\Program Files (x86)\Common Files\ApnStub.exe moved successfully. [color=#A23BEC]< netsh advfirewall reset /C >[/color] Ok. C:\Users\admin\Desktop\cmd.bat deleted successfully. C:\Users\admin\Desktop\cmd.txt deleted successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\ deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: admin ->Temp folder emptied: 49090775 bytes ->Temporary Internet Files folder emptied: 9259914 bytes ->Java cache emptied: 1185472 bytes ->FireFox cache emptied: 89058003 bytes ->Google Chrome cache emptied: 8112678 bytes ->Flash cache emptied: 738 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 154251775 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 809330 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 297.00 mb OTL by OldTimer - Version 3.2.61.3 log created on 09112012_213012 Files\Folders moved on Reboot... C:\Users\admin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot...