All processes killed ========== OTL ========== C:\Documents and Settings\Administrator\zobaqixidymu.exe moved successfully. E:\autorun.inf moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Regedit32 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\TrialReset deleted successfully. Registry value HKEY_USERS\S-1-5-21-1715567821-1604221776-725345543-500\Software\Microsoft\Windows\CurrentVersion\Run\\EXPLORER.EXE deleted successfully. C:\WINDOWS\system32\EXPLORER.EXE moved successfully. Registry value HKEY_USERS\S-1-5-21-1715567821-1604221776-725345543-500\Software\Microsoft\Windows\CurrentVersion\Run\\wsctf.exe deleted successfully. Registry value HKEY_USERS\S-1-5-21-1715567821-1604221776-725345543-500\Software\Microsoft\Windows\CurrentVersion\Run\\ziqokifixubg deleted successfully. C:\Documents and Settings\Administrator\ziqokifixubg.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:EXPLORER.EXE deleted successfully. File C:\WINDOWS\System32\EXPLORER.EXE not found. Service ZDPSp50 stopped successfully! Service ZDPSp50 deleted successfully! File System32\Drivers\ZDPSp50.sys not found. Service ZDCndis5 stopped successfully! Service ZDCndis5 deleted successfully! File C:\WINDOWS\system32\ZDCndis5.SYS not found. Service PCANDIS5 stopped successfully! Service PCANDIS5 deleted successfully! File C:\WINDOWS\system32\PCANDIS5.SYS not found. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Shell"|"explorer.exe" /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\\"CheckedValue"|dword:00000001 /E : value set successfully! Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2\ deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 418036 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 37682 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 01222013_090945 Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\egzamin eurofun.wps not found! File\Folder C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\relatywizm etyczny2.doc not found! PendingFileRenameOperations files... Registry entries deleted on Reboot...