All processes killed ========== FILES ========== [color=#A23BEC]< netsh winsock reset /C >[/color] Pomy˜lnie zresetowano Winsock Catalog. Musisz ponownie uruchomi† komputer, aby ukoäczy† resetowanie. C:\wirusy\cmd.bat deleted successfully. C:\wirusy\cmd.txt deleted successfully. C:\Program Files\SearchPredict\PRFireFox\chrome\content\searchpredict folder moved successfully. C:\Program Files\SearchPredict\PRFireFox\chrome\content folder moved successfully. C:\Program Files\SearchPredict\PRFireFox\chrome folder moved successfully. C:\Program Files\SearchPredict\PRFireFox folder moved successfully. C:\Program Files\SearchPredict\Chrome folder moved successfully. C:\Program Files\SearchPredict folder moved successfully. C:\Documents and Settings\Patryk\A_Drunken_Mouse_Cursor_58137.exe moved successfully. C:\Documents and Settings\Patryk\M2 MultiversionHack by banjo1 v3.90.exe moved successfully. C:\Documents and Settings\Patryk\M2 MultiversionHack by banjo1 v3.87.exe moved successfully. C:\Documents and Settings\Patryk\fishing_beta_0.1.3i(1).exe moved successfully. C:\Documents and Settings\Patryk\FishBOT.exe moved successfully. C:\Documents and Settings\Patryk\fishbot ver.1.3.exe moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\logs\ORSP Client folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\logs\FSMA folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\logs\FSFW folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\logs\DAAS2 folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\logs folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\Daas2\revocation folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\Daas2\keys folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\Daas2\crl folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\Daas2\cert folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\Daas2\acl folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure\Daas2 folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F-Secure folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\fssg folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\MSScanAppDataDir folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\TEMP folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\F-Secure\System Control folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\F-Secure\Spam Control folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\F-Secure folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox\Profiles\pxlqqvhl.default\minidumps folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox\Profiles\pxlqqvhl.default\extensions folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox\Profiles\pxlqqvhl.default\chrome folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox\Profiles\pxlqqvhl.default\bookmarkbackups folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox\Profiles\pxlqqvhl.default folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox\Profiles folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox\Crash Reports\submitted folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox\Crash Reports\pending folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox\Crash Reports folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Firefox folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla\Extensions folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Mozilla folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\OpenCandy\OpenCandy_14AAB260B31F4CE4A3314B561CF50729 folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\OpenCandy folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\cache folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2} folder moved successfully. C:\Documents and Settings\Patryk\Dane aplikacji\Toolbar4 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\9 stycznia 2010 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\7 lutego 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\5 lutego 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\25 lipca 2010 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\24 sierpnia 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\24 lipca 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\23 grudnia 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\22 lipca 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\21 czerwca 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\19 sierpnia 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\18 sierpnia 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\17 sierpnia 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\16 października 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\15 maja 2010 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\15 kwietnia 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\11 października 2009 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\10 marca 2010 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup\10 kwietnia 2010 folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\backup folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums\4838f37c834977319e6c8f010c3ab62b folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Picasa2Albums folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\GBScreensaver folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Plugin Data\Google Gears folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Plugin Data folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Cache folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google\Chrome folder moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Dane aplikacji\Google folder moved successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Google\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Mozilla\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\SpeedBit\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Google\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\SpeedBit\ deleted successfully. ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-789336058-1214440339-1417001333-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}\ not found. Registry key HKEY_USERS\S-1-5-21-789336058-1214440339-1417001333-1003\Software\Microsoft\Internet Explorer\SearchScopes\{E73DE7CC-1F20-4bc9-BF41-3ED837DAE266}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E73DE7CC-1F20-4bc9-BF41-3ED837DAE266}\ not found. Registry key HKEY_USERS\S-1-5-21-789336058-1214440339-1417001333-1003\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{389943B0-C3A2-4E69-82CB-8596A84CB3DC}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{389943B0-C3A2-4E69-82CB-8596A84CB3DC}\ not found. File C:\Program Files\SearchPredict\SearchPredict.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sniffer deleted successfully. Registry value HKEY_USERS\S-1-5-21-789336058-1214440339-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Gadu-Gadu 10 deleted successfully. Registry value HKEY_USERS\S-1-5-21-789336058-1214440339-1417001333-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\WINDOWS\svchost.exe deleted successfully. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Service NaiAvFilter102 stopped successfully! Service NaiAvFilter102 deleted successfully! File Device\NaiAvFilter102.sys not found. Service InCDRm stopped successfully! Service InCDRm deleted successfully! File system32\drivers\InCDRm.sys not found. Service InCDPass stopped successfully! Service InCDPass deleted successfully! File system32\drivers\InCDPass.sys not found. Service InCDFs stopped successfully! Service InCDFs deleted successfully! File system32\drivers\InCDFs.sys not found. Service EagleNT stopped successfully! Service EagleNT deleted successfully! File C:\WINDOWS\system32\drivers\EagleNT.sys not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 5691340 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33258 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Patryk ->Temp folder emptied: 1561665364 bytes ->Temporary Internet Files folder emptied: 157110707 bytes ->Java cache emptied: 26987168 bytes ->FireFox cache emptied: 138511106 bytes ->Flash cache emptied: 169984 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2352022 bytes %systemroot%\System32 .tmp files removed: 3870756 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1 809,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 03052013_212719 Files\Folders moved on Reboot... C:\Documents and Settings\Patryk\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KV8A041A\16766-84-wpisy-w-mbam[1].htm moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Temporary Internet Files\Content.IE5\HF52CHDT\fastbutton[2].htm moved successfully. C:\Documents and Settings\Patryk\Ustawienia lokalne\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot...