All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C424171E-592A-415A-9EB1-DFD6D95D3530} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415A-9EB1-DFD6D95D3530}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Rysoehgeit deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Upzyo deleted successfully. Service vToolbarUpdater14.1.7 stopped successfully! Service vToolbarUpdater14.1.7 deleted successfully! C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe moved successfully. Service autorun stopped successfully! Service autorun deleted successfully! File c:\huadio.tmp not found. ========== FILES ========== C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater folder moved successfully. C:\Program Files\Common Files\AVG Secure Search folder moved successfully. C:\Users\a\AppData\Local\IAC\Test folder moved successfully. C:\Users\a\AppData\Local\IAC folder moved successfully. C:\Users\a\AppData\Roaming\Somau folder moved successfully. C:\Users\a\AppData\Roaming\Roop folder moved successfully. C:\Users\a\AppData\Roaming\Maety folder moved successfully. C:\Windows\DeleteOnReboot.bat moved successfully. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully! HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully! Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Mozilla\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\ deleted successfully. Registry key HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: a ->Temp folder emptied: 1564171 bytes ->Temporary Internet Files folder emptied: 11808398 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 45985577 bytes ->Flash cache emptied: 689 bytes User: Agnieszka dodatkowe ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 52582083 bytes RecycleBin emptied: 935 bytes Total Files Cleaned = 107,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 05232013_214341 Files\Folders moved on Reboot... C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot...