All processes killed ========== OTL ========== Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{814C76CB-2623-43F4-AAD0-58A0E5190A20}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{814C76CB-2623-43F4-AAD0-58A0E5190A20}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! C:\Documents and Settings\jmarie\Application Data\Mozilla\Firefox\Profiles\5xmvgdgd.default\searchplugins\safesearch.xml moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53707962-6F74-2D53-2644-206D7942484F}\ deleted successfully. C:\Program Files\Spybot - Search & Destroy\SDHelper.dll moved successfully. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. C:\Documents and Settings\All Users\Application Data\{0AD3E795-7EF0-4177-8A06-05D4F8A4DEBB} folder moved successfully. C:\WINDOWS\tasks\RegistryBooster Startup.job moved successfully. C:\Documents and Settings\jmarie\Application Data\SAS7_000.DAT moved successfully. C:\windows\canopus.ini moved successfully. C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT moved successfully. C:\Documents and Settings\All Users\Application Data\Internet Services moved successfully. C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT moved successfully. C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT moved successfully. C:\Documents and Settings\All Users\Application Data\PKP_DLeo.DAT moved successfully. C:\Documents and Settings\All Users\Application Data\bcntatzxryfczze moved successfully. C:\Documents and Settings\All Users\Application Data\90919AF730.sys moved successfully. C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86 folder moved successfully. C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1 folder moved successfully. C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB\x86\x86 folder moved successfully. C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB\x86 folder moved successfully. C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB folder moved successfully. C:\Documents and Settings\jmarie\Application Data\Uniblue\RegistryBooster\backup folder moved successfully. C:\Documents and Settings\jmarie\Application Data\Uniblue\RegistryBooster folder moved successfully. C:\Documents and Settings\jmarie\Application Data\Uniblue folder moved successfully. C:\Program Files\Kaspersky Lab\NetworkAgent\Products folder moved successfully. C:\Program Files\Kaspersky Lab\NetworkAgent\Data\Tasks folder moved successfully. C:\Program Files\Kaspersky Lab\NetworkAgent\Data\Events folder moved successfully. C:\Program Files\Kaspersky Lab\NetworkAgent\Data\Cleaner folder moved successfully. C:\Program Files\Kaspersky Lab\NetworkAgent\Data\Cert folder moved successfully. C:\Program Files\Kaspersky Lab\NetworkAgent\Data folder moved successfully. C:\Program Files\Kaspersky Lab\NetworkAgent\$FTClTmp folder moved successfully. C:\Program Files\Kaspersky Lab\NetworkAgent folder moved successfully. C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations folder moved successfully. C:\Program Files\Kaspersky Lab folder moved successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:0FF263E8 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:A9967A61 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:F4C624DE deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:661DFA1C deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:69E87FA2 deleted successfully. File ptytemp] not found. OTL by OldTimer - Version 3.2.69.0 log created on 05262016_131932 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot...