
GMER:
http://wklej.org/id/317533/
OTL
Otl.txt http://wklej.org/id/317509/
Extras.txt http://wklej.org/id/317510/
HijackThis:
http://wklej.org/id/317534/
Silent Runners.vbs
http://wklej.org/id/317557/
[Kernel | Boot | Running] -- D:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
:OTL
FF - prefs.js..browser.search.selectedEngine: "MyWebSearch"
FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZVfox000&fl=0&ptb=2x3i.bBCLMc074WWP.w4KQ&url=http://search.mywebsearch.com/mywebsearch/GGmain.jhtml&st=kwd&n=77cea143&searchfor="
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKU\S-1-5-21-515967899-746137067-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
:Files
C:\WINDOWS\tasks\User_Feed_Synchronization-{A9376F27-71E9-4572-9F4B-879C5EEA7541}.job
:Commands
[emptytemp]
All processes killed
========== OTL ==========
Prefs.js: "MyWebSearch" removed from browser.search.selectedEngine
Prefs.js: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZVfox000&fl=0&ptb=2x3i.bBCLMc074WWP.w4KQ&url=http://search.mywebsearch.com/mywebsearch/GGmain.jhtml&st=kwd&n=77cea143&searchfor=" removed from keyword.URL
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
C:\Program Files\AVG\AVG9\avgssie.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-515967899-746137067-1417001333-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93}\ not found.
========== FILES ==========
C:\WINDOWS\tasks\User_Feed_Synchronization-{A9376F27-71E9-4572-9F4B-879C5EEA7541}.job moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 71849 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Stefan
->Temp folder emptied: 8304016 bytes
->Temporary Internet Files folder emptied: 13578943 bytes
->Java cache emptied: 998321 bytes
->FireFox cache emptied: 98772376 bytes
->Flash cache emptied: 6896 bytes
User: Szymon
->Temp folder emptied: 236618131 bytes
->Temporary Internet Files folder emptied: 6289571 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 53499628 bytes
->Flash cache emptied: 44692 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 155648 bytes
%systemroot%\System32 .tmp files removed: 2673152 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 98968 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 402,00 mb
OTL by OldTimer - Version 3.2.1.2 log created on 04182010_101817
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 31 gości