

Gmer:
http://www.wklej.org/id/385109/
Otl:
http://www.wklej.org/id/385117/
http://www.wklej.org/id/385118/
Z góry dzięki.
:Processes
explorer.exe
:OTL
IE - HKU\S-1-5-21-484763869-1606980848-1177238915-1004\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - Reg Error: Value error. File not found
FF - prefs.js..browser.search.defaultthis.engineName: "free-downloads.net Customized Web Search"
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.2.0185
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q={searchTerms}"
O2 - BHO: (no name) - {ecdee021-0d17-467f-a1ff-c7a115230949} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {ecdee021-0d17-467f-a1ff-c7a115230949} - Reg Error: Value error. File not found
O3 - HKU\S-1-5-21-484763869-1606980848-1177238915-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-484763869-1606980848-1177238915-1004\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKU\S-1-5-21-484763869-1606980848-1177238915-1004..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe File not found
O4 - HKU\S-1-5-21-484763869-1606980848-1177238915-1004..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe File not found
O4 - HKU\S-1-5-21-484763869-1606980848-1177238915-1004..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:C04CAC43
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:364682BC
:Files
C:\Documents and Settings\dom\Dane aplikacji\Mozilla\Firefox\Profiles\rtr9o8yk.default\extensions\DTToolbar@toolbarnet.com
C:\Documents and Settings\dom\Dane aplikacji\Mozilla\Firefox\Profiles\rtr9o8yk.default\extensions\{ecdee021-0d17-467f-a1ff-c7a115230949}
C:\Documents and Settings\dom\Dane aplikacji\Mozilla\Firefox\Profiles\rtr9o8yk.default\searchplugins\conduit.xml
C:\Program Files\DAEMON Tools Toolbar
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\Norton Security Scan for dom.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\Documents and Settings\dom\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
:Commands
[emptytemp]
[emptyflash]
[clearallrestorepoints]
C:\WINDOWS\System32\TLFL6.dat
/md5start
kbdclass.sys
/md5stop
c:\windows\system32\drivers\kbdclass.sys /md5
c:\windows\system32\drivers\* /s /lockedfiles
:processes
killallprocesses
:files
net stop Kbdclass
C:\WINDOWS\Driver Cache\i386\sp3.cab:kbdclass.sys /e
C:\WINDOWS\System32\drivers\kbdclass.sys|C:\kbdclass.sys /replace
:commands
[reboot]
========== PROCESSES ==========
All processes killed
========== FILES ==========
File\Folder net stop Kbdclass not found.
kbdclass.sys extracted to C:\
File C:\WINDOWS\System32\drivers\kbdclass.sys successfully replaced with C:\kbdclass.sys
========== COMMANDS ==========
OTL by OldTimer - Version 3.2.11.0 log created on 09072010_120414
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
gratulujęWin32:Sality napisał(a):Mój 1000 post na forum
/md5start
kbdclass.sys
/md5stop
c:\windows\system32\drivers\kbdclass.sys /md5
c:\windows\system32\drivers\* /s /lockedfiles
[2008-04-15 14:00:00 | 000,024,960 | ---- | M] () MD5=31B61179F9D2AE3779AFA5D2DEE736A7
[2008-04-14 21:50:08 | 000,024,960 | ---- | M] (Microsoft Corporation) MD5=2AECA45D4AEAACBDCB77AD11184E4601
:PROCESSES
:SERVICES
:OTL
:FILES
:REG
:COMMANDS
[purity]
[emptytemp]
[emptyflash]
[clearallrestorepoints]
All processes killed
========== PROCESSES ==========
========== SERVICES/DRIVERS ==========
========== OTL ==========
========== FILES ==========
========== REGISTRY ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
User: dom
->Temp folder emptied: 85504 bytes
->Temporary Internet Files folder emptied: 61716 bytes
->Java cache emptied: 12232 bytes
->FireFox cache emptied: 57644359 bytes
->Flash cache emptied: 1668 bytes
User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: Misiek
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 503085 bytes
->FireFox cache emptied: 40641917 bytes
->Flash cache emptied: 2709 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 95,00 mb
[EMPTYFLASH]
User: All Users
User: Default User
User: dom
->Flash cache emptied: 0 bytes
User: LocalService
User: Misiek
->Flash cache emptied: 0 bytes
User: NetworkService
Total Flash Files Cleaned = 0,00 mb
Restore points cleared and new OTL Restore Point set!
OTL by OldTimer - Version 3.2.11.0 log created on 09072010_125149
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 19 gości