
http://wklej.org/id/98288/ HijackThis
http://wklej.org/id/98292/ OTListIt
http://wklej.org/id/98293/ OTListIt cz. 2
:OTLI
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {37B85A29-692B-4205-9CAD-2626E4993404} - Reg Error: Key error. File not found
O4 - HKU\.DEFAULT..\Run: [] C:\Documents and Settings\User\.exe /i File not found
O4 - HKU\S-1-5-18..\Run: [] C:\Documents and Settings\User\.exe /i File not found
O20 - Winlogon\Notify\crypt: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O29 - HKLM SecurityProviders - (digiwet.dll) - File not found
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
:Commands
[emptytemp]
[start explorer]
[Reboot]
========== OTLISTIT ==========
Process explorer.exe killed successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{37B85A29-692B-4205-9CAD-2626E4993404} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:digiwet.dll deleted successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\"SecurityProviders"|"msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\Mama\Ustawienia lokalne\Temp\etilqs_bGUhPaPlhS5XNwXdTzSY scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Mama\Ustawienia lokalne\Temp\fla10A1.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Mama\Ustawienia lokalne\Temp\Perflib_Perfdata_234.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Mama\Ustawienia lokalne\Temp\~DFAED.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully
OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05312009_120756
Files moved on Reboot...
File move failed. C:\Documents and Settings\Mama\Ustawienia lokalne\Temp\etilqs_bGUhPaPlhS5XNwXdTzSY scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Mama\Ustawienia lokalne\Temp\fla10A1.tmp scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Mama\Ustawienia lokalne\Temp\Perflib_Perfdata_234.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Mama\Ustawienia lokalne\Temp\~DFAED.tmp scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 5 gości