Re: total xp security
Napsal: 20 úno 2011 12:35
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-789336058-1682526488-682003330-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\ deleted successfully.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "ICQ Search" removed from browser.search.selectedEngine
========== FILES ==========
C:\WINDOWS\system32\_000005_.tmp.dll moved successfully.
C:\WINDOWS\system32\SET111.tmp moved successfully.
C:\WINDOWS\system32\SET112.tmp moved successfully.
C:\WINDOWS\system32\SET115.tmp moved successfully.
C:\WINDOWS\system32\SET1FF.tmp moved successfully.
C:\WINDOWS\system32\SET203.tmp moved successfully.
C:\WINDOWS\system32\SET20B.tmp moved successfully.
C:\WINDOWS\system32\SET53.tmp moved successfully.
C:\WINDOWS\system32\SET58.tmp moved successfully.
C:\WINDOWS\system32\SET5B.tmp moved successfully.
C:\WINDOWS\system32\SET65.tmp moved successfully.
C:\WINDOWS\system32\SET68.tmp moved successfully.
C:\WINDOWS\system32\SET6B.tmp moved successfully.
C:\WINDOWS\system32\SET6D.tmp moved successfully.
C:\WINDOWS\system32\SET6E.tmp moved successfully.
C:\WINDOWS\system32\SET70.tmp moved successfully.
C:\WINDOWS\system32\SET71.tmp moved successfully.
C:\WINDOWS\system32\SET73.tmp moved successfully.
C:\WINDOWS\system32\SET77.tmp moved successfully.
C:\WINDOWS\system32\SET79.tmp moved successfully.
C:\WINDOWS\system32\SET7B.tmp moved successfully.
C:\WINDOWS\system32\SET7C.tmp moved successfully.
C:\WINDOWS\system32\SET80.tmp moved successfully.
C:\WINDOWS\system32\SET83.tmp moved successfully.
C:\WINDOWS\system32\SET87.tmp moved successfully.
C:\WINDOWS\system32\SETAE.tmp moved successfully.
C:\WINDOWS\system32\SETAF.tmp moved successfully.
C:\WINDOWS\system32\SETB0.tmp moved successfully.
C:\WINDOWS\system32\SETB1.tmp moved successfully.
C:\WINDOWS\system32\SETB5.tmp moved successfully.
C:\WINDOWS\system32\SETB6.tmp moved successfully.
C:\WINDOWS\system32\SETB7.tmp moved successfully.
C:\WINDOWS\system32\SETB8.tmp moved successfully.
C:\WINDOWS\system32\SETBC.tmp moved successfully.
C:\WINDOWS\system32\SETBE.tmp moved successfully.
C:\WINDOWS\system32\SETBF.tmp moved successfully.
C:\WINDOWS\system32\SETC1.tmp moved successfully.
C:\WINDOWS\system32\SETC2.tmp moved successfully.
C:\WINDOWS\system32\SETC7.tmp moved successfully.
C:\WINDOWS\system32\SETC8.tmp moved successfully.
C:\WINDOWS\system32\SETC9.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET11.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET15.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET16.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET19.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET1F.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET20.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET21.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET23.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET25.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET27.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET28.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET2A.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET2B.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET2D.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET2F.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET30.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET34.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET37.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET3A.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET3B.tmp moved successfully.
C:\WINDOWS\002748_.tmp moved successfully.
C:\WINDOWS\SET21.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP15C.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP16.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1BF.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP239.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP258.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP28A.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP368.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP456.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA5.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEB.tmp folder moved successfully.
C:\WINDOWS\Help\SET3F.tmp moved successfully.
C:\WINDOWS\Help\SET40.tmp moved successfully.
C:\WINDOWS\Help\SET41.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO14\VDM49.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO14\VDM4E.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO14\VOBRA.00\_SPEC\PDF\VDM11C.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO14\VOBRA.00\_SPEC\PDF\VDM11D.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO15\VDM1A2.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO15\VDM1A3.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO15\INFINITY.00\_SPEC\PDF\VDM6A.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO15\VOBRA.00\_SPEC\PDF\VDM81.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO16\VDM89.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO17\VDM6C.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2006\poznámky p.Klečková\~WRL0001.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2007\poznámky p.Klečková\~WRL0001.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2008\poznámky p.Klečková\~WRL0001.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2008\poznámky p.Krejčová\~WRL0001.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2009\poznámky p.Krejčová\~WRL0001.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
File\Folder C:\WINDOWS\system32\drivers\vrmf.sys not found.
File\Folder C:\WINDOWS\system32\drivers\xdqaxar.sys not found.
C:\Documents and Settings\Fany\Local Settings\Data aplikací\1y6p453646exnf5s31f73u2i843 moved successfully.
C:\Documents and Settings\All Users\Data aplikací\1y6p453646exnf5s31f73u2i843 moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 84 bytes
User: Fany
->Temp folder emptied: 587193 bytes
->Temporary Internet Files folder emptied: 35074499 bytes
->Java cache emptied: 50446945 bytes
->FireFox cache emptied: 41866325 bytes
->Flash cache emptied: 96550 bytes
User: LocalService
->Temp folder emptied: 8634315 bytes
->Temporary Internet Files folder emptied: 3505434 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33237 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23266644 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 156,00 mb
[EMPTYFLASH]
User: All Users
User: Default User
->Flash cache emptied: 0 bytes
User: Fany
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.20.6 log created on 02202011_122307
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...
========== OTL ==========
No active process named explorer.exe was found!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-789336058-1682526488-682003330-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\ deleted successfully.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "ICQ Search" removed from browser.search.selectedEngine
========== FILES ==========
C:\WINDOWS\system32\_000005_.tmp.dll moved successfully.
C:\WINDOWS\system32\SET111.tmp moved successfully.
C:\WINDOWS\system32\SET112.tmp moved successfully.
C:\WINDOWS\system32\SET115.tmp moved successfully.
C:\WINDOWS\system32\SET1FF.tmp moved successfully.
C:\WINDOWS\system32\SET203.tmp moved successfully.
C:\WINDOWS\system32\SET20B.tmp moved successfully.
C:\WINDOWS\system32\SET53.tmp moved successfully.
C:\WINDOWS\system32\SET58.tmp moved successfully.
C:\WINDOWS\system32\SET5B.tmp moved successfully.
C:\WINDOWS\system32\SET65.tmp moved successfully.
C:\WINDOWS\system32\SET68.tmp moved successfully.
C:\WINDOWS\system32\SET6B.tmp moved successfully.
C:\WINDOWS\system32\SET6D.tmp moved successfully.
C:\WINDOWS\system32\SET6E.tmp moved successfully.
C:\WINDOWS\system32\SET70.tmp moved successfully.
C:\WINDOWS\system32\SET71.tmp moved successfully.
C:\WINDOWS\system32\SET73.tmp moved successfully.
C:\WINDOWS\system32\SET77.tmp moved successfully.
C:\WINDOWS\system32\SET79.tmp moved successfully.
C:\WINDOWS\system32\SET7B.tmp moved successfully.
C:\WINDOWS\system32\SET7C.tmp moved successfully.
C:\WINDOWS\system32\SET80.tmp moved successfully.
C:\WINDOWS\system32\SET83.tmp moved successfully.
C:\WINDOWS\system32\SET87.tmp moved successfully.
C:\WINDOWS\system32\SETAE.tmp moved successfully.
C:\WINDOWS\system32\SETAF.tmp moved successfully.
C:\WINDOWS\system32\SETB0.tmp moved successfully.
C:\WINDOWS\system32\SETB1.tmp moved successfully.
C:\WINDOWS\system32\SETB5.tmp moved successfully.
C:\WINDOWS\system32\SETB6.tmp moved successfully.
C:\WINDOWS\system32\SETB7.tmp moved successfully.
C:\WINDOWS\system32\SETB8.tmp moved successfully.
C:\WINDOWS\system32\SETBC.tmp moved successfully.
C:\WINDOWS\system32\SETBE.tmp moved successfully.
C:\WINDOWS\system32\SETBF.tmp moved successfully.
C:\WINDOWS\system32\SETC1.tmp moved successfully.
C:\WINDOWS\system32\SETC2.tmp moved successfully.
C:\WINDOWS\system32\SETC7.tmp moved successfully.
C:\WINDOWS\system32\SETC8.tmp moved successfully.
C:\WINDOWS\system32\SETC9.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET11.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET15.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET16.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET19.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET1F.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET20.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET21.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET23.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET25.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET27.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET28.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET2A.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET2B.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET2D.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET2F.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET30.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET34.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET37.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET3A.tmp moved successfully.
C:\WINDOWS\system32\dllcache\SET3B.tmp moved successfully.
C:\WINDOWS\002748_.tmp moved successfully.
C:\WINDOWS\SET21.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP15C.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP16.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1BF.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP239.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP258.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP28A.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP368.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP456.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA5.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEB.tmp folder moved successfully.
C:\WINDOWS\Help\SET3F.tmp moved successfully.
C:\WINDOWS\Help\SET40.tmp moved successfully.
C:\WINDOWS\Help\SET41.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO14\VDM49.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO14\VDM4E.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO14\VOBRA.00\_SPEC\PDF\VDM11C.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO14\VOBRA.00\_SPEC\PDF\VDM11D.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO15\VDM1A2.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO15\VDM1A3.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO15\INFINITY.00\_SPEC\PDF\VDM6A.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO15\VOBRA.00\_SPEC\PDF\VDM81.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO16\VDM89.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\STEREO17\VDM6C.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2006\poznámky p.Klečková\~WRL0001.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2007\poznámky p.Klečková\~WRL0001.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2008\poznámky p.Klečková\~WRL0001.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2008\poznámky p.Krejčová\~WRL0001.tmp moved successfully.
C:\WINDOWS\ostatní sterea A ÚČTA\UCTO2009\poznámky p.Krejčová\~WRL0001.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
File\Folder C:\WINDOWS\system32\drivers\vrmf.sys not found.
File\Folder C:\WINDOWS\system32\drivers\xdqaxar.sys not found.
C:\Documents and Settings\Fany\Local Settings\Data aplikací\1y6p453646exnf5s31f73u2i843 moved successfully.
C:\Documents and Settings\All Users\Data aplikací\1y6p453646exnf5s31f73u2i843 moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 84 bytes
User: Fany
->Temp folder emptied: 587193 bytes
->Temporary Internet Files folder emptied: 35074499 bytes
->Java cache emptied: 50446945 bytes
->FireFox cache emptied: 41866325 bytes
->Flash cache emptied: 96550 bytes
User: LocalService
->Temp folder emptied: 8634315 bytes
->Temporary Internet Files folder emptied: 3505434 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33237 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23266644 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 156,00 mb
[EMPTYFLASH]
User: All Users
User: Default User
->Flash cache emptied: 0 bytes
User: Fany
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.20.6 log created on 02202011_122307
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...