All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\epfbgpabltbhrxf deleted successfully. C:\Documents and Settings\Właściciel\Menu Start\Programy\Autostart\GIGABYTE VGA Utility.lnk moved successfully. C:\Documents and Settings\Właściciel\0.9264946446682817.exe moved successfully. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Conduit\CT2801948 folder moved successfully. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Conduit\Community Alerts\Log folder moved successfully. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Conduit\Community Alerts folder moved successfully. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Conduit folder moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\cuvahlgohfdlxum moved successfully. C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\zdgqmub8.default\searchplugins\conduit.xml moved successfully. C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\zdgqmub8.default\extensions\DTToolbar@toolbarnet.com\components\Resources folder moved successfully. C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\zdgqmub8.default\extensions\DTToolbar@toolbarnet.com\components folder moved successfully. C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\zdgqmub8.default\extensions\DTToolbar@toolbarnet.com\chrome\content folder moved successfully. C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\zdgqmub8.default\extensions\DTToolbar@toolbarnet.com\chrome folder moved successfully. C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\zdgqmub8.default\extensions\DTToolbar@toolbarnet.com folder moved successfully. Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource=2&q=" removed from keyword.URL Prefs.js: "http://search.conduit.com/?ctid=CT2801948&SearchSource=13" removed from browser.startup.homepage Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{37483b40-c254-4a72-bda4-22ee90182c1e} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37483b40-c254-4a72-bda4-22ee90182c1e}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: wba[ciciel User: Właściciel ->Temp folder emptied: 671384 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 131520 bytes RecycleBin emptied: 388067 bytes Total Files Cleaned = 1,00 mb OTL by OldTimer - Version 3.2.53.1 log created on 01062007_233001 Files\Folders moved on Reboot... File\Folder C:\WINDOWS\temp\_avast4_\Webshlock.txt not found! C:\WINDOWS\temp\Perflib_Perfdata_5bc.dat moved successfully. PendingFileRenameOperations files... File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found! File C:\WINDOWS\temp\Perflib_Perfdata_5bc.dat not found! Registry entries deleted on Reboot...
larwa7991