1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117. | All processes killed
========== OTL ==========
No active process named MWSOEMON.EXE was found!
Registry value HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\URLSearchHooks\\\\{00A6FAF6-072E-44cf-8957-5838F569A31D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00A6FAF6-072E-44cf-8957-5838F569A31D}\\ deleted successfully.
C:\\Program Files\\MyWebSearch\\bar\\7.bin\\MWSSRCAS.DLL moved successfully.
C:\\Documents and Settings\\admin\\Dane aplikacji\\Mozilla\\Firefox\\Profiles\\e1jfl1ih.default\\searchplugins\\mywebsearch.xml moved successfully.
C:\\Program Files\\Mozilla Firefox\\plugins\\NPMyWebS.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{00A6FAF1-072E-44cf-8957-5838F569A31D}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00A6FAF1-072E-44cf-8957-5838F569A31D}\\ deleted successfully.
File C:\\Program Files\\MyWebSearch\\bar\\7.bin\\MWSSRCAS.DLL not found.
Registry key HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\\ deleted successfully.
C:\\Program Files\\MyWebSearch\\bar\\7.bin\\MWSBAR.DLL moved successfully.
Registry value HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Toolbar\\\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\\ deleted successfully.
File C:\\Program Files\\MyWebSearch\\bar\\7.bin\\MWSBAR.DLL not found.
Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser\\\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\\ not found.
File C:\\Program Files\\MyWebSearch\\bar\\7.bin\\MWSBAR.DLL not found.
Registry value HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\My Web Search Bar deleted successfully.
File C:\\Program Files\\MyWebSearch\\bar\\7.bin\\MWSBAR.DLL not found.
Registry value HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\MyWebSearch Email Plugin deleted successfully.
C:\\Program Files\\MyWebSearch\\bar\\7.bin\\MWSOEMON.EXE moved successfully.
Registry value HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\MyWebSearch Plugin deleted successfully.
C:\\Program Files\\MyWebSearch\\bar\\7.bin\\M3PLUGIN.DLL moved successfully.
Registry value HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\WrtMon.exe deleted successfully.
C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\WrtMon.exe moved successfully.
Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\cdoosoft not found.
C:\\Documents and Settings\\admin\\Ustawienia lokalne\\Temp\\herss.exe moved successfully.
Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\MyWebSearch Email Plugin deleted successfully.
File C:\\Program Files\\MyWebSearch\\bar\\7.bin\\MWSOEMON.EXE not found.
Registry value HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\PopularScreensaversWallpaper deleted successfully.
C:\\Program Files\\MyWebSearch\\bar\\7.bin\\F3SCRCTR.DLL moved successfully.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4281dd50-cc84-11de-bef2-000fea14eaf1}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4281dd50-cc84-11de-bef2-000fea14eaf1}\\ not found.
File F:\\k8jc.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4281dd50-cc84-11de-bef2-000fea14eaf1}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4281dd50-cc84-11de-bef2-000fea14eaf1}\\ not found.
File F:\\k8jc.exe not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4943334c-0157-11dd-b821-000fea14eaf1}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4943334c-0157-11dd-b821-000fea14eaf1}\\ not found.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{4943334c-0157-11dd-b821-000fea14eaf1}\\ not found.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4943334c-0157-11dd-b821-000fea14eaf1}\\ not found.
C:\\WINDOWS\\system32\\setup.exe moved successfully.
Registry key HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{88d29556-354b-11dc-b512-000fea14eaf1}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{88d29556-354b-11dc-b512-000fea14eaf1}\\ not found.
C:\\k8jc.exe moved successfully.
File C:\\k8jc.exe not found.
========== FILES ==========
C:\\Program Files\\MyWebSearch\\SrchAstt\\6.bin folder moved successfully.
C:\\Program Files\\MyWebSearch\\SrchAstt folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\setups folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\Settings folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\Notifier folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\Message folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\icons folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\History folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\Game folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\Cache folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\Avatar folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\7.bin folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar\\5.bin folder moved successfully.
C:\\Program Files\\MyWebSearch\\bar folder moved successfully.
C:\\Program Files\\MyWebSearch folder moved successfully.
File\\Folder C:\\Program Files\\Mozilla Firefox\\plugins\\NPMyWebS.dll not found.
File\\Folder C:\\k8jc.exe not found.
File\\Folder F:\\k8jc.exe not found.
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\\software\\microsoft\\windows\\currentversion\\explorer\\mountpoints2\\ deleted successfully.
HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\\\\"SuperHidden\"|dword:00000001 /E : value set successfully!
HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\\\\"Hidden\"|dword:00000001 /E : value set successfully!
HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\\\\"ShowSuperHidden\"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Folder\\Hidden\\SHOWALL\\\\\"CheckedValue\"|dword:00000001 /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Folder\\SuperHidden\\Policy\\DontShowSuperHidden\\ deleted successfully.
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Folder\\SuperHidden\\Policy\\DontShowSuperHidden\\\\@|\"\" /E : value set successfully!
========== COMMANDS ==========
[EMPTYTEMP]
User: admin
->Temp folder emptied: 2058332 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 86237919 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2114584 bytes
%systemroot%\\System32 .tmp files removed: 5552676 bytes
Windows Temp folder emptied: 32768 bytes
RecycleBin emptied: 27265208 bytes
Total Files Cleaned = 117,71 mb
OTL by OldTimer - Version 3.1.16.0 log created on 12132009_141218
Files\\Folders moved on Reboot...
File move failed. C:\\WINDOWS\\temp\\_avast4_\\Webshlock.txt scheduled to be moved on reboot.
C:\\WINDOWS\\temp\\Perflib_Perfdata_620.dat moved successfully.
Registry entries deleted on Reboot...
|