All processes killed
========== OTL ==========
No active process named explorer.exe was found!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "Ask.com" removed from browser.search.selectedEngine
Prefs.js: "http://www.theprizeday.com/today.php|http://www.ask.com?o=13170&l=dis" removed from browser.startup.homepage
Prefs.js:
Zango@Zango.com:10.3.85.0 removed from extensions.enabledItems
Prefs.js:
toolbar@ask.com:3.5.1.110 removed from extensions.enabledItems
C:\Documents and Settings\Roman\Data aplikací\Mozilla\Firefox\Profiles\0sdkz6lh.default\searchplugins\askcom.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\answers.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\combofix deleted successfully.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\WINDOWS\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2 deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8 deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:59756FA4 deleted successfully.
========== FILES ==========
C:\WINDOWS\002745_.tmp moved successfully.
C:\WINDOWS\SET21.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\System32\CONFIG.TMP moved successfully.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\RECYCLER\S-1-5-21-3381830484-841843799-610201639-1005 folder moved successfully.
C:\RECYCLER folder moved successfully.
File\Folder C:\$RECYCLE.BIN not found.
File\Folder C:\Documents and Settings\NetworkService\Data aplikací\rbuwzv.dat not found.
C:\Documents and Settings\All Users\Data aplikací\NOS\Adobe_Downloads folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\NOS folder moved successfully.
C:\Documents and Settings\Roman\Local Settings\Data aplikací\Threat Expert\Browser Defender folder moved successfully.
C:\Documents and Settings\Roman\Local Settings\Data aplikací\Threat Expert folder moved successfully.
C:\WINDOWS\PCTBDCore.dll.old moved successfully.
C:\WINDOWS\tasks\SA.DAT moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 78924 bytes
User: Administrator.ROMAN-B8F685043
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 4738 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Roman
->Temp folder emptied: 2546060 bytes
->Temporary Internet Files folder emptied: 254819779 bytes
->FireFox cache emptied: 51174147 bytes
->Google Chrome cache emptied: 6201409 bytes
->Flash cache emptied: 2275846 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1608 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 2412876 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 305,00 mb
[EMPTYFLASH]
User: Administrator
User: Administrator.ROMAN-B8F685043
User: All Users
User: Default User
User: LocalService
User: NetworkService
User: Roman
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.1.37.3 log created on 03222010_213627
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...