
format z powodu kavo.exe i kilku niezidentyfikowanych. Ta konfiguracja ma posłużyć do zrobienia ghousta więc chce mieć pewność że jest ok. Dzieki za pomoc
z hijacka
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:47:33, on 2008-02-12
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
F:\Program Files\Alwil Software\Avast4\ashServ.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\lxdccoms.exe
F:\WINDOWS\system32\SLEE81.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
F:\WINDOWS\system32\igfxtray.exe
F:\WINDOWS\system32\hkcmd.exe
F:\WINDOWS\SOUNDMAN.EXE
F:\WINDOWS\ALCWZRD.EXE
F:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\Lexmark 1300 Series\lxdcamon.exe
F:\Program Files\Lexmark 2300 Series\lxcgmon.exe
F:\Program Files\Lexmark 2300 Series\ezprint.exe
F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
F:\Program Files\CafeNews\CN.exe
F:\Program Files\Spik\Spik.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
F:\WINDOWS\system32\lxcgcoms.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Pasek narzędzi - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - F:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - F:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - F:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: Lexmark Pasek narzędzi - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - F:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - F:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - F:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O4 - HKLM\..\Run: [IgfxTray] F:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] F:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Skrót do strony właściwości High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [iKeyWorks] F:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [lxdcmon.exe] "F:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "F:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [LXDCCATS] rundll32 F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [REGSHAVE] F:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [lxcgmon.exe] "F:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "F:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [avast!] F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [CafeNews] F:\Program Files\CafeNews\CN.exe /autostart
O4 - HKLM\..\Run: [Spik] F:\Program Files\Spik\Spik.exe -autostart
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [SSSSE7] "F:\Program Files\Steganos Security Suite 7 SE\sssse7.exe" -firstboot (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [SSSSE7] "F:\Program Files\Steganos Security Suite 7 SE\sssse7.exe" -firstboot (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SSSSE7] "F:\Program Files\Steganos Security Suite 7 SE\sssse7.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SSSSE7] "F:\Program Files\Steganos Security Suite 7 SE\sssse7.exe" -firstboot (User 'Default user')
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Subskrybuj w Cafe News - F:\Program Files\CafeNews\addFeed.htm
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1202688117000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202688266390
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F5C349F-DE60-4B93-96D4-08928EE649B4}: NameServer = 213.241.79.37 83.238.255.76
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wpmsg - {2E0AC5A0-3597-11D6-B3ED-0001021DC1C3} - F:\Program Files\Spik\url_wpmsg.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: lxcg_device - - F:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: lxdc_device - - F:\WINDOWS\system32\lxdccoms.exe
O23 - Service: Steganos Live Encryption Engine 8.1 [Service] (SLEE_81_SERVICE) - Unknown owner - F:\WINDOWS\system32\SLEE81.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - F:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7968 bytes
z silentruna
- Kod: Zaznacz wszystko
"Silent Runners.vbs", revision 55, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "F:\WINDOWS\system32\ctfmon.exe" [MS]
"SpybotSD TeaTimer" = "F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" ["Safer Networking Limited"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"IgfxTray" = "F:\WINDOWS\system32\igfxtray.exe" ["Intel Corporation"]
"HotKeysCmds" = "F:\WINDOWS\system32\hkcmd.exe" ["Intel Corporation"]
"Skrót do strony właściwości High Definition Audio" = "HDAudPropShortcut.exe" ["Windows (R) Server 2003 DDK provider"]
"SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
"AlcWzrd" = "ALCWZRD.EXE" ["RealTek Semicoductor Corp."]
"Alcmtr" = "ALCMTR.EXE" ["Realtek Semiconductor Corp."]
"iKeyWorks" = "F:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe" ["A4Tech Co.,Ltd."]
"SpeedTouch USB Diagnostics" = ""F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon" ["THOMSON Telecom Belgium"]
"RemoteControl" = ""F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]
"lxdcmon.exe" = ""F:\Program Files\Lexmark 1300 Series\lxdcmon.exe"" [file not found]
"lxdcamon" = ""F:\Program Files\Lexmark 1300 Series\lxdcamon.exe"" [null data]
"LXDCCATS" = "rundll32 F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16" [MS]
"REGSHAVE" = "F:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN" ["FUJI PHOTO FILM CO., LTD."]
"lxcgmon.exe" = ""F:\Program Files\Lexmark 2300 Series\lxcgmon.exe"" ["Lexmark International, Inc."]
"EzPrint" = ""F:\Program Files\Lexmark 2300 Series\ezprint.exe"" ["Lexmark International Inc."]
"avast!" = "F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" ["ALWIL Software"]
"ZoneAlarm Client" = ""F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"" ["Zone Labs, LLC"]
"CafeNews" = "F:\Program Files\CafeNews\CN.exe /autostart" ["Cafe News sp. z o.o. www.cafenews.pl, Multimedia Cafe www.mmcafe.pl"]
"Spik" = "F:\Program Files\Spik\Spik.exe -autostart" [null data]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
\InProcServer32\(Default) = "F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{1017A80C-6F09-4548-A84D-EDD6AC9525F0}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Lexmark Pasek narzędzi"
\InProcServer32\(Default) = "F:\Program Files\Lexmark Toolbar\toolband.dll" [null data]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Spybot-S&D IE Protection"
\InProcServer32\(Default) = "F:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
{C451C08A-EC37-45DF-AAAD-18B51AB5E837}\(Default) = (no title provided)
-> {HKLM...CLSID} = "PDFCreator Toolbar Helper"
\InProcServer32\(Default) = "F:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll" [null data]
{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}\(Default) = "ZoneAlarm Spy Blocker BHO"
-> {HKLM...CLSID} = "ZoneAlarm Spy Blocker BHO"
\InProcServer32\(Default) = "F:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" ["ZoneAlarm"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "F:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}" = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"
-> {HKLM...CLSID} = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"
\InProcServer32\(Default) = "F:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "F:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]
"{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"
-> {HKLM...CLSID} = "Microsoft Office Metadata Handler"
\InProcServer32\(Default) = "F:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
"{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"
-> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler"
\InProcServer32\(Default) = "F:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "F:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
"{D9872D13-7651-4471-9EEE-F0A00218BEBB}" = "Multiscan"
-> {HKLM...CLSID} = "ZLAVShExt Class"
\InProcServer32\(Default) = "F:\Program Files\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "F:\Program Files\WinRAR\rarext.dll" [null data]
"{B4B924A2-EBDA-11DA-95DA-00E08161165F}" = "Dodatki Spika"
-> {HKLM...CLSID} = "SpikShellExt Class"
\InProcServer32\(Default) = "F:\Program Files\Spik\shellext_wpmsg.dll" ["Wirtualna Polska"]
"{00000000-5736-4205-0100-1967b1b2ce60}" = "Steganos Security Suite 7 Special Edition"
-> {HKLM...CLSID} = "Steganos Security Suite 7 Special Edition"
\InProcServer32\(Default) = "f:\program files\steganos security suite 7 se\sssse7se.dll" [null data]
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter"
\InProcServer32\(Default) = "F:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "F:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
Spik\(Default) = "{B4B924A2-EBDA-11DA-95DA-00E08161165F}"
-> {HKLM...CLSID} = "SpikShellExt Class"
\InProcServer32\(Default) = "F:\Program Files\Spik\shellext_wpmsg.dll" ["Wirtualna Polska"]
Steganos Security Suite 7 Special Edition\(Default) = "{00000000-5736-4205-0100-1967b1b2ce60}"
-> {HKLM...CLSID} = "Steganos Security Suite 7 Special Edition"
\InProcServer32\(Default) = "f:\program files\steganos security suite 7 se\sssse7se.dll" [null data]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "F:\Program Files\WinRAR\rarext.dll" [null data]
ZLAVShExt\(Default) = "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"
-> {HKLM...CLSID} = "ZLAVShExt Class"
\InProcServer32\(Default) = "F:\Program Files\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
Steganos Security Suite 7 Special Edition\(Default) = "{00000000-5736-4205-0100-1967b1b2ce60}"
-> {HKLM...CLSID} = "Steganos Security Suite 7 Special Edition"
\InProcServer32\(Default) = "f:\program files\steganos security suite 7 se\sssse7se.dll" [null data]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "F:\Program Files\WinRAR\rarext.dll" [null data]
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "F:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
Spik\(Default) = "{B4B924A2-EBDA-11DA-95DA-00E08161165F}"
-> {HKLM...CLSID} = "SpikShellExt Class"
\InProcServer32\(Default) = "F:\Program Files\Spik\shellext_wpmsg.dll" ["Wirtualna Polska"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "F:\Program Files\WinRAR\rarext.dll" [null data]
ZLAVShExt\(Default) = "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"
-> {HKLM...CLSID} = "ZLAVShExt Class"
\InProcServer32\(Default) = "F:\Program Files\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]
Group Policies {policy setting}:
--------------------------------
Note: detected settings may not have any effect.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Devices: Allow undock without having to log on}
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "F:\WINDOWS\web\wallpaper\Idylla.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "F:\WINDOWS\web\wallpaper\Idylla.bmp"
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "F:\WINDOWS\System32\logon.scr" [MS]
DESKTOP.INI DLL launch in local fixed drive directories:
--------------------------------------------------------
WARNING! D: is an unreadable partition!
WARNING! E: is an unreadable partition!
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 21
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}"
-> {HKLM...CLSID} = "Lexmark Pasek narzędzi"
\InProcServer32\(Default) = "F:\Program Files\Lexmark Toolbar\toolband.dll" [null data]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"
-> {HKLM...CLSID} = "ZoneAlarm Spy Blocker"
\InProcServer32\(Default) = "F:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" ["ZoneAlarm"]
"{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}"
-> {HKLM...CLSID} = "PDFCreator Toolbar"
\InProcServer32\(Default) = "F:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll" [null data]
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = (no title provided)
-> {HKLM...CLSID} = "Lexmark Pasek narzędzi"
\InProcServer32\(Default) = "F:\Program Files\Lexmark Toolbar\toolband.dll" [null data]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}" = (no title provided)
-> {HKLM...CLSID} = "ZoneAlarm Spy Blocker"
\InProcServer32\(Default) = "F:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" ["ZoneAlarm"]
"{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}" = "PDFCreator Toolbar"
-> {HKLM...CLSID} = "PDFCreator Toolbar"
\InProcServer32\(Default) = "F:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll" [null data]
Explorer Bars
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
HKLM\SOFTWARE\Classes\CLSID\{916C1EF1-CA89-4F1B-AFDA-3CA85BD0F831}\(Default) = "ZoneAlarm PopBlocker"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "F:\WINDOWS\system32\shdocvw.dll" [MS]
HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Poszukaj"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{2670000A-7350-4F3C-8081-5663EE0C6C49}\
"ButtonText" = "Wyślij do programu OneNote"
"MenuText" = "Wyślij &do programu OneNote"
"CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}"
-> {HKLM...CLSID} = "Send to OneNote from Internet Explorer button"
\InProcServer32\(Default) = "F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll" [MS]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
"ButtonText" = "Research"
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\
"MenuText" = "Spybot - Search & Destroy Configuration"
"CLSIDExtension" = "{53707962-6F74-2D53-2644-206D7942484F}"
-> {HKLM...CLSID} = "Spybot-S&D IE Protection"
\InProcServer32\(Default) = "F:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "F:\Program Files\Messenger\msmsgs.exe" [MS]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
avast! Antivirus, avast! Antivirus, ""F:\Program Files\Alwil Software\Avast4\ashServ.exe"" ["ALWIL Software"]
avast! iAVS4 Control Service, aswUpdSv, ""F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" ["ALWIL Software"]
avast! Mail Scanner, avast! Mail Scanner, ""F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
avast! Web Scanner, avast! Web Scanner, ""F:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
lxcg_device, lxcg_device, "F:\WINDOWS\system32\lxcgcoms.exe -service" [" "]
lxdc_device, lxdc_device, "F:\WINDOWS\system32\lxdccoms.exe -service" [" "]
Steganos Live Encryption Engine 8.1 [Service], SLEE_81_SERVICE, "F:\WINDOWS\system32\SLEE81.exe" [null data]
TrueVector Internet Monitor, vsmon, "F:\WINDOWS\system32\ZoneLabs\vsmon.exe -service" ["Zone Labs, LLC"]
Windows User Mode Driver Framework, UMWdf, "F:\WINDOWS\system32\wdfmgr.exe" [MS]
Print Monitors:
---------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
1300 Series Port\Driver = "lxdclmpm.DLL" [" "]
2300 Series Port\Driver = "lxcglmpm.DLL" [" "]
PDFCreator\Driver = "pdfcmnnt.dll" ["internet-support foehr.com"]
Send To Microsoft OneNote Monitor\Driver = "msonpmon.dll" [MS]
---------- (launch time: 2008-02-12 21:45:05)
<<!>>: Suspicious data at a malware launch point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 40 seconds.
---------- (total run time: 85 seconds)
z combofixa
- Kod: Zaznacz wszystko
ComboFix 08-02-13.1 - rybak_dusz 2008-02-12 21:56:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.534 [GMT 1:00]
Running from: F:\Documents and Settings\rybak_dusz\Pulpit\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((( Files Created from 2008-01-13 to 2008-02-13 )))))))))))))))))))))))))))))))
.
2008-02-12 21:46 . 2008-02-12 21:46 <DIR> d-------- F:\Program Files\Trend Micro
2008-02-12 21:36 . 2008-02-12 21:36 1,167 --a------ F:\WINDOWS\mozver.dat
2008-02-12 21:34 . 2008-02-12 21:34 <DIR> d-------- F:\WINDOWS\LastGood
2008-02-11 08:51 . 2007-07-30 19:19 271,224 --a------ F:\WINDOWS\system32\mucltui.dll
2008-02-11 08:51 . 2007-07-30 19:18 30,072 --a------ F:\WINDOWS\system32\mucltui.dll.mui
2008-02-11 01:21 . 2008-02-12 21:34 <DIR> d--h----- F:\WINDOWS\$hf_mig$
2008-02-11 01:21 . 2005-06-28 10:21 22,752 --a------ F:\WINDOWS\system32\spupdsvc.exe
2008-02-11 01:02 . 2007-07-30 19:19 43,352 --a------ F:\WINDOWS\system32\wups2.dll
2008-02-11 01:02 . 2007-07-30 19:19 38,232 --a------ F:\WINDOWS\system32\wucltui.dll.mui
2008-02-11 01:02 . 2007-07-30 19:20 30,040 --a------ F:\WINDOWS\system32\wuaucpl.cpl.mui
2008-02-11 01:02 . 2007-07-30 19:20 30,040 --a------ F:\WINDOWS\system32\wuapi.dll.mui
2008-02-11 01:02 . 2007-07-30 19:18 21,336 --a------ F:\WINDOWS\system32\wuaueng.dll.mui
2008-02-11 01:01 . 2008-02-11 01:01 <DIR> d---s---- F:\Documents and Settings\rybak_dusz\UserData
2008-02-11 00:47 . 2008-02-11 00:47 <DIR> d-------- F:\Documents and Settings\rybak_dusz\Dane aplikacji\skypePM
2008-02-11 00:47 . 2008-02-11 00:47 32 --a------ F:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-02-11 00:44 . 2008-02-11 00:44 <DIR> d-------- F:\Program Files\Skype
2008-02-11 00:44 . 2008-02-11 00:44 <DIR> d-------- F:\Program Files\Common Files\Skype
2008-02-11 00:44 . 2008-02-11 01:44 <DIR> d-------- F:\Documents and Settings\rybak_dusz\Dane aplikacji\Skype
2008-02-11 00:44 . 2008-02-11 00:44 <DIR> d-------- F:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-02-11 00:43 . 2008-02-11 00:43 <DIR> d-------- F:\Program Files\Steganos Security Suite 7 SE
2008-02-11 00:40 . 2008-02-11 00:40 0 --a------ F:\WINDOWS\nsreg.dat
2008-02-11 00:38 . 2008-02-11 00:39 <DIR> d-------- F:\Program Files\Spik
2008-02-11 00:38 . 2008-02-11 00:38 <DIR> d-------- F:\Documents and Settings\rybak_dusz\Dane aplikacji\Spik
2008-02-11 00:35 . 2008-02-11 00:35 <DIR> d-------- F:\Program Files\XnView
2008-02-11 00:34 . 2008-02-11 00:36 <DIR> d-------- F:\Program Files\Winamp
2008-02-11 00:34 . 2008-02-11 00:34 <DIR> d-------- F:\Program Files\totalcmd
2008-02-11 00:34 . 2008-02-11 00:34 <DIR> d-------- F:\Documents and Settings\rybak_dusz\Dane aplikacji\Winamp
2008-02-11 00:33 . 2008-02-11 00:33 <DIR> d-------- F:\Program Files\Spybot - Search & Destroy
2008-02-11 00:33 . 2008-02-11 00:59 <DIR> d-------- F:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-02-11 00:29 . 2008-02-11 00:29 14,290 --a------ F:\Program Files\settings.dat
2008-02-11 00:28 . 2008-02-11 00:28 <DIR> d-------- F:\Program Files\PDFCreator Toolbar
2008-02-11 00:28 . 2008-02-11 00:29 <DIR> d-------- F:\Program Files\PDFCreator
2008-02-11 00:28 . 2004-03-09 00:00 662,288 --a------ F:\WINDOWS\system32\MSCOMCT2.OCX
2008-02-11 00:28 . 2008-02-11 00:28 253,116 --a------ F:\WINDOWS\PDFCreator_Toolbar_Uninstaller_3781.exe
2008-02-11 00:28 . 2005-10-15 12:32 196,608 --a------ F:\WINDOWS\system32\pdfcmnnt.dll
2008-02-11 00:28 . 1998-06-24 00:00 137,000 --a------ F:\WINDOWS\system32\MSMAPI32.OCX
2008-02-11 00:28 . 1998-07-06 00:00 23,552 --a------ F:\WINDOWS\system32\MSMPIDE.DLL
2008-02-11 00:27 . 2008-02-11 00:27 <DIR> d-------- F:\Program Files\FastStone Image Viewer
2008-02-11 00:25 . 2008-02-11 00:26 <DIR> d-------- F:\Program Files\DAEMON Tools Lite
2008-02-11 00:25 . 2008-02-11 01:39 <DIR> d-------- F:\Program Files\AdVantage
2008-02-11 00:25 . 2008-02-11 00:25 <DIR> d-------- F:\Documents and Settings\rybak_dusz\Dane aplikacji\DAEMON Tools
2008-02-11 00:21 . 2008-02-11 00:21 716,272 --a------ F:\WINDOWS\system32\drivers\sptd.sys
2008-02-11 00:17 . 2008-02-11 00:17 <DIR> d-------- F:\Program Files\CafeNews
2008-02-11 00:17 . 2008-02-11 00:17 <DIR> d-------- F:\Documents and Settings\rybak_dusz\PressService
2008-02-11 00:16 . 2008-02-11 00:16 1,559,040 --a------ F:\WINDOWS\system32\xvidcore.dll
2008-02-11 00:16 . 2008-02-11 00:16 524,288 --a------ F:\WINDOWS\system32\DivXsm.exe
2008-02-11 00:16 . 2008-02-11 00:16 352,401 --a------ F:\WINDOWS\system32\DivXMedia.ax
2008-02-11 00:16 . 2008-02-11 00:16 77,824 --a------ F:\WINDOWS\system32\xvid.ax
2008-02-11 00:15 . 2008-02-11 00:15 <DIR> d-------- F:\Program Files\MarBit
2008-02-11 00:14 . 2008-02-11 00:14 <DIR> d-------- F:\Program Files\Common Files\Adobe
2008-02-11 00:14 . 2008-02-11 00:42 1,010 --a------ F:\WINDOWS\unins000.dat
2008-02-11 00:13 . 2008-02-11 00:13 <DIR> d-------- F:\Program Files\AllMyMovies
2008-02-11 00:05 . 2008-02-13 21:58 974,880 --ahs---- F:\WINDOWS\system32\drivers\fidbox.dat
2008-02-11 00:05 . 2008-02-12 21:31 12,968 --ahs---- F:\WINDOWS\system32\drivers\fidbox.idx
2008-02-11 00:04 . 2008-02-11 00:04 <DIR> d-------- F:\Program Files\ZoneAlarmSB
2008-02-11 00:02 . 2008-02-11 00:02 <DIR> d-------- F:\Program Files\Zone Labs
2008-02-11 00:02 . 2008-02-11 00:02 <DIR> d-------- F:\Documents and Settings\All Users\Dane aplikacji\MailFrontier
2008-02-11 00:01 . 2008-02-11 00:01 <DIR> d-------- F:\Program Files\Alwil Software
2008-02-11 00:01 . 2003-03-18 21:20 1,060,864 --a------ F:\WINDOWS\system32\MFC71.dll
2008-02-11 00:01 . 2007-12-04 14:04 837,496 --a------ F:\WINDOWS\system32\aswBoot.exe
2008-02-11 00:01 . 2003-03-18 20:14 499,712 --a------ F:\WINDOWS\system32\MSVCP71.dll
2008-02-11 00:01 . 2004-01-09 10:13 380,928 --a------ F:\WINDOWS\system32\actskin4.ocx
2008-02-11 00:01 . 2003-02-21 04:42 348,160 --a------ F:\WINDOWS\system32\MSVCR71.dll
2008-02-11 00:01 . 2007-12-04 13:54 95,608 --a------ F:\WINDOWS\system32\AvastSS.scr
2008-02-11 00:01 . 2007-12-04 15:55 94,544 --a------ F:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-11 00:01 . 2007-12-04 15:56 93,264 --a------ F:\WINDOWS\system32\drivers\aswmon.sys
2008-02-11 00:01 . 2007-12-04 15:51 42,912 --a------ F:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-11 00:01 . 2007-12-04 15:49 26,624 --a------ F:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-11 00:01 . 2007-12-04 15:53 23,152 --a------ F:\WINDOWS\system32\drivers\aswRdr.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-12 20:33 --------- d-----w F:\Program Files\Lx_cats
2008-02-10 23:17 921,600 ----a-w F:\WINDOWS\system32\vorbisenc.dll
2008-02-10 23:17 9,216 ----a-w F:\WINDOWS\system32\cpuinf32.dll
2008-02-10 23:17 892,928 ----a-w F:\WINDOWS\system32\iconv.dll
2008-02-10 23:17 45,056 ----a-w F:\WINDOWS\system32\ogg.dll
2008-02-10 23:17 245,760 ----a-w F:\WINDOWS\system32\mplvpx.dll
2008-02-10 23:17 237,568 ----a-w F:\WINDOWS\system32\OggDS.dll
2008-02-10 23:17 188,416 ----a-w F:\WINDOWS\system32\vorbis.dll
2008-02-10 23:17 1,415,680 ----a-w F:\WINDOWS\system32\WMV9VCM.dll
2008-02-10 22:59 --------- d-----w F:\Program Files\Lexmark 2300 Series
2008-02-10 22:54 --------- d-----w F:\Program Files\FinePixViewer
2008-02-10 22:54 --------- d-----w F:\Documents and Settings\rybak_dusz\Dane aplikacji\FUJIFILM
2008-02-10 22:51 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-02-10 22:51 --------- d-----w F:\Program Files\PIXELA
2008-02-10 22:51 --------- d-----w F:\Program Files\Common Files\InstallShield
2008-02-10 22:50 --------- d-----w F:\Program Files\REGSHAVE
2008-02-10 22:46 --------- d-----w F:\Program Files\Lexmark Toolbar
2008-02-10 22:46 --------- d-----w F:\Documents and Settings\rybak_dusz\Dane aplikacji\Lexmark Imaging Studio
2008-02-10 22:45 --------- d-----w F:\Program Files\Lexmark 1300 Series
2008-02-10 22:29 --------- d-----w F:\Program Files\Microsoft Works
2008-02-10 22:29 --------- d-----w F:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-02-10 22:23 --------- d-----w F:\Program Files\CyberLink
2008-02-10 22:23 --------- d-----w F:\Documents and Settings\All Users\Dane aplikacji\CyberLink
2008-02-10 22:20 --------- d-----w F:\Program Files\Ahead
2008-02-10 22:19 --------- d-----w F:\Program Files\Common Files\Nero
2008-02-10 22:18 --------- d-----w F:\Program Files\Common Files\Ahead
2008-02-10 22:18 --------- d-----w F:\Documents and Settings\All Users\Dane aplikacji\Ahead
2008-02-10 22:15 --------- d-----w F:\Documents and Settings\All Users\Dane aplikacji\Bluetooth
2008-02-10 22:11 --------- d-----w F:\Program Files\IVT Corporation
2008-02-10 22:07 --------- d-----w F:\Program Files\Thomson
2008-02-10 22:05 --------- d-----w F:\Program Files\NEC DISPLAY SOLUTIONS
2008-02-10 22:04 6,494 ----a-w F:\WINDOWS\system32\drivers\Moni2c.sys
2008-02-10 22:02 --------- d-----w F:\Program Files\A4Tech
2008-02-10 21:58 73,728 ----a-w F:\WINDOWS\ALCFDRTM.EXE
2008-02-10 21:56 --------- d-----w F:\Program Files\Realtek
2008-02-10 21:56 --------- d-----w F:\Program Files\GIGABYTE
2008-02-10 21:53 --------- d-----w F:\Program Files\Intel
2008-02-10 21:20 --------- d-----w F:\Program Files\microsoft frontpage
2008-02-10 21:19 --------- d-----w F:\Program Files\Usługi online
2007-11-14 15:05 75,248 ----a-w F:\WINDOWS\zllsputility.exe
2007-11-14 15:05 1,086,952 ----a-w F:\WINDOWS\system32\zpeng24.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-02-11 00:04 262144 --a------ F:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1017A80C-6F09-4548-A84D-EDD6AC9525F0}
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= F:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-02-11 00:04 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
"SpybotSD TeaTimer"="F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="F:\WINDOWS\system32\igfxtray.exe" [2004-11-02 02:03 155648]
"HotKeysCmds"="F:\WINDOWS\system32\hkcmd.exe" [2004-11-02 01:59 126976]
"Skrót do strony właściwości High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 15:10 61952 F:\WINDOWS\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-11-02 07:53 77824 F:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-12-10 08:38 2749440 F:\WINDOWS\ALCWZRD.EXE]
"iKeyWorks"="F:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe" [2005-04-14 05:35 73728]
"SpeedTouch USB Diagnostics"="F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"RemoteControl"="F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"lxdcmon.exe"="F:\Program Files\Lexmark 1300 Series\lxdcmon.exe" [ ]
"lxdcamon"="F:\Program Files\Lexmark 1300 Series\lxdcamon.exe" [2007-02-06 00:32 20480]
"LXDCCATS"="F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll" [2007-01-22 23:05 102400]
"REGSHAVE"="F:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 22:32 53248]
"lxcgmon.exe"="F:\Program Files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 02:08 200704]
"EzPrint"="F:\Program Files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 08:05 94208]
"avast!"="F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"ZoneAlarm Client"="F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"CafeNews"="F:\Program Files\CafeNews\CN.exe" [2007-06-28 13:43 1224704]
"Spik"="F:\Program Files\Spik\Spik.exe" [2008-01-24 14:33 103912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SSSSE7"="F:\Program Files\Steganos Security Suite 7 SE\sssse7.exe" [2004-11-30 13:52 249856]
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BlueSoleil.lnk]
path=F:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BlueSoleil.lnk
backup=F:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Exif Launcher.lnk]
path=F:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Exif Launcher.lnk
backup=F:\WINDOWS\pss\Exif Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage]
--a------ 2007-11-05 11:12 884176 F:\Program Files\AdVantage\AdVantage.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-01-17 17:51 486856 F:\Program Files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 F:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-02-01 17:26 22014760 F:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"odserv"=3 (0x3)
"BlueSoleil Hid Service"=2 (0x2)
R2 lxdc_device;lxdc_device;F:\WINDOWS\system32\lxdccoms.exe [2007-02-13 00:56]
R2 SLEE_81_DRIVER;Steganos Live Encryption Engine 8.1 [Driver];F:\WINDOWS\system32\drivers\SLEE81.sys [2004-11-19 09:28]
S3 DDCCI;DDC/CI monitor;F:\WINDOWS\system32\DRIVERS\Moni2c.sys [2008-02-10 23:04]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c6407fe-d82b-11dc-b14b-000e50ea25e8}]
\Shell\Auto\command - UFO.exe
\Shell\AutoRun\command - F:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-13 21:58:06
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXDCCATS = rundll32 F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16?????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: F:\WINDOWS\explorer.exe [6.00.2900.2180]
-> F:\Program Files\Spik\idlehk.dll
.
Completion time: 2008-02-13 21:58:49
.
2008-02-12 20:28:20 --- E O F ---