Logfile of HijackThis v1.99.1 Scan saved at 08:27:52, on 2007-04-04 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\hkcmd.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe C:\WINDOWS\system32\proquota.exe C:\Program Files\Internet Explorer\iexplore.exe \SBS2005\desktop$\poziomd\student015d\Pulpit\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sbs2005/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://sbs2005:8080/array.dll?Get.Routing.Script R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sbs2005:8080 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is missing O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar_pl_4.0.1601-big.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar_pl_4.0.1601-big.dll O4 - HKLM…\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM…\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM…\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM…\Run: [RemoteControl] “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” O4 - HKLM…\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM…\Run: [ccApp] “C:\Program Files\Common Files\Symantec Shared\ccApp.exe” O4 - HKLM…\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background O4 - HKCU…\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - Global Startup: Microsoft Firewall Client Management.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra ‘Tools’ menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll O10 - Broken Internet access because of LSP provider ‘ws2icp.dll’ missing O14 - IERESET.INF: START_PAGE_URL=http://companyweb O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar1.google.com/data/pl/big/ … gleNav.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup … 2969911490 O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - http://sbs2005/tsweb/msrdp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sbsmenis.edu.pl O17 - HKLM\Software…\Telephony: DomainName = sbsmenis.edu.pl O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sbsmenis.edu.pl O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing) O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Cenzor Upgrade (CenzorUpgrade) - Unknown owner - C:\WINDOWS\system32\Cenzorupg.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe “Silent Runners.vbs”, revision R50, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “MSMSGS” = ““C:\Program Files\Messenger\msmsgs.exe” /background” [MS] “swg” = “C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe” [“Google Inc.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “SoundMan” = “SOUNDMAN.EXE” [“Realtek Semiconductor Corp.”] “IgfxTray” = “C:\WINDOWS\system32\igfxtray.exe” [“Intel Corporation”] “HotKeysCmds” = “C:\WINDOWS\system32\hkcmd.exe” [“Intel Corporation”] “NeroFilterCheck” = “C:\WINDOWS\system32\NeroCheck.exe” [“Ahead Software Gmbh”] “RemoteControl” = ““C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”” [“Cyberlink Corp.”] “HP Software Update” = “C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [“Hewlett-Packard Co.”] “ccApp” = ““C:\Program Files\Common Files\Symantec Shared\ccApp.exe”” [“Symantec Corporation”] “vptray” = “C:\PROGRA~1\SYMANT~1\VPTray.exe” [“Symantec Corporation”] “QuickTime Task” = ““C:\Program Files\QuickTime\qttask.exe” -atboottime” [“Apple Computer, Inc.”] “KernelFaultCheck” = “C:\WINDOWS\system32\dumprep 0 -k” HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {AA58ED58-01DD-4d91-8333-CF10577473F7}(Default) = (no title provided) -> {HKLM…CLSID} = “Google Toolbar Helper” \InProcServer32(Default) = “c:\windows\downloaded program files\googletoolbar_pl_4.0.1601-big.dll” [“Google Inc.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Rozszerzenie CPL kadrowania wyświetlania” -> {HKLM…CLSID} = “Rozszerzenie CPL kadrowania wyświetlania” \InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”] “{00020D75-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Desktop Icon Handler” -> {HKLM…CLSID} = “Microsoft Office Outlook” \InProcServer32(Default) = “C:\PROGRA~1\MICROS~4\OFFICE11\MLSHEXT.DLL” [MS] “{0006F045-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Custom Icon Handler” -> {HKLM…CLSID} = “Rozszerzenie ikon plików programu Outlook” \InProcServer32(Default) = “C:\PROGRA~1\MICROS~4\OFFICE11\OLKFSTUB.DLL” [MS] “{42042206-2D85-11D3-8CFF-005004838597}” = “Microsoft Office HTML Icon Handler” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Microsoft Office\OFFICE11\msohev.dll” [MS] “{cc86590a-b60a-48e6-996b-41d25ed39a1e}” = “Portable Media Devices Menu” -> {HKLM…CLSID} = “Portable Media Devices Menu” \InProcServer32(Default) = “C:\WINDOWS\system32\Audiodev.dll” [MS] “{B327765E-D724-4347-8B16-78AE18552FC3}” = “NeroDigitalIconHandler” -> {HKLM…CLSID} = “NeroDigitalIconHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{7F1CF152-04F8-453A-B34C-E609530A9DC8}” = “NeroDigitalPropSheetHandler” -> {HKLM…CLSID} = “NeroDigitalPropSheetHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{BDA77241-42F6-11d0-85E2-00AA001FE28C}” = “LDVP Shell Extensions” -> {HKLM…CLSID} = “VpshellEx Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll” [“Symantec Corporation”] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ <> igfxcui\DLLName = “igfxsrvc.dll” [“Intel Corporation”] <> NavLogon\DLLName = “C:\WINDOWS\system32\NavLogon.dll” [“Symantec Corporation”] HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\0\ DisplayName = “Men Studenci” 0\ -> launches: “\sbsmenis.edu.pl\sysvol\sbsmenis.edu.pl\Policies{EDB5126B-6624-44D5-8DF2-2CE1C763AE0F}\User\Scripts\Logon\printer.cmd” [** WMI GetObject error **] HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\0\ DisplayName = “Komputery” 0\ -> launches: “\sbsmenis.edu.pl\sysvol\sbsmenis.edu.pl\Policies{2EDC9B26-BAB7-4868-BD60-A859BB0DFE13}\Machine\Scripts\Startup\isacli.cmd” [** WMI GetObject error **] HKLM\Software\Classes\PROTOCOLS\Filter\ <> text/xml\CLSID = “{807553E5-5146-11D5-A672-00B0D022E945}” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL” [MS] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {7D4D6379-F301-4311-BEBA-E26EB0561882}(Default) = “NeroDigitalExt.NeroDigitalColumnHandler” -> {HKLM…CLSID} = “NeroDigitalColumnHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ LDVPMenu(Default) = “{BDA77241-42F6-11d0-85E2-00AA001FE28C}” -> {HKLM…CLSID} = “VpshellEx Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll” [“Symantec Corporation”] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ LDVPMenu(Default) = “{BDA77241-42F6-11d0-85E2-00AA001FE28C}” -> {HKLM…CLSID} = “VpshellEx Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll” [“Symantec Corporation”] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ “DisallowRun” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “RecycleBinSize” = (REG_DWORD) hex:0x00000005 {unrecognized setting} “NoManageMyComputerVerb” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoHardwareTab” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “ForceStartMenuLogOff” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoRecentDocsHistory” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoResolveSearch” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoResolveTrack” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoStartMenuSubFolders” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoChangeStartMenu” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoCommonGroups” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoWindowsUpdate” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Start Menu and Taskbar| Remove links and access to Windows Update} “ClearRecentDocsOnExit” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “GreyMSIAds” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “Intellimenus” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoInstrumentation” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “DisablePersonalDirChange” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoActiveDesktopChanges” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Desktop|Desktop / Active Desktop| Prohibit changes} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ “NoWelcomeScreen” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoMSAppLogo5ChannelNotify” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “DisableRegistryTools” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|System| Prevent access to registry editing tools} “NoDispSettingsPage” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoDispScrSavPage” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “SetVisualStyle” = (REG_SZ) %systemroot%\resources\themes\luna\luna.msstyles {unrecognized setting} “HideLogonScripts” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “RunLogonScriptSync” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “HideLogoffScripts” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “HideLegacyLogonScripts” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “DisableLockWorkstation” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “EnableProfileQuota” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “ProfileQuotaMessage” = (REG_SZ) Przekroczony został obszar przechowywania profilów. Przed wylogowaniem musisz przenieść niektóre elementy z profilu do magazynu sieciowego lub lokalnego. {unrecognized setting} “MaxProfileSize” = (REG_DWORD) hex:0x00007530 {unrecognized setting} “WarnUser” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “WarnUserTimeout” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\ “Connwiz Admin Lock” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “ResetWebSettings” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable the Reset Web Settings feature} “Check_If_Default” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “Autoconfig” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “History” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “Ratings” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “Advanced” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable changing Advanced page settings} “Connection Settings” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable changing connection settings} “Proxy” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable changing proxy settings} “HomePage” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable changing home page settings} “Cache” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “Accessibility” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\ “NoJITSetup” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoUpdateCheck” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoSplash” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\ “NoExternalBranding” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoHelpItemSendFeedback” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKCU\Software\Policies\Microsoft\Windows\Network Connections\ “NC_EnableAdminProhibits” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_AddRemoveComponents” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit adding and removing components for a LAN or remote access connection} “NC_DialupPrefs” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_AdvancedSettings” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_NewConnectionWizard” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_LanProperties” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit access to properties of a LAN connection} “NC_RasChangeProperties” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit access to properties of components of a remote access connection} “NC_LanChangeProperties” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit access to properties of components of a LAN connection} “NC_AllowAdvancedTCPIPConfig” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_RasConnect” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_DeleteConnection” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit deletion of remote access connections} “NC_ChangeBindState” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_RenameMyRasConnection” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_RasMyProperties” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_Statistics” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit viewing of status for an active connection} “NC_RenameConnection” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_RasAllUserProperties” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_DeleteAllUserConnection” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_LanConnect” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_RenameLanConnection” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NC_RenameAllUserRasConnection” = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKCU\Software\Policies\Microsoft\Windows\System\ “GroupPolicyMinTransferRate” = (REG_DWORD) hex:0x0000012C {unrecognized setting} “GroupPolicyRefreshTime” = (REG_DWORD) hex:0x0000003C {unrecognized setting} “GroupPolicyRefreshTimeOffset” = (REG_DWORD) hex:0x0000001E {unrecognized setting} HKLM\Software\Policies\Microsoft\Windows\Task Scheduler5.0\ “Property Pages” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “Execution” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “DragAndDrop” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “Task Creation” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “Task Deletion” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Administrative Templates|Windows Components|Task Scheduler| Prohibit Task deletion} “Disable Advanced” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “Allow Browse” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} “undockwithoutlogon” = (REG_DWORD) hex:0x00000000 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} “disablecad” = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore\ “DisableSR” = (REG_DWORD) hex:0x00000000 {Computer Configuration|Administrative Templates|System|System Restore| Turn off System Restore} “DisableConfig” = (REG_DWORD) hex:0x00000000 {Computer Configuration|Administrative Templates|System|System Restore| Turn off Configuration} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ “Wallpaper” = “C:\WINDOWS\Web\Wallpaper\Idylla.bmp” Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ “Wallpaper” = “C:\WINDOWS\Web\Wallpaper\Idylla.bmp” Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ “SCRNSAVE.EXE” = “C:\WINDOWS\System32\logon.scr” [MS] Startup items in “student015d” & “All Users” startup folders: ------------------------------------------------------------- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart “Microsoft Firewall Client Management” -> shortcut to: “C:\WINDOWS\Installer{199B7F78-69B7-47C5-8D4B-A3ED1391FB6B}\NewShortcut1_8C7A59A89ABE459A9A9308C281A4A264.exe” [“InstallShield Software Corp.”] Enabled Scheduled Tasks: ------------------------ “AppleSoftwareUpdate.job” – insufficient permission to read this file! Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “C:\Program Files\Microsoft Firewall Client 2004\FwcWsp.dll” [“Microsoft ® Corporation”] 000000000002\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000004\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: ws2icp.dll [null data], 01 - 05, 21 C:\Program Files\Microsoft Firewall Client 2004\FwcWsp.dll [“Microsoft ® Corporation”], 06, 08, 11, 13 %SystemRoot%\system32\mswsock.dll [MS], 07, 09 - 10, 15 - 20 %SystemRoot%\system32\rsvpsp.dll [MS], 12, 14 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ “{2318C2B1-4965-11D4-9B18-009027A5CD4F}” -> {HKLM…CLSID} = “&Google” \InProcServer32(Default) = “c:\windows\downloaded program files\googletoolbar_pl_4.0.1601-big.dll” [“Google Inc.”] HKLM\Software\Microsoft\Internet Explorer\Toolbar\ “{2318C2B1-4965-11D4-9B18-009027A5CD4F}” = (no title provided) -> {HKLM…CLSID} = “&Google” \InProcServer32(Default) = “c:\windows\downloaded program files\googletoolbar_pl_4.0.1601-big.dll” [“Google Inc.”] Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ HKLM\Software\Classes\CLSID{FF059E31-CC5A-4E2E-BF3B-96E929D65503}(Default) = “&Badanie” Implemented Categories{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32(Default) = “C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL” [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {92780B25-18CC-41C8-B9BE-3C9C571A8263}\ “ButtonText” = “Badanie” {FB5F1910-F110-11D2-BB9E-00C04F795683}\ “ButtonText” = “@C:\Program Files\Messenger\Msgslang.dll,-61144” “MenuText” = “@C:\Program Files\Messenger\Msgslang.dll,-61144” “Exec” = “C:\Program Files\Messenger\msmsgs.exe” [MS] Miscellaneous IE Hijack Points ------------------------------ C:\WINDOWS\INF\IERESET.INF (used to “Reset Web Settings”) Added lines (compared with English-language version): [strings]: START_PAGE_URL=http://companyweb Missing lines (compared with English-language version): [strings]: 1 line Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Firewall Client Agent, FwcAgent, ““C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe”” [“Microsoft ® Corporation”] Machine Debug Manager, MDM, ““C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE”” [MS] Symantec AntiVirus, Symantec AntiVirus, ““C:\Program Files\Symantec AntiVirus\Rtvscan.exe”” [“Symantec Corporation”] Symantec AntiVirus Definition Watcher, DefWatch, ““C:\Program Files\Symantec AntiVirus\DefWatch.exe”” [“Symantec Corporation”] Symantec Event Manager, ccEvtMgr, ““C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe”” [“Symantec Corporation”] Symantec Settings Manager, ccSetMgr, ““C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe”” [“Symantec Corporation”] Symantec SPBBCSvc, SPBBCSvc, ““C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe”” [“Symantec Corporation”] Windows User Mode Driver Framework, UMWdf, “C:\WINDOWS\system32\wdfmgr.exe” [MS] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ Microsoft Document Imaging Writer Monitor\Driver = “mdimon.dll” [MS] ---------- <>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer “No” at the first message box and “Yes” at the second message box. ---------- (total run time: 66 seconds, including 2 seconds for message boxes)