GreghorN
(Greghorn)
28 Październik 2007 19:45
#1
Witam, ostatnio mam problemy z pcetem, 100% użycie procka, zwiechy itp. stwierdziłem że wrzucę na forum loga z hijack ale nie mogę?! Po instalacji programu, przy próbie włączenia wyskoczył error : runtime error 32 at 0040A7D , klikam ok, a po jakimś czasie ponownie wyskakuje ten error, i tak cały czas, resetowałem komputer, nie odpalałem więcej Hijack ale error i tak wyskakuje.
Wie ktoś co z tym zrobić? Z góry dzięki za pomoc
LostWorld
(LostWorld)
28 Październik 2007 20:16
#2
To zapodaj log z Silenta , pokazuje ‘‘troszkę więcej’’ niż log z Hijackthis…
GreghorN
(Greghorn)
28 Październik 2007 20:43
#3
Ok, prosze bardzo, oto log z Silent Runnera
“Silent Runners.vbs”, revision 52, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ “w” = “F:\WINDOWS\WinRaR.exe” “wm” = “F:\WINDOWS\winlogor.exe” “wl” = “F:\WINDOWS\intent.exe” “mm” = “F:\WINDOWS\sourro.exe” “zx” = “F:\WINDOWS\winadr.exe” HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “RegClean Expert Scheduler” = ““F:\Program Files\Registry Clean Expert\RCHelper.exe” /startup” [“iExpert Software”] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “NvCplDaemon” = “RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup” [MS] “NvMediaCenter” = “RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit” [MS] “QuickTime Task” = ““F:\Program Files\QuickTime\qttask.exe” -atboottime” [“Apple Inc.”] “SunJavaUpdateSched” = ““F:\Program Files\Java\jre1.6.0_03\bin\jusched.exe”” [“Sun Microsystems, Inc.”] “ZoneAlarm Client” = ““F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe”” [“Zone Labs, LLC”] “WINDVDPatch” = “CTHELPER.EXE” [“Creative Technology Ltd”] “Jet Detection” = ““F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe”” [empty string] “Vistadrv” = “C:\Documents and Settings\Tomek.HOME\Pulpit\Pobierane\Vistadrive\Vistadrive\vsdrv.exe” [null data] “Sony Ericsson PC Suite” = ““F:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions” [“Sony Ericsson Mobile Communications AB”] “PowerS” = “F:\WINDOWS\PowerS.exe” [“prolink”] “WinampAgent” = “F:\Program Files\Winamp\winampa.exe” [null data] “mxlrqdc” = “F:\Program Files\Common Files\System\sudlces.exe” [null data] “vsttfnv” = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “AcroIEHlprObj Class” \InProcServer32(Default) = “F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}(Default) = “BitComet ClickCapture” -> {HKLM…CLSID} = “BitComet Helper” \InProcServer32(Default) = “F:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll” [“BitComet”] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM…CLSID} = “SSVHelper Class” \InProcServer32(Default) = “F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll” [“Sun Microsystems, Inc.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “F:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”] “{A70C977A-BF00-412C-90B7-034C51DA2439}” = “NvCpl DesktopContext Class” -> {HKLM…CLSID} = “DesktopContext Class” \InProcServer32(Default) = “F:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{FFB699E0-306A-11d3-8BD1-00104B6F7516}” = “Play on my TV helper” -> {HKLM…CLSID} = “NVIDIA CPL Extension” \InProcServer32(Default) = “F:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{1CDB2949-8F65-4355-8456-263E7C208A5D}” = “Desktop Explorer” -> {HKLM…CLSID} = “Desktop Explorer” \InProcServer32(Default) = “F:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}” = “Desktop Explorer Menu” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “F:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A48}” = “nView Desktop Context Menu” -> {HKLM…CLSID} = “nView Desktop Context Menu” \InProcServer32(Default) = “F:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{ABC70703-32AF-11d4-90C4-D483A70F4825}” = “CMenuExtender” -> {HKLM…CLSID} = “CMenuExtender” \InProcServer32(Default) = “F:\WINDOWS\BricoPacks\Vista Inspirat\iColorFolder\CMExt.dll” [“Revenger inc.”] “{453D1B6D-BD6A-4FA1-B876-9E4DD848D434}” = “AQQ File Transfer Shell Extension” -> {HKLM…CLSID} = “AQQ File Transfer Shell Extension” \InProcServer32(Default) = “F:\PROGRA~1\WapSter\AQQ\System\AQQSHE~1.DLL” [null data] “{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}” = “Messenger Sharing Folders” -> {HKLM…CLSID} = “Moje foldery udostępniania” \InProcServer32(Default) = “F:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll” [MS] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “F:\Program Files\WinRAR\rarext.dll” [null data] “{2B3453E4-49DF-11D3-8229-0080BE509050}” = “GMail Drive” -> {HKLM…CLSID} = “GMail Drive” \InProcServer32(Default) = “F:\WINDOWS\system32\ShellExt\GMailFS.dll” [“Bjarke Viksoe”] “{2B3453E4-49DF-11D3-8229-0080BE509052}” = “GMailFS Property Sheet” -> {HKLM…CLSID} = “GMailFS Property Sheet” \InProcServer32(Default) = “F:\WINDOWS\system32\ShellExt\GMailFS.dll” [“Bjarke Viksoe”] “{2B3453E4-49DF-11D3-8229-0080BE509054}” = “GMailFS Drop Handler” -> {HKLM…CLSID} = “GMailFS Drop Handler” \InProcServer32(Default) = “F:\WINDOWS\system32\ShellExt\GMailFS.dll” [“Bjarke Viksoe”] “{2B3453E4-49DF-11D3-8229-0080BE509056}” = “GMailFS Context Menu” -> {HKLM…CLSID} = “GMailFS Context Menu” \InProcServer32(Default) = “F:\WINDOWS\system32\ShellExt\GMailFS.dll” [“Bjarke Viksoe”] “{A5110426-177D-4e08-AB3F-785F10B4439C}” = “Sony Ericsson File Manager” -> {HKLM…CLSID} = “Sony Ericsson File Manager” \InProcServer32(Default) = “F:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrgui.dll” [“Sony Ericsson Mobile Communications AB”] HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ “WPDShServiceObj” = “{AAA288BA-9A4C-45B0-95D7-94D524869DB5}” -> {HKLM…CLSID} = “WPDShServiceObj Class” \InProcServer32(Default) = “F:\WINDOWS\system32\WPDShServiceObj.dll” [MS] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ <> “Userinit” = “F:\WINDOWS\system32\userinit.exe,F:\WINDOWS\system32\SVCH0ST.EXE” [MS], [null data] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ <> 360rpt.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> 360Safe.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> 360tray.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> adam.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> AgentSvr.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> AppSvc32.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> ArSwp.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> AST.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> autoruns.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> avconsol.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> avgrssvc.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> AvMonitor.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> avp.com \Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> avp.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> CCenter.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> ccSvcHst.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> EGHOST.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> FileDsty.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> FTCleanerShell.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> FYFireWall.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> HijackThis.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> IceSword.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> iparmo.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> Iparmor.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> isPwdSvc.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> kabaload.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KaScrScn.SCR\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KASMain.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KASTask.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KAV32.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KAVDX.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KAVPF.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KAVPFW.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KAVSetup.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KAVStart.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KISLnchr.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KMailMon.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KMFilter.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KPFW32.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KPFW32X.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KPfwSvc.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KRegEx.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KRepair.com \Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KsLoader.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KVCenter.kxp\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KvDetect.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KvfwMcl.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KVMonXP.kxp\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KVMonXP_1.kxp\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> kvol.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> kvolself.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KvReport.kxp\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KVScan.kxp\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KVSrvXP.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KVStub.kxp\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> kvupload.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> kvwsc.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KvXP.kxp\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KvXP_1.kxp\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KWatch.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KWatch9x.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> KWatchX.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> loaddll.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> MagicSet.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> mcconsol.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> mmqczj.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> mmsk.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> Navapsvc.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> Navapw32.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> nod32.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> nod32krn.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> nod32kui.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> NPFMntor.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> PFW.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> PFWLiveUpdate.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> QHSET.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> QQDoctor.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> QQKav.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> Ras.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> Rav.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> RavMon.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> RavMonD.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> RavStub.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> RavTask.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> RegClean.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> rfwcfg.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> rfwmain.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> rfwsrv.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> RsAgent.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> Rsaupd.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> rstrui.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> runiep.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> safelive.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> scan32.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> shcfg32.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> SmartUp.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> SREng.EXE\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> symlcsvc.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> SysSafe.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> TrojanDetector.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> Trojanwall.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> TrojDie.kxp\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> UIHost.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> UmxAgent.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> UmxAttachment.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> UmxCfg.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> UmxFwHlp.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> UmxPol.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> upiea.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> UpLive.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> USBCleaner.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> vsstat.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> webscanx.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] <> WoptiClean.exe\Debugger = “F:\Program Files\Common Files\Microsoft Shared\sirwnmi.exe” [null data] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info” -> {HKLM…CLSID} = “PDF Shell Extension” \InProcServer32(Default) = “F:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ AQQFileTransfer(Default) = “{453D1B6D-BD6A-4FA1-B876-9E4DD848D434}” -> {HKLM…CLSID} = “AQQ File Transfer Shell Extension” \InProcServer32(Default) = “F:\PROGRA~1\WapSter\AQQ\System\AQQSHE~1.DLL” [null data] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “F:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ CMenuExtender(Default) = “{ABC70703-32AF-11d4-90C4-D483A70F4825}” -> {HKLM…CLSID} = “CMenuExtender” \InProcServer32(Default) = “F:\WINDOWS\BricoPacks\Vista Inspirat\iColorFolder\CMExt.dll” [“Revenger inc.”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “F:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “F:\Program Files\WinRAR\rarext.dll” [null data] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ “NoStartBanner” = (REG_BINARY) hex:01 {Remove “Click here to begin” from Start button} “NoInstrumentation” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoStartMenuSubFolders” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoFavoritesMenu” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Start Menu and Taskbar| Remove Favorites menu from Start Menu} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} “undockwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ “Wallpaper” = “F:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp” Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ “Wallpaper” = “F:\Documents and Settings\Tomek\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp” Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ “SCRNSAVE.EXE” = “F:\WINDOWS\system32\logon.scr” [MS] Startup items in “Tomek” & “All Users” startup folders: ------------------------------------------------------- F:\Documents and Settings\Tomek\Menu Start\Programy\Autostart “Y’z ToolBar” -> shortcut to: “F:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe” [“Y’z@Home”] “Adobe Gamma” -> shortcut to: “F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe” [“Adobe Systems, Inc.”] <> “ET Q3 Minizer.exe” [“By UberGames”] F:\Documents and Settings\All Users\Menu Start\Programy\Autostart “Last.fm Helper” -> shortcut to: “F:\Program Files\Last.fm\LastFMHelper.exe” [“Last.fm”] Enabled Scheduled Tasks: ------------------------ “AppleSoftwareUpdate” -> launches: “F:\Program Files\Apple Software Update\SoftwareUpdate.exe -Task” [“Apple Computer, Inc.”] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ “MenuText” = “Sun Java Console” “CLSIDExtension” = “{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}” -> {HKCU…CLSID} = “Java Plug-in 1.6.0_03” \InProcServer32(Default) = “F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll” [“Sun Microsystems, Inc.”] -> {HKLM…CLSID} = “Java Plug-in 1.6.0_03” \InProcServer32(Default) = “F:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll” [“Sun Microsystems, Inc.”] {FB5F1910-F110-11D2-BB9E-00C04F795683}\ “ButtonText” = “Messenger” “MenuText” = “Windows Messenger” “Exec” = “F:\Program Files\Messenger\msmsgs.exe” [MS] Miscellaneous IE Hijack Points ------------------------------ HKLM\Software\Microsoft\Internet Explorer\AboutURLs\ <> “Tabs” = “F:\Documents and Settings\Tomek\Dane aplikacji\MEGAUPLOADTOOLBAR\tabwelcome.html” [file not found] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ pangu_service_display, pangu_service_svcname, “F:\WINDOWS\system32\temp_0.exe” [null data] PnkBstrA, PnkBstrA, “F:\WINDOWS\system32\PnkBstrA.exe” [null data] TrueVector Internet Monitor, vsmon, “F:\WINDOWS\system32\ZONELABS\vsmon.exe -service” [“Zone Labs, LLC”] WinFast® Display Driver Service, NVSvc, “F:\WINDOWS\system32\nvsvc32.exe” [“NVIDIA Corporation”] ---------- (launch time: 2007-10-28 21:40:10) <>: Suspicious data at a malware launch point. <>: Suspicious data at a browser hijack point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer “No” at the first message box and “Yes” at the second message box. ---------- (total run time: 69 seconds, including 3 seconds for message boxes)