HIJACK:
Logfile of HijackThis v1.99.1
Scan saved at 16:44:38, on 2006-12-16
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
F:\INSTAL\Avast\aswUpdSv.exe
F:\INSTAL\Avast\ashServ.exe
C:\WINDOWS\System32\svchost.exe
F:\INSTAL\Avast\ashMaiSv.exe
F:\INSTAL\Avast\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LClock\LClock.exe
F:\INSTAL\Avast\ashDisp.exe
F:\INSTAL\Cursor\CursorXP.exe
F:\INSTAL\StatBar\StatBar.exe
F:\INSTAL\Winamp\winamp.exe
F:\INSTAL\Mozilla\firefox.exe
H:\PROGRAMY\Programy\Do LOGA\hijackthis1.99.1\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/pl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.pl/search?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [avast!] F:\INSTAL\Avast\ashDisp.exe
O4 - HKCU\..\Run: [CursorXP] F:\INSTAL\Cursor\CursorXP.exe
O4 - HKCU\..\Run: [StatBar] F:\INSTAL\StatBar\StatBar.exe
O4 - HKCU\..\Run: [Kalendarz] F:\INSTAL\Kalendarz XP\Kalendarz.exe
O4 - HKCU\..\Run: [Winamp] F:\INSTAL\Winamp\winamp.exe
O8 - Extra context menu item: &Clean Traces - F:\INSTAL\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - F:\INSTAL\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - F:\INSTAL\DAP\dapextie2.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://F:\INSTAL\Office\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save to &Xdrive - res://F:\INSTAL\XDriver\xdrive.exe/std.html
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\INSTAL\Office\OFFICE11\REFIEBAR.DLL
O20 - Winlogon Notify: !SASWinLogon - F:\INSTAL\AntiSpyware\SASWINLO.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - F:\INSTAL\Avast\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - F:\INSTAL\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - F:\INSTAL\Avast\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - F:\INSTAL\Avast\ashWebSv.exe" /service (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - F:\INSTAL\TuneUP\WinStylerThemeSvc.exe
RUNNERS:
"Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CursorXP" = "F:\INSTAL\Cursor\CursorXP.exe" [" "]
"StatBar" = "F:\INSTAL\StatBar\StatBar.exe" ["Globe Software"]
"Kalendarz" = "F:\INSTAL\Kalendarz XP\Kalendarz.exe" [null data]
"Winamp" = "F:\INSTAL\Winamp\winamp.exe" ["Nullsoft"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"LClock" = "C:\Program Files\LClock\LClock.exe" [null data]
"avast!" = "F:\INSTAL\Avast\ashDisp.exe" [null data]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {HKLM...CLSID} = "Portable Media Devices Menu"
\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "F:\INSTAL\Avast\ashShell.dll" ["ALWIL Software"]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "F:\INSTAL\Office\OFFICE11\msohev.dll" [MS]
"{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"
-> {HKLM...CLSID} = "SimpleShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll" [empty string]
"{44440D00-FF19-4AFC-B765-9A0970567D97}" = "TuneUp Theme Extension"
-> {HKLM...CLSID} = "TuneUp Theme Extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32\uxtuneup.dll" ["TuneUp Software GmbH"]
"{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}" = "TuneUp Shredder Shell Context Menu Extension"
-> {HKLM...CLSID} = "TuneUp Shredder Shell Context Menu Extension"
\InProcServer32\(Default) = ""F:\INSTAL\TuneUP\sdshelex.dll"" ["TuneUp Software GmbH"]
"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"
-> {HKLM...CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "F:\INSTAL\Unlocker\UnlockerCOM.dll" [null data]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "F:\INSTAL\WinRaR\rarext.dll" [null data]
"{5D64CBA3-BDEC-427C-8A7F-8CB7C9EA7C74}" = "xdrive.LinkedIconOverlay"
-> {HKLM...CLSID} = "Xdrive LinkedIconOverlay Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\Overlay.dll" ["XDrive"]
"{7C541B8D-BD5A-4687-9010-50E2B5D4A8E4}" = "xdrive.LinkedSharedIconOverlay"
-> {HKLM...CLSID} = "Xdrive LinkedSharedIconOverlay Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\Overlay.dll" ["XDrive"]
"{39C2972F-3338-471B-8D67-FA82E46E3AC2}" = "xdrive.SharedIconOverlay"
-> {HKLM...CLSID} = "Xdrive SharedIconOverlay Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\Overlay.dll" ["XDrive"]
"{802293E4-9A69-4387-A084-42814E0BAE29}" = "XDrive properties shell extension"
-> {HKLM...CLSID} = "ShellExtnObj Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\PropExt.dll" [null data]
"{24E75230-0B5A-445D-822E-119FBB211AF4}" = "ExecHook"
-> {HKLM...CLSID} = "ShellObj Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\ExecHook.dll" [null data]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<> "{24E75230-0B5A-445D-822E-119FBB211AF4}" = "ExecHook"
-> {HKLM...CLSID} = "ShellObj Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\ExecHook.dll" [null data]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<> !SASWinLogon\DLLName = "F:\INSTAL\AntiSpyware\SASWINLO.DLL" ["SUPERAntiSpyware.com"]
<> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
HKLM\Software\Classes\PROTOCOLS\Filter\
<> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "F:\INSTAL\Avast\ashShell.dll" ["ALWIL Software"]
PropExt\(Default) = "{802293E4-9A69-4387-A084-42814E0BAE29}"
-> {HKLM...CLSID} = "ShellExtnObj Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\PropExt.dll" [null data]
TuneUp Shredder\(Default) = "{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}"
-> {HKLM...CLSID} = "TuneUp Shredder Shell Context Menu Extension"
\InProcServer32\(Default) = ""F:\INSTAL\TuneUP\sdshelex.dll"" ["TuneUp Software GmbH"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "F:\INSTAL\WinRaR\rarext.dll" [null data]
XdriveRightClickExt\(Default) = "{3C6CC269-AFF3-4D07-BB07-B26A86A4FEED}"
-> {HKLM...CLSID} = "RightClickContextMenu Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\RightClickExt.dll" [null data]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
TuneUp Shredder\(Default) = "{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}"
-> {HKLM...CLSID} = "TuneUp Shredder Shell Context Menu Extension"
\InProcServer32\(Default) = ""F:\INSTAL\TuneUP\sdshelex.dll"" ["TuneUp Software GmbH"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "F:\INSTAL\WinRaR\rarext.dll" [null data]
XdriveRightClickExt\(Default) = "{3C6CC269-AFF3-4D07-BB07-B26A86A4FEED}"
-> {HKLM...CLSID} = "RightClickContextMenu Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\RightClickExt.dll" [null data]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "F:\INSTAL\Avast\ashShell.dll" ["ALWIL Software"]
PropExt\(Default) = "{802293E4-9A69-4387-A084-42814E0BAE29}"
-> {HKLM...CLSID} = "ShellExtnObj Class"
\InProcServer32\(Default) = "F:\INSTAL\XDriver\PropExt.dll" [null data]
UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"
-> {HKLM...CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "F:\INSTAL\Unlocker\UnlockerCOM.dll" [null data]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "F:\INSTAL\WinRaR\rarext.dll" [null data]
HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"
-> {HKLM...CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "F:\INSTAL\Unlocker\UnlockerCOM.dll" [null data]
Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------
Note: detected settings may not have any effect.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"DisallowRun" = (REG_DWORD) hex:0x00000001
{unrecognized setting}
"NoFolderOptions" = (REG_DWORD) hex:0x00000001
{User Configuration|Administrative Templates|Windows Components|Windows Explorer|
Removes the Folder Options menu item from the Tools menu}
"NoStartMenuMorePrograms" = (REG_DWORD) hex:0x00000001
{User Configuration|Administrative Templates|Start Menu and Taskbar|
Remove All Programs list from the Start menu}
"ClearRecentDocsOnExit" = (REG_DWORD) hex:0x00000001
{unrecognized setting}
"NoRecentDocsNetHood" = (REG_DWORD) hex:0x00000001
{unrecognized setting}
"NoViewOnDrive" = (REG_DWORD) hex:0x0000000C
{unrecognized setting}
"NoDrives" = (REG_DWORD) hex:0x0000000C
{unrecognized setting}
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\AREK\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\MGB_SC~1.SCR" (MGB_ScreenSaver.scr) ["Tenmiles Corporation"]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\System32\nwprovau.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 33
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Explorer Bars
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Badanie"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "F:\INSTAL\Office\OFFICE11\REFIEBAR.DLL" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
"ButtonText" = "Badanie"
Miscellaneous IE Hijack Points
------------------------------
HKLM\Software\Microsoft\Internet Explorer\AboutURLs\
<> "TuneUp" = "file://C|/Documents and Settings/All Users/Dane aplikacji/TuneUp Software/Common/base.css" [file not found]
HOSTS file
----------
C:\WINDOWS\System32\drivers\etc\HOSTS
maps: 2 domain names to IP addresses,
1 of the IP addresses is *not* localhost!
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
Agent SAP, NwSapAgent, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\ipxsap.dll" [MS]}
Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
avast! Antivirus, avast! Antivirus, ""F:\INSTAL\Avast\ashServ.exe"" [null data]
avast! iAVS4 Control Service, aswUpdSv, ""F:\INSTAL\Avast\aswUpdSv.exe"" [null data]
avast! Mail Scanner, avast! Mail Scanner, ""F:\INSTAL\Avast\ashMaiSv.exe" /service" ["ALWIL Software"]
avast! Web Scanner, avast! Web Scanner, ""F:\INSTAL\Avast\ashWebSv.exe" /service" ["ALWIL Software"]
TuneUp Design Expansion, UxTuneUp, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\uxtuneup.dll" ["TuneUp Software GmbH"]}
Usługa Pomocnik IPv6, 6to4, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\6to4svc.dll" [MS]}
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]
----------
<>: Suspicious data at a malware launch point.
<>: Suspicious data at a browser hijack point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 83 seconds, including 2 seconds for message boxes)