tu logo z DSS. Deckard’s System Scanner v20071014.68
Run by User on 2005-08-03 15:08:08
Computer is in Normal Mode.
– System Restore --------------------------------------------------------------
Successfully created a Deckard’s System Scanner Restore Point.
– Last 5 Restore Point(s) –
16: 2005-08-03 13:08:10 UTC - RP39 - Deckard’s System Scanner Restore Point
15: 2005-08-03 12:11:39 UTC - RP38 - Punkt kontrolny systemu
14: 2005-08-02 10:35:30 UTC - RP37 - Punkt kontrolny systemu
13: 2005-07-30 19:22:44 UTC - RP36 - Punkt kontrolny systemu
12: 2005-07-28 20:26:48 UTC - RP35 - Punkt kontrolny systemu
– First Restore Point –
1: 2005-07-12 11:38:10 UTC - RP24 - Usunięto ESET NOD32 Antivirus
Backed up registry hives.
Performed disk cleanup.
– HijackThis (run as User.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:09:01, on 2005-08-03
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\User\Pulpit\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\User.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {31E7B3BE-10E7-46A8-8F6D-EFE84C967181} - C:\WINDOWS\system32\nnnoMCUl.dll
O2 - BHO: (no name) - {73984FE0-9702-4C55-9C7B-9BA3C5861F25} - C:\WINDOWS\system32\khfGwWMf.dll
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [MSConfig] C:\WINDOWS\system32\msconfig.exe /auto
O4 - HKCU…\Run: [DAEMON Tools Lite] “C:\Program Files\DAEMON Tools Lite\daemon.exe” -autorun
O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O17 - HKLM\System\CCS\Services\Tcpip…{5C149324-DE72-4062-857C-9CC20A47FBCA}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip…{BBA527F0-0FFD-4FBC-9104-E6674CCE3A63}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: bw00 - {9AD51BC0-535D-4C8E-88E0-0E67104B86E9} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: khfGwWMf - C:\WINDOWS\SYSTEM32\khfGwWMf.dll
O21 - SSODL: fsrpknov - {81A99A30-C2B0-4AC9-841E-29C125650B59} - C:\WINDOWS\fsrpknov.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 2447 bytes
– File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL “%1”,%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser “%1”,%*
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 sisidex - c:\windows\system32\drivers\sisidex.sys
R0 sisperf (Add Performance Filter Driver) - c:\windows\system32\drivers\sisperf.sys
R2 TBPanel - c:\windows\system32\drivers\tbpanel.sys
S3 Cardex - c:\windows\system32\drivers\tbpanel.sys
S3 gwiopm - d:\unknown device identifier\gwiopm.sys (file missing)
– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
– Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
– Files created between 2005-07-03 and 2005-08-03 -----------------------------
2007-10-11 09:55:10 88576 --a------ C:\WINDOWS\system32\infocardapi.dll
2007-10-09 12:58:20 16896 --a------ C:\WINDOWS\system32\tswpfwrp.exe
2007-05-12 11:06:08 218624 --a------ C:\WINDOWS\system32\uxtheme.dll
2007-05-12 11:06:08 140800 --a------ C:\WINDOWS\system32\sfc_os.dll
2007-05-11 12:28:03 2707456 --a------ C:\WINDOWS\system32\winntbbu.dll
2007-05-11 11:56:04 476672 --a------ C:\WINDOWS\system32\zipfldr.dll
2007-05-11 11:52:36 764928 --a------ C:\WINDOWS\system32\wiashext.dll
2007-05-11 11:52:00 113664 --a------ C:\WINDOWS\system32\stobject.dll
2007-05-11 11:51:34 494080 --a------ C:\WINDOWS\system32\shimgvw.dll
2007-05-11 11:51:23 1271296 --a------ C:\WINDOWS\system32\setupapi.dll
2007-05-11 11:51:08 858112 --a------ C:\WINDOWS\system32\rasdlg.dll
2007-05-11 11:50:47 175104 --a------ C:\WINDOWS\system32\photowiz.dll
2007-05-11 11:49:49 1561088 --a------ C:\WINDOWS\system32\msgina.dll
2007-05-11 11:49:21 404992 --a------ C:\WINDOWS\system32\fontext.dll
2007-05-11 11:48:47 504832 --a------ C:\WINDOWS\system32\cmdial32.dll
2007-05-11 11:48:36 37888 --a------ C:\WINDOWS\system32\batmeter.dll
2007-05-11 08:57:43 83456 --a------ C:\WINDOWS\system32\dfrgres.dll
2007-05-10 21:55:50 354816 --a------ C:\WINDOWS\system32\mydocs.dll
2007-05-10 21:55:33 1423872 --a------ C:\WINDOWS\explorer.exe
2007-05-10 18:22:31 494080 --a------ C:\WINDOWS\system32\wiaacmgr.exe
2007-05-10 18:22:14 225280 --a------ C:\WINDOWS\system32\taskmgr.exe
2007-05-10 18:21:33 71680 --a------ C:\WINDOWS\system32\notepad.exe
2007-05-10 18:20:12 1153536 --a------ C:\WINDOWS\system32\logonui.exe
2007-05-10 17:57:24 15360 --a------ C:\WINDOWS\system32\msisip.dll
2007-05-10 17:57:12 884736 --a------ C:\WINDOWS\system32\msimsg.dll
2007-05-10 17:57:02 271360 --a------ C:\WINDOWS\system32\msihnd.dll
2007-05-10 17:56:50 78848 --a------ C:\WINDOWS\system32\msiexec.exe
2007-05-10 17:56:44 2890240 --a------ C:\WINDOWS\system32\msi.dll
2007-05-10 16:51:30 1548288 --a------ C:\WINDOWS\system32\sfcfiles.dll
2007-05-10 16:14:49 45056 --a------ C:\WINDOWS\system32\rcimlby.exe
2007-05-10 16:14:39 293888 --a------ C:\WINDOWS\system32\osk.exe
2007-05-10 16:14:32 58880 --a------ C:\WINDOWS\system32\narrator.exe
2007-05-10 16:13:56 168960 --a------ C:\WINDOWS\system32\mobsync.exe
2007-05-10 16:13:34 76288 --a------ C:\WINDOWS\system32\magnify.exe
2007-03-22 20:25:02 124928 -----n— C:\WINDOWS\system32\prntvpt.dll
2005-08-03 15:08:55 0 d-------- C:\Program Files\Trend Micro
2005-08-03 15:03:19 0 d-------- C:\Combo-Fix
2005-08-02 21:42:28 98688 --a------ C:\WINDOWS\system32\wnjuiowx.dll
2005-07-30 22:22:56 99712 --a------ C:\WINDOWS\system32\wueujwhy.dll
2005-07-30 21:22:53 99712 --a------ C:\WINDOWS\system32\mhyemyyj.dll
2005-07-29 20:32:40 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2005-07-29 20:30:53 0 d-------- C:\Program Files\Skype
2005-07-29 20:30:53 0 d-------- C:\Program Files\Common Files\Skype
2005-07-25 18:13:03 94848 --a------ C:\WINDOWS\system32\rkwrcbxr.dll
2005-07-17 13:05:19 92672 --a------ C:\WINDOWS\system32\psyxgkga.dll
2005-07-13 01:19:21 0 d-------- C:\Program Files\Alwil Software
2005-07-09 02:43:16 32060 --ahs---- C:\WINDOWS\system32\lUCMonnn.ini2
2005-07-09 02:43:10 318208 -----n— C:\WINDOWS\system32\nnnoMCUl.dll
2005-07-09 02:38:07 29568 --a------ C:\WINDOWS\system32\yayvUMGy.dll
2005-07-09 02:38:07 29568 --a------ C:\WINDOWS\system32\khfGwWMf.dll
2005-07-09 02:37:42 200704 --a------ C:\WINDOWS\sqvgnrpx.dll
2005-07-09 02:37:42 270336 -----n— C:\WINDOWS\fsrpknov.dll
– Find3M Report ---------------------------------------------------------------
2007-05-11 11:50:25 335360 --a------ C:\WINDOWS\system32\mstask.dll
2007-05-10 18:21:56 159744 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-05-10 18:21:24 718336 --a------ C:\WINDOWS\system32\mstsc.exe
2007-05-10 18:19:30 118272 --a------ C:\WINDOWS\system32\calc.exe
2007-05-10 16:13:09 190976 --a------ C:\WINDOWS\system32\accwiz.exe
2005-08-03 14:57:26 0 d-------- C:\Program Files\Tlen.pl
2005-08-03 14:15:37 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Skype
2005-08-03 13:01:36 0 d-------- C:\Program Files\MoorHunt
2005-08-03 12:01:38 0 d-------- C:\Program Files\HLSW
2005-08-03 11:12:11 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Tlen.pl
2005-08-03 10:27:00 0 d-------- C:\Documents and Settings\User\Dane aplikacji\skypePM
2005-07-31 07:59:08 0 d-------- C:\Documents and Settings\User\Dane aplikacji\teamspeak2
2005-07-29 20:30:53 0 d-------- C:\Program Files\Common Files
2005-07-27 13:19:53 0 d-------- C:\Program Files\DMW Client 3
2005-07-14 15:31:34 0 d-------- C:\Program Files\Common Files\InstallShield
2005-07-13 11:40:22 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Identities
2005-07-13 00:11:29 488436 --a------ C:\WINDOWS\system32\perfh015.dat
2005-07-13 00:11:29 82614 --a------ C:\WINDOWS\system32\perfc015.dat
2005-07-10 16:11:10 0 d-------- C:\Documents and Settings\User\Dane aplikacji\COWON
– Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{31E7B3BE-10E7-46A8-8F6D-EFE84C967181}]
2005-07-09 02:43 318208 --------- C:\WINDOWS\system32\nnnoMCUl.dll
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{73984FE0-9702-4C55-9C7B-9BA3C5861F25}]
2005-07-09 02:38 29568 --a------ C:\WINDOWS\system32\khfGwWMf.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2005-01-29 12:57]
“MSConfig”=“C:\WINDOWS\system32\msconfig.exe” [2007-05-10 16:33]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“DAEMON Tools Lite”=“C:\Program Files\DAEMON Tools Lite\daemon.exe” [2008-04-01 11:39]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 02:44]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“DisableCAD”=1 (0x1)
“DisableStatusMessages”=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
“DisableRegistryTools”=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoSMHelp”=1 (0x1)
“NoSMMyPictures”=1 (0x1)
“NoSMConfigurePrograms”=1 (0x1)
“ClearRecentDocsOnExit”=1 (0x1)
“NoRecentDocsMenu”=1 (0x1)
“NoRecentDocsHistory”=1 (0x1)
“NoStartBanner”=1 (0x1)
“NoInstrumentation”=1 (0x1)
“NoStartMenuMFUprogramsList”=1 (0x1)
“NoLowDiskSpaceChecks”=1 (0x1)
“NoResolveTrack”=1 (0x1)
“LinkResolveIgnoreLinkInfo”=1 (0x1)
“NoResolveSearch”=1 (0x1)
[HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer]
“NoSMHelp”=1 (0x1)
“NoSMMyPictures”=1 (0x1)
“NoSMConfigurePrograms”=1 (0x1)
“ClearRecentDocsOnExit”=1 (0x1)
“NoRecentDocsMenu”=1 (0x1)
“NoRecentDocsHistory”=1 (0x1)
“NoStartBanner”=1 (0x1)
“NoInstrumentation”=1 (0x1)
“NoStartMenuMFUprogramsList”=1 (0x1)
“NoLowDiskSpaceChecks”=1 (0x1)
“NoResolveTrack”=1 (0x1)
“LinkResolveIgnoreLinkInfo”=1 (0x1)
“NoResolveSearch”=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
“{73984FE0-9702-4C55-9C7B-9BA3C5861F25}”= C:\WINDOWS\system32\khfGwWMf.dll [2005-07-09 02:38 29568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
“fsrpknov”= {81A99A30-C2B0-4AC9-841E-29C125650B59} - C:\WINDOWS\fsrpknov.dll [2008-07-08 11:01 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfGwWMf]
khfGwWMf.dll 2005-07-09 02:38 29568 C:\WINDOWS\system32\khfGwWMf.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
“Authentication Packages”= msv1_0 C:\WINDOWS\system32\nnnoMCUl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage]
“C:\Program Files\AdVantage\AdVantage.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DmwClient]
“C:\Program Files\DMW Client 3\dmwclient.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
“C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vcs6diamond]
D:\AV Vcs 6.0 DIAMOND\Vcs6Core.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService WebClient LmHosts RemoteRegistry upnphost SSDPSRV
– Hosts -----------------------------------------------------------------------
127.0.0.1 http://www.system-defender.com/freeware … id=37&p=01
– End of Deckard’s System Scanner: finished at 2005-08-03 15:10:00 ------------
(ja za godzinke wroce to dalej bedziemy probowac) pozdrawiam