Kaktusek
(Pbiernacki28)
31 Październik 2006 20:54
#1
Logfile of HijackThis v1.99.1 Scan saved at 21:28:35, on 2006-10-31 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Gadu-Gadu\gg.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe C:\Program Files\ivo\UniSpiker-2.6\uni_spiker-2.6.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\Program Files\Skype\Phone\Skype.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Piotrek\Pulpit\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O4 - HKLM…\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM…\Run: [ATICCC] “C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” runtime O4 - HKLM…\Run: [tguard] C:\Program Files\Beniamin\tguard.exe O4 - HKLM…\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM…\Run: [RemoteControl] “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” O4 - HKLM…\Run: [LanguageShortcut] “C:\Program Files\CyberLink\PowerDVD\Language\Language.exe” O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM…\Run: [nod32kui] “C:\Program Files\Eset\nod32kui.exe” /WAITSERVICE O4 - HKLM…\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM…\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe O4 - HKCU…\Run: [Gadu-Gadu] “C:\Program Files\Gadu-Gadu\gg.exe” /tray O4 - Startup: UniSpiker-2.6.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: ATI CATALYST – pasek zadań.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O15 - Trusted Zone: http://*.mks.com.pl O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} (MainControl Class) - http://mks.com.pl/skaner/SkanerOnline.cab O17 - HKLM\System\CCS\Services\Tcpip…{4089B6BB-21D6-42D0-86FB-61B40E349745}: NameServer = 10.0.3.250,62.233.128.17 O17 - HKLM\System\CS1\Services\Tcpip…{4089B6BB-21D6-42D0-86FB-61B40E349745}: NameServer = 10.0.3.250,62.233.128.17 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
Wiem że na kompie mam 5 trojanów, ale nie wiem jak je usunąc, więc czy w tym logu widac jakies trojanki? Proszę o sprawdzenie.
adam9870
(adam9870)
31 Październik 2006 21:07
#2
W logu nic nie widać - jest ok.
Tylko poza małym szczegółem:
Jeśli Sbybot ma na to ochronę to nie usuwasz i jeśli nie przeszkadza Ci to. A w przeciwnym wypadku - wpisy lecą.
Skąd masz podejrzenia, że złapałeś trojany? Jeśli poinformował Cię to tym program antywirusowy to proszę podać dokładną ścieżkę do plików.
Użyj Windows Worms Doors Cleanera zmień znaczki z disable na enable (wszystkie znaczki maja być na zielono, jezeli któryś z nich bedzie na żółto to go zostaw). Po użyciu narzędzia wymagany jest restart.
Wklej jeszcze loga z SilentRunners . Może on coś pokaże…
Kaktusek
(Pbiernacki28)
31 Październik 2006 21:21
#3
Oto log z SilentRunnersa
“Silent Runners.vbs”, revision 49, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “Gadu-Gadu” = ““C:\Program Files\Gadu-Gadu\gg.exe” /tray” [“Gadu-Gadu S.A.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “SoundMan” = “SOUNDMAN.EXE” [“Realtek Semiconductor Corp.”] “ATICCC” = ““C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” runtime” [null data] “tguard” = “C:\Program Files\Beniamin\tguard.exe” [file not found] “PWRISOVM.EXE” = “C:\Program Files\PowerISO\PWRISOVM.EXE” [“PowerISO Computing, Inc.”] “RemoteControl” = ““C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”” [“Cyberlink Corp.”] “LanguageShortcut” = ““C:\Program Files\CyberLink\PowerDVD\Language\Language.exe”” [null data] “NeroFilterCheck” = “C:\WINDOWS\system32\NeroCheck.exe” [“Ahead Software Gmbh”] “nod32kui” = ““C:\Program Files\Eset\nod32kui.exe” /WAITSERVICE” ["Eset "] “MSConfig” = “C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto” [MS] “TrojanScanner” = “C:\Program Files\Trojan Remover\Trjscan.exe” [“Simply Super Software”] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “AcroIEHlprObj Class” \InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] {53707962-6F74-2D53-2644-206D7942484F}(Default) = (no title provided) -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Spybot - Search & Destroy\SDHelper.dll” [“Safer Networking Limited”] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM…CLSID} = “SSVHelper Class” \InProcServer32(Default) = “C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll” [“Sun Microsystems, Inc.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Rozszerzenie CPL kadrowania wyświetlania” -> {HKLM…CLSID} = “Rozszerzenie CPL kadrowania wyświetlania” \InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “C:\WINDOWS\System32\hticons.dll” [“Hilgraeve, Inc.”] “{5E2121EE-0300-11D4-8D3B-444553540000}” = “Catalyst Context Menu extension” -> {HKLM…CLSID} = “SimpleShlExt Class” \InProcServer32(Default) = “C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll” [empty string] “{cc86590a-b60a-48e6-996b-41d25ed39a1e}” = “Portable Media Devices Menu” -> {HKLM…CLSID} = “Portable Media Devices Menu” \InProcServer32(Default) = “C:\WINDOWS\system32\Audiodev.dll” [MS] “{59850401-6664-101B-B21C-00AA004BA90B}” = “Microsoft Office Binder Unbind” -> {HKLM…CLSID} = “Microsoft Office Binder Unbind” \InProcServer32(Default) = “C:\PROGRA~1\MICROS~2\Office\1045\UNBIND.DLL” [MS] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] “{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}” = “PowerISO” -> {HKLM…CLSID} = “PowerISO” \InProcServer32(Default) = “C:\Program Files\PowerISO\PWRISOSH.DLL” [“PowerISO Computing, Inc.”] “{B327765E-D724-4347-8B16-78AE18552FC3}” = “NeroDigitalIconHandler” -> {HKLM…CLSID} = “NeroDigitalIconHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{7F1CF152-04F8-453A-B34C-E609530A9DC8}” = “NeroDigitalPropSheetHandler” -> {HKLM…CLSID} = “NeroDigitalPropSheetHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{B089FE88-FB52-11D3-BDF1-0050DA34150D}” = “NOD32 Context Menu Shell Extension” -> {HKLM…CLSID} = “NOD32 Context Menu Shell Extension” \InProcServer32(Default) = “C:\Program Files\Eset\nodshex.dll” [null data] “{52B87208-9CCF-42C9-B88E-069281105805}” = “Trojan Remover Shell Extension” -> {HKLM…CLSID} = “Trojan Remover Shell Extension” \InProcServer32(Default) = “C:\PROGRA~1\TROJAN~1\Trshlex.dll” [“Simply Super Software”] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ <> AtiExtEvent\DLLName = “Ati2evxx.dll” [“ATI Technologies Inc.”] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {7D4D6379-F301-4311-BEBA-E26EB0561882}(Default) = “NeroDigitalExt.NeroDigitalColumnHandler” -> {HKLM…CLSID} = “NeroDigitalColumnHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info” -> {HKLM…CLSID} = “PDF Shell Extension” \InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ NOD32 Context Menu Shell Extension(Default) = “{B089FE88-FB52-11D3-BDF1-0050DA34150D}” -> {HKLM…CLSID} = “NOD32 Context Menu Shell Extension” \InProcServer32(Default) = “C:\Program Files\Eset\nodshex.dll” [null data]
O tych trojanach poinformował mnie nodzik
mam 4 takie http://proffy209.com/adv/122fil_mem.htm
i jeden taki http://proffy209.com/adv/122/xpl.wmf
adam9870
(adam9870)
31 Październik 2006 21:24
#4
Log z silenta jest ucięty. Poczekaj aż program skończy robić log, poinformuje wtedy odpowiednim komunikatem i dopiero wtedy wklej go na forum. Ale myślę, że na 99% nic nie pokaże.
Kiedy nodzik informuje Cię o tych wirusach? Radziłbym po prostu nie wchodzić na stronę na, której są śmieci. I nie zapomnij pozamykać portów robakom przy pomocy wwdc.
Kaktusek
(Pbiernacki28)
31 Październik 2006 21:31
#5
O wirusach poinformował mnie tylko raz, przy wejściu na taką jedną stronę. Gdy wchodzę w dziennik infekcji mam tam zapisane te 5 ataków trojanów i pisze że nie podją żadnych czynnościco do tych trojanów.Oto komplety log:
“Silent Runners.vbs”, revision 49, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “Gadu-Gadu” = ““C:\Program Files\Gadu-Gadu\gg.exe” /tray” [“Gadu-Gadu S.A.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “SoundMan” = “SOUNDMAN.EXE” [“Realtek Semiconductor Corp.”] “ATICCC” = ““C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” runtime” [null data] “tguard” = “C:\Program Files\Beniamin\tguard.exe” [file not found] “PWRISOVM.EXE” = “C:\Program Files\PowerISO\PWRISOVM.EXE” [“PowerISO Computing, Inc.”] “RemoteControl” = ““C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”” [“Cyberlink Corp.”] “LanguageShortcut” = ““C:\Program Files\CyberLink\PowerDVD\Language\Language.exe”” [null data] “NeroFilterCheck” = “C:\WINDOWS\system32\NeroCheck.exe” [“Ahead Software Gmbh”] “nod32kui” = ““C:\Program Files\Eset\nod32kui.exe” /WAITSERVICE” ["Eset "] “MSConfig” = “C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto” [MS] “TrojanScanner” = “C:\Program Files\Trojan Remover\Trjscan.exe” [“Simply Super Software”] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “AcroIEHlprObj Class” \InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] {53707962-6F74-2D53-2644-206D7942484F}(Default) = (no title provided) -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Spybot - Search & Destroy\SDHelper.dll” [“Safer Networking Limited”] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM…CLSID} = “SSVHelper Class” \InProcServer32(Default) = “C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll” [“Sun Microsystems, Inc.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Rozszerzenie CPL kadrowania wyświetlania” -> {HKLM…CLSID} = “Rozszerzenie CPL kadrowania wyświetlania” \InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “C:\WINDOWS\System32\hticons.dll” [“Hilgraeve, Inc.”] “{5E2121EE-0300-11D4-8D3B-444553540000}” = “Catalyst Context Menu extension” -> {HKLM…CLSID} = “SimpleShlExt Class” \InProcServer32(Default) = “C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll” [empty string] “{cc86590a-b60a-48e6-996b-41d25ed39a1e}” = “Portable Media Devices Menu” -> {HKLM…CLSID} = “Portable Media Devices Menu” \InProcServer32(Default) = “C:\WINDOWS\system32\Audiodev.dll” [MS] “{59850401-6664-101B-B21C-00AA004BA90B}” = “Microsoft Office Binder Unbind” -> {HKLM…CLSID} = “Microsoft Office Binder Unbind” \InProcServer32(Default) = “C:\PROGRA~1\MICROS~2\Office\1045\UNBIND.DLL” [MS] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] “{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}” = “PowerISO” -> {HKLM…CLSID} = “PowerISO” \InProcServer32(Default) = “C:\Program Files\PowerISO\PWRISOSH.DLL” [“PowerISO Computing, Inc.”] “{B327765E-D724-4347-8B16-78AE18552FC3}” = “NeroDigitalIconHandler” -> {HKLM…CLSID} = “NeroDigitalIconHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{7F1CF152-04F8-453A-B34C-E609530A9DC8}” = “NeroDigitalPropSheetHandler” -> {HKLM…CLSID} = “NeroDigitalPropSheetHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{B089FE88-FB52-11D3-BDF1-0050DA34150D}” = “NOD32 Context Menu Shell Extension” -> {HKLM…CLSID} = “NOD32 Context Menu Shell Extension” \InProcServer32(Default) = “C:\Program Files\Eset\nodshex.dll” [null data] “{52B87208-9CCF-42C9-B88E-069281105805}” = “Trojan Remover Shell Extension” -> {HKLM…CLSID} = “Trojan Remover Shell Extension” \InProcServer32(Default) = “C:\PROGRA~1\TROJAN~1\Trshlex.dll” [“Simply Super Software”] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ <> AtiExtEvent\DLLName = “Ati2evxx.dll” [“ATI Technologies Inc.”] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {7D4D6379-F301-4311-BEBA-E26EB0561882}(Default) = “NeroDigitalExt.NeroDigitalColumnHandler” -> {HKLM…CLSID} = “NeroDigitalColumnHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info” -> {HKLM…CLSID} = “PDF Shell Extension” \InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ NOD32 Context Menu Shell Extension(Default) = “{B089FE88-FB52-11D3-BDF1-0050DA34150D}” -> {HKLM…CLSID} = “NOD32 Context Menu Shell Extension” \InProcServer32(Default) = “C:\Program Files\Eset\nodshex.dll” [null data] PowerISO(Default) = “{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}” -> {HKLM…CLSID} = “PowerISO” \InProcServer32(Default) = “C:\Program Files\PowerISO\PWRISOSH.DLL” [“PowerISO Computing, Inc.”] Trojan Remover(Default) = “{52B87208-9CCF-42C9-B88E-069281105805}” -> {HKLM…CLSID} = “Trojan Remover Shell Extension” \InProcServer32(Default) = “C:\PROGRA~1\TROJAN~1\Trshlex.dll” [“Simply Super Software”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ PowerISO(Default) = “{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}” -> {HKLM…CLSID} = “PowerISO” \InProcServer32(Default) = “C:\Program Files\PowerISO\PWRISOSH.DLL” [“PowerISO Computing, Inc.”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ NOD32 Context Menu Shell Extension(Default) = “{B089FE88-FB52-11D3-BDF1-0050DA34150D}” -> {HKLM…CLSID} = “NOD32 Context Menu Shell Extension” \InProcServer32(Default) = “C:\Program Files\Eset\nodshex.dll” [null data] PowerISO(Default) = “{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}” -> {HKLM…CLSID} = “PowerISO” \InProcServer32(Default) = “C:\Program Files\PowerISO\PWRISOSH.DLL” [“PowerISO Computing, Inc.”] Trojan Remover(Default) = “{52B87208-9CCF-42C9-B88E-069281105805}” -> {HKLM…CLSID} = “Trojan Remover Shell Extension” \InProcServer32(Default) = “C:\PROGRA~1\TROJAN~1\Trshlex.dll” [“Simply Super Software”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ “NoNetHood” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoDrives” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoFavoritesMenu” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Start Menu and Taskbar| Remove Favorites menu from Start Menu} “NoCommonGroups” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoLogOff” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|System|Logon/Logoff| Disable Logoff} “StartMenuLogoff” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoFind” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoStartMenuSubFolders” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoSetTaskBar” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Start Menu and Taskbar| Prevent changes to Taskbar and Start Menu Settings} “NoSetFolders” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoDesktop” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoRecentDocsMenu” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoSMHelp” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Start Menu and Taskbar| Remove Help menu from Start Menu} “NoControlPanel” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoNetworkConnections” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Start Menu and Taskbar| Remove Network Connections from Start Menu} “NoSMMyDocs” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Start Menu and Taskbar| Remove Documents menu from Start Menu} “NoSetActiveDesktop” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoFolderOptions” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Windows Explorer| Removes the Folder Options menu item from the Tools menu} “NoActiveDesktopChanges” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Desktop|Desktop / Active Desktop| Prohibit changes} “NoSaveSettings” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Desktop| Don’t save settings at exit} “NoRun” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoClose” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoNetConnectDisconnect” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoTrayContextMenu” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoViewContextMenu” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoWinKeys” = (REG_DWORD) hex:0x00000000 {Disable Windows+X hotkeys} “NoThemesTab” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoChangeKeyboardNavigationIndicators” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoChangeAnimation” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoDFSTab” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoSecurityTab” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Windows Explorer| Remove Security tab} “NoHardwareTab” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoToolbarCustomize” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer|Toolbars| Disable customizing browser toolbar buttons} “NoBandCustomize” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer|Toolbars| Disable customizing browser toolbars} “NoShellSearchButton” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoPropertiesMyComputer” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoFileAssociate” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoFileUrl” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoSMMyPictures” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Start Menu and Taskbar| Remove My Pictures icon from Start Menu} “NoStartMenuMyMusic” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoTrayItemsDisplay” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Start Menu and Taskbar| Hide the notification area} “NoToolbarsOnTaskbar” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “LockTaskbar” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “HideClock” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoCDBurning” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoStartMenuMFUprogramsList” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoStartMenuPinnedList” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoStartMenuMorePrograms” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Start Menu and Taskbar| Remove All Programs list from the Start menu} “NoComputersNearMe” = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “DisableTaskMgr” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|System|Ctrl+Alt+Del Options| Remove Task Manager} “NoDispAppearancePage” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoDispBackgroundPage” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Control Panel|Display| Hide Desktop tab} “NoDispScrSavPage” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoDispSettingsPage” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoDispCPL” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Control Panel|Display| Remove Display in Control Panel} “DisableRegistryTools” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|System| Prevent access to registry editing tools} “DisableLockWorkstation” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “DisableChangePassword” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoVisualStyleChoice” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoColorChoice” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoSizeChoice” = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\ “Privacytab” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer|Internet Control Panel| Disable the Privacy page} “Accessibility” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “GeneralTab” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer|Internet Control Panel| Disable the General page} “SecurityTab” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer|Internet Control Panel| Disable the Security page} “ContentTab” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer|Internet Control Panel| Disable the Content page} “ConnectionsTab” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer|Internet Control Panel| Disable the Connections page} “ProgramsTab” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “AdvancedTab” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer|Internet Control Panel| Disable the Advanced page} “CertifPers” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “CertifSite” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “SecChangeSettings” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “SecAddSites” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “FormSuggest” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “FormSuggest Passwords” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Settings” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Prevent the deletion of temporary Internet files and cookies} “ResetWebSettings” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable the Reset Web Settings feature} “Advanced” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable changing Advanced page settings} “Autoconfig” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Cache” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “CalendarContact” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Certificates” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Colors” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Connection Settings” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable changing connection settings} “Connection Wizard” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Fonts” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “History” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “HomePage” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable changing home page settings} “Languages” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Links” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Messaging” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Profiles” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Proxy” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer| Disable changing proxy settings} “Ratings” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Wallet” = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\ “NoBrowserClose” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoBrowserContextMenu” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoBrowserOptions” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Internet Explorer|Browser Menus| Tools menu: Disable Internet Options… menu option} “NoBrowserSaveAs” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoFavorites” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoFileNew” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoFileOpen” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoFindFiles” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoSelectDownloadDir” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoTheaterMode” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoAddressBar” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoToolBar” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoLinksBar” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “NoHelpMenu” = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKCU\Software\Policies\Microsoft\Windows\Network Connections\ “NC_AddRemoveComponents” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit adding and removing components for a LAN or remote access connection} “NC_AdvancedSettings” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_AllowAdvancedTCPIPConfig” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_ChangeBindState” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_DeleteAllUserConnection” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_DeleteConnection” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit deletion of remote access connections} “NC_DialupPrefs” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_LanChangeProperties” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit access to properties of components of a LAN connection} “NC_LanConnect” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_LanProperties” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit access to properties of a LAN connection} “NC_NewConnectionWizard” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_RasAllUserProperties” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_RasChangeProperties” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit access to properties of components of a remote access connection} “NC_RasConnect” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_RasMyProperties” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_RenameAllUserRasConnection” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_RenameConnection” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_RenameLanConnection” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_RenameMyRasConnection” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NC_Statistics” = (REG_DWORD) hex:0x00000001 {User Configuration|Administrative Templates|Network|Network and Dial-up Connections| Prohibit viewing of status for an active connection} HKCU\Software\Policies\Microsoft\Windows\System\ “DisableCMD” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|System| Disable the command prompt} HKCU\Software\Policies\Microsoft\Windows\Task Scheduler5.0\ “Execution” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Disable Advanced” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Property Pages” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Allow Browse” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Task Creation” = (REG_DWORD) hex:0x00000000 {unrecognized setting} “Task Deletion” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Windows Components|Task Scheduler| Prohibit Task deletion} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} “undockwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ “Wallpaper” = “C:\WINDOWS\web\wallpaper\Idylla.bmp” Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ “Wallpaper” = “C:\WINDOWS\web\wallpaper\Idylla.bmp” Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ “SCRNSAVE.EXE” = “C:\WINDOWS\System32\logon.scr” [MS] Startup items in “Piotrek” & “All Users” startup folders: --------------------------------------------------------- C:\Documents and Settings\Piotrek\Menu Start\Programy\Autostart “UniSpiker-2.6” -> shortcut to: “C:\Program Files\ivo\UniSpiker-2.6\uni_spiker-2.6.exe” [null data] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart “Adobe Reader Speed Launch” -> shortcut to: “C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe” [“Adobe Systems Incorporated”] “ATI CATALYST – pasek zadań” -> shortcut to: “C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe SystemTray” [null data] “Microsoft Office” -> shortcut to: “C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l” [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: C:\WINDOWS\system32\imon.dll ["Eset "], 01 - 05, 17 %SystemRoot%\system32\mswsock.dll [MS], 06 - 08, 11 - 16 %SystemRoot%\system32\rsvpsp.dll [MS], 09 - 10 Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Ati HotKey Poller, Ati HotKey Poller, “C:\WINDOWS\system32\Ati2evxx.exe” [“ATI Technologies Inc.”] Cyberlink RichVideo Service(CRVS), RichVideo, ““C:\Program Files\CyberLink\Shared files\RichVideo.exe”” [empty string] LightScribeService Direct Disc Labeling Service, LightScribeService, ““C:\Program Files\Common Files\LightScribe\LSSrvc.exe”” [“Hewlett-Packard Company”] NOD32 Kernel Service, NOD32krn, ““C:\Program Files\Eset\nod32krn.exe”” ["Eset "] Windows User Mode Driver Framework, UMWdf, “C:\WINDOWS\system32\wdfmgr.exe” [MS] ---------- <>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer “No” at the first message box and “Yes” at the second message box. ---------- (total run time: 186 seconds, including 17 seconds for message boxes)
Gutek
(Gutek)
31 Październik 2006 21:44
#6