log z Evido
- Kod: Zaznacz wszystko
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 19:57:19 2006-11-06
+ Scan result:
C:Program FilesPrintViewprinthook030.dll -> Adware.PrintView : Cleaned.
C:Program FilesPrintViewpvmodule.exe -> Adware.PrintView : Cleaned.
C:WINDOWSsystem32wkwpafek.dll -> Adware.PurityScan : Cleaned.
C:Program FilesDeskbar -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarCache -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarabout.html -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarasis.xml -> Adware.Softomate : Cleaned.
C:Program FilesDeskbardeskbar.crc -> Adware.Softomate : Cleaned.
C:Program FilesDeskbardeskbar.dll -> Adware.Softomate : Cleaned.
C:Program FilesDeskbardeskbar.inf -> Adware.Softomate : Cleaned.
C:Program FilesDeskbaricons.bmp -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarinst.bat -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarmbback.bmp -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarmbbigopen.bmp -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarmbclose.bmp -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarmbfwd.bmp -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarmblogo.bmp -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarmbsep.bmp -> Adware.Softomate : Cleaned.
C:Program FilesDeskbaroptions.html -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarsoftomate.gif -> Adware.Softomate : Cleaned.
C:Program FilesDeskbarversion.txt -> Adware.Softomate : Cleaned.
HKLMSOFTWAREClassesCLSID{A8B28872-3324-4CD2-8AA3-7D555C872D96} -> Adware.Softomate : Cleaned.
HKLMSOFTWAREClassesCLSID{D7CC80D4-376C-4586-B023-4F35C2CEB28E} -> Adware.Softomate : Cleaned.
HKLMSOFTWAREClassesCLSID{D8C2D4B4-EEAF-4EC4-B1F8-9B6ED15D5A38} -> Adware.Softomate : Cleaned.
HKLMSOFTWAREClassesTypeLib{A4C8F181-6CDB-4DCC-9FC9-BB9933C81E1F} -> Adware.Softomate : Cleaned.
HKUS-1-5-21-1085031214-1844823847-839522115-1003SoftwareMicrosoftWindowsCurrentVersionExtStats{A8B28872-3324-4CD2-8AA3-7D555C872D96} -> Adware.Softomate : Cleaned.
C:WINDOWSsystem32sporder.dll -> Adware.WinAntiVirus : Cleaned.
C:mc44a3.exe -> Downloader.Adload.fu : Cleaned.
C:kybrdff_e33.exe -> Downloader.Adload.gw : Cleaned.
E:ŚciągnięteMobtime Cell Phone Manager 2006 6.0.9 Crack(1).rar/crack.exe -> Downloader.Agent.aey : Cleaned.
C:Program FilesCommon Filesѕуstem32
tvdm.exe -> Downloader.PurityScan.dr : Cleaned.
C:Documents and SettingsPaffełPulpitprogramy do siemensaJokerV034JokerV0343JokerV0343.exe -> Downloader.Small : Cleaned.
E:ŚciągnięteMobTime Cell Phone Manager 2006 6.1.0 crack.rar/crack.exe -> Dropper.Agent.anl : Cleaned.
E:ŚciągnięteMobTime Cell Phone Manager 2006 6.1.0 crackcrack.exe -> Dropper.Agent.anl : Cleaned.
E:ŚciągnięteMobtime Cell Phone Manager 2006 6.1.0 Crack(2).rar/crack.exe -> Dropper.Agent.anl : Cleaned.
E:ŚciągnięteMobtime Cell Phone Manager 2006 6.1.0 Crack(2)crack.exe -> Dropper.Agent.anl : Cleaned.
C:Program FilesCommon FilesMicrosoft SharedMSWNInfoUpdService.exe -> Dropper.Delf.vt : Cleaned.
C:Program FilesCommon FilesMicrosoft SharedMSWNInfoServiceDLLrun.exe -> Hijacker.Delf.fm : Cleaned.
:mozilla.300:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.301:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.302:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.337:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.41:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.42:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.113:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.114:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.117:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.118:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.26:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.27:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.385:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.386:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.392:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.393:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.398:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.399:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.53:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.54:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.62:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.63:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.209:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.211:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.190:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.61:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.197:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.228:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.298:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.367:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.177:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.178:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.179:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.180:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.250:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.251:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.252:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:Documents and SettingsPaffełCookiespaffeł@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:Documents and SettingsPaffełCookiespaffeł@media.fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.289:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.72:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.144:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.145:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.260:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.261:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.262:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.120:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Itrack : Cleaned.
:mozilla.384:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.299:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.175:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.176:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.155:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.156:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.157:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.321:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.322:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.188:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.189:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.223:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.224:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.225:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.226:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.227:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.387:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.389:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.390:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.171:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.275:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.277:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.33:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.34:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.35:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.36:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.37:C:Documents and SettingsmamaDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.71:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.72:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
C:Documents and SettingsPaffełCookiespaffeł@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.173:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.152:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.153:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.154:C:Documents and SettingsPaffełDane aplikacjiMozillaFirefoxProfiles
2cm95iu.defaultcookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:dfndrff_e33.exe -> Trojan.Pakes : Cleaned.
C:
wnmff_e33.exe -> Trojan.Pakes : Cleaned.
::Report end
log z Hijacka
- Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 20:52:52, on 2006-11-06
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
C:Program Filesewido anti-spyware 4.0guard.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesGadu-Gadugg.exe
C:Program FilesAdobeAcrobat 7.0Reader eader_sl.exe
C:WINDOWSsystem32wuauclt.exe
C:Documents and SettingsPaffełPulpit óżne skróty do utrzymania porządku na dyskuhijackthisHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://google.bearshare.com/pl/
O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Reader eader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06inssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06inssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:Program Filesewido anti-spyware 4.0guard.exe
log z Silent Runners
- Kod: Zaznacz wszystko
"Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCUSoftwareMicrosoftWindowsCurrentVersionRun {++}
"Gadu-Gadu" = ""C:Program FilesGadu-Gadugg.exe" /tray" ["Gadu-Gadu Sp. z o.o."]
HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
InProcServer32(Default) = "C:WINDOWSSystem32hticons.dll" ["Hilgraeve, Inc."]
"{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"
-> {HKLM...CLSID} = "SimpleShlExt Class"
InProcServer32(Default) = "C:Program FilesATI TechnologiesATI.ACEatiacmxx.dll" [empty string]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10msohev.dll" [MS]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRAR arext.dll" [null data]
"{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
-> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
"{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
-> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM...CLSID} = "RealOne Player Context Menu Class"
InProcServer32(Default) = "C:Program FilesReal Alternative pshell.dll" ["RealNetworks, Inc."]
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Uniwersalne urządzenia Plug and Play"
-> {HKLM...CLSID} = "Uniwersalne urządzenia Plug and Play"
InProcServer32(Default) = "C:WINDOWSsystem32upnpui.dll" [MS]
"{79BC0345-1015-11D2-A299-006008312725}" = "blue.shell"
-> {HKLM...CLSID} = "Studio.Project"
InProcServer32(Default) = "C:Program FilesPinnacleStudio 10programsBlueShellExt.dll" [file not found]
"{ED65AB21-B24F-11d3-BA80-00C0CA16AA37}" = "Mobile"
-> {HKLM...CLSID} = "Mobile"
InProcServer32(Default) = "C:Program FilesSiemens Data SuiteDESDESShellExt.dll" ["Siemens AG"]
"{ED65AB22-B24F-11d3-BA80-00C0CA16AA37}" = "Mobile ContextMenuHandler"
-> {HKLM...CLSID} = "Mobile ContextMenuHandler"
InProcServer32(Default) = "C:Program FilesSiemens Data SuiteDESDESShellExt.dll" ["Siemens AG"]
"{ED65AB23-B24F-11d3-BA80-00C0CA16AA37}" = "Mobile PropertySheetHandler"
-> {HKLM...CLSID} = "Mobile PropertySheetHandler"
InProcServer32(Default) = "C:Program FilesSiemens Data SuiteDESDESShellExt.dll" ["Siemens AG"]
HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks
<<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "ewido anti-spyware 4.0"
-> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
InProcServer32(Default) = "C:Program Filesewido anti-spyware 4.0shellexecutehook.dll" ["Anti-Malware Development a.s."]
HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonNotify
<<!>> AtiExtEventDLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
HKLMSoftwareClassesFoldershellexColumnHandlers
{7D4D6379-F301-4311-BEBA-E26EB0561882}(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"
-> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
{F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
InProcServer32(Default) = "C:Program FilesAdobeAcrobat 7.0ActiveXPDFShell.dll" ["Adobe Systems, Inc."]
HKLMSoftwareClasses*shellexContextMenuHandlers
ewido anti-spyware(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM...CLSID} = "CContextScan Object"
InProcServer32(Default) = "C:Program Filesewido anti-spyware 4.0context.dll" ["Anti-Malware Development a.s."]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRAR arext.dll" [null data]
HKLMSoftwareClassesDirectoryshellexContextMenuHandlers
ewido anti-spyware(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM...CLSID} = "CContextScan Object"
InProcServer32(Default) = "C:Program Filesewido anti-spyware 4.0context.dll" ["Anti-Malware Development a.s."]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRAR arext.dll" [null data]
HKLMSoftwareClassesFoldershellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRAR arext.dll" [null data]
Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------
Note: detected settings may not have any effect.
HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer
"NoChangeStartMenu" = (REG_DWORD) hex:0x00000001
{unrecognized setting}
"NoClose" = (REG_DWORD) hex:0x00000001
{unrecognized setting}
"NoLogOff" = (REG_DWORD) hex:0x00000001
{User Configuration|Administrative Templates|System|Logon/Logoff|
Disable Logoff}
"NoRun" = (REG_DWORD) hex:0x00000001
{unrecognized setting}
HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem
"DisableTaskMgr" = (REG_DWORD) hex:0x00000001
{User Configuration|Administrative Templates|System|Ctrl+Alt+Del Options|
Remove Task Manager}
"DisableRegistryTools" = (REG_DWORD) hex:0x00000000
{User Configuration|Administrative Templates|System|
Prevent access to registry editing tools}
HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral
"Wallpaper" = "C:WINDOWSsystem32configsystemprofileUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCUControl PanelDesktop
"Wallpaper" = "C:Documents and SettingsPaffełUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"
Enabled Screen Saver:
---------------------
HKCUControl PanelDesktop
"SCRNSAVE.EXE" = "C:WINDOWSSystem32ssmypics.scr" [MS]
Startup items in "Paffeł" & "All Users" startup folders:
--------------------------------------------------------
C:Documents and SettingsAll UsersMenu StartProgramyAutostart
"Adobe Reader Speed Launch" -> shortcut to: "C:Program FilesAdobeAcrobat 7.0Reader eader_sl.exe" ["Adobe Systems Incorporated"]
"BlueSoleil" -> shortcut to: "C:Program FilesIVT CorporationBlueSoleilBlueSoleil.exe" ["IVT Corporation"]
"Microsoft Office" -> shortcut to: "C:Program FilesMicrosoft OfficeOffice10OSA.EXE -b -l" [MS]
Enabled Scheduled Tasks:
------------------------
"AppleSoftwareUpdate" -> launches: "C:Program FilesApple Software UpdateSoftwareUpdate.exe -Task" ["Apple Computer, Inc."]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
Transport Service Providers
HKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 15
%SystemRoot%system32 svpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Extensions (Tools menu items, main toolbar menu buttons)
HKLMSoftwareMicrosoftInternet ExplorerExtensions
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}"
-> {HKCU...CLSID} = "Java Plug-in"
InProcServer32(Default) = "C:Program FilesJavajre1.5.0_06inssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM...CLSID} = "Java Plug-in 1.5.0_06"
InProcServer32(Default) = "C:Program FilesJavajre1.5.0_06in
pjpi150_06.dll" ["Sun Microsystems, Inc."]
{FB5F1910-F110-11D2-BB9E-00C04F795683}
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:Program FilesMessengermsmsgs.exe" [MS]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
Ati HotKey Poller, Ati HotKey Poller, "C:WINDOWSsystem32Ati2evxx.exe" ["ATI Technologies Inc."]
BlueSoleil Hid Service, BlueSoleil Hid Service, "C:Program FilesIVT CorporationBlueSoleilBTNtService.exe" [null data]
ewido anti-spyware 4.0 guard, ewido anti-spyware 4.0 guard, "C:Program Filesewido anti-spyware 4.0guard.exe" ["Anti-Malware Development a.s."]
Windows User Mode Driver Framework, UMWdf, "C:WINDOWSsystem32wdfmgr.exe" [MS]
----------
<<!>>: Suspicious data at a malware launch point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 29 seconds.
---------- (total run time: 59 seconds)
[code[/code]