Hej
Oto logi:
Logfile of HijackThis v1.99.1
Scan saved at 19:53:57, on 27/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32csrss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesIntelWirelessBinEvtEng.exe
C:Program FilesIntelWirelessBinS24EvMon.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesThinkPadConnectUtilitiesAcPrfMgrSvc.exe
C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0avp.exe
C:Program FilesLenovoBluetooth Softwareintwdins.exe
C:WINDOWSsystem32PMSveH.exe
C:Program FilesIntelWirelessBinRegSrvc.exe
C:Program FilesAlcohol 120StarWindStarWindService.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesIBM ThinkVantageRescue and Recovery
rservice.exe
C:Program FilesIBM ThinkVantageCommonScheduler vtsched.exe
C:Program FilesThinkVantageSystemUpdateUCLauncherService.exe
C:WINDOWSsystem32wdfmgr.exe
C:Program FilesThinkPadConnectUtilitiesAcSvc.exe
C:WINDOWSSystem32alg.exe
C:Program FilesIBM ThinkVantageCommonLoggerlogmon.exe
C:Program FilesThinkPadConnectUtilitiesSvcGuiHlpr.exe
C:WINDOWSExplorer.EXE
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesLenovoHOTKEYTPHKMGR.exe
C:Program FilesLenovoHOTKEYTpWAudAp.exe
C:WINDOWSsystem32PMHandler.exe
C:WINDOWSAGRSMMSG.exe
C:WINDOWSsystem32igfxtray.exe
C:WINDOWSsystem32hkcmd.exe
C:WINDOWSsystem32igfxpers.exe
C:WINDOWSvsnp2std.exe
C:PROGRA~1THINKV~1AMSGamsg.exe
C:PROGRA~1LenovoLENOVO~2LPMGR.exe
C:Program FilesIBM ThinkVantageClient Security Solutioncssauthe.exe
C:Program FilesThinkPadConnectUtilitiesACTray.exe
C:Program FilesThinkPadConnectUtilitiesACWLIcon.exe
C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0avp.exe
C:Program FilesGadu-Gadugg.exe
C:Program FilesSkypePhoneSkype.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe
C:Program FilesLenovoBluetooth SoftwareBTTray.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:Program FilesWinampwinamp.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:Program FilesinstalkiinternetoweantyviryHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.wp.pl
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://www.lenovo.com/us/en/
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.wp.pl
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar3.dll
O4 - HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM..Run: [TPHOTKEY] C:Program FilesLenovoHOTKEYTPHKMGR.exe
O4 - HKLM..Run: [TPWAUDAP] C:Program FilesLenovoHOTKEYTpWAudAp.exe
O4 - HKLM..Run: [PMHandler] C:WINDOWSsystem32PMHandler.exe
O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM..Run: [igfxtray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [igfxhkcmd] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [igfxpers] C:WINDOWSsystem32igfxpers.exe
O4 - HKLM..Run: [snp2std] C:WINDOWSvsnp2std.exe
O4 - HKLM..Run: [suScheduler] C:Program FilesThinkVantageSystemUpdateUCLauncher.exe /SCHEDULER
O4 - HKLM..Run: [AMSG] C:PROGRA~1THINKV~1AMSGamsg.exe
O4 - HKLM..Run: [LPManager] C:PROGRA~1LenovoLENOVO~2LPMGR.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [cssauthe] "C:Program FilesIBM ThinkVantageClient Security Solutioncssauthe.exe" silent
O4 - HKLM..Run: [DiskeeperSystray] "C:Program FilesDiskeeper CorporationDiskeeperDkIcon.exe"
O4 - HKLM..Run: [ACTray] C:Program FilesThinkPadConnectUtilitiesACTray.exe
O4 - HKLM..Run: [ACWLIcon] C:Program FilesThinkPadConnectUtilitiesACWLIcon.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [TrojanScanner] C:Program FilesTrojan RemoverTrjscan.exe
O4 - HKLM..Run: [kav] "C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0avp.exe"
O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray
O4 - HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe
O4 - HKCU..Run: [SpySweeper] "C:Program FilesWebrootSpy SweeperSpySweeper.exe" /0
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Reader
eader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O7 - HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem, DisableRegedit=1
O8 - Extra context menu item: Send to &Bluetooth Device... - C:Program FilesLenovoBluetooth Softwaretsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesIBMJava142jreinNPJPI142.dll
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesIBMJava142jreinNPJPI142.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0scieplugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/us/en/
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) -
https://ebanking.northernbank.co.uk/htm ... afekey.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:WINDOWSSYSTEM32igfxdev.dll
O20 - Winlogon Notify: klogon - C:WINDOWSsystem32klogon.dll
O20 - Winlogon Notify: tphotkey - C:WINDOWSSYSTEM32 phklock.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:Program FilesThinkPadConnectUtilitiesAcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:Program FilesThinkPadConnectUtilitiesAcSvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe (file missing)
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0avp.exe" -r (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:Program FilesLenovoBluetooth Softwareintwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSetMgr.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:Program FilesIntelWirelessBinEvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: LiveUpdate - Unknown owner - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE (file missing)
O23 - Service: PMSveH - Lenovo - C:WINDOWSsystem32PMSveH.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:WINDOWSsystem32PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:Program FilesIntelWirelessBinRegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:Program FilesIntelWirelessBinS24EvMon.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:Program FilesAlcohol 120StarWindStarWindService.exe
O23 - Service: TVT Backup Service - Unknown owner - C:Program FilesIBM ThinkVantageRescue and Recovery
rservice.exe
O23 - Service: TVT Scheduler - Unknown owner - C:Program FilesIBM ThinkVantageCommonScheduler vtsched.exe
O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:Program FilesThinkVantageSystemUpdateUCLauncherService.exe
i silent:
"Silent Runners.vbs", revision R50,
http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCUSoftwareMicrosoftWindowsCurrentVersionRun {++}
"Gadu-Gadu" = ""C:Program FilesGadu-Gadugg.exe" /tray" ["Gadu-Gadu S.A."]
"Skype" = ""C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized" ["Skype Technologies S.A."]
"ctfmon.exe" = "C:WINDOWSsystem32ctfmon.exe" [MS]
"swg" = "C:Program FilesGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe" ["Google Inc."]
"SpySweeper" = ""C:Program FilesWebrootSpy SweeperSpySweeper.exe" /0" ["Webroot Software, Inc."]
HKLMSoftwareMicrosoftWindowsCurrentVersionRun {++}
"SynTPEnh" = "C:Program FilesSynapticsSynTPSynTPEnh.exe" ["Synaptics, Inc."]
"High Definition Audio Property Page Shortcut" = "HDAShCut.exe" ["Windows (R) Server 2003 DDK provider"]
"TPHOTKEY" = "C:Program FilesLenovoHOTKEYTPHKMGR.exe" [null data]
"TPWAUDAP" = "C:Program FilesLenovoHOTKEYTpWAudAp.exe" [null data]
"PMHandler" = "C:WINDOWSsystem32PMHandler.exe" ["Lenovo"]
"AGRSMMSG" = "AGRSMMSG.exe" ["Agere Systems"]
"igfxtray" = "C:WINDOWSsystem32igfxtray.exe" ["Intel Corporation"]
"igfxhkcmd" = "C:WINDOWSsystem32hkcmd.exe" ["Intel Corporation"]
"igfxpers" = "C:WINDOWSsystem32igfxpers.exe" ["Intel Corporation"]
"snp2std" = "C:WINDOWSvsnp2std.exe" ["Sonix"]
"suScheduler" = "C:Program FilesThinkVantageSystemUpdateUCLauncher.exe /SCHEDULER" [null data]
"AMSG" = "C:PROGRA~1THINKV~1AMSGamsg.exe" ["LENOVO"]
"LPManager" = "C:PROGRA~1LenovoLENOVO~2LPMGR.exe" ["Lenovo Group Limited"]
"ccApp" = ""C:Program FilesCommon FilesSymantec SharedccApp.exe"" [file not found]
"cssauthe" = ""C:Program FilesIBM ThinkVantageClient Security Solutioncssauthe.exe" silent" ["Lenovo Group Limited"]
"DiskeeperSystray" = ""C:Program FilesDiskeeper CorporationDiskeeperDkIcon.exe"" ["Diskeeper Corporation"]
"ACTray" = "C:Program FilesThinkPadConnectUtilitiesACTray.exe" ["Lenovo"]
"ACWLIcon" = "C:Program FilesThinkPadConnectUtilitiesACWLIcon.exe" ["Lenovo"]
"NeroFilterCheck" = "C:WINDOWSsystem32NeroCheck.exe" ["Ahead Software Gmbh"]
"TrojanScanner" = "C:Program FilesTrojan RemoverTrjscan.exe" ["Simply Super Software"]
"kav" = ""C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0avp.exe"" ["Kaspersky Lab"]
"(Default)" = "(empty string)" [file not found]
HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects
{02478D38-C3F9-4EFB-9B51-7695ECA05670}(Default) = (no title provided)
{HKLM...CLSID} = "Yahoo! Toolbar Helper"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpnyt.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided)
{HKLM...CLSID} = "Adobe PDF Reader Link Helper"
InProcServer32(Default) = "C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll" ["Adobe Systems Incorporated"]
{9030D464-4C02-4ABF-8ECC-5164760863C6}(Default) = (no title provided)
{HKLM...CLSID} = "Windows Live Sign-in Helper"
InProcServer32(Default) = "C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll" [MS]
{AA58ED58-01DD-4d91-8333-CF10577473F7}(Default) = (no title provided)
{HKLM...CLSID} = "Google Toolbar Helper"
InProcServer32(Default) = "c:program filesgooglegoogletoolbar3.dll" ["Google Inc."]
HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
{HKLM...CLSID} = "Display Panning CPL Extension"
InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
{HKLM...CLSID} = "HyperTerminal Icon Ext"
InProcServer32(Default) = "C:WINDOWSsystem32hticons.dll" ["Hilgraeve, Inc."]
"{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
{HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesSynapticsSynTPSynTPCpl.dll" ["Synaptics, Inc."]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
{HKLM...CLSID} = "Portable Media Devices Menu"
InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]
"{6af09ec9-b429-11d4-a1fb-0090960218cb}" = "My Bluetooth Places"
{HKLM...CLSID} = "My Bluetooth Places"
InProcServer32(Default) = "C:WINDOWSsystem32tneighborhood.dll" ["Broadcom Corporation."]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
{HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10msohev.dll" [MS]
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
{HKLM...CLSID} = "My Sharing Folders"
InProcServer32(Default) = "C:Program FilesMSN Messengerfsshext.8.0.0812.00.dll" [MS]
"{52B87208-9CCF-42C9-B88E-069281105805}" = "Trojan Remover Shell Extension"
{HKLM...CLSID} = "Trojan Remover Shell Extension"
InProcServer32(Default) = "C:PROGRA~1TROJAN~1Trshlex.dll" ["Simply Super Software"]
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}" = "Webroot Spy Sweeper Context Menu Integration"
{HKLM...CLSID} = "Webroot Spy Sweeper Context Menu Integration"
InProcServer32(Default) = "C:PROGRA~1WebrootSPYSWE~1SSCtxMnu.dll" ["Webroot Software, Inc."]
"{85E0B171-04FA-11D1-B7DA-00A0C90348D6}" = "Web Anti-Virus"
{HKLM...CLSID} = "Web Anti-Virus"
InProcServer32(Default) = "C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0scieplugin.dll" ["Kaspersky Lab"]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
{HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRAR
arext.dll" [null data]
HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonNotify
<<!>> ACNotifyDLLName = "ACNotify.dll" [file not found]
<<!>> igfxcuiDLLName = "igfxdev.dll" ["Intel Corporation"]
<<!>> klogonDLLName = "C:WINDOWSsystem32klogon.dll" ["Kaspersky Lab"]
<<!>> tphotkeyDLLName = "tphklock.dll" [null data]
HKLMSoftwareClassesFoldershellexColumnHandlers
{F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = "PDF Column Info"
{HKLM...CLSID} = "PDF Shell Extension"
InProcServer32(Default) = "C:Program FilesAdobeAcrobat 7.0ActiveXPDFShell.dll" ["Adobe Systems, Inc."]
HKLMSoftwareClasses*shellexContextMenuHandlers
Kaspersky Anti-Virus(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
{HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0shellex.dll" ["Kaspersky Lab"]
Trojan Remover(Default) = "{52B87208-9CCF-42C9-B88E-069281105805}"
{HKLM...CLSID} = "Trojan Remover Shell Extension"
InProcServer32(Default) = "C:PROGRA~1TROJAN~1Trshlex.dll" ["Simply Super Software"]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
{HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRAR
arext.dll" [null data]
HKLMSoftwareClassesDirectoryshellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
{HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRAR
arext.dll" [null data]
HKLMSoftwareClassesFoldershellexContextMenuHandlers
Kaspersky Anti-Virus(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
{HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0shellex.dll" ["Kaspersky Lab"]
SpySweeper(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"
{HKLM...CLSID} = "Webroot Spy Sweeper Context Menu Integration"
InProcServer32(Default) = "C:PROGRA~1WebrootSPYSWE~1SSCtxMnu.dll" ["Webroot Software, Inc."]
Trojan Remover(Default) = "{52B87208-9CCF-42C9-B88E-069281105805}"
{HKLM...CLSID} = "Trojan Remover Shell Extension"
InProcServer32(Default) = "C:PROGRA~1TROJAN~1Trshlex.dll" ["Simply Super Software"]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
{HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRAR
arext.dll" [null data]
Group Policies {policy setting}:
--------------------------------
Note: detected settings may not have any effect.
HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}
"DisableTaskMgr" = (REG_DWORD) hex:0x00000001
{unrecognized setting}
"DisableRegistryTools" = (REG_DWORD) hex:0x00000001
{unrecognized setting}
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral
"Wallpaper" = "C:WINDOWSsystem32configsystemprofileLocal SettingsApplication DataMicrosoftWallpaper1.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCUControl PanelDesktop
"Wallpaper" = "C:Documents and SettingsyezLocal SettingsApplication DataMicrosoftWallpaper1.bmp"
Enabled Screen Saver:
---------------------
HKCUControl PanelDesktop
"SCRNSAVE.EXE" = "C:WINDOWSsystem32sstext3d.scr" [MS]
Startup items in "yez" & "All Users" startup folders:
-----------------------------------------------------
C:Documents and SettingsAll UsersStart MenuProgramsStartup
"Adobe Reader Speed Launch"
shortcut to: "C:Program FilesAdobeAcrobat 7.0Reader
eader_sl.exe" ["Adobe Systems Incorporated"]
"Bluetooth"
shortcut to: "C:Program FilesLenovoBluetooth SoftwareBTTray.exe" ["Broadcom Corporation."]
"Microsoft Office"
shortcut to: "C:Program FilesMicrosoft OfficeOffice10OSA.EXE -b -l" [MS]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
Transport Service Providers
HKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 19
%SystemRoot%system32
svpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCUSoftwareMicrosoftInternet ExplorerToolbarShellBrowser
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
{HKLM...CLSID} = "&Google"
InProcServer32(Default) = "c:program filesgooglegoogletoolbar3.dll" ["Google Inc."]
HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
{HKLM...CLSID} = "&Google"
InProcServer32(Default) = "c:program filesgooglegoogletoolbar3.dll" ["Google Inc."]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
{HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpnyt.dll" ["Yahoo! Inc."]
HKLMSoftwareMicrosoftInternet ExplorerToolbar
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
{HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpnyt.dll" ["Yahoo! Inc."]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
{HKLM...CLSID} = "&Google"
InProcServer32(Default) = "c:program filesgooglegoogletoolbar3.dll" ["Google Inc."]
Explorer Bars
HKLMSoftwareMicrosoftInternet ExplorerExplorer Bars
HKLMSoftwareClassesCLSID{85E0B171-04FA-11D1-B7DA-00A0C90348D6}(Default) = "Web Anti-Virus"
Implemented Categories{00021493-0000-0000-C000-000000000046} [vertical bar]
InProcServer32(Default) = "C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0scieplugin.dll" ["Kaspersky Lab"]
Extensions (Tools menu items, main toolbar menu buttons)
HKLMSoftwareMicrosoftInternet ExplorerExtensions
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
"MenuText" = "IBM Java Console"
"CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-00401C608501}"
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}
"ButtonText" = "Web Anti-Virus"
{FB5F1910-F110-11D2-BB9E-00C04F795683}
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:Program FilesMessengermsmsgs.exe" [MS]
Miscellaneous IE Hijack Points
------------------------------
C:WINDOWSINFIERESET.INF (used to "Reset Web Settings")
Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://www.lenovo.com/us/en/
Missing lines (compared with English-language version):
[Strings]: 1 line
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
Ac Profile Manager Service, AcPrfMgrSvc, "C:Program FilesThinkPadConnectUtilitiesAcPrfMgrSvc.exe" [null data]
Access Connections Main Service, AcSvc, "C:Program FilesThinkPadConnectUtilitiesAcSvc.exe" ["Lenovo"]
Bluetooth Service, btwdins, "C:Program FilesLenovoBluetooth Softwareintwdins.exe" ["Broadcom Corporation."]
Intel(R) PROSet/Wireless Event Log, EvtEng, "C:Program FilesIntelWirelessBinEvtEng.exe" ["Intel Corporation"]
Intel(R) PROSet/Wireless Registry Service, RegSrvc, "C:Program FilesIntelWirelessBinRegSrvc.exe" ["Intel Corporation"]
Intel(R) PROSet/Wireless Service, S24EventMonitor, "C:Program FilesIntelWirelessBinS24EvMon.exe" ["Intel Corporation "]
Kaspersky Anti-Virus 6.0, AVP, ""C:Program FilesKaspersky LabKaspersky Anti-Virus 6.0avp.exe" -r" ["Kaspersky Lab"]
PMSveH, PMSveH, "C:WINDOWSsystem32PMSveH.exe" ["Lenovo"]
StarWind iSCSI Service, StarWindService, "C:Program FilesAlcohol 120StarWindStarWindService.exe" ["Rocket Division Software"]
ThinkVantage System Update, UCLauncherService, "C:Program FilesThinkVantageSystemUpdateUCLauncherService.exe" [null data]
TVT Backup Service, TVT Backup Service, ""C:Program FilesIBM ThinkVantageRescue and Recovery
rservice.exe"" [empty string]
TVT Scheduler, TVT Scheduler, ""C:Program FilesIBM ThinkVantageCommonScheduler vtsched.exe"" [empty string]
Windows User Mode Driver Framework, UMWdf, "C:WINDOWSsystem32wdfmgr.exe" [MS]
Print Monitors:
---------------
HKLMSystemCurrentControlSetControlPrintMonitors
Bluetooth Printer PortDriver = "bthcrp.dll" ["Broadcom Corporation."]
----------
<<!>>: Suspicious data at a malware launch point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 63 seconds, including 43 seconds for message boxes)