Cos mi chyba zjada pakiety! LOG
#1
czesc wszystkim dzisiaj zaprezentuje moj nowu produkt Grin (to nie reklama pamersów) przejde do rzeczy cos mi sie dzieje z gg albo z mojim netem:shock:jak do kogos pisze to nie odpowiada a jeszcze przedwczoraj reinstalowałęm gg:?i czyszciłem rejestr Jv16tools
z tego co pamietamto wchodziłem na taki link cos w tym stylu hsqvyrpzeh.info
jak narazie poprubuje poskanować jakimis skanerami online.
wrzuce loga z Hijacka :
Cytat: Logfile of HijackThis v1.99.1
Scan saved at 17:45:29, on 2006-12-27
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32atievxx.exe
CTonguerogram FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
CTonguerogram FilesLClockLClock.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32wscntfy.exe
CTonguerogram FilesWinampwinamp.exe
CTonguerogram FilesGadu-Gadugg.exe
CTonguerogram FilesWinRARWinRAR.exe
CGrinOCUME~1KompUSTAWI~1TempRar$EX01.184HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =

[Aby zobaczyć linki, zarejestruj się tutaj]

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - CTonguerogram FilesFlashGetJccatch.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - CTonguerogram FilesBitComettoolsBitCometBHO.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - CTongueROGRA~1MEGAUP~1MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - CTonguerogram FilesJavajre1.5.0_09binssv.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - CTonguerogram FilesFlashGetgetflash.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - CTongueROGRA~1MEGAUP~1MEGAUP~1.DLL
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - CTonguerogram FilesFlashGetfgiebar.dll
O4 - HKLM..Run: [LClock]CTonguerogram FilesLClockLClock.exe
O4 - HKCU..Run: [ctfmon.exe]C:WINDOWSsystem32ctfmon.exe
O8 - Extra context menu item: &Ściągnij przy pomocy FlashGet''a - CTonguerogram FilesFlashGetjc_link.htm
O8 - Extra context menu item: &Ściągnij wszystko przy pomocy FlashGet''a - CTonguerogram FilesFlashGetjc_all.htm
O8 - Extra context menu item: Download all links using BitComet -

[Aby zobaczyć linki, zarejestruj się tutaj]

FilesBitCometBitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet -

[Aby zobaczyć linki, zarejestruj się tutaj]

FilesBitCometBitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet -

[Aby zobaczyć linki, zarejestruj się tutaj]

FilesBitCometBitComet.exe/AddLink.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -

[Aby zobaczyć linki, zarejestruj się tutaj]

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - CTonguerogram FilesJavajre1.5.0_09binssv.dll
O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - CTonguerogram FilesJavajre1.5.0_09binssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - CTongueROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - CTongueROGRA~1FlashGetflashget.exe
O9 - Extra ''Tools'' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - CTongueROGRA~1FlashGetflashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - CTonguerogram FilesMessengermsmsgs.exe
O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - CTonguerogram FilesMessengermsmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

[Aby zobaczyć linki, zarejestruj się tutaj]

O17 - HKLMSystemCCSServicesTcpip..{DB45CA7F-A440-41A7-AB08-7D3E6A11CE6D}: NameServer = 194.204.152.34,194.204.159.1


Tutaj z silenta :
Cytat: "Silent Runners.vbs", revision 46,

[Aby zobaczyć linki, zarejestruj się tutaj]

Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"ctfmon.exe" = "C:WINDOWSsystem32ctfmon.exe" [MS]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"LClock" = "CTonguerogram FilesLClockLClock.exe" [null data]

HKLMSoftwareMicrosoftActive SetupInstalled Components
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}(Default) = "Outlook Express"
StubPath = "C:WINDOWSsystem32shmgrate.exe OCInstallUserConfigOE" [MS]

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}(Default) = (no title provided)
-> {HKLM...CLSID} = "IeCatch5 Class"
InProcServer32(Default) = "CTonguerogram FilesFlashGetJccatch.dll" ["FlashGet"]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}(Default) = "BitComet ClickCapture"
-> {HKLM...CLSID} = "BitComet Helper"
InProcServer32(Default) = "CTonguerogram FilesBitComettoolsBitCometBHO.dll" ["BitComet"]
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}(Default) = (no title provided)
-> {HKLM...CLSID} = "Megaupload Toolbar"
InProcServer32(Default) = "CTongueROGRA~1MEGAUP~1MEGAUP~1.DLL" ["MegaUpload"]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
InProcServer32(Default) = "CTonguerogram FilesJavajre1.5.0_09binssv.dll" ["Sun Microsystems, Inc."]
{F156768E-81EF-470C-9057-481BA8380DBA}(Default) = (no title provided)
-> {HKLM...CLSID} = "gFlash Class"
InProcServer32(Default) = "CTonguerogram FilesFlashGetgetflash.dll" [empty string]

HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
InProcServer32(Default) = "C:WINDOWSsystem32hticons.dll" ["Hilgraeve, Inc."]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {HKLM...CLSID} = "Microsoft Office Outlook"
InProcServer32(Default) = "CTongueROGRA~1MICROS~2OFFICE11MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
InProcServer32(Default) = "CTongueROGRA~1MICROS~2OFFICE11OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "CTonguerogram FilesMicrosoft OfficeOFFICE11msohev.dll" [MS]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {HKLM...CLSID} = "Portable Media Devices"
InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {HKLM...CLSID} = "Portable Media Devices Menu"
InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]
"{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
-> {HKLM...CLSID} = "Shell Search Band"
InProcServer32(Default) = "C:WINDOWSsystem32browseui.dll" [MS]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "CTonguerogram FilesWinRARrarext.dll" [null data]

HKLMSoftwareClassesPROTOCOLSFilter
INFECTION WARNING! text/xmlCLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "CTonguerogram FilesCommon FilesMicrosoft SharedOFFICE11MSOXMLMF.DLL" [MS]

HKLMSoftwareClasses*shellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "CTonguerogram FilesWinRARrarext.dll" [null data]

HKLMSoftwareClassesDirectoryshellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "CTonguerogram FilesWinRARrarext.dll" [null data]

HKLMSoftwareClassesFoldershellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "CTonguerogram FilesWinRARrarext.dll" [null data]


Active Desktop and Wallpaper:
-----------------------------

Active Desktop is disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState

HKCUControl PanelDesktop
"Wallpaper" = "CGrinocuments and SettingsKompUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]

Transport Service Providers

HKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name] , (at) ## range:
%SystemRoot%system32mswsock.dll [MS] , 01 - 04, 07 - 14
%SystemRoot%system32rsvpsp.dll [MS] , 05 - 06


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser
"{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}"
-> {HKLM...CLSID} = "Megaupload Toolbar"
InProcServer32(Default) = "CTongueROGRA~1MEGAUP~1MEGAUP~1.DLL" ["MegaUpload"]

HKLMSoftwareMicrosoftInternet ExplorerToolbar
"{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" = (no title provided)
-> {HKLM...CLSID} = "Megaupload Toolbar"
InProcServer32(Default) = "CTongueROGRA~1MEGAUP~1MEGAUP~1.DLL" ["MegaUpload"]
"{E0E899AB-F487-11D5-8D29-0050BA6940E3}" = "FlashGet"
-> {HKLM...CLSID} = "FlashGet"
InProcServer32(Default) = "CTonguerogram FilesFlashGetfgiebar.dll" ["Amaze Soft"]

Extensions (Tools menu items, main toolbar menu buttons)

HKLMSoftwareMicrosoftInternet ExplorerExtensions
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}"
-> {HKCU...CLSID} = "Java Plug-in 1.5.0_09"
InProcServer32(Default) = "CTonguerogram FilesJavajre1.5.0_09binssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM...CLSID} = "Java Plug-in 1.5.0_09"
InProcServer32(Default) = "CTonguerogram FilesJavajre1.5.0_09binnpjpi150_09.dll" ["Sun Microsystems, Inc."]

{92780B25-18CC-41C8-B9BE-3C9C571A8263}
"ButtonText" = "Badanie"

{D6E814A0-E0C5-11D4-8D29-0050BA6940E3}
"ButtonText" = "FlashGet"
"MenuText" = "FlashGet"
"Exec" = "CTongueROGRA~1FlashGetflashget.exe" ["FlashGet.com"]

{FB5F1910-F110-11D2-BB9E-00C04F795683}
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "CTonguerogram FilesMessengermsmsgs.exe" [MS]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:WINDOWSsystem32atievxx.exe" [MS]
Machine Debug Manager, MDM, ""CTonguerogram FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE"" [MS]
Windows User Mode Driver Framework, UMWdf, "C:WINDOWSsystem32wdfmgr.exe" [MS]


Print Monitors:
---------------

HKLMSystemCurrentControlSetControlPrintMonitors
Microsoft Document Imaging Writer MonitorDriver = "mdimon.dll" [MS]


----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
use the -supp parameter or answer "No" at the first message box.
---------- (total run time: 71 seconds, including 5 seconds for message boxes)

dodam jeszcze ze nawet infobot mi nie odpowiada w gg:oops:a i jeszcze muli mi okropnie firefox ale to moze z powodu małej ilosci ram dlatego urzywam IE ;/ ale w link wchodziłem firefoxem ;]dodatkowe informacje dotyczace tego linku (hsqvyrpzeh.info/?ifccab.jpg nie wbijac nawet jak wyśle komuś...)- to ma ustawiona jedna osoba u mnie na gg jako opis ?? lecz jest właśnie problem w tym ze do niego niemoge napsać poprostu niedocierają wiadomosci.
z góry dzieki
Odpowiedz
#2
W logu nic nie ma... Kochany, po prostu dostałeś bana na gg. Poczekaj trochę, za kilka dni wszystko wróci do normy. Dla pewności wrzuć mi jescze loga z

[Aby zobaczyć linki, zarejestruj się tutaj]

i nowszej wersji Silenta, bo ta jest stara.
Odpowiedz
#3
phancy napisał(a):po prostu dostałeś bana na gg

O tak masz racje bo dzis patrze a juz w porządkubo mi infobot odpowiada:banan::papryczka:
a jeszcze cos skanowałem wczoraj kasperscy online i nic nie wykryło.
apropo ComboFix-a:? nie lubie niebieskich ekranów WINDOWSOWYCH Smilejuż o wiele bardziej lubie linuksowo konsole od tego bleeeee....

to wrzuce tego loga z sinelna nowego :

Cytat:"Silent Runners.vbs", revision 49,

[Aby zobaczyć linki, zarejestruj się tutaj]

Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCUSoftwareMicrosoftWindowsCurrentVersionRun {++}
"ctfmon.exe" = "C:WINDOWSsystem32ctfmon.exe" [MS]

HKLMSoftwareMicrosoftWindowsCurrentVersionRun {++}
"LClock" = "CTonguerogram FilesLClockLClock.exe" [null data]

HKLMSoftwareMicrosoftActive SetupInstalled Components
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}(Default) = "Outlook Express"
StubPath = "C:WINDOWSsystem32shmgrate.exe OCInstallUserConfigOE" [MS]

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}(Default) = (no title provided)
-> {HKLM...CLSID} = "IeCatch5 Class"
InProcServer32(Default) = "CTonguerogram FilesFlashGetJccatch.dll" ["FlashGet"]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}(Default) = "BitComet ClickCapture"
-> {HKLM...CLSID} = "BitComet Helper"
InProcServer32(Default) = "CTonguerogram FilesBitComettoolsBitCometBHO.dll" ["BitComet"]
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}(Default) = (no title provided)
-> {HKLM...CLSID} = "Megaupload Toolbar"
InProcServer32(Default) = "CTongueROGRA~1MEGAUP~1MEGAUP~1.DLL" ["MegaUpload"]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
InProcServer32(Default) = "CTonguerogram FilesJavajre1.5.0_09binssv.dll" ["Sun Microsystems, Inc."]
{F156768E-81EF-470C-9057-481BA8380DBA}(Default) = (no title provided)
-> {HKLM...CLSID} = "gFlash Class"
InProcServer32(Default) = "CTonguerogram FilesFlashGetgetflash.dll" [empty string]

HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
InProcServer32(Default) = "C:WINDOWSsystem32hticons.dll" ["Hilgraeve, Inc."]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {HKLM...CLSID} = "Microsoft Office Outlook"
InProcServer32(Default) = "CTongueROGRA~1MICROS~2OFFICE11MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
InProcServer32(Default) = "CTongueROGRA~1MICROS~2OFFICE11OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "CTonguerogram FilesMicrosoft OfficeOFFICE11msohev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {HKLM...CLSID} = "Portable Media Devices Menu"
InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "CTonguerogram FilesWinRARrarext.dll" [null data]

HKLMSoftwareClassesPROTOCOLSFilter
<<!>> text/xmlCLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "CTonguerogram FilesCommon FilesMicrosoft SharedOFFICE11MSOXMLMF.DLL" [MS]

HKLMSoftwareClasses*shellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "CTonguerogram FilesWinRARrarext.dll" [null data]

HKLMSoftwareClassesDirectoryshellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "CTonguerogram FilesWinRARrarext.dll" [null data]

HKLMSoftwareClassesFoldershellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "CTonguerogram FilesWinRARrarext.dll" [null data]


Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------

Note: detected settings may not have any effect.

HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral
"Wallpaper" = "C:WINDOWSsystem32configsystemprofileUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCUControl PanelDesktop
"Wallpaper" = "CGrinocuments and SettingsKompUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]

Transport Service Providers

HKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name] , (at) ## range:
%SystemRoot%system32mswsock.dll [MS] , 01 - 04, 07 - 14
%SystemRoot%system32rsvpsp.dll [MS] , 05 - 06


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser
"{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}"
-> {HKLM...CLSID} = "Megaupload Toolbar"
InProcServer32(Default) = "CTongueROGRA~1MEGAUP~1MEGAUP~1.DLL" ["MegaUpload"]

HKLMSoftwareMicrosoftInternet ExplorerToolbar
"{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" = (no title provided)
-> {HKLM...CLSID} = "Megaupload Toolbar"
InProcServer32(Default) = "CTongueROGRA~1MEGAUP~1MEGAUP~1.DLL" ["MegaUpload"]
"{E0E899AB-F487-11D5-8D29-0050BA6940E3}" = "FlashGet"
-> {HKLM...CLSID} = "FlashGet"
InProcServer32(Default) = "CTonguerogram FilesFlashGetfgiebar.dll" ["Amaze Soft"]

Explorer Bars

HKLMSoftwareMicrosoftInternet ExplorerExplorer Bars

HKLMSoftwareClassesCLSID{FF059E31-CC5A-4E2E-BF3B-96E929D65503}(Default) = "&Badanie"
Implemented Categories{00021493-0000-0000-C000-000000000046} [vertical bar]
InProcServer32(Default) = "CTongueROGRA~1MICROS~2OFFICE11REFIEBAR.DLL" [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKLMSoftwareMicrosoftInternet ExplorerExtensions
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}"
-> {HKCU...CLSID} = "Java Plug-in 1.5.0_09"
InProcServer32(Default) = "CTonguerogram FilesJavajre1.5.0_09binssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM...CLSID} = "Java Plug-in 1.5.0_09"
InProcServer32(Default) = "CTonguerogram FilesJavajre1.5.0_09binnpjpi150_09.dll" ["Sun Microsystems, Inc."]

{92780B25-18CC-41C8-B9BE-3C9C571A8263}
"ButtonText" = "Badanie"

{D6E814A0-E0C5-11D4-8D29-0050BA6940E3}
"ButtonText" = "FlashGet"
"MenuText" = "FlashGet"
"Exec" = "CTongueROGRA~1FlashGetflashget.exe" ["FlashGet.com"]

{FB5F1910-F110-11D2-BB9E-00C04F795683}
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "CTonguerogram FilesMessengermsmsgs.exe" [MS]


Miscellaneous IE Hijack Points
------------------------------

C:WINDOWSINFIERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
: ˙ţ[ V e r s i o n ]

:S i g n a t u r e = " $ C H I C A G O $ "

:A d v a n c e d I N F = 2 . 5 , " Y o u n e e d a n e w v e r s i o n o f a d v p a c k . d l l "

:

:[ R e s t o r e H o m e P a g e ]

:A d d R e g = R e s t o r e H o m e P a g e . r e g

:

:[ R e s t o r e B r o w s e r S e t t i n g s ]

:A d d R e g = R e s t o r e B r o w s e r S e t t i n g s . r e g

Grin e l R e g = D e l e t e T e m p l a t e s . r e g , D e l e t e A u t o s e a r c h . r e g

:

:[ R e s t o r e H o m e P a g e . r e g ]

:H K C U , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i n " , " S t a r t P a g e " , 0 , % S T A R T _ P A G E _ U R L %

:

:[ R e s t o r e B r o w s e r S e t t i n g s . r e g ]

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i n " , " D e f a u l t _ P a g e _ U R L " , 0 , % S T A R T _ P A G E _ U R L %

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i n " , " D e f a u l t _ S e a r c h _ U R L " , 0 , % S E A R C H _ P A G E _ U R L %

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i n " , " S e a r c h P a g e " , 0 , % S E A R C H _ P A G E _ U R L %

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i nU r l T e m p l a t e " , " 1 " , 0 , " w w w . % s . c o m "

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i nU r l T e m p l a t e " , " 2 " , 0 , " w w w . % s . o r g "

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i nU r l T e m p l a t e " , " 3 " , 0 , " w w w . % s . n e t "

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i nU r l T e m p l a t e " , " 4 " , 0 , " w w w . % s . e d u "

:H K C U , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i n " , " S e a r c h P a g e " , 0 , % S E A R C H _ P A G E _ U R L %

:

:; N O T E ( a n d r e w g u ) i e 5 . 5 b # 1 0 8 2 5 9 - a u t o s e a r c h s e t t i n g s a r e n o t p r o p e r l y r e s e t

:H K C U , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rS e a r c h U r l " , " P r o v i d e r " , 0 , " "

:

:t m "

:t m "

:H K L M , " S o f t w a r eM i c r o s o f tW i n d o w sC u r r e n t V e r s i o nI n t e r n e t S e t t i n g sS a f e S i t e s " , % S A F E S I T E _ V A L U E % , 0 , " h t t p : / / i e . s e a r c h . m s n . c o m / * "

:

:[ D e l e t e T e m p l a t e s . r e g ]

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i nU r l T e m p l a t e " , " 5 "

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i nU r l T e m p l a t e " , " 6 "

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i nU r l T e m p l a t e " , " 7 "

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i nU r l T e m p l a t e " , " 8 "

:H K L M , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i nU r l T e m p l a t e " , " 9 "

:

:[ D e l e t e A u t o s e a r c h . r e g ]

:; N O T E ( a n d r e w g u ) i e 5 . 5 b # 1 0 8 2 5 9 - a u t o s e a r c h s e t t i n g s a r e n o t p r o p e r l y r e s e t

:H K C U , " S o f t w a r eM i c r o s o f tI n t e r n e t E x p l o r e rM a i n " , " A u t o S e a r c h "

:

:[ S t r i n g s ]

:S T A R T _ P A G E _ U R L = " h t t p : / / w w w . m i c r o s o f t . c o m / i s a p i / r e d i r . d l l ? p r d = i e & p v e r = 6 & a r = m s n h o m e "

:S E A R C H _ P A G E _ U R L = " h t t p : / / w w w . m i c r o s o f t . c o m / i s a p i / r e d i r . d l l ? p r d = i e & a r = i e s e a r c h "

:S A F E S I T E _ V A L U E = " i e . s e a r c h . m s n . c o m "

:

:; I M P O R T A N T N O T E :

:; I E b r a n d i n g d l l ( i e d k c s 3 2 . d l l ) u s e s t h e f o l l o w i n g e n t r i e s t o r e s t o r e t h e d e f a u l t M S v a l u e s .

:; I n t h e v a n i l l a v e r s i o n o f I E , t h e v a l u e s m u s t b e t h e s a m e a s t h e i r c o r r e s p o n d i n g n o n M S _ * v a l u e s .

:; F o r e x a m p l e , S T A R T _ P A G E _ U R L a n d M S _ S T A R T _ P A G E _ U R L m u s t h a v e t h e s a m e U R L i n t h e I E v e r s i o n r e l e a s e d b y M S .

:M S _ S T A R T _ P A G E _ U R L = " h t t p : / / w w w . m i c r o s o f t . c o m / i s a p i / r e d i r . d l l ? p r d = i e & p v e r = 6 & a r = m s n h o m e "

:

Missing lines (compared with English-language version):
[Version] : 2 lines
[RestoreHomePage] : 1 line
[RestoreHomePage.reg] : 1 line
[RestoreBrowserSettings.reg] : 12 lines
[DeleteTemplates.reg] : 5 lines
[DeleteAutosearch.reg] : 1 line
[Strings] : 1 line
[RestoreBrowserSettings] : 2 lines
[Strings] : 3 lines


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:WINDOWSsystem32atievxx.exe" [MS]
Machine Debug Manager, MDM, ""CTonguerogram FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE"" [MS]
Windows User Mode Driver Framework, UMWdf, "C:WINDOWSsystem32wdfmgr.exe" [MS]


Print Monitors:
---------------

HKLMSystemCurrentControlSetControlPrintMonitors
Microsoft Document Imaging Writer MonitorDriver = "mdimon.dll" [MS]


----------
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 110 seconds, including 6 seconds for message boxes)

p.s. Wiedziałęm że moge na Ciebie liczyć ,,phancy'''' DZIEKUJE Smile
Odpowiedz
#4
Ten log również czysty Smile
Odpowiedz


Skocz do:


Użytkownicy przeglądający ten wątek: 1 gości