
1. Logfile of Trend Micro HijackThis v2.0.2
2. Scan saved at 16:50:12, on 08-01-18
3. Platform: Windows 98 SE (Win9x 4.10.2222A)
4. MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
5. Boot mode: Normal
6.
7. Running processes:
8. C:\WINDOWS\SYSTEM\KERNEL32.DLL
9. C:\WINDOWS\SYSTEM\MSGSRV32.EXE
10. C:\WINDOWS\SYSTEM\MPREXE.EXE
11. C:\WINDOWS\SYSTEM\MSTASK.EXE
12. C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
13. C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
14. C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
15. C:\WINDOWS\SYSTEM\SCARDSVR.EXE
16. C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SCHEDM.EXE
17. C:\WINDOWS\SYSTEM\mmtask.tsk
18. C:\WINDOWS\TASKMON.EXE
19. C:\WINDOWS\SYSTEM\INTERNAT.EXE
20. C:\WINDOWS\SYSTEM\SYSTRAY.EXE
21. C:\PROGRAM FILES\HEWLETT-PACKARD\ORDERREMINDER\ORDERREMINDER.EXE
22. C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGCTRL.EXE
23. C:\WINDOWS\SYSTEM\SPOOL32.EXE
24. C:\PROGRAM FILES\OPENOFFICE.ORG 2.2\PROGRAM\SOFFICE.EXE
25. C:\PROGRAM FILES\OPENOFFICE.ORG 2.2\PROGRAM\SOFFICE.EXE
26. C:\WINDOWS\SYSTEM\WMIEXE.EXE
27. C:\PROGRAM FILES\OPENOFFICE.ORG 2.2\PROGRAM\SOFFICE.BIN
28. C:\PROGRAM FILES\OPENOFFICE.ORG 2.2\PROGRAM\SOFFICE.BIN
29. C:\WINDOWS\SYSTEM\DDHELP.EXE
30. C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
31. C:\WINDOWS\EXPLORER.EXE
32. C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE
33.
34. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
35. R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
36. O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0 CE\READER\ACTIVEX\ACROIEHELPER.DLL
37. O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
38. O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
39. O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
40. O4 - HKLM\..\Run: [internat.exe] internat.exe
41. O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
42. O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
43. O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
44. O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
45. O4 - HKLM\..\Run: [avgctrl] "C:\Program Files\AntiVir PersonalEdition Classic\avgctrl.exe" /min
46. O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
47. O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
48. O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
49. O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
50. O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
51. O4 - HKLM\..\RunServices: [SCardSvr] C:\WINDOWS\SYSTEM\SCardSvr.exe
52. O4 - HKLM\..\RunServices: [schedm] "C:\Program Files\AntiVir PersonalEdition Classic\schedm.exe"
53. O4 - .DEFAULT Startup: OpenOffice.ux.pl 2.0.1.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe (User 'Default user')
54. O4 - .DEFAULT Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe (User 'Default user')
55. O4 - .DEFAULT Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (User 'Default user')
56. O4 - Startup: OpenOffice.ux.pl 2.0.1.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
57. O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
58. O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
59. O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
60. O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
61. O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} (MainControl Class) - http://mks.com.pl/skaner/SkanerOnline.cab
62.
63. --
64. End of file - 3835 bytes
# "Silent Runners.vbs", revision 55, http://www.silentrunners.org/
# Operating System: Windows 98
# Output limited to non-default values, except where indicated by "{++}"
#
#
# Startup items buried in registry:
# ---------------------------------
#
# HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
# "ScanRegistry" = "C:\WINDOWS\scanregw.exe /autorun" [MS]
# "TaskMonitor" = "C:\WINDOWS\taskmon.exe" [MS]
# "internat.exe" = "internat.exe" [MS]
# "SystemTray" = "SysTray.Exe" [MS]
# "LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
# "Zone Labs Client" = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" ["Zone Labs, LLC"]
# "OrderReminder" = "C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" ["Hewlett-Packard"]
# "avgctrl" = ""C:\Program Files\AntiVir PersonalEdition Classic\avgctrl.exe" /min" ["Avira GmbH"]
#
# HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\ {++}
# "LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
# "SchedulingAgent" = "mstask.exe" [MS]
# "KB918547" = "C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE" [MS]
# "KB891711" = "C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE" [MS]
# "TrueVector" = "C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service" ["Zone Labs, LLC"]
# "SCardSvr" = "C:\WINDOWS\SYSTEM\SCardSvr.exe" [MS]
# "schedm" = ""C:\Program Files\AntiVir PersonalEdition Classic\schedm.exe"" ["Avira GmbH"]
#
# HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
# {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
# -> {HKLM...CLSID} = "AcroIEHlprObj Class"
# \InProcServer32\(Default) = "C:\PROGRAM FILES\ADOBE\ACROBAT 6.0 CE\READER\ACTIVEX\ACROIEHELPER.DLL" ["Adobe Systems Incorporated"]
#
# HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
# "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" = "OpenOffice.org Column Handler"
# -> {HKLM...CLSID} = (no title provided)
# \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
# "{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" = "OpenOffice.org Infotip Handler"
# -> {HKLM...CLSID} = (no title provided)
# \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
# "{63542C48-9552-494A-84F7-73AA6A7C99C1}" = "OpenOffice.org Property Sheet Handler"
# -> {HKLM...CLSID} = (no title provided)
# \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
# "{3B092F0C-7696-40E3-A80F-68D74DA84210}" = "OpenOffice.org Thumbnail Viewer"
# -> {HKLM...CLSID} = (no title provided)
# \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
# "{2E9D3540-211C-11d0-A5F2-00A0248C37BE}" = "Nero Shell Extension Property Sheet"
# -> {HKLM...CLSID} = "Nero Shell Extension Property Sheet"
# \InProcServer32\(Default) = "C:\Program Files\Ahead\Nero\neroshx.dll" ["ahead software gmbh im stoeckmaedle 6 76307 karlsbad, germany Fax: ++49-7248-911-888 e-mail: info@ahead.de"]
# "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
# -> {HKLM...CLSID} = "WinRAR"
# \InProcServer32\(Default) = "C:\PROGRAM FILES\WINRAR\rarext.dll" [null data]
#
# HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
# {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = "OpenOffice.org Column Handler"
# -> {HKLM...CLSID} = (no title provided)
# \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
#
# HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
# WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
# -> {HKLM...CLSID} = "WinRAR"
# \InProcServer32\(Default) = "C:\PROGRAM FILES\WINRAR\rarext.dll" [null data]
# Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
# -> {HKLM...CLSID} = "Shell Extension for Malware scanning"
# \InProcServer32\(Default) = "C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SHLEXT.DLL" ["Avira GmbH"]
#
# HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
# WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
# -> {HKLM...CLSID} = "WinRAR"
# \InProcServer32\(Default) = "C:\PROGRAM FILES\WINRAR\rarext.dll" [null data]
#
# HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
# WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
# -> {HKLM...CLSID} = "WinRAR"
# \InProcServer32\(Default) = "C:\PROGRAM FILES\WINRAR\rarext.dll" [null data]
# Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
# -> {HKLM...CLSID} = "Shell Extension for Malware scanning"
# \InProcServer32\(Default) = "C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SHLEXT.DLL" ["Avira GmbH"]
#
#
# Active Desktop and Wallpaper:
# -----------------------------
#
# Active Desktop may be enabled at this entry:
# HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
#
#
# Startup items in "Startup" & "All Users...Startup" folders:
# -----------------------------------------------------------
#
# C:\WINDOWS\Menu Start\Programy\Autostart
# "OpenOffice.ux.pl 2.0.1" -> shortcut to: "C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe" [null data]
# "OpenOffice.org 2.2" -> shortcut to: "C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe" [null data]
# "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
#
#
# Enabled Scheduled Tasks:
# ------------------------
#
# "Rozpoczęcie aplikacji dostrajania" -> launches: "walign" [MS]
#
#
# Winsock2 Service Provider DLLs:
# -------------------------------
#
# Namespace Service Providers
#
# HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
# 000000000001\LibraryPath = "C:\WINDOWS\SYSTEM\rnr20.dll" [MS]
#
# Transport Service Providers
#
# HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
# 00000000000#\PackedCatalogItem (contains) DLL [Company Name], (at) # range:
# C:\WINDOWS\SYSTEM\mswsosp.dll [MS], 1
# C:\WINDOWS\SYSTEM\msafd.dll [MS], 2 - 4
# C:\WINDOWS\SYSTEM\rsvpsp.dll [MS], 5 - 6
#
#
# Miscellaneous IE Hijack Points
# ------------------------------
#
# HKLM\Software\Microsoft\Internet Explorer\Version = (invalid data)
# The Internet Explorer version cannot be found!
#
# C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")
# The contents of IERESET.INF cannot be reliably checked!
#
# Added lines (compared with English-language version):
# [Strings]: START_PAGE_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
# [Strings]: MS_START_PAGE_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
#
# Missing lines (compared with English-language version):
# [Strings]: 2 lines
#
#
# Print Monitors:
# ---------------
#
# HKLM\System\CurrentControlSet\Control\Print\Monitors\
# HPLJ1020LM\Driver = "ZLhp1020.DLL" ["Zenographics, Inc."]
# USBPortMonitor\Driver = "usbmon.dll" [MS]
#
#
# ---------- (launch time: 2008-01-18 17:05:26)
# + This report excludes default entries except where indicated.
# + To see *everywhere* the script checks and *everything* it finds,
# launch it from a command prompt or a shortcut with the -all parameter.
# + To search all directories of local fixed drives for DESKTOP.INI
# DLL launch points, use the -supp parameter or answer "No" at the
# first message box and "Yes" at the second message box.
# ---------- (total run time: 49 seconds, including 18 seconds for message boxes)
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 32 gości