Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3900: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3902: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3903: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3904: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
Zawiesza sie i wylapoje wirusy w plikach np gg czy skype • programosy.pl

  • Ogłoszenie:

Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Postprzez marcinbak10 08 Sty 2010, 22:08

reklama
mam taki problem komp mi zwolnil strasznie i nood znajduje wirusy w plikach z rozszezeniem .exe takich jak gg skype czy soundman prosze o pomoc z tym szkodnikiem log z rsita
Kod: Zaznacz wszystko
Logfile of random's system information tool 1.06 (written by random/random)
Run by Marcin at 2010-01-08 21:05:18
Microsoft Windows XP Professional Dodatek Service Pack 3
System drive C: has 2 GB (10%) free of 20 GB
Total RAM: 1535 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:05:40, on 2010-01-08
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Nowe Gadu-Gadu\gg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager .exe
C:\Program Files\OVISLINK\Common\AirliveUI.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Documents and Settings\Marcin\Menu Start\Programy\Autostart\WinCE3.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
G:\RSIT.exe
C:\Documents and Settings\Marcin\Pulpit\tmp\Marcin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-781cd0e19f00} - c:\program files\steganos internet anonym pro 7\siapro7iep.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe
O4 - HKCU\..\Run: [UberIcon] "c:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager .exe"
O4 - HKUS\S-1-5-19\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: WinCE3.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: AirLive 802.11G Wireless Utility.lnk = C:\Program Files\OVISLINK\Common\AirliveUI.exe
O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Dane aplikacji\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Pobierz wszystkie VIdeo za pomocą BitComet - res://D:\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - res://D:\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Pobierz za pomocą BitComet - res://D:\BitComet\BitComet.exe/AddLink.htm
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\EXPRES~2\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://D:\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{175D818A-1397-4B80-8551-57FB83BC22D0}: NameServer = 194.204.152.34,194.204.159.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{175D818A-1397-4B80-8551-57FB83BC22D0}: NameServer = 194.204.152.34,194.204.159.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - D:\Hotspot Shield\bin\HssTrayService.EXE (file missing)
O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 10175 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 37808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - D:\BitComet\tools\BitCometBHO_1.3.3.2.dll [2009-03-02 636216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ccec60fc-2608-4e58-9659-3ffc159e8ea9}]
SHOUTcast Loader - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll [2008-09-17 1275176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-04-04 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-04-04 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}]
IEPluginBHO Class - C:\Documents and Settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll [2009-07-14 42088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
Hotspot Shield Class - C:\Program Files\Hotspot Shield\hssie\HssIE.dll [2009-08-27 218160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{00000000-5736-4205-0008-781cd0e19f00} - Steganos Internet Anonym - c:\program files\steganos internet anonym pro 7\siapro7iep.dll [2005-07-20 450560]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-04-19 7700480]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-02-06 2021400]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nowe Gadu-Gadu"=C:\Program Files\Nowe Gadu-Gadu\gg.exe [2010-01-08 11391592]
"ALLUpdate"=C:\Program Files\ALLPlayer\ALLUpdate.exe [2009-06-04 869888]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=c:\program files\daemon tools lite\daemon.exe [2010-01-08 11391592]
"nodenable"=C:\Program Files\eset\nodenable.exe [2010-01-08 11391592]
"UberIcon"=c:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager .exe [2006-05-21 180224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2005-12-16 94208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
C:\WINDOWS\system32\CTHELPER.EXE [2003-06-09 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2010-01-08 11391592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe [2005-03-31 1106944]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
C:\Program Files\Lexmark Fax Solutions\fm3032.exe [2004-02-04 294912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPLA!]
C:\Program Files\ipla\ipla.exe [2009-12-12 14100376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
D:\itunes\iTunesHelper.exe [2009-07-13 292128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe [2001-11-29 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 2200 Series]
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe [2004-02-13 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\System32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2007-04-19 7700480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\System32\NvMcTray.dll [2007-04-19 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
D:\Nokia PC Suite 6\LaunchApplication.exe [2005-03-22 167936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
D:\Nokia PC Suite 6\PcSync2.exe [2005-04-20 847872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Prec]
D:\Prec\PrecStarter.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIAPRO7]
C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe [2005-07-20 274432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-04-04 148888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
C:\Program Files\Trojan Remover\Trjscan.exe [2009-04-29 1053576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2009-02-25 37888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [2002-09-13 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Marcin^Menu Start^Programy^Autostart^Microsoft Office Groove.lnk]
C:\PROGRA~1\MICROS~2\Office12\GROOVE.EXE [2007-08-28 340856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Marcin^Menu Start^Programy^Autostart^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk]
C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [2007-12-07 101440]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
AirLive 802.11G Wireless Utility.lnk - C:\Program Files\OVISLINK\Common\AirliveUI.exe

C:\Documents and Settings\Marcin\Menu Start\Programy\Autostart
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
WinCE3.exe
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoWindowsUpdate"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoLowDiscSpaceChecks"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\nfs\NFSC.exe"="D:\nfs\NFSC.exe:*:Enabled:NFSC"
"C:\WINDOWS\system32\LEXPPS.EXE"="C:\WINDOWS\system32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE"
"C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe"="C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\totalcmd\TOTALCMD.EXE"="D:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"D:\BitComet\BitComet.exe"="D:\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"D:\Counter-Strike 1.6\hl.exe"="D:\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Counter-Strike 1.6\hlds.exe"="D:\Counter-Strike 1.6\hlds.exe:*:Enabled:HLDS Launcher"
"C:\Documents and Settings\Marcin\Pulpit\CabalTemp\ESTSetupLoader.exe"="C:\Documents and Settings\Marcin\Pulpit\CabalTemp\ESTSetupLoader.exe:*:Enabled:EST! download engine"
"C:\Program Files\SHOUTcast\sc_serv.exe"="C:\Program Files\SHOUTcast\sc_serv.exe:*:Enabled:sc_serv"
"C:\Program Files\Hamachi\hamachi.exe"="C:\Program Files\Hamachi\hamachi.exe:*:Disabled:Hamachi Client"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary"
"C:\hipcio\aplikacja\gift\giftl.exe"="C:\hipcio\aplikacja\gift\giftl.exe:*:Enabled:Darmowe pobieranie plików z sieci"
"C:\Program Files\Ares\Ares.exe"="C:\Program Files\Ares\Ares.exe:*:Disabled:Ares p2p for windows"
"D:\itunes\iTunes.exe"="D:\itunes\iTunes.exe:*:Disabled:iTunes"
"C:\Program Files\Nowe Gadu-Gadu\gg.exe"="C:\Program Files\Nowe Gadu-Gadu\gg.exe:*:Disabled:Nowe Gadu-Gadu"
"c:\program files\relevantknowledge\rlvknlg.exe"="c:\program files\relevantknowledge\rlvknlg.exe:*:Disabled:rlvknlg.exe"
"D:\SopCast\adv\SopAdver.exe"="D:\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"D:\SopCast\SopCast.exe"="D:\SopCast\SopCast.exe:*:Disabled:SopCast Main Application"
"D:\ned for speed underground\Speed.exe"="D:\ned for speed underground\Speed.exe:*:Disabled:Speed"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\Program Files\FOX\Aliens vs. Predator 2\lithtech.exe"="D:\Program Files\FOX\Aliens vs. Predator 2\lithtech.exe:*:Enabled:Client"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\WINDOWS\system32\xglslrx.exe"="C:\WINDOWS\system32\xglslrx.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\xglslrx .exe"="C:\WINDOWS\system32\xglslrx .exe:*:Enabled:ENABLE"
"c:\program files\skype\phone\skype .exe"="c:\program files\skype\phone\skype .exe:*:Enabled:skype "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-01-08 21:05:18 ----DC---- C:\rsit
2010-01-05 15:42:12 ----A---- C:\Program Files\RUNDLL32.EXE274520609.dat
2010-01-01 16:47:09 ----D---- C:\Program Files\RocketDock
2010-01-01 16:33:13 ----A---- C:\WINDOWS\system32\soundman.exe.delme98
2010-01-01 16:29:47 ----A---- C:\WINDOWS\BricoPackUninst.cmd
2010-01-01 16:23:18 ----A---- C:\WINDOWS\BricoPackUninst.txt
2010-01-01 16:23:18 ----A---- C:\WINDOWS\BricoPackFoldersDelete.cmd
2010-01-01 16:22:52 ----D---- C:\WINDOWS\BricoPacks
2010-01-01 12:33:56 ----A---- C:\WINDOWS\system32\xglslrx.exe.delme99
2009-12-16 21:59:43 ----D---- C:\Documents and Settings\Marcin\Dane aplikacji\Free Monitor for Google
2009-12-16 21:59:32 ----D---- C:\Program Files\Free Monitor for Google
2009-12-14 03:01:38 ----SHDC---- C:\Config.Msi
2009-12-13 08:51:28 ----A---- C:\WINDOWS\system32\muweb.dll
2009-12-13 08:51:28 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-12-13 08:51:28 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-12-12 19:11:34 ----D---- C:\Program Files\PlayReady
2009-12-10 11:18:50 ----HDC---- C:\WINDOWS\$NtUninstallKB976325$
2009-12-10 03:19:18 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2009-12-10 03:14:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2009-12-10 03:10:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2009-12-10 03:07:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2009-12-10 03:02:17 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$

======List of files/folders modified in the last 1 months======

2010-01-08 21:02:28 ----D---- C:\Program Files\Mozilla Firefox
2010-01-08 20:58:31 ----AD---- C:\WINDOWS\temp
2010-01-08 20:57:56 ----D---- C:\Documents and Settings\Marcin\Dane aplikacji\Hamachi
2010-01-08 20:56:10 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-08 20:43:05 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-08 18:58:00 ----D---- C:\WINDOWS\Prefetch
2010-01-08 16:59:07 ----D---- C:\WINDOWS\system32
2010-01-08 16:55:24 ----D---- C:\Documents and Settings\Marcin\Dane aplikacji\Skype
2010-01-08 16:47:57 ----D---- C:\Program Files\DAEMON Tools Lite
2010-01-08 16:47:48 ----D---- C:\Program Files\Nowe Gadu-Gadu
2010-01-08 16:46:48 ----D---- C:\Program Files\ESET
2010-01-08 16:46:34 ----D---- C:\WINDOWS
2010-01-08 16:44:46 ----D---- C:\Program Files\Messenger
2010-01-08 16:44:08 ----D---- C:\Documents and Settings\Marcin\Dane aplikacji\skypePM
2010-01-08 16:42:17 ----D---- C:\Program Files
2010-01-06 18:57:11 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-04 18:38:16 ----DC---- C:\Documents and Settings\All Users\Dane aplikacji\DVD Shrink
2010-01-04 15:31:38 ----D---- C:\WINDOWS\system32\drivers
2010-01-03 11:02:12 ----D---- C:\Program Files\ALLPlayer
2010-01-03 10:52:39 ----D---- C:\Program Files\NAPI-PROJEKT
2010-01-02 11:31:12 ----A---- C:\WINDOWS\updreg.exe.delme96
2010-01-01 16:33:31 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-01 16:33:01 ----SD---- C:\WINDOWS\Tasks
2010-01-01 16:32:10 ----RSD---- C:\WINDOWS\Fonts
2010-01-01 16:32:10 ----D---- C:\WINDOWS\system32\usmt
2010-01-01 16:32:10 ----D---- C:\Program Files\Outlook Express
2010-01-01 16:32:10 ----D---- C:\Program Files\Movie Maker
2010-01-01 16:32:10 ----D---- C:\Program Files\Internet Explorer
2010-01-01 16:29:46 ----A---- C:\WINDOWS\system32\uxtheme.dll
2010-01-01 16:27:22 ----D---- C:\WINDOWS\Cursors
2010-01-01 16:26:51 ----D---- C:\WINDOWS\Media
2010-01-01 14:33:13 ----D---- C:\Documents and Settings\Marcin\Dane aplikacji\ArcaMicroScan
2010-01-01 12:54:04 ----A---- C:\WINDOWS\system32\BASSMOD.dll
2010-01-01 03:02:20 ----SHD---- C:\WINDOWS\Installer
2009-12-21 16:58:43 ----D---- C:\WINDOWS\Minidump
2009-12-19 15:59:40 ----A---- C:\WINDOWS\wincmd.ini
2009-12-19 12:47:24 ----A---- C:\WINDOWS\wcx_ftp.ini
2009-12-17 20:43:54 ----D---- C:\Documents and Settings\Marcin\Dane aplikacji\Adobe
2009-12-14 03:15:53 ----D---- C:\WINDOWS\Microsoft.NET
2009-12-14 03:12:49 ----DC---- C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2009-12-14 03:07:25 ----RSD---- C:\WINDOWS\assembly
2009-12-13 08:51:28 ----HD---- C:\WINDOWS\inf
2009-12-12 19:11:39 ----DC---- C:\Documents and Settings\All Users\Dane aplikacji\ipla
2009-12-12 19:11:34 ----SDC---- C:\Documents and Settings\All Users\Dane aplikacji\Microsoft
2009-12-12 19:08:42 ----D---- C:\Documents and Settings\Marcin\Dane aplikacji\ipla
2009-12-12 19:08:35 ----D---- C:\Program Files\ipla
2009-12-12 12:40:16 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-12-10 03:22:45 ----A---- C:\WINDOWS\imsins.BAK
2009-12-10 03:10:02 ----HD---- C:\WINDOWS\$hf_mig$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
R1 SysTool;SysTool Overclocking Utility; C:\WINDOWS\system32\DRIVERS\SysTool.sys [2006-11-10 24064]
R1 Tcpip6;Sterownik protokołu IPv6 Microsoft; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2008-06-20 225856]
R1 WS2IFSL;Środowisko wspomagające dostawcę usług innych niż IFS - Windows Socket 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-17 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.5.3.0; C:\WINDOWS\System32\DRIVERS\AegisP.sys [2009-03-23 21419]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-02-06 113448]
R2 PfModNT;PfModNT; \??\C:\WINDOWS\System32\drivers\PfModNT.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-07-15 3640000]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys [2003-06-09 186068]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2003-06-09 494384]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys [2003-06-09 6144]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys [2003-06-09 136448]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys [2003-06-09 116416]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2003-06-09 819984]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-11-07 25280]
R3 HssDrv;Hotspot Shield Helper Miniport; C:\WINDOWS\System32\DRIVERS\HssDrv.sys [2009-09-15 37376]
R3 ms_mpu401;Sterownik portu MIDI UART Microsoft MPU-401; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2007-04-19 3988384]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2005-04-05 12928]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2003-06-09 113840]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-08-17 5888]
R3 RT61;AirLive WT-2000PCI; C:\WINDOWS\System32\DRIVERS\RT61.sys [2007-07-27 483968]
R3 taphss;Anchorfree HSS Adapter; C:\WINDOWS\system32\DRIVERS\taphss.sys [2009-09-15 32768]
R3 tapvpn;TAP VPN Adapter; C:\WINDOWS\System32\DRIVERS\tapvpn.sys [2008-01-23 27136]
R3 tunmp;Sterownik karty Microsoft Tun Miniport; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Standardowy sterownik koncentratora USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Sterownik Miniport otwartego kontrolera hosta USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S3 avde3h3d;avde3h3d; C:\WINDOWS\system32\drivers\avde3h3d.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\D:\MediaCoder iPod Edition\SysInfo.sys []
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\System32\drivers\ctdvda2k.sys []
S3 ctljystk;Port gier dla karty Creative SB Live!; C:\WINDOWS\System32\DRIVERS\ctljystk.sys [2001-08-17 3712]
S3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\System32\drivers\hap16v2k.sys [2003-06-09 135696]
S3 HidUsb;Sterownik Microsoft klasy HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mdxgthkn;mdxgthkn; \??\C:\DOCUME~1\Marcin\USTAWI~1\Temp\mdxgthkn.sys []
S3 Nokia USB Generic;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2005-02-15 6300]
S3 Nokia USB Modem;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2005-02-15 9021]
S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2005-02-17 140619]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [2005-04-05 33536]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2009-07-22 28592]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-06-05 39424]
S3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Klasa PRINTER USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Sterownik skanera USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Sterownik magazynu masowego USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Sterownik filtru Przywracania systemu; C:\WINDOWS\System32\DRIVERS\sr.sys [2008-04-14 73472]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Usługa Pomocnik IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-06-05 144712]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\System32\CTsvcCDA.exe [1999-12-13 44032]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe [2007-10-16 81920]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
R2 HotspotShieldService;Hotspot Shield Service; C:\Program Files\Hotspot Shield\bin\openvpnas.exe [2009-09-15 204848]
R2 HssSrv;Hotspot Shield Helper Service; C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe [2009-09-15 331824]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-04-04 152984]
R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2004-01-14 311296]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2007-04-19 159810]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-09-13 66872]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINDOWS\System32\MsPMSPSv.exe [2000-06-26 53520]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe [2007-10-16 2711552]
S2 SSHNAS;SSHNAS; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;Usuga stanu ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-02-06 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-05-24 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 HssTrayService;Hotspot Shield Tray Service; D:\Hotspot Shield\bin\HssTrayService.EXE []
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;Usługa iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-07-13 542496]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2009-11-17 3596060]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Usługa udostępniania w sieci programu Windows Media Player; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-12-01 918016]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------


Dodano Dzisiaj, 21:11:
i log z hijacka
Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 21:11:01, on 2010-01-08
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Nowe Gadu-Gadu\gg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager .exe
C:\Program Files\OVISLINK\Common\AirliveUI.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Documents and Settings\Marcin\Menu Start\Programy\Autostart\WinCE3.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-781cd0e19f00} - c:\program files\steganos internet anonym pro 7\siapro7iep.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe
O4 - HKCU\..\Run: [UberIcon] "c:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager .exe"
O4 - HKUS\S-1-5-19\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: WinCE3.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: AirLive 802.11G Wireless Utility.lnk = C:\Program Files\OVISLINK\Common\AirliveUI.exe
O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Dane aplikacji\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Pobierz wszystkie VIdeo za pomocą BitComet - res://D:\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - res://D:\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Pobierz za pomocą BitComet - res://D:\BitComet\BitComet.exe/AddLink.htm
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\EXPRES~2\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://D:\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{175D818A-1397-4B80-8551-57FB83BC22D0}: NameServer = 194.204.152.34,194.204.159.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{175D818A-1397-4B80-8551-57FB83BC22D0}: NameServer = 194.204.152.34,194.204.159.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - D:\Hotspot Shield\bin\HssTrayService.EXE (file missing)
O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 10522 bytes
Awatar użytkownika
marcinbak10
~user
 
Posty: 62
Dołączenie: 18 Mar 2009, 21:38
Miejscowość: włoszczowa



Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Postprzez wojtas 09 Sty 2010, 16:23

zrób skan : http://www.programosy.pl/program,dr-web-cureit.html pokaż raport oraz Daj loga z combofixa ale zainstaluj wraz z nim konsolę odzyskiwania ( instrukcja programu )

Autor postu otrzymał pochwałę
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Postprzez marcinbak10 13 Sty 2010, 17:20

niestety dr webem nie da sie przeskanowac bo mi wywala blue screny

Image
za chwile dam loga z combofixa

Dodano Dzisiaj, 16:51:
Kod: Zaznacz wszystko
ComboFix 10-01-12.05 - Marcin 2010-01-13  16:37:52.4.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1250.48.1045.18.1535.1001 [GMT 1:00]
Uruchomiony z: G:\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezydentny antywirus jest aktywny

.

(((((((((((((((((((((((((((((((((((((((   Usunięto   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Marcin\Menu Start\Programy\Autostart\WinCE3.exe
c:\documents and settings\Marcin\rundll32.exe
c:\program files\Internet Explorer\wmpscfgs.exe
c:\program files\RelevantKnowledge
c:\program files\RelevantKnowledge\rlls.dll
c:\program files\RelevantKnowledge\rloci.bin
c:\program files\RelevantKnowledge\rlservice.exe
c:\windows\system32\_000057_.tmp.dll
c:\windows\system32\ctfmon .exe
c:\windows\system32\Data
c:\windows\system32\Data\CT0060W.DAT
c:\windows\system32\Data\CTP0060W.DAT
c:\windows\system32\Data\CTP0061W.DAT
c:\windows\system32\Data\CTP0100W.DAT
c:\windows\system32\Data\CTP0101W.DAT
c:\windows\system32\Data\CTP0102W.DAT
c:\windows\system32\Data\CTP0103W.DAT
c:\windows\system32\Data\CTP0105W.DAT
c:\windows\system32\Data\CTP0170W.DAT
c:\windows\system32\Data\CTP017AW.DAT
c:\windows\system32\Data\CTP017BW.DAT
c:\windows\system32\Data\CTP017CW.DAT
c:\windows\system32\Data\CTP017DW.DAT
c:\windows\system32\Data\CTP017EW.DAT
c:\windows\system32\Data\CTP017FW.DAT
c:\windows\system32\Data\CTP017GW.DAT
c:\windows\system32\Data\CTP017HW.DAT
c:\windows\system32\Data\CTP0221W.DAT
c:\windows\system32\Data\CTP0222W.DAT
c:\windows\system32\Data\CTP0226W.DAT
c:\windows\system32\Data\CTP0228W.DAT
c:\windows\system32\Data\CTP1140W.DAT
c:\windows\system32\Data\CTP4620W.DAT
c:\windows\system32\Data\CTP4670W.DAT
c:\windows\system32\Data\CTP4760W.DAT
c:\windows\system32\Data\CTP4780W.DAT
c:\windows\system32\Data\CTP4790W.DAT
c:\windows\system32\Data\CTP4830W.DAT
c:\windows\system32\Data\CTP4831W.DAT
c:\windows\system32\Data\CTP4832W.DAT
c:\windows\system32\Data\CTP4840W.DAT
c:\windows\system32\Data\CTP4850W.DAT
c:\windows\system32\Data\CTP4870W.DAT
c:\windows\system32\Data\CTP4871W.DAT
c:\windows\system32\Data\CTP4872W.DAT
c:\windows\system32\Data\CTP4875W.DAT
c:\windows\system32\Data\CTP4890W.DAT
c:\windows\system32\Data\CTP4891W.DAT
c:\windows\system32\Data\CTP4893W.DAT
c:\windows\system32\Data\CTPDXW.DAT
c:\windows\system32\Data\CTPM002W.DAT
c:\windows\system32\Data\CTSBASW.DAT
c:\windows\system32\ieuinit.inf
c:\windows\system32\kr_done1
c:\windows\system32\rundll32 .exe
c:\windows\system32\twain_32.dll
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
c:\windows\updreg .exe

Zainfekowana kopia c:\windows\system32\winlogon.exe została znaleziona. Problem naprawiono
Plik odzyskano z - c:\windows\ServicePackFiles\i386\winlogon.exe

.
(((((((((((((((((((((((((((((((((((((((   Sterowniki/Usługi   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SSHNAS
-------\Service_SSHNAS


(((((((((((((((((((((((((   Pliki utworzone od 2009-12-13 do 2010-01-13  )))))))))))))))))))))))))))))))
.

2010-01-08 21:14 . 2010-01-08 21:14   --------   dc----w-   C:\Downloads
2010-01-08 20:09 . 2010-01-08 20:09   388096   ----a-r-   c:\documents and settings\Marcin\Dane aplikacji\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-08 20:09 . 2010-01-08 20:09   --------   d-----w-   c:\program files\TrendMicro
2010-01-08 20:05 . 2010-01-08 20:05   --------   dc----w-   C:\rsit
2010-01-05 14:42 . 2010-01-05 14:42   4   ----a-w-   c:\program files\RUNDLL32.EXE274520609.dat
2010-01-01 15:47 . 2010-01-08 20:45   --------   d-----w-   c:\program files\RocketDock
2010-01-01 15:29 . 2010-01-01 15:29   65701   ----a-w-   c:\windows\BricoPackUninst.cmd
2010-01-01 15:23 . 2010-01-01 15:29   7275   ----a-w-   c:\windows\BricoPackFoldersDelete.cmd
2010-01-01 15:22 . 2010-01-01 15:22   --------   d-----w-   c:\windows\BricoPacks
2009-12-16 20:59 . 2009-12-16 21:16   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\Free Monitor for Google
2009-12-16 20:59 . 2009-12-16 20:59   --------   d-----w-   c:\program files\Free Monitor for Google

.
((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-13 15:42 . 2009-03-23 17:06   288   ----a-w-   c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000002-80671102}.dat
2010-01-13 15:42 . 2009-03-23 17:06   288   ----a-w-   c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000002-80671102}.dat
2010-01-13 15:03 . 2009-08-14 19:03   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\Hamachi
2010-01-08 20:47 . 2009-05-05 19:37   --------   d-----w-   c:\program files\Total Video Converter
2010-01-08 20:37 . 2009-08-14 06:06   --------   d-----w-   c:\program files\ESET
2010-01-08 20:24 . 2009-05-30 22:14   --------   d-----w-   c:\program files\ALLPlayer
2010-01-08 15:55 . 2009-11-16 15:52   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\Skype
2010-01-08 15:47 . 2009-04-17 13:35   --------   d-----w-   c:\program files\DAEMON Tools Lite
2010-01-08 15:47 . 2009-03-23 17:22   --------   d-----w-   c:\program files\Nowe Gadu-Gadu
2010-01-08 15:44 . 2009-11-16 16:06   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\skypePM
2010-01-04 17:38 . 2009-05-16 11:35   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\DVD Shrink
2010-01-03 09:52 . 2009-05-30 22:14   --------   d-----w-   c:\program files\NAPI-PROJEKT
2010-01-01 15:29 . 2002-09-20 17:04   219648   ----a-w-   c:\windows\system32\uxtheme.dll
2010-01-01 15:29 . 2009-04-12 13:13   81824   ----a-w-   c:\documents and settings\Marcin\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2010-01-01 13:33 . 2009-07-03 13:57   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\ArcaMicroScan
2009-12-14 02:12 . 2009-06-10 15:03   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2009-12-12 18:11 . 2009-04-25 13:46   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\ipla
2009-12-12 18:11 . 2009-12-12 18:11   --------   d-----w-   c:\program files\PlayReady
2009-12-12 18:08 . 2009-04-25 13:46   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\ipla
2009-12-12 18:08 . 2009-04-25 13:46   --------   d-----w-   c:\program files\ipla
2009-12-12 11:40 . 2001-10-26 16:15   85136   ----a-w-   c:\windows\system32\perfc015.dat
2009-12-12 11:40 . 2001-10-26 16:15   493976   ----a-w-   c:\windows\system32\perfh015.dat
2009-12-12 11:29 . 2009-05-24 10:06   80240   -c--a-w-   c:\documents and settings\na chwile\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-12-12 11:29 . 2009-12-12 11:29   --------   dc----w-   c:\documents and settings\na chwile\Dane aplikacji\ipla
2009-11-28 15:54 . 2009-08-05 15:49   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\OpenFM
2009-11-21 16:26 . 2009-11-21 16:25   --------   d-----w-   c:\program files\Opera
2009-11-16 16:06 . 2009-11-16 16:06   56   ---ha-w-   c:\windows\system32\ezsidmv.dat
2009-11-16 15:52 . 2009-11-16 15:50   --------   d-----r-   c:\program files\Skype
2009-11-16 15:50 . 2009-11-16 15:50   --------   d-----w-   c:\program files\Common Files\Skype
2009-11-16 15:50 . 2009-11-16 15:50   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\Skype
2009-11-14 17:56 . 2009-11-14 17:55   --------   d-----w-   c:\program files\VirtualDJ
2009-11-10 16:13 . 2009-11-10 16:13   60416   ----a-w-   c:\windows\ALCFDRTM.EXE
2009-11-07 19:35 . 2009-08-14 19:01   25280   ----a-w-   c:\windows\system32\drivers\hamachi.sys
2009-10-29 05:26 . 2002-09-20 17:05   704000   ----a-w-   c:\windows\system32\wininet.dll
2009-10-21 05:40 . 2009-04-12 13:03   25088   ----a-w-   c:\windows\system32\httpapi.dll
2009-10-21 05:40 . 2009-04-12 13:03   75776   ----a-w-   c:\windows\system32\strmfilt.dll
2009-10-20 16:20 . 2009-04-12 12:59   265728   ------w-   c:\windows\system32\drivers\http.sys
2009-10-18 07:17 . 2009-10-18 07:17   0   ----a-w-   c:\windows\system32\cd.dat
2009-10-09 07:14 . 2009-10-09 07:10   8801704   ----a-w-   c:\program files\FLV PlayerATBSetup.exe
2009-05-01 21:02 . 2009-05-01 21:02   1044480   ----a-w-   c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02   200704   ----a-w-   c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-05-03 10:06 . 2009-05-03 11:19   163328   --sh--r-   c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2009-05-03 11:19   31232   --sh--r-   c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2009-05-03 11:19   216064   --sh--r-   c:\windows\system32\nbDX.dll
.
[code]<pre>
c:\program files\ALLPlayer\allupdate .exe
c:\program files\DAEMON Tools Lite\daemon .exe
c:\program files\ESET\nodenable .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\Nowe Gadu-Gadu\gg .exe
c:\program files\RocketDock\rocketdock .exe
c:\program files\Skype\Phone\skype .exe
c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\rocketdock .exe
c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\ubericon manager .exe
</pre>[/code]

------- Sigcheck -------

[-] 2009-08-06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226] . . c:\windows\ServicePackFiles\i386\wuauclt.exe
[-] 2009-08-06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
[7] 2009-08-06 . 62BB79160F86CD962F312C68C6239BFD . 53472 . . [7.4.7600.226] . . c:\windows\system32\dllcache\wuauclt.exe
[-] 2002-09-20 . 2BDCBF19C5222FDA21B049D1FBAC7B36 . 142336 . . [5.4.3630.1106] . . c:\windows\$NtServicePackUninstall$\wuauclt.exe

[-] 2009-10-29 . AF365531C7434D7DC2B19721CBC40856 . 3532800 . . [6.00.2900.5897] . . c:\windows\ServicePackFiles\i386\mshtml.dll
[-] 2009-10-29 . AF365531C7434D7DC2B19721CBC40856 . 3532800 . . [6.00.2900.5897] . . c:\windows\system32\mshtml.dll
[7] 2009-10-29 . 2E6A5DFB8C17AFA768C133E07692CD0F . 3091968 . . [6.00.2900.5897] . . c:\windows\system32\dllcache\mshtml.dll
[7] 2009-10-29 . ED8E4599D07EA8BB78DF1DE2D01DFE8D . 3094016 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\mshtml.dll
[7] 2009-10-19 . 27642F792884EDAF17E20015EF8D14A0 . 3091968 . . [6.00.2900.5890] . . c:\windows\$NtUninstallKB976325$\mshtml.dll
[7] 2009-10-19 . FE866674FCCBB3C48C08D1C38A7495F3 . 3093504 . . [6.00.2900.5890] . . c:\windows\$hf_mig$\KB976749\SP3QFE\mshtml.dll
[7] 2009-09-25 . B8CD6BEC812643CEF0267A3BDE031171 . 3091968 . . [6.00.2900.5880] . . c:\windows\$NtUninstallKB976749$\mshtml.dll
[7] 2009-09-25 . 4FA7BCC0D7E9C23124741A6C084AD1F4 . 3093504 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\mshtml.dll
[7] 2009-07-18 . F7AF065A9862881D4AB4087DE280E191 . 3090432 . . [6.00.2900.5848] . . c:\windows\$NtUninstallKB974455$\mshtml.dll
[7] 2009-07-18 . ECE00769606C4E3A1162809F6561D019 . 3090944 . . [6.00.2900.5848] . . c:\windows\$hf_mig$\KB972260\SP3QFE\mshtml.dll
[7] 2008-04-14 . EBEF7EDB0DF1B4BF195FDA7CCFB7AC30 . 3066880 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB972260$\mshtml.dll
[-] 2002-09-20 . 9AB0EE83610E6E1F32592C28F394643C . 2833920 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\mshtml.dll

[-] 2009-10-29 . 229358ACC890C9898FFB8FC5089A1C06 . 704000 . . [6.00.2900.5897] . . c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2009-10-29 . 229358ACC890C9898FFB8FC5089A1C06 . 704000 . . [6.00.2900.5897] . . c:\windows\system32\wininet.dll
[7] 2009-10-29 . 95B46900474333E7029B0B2EFC2CE375 . 669696 . . [6.00.2900.5897] . . c:\windows\system32\dllcache\wininet.dll
[7] 2009-10-29 . 581984033E11303CABE8E7B86368DBDA . 671232 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\wininet.dll
[7] 2009-09-25 . 1F8828A945D7FB98AADB27D0B5B232C1 . 669696 . . [6.00.2900.5880] . . c:\windows\$NtUninstallKB976325$\wininet.dll
[7] 2009-09-25 . 35AC400C8625B4E78D129D6E2F25FDE6 . 671232 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\wininet.dll
[7] 2009-06-26 . 89BEAC1F845B315911FB8AE458164512 . 669184 . . [6.00.2900.5835] . . c:\windows\$NtUninstallKB974455$\wininet.dll
[7] 2009-06-26 . 659F7EEDDB355B1F97BD0E0435736D2B . 670720 . . [6.00.2900.5835] . . c:\windows\$hf_mig$\KB972260\SP3QFE\wininet.dll
[7] 2008-04-14 . 0457F0AFD6EE10445D8CF721FB5FA4EB . 668672 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB972260$\wininet.dll
[-] 2002-09-20 . 4965C02574610E9B2D1E18D63D11A772 . 601600 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\wininet.dll

[-] 2008-04-14 . F042E3426D45D86D9BB55F6A79AB441A . 977408 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . F042E3426D45D86D9BB55F6A79AB441A . 977408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2002-09-20 . F4AF85D918E83D71341FCE2AA5318181 . 1005568 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\explorer.exe
.
(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane 
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{14f0d511-36a2-41ca-ae01-ba4f87282c97}"= "c:\program files\SHOUTcast Radio Toolbar\shoutcasttb.dll" [2008-09-17 1275176]

[HKEY_CLASSES_ROOT\clsid\{14f0d511-36a2-41ca-ae01-ba4f87282c97}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{8613efdf-b530-4b1d-b970-b09f99977813}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-08-27 16:48   218160   ----a-w-   c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nowe Gadu-Gadu"="c:\program files\Nowe Gadu-Gadu\gg.exe" [2010-01-08 11391592]
"ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2009-06-04 869888]
"DAEMON Tools Lite"="c:\program files\daemon tools lite\daemon.exe" [2010-01-08 11391592]
"nodenable"="c:\program files\eset\nodenable.exe" [2010-01-08 11391592]
"UberIcon"="c:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager .exe" [2006-05-21 180224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SIAPRO7"="c:\program files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" [2005-07-20 274432]

c:\documents and settings\Marcin\Menu Start\Programy\Autostart\
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2009-11-7 625952]

c:\documents and settings\All Users\Menu Start\Programy\Autostart\
AirLive 802.11G Wireless Utility.lnk - c:\program files\OVISLINK\Common\AirliveUI.exe [2009-3-23 1290240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiscSpaceChecks"= 000000000000f03f

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Marcin^Menu Start^Programy^Autostart^Microsoft Office Groove.lnk]
path=c:\documents and settings\Marcin\Menu Start\Programy\Autostart\Microsoft Office Groove.lnk
backup=c:\windows\pss\Microsoft Office Groove.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Marcin^Menu Start^Programy^Autostart^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk]
path=c:\documents and settings\Marcin\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
backup=c:\windows\pss\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2005-12-16 10:57   94208   ----a-w-   c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
2003-06-09 02:07   28672   ----a-w-   c:\windows\system32\CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-01-08 15:48   11391592   ----a-w-   c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
2005-03-31 07:30   1106944   ----a-w-   c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
2004-02-04 14:33   294912   ----a-w-   c:\program files\Lexmark Fax Solutions\fm3032.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2007-08-24 05:00   33648   ----a-w-   c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPLA!]
2009-12-12 13:48   14100376   ----a-w-   c:\program files\ipla\ipla.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-07-13 12:03   292128   ----a-w-   d:\itunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
2001-11-29 00:00   28672   ----a-w-   c:\program files\Creative\SBLive\Program\ADGJDet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 2200 Series]
2004-02-13 13:34   57344   ----a-w-   c:\program files\Lexmark 2200 Series\lxbvbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 08:50   155648   ----a-w-   c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2007-04-19 05:26   7700480   ----a-w-   c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2007-04-19 05:26   86016   ----a-w-   c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2007-04-19 05:26   1626112   ----a-w-   c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
2005-03-22 07:39   167936   ----a-w-   d:\nokia pc suite 6\LaunchApplication.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
2005-04-20 07:57   847872   ----a-w-   d:\nokia pc suite 6\PcSync2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Prec]
d:\prec\PrecStarter.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18   413696   ----a-w-   c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIAPRO7]
2005-07-20 12:05   274432   ----a-w-   c:\program files\Steganos Internet Anonym Pro 7\SIAPRO7.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-04-04 20:58   148888   ----a-w-   c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
2009-04-29 16:19   1053576   ----a-w-   c:\program files\Trojan Remover\Trjscan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-02-25 21:26   37888   ----a-w-   c:\program files\Winamp\winampa.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"d:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\BitComet\\BitComet.exe"=
"d:\\Counter-Strike 1.6\\hl.exe"=
"d:\\Counter-Strike 1.6\\hlds.exe"=
"c:\\Program Files\\SHOUTcast\\sc_serv.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"d:\\itunes\\iTunes.exe"=
"c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"d:\\SopCast\\adv\\SopAdver.exe"=
"d:\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\Program Files\\FOX\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\program files\\skype\\phone\\skype .exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8461:TCP"= 8461:TCP:*:Disabled:GoD High Port
"8462:TCP"= 8462:TCP:*:Disabled:GoD Low Port
"22602:TCP"= 22602:TCP:BitComet 22602 TCP
"22602:UDP"= 22602:UDP:BitComet 22602 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-04-15 717296]
R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\drivers\tffsport.sys [2009-03-29 149376]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-02-06 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-02-06 93336]
R1 SysTool;SysTool Overclocking Utility;c:\windows\system32\drivers\SysTool.sys [2006-11-10 24064]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance [?]
S3 mdxgthkn;mdxgthkn;\??\c:\docume~1\Marcin\USTAWI~1\Temp\mdxgthkn.sys --> c:\docume~1\Marcin\USTAWI~1\Temp\mdxgthkn.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
Zawartość folderu 'Zaplanowane zadania'

2010-01-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://google.atcomet.com/b/
uInternet Settings,ProxyServer = http=
uInternet Settings,ProxyOverride = *.local
IE: &SHOUTcast Search - c:\documents and settings\All Users\Dane aplikacji\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Pobierz wszystkie VIdeo za pomocą BitComet - d:\bitcomet\BitComet.exe/AddVideo.htm
IE: Pobierz wszystko za pomocą BitComet - d:\bitcomet\BitComet.exe/AddAllLink.htm
IE: Pobierz za pomocą BitComet - d:\bitcomet\BitComet.exe/AddLink.htm
LSP: c:\program files\Secure Surfing Engine\sselsp.dll
TCP: {175D818A-1397-4B80-8551-57FB83BC22D0} = 194.204.152.34,194.204.159.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Marcin\Dane aplikacji\Mozilla\Firefox\Profiles\qw7i44od.default\
FF - component: c:\documents and settings\Marcin\Dane aplikacji\Mozilla\Firefox\Profiles\qw7i44od.default\extensions\{a3b7b698-c13e-4f08-8c43-4ae1cfe8f6e8}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Marcin\Dane aplikacji\Mozilla\Firefox\Profiles\qw7i44od.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll
FF - plugin: c:\documents and settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\nppl3260.dll
FF - plugin: c:\documents and settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin9.dll
FF - plugin: c:\program files\Opera\program\plugins\nppdf32.dll
FF - plugin: c:\program files\Opera\program\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Opera\program\plugins\npqtplugin9.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin9.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - USUNIĘTO PUSTE WPISY - - - -

AddRemove-HijackThis - c:\documents and settings\Marcin\Pulpit\HijackThis.exe
AddRemove-SC Net Speed Booster_is1 - f:\sc net speed booster\unins000.exe
AddRemove-Soul Reaver 2 Demo - d:\\Eidos Interactive\Soul Reaver 2 Demo\uninstsr2demo.exe
AddRemove-TV - D:\hjhvjvUninst0.exe
AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:\program files\relevantknowledge\rlvknlg.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-13 16:44
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ... 

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ... 

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89A6A1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba8ecf28
\Driver\ACPI -> ACPI.sys @ 0xba666cb8
\Driver\atapi -> atapi.sys @ 0xba5fbb40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
NDIS: AirLive WT-2000PCI -> SendCompleteHandler -> NDIS.sys @ 0xba4cab0a
PacketIndicateHandler -> NDIS.sys @ 0xba4d5a21
SendHandler -> NDIS.sys @ 0xba4ca949
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------

[HKEY_USERS\S-1-5-21-1659004503-179605362-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1659004503-179605362-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D6C33E2A-8CD9-F347-F73F-23696A1F7B76}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaapmefhllbnojjelm"=hex:6b,61,6a,6a,68,6b,65,6b,70,63,63,6b,62,65,63,6d,69,6c,
   6c,62,66,6e,00,00
"hagpchodlgoeagnb"=hex:69,61,62,6b,69,61,70,68,67,64,6d,61,6b,64,64,63,70,6b,
   00,00
"iampefcfehpdaefbee"=hex:63,61,6d,6a,66,6c,00,7c

[HKEY_USERS\S-1-5-21-1659004503-179605362-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F94FC1DC-F69D-C919-D553-F066DDBB7738}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------

- - - - - - - > 'lsass.exe'(708)
c:\windows\system32\scecli.dll
c:\program files\Secure Surfing Engine\sselsp.dll

- - - - - - - > 'explorer.exe'(2516)
c:\windows\system32\SHDOCVW.dll
c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.dll
c:\windows\bricopacks\vista inspirat 2\ubericon\UberIcon.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\WPDShServiceObj.dll
d:\nokia pc suite 6\PhoneBrowser.dll
d:\nokia pc suite 6\PCSCM.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.exe
c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Nowe Gadu-Gadu\spellchecker_gg.exe
c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\wscntfy.exe
c:\windows\System32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Czas ukończenia: 2010-01-13  16:50:01 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt  2010-01-13 15:49

Przed: 757 518 336 bajtów wolnych
Po: 4 677 578 752 bajtów wolnych

WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - BBE3F8797706CA0520F4F7085EE38B98


Dodano Dzisiaj, 17:08:
po logu z combofixa wysiadl mi dzwiek i non stop wyskakuje blue scren jak chce cos wlaczyc dac srena ??????

Dodano Dzisiaj, 17:11:
glosu nie ma bo mi wywalilo stery od creativa zostaly tylko od wbudowanej karty
Awatar użytkownika
marcinbak10
~user
 
Posty: 62
Dołączenie: 18 Mar 2009, 21:38
Miejscowość: włoszczowa



Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Postprzez wojtas 13 Sty 2010, 22:49

przeinstaluj sterowniki od karty graficznej , od kontrolera sata nvidi ( od płyty głównej wszystkie ) potem odpal drweba..

Otworz notatnik i wklej w nim to:

File::
c:\program files\RUNDLL32.EXE274520609.dat
c:\program files\ALLPlayer\allupdate .exe
c:\program files\DAEMON Tools Lite\daemon .exe
c:\program files\ESET\nodenable .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\Nowe Gadu-Gadu\gg .exe
c:\program files\RocketDock\rocketdock .exe
c:\program files\Skype\Phone\skype .exe
c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\rocketdock .exe
c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\ubericon manager .exe



>>Plik>>Zapisz jako... >>> CFScript
Przeciągnij i upuść plik CFScript.txt na plik ComboFix.exe
-->Image
Rozpocznie się usuwanie i powstanie log daj go
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Postprzez marcinbak10 14 Sty 2010, 21:16

przeinstalowalem stery log z combofixa i zalaczam dr weba :)
Kod: Zaznacz wszystko
ComboFix 10-01-14.01 - Marcin 2010-01-14  19:54:25.5.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1250.48.1045.18.1535.912 [GMT 1:00]
Uruchomiony z: G:\ComboFix.exe
Użyto następujących komend :: G:\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezydentny antywirus jest aktywny


FILE ::
"c:\program files\ALLPlayer\allupdate .exe"
"c:\program files\DAEMON Tools Lite\daemon .exe"
"c:\program files\ESET\nodenable .exe"
"c:\program files\Messenger\msmsgs .exe"
"c:\program files\Nowe Gadu-Gadu\gg .exe"
"c:\program files\RocketDock\rocketdock .exe"
"c:\program files\RUNDLL32.EXE274520609.dat"
"c:\program files\Skype\Phone\skype .exe"
"c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\rocketdock .exe"
"c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\ubericon manager .exe"
.

(((((((((((((((((((((((((((((((((((((((   Usunięto   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\ALLPlayer\allupdate .exe
c:\program files\DAEMON Tools Lite\daemon .exe
c:\program files\ESET\nodenable .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\Nowe Gadu-Gadu\gg .exe
c:\program files\RocketDock\rocketdock .exe
c:\program files\RUNDLL32.EXE274520609.dat
c:\program files\Skype\Phone\skype .exe
c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\rocketdock .exe
c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\ubericon manager .exe
c:\windows\system32\Data
c:\windows\system32\Data\CT0060W.DAT
c:\windows\system32\Data\CTP0060W.DAT
c:\windows\system32\Data\CTP0061W.DAT
c:\windows\system32\Data\CTP0100W.DAT
c:\windows\system32\Data\CTP0101W.DAT
c:\windows\system32\Data\CTP0102W.DAT
c:\windows\system32\Data\CTP0103W.DAT
c:\windows\system32\Data\CTP0105W.DAT
c:\windows\system32\Data\CTP0170W.DAT
c:\windows\system32\Data\CTP017AW.DAT
c:\windows\system32\Data\CTP017BW.DAT
c:\windows\system32\Data\CTP017CW.DAT
c:\windows\system32\Data\CTP017DW.DAT
c:\windows\system32\Data\CTP017EW.DAT
c:\windows\system32\Data\CTP017FW.DAT
c:\windows\system32\Data\CTP017GW.DAT
c:\windows\system32\Data\CTP017HW.DAT
c:\windows\system32\Data\CTP0221W.DAT
c:\windows\system32\Data\CTP0222W.DAT
c:\windows\system32\Data\CTP0226W.DAT
c:\windows\system32\Data\CTP0228W.DAT
c:\windows\system32\Data\CTP1140W.DAT
c:\windows\system32\Data\CTP4620W.DAT
c:\windows\system32\Data\CTP4670W.DAT
c:\windows\system32\Data\CTP4760W.DAT
c:\windows\system32\Data\CTP4780W.DAT
c:\windows\system32\Data\CTP4790W.DAT
c:\windows\system32\Data\CTP4830W.DAT
c:\windows\system32\Data\CTP4831W.DAT
c:\windows\system32\Data\CTP4832W.DAT
c:\windows\system32\Data\CTP4840W.DAT
c:\windows\system32\Data\CTP4850W.DAT
c:\windows\system32\Data\CTP4870W.DAT
c:\windows\system32\Data\CTP4871W.DAT
c:\windows\system32\Data\CTP4872W.DAT
c:\windows\system32\Data\CTP4875W.DAT
c:\windows\system32\Data\CTP4890W.DAT
c:\windows\system32\Data\CTP4891W.DAT
c:\windows\system32\Data\CTP4893W.DAT
c:\windows\system32\Data\CTPDXW.DAT
c:\windows\system32\Data\CTPM002W.DAT
c:\windows\system32\Data\CTSBASW.DAT
c:\windows\system32\winlogon.bak

.
(((((((((((((((((((((((((   Pliki utworzone od 2009-12-14 do 2010-01-14  )))))))))))))))))))))))))))))))
.

2010-01-13 16:37 . 2010-01-14 18:23   288   ----a-w-   c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000002-80671102}.dat
2010-01-13 16:37 . 2010-01-14 18:23   288   ----a-w-   c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000002-80671102}.dat
2010-01-13 15:21 . 2009-11-21 16:03   471552   -c----w-   c:\windows\system32\dllcache\aclayers.dll
2010-01-08 21:14 . 2010-01-08 21:14   --------   dc----w-   C:\Downloads
2010-01-08 20:09 . 2010-01-08 20:09   388096   ----a-r-   c:\documents and settings\Marcin\Dane aplikacji\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-08 20:09 . 2010-01-08 20:09   --------   d-----w-   c:\program files\TrendMicro
2010-01-08 20:05 . 2010-01-08 20:05   --------   dc----w-   C:\rsit
2010-01-01 15:47 . 2010-01-14 18:59   --------   d-----w-   c:\program files\RocketDock
2010-01-01 15:29 . 2010-01-01 15:29   65701   ----a-w-   c:\windows\BricoPackUninst.cmd
2010-01-01 15:23 . 2010-01-01 15:29   7275   ----a-w-   c:\windows\BricoPackFoldersDelete.cmd
2010-01-01 15:22 . 2010-01-01 15:22   --------   d-----w-   c:\windows\BricoPacks
2009-12-16 20:59 . 2009-12-16 21:16   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\Free Monitor for Google
2009-12-16 20:59 . 2009-12-16 20:59   --------   d-----w-   c:\program files\Free Monitor for Google

.
((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-14 18:59 . 2009-03-23 17:22   --------   d-----w-   c:\program files\Nowe Gadu-Gadu
2010-01-14 18:59 . 2009-08-14 06:06   --------   d-----w-   c:\program files\ESET
2010-01-14 18:59 . 2009-04-17 13:35   --------   d-----w-   c:\program files\DAEMON Tools Lite
2010-01-14 18:59 . 2009-05-30 22:14   --------   d-----w-   c:\program files\ALLPlayer
2010-01-14 18:57 . 2009-08-14 19:03   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\Hamachi
2010-01-14 02:01 . 2009-06-10 15:03   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2010-01-08 20:47 . 2009-05-05 19:37   --------   d-----w-   c:\program files\Total Video Converter
2010-01-08 15:55 . 2009-11-16 15:52   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\Skype
2010-01-08 15:44 . 2009-11-16 16:06   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\skypePM
2010-01-04 17:38 . 2009-05-16 11:35   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\DVD Shrink
2010-01-03 09:52 . 2009-05-30 22:14   --------   d-----w-   c:\program files\NAPI-PROJEKT
2010-01-01 15:29 . 2002-09-20 17:04   219648   ----a-w-   c:\windows\system32\uxtheme.dll
2010-01-01 15:29 . 2009-04-12 13:13   81824   ----a-w-   c:\documents and settings\Marcin\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2010-01-01 13:33 . 2009-07-03 13:57   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\ArcaMicroScan
2009-12-12 18:11 . 2009-04-25 13:46   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\ipla
2009-12-12 18:11 . 2009-12-12 18:11   --------   d-----w-   c:\program files\PlayReady
2009-12-12 18:08 . 2009-04-25 13:46   --------   d-----w-   c:\documents and settings\Marcin\Dane aplikacji\ipla
2009-12-12 18:08 . 2009-04-25 13:46   --------   d-----w-   c:\program files\ipla
2009-12-12 11:40 . 2001-10-26 16:15   85136   ----a-w-   c:\windows\system32\perfc015.dat
2009-12-12 11:40 . 2001-10-26 16:15   493976   ----a-w-   c:\windows\system32\perfh015.dat
2009-12-12 11:29 . 2009-05-24 10:06   80240   -c--a-w-   c:\documents and settings\na chwile\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-12-12 11:29 . 2009-12-12 11:29   --------   dc----w-   c:\documents and settings\na chwile\Dane aplikacji\ipla
2009-11-28 15:54 . 2009-08-05 15:49   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\OpenFM
2009-11-21 16:26 . 2009-11-21 16:25   --------   d-----w-   c:\program files\Opera
2009-11-21 16:03 . 2002-09-20 17:03   471552   ----a-w-   c:\windows\AppPatch\aclayers.dll
2009-11-16 16:06 . 2009-11-16 16:06   56   ---ha-w-   c:\windows\system32\ezsidmv.dat
2009-11-16 15:52 . 2009-11-16 15:50   --------   d-----r-   c:\program files\Skype
2009-11-16 15:50 . 2009-11-16 15:50   --------   d-----w-   c:\program files\Common Files\Skype
2009-11-16 15:50 . 2009-11-16 15:50   --------   dc----w-   c:\documents and settings\All Users\Dane aplikacji\Skype
2009-11-10 16:13 . 2009-11-10 16:13   60416   ----a-w-   c:\windows\ALCFDRTM.EXE
2009-11-07 19:35 . 2009-08-14 19:01   25280   ----a-w-   c:\windows\system32\drivers\hamachi.sys
2009-10-29 05:26 . 2002-09-20 17:05   704000   ----a-w-   c:\windows\system32\wininet.dll
2009-10-21 05:40 . 2009-04-12 13:03   25088   ----a-w-   c:\windows\system32\httpapi.dll
2009-10-21 05:40 . 2009-04-12 13:03   75776   ----a-w-   c:\windows\system32\strmfilt.dll
2009-10-20 16:20 . 2009-04-12 12:59   265728   ------w-   c:\windows\system32\drivers\http.sys
2009-10-18 07:17 . 2009-10-18 07:17   0   ----a-w-   c:\windows\system32\cd.dat
2009-10-09 07:14 . 2009-10-09 07:10   8801704   ----a-w-   c:\program files\FLV PlayerATBSetup.exe
2009-05-01 21:02 . 2009-05-01 21:02   1044480   ----a-w-   c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02   200704   ----a-w-   c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-05-03 10:06 . 2009-05-03 11:19   163328   --sh--r-   c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2009-05-03 11:19   31232   --sh--r-   c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2009-05-03 11:19   216064   --sh--r-   c:\windows\system32\nbDX.dll
.

------- Sigcheck -------

[-] 2009-08-06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226] . . c:\windows\ServicePackFiles\i386\wuauclt.exe
[-] 2009-08-06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
[7] 2009-08-06 . 62BB79160F86CD962F312C68C6239BFD . 53472 . . [7.4.7600.226] . . c:\windows\system32\dllcache\wuauclt.exe
[-] 2002-09-20 . 2BDCBF19C5222FDA21B049D1FBAC7B36 . 142336 . . [5.4.3630.1106] . . c:\windows\$NtServicePackUninstall$\wuauclt.exe

[-] 2009-10-29 . AF365531C7434D7DC2B19721CBC40856 . 3532800 . . [6.00.2900.5897] . . c:\windows\ServicePackFiles\i386\mshtml.dll
[-] 2009-10-29 . AF365531C7434D7DC2B19721CBC40856 . 3532800 . . [6.00.2900.5897] . . c:\windows\system32\mshtml.dll
[7] 2009-10-29 . 2E6A5DFB8C17AFA768C133E07692CD0F . 3091968 . . [6.00.2900.5897] . . c:\windows\system32\dllcache\mshtml.dll
[7] 2009-10-29 . ED8E4599D07EA8BB78DF1DE2D01DFE8D . 3094016 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\mshtml.dll
[7] 2009-10-19 . 27642F792884EDAF17E20015EF8D14A0 . 3091968 . . [6.00.2900.5890] . . c:\windows\$NtUninstallKB976325$\mshtml.dll
[7] 2009-10-19 . FE866674FCCBB3C48C08D1C38A7495F3 . 3093504 . . [6.00.2900.5890] . . c:\windows\$hf_mig$\KB976749\SP3QFE\mshtml.dll
[7] 2009-09-25 . B8CD6BEC812643CEF0267A3BDE031171 . 3091968 . . [6.00.2900.5880] . . c:\windows\$NtUninstallKB976749$\mshtml.dll
[7] 2009-09-25 . 4FA7BCC0D7E9C23124741A6C084AD1F4 . 3093504 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\mshtml.dll
[7] 2009-07-18 . F7AF065A9862881D4AB4087DE280E191 . 3090432 . . [6.00.2900.5848] . . c:\windows\$NtUninstallKB974455$\mshtml.dll
[7] 2009-07-18 . ECE00769606C4E3A1162809F6561D019 . 3090944 . . [6.00.2900.5848] . . c:\windows\$hf_mig$\KB972260\SP3QFE\mshtml.dll
[7] 2008-04-14 . EBEF7EDB0DF1B4BF195FDA7CCFB7AC30 . 3066880 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB972260$\mshtml.dll
[-] 2002-09-20 . 9AB0EE83610E6E1F32592C28F394643C . 2833920 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\mshtml.dll

[-] 2009-10-29 . 229358ACC890C9898FFB8FC5089A1C06 . 704000 . . [6.00.2900.5897] . . c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2009-10-29 . 229358ACC890C9898FFB8FC5089A1C06 . 704000 . . [6.00.2900.5897] . . c:\windows\system32\wininet.dll
[7] 2009-10-29 . 95B46900474333E7029B0B2EFC2CE375 . 669696 . . [6.00.2900.5897] . . c:\windows\system32\dllcache\wininet.dll
[7] 2009-10-29 . 581984033E11303CABE8E7B86368DBDA . 671232 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\wininet.dll
[7] 2009-09-25 . 1F8828A945D7FB98AADB27D0B5B232C1 . 669696 . . [6.00.2900.5880] . . c:\windows\$NtUninstallKB976325$\wininet.dll
[7] 2009-09-25 . 35AC400C8625B4E78D129D6E2F25FDE6 . 671232 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\wininet.dll
[7] 2009-06-26 . 89BEAC1F845B315911FB8AE458164512 . 669184 . . [6.00.2900.5835] . . c:\windows\$NtUninstallKB974455$\wininet.dll
[7] 2009-06-26 . 659F7EEDDB355B1F97BD0E0435736D2B . 670720 . . [6.00.2900.5835] . . c:\windows\$hf_mig$\KB972260\SP3QFE\wininet.dll
[7] 2008-04-14 . 0457F0AFD6EE10445D8CF721FB5FA4EB . 668672 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB972260$\wininet.dll
[-] 2002-09-20 . 4965C02574610E9B2D1E18D63D11A772 . 601600 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\wininet.dll

[-] 2008-04-14 . F042E3426D45D86D9BB55F6A79AB441A . 977408 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . F042E3426D45D86D9BB55F6A79AB441A . 977408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2002-09-20 . F4AF85D918E83D71341FCE2AA5318181 . 1005568 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\explorer.exe
.
(((((((((((((((((((((((((((((   SnapShot@2010-01-13_15.44.32   )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-14 18:24 . 2010-01-14 18:24   16384              c:\windows\temp\Perflib_Perfdata_798.dat
+ 2009-10-02 19:12 . 2009-05-26 11:43   19320              c:\windows\system32\spmsg.dll
- 2009-10-02 19:12 . 2008-07-08 13:20   19320              c:\windows\system32\spmsg.dll
- 2009-03-23 14:50 . 2001-08-17 06:35   36864              c:\windows\system32\sfman32.dll
+ 2001-08-17 06:35 . 2001-08-17 06:35   36864              c:\windows\system32\sfman32.dll
+ 2010-01-14 18:12 . 2007-04-19 05:26   81920              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvwddi.dll
+ 2010-01-14 18:12 . 2007-04-19 05:26   86016              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvmctray.dll
+ 2010-01-14 18:12 . 2007-04-19 05:26   35840              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvcod.dll
+ 2010-01-14 17:42 . 2005-04-05 19:22   12928              c:\windows\system32\ReinstallBackups\0011\DriverFiles\nvnetbus.sys
+ 2010-01-14 17:42 . 2005-04-04 11:00   32256              c:\windows\system32\ReinstallBackups\0011\DriverFiles\nvconrm.dll
+ 2010-01-13 16:36 . 2008-04-13 22:15   10624              c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\gameenum.sys
+ 2010-01-13 16:35 . 2001-08-17 06:35   36864              c:\windows\system32\ReinstallBackups\0007\DriverFiles\sfman32.dll
+ 2010-01-13 16:35 . 2008-04-14 20:51   23552              c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\wdmaud.drv
+ 2010-01-13 16:35 . 2004-07-09 03:27   48512              c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\stream.sys
+ 2010-01-13 16:35 . 2008-04-13 23:15   60160              c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\drmk.sys
+ 2010-01-13 16:35 . 2003-06-16 01:35   53674              c:\windows\system32\ReinstallBackups\0007\DriverFiles\ctdaught.dat
+ 2010-01-13 16:35 . 2003-06-09 01:40   65536              c:\windows\system32\ReinstallBackups\0007\DriverFiles\a3d.dll
+ 2010-01-14 17:39 . 2008-04-14 20:03   68608              c:\windows\system32\ReinstallBackups\0004\DriverFiles\i386\pci.sys
- 2009-03-23 14:50 . 2001-06-28 03:05   36864              c:\windows\system32\REGPLIB.EXE
+ 2001-06-28 03:05 . 2001-06-28 03:05   36864              c:\windows\system32\REGPLIB.EXE
- 2007-04-19 05:26 . 2007-04-19 05:26   81920              c:\windows\system32\nvwddi.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   81920              c:\windows\system32\nvwddi.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   86016              c:\windows\system32\nvmctray.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   86016              c:\windows\system32\nvmctray.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   45056              c:\windows\system32\nvmccsrs.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   45056              c:\windows\system32\nvmccsrs.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   35840              c:\windows\system32\nvcodins.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   35840              c:\windows\system32\nvcodins.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   35840              c:\windows\system32\nvcod.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   35840              c:\windows\system32\nvcod.dll
+ 2001-09-21 09:08 . 2001-09-21 09:08   49152              c:\windows\system32\KILLAPPS.EXE
- 2009-03-23 14:50 . 2001-09-21 09:08   49152              c:\windows\system32\KILLAPPS.EXE
+ 2001-10-26 17:29 . 2009-10-15 16:33   81920              c:\windows\system32\fontsub.dll
- 2001-10-26 17:29 . 2009-07-29 04:37   81920              c:\windows\system32\fontsub.dll
- 2009-03-23 14:50 . 2002-09-16 04:38   20480              c:\windows\system32\ENSDEF.EXE
+ 2002-09-16 04:38 . 2002-09-16 04:38   20480              c:\windows\system32\ENSDEF.EXE
- 2009-03-23 14:50 . 2001-07-11 02:51   77824              c:\windows\system32\EAXAC3.DLL
+ 2001-07-11 02:51 . 2001-07-11 02:51   77824              c:\windows\system32\EAXAC3.DLL
+ 2009-03-23 14:45 . 2008-04-14 21:03   68608              c:\windows\system32\drivers\pci.sys
- 2009-03-23 14:45 . 2008-04-14 20:03   68608              c:\windows\system32\drivers\pci.sys
- 2009-03-23 14:50 . 2008-04-13 22:15   10624              c:\windows\system32\drivers\gameenum.sys
+ 2009-03-23 14:50 . 2008-04-13 23:15   10624              c:\windows\system32\drivers\gameenum.sys
+ 2009-03-23 14:45 . 2008-04-14 21:03   68608              c:\windows\system32\dllcache\pci.sys
+ 2009-03-23 14:50 . 2008-04-13 23:15   10624              c:\windows\system32\dllcache\gameenum.sys
- 2009-07-29 04:37 . 2009-07-29 04:37   81920              c:\windows\system32\dllcache\fontsub.dll
+ 2009-07-29 04:37 . 2009-10-15 16:33   81920              c:\windows\system32\dllcache\fontsub.dll
+ 2003-06-09 01:40 . 2003-06-09 01:40   65536              c:\windows\system32\dllcache\a3d.dll
- 2009-03-23 14:50 . 2003-06-09 02:07   45056              c:\windows\system32\CTSPKHLP.DLL
+ 2003-06-09 02:07 . 2003-06-09 02:07   45056              c:\windows\system32\CTSPKHLP.DLL
- 2009-03-23 14:50 . 2003-06-09 02:07   28672              c:\windows\system32\CTHELPER.EXE
+ 2003-06-09 02:07 . 2003-06-09 02:07   28672              c:\windows\system32\CTHELPER.EXE
+ 2003-06-09 01:46 . 2003-06-09 01:46   36864              c:\windows\system32\CTEMUPIA.DLL
- 2009-03-23 14:50 . 2003-06-09 01:46   36864              c:\windows\system32\CTEMUPIA.DLL
- 2009-03-23 14:50 . 2003-06-16 01:35   53674              c:\windows\system32\ctdaught.dat
+ 2003-06-16 01:35 . 2003-06-16 01:35   53674              c:\windows\system32\ctdaught.dat
+ 2003-06-09 02:07 . 2003-06-09 02:07   57344              c:\windows\system32\CTAGENT.DLL
- 2009-03-23 14:50 . 2003-06-09 02:07   57344              c:\windows\system32\CTAGENT.DLL
+ 2003-06-09 02:05 . 2003-06-09 02:05   53248              c:\windows\system32\AC3API.DLL
- 2009-03-23 14:50 . 2003-06-09 02:05   53248              c:\windows\system32\AC3API.DLL
- 2009-03-23 14:50 . 2003-06-09 01:40   65536              c:\windows\system32\a3d.dll
+ 2003-06-09 01:40 . 2003-06-09 01:40   65536              c:\windows\system32\a3d.dll
+ 2002-12-03 09:55 . 2002-12-03 09:55   49152              c:\windows\MIDIDEF.EXE
- 2009-03-23 14:50 . 2002-12-03 09:55   49152              c:\windows\MIDIDEF.EXE
- 2009-06-10 15:11 . 2009-12-14 02:12   35088              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   35088              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   18704              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   18704              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   20240              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   20240              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2003-06-09 02:07 . 2003-06-09 02:07   94208              c:\windows\DEVREG.DLL
- 2009-03-23 14:50 . 2003-06-09 02:07   94208              c:\windows\DEVREG.DLL
+ 2003-06-09 02:07 . 2003-06-09 02:07   49152              c:\windows\CTDCRES.DLL
- 2009-03-23 14:50 . 2003-06-09 02:07   49152              c:\windows\CTDCRES.DLL
+ 2010-01-14 17:42 . 2005-04-05 19:19   9728              c:\windows\system32\ReinstallBackups\0011\DriverFiles\bdco1.dll
+ 2010-01-13 16:35 . 2002-12-11 23:14   4096              c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\ksuser.dll
- 2009-03-23 14:50 . 2003-06-09 01:44   6144              c:\windows\system32\drivers\CTPRXY2K.SYS
+ 2003-06-09 01:44 . 2003-06-09 01:44   6144              c:\windows\system32\drivers\CTPRXY2K.SYS
- 2001-10-26 17:29 . 2009-07-29 04:37   119808              c:\windows\system32\t2embed.dll
+ 2001-10-26 17:29 . 2009-10-15 16:33   119808              c:\windows\system32\t2embed.dll
- 2009-03-23 14:50 . 2003-06-09 01:48   270336              c:\windows\system32\SFMS32.DLL
+ 2003-06-09 01:48 . 2003-06-09 01:48   270336              c:\windows\system32\SFMS32.DLL
+ 2010-01-14 18:12 . 2007-04-19 05:26   159810              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvsvc32.exe
+ 2010-01-14 18:12 . 2007-04-19 05:26   286720              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvnt4cpl.dll
+ 2010-01-14 18:12 . 2007-04-19 05:26   229376              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvmccs.dll
+ 2010-01-14 18:12 . 2007-04-19 05:26   581632              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvhwvid.dll
+ 2010-01-14 18:12 . 2007-04-19 05:26   212992              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvapi.dll
+ 2010-01-14 17:42 . 2005-04-05 19:22   208256              c:\windows\system32\ReinstallBackups\0011\DriverFiles\nvsnpu.sys
+ 2010-01-14 17:42 . 2005-04-05 19:22   261888              c:\windows\system32\ReinstallBackups\0011\DriverFiles\nvnrm.sys
+ 2010-01-13 16:35 . 2008-04-13 23:49   146048              c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\portcls.sys
+ 2010-01-13 16:35 . 2003-06-09 01:42   819984              c:\windows\system32\ReinstallBackups\0007\DriverFiles\ha10kx2k.sys
+ 2010-01-13 16:35 . 2003-06-16 01:40   251970              c:\windows\system32\ReinstallBackups\0007\DriverFiles\ctstatic.dat
+ 2010-01-13 16:35 . 2003-06-09 01:44   113840              c:\windows\system32\ReinstallBackups\0007\DriverFiles\ctoss2k.sys
+ 2010-01-13 16:35 . 2003-06-16 01:52   189490              c:\windows\system32\ReinstallBackups\0007\DriverFiles\ctdlang.dat
+ 2010-01-13 16:35 . 2003-06-16 01:43   114972              c:\windows\system32\ReinstallBackups\0007\DriverFiles\ctbasicw.dat
+ 2010-01-13 16:35 . 2003-06-09 01:44   494384              c:\windows\system32\ReinstallBackups\0007\DriverFiles\ctaud2k.sys
- 2009-03-23 14:50 . 2003-06-09 01:48   110592              c:\windows\system32\PIAPROXY.DLL
+ 2003-06-09 01:48 . 2003-06-09 01:48   110592              c:\windows\system32\PIAPROXY.DLL
- 2009-03-23 14:50 . 2003-06-09 01:47   159744              c:\windows\system32\OPENAL32.DLL
+ 2003-06-09 01:47 . 2003-06-09 01:47   159744              c:\windows\system32\OPENAL32.DLL
+ 2007-04-19 05:26 . 2006-10-22 04:22   167936              c:\windows\system32\nvwrszht.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   167936              c:\windows\system32\nvwrszht.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   163840              c:\windows\system32\nvwrszhc.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   163840              c:\windows\system32\nvwrszhc.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   303104              c:\windows\system32\nvwrstr.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   303104              c:\windows\system32\nvwrstr.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   294912              c:\windows\system32\nvwrssv.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   294912              c:\windows\system32\nvwrssv.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   303104              c:\windows\system32\nvwrssl.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   303104              c:\windows\system32\nvwrssl.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   299008              c:\windows\system32\nvwrssk.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   299008              c:\windows\system32\nvwrssk.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   315392              c:\windows\system32\nvwrsru.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   315392              c:\windows\system32\nvwrsru.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   319488              c:\windows\system32\nvwrsptb.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   319488              c:\windows\system32\nvwrsptb.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   323584              c:\windows\system32\nvwrspt.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   323584              c:\windows\system32\nvwrspt.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   294912              c:\windows\system32\nvwrspl.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   294912              c:\windows\system32\nvwrspl.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   299008              c:\windows\system32\nvwrsno.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   299008              c:\windows\system32\nvwrsno.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   319488              c:\windows\system32\nvwrsnl.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   319488              c:\windows\system32\nvwrsnl.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   196608              c:\windows\system32\nvwrsko.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   196608              c:\windows\system32\nvwrsko.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   212992              c:\windows\system32\nvwrsja.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   212992              c:\windows\system32\nvwrsja.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   323584              c:\windows\system32\nvwrsit.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   323584              c:\windows\system32\nvwrsit.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   315392              c:\windows\system32\nvwrshu.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   315392              c:\windows\system32\nvwrshu.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   278528              c:\windows\system32\nvwrshe.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   278528              c:\windows\system32\nvwrshe.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   327680              c:\windows\system32\nvwrsfr.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   327680              c:\windows\system32\nvwrsfr.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   303104              c:\windows\system32\nvwrsfi.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   303104              c:\windows\system32\nvwrsfi.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   327680              c:\windows\system32\nvwrsesm.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   327680              c:\windows\system32\nvwrsesm.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   335872              c:\windows\system32\nvwrses.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   335872              c:\windows\system32\nvwrses.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   286720              c:\windows\system32\nvwrseng.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   286720              c:\windows\system32\nvwrseng.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   335872              c:\windows\system32\nvwrsel.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   335872              c:\windows\system32\nvwrsel.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   311296              c:\windows\system32\nvwrsde.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   311296              c:\windows\system32\nvwrsde.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   294912              c:\windows\system32\nvwrsda.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   294912              c:\windows\system32\nvwrsda.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   286720              c:\windows\system32\nvwrscs.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   286720              c:\windows\system32\nvwrscs.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   282624              c:\windows\system32\nvwrsar.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   282624              c:\windows\system32\nvwrsar.dll
+ 2009-03-23 14:45 . 2006-10-22 14:06   208896              c:\windows\system32\nvusmb.exe
+ 2009-03-23 14:45 . 2006-10-22 14:06   208896              c:\windows\system32\nvunrm.exe
+ 2009-03-23 14:45 . 2006-10-22 14:06   208896              c:\windows\system32\NVUNINST.EXE
- 2007-04-19 05:26 . 2007-04-19 05:26   159810              c:\windows\system32\nvsvc32.exe
+ 2007-04-19 05:26 . 2006-10-22 04:22   159810              c:\windows\system32\nvsvc32.exe
+ 2007-04-19 05:26 . 2006-10-22 04:22   466944              c:\windows\system32\nvshell.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   466944              c:\windows\system32\nvshell.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   118784              c:\windows\system32\nvrszht.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   118784              c:\windows\system32\nvrszht.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   221184              c:\windows\system32\nvrszhc.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   221184              c:\windows\system32\nvrszhc.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   249856              c:\windows\system32\nvrstr.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   249856              c:\windows\system32\nvrstr.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   245760              c:\windows\system32\nvrssv.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   245760              c:\windows\system32\nvrssv.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   249856              c:\windows\system32\nvrssl.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   249856              c:\windows\system32\nvrssl.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   249856              c:\windows\system32\nvrssk.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   249856              c:\windows\system32\nvrssk.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   262144              c:\windows\system32\nvrsru.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   262144              c:\windows\system32\nvrsru.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   262144              c:\windows\system32\nvrsptb.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   262144              c:\windows\system32\nvrsptb.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   266240              c:\windows\system32\nvrspt.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   266240              c:\windows\system32\nvrspt.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   249856              c:\windows\system32\nvrspl.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   249856              c:\windows\system32\nvrspl.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   249856              c:\windows\system32\nvrsno.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   249856              c:\windows\system32\nvrsno.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   266240              c:\windows\system32\nvrsnl.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   266240              c:\windows\system32\nvrsnl.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   258048              c:\windows\system32\nvrsko.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   258048              c:\windows\system32\nvrsko.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   262144              c:\windows\system32\nvrsja.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   262144              c:\windows\system32\nvrsja.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   274432              c:\windows\system32\nvrsit.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   274432              c:\windows\system32\nvrsit.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   253952              c:\windows\system32\nvrshu.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   253952              c:\windows\system32\nvrshu.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   323584              c:\windows\system32\nvrshe.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   323584              c:\windows\system32\nvrshe.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   278528              c:\windows\system32\nvrsfr.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   278528              c:\windows\system32\nvrsfr.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   241664              c:\windows\system32\nvrsfi.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   241664              c:\windows\system32\nvrsfi.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   266240              c:\windows\system32\nvrsesm.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   266240              c:\windows\system32\nvrsesm.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   274432              c:\windows\system32\nvrses.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   274432              c:\windows\system32\nvrses.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   241664              c:\windows\system32\nvrseng.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   241664              c:\windows\system32\nvrseng.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   274432              c:\windows\system32\nvrsel.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   274432              c:\windows\system32\nvrsel.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   270336              c:\windows\system32\nvrsde.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   270336              c:\windows\system32\nvrsde.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   245760              c:\windows\system32\nvrsda.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   245760              c:\windows\system32\nvrsda.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   241664              c:\windows\system32\nvrscs.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   241664              c:\windows\system32\nvrscs.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   323584              c:\windows\system32\nvrsar.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   323584              c:\windows\system32\nvrsar.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   286720              c:\windows\system32\nvnt4cpl.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   286720              c:\windows\system32\nvnt4cpl.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   888832              c:\windows\system32\nvmobls.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   458752              c:\windows\system32\nvmccssr.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   188416              c:\windows\system32\nvmccss.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   229376              c:\windows\system32\nvmccs.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   229376              c:\windows\system32\nvmccs.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   581632              c:\windows\system32\nvhwvid.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   581632              c:\windows\system32\nvhwvid.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   311296              c:\windows\system32\nvexpbar.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   794624              c:\windows\system32\nvcplui.exe
+ 2007-04-19 05:26 . 2006-10-22 04:22   147456              c:\windows\system32\nvcolor.exe
- 2007-04-19 05:26 . 2007-04-19 05:26   147456              c:\windows\system32\nvcolor.exe
- 2007-04-19 05:26 . 2007-04-19 05:26   442368              c:\windows\system32\nvappbar.exe
+ 2007-04-19 05:26 . 2006-10-22 04:22   442368              c:\windows\system32\nvappbar.exe
- 2007-04-19 05:26 . 2007-04-19 05:26   212992              c:\windows\system32\nvapi.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   212992              c:\windows\system32\nvapi.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   425984              c:\windows\system32\keystone.exe
- 2007-04-19 05:26 . 2007-04-19 05:26   425984              c:\windows\system32\keystone.exe
+ 2003-06-09 01:42 . 2003-06-09 01:42   135696              c:\windows\system32\drivers\HAP16V2K.SYS
- 2009-03-23 14:50 . 2003-06-09 01:42   135696              c:\windows\system32\drivers\HAP16V2K.SYS
+ 2003-06-09 01:42 . 2003-06-09 01:42   819984              c:\windows\system32\drivers\ha10kx2k.sys
- 2009-03-23 14:50 . 2003-06-09 01:42   819984              c:\windows\system32\drivers\ha10kx2k.sys
+ 2003-06-09 01:45 . 2003-06-09 01:45   116416              c:\windows\system32\drivers\EMUPIA2K.SYS
- 2009-03-23 14:50 . 2003-06-09 01:45   116416              c:\windows\system32\drivers\EMUPIA2K.SYS
+ 2003-06-09 01:44 . 2003-06-09 01:44   136448              c:\windows\system32\drivers\CTSFM2K.SYS
- 2009-03-23 14:50 . 2003-06-09 01:44   136448              c:\windows\system32\drivers\CTSFM2K.SYS
- 2009-03-23 14:50 . 2003-06-09 01:44   113840              c:\windows\system32\drivers\ctoss2k.sys
+ 2003-06-09 01:44 . 2003-06-09 01:44   113840              c:\windows\system32\drivers\ctoss2k.sys
+ 2003-06-09 01:44 . 2003-06-09 01:44   494384              c:\windows\system32\drivers\ctaud2k.sys
- 2009-03-23 14:50 . 2003-06-09 01:44   494384              c:\windows\system32\drivers\ctaud2k.sys
+ 2003-06-09 01:42 . 2003-06-09 01:42   186068              c:\windows\system32\drivers\CTAC32K.SYS
- 2009-03-23 14:50 . 2003-06-09 01:42   186068              c:\windows\system32\drivers\CTAC32K.SYS
+ 2009-07-29 04:37 . 2009-10-15 16:33   119808              c:\windows\system32\dllcache\t2embed.dll
- 2009-07-29 04:37 . 2009-07-29 04:37   119808              c:\windows\system32\dllcache\t2embed.dll
+ 2003-06-16 01:40 . 2003-06-16 01:40   251970              c:\windows\system32\ctstatic.dat
- 2009-03-23 14:50 . 2003-06-16 01:40   251970              c:\windows\system32\ctstatic.dat
+ 2003-06-09 02:06 . 2003-06-09 02:06   110592              c:\windows\system32\CTSCAL.DLL
- 2009-03-23 14:50 . 2003-06-09 02:06   110592              c:\windows\system32\CTSCAL.DLL
- 2009-03-23 14:50 . 2003-06-09 01:47   655360              c:\windows\system32\CTSBLFX.DLL
+ 2003-06-09 01:47 . 2003-06-09 01:47   655360              c:\windows\system32\CTSBLFX.DLL
- 2009-03-23 14:50 . 2003-06-09 01:47   155648              c:\windows\system32\CTOSUSER.DLL
+ 2003-06-09 01:47 . 2003-06-09 01:47   155648              c:\windows\system32\CTOSUSER.DLL
- 2009-03-23 14:50 . 2003-06-09 01:47   110592              c:\windows\system32\CTDPROXY.DLL
+ 2003-06-09 01:47 . 2003-06-09 01:47   110592              c:\windows\system32\CTDPROXY.DLL
- 2009-03-23 14:50 . 2003-06-16 01:52   189490              c:\windows\system32\ctdlang.dat
+ 2003-06-16 01:52 . 2003-06-16 01:52   189490              c:\windows\system32\ctdlang.dat
+ 2003-06-09 02:06 . 2003-06-09 02:06   139264              c:\windows\system32\CTDCIFCE.DLL
- 2009-03-23 14:50 . 2003-06-09 02:06   139264              c:\windows\system32\CTDCIFCE.DLL
+ 2003-06-09 02:06 . 2003-06-09 02:06   372736              c:\windows\system32\CTDC0001.DLL
- 2009-03-23 14:50 . 2003-06-09 02:06   372736              c:\windows\system32\CTDC0001.DLL
+ 2003-06-09 02:06 . 2003-06-09 02:06   323584              c:\windows\system32\CTDC0000.DLL
- 2009-03-23 14:50 . 2003-06-09 02:06   323584              c:\windows\system32\CTDC0000.DLL
- 2009-03-23 14:50 . 2003-06-16 01:43   114972              c:\windows\system32\ctbasicw.dat
+ 2003-06-16 01:43 . 2003-06-16 01:43   114972              c:\windows\system32\ctbasicw.dat
- 2009-03-23 14:50 . 2003-06-16 01:52   142968              c:\windows\system32\CTBAS2W.DAT
+ 2003-06-16 01:52 . 2003-06-16 01:52   142968              c:\windows\system32\CTBAS2W.DAT
- 2009-03-23 14:50 . 2003-06-09 01:45   495616              c:\windows\system32\CTAUDFX.DLL
+ 2003-06-09 01:45 . 2003-06-09 01:45   495616              c:\windows\system32\CTAUDFX.DLL
- 2009-03-23 14:50 . 2003-06-09 01:47   106496              c:\windows\system32\CTASIO.DLL
+ 2003-06-09 01:47 . 2003-06-09 01:47   106496              c:\windows\system32\CTASIO.DLL
+ 2003-06-09 01:45 . 2003-06-09 01:45   126976              c:\windows\system32\COMMONFX.DLL
- 2009-03-23 14:50 . 2003-06-09 01:45   126976              c:\windows\system32\COMMONFX.DLL
- 2009-03-23 14:50 . 2003-06-09 02:07   180224              c:\windows\READREG.EXE
+ 2003-06-09 02:07 . 2003-06-09 02:07   180224              c:\windows\READREG.EXE
+ 2003-06-09 02:07 . 2003-06-09 02:07   184320              c:\windows\PSCONV.EXE
- 2009-03-23 14:50 . 2003-06-09 02:07   184320              c:\windows\PSCONV.EXE
+ 2009-06-10 15:11 . 2010-01-14 02:01   888080              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   888080              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   272648              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   272648              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   922384              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   922384              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   845584              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   845584              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   217864              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   217864              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   184080              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   184080              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   159504              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   159504              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2010-01-14 18:12 . 2007-04-19 05:26   5644288              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvoglnt.dll
+ 2010-01-14 18:12 . 2007-04-19 05:26   7700480              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nvcpl.dll
+ 2010-01-14 18:12 . 2007-04-19 05:26   3988384              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nv4_mini.sys
+ 2010-01-14 18:12 . 2007-04-19 05:26   4543616              c:\windows\system32\ReinstallBackups\0012\DriverFiles\nv4_disp.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   1622016              c:\windows\system32\nwiz.exe
+ 2006-10-22 04:22 . 2006-10-22 04:22   1732608              c:\windows\system32\nvwssr.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   1236992              c:\windows\system32\nvwss.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   1019904              c:\windows\system32\nvwimg.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   1019904              c:\windows\system32\nvwimg.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   1662976              c:\windows\system32\nvwdmcpl.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   2973696              c:\windows\system32\nvvitvsr.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   2924544              c:\windows\system32\nvvitvs.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   5644288              c:\windows\system32\nvoglnt.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   5644288              c:\windows\system32\nvoglnt.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   2859008              c:\windows\system32\nvmoblsr.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   1470464              c:\windows\system32\nview.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   3203072              c:\windows\system32\nvgamesr.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   3047424              c:\windows\system32\nvgames.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   1339392              c:\windows\system32\nvdspsch.exe
+ 2007-04-19 05:26 . 2006-10-22 04:22   1339392              c:\windows\system32\nvdspsch.exe
+ 2006-10-22 04:22 . 2006-10-22 04:22   5255168              c:\windows\system32\nvdispsr.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   5619712              c:\windows\system32\nvdisps.dll
+ 2006-10-22 04:22 . 2006-10-22 04:22   1011712              c:\windows\system32\nvcpluir.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   7700480              c:\windows\system32\nvcpl.dll
- 2007-04-19 05:26 . 2007-04-19 05:26   7700480              c:\windows\system32\nvcpl.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   4527488              c:\windows\system32\nv4_disp.dll
+ 2007-04-19 05:26 . 2006-10-22 04:22   3994624              c:\windows\system32\drivers\nv4_mini.sys
+ 2007-04-19 05:26 . 2006-10-22 04:22   3994624              c:\windows\system32\dllcache\nv4_mini.sys
+ 2009-12-03 13:15 . 2009-12-03 13:15   5004288              c:\windows\Installer\203c8be.msp
- 2009-06-10 15:11 . 2009-12-14 02:12   1172240              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   1172240              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-06-10 15:11 . 2009-12-14 02:12   1165584              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-06-10 15:11 . 2010-01-14 02:01   1165584              c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
.
-- Migawka wyzerowana --
.
(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane 
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{14f0d511-36a2-41ca-ae01-ba4f87282c97}"= "c:\program files\SHOUTcast Radio Toolbar\shoutcasttb.dll" [2008-09-17 1275176]

[HKEY_CLASSES_ROOT\clsid\{14f0d511-36a2-41ca-ae01-ba4f87282c97}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{8613efdf-b530-4b1d-b970-b09f99977813}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-08-27 16:48   218160   ----a-w-   c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nowe Gadu-Gadu"="c:\program files\Nowe Gadu-Gadu\gg.exe" [2010-01-08 11391592]
"ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2009-06-04 869888]
"DAEMON Tools Lite"="c:\program files\daemon tools lite\daemon.exe" [2010-01-08 11391592]
"nodenable"="c:\program files\eset\nodenable.exe" [2010-01-08 11391592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"CTHelper"="CTHELPER.EXE" [2003-06-09 28672]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SIAPRO7"="c:\program files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" [2005-07-20 274432]

c:\documents and settings\Marcin\Menu Start\Programy\Autostart\
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2009-11-7 625952]

c:\documents and settings\All Users\Menu Start\Programy\Autostart\
AirLive 802.11G Wireless Utility.lnk - c:\program files\OVISLINK\Common\AirliveUI.exe [2009-3-23 1290240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiscSpaceChecks"= 000000000000f03f

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Marcin^Menu Start^Programy^Autostart^Microsoft Office Groove.lnk]
path=c:\documents and settings\Marcin\Menu Start\Programy\Autostart\Microsoft Office Groove.lnk
backup=c:\windows\pss\Microsoft Office Groove.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Marcin^Menu Start^Programy^Autostart^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk]
path=c:\documents and settings\Marcin\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
backup=c:\windows\pss\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2005-12-16 10:57   94208   ----a-w-   c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
2003-06-09 02:07   28672   ----a-w-   c:\windows\system32\CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-01-08 15:48   11391592   ----a-w-   c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
2005-03-31 07:30   1106944   ----a-w-   c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
2004-02-04 14:33   294912   ----a-w-   c:\program files\Lexmark Fax Solutions\fm3032.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2007-08-24 05:00   33648   ----a-w-   c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPLA!]
2009-12-12 13:48   14100376   ----a-w-   c:\program files\ipla\ipla.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-07-13 12:03   292128   ----a-w-   d:\itunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
2001-11-29 00:00   28672   ----a-w-   c:\program files\Creative\SBLive\Program\ADGJDet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 2200 Series]
2004-02-13 13:34   57344   ----a-w-   c:\program files\Lexmark 2200 Series\lxbvbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 08:50   155648   ----a-w-   c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 04:22   7700480   ----a-w-   c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 04:22   86016   ----a-w-   c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 04:22   1622016   ----a-w-   c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
2005-03-22 07:39   167936   ----a-w-   d:\nokia pc suite 6\LaunchApplication.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
2005-04-20 07:57   847872   ----a-w-   d:\nokia pc suite 6\PcSync2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18   413696   ----a-w-   c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIAPRO7]
2005-07-20 12:05   274432   ----a-w-   c:\program files\Steganos Internet Anonym Pro 7\SIAPRO7.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-04-04 20:58   148888   ----a-w-   c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
2009-04-29 16:19   1053576   ----a-w-   c:\program files\Trojan Remover\Trjscan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-02-25 21:26   37888   ----a-w-   c:\program files\Winamp\winampa.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"d:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\BitComet\\BitComet.exe"=
"d:\\Counter-Strike 1.6\\hl.exe"=
"d:\\Counter-Strike 1.6\\hlds.exe"=
"c:\\Program Files\\SHOUTcast\\sc_serv.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"d:\\itunes\\iTunes.exe"=
"c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"d:\\SopCast\\adv\\SopAdver.exe"=
"d:\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\Program Files\\FOX\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8461:TCP"= 8461:TCP:*:Disabled:GoD High Port
"8462:TCP"= 8462:TCP:*:Disabled:GoD Low Port
"22602:TCP"= 22602:TCP:BitComet 22602 TCP
"22602:UDP"= 22602:UDP:BitComet 22602 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\drivers\tffsport.sys [2009-03-29 149376]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-02-06 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-02-06 93336]
R1 SysTool;SysTool Overclocking Utility;c:\windows\system32\drivers\SysTool.sys [2006-11-10 24064]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-04-15 717296]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance [?]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance [?]
S3 mdxgthkn;mdxgthkn;\??\c:\docume~1\Marcin\USTAWI~1\Temp\mdxgthkn.sys --> c:\docume~1\Marcin\USTAWI~1\Temp\mdxgthkn.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
Zawartość folderu 'Zaplanowane zadania'

2010-01-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://google.atcomet.com/b/
uInternet Settings,ProxyServer = http=
uInternet Settings,ProxyOverride = *.local
IE: &SHOUTcast Search - c:\documents and settings\All Users\Dane aplikacji\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Pobierz wszystkie VIdeo za pomocą BitComet - d:\bitcomet\BitComet.exe/AddVideo.htm
IE: Pobierz wszystko za pomocą BitComet - d:\bitcomet\BitComet.exe/AddAllLink.htm
IE: Pobierz za pomocą BitComet - d:\bitcomet\BitComet.exe/AddLink.htm
LSP: c:\program files\Secure Surfing Engine\sselsp.dll
TCP: {175D818A-1397-4B80-8551-57FB83BC22D0} = 194.204.152.34,194.204.159.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Marcin\Dane aplikacji\Mozilla\Firefox\Profiles\qw7i44od.default\
FF - component: c:\documents and settings\Marcin\Dane aplikacji\Mozilla\Firefox\Profiles\qw7i44od.default\extensions\{a3b7b698-c13e-4f08-8c43-4ae1cfe8f6e8}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Marcin\Dane aplikacji\Mozilla\Firefox\Profiles\qw7i44od.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll
FF - plugin: c:\documents and settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\nppl3260.dll
FF - plugin: c:\documents and settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin9.dll
FF - plugin: c:\program files\Opera\program\plugins\nppdf32.dll
FF - plugin: c:\program files\Opera\program\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Opera\program\plugins\npqtplugin9.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin9.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - USUNIĘTO PUSTE WPISY - - - -

HKCU-Run-UberIcon - c:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager .exe
MSConfigStartUp-Prec - d:\prec\PrecStarter.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-14 20:00
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ... 

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ... 

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------

[HKEY_USERS\S-1-5-21-1659004503-179605362-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1659004503-179605362-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D6C33E2A-8CD9-F347-F73F-23696A1F7B76}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaapmefhllbnojjelm"=hex:6b,61,6a,6a,68,6b,65,6b,70,63,63,6b,62,65,63,6d,69,6c,
   6c,62,66,6e,00,00
"hagpchodlgoeagnb"=hex:69,61,62,6b,69,61,70,68,67,64,6d,61,6b,64,64,63,70,6b,
   00,00
"iampefcfehpdaefbee"=hex:63,61,6d,6a,66,6c,00,7c

[HKEY_USERS\S-1-5-21-1659004503-179605362-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F94FC1DC-F69D-C919-D553-F066DDBB7738}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------

- - - - - - - > 'lsass.exe'(192)
c:\windows\system32\scecli.dll
c:\program files\Secure Surfing Engine\sselsp.dll
.
Czas ukończenia: 2010-01-14  20:02:37
ComboFix-quarantined-files.txt  2010-01-14 19:02
ComboFix2.txt  2010-01-13 15:50

Przed: 5 015 257 088 bajtów wolnych
Po: 4 933 545 984 bajtów wolnych

- - End Of File - - A367337A2D4999E021BD945AD01E7B27
Awatar użytkownika
marcinbak10
~user
 
Posty: 62
Dołączenie: 18 Mar 2009, 21:38
Miejscowość: włoszczowa



Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Postprzez wojtas 14 Sty 2010, 22:25

zrób skan Malwarebytes Anti-Malware (zaktualizuj, usuń co znajdzie ) i daj raport ze skanu oraz raport z Weba
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Postprzez marcinbak10 15 Sty 2010, 19:14

OTO LOG Z MALWERBYTES A WEBEM NIE MOGE PRZESKANOWAC BO MI BLUSCREN WYWALA I DZWIEK POMIMO ZE PRZEINSTALOWALEM STERY

Kod: Zaznacz wszystko
Malwarebytes' Anti-Malware 1.44
Wersja bazy definicji: 3569
Windows 5.1.2600 Dodatek Service Pack 3
Internet Explorer 6.0.2900.5512

2010-01-15 18:11:49
mbam-log-2010-01-15 (18-11-49).txt

Typ skanowania: Pełne skanowanie (C:\|D:\|E:\|F:\|G:\|)
Przeskanowane obiekty: 292211
Upłynęło: 1 hour(s), 3 minute(s), 46 second(s)

Zainfekowane procesy w pamięci: 0
Zainfekowane moduły pamięci: 0
Zainfekowane klucze rejestru: 21
Zainfekowane wartości rejestru: 0
Zainfekowane pliki rejestru: 0
Zainfekowane foldery: 0
Zainfekowane pliki: 10

Zainfekowane procesy w pamięci:
(Nie wykryto groźnych plików)

Zainfekowane moduły pamięci:
(Nie wykryto groźnych plików)

Zainfekowane klucze rejestru:
HKEY_CLASSES_ROOT\gnucdna.core (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{2850bdc7-2330-4e31-9fa0-88268846539a} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0be385a3-85a5-4722-b677-68dae891ff21} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{272c0d60-0561-4c83-b3db-eb0a71f9d2eb} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{284477e4-a7cb-4055-9e1b-0ea7cba28945} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{70ca4938-6a0f-4641-a9a9-c936e4c1e7de} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7468213e-010e-4ec6-a17d-642e909ba7ec} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{89dc33a2-f86f-42a1-8b5f-d4d1943efc9c} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a916af3c-976d-4358-8736-95bea0b5fd2c} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b86f4810-19a9-4050-9ac9-b5cf60b5799a} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bb5b7e14-f8b4-4365-a24d-f4965c33e1ee} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{be45f056-e005-437b-be88-23acf70b0b6a} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c13d4627-02f5-4b03-897a-bf6a90022dd2} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c636f1fc-6ae4-4e6a-90ab-6d61d821a0dd} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cb971ac0-6408-40da-a540-92f9f256f51f} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d5694dfe-43b6-4e05-aa29-8c556c968973} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e2032ec2-a9ac-4ed7-9bdb-ebecacf076f2} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{ebab4a71-8c34-461a-b57d-dd041d439555} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f06fea43-0cc3-4bf6-a85b-5efb1c07aa4b} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fc94a0f7-9c7c-4ae2-9106-5c212332b209} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f02c0ae1-d796-42c9-81e1-084d88f79b8e} (Adware.WhenU) -> Quarantined and deleted successfully.

Zainfekowane wartości rejestru:
(Nie wykryto groźnych plików)

Zainfekowane pliki rejestru:
(Nie wykryto groźnych plików)

Zainfekowane foldery:
(Nie wykryto groźnych plików)

Zainfekowane pliki:
C:\WINDOWS\system32\GnucDNA.dll (Adware.WhenU) -> Quarantined and deleted successfully.
C:\ComboFix\Combo-Fix.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\ALLPlayer\allupdate .exe.vir (Malware.Trace) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\DAEMON Tools Lite\daemon .exe.vir (Malware.Trace) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\ESET\nodenable .exe.vir (Malware.Trace) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\Messenger\msmsgs .exe.vir (Malware.Trace) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\Nowe Gadu-Gadu\gg .exe.vir (Malware.Trace) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlservice.exe.vir (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\RocketDock\rocketdock .exe.vir (Malware.Trace) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\Skype\Phone\skype .exe.vir (Malware.Trace) -> Quarantined and deleted successfully.
Awatar użytkownika
marcinbak10
~user
 
Posty: 62
Dołączenie: 18 Mar 2009, 21:38
Miejscowość: włoszczowa



Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Postprzez wojtas 15 Sty 2010, 19:29

system jest już czysty
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Zawiesza sie i wylapoje wirusy w plikach np gg czy skype

Postprzez marcinbak10 15 Sty 2010, 19:32

DZIĘKI ZA POMOC KOLEJNY RAZ :))))) JESTEŚCIE SUPER :)))))))
Awatar użytkownika
marcinbak10
~user
 
Posty: 62
Dołączenie: 18 Mar 2009, 21:38
Miejscowość: włoszczowa




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 14 gości