
- Kod: Zaznacz wszystko
- Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\LEXBCES.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\LEXPPS.EXE
 C:\Program Files\Keymaestro\Multimedia Keyboard\nhksrv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
 C:\WINDOWS\System32\winldra.exe
 C:\Program Files\Tlen.pl\tlen.exe
 C:\Program Files\Neostrada TP\NeostradaTP.exe
 C:\Program Files\Neostrada TP\ComComp.exe
 C:\Program Files\Neostrada TP\Watch.exe
 C:\Program Files\Winamp\Winamp.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Documents and Settings\Prezes\Pulpit\hijackthis\HijackThis.exe
 R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchforfree.info/browser/
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://szukaj.wp.pl
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchforfree.info/browser/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://searchforfree.info/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchforfree.info/browser/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchforfree.info/browser/
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchforfree.info/
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchforfree.info/browser/
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://searchforfree.info/browser/
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 F3 - REG:win.ini: run=C:\WINDOWS\htmlsync.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
 O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
 O4 - HKLM\..\Run: [icasServ] C:\WINDOWS\System32\icasServ.exe
 O4 - HKLM\..\Run: [load32] C:\WINDOWS\System32\winldra.exe
 O4 - HKLM\..\Run: [isystem] C:\WINDOWS\System32\isystem.exe
 O4 - HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe
 O4 - HKCU\..\Run: [ldriver] C:\WINDOWS\System32\ldriver.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{4B0E7EA7-D885-4E98-BEFD-564F7461CEEF}: NameServer = 194.204.152.34 217.98.63.164
 O21 - SSODL: buWYCVU - {B0AE02F5-1A04-A85F-E352-56FAA1ED044C} - C:\WINDOWS\System32\zahq.dll
 O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
 O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Keymaestro\Multimedia Keyboard\nhksrv.exe
 O23 - Service: Tenebril antispyware satellite (TNBRLDS) - Unknown owner - C:\Program Files\GhostSurf 2005\DeleteSvc.exe (file missing)
Autor postu otrzymał pochwałę

 
	
