Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3900: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3902: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3903: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3904: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
peosze o sprawdzenie loga • programosy.pl

  • Ogłoszenie:

peosze o sprawdzenie loga

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

peosze o sprawdzenie loga

Postprzez kybula 08 Kwi 2007, 16:55

reklama
chcialem pobrac gre przez p2p i pobralem plik 758kb-nie mega, w ktorym znajdowal sie dziwny plik. za chwilke zaczely sieotwierac strony w IE, pozniej komp wariowal tak ogolnie.

oto moj log z silent runne
Kod: Zaznacz wszystko
"Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\
"{5830E138-0BB2-1045-0201-050403250030}" = ""C:\Program Files\Common Files\{5830E138-0BB2-1045-0201-050403250030}\Update.exe" mc-110-12-0000137" [null data]

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [file not found]
"Steam" = ""C:\Program Files\Valve\Steam\Steam.exe" -silent" ["Valve Corporation"]
"Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]
"DeluxeCommunications" = "C:\Program Files\DeluxeCommunications\Dxc.exe" [null data]
"IpWins" = "C:\Program Files\Ipwindows\ipwins.exe" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"lxcgmon.exe" = ""C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"" ["Lexmark International, Inc."]
"EzPrint" = ""C:\Program Files\Lexmark 2300 Series\ezprint.exe"" ["Lexmark International Inc."]
"DAEMON Tools" = ""C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033" ["DT Soft Ltd."]
"WinampAgent" = "C:\Program Files\Winamp\winampa.exe" [null data]
"ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
"Windows Defender" = ""C:\Program Files\Windows Defender\MSASCui.exe" -hide" [MS]
"DeluxeCommunications" = "C:\Program Files\DeluxeCommunications\Dxc.exe" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "AcroIEHlprObj Class"
                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{10234DDB-DA1F-4F21-AAA4-5E396EA37C8F}\(Default) = (no title provided)
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\Program Files\Messenger\mesodiqux.dll" [file not found]
{37B85A21-692B-4205-9CAD-2626E4993404}\(Default) = "My Global Search Bar BHO"
  -> {HKLM...CLSID} = "My Global Search Bar BHO"
                   \InProcServer32\(Default) = "C:\Program Files\MyGlobalSearch\bar\2.bin\MGSBAR.DLL" ["My Global Search"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
{C318CD44-E327-4377-A28E-6EC16A921AE8}\(Default) = "Plugin"
  -> {HKLM...CLSID} = "WebBuying Assistant"
                   \InProcServer32\(Default) = "C:\Program Files\Web Buying\v1.6.8\webbuying.dll" [file not found]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
  -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
  -> {HKLM...CLSID} = "AlcoholShellEx"
                   \InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AxShlex.dll" ["Alcohol Soft Development Team"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" = "Microsoft AntiMalware ShellExecuteHook"
  -> {HKLM...CLSID} = "Microsoft AntiMalware ShellExecuteHook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\WIFD1F~1\MpShHook.dll" [MS]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
<<!>> "AppInit_DLLs" = "dxclib303562752.dll" [null data]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
"System" = (value not set)

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\mateusz cybulski\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\POLKOM~4.SCR" (PolKompWio.scr) [null data]


Startup items in "mateusz cybulski" & "All Users" startup folders:
------------------------------------------------------------------

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
"Adobe Gamma Loader.exe" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
"InterVideo WinCinema Manager" -> shortcut to: "C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe" ["InterVideo Inc."]
<<!>> "taskmgr.exe" ["Windows Installer"]


Enabled Scheduled Tasks:
------------------------

"MP Scheduled Scan" -> launches: "C:\Program Files\Windows Defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{37B85A29-692B-4205-9CAD-2626E4993404}"
  -> {HKLM...CLSID} = "My Global Search Bar"
                   \InProcServer32\(Default) = "C:\Program Files\MyGlobalSearch\bar\2.bin\MGSBAR.DLL" ["My Global Search"]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}"
  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_01"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll" ["Sun Microsystems, Inc."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [file not found]


Miscellaneous IE Hijack Points
------------------------------

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=www.actina.pl

Missing lines (compared with English-language version):
[Strings]: 1 line

HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
<<H>> "{A8BD6820-6ED7-423E-9558-2D1486B0FEEA}" = "*n" (unwritable string)
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\Program Files\DeluxeCommunications\DxcBho.dll" [null data]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
Client IP-IPX, Client IP-IPX, ""C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137" [null data]
CPUCooLServer Service, CPUCooLServer, ""C:\Program Files\CPUCooL\CooLSrv.exe"" [null data]
lxcg_device, lxcg_device, "C:\WINDOWS\system32\lxcgcoms.exe -service" [" "]
StarWind iSCSI Service, StarWindService, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" ["Rocket Division Software"]
Windows Defender, WinDefend, ""C:\Program Files\Windows Defender\MsMpEng.exe"" [MS]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
2300 Series Port\Driver = "lxcglmpm.DLL" [" "]


----------
<<!>>: Suspicious data at a malware launch point.
<<H>>: Suspicious data at a browser hijack point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
  DLL launch points, use the -supp parameter or answer "No" at the
  first message box and "Yes" at the second message box.
---------- (total run time: 46 seconds, including 14 seconds for message boxes)


z góry Dzieki za pomoc.
NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA



Postprzez wojtas 08 Kwi 2007, 17:09

podrzuc loga z Hijack This
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez kybula 08 Kwi 2007, 19:40

ok jasne

Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 19:27:10, on 2007-04-08
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchosts.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\CPUCooL\CooLSrv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\{5830E138-0BB2-1045-0201-050403250030}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mateusz cybulski\Pulpit\hijackthis\HijackThis.exe
C:\DOCUME~1\MATEUS~1\USTAWI~1\Temp\b122.exe
C:\Program Files\Ipwindows\ipwins.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {10234DDB-DA1F-4F21-AAA4-5E396EA37C8F} - C:\Program Files\Messenger\mesodiqux.dll (file missing)
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\2.bin\MGSBAR.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Plugin - {C318CD44-E327-4377-A28E-6EC16A921AE8} - C:\Program Files\Web Buying\v1.6.8\webbuying.dll (file missing)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: taskmgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=www.actina.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O20 - AppInit_DLLs: dxclib303562752.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137 (file missing)
O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Program Files\CPUCooL\CooLSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: lxcg_device -   - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA



Postprzez wojtas 08 Kwi 2007, 19:47

Wyłącz przywracanie systemu ( właściwości mój komputer-zakładka przywracanie - wyłącz przywracanie na wszystkich dyskach)
Start do awaryjnego ( F8 ) przy starcie komputera.

Ściągnij program http://downloads.subratam.org/Fixwareout.exe i zastosuj go.

Start -> uruchom -> services.msc -> zatrzymaj i wyłącz usługe Client IP-IPX

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {10234DDB-DA1F-4F21-AAA4-5E396EA37C8F} - C:\Program Files\Messenger\mesodiqux.dll (file missing)
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\2.bin\MGSBAR.DLL
O2 - BHO: Plugin - {C318CD44-E327-4377-A28E-6EC16A921AE8} - C:\Program Files\Web Buying\v1.6.8\webbuying.dll (file missing)
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - Global Startup: taskmgr.exe << PLIK bedzie w C:\Documents and Settings\mateusz cybulski\menu start\programy\autostart
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O20 - AppInit_DLLs: dxclib303562752.dll
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137 (file missing)


Odpalasz hijackthis i zaznaczasz ptaszkami powyższe wpisy i dajesz Fix checked.
Pogrubione pliki usuwasz ręcznie z dysku
potem nowe logi z Hijack This oraz Silent runners
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez kybula 08 Kwi 2007, 22:55

mam taki problem...nie mam folderu system32... szukalem wczesniej na rozne sposoby ale nic!!!

log z fixwareout

Kod: Zaznacz wszystko

Fixwareout Last edited 4/5/2007
Post this report in the forums please
...
»»»»»Prerun check

»»»»» System restarted

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
»»»»» Misc files.
....
»»»»» Checking for older varients.
....

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other



»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"lxcgmon.exe"="\"C:\\Program Files\\Lexmark 2300 Series\\lxcgmon.exe\""
"EzPrint"="\"C:\\Program Files\\Lexmark 2300 Series\\ezprint.exe\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Steam"="\"C:\\Program Files\\Valve\\Steam\\Steam.exe\" -silent"
"Gadu-Gadu"="\"C:\\Program Files\\Gadu-Gadu\\gg.exe\" /tray"
"DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"
"IpWins"="C:\\Program Files\\Ipwindows\\ipwins.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»



z hijackthis

Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 22:42:26, on 2007-04-08
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CPUCooL\CooLSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\{5830E138-0BB2-1045-0201-050403250030}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mateusz cybulski\Pulpit\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=www.actina.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Program Files\CPUCooL\CooLSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: lxcg_device -   - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe




i runner

Kod: Zaznacz wszystko
"Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\
"{5830E138-0BB2-1045-0201-050403250030}" = ""C:\Program Files\Common Files\{5830E138-0BB2-1045-0201-050403250030}\Update.exe" mc-110-12-0000137" [null data]

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [file not found]
"Steam" = ""C:\Program Files\Valve\Steam\Steam.exe" -silent" ["Valve Corporation"]
"Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]
"DeluxeCommunications" = "C:\Program Files\DeluxeCommunications\Dxc.exe" [file not found]
"IpWins" = "C:\Program Files\Ipwindows\ipwins.exe" [file not found]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"lxcgmon.exe" = ""C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"" ["Lexmark International, Inc."]
"EzPrint" = ""C:\Program Files\Lexmark 2300 Series\ezprint.exe"" ["Lexmark International Inc."]
"DAEMON Tools" = ""C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033" ["DT Soft Ltd."]
"WinampAgent" = "C:\Program Files\Winamp\winampa.exe" [null data]
"ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
"Windows Defender" = ""C:\Program Files\Windows Defender\MSASCui.exe" -hide" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "AcroIEHlprObj Class"
                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
  -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
  -> {HKLM...CLSID} = "AlcoholShellEx"
                   \InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AxShlex.dll" ["Alcohol Soft Development Team"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" = "Microsoft AntiMalware ShellExecuteHook"
  -> {HKLM...CLSID} = "Microsoft AntiMalware ShellExecuteHook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\WIFD1F~1\MpShHook.dll" [MS]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
"System" = (value not set)

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\mateusz cybulski\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\POLKOM~4.SCR" (PolKompWio.scr) [null data]


powiedz mi jedna rzecz-jak sprawdzasz hijack this to na stroni hijackthis.de i takl wklejasz loga czy w jakis bardziej wyszukany sposob?
cos na kompie jeszcze jest bo mam spam...
NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA



Postprzez wojtas 08 Kwi 2007, 23:01

kybula napisał(a):powiedz mi jedna rzecz-jak sprawdzasz hijack this to na stroni hijackthis.de i takl wklejasz loga czy w jakis bardziej wyszukany sposob?


nie samodzielnie sprawdzam

kybula napisał(a):nie mam folderu system32


niemozliwe :wink: moze jest ukryty??

Pobierz i uruchom narzędzie : The Avenger
http://swandog46.geekstogo.com/avenger.zip
Zaznacz opcję Input script manually i kliknij na Lupkę z prawej strony. W okienku, które się otworzy wklejasz:

Folders to delete:

C:\Program Files\Common Files\{5830E138-0BB2-1045-0201-050403250030}
C:\Program Files\Ipwindows


Klikasz Done, a następnie zielone światełko i zgadzasz się na restart klikając OK.
Po restarcie w HijackThis usuwasz wpis/y

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll (file missing)
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184



Kasujesz ręcznie z dysku plik: C:\Avenger\backup.zip i wklejasz na forum raport: C:\avenger.txt + log z comboscana + log z Silent Runners tym razem caly bo ten jest urwany .

http://www.techsupportforum.com/sectools/Deckard/comboscan.exe
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez kybula 09 Kwi 2007, 01:13

sys32 nie ma..no nie moge znalesc-nie jestem jakims ulomem ze bym nie mogl ukrytego pliku znalesc..poprostu nie ma go... w wyszukiwarce tez nic-wiez ze to dziwne bo przeceiez polowa systemu jest w tym folderze..ale coz...


Kod: Zaznacz wszystko
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\illncvut

*******************

Script file located at: \??\C:\opvemkmg.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Folder C:\Program Files\Common Files\{5830E138-0BB2-1045-0201-050403250030} deleted successfully.


Folder C:\Program Files\Ipwindows not found!
Deletion of folder C:\Program Files\Ipwindows failed!

Could not process line:
C:\Program Files\Ipwindows
Status: 0xc0000034


Completed script processing.

*******************

Finished!  Terminate.[quote]

C/PF/ipwindows usonolem reznie w safeboot wiec go nie znalazl.


comboscan:

[code]ComboScan v20070306.20 run by mateusz cybulski on 2007-04-09 at 00:56:29
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as mateusz cybulski.exe) ------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 00:56:30, on 2007-04-09
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CPUCooL\CooLSrv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mateusz cybulski\Pulpit\comboscan.exe
C:\DOCUME~1\MATEUS~1\Pulpit\HIJACK~1\MATEUS~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=www.actina.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Program Files\CPUCooL\CooLSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: lxcg_device -   - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


-- Files created between 2007-03-09 and 2007-04-09 -----------------------------

2007-04-09 00:44:12         0 d-------- C:\avenger
2007-04-08 19:24:41         0 d-------- C:\Program Files\Common Files\{5830E138-0BB3-1045-0201-050403250030}<{5830E~3>
2007-04-08 15:39:28         0 d-------- C:\Program Files\Common Files\{5830E138-0BB7-1045-0201-050403250030}<{5830E~2>
2007-04-08 15:00:52       167 --a------ C:\WINDOWS\system32\4369.bat
2007-04-08 15:00:42         0 d-------- C:\Program Files\Common Files\{3830E138-0BB2-1045-0201-050403250030}<{3830E~1>
2007-04-08 15:00:41     96768 --a------ C:\WINDOWS\system32\dxclib303562752.dll<DXCLIB~1.DLL>
2007-04-08 15:00:39      3072 --a------ C:\WINDOWS\system32\unsvchosts.exe<UNSVCH~1.EXE>
2007-04-08 15:00:39     36864 --a------ C:\WINDOWS\system32\svchosts.exe
2007-04-08 15:00:37    365568 --a------ C:\WINDOWS\system32\bkd.exe
2007-04-08 15:00:36     38725 --a------ C:\WINDOWS\system32\install.exe
2007-04-08 15:00:32    105434 --a------ C:\WINDOWS\VTTC.exe
2007-04-08 15:00:28      8464 --a------ C:\WINDOWS\system32\sporder.dll
2007-04-08 15:00:27     50688 --a-s---- C:\WINDOWS\NDNuninstall6_38.exe<NDNUNI~1.EXE>
2007-04-08 15:00:26     72320 --a------ C:\WINDOWS\system32\drivers\core.sys
2007-04-08 15:00:25         0 d-------- C:\WINDOWS\system32\micro1
2007-04-08 15:00:16         0 d-------- C:\WINDOWS\system32\bund1
2007-04-08 15:00:14     41792 --a------ C:\WINDOWS\system32\app.exe
2007-04-08 15:00:13     32768 --a------ C:\WINDOWS\system32\setup9x.exe
2007-04-08 15:00:05         0 --a------ C:\WINDOWS\system32\taskkill.exe
2007-04-08 14:59:59    147456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-04-04 21:53:02    184320 --a------ C:\WINDOWS\sys101479598392.exe<SYS101~1.EXE>
2007-04-04 01:05:23     53248 --a------ C:\WINDOWS\111uninst.exe<111UNI~1.EXE>
2007-03-29 11:49:47         0 d-------- C:\Program Files\Windows Defender<WIFD1F~1>
2007-03-24 19:33:27         0 d-------- C:\Program Files\Gothic III<GOTHIC~1>
2007-03-24 11:21:28         0 d-------- C:\Program Files\Windows Media Connect 2<WINDOW~4>
2007-03-24 11:18:55         0 d-------- C:\WINDOWS\system32\LogFiles
2007-03-24 11:18:55         0 d-------- C:\WINDOWS\system32\drivers\UMDF
2007-03-15 16:46:35     57344 --a------ C:\WINDOWS\uni_eh10.exe


-- Find3M Report ---------------------------------------------------------------

2007-04-09 00:47:47    355486 --a------ C:\WINDOWS\system32\perfh015.dat
2007-04-09 00:47:47     49492 --a------ C:\WINDOWS\system32\perfc015.dat
2007-04-09 00:33:43         0 d-------- C:\Program Files\BearShare<BEARSH~1>
2007-04-08 21:49:25     23552 --a------ C:\setup.exe
2007-04-08 19:31:05         0 d-------- C:\Program Files\InetGet2
2007-04-08 15:03:07    828444 --a------ C:\Documents and Settings\mateusz cybulski\Dane aplikacji\Dxcknwrd.dll
2007-04-08 15:00:43         0 d-------- C:\Program Files\Windows NT<WINDOW~1>
2007-04-06 23:45:17         0 d-------- C:\Program Files\NAPI-PROJEKT<NAPI-P~1>
2007-04-06 19:57:29         0 d-------- C:\Program Files\Gadu-Gadu<GADU-G~1>
2007-04-04 23:49:25    249856 -----n--- C:\WINDOWS\Setup1.exe
2007-03-25 22:30:41         0 d-------- C:\Documents and Settings\mateusz cybulski\Dane aplikacji\Arcsoft
2007-03-22 11:52:49       341 --a------ C:\WINDOWS\system32\lsprst7.dll
2007-03-22 11:52:48        73 --a------ C:\WINDOWS\system32\ssprs.dll
2007-03-08 17:38:47    579072 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:38:47     40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:38:47    281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:37:33   1843840 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-03 23:11:59         0 d-------- C:\Program Files\Valve
2007-03-03 23:06:32         0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-03-03 23:06:24         0 d-------- C:\Program Files\PowerQuest<POWERQ~1>
2007-03-03 22:16:20         0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-03-03 22:16:18         0 d-------- C:\Program Files\Symantec
2007-03-03 22:15:07         0 d-------- C:\Program Files\Kaspersky Lab<KASPER~1>
2007-03-03 22:15:05         0 d-------- C:\Program Files\Common Files\Kaspersky Lab<KASPER~1>
2007-03-03 21:50:32         0 d-------- C:\Program Files\Norton AntiVirus<NORTON~1>
2007-03-03 14:13:48         0 d-------- C:\Program Files\ATI Technologies<ATITEC~1>
2007-03-03 14:10:43         0 d-------- C:\Program Files\C-Media 3D Audio<C-MEDI~1>
2007-02-23 00:06:17         0 d-------- C:\Program Files\DC++<DC__~1>
2007-02-21 19:23:54         0 d-------- C:\Program Files\The All-Seeing Eye<THEALL~1>
2007-01-29 10:58:06     60416 -----n--- C:\WINDOWS\system32\tzchange.exe


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Steam"="\"C:\\Program Files\\Valve\\Steam\\Steam.exe\" -silent"
"Gadu-Gadu"="\"C:\\Program Files\\Gadu-Gadu\\gg.exe\" /tray"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"lxcgmon.exe"="\"C:\\Program Files\\Lexmark 2300 Series\\lxcgmon.exe\""
"EzPrint"="\"C:\\Program Files\\Lexmark 2300 Series\\ezprint.exe\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BearShare"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
   

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB2-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB2-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB7-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB7-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB3-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB3-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB2-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB7-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB7-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB3-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB3-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
   Source   REG_SZ            http://www.portal24h.pl/humor/dyplomy/palenie_trawy.jpg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService   REG_MULTI_SZ      Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService   REG_MULTI_SZ      DnsCache\0\0
rpcss   REG_MULTI_SZ      RpcSs\0\0
imgsvc   REG_MULTI_SZ      StiSvc\0\0
termsvcs   REG_MULTI_SZ      TermService\0\0
HTTPFilter   REG_MULTI_SZ      HTTPFilter\0\0
DcomLaunch   REG_MULTI_SZ      DcomLaunch\0TermService\0\0
WudfServiceGroup   REG_MULTI_SZ      WUDFSvc\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{58b1faeb-8c0c-11da-9af0-806d6172696f}]
Shell\AutoRun\command   D:\AutoRun.exe

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{58b1faec-8c0c-11da-9af0-806d6172696f}]
Shell\AutoRun\command   C:\setup.exe


-- End of ComboScan: finished at 2007-04-09 at 00:56:46 ------------------------

[/code]


runner




[code]"Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\
"{5830E138-0BB2-1045-0201-050403250030}" = ""C:\Program Files\Common Files\{5830E138-0BB2-1045-0201-050403250030}\Update.exe" mc-110-12-0000137" [file not found]

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [file not found]
"Steam" = ""C:\Program Files\Valve\Steam\Steam.exe" -silent" ["Valve Corporation"]
"Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"lxcgmon.exe" = ""C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"" ["Lexmark International, Inc."]
"EzPrint" = ""C:\Program Files\Lexmark 2300 Series\ezprint.exe"" ["Lexmark International Inc."]
"DAEMON Tools" = ""C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033" ["DT Soft Ltd."]
"WinampAgent" = "C:\Program Files\Winamp\winampa.exe" [null data]
"ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
"Windows Defender" = ""C:\Program Files\Windows Defender\MSASCui.exe" -hide" [MS]
"BearShare" = ""C:\Program Files\BearShare\BearShare.exe" /pause" ["Free Peers, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "AcroIEHlprObj Class"
                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
  -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
  -> {HKLM...CLSID} = "AlcoholShellEx"
                   \InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AxShlex.dll" ["Alcohol Soft Development Team"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" = "Microsoft AntiMalware ShellExecuteHook"
  -> {HKLM...CLSID} = "Microsoft AntiMalware ShellExecuteHook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\WIFD1F~1\MpShHook.dll" [MS]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
"System" = (value not set)

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\mateusz cybulski\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\POLKOM~4.SCR" (PolKompWio.scr) [null data]


Startup items in "mateusz cybulski" & "All Users" startup folders:
------------------------------------------------------------------

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
"Adobe Gamma Loader.exe" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
"InterVideo WinCinema Manager" -> shortcut to: "C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe" ["InterVideo Inc."]


Enabled Scheduled Tasks:
------------------------

"MP Scheduled Scan" -> launches: "C:\Program Files\Windows Defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{37B85A29-692B-4205-9CAD-2626E4993404}"
  -> {HKLM...CLSID} = "My Global Search Bar"
                   \InProcServer32\(Default) = "C:\Program Files\MyGlobalSearch\bar\2.bin\MGSBAR.DLL" [file not found]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}"
  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_01"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll" ["Sun Microsystems, Inc."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [file not found]


Miscellaneous IE Hijack Points
------------------------------

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=www.actina.pl

Missing lines (compared with English-language version):
[Strings]: 1 line


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
CPUCooLServer Service, CPUCooLServer, ""C:\Program Files\CPUCooL\CooLSrv.exe"" [null data]
lxcg_device, lxcg_device, "C:\WINDOWS\system32\lxcgcoms.exe -service" [" "]
StarWind iSCSI Service, StarWindService, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" ["Rocket Division Software"]
Windows Defender, WinDefend, ""C:\Program Files\Windows Defender\MsMpEng.exe"" [MS]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
2300 Series Port\Driver = "lxcglmpm.DLL" [" "]


----------
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
  took 176 seconds.
---------- (total run time: 206 seconds)
[/code]

[size=75][ [i][b][color=#B50158]Dodano:[/b] Dzisiaj o 0:21[/i] ][/size] [/color]
cos pochrzanilem z ogami..sorry jeszcze raz..;/

[code]Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\illncvut

*******************

Script file located at: \??\C:\opvemkmg.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Folder C:\Program Files\Common Files\{5830E138-0BB2-1045-0201-050403250030} deleted successfully.


Folder C:\Program Files\Ipwindows not found!
Deletion of folder C:\Program Files\Ipwindows failed!

Could not process line:
C:\Program Files\Ipwindows
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.[/code]


C/PF/ipwindows usonolem wczesniej w safeboot wiec go nie znalazl.


[code]
ComboScan v20070306.20 run by mateusz cybulski on 2007-04-09 at 01:09:10
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as mateusz cybulski.exe) ------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 01:09:11, on 2007-04-09
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CPUCooL\CooLSrv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mateusz cybulski\Pulpit\comboscan.exe
C:\DOCUME~1\MATEUS~1\Pulpit\HIJACK~1\MATEUS~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=www.actina.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Program Files\CPUCooL\CooLSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: lxcg_device -   - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


-- Files created between 2007-03-09 and 2007-04-09 -----------------------------

2007-04-09 00:44:12         0 d-------- C:\avenger
2007-04-08 19:24:41         0 d-------- C:\Program Files\Common Files\{5830E138-0BB3-1045-0201-050403250030}<{5830E~3>
2007-04-08 15:39:28         0 d-------- C:\Program Files\Common Files\{5830E138-0BB7-1045-0201-050403250030}<{5830E~2>
2007-04-08 15:00:52       167 --a------ C:\WINDOWS\system32\4369.bat
2007-04-08 15:00:42         0 d-------- C:\Program Files\Common Files\{3830E138-0BB2-1045-0201-050403250030}<{3830E~1>
2007-04-08 15:00:41     96768 --a------ C:\WINDOWS\system32\dxclib303562752.dll<DXCLIB~1.DLL>
2007-04-08 15:00:39      3072 --a------ C:\WINDOWS\system32\unsvchosts.exe<UNSVCH~1.EXE>
2007-04-08 15:00:39     36864 --a------ C:\WINDOWS\system32\svchosts.exe
2007-04-08 15:00:37    365568 --a------ C:\WINDOWS\system32\bkd.exe
2007-04-08 15:00:36     38725 --a------ C:\WINDOWS\system32\install.exe
2007-04-08 15:00:32    105434 --a------ C:\WINDOWS\VTTC.exe
2007-04-08 15:00:28      8464 --a------ C:\WINDOWS\system32\sporder.dll
2007-04-08 15:00:27     50688 --a-s---- C:\WINDOWS\NDNuninstall6_38.exe<NDNUNI~1.EXE>
2007-04-08 15:00:26     72320 --a------ C:\WINDOWS\system32\drivers\core.sys
2007-04-08 15:00:25         0 d-------- C:\WINDOWS\system32\micro1
2007-04-08 15:00:16         0 d-------- C:\WINDOWS\system32\bund1
2007-04-08 15:00:14     41792 --a------ C:\WINDOWS\system32\app.exe
2007-04-08 15:00:13     32768 --a------ C:\WINDOWS\system32\setup9x.exe
2007-04-08 15:00:05         0 --a------ C:\WINDOWS\system32\taskkill.exe
2007-04-08 14:59:59    147456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-04-04 21:53:02    184320 --a------ C:\WINDOWS\sys101479598392.exe<SYS101~1.EXE>
2007-04-04 01:05:23     53248 --a------ C:\WINDOWS\111uninst.exe<111UNI~1.EXE>
2007-03-29 11:49:47         0 d-------- C:\Program Files\Windows Defender<WIFD1F~1>
2007-03-24 19:33:27         0 d-------- C:\Program Files\Gothic III<GOTHIC~1>
2007-03-24 11:21:28         0 d-------- C:\Program Files\Windows Media Connect 2<WINDOW~4>
2007-03-24 11:18:55         0 d-------- C:\WINDOWS\system32\LogFiles
2007-03-24 11:18:55         0 d-------- C:\WINDOWS\system32\drivers\UMDF
2007-03-15 16:46:35     57344 --a------ C:\WINDOWS\uni_eh10.exe


-- Find3M Report ---------------------------------------------------------------

2007-04-09 00:47:47    355486 --a------ C:\WINDOWS\system32\perfh015.dat
2007-04-09 00:47:47     49492 --a------ C:\WINDOWS\system32\perfc015.dat
2007-04-09 00:33:43         0 d-------- C:\Program Files\BearShare<BEARSH~1>
2007-04-08 21:49:25     23552 --a------ C:\setup.exe
2007-04-08 19:31:05         0 d-------- C:\Program Files\InetGet2
2007-04-08 15:03:07    828444 --a------ C:\Documents and Settings\mateusz cybulski\Dane aplikacji\Dxcknwrd.dll
2007-04-08 15:00:43         0 d-------- C:\Program Files\Windows NT<WINDOW~1>
2007-04-06 23:45:17         0 d-------- C:\Program Files\NAPI-PROJEKT<NAPI-P~1>
2007-04-06 19:57:29         0 d-------- C:\Program Files\Gadu-Gadu<GADU-G~1>
2007-04-04 23:49:25    249856 -----n--- C:\WINDOWS\Setup1.exe
2007-03-25 22:30:41         0 d-------- C:\Documents and Settings\mateusz cybulski\Dane aplikacji\Arcsoft
2007-03-22 11:52:49       341 --a------ C:\WINDOWS\system32\lsprst7.dll
2007-03-22 11:52:48        73 --a------ C:\WINDOWS\system32\ssprs.dll
2007-03-08 17:38:47    579072 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:38:47     40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:38:47    281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:37:33   1843840 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-03 23:11:59         0 d-------- C:\Program Files\Valve
2007-03-03 23:06:32         0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-03-03 23:06:24         0 d-------- C:\Program Files\PowerQuest<POWERQ~1>
2007-03-03 22:16:20         0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-03-03 22:16:18         0 d-------- C:\Program Files\Symantec
2007-03-03 22:15:07         0 d-------- C:\Program Files\Kaspersky Lab<KASPER~1>
2007-03-03 22:15:05         0 d-------- C:\Program Files\Common Files\Kaspersky Lab<KASPER~1>
2007-03-03 21:50:32         0 d-------- C:\Program Files\Norton AntiVirus<NORTON~1>
2007-03-03 14:13:48         0 d-------- C:\Program Files\ATI Technologies<ATITEC~1>
2007-03-03 14:10:43         0 d-------- C:\Program Files\C-Media 3D Audio<C-MEDI~1>
2007-02-23 00:06:17         0 d-------- C:\Program Files\DC++<DC__~1>
2007-02-21 19:23:54         0 d-------- C:\Program Files\The All-Seeing Eye<THEALL~1>
2007-01-29 10:58:06     60416 -----n--- C:\WINDOWS\system32\tzchange.exe


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Steam"="\"C:\\Program Files\\Valve\\Steam\\Steam.exe\" -silent"
"Gadu-Gadu"="\"C:\\Program Files\\Gadu-Gadu\\gg.exe\" /tray"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"lxcgmon.exe"="\"C:\\Program Files\\Lexmark 2300 Series\\lxcgmon.exe\""
"EzPrint"="\"C:\\Program Files\\Lexmark 2300 Series\\ezprint.exe\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BearShare"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
   

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB2-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB2-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB7-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB7-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB3-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB3-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB2-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB7-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB7-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB3-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB3-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
   Source   REG_SZ            http://www.portal24h.pl/humor/dyplomy/palenie_trawy.jpg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService   REG_MULTI_SZ      Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService   REG_MULTI_SZ      DnsCache\0\0
rpcss   REG_MULTI_SZ      RpcSs\0\0
imgsvc   REG_MULTI_SZ      StiSvc\0\0
termsvcs   REG_MULTI_SZ      TermService\0\0
HTTPFilter   REG_MULTI_SZ      HTTPFilter\0\0
DcomLaunch   REG_MULTI_SZ      DcomLaunch\0TermService\0\0
WudfServiceGroup   REG_MULTI_SZ      WUDFSvc\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{58b1faeb-8c0c-11da-9af0-806d6172696f}]
Shell\AutoRun\command   D:\AutoRun.exe

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{58b1faec-8c0c-11da-9af0-806d6172696f}]
Shell\AutoRun\command   C:\setup.exe


-- End of ComboScan: finished at 2007-04-09 at 01:09:28 ------------------------

[/code]


[code]
"Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\
"{5830E138-0BB2-1045-0201-050403250030}" = ""C:\Program Files\Common Files\{5830E138-0BB2-1045-0201-050403250030}\Update.exe" mc-110-12-0000137" [file not found]

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [file not found]
"Steam" = ""C:\Program Files\Valve\Steam\Steam.exe" -silent" ["Valve Corporation"]
"Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"lxcgmon.exe" = ""C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"" ["Lexmark International, Inc."]
"EzPrint" = ""C:\Program Files\Lexmark 2300 Series\ezprint.exe"" ["Lexmark International Inc."]
"DAEMON Tools" = ""C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033" ["DT Soft Ltd."]
"WinampAgent" = "C:\Program Files\Winamp\winampa.exe" [null data]
"ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
"Windows Defender" = ""C:\Program Files\Windows Defender\MSASCui.exe" -hide" [MS]
"BearShare" = ""C:\Program Files\BearShare\BearShare.exe" /pause" ["Free Peers, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "AcroIEHlprObj Class"
                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
  -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
  -> {HKLM...CLSID} = "AlcoholShellEx"
                   \InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AxShlex.dll" ["Alcohol Soft Development Team"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" = "Microsoft AntiMalware ShellExecuteHook"
  -> {HKLM...CLSID} = "Microsoft AntiMalware ShellExecuteHook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\WIFD1F~1\MpShHook.dll" [MS]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
"System" = (value not set)

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\mateusz cybulski\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\POLKOM~4.SCR" (PolKompWio.scr) [null data]


Startup items in "mateusz cybulski" & "All Users" startup folders:
------------------------------------------------------------------

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
"Adobe Gamma Loader.exe" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
"InterVideo WinCinema Manager" -> shortcut to: "C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe" ["InterVideo Inc."]


Enabled Scheduled Tasks:
------------------------

"MP Scheduled Scan" -> launches: "C:\Program Files\Windows Defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{37B85A29-692B-4205-9CAD-2626E4993404}"
  -> {HKLM...CLSID} = "My Global Search Bar"
                   \InProcServer32\(Default) = "C:\Program Files\MyGlobalSearch\bar\2.bin\MGSBAR.DLL" [file not found]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}"
  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_01"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll" ["Sun Microsystems, Inc."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [file not found]


Miscellaneous IE Hijack Points
------------------------------

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=www.actina.pl

Missing lines (compared with English-language version):
[Strings]: 1 line


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
CPUCooLServer Service, CPUCooLServer, ""C:\Program Files\CPUCooL\CooLSrv.exe"" [null data]
lxcg_device, lxcg_device, "C:\WINDOWS\system32\lxcgcoms.exe -service" [" "]
StarWind iSCSI Service, StarWindService, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" ["Rocket Division Software"]
Windows Defender, WinDefend, ""C:\Program Files\Windows Defender\MsMpEng.exe"" [MS]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
2300 Series Port\Driver = "lxcglmpm.DLL" [" "]


----------
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
  took 176 seconds.
---------- (total run time: 206 seconds)
NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA



Postprzez wojtas 09 Kwi 2007, 11:46

poszukaj na kompie:

C:\Program Files\Common Files\{5830E138-0BB3-1045-0201-050403250030}
C:\Program Files\Common Files\{5830E138-0BB7-1045-0201-050403250030}
C:\Program Files\Common Files\{3830E138-0BB2-1045-0201-050403250030}


skasuj pogrubione

scaignij:
ATF_Cleaner
http://www.atribune.org/ccount/click.php?id=1
zaznacz
Windows Temp
Temporary internet files
i wcisnij EMPTY SELECTED


uruchom narzędzie : The Avenger
Zaznacz opcję Input script manually i kliknij na Lupkę z prawej strony. W okienku, które się otworzy wklejasz:

Files to delete:

C:\WINDOWS\system32\4369.bat
C:\WINDOWS\system32\dxclib303562752.dll
C:\WINDOWS\system32\unsvchosts.exe
C:\WINDOWS\system32\svchosts.exe
C:\WINDOWS\system32\bkd.exe
C:\WINDOWS\system32\install.exe
C:\WINDOWS\VTTC.exe
C:\WINDOWS\NDNuninstall6_38.exe
C:\WINDOWS\system32\app.exe
C:\WINDOWS\system32\setup9x.exe
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\sys101479598392.exe
C:\WINDOWS\111uninst.exe
C:\WINDOWS\uni_eh10.exe
C:\setup.exe
C:\WINDOWS\Setup1.exe

Folders to delete:

C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\micro1



Klikasz Done, a następnie zielone światełko i zgadzasz się na restart klikając OK.
Po restarcie w HijackThis usuwasz wpis/y

O17 - HKLM\System\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184


potem :

Ściągasz http://downloads.subratam.org/Fixwareout.exe i zastosuj go w awaryjnym trybie

nastepnie ten plik:

C:\WINDOWS\system32\drivers\core.sys


skanujesz skanerami i dajesz z nich raport:

http://virusscan.jotti.org/
http://www.virustotal.com/en/indexf.html

otwierasz notatnika w nim wklejasz:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=-

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{37B85A29-692B-4205-9CAD-2626E4993404}"=-

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"=-

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"=-

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB2-1045-0201-050403250030}"=-



w notatniku u góry>>>plik zapisz jako>>>Zmien rozszerzenie z TXT na Wszystkie pliki *.* >>> Zapisz pod nazwą FIX.REG

Klikasz dwa razy na powstały plik fix i dodajesz go do rejestru....


Kasujesz ręcznie z dysku plik: C:\Avenger\backup.zip i wklejasz na forum raport: C:\avenger.txt + log z comboscana + log z Silent Runners.
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez kybula 10 Kwi 2007, 00:05

wszystko zrobione-tylko nie moglem zeskanowac tego pliku C:\WINDOWS\system32\drivers\core.sys
bo wyskakiwal mi komunikat ze plik ma 0 bajtow.w wirusscan i virustotal. a plik w rzeczywistosci wazy ok70,kb.

avenger.

Kod: Zaznacz wszystko
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\nwtabxue

*******************

Script file located at: ilapqwfn

Could not open script file!  Error

Could not open script file!  Status: 0xc000003b  Abort!



runner

Kod: Zaznacz wszystko
"Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [file not found]
"Steam" = ""C:\Program Files\Valve\Steam\Steam.exe" -silent" ["Valve Corporation"]
"Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"lxcgmon.exe" = ""C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"" ["Lexmark International, Inc."]
"EzPrint" = ""C:\Program Files\Lexmark 2300 Series\ezprint.exe"" ["Lexmark International Inc."]
"DAEMON Tools" = ""C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033" ["DT Soft Ltd."]
"WinampAgent" = "C:\Program Files\Winamp\winampa.exe" [null data]
"ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
"Windows Defender" = ""C:\Program Files\Windows Defender\MSASCui.exe" -hide" [MS]
"BearShare" = ""C:\Program Files\BearShare\BearShare.exe" /pause" ["Free Peers, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "AcroIEHlprObj Class"
                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
  -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
  -> {HKLM...CLSID} = "AlcoholShellEx"
                   \InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AxShlex.dll" ["Alcohol Soft Development Team"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" = "Microsoft AntiMalware ShellExecuteHook"
  -> {HKLM...CLSID} = "Microsoft AntiMalware ShellExecuteHook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\WIFD1F~1\MpShHook.dll" [MS]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\mateusz cybulski\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\POLKOM~4.SCR" (PolKompWio.scr) [null data]


Startup items in "mateusz cybulski" & "All Users" startup folders:
------------------------------------------------------------------

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
"Adobe Gamma Loader.exe" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
"InterVideo WinCinema Manager" -> shortcut to: "C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe" ["InterVideo Inc."]


Enabled Scheduled Tasks:
------------------------

"MP Scheduled Scan" -> launches: "C:\Program Files\Windows Defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}"
  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_01"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll" ["Sun Microsystems, Inc."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [file not found]


Miscellaneous IE Hijack Points
------------------------------

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=www.actina.pl

Missing lines (compared with English-language version):
[Strings]: 1 line


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
CPUCooLServer Service, CPUCooLServer, ""C:\Program Files\CPUCooL\CooLSrv.exe"" [null data]
lxcg_device, lxcg_device, "C:\WINDOWS\system32\lxcgcoms.exe -service" [" "]
StarWind iSCSI Service, StarWindService, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" ["Rocket Division Software"]
Windows Defender, WinDefend, ""C:\Program Files\Windows Defender\MsMpEng.exe"" [MS]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
2300 Series Port\Driver = "lxcglmpm.DLL" [" "]


----------
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
  DLL launch points, use the -supp parameter or answer "No" at the
  first message box and "Yes" at the second message box.
---------- (total run time: 41 seconds, including 4 seconds for message boxes)



i combo

Kod: Zaznacz wszystko
ComboScan v20070306.20 run by mateusz cybulski on 2007-04-09 at 23:47:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as mateusz cybulski.exe) ------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 23:52:26, on 2007-04-09
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CPUCooL\CooLSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\fixwareout\FindT\nircmd.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\BearShare\BearShare.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mateusz cybulski\Pulpit\comboscan-1.exe
C:\DOCUME~1\MATEUS~1\Pulpit\mateusz cybulski.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=www.actina.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Program Files\CPUCooL\CooLSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: lxcg_device -   - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


-- Files created between 2007-03-09 and 2007-04-09 -----------------------------

2007-04-08 15:00:52       167 --a------ C:\WINDOWS\system32\4369.bat
2007-04-08 15:00:39     72192 --a------ C:\WINDOWS\system32\unsvchosts.exe<UNSVCH~1.EXE>
2007-04-08 15:00:39     36864 --a------ C:\WINDOWS\system32\svchosts.exe
2007-04-08 15:00:36     41984 --a------ C:\WINDOWS\system32\install.exe
2007-04-08 15:00:32     38400 --a------ C:\WINDOWS\VTTC.exe
2007-04-08 15:00:28      8464 --a------ C:\WINDOWS\system32\sporder.dll
2007-04-08 15:00:26     72320 --a------ C:\WINDOWS\system32\drivers\core.sys
2007-04-08 15:00:25         0 d-------- C:\WINDOWS\system32\micro1
2007-04-08 15:00:16         0 d-------- C:\WINDOWS\system32\bund1
2007-04-08 15:00:14     35840 --a------ C:\WINDOWS\system32\app.exe
2007-04-08 15:00:13     36864 --a------ C:\WINDOWS\system32\setup9x.exe
2007-04-08 15:00:05         0 --a------ C:\WINDOWS\system32\taskkill.exe
2007-04-08 14:59:59    147456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-04-04 01:05:23     57344 --a------ C:\WINDOWS\111uninst.exe<111UNI~1.EXE>
2007-03-29 11:49:47         0 d-------- C:\Program Files\Windows Defender<WIFD1F~1>
2007-03-24 19:33:27         0 d-------- C:\Program Files\Gothic III<GOTHIC~1>
2007-03-24 11:21:28         0 d-------- C:\Program Files\Windows Media Connect 2<WINDOW~4>
2007-03-24 11:18:55         0 d-------- C:\WINDOWS\system32\LogFiles
2007-03-24 11:18:55         0 d-------- C:\WINDOWS\system32\drivers\UMDF
2007-03-15 16:46:35     57344 --a------ C:\WINDOWS\uni_eh10.exe


-- Find3M Report ---------------------------------------------------------------

2007-04-09 23:44:31    289280 --a------ C:\WINDOWS\winhlp32.exe
2007-04-09 23:44:31   2027520 --a------ C:\WINDOWS\UNNeroVision.exe<UNNERO~1.EXE>
2007-04-09 23:44:31    103936 --a------ C:\WINDOWS\UninstallFirefox.exe<UNINST~1.EXE>
2007-04-09 23:44:31    287744 --a------ C:\WINDOWS\unin0407.exe
2007-04-09 23:44:31     29184 --a------ C:\WINDOWS\twunk_32.exe
2007-04-09 23:44:30     19456 --a------ C:\WINDOWS\TASKMAN.EXE
2007-04-09 23:44:30    857600 --a------ C:\WINDOWS\system32\XMNT2002.exe
2007-04-09 23:44:30     30208 --a------ C:\WINDOWS\system32\xmlinst.exe
2007-04-09 23:44:30     34816 --a------ C:\WINDOWS\system32\xcopy.exe
2007-04-09 23:44:30     36352 --a------ C:\WINDOWS\system32\wupdmgr.exe
2007-04-09 23:44:30    150528 --a------ C:\WINDOWS\system32\WudfHost.exe
2007-04-09 23:44:30    172544 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-04-09 23:44:30    118784 --a------ C:\WINDOWS\system32\wscript.exe
2007-04-09 23:44:29      9216 --a------ C:\WINDOWS\system32\write.exe
2007-04-09 23:44:29     36352 --a------ C:\WINDOWS\system32\wpnpinst.exe
2007-04-09 23:44:29     20992 --a------ C:\WINDOWS\system32\wpdshextautoplay.exe<WPDSHE~1.EXE>
2007-04-09 23:44:29     35840 --a------ C:\WINDOWS\system32\wpabaln.exe
2007-04-09 23:44:29     77824 --a------ C:\WINDOWS\system32\wmpstub.exe
2007-04-09 23:44:29      9216 --a------ C:\WINDOWS\system32\winver.exe
2007-04-09 23:44:29     15360 --a------ C:\WINDOWS\system32\winmsd.exe
2007-04-09 23:44:29    123904 --a------ C:\WINDOWS\system32\winmine.exe
2007-04-09 23:44:29     11776 --a------ C:\WINDOWS\system32\winhlp32.exe
2007-04-09 23:44:29     38912 --a------ C:\WINDOWS\system32\winchat.exe
2007-04-09 23:44:29    439296 --a------ C:\WINDOWS\system32\wiaacmgr.exe
2007-04-09 23:44:28     69632 --a------ C:\WINDOWS\system32\wextract.exe
2007-04-09 23:44:28     12288 --a------ C:\WINDOWS\system32\wdfmgr.exe
2007-04-09 23:44:28     54784 --a------ C:\WINDOWS\system32\w32tm.exe
2007-04-09 23:44:28    295936 --a------ C:\WINDOWS\system32\vssvc.exe
2007-04-09 23:44:27     37888 --a------ C:\WINDOWS\system32\vssadmin.exe
2007-04-09 23:44:27    105984 --a------ C:\WINDOWS\system32\verifier.exe
2007-04-09 23:44:27     32768 --a------ C:\WINDOWS\system32\verclsid.exe
2007-04-09 23:44:27     12288 --a------ C:\WINDOWS\system32\uwdf.exe
2007-04-09 23:44:27     53760 --a------ C:\WINDOWS\system32\utilman.exe
2007-04-09 23:44:27     73728 --a------ C:\WINDOWS\system32\usrshuta.exe
2007-04-09 23:44:27     65536 --a------ C:\WINDOWS\system32\usrprbda.exe
2007-04-09 23:44:27     81920 --a------ C:\WINDOWS\system32\usrmlnka.exe
2007-04-09 23:44:27     28672 --a------ C:\WINDOWS\system32\userinit.exe
2007-04-09 23:44:26     22528 --a------ C:\WINDOWS\system32\ups.exe
2007-04-09 23:44:26     20480 --a------ C:\WINDOWS\system32\upnpcont.exe
2007-04-09 23:44:26      8192 --a------ C:\WINDOWS\system32\unlodctr.exe
2007-04-09 23:44:26     64000 --a------ C:\WINDOWS\system32\tzchange.exe
2007-04-09 23:44:26     21504 --a------ C:\WINDOWS\system32\tsshutdn.exe
2007-04-09 23:44:26     20480 --a------ C:\WINDOWS\system32\tskill.exe
2007-04-09 23:44:26     18944 --a------ C:\WINDOWS\system32\tsdiscon.exe
2007-04-09 23:44:26     48128 --a------ C:\WINDOWS\system32\tscupgrd.exe
2007-04-09 23:44:26     18944 --a------ C:\WINDOWS\system32\tscon.exe
2007-04-09 23:44:26     35840 --a------ C:\WINDOWS\system32\tracert6.exe
2007-04-09 23:44:26     16896 --a------ C:\WINDOWS\system32\tracert.exe
2007-04-09 23:44:26    350720 --a------ C:\WINDOWS\system32\tourstart.exe<TOURST~1.EXE>
2007-04-09 23:44:26     20992 --a------ C:\WINDOWS\system32\tftp.exe
2007-04-09 23:44:25     81920 --a------ C:\WINDOWS\system32\telnet.exe
2007-04-09 23:44:25     23552 --a------ C:\WINDOWS\system32\tcpsvcs.exe
2007-04-09 23:44:25     16896 --a------ C:\WINDOWS\system32\tcmsetup.exe
2007-04-09 23:44:25    143360 --a------ C:\WINDOWS\system32\taskmgr.exe
2007-04-09 23:44:25     19456 --a------ C:\WINDOWS\system32\taskman.exe
2007-04-09 23:44:25      7168 --a------ C:\WINDOWS\system32\systray.exe
2007-04-09 23:44:25    110592 --a------ C:\WINDOWS\system32\sysocmgr.exe
2007-04-09 23:44:25     40960 --a------ C:\WINDOWS\system32\syskey.exe
2007-04-09 23:44:25     54784 --a------ C:\WINDOWS\system32\syncapp.exe
2007-04-09 23:44:25     84992 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-04-09 23:44:25     48128 --a------ C:\WINDOWS\system32\swsc.exe
2007-04-09 23:44:25    140288 --a------ C:\WINDOWS\system32\swreg.exe
2007-04-09 23:44:25     13312 --a------ C:\WINDOWS\system32\subst.exe
2007-04-09 23:44:25     28672 --a------ C:\WINDOWS\system32\stup3.exe
2007-04-09 23:44:25     18432 --a------ C:\WINDOWS\system32\stimon.exe
2007-04-09 23:44:24     84480 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-04-09 23:44:24     25088 --a------ C:\WINDOWS\system32\spupdwxp.exe
2007-04-09 23:44:24     20992 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-04-09 23:44:24     13824 --a------ C:\WINDOWS\system32\sprestrt.exe
2007-04-09 23:44:22     15360 --a------ C:\WINDOWS\system32\spnpinst.exe
2007-04-09 23:44:22    542720 --a------ C:\WINDOWS\system32\spider.exe
2007-04-09 23:44:22     11776 --a------ C:\WINDOWS\system32\spdwnwxp.exe
2007-04-09 23:44:22     27648 --a------ C:\WINDOWS\system32\sort.exe
2007-04-09 23:44:22     60928 --a------ C:\WINDOWS\system32\sol.exe
2007-04-09 23:44:22    143360 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-04-09 23:44:22    136192 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-04-09 23:44:22     94720 --a------ C:\WINDOWS\system32\smlogsvc.exe
2007-04-09 23:44:22     11776 --a------ C:\WINDOWS\system32\smbinst.exe
2007-04-09 23:44:22     77824 --a------ C:\WINDOWS\system32\slserv.exe
2007-04-09 23:44:22     36864 --a------ C:\WINDOWS\system32\slrundll.exe
2007-04-09 23:44:22     30208 --a------ C:\WINDOWS\system32\skeys.exe
2007-04-09 23:44:22     74752 --a------ C:\WINDOWS\system32\sigverif.exe
2007-04-09 23:44:21     24064 --a------ C:\WINDOWS\system32\shutdown.exe
2007-04-09 23:44:21     81920 --a------ C:\WINDOWS\system32\shrpubw.exe
2007-04-09 23:44:21     46080 --a------ C:\WINDOWS\system32\shmgrate.exe
2007-04-09 23:44:21     18944 --a------ C:\WINDOWS\system32\shadow.exe
2007-04-09 23:44:21     13824 --a------ C:\WINDOWS\system32\sfc.exe
2007-04-09 23:44:21     26624 --a------ C:\WINDOWS\system32\setup.exe
2007-04-09 23:44:21     36352 --a------ C:\WINDOWS\system32\sethc.exe
2007-04-09 23:44:21    145408 --a------ C:\WINDOWS\system32\sessmgr.exe
2007-04-09 23:44:21     81408 --a------ C:\WINDOWS\system32\sdbinst.exe
2007-04-09 23:44:21    101888 --a------ C:\WINDOWS\system32\scardsvr.exe
2007-04-09 23:44:21     34816 --a------ C:\WINDOWS\system32\sc.exe
2007-04-09 23:44:21     17408 --a------ C:\WINDOWS\system32\savedump.exe
2007-04-09 23:44:20     19968 --a------ C:\WINDOWS\system32\rwinsta.exe
2007-04-09 23:44:20     17920 --a------ C:\WINDOWS\system32\runonce.exe
2007-04-09 23:44:20     36864 --a------ C:\WINDOWS\system32\rundll32.exe
2007-04-09 23:44:20     20992 --a------ C:\WINDOWS\system32\runas.exe
2007-04-09 23:44:20     81408 --a------ C:\WINDOWS\system32\rtcshare.exe
2007-04-09 23:44:20    136704 --a------ C:\WINDOWS\system32\rsvp.exe
2007-04-09 23:44:20     52736 --a------ C:\WINDOWS\system32\rsmui.exe
2007-04-09 23:44:20     28160 --a------ C:\WINDOWS\system32\rsmsink.exe
2007-04-09 23:44:20     57856 --a------ C:\WINDOWS\system32\rsm.exe
2007-04-09 23:44:20     18944 --a------ C:\WINDOWS\system32\rsh.exe
2007-04-09 23:44:20     29184 --a------ C:\WINDOWS\system32\routemon.exe
2007-04-09 23:44:19     24064 --a------ C:\WINDOWS\system32\route.exe
2007-04-09 23:44:19     17920 --a------ C:\WINDOWS\system32\rexec.exe
2007-04-09 23:44:19     13824 --a------ C:\WINDOWS\system32\reset.exe
2007-04-09 23:44:19     16896 --a------ C:\WINDOWS\system32\replace.exe
2007-04-09 23:44:16      8192 --a------ C:\WINDOWS\system32\regwiz.exe
2007-04-09 23:44:16     15872 --a------ C:\WINDOWS\system32\regsvr32.exe
2007-04-09 23:44:16     37888 --a------ C:\WINDOWS\system32\regini.exe
2007-04-09 23:44:16      7168 --a------ C:\WINDOWS\system32\regedt32.exe
2007-04-09 23:44:16     56832 --a------ C:\WINDOWS\system32\reg.exe
2007-04-09 23:44:16     11264 --a------ C:\WINDOWS\system32\recover.exe
2007-04-09 23:44:16     70656 --a------ C:\WINDOWS\system32\rdshost.exe
2007-04-09 23:44:16     17408 --a------ C:\WINDOWS\system32\rdsaddin.exe
2007-04-09 23:44:16     66560 --a------ C:\WINDOWS\system32\rdpclip.exe
2007-04-09 23:44:16     25600 --a------ C:\WINDOWS\system32\rcp.exe
2007-04-09 23:44:16     39424 --a------ C:\WINDOWS\system32\rcimlby.exe
2007-04-09 23:44:15     60416 --a------ C:\WINDOWS\system32\rasphone.exe
2007-04-09 23:44:15     15360 --a------ C:\WINDOWS\system32\rasdial.exe
2007-04-09 23:44:15     15360 --a------ C:\WINDOWS\system32\rasautou.exe
2007-04-09 23:44:15     26624 --a------ C:\WINDOWS\system32\qwinsta.exe
2007-04-09 23:44:15     24576 --a------ C:\WINDOWS\system32\qprocess.exe
2007-04-09 23:44:15     20992 --a------ C:\WINDOWS\system32\qappsrv.exe
2007-04-09 23:44:15     13312 --a------ C:\WINDOWS\system32\proxycfg.exe
2007-04-09 23:44:15     54272 --a------ C:\WINDOWS\system32\proquota.exe
2007-04-09 23:44:15    113152 --a------ C:\WINDOWS\system32\progman.exe
2007-04-09 23:44:15     57344 --a------ C:\WINDOWS\system32\Process.exe
2007-04-09 23:44:15     13312 --a------ C:\WINDOWS\system32\print.exe
2007-04-09 23:44:15     52736 --a------ C:\WINDOWS\system32\powercfg.exe
2007-04-09 23:44:15     37376 --a------ C:\WINDOWS\system32\ping6.exe
2007-04-09 23:44:15     22528 --a------ C:\WINDOWS\system32\ping.exe
2007-04-09 23:44:14     19456 --a------ C:\WINDOWS\system32\perfmon.exe
2007-04-09 23:44:14     18944 --a------ C:\WINDOWS\system32\pentnt.exe
2007-04-09 23:44:14     26112 --a------ C:\WINDOWS\system32\pathping.exe
2007-04-09 23:44:14     62976 --a------ C:\WINDOWS\system32\packager.exe
2007-04-09 23:44:14     45056 --a------ C:\WINDOWS\system32\osuninst.exe
2007-04-09 23:44:14    220160 --a------ C:\WINDOWS\system32\osk.exe
2007-04-09 23:44:13     73728 --a------ C:\WINDOWS\system32\odbcconf.exe
2007-04-09 23:44:13     36864 --a------ C:\WINDOWS\system32\odbcad32.exe
2007-04-09 23:44:13    423936 --a------ C:\WINDOWS\system32\ntvdm.exe
2007-04-09 23:44:13     35328 --a------ C:\WINDOWS\system32\ntsd.exe
2007-04-09 23:44:12     83456 --a------ C:\WINDOWS\system32\nslookup.exe
2007-04-09 23:44:12     41984 --a------ C:\WINDOWS\system32\netstat.exe
2007-04-09 23:44:12     91136 --a------ C:\WINDOWS\system32\netsh.exe
2007-04-09 23:44:12    339968 --a------ C:\WINDOWS\system32\netsetup.exe
2007-04-09 23:44:12    118272 --a------ C:\WINDOWS\system32\netdde.exe
2007-04-09 23:44:12    129024 --a------ C:\WINDOWS\system32\net1.exe
2007-04-09 23:44:12     46592 --a------ C:\WINDOWS\system32\net.exe
2007-04-09 23:44:12    155648 --a------ C:\WINDOWS\system32\NeroCheck.exe<NEROCH~1.EXE>
2007-04-09 23:44:12      8192 --a------ C:\WINDOWS\system32\nddeapir.exe
2007-04-09 23:44:11     25600 --a------ C:\WINDOWS\system32\nbtstat.exe
2007-04-09 23:44:11     58880 --a------ C:\WINDOWS\system32\narrator.exe
2007-04-09 23:44:11    412160 --a------ C:\WINDOWS\system32\mstsc.exe
2007-04-09 23:44:11     15872 --a------ C:\WINDOWS\system32\mstinit.exe
2007-04-09 23:44:11     10240 --a------ C:\WINDOWS\system32\msswchx.exe
2007-04-09 23:44:11    349184 --a------ C:\WINDOWS\system32\mspaint.exe
2007-04-09 23:44:11     82944 --a------ C:\WINDOWS\system32\msiexec.exe
2007-04-09 23:44:11     33280 --a------ C:\WINDOWS\system32\mshta.exe
2007-04-09 23:44:11    131584 --a------ C:\WINDOWS\system32\mshearts.exe
2007-04-09 23:44:11     26112 --a------ C:\WINDOWS\system32\msg.exe
2007-04-09 23:44:11      9728 --a------ C:\WINDOWS\system32\msdtc.exe
2007-04-09 23:44:09     17408 --a------ C:\WINDOWS\system32\mrinfo.exe
2007-04-09 23:44:09     25600 --a------ C:\WINDOWS\system32\mpnotify.exe
2007-04-09 23:44:09    128512 --a------ C:\WINDOWS\system32\mplay32.exe
2007-04-09 23:44:09     11776 --a------ C:\WINDOWS\system32\mountvol.exe
2007-04-09 23:44:09    147456 --a------ C:\WINDOWS\system32\mobsync.exe
2007-04-09 23:44:09     36864 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2007-04-09 23:44:09    819200 --a------ C:\WINDOWS\system32\mmc.exe
2007-04-09 23:44:09     55808 --a------ C:\WINDOWS\system32\migpwd.exe
2007-04-09 23:44:08     44544 --a------ C:\WINDOWS\system32\MAPISRVR.EXE
2007-04-09 23:44:07     89600 --a------ C:\WINDOWS\system32\makecab.exe
2007-04-09 23:44:07     76800 --a------ C:\WINDOWS\system32\magnify.exe
2007-04-09 23:44:07    376832 --a------ C:\WINDOWS\system32\lxcgih.exe
2007-04-09 23:44:07     11776 --a------ C:\WINDOWS\system32\lpr.exe
2007-04-09 23:44:07      9728 --a------ C:\WINDOWS\system32\lpq.exe
2007-04-09 23:44:07    519168 --a------ C:\WINDOWS\system32\logonui.exe
2007-04-09 23:44:07     19456 --a------ C:\WINDOWS\system32\logoff.exe
2007-04-09 23:44:07     64512 --a------ C:\WINDOWS\system32\logman.exe
2007-04-09 23:44:07    104448 --a------ C:\WINDOWS\system32\logagent.exe
2007-04-09 23:44:07      9216 --a------ C:\WINDOWS\system32\lodctr.exe
2007-04-09 23:44:07     79360 --a------ C:\WINDOWS\system32\locator.exe
2007-04-09 23:44:07     30208 --a------ C:\WINDOWS\system32\lnkstub.exe
2007-04-09 23:44:07     33792 --a------ C:\WINDOWS\system32\lights.exe
2007-04-09 23:44:06     13824 --a------ C:\WINDOWS\system32\label.exe
2007-04-09 23:44:06     27648 --a------ C:\WINDOWS\system32\ipxroute.exe
2007-04-09 23:44:06     57344 --a------ C:\WINDOWS\system32\ipv6.exe
2007-04-09 23:44:06     48640 --a------ C:\WINDOWS\system32\ipsec6.exe
2007-04-09 23:44:06     60928 --a------ C:\WINDOWS\system32\ipconfig.exe
2007-04-09 23:44:06   1219584 --a------ C:\WINDOWS\system32\IMMC.EXE
2007-04-09 23:44:05    153600 --a------ C:\WINDOWS\system32\imapi.exe
2007-04-09 23:44:05    118272 --a------ C:\WINDOWS\system32\iexpress.exe
2007-04-09 23:44:05     37888 --a------ C:\WINDOWS\system32\ie4uinit.exe
2007-04-09 23:44:05     11776 --a------ C:\WINDOWS\system32\hostname.exe
2007-04-09 23:44:05     18432 --a------ C:\WINDOWS\system32\help.exe
2007-04-09 23:44:05     43008 --a------ C:\WINDOWS\system32\grpconv.exe
2007-04-09 23:44:05     48128 --a------ C:\WINDOWS\system32\ftp.exe
2007-04-09 23:44:05     66560 --a------ C:\WINDOWS\system32\fsutil.exe
2007-04-09 23:44:05    196608 --a------ C:\WINDOWS\system32\fsquirt.exe
2007-04-09 23:44:05     59392 --a------ C:\WINDOWS\system32\freecell.exe
2007-04-09 23:44:05     10752 --a------ C:\WINDOWS\system32\forcedos.exe
2007-04-09 23:44:05     25088 --a------ C:\WINDOWS\system32\fontview.exe
2007-04-09 23:44:04     27136 --a------ C:\WINDOWS\system32\fltmc.exe
2007-04-09 23:44:04      7168 --a------ C:\WINDOWS\system32\fixmapi.exe
2007-04-09 23:44:04     13312 --a------ C:\WINDOWS\system32\finger.exe
2007-04-09 23:44:04     31744 --a------ C:\WINDOWS\system32\findstr.exe
2007-04-09 23:44:04     13312 --a------ C:\WINDOWS\system32\find.exe
2007-04-09 23:44:04     18944 --a------ C:\WINDOWS\system32\fc.exe
2007-04-09 23:44:04     25088 --a------ C:\WINDOWS\system32\faxpatch.exe
2007-04-09 23:44:04     49152 --a------ C:\WINDOWS\system32\extrac32.exe
2007-04-09 23:44:04     19968 --a------ C:\WINDOWS\system32\expand.exe
2007-04-09 23:44:04     12800 --a------ C:\WINDOWS\system32\eventvwr.exe
2007-04-09 23:44:04    198144 --a------ C:\WINDOWS\system32\eudcedit.exe
2007-04-09 23:44:03     43008 --a------ C:\WINDOWS\system32\esentutl.exe
2007-04-09 23:44:03     50176 --a------ C:\WINDOWS\system32\dxdllreg.exe
2007-04-09 23:44:03   1302528 --a------ C:\WINDOWS\system32\dxdiag.exe
2007-04-09 23:44:03    184320 --a------ C:\WINDOWS\system32\dwwin.exe
2007-04-09 23:44:03     21504 --a------ C:\WINDOWS\system32\dvdupgrd.exe
2007-04-09 23:44:03     61440 --a------ C:\WINDOWS\system32\dvdplay.exe
2007-04-09 23:44:03     14336 --a------ C:\WINDOWS\system32\dumprep.exe
2007-04-09 23:44:03     55296 --a------ C:\WINDOWS\system32\dumphive.exe
2007-04-09 23:44:03     50688 --a------ C:\WINDOWS\system32\drwtsn32.exe
2007-04-09 23:44:03    253440 --a------ C:\WINDOWS\system32\drmupgds.exe
2007-04-09 23:44:02     87040 --a------ C:\WINDOWS\system32\dpvsetup.exe
2007-04-09 23:44:02     22016 --a------ C:\WINDOWS\system32\dpnsvr.exe
2007-04-09 23:44:02     33792 --a------ C:\WINDOWS\system32\dplaysvr.exe
2007-04-09 23:44:02     14848 --a------ C:\WINDOWS\system32\doskey.exe
2007-04-09 23:44:02     19456 --a------ C:\WINDOWS\system32\dmremote.exe
2007-04-09 23:44:02    228864 --a------ C:\WINDOWS\system32\dmadmin.exe
2007-04-09 23:44:01      8704 --a------ C:\WINDOWS\system32\dllhst3g.exe
2007-04-09 23:43:46     22016 --a------ C:\WINDOWS\system32\diskperf.exe
2007-04-09 23:43:46    168448 --a------ C:\WINDOWS\system32\diskpart.exe
2007-04-09 23:43:46     89600 --a------ C:\WINDOWS\system32\diantz.exe
2007-04-09 23:43:45     86528 --a------ C:\WINDOWS\system32\dfrgfat.exe
2007-04-09 23:43:45     28672 --a------ C:\WINDOWS\system32\defrag.exe
2007-04-09 23:43:45     34816 --a------ C:\WINDOWS\system32\ddeshare.exe
2007-04-09 23:43:45      8704 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2007-04-09 23:43:45    102400 --a------ C:\WINDOWS\system32\cscript.exe
2007-04-09 23:43:45     17920 --a------ C:\WINDOWS\system32\convert.exe
2007-04-09 23:43:45     11776 --a------ C:\WINDOWS\system32\control.exe
2007-04-09 23:43:45     31232 --a------ C:\WINDOWS\system32\conime.exe
2007-04-09 23:43:44     21504 --a------ C:\WINDOWS\system32\compact.exe
2007-04-09 23:43:44     19968 --a------ C:\WINDOWS\system32\comp.exe
2007-04-09 23:43:44     68096 --a------ C:\WINDOWS\system32\cmstp.exe
2007-04-09 23:43:44     43008 --a------ C:\WINDOWS\system32\cmmon32.exe
2007-04-09 23:43:44     50688 --a------ C:\WINDOWS\system32\cmdl32.exe
2007-04-09 23:43:44    399360 --a------ C:\WINDOWS\system32\cmd.exe
2007-04-09 23:43:44     37376 --a------ C:\WINDOWS\system32\clipsrv.exe
2007-04-09 23:43:44    107520 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-04-09 23:43:44     24576 --a------ C:\WINDOWS\system32\cliconfg.exe
2007-04-09 23:43:43     68608 --a------ C:\WINDOWS\system32\cleanmgr.exe
2007-04-09 23:43:43     11776 --a------ C:\WINDOWS\system32\ckcnv.exe
2007-04-09 23:43:43      9728 --a------ C:\WINDOWS\system32\cisvc.exe
2007-04-09 23:43:43     12288 --a------ C:\WINDOWS\system32\cidaemon.exe
2007-04-09 23:43:43     15360 --a------ C:\WINDOWS\system32\chkntfs.exe
2007-04-09 23:43:43     15872 --a------ C:\WINDOWS\system32\chkdsk.exe
2007-04-09 23:43:43     84480 --a------ C:\WINDOWS\system32\charmap.exe
2007-04-09 23:43:43    118784 --a------ C:\WINDOWS\system32\calc.exe
2007-04-09 23:43:43     23040 --a------ C:\WINDOWS\system32\cacls.exe
2007-04-09 23:43:42      8704 --a------ C:\WINDOWS\system32\bootvrfy.exe
2007-04-09 23:43:42      8192 --a------ C:\WINDOWS\system32\bootok.exe
2007-04-09 23:43:42     75264 --a------ C:\WINDOWS\system32\blastcln.exe
2007-04-09 23:43:42     14848 --a------ C:\WINDOWS\system32\autolfn.exe
2007-04-09 23:43:42    606208 --a------ C:\WINDOWS\system32\autofmt.exe
2007-04-09 23:43:41    627712 --a------ C:\WINDOWS\system32\autoconv.exe
2007-04-09 23:43:41    613888 --a------ C:\WINDOWS\system32\autochk.exe
2007-04-09 23:43:41     18432 --a------ C:\WINDOWS\system32\auditusr.exe
2007-04-09 23:43:41     15360 --a------ C:\WINDOWS\system32\attrib.exe
2007-04-09 23:43:41     14848 --a------ C:\WINDOWS\system32\atmadm.exe
2007-04-09 23:43:41    348160 --a------ C:\WINDOWS\system32\atiptaxx.exe
2007-04-09 23:43:41     65536 --a------ C:\WINDOWS\system32\atiphexx.exe
2007-04-09 23:43:40     45056 --a------ C:\WINDOWS\system32\atiiprxx.exe
2007-04-09 23:43:40   1835008 --a------ C:\WINDOWS\system32\atiadaxx.exe
2007-04-09 23:43:40    520192 --a------ C:\WINDOWS\system32\ati2sgag.exe
2007-04-09 23:43:40     28672 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
2007-04-09 23:43:40     29184 --a------ C:\WINDOWS\system32\at.exe
2007-04-09 23:43:40     23552 --a------ C:\WINDOWS\system32\arp.exe
2007-04-09 23:43:40     48128 --a------ C:\WINDOWS\system32\alg.exe
2007-04-09 23:43:40    102400 --a------ C:\WINDOWS\system32\ahui.exe
2007-04-09 23:43:39      8192 --a------ C:\WINDOWS\system32\actmovie.exe
2007-04-09 23:43:39    191488 --a------ C:\WINDOWS\system32\accwiz.exe
2007-04-09 23:43:39     20480 --a------ C:\WINDOWS\system32\ac3config.exe<AC3CON~1.EXE>
2007-04-09 23:43:39     76800 --a------ C:\WINDOWS\ST6UNST.EXE
2007-04-09 23:43:38     36864 --a------ C:\WINDOWS\slrundll.exe
2007-04-09 23:43:38    253952 --a------ C:\WINDOWS\Setup1.exe
2007-04-09 23:43:00    153088 --a------ C:\WINDOWS\regedit.exe
2007-04-09 23:42:52     73728 --a------ C:\WINDOWS\notepad.exe
2007-04-09 23:42:51    724992 --a------ C:\WINDOWS\iun6002ev.exe<IUN600~1.EXE>
2007-04-09 23:42:51    310272 --a------ C:\WINDOWS\IsUninst.exe
2007-04-09 23:42:51    330752 --a------ C:\WINDOWS\IsUn0415.exe
2007-04-09 23:42:46     14336 --a------ C:\WINDOWS\hh.exe
2007-04-09 23:42:42     98304 --a------ C:\WINDOWS\DIIUnin.exe
2007-04-09 23:42:42    270336 --a------ C:\WINDOWS\CMIUninstall.exe<CMIUNI~1.EXE>
2007-04-09 23:42:42    229376 --a------ C:\WINDOWS\CmiRmRedundDir.exe<CMIRMR~1.EXE>
2007-04-09 23:42:41     37888 --a------ C:\WINDOWS\BitTorrentAbsoluteDownloader.exe<BITTOR~1.EXE>
2007-04-09 23:41:25     30208 --a------ C:\setup.exe
2007-04-09 23:36:05     38400 --ahs---- C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe<YAZZLE~2.EXE>
2007-04-09 23:36:05    161280 --ahs---- C:\Program Files\Common Files\Yazzle1122OinAdmin.exe<YAZZLE~1.EXE>
2007-04-09 23:34:31    355486 --a------ C:\WINDOWS\system32\perfh015.dat
2007-04-09 23:34:31     49492 --a------ C:\WINDOWS\system32\perfc015.dat
2007-04-09 22:55:34         0 d-------- C:\Program Files\BearShare<BEARSH~1>
2007-04-08 19:31:05         0 d-------- C:\Program Files\InetGet2
2007-04-08 15:03:07    828444 --a------ C:\Documents and Settings\mateusz cybulski\Dane aplikacji\Dxcknwrd.dll
2007-04-08 15:00:43         0 d-------- C:\Program Files\Windows NT<WINDOW~1>
2007-04-06 23:45:17         0 d-------- C:\Program Files\NAPI-PROJEKT<NAPI-P~1>
2007-04-06 19:57:29         0 d-------- C:\Program Files\Gadu-Gadu<GADU-G~1>
2007-03-25 22:30:41         0 d-------- C:\Documents and Settings\mateusz cybulski\Dane aplikacji\Arcsoft
2007-03-22 11:52:49       341 --a------ C:\WINDOWS\system32\lsprst7.dll
2007-03-22 11:52:48        73 --a------ C:\WINDOWS\system32\ssprs.dll
2007-03-08 17:38:47    579072 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:38:47     40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:38:47    281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:37:33   1843840 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-03 23:11:59         0 d-------- C:\Program Files\Valve
2007-03-03 23:06:32         0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-03-03 23:06:24         0 d-------- C:\Program Files\PowerQuest<POWERQ~1>
2007-03-03 22:16:20         0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-03-03 22:16:18         0 d-------- C:\Program Files\Symantec
2007-03-03 22:15:07         0 d-------- C:\Program Files\Kaspersky Lab<KASPER~1>
2007-03-03 22:15:05         0 d-------- C:\Program Files\Common Files\Kaspersky Lab<KASPER~1>
2007-03-03 21:50:32         0 d-------- C:\Program Files\Norton AntiVirus<NORTON~1>
2007-03-03 14:13:48         0 d-------- C:\Program Files\ATI Technologies<ATITEC~1>
2007-03-03 14:10:43         0 d-------- C:\Program Files\C-Media 3D Audio<C-MEDI~1>
2007-02-23 00:06:17         0 d-------- C:\Program Files\DC++<DC__~1>
2007-02-21 19:23:54         0 d-------- C:\Program Files\The All-Seeing Eye<THEALL~1>


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Steam"="\"C:\\Program Files\\Valve\\Steam\\Steam.exe\" -silent"
"Gadu-Gadu"="\"C:\\Program Files\\Gadu-Gadu\\gg.exe\" /tray"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"lxcgmon.exe"="\"C:\\Program Files\\Lexmark 2300 Series\\lxcgmon.exe\""
"EzPrint"="\"C:\\Program Files\\Lexmark 2300 Series\\ezprint.exe\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BearShare"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
   

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB7-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB7-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB3-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB3-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB7-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB7-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"
"{5830E138-0BB3-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB3-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
   Source   REG_SZ            http://www.portal24h.pl/humor/dyplomy/palenie_trawy.jpg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService   REG_MULTI_SZ      Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService   REG_MULTI_SZ      DnsCache\0\0
rpcss   REG_MULTI_SZ      RpcSs\0\0
imgsvc   REG_MULTI_SZ      StiSvc\0\0
termsvcs   REG_MULTI_SZ      TermService\0\0
HTTPFilter   REG_MULTI_SZ      HTTPFilter\0\0
DcomLaunch   REG_MULTI_SZ      DcomLaunch\0TermService\0\0
WudfServiceGroup   REG_MULTI_SZ      WUDFSvc\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{58b1faeb-8c0c-11da-9af0-806d6172696f}]
Shell\AutoRun\command   D:\AutoRun.exe

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{58b1faec-8c0c-11da-9af0-806d6172696f}]
Shell\AutoRun\command   C:\setup.exe


-- End of ComboScan: finished at 2007-04-09 at 23:52:45 ------------------------



[ Dodano: Dzisiaj o 23:23 ]
po ktorejsc z czynnosci-chyba fixwareout pojawil mi sie komunikat:

16-bitowy podsystem MS-DOS

dl.exe
NTVDM CPU: napotkano niedozwoloną instrulcję.
CS:06e8 IP:fff6 OP:ff f9 ff ff 00 Wybierz przycisk "zamknij"
abe zakonczyc dzialanie aplikacji.


uruchamia sie to przy dzialaniu roznych aplikancji-gier itp.

net ogolnie tez baaardzo sie zwalil-nie chce wykonywac polecen, bardzo wolno wszystko sie dzieje.
NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA



Postprzez wojtas 10 Kwi 2007, 11:01

Użyj WWDC :
http://www.firewallleaktester.com/wwdc.htm
Zmień opcje z disable na enable. Uruchom ponownie komputer.
Tak powinny wyglądać porty (NetBIOS może być żółty) :
http://www.firewallleaktester.com/images_site/wwdc.jpg

czy ty nie mozesz skasowac tych wpisow:

O17 - HKLM\System\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184


czy kasujesz a one dalej sa?

sciagnij gmera:

http://gmer.net/gmer.zip

W Gmerze w zakładce CMD z zaznaczoną opcją CMD.EXE wklej:

gmer -killall
gmer -del file C:\WINDOWS\system32\4369.bat
gmer -del file C:\WINDOWS\system32\unsvchosts.exe
gmer -del file C:\WINDOWS\system32\svchosts.exe
gmer -del file C:\WINDOWS\system32\install.exe
gmer -del file C:\WINDOWS\VTTC.exe
gmer -del file C:\WINDOWS\system32\sporder.dll
gmer -del file C:\WINDOWS\system32\micro1
gmer -del file C:\WINDOWS\system32\bund1
gmer -del file C:\WINDOWS\system32\app.exe
gmer -del file C:\WINDOWS\system32\setup9x.exe
gmer -del file C:\WINDOWS\system32\vbzip10.dll
gmer -del file C:\WINDOWS\111uninst.exe
gmer -del file C:\WINDOWS\uni_eh10.exe
gmer -del file C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
gmer -del file C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
gmer –reboot


I kliknij z prawej strony na Uruchom.

wklej do notatnika:

Windows Registry Editor Version 5.00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB7-1045-0201-050403250030}"=-

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB7-1045-0201-050403250030}"=-


w notatniku u góry>>>plik zapisz jako>>>Zmien rozszerzenie z TXT na Wszystkie pliki *.* >>> Zapisz pod nazwą FIX.REG

Klikasz dwa razy na powstały plik fix i dodajesz go do rejestru....

odpal SmitfraudFix z opcji 2

http://siri.urz.free.fr/Fix/SmitfraudFix.php
opis >>

http://forum.programosy.pl/trudne-przypadki-i-metody-usuwania-vt41947.html

i przejedź nim dysk


potem nowy log z comboscana
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez kybula 10 Kwi 2007, 13:58

nic nie dziala na tym kompie juz.:( IE wogole nie chodzi, mozzila sie wali-nie wykonuje zadnych polecen...

jesszcze pojawil mi sie komunikat zamykania systemu-odlicza 60 sec i zamyka system-ale go przechytrzylem i cofnalem czas w panelu sterowania o pare godzin-dzieje sie tak jak zamykam proces svchost.exe

tamte logi w hijack this zawsze kasuje-ale pojawiaja sie od nowa.
comboscan tez zaza wariowac-twierdzi ze nie ma hijackthis na kompie-jak mu pokazuje gdzie to twoerdzi ze nie o taki mu chodzilo-kiedy klikam zeby sam sobie pobral to tez blad, ja nie moge prawie na nic wejsc...

combo:

Kod: Zaznacz wszystko
ComboScan v20070306.20 run by mateusz cybulski on 2007-04-10 at 13:34:25
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis Clone ------------------------------------------------------------

Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-04-10 06:41:29
Platform: Windows XP Dodatek Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.0.2900.2180)

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\CPUCooL\CooLSRV.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BearShare\BearShare.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mateusz cybulski\Pulpit\comboscan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mateusz cybulski\Pulpit\comboscan-1.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\BenQ\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\NPJPI150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\NPJPI150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{2B5EF327-9852-4281-9BD9-A5F78737EB6F}: NameServer = 85.255.116.101 85.255.112.184
O20 - Winlogon Notify: AtiExtEvent - C:\WINDOWS\system32\Ati2evxx.dll
O23 - Service: Urządzenie alarmowe (Alerter) - C:\WINDOWS\System32\svchost.exe -k LocalService
O23 - Service: Usługa bramy warstwy aplikacji (ALG) - C:\WINDOWS\system32\alg.exe
O23 - Service: Zarządzanie aplikacjami (AppMgmt) - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Ati HotKey Poller - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: ATI Smart - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Windows Audio (AudioSrv) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Usługa inteligentnego transferu w tle (BITS) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Przeglądarka komputera (Browser) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Usługa indeksowania (CiSvc) - C:\WINDOWS\system32\cisvc.exe
O23 - Service: Client IP-IPX - "C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137
O23 - Service: ClipBook (ClipSrv) - C:\WINDOWS\system32\clipsrv.exe
O23 - Service: Aplikacja systemowa modelu COM+ (COMSysApp) - C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
O23 - Service: CPUCooLServer Service (CPUCooLServer) - "C:\Program Files\CPUCooL\CooLSrv.exe"
O23 - Service: Usługi kryptograficzne (CryptSvc) - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Program uruchamiający proces serwera DCOM (DcomLaunch) - C:\WINDOWS\system32\svchost -k DcomLaunch
O23 - Service: Klient DHCP (Dhcp) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Usługa administracyjna Menedżera dysków logicznych (dmadmin) - C:\WINDOWS\System32\dmadmin.exe /com
O23 - Service: Menedżer dysków logicznych (dmserver) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Klient DNS (Dnscache) - C:\WINDOWS\System32\svchost.exe -k NetworkService
O23 - Service: Usługa raportowania błędów (ERSvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Dziennik zdarzeń (Eventlog) - C:\WINDOWS\system32\services.exe
O23 - Service: System zdarzeń COM+ (EventSystem) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Zgodność szybkiego przełączania użytkowników (FastUserSwitchingCompatibility) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Pomoc i obsługa techniczna (helpsvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Dostęp do urządzeń interfejsu HID (HidServ) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: HTTP SSL (HTTPFilter) - C:\WINDOWS\System32\svchost.exe -k HTTPFilter
O23 - Service: InstallDriver Table Manager (IDriverT) - "C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"
O23 - Service: Usługa COM nagrywania dysków CD IMAPI (ImapiService) - C:\WINDOWS\system32\imapi.exe
O23 - Service: Serwer (lanmanserver) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Stacja robocza (lanmanworkstation) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Pomoc TCP/IP NetBIOS (LmHosts) - C:\WINDOWS\System32\svchost.exe -k LocalService
O23 - Service: lxcg_device - C:\WINDOWS\system32\lxcgcoms.exe -service
O23 - Service: Posłaniec (Messenger) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Distributed Transaction Coordinator (MSDTC) - C:\WINDOWS\system32\msdtc.exe
O23 - Service: Instalator Windows (MSIServer) - C:\WINDOWS\system32\msiexec.exe /V
O23 - Service: DDE sieci (NetDDE) - C:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE sieci (NetDDEdsdm) - C:\WINDOWS\system32\netdde.exe
O23 - Service: Logowanie do sieci (Netlogon) - C:\WINDOWS\system32\lsass.exe
O23 - Service: Połączenia sieciowe (Netman) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Rozpoznawanie lokalizacji w sieci (NLA) (Nla) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Usługa NT LM Security Support Provider (NtLmSsp) - C:\WINDOWS\system32\lsass.exe
O23 - Service: Magazyn wymienny (NtmsSvc) - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Plug and Play (PlugPlay) - C:\WINDOWS\system32\services.exe
O23 - Service: Usługi IPSEC (PolicyAgent) - C:\WINDOWS\system32\lsass.exe
O23 - Service: Magazyn chroniony (ProtectedStorage) - C:\WINDOWS\system32\lsass.exe
O23 - Service: Menedżer autopołączenia dostępu zdalnego (RasAuto) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Menedżer połączeń usługi Dostęp zdalny (RasMan) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Menedżer sesji pomocy pulpitu zdalnego (RDSessMgr) - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Routing i dostęp zdalny (RemoteAccess) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Lokalizator usługi zdalnego wywołania procedury (RPC) (RpcLocator) - C:\WINDOWS\system32\locator.exe
O23 - Service: Zdalne wywoływanie procedur (RPC) (RpcSs) - C:\WINDOWS\system32\svchost -k rpcss
O23 - Service: QoS RSVP (RSVP) - C:\WINDOWS\system32\rsvp.exe
O23 - Service: Menedżer kont zabezpieczeń (SamSs) - C:\WINDOWS\system32\lsass.exe
O23 - Service: Karta inteligentna (SCardSvr) - C:\WINDOWS\system32\scardsvr.exe
O23 - Service: Harmonogram zadań (Schedule) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Logowanie pomocnicze (seclogon) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Zawiadomienie o zdarzeniu systemowym (SENS) - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Wykrywanie sprzętu powłoki (ShellHWDetection) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Bufor wydruku (Spooler) - C:\WINDOWS\system32\spoolsv.exe
O23 - Service: Usługa przywracania systemu (srservice) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Usługa odnajdywania SSDP (SSDPSRV) - C:\WINDOWS\System32\svchost.exe -k LocalService
O23 - Service: StarWind iSCSI Service (StarWindService) - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Image Acquisition (WIA) (stisvc) - C:\WINDOWS\System32\svchost.exe -k imgsvc
O23 - Service: MS Software Shadow Copy Provider (SwPrv) - C:\WINDOWS\System32\dllhost.exe /Processid:{991777BD-563B-4BAE-BF31-E38638D90D3F}
O23 - Service: SymWMI Service (SymWSC) - "C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe"
O23 - Service: Dzienniki wydajności i alerty (SysmonLog) - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Telefonia (TapiSrv) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Usługi terminalowe (TermService) - C:\WINDOWS\System32\svchost -k DComLaunch
O23 - Service: Kompozycje (Themes) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Klient śledzenia łączy rozproszonych (TrkWks) - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Host uniwersalnego urządzenia Plug and Play (upnphost) - C:\WINDOWS\System32\svchost.exe -k LocalService
O23 - Service: Zasilacz awaryjny (UPS) (UPS) - C:\WINDOWS\system32\ups.exe
O23 - Service: Kopiowanie woluminów w tle (VSS) - C:\WINDOWS\system32\vssvc.exe
O23 - Service: Usługa Czas systemu Windows (W32Time) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: WebClient - C:\WINDOWS\System32\svchost.exe -k LocalService
O23 - Service: Windows Defender (WinDefend) - "C:\Program Files\Windows Defender\MsMpEng.exe"
O23 - Service: Instrumentacja zarządzania Windows (winmgmt) - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Usługa numeru seryjnego multimediów przenośnych (WmdmPmSN) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Karta wydajności WMI (WmiApSrv) - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Usługa udostępniania w sieci programu Windows Media Player (WMPNetworkSvc) - "C:\Program Files\Windows Media Player\WMPNetwk.exe"
O23 - Service: Centrum zabezpieczeń (wscsvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Aktualizacje automatyczne (wuauserv) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Windows Driver Foundation - User-mode Driver Framework (WudfSvc) - C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
O23 - Service: Konfiguracja zerowej sieci bezprzewodowej (WZCSVC) - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Usługa dostarczania sieci (xmlprov) - C:\WINDOWS\System32\svchost.exe -k netsvcs


-- Files created between 2007-03-10 and 2007-04-10 -----------------------------

2007-04-10 12:52:31        80 --a------ C:\WINDOWS\gmer_uninstall.cmd<GMER_U~1.CMD>
2007-04-08 15:00:26     72320 --a------ C:\WINDOWS\system32\drivers\core.sys
2007-04-08 15:00:25         0 d-a------ C:\WINDOWS\system32\micro1
2007-04-08 15:00:16         0 d-a------ C:\WINDOWS\system32\bund1
2007-04-08 15:00:05         0 --a------ C:\WINDOWS\system32\taskkill.exe
2007-03-29 11:49:47         0 d-------- C:\Program Files\Windows Defender<WIFD1F~1>
2007-03-24 19:33:27         0 d-------- C:\Program Files\Gothic III<GOTHIC~1>
2007-03-24 11:21:28         0 d-------- C:\Program Files\Windows Media Connect 2<WINDOW~4>
2007-03-24 11:18:55         0 d-------- C:\WINDOWS\system32\LogFiles
2007-03-24 11:18:55         0 d-------- C:\WINDOWS\system32\drivers\UMDF


-- Find3M Report ---------------------------------------------------------------

2007-04-10 13:36:13     30208 --a------ C:\setup.exe
2007-04-10 13:31:04    355486 --a------ C:\WINDOWS\system32\perfh015.dat
2007-04-10 13:31:04     49492 --a------ C:\WINDOWS\system32\perfc015.dat
2007-04-10 13:24:58      2222 --a------ C:\WINDOWS\system32\tmp.reg
2007-04-10 12:42:50     17408 --a------ C:\WINDOWS\system32\wscntfy.exe
2007-04-10 12:42:38    348160 --a------ C:\WINDOWS\system32\ati2evxx.exe
2007-04-10 12:37:11         0 d-------- C:\Program Files\Mozilla Firefox<MOZILL~1>
2007-04-10 00:23:49     73728 --a------ C:\WINDOWS\system32\notepad.exe
2007-04-09 23:44:31    289280 --a------ C:\WINDOWS\winhlp32.exe
2007-04-09 23:44:31   2027520 --a------ C:\WINDOWS\UNNeroVision.exe<UNNERO~1.EXE>
2007-04-09 23:44:31    103936 --a------ C:\WINDOWS\UninstallFirefox.exe<UNINST~1.EXE>
2007-04-09 23:44:31    287744 --a------ C:\WINDOWS\unin0407.exe
2007-04-09 23:44:31     29184 --a------ C:\WINDOWS\twunk_32.exe
2007-04-09 23:44:30     19456 --a------ C:\WINDOWS\TASKMAN.EXE
2007-04-09 23:44:30    857600 --a------ C:\WINDOWS\system32\XMNT2002.exe
2007-04-09 23:44:30     30208 --a------ C:\WINDOWS\system32\xmlinst.exe
2007-04-09 23:44:30     34816 --a------ C:\WINDOWS\system32\xcopy.exe
2007-04-09 23:44:30     36352 --a------ C:\WINDOWS\system32\wupdmgr.exe
2007-04-09 23:44:30    150528 --a------ C:\WINDOWS\system32\WudfHost.exe
2007-04-09 23:44:30    172544 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-04-09 23:44:30    118784 --a------ C:\WINDOWS\system32\wscript.exe
2007-04-09 23:44:29      9216 --a------ C:\WINDOWS\system32\write.exe
2007-04-09 23:44:29     36352 --a------ C:\WINDOWS\system32\wpnpinst.exe
2007-04-09 23:44:29     20992 --a------ C:\WINDOWS\system32\wpdshextautoplay.exe<WPDSHE~1.EXE>
2007-04-09 23:44:29     35840 --a------ C:\WINDOWS\system32\wpabaln.exe
2007-04-09 23:44:29     77824 --a------ C:\WINDOWS\system32\wmpstub.exe
2007-04-09 23:44:29      9216 --a------ C:\WINDOWS\system32\winver.exe
2007-04-09 23:44:29     15360 --a------ C:\WINDOWS\system32\winmsd.exe
2007-04-09 23:44:29    123904 --a------ C:\WINDOWS\system32\winmine.exe
2007-04-09 23:44:29     11776 --a------ C:\WINDOWS\system32\winhlp32.exe
2007-04-09 23:44:29     38912 --a------ C:\WINDOWS\system32\winchat.exe
2007-04-09 23:44:29    439296 --a------ C:\WINDOWS\system32\wiaacmgr.exe
2007-04-09 23:44:28     69632 --a------ C:\WINDOWS\system32\wextract.exe
2007-04-09 23:44:28     12288 --a------ C:\WINDOWS\system32\wdfmgr.exe
2007-04-09 23:44:28     54784 --a------ C:\WINDOWS\system32\w32tm.exe
2007-04-09 23:44:28    295936 --a------ C:\WINDOWS\system32\vssvc.exe
2007-04-09 23:44:27     37888 --a------ C:\WINDOWS\system32\vssadmin.exe
2007-04-09 23:44:27    105984 --a------ C:\WINDOWS\system32\verifier.exe
2007-04-09 23:44:27     32768 --a------ C:\WINDOWS\system32\verclsid.exe
2007-04-09 23:44:27     12288 --a------ C:\WINDOWS\system32\uwdf.exe
2007-04-09 23:44:27     53760 --a------ C:\WINDOWS\system32\utilman.exe
2007-04-09 23:44:27     73728 --a------ C:\WINDOWS\system32\usrshuta.exe
2007-04-09 23:44:27     65536 --a------ C:\WINDOWS\system32\usrprbda.exe
2007-04-09 23:44:27     81920 --a------ C:\WINDOWS\system32\usrmlnka.exe
2007-04-09 23:44:27     28672 --a------ C:\WINDOWS\system32\userinit.exe
2007-04-09 23:44:26     22528 --a------ C:\WINDOWS\system32\ups.exe
2007-04-09 23:44:26     20480 --a------ C:\WINDOWS\system32\upnpcont.exe
2007-04-09 23:44:26      8192 --a------ C:\WINDOWS\system32\unlodctr.exe
2007-04-09 23:44:26     64000 --a------ C:\WINDOWS\system32\tzchange.exe
2007-04-09 23:44:26     21504 --a------ C:\WINDOWS\system32\tsshutdn.exe
2007-04-09 23:44:26     20480 --a------ C:\WINDOWS\system32\tskill.exe
2007-04-09 23:44:26     18944 --a------ C:\WINDOWS\system32\tsdiscon.exe
2007-04-09 23:44:26     48128 --a------ C:\WINDOWS\system32\tscupgrd.exe
2007-04-09 23:44:26     18944 --a------ C:\WINDOWS\system32\tscon.exe
2007-04-09 23:44:26     35840 --a------ C:\WINDOWS\system32\tracert6.exe
2007-04-09 23:44:26     16896 --a------ C:\WINDOWS\system32\tracert.exe
2007-04-09 23:44:26    350720 --a------ C:\WINDOWS\system32\tourstart.exe<TOURST~1.EXE>
2007-04-09 23:44:26     20992 --a------ C:\WINDOWS\system32\tftp.exe
2007-04-09 23:44:25     81920 --a------ C:\WINDOWS\system32\telnet.exe
2007-04-09 23:44:25     23552 --a------ C:\WINDOWS\system32\tcpsvcs.exe
2007-04-09 23:44:25     16896 --a------ C:\WINDOWS\system32\tcmsetup.exe
2007-04-09 23:44:25    143360 --a------ C:\WINDOWS\system32\taskmgr.exe
2007-04-09 23:44:25     19456 --a------ C:\WINDOWS\system32\taskman.exe
2007-04-09 23:44:25      7168 --a------ C:\WINDOWS\system32\systray.exe
2007-04-09 23:44:25    110592 --a------ C:\WINDOWS\system32\sysocmgr.exe
2007-04-09 23:44:25     40960 --a------ C:\WINDOWS\system32\syskey.exe
2007-04-09 23:44:25     54784 --a------ C:\WINDOWS\system32\syncapp.exe
2007-04-09 23:44:25     13312 --a------ C:\WINDOWS\system32\subst.exe
2007-04-09 23:44:25     28672 --a------ C:\WINDOWS\system32\stup3.exe
2007-04-09 23:44:25     18432 --a------ C:\WINDOWS\system32\stimon.exe
2007-04-09 23:44:24     25088 --a------ C:\WINDOWS\system32\spupdwxp.exe
2007-04-09 23:44:24     20992 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-04-09 23:44:24     13824 --a------ C:\WINDOWS\system32\sprestrt.exe
2007-04-09 23:44:22     15360 --a------ C:\WINDOWS\system32\spnpinst.exe
2007-04-09 23:44:22    542720 --a------ C:\WINDOWS\system32\spider.exe
2007-04-09 23:44:22     11776 --a------ C:\WINDOWS\system32\spdwnwxp.exe
2007-04-09 23:44:22     27648 --a------ C:\WINDOWS\system32\sort.exe
2007-04-09 23:44:22     60928 --a------ C:\WINDOWS\system32\sol.exe
2007-04-09 23:44:22    143360 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-04-09 23:44:22    136192 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-04-09 23:44:22     94720 --a------ C:\WINDOWS\system32\smlogsvc.exe
2007-04-09 23:44:22     11776 --a------ C:\WINDOWS\system32\smbinst.exe
2007-04-09 23:44:22     77824 --a------ C:\WINDOWS\system32\slserv.exe
2007-04-09 23:44:22     36864 --a------ C:\WINDOWS\system32\slrundll.exe
2007-04-09 23:44:22     30208 --a------ C:\WINDOWS\system32\skeys.exe
2007-04-09 23:44:22     74752 --a------ C:\WINDOWS\system32\sigverif.exe
2007-04-09 23:44:21     24064 --a------ C:\WINDOWS\system32\shutdown.exe
2007-04-09 23:44:21     81920 --a------ C:\WINDOWS\system32\shrpubw.exe
2007-04-09 23:44:21     46080 --a------ C:\WINDOWS\system32\shmgrate.exe
2007-04-09 23:44:21     18944 --a------ C:\WINDOWS\system32\shadow.exe
2007-04-09 23:44:21     13824 --a------ C:\WINDOWS\system32\sfc.exe
2007-04-09 23:44:21     26624 --a------ C:\WINDOWS\system32\setup.exe
2007-04-09 23:44:21     36352 --a------ C:\WINDOWS\system32\sethc.exe
2007-04-09 23:44:21    145408 --a------ C:\WINDOWS\system32\sessmgr.exe
2007-04-09 23:44:21     81408 --a------ C:\WINDOWS\system32\sdbinst.exe
2007-04-09 23:44:21    101888 --a------ C:\WINDOWS\system32\scardsvr.exe
2007-04-09 23:44:21     34816 --a------ C:\WINDOWS\system32\sc.exe
2007-04-09 23:44:21     17408 --a------ C:\WINDOWS\system32\savedump.exe
2007-04-09 23:44:20     19968 --a------ C:\WINDOWS\system32\rwinsta.exe
2007-04-09 23:44:20     17920 --a------ C:\WINDOWS\system32\runonce.exe
2007-04-09 23:44:20     36864 --a------ C:\WINDOWS\system32\rundll32.exe
2007-04-09 23:44:20     20992 --a------ C:\WINDOWS\system32\runas.exe
2007-04-09 23:44:20     81408 --a------ C:\WINDOWS\system32\rtcshare.exe
2007-04-09 23:44:20    136704 --a------ C:\WINDOWS\system32\rsvp.exe
2007-04-09 23:44:20     52736 --a------ C:\WINDOWS\system32\rsmui.exe
2007-04-09 23:44:20     28160 --a------ C:\WINDOWS\system32\rsmsink.exe
2007-04-09 23:44:20     57856 --a------ C:\WINDOWS\system32\rsm.exe
2007-04-09 23:44:20     18944 --a------ C:\WINDOWS\system32\rsh.exe
2007-04-09 23:44:20     29184 --a------ C:\WINDOWS\system32\routemon.exe
2007-04-09 23:44:19     24064 --a------ C:\WINDOWS\system32\route.exe
2007-04-09 23:44:19     17920 --a------ C:\WINDOWS\system32\rexec.exe
2007-04-09 23:44:19     13824 --a------ C:\WINDOWS\system32\reset.exe
2007-04-09 23:44:19     16896 --a------ C:\WINDOWS\system32\replace.exe
2007-04-09 23:44:16      8192 --a------ C:\WINDOWS\system32\regwiz.exe
2007-04-09 23:44:16     15872 --a------ C:\WINDOWS\system32\regsvr32.exe
2007-04-09 23:44:16     37888 --a------ C:\WINDOWS\system32\regini.exe
2007-04-09 23:44:16      7168 --a------ C:\WINDOWS\system32\regedt32.exe
2007-04-09 23:44:16     56832 --a------ C:\WINDOWS\system32\reg.exe
2007-04-09 23:44:16     11264 --a------ C:\WINDOWS\system32\recover.exe
2007-04-09 23:44:16     70656 --a------ C:\WINDOWS\system32\rdshost.exe
2007-04-09 23:44:16     17408 --a------ C:\WINDOWS\system32\rdsaddin.exe
2007-04-09 23:44:16     66560 --a------ C:\WINDOWS\system32\rdpclip.exe
2007-04-09 23:44:16     25600 --a------ C:\WINDOWS\system32\rcp.exe
2007-04-09 23:44:16     39424 --a------ C:\WINDOWS\system32\rcimlby.exe
2007-04-09 23:44:15     60416 --a------ C:\WINDOWS\system32\rasphone.exe
2007-04-09 23:44:15     15360 --a------ C:\WINDOWS\system32\rasdial.exe
2007-04-09 23:44:15     15360 --a------ C:\WINDOWS\system32\rasautou.exe
2007-04-09 23:44:15     26624 --a------ C:\WINDOWS\system32\qwinsta.exe
2007-04-09 23:44:15     24576 --a------ C:\WINDOWS\system32\qprocess.exe
2007-04-09 23:44:15     20992 --a------ C:\WINDOWS\system32\qappsrv.exe
2007-04-09 23:44:15     13312 --a------ C:\WINDOWS\system32\proxycfg.exe
2007-04-09 23:44:15     54272 --a------ C:\WINDOWS\system32\proquota.exe
2007-04-09 23:44:15    113152 --a------ C:\WINDOWS\system32\progman.exe
2007-04-09 23:44:15     13312 --a------ C:\WINDOWS\system32\print.exe
2007-04-09 23:44:15     52736 --a------ C:\WINDOWS\system32\powercfg.exe
2007-04-09 23:44:15     37376 --a------ C:\WINDOWS\system32\ping6.exe
2007-04-09 23:44:15     22528 --a------ C:\WINDOWS\system32\ping.exe
2007-04-09 23:44:14     19456 --a------ C:\WINDOWS\system32\perfmon.exe
2007-04-09 23:44:14     18944 --a------ C:\WINDOWS\system32\pentnt.exe
2007-04-09 23:44:14     26112 --a------ C:\WINDOWS\system32\pathping.exe
2007-04-09 23:44:14     62976 --a------ C:\WINDOWS\system32\packager.exe
2007-04-09 23:44:14     45056 --a------ C:\WINDOWS\system32\osuninst.exe
2007-04-09 23:44:14    220160 --a------ C:\WINDOWS\system32\osk.exe
2007-04-09 23:44:13     73728 --a------ C:\WINDOWS\system32\odbcconf.exe
2007-04-09 23:44:13     36864 --a------ C:\WINDOWS\system32\odbcad32.exe
2007-04-09 23:44:13    423936 --a------ C:\WINDOWS\system32\ntvdm.exe
2007-04-09 23:44:13     35328 --a------ C:\WINDOWS\system32\ntsd.exe
2007-04-09 23:44:12     83456 --a------ C:\WINDOWS\system32\nslookup.exe
2007-04-09 23:44:12     41984 --a------ C:\WINDOWS\system32\netstat.exe
2007-04-09 23:44:12     91136 --a------ C:\WINDOWS\system32\netsh.exe
2007-04-09 23:44:12    339968 --a------ C:\WINDOWS\system32\netsetup.exe
2007-04-09 23:44:12    118272 --a------ C:\WINDOWS\system32\netdde.exe
2007-04-09 23:44:12    129024 --a------ C:\WINDOWS\system32\net1.exe
2007-04-09 23:44:12     46592 --a------ C:\WINDOWS\system32\net.exe
2007-04-09 23:44:12    155648 --a------ C:\WINDOWS\system32\NeroCheck.exe<NEROCH~1.EXE>
2007-04-09 23:44:12      8192 --a------ C:\WINDOWS\system32\nddeapir.exe
2007-04-09 23:44:11     25600 --a------ C:\WINDOWS\system32\nbtstat.exe
2007-04-09 23:44:11     58880 --a------ C:\WINDOWS\system32\narrator.exe
2007-04-09 23:44:11    412160 --a------ C:\WINDOWS\system32\mstsc.exe
2007-04-09 23:44:11     15872 --a------ C:\WINDOWS\system32\mstinit.exe
2007-04-09 23:44:11     10240 --a------ C:\WINDOWS\system32\msswchx.exe
2007-04-09 23:44:11    349184 --a------ C:\WINDOWS\system32\mspaint.exe
2007-04-09 23:44:11     82944 --a------ C:\WINDOWS\system32\msiexec.exe
2007-04-09 23:44:11     33280 --a------ C:\WINDOWS\system32\mshta.exe
2007-04-09 23:44:11    131584 --a------ C:\WINDOWS\system32\mshearts.exe
2007-04-09 23:44:11     26112 --a------ C:\WINDOWS\system32\msg.exe
2007-04-09 23:44:11      9728 --a------ C:\WINDOWS\system32\msdtc.exe
2007-04-09 23:44:09     17408 --a------ C:\WINDOWS\system32\mrinfo.exe
2007-04-09 23:44:09     25600 --a------ C:\WINDOWS\system32\mpnotify.exe
2007-04-09 23:44:09    128512 --a------ C:\WINDOWS\system32\mplay32.exe
2007-04-09 23:44:09     11776 --a------ C:\WINDOWS\system32\mountvol.exe
2007-04-09 23:44:09    147456 --a------ C:\WINDOWS\system32\mobsync.exe
2007-04-09 23:44:09     36864 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2007-04-09 23:44:09    819200 --a------ C:\WINDOWS\system32\mmc.exe
2007-04-09 23:44:09     55808 --a------ C:\WINDOWS\system32\migpwd.exe
2007-04-09 23:44:08     44544 --a------ C:\WINDOWS\system32\MAPISRVR.EXE
2007-04-09 23:44:07     89600 --a------ C:\WINDOWS\system32\makecab.exe
2007-04-09 23:44:07     76800 --a------ C:\WINDOWS\system32\magnify.exe
2007-04-09 23:44:07    376832 --a------ C:\WINDOWS\system32\lxcgih.exe
2007-04-09 23:44:07     11776 --a------ C:\WINDOWS\system32\lpr.exe
2007-04-09 23:44:07      9728 --a------ C:\WINDOWS\system32\lpq.exe
2007-04-09 23:44:07    519168 --a------ C:\WINDOWS\system32\logonui.exe
2007-04-09 23:44:07     19456 --a------ C:\WINDOWS\system32\logoff.exe
2007-04-09 23:44:07     64512 --a------ C:\WINDOWS\system32\logman.exe
2007-04-09 23:44:07    104448 --a------ C:\WINDOWS\system32\logagent.exe
2007-04-09 23:44:07      9216 --a------ C:\WINDOWS\system32\lodctr.exe
2007-04-09 23:44:07     79360 --a------ C:\WINDOWS\system32\locator.exe
2007-04-09 23:44:07     30208 --a------ C:\WINDOWS\system32\lnkstub.exe
2007-04-09 23:44:07     33792 --a------ C:\WINDOWS\system32\lights.exe
2007-04-09 23:44:06     13824 --a------ C:\WINDOWS\system32\label.exe
2007-04-09 23:44:06     27648 --a------ C:\WINDOWS\system32\ipxroute.exe
2007-04-09 23:44:06     57344 --a------ C:\WINDOWS\system32\ipv6.exe
2007-04-09 23:44:06     48640 --a------ C:\WINDOWS\system32\ipsec6.exe
2007-04-09 23:44:06     60928 --a------ C:\WINDOWS\system32\ipconfig.exe
2007-04-09 23:44:06   1219584 --a------ C:\WINDOWS\system32\IMMC.EXE
2007-04-09 23:44:05    153600 --a------ C:\WINDOWS\system32\imapi.exe
2007-04-09 23:44:05    118272 --a------ C:\WINDOWS\system32\iexpress.exe
2007-04-09 23:44:05     37888 --a------ C:\WINDOWS\system32\ie4uinit.exe
2007-04-09 23:44:05     11776 --a------ C:\WINDOWS\system32\hostname.exe
2007-04-09 23:44:05     18432 --a------ C:\WINDOWS\system32\help.exe
2007-04-09 23:44:05     43008 --a------ C:\WINDOWS\system32\grpconv.exe
2007-04-09 23:44:05     48128 --a------ C:\WINDOWS\system32\ftp.exe
2007-04-09 23:44:05     66560 --a------ C:\WINDOWS\system32\fsutil.exe
2007-04-09 23:44:05    196608 --a------ C:\WINDOWS\system32\fsquirt.exe
2007-04-09 23:44:05     59392 --a------ C:\WINDOWS\system32\freecell.exe
2007-04-09 23:44:05     10752 --a------ C:\WINDOWS\system32\forcedos.exe
2007-04-09 23:44:05     25088 --a------ C:\WINDOWS\system32\fontview.exe
2007-04-09 23:44:04     27136 --a------ C:\WINDOWS\system32\fltmc.exe
2007-04-09 23:44:04      7168 --a------ C:\WINDOWS\system32\fixmapi.exe
2007-04-09 23:44:04     13312 --a------ C:\WINDOWS\system32\finger.exe
2007-04-09 23:44:04     31744 --a------ C:\WINDOWS\system32\findstr.exe
2007-04-09 23:44:04     13312 --a------ C:\WINDOWS\system32\find.exe
2007-04-09 23:44:04     18944 --a------ C:\WINDOWS\system32\fc.exe
2007-04-09 23:44:04     25088 --a------ C:\WINDOWS\system32\faxpatch.exe
2007-04-09 23:44:04     49152 --a------ C:\WINDOWS\system32\extrac32.exe
2007-04-09 23:44:04     19968 --a------ C:\WINDOWS\system32\expand.exe
2007-04-09 23:44:04     12800 --a------ C:\WINDOWS\system32\eventvwr.exe
2007-04-09 23:44:04    198144 --a------ C:\WINDOWS\system32\eudcedit.exe
2007-04-09 23:44:03     43008 --a------ C:\WINDOWS\system32\esentutl.exe
2007-04-09 23:44:03     50176 --a------ C:\WINDOWS\system32\dxdllreg.exe
2007-04-09 23:44:03   1302528 --a------ C:\WINDOWS\system32\dxdiag.exe
2007-04-09 23:44:03    184320 --a------ C:\WINDOWS\system32\dwwin.exe
2007-04-09 23:44:03     21504 --a------ C:\WINDOWS\system32\dvdupgrd.exe
2007-04-09 23:44:03     61440 --a------ C:\WINDOWS\system32\dvdplay.exe
2007-04-09 23:44:03     14336 --a------ C:\WINDOWS\system32\dumprep.exe
2007-04-09 23:44:03     50688 --a------ C:\WINDOWS\system32\drwtsn32.exe
2007-04-09 23:44:03    253440 --a------ C:\WINDOWS\system32\drmupgds.exe
2007-04-09 23:44:02     87040 --a------ C:\WINDOWS\system32\dpvsetup.exe
2007-04-09 23:44:02     22016 --a------ C:\WINDOWS\system32\dpnsvr.exe
2007-04-09 23:44:02     33792 --a------ C:\WINDOWS\system32\dplaysvr.exe
2007-04-09 23:44:02     14848 --a------ C:\WINDOWS\system32\doskey.exe
2007-04-09 23:44:02     19456 --a------ C:\WINDOWS\system32\dmremote.exe
2007-04-09 23:44:02    228864 --a------ C:\WINDOWS\system32\dmadmin.exe
2007-04-09 23:44:01      8704 --a------ C:\WINDOWS\system32\dllhst3g.exe
2007-04-09 23:43:46     22016 --a------ C:\WINDOWS\system32\diskperf.exe
2007-04-09 23:43:46    168448 --a------ C:\WINDOWS\system32\diskpart.exe
2007-04-09 23:43:46     89600 --a------ C:\WINDOWS\system32\diantz.exe
2007-04-09 23:43:45     86528 --a------ C:\WINDOWS\system32\dfrgfat.exe
2007-04-09 23:43:45     28672 --a------ C:\WINDOWS\system32\defrag.exe
2007-04-09 23:43:45     34816 --a------ C:\WINDOWS\system32\ddeshare.exe
2007-04-09 23:43:45      8704 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2007-04-09 23:43:45    102400 --a------ C:\WINDOWS\system32\cscript.exe
2007-04-09 23:43:45     17920 --a------ C:\WINDOWS\system32\convert.exe
2007-04-09 23:43:45     11776 --a------ C:\WINDOWS\system32\control.exe
2007-04-09 23:43:45     31232 --a------ C:\WINDOWS\system32\conime.exe
2007-04-09 23:43:44     21504 --a------ C:\WINDOWS\system32\compact.exe
2007-04-09 23:43:44     19968 --a------ C:\WINDOWS\system32\comp.exe
2007-04-09 23:43:44     68096 --a------ C:\WINDOWS\system32\cmstp.exe
2007-04-09 23:43:44     43008 --a------ C:\WINDOWS\system32\cmmon32.exe
2007-04-09 23:43:44     50688 --a------ C:\WINDOWS\system32\cmdl32.exe
2007-04-09 23:43:44    399360 --a------ C:\WINDOWS\system32\cmd.exe
2007-04-09 23:43:44     37376 --a------ C:\WINDOWS\system32\clipsrv.exe
2007-04-09 23:43:44    107520 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-04-09 23:43:44     24576 --a------ C:\WINDOWS\system32\cliconfg.exe
2007-04-09 23:43:43     68608 --a------ C:\WINDOWS\system32\cleanmgr.exe
2007-04-09 23:43:43     11776 --a------ C:\WINDOWS\system32\ckcnv.exe
2007-04-09 23:43:43      9728 --a------ C:\WINDOWS\system32\cisvc.exe
2007-04-09 23:43:43     12288 --a------ C:\WINDOWS\system32\cidaemon.exe
2007-04-09 23:43:43     15360 --a------ C:\WINDOWS\system32\chkntfs.exe
2007-04-09 23:43:43     15872 --a------ C:\WINDOWS\system32\chkdsk.exe
2007-04-09 23:43:43     84480 --a------ C:\WINDOWS\system32\charmap.exe
2007-04-09 23:43:43    118784 --a------ C:\WINDOWS\system32\calc.exe
2007-04-09 23:43:43     23040 --a------ C:\WINDOWS\system32\cacls.exe
2007-04-09 23:43:42      8704 --a------ C:\WINDOWS\system32\bootvrfy.exe
2007-04-09 23:43:42      8192 --a------ C:\WINDOWS\system32\bootok.exe
2007-04-09 23:43:42     75264 --a------ C:\WINDOWS\system32\blastcln.exe
2007-04-09 23:43:42     14848 --a------ C:\WINDOWS\system32\autolfn.exe
2007-04-09 23:43:42    606208 --a------ C:\WINDOWS\system32\autofmt.exe
2007-04-09 23:43:41    627712 --a------ C:\WINDOWS\system32\autoconv.exe
2007-04-09 23:43:41    613888 --a------ C:\WINDOWS\system32\autochk.exe
2007-04-09 23:43:41     18432 --a------ C:\WINDOWS\system32\auditusr.exe
2007-04-09 23:43:41     15360 --a------ C:\WINDOWS\system32\attrib.exe
2007-04-09 23:43:41     14848 --a------ C:\WINDOWS\system32\atmadm.exe
2007-04-09 23:43:41    348160 --a------ C:\WINDOWS\system32\atiptaxx.exe
2007-04-09 23:43:41     65536 --a------ C:\WINDOWS\system32\atiphexx.exe
2007-04-09 23:43:40     45056 --a------ C:\WINDOWS\system32\atiiprxx.exe
2007-04-09 23:43:40   1835008 --a------ C:\WINDOWS\system32\atiadaxx.exe
2007-04-09 23:43:40    520192 --a------ C:\WINDOWS\system32\ati2sgag.exe
2007-04-09 23:43:40     28672 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
2007-04-09 23:43:40     29184 --a------ C:\WINDOWS\system32\at.exe
2007-04-09 23:43:40     23552 --a------ C:\WINDOWS\system32\arp.exe
2007-04-09 23:43:40     48128 --a------ C:\WINDOWS\system32\alg.exe
2007-04-09 23:43:40    102400 --a------ C:\WINDOWS\system32\ahui.exe
2007-04-09 23:43:39      8192 --a------ C:\WINDOWS\system32\actmovie.exe
2007-04-09 23:43:39    191488 --a------ C:\WINDOWS\system32\accwiz.exe
2007-04-09 23:43:39     20480 --a------ C:\WINDOWS\system32\ac3config.exe<AC3CON~1.EXE>
2007-04-09 23:43:39     76800 --a------ C:\WINDOWS\ST6UNST.EXE
2007-04-09 23:43:38     36864 --a------ C:\WINDOWS\slrundll.exe
2007-04-09 23:43:38    253952 --a------ C:\WINDOWS\Setup1.exe
2007-04-09 23:43:00    153088 --a------ C:\WINDOWS\regedit.exe
2007-04-09 23:42:52     73728 --a------ C:\WINDOWS\notepad.exe
2007-04-09 23:42:51    724992 --a------ C:\WINDOWS\iun6002ev.exe<IUN600~1.EXE>
2007-04-09 23:42:51    310272 --a------ C:\WINDOWS\IsUninst.exe
2007-04-09 23:42:51    330752 --a------ C:\WINDOWS\IsUn0415.exe
2007-04-09 23:42:46     14336 --a------ C:\WINDOWS\hh.exe
2007-04-09 23:42:42     98304 --a------ C:\WINDOWS\DIIUnin.exe
2007-04-09 23:42:42    270336 --a------ C:\WINDOWS\CMIUninstall.exe<CMIUNI~1.EXE>
2007-04-09 23:42:42    229376 --a------ C:\WINDOWS\CmiRmRedundDir.exe<CMIRMR~1.EXE>
2007-04-09 23:42:41     37888 --a------ C:\WINDOWS\BitTorrentAbsoluteDownloader.exe<BITTOR~1.EXE>
2007-04-09 22:55:34         0 d-------- C:\Program Files\BearShare<BEARSH~1>
2007-04-08 19:31:05         0 d-------- C:\Program Files\InetGet2
2007-04-08 15:03:07    828444 --a------ C:\Documents and Settings\mateusz cybulski\Dane aplikacji\Dxcknwrd.dll
2007-04-08 15:00:43         0 d-------- C:\Program Files\Windows NT<WINDOW~1>
2007-04-06 23:45:17         0 d-------- C:\Program Files\NAPI-PROJEKT<NAPI-P~1>
2007-04-06 19:57:29         0 d-------- C:\Program Files\Gadu-Gadu<GADU-G~1>
2007-03-25 22:30:41         0 d-------- C:\Documents and Settings\mateusz cybulski\Dane aplikacji\Arcsoft
2007-03-22 11:52:49       341 --a------ C:\WINDOWS\system32\lsprst7.dll
2007-03-22 11:52:48        73 --a------ C:\WINDOWS\system32\ssprs.dll
2007-03-08 17:38:47    579072 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:38:47     40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:38:47    281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:37:33   1843840 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-03 23:11:59         0 d-------- C:\Program Files\Valve
2007-03-03 23:06:32         0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-03-03 23:06:24         0 d-------- C:\Program Files\PowerQuest<POWERQ~1>
2007-03-03 22:16:20         0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-03-03 22:16:18         0 d-------- C:\Program Files\Symantec
2007-03-03 22:15:07         0 d-------- C:\Program Files\Kaspersky Lab<KASPER~1>
2007-03-03 22:15:05         0 d-------- C:\Program Files\Common Files\Kaspersky Lab<KASPER~1>
2007-03-03 21:50:32         0 d-------- C:\Program Files\Norton AntiVirus<NORTON~1>
2007-03-03 14:13:48         0 d-------- C:\Program Files\ATI Technologies<ATITEC~1>
2007-03-03 14:10:43         0 d-------- C:\Program Files\C-Media 3D Audio<C-MEDI~1>
2007-02-23 00:06:17         0 d-------- C:\Program Files\DC++<DC__~1>
2007-02-21 19:23:54         0 d-------- C:\Program Files\The All-Seeing Eye<THEALL~1>


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Steam"="\"C:\\Program Files\\Valve\\Steam\\Steam.exe\" -silent"
"Gadu-Gadu"="\"C:\\Program Files\\Gadu-Gadu\\gg.exe\" /tray"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"lxcgmon.exe"="\"C:\\Program Files\\Lexmark 2300 Series\\lxcgmon.exe\""
"EzPrint"="\"C:\\Program Files\\Lexmark 2300 Series\\ezprint.exe\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BearShare"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
   

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB3-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB3-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB3-1045-0201-050403250030}"="\"C:\\Program Files\\Common Files\\{5830E138-0BB3-1045-0201-050403250030}\\Update.exe\" mc-110-12-0000137"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
   Source   REG_SZ            http://www.portal24h.pl/humor/dyplomy/palenie_trawy.jpg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService   REG_MULTI_SZ      Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService   REG_MULTI_SZ      DnsCache\0\0
rpcss   REG_MULTI_SZ      RpcSs\0\0
imgsvc   REG_MULTI_SZ      StiSvc\0\0
termsvcs   REG_MULTI_SZ      TermService\0\0
HTTPFilter   REG_MULTI_SZ      HTTPFilter\0\0
DcomLaunch   REG_MULTI_SZ      DcomLaunch\0TermService\0\0
WudfServiceGroup   REG_MULTI_SZ      WUDFSvc\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{58b1faeb-8c0c-11da-9af0-806d6172696f}]
Shell\AutoRun\command   D:\AutoRun.exe


-- End of ComboScan: finished at 2007-04-10 at 06:41:59 ------------------------

NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA



Postprzez wojtas 10 Kwi 2007, 14:05

wklej do notatnika:

Windows Registry Editor Version 5.00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB7-1045-0201-050403250030}"=-

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
"{5830E138-0BB7-1045-0201-050403250030}"=-


w notatniku u góry>>>plik zapisz jako>>>Zmien rozszerzenie z TXT na Wszystkie pliki *.* >>> Zapisz pod nazwą FIX.REG

Klikasz dwa razy na powstały plik fix i dodajesz go do rejestru...



odapl gmera zakladka "

1) Rootkit >>> zaznaczone Pokaż wszystko >>> wskazane tylko Usługi >>> Szukaj >>> Kopiuj >>> CTRL+V do posta
2) Rootkit >>> odznaczone Pokaż wszystko >>> wskazane wszystkie obiekty do skanu >>> Szukaj >>> Kopiuj >>> CTRL+V do posta
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez kybula 10 Kwi 2007, 18:37

log z gmer z wlaczonym-pokazuj wszystko:

Kod: Zaznacz wszystko
GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-04-10 10:40:52
Windows 5.1.2600 Dodatek Service Pack 2


---- Services - GMER 1.0.12 ----

Service                                                                                 [DISABLED] Abiosdsk
Service                                                                                 [DISABLED] abp480n5
Service  C:\WINDOWS\System32\DRIVERS\ACPI.sys                                           [BOOT] ACPI
Service                                                                                 [DISABLED] ACPIEC
Service                                                                                 [DISABLED] adpu160m
Service  C:\WINDOWS\system32\drivers\aec.sys                                            [MANUAL] aec
Service  C:\WINDOWS\System32\drivers\afd.sys                                            [SYSTEM] AFD
Service  C:\WINDOWS\System32\DRIVERS\agp440.sys                                         [BOOT] agp440
Service                                                                                 [DISABLED] Aha154x
Service                                                                                 [DISABLED] aic78u2
Service                                                                                 [DISABLED] aic78xx
Service  C:\WINDOWS\system32\DRIVERS\alcan5wn.sys                                       [MANUAL] alcan5wn
Service  C:\WINDOWS\system32\DRIVERS\alcaudsl.sys                                       [MANUAL] alcaudsl
Service  C:\WINDOWS\System32\svchost.exe                                                [DISABLED] Alerter
Service  C:\WINDOWS\System32\alg.exe                                                    [MANUAL] ALG
Service                                                                                 [DISABLED] AliIde
Service                                                                                 [DISABLED] amsint
Service  C:\WINDOWS\system32\svchost.exe                                                [MANUAL] AppMgmt
Service                                                                                 [DISABLED] asc
Service                                                                                 [DISABLED] asc3350p
Service                                                                                 [DISABLED] asc3550
Service  C:\WINDOWS\System32\DRIVERS\asyncmac.sys                                       [MANUAL] AsyncMac
Service  C:\WINDOWS\System32\DRIVERS\atapi.sys                                          [BOOT] atapi
Service                                                                                 [DISABLED] Atdisk
Service  C:\WINDOWS\system32\Ati2evxx.exe                                               [AUTO] Ati HotKey Poller
Service  C:\WINDOWS\system32\ati2sgag.exe                                               [AUTO] ATI Smart
Service  C:\WINDOWS\System32\DRIVERS\ati2mtag.sys                                       [MANUAL] ati2mtag
Service                                                                                 Atierecord
Service  C:\WINDOWS\system32\DRIVERS\ATITool.sys                                        [SYSTEM] ATITool
Service  C:\Program Files\Radeon Omega Drivers\v2.6.83\ATI Tray Tools\atitray.sys       [SYSTEM] atitray
Service  C:\WINDOWS\system32\DRIVERS\atksgt.sys                                         [AUTO] atksgt
Service  C:\WINDOWS\System32\DRIVERS\atmarpc.sys                                        [MANUAL] Atmarpc
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] AudioSrv
Service  C:\WINDOWS\System32\DRIVERS\audstub.sys                                        [MANUAL] audstub
Service                                                                                 BattC
Service                                                                                 [SYSTEM] Beep
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] BITS
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] Browser
Service                                                                                 [DISABLED] cbidf2k
Service                                                                                 [DISABLED] cd20xrnt
Service                                                                                 [SYSTEM] Cdaudio
Service                                                                                 [DISABLED] Cdfs
Service  C:\WINDOWS\System32\DRIVERS\cdrom.sys                                          [SYSTEM] Cdrom
Service  C:\Program Files\InfinaDyne\Shared\CDRPDACC.SYS                                [AUTO] CDRPDACC
Service                                                                                 [SYSTEM] Changer
Service  C:\WINDOWS\system32\cisvc.exe                                                  [MANUAL] CiSvc
Service  C:\WINDOWS\system32\svchosts.exe                                               [DISABLED] Client IP-IPX
Service  C:\WINDOWS\system32\clipsrv.exe                                                [DISABLED] ClipSrv
Service                                                                                 [DISABLED] CmdIde
Service  C:\WINDOWS\system32\drivers\cmuda.sys                                          [MANUAL] cmuda
Service  C:\WINDOWS\System32\dllhost.exe                                                [MANUAL] COMSysApp
Service                                                                                 ContentFilter
Service                                                                                 ContentIndex
Service  C:\WINDOWS\system32\drivers\core.sys                                           [SYSTEM] core
Service                                                                                 [DISABLED] Cpqarray
Service  C:\Program Files\CPUCooL\CooLSrv.exe                                           [AUTO] CPUCooLServer
Service  C:\WINDOWS\system32\svchost.exe                                                [AUTO] CryptSvc
Service                                                                                 [DISABLED] dac2w2k
Service                                                                                 [DISABLED] dac960nt
Service  C:\WINDOWS\system32\svchost.exe                                                [AUTO] DcomLaunch
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] Dhcp
Service  C:\WINDOWS\System32\DRIVERS\disk.sys                                           [BOOT] Disk
Service  C:\WINDOWS\System32\dmadmin.exe                                                [MANUAL] dmadmin
Service  C:\WINDOWS\System32\drivers\dmboot.sys                                         [DISABLED] dmboot
Service  C:\WINDOWS\System32\drivers\dmio.sys                                           [DISABLED] dmio
Service  C:\WINDOWS\System32\drivers\dmload.sys                                         [DISABLED] dmload
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] dmserver
Service  C:\WINDOWS\system32\drivers\DMusic.sys                                         [MANUAL] DMusic
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] Dnscache
Service                                                                                 [DISABLED] dpti2o
Service  C:\WINDOWS\system32\drivers\drmkaud.sys                                        [MANUAL] drmkaud
Service  C:\WINDOWS\System32\Drivers\dtscsi.sys                                         [MANUAL] dtscsi
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] ERSvc
Service  C:\WINDOWS\system32\services.exe                                               [AUTO] Eventlog
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] EventSystem
Service                                                                                 [DISABLED] Fastfat
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] FastUserSwitchingCompatibility
Service  C:\WINDOWS\System32\DRIVERS\fdc.sys                                            [MANUAL] Fdc
Service                                                                                 [SYSTEM] Fips
Service  C:\WINDOWS\System32\DRIVERS\flpydisk.sys                                       [MANUAL] Flpydisk
Service  C:\WINDOWS\system32\drivers\fltmgr.sys                                         [BOOT] FltMgr
Service                                                                                 [SYSTEM] Fs_Rec
Service  C:\WINDOWS\System32\DRIVERS\ftdisk.sys                                         [BOOT] Ftdisk
Service  C:\WINDOWS\System32\DRIVERS\gameenum.sys                                       [MANUAL] gameenum
Service  C:\WINDOWS\System32\DRIVERS\gmer.sys                                           [MANUAL] gmer
Service  C:\WINDOWS\System32\DRIVERS\msgpc.sys                                          [MANUAL] Gpc
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] helpsvc
Service  C:\WINDOWS\System32\svchost.exe                                                [DISABLED] HidServ
Service  C:\WINDOWS\System32\DRIVERS\hidusb.sys                                         [MANUAL] hidusb
Service                                                                                 [DISABLED] hpn
Service  C:\WINDOWS\System32\Drivers\HTTP.sys                                           [MANUAL] HTTP
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] HTTPFilter
Service                                                                                 [SYSTEM] i2omgmt
Service                                                                                 [DISABLED] i2omp
Service  C:\WINDOWS\System32\DRIVERS\i8042prt.sys                                       [SYSTEM] i8042prt
Service  C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe  [MANUAL] IDriverT
Service  C:\WINDOWS\System32\DRIVERS\imapi.sys                                          [SYSTEM] Imapi
Service  C:\WINDOWS\System32\imapi.exe                                                  [MANUAL] ImapiService
Service                                                                                 inetaccs
Service                                                                                 [DISABLED] ini910u
Service                                                                                 Inport
Service                                                                                 [DISABLED] IntelIde
Service  C:\WINDOWS\System32\DRIVERS\intelppm.sys                                       [SYSTEM] intelppm
Service  C:\WINDOWS\system32\drivers\ip6fw.sys                                          [MANUAL] ip6fw
Service  C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys                                       [MANUAL] IpFilterDriver
Service  C:\WINDOWS\System32\DRIVERS\ipinip.sys                                         [MANUAL] IpInIp
Service  C:\WINDOWS\System32\DRIVERS\ipnat.sys                                          [MANUAL] IpNat
Service  C:\WINDOWS\System32\DRIVERS\ipsec.sys                                          [SYSTEM] IPSec
Service  C:\WINDOWS\System32\DRIVERS\irenum.sys                                         [MANUAL] IRENUM
Service                                                                                 ISAPISearch
Service  C:\WINDOWS\System32\DRIVERS\isapnp.sys                                         [BOOT] isapnp
Service  C:\WINDOWS\System32\DRIVERS\kbdclass.sys                                       [SYSTEM] Kbdclass
Service  C:\WINDOWS\system32\drivers\kmixer.sys                                         [MANUAL] kmixer
Service                                                                                 [BOOT] KSecDD
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] lanmanserver
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] lanmanworkstation
Service                                                                                 [SYSTEM] lbrtfdc
Service                                                                                 ldap
Service                                                                                 LicenseService
Service  C:\WINDOWS\system32\DRIVERS\lirsgt.sys                                         [AUTO] lirsgt
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] LmHosts
Service  C:\WINDOWS\system32\lxcgcoms.exe                                               [MANUAL] lxcg_device
Service  C:\WINDOWS\System32\svchost.exe                                                [DISABLED] Messenger
Service                                                                                 [SYSTEM] mnmdd
Service  C:\WINDOWS\System32\mnmsrvc.exe                                                [MANUAL] mnmsrvc
Service                                                                                 [MANUAL] Modem
Service  C:\WINDOWS\System32\DRIVERS\mouclass.sys                                       [SYSTEM] Mouclass
Service  C:\WINDOWS\System32\DRIVERS\mouhid.sys                                         [MANUAL] mouhid
Service                                                                                 [BOOT] MountMgr
Service                                                                                 [DISABLED] mraid35x
Service  C:\WINDOWS\System32\DRIVERS\mrxdav.sys                                         [MANUAL] MRxDAV
Service  C:\WINDOWS\System32\DRIVERS\mrxsmb.sys                                         [SYSTEM] MRxSmb
Service  C:\WINDOWS\System32\msdtc.exe                                                  [MANUAL] MSDTC
Service                                                                                 [SYSTEM] Msfs
Service  C:\WINDOWS\system32\msiexec.exe                                                [MANUAL] MSIServer
Service  C:\WINDOWS\system32\drivers\MSKSSRV.sys                                        [MANUAL] MSKSSRV
Service  C:\WINDOWS\system32\drivers\MSPCLOCK.sys                                       [MANUAL] MSPCLOCK
Service  C:\WINDOWS\system32\drivers\MSPQM.sys                                          [MANUAL] MSPQM
Service  C:\WINDOWS\System32\DRIVERS\mssmbios.sys                                       [MANUAL] mssmbios
Service                                                                                 [BOOT] Mup
Service                                                                                 [BOOT] NDIS
Service  C:\WINDOWS\System32\DRIVERS\ndistapi.sys                                       [MANUAL] NdisTapi
Service  C:\WINDOWS\System32\DRIVERS\ndisuio.sys                                        [MANUAL] Ndisuio
Service  C:\WINDOWS\System32\DRIVERS\ndiswan.sys                                        [MANUAL] NdisWan
Service                                                                                 [MANUAL] NDProxy
Service  C:\WINDOWS\System32\DRIVERS\netbios.sys                                        [SYSTEM] NetBIOS
Service  C:\WINDOWS\System32\DRIVERS\netbt.sys                                          [MANUAL] NetBT
Service  C:\WINDOWS\system32\netdde.exe                                                 [DISABLED] NetDDE
Service  C:\WINDOWS\system32\netdde.exe                                                 [DISABLED] NetDDEdsdm
Service  C:\WINDOWS\System32\lsass.exe                                                  [MANUAL] Netlogon
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] Netman
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] Nla
Service                                                                                 [SYSTEM] Npfs
Service                                                                                 [DISABLED] Ntfs
Service                                                                                 [SYSTEM] ntiowp
Service  C:\WINDOWS\System32\lsass.exe                                                  [MANUAL] NtLmSsp
Service  C:\WINDOWS\system32\svchost.exe                                                [MANUAL] NtmsSvc
Service                                                                                 [SYSTEM] Null
Service  C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys                                       [MANUAL] NwlnkFlt
Service  C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys                                       [MANUAL] NwlnkFwd
Service  C:\WINDOWS\System32\DRIVERS\parport.sys                                        [MANUAL] Parport
Service                                                                                 [BOOT] PartMgr
Service                                                                                 [AUTO] ParVdm
Service  C:\WINDOWS\System32\DRIVERS\pci.sys                                            [BOOT] PCI
Service                                                                                 [SYSTEM] PCIDump
Service  C:\WINDOWS\System32\DRIVERS\pciide.sys                                         [BOOT] PCIIde
Service                                                                                 [DISABLED] Pcmcia
Service                                                                                 [MANUAL] PDCOMP
Service                                                                                 [MANUAL] PDFRAME
Service                                                                                 [MANUAL] PDRELI
Service                                                                                 [MANUAL] PDRFRAME
Service                                                                                 [DISABLED] perc2
Service                                                                                 [DISABLED] perc2hib
Service                                                                                 PerfDisk
Service                                                                                 PerfNet
Service                                                                                 PerfOS
Service                                                                                 PerfProc
Service  C:\WINDOWS\system32\drivers\pfc.sys                                            [MANUAL] Pfc
Service  C:\WINDOWS\system32\services.exe                                               [AUTO] PlugPlay
Service  C:\WINDOWS\System32\lsass.exe                                                  [AUTO] PolicyAgent
Service  C:\WINDOWS\System32\DRIVERS\raspptp.sys                                        [MANUAL] PptpMiniport
Service                                                                                 [SYSTEM] PQNTDrv
Service  C:\WINDOWS\System32\DRIVERS\processr.sys                                       [SYSTEM] Processor
Service  C:\WINDOWS\system32\lsass.exe                                                  [AUTO] ProtectedStorage
Service  C:\WINDOWS\System32\DRIVERS\psched.sys                                         [MANUAL] PSched
Service  C:\WINDOWS\System32\DRIVERS\ptilink.sys                                        [MANUAL] Ptilink
Service  C:\WINDOWS\system32\DRIVERS\PxHelp20.sys                                       [BOOT] PxHelp20
Service                                                                                 [DISABLED] ql1080
Service                                                                                 [DISABLED] Ql10wnt
Service                                                                                 [DISABLED] ql12160
Service                                                                                 [DISABLED] ql1240
Service                                                                                 [DISABLED] ql1280
Service  C:\WINDOWS\System32\DRIVERS\rasacd.sys                                         [SYSTEM] RasAcd
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] RasAuto
Service  C:\WINDOWS\System32\DRIVERS\rasl2tp.sys                                        [MANUAL] Rasl2tp
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] RasMan
Service  C:\WINDOWS\System32\DRIVERS\raspppoe.sys                                       [MANUAL] RasPppoe
Service  C:\WINDOWS\System32\DRIVERS\raspti.sys                                         [MANUAL] Raspti
Service  C:\WINDOWS\System32\DRIVERS\rdbss.sys                                          [SYSTEM] Rdbss
Service  C:\WINDOWS\System32\DRIVERS\RDPCDD.sys                                         [SYSTEM] RDPCDD
Service                                                                                 RDPDD
Service                                                                                 RDPNP
Service                                                                                 [MANUAL] RDPWD
Service  C:\WINDOWS\system32\sessmgr.exe                                                [MANUAL] RDSessMgr
Service  C:\WINDOWS\System32\DRIVERS\redbook.sys                                        [SYSTEM] redbook
Service  C:\WINDOWS\System32\svchost.exe                                                [DISABLED] RemoteAccess
Service  C:\WINDOWS\System32\locator.exe                                                [MANUAL] RpcLocator
Service  C:\WINDOWS\system32\svchost.exe                                                [AUTO] RpcSs
Service  C:\WINDOWS\System32\rsvp.exe                                                   [MANUAL] RSVP
Service  C:\WINDOWS\System32\DRIVERS\R8139n51.SYS                                       [MANUAL] rtl8139
Service  C:\WINDOWS\system32\lsass.exe                                                  [AUTO] SamSs
Service  C:\WINDOWS\System32\SCardSvr.exe                                               [MANUAL] SCardSvr
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] Schedule
Service                                                                                 ScsiPort
Service  C:\WINDOWS\System32\DRIVERS\secdrv.sys                                         [AUTO] Secdrv
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] seclogon
Service  C:\WINDOWS\system32\svchost.exe                                                [AUTO] SENS
Service  C:\WINDOWS\System32\DRIVERS\serenum.sys                                        [MANUAL] serenum
Service  C:\WINDOWS\System32\DRIVERS\serial.sys                                         [SYSTEM] Serial
Service  C:\WINDOWS\System32\drivers\sfdrv01.sys                                        [BOOT] sfdrv01
Service  C:\WINDOWS\System32\drivers\sfhlp02.sys                                        [BOOT] sfhlp02
Service                                                                                 [SYSTEM] Sfloppy
Service  C:\WINDOWS\System32\drivers\sfsync04.sys                                       [BOOT] sfsync04
Service                                                                                 SharedAccess
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] ShellHWDetection
Service                                                                                 [DISABLED] Simbad
Service                                                                                 [DISABLED] Sparrow
Service  C:\WINDOWS\system32\drivers\splitter.sys                                       [MANUAL] splitter
Service  C:\WINDOWS\system32\spoolsv.exe                                                [AUTO] Spooler
Service  C:\WINDOWS\System32\Drivers\sptd.sys                                           [BOOT] sptd
Service  C:\WINDOWS\System32\DRIVERS\sr.sys                                             [BOOT] sr
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] srservice
Service  C:\WINDOWS\System32\DRIVERS\srv.sys                                            [MANUAL] Srv
Service  C:\WINDOWS\System32\svchost.exe                                                [DISABLED] SSDPSRV
Service  C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe         [AUTO] StarWindService
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] stisvc
Service  C:\WINDOWS\System32\DRIVERS\swenum.sys                                         [MANUAL] swenum
Service  C:\WINDOWS\system32\drivers\swmidi.sys                                         [MANUAL] swmidi
Service  C:\WINDOWS\System32\dllhost.exe                                                [MANUAL] SwPrv
Service                                                                                 swwd
Service                                                                                 [DISABLED] symc810
Service                                                                                 [DISABLED] symc8xx
Service  C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe       [AUTO] SymWSC
Service                                                                                 [DISABLED] sym_hi
Service                                                                                 [DISABLED] sym_u3
Service  C:\WINDOWS\system32\drivers\sysaudio.sys                                       [MANUAL] sysaudio
Service  C:\WINDOWS\system32\smlogsvc.exe                                               [MANUAL] SysmonLog
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] TapiSrv
Service  C:\WINDOWS\System32\DRIVERS\tcpip.sys                                          [SYSTEM] Tcpip
Service                                                                                 [MANUAL] TDPIPE
Service                                                                                 [MANUAL] TDTCP
Service  C:\WINDOWS\System32\DRIVERS\termdd.sys                                         [SYSTEM] TermDD
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] TermService
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] Themes
Service  C:\DOCUME~1\MATEUS~1\USTAWI~1\Temp\tni3D.tmp                                   [MANUAL] TnIDriver
Service                                                                                 [DISABLED] TosIde
Service  C:\WINDOWS\system32\svchost.exe                                                [AUTO] TrkWks
Service                                                                                 TSDDD
Service                                                                                 [DISABLED] Udfs
Service                                                                                 [DISABLED] ultra
Service  C:\WINDOWS\System32\DRIVERS\update.sys                                         [MANUAL] Update
Service  C:\WINDOWS\System32\svchost.exe                                                [DISABLED] upnphost
Service  C:\WINDOWS\System32\ups.exe                                                    [MANUAL] UPS
Service  C:\WINDOWS\System32\DRIVERS\usbccgp.sys                                        [MANUAL] usbccgp
Service  C:\WINDOWS\System32\DRIVERS\usbehci.sys                                        [MANUAL] usbehci
Service  C:\WINDOWS\System32\DRIVERS\usbhub.sys                                         [MANUAL] usbhub
Service  C:\WINDOWS\System32\DRIVERS\usbprint.sys                                       [MANUAL] usbprint
Service  C:\WINDOWS\System32\DRIVERS\usbscan.sys                                        [MANUAL] usbscan
Service  C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS                                        [MANUAL] USBSTOR
Service  C:\WINDOWS\System32\DRIVERS\usbuhci.sys                                        [MANUAL] usbuhci
Service  C:\WINDOWS\System32\drivers\vga.sys                                            [SYSTEM] VgaSave
Service                                                                                 [DISABLED] ViaIde
Service                                                                                 [BOOT] VolSnap
Service  C:\WINDOWS\System32\vssvc.exe                                                  [MANUAL] VSS
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] W32Time
Service                                                                                 W3SVC
Service  C:\WINDOWS\System32\DRIVERS\wanarp.sys                                         [MANUAL] Wanarp
Service                                                                                 [MANUAL] WDICA
Service  C:\WINDOWS\system32\drivers\wdmaud.sys                                         [MANUAL] wdmaud
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] WebClient
Service  C:\Program Files\Windows Defender\MsMpEng.exe                                  [AUTO] WinDefend
Service  C:\WINDOWS\system32\svchost.exe                                                [AUTO] winmgmt
Service                                                                                 [MANUAL] Winsock
Service                                                                                 WinSock2
Service                                                                                 WinTrust
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] WmdmPmSN
Service                                                                                 Wmi
Service                                                                                 WmiApRpl
Service  C:\WINDOWS\System32\wbem\wmiapsrv.exe                                          [MANUAL] WmiApSrv
Service  C:\Program Files\Windows Media Player\WMPNetwk.exe                             [MANUAL] WMPNetworkSvc
Service  C:\WINDOWS\System32\drivers\ws2ifsl.sys                                        [DISABLED] WS2IFSL
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] wscsvc
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] wuauserv
Service  C:\WINDOWS\system32\DRIVERS\WudfPf.sys                                         [MANUAL] WudfPf
Service  C:\WINDOWS\system32\DRIVERS\wudfrd.sys                                         [MANUAL] WudfRd
Service  C:\WINDOWS\system32\svchost.exe                                                [MANUAL] WudfSvc
Service  C:\WINDOWS\System32\svchost.exe                                                [AUTO] WZCSVC
Service  C:\WINDOWS\System32\svchost.exe                                                [MANUAL] xmlprov
Service                                                                                 {A434A052-594D-4B4F-BB16-618B124693E4}

---- EOF - GMER 1.0.12 ----


i wylaczonym.

[code]GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-04-10 10:40:52
Windows 5.1.2600 Dodatek Service Pack 2


---- Services - GMER 1.0.12 ----

Service [DISABLED] Abiosdsk
Service [DISABLED] abp480n5
Service C:\WINDOWS\System32\DRIVERS\ACPI.sys [BOOT] ACPI
Service [DISABLED] ACPIEC
Service [DISABLED] adpu160m
Service C:\WINDOWS\system32\drivers\aec.sys [MANUAL] aec
Service C:\WINDOWS\System32\drivers\afd.sys [SYSTEM] AFD
Service C:\WINDOWS\System32\DRIVERS\agp440.sys [BOOT] agp440
Service [DISABLED] Aha154x
Service [DISABLED] aic78u2
Service [DISABLED] aic78xx
Service C:\WINDOWS\system32\DRIVERS\alcan5wn.sys [MANUAL] alcan5wn
Service C:\WINDOWS\system32\DRIVERS\alcaudsl.sys [MANUAL] alcaudsl
Service C:\WINDOWS\System32\svchost.exe [DISABLED] Alerter
Service C:\WINDOWS\System32\alg.exe [MANUAL] ALG
Service [DISABLED] AliIde
Service [DISABLED] amsint
Service C:\WINDOWS\system32\svchost.exe [MANUAL] AppMgmt
Service [DISABLED] asc
Service [DISABLED] asc3350p
Service [DISABLED] asc3550
Service C:\WINDOWS\System32\DRIVERS\asyncmac.sys [MANUAL] AsyncMac
Service C:\WINDOWS\System32\DRIVERS\atapi.sys [BOOT] atapi
Service [DISABLED] Atdisk
Service C:\WINDOWS\system32\Ati2evxx.exe [AUTO] Ati HotKey Poller
Service C:\WINDOWS\system32\ati2sgag.exe [AUTO] ATI Smart
Service C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [MANUAL] ati2mtag
Service Atierecord
Service C:\WINDOWS\system32\DRIVERS\ATITool.sys [SYSTEM] ATITool
Service C:\Program Files\Radeon Omega Drivers\v2.6.83\ATI Tray Tools\atitray.sys [SYSTEM] atitray
Service C:\WINDOWS\system32\DRIVERS\atksgt.sys [AUTO] atksgt
Service C:\WINDOWS\System32\DRIVERS\atmarpc.sys [MANUAL] Atmarpc
Service C:\WINDOWS\System32\svchost.exe [AUTO] AudioSrv
Service C:\WINDOWS\System32\DRIVERS\audstub.sys [MANUAL] audstub
Service BattC
Service [SYSTEM] Beep
Service C:\WINDOWS\System32\svchost.exe [AUTO] BITS
Service C:\WINDOWS\System32\svchost.exe [AUTO] Browser
Service [DISABLED] cbidf2k
Service [DISABLED] cd20xrnt
Service [SYSTEM] Cdaudio
Service [DISABLED] Cdfs
Service C:\WINDOWS\System32\DRIVERS\cdrom.sys [SYSTEM] Cdrom
Service C:\Program Files\InfinaDyne\Shared\CDRPDACC.SYS [AUTO] CDRPDACC
Service [SYSTEM] Changer
Service C:\WINDOWS\system32\cisvc.exe [MANUAL] CiSvc
Service C:\WINDOWS\system32\svchosts.exe [DISABLED] Client IP-IPX
Service C:\WINDOWS\system32\clipsrv.exe [DISABLED] ClipSrv
Service [DISABLED] CmdIde
Service C:\WINDOWS\system32\drivers\cmuda.sys [MANUAL] cmuda
Service C:\WINDOWS\System32\dllhost.exe [MANUAL] COMSysApp
Service ContentFilter
Service ContentIndex
Service C:\WINDOWS\system32\drivers\core.sys [SYSTEM] core
Service [DISABLED] Cpqarray
Service C:\Program Files\CPUCooL\CooLSrv.exe [AUTO] CPUCooLServer
Service C:\WINDOWS\system32\svchost.exe [AUTO] CryptSvc
Service [DISABLED] dac2w2k
Service [DISABLED] dac960nt
Service C:\WINDOWS\system32\svchost.exe [AUTO] DcomLaunch
Service C:\WINDOWS\System32\svchost.exe [AUTO] Dhcp
Service C:\WINDOWS\System32\DRIVERS\disk.sys [BOOT] Disk
Service C:\WINDOWS\System32\dmadmin.exe [MANUAL] dmadmin
Service C:\WINDOWS\System32\drivers\dmboot.sys [DISABLED] dmboot
Service C:\WINDOWS\System32\drivers\dmio.sys [DISABLED] dmio
Service C:\WINDOWS\System32\drivers\dmload.sys [DISABLED] dmload
Service C:\WINDOWS\System32\svchost.exe [MANUAL] dmserver
Service C:\WINDOWS\system32\drivers\DMusic.sys [MANUAL] DMusic
Service C:\WINDOWS\System32\svchost.exe [AUTO] Dnscache
Service [DISABLED] dpti2o
Service C:\WINDOWS\system32\drivers\drmkaud.sys [MANUAL] drmkaud
Service C:\WINDOWS\System32\Drivers\dtscsi.sys [MANUAL] dtscsi
Service C:\WINDOWS\System32\svchost.exe [AUTO] ERSvc
Service C:\WINDOWS\system32\services.exe [AUTO] Eventlog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] EventSystem
Service [DISABLED] Fastfat
Service C:\WINDOWS\System32\svchost.exe [MANUAL] FastUserSwitchingCompatibility
Service C:\WINDOWS\System32\DRIVERS\fdc.sys [MANUAL] Fdc
Service [SYSTEM] Fips
Service C:\WINDOWS\System32\DRIVERS\flpydisk.sys [MANUAL] Flpydisk
Service C:\WINDOWS\system32\drivers\fltmgr.sys [BOOT] FltMgr
Service [SYSTEM] Fs_Rec
Service C:\WINDOWS\System32\DRIVERS\ftdisk.sys [BOOT] Ftdisk
Service C:\WINDOWS\System32\DRIVERS\gameenum.sys [MANUAL] gameenum
Service C:\WINDOWS\System32\DRIVERS\gmer.sys [MANUAL] gmer
Service C:\WINDOWS\System32\DRIVERS\msgpc.sys [MANUAL] Gpc
Service C:\WINDOWS\System32\svchost.exe [AUTO] helpsvc
Service C:\WINDOWS\System32\svchost.exe [DISABLED] HidServ
Service C:\WINDOWS\System32\DRIVERS\hidusb.sys [MANUAL] hidusb
Service [DISABLED] hpn
Service C:\WINDOWS\System32\Drivers\HTTP.sys [MANUAL] HTTP
Service C:\WINDOWS\System32\svchost.exe [MANUAL] HTTPFilter
Service [SYSTEM] i2omgmt
Service [DISABLED] i2omp
Service C:\WINDOWS\System32\DRIVERS\i8042prt.sys [SYSTEM] i8042prt
Service C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [MANUAL] IDriverT
Service C:\WINDOWS\System32\DRIVERS\imapi.sys [SYSTEM] Imapi
Service C:\WINDOWS\System32\imapi.exe [MANUAL] ImapiService
Service inetaccs
Service [DISABLED] ini910u
Service Inport
Service [DISABLED] IntelIde
Service C:\WINDOWS\System32\DRIVERS\intelppm.sys [SYSTEM] intelppm
Service C:\WINDOWS\system32\drivers\ip6fw.sys [MANUAL] ip6fw
Service C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys [MANUAL] IpFilterDriver
Service C:\WINDOWS\System32\DRIVERS\ipinip.sys [MANUAL] IpInIp
Service C:\WINDOWS\System32\DRIVERS\ipnat.sys [MANUAL] IpNat
Service C:\WINDOWS\System32\DRIVERS\ipsec.sys [SYSTEM] IPSec
Service C:\WINDOWS\System32\DRIVERS\irenum.sys [MANUAL] IRENUM
Service ISAPISearch
Service C:\WINDOWS\System32\DRIVERS\isapnp.sys [BOOT] isapnp
Service C:\WINDOWS\System32\DRIVERS\kbdclass.sys [SYSTEM] Kbdclass
Service C:\WINDOWS\system32\drivers\kmixer.sys [MANUAL] kmixer
Service [BOOT] KSecDD
Service C:\WINDOWS\System32\svchost.exe [AUTO] lanmanserver
Service C:\WINDOWS\System32\svchost.exe [AUTO] lanmanworkstation
Service [SYSTEM] lbrtfdc
Service ldap
Service LicenseService
Service C:\WINDOWS\system32\DRIVERS\lirsgt.sys [AUTO] lirsgt
Service C:\WINDOWS\System32\svchost.exe [AUTO] LmHosts
Service C:\WINDOWS\system32\lxcgcoms.exe [MANUAL] lxcg_device
Service C:\WINDOWS\System32\svchost.exe [DISABLED] Messenger
Service [SYSTEM] mnmdd
Service C:\WINDOWS\System32\mnmsrvc.exe [MANUAL] mnmsrvc
Service [MANUAL] Modem
Service C:\WINDOWS\System32\DRIVERS\mouclass.sys [SYSTEM] Mouclass
Service C:\WINDOWS\System32\DRIVERS\mouhid.sys [MANUAL] mouhid
Service [BOOT] MountMgr
Service [DISABLED] mraid35x
Service C:\WINDOWS\System32\DRIVERS\mrxdav.sys [MANUAL] MRxDAV
Service C:\WINDOWS\System32\DRIVERS\mrxsmb.sys [SYSTEM] MRxSmb
Service C:\WINDOWS\System32\msdtc.exe [MANUAL] MSDTC
Service [SYSTEM] Msfs
Service C:\WINDOWS\system32\msiexec.exe [MANUAL] MSIServer
Service C:\WINDOWS\system32\drivers\MSKSSRV.sys [MANUAL] MSKSSRV
Service C:\WINDOWS\system32\drivers\MSPCLOCK.sys [MANUAL] MSPCLOCK
Service C:\WINDOWS\system32\drivers\MSPQM.sys [MANUAL] MSPQM
Service C:\WINDOWS\System32\DRIVERS\mssmbios.sys [MANUAL] mssmbios
Service [BOOT] Mup
Service [BOOT] NDIS
Service C:\WINDOWS\System32\DRIVERS\ndistapi.sys [MANUAL] NdisTapi
Service C:\WINDOWS\System32\DRIVERS\ndisuio.sys [MANUAL] Ndisuio
Service C:\WINDOWS\System32\DRIVERS\ndiswan.sys [MANUAL] NdisWan
Service [MANUAL] NDProxy
Service C:\WINDOWS\System32\DRIVERS\netbios.sys [SYSTEM] NetBIOS
Service C:\WINDOWS\System32\DRIVERS\netbt.sys [MANUAL] NetBT
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDE
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDEdsdm
Service C:\WINDOWS\System32\lsass.exe [MANUAL] Netlogon
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Netman
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Nla
Service [SYSTEM] Npfs
Service [DISABLED] Ntfs
Service [SYSTEM] ntiowp
Service C:\WINDOWS\System32\lsass.exe [MANUAL] NtLmSsp
Service C:\WINDOWS\system32\svchost.exe [MANUAL] NtmsSvc
Service [SYSTEM] Null
Service C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys [MANUAL] NwlnkFlt
Service C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys [MANUAL] NwlnkFwd
Service C:\WINDOWS\System32\DRIVERS\parport.sys [MANUAL] Parport
Service [BOOT] PartMgr
Service [AUTO] ParVdm
Service C:\WINDOWS\System32\DRIVERS\pci.sys [BOOT] PCI
Service [SYSTEM] PCIDump
Service C:\WINDOWS\System32\DRIVERS\pciide.sys [BOOT] PCIIde
Service [DISABLED] Pcmcia
Service [MANUAL] PDCOMP
Service [MANUAL] PDFRAME
Service [MANUAL] PDRELI
Service [MANUAL] PDRFRAME
Service [DISABLED] perc2
Service [DISABLED] perc2hib
Service PerfDisk
Service PerfNet
Service PerfOS
Service PerfProc
Service C:\WINDOWS\system32\drivers\pfc.sys [MANUAL] Pfc
Service C:\WINDOWS\system32\services.exe [AUTO] PlugPlay
Service C:\WINDOWS\System32\lsass.exe [AUTO] PolicyAgent
Service C:\WINDOWS\System32\DRIVERS\raspptp.sys [MANUAL] PptpMiniport
Service [SYSTEM] PQNTDrv
Service C:\WINDOWS\System32\DRIVERS\processr.sys [SYSTEM] Processor
Service C:\WINDOWS\system32\lsass.exe [AUTO] ProtectedStorage
Service C:\WINDOWS\System32\DRIVERS\psched.sys [MANUAL] PSched
Service C:\WINDOWS\System32\DRIVERS\ptilink.sys [MANUAL] Ptilink
Service C:\WINDOWS\system32\DRIVERS\PxHelp20.sys [BOOT] PxHelp20
Service [DISABLED] ql1080
Service [DISABLED] Ql10wnt
Service [DISABLED] ql12160
Service [DISABLED] ql1240
Service [DISABLED] ql1280
Service C:\WINDOWS\System32\DRIVERS\rasacd.sys [SYSTEM] RasAcd
Service C:\WINDOWS\System32\svchost.exe [MANUAL] RasAuto
Service C:\WINDOWS\System32\DRIVERS\rasl2tp.sys [MANUAL] Rasl2tp
Service C:\WINDOWS\System32\svchost.exe [MANUAL] RasMan
Service C:\WINDOWS\System32\DRIVERS\raspppoe.sys [MANUAL] RasPppoe
Service C:\WINDOWS\System32\DRIVERS\raspti.sys [MANUAL] Raspti
Service C:\WINDOWS\System32\DRIVERS\rdbss.sys [SYSTEM] Rdbss
Service C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [SYSTEM] RDPCDD
Service RDPDD
Service RDPNP
Service [MANUAL] RDPWD
Service C:\WINDOWS\system32\sessmgr.exe [MANUAL] RDSessMgr
Service C:\WINDOWS\System32\DRIVERS\redbook.sys [SYSTEM] redbook
Service C:\WINDOWS\System32\svchost.exe [DISABLED] RemoteAccess
Service C:\WINDOWS\System32\locator.exe [MANUAL] RpcLocator
Service C:\WINDOWS\system32\svchost.exe [AUTO] RpcSs
Service C:\WINDOWS\System32\rsvp.exe [MANUAL] RSVP
Service C:\WINDOWS\System32\DRIVERS\R8139n51.SYS [MANUAL] rtl8139
Service C:\WINDOWS\system32\lsass.exe [AUTO] SamSs
Service C:\WINDOWS\System32\SCardSvr.exe [MANUAL] SCardSvr
Service C:\WINDOWS\System32\svchost.exe [AUTO] Schedule
Service ScsiPort
Service C:\WINDOWS\System32\DRIVERS\secdrv.sys [AUTO] Secdrv
Service C:\WINDOWS\System32\svchost.exe [AUTO] seclogon
Service C:\WINDOWS\system32\svchost.exe [AUTO] SENS
Service C:\WINDOWS\System32\DRIVERS\serenum.sys [MANUAL] serenum
Service C:\WINDOWS\System32\DRIVERS\serial.sys [SYSTEM] Serial
Service C:\WINDOWS\System32\drivers\sfdrv01.sys [BOOT] sfdrv01
Service C:\WINDOWS\System32\drivers\sfhlp02.sys [BOOT] sfhlp02
Service [SYSTEM] Sfloppy
Service C:\WINDOWS\System32\drivers\sfsync04.sys [BOOT] sfsync04
Service SharedAccess
Service C:\WINDOWS\System32\svchost.exe [AUTO] ShellHWDetection
Service [DISABLED] Simbad
Service [DISABLED] Sparrow
Service C:\WINDOWS\system32\drivers\splitter.sys [MANUAL] splitter
Service C:\WINDOWS\system32\spoolsv.exe [AUTO] Spooler
Service C:\WINDOWS\System32\Drivers\sptd.sys [BOOT] sptd
Service C:\WINDOWS\System32\DRIVERS\sr.sys [BOOT] sr
Service C:\WINDOWS\System32\svchost.exe [AUTO] srservice
Service C:\WINDOWS\System32\DRIVERS\srv.sys [MANUAL] Srv
Service C:\WINDOWS\System32\svchost.exe [DISABLED] SSDPSRV
Service C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [AUTO] StarWindService
Service C:\WINDOWS\System32\svchost.exe [AUTO] stisvc
Service C:\WINDOWS\System32\DRIVERS\swenum.sys [MANUAL] swenum
Service C:\WINDOWS\system32\drivers\swmidi.sys [MANUAL] swmidi
Service C:\WINDOWS\System32\dllhost.exe [MANUAL] SwPrv
Service swwd
Service [DISABLED] symc810
Service [DISABLED] symc8xx
Service C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe [AUTO] SymWSC
Service [DISABLED] sym_hi
Service [DISABLED] sym_u3
Service C:\WINDOWS\system32\drivers\sysaudio.sys [MANUAL] sysaudio
Service C:\WINDOWS\system32\smlogsvc.exe [MANUAL] SysmonLog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TapiSrv
Service C:\WINDOWS\System32\DRIVERS\tcpip.sys [SYSTEM] Tcpip
Service [MANUAL] TDPIPE
Service [MANUAL] TDTCP
Service C:\WINDOWS\System32\DRIVERS\termdd.sys [SYSTEM] TermDD
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TermService
Service C:\WINDOWS\System32\svchost.exe [AUTO] Themes
Service C:\DOCUME~1\MATEUS~1\USTAWI~1\Temp\tni3D.tmp [MANUAL] TnIDriver
Service [DISABLED] TosIde
Service C:\WINDOWS\system32\svchost.exe [AUTO] TrkWks
Service TSDDD
Service [DISABLED] Udfs
Service [DISABLED] ultra
Service C:\WINDOWS\System32\DRIVERS\update.sys [MANUAL] Update
Service C:\WINDOWS\System32\svchost.exe [DISABLED] upnphost
Service C:\WINDOWS\System32\ups.exe [MANUAL] UPS
Service C:\WINDOWS\System32\DRIVERS\usbccgp.sys [MANUAL] usbccgp
Service C:\WINDOWS\System32\DRIVERS\usbehci.sys [MANUAL] usbehci
Service C&
NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA



Postprzez wojtas 10 Kwi 2007, 18:46

W Gmerze w zakładce CMD z zaznaczoną opcją CMD.EXE wklej:

gmer -killall
gmer -del service Client IP-IPX
gmer -del service Themes
gmer -del file C:\WINDOWS\system32\svchosts.exe
gmer -del file C:\DOCUME~1\MATEUS~1\USTAWI~1\Temp\tni3D.tmp
gmer –reboot



I kliknij z prawej strony na Uruchom.

1 log dales dobry ale w drugi zly.W Drugim logu maja byc zaznaczone tylko uslugi i pokaz wszystko.
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez kybula 10 Kwi 2007, 18:47

ups..zle wyslalem,poprawka-:
nie moge wyslac calego loga na raz bo jest za dlugi i serwer sie pluje wiec dziele go na polowy.


Kod: Zaznacz wszystko
GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-04-10 11:28:41
Windows 5.1.2600 Dodatek Service Pack 2


---- System - GMER 1.0.12 ----

SSDT    \SystemRoot\system32\drivers\core.sys                                                                    ZwClose
SSDT    \SystemRoot\system32\drivers\core.sys                                                                    ZwCreateKey
SSDT    \SystemRoot\system32\drivers\core.sys                                                                    ZwDeleteKey
SSDT    \SystemRoot\system32\drivers\core.sys                                                                    ZwDeleteValueKey
SSDT    sptd.sys                                                                                                 ZwEnumerateKey
SSDT    sptd.sys                                                                                                 ZwEnumerateValueKey
SSDT    \SystemRoot\system32\drivers\core.sys                                                                    ZwLoadKey
SSDT    \SystemRoot\system32\drivers\core.sys                                                                    ZwOpenKey
SSDT    sptd.sys                                                                                                 ZwQueryKey
SSDT    sptd.sys                                                                                                 ZwQueryValueKey
SSDT    \SystemRoot\system32\drivers\core.sys                                                                    ZwReplaceKey
SSDT    \SystemRoot\system32\drivers\core.sys                                                                    ZwRestoreKey
SSDT    \SystemRoot\system32\drivers\core.sys                                                                    ZwSetValueKey

---- Kernel code sections - GMER 1.0.12 ----

?       C:\WINDOWS\system32\drivers\sptd.sys                                                                     Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
.text   USBPORT.SYS!DllUnload                                                                                    F67A562C 5 Bytes  JMP 865A21B8
?       C:\WINDOWS\System32\Drivers\dtscsi.sys                                                                   Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
?       C:\WINDOWS\system32\drivers\core.sys                                                                     Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.

---- Devices - GMER 1.0.12 ----


[ Dodano: Dzisiaj o 17:49 ]
Kod: Zaznacz wszystko
---- Devices - GMER 1.0.12 ----

Device  \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE                                                                     867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE                                                                      867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_READ                                                                       867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE                                                                      867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION                                                          867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION                                                            867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA                                                                   867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA                                                                     867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS                                                              867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION                                                   867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION                                                     867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL                                                          867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL                                                        867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL                                                             867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN                                                                   867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL                                                               867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP                                                                    867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY                                                             867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY                                                               867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA                                                                867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA                                                                  867D21D8
Device  \FileSystem\Ntfs \Ntfs IRP_MJ_PNP                                                                        867D21D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{A434A052-594D-4B4F-BB16-618B124693E4} IRP_MJ_CREATE                   861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{A434A052-594D-4B4F-BB16-618B124693E4} IRP_MJ_CLOSE                    861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{A434A052-594D-4B4F-BB16-618B124693E4} IRP_MJ_DEVICE_CONTROL           861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{A434A052-594D-4B4F-BB16-618B124693E4} IRP_MJ_INTERNAL_DEVICE_CONTROL  861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{A434A052-594D-4B4F-BB16-618B124693E4} IRP_MJ_CLEANUP                  861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{A434A052-594D-4B4F-BB16-618B124693E4} IRP_MJ_PNP                      861DD1D8
Device  \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE                                                           865A11D8
Device  \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE                                                            865A11D8
Device  \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          865A11D8
Device  \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER                                                            865A11D8
Device  \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP                                                              865A11D8
Device  \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE                                                           865A11D8
Device  \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE                                                            865A11D8
Device  \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          865A11D8
Device  \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER                                                            865A11D8
Device  \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP                                                              865A11D8
Device  \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE                                                           865A11D8
Device  \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE                                                            865A11D8
Device  \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          865A11D8
Device  \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER                                                            865A11D8
Device  \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP                                                              865A11D8
Device  \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE                                                           865A11D8
Device  \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE                                                            865A11D8
Device  \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          865A11D8
Device  \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER                                                            865A11D8
Device  \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP                                                              865A11D8
Device  \Driver\00000116 \Device\00000047 IRP_MJ_POWER                                                           [F7779D74] sptd.sys
Device  \Driver\00000116 \Device\00000047 IRP_MJ_SYSTEM_CONTROL                                                  [F77932A2] sptd.sys
Device  \Driver\00000116 \Device\00000047 IRP_MJ_PNP                                                             [F7794228] sptd.sys
Device  \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CREATE                                                           86574980
Device  \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CLOSE                                                            86574980
Device  \Driver\usbehci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL                                                   86574980
Device  \Driver\usbehci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          86574980
Device  \Driver\usbehci \Device\USBPDO-4 IRP_MJ_POWER                                                            86574980
Device  \Driver\usbehci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL                                                   86574980
Device  \Driver\usbehci \Device\USBPDO-4 IRP_MJ_PNP                                                              86574980
Device  \Driver\NetBT \Device\NetBT_Tcpip_{2B5EF327-9852-4281-9BD9-A5F78737EB6F} IRP_MJ_CREATE                   861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{2B5EF327-9852-4281-9BD9-A5F78737EB6F} IRP_MJ_CLOSE                    861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{2B5EF327-9852-4281-9BD9-A5F78737EB6F} IRP_MJ_DEVICE_CONTROL           861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{2B5EF327-9852-4281-9BD9-A5F78737EB6F} IRP_MJ_INTERNAL_DEVICE_CONTROL  861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{2B5EF327-9852-4281-9BD9-A5F78737EB6F} IRP_MJ_CLEANUP                  861DD1D8
Device  \Driver\NetBT \Device\NetBT_Tcpip_{2B5EF327-9852-4281-9BD9-A5F78737EB6F} IRP_MJ_PNP                      861DD1D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE                                                     867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ                                                       867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE                                                      867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS                                              867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL                                             867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL                                    867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN                                                   867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP                                                    867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER                                                      867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL                                             867611D8
Device  \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP                                                        867611D8
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE                                                               8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE                                                                8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ                                                                 8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE                                                                8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS                                                        8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL                                                       8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL                                              8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN                                                             8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER                                                                8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL                                                       8655C918
Device  \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP                                                                  8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE                                                               8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE                                                                8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ                                                                 8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE                                                                8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS                                                        8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL                                                       8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL                                              8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN                                                             8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER                                                                8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL                                                       8655C918
Device  \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP                                                                  8655C918
Device  \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE                                                867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE                                                 867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL                                        867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL                               [F7701A6C] sfsync04.sys
Device  \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER                                                 867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL                                        867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP                                                   867D31D8
Device  \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE                                                         867D31D8
Device  \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE                                                          867D31D8
Device  \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL                                                 867D31D8
Device  \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL                                        [F7701A6C] sfsync04.sys
Device  \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER                                                          867D31D8
Device  \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL                                                 867D31D8
Device  \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP                                                            867D31D8
Device  \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE                                                         867D31D8
Device  \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE                                                          867D31D8
Device  \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL                                                 867D31D8
Device  \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL                                        [F7701A6C] sfsync04.sys
Device  \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER                                                          867D31D8
Device  \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL                                                 867D31D8
Device  \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP                                                            867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CREATE                                                867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CLOSE                                                 867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_DEVICE_CONTROL                                        867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_INTERNAL_DEVICE_CONTROL                               [F7701A6C] sfsync04.sys
Device  \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_POWER                                                 867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SYSTEM_CONTROL                                        867D31D8
Device  \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_PNP                                                   867D31D8
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE                                                               8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE                                                                8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ                                                                 8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE                                                                8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS                                                        8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL                                                       8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL                                              8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN                                                             8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER                                                                8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL                                                       8655C918
Device  \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP                                                                  8655C918
Device  \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE                                                    861DD1D8
Device  \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE                                                     861DD1D8
Device  \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL                                            861DD1D8
Device  \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL                                   861DD1D8
Device  \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP                                                   861DD1D8
Device  \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP                                                       861DD1D8
Device  \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE                                                           865A11D8
Device  \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE                                                            865A11D8
Device  \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          865A11D8
Device  \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER                                                            865A11D8
Device  \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP                                                              865A11D8
Device  \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE                                                           865A11D8
Device  \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE                                                            865A11D8
Device  \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          865A11D8
Device  \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER                                                            865A11D8
Device  \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP                                                              865A11D8
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE                                          862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE                               862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE                                           862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ                                            862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE                                           862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION                               862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION                                 862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA                                        862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA                                          862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS                                   862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION                        862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION                          862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL                               862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL                             862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL                                  862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL                         862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN                                        862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL                                    862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP                                         862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT                                 862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY                                  862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY                                    862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER                                           862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL                                  862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE                                   862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA                                     862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA                                       862C0980
Device  \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP                                             862C0980
Device  \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CREATE                                                           865A11D8
Device  \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CLOSE                                                            865A11D8
Device  \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          865A11D8
Device  \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_POWER                                                            865A11D8
Device  \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_PNP                                                              865A11D8
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE                                                862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE                                     862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE                                                 862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ                                                  862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE                                                 862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION                                     862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION                                       862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA                                              862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA                                                862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS                                         862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION                              862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION                                862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL                                     862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL                                   862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL                                        862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL                               862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN                                              862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL                                          862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP                                               862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT                                       862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY                                        862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY                                          862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER                                                 862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL                                        862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE                                         862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA                                           862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA                                             862C0980
Device  \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP                                                   862C0980
Device  \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CREATE                                                           865A11D8
Device  \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CLOSE                                                            865A11D8
Device  \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          865A11D8
Device  \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_POWER                                                            865A11D8
Device  \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL                                                   865A11D8
Device  \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_PNP                                                              865A11D8
Device  \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CREATE                                                           86574980
Device  \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CLOSE                                                            86574980
Device  \Driver\usbehci \Device\USBFDO-4 IRP_MJ_DEVICE_CONTROL                                                   86574980
Device  \Driver\usbehci \Device\USBFDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL                                          86574980
Device  \Driver\usbehci \Device\USBFDO-4 IRP_MJ_POWER                                                            86574980
Device  \Driver\usbehci \Device\USBFDO-4 IRP_MJ_SYSTEM_CONTROL                                                   86574980
Device  \Driver\usbehci \Device\USBFDO-4 IRP_MJ_PNP                                                              86574980
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE                                                           867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_READ                                                             867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE                                                            867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS                                                    867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL                                                   867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL                                          867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN                                                         867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP                                                          867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER                                                            867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL                                                   867611D8
Device  \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP                                                              867611D8
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_CREATE                                   864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_CLOSE                                    864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_DEVICE_CONTROL                           864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL                  [F7701A6C] sfsync04.sys
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_POWER                                    864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_SYSTEM_CONTROL                           864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_PNP                                      864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CREATE                                   864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CLOSE                                    864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL                           864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL                  [F7701A6C] sfsync04.sys
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_POWER                                    864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL                           864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_PNP                                      864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE                                                        864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CLOSE                                                         864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_DEVICE_CONTROL                                                864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL                                       [F7701A6C] sfsync04.sys
Device  \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_POWER                                                         864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SYSTEM_CONTROL                                                864E6958
Device  \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_PNP                                                           864E6958
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE                                                                     861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE                                                                      861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_READ                                                                       861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION                                                          861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION                                                            861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION                                                   861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL                                                          861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL                                                        861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL                                                             861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN                                                                   861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL                                                               861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP                                                                    861A61D8
Device  \FileSystem\Cdfs \Cdfs IRP_MJ_PNP                                                                        861A61D8

---- Modules - GMER 1.0.12 ----

Module  (noname) (*** hidden *** )                                                                               F7AA2000                                                                               

---- EOF - GMER 1.0.12 ----
NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA



Postprzez wojtas 10 Kwi 2007, 20:14

ok czekam na nowe logi po usuwaniu
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez kybula 10 Kwi 2007, 21:09

comoboscana za kazdym razem gdy chce uruchomic musze pobierac od nowa bo cos sie wali, wogole nic juz nie dziala, za kazdym razem jakies bledy.. nie ma programu ktory wszystko by ot tak zrobil? chocm\by sie 5 godzin meczyl? mam na kompie pelno potrzebnych rzeczy i nie moge formatowac...

skasowac svchosts nie moge bo byl blad.
NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA



Postprzez wojtas 10 Kwi 2007, 21:10

nowe logi daj z gmera i comboscana wrzuc na jakis serwer 3 logi 2 z gmera i combo.... jakie bledy??
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez kybula 17 Kwi 2007, 22:03

dzieki za pomoc ale juz jestem po formacie-przymierzalem sioe do tego od dawna a przez dwa miesiace jeszcze bym tego nie zrobil wiec zgralem kilkadziesiac giga na plyty i sie udalo. Dzieki za pomoc:P
NO FORMAT C...fight to die
kybula
~user
 
Posty: 64
Dołączenie: 19 Sty 2006, 20:33
Miejscowość: WWA




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 20 gości