Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3900: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3902: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3903: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3904: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
Pozostałości po wirusie? • programosy.pl

  • Ogłoszenie:

Pozostałości po wirusie?

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Pozostałości po wirusie?

Postprzez Manieq 11 Lis 2008, 14:10

reklama
Witam. Dzisiaj mój nod wykrył Trojana. Nie chciał go usunąć, zainstalowałem najnowszego Kasperskiego. Teraz pytanie, czy wszystko jest dobrze, bo prędkość internetu nie jest zadowalająca :) Logi:
Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:52:44, on 2008-11-11
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Porządkujące\Advanced WindowsCare V2 Pro\Awc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Komunikatory\Gadu-Gadu\gg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Użytkowe\Desktop Sidebar\dsidebar.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Użytkowe\Java\bin\jqs.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\PROGRA~1\PRZEGL~1\MOZILL~1\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Manieq\Pulpit\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Użytkowe\Desktop Sidebar\sbhelp.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\Biuro\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Użytkowe\Java\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Użytkowe\Java\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Użytkowe\Java\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Advanced WindowsCare V2 Pro] "C:\Program Files\Porządkujące\Advanced WindowsCare V2 Pro\Awc.exe" /startup
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Komunikatory\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SIDEBAR] "C:\Program Files\Użytkowe\Desktop Sidebar\dsidebar.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\Biuro\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Użytkowe\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Użytkowe\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Biuro\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Biuro\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Biuro\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1EE116A-6715-4784-8B2D-014D214B5988}: NameServer = 82.177.140.1,82.177.174.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\Biuro\MICROS~1\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Kaspersky Lab\Kaspersky Anti-Virus 2009\mzvkbd.dll,C:\PROGRA~1\Kaspersky Lab\Kaspersky Anti-Virus 2009\mzvkbd3.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Użytkowe\Java\bin\jqs.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)

--
End of file - 6950 bytes


Combofix:
Kod: Zaznacz wszystko
ComboFix 08-11-10.01 - Manieq 2008-11-11 13:00:04.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1250.1.1045.18.528 [GMT 1:00]
Uruchomiony z: C:\Documents and Settings\Manieq\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania

[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.

(((((((((((((((((((((((((((((((((((((((   Usunięto   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\msvrc20.dll

.
(((((((((((((((((((((((((   Pliki utworzone od 2008-10-11 do 2008-11-11  )))))))))))))))))))))))))))))))
.

2008-11-11 13:04 . 2008-11-11 13:04   <DIR>   d--------   C:\WINDOWS\system32\xircom
2008-11-11 13:04 . 2008-11-11 13:04   <DIR>   d--------   C:\Program Files\microsoft frontpage
2008-11-11 10:24 . 2008-11-11 10:24   <DIR>   d--------   C:\Program Files\Kaspersky Lab
2008-11-11 10:24 . 2008-11-11 13:05   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-11-11 10:24 . 2008-11-11 13:03   4,895,776   --ahs----   C:\WINDOWS\system32\drivers\fidbox.dat
2008-11-11 10:24 . 2008-11-11 13:03   270,368   --ahs----   C:\WINDOWS\system32\drivers\fidbox2.dat
2008-11-11 10:24 . 2008-11-11 10:24   96,976   --a------   C:\WINDOWS\system32\drivers\klin.dat
2008-11-11 10:24 . 2008-11-11 10:24   87,855   --a------   C:\WINDOWS\system32\drivers\klick.dat
2008-11-11 10:24 . 2008-11-11 13:03   41,424   --ahs----   C:\WINDOWS\system32\drivers\fidbox.idx
2008-11-11 10:24 . 2008-11-11 13:03   4,100   --ahs----   C:\WINDOWS\system32\drivers\fidbox2.idx
2008-11-11 10:18 . 2008-11-11 10:18   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-11-11 09:22 . 2008-11-11 09:22   <DIR>   d--------   C:\Program Files\Odzyskiwanie Danych
2008-11-09 14:11 . 2008-11-09 14:11   <DIR>   d--------   C:\Documents and Settings\Manieq\Dane aplikacji\Media Player Classic
2008-11-08 15:50 . 2008-11-08 17:08   754   --a------   C:\WINDOWS\WORDPAD.INI
2008-11-08 15:21 . 2008-11-08 15:26   <DIR>   d--------   C:\Program Files\VstPlugins
2008-11-08 15:21 . 2002-07-07 23:14   1,294,336   --a------   C:\WINDOWS\system32\vorbis.acm
2008-11-08 15:21 . 2006-06-20 09:56   225,280   --a------   C:\WINDOWS\system32\rewire.dll
2008-11-08 15:19 . 2008-11-08 15:26   <DIR>   d--------   C:\Program Files\Image-Line
2008-11-08 14:47 . 2008-11-08 14:47   <DIR>   d--------   C:\Documents and Settings\Manieq\.mysqlcc
2008-11-08 11:08 . 2007-06-19 21:52   419,840   --a------   C:\WINDOWS\system32\ws_edit.lib
2008-11-08 11:08 . 2006-08-17 22:37   130,048   --a------   C:\WINDOWS\system32\webserv.cpl
2008-11-08 11:07 . 2008-11-08 16:27   45,963   --a------   C:\WINDOWS\php.ini
2008-11-08 11:07 . 2008-11-08 14:29   502   --a------   C:\WINDOWS\my.ini
2008-11-08 11:06 . 2008-11-08 11:06   <DIR>   d--------   C:\Program Files\WWW
2008-11-08 00:36 . 2008-11-08 00:36   <DIR>   d--------   C:\Program Files\Macromedia
2008-11-08 00:33 . 2008-11-08 00:33   <DIR>   d--------   C:\WINDOWS\system32\QuickTime
2008-11-08 00:33 . 2008-11-08 00:33   <DIR>   d--------   C:\Program Files\Common Files\Macromedia
2008-11-06 20:02 . 2008-11-06 20:02   <DIR>   d--------   C:\Program Files\Gry
2008-11-06 17:45 . 2008-11-06 17:45   <DIR>   d--------   C:\Documents and Settings\Manieq\Dane aplikacji\teamspeak2
2008-11-06 15:55 . 2008-11-06 15:55   <DIR>   d--------   C:\Program Files\TightVNC
2008-11-05 21:56 . 2008-11-05 21:56   <DIR>   d--------   C:\WINDOWS\system32\Adobe
2008-11-05 18:01 . 2008-11-05 18:05   81,920   --a------   C:\WINDOWS\ALCFDRTM.VER
2008-11-05 18:01 . 2008-11-05 18:01   81,920   --a------   C:\WINDOWS\ALCFDRTM.EXE
2008-11-05 16:46 . 1998-10-07 13:54   327,168   --a------   C:\WINDOWS\IsUn0415.exe
2008-11-04 15:57 . 2008-11-04 15:57   <DIR>   d--------   C:\Program Files\Dźwięki
2008-11-03 07:31 . 2008-11-03 07:44   1,674   --a------   C:\explo.pl
2008-11-03 07:26 . 2008-11-06 17:27   <DIR>   d--------   C:\Documents and Settings\Manieq\Dane aplikacji\Skype
2008-11-03 07:25 . 2008-11-03 07:31   <DIR>   d--------   C:\Perl
2008-11-02 18:06 . 2008-11-04 20:03   <DIR>   d--------   C:\Documents and Settings\Manieq\Dane aplikacji\XnView
2008-11-02 15:53 . 2008-04-14 00:15   60,032   --a------   C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-11-01 14:28 . 2008-11-10 21:51   69   --a------   C:\WINDOWS\NeroDigital.ini
2008-11-01 12:56 . 2008-11-01 13:16   <DIR>   d--------   C:\Program Files\Porządkujące
2008-11-01 11:55 . 2008-11-11 13:03   <DIR>   d--------   C:\Documents and Settings\Manieq\Dane aplikacji\Desktop Sidebar
2008-11-01 11:40 . 2008-11-01 11:42   <DIR>   d--------   C:\Documents and Settings\Manieq\Pasek Boczny
2008-11-01 11:07 . 2005-09-14 20:17   20,016   ---------   C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-11-01 10:55 . 2008-11-01 10:55   <DIR>   d--------   C:\Documents and Settings\Manieq\Dane aplikacji\WinAmp Control
2008-11-01 10:26 . 2008-11-08 16:57   <DIR>   d--------   C:\Program Files\Google
2008-11-01 10:22 . 2000-05-17 09:52   187,392   --a------   C:\WINDOWS\system32\JPGUtils.dll
2008-11-01 10:22 . 2008-11-01 10:22   24   --a------   C:\WINDOWS\LogonStudio.ini
2008-11-01 10:03 . 2008-11-01 10:02   410,976   --a------   C:\WINDOWS\system32\deploytk.dll
2008-11-01 10:03 . 2008-11-01 10:02   73,728   --a------   C:\WINDOWS\system32\javacpl.cpl
2008-11-01 00:09 . 2008-11-08 12:07   <DIR>   d--------   C:\Program Files\SAM
2008-10-31 23:53 . 2008-11-08 15:46   <DIR>   d--------   C:\Documents and Settings\Manieq\Dane aplikacji\MySQL
2008-10-31 23:44 . 2008-10-31 23:52   <DIR>   d--------   C:\Program Files\MySQL
2008-10-31 23:20 . 2008-10-31 23:20   0   --a------   C:\WINDOWS\nsreg.dat
2008-10-31 22:52 . 2006-10-26 19:56   32,592   --a------   C:\WINDOWS\system32\msonpmon.dll
2008-10-31 22:50 . 2008-10-31 22:50   <DIR>   d--------   C:\Program Files\Microsoft Works
2008-10-31 22:49 . 2008-10-31 22:49   <DIR>   d--------   C:\Program Files\MSBuild
2008-10-31 22:44 . 2008-10-31 22:49   <DIR>   d--------   C:\WINDOWS\SHELLNEW
2008-10-31 22:43 . 2008-10-31 22:43   <DIR>   dr-h-----   C:\MSOCache
2008-10-31 22:43 . 2008-11-03 16:37   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-10-31 22:38 . 2008-10-31 22:38   <DIR>   d--h-----   C:\WINDOWS\system32\GroupPolicy
2008-10-31 22:38 . 2008-10-31 22:57   <DIR>   d--------   C:\Program Files\ObjectDock
2008-10-31 22:38 . 2008-11-01 10:24   <DIR>   d--------   C:\Program Files\Common Files\Stardock
2008-10-31 22:38 . 2008-10-31 22:38   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\Symantec
2008-10-31 22:36 . 2008-10-31 22:37   <DIR>   d--------   C:\Program Files\Nero
2008-10-31 22:36 . 2008-10-31 22:37   <DIR>   d--------   C:\Program Files\Common Files\Ahead
2008-10-31 22:36 . 2008-10-31 22:36   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\Nero
2008-10-31 22:36 . 2004-07-26 16:16   1,568,768   --a------   C:\WINDOWS\system32\imagX7.dll
2008-10-31 22:36 . 2003-03-19 06:20   1,060,864   --a------   C:\WINDOWS\system32\mfc71.dll
2008-10-31 22:36 . 2003-03-18 20:12   1,047,552   --a------   C:\WINDOWS\system32\mfc71u.dll
2008-10-31 22:36 . 2003-03-18 22:14   499,712   --a------   C:\WINDOWS\system32\msvcp71.dll
2008-10-31 22:36 . 2004-07-26 16:16   476,320   --a------   C:\WINDOWS\system32\imagXpr7.dll
2008-10-31 22:36 . 2004-07-26 16:16   471,040   --a------   C:\WINDOWS\system32\imagXRA7.dll
2008-10-31 22:36 . 2004-07-09 08:43   364,544   --a------   C:\WINDOWS\system32\TwnLib4.dll
2008-10-31 22:36 . 2003-02-21 04:42   348,160   --a------   C:\WINDOWS\system32\msvcr71.dll
2008-10-31 22:36 . 2004-07-26 16:16   262,144   --a------   C:\WINDOWS\system32\imagXR7.dll
2008-10-31 22:31 . 2008-10-31 23:19   <DIR>   d--------   C:\Program Files\Przeglądarki
2008-10-31 22:28 . 2008-11-01 11:56   <DIR>   d--------   C:\Program Files\Kodeki
2008-10-31 22:26 . 2008-10-31 22:26   <DIR>   d--------   C:\Documents and Settings\Manieq\Dane aplikacji\Gadu-Gadu
2008-10-31 22:26 . 2008-10-31 22:26   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-10-31 22:25 . 2008-11-06 17:44   <DIR>   d--------   C:\Program Files\Komunikatory
2008-10-31 22:25 . 2008-11-03 00:12   <DIR>   d--------   C:\Documents and Settings\Manieq\Gadu-Gadu
2008-10-31 22:18 . 2008-11-08 00:32   <DIR>   d--------   C:\WINDOWS\Downloaded Installations
2008-10-31 22:18 . 2004-08-22 16:31   155,136   --a------   C:\WINDOWS\system32\drivers\d347bus.sys
2008-10-31 22:18 . 2004-08-22 16:31   5,248   --a------   C:\WINDOWS\system32\drivers\d347prt.sys
2008-10-31 22:07 . 2008-10-31 22:43   <DIR>   d--------   C:\Program Files\Biuro
2008-10-31 22:04 . 2008-10-31 22:04   <DIR>   d--------   C:\Program Files\Bonjour
2008-10-31 22:04 . 2008-04-14 22:51   129,536   --a------   C:\WINDOWS\system32\ksproxy.ax
2008-10-31 22:03 . 2008-04-14 22:35   58,880   --a------   C:\WINDOWS\system32\drivers\redbook.sys
2008-10-31 22:03 . 2008-04-14 01:06   14,208   --a------   C:\WINDOWS\system32\drivers\battc.sys
2008-10-31 22:03 . 2008-04-14 01:06   13,952   --a------   C:\WINDOWS\system32\drivers\CmBatt.sys
2008-10-31 22:03 . 2008-04-14 01:06   10,240   --a------   C:\WINDOWS\system32\drivers\compbatt.sys
2008-10-31 22:02 . 2008-04-14 23:50   77,312   --a------   C:\WINDOWS\system32\usbui.dll
2008-10-31 22:02 . 2008-04-14 01:06   8,832   --a------   C:\WINDOWS\system32\drivers\wmiacpi.sys
2008-10-31 22:00 . 2008-11-11 13:00   <DIR>   d--------   C:\WINDOWS\system32\CatRoot2
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   dr-h-----   C:\Documents and Settings\Default User\Ustawienia lokalne
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--------   C:\Documents and Settings\Default User\Ulubione
2008-10-31 22:00 . 2008-10-31 21:11   <DIR>   d--h-----   C:\Documents and Settings\Default User\Szablony
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--------   C:\Documents and Settings\Default User\Pulpit
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--------   C:\Documents and Settings\Default User\Moje dokumenty
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   dr-------   C:\Documents and Settings\Default User\Menu Start
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   dr-h-----   C:\Documents and Settings\Default User\Dane aplikacji
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--------   C:\Documents and Settings\All Users\Ulubione
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--h-----   C:\Documents and Settings\All Users\Szablony
2008-10-31 22:00 . 2008-11-08 10:30   <DIR>   d--------   C:\Documents and Settings\All Users\Pulpit
2008-10-31 22:00 . 2008-11-08 09:58   <DIR>   dr-------   C:\Documents and Settings\All Users\Menu Start
2008-10-31 22:00 . 2008-10-31 22:05   <DIR>   dr-------   C:\Documents and Settings\All Users\Dokumenty
2008-10-31 22:00 . 2008-11-11 10:24   <DIR>   dr-h-----   C:\Documents and Settings\All Users\Dane aplikacji

.
((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 10:55   ---------   d---a-w   C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-11-11 09:21   ---------   d-----w   C:\Program Files\Bezpieczeństwo
2008-11-09 13:53   ---------   d-----w   C:\Program Files\Dźwięk
2008-11-08 11:07   ---------   d-----w   C:\Program Files\Windows Media Connect 2
2008-11-07 23:33   ---------   d-----w   C:\Program Files\Użytkowe
2008-11-07 23:32   ---------   d-----w   C:\Program Files\Common Files\InstallShield
2008-11-04 18:54   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
2008-11-01 11:51   ---------   d-----w   C:\Program Files\Grafika
2008-11-01 09:23   1,015,296   ----a-w   C:\WINDOWS\system32\logonuiX.exe
2008-10-31 21:07   ---------   d-----w   C:\Program Files\Common Files\Adobe
2008-10-31 20:58   ---------   d-----w   C:\Program Files\Common Files\Macrovision Shared
2008-10-31 20:54   298,104   ----a-w   C:\WINDOWS\system32\imon.dll
2008-10-31 20:43   ---------   d-----w   C:\Documents and Settings\Manieq\Dane aplikacji\URSoft
2008-10-31 20:35   ---------   d-----w   C:\Program Files\Synaptics
2008-10-31 20:35   ---------   d-----w   C:\Program Files\Intel
2008-10-31 20:30   ---------   d-----w   C:\Program Files\Realtek
2008-10-31 20:25   ---------   d-----w   C:\Program Files\Firebird
2008-10-31 20:14   ---------   d-----w   C:\Program Files\Usługi online
.

------- Sigcheck -------

2008-05-02 07:48  361344  8e036eec565910417ea020ce0962aa24   C:\WINDOWS\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="C:\Program Files\Komunikatory\Gadu-Gadu\gg.exe" [2007-07-09 08:39 2119104]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 21:51 15360]
"SIDEBAR"="C:\Program Files\Użytkowe\Desktop Sidebar\dsidebar.exe" [2006-07-09 21:58 1777664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 12:07 761946]
"Advanced WindowsCare V2 Pro"="C:\Program Files\Porządkujące\Advanced WindowsCare V2 Pro\Awc.exe" [2006-11-21 20:19 2507776]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 19:20 206088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 21:51 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2008-03-01 15:02 124928 C:\WINDOWS\system32\advpack.dll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 14:13 49152 C:\PROGRA~1\COMMON~1\Stardock\MCPStub.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Biuro\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Biuro\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Biuro\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Komunikatory\\Skype\\Phone\\Skype.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 17:29 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 17:06 24592]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09186593-af2b-11dd-ab8a-0016d4c9b294}]
\Shell\AutoRun\command - H:\whi.com
\Shell\explore\Command - H:\whi.com
\Shell\open\Command - H:\whi.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{576f9d19-af68-11dd-ab8d-0016d4c9b294}]
\Shell\AutoRun\command - H:\whi.com
\Shell\explore\Command - H:\whi.com
\Shell\open\Command - H:\whi.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e5a648be-a8f8-11dd-ab5e-0016d4c9b294}]
\Shell\AutoRun\command - H:\setup.exe
.
Zawartość folderu 'Zaplanowane zadania'

2008-11-10 C:\WINDOWS\Tasks\Advanced WindowsCare V2 Pro.job
- C:\Program Files\Porz []

2008-11-10 C:\WINDOWS\Tasks\AwcProUpdate.job
- C:\Program Files\Porz []

2008-11-10 C:\WINDOWS\Tasks\AwcProUpdate.job
- C:\Program Files\Porz []
.
- - - - USUNIĘTO PUSTE WPISY - - - -

MSConfigStartUp-kamsoft - C:\WINDOWS\system32\kamsoft.exe


.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\Manieq\Dane aplikacji\Mozilla\Firefox\Profiles\02ng3lol.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.allegro.pl
FF -: plugin - C:\PROGRA~1\PRZEGL~1\MOZILL~1\plugins\npnul32.dll
FF -: plugin - C:\Program Files\Biuro\Reader\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Kodeki\Real Alternative\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\Kodeki\Real Alternative\browser\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\PrzeglÄ…darki\Opera\program\plugins\npdsplay.dll
FF -: plugin - C:\Program Files\PrzeglÄ…darki\Opera\program\plugins\NPOFF12.DLL
FF -: plugin - C:\Program Files\PrzeglÄ…darki\Opera\program\plugins\NPSWF32.dll
FF -: plugin - C:\Program Files\PrzeglÄ…darki\Opera\program\plugins\npwmsdrm.dll
FF -: plugin - C:\Program Files\UĹĽytkowe\Java\bin\new_plugin\npdeploytk.dll
FF -: plugin - C:\Program Files\UĹĽytkowe\Java\bin\new_plugin\npjp2.dll
.

MSConfigStartUp-kamsoft - C:\WINDOWS\system32\kamsoft.exe Ten plik był zainfekowany wirusem, Kasperski go skasował
Sprzedam / zamienię Asusa TF101 16GB + Dock.
Awatar użytkownika
Manieq
~user
 
Posty: 1175
Dołączenie: 20 Gru 2006, 20:24
Miejscowość: Bogatynia
Pochwały: 31



Pozostałości po wirusie?

Postprzez Magik 11 Lis 2008, 14:51

Zastosuj SDFix . Po pobraniu uruchom go a rozpakuje się do C:\SDFix. Uruchom komputer w trybie awaryjnym (F8 przy stracie systemu). Będšc w awaryjnym uruchom plik RunThis.bat z folderu SDFixa. ZatwierdŸ czyszczenie przez Y. Poczekaj aż ukończy i komputer zresetuje



Potem wejdz do folderu C:\SDFix wrzuc zawartoœć pliku Report.txt + log z combofixa oraz daj loga z hijacka
Image Image
Awatar użytkownika
Magik
~user
 
Posty: 7956
Dołączenie: 08 Maj 2004, 09:17
Miejscowość: Głogów
Pochwały: 886



Re: pozostałości po wirusie?

Postprzez Manieq 11 Lis 2008, 17:16

Kod: Zaznacz wszystko
[b]SDFix: Version 1.240 [/b]
Run by Manieq on 2008-11-11 at 14:01

Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


[b]Checking Files [/b]:

No Trojan Files Found






Removing Temp Files

[b]ADS Check [/b]:



                                 [b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-11 14:50:25
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,7e,7a,20,e6,0e,df,a4,a0,9a,eb,17,88,41,ba,05,8a,db,..
"hj34z0"=hex:91,89,b2,c3,35,b6,01,fc,45,f7,12,fe,4a,d1,4d,1e,6a,47,82,78,59,..
"hj34z1"=hex:0e,89,b2,c3,4d,b6,01,fc,44,f7,13,fe,4b,d1,4d,1e,6a,47,82,78,79,..
"hj34z2"=hex:0e,89,b2,c3,4d,b6,01,fc,44,f7,13,fe,4b,d1,4d,1e,6a,47,82,78,79,..
"hj34z3"=hex:0e,89,b2,c3,4d,b6,01,fc,44,f7,13,fe,4b,d1,4d,1e,6a,47,82,78,79,..
"hj34z4"=hex:0e,89,b2,c3,4d,b6,01,fc,44,f7,13,fe,4b,d1,4d,1e,6a,47,82,78,79,..

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"NoPopUpsOnBoot"=dword:00000001
"appinit_dlls"=""

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services [/b]:




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Biuro\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Biuro\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Biuro\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Biuro\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Biuro\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Biuro\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Komunikatory\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Komunikatory\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[b]Remaining Files [/b]:



[b]Files with Hidden Attributes [/b]:

Mon 14 Apr 2008     1,695,232 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Mon 14 Apr 2008        60,928 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"

[b]Finished![/b]



Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:10, on 2008-11-11
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Użytkowe\Java\bin\jqs.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Użytkowe\Desktop Sidebar\dsidebar.exe
C:\PROGRA~1\PRZEGL~1\MOZILL~1\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Manieq\Pulpit\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Użytkowe\Desktop Sidebar\sbhelp.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\Biuro\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Użytkowe\Java\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Użytkowe\Java\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Użytkowe\Java\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Advanced WindowsCare V2 Pro] "C:\Program Files\Porządkujące\Advanced WindowsCare V2 Pro\Awc.exe" /startup
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\PROGRA~1\KOMUNI~1\GADU-G~1\gg.exe" /tray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SIDEBAR] "C:\Program Files\Użytkowe\Desktop Sidebar\dsidebar.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\Biuro\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Użytkowe\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Użytkowe\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Biuro\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Biuro\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Biuro\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1EE116A-6715-4784-8B2D-014D214B5988}: NameServer = 82.177.140.1,82.177.174.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\Biuro\MICROS~1\Office12\GR99D3~1.DLL
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Użytkowe\Java\bin\jqs.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)

--
End of file - 6177 bytes


Kod: Zaznacz wszystko
ComboFix 08-11-10.01 - Manieq 2008-11-11 16:12:06.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1250.1.1045.18.528 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Manieq\Pulpit\ComboFix.exe

[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.

(((((((((((((((((((((((((((((((((((((((   Usunięto   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\msvrc20.dll

.
(((((((((((((((((((((((((   Pliki utworzone od 2008-10-11 do 2008-11-11  )))))))))))))))))))))))))))))))
.

2008-11-11 14:00 . 2008-11-11 14:00   580,096   --a------   c:\windows\system32\dllcache\user32.dll
2008-11-11 13:58 . 2008-11-11 13:58   <DIR>   d--------   c:\windows\ERUNT
2008-11-11 13:55 . 2008-11-11 14:51   <DIR>   d--------   C:\SDFix
2008-11-11 13:04 . 2008-11-11 13:04   <DIR>   d--------   c:\windows\system32\xircom
2008-11-11 13:04 . 2008-11-11 13:04   <DIR>   d--------   c:\program files\microsoft frontpage
2008-11-11 10:24 . 2008-11-11 10:24   <DIR>   d--------   c:\program files\Kaspersky Lab
2008-11-11 10:24 . 2008-11-11 14:51   <DIR>   d--------   c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab
2008-11-11 10:24 . 2008-11-11 13:03   4,895,776   --ahs----   c:\windows\system32\drivers\fidbox.dat
2008-11-11 10:24 . 2008-11-11 16:12   294,944   --ahs----   c:\windows\system32\drivers\fidbox2.dat
2008-11-11 10:24 . 2008-11-11 10:24   96,976   --a------   c:\windows\system32\drivers\klin.dat
2008-11-11 10:24 . 2008-11-11 10:24   87,855   --a------   c:\windows\system32\drivers\klick.dat
2008-11-11 10:24 . 2008-11-11 13:03   41,424   --ahs----   c:\windows\system32\drivers\fidbox.idx
2008-11-11 10:24 . 2008-11-11 16:12   4,184   --ahs----   c:\windows\system32\drivers\fidbox2.idx
2008-11-11 10:18 . 2008-11-11 10:18   <DIR>   d--------   c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-11-11 09:22 . 2008-11-11 09:22   <DIR>   d--------   c:\program files\Odzyskiwanie Danych
2008-11-09 14:11 . 2008-11-09 14:11   <DIR>   d--------   c:\documents and settings\Manieq\Dane aplikacji\Media Player Classic
2008-11-08 15:50 . 2008-11-08 17:08   754   --a------   c:\windows\WORDPAD.INI
2008-11-08 15:21 . 2008-11-08 15:26   <DIR>   d--------   c:\program files\VstPlugins
2008-11-08 15:21 . 2002-07-07 23:14   1,294,336   --a------   c:\windows\system32\vorbis.acm
2008-11-08 15:21 . 2006-06-20 09:56   225,280   --a------   c:\windows\system32\rewire.dll
2008-11-08 15:19 . 2008-11-08 15:26   <DIR>   d--------   c:\program files\Image-Line
2008-11-08 14:47 . 2008-11-08 14:47   <DIR>   d--------   c:\documents and settings\Manieq\.mysqlcc
2008-11-08 11:08 . 2007-06-19 21:52   419,840   --a------   c:\windows\system32\ws_edit.lib
2008-11-08 11:08 . 2006-08-17 22:37   130,048   --a------   c:\windows\system32\webserv.cpl
2008-11-08 11:07 . 2008-11-08 16:27   45,963   --a------   c:\windows\php.ini
2008-11-08 11:07 . 2008-11-08 14:29   502   --a------   c:\windows\my.ini
2008-11-08 11:06 . 2008-11-08 11:06   <DIR>   d--------   c:\program files\WWW
2008-11-08 00:36 . 2008-11-08 00:36   <DIR>   d--------   c:\program files\Macromedia
2008-11-08 00:33 . 2008-11-08 00:33   <DIR>   d--------   c:\windows\system32\QuickTime
2008-11-08 00:33 . 2008-11-08 00:33   <DIR>   d--------   c:\program files\Common Files\Macromedia
2008-11-06 20:02 . 2008-11-06 20:02   <DIR>   d--------   c:\program files\Gry
2008-11-06 17:45 . 2008-11-06 17:45   <DIR>   d--------   c:\documents and settings\Manieq\Dane aplikacji\teamspeak2
2008-11-06 15:55 . 2008-11-06 15:55   <DIR>   d--------   c:\program files\TightVNC
2008-11-05 21:56 . 2008-11-05 21:56   <DIR>   d--------   c:\windows\system32\Adobe
2008-11-05 18:01 . 2008-11-05 18:05   81,920   --a------   c:\windows\ALCFDRTM.VER
2008-11-05 18:01 . 2008-11-05 18:01   81,920   --a------   c:\windows\ALCFDRTM.EXE
2008-11-05 16:46 . 1998-10-07 13:54   327,168   --a------   c:\windows\IsUn0415.exe
2008-11-04 15:57 . 2008-11-04 15:57   <DIR>   d--------   c:\program files\Dźwięki
2008-11-03 07:31 . 2008-11-03 07:44   1,674   --a------   C:\explo.pl
2008-11-03 07:26 . 2008-11-06 17:27   <DIR>   d--------   c:\documents and settings\Manieq\Dane aplikacji\Skype
2008-11-03 07:25 . 2008-11-03 07:31   <DIR>   d--------   C:\Perl
2008-11-02 18:06 . 2008-11-04 20:03   <DIR>   d--------   c:\documents and settings\Manieq\Dane aplikacji\XnView
2008-11-02 15:53 . 2008-04-14 00:15   60,032   --a------   c:\windows\system32\drivers\USBAUDIO.sys
2008-11-01 14:28 . 2008-11-10 21:51   69   --a------   c:\windows\NeroDigital.ini
2008-11-01 12:56 . 2008-11-01 13:16   <DIR>   d--------   c:\program files\Porządkujące
2008-11-01 11:55 . 2008-11-11 13:03   <DIR>   d--------   c:\documents and settings\Manieq\Dane aplikacji\Desktop Sidebar
2008-11-01 11:40 . 2008-11-01 11:42   <DIR>   d--------   c:\documents and settings\Manieq\Pasek Boczny
2008-11-01 11:07 . 2005-09-14 20:17   20,016   ---------   c:\windows\system32\drivers\pxhelp20.sys
2008-11-01 10:55 . 2008-11-01 10:55   <DIR>   d--------   c:\documents and settings\Manieq\Dane aplikacji\WinAmp Control
2008-11-01 10:26 . 2008-11-08 16:57   <DIR>   d--------   c:\program files\Google
2008-11-01 10:22 . 2000-05-17 09:52   187,392   --a------   c:\windows\system32\JPGUtils.dll
2008-11-01 10:22 . 2008-11-01 10:22   24   --a------   c:\windows\LogonStudio.ini
2008-11-01 10:03 . 2008-11-01 10:02   410,976   --a------   c:\windows\system32\deploytk.dll
2008-11-01 10:03 . 2008-11-01 10:02   73,728   --a------   c:\windows\system32\javacpl.cpl
2008-11-01 00:09 . 2008-11-08 12:07   <DIR>   d--------   c:\program files\SAM
2008-10-31 23:53 . 2008-11-08 15:46   <DIR>   d--------   c:\documents and settings\Manieq\Dane aplikacji\MySQL
2008-10-31 23:44 . 2008-10-31 23:52   <DIR>   d--------   c:\program files\MySQL
2008-10-31 23:20 . 2008-10-31 23:20   0   --a------   c:\windows\nsreg.dat
2008-10-31 22:52 . 2006-10-26 19:56   32,592   --a------   c:\windows\system32\msonpmon.dll
2008-10-31 22:50 . 2008-10-31 22:50   <DIR>   d--------   c:\program files\Microsoft Works
2008-10-31 22:49 . 2008-10-31 22:49   <DIR>   d--------   c:\program files\MSBuild
2008-10-31 22:44 . 2008-10-31 22:49   <DIR>   d--------   c:\windows\SHELLNEW
2008-10-31 22:43 . 2008-10-31 22:43   <DIR>   dr-h-----   C:\MSOCache
2008-10-31 22:43 . 2008-11-03 16:37   <DIR>   d--------   c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2008-10-31 22:38 . 2008-10-31 22:38   <DIR>   d--h-----   c:\windows\system32\GroupPolicy
2008-10-31 22:38 . 2008-10-31 22:57   <DIR>   d--------   c:\program files\ObjectDock
2008-10-31 22:38 . 2008-11-01 10:24   <DIR>   d--------   c:\program files\Common Files\Stardock
2008-10-31 22:38 . 2008-10-31 22:38   <DIR>   d--------   c:\documents and settings\All Users\Dane aplikacji\Symantec
2008-10-31 22:36 . 2008-10-31 22:37   <DIR>   d--------   c:\program files\Nero
2008-10-31 22:36 . 2008-10-31 22:37   <DIR>   d--------   c:\program files\Common Files\Ahead
2008-10-31 22:36 . 2008-10-31 22:36   <DIR>   d--------   c:\documents and settings\All Users\Dane aplikacji\Nero
2008-10-31 22:36 . 2004-07-26 16:16   1,568,768   --a------   c:\windows\system32\imagX7.dll
2008-10-31 22:36 . 2003-03-19 06:20   1,060,864   --a------   c:\windows\system32\mfc71.dll
2008-10-31 22:36 . 2003-03-18 20:12   1,047,552   --a------   c:\windows\system32\mfc71u.dll
2008-10-31 22:36 . 2003-03-18 22:14   499,712   --a------   c:\windows\system32\msvcp71.dll
2008-10-31 22:36 . 2004-07-26 16:16   476,320   --a------   c:\windows\system32\imagXpr7.dll
2008-10-31 22:36 . 2004-07-26 16:16   471,040   --a------   c:\windows\system32\imagXRA7.dll
2008-10-31 22:36 . 2004-07-09 08:43   364,544   --a------   c:\windows\system32\TwnLib4.dll
2008-10-31 22:36 . 2003-02-21 04:42   348,160   --a------   c:\windows\system32\msvcr71.dll
2008-10-31 22:36 . 2004-07-26 16:16   262,144   --a------   c:\windows\system32\imagXR7.dll
2008-10-31 22:31 . 2008-10-31 23:19   <DIR>   d--------   c:\program files\Przeglądarki
2008-10-31 22:28 . 2008-11-01 11:56   <DIR>   d--------   c:\program files\Kodeki
2008-10-31 22:26 . 2008-10-31 22:26   <DIR>   d--------   c:\documents and settings\Manieq\Dane aplikacji\Gadu-Gadu
2008-10-31 22:26 . 2008-10-31 22:26   <DIR>   d--------   c:\documents and settings\All Users\Dane aplikacji\Skype
2008-10-31 22:25 . 2008-11-06 17:44   <DIR>   d--------   c:\program files\Komunikatory
2008-10-31 22:25 . 2008-11-03 00:12   <DIR>   d--------   c:\documents and settings\Manieq\Gadu-Gadu
2008-10-31 22:18 . 2008-11-08 00:32   <DIR>   d--------   c:\windows\Downloaded Installations
2008-10-31 22:18 . 2004-08-22 16:31   155,136   --a------   c:\windows\system32\drivers\d347bus.sys
2008-10-31 22:18 . 2004-08-22 16:31   5,248   --a------   c:\windows\system32\drivers\d347prt.sys
2008-10-31 22:07 . 2008-10-31 22:43   <DIR>   d--------   c:\program files\Biuro
2008-10-31 22:04 . 2008-10-31 22:04   <DIR>   d--------   c:\program files\Bonjour
2008-10-31 22:04 . 2008-04-14 22:51   129,536   --a------   c:\windows\system32\ksproxy.ax
2008-10-31 22:03 . 2008-04-14 22:35   58,880   --a------   c:\windows\system32\drivers\redbook.sys
2008-10-31 22:03 . 2008-04-14 01:06   14,208   --a------   c:\windows\system32\drivers\battc.sys
2008-10-31 22:03 . 2008-04-14 01:06   13,952   --a------   c:\windows\system32\drivers\CmBatt.sys
2008-10-31 22:03 . 2008-04-14 01:06   10,240   --a------   c:\windows\system32\drivers\compbatt.sys
2008-10-31 22:02 . 2008-04-14 23:50   77,312   --a------   c:\windows\system32\usbui.dll
2008-10-31 22:02 . 2008-04-14 01:06   8,832   --a------   c:\windows\system32\drivers\wmiacpi.sys
2008-10-31 22:00 . 2008-11-11 16:12   <DIR>   d--------   c:\windows\system32\CatRoot2
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   dr-h-----   c:\documents and settings\Default User\Ustawienia lokalne
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--------   c:\documents and settings\Default User\Ulubione
2008-10-31 22:00 . 2008-10-31 21:11   <DIR>   d--h-----   c:\documents and settings\Default User\Szablony
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--------   c:\documents and settings\Default User\Pulpit
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--------   c:\documents and settings\Default User\Moje dokumenty
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   dr-------   c:\documents and settings\Default User\Menu Start
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   dr-h-----   c:\documents and settings\Default User\Dane aplikacji
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--------   c:\documents and settings\All Users\Ulubione
2008-10-31 22:00 . 2008-10-31 22:00   <DIR>   d--h-----   c:\documents and settings\All Users\Szablony
2008-10-31 22:00 . 2008-11-08 10:30   <DIR>   d--------   c:\documents and settings\All Users\Pulpit
2008-10-31 22:00 . 2008-11-08 09:58   <DIR>   dr-------   c:\documents and settings\All Users\Menu Start
2008-10-31 22:00 . 2008-10-31 22:05   <DIR>   dr-------   c:\documents and settings\All Users\Dokumenty
2008-10-31 22:00 . 2008-11-11 10:24   <DIR>   dr-h-----   c:\documents and settings\All Users\Dane aplikacji

.
((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 10:55   ---------   d---a-w   c:\documents and settings\All Users\Dane aplikacji\TEMP
2008-11-11 09:21   ---------   d-----w   c:\program files\Bezpieczeństwo
2008-11-09 13:53   ---------   d-----w   c:\program files\Dźwięk
2008-11-08 11:07   ---------   d-----w   c:\program files\Windows Media Connect 2
2008-11-07 23:33   ---------   d-----w   c:\program files\Użytkowe
2008-11-07 23:32   ---------   d-----w   c:\program files\Common Files\InstallShield
2008-11-04 18:54   ---------   d--h--w   c:\program files\InstallShield Installation Information
2008-11-01 11:51   ---------   d-----w   c:\program files\Grafika
2008-11-01 09:23   1,015,296   ----a-w   c:\windows\system32\logonuiX.exe
2008-10-31 21:07   ---------   d-----w   c:\program files\Common Files\Adobe
2008-10-31 20:58   ---------   d-----w   c:\program files\Common Files\Macrovision Shared
2008-10-31 20:54   298,104   ----a-w   c:\windows\system32\imon.dll
2008-10-31 20:43   ---------   d-----w   c:\documents and settings\Manieq\Dane aplikacji\URSoft
2008-10-31 20:35   ---------   d-----w   c:\program files\Synaptics
2008-10-31 20:35   ---------   d-----w   c:\program files\Intel
2008-10-31 20:30   ---------   d-----w   c:\program files\Realtek
2008-10-31 20:25   ---------   d-----w   c:\program files\Firebird
2008-10-31 20:14   ---------   d-----w   c:\program files\Usługi online
.

------- Sigcheck -------

2008-05-02 07:48  361344  8e036eec565910417ea020ce0962aa24   c:\windows\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((   snapshot@2008-11-11_13.08.15.37   )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 14:27:04   163,328   ----a-w   c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2008-11-11 12:59:06   3,706,880   ----a-w   c:\windows\ERUNT\SDFIX\Users\[u]0[/u]0000001\NTUSER.DAT
+ 2008-11-11 12:59:07   192,512   ----a-w   c:\windows\ERUNT\SDFIX\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-08-07 14:27:04   163,328   ----a-w   c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-11-11 12:58:43   3,706,880   ----a-w   c:\windows\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000001\NTUSER.DAT
+ 2008-11-11 12:58:43   192,512   ----a-w   c:\windows\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000002\UsrClass.dat
- 2008-11-09 18:49:39   58,930   ----a-w   c:\windows\system32\perfc009.dat
+ 2008-11-11 13:52:43   58,930   ----a-w   c:\windows\system32\perfc009.dat
- 2008-11-09 18:49:39   74,648   ----a-w   c:\windows\system32\perfc015.dat
+ 2008-11-11 13:52:43   74,648   ----a-w   c:\windows\system32\perfc015.dat
- 2008-11-09 18:49:39   392,630   ----a-w   c:\windows\system32\perfh009.dat
+ 2008-11-11 13:52:43   392,630   ----a-w   c:\windows\system32\perfh009.dat
- 2008-11-09 18:49:39   448,586   ----a-w   c:\windows\system32\perfh015.dat
+ 2008-11-11 13:52:43   448,586   ----a-w   c:\windows\system32\perfh015.dat
+ 2008-11-11 13:48:33   16,384   ----atw   c:\windows\Temp\Perflib_Perfdata_530.dat
.
(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="c:\progra~1\KOMUNI~1\GADU-G~1\gg.exe" [2007-07-09 2119104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SIDEBAR"="c:\program files\Użytkowe\Desktop Sidebar\dsidebar.exe" [2006-07-09 1777664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"Advanced WindowsCare V2 Pro"="c:\program files\Porządkujące\Advanced WindowsCare V2 Pro\Awc.exe" [2006-11-21 2507776]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 206088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2008-03-01 c:\windows\system32\advpack.dll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\\WINDOWS\\system32\\logonuiX.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 14:13 49152 c:\progra~1\COMMON~1\Stardock\MCPStub.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kamsoft]
c:\windows\system32\kamsoft.exe [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Biuro\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Biuro\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Biuro\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Komunikatory\\Skype\\Phone\\Skype.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09186593-af2b-11dd-ab8a-0016d4c9b294}]
\Shell\AutoRun\command - H:\whi.com
\Shell\explore\Command - H:\whi.com
\Shell\open\Command - H:\whi.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{576f9d19-af68-11dd-ab8d-0016d4c9b294}]
\Shell\AutoRun\command - H:\whi.com
\Shell\explore\Command - H:\whi.com
\Shell\open\Command - H:\whi.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e5a648be-a8f8-11dd-ab5e-0016d4c9b294}]
\Shell\AutoRun\command - H:\setup.exe
.
Zawartość folderu 'Zaplanowane zadania'

2008-11-10 c:\windows\Tasks\Advanced WindowsCare V2 Pro.job
- c:\program files\Porz []

2008-11-10 c:\windows\Tasks\AwcProUpdate.job
- c:\program files\Porz []

2008-11-10 c:\windows\Tasks\AwcProUpdate.job
- c:\program files\Porz []
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - c:\documents and settings\Manieq\Dane aplikacji\Mozilla\Firefox\Profiles\[u]0[/u]2ng3lol.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.allegro.pl
FF -: plugin - c:\progra~1\PRZEGL~1\MOZILL~1\plugins\npnul32.dll
FF -: plugin - c:\program files\Biuro\Reader\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Kodeki\Real Alternative\browser\plugins\nppl3260.dll
FF -: plugin - c:\program files\Kodeki\Real Alternative\browser\plugins\nprpjplug.dll
FF -: plugin - c:\program files\PrzeglÄ…darki\Opera\program\plugins\npdsplay.dll
FF -: plugin - c:\program files\PrzeglÄ…darki\Opera\program\plugins\NPOFF12.DLL
FF -: plugin - c:\program files\PrzeglÄ…darki\Opera\program\plugins\NPSWF32.dll
FF -: plugin - c:\program files\PrzeglÄ…darki\Opera\program\plugins\npwmsdrm.dll
FF -: plugin - c:\program files\UĹĽytkowe\Java\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\UĹĽytkowe\Java\bin\new_plugin\npjp2.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-11 16:14:29
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ...

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 4.1\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 4.1\my.ini\" MySQL"
.
Czas ukończenia: 2008-11-11 16:16:06
ComboFix-quarantined-files.txt  2008-11-11 15:15:46

Przed: 9,404,633,088 bajtów wolnych
Po: 9,425,428,480 bajtów wolnych

261
Sprzedam / zamienię Asusa TF101 16GB + Dock.
Awatar użytkownika
Manieq
~user
 
Posty: 1175
Dołączenie: 20 Gru 2006, 20:24
Miejscowość: Bogatynia
Pochwały: 31



Pozostałości po wirusie?

Postprzez Magik 11 Lis 2008, 17:29

fixik

Kod: Zaznacz wszystko
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'US&#321;UGA LOKALNA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'US&#321;UGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user'



wklej do notatnika

Kod: Zaznacz wszystko
FILE::
c:\windows\system32\rewire.dll


>>Plik>>Zapisz jako... >>> CFScript
Przeciągnij i upuść plik CFScript.txt na plik ComboFix.exe

wklej do notatnika

Kod: Zaznacz wszystko
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09186593-af2b-11dd-ab8a-0016d4c9b294}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{576f9d19-af68-11dd-ab8d-0016d4c9b294}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e5a648be-a8f8-11dd-ab5e-0016d4c9b294}]



zapisz jao fix.reg i odpal


przeskanuj i wklej raport
http://www.kaspersky.pl/resources/virusscanner/kavwebscan.html
Image Image
Awatar użytkownika
Magik
~user
 
Posty: 7956
Dołączenie: 08 Maj 2004, 09:17
Miejscowość: Głogów
Pochwały: 886




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 46 gości

cron