Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3900: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3902: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3903: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3904: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
Reader_s.exe ,poderzenie viruta - logi • programosy.pl

  • Ogłoszenie:

Reader_s.exe ,poderzenie viruta - logi

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Reader_s.exe ,poderzenie viruta - logi

Postprzez LOLSiq 09 Maj 2009, 23:05

reklama
Witam. Otóż dzisiaj przeczytałem na internecie że proces reader_s to wirus. Otóż niedawno (przed formatem) Kaspersky wykrywał mi viruty, tylko że nie formatowałem wszystkich partycji tylko partycję systemową i boję się że mogę mieć jeszcze te viruty. Proszę o sprawdzenie logów i informacje jak się tego pozbyć.
Pozdrawiam LOLSiq.


RSIT

Kod: Zaznacz wszystko
Plik LOG:
Logfile of random's system information tool 1.06 (written by random/random)
Run by csd at 2009-05-09 23:01:45
Microsoft Windows XP Professional Dodatek Service Pack 2
System drive C: has 15 GB (81%) free of 19 GB
Total RAM: 255 MB (12% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:01:52, on 2009-05-09
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\PnkBstrA.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\csd\Pulpit\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\csd.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://signup.live.com/signup.aspx?mkt=en-us&rollrs=12&lic=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [reader_s] C:\WINNT\System32\reader_s.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\csd\reader_s.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{EAF8C60B-0082-4183-A95D-EB37FDA907EA}: NameServer = 190.168.30.1,194.204.159.1
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINNT\system32\PnkBstrA.exe

--
End of file - 3843 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-06-28 364544]
"SoundMan"=C:\WINNT\SOUNDMAN.EXE [2003-06-10 72704]
"reader_s"=C:\WINNT\System32\reader_s.exe [2009-05-09 36352]
"NeroFilterCheck"=C:\WINNT\system32\NeroCheck.exe [2001-07-09 176128]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINNT\system32\ctfmon.exe [2004-08-04 32768]
"Gadu-Gadu"=C:\Program Files\Gadu-Gadu\gg.exe [2008-03-20 2127296]
"reader_s"=C:\Documents and Settings\csd\reader_s.exe [2009-05-09 36352]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2005-10-28 114688]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
Ralink Wireless Utility.lnk - C:\Program Files\RALINK\Common\RaUI.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINNT\system32\Ati2evxx.dll [2004-08-01 46080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"\??\C:\WINNT\system32\winlogon.exe"="\??\C:\WINNT\system32\winlogon.exe:*:enabled:@shell32.dll,-1"
"C:\WINNT\System32\PnkBstrA.exe"="C:\WINNT\System32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINNT\System32\PnkBstrB.exe"="C:\WINNT\System32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Mozilla Firefox\FIREFOX.EXE"="C:\Program Files\Mozilla Firefox\FIREFOX.EXE:*:Enabled:Firefox"
"C:\Documents and Settings\CSD\Pulpit\q3arena\quake3.exe"="C:\Documents and Settings\CSD\Pulpit\q3arena\quake3.exe:*:Enabled:quake3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2009-05-09 23:01:45 ----D---- C:\rsit
2009-05-09 22:35:26 ----A---- C:\WINNT\system32\OLD169.tmp
2009-05-09 22:35:24 ----A---- C:\WINNT\system32\OLD15C.tmp
2009-05-09 22:35:23 ----A---- C:\WINNT\system32\OLD159.tmp
2009-05-09 22:35:04 ----A---- C:\WINNT\system32\OLDFA.tmp
2009-05-09 22:35:03 ----A---- C:\WINNT\system32\OLDF7.tmp
2009-05-09 22:35:03 ----A---- C:\WINNT\system32\OLDF4.tmp
2009-05-09 22:35:03 ----A---- C:\WINNT\system32\OLDF1.tmp
2009-05-09 22:35:00 ----A---- C:\WINNT\system32\OLDE3.tmp
2009-05-09 22:34:55 ----A---- C:\WINNT\system32\OLDCA.tmp
2009-05-09 22:34:41 ----A---- C:\WINNT\system32\OLD8F.tmp
2009-05-09 22:34:40 ----A---- C:\WINNT\system32\OLD8A.tmp
2009-05-09 22:34:32 ----A---- C:\WINNT\system32\OLD68.tmp
2009-05-09 22:34:32 ----A---- C:\WINNT\system32\OLD65.tmp
2009-05-09 22:34:28 ----A---- C:\WINNT\system32\OLD60.tmp
2009-05-09 22:34:25 ----A---- C:\WINNT\system32\OLD58.tmp
2009-05-09 22:34:20 ----A---- C:\WINNT\system32\OLD4E.tmp
2009-05-09 22:34:19 ----A---- C:\WINNT\system32\OLD4B.tmp
2009-05-09 22:33:59 ----D---- C:\WINNT\LastGood
2009-05-09 22:33:59 ----A---- C:\WINNT\system32\OLDC.tmp
2009-05-09 22:31:56 ----D---- C:\Program Files\xerox
2009-05-09 22:31:55 ----D---- C:\WINNT\system32\xircom
2009-05-09 22:31:53 ----SHD---- C:\WINNT\system32\dllcache
2009-05-09 22:31:53 ----D---- C:\Program Files\microsoft frontpage
2009-05-09 22:26:13 ----D---- C:\WINNT\ERUNT
2009-05-09 22:24:28 ----D---- C:\SDFix
2009-05-09 21:58:38 ----SHD---- C:\FOUND.002
2009-05-09 21:51:54 ----D---- C:\Qoobox
2009-05-09 21:51:52 ----A---- C:\Bug.txt
2009-05-09 21:24:44 ----SHD---- C:\Recycled
2009-05-09 21:02:50 ----SHD---- C:\FOUND.001
2009-05-09 19:40:34 ----A---- C:\WINNT\system32\Wnaspi32.dll
2009-05-09 19:39:10 ----A---- C:\WINNT\ntbtlog.txt
2009-05-09 19:34:33 ----D---- C:\Documents and Settings\csd\Dane aplikacji\WinRAR
2009-05-09 19:16:01 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Gadu-Gadu
2009-05-09 18:16:12 ----A---- C:\WINNT\NeroDigital.ini
2009-05-09 18:12:49 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Ahead
2009-05-09 18:11:56 ----D---- C:\Program Files\Nero
2009-05-09 18:11:56 ----D---- C:\Program Files\Common Files\Ahead
2009-05-09 18:06:47 ----D---- C:\Program Files\WinRAR
2009-05-09 18:05:40 ----SHD---- C:\FOUND.000
2009-05-09 17:37:39 ----D---- C:\Program Files\Trend Micro
2009-05-09 16:30:56 ----A---- C:\WINNT\system32\reader_s.exe
2009-05-09 10:41:56 ----D---- C:\Documents and Settings\csd\Dane aplikacji\id Software
2009-05-09 10:39:48 ----A---- C:\WINNT\system32\PnkBstrB.exe
2009-05-09 10:39:44 ----D---- C:\WINNT\system32\LogFiles
2009-05-09 10:39:44 ----A---- C:\WINNT\system32\PnkBstrA.exe
2009-05-09 10:39:44 ----A---- C:\WINNT\system32\pbsvc.exe
2009-05-09 10:39:40 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\id Software
2009-05-09 10:26:18 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\InterAction studios
2009-05-09 10:01:46 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Macromedia
2009-05-09 10:01:45 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Adobe
2009-05-09 10:01:22 ----A---- C:\WINNT\RtlRack.ini
2009-05-09 09:51:10 ----A---- C:\WINNT\system32\ksuser.dll
2009-05-09 09:51:08 ----D---- C:\Program Files\Realtek Sound Manager
2009-05-09 09:51:06 ----D---- C:\Program Files\AvRack
2009-05-09 09:51:05 ----N---- C:\WINNT\avrack.ini
2009-05-09 09:51:04 ----A---- C:\WINNT\system32\Audio3D.dll
2009-05-09 09:51:04 ----A---- C:\WINNT\system32\a3d.dll
2009-05-09 09:51:03 ----A---- C:\WINNT\SOUNDMAN.EXE
2009-05-09 09:50:59 ----N---- C:\WINNT\alcupd.exe
2009-05-09 09:50:59 ----N---- C:\WINNT\alcrmv.exe
2009-05-09 09:50:10 ----A---- C:\WINNT\IsUninst.exe
2009-05-09 09:48:32 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Help
2009-05-09 09:44:24 ----N---- C:\WINNT\system32\ati2sgag.exe
2009-05-09 09:44:19 ----RA---- C:\WINNT\system32\atiiiexx.dll
2009-05-09 09:44:11 ----D---- C:\WINNT\system32\ReinstallBackups
2009-05-09 09:43:57 ----D---- C:\Program Files\ATI Technologies
2009-05-09 09:35:05 ----D---- C:\Program Files\Gadu-Gadu
2009-05-09 08:43:17 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Mozilla
2009-05-09 08:40:32 ----D---- C:\WINNT\system32\DRVSTORE
2009-05-09 08:40:14 ----A---- C:\WINNT\system32\Install6x.dll
2009-05-09 08:40:14 ----A---- C:\WINNT\system32\AegisI5.exe
2009-05-09 08:40:04 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-09 08:39:56 ----D---- C:\Program Files\Common Files\InstallShield
2009-05-09 08:39:10 ----D---- C:\Program Files\RALINK
2009-05-09 08:38:46 ----D---- C:\Program Files\Mozilla Firefox
2009-05-09 08:38:04 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Identities
2009-05-09 08:38:03 ----HD---- C:\Program Files\Uninstall Information
2009-05-09 08:37:55 ----SD---- C:\Documents and Settings\csd\Dane aplikacji\Microsoft
2009-05-09 08:37:55 ----ASH---- C:\Documents and Settings\csd\Dane aplikacji\desktop.ini
2009-05-09 08:32:36 ----SHD---- C:\System Volume Information
2009-05-09 08:32:36 ----D---- C:\WINNT\SoftwareDistribution
2009-05-09 08:32:35 ----SD---- C:\WINNT\system32\Microsoft
2009-05-09 08:32:35 ----D---- C:\WINNT\Prefetch
2009-05-09 08:32:35 ----A---- C:\WINNT\SchedLgU.Txt
2009-05-09 08:31:07 ----A---- C:\WINNT\system32\spupdsvc.exe
2009-05-09 08:31:00 ----N---- C:\WINNT\system32\spmsg.dll
2009-05-09 08:30:58 ----HD---- C:\WINNT\$hf_mig$
2009-05-09 08:30:44 ----A---- C:\WINNT\control.ini
2009-05-09 08:30:44 ----A---- C:\AUTOEXEC.BAT
2009-05-09 08:30:29 ----A---- C:\WINNT\OEWABLog.txt
2009-05-09 08:30:25 ----A---- C:\WINNT\system32\mapi32.dll
2009-05-09 08:29:32 ----SD---- C:\WINNT\Downloaded Program Files
2009-05-09 08:29:32 ----RD---- C:\WINNT\Offline Web Pages
2009-05-09 08:29:32 ----RAH---- C:\WINNT\system32\logonui.exe.manifest
2009-05-09 08:29:26 ----RAH---- C:\WINNT\system32\cdplayer.exe.manifest
2009-05-09 08:29:21 ----HD---- C:\Program Files\WindowsUpdate
2009-05-09 08:29:18 ----D---- C:\Program Files\Usługi online
2009-05-09 08:28:59 ----D---- C:\WINNT\system32\DirectX
2009-05-09 08:28:36 ----A---- C:\WINNT\system32\atrace.dll
2009-05-09 08:28:33 ----A---- C:\WINNT\system32\desktop.ini
2009-05-09 08:28:33 ----A---- C:\WINNT\desktop.ini
2009-05-09 08:28:24 ----A---- C:\WINNT\system32\nmevtmsg.dll
2009-05-09 08:28:23 ----A---- C:\WINNT\system32\acctres.dll
2009-05-09 08:28:22 ----D---- C:\Program Files\Common Files\Services
2009-05-09 08:28:19 ----SD---- C:\WINNT\Tasks
2009-05-09 08:28:19 ----A---- C:\WINNT\system32\icfgnt5.dll
2009-05-09 08:28:18 ----D---- C:\Program Files\Common Files\MSSoap
2009-05-09 08:28:13 ----D---- C:\WINNT\srchasst
2009-05-09 08:28:12 ----D---- C:\WINNT\system32\Macromed
2009-05-09 08:28:09 ----A---- C:\WINNT\system32\wuweb.dll
2009-05-09 08:28:09 ----A---- C:\WINNT\system32\wucltui.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wups.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuauserv.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuaueng1.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuaueng.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuauclt1.exe
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuauclt.exe
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuapi.dll
2009-05-09 08:28:07 ----A---- C:\WINNT\system32\qmgrprxy.dll
2009-05-09 08:28:07 ----A---- C:\WINNT\system32\qmgr.dll
2009-05-09 08:28:07 ----A---- C:\WINNT\system32\bitsprx3.dll
2009-05-09 08:28:07 ----A---- C:\WINNT\system32\bitsprx2.dll
2009-05-09 08:28:03 ----D---- C:\Program Files\Movie Maker
2009-05-09 08:27:57 ----A---- C:\WINNT\system32\safrslv.dll
2009-05-09 08:27:57 ----A---- C:\WINNT\system32\safrdm.dll
2009-05-09 08:27:57 ----A---- C:\WINNT\system32\safrcdlg.dll
2009-05-09 08:27:57 ----A---- C:\WINNT\system32\racpldlg.dll
2009-05-09 08:27:52 ----D---- C:\WINNT\system32\Restore
2009-05-09 08:27:52 ----A---- C:\WINNT\system32\fltMc.exe
2009-05-09 08:27:52 ----A---- C:\WINNT\system32\fltlib.dll
2009-05-09 08:27:51 ----A---- C:\WINNT\system32\srsvc.dll
2009-05-09 08:27:51 ----A---- C:\WINNT\system32\srrstr.dll
2009-05-09 08:27:51 ----A---- C:\WINNT\system32\srclient.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\nmmkcert.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\msconf.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\mnmsrvc.exe
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\mnmdd.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\isrdbg32.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\ils.dll
2009-05-09 08:27:47 ----D---- C:\Program Files\NetMeeting
2009-05-09 08:27:46 ----A---- C:\WINNT\system32\msoert2.dll
2009-05-09 08:27:46 ----A---- C:\WINNT\system32\msoeacct.dll
2009-05-09 08:27:45 ----A---- C:\WINNT\system32\inetres.dll
2009-05-09 08:27:45 ----A---- C:\WINNT\system32\inetcomm.dll
2009-05-09 08:27:43 ----D---- C:\Program Files\Outlook Express
2009-05-09 08:27:43 ----A---- C:\WINNT\system32\schedsvc.dll
2009-05-09 08:27:43 ----A---- C:\WINNT\system32\mstinit.exe
2009-05-09 08:27:42 ----A---- C:\WINNT\system32\mstask.dll
2009-05-09 08:27:42 ----A---- C:\WINNT\system32\isign32.dll
2009-05-09 08:27:42 ----A---- C:\WINNT\system32\icwphbk.dll
2009-05-09 08:27:42 ----A---- C:\WINNT\system32\icwdial.dll
2009-05-09 08:27:41 ----A---- C:\WINNT\system32\inetcfg.dll
2009-05-09 08:27:35 ----D---- C:\Program Files\Common Files\System
2009-05-09 08:27:33 ----D---- C:\Program Files\Internet Explorer
2009-05-09 08:26:49 ----D---- C:\Program Files\ComPlus Applications
2009-05-09 08:26:47 ----A---- C:\WINNT\vbaddin.ini
2009-05-09 08:26:47 ----A---- C:\WINNT\vb.ini
2009-05-09 08:26:43 ----D---- C:\WINNT\Registration
2009-05-09 08:26:37 ----D---- C:\Program Files\Windows Media Player
2009-05-09 08:26:30 ----D---- C:\Program Files\Messenger
2009-05-09 08:26:26 ----D---- C:\Program Files\MSN Gaming Zone
2009-05-09 08:26:26 ----A---- C:\WINNT\system32\write.exe
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\sndvol32.exe
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\hticons.dll
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\avwav.dll
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\avtapi.dll
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\avmeter.dll
2009-05-09 08:26:13 ----A---- C:\WINNT\system32\winchat.exe
2009-05-09 08:26:04 ----A---- C:\WINNT\system32\getuname.dll
2009-05-09 08:26:04 ----A---- C:\WINNT\system32\charmap.exe
2009-05-09 08:26:04 ----A---- C:\WINNT\system32\calc.exe
2009-05-09 08:26:03 ----A---- C:\WINNT\system32\winmine.exe
2009-05-09 08:26:03 ----A---- C:\WINNT\system32\sol.exe
2009-05-09 08:26:03 ----A---- C:\WINNT\system32\mshearts.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\usrlogon.cmd
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tsshutdn.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tslabels.ini
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tskill.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tsdiscon.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tscon.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\reset.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\freecell.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\shadow.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\rwinsta.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\regini.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\rdpcfgex.dll
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\qwinsta.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\qappsrv.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\msg.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\logoff.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\cdmodem.dll
2009-05-09 08:26:00 ----A---- C:\WINNT\system32\msdtcprf.ini
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\stclient.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\mtxlegih.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\mtxex.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\mtxdm.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\dcomcnfg.exe
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\comrepl.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\comaddin.dll
2009-05-09 08:25:58 ----A---- C:\WINNT\system32\comsnap.dll
2009-05-09 08:25:52 ----A---- C:\WINNT\system32\wmimgmt.msc
2009-05-09 08:25:50 ----A---- C:\WINNT\system32\sndrec32.exe
2009-05-09 08:25:50 ----A---- C:\WINNT\system32\mplay32.exe
2009-05-09 08:25:50 ----A---- C:\WINNT\system32\hypertrm.dll
2009-05-09 08:25:50 ----A---- C:\WINNT\system32\accwiz.exe
2009-05-09 08:25:49 ----D---- C:\Program Files\Windows NT
2009-05-09 08:25:49 ----A---- C:\WINNT\system32\spider.exe
2009-05-09 08:25:49 ----A---- C:\WINNT\system32\mspaint.exe
2009-05-09 08:25:49 ----A---- C:\WINNT\system32\clipbrd.exe
2009-05-09 08:25:48 ----A---- C:\WINNT\system32\tscfgwmi.dll
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\sessmgr.exe
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\remotepg.dll
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\rdshost.exe
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\rdsaddin.exe
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\rdchost.dll
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\mstscax.dll
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\mstsc.exe
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\tscupgrd.exe
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\termsrv.dll
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\rdpwsx.dll
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\rdpsnd.dll
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\rdpclip.exe
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\qprocess.exe
2009-05-09 08:25:45 ----D---- C:\WINNT\system32\MsDtc
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\mtxoci.dll
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\msdtcuiu.dll
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\msdtcprx.dll
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\icaapi.dll
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\cfgbkend.dll
2009-05-09 08:25:44 ----A---- C:\WINNT\system32\xolehlp.dll
2009-05-09 08:25:44 ----A---- C:\WINNT\system32\msdtctm.dll
2009-05-09 08:25:44 ----A---- C:\WINNT\system32\msdtclog.dll
2009-05-09 08:25:44 ----A---- C:\WINNT\system32\msdtc.exe
2009-05-09 08:25:43 ----D---- C:\WINNT\system32\Com
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\colbact.dll
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\clbcatex.dll
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\catsrvut.dll
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\catsrvps.dll
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\catsrv.dll
2009-05-09 08:25:42 ----A---- C:\WINNT\system32\comuid.dll
2009-05-09 08:25:42 ----A---- C:\WINNT\system32\comsvcs.dll
2009-05-09 08:25:42 ----A---- C:\WINNT\system32\clbcatq.dll
2009-05-09 08:25:35 ----A---- C:\WINNT\system32\servdeps.dll
2009-05-09 08:25:35 ----A---- C:\WINNT\system32\mmfutil.dll
2009-05-09 08:25:35 ----A---- C:\WINNT\system32\licwmi.dll
2009-05-09 08:25:35 ----A---- C:\WINNT\system32\cmprops.dll
2009-05-09 08:24:24 ----A---- C:\WINNT\system32\h323log.txt
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ativvaxx.dll
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ati3duag.dll
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ati3d1ag.dll
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ati2dvag.dll
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ati2cqag.dll
2009-05-09 08:20:46 ----A---- C:\WINNT\system32\usbui.dll
2009-05-09 08:19:50 ----SHD---- C:\WINNT\Installer
2009-05-09 08:19:50 ----A---- C:\WINNT\system32\PerfStringBackup.INI
2009-05-09 08:19:49 ----D---- C:\Program Files\Common Files\ODBC
2009-05-09 08:19:49 ----A---- C:\WINNT\ODBCINST.INI
2009-05-09 08:19:46 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-05-09 08:19:45 ----RD---- C:\Program Files
2009-05-09 08:19:45 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-09 08:19:45 ----D---- C:\Program Files\Common Files
2009-05-09 08:19:35 ----RA---- C:\WINNT\system32\kbdazel.dll
2009-05-09 08:19:34 ----RA---- C:\WINNT\system32\kbdtuq.dll
2009-05-09 08:19:34 ----RA---- C:\WINNT\system32\kbdtuf.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbduzb.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdur.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdtat.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdmon.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdkyr.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdkaz.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdaze.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdycc.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdru1.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdru.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdbu.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdblr.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhept.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhela3.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhela2.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhe319.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhe220.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhe.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdgkl.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdlv1.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdlv.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdlt1.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdlt.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdest.dll
2009-05-09 08:19:17 ----RA---- C:\WINNT\system32\kbdsl1.dll
2009-05-09 08:19:17 ----RA---- C:\WINNT\system32\kbdsl.dll
2009-05-09 08:19:17 ----RA---- C:\WINNT\system32\kbdro.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdycl.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdhu1.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdhu.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdcz2.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdcz1.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdcz.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdcr.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\KBDAL.DLL
2009-05-09 08:19:15 ----A---- C:\WINNT\system32\spxcoins.dll
2009-05-09 08:19:15 ----A---- C:\WINNT\system32\irclass.dll
2009-05-09 08:19:15 ----A---- C:\WINNT\system32\dgsetup.dll
2009-05-09 08:19:15 ----A---- C:\WINNT\system32\dgrpsetu.dll
2009-05-09 08:19:14 ----A---- C:\WINNT\system32\EqnClass.Dll
2009-05-09 08:19:11 ----N---- C:\WINNT\system32\CONFIG.TMP
2009-05-09 08:19:11 ----A---- C:\WINNT\TASKMAN.EXE
2009-05-09 08:19:10 ----A---- C:\WINNT\system32\storprop.dll
2009-05-09 08:19:10 ----A---- C:\WINNT\system32\batt.dll
2009-05-09 08:19:10 ----A---- C:\WINNT\NOTEPAD.EXE
2009-05-09 08:19:03 ----ASH---- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
2009-05-09 08:18:53 ----RA---- C:\WINNT\SET8.tmp
2009-05-09 08:18:51 ----RA---- C:\WINNT\SET4.tmp
2009-05-09 08:18:49 ----RA---- C:\WINNT\SET3.tmp
2009-05-09 08:18:44 ----D---- C:\WINNT\system32\CatRoot2
2009-05-09 08:18:44 ----D---- C:\WINNT\system32\CatRoot
2009-05-09 08:18:38 ----SD---- C:\Documents and Settings\All Users\Dane aplikacji\Microsoft
2009-05-09 08:18:18 ----A---- C:\WINNT\setuplog.txt
2009-05-09 08:18:15 ----D---- C:\Documents and Settings
2009-05-09 08:17:34 ----SH---- C:\boot.ini
2009-05-09 08:13:53 ----RSD---- C:\WINNT\Fonts
2009-05-09 08:13:53 ----RD---- C:\WINNT\Web
2009-05-09 08:13:53 ----HD---- C:\WINNT\inf
2009-05-09 08:13:53 ----D---- C:\WINNT\WinSxS
2009-05-09 08:13:53 ----D---- C:\WINNT\twain_32
2009-05-09 08:13:53 ----D---- C:\WINNT\Temp
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\wins
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\wbem
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\usmt
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\spool
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\ShellExt
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\Setup
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\ras
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\PreInstall
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\oobe
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\npp
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\mui
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\inetsrv
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\IME
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\icsxml
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\ias
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\export
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\drivers
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\dhcp
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\config
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\3com_dmi
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\3076
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\2052
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1054
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1045
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1042
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1041
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1037
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1033
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1031
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1028
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1025
2009-05-09 08:13:53 ----D---- C:\WINNT\system32
2009-05-09 08:13:53 ----D---- C:\WINNT\system
2009-05-09 08:13:53 ----D---- C:\WINNT\security
2009-05-09 08:13:53 ----D---- C:\WINNT\Resources
2009-05-09 08:13:53 ----D---- C:\WINNT\repair
2009-05-09 08:13:53 ----D---- C:\WINNT\Provisioning
2009-05-09 08:13:53 ----D---- C:\WINNT\PeerNet
2009-05-09 08:13:53 ----D---- C:\WINNT\pchealth
2009-05-09 08:13:53 ----D---- C:\WINNT\mui
2009-05-09 08:13:53 ----D---- C:\WINNT\msapps
2009-05-09 08:13:53 ----D---- C:\WINNT\msagent
2009-05-09 08:13:53 ----D---- C:\WINNT\Media
2009-05-09 08:13:53 ----D---- C:\WINNT\java
2009-05-09 08:13:53 ----D---- C:\WINNT\ime
2009-05-09 08:13:53 ----D---- C:\WINNT\Help
2009-05-09 08:13:53 ----D---- C:\WINNT\ehome
2009-05-09 08:13:53 ----D---- C:\WINNT\Driver Cache
2009-05-09 08:13:53 ----D---- C:\WINNT\Debug
2009-05-09 08:13:53 ----D---- C:\WINNT\Cursors
2009-05-09 08:13:53 ----D---- C:\WINNT\Connection Wizard
2009-05-09 08:13:53 ----D---- C:\WINNT\Config
2009-05-09 08:13:53 ----D---- C:\WINNT\AppPatch
2009-05-09 08:13:53 ----D---- C:\WINNT\addins
2009-05-09 08:13:53 ----D---- C:\WINNT
2009-05-09 08:13:53 ----A---- C:\WINNT\DUMPdaa0.tmp

======List of files/folders modified in the last 1 months======

2009-05-09 08:30:46 ----A---- C:\WINNT\win.ini
2009-05-09 08:19:46 ----A---- C:\WINNT\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;Sterownik procesora AMD K7; C:\WINNT\system32\DRIVERS\amdk7.sys [2006-07-15 41472]
R1 ASPI32;ASPI32; C:\WINNT\system32\drivers\ASPI32.sys [2002-07-17 16877]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.10.0; C:\WINNT\system32\DRIVERS\AegisP.sys [2009-05-09 21275]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINNT\system32\drivers\ALCXWDM.SYS [2003-06-19 752764]
R3 ati2mtag;ati2mtag; C:\WINNT\system32\DRIVERS\ati2mtag.sys [2004-08-01 1241088]
R3 catchme;catchme; \??\C:\DOCUME~1\csd\USTAWI~1\Temp\catchme.sys []
R3 RT61;Ralink RT61 Wireless Driver; C:\WINNT\system32\DRIVERS\RT61.sys [2006-05-04 380928]
R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINNT\system32\DRIVERS\usbehci.sys [2006-07-15 30080]
R3 usbhub;Koncentrator z obsługą USB2; C:\WINNT\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Sterownik Miniport uniwersalnego kontrolera hosta USB Microsoft; C:\WINNT\system32\DRIVERS\usbuhci.sys [2006-07-15 20608]
S1 InCDPass;InCDPass; C:\WINNT\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINNT\system32\drivers\InCDRm.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S4 InCDFs;InCD File System; C:\WINNT\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\WINNT\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINNT\system32\Ati2evxx.exe [2004-08-01 397312]
R2 PnkBstrA;PnkBstrA; C:\WINNT\system32\PnkBstrA.exe [2009-05-09 66872]
S2 ATI Smart;ATI Smart; C:\WINNT\system32\ati2sgag.exe [2005-06-28 536576]

-----------------EOF-----------------
LOLSiq
~user
 
Posty: 4
Dołączenie: 09 Maj 2009, 22:48



Reader_s.exe ,poderzenie viruta - logi

Postprzez Okocza 09 Maj 2009, 23:13

Wykonaj to co jest podane w tym temacie

Zastosuj SDFix . Po pobraniu uruchom go a rozpakuje się do C:\SDFix. Uruchom komputer w trybie awaryjnym (F8 przy stracie systemu). Będąc w awaryjnym uruchom plik RunThis.bat z folderu SDFixa. Zatwierdź czyszczenie przez Y. Poczekaj aż ukończy i komputer zresetuje

Potem wejdz do folderu C:\SDFix wrzuc zawartość pliku Report.txt + log z dss'a oraz daj loga z hijacka

Autor postu otrzymał pochwałę
eMachines E730G - Core i5-430M, 2GiB RAM, ATI Mobility Radeon HD5470, WD 320GiB; Cort Z-44,DR 0.09-0.42, Peavey Backstage
Mac OS X 10.7.4 Lion // Windows 7 Professional x64 // NIE POMAGAM NA PW/GG/E-MAIL
Image
"Moje Ego i Anima spotykają się i wymieniają przepisami na ciasteczka" - Maynard James Keenan
Awatar użytkownika
Okocza
~user
 
Posty: 8001
Dołączenie: 19 Mar 2006, 11:53
Pochwały: 406



Reader_s.exe ,poderzenie viruta - logi

Postprzez LOLSiq 10 Maj 2009, 09:56

Wykonałem to co jest w tym temacie w 50%, ponieważ Windows Worms Doors Cleaner poszedł bez problemowo a Seconfig XP nie zadziałał. Wygląda to tak rozpakowuje - włączam - klikam Tak i znów pokazuje się okienko z akceptowaniem zasad, i tak mogę klikać w "TAK" bez przerwy.

Report.txt z SDFix'a

Kod: Zaznacz wszystko
[b]SDFix: Version 1.240 [/b]
Run by Administrator on 2009-05-10 at 09:34

Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


[b]Checking Files [/b]:

Trojan Files Found:

C:\WINNT\system32\1.tmp - Deleted
C:\WINNT\system32\1.tmp - Deleted





Removing Temp Files

[b]ADS Check [/b]:



                                 [b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-10 09:36:05
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services [/b]:




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"\\??\\C:\\WINNT\\system32\\winlogon.exe"="\\??\\C:\\WINNT\\system32\\winlogon.exe:*:enabled:@shell32.dll,-1"
"C:\\WINNT\\System32\\PnkBstrA.exe"="C:\\WINNT\\System32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINNT\\System32\\PnkBstrB.exe"="C:\\WINNT\\System32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"="C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE:*:Enabled:Firefox"
"C:\\Documents and Settings\\CSD\\Pulpit\\q3arena\\quake3.exe"="C:\\Documents and Settings\\CSD\\Pulpit\\q3arena\\quake3.exe:*:Enabled:quake3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[b]Remaining Files [/b]:


File Backups: - C:\SDFix\backups\backups.zip

[b]Files with Hidden Attributes [/b]:


[b]Finished![/b]



HIJACKTHIS

Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:37:07, on 2009-05-10
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\PnkBstrA.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\System32\reader_s.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Documents and Settings\csd\reader_s.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINNT\System32\svchost.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://signup.live.com/signup.aspx?mkt=en-us&rollrs=12&lic=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [reader_s] C:\WINNT\System32\reader_s.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\csd\reader_s.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{EAF8C60B-0082-4183-A95D-EB37FDA907EA}: NameServer = 190.168.30.1,194.204.159.1
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINNT\system32\PnkBstrA.exe

--
End of file - 3757 bytes


DSS


Kod: Zaznacz wszystko
DDS (Ver_09-03-16.01) - FAT32x86 
Run by csd at  9:48:28,85 on 2009-05-10
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional  5.1.2600.2.1250.48.1045.18.255.37 [GMT 2:00]


============== Running Processes ===============

C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost -k DcomLaunch
SVCHOST.EXE
C:\WINNT\System32\svchost.exe -k netsvcs
SVCHOST.EXE
SVCHOST.EXE
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\PnkBstrA.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\System32\reader_s.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Documents and Settings\csd\reader_s.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\RALINK\Common\RaUI.exe
svchost.exe C:\WINNT\system32\8M¨˙
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\csd\Pulpit\dds.pif

============== Pseudo HJT Report ===============

uInternet Connection Wizard,ShellNext = https://signup.live.com/signup.aspx?mkt=en-us&rollrs=12&lic=1
uRun: [CTFMON.EXE] c:\winnt\system32\ctfmon.exe
uRun: [Gadu-Gadu] "c:\program files\gadu-gadu\gg.exe" /tray
uRun: [reader_s] c:\documents and settings\csd\reader_s.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [reader_s] c:\winnt\system32\reader_s.exe
mRun: [NeroFilterCheck] c:\winnt\system32\NeroCheck.exe
dRun: [CTFMON.EXE] c:\winnt\system32\CTFMON.EXE
dRun: [reader_s] c:\documents and settings\csd\reader_s.exe
StartupFolder: c:\docume~1\alluse~1\menust~1\programy\autost~1\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: {EAF8C60B-0082-4183-A95D-EB37FDA907EA} = 190.168.30.1,194.204.159.1
Notify: AtiExtEvent - Ati2evxx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\csd\daneap~1\mozilla\firefox\profiles\wee8o8vz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/
FF - plugin: c:\documents and settings\all users\dane aplikacji\id software\quakelive\npquakezero.dll

============= SERVICES / DRIVERS ===============

S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]

=============== Created Last 30 ================

2009-05-10 09:46   <DIR>   --d-h---   c:\winnt\PIF
2009-05-10 09:36   44   a-------   c:\winnt\system32\5.tmp
2009-05-10 09:34   578,560   a-------   c:\winnt\system32\dllcache\user32.dll
2009-05-09 22:34   333,312   a-------   c:\winnt\system32\dllcache\aqueue.dll
2009-05-09 22:33   290,816   a-------   c:\winnt\system32\dllcache\adsiis51.dll
2009-05-09 22:33   43,520   a-------   c:\winnt\system32\dllcache\admwprox.dll
2009-05-09 22:33   20,540   a-------   c:\winnt\system32\dllcache\admin.dll
2009-05-09 22:31   <DIR>   --d-----   c:\winnt\system32\xircom
2009-05-09 22:31   <DIR>   --dsh---   c:\winnt\system32\dllcache
2009-05-09 22:26   <DIR>   --d-----   c:\winnt\ERUNT
2009-05-09 22:24   <DIR>   --d-----   C:\SDFix
2009-05-09 21:58   <DIR>   --dsh---   C:\FOUND.002
2009-05-09 21:24   <DIR>   --dsh---   C:\Recycled
2009-05-09 21:02   <DIR>   --dsh---   C:\FOUND.001
2009-05-09 19:40   45,056   a-------   c:\winnt\system32\Wnaspi32.dll
2009-05-09 19:40   16,877   a-------   c:\winnt\system32\drivers\Aspi32.sys
2009-05-09 19:40   4,455   a-------   c:\winnt\system\Winaspi.dll
2009-05-09 19:40   3,535   a-------   c:\winnt\system\Wowpost.exe
2009-05-09 19:16   <DIR>   --d-----   c:\docume~1\csd\daneap~1\Gadu-Gadu
2009-05-09 18:16   69   a-------   c:\winnt\NeroDigital.ini
2009-05-09 18:11   <DIR>   --d-----   c:\program files\Nero
2009-05-09 18:05   <DIR>   --dsh---   C:\FOUND.000
2009-05-09 17:37   <DIR>   --d-----   c:\program files\Trend Micro
2009-05-09 16:30   36,352   a-------   c:\winnt\system32\reader_s.exe
2009-05-09 16:30   36,352   a-------   c:\documents and settings\csd\reader_s.exe
2009-05-09 10:41   <DIR>   --d-----   c:\docume~1\csd\daneap~1\id Software
2009-05-09 10:40   22,328   a-------   c:\winnt\system32\drivers\PnkBstrK.sys
2009-05-09 10:40   22,328   a-------   c:\docume~1\csd\daneap~1\PnkBstrK.sys
2009-05-09 10:39   107,832   a-------   c:\winnt\system32\PnkBstrB.exe
2009-05-09 10:39   2,267,136   a-------   c:\winnt\system32\pbsvc.exe
2009-05-09 10:39   66,872   a-------   c:\winnt\system32\PnkBstrA.exe
2009-05-09 10:39   <DIR>   --d-----   c:\winnt\system32\LogFiles
2009-05-09 10:39   <DIR>   --d-----   c:\docume~1\alluse~1\daneap~1\id Software
2009-05-09 10:26   <DIR>   --d-----   c:\docume~1\alluse~1\daneap~1\InterAction studios
2009-05-09 10:25   24,576   a-------   c:\winnt\system32\¨Ďq
2009-05-09 10:01   204   a-------   c:\winnt\RtlRack.ini
2009-05-09 09:56   22   a-------   c:\winnt\system32\ati64hlp.stb
2009-05-09 09:51   <DIR>   --d-----   c:\program files\Realtek Sound Manager
2009-05-09 09:51   <DIR>   --d-----   c:\program files\AvRack
2009-05-09 09:50   208,896   --------   c:\winnt\alcupd.exe
2009-05-09 09:50   135,168   --------   c:\winnt\alcrmv.exe
2009-05-09 09:50   26,880   a-------   c:\winnt\system32\drivers\VIAAGP1.SYS
2009-05-09 09:50   324,096   a-------   c:\winnt\IsUninst.exe
2009-05-09 09:50   <DIR>   --d-----   c:\documents and settings\csd\WINDOWS
2009-05-09 09:48   22   a-------   c:\winnt\system32\ati64hl2.stb
2009-05-09 09:44   536,576   --------   c:\winnt\system32\ati2sgag.exe
2009-05-09 09:44   307,200   a----r--   c:\winnt\system32\atiiiexx.dll
2009-05-09 09:44   5,396   a----r--   c:\winnt\system32\atifglpf.xml
2009-05-09 09:44   95,617   a----r--   c:\winnt\system32\atiicdxx.dat
2009-05-09 09:44   524,850   a----r--   c:\winnt\system32\drivers\ativcaxx.cpa
2009-05-09 09:44   58,521   a----r--   c:\winnt\system32\drivers\ativckxx.vp
2009-05-09 09:44   21,472   a----r--   c:\winnt\system32\drivers\ativvpxx.vp
2009-05-09 09:44   900   a----r--   c:\winnt\system32\drivers\ativcaxx.vp
2009-05-09 09:44   <DIR>   --d-----   c:\winnt\system32\ReinstallBackups
2009-05-09 09:43   <DIR>   --d-----   c:\program files\ATI Technologies
2009-05-09 09:35   <DIR>   --d-----   c:\documents and settings\csd\Gadu-Gadu
2009-05-09 09:35   <DIR>   --d-----   c:\program files\Gadu-Gadu
2009-05-09 08:40   21,275   a-------   c:\winnt\system32\drivers\AegisP.sys
2009-05-09 08:40   380,928   a-------   c:\winnt\system32\drivers\rt61.sys
2009-05-09 08:40   315,392   a-------   c:\winnt\system32\AegisI5.exe
2009-05-09 08:40   295,028   a-------   c:\winnt\system32\Install6x.dll
2009-05-09 08:40   8,192   a-------   c:\winnt\system32\drivers\RT2661.bin
2009-05-09 08:40   8,192   a-------   c:\winnt\system32\drivers\RT2561s.bin
2009-05-09 08:40   8,192   a-------   c:\winnt\system32\drivers\RT2561.bin
2009-05-09 08:40   78   a-------   c:\winnt\filespec6x
2009-05-09 08:39   <DIR>   --d-----   c:\program files\RALINK
2009-05-09 08:37   <DIR>   --d-hr--   c:\documents and settings\csd\Dane aplikacji
2009-05-09 08:37   <DIR>   --d-h---   c:\documents and settings\csd\Ustawienia lokalne
2009-05-09 08:37   <DIR>   --d-h---   c:\documents and settings\csd\Szablony
2009-05-09 08:37   <DIR>   --d--r--   c:\documents and settings\csd\Ulubione
2009-05-09 08:37   <DIR>   --d--r--   c:\documents and settings\csd\Moje dokumenty
2009-05-09 08:37   <DIR>   --d--r--   c:\documents and settings\csd\Menu Start
2009-05-09 08:37   <DIR>   --d-----   c:\documents and settings\csd\Pulpit
2009-05-09 08:37   <DIR>   --d-----   c:\documents and settings\csd
2009-05-09 08:32   <DIR>   --ds----   c:\winnt\system32\Microsoft
2009-05-09 08:32   8,192   a-------   c:\winnt\REGLOCS.OLD
2009-05-09 08:31   22,752   a-------   c:\winnt\system32\spupdsvc.exe
2009-05-09 08:29   <DIR>   --dsh---   c:\documents and settings\all users\DRM
2009-05-09 08:29   488   a---hr--   c:\winnt\system32\WindowsLogon.manifest
2009-05-09 08:29   488   a---hr--   c:\winnt\system32\logonui.exe.manifest
2009-05-09 08:29   <DIR>   --ds----   c:\winnt\Downloaded Program Files
2009-05-09 08:29   <DIR>   --d--r--   c:\winnt\Offline Web Pages
2009-05-09 08:29   749   a---hr--   c:\winnt\WindowsShell.Manifest
2009-05-09 08:29   749   a---hr--   c:\winnt\system32\wuaucpl.cpl.manifest
2009-05-09 08:29   749   a---hr--   c:\winnt\system32\sapi.cpl.manifest
2009-05-09 08:29   749   a---hr--   c:\winnt\system32\nwc.cpl.manifest
2009-05-09 08:29   749   a---hr--   c:\winnt\system32\ncpa.cpl.manifest
2009-05-09 08:29   749   a---hr--   c:\winnt\system32\cdplayer.exe.manifest
2009-05-09 08:29   <DIR>   --d-h---   c:\program files\WindowsUpdate
2009-05-09 08:29   <DIR>   --d-----   c:\program files\Usługi online
2009-05-09 08:28   <DIR>   --d-----   c:\program files\common files\MSSoap
2009-05-09 08:26   <DIR>   --d-----   c:\program files\Messenger
2009-05-09 08:26   <DIR>   --d-----   c:\program files\MSN Gaming Zone
2009-05-09 08:25   <DIR>   --d-----   c:\program files\Windows NT
2009-05-09 08:19   <DIR>   --d-----   c:\program files\common files\ODBC
2009-05-09 08:19   <DIR>   --d-----   c:\program files\common files\SpeechEngines
2009-05-09 08:19   <DIR>   --d-h---   c:\documents and settings\all users\Szablony
2009-05-09 08:19   <DIR>   --d--r--   c:\documents and settings\all users\Menu Start
2009-05-09 08:19   <DIR>   --d--r--   c:\documents and settings\all users\Dokumenty
2009-05-09 08:19   <DIR>   --d-----   c:\documents and settings\all users\Ulubione
2009-05-09 08:19   <DIR>   --d-----   c:\documents and settings\all users\Pulpit
2009-05-09 08:18   <DIR>   --d-hr--   c:\documents and settings\all users\Dane aplikacji

==================== Find3M  ====================

2009-05-09 22:00   102,400   a-------   c:\winnt\DUMPdaa0.tmp
2009-05-09 16:44   182,912   a-------   c:\winnt\system32\drivers\ndis.sys
2009-05-09 08:47   355,830   a-------   c:\winnt\system32\perfh015.dat
2009-05-09 08:47   49,712   a-------   c:\winnt\system32\perfc015.dat
2009-05-09 08:30   86,315   a-------   c:\winnt\pchealth\helpctr\offlinecache\index.dat
2009-05-09 08:27   21,856   a-------   c:\winnt\system32\emptyregdb.dat

============= FINISH:  9:48:41,23 ===============



ATTACH


Kod: Zaznacz wszystko
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-03-16.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2009-05-09 08:31:24
System Uptime: 2009-05-10 09:35:24 (0 hours ago)

Motherboard: MSI |  | MS-6712
Processor: AMD Athlon(tm) XP 2600+ | Socket-A | 1975/158mhz

==== Disk Partitions =========================

C: is FIXED (FAT32) - 19 GiB total, 14,921 GiB free.
D: is FIXED (NTFS) - 19 GiB total, 0,978 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 77 GiB total, 51,52 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 2009-05-09 08:38:16 - Punkt kontrolny systemu
RP2: 2009-05-09 08:40:04 - Installed Ralink Wireless LAN Card
RP3: 2009-05-09 10:39:36 - Installed Quake Live Mozilla Plugin
RP4: 2009-05-09 18:11:52 - Zainstalowano: Nero 7 Demo

==== Installed Programs ======================

Adobe Flash Player 10 Plugin
Aktualizacja zabezpieczeń dla systemu Windows XP (KB916281)
Archiwizator WinRAR
ATI Display Driver
Gadu-Gadu 7.7
HijackThis 2.0.2
Mozilla Firefox (3.0.5)
Narzędzie Software Uninstall Utility firmy ATI
Nero 7 Demo
Panel sterowania ATI
PunkBuster Services
Quake Live Mozilla Plugin
Ralink Wireless LAN Card
Realtek AC'97 Audio
Security Update for Step By Step Interactive Training (KB898458)
WebFldrs XP

==== Event Viewer Messages From Past Week ========

2009-05-09 22:35:37, informacje: Windows File Protection [64018]  - Skanowanie plików przez Ochronę plików systemu Windows zostało anulowane przez użytkownika. Nazwa użytkownika: csd.
2009-05-09 22:35:34, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\program files\msn gaming zone\windows\bckgzm.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:35:32, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\program files\msn gaming zone\windows\bckgzm.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 1.2.626.1.
2009-05-09 22:35:26, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\auditusr.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:35:26, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\auditusr.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:35:24, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\attrib.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:35:23, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\attrib.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.0.
2009-05-09 22:35:23, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\atmadm.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.2180.
2009-05-09 22:35:23, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\atmadm.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:35:04, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\at.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.2180.
2009-05-09 22:35:04, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\at.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:35:03, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\asr_pfu.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.2180.
2009-05-09 22:35:03, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\asr_ldm.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 2600.0.503.0.
2009-05-09 22:35:03, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\asr_fmt.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.2180.
2009-05-09 22:35:03, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\asr_pfu.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:35:03, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\asr_ldm.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:35:03, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\asr_fmt.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:35:00, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\arp.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.0.
2009-05-09 22:35:00, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\arp.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:55, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\alg.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.2180.
2009-05-09 22:34:55, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\alg.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:50, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\msagent\agentsvr.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 2.0.0.3422.
2009-05-09 22:34:50, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\msagent\agentsvr.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:42, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\actmovie.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:41, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\actmovie.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 6.5.2600.2180.
2009-05-09 22:34:41, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\accwiz.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:39, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\accwiz.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.2180.
2009-05-09 22:34:33, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\inf\unregmp2.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 9.0.0.3250.
2009-05-09 22:34:33, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\inf\unregmp2.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:32, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\odbcconf.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 3.525.1117.0.
2009-05-09 22:34:32, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\odbcconf.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:32, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\odbcad32.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:31, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\odbcad32.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 3.525.1117.0.
2009-05-09 22:34:29, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\program files\windows media player\mplayer2.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:28, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\logagent.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 9.0.0.3250.
2009-05-09 22:34:28, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\program files\windows media player\mplayer2.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 6.4.9.1125.
2009-05-09 22:34:28, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\logagent.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:25, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\sysocmgr.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.2180.
2009-05-09 22:34:25, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\sysocmgr.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:20, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\sfc.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.0.
2009-05-09 22:34:20, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\sfc.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:34:19, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\sdbinst.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.2180.
2009-05-09 22:34:19, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\sdbinst.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:33:59, informacje: Windows File Protection [64020]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\ahui.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej. Wersja pliku dla pliku systemowego jest 5.1.2600.2180.
2009-05-09 22:33:59, informacje: Windows File Protection [64019]  - Skanowanie przeprowadzone przez Ochronę plików systemu Windows wykryło, że plik systemowy c:\winnt\system32\ahui.exe ma zły podpis. Dla zachowania stabilności systemu ten plik przywrócono do wersji oryginalnej.
2009-05-09 22:32:25, informacje: Windows File Protection [64016]  - Ochrona plików systemu Windows rozpoczęła skanowanie plików.
2009-05-09 08:37:52, informacje: Windows File Protection [64032]  - Ochrona plików systemu Windows nie jest aktywna w tym systemie.

==== End Of File ===========================
LOLSiq
~user
 
Posty: 4
Dołączenie: 09 Maj 2009, 22:48



Reader_s.exe ,poderzenie viruta - logi

Postprzez Okocza 10 Maj 2009, 09:58

LOLSiq, daj jeszcze log z RSIT'a z ostatnich 2 miesięcy pliki niech pokaże.
eMachines E730G - Core i5-430M, 2GiB RAM, ATI Mobility Radeon HD5470, WD 320GiB; Cort Z-44,DR 0.09-0.42, Peavey Backstage
Mac OS X 10.7.4 Lion // Windows 7 Professional x64 // NIE POMAGAM NA PW/GG/E-MAIL
Image
"Moje Ego i Anima spotykają się i wymieniają przepisami na ciasteczka" - Maynard James Keenan
Awatar użytkownika
Okocza
~user
 
Posty: 8001
Dołączenie: 19 Mar 2006, 11:53
Pochwały: 406



Reader_s.exe ,poderzenie viruta - logi

Postprzez LOLSiq 10 Maj 2009, 10:26

Tylko że ja nie dawno formatowałem parę dni temu;/
Daje logi z RSITA:

Kod: Zaznacz wszystko
Logfile of random's system information tool 1.06 (written by random/random)
Run by csd at 2009-05-10 10:24:37
Microsoft Windows XP Professional Dodatek Service Pack 2
System drive C: has 15 GB (77%) free of 19 GB
Total RAM: 255 MB (12% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:46, on 2009-05-10
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\PnkBstrA.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\System32\reader_s.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Documents and Settings\csd\reader_s.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Documents and Settings\csd\Pulpit\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\csd.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://signup.live.com/signup.aspx?mkt=en-us&rollrs=12&lic=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [reader_s] C:\WINNT\System32\reader_s.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\csd\reader_s.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{EAF8C60B-0082-4183-A95D-EB37FDA907EA}: NameServer = 190.168.30.1,194.204.159.1
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINNT\system32\PnkBstrA.exe

--
End of file - 3967 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-06-28 364544]
"SoundMan"=C:\WINNT\SOUNDMAN.EXE [2003-06-10 72704]
"reader_s"=C:\WINNT\System32\reader_s.exe [2009-05-09 36352]
"NeroFilterCheck"=C:\WINNT\system32\NeroCheck.exe [2001-07-09 176128]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINNT\system32\ctfmon.exe [2004-08-04 32768]
"Gadu-Gadu"=C:\Program Files\Gadu-Gadu\gg.exe [2008-03-20 2127296]
"reader_s"=C:\Documents and Settings\csd\reader_s.exe [2009-05-09 36352]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2005-10-28 114688]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
Ralink Wireless Utility.lnk - C:\Program Files\RALINK\Common\RaUI.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINNT\system32\Ati2evxx.dll [2004-08-01 46080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"\??\C:\WINNT\system32\winlogon.exe"="\??\C:\WINNT\system32\winlogon.exe:*:enabled:@shell32.dll,-1"
"C:\WINNT\System32\PnkBstrA.exe"="C:\WINNT\System32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINNT\System32\PnkBstrB.exe"="C:\WINNT\System32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Mozilla Firefox\FIREFOX.EXE"="C:\Program Files\Mozilla Firefox\FIREFOX.EXE:*:Enabled:Firefox"
"C:\Documents and Settings\CSD\Pulpit\q3arena\quake3.exe"="C:\Documents and Settings\CSD\Pulpit\q3arena\quake3.exe:*:Enabled:quake3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3203e782-3c71-11de-837b-806d6172696f}]
shell\AutoRun\command - E:\autoplay.exe


======List of files/folders created in the last 1 months======

2009-05-10 10:20:01 ----A---- C:\WINNT\War3Unin.exe
2009-05-10 10:16:03 ----D---- C:\Program Files\Warcraft III
2009-05-10 09:46:13 ----HD---- C:\WINNT\PIF
2009-05-10 09:36:41 ----A---- C:\WINNT\system32\5.tmp
2009-05-09 23:01:45 ----D---- C:\rsit
2009-05-09 22:31:56 ----D---- C:\Program Files\xerox
2009-05-09 22:31:55 ----D---- C:\WINNT\system32\xircom
2009-05-09 22:31:53 ----SHD---- C:\WINNT\system32\dllcache
2009-05-09 22:31:53 ----D---- C:\Program Files\microsoft frontpage
2009-05-09 22:26:13 ----D---- C:\WINNT\ERUNT
2009-05-09 22:24:28 ----D---- C:\SDFix
2009-05-09 21:58:38 ----SHD---- C:\FOUND.002
2009-05-09 21:51:54 ----D---- C:\Qoobox
2009-05-09 21:51:52 ----A---- C:\Bug.txt
2009-05-09 21:24:44 ----SHD---- C:\Recycled
2009-05-09 21:02:50 ----SHD---- C:\FOUND.001
2009-05-09 19:40:34 ----A---- C:\WINNT\system32\Wnaspi32.dll
2009-05-09 19:39:10 ----A---- C:\WINNT\ntbtlog.txt
2009-05-09 19:34:33 ----D---- C:\Documents and Settings\csd\Dane aplikacji\WinRAR
2009-05-09 19:16:01 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Gadu-Gadu
2009-05-09 18:16:12 ----A---- C:\WINNT\NeroDigital.ini
2009-05-09 18:12:49 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Ahead
2009-05-09 18:11:56 ----D---- C:\Program Files\Nero
2009-05-09 18:11:56 ----D---- C:\Program Files\Common Files\Ahead
2009-05-09 18:06:47 ----D---- C:\Program Files\WinRAR
2009-05-09 18:05:40 ----SHD---- C:\FOUND.000
2009-05-09 17:37:39 ----D---- C:\Program Files\Trend Micro
2009-05-09 16:30:56 ----A---- C:\WINNT\system32\reader_s.exe
2009-05-09 10:41:56 ----D---- C:\Documents and Settings\csd\Dane aplikacji\id Software
2009-05-09 10:39:48 ----A---- C:\WINNT\system32\PnkBstrB.exe
2009-05-09 10:39:44 ----D---- C:\WINNT\system32\LogFiles
2009-05-09 10:39:44 ----A---- C:\WINNT\system32\PnkBstrA.exe
2009-05-09 10:39:44 ----A---- C:\WINNT\system32\pbsvc.exe
2009-05-09 10:39:40 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\id Software
2009-05-09 10:26:18 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\InterAction studios
2009-05-09 10:01:46 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Macromedia
2009-05-09 10:01:45 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Adobe
2009-05-09 10:01:22 ----A---- C:\WINNT\RtlRack.ini
2009-05-09 09:51:10 ----A---- C:\WINNT\system32\ksuser.dll
2009-05-09 09:51:08 ----D---- C:\Program Files\Realtek Sound Manager
2009-05-09 09:51:06 ----D---- C:\Program Files\AvRack
2009-05-09 09:51:05 ----N---- C:\WINNT\avrack.ini
2009-05-09 09:51:04 ----A---- C:\WINNT\system32\Audio3D.dll
2009-05-09 09:51:04 ----A---- C:\WINNT\system32\a3d.dll
2009-05-09 09:51:03 ----A---- C:\WINNT\SOUNDMAN.EXE
2009-05-09 09:50:59 ----N---- C:\WINNT\alcupd.exe
2009-05-09 09:50:59 ----N---- C:\WINNT\alcrmv.exe
2009-05-09 09:50:10 ----A---- C:\WINNT\IsUninst.exe
2009-05-09 09:48:32 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Help
2009-05-09 09:44:24 ----N---- C:\WINNT\system32\ati2sgag.exe
2009-05-09 09:44:19 ----RA---- C:\WINNT\system32\atiiiexx.dll
2009-05-09 09:44:11 ----D---- C:\WINNT\system32\ReinstallBackups
2009-05-09 09:43:57 ----D---- C:\Program Files\ATI Technologies
2009-05-09 09:35:05 ----D---- C:\Program Files\Gadu-Gadu
2009-05-09 08:43:17 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Mozilla
2009-05-09 08:40:32 ----D---- C:\WINNT\system32\DRVSTORE
2009-05-09 08:40:14 ----A---- C:\WINNT\system32\Install6x.dll
2009-05-09 08:40:14 ----A---- C:\WINNT\system32\AegisI5.exe
2009-05-09 08:40:04 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-09 08:39:56 ----D---- C:\Program Files\Common Files\InstallShield
2009-05-09 08:39:10 ----D---- C:\Program Files\RALINK
2009-05-09 08:38:46 ----D---- C:\Program Files\Mozilla Firefox
2009-05-09 08:38:04 ----D---- C:\Documents and Settings\csd\Dane aplikacji\Identities
2009-05-09 08:38:03 ----HD---- C:\Program Files\Uninstall Information
2009-05-09 08:37:55 ----SD---- C:\Documents and Settings\csd\Dane aplikacji\Microsoft
2009-05-09 08:37:55 ----ASH---- C:\Documents and Settings\csd\Dane aplikacji\desktop.ini
2009-05-09 08:32:36 ----SHD---- C:\System Volume Information
2009-05-09 08:32:36 ----D---- C:\WINNT\SoftwareDistribution
2009-05-09 08:32:35 ----SD---- C:\WINNT\system32\Microsoft
2009-05-09 08:32:35 ----D---- C:\WINNT\Prefetch
2009-05-09 08:32:35 ----A---- C:\WINNT\SchedLgU.Txt
2009-05-09 08:31:07 ----A---- C:\WINNT\system32\spupdsvc.exe
2009-05-09 08:31:00 ----N---- C:\WINNT\system32\spmsg.dll
2009-05-09 08:30:58 ----HD---- C:\WINNT\$hf_mig$
2009-05-09 08:30:44 ----A---- C:\WINNT\control.ini
2009-05-09 08:30:44 ----A---- C:\AUTOEXEC.BAT
2009-05-09 08:30:29 ----A---- C:\WINNT\OEWABLog.txt
2009-05-09 08:30:25 ----A---- C:\WINNT\system32\mapi32.dll
2009-05-09 08:29:32 ----SD---- C:\WINNT\Downloaded Program Files
2009-05-09 08:29:32 ----RD---- C:\WINNT\Offline Web Pages
2009-05-09 08:29:32 ----RAH---- C:\WINNT\system32\logonui.exe.manifest
2009-05-09 08:29:26 ----RAH---- C:\WINNT\system32\cdplayer.exe.manifest
2009-05-09 08:29:21 ----HD---- C:\Program Files\WindowsUpdate
2009-05-09 08:29:18 ----D---- C:\Program Files\Usługi online
2009-05-09 08:28:59 ----D---- C:\WINNT\system32\DirectX
2009-05-09 08:28:36 ----A---- C:\WINNT\system32\atrace.dll
2009-05-09 08:28:33 ----A---- C:\WINNT\system32\desktop.ini
2009-05-09 08:28:33 ----A---- C:\WINNT\desktop.ini
2009-05-09 08:28:24 ----A---- C:\WINNT\system32\nmevtmsg.dll
2009-05-09 08:28:23 ----A---- C:\WINNT\system32\acctres.dll
2009-05-09 08:28:22 ----D---- C:\Program Files\Common Files\Services
2009-05-09 08:28:19 ----SD---- C:\WINNT\Tasks
2009-05-09 08:28:19 ----A---- C:\WINNT\system32\icfgnt5.dll
2009-05-09 08:28:18 ----D---- C:\Program Files\Common Files\MSSoap
2009-05-09 08:28:13 ----D---- C:\WINNT\srchasst
2009-05-09 08:28:12 ----D---- C:\WINNT\system32\Macromed
2009-05-09 08:28:09 ----A---- C:\WINNT\system32\wuweb.dll
2009-05-09 08:28:09 ----A---- C:\WINNT\system32\wucltui.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wups.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuauserv.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuaueng1.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuaueng.dll
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuauclt1.exe
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuauclt.exe
2009-05-09 08:28:08 ----A---- C:\WINNT\system32\wuapi.dll
2009-05-09 08:28:07 ----A---- C:\WINNT\system32\qmgrprxy.dll
2009-05-09 08:28:07 ----A---- C:\WINNT\system32\qmgr.dll
2009-05-09 08:28:07 ----A---- C:\WINNT\system32\bitsprx3.dll
2009-05-09 08:28:07 ----A---- C:\WINNT\system32\bitsprx2.dll
2009-05-09 08:28:03 ----D---- C:\Program Files\Movie Maker
2009-05-09 08:27:57 ----A---- C:\WINNT\system32\safrslv.dll
2009-05-09 08:27:57 ----A---- C:\WINNT\system32\safrdm.dll
2009-05-09 08:27:57 ----A---- C:\WINNT\system32\safrcdlg.dll
2009-05-09 08:27:57 ----A---- C:\WINNT\system32\racpldlg.dll
2009-05-09 08:27:52 ----D---- C:\WINNT\system32\Restore
2009-05-09 08:27:52 ----A---- C:\WINNT\system32\fltMc.exe
2009-05-09 08:27:52 ----A---- C:\WINNT\system32\fltlib.dll
2009-05-09 08:27:51 ----A---- C:\WINNT\system32\srsvc.dll
2009-05-09 08:27:51 ----A---- C:\WINNT\system32\srrstr.dll
2009-05-09 08:27:51 ----A---- C:\WINNT\system32\srclient.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\nmmkcert.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\msconf.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\mnmsrvc.exe
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\mnmdd.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\isrdbg32.dll
2009-05-09 08:27:50 ----A---- C:\WINNT\system32\ils.dll
2009-05-09 08:27:47 ----D---- C:\Program Files\NetMeeting
2009-05-09 08:27:46 ----A---- C:\WINNT\system32\msoert2.dll
2009-05-09 08:27:46 ----A---- C:\WINNT\system32\msoeacct.dll
2009-05-09 08:27:45 ----A---- C:\WINNT\system32\inetres.dll
2009-05-09 08:27:45 ----A---- C:\WINNT\system32\inetcomm.dll
2009-05-09 08:27:43 ----D---- C:\Program Files\Outlook Express
2009-05-09 08:27:43 ----A---- C:\WINNT\system32\schedsvc.dll
2009-05-09 08:27:43 ----A---- C:\WINNT\system32\mstinit.exe
2009-05-09 08:27:42 ----A---- C:\WINNT\system32\mstask.dll
2009-05-09 08:27:42 ----A---- C:\WINNT\system32\isign32.dll
2009-05-09 08:27:42 ----A---- C:\WINNT\system32\icwphbk.dll
2009-05-09 08:27:42 ----A---- C:\WINNT\system32\icwdial.dll
2009-05-09 08:27:41 ----A---- C:\WINNT\system32\inetcfg.dll
2009-05-09 08:27:35 ----D---- C:\Program Files\Common Files\System
2009-05-09 08:27:33 ----D---- C:\Program Files\Internet Explorer
2009-05-09 08:26:49 ----D---- C:\Program Files\ComPlus Applications
2009-05-09 08:26:47 ----A---- C:\WINNT\vbaddin.ini
2009-05-09 08:26:47 ----A---- C:\WINNT\vb.ini
2009-05-09 08:26:43 ----D---- C:\WINNT\Registration
2009-05-09 08:26:37 ----D---- C:\Program Files\Windows Media Player
2009-05-09 08:26:30 ----D---- C:\Program Files\Messenger
2009-05-09 08:26:26 ----D---- C:\Program Files\MSN Gaming Zone
2009-05-09 08:26:26 ----A---- C:\WINNT\system32\write.exe
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\sndvol32.exe
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\hticons.dll
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\avwav.dll
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\avtapi.dll
2009-05-09 08:26:14 ----A---- C:\WINNT\system32\avmeter.dll
2009-05-09 08:26:13 ----A---- C:\WINNT\system32\winchat.exe
2009-05-09 08:26:04 ----A---- C:\WINNT\system32\getuname.dll
2009-05-09 08:26:04 ----A---- C:\WINNT\system32\charmap.exe
2009-05-09 08:26:04 ----A---- C:\WINNT\system32\calc.exe
2009-05-09 08:26:03 ----A---- C:\WINNT\system32\winmine.exe
2009-05-09 08:26:03 ----A---- C:\WINNT\system32\sol.exe
2009-05-09 08:26:03 ----A---- C:\WINNT\system32\mshearts.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\usrlogon.cmd
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tsshutdn.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tslabels.ini
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tskill.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tsdiscon.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\tscon.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\reset.exe
2009-05-09 08:26:02 ----A---- C:\WINNT\system32\freecell.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\shadow.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\rwinsta.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\regini.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\rdpcfgex.dll
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\qwinsta.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\qappsrv.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\msg.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\logoff.exe
2009-05-09 08:26:01 ----A---- C:\WINNT\system32\cdmodem.dll
2009-05-09 08:26:00 ----A---- C:\WINNT\system32\msdtcprf.ini
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\stclient.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\mtxlegih.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\mtxex.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\mtxdm.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\dcomcnfg.exe
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\comrepl.dll
2009-05-09 08:25:59 ----A---- C:\WINNT\system32\comaddin.dll
2009-05-09 08:25:58 ----A---- C:\WINNT\system32\comsnap.dll
2009-05-09 08:25:52 ----A---- C:\WINNT\system32\wmimgmt.msc
2009-05-09 08:25:50 ----A---- C:\WINNT\system32\sndrec32.exe
2009-05-09 08:25:50 ----A---- C:\WINNT\system32\mplay32.exe
2009-05-09 08:25:50 ----A---- C:\WINNT\system32\hypertrm.dll
2009-05-09 08:25:50 ----A---- C:\WINNT\system32\accwiz.exe
2009-05-09 08:25:49 ----D---- C:\Program Files\Windows NT
2009-05-09 08:25:49 ----A---- C:\WINNT\system32\spider.exe
2009-05-09 08:25:49 ----A---- C:\WINNT\system32\mspaint.exe
2009-05-09 08:25:49 ----A---- C:\WINNT\system32\clipbrd.exe
2009-05-09 08:25:48 ----A---- C:\WINNT\system32\tscfgwmi.dll
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\sessmgr.exe
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\remotepg.dll
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\rdshost.exe
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\rdsaddin.exe
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\rdchost.dll
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\mstscax.dll
2009-05-09 08:25:47 ----A---- C:\WINNT\system32\mstsc.exe
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\tscupgrd.exe
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\termsrv.dll
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\rdpwsx.dll
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\rdpsnd.dll
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\rdpclip.exe
2009-05-09 08:25:46 ----A---- C:\WINNT\system32\qprocess.exe
2009-05-09 08:25:45 ----D---- C:\WINNT\system32\MsDtc
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\mtxoci.dll
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\msdtcuiu.dll
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\msdtcprx.dll
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\icaapi.dll
2009-05-09 08:25:45 ----A---- C:\WINNT\system32\cfgbkend.dll
2009-05-09 08:25:44 ----A---- C:\WINNT\system32\xolehlp.dll
2009-05-09 08:25:44 ----A---- C:\WINNT\system32\msdtctm.dll
2009-05-09 08:25:44 ----A---- C:\WINNT\system32\msdtclog.dll
2009-05-09 08:25:44 ----A---- C:\WINNT\system32\msdtc.exe
2009-05-09 08:25:43 ----D---- C:\WINNT\system32\Com
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\colbact.dll
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\clbcatex.dll
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\catsrvut.dll
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\catsrvps.dll
2009-05-09 08:25:43 ----A---- C:\WINNT\system32\catsrv.dll
2009-05-09 08:25:42 ----A---- C:\WINNT\system32\comuid.dll
2009-05-09 08:25:42 ----A---- C:\WINNT\system32\comsvcs.dll
2009-05-09 08:25:42 ----A---- C:\WINNT\system32\clbcatq.dll
2009-05-09 08:25:35 ----A---- C:\WINNT\system32\servdeps.dll
2009-05-09 08:25:35 ----A---- C:\WINNT\system32\mmfutil.dll
2009-05-09 08:25:35 ----A---- C:\WINNT\system32\licwmi.dll
2009-05-09 08:25:35 ----A---- C:\WINNT\system32\cmprops.dll
2009-05-09 08:24:24 ----A---- C:\WINNT\system32\h323log.txt
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ativvaxx.dll
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ati3duag.dll
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ati3d1ag.dll
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ati2dvag.dll
2009-05-09 08:21:07 ----A---- C:\WINNT\system32\ati2cqag.dll
2009-05-09 08:20:46 ----A---- C:\WINNT\system32\usbui.dll
2009-05-09 08:19:50 ----SHD---- C:\WINNT\Installer
2009-05-09 08:19:50 ----A---- C:\WINNT\system32\PerfStringBackup.INI
2009-05-09 08:19:49 ----D---- C:\Program Files\Common Files\ODBC
2009-05-09 08:19:49 ----A---- C:\WINNT\ODBCINST.INI
2009-05-09 08:19:46 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-05-09 08:19:45 ----RD---- C:\Program Files
2009-05-09 08:19:45 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-09 08:19:45 ----D---- C:\Program Files\Common Files
2009-05-09 08:19:35 ----RA---- C:\WINNT\system32\kbdazel.dll
2009-05-09 08:19:34 ----RA---- C:\WINNT\system32\kbdtuq.dll
2009-05-09 08:19:34 ----RA---- C:\WINNT\system32\kbdtuf.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbduzb.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdur.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdtat.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdmon.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdkyr.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdkaz.dll
2009-05-09 08:19:32 ----RA---- C:\WINNT\system32\kbdaze.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdycc.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdru1.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdru.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdbu.dll
2009-05-09 08:19:31 ----RA---- C:\WINNT\system32\kbdblr.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhept.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhela3.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhela2.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhe319.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhe220.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdhe.dll
2009-05-09 08:19:29 ----RA---- C:\WINNT\system32\kbdgkl.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdlv1.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdlv.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdlt1.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdlt.dll
2009-05-09 08:19:27 ----RA---- C:\WINNT\system32\kbdest.dll
2009-05-09 08:19:17 ----RA---- C:\WINNT\system32\kbdsl1.dll
2009-05-09 08:19:17 ----RA---- C:\WINNT\system32\kbdsl.dll
2009-05-09 08:19:17 ----RA---- C:\WINNT\system32\kbdro.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdycl.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdhu1.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdhu.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdcz2.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdcz1.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdcz.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\kbdcr.dll
2009-05-09 08:19:16 ----RA---- C:\WINNT\system32\KBDAL.DLL
2009-05-09 08:19:15 ----A---- C:\WINNT\system32\spxcoins.dll
2009-05-09 08:19:15 ----A---- C:\WINNT\system32\irclass.dll
2009-05-09 08:19:15 ----A---- C:\WINNT\system32\dgsetup.dll
2009-05-09 08:19:15 ----A---- C:\WINNT\system32\dgrpsetu.dll
2009-05-09 08:19:14 ----A---- C:\WINNT\system32\EqnClass.Dll
2009-05-09 08:19:11 ----N---- C:\WINNT\system32\CONFIG.TMP
2009-05-09 08:19:11 ----A---- C:\WINNT\TASKMAN.EXE
2009-05-09 08:19:10 ----A---- C:\WINNT\system32\storprop.dll
2009-05-09 08:19:10 ----A---- C:\WINNT\system32\batt.dll
2009-05-09 08:19:10 ----A---- C:\WINNT\NOTEPAD.EXE
2009-05-09 08:19:03 ----ASH---- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
2009-05-09 08:18:53 ----RA---- C:\WINNT\SET8.tmp
2009-05-09 08:18:51 ----RA---- C:\WINNT\SET4.tmp
2009-05-09 08:18:49 ----RA---- C:\WINNT\SET3.tmp
2009-05-09 08:18:44 ----D---- C:\WINNT\system32\CatRoot2
2009-05-09 08:18:44 ----D---- C:\WINNT\system32\CatRoot
2009-05-09 08:18:38 ----SD---- C:\Documents and Settings\All Users\Dane aplikacji\Microsoft
2009-05-09 08:18:18 ----A---- C:\WINNT\setuplog.txt
2009-05-09 08:18:15 ----D---- C:\Documents and Settings
2009-05-09 08:17:34 ----SH---- C:\boot.ini
2009-05-09 08:13:53 ----RSD---- C:\WINNT\Fonts
2009-05-09 08:13:53 ----RD---- C:\WINNT\Web
2009-05-09 08:13:53 ----HD---- C:\WINNT\inf
2009-05-09 08:13:53 ----D---- C:\WINNT\WinSxS
2009-05-09 08:13:53 ----D---- C:\WINNT\twain_32
2009-05-09 08:13:53 ----D---- C:\WINNT\Temp
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\wins
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\wbem
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\usmt
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\spool
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\ShellExt
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\Setup
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\ras
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\PreInstall
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\oobe
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\npp
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\mui
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\inetsrv
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\IME
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\icsxml
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\ias
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\export
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\drivers
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\dhcp
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\config
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\3com_dmi
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\3076
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\2052
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1054
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1045
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1042
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1041
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1037
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1033
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1031
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1028
2009-05-09 08:13:53 ----D---- C:\WINNT\system32\1025
2009-05-09 08:13:53 ----D---- C:\WINNT\system32
2009-05-09 08:13:53 ----D---- C:\WINNT\system
2009-05-09 08:13:53 ----D---- C:\WINNT\security
2009-05-09 08:13:53 ----D---- C:\WINNT\Resources
2009-05-09 08:13:53 ----D---- C:\WINNT\repair
2009-05-09 08:13:53 ----D---- C:\WINNT\Provisioning
2009-05-09 08:13:53 ----D---- C:\WINNT\PeerNet
2009-05-09 08:13:53 ----D---- C:\WINNT\pchealth
2009-05-09 08:13:53 ----D---- C:\WINNT\mui
2009-05-09 08:13:53 ----D---- C:\WINNT\msapps
2009-05-09 08:13:53 ----D---- C:\WINNT\msagent
2009-05-09 08:13:53 ----D---- C:\WINNT\Media
2009-05-09 08:13:53 ----D---- C:\WINNT\java
2009-05-09 08:13:53 ----D---- C:\WINNT\ime
2009-05-09 08:13:53 ----D---- C:\WINNT\Help
2009-05-09 08:13:53 ----D---- C:\WINNT\ehome
2009-05-09 08:13:53 ----D---- C:\WINNT\Driver Cache
2009-05-09 08:13:53 ----D---- C:\WINNT\Debug
2009-05-09 08:13:53 ----D---- C:\WINNT\Cursors
2009-05-09 08:13:53 ----D---- C:\WINNT\Connection Wizard
2009-05-09 08:13:53 ----D---- C:\WINNT\Config
2009-05-09 08:13:53 ----D---- C:\WINNT\AppPatch
2009-05-09 08:13:53 ----D---- C:\WINNT\addins
2009-05-09 08:13:53 ----D---- C:\WINNT
2009-05-09 08:13:53 ----A---- C:\WINNT\DUMPdaa0.tmp

======List of files/folders modified in the last 1 months======

2009-05-09 08:30:46 ----A---- C:\WINNT\win.ini
2009-05-09 08:19:46 ----A---- C:\WINNT\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;Sterownik procesora AMD K7; C:\WINNT\system32\DRIVERS\amdk7.sys [2006-07-15 41472]
R1 ASPI32;ASPI32; C:\WINNT\system32\drivers\ASPI32.sys [2002-07-17 16877]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.10.0; C:\WINNT\system32\DRIVERS\AegisP.sys [2009-05-09 21275]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINNT\system32\drivers\ALCXWDM.SYS [2003-06-19 752764]
R3 ati2mtag;ati2mtag; C:\WINNT\system32\DRIVERS\ati2mtag.sys [2004-08-01 1241088]
R3 catchme;catchme; \??\C:\DOCUME~1\csd\USTAWI~1\Temp\catchme.sys []
R3 RT61;Ralink RT61 Wireless Driver; C:\WINNT\system32\DRIVERS\RT61.sys [2006-05-04 380928]
R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINNT\system32\DRIVERS\usbehci.sys [2006-07-15 30080]
R3 usbhub;Koncentrator z obsługą USB2; C:\WINNT\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Sterownik Miniport uniwersalnego kontrolera hosta USB Microsoft; C:\WINNT\system32\DRIVERS\usbuhci.sys [2006-07-15 20608]
S1 InCDPass;InCDPass; C:\WINNT\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINNT\system32\drivers\InCDRm.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S4 InCDFs;InCD File System; C:\WINNT\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\WINNT\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINNT\system32\Ati2evxx.exe [2004-08-01 397312]
R2 PnkBstrA;PnkBstrA; C:\WINNT\system32\PnkBstrA.exe [2009-05-09 66872]
S2 ATI Smart;ATI Smart; C:\WINNT\system32\ati2sgag.exe [2005-06-28 536576]

-----------------EOF-----------------
LOLSiq
~user
 
Posty: 4
Dołączenie: 09 Maj 2009, 22:48



Reader_s.exe ,poderzenie viruta - logi

Postprzez wojtas 10 Maj 2009, 10:29

a więc tak moim zdaniem nie ma co walczyć ... jest modyfikacja plików :/ musisz robic formata wszystkich partycji.. filmy muze mozesz sobie gdzies zgrać... ale pliki .exe są zarażone. no chyba ze bedziesz cos probować :

http://www.searchengines.pl/Infekcje-plikow-wykonywalnych-exe-dll-scr-t122692.html

Autor postu otrzymał pochwałę
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Reader_s.exe ,poderzenie viruta - logi

Postprzez LOLSiq 10 Maj 2009, 10:30

Dobra to ja sie poddaje. Zrobie tego formata, trudno sie mówi.

Dziękuje za pomoc.
LOLSiq
~user
 
Posty: 4
Dołączenie: 09 Maj 2009, 22:48




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 9 gości