
Oto logi:
1. HijackThis:
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22:38, on 2007-09-12
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\NOTEPAD.EXE
E:\dodatki\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.onet.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = L1cza
O1 - Hosts: 69.80.225.31 nprotect.ryl.com.my
O1 - Hosts: 72.232.248.222 nprotect.battlelands.net
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: SAGEM Wi-Fi 11g USB adapter LAN Utility.lnk = ?
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://mks.com.pl
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1173383578687
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MainControl Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 4908 bytes
2.ComboScan:
- Kod: Zaznacz wszystko
ComboScan v20070306.20 run by SZEWCO on 2007-09-12 at 22:37:28
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as SZEWCO.exe) ----------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 22:37, on 2007-09-12
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\csrs.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
E:\dodatki\comboscan.exe
E:\dodatki\SZEWCO.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.onet.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = L1cza
O1 - Hosts: 69.80.225.31 nprotect.ryl.com.my
O1 - Hosts: 72.232.248.222 nprotect.battlelands.net
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: SAGEM Wi-Fi 11g USB adapter LAN Utility.lnk = ?
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://mks.com.pl
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1173383578687
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MainControl Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
-- Files created between 2007-08-12 and 2007-09-12 -----------------------------
2007-09-07 17:21:35 17664 --a------ C:\WINDOWS\system32\drivers\ZDPSp50.sys
2007-09-07 17:21:35 29184 --a------ C:\WINDOWS\system32\drivers\BRGSp50a64.sys<BRGSP5~1.SYS>
2007-09-07 17:21:35 20608 --a------ C:\WINDOWS\system32\drivers\BRGSp50.sys
2007-09-07 17:21:35 0 d-------- C:\Program Files\SAGEM WiFi manager<SAGEMW~1>
2007-09-07 17:21:28 0 d-------- C:\Program Files\SAGEM
2007-09-07 17:20:50 402432 --a------ C:\WINDOWS\system32\drivers\WlanBZXP.sys
2007-09-07 17:20:50 493440 --a------ C:\WINDOWS\system32\drivers\WlanBZ64.SYS
2007-09-07 17:20:43 31744 --a------ C:\WINDOWS\system32\drivers\ZDPSp50a64.sys<ZDPSP5~1.SYS>
2007-09-03 05:27:36 122880 --a------ C:\Documents and Settings\SZEWCO\9332736.dll
2007-08-30 14:19:26 122880 --a------ C:\Documents and Settings\SZEWCO\830121926.dll<830121~1.DLL>
2007-08-25 10:07:15 55004 --a------ C:\WINDOWS\system32\xpdx.sys
2007-08-25 07:56:04 0 d-------- C:\Program Files\SD EnterNET<SDENTE~1>
2007-08-24 22:01:32 834790 --a------ C:\Program Files\LRGHZFLV3UIO56B6TPWTUKZPVRYJRU5C Free-Games_Navy_Field_Resurrection_Of_The_Steel_Fleet_1175.exe<LRGHZF~1.EXE>
2007-08-24 13:50:25 0 d-------- C:\NavyFIELD_WorldLeague2007_FullClient<NAVYFI~1>
2007-08-21 22:02:07 0 d-------- C:\Program Files\mIRC
2007-08-20 14:34:28 0 d-------- C:\Fishing Simulator 2<FISHIN~1>
2007-08-19 11:02:17 0 d-------- C:\Program Files\Wedkarz
2007-08-18 00:07:27 0 d-------- C:\psyBNC-2.3.2-7<PSYBNC~1.2-7>
2007-08-17 20:21:14 8704 --a------ C:\WINDOWS\csrs.exe
2007-08-17 20:20:14 5120 --a------ C:\WINDOWS\csrss.dll
-- Find3M Report ---------------------------------------------------------------
2007-09-10 18:22:16 24 --a------ C:\WINDOWS\system32\DVCStateBkp-{00000001-00000000-00000008-00001102-00000002-80651102}.dat<DVCSTA~2.DAT>
2007-09-10 18:22:16 24 --a------ C:\WINDOWS\system32\DVCState-{00000001-00000000-00000008-00001102-00000002-80651102}.dat<DVCSTA~1.DAT>
2007-09-07 22:36:46 0 d-------- C:\Program Files\ffdshow
2007-09-07 17:21:35 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-09-05 21:20:44 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-09-01 14:58:01 0 d-------- C:\Documents and Settings\SZEWCO\Dane aplikacji\Skype
2007-08-24 22:09:41 0 d-------- C:\Documents and Settings\SZEWCO\Dane aplikacji\Azureus
2007-08-24 22:09:07 0 d-------- C:\Program Files\Azureus
2007-08-24 22:04:40 2081 --a------ C:\Program Files\LRGHZFLV3UIO56B6TPWTUKZPVRYJRU5C Free-Games_Navy_Field_Resurrection_Of_The_Steel_Fleet_1175.exe.sd<LRGHZF~1.SD>
2007-08-22 14:53:09 1902 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-21 22:01:25 0 d-------- C:\Program Files\AC3Filter<AC3FIL~1>
2007-08-17 22:41:10 0 d-------- C:\Program Files\Gadu-Gadu<GADU-G~1>
2007-08-15 22:19:00 28460032 --a------ C:\Documents and Settings\SZEWCO\Dane aplikacji\Outlook.pst
2007-08-15 22:19:00 271360 --a------ C:\Documents and Settings\SZEWCO\Dane aplikacji\archive.pst
2007-08-08 21:56:38 132075 --a------ C:\WINDOWS\system32\dnd823b8e7.dat<DND823~1.DAT>
2007-08-08 21:28:48 79761 --a------ C:\Documents and Settings\SZEWCO\Dane aplikacji\tmp6.tmp.exe<TMP6TM~1.EXE>
2007-08-08 21:28:21 131426 --a------ C:\WINDOWS\cbxutt.dll
2007-08-08 21:28:21 124693 --a------ C:\Documents and Settings\SZEWCO\Dane aplikacji\tmp1.tmp.exe<TMP1TM~1.EXE>
2007-08-08 20:46:07 131426 --a------ C:\WINDOWS\ddbcbc.dll
2007-08-07 14:57:30 0 d-------- C:\Program Files\Minefield<MINEFI~1>
2007-08-05 23:35:16 13380 --a------ C:\WINDOWS\system32\ssttqol.dll
2007-08-05 21:04:36 13380 --a------ C:\WINDOWS\system32\gebcdbx.dll
2007-08-05 18:35:20 13380 --a------ C:\WINDOWS\system32\ddccbcd.dll
2007-08-05 16:05:40 13380 --a------ C:\WINDOWS\system32\pmnllmn.dll
2007-08-05 13:24:41 25664 --a------ C:\WINDOWS\system32\0MT8d8jA.exe
2007-07-20 23:28:43 0 d-------- C:\Program Files\Metrum Demo<METRUM~1>
2007-07-19 11:49:35 10 --ah----- C:\WINDOWS\popcinfo.dat
2007-06-26 08:38:36 48776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-06-20 20:46:04 266088 --a------ C:\WINDOWS\system32\xactengine2_8.dll<XA3866~1.DLL>
2007-06-20 20:45:20 18280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll<X3DAUD~3.DLL>
-- Registry Dump ---------------------------------------------------------------
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvMediaCenter"="RunDLL32.exe NvMCTray.dll,NvTaskbarInit"
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"LanguageShortcut"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
"item"="TeaTimer"
"hkey"="HKCU"
"command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
"inimapping"="0"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"5T19I3B27A"="C:\\WINDOWS\\csrs.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{00d18c3a-c931-11db-83b3-0060b342dc4c}]
Shell\AutoRun\command G:\SETUP.EXE
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bbde3380-c97a-11db-83b4-0060b342dc4c}]
Shell\AutoRun\command H:\SETUP.EXE
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bbde3381-c97a-11db-83b4-0060b342dc4c}]
Shell\AutoRun\command I:\PlayD2.EXE
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bbde3382-c97a-11db-83b4-0060b342dc4c}]
Shell\AutoRun\command J:\SETUP.EXE
-- End of ComboScan: finished at 2007-09-12 at 22:37:47 ------------------------
Niestety loga z SR nie moge dac bo mi wyskakuja jakis krzaczki i moge kopiowac tylko do tego miejsca.
>> Z gory dzieki za pomoc <<