Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3900: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3902: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3903: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3904: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
Win32.zafi.b • programosy.pl

  • Ogłoszenie:

Win32.zafi.b

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Win32.zafi.b

Postprzez MetalMan 02 Sty 2009, 11:04

reklama
Witam!
Wczoraj zaczęło mi wyskakiwać takie okienko Image
Wiem że to podpucha,bo gdy kliknę enable protection wywala mnie no stronki z jakimś antyvir'em do kupienia.Podobna strona wyskakuje mi gdy włączę jakąkolwiek przeglądarkę.Avast oczywiście nic nie wykrywa sciana sciana sciana
Zauważyłem że od tego zdarzenia komputer cholernie zwolnił.....
Proszę pilnie o pomoc!

PS:Log z hijackthis:
Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:55:09, on 2009-01-02
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Mouse Driver\KMWDSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
D:\Alcohol 52\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NEOSTR~1\CnxMon.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BenQ\BenQ Tilt-Wheel Mouse\4.0\ACQTMAPP.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\BenQ\BenQ Tilt-Wheel Mouse\4.0\ACQHIDCL.DAT
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Documents and Settings\Adam Rusin\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Vista Inspirat 2\RocketDock\RocketDock.exe
D:\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\NEOSTR~1\NeostradaTP.exe
C:\PROGRA~1\NEOSTR~1\ComComp.exe
C:\PROGRA~1\NEOSTR~1\Watch.exe
D:\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://szukaj.wp.pl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O1 - Hosts: 72.167.163.234 www.google-analytics.com
O1 - Hosts: 72.167.163.234 pagead.googlesyndication.com
O1 - Hosts: 72.167.163.234 pagead2.googlesyndication.com
O1 - Hosts: 72.167.163.234 ads1.msn.com
O1 - Hosts: 38.113.174.32 dehp.myspace.com
O1 - Hosts: 38.113.174.32 demr.myspace.com
O1 - Hosts: 38.113.174.32 desk.myspace.com
O1 - Hosts: 38.113.174.32 delb.myspace.com
O1 - Hosts: 38.113.174.32 delb2.myspace.com
O1 - Hosts: 38.113.174.32 debr.myspace.com
O1 - Hosts: 38.113.174.32 view.atdmt.com
O1 - Hosts: 38.113.170.200 themis.geocities.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: adssite - {1214451e-8bc7-f2b4-960b-44b94fafb5ca} - C:\WINDOWS\system32\nsa86.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {2F2445E7-8ACA-4E40-9351-969F43F1A3CF} - (no file)
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - D:\dfzfdd\sbhelp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: rightonads optimizer - {7D9362F8-77D8-4b29-97B5-621D550890C0} - (no file)
O2 - BHO: ads_optimizer - {9C8A568E-4201-478a-8536-526CF371D2E2} - (no file)
O2 - BHO: (no name) - {ad7a710b-f5af-46f3-abd3-dbcb14f1d61e} - C:\WINDOWS\system32\tokibete.dll
O2 - BHO: (no name) - {C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148} - (no file)
O2 - BHO: MySidesearch Search Assistant - {DDFA1356-E6ED-42a5-9D62-93211D424A90} - (no file)
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ACQTMOUSE] "C:\Program Files\BenQ\BenQ Tilt-Wheel Mouse\4.0\ACQTMAPP.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UVS11 Preload] D:\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Mouse Driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [defusubovo] Rundll32.exe "C:\WINDOWS\system32\radozema.dll",s
O4 - HKLM\..\Run: [defusubovo] Rundll32.exe "C:\WINDOWS\system32\radozema.dll",s
O4 - HKLM\..\Run: [b0c914c2] rundll32.exe "C:\WINDOWS\system32\panosiru.dll",b
O4 - HKLM\..\Run: [CPMb3fa275e] Rundll32.exe "c:\windows\system32\suzeyiji.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Adam Rusin\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [TopDesk] D:\TopDesk\topdesk.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Alcohol 52\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\Run: [defusubovo] Rundll32.exe "C:\WINDOWS\system32\radozema.dll",s (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - Startup: RocketDock.lnk = D:\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = D:\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = D:\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: wkcalrem.LNK = D:\Microsoft Works\WkCalRem.exe
O4 - Startup: Y'z Shadow.lnk = D:\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Startup: Yahoo! Widget Engine.lnk = D:\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\dfzfdd\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\dfzfdd\sbhelp.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{41D4C4A1-97FA-4C30-9700-49D601AE4E78}: NameServer = 194.204.159.1 217.98.63.164
O20 - AppInit_DLLs: C:\WINDOWS\system32\yijeziye.dll c:\windows\system32\suzeyiji.dll
O20 - Winlogon Notify: jkkli - C:\WINDOWS\
O20 - Winlogon Notify: urqqqol - urqqqol.dll (file missing)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\suzeyiji.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\suzeyiji.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Mouse Driver\KMWDSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 11348 bytes
MetalMan
~user
 
Posty: 7
Dołączenie: 12 Sie 2008, 19:26



Win32.zafi.b

Postprzez wojtas 02 Sty 2009, 12:20

Wykonaj to co jest podane w tym temacie

Zastosuj SDFix . Po pobraniu uruchom go a rozpakuje się do C:\SDFix. Uruchom komputer w trybie awaryjnym (F8 przy stracie systemu). Będąc w awaryjnym uruchom plik RunThis.bat z folderu SDFixa. Zatwierdź czyszczenie przez Y. Poczekaj aż ukończy i komputer zresetuje

Potem wejdz do folderu C:\SDFix wrzuc zawartość pliku Report.txt + log z combofixa oraz daj loga z hijacka
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Re: win32.zafi.b

Postprzez MetalMan 02 Sty 2009, 13:52

Combofix:
Kod: Zaznacz wszystko
ComboFix 09-01-01.01 - Adam Rusin 2009-01-02 12:23:46.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1250.1.1045.18.447.54 [GMT 1:00]
Running from: c:\documents and settings\Adam Rusin\Pulpit\ComboFix.exe
AV: AVG 7.5.519 *On-access scanning disabled* (Outdated)
AV: avast! antivirus 4.8.1201 [VPS 080721-0] *On-access scanning disabled* (Outdated)
* Created a new restore point

[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
[color=purple]The following files were disabled during the run:[/color]
c:\windows\system32\yijeziye.dll
c:\windows\system32\podidede.dll


((((   Other Deletions   ))))))))))
.

c:\documents and settings\Adam Rusin\Dane aplikacji\EurekaLog
c:\documents and settings\Adam Rusin\Dane aplikacji\urlredir.cfg
c:\documents and settings\WLASCICIEL\Dane aplikacji\Google\mjkovl.dll
c:\documents and settings\WLASCICIEL\Dane aplikacji\Google\pzpsp23511834.exe
c:\documents and settings\WLASCICIEL\Dane aplikacji\urlredir.cfg
c:\program files\Mozilla Firefox\components\nsBrowserOpt.dll
c:\program files\myglobalsearch
c:\program files\myglobalsearch\bar\History\search
c:\windows\BMb3fa275e.txt
c:\windows\BMb3fa275e.xml
c:\windows\cookies.ini
c:\windows\pi.exe
c:\windows\system32\ilkkj.bak1
c:\windows\system32\ilkkj.bak2
c:\windows\system32\ilkkj.ini
c:\windows\system32\ilkkj.ini2
c:\windows\system32\ilkkj.tmp
c:\windows\system32\jakiyohe.dll
c:\windows\system32\livifeju.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\panosiru.dll
c:\windows\system32\podidede.dll.vir
c:\windows\system32\pukugusa.dll
c:\windows\system32\radozema.dll
c:\windows\system32\suzeyiji.dll
c:\windows\system32\tokibete.dll
c:\windows\system32\yijeziye.dll.vir

.
(((((((   Drivers/Services   ))))))))))
.

-------\Legacy_ISODRIVE
-------\Service_ISODrive


((((((   Files Created from 2008-12-02 to 2009-01-02  )))))
.

2009-01-02 11:50 . 2009-01-02 11:51   <DIR>   d--------   c:\windows\ERUNT
2009-01-02 11:43 . 2009-01-02 12:12   <DIR>   d--------   C:\SDFix
2009-01-02 10:29 . 2009-01-01 22:33   1,266,209   --ahs----   c:\windows\system32\asugukup.ini
2009-01-01 22:30 . 2009-01-01 22:33   1,266,209   --ahs----   c:\windows\system32\urisonap.ini
2009-01-01 15:18 . 2009-01-01 15:18   <DIR>   d--------   c:\program files\Common Files\ParallelGraphics
2009-01-01 10:29 . 2009-01-01 10:30   1,266,209   --ahs----   c:\windows\system32\ujefivil.ini
2008-12-31 01:14 . 2008-12-31 01:14   <DIR>   d--------   c:\documents and settings\WLASCICIEL\Dane aplikacji\Apple Computer
2008-12-30 13:13 . 2008-12-30 13:13   686,592   --a------   c:\windows\system32\nsa86.dll
2008-12-29 15:53 . 2008-12-29 15:53   <DIR>   d--------   c:\program files\Audio Phonics, Inc
2008-12-24 09:13 . 2008-12-24 09:13   <DIR>   d--------   c:\program files\Common Files\EZB Systems
2008-12-11 21:37 . 2008-12-11 21:37   42,320   --a------   c:\windows\system32\xfcodec.dll
2008-12-11 16:52 . 2008-12-11 16:52   <DIR>   d--------   c:\program files\Cistone Media Burner
2008-12-08 00:20 . 2008-12-08 00:20   552   --a------   c:\windows\system32\d3d8caps.dat
2008-12-05 21:39 . 2008-10-20 14:44   237,056   --a------   c:\windows\system32\mwgfx24.dll
2008-12-05 21:39 . 2008-09-29 10:03   188,928   --a------   c:\windows\system32\mwgfx.dll
2008-12-05 21:39 . 2008-09-05 09:32   104,960   --a------   c:\windows\system32\mwdds.dll
2008-12-05 21:39 . 2004-05-14 12:13   56,832   --a------   c:\windows\system32\mwace.dll
2008-12-05 21:39 . 2007-08-19 10:37   28,672   --a------   c:\windows\system32\mwgfxcopy.exe

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 11:20   ---------   d-----w   c:\program files\Neostrada TP
2009-01-01 21:48   ---------   d-----w   c:\documents and settings\Adam Rusin\Dane aplikacji\Xfire
2009-01-01 17:44   ---------   d-----w   c:\documents and settings\Adam Rusin\Dane aplikacji\Hamachi
2008-12-31 17:00   ---------   d-----w   c:\program files\Norton Security Scan
2008-12-29 15:09   674,821   ----a-w   c:\windows\Fonts\unins000.exe
2008-12-27 11:28   ---------   d--h--w   c:\program files\InstallShield Installation Information
2008-12-24 08:06   ---------   d-----w   c:\documents and settings\Adam Rusin\Dane aplikacji\BitTorrent
2008-12-22 08:45   ---------   d---a-w   c:\documents and settings\All Users\Dane aplikacji\TEMP
2008-12-06 14:58   1,130   ----a-w   c:\documents and settings\Adam Rusin\Dane aplikacji\wklnhst.dat
2008-12-03 16:35   ---------   d-----w   c:\program files\SystemRequirementsLab
2008-12-03 15:38   ---------   d-----w   c:\documents and settings\Adam Rusin\Dane aplikacji\Skype
2008-12-01 18:35   ---------   d-----w   c:\documents and settings\Adam Rusin\Dane aplikacji\OtakuSoftware
2008-11-20 19:36   ---------   d-----w   c:\documents and settings\Adam Rusin\Dane aplikacji\LEGO Company
2008-11-08 09:44   ---------   d-----w   c:\documents and settings\Adam Rusin\Dane aplikacji\Thinstall
2007-08-04 12:21   22,880   -c--a-w   c:\documents and settings\WLASCICIEL\Dane aplikacji\GDIPFONTCACHEV1.DAT
2006-04-25 18:39   24,192   -c--a-w   c:\documents and settings\WLASCICIEL\usbsermptxp.sys
2006-04-25 18:39   22,768   -c--a-w   c:\documents and settings\WLASCICIEL\usbsermpt.sys
2004-09-28 02:00   26,240   ----a-w   c:\windows\inf\RAMDSK.SYS
2008-12-19 05:33   67,688   ----a-w   c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 05:33   54,368   ----a-w   c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 05:33   34,944   ----a-w   c:\program files\mozilla firefox\components\myspell.dll
2008-12-30 12:13   655,872   ----a-w   c:\program files\mozilla firefox\components\nsadssite.dll
2008-09-04 12:15   343,552   ----a-w   c:\program files\mozilla firefox\components\nsbads.dll
2008-01-18 10:06   278,528   ----a-w   c:\program files\mozilla firefox\components\nsBrowserCmp.dll
2008-12-19 05:33   46,712   ----a-w   c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 05:33   172,136   ----a-w   c:\program files\mozilla firefox\components\xpinstal.dll
2006-05-03 10:06   163,328   --sha-r   c:\windows\system32\flvDX.dll
2008-08-18 16:35   13   --sha-r   c:\windows\system32\IEcacher.dll
2007-02-21 11:47   31,232   --sha-r   c:\windows\system32\msfDX.dll
2007-12-17 13:43   27,648   --sha-w   c:\windows\system32\Smab0.dll
.

------- Sigcheck -------

2005-10-21 04:39  664064  720005547ae4e3002ca171b50141f0ed   c:\windows\$hf_mig$\KB905915\SP2QFE\wininet.dll
2008-02-16 10:32  668672  193f94d811881d00867aeb1d6780f44f   c:\windows\$hf_mig$\KB947864\SP2QFE\wininet.dll
2004-08-03 23:44  658944  d37dafb534ac8343d59a1b501abe852c   c:\windows\$NtUninstallKB905915$\wininet.dll
2005-10-21 04:42  660992  406f49324af7b16c9f896e36851be621   c:\windows\$NtUninstallKB947864$\wininet.dll
2008-02-16 10:05  696320  61083f5c46bd024c02ba7f607cd1cc6c   c:\windows\system32\wininet.dll
2008-02-16 10:05  696320  61083f5c46bd024c02ba7f607cd1cc6c   c:\windows\system32\dllcache\wininet.dll

2004-08-03 23:44  975872  196c130d31317fe53de984220b5e13b9   c:\windows\explorer.exe
2007-06-13 14:23  1034752  029a562e81bbee088c61d418bf408f44   c:\windows\SoftwareDistribution\Download\8d454b309577cd5649a81b0f39c2c9c7\sp2gdr\explorer.exe
2007-06-13 14:12  1034752  8db0650b211425b9cdb7d1c4a8f6b482   c:\windows\SoftwareDistribution\Download\8d454b309577cd5649a81b0f39c2c9c7\sp2qfe\explorer.exe
2004-08-03 23:44  975872  196c130d31317fe53de984220b5e13b9   c:\windows\system32\dllcache\explorer.exe

2007-07-30 18:19  68440  84d9a61860272d6177d46c86b8431557   c:\windows\system32\wuauclt.exe
2007-07-30 18:19  68440  84d9a61860272d6177d46c86b8431557   c:\windows\system32\dllcache\wuauclt.exe
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Google Update"="c:\documents and settings\Adam Rusin\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
"TopDesk"="d:\topdesk\topdesk.exe" [2007-06-20 2167296]
"AlcoholAutomount"="d:\alcohol 52\axcmd.exe" [2007-07-02 219008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WooCnxMon"="c:\progra~1\NEOSTR~1\CnxMon.exe" [2003-10-16 24576]
"WOOWATCH"="c:\progra~1\NEOSTR~1\Watch.exe" [2003-10-16 20480]
"WOOTASKBARICON"="c:\progra~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 53248]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"ACQTMOUSE"="c:\program files\BenQ\BenQ Tilt-Wheel Mouse\4.0\ACQTMAPP.exe" [2007-07-08 501760]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 79224]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-22 180269]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"UVS11 Preload"="d:\ulead systems\Ulead VideoStudio 11\uvPL.exe" [2007-09-12 340136]
"KMCONFIG"="c:\program files\Mouse Driver\StartAutorun.exe" [2007-03-06 212992]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2008-10-01 289576]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]

c:\documents and settings\Adam Rusin\Menu Start\Programy\Autostart\
RocketDock.lnk - d:\vista inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
TransBar.lnk - d:\vista inspirat 2\TransBar\TransBar.exe [2005-06-01 65536]
UberIcon.lnk - d:\vista inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 180224]
wkcalrem.LNK - d:\microsoft works\WkCalRem.exe [2007-06-20 46432]
Y'z Shadow.lnk - d:\vista inspirat 2\YzShadow\YzShadow.exe [2006-05-21 155648]
Yahoo! Widget Engine.lnk - d:\widgets\YahooWidgetEngine.exe [2007-03-22 2958896]

c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-09-19 113664]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-02-05 962661]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 1 (0x1)
"SynchronousUserGroupPolicy"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoWelcomeScreen"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"vidc.i263"= i263_32.drv
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"vidc.div2"= divxc32.dll
"vidc.div3"= divxc32.dll
"vidc.div4"= divxc32f.dll
"vidc.mjpg"= pvmjpg21.dll
"vidc.rt21"= IR21_R.DLL
"vidc.ir21"= IR21_R.DLL
"msacm.wrpr"= aviwrap.dll
"vidc.wrpr"= aviwrap.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AQQ]
--a------ 2008-12-29 11:39 1659392 d:\aqq\WAPSTE~1\AQQ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2008-02-26 02:23 443968 c:\program files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\PROGRAMY\\BearShare\\BearShare.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Wierszownik\\data\\bin\\mysqld-nt.exe"=
"d:\\PROGRAMY\\Phone\\Skype.exe"=
"d:\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Tlen.pl\\tlen.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\ijji\\ENGLISH\\u_skid.exe"=
"d:\\PROGRAMY\\Opera\\Opera.exe"=
"d:\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\BitTorrent_DNA\\dna.exe"=
"d:\\uTorrent\\utorrent.exe"=
"d:\\AQQ\\AQQ.exe"=
"c:\\Program Files\\backburner 2\\monitor.exe"=
"c:\\Program Files\\backburner 2\\manager.exe"=
"c:\\Program Files\\backburner 2\\server.exe"=
"d:\\Xfire\\xfire.exe"=
"d:\\konnekcior\\konnekt.exe"=
"d:\\Teamspeak2_RC2 server\\server_windows.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\AQQ\\WapSter AQQ\\AQQ.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"d:\\Nowe Gadu-Gadu\\gg.exe"=
"d:\\AQQ\\WapSter AQQ\\AQQ\\AQQ.exe"=
"d:\\AQQ\\WAPSTE~1\\AQQ.exe"=
"d:\\Snikers\\Snikers.exe"=
"d:\\LFS Z\\LfsRevLimiter.0.9.exe"=
"d:\\LFS Z\\LFS.exe"=
"d:\\totalcmd\\TOTALCMD.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Itunes\\iTunes.exe"=
"d:\\YSFLIGHT\\fsmaino.exe"=
"d:\\YSFLIGHT1\\fsmainsvr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"d:\\Counter-Strike\\hlds.exe"=
"d:\\Counter-Strike\\hl.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8461:TCP"= 8461:TCP:GoD High Port
"8462:TCP"= 8462:TCP:GoD Low Port

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-13 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-13 20560]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Mouse Driver\KMWDSrv.exe [2007-04-05 208896]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\Drivers\e4ldr.sys []
S3 ACRUSBTM;ACRUSBTM;\??\c:\windows\system32\drivers\ACRUSBTM.SYS [2008-04-08 28672]
S3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\DRIVERS\e4usbaw.sys []
S3 SER120;OTI Serial port driver;c:\windows\system32\DRIVERS\SER120.sys [2006-05-01 32910]
S3 usb2vcom;USB to Serial Bridge Controller;c:\windows\system32\Drivers\usb2vcom.sys [2005-01-05 22760]
S3 V0010bVd;Creative WebCam Vista #2;c:\windows\system32\DRIVERS\V0010bVd.sys [2007-07-08 186551]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd898ce4-94e8-11dc-b553-4d6564696130}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
.
Contents of the 'Scheduled Tasks' folder

2009-01-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2993753242-1505528993-422160106-1007.job
- c:\documents and settings\Adam Rusin\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2008-09-03 15:57]

2008-12-31 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2008-01-09 04:08]
.
- - - - ORPHANS REMOVED - - - -

BHO-{2F2445E7-8ACA-4E40-9351-969F43F1A3CF} - (no file)
BHO-{ad7a710b-f5af-46f3-abd3-dbcb14f1d61e} - c:\windows\system32\tokibete.dll
HKLM-Run-winssvc - c:\documents and settings\WLASCICIEL\Dane aplikacji\Google\pzpsp23511834.exe
HKLM-Run-CPMb3fa275e - c:\windows\system32\podidede.dll
Notify-jkkli - (no file)
Notify-urqqqol - urqqqol.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.neostrada.pl
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Winamp Search - c:\documents and settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: { - c:\program files\Messenger\msmsgs.exe
FF - ProfilePath - c:\documents and settings\Adam Rusin\Dane aplikacji\Mozilla\Firefox\Profiles\hftfhlf4.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (pl)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/webhp?rls=ig
FF - component: d:\mozilla firefox\components\nsadssite.dll
FF - component: d:\mozilla firefox\components\nsbads.dll
FF - plugin: c:\documents and settings\Adam Rusin\Ustawienia lokalne\Dane aplikacji\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Common Files\ParallelGraphics\Cortona\npCortona.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\real player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\real player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\real player\Netscape6\nprpjplug.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\mozilla firefox\plugins\npqtplugin8.dll
FF - plugin: d:\mozilla firefox\plugins\npyaxmpb.dll
FF - plugin: d:\op\program\plugins\npdsplay.dll
FF - plugin: d:\op\program\plugins\npwmsdrm.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-02 12:32:23
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\Network1-2993753242-1505528993-422160106-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2901510C-068C-B9B0-4B1D-1CBAD1DF16E6}*NULL*]
"naefgfjldnamlmhkdcmfhpcgdegf"=hex:69,61,63,63,67,6a,66,6b,68,6f,6e,6b,70,67,\
  61,66,67,68,00,00
"oaoehfdffiahefldheplhlpgoomlme"=hex:6a,61,63,63,67,6a,66,6b,64,6f,66,63,70,68,\
  6e,6a,6b,6d,65,70,00,09

[HKEY_USERS\Network1-2993753242-1505528993-422160106-1007\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*NULL*]
"??"=hex:fc,6f,7e,ed,fb,13,17,78,10,b3,bb,25,db,76,bb,78,a4,46,49,21,bd,e2,ec,\
  2b,00,36,e7,dc,fa,ae,06,31,e2,fd,4c,fd,49,b2,97,f6,d9,87,17,16,28,11,b3,52,\
  26,10,33,84,38,24,10,50,ac,cb,97,b6,fe,c4,f8,35,24,38,87,38,d2,1b,50,2b,33,\
  e3,e4,bd,c5,ed,fa,15,e7,94,4d,19,6b,24,7f,5b,51,ec,6d,03,d4,ba,3d,8b,9c,fe,\
  39,f7,8c,13,24,0b,9f,97,07,08,fe,34,5f,e6,b1,38,29,01,36,9c,7c,ed,83,7e,35,\
  b1,a2,36,c0,f4,bd,6c,29,a1,1c,3e,60,74,d2,13,51,52,3b,d6,9f,a0,c4,27,59,74,\
  7f,92,d5,30,45,36,d2,f1,25,d0,50,a5,d3,c3,62,e7,8c,57,31,eb,f9,3c,62,c2,4e,\
  9b,8b,1a,1e,58,6e,9a,e6,d0,9c,28,e7,ba,fb,b9,98,d6,46,bd,a1,7a,ac,ef,7d,c2,\
  40,0f,4d,f5,80,11,d6,a6,97,52,aa,b6,2c,2a,d5,f6,a5,d7,12,b8,88,ec,fc,ea,1a,\
  55,17,10,12,40,ba,40,8a,71,d5,25,df,65,a1,40,89,e3,63,f8,00,44,ca,29,4f,65,\
  77,30,ab,5d,68,c6,06,0d,b7,8e,d9,2e,98,83,bf,4c,fe,05,78,0c,b0,dc,31,2c,6e,\
  24,58,85,57,12,4e,02,3b,dd,5c,d2,98,5e,31,3a,fa,c8,6a,d9,01,2b,53,99,25,42,\
  a9,0b,85,b3,11,96,99,1e,98,5f,38,4f,53,41,ad,fb,20,a2,a3,70,e6,9e,98,d5,c4,\
  6c,95,82,26,93,c0,c9,f0,ee,eb,cd,0b,28,7d,39,bf,08,a7,8f,ab,a0,47,6e,90,9e,\
  1f,32,64,ad,6e,e7,cd,f5,bf,e7,67,b3,f2,89,10,20,a3,20,62,8b,2e,d8,ee,f0,bf,\
  5a,c2,45,0f,b8,c3,a1,26,04,b7,6a,2c,be,6f,b0,0b,41,e5,c5,1d,bb,33,3e,14,6b,\
  6c,7a,82,05,78,85,64,6f,00,c5,6c,2f,3d,a5,71,54,d1,00,82,fd,c6,5f,3a,98,d5,\
  f6,6b,ef,87,f8,e7,5d,3d,b5,ac,15,71,ef,dd,a8,f4,cf,f2,f6,ac,cc,c4,b0,c7,0c,\
  60,e0,1a,e8,3a,f3,b7,53,42,9a,1f,b2,bd,00,61,a3,e1,9f,3c,7a,77,3f,31,20,86,\
  8f,37,93,d9,67,f8,70,da,d4,d4,23,f1,ea,95,bf,48,32,ec,e1,25,6e,71,7a,5a,ed,\
  6f,7b,fb,8b,32,d0,b8,24,64,e9,20,c0,74,8f,33,d8,e0,77,c6,5d,3c,90,12,e7,86,\
  70,f6,62,ca,e8,89,a7,03,40,44,ae,6b,d4,8c,5a,78,7a,78,74,8b,f4,f8,24,b6,f9,\
  8a,4d,57,67,b8,f1,98,09,64,cf,67,90,44,81,9c,b3,89,44,35,80,de,25,53,2a,01,\
  43,b7,88,80,48,bd,7c,bd,a5,85,5e,55,1f,2e,de,a9,4f,84,8a,a4,63,42,4c,d3,da,\
  ba,71,a6,60,ff,5d,7a,3c,c9,df,fe,b6,db,3c,8c,de,55,3d,e7,a8,50,95,6e,70,0f,\
  f4,37,57,f4,c6,50,bb,fd,65,c1,74,d0,1f,a8,a9,2e,1f,13,a5,86,3c,e3,6e,26,5b,\
  31,1c,4b,1a,8c,4e,e9,c4,6b,9e,d5,30,4f,b1,37,ad,49,3a,a2,9b,9e,02,66,fd,fc,\
  95,80,7f,0e,12,b1,9f,4b,9b,e2,55,5b,a4,79,e8,f0,29,66,5f,d5,82,fb,b1,41,0c,\
  ac,6f,36,84,20,1a,31,97,ec,36,2d,08,8b,af,94,41,8f,af,d7,0b,c8,4a,6a,6c,84,\
  45,81,f9,b9,06,68,68,17,74,8a,74,3e,7f,43,b5,86,c4,5e,38,ff,ea,02,27,fe,66,\
  a8,e0,3c,86,18,25,ab,57,0f,53,90,1a,ee,68,b7,59,4e,cd,01,38,3c,ad,0f,60,4f,\
  55,ae,39,a9,8c,3d,02,c6,df,c7,94,c5,8b,74,fe,67,74,71,22,27,e7,05,a1,b3,4c,\
  9c,55,70,06,31,80,8f,db,b6,80,78,a3,8b,98,4f,a0,31,5c,00,ea,99,29,71,06,e8,\
  12,2f,08,c7,9e,9e,51,12,dc,8b,71,61,68,5f,16,c5,95,29,43,be,48,22,11,cb,d1,\
  01,32,78,10,65,44,80,e2,ed,48,e5,1c,9e,da,9d,42,bf,dc,8d,cc,34,67,99,b5,20,\
  7d,d8,fc,7c
"??"=hex:59,e5,97,70,47,08,a5,1e,f6,13,83,cc,52,0d,a6,6c
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\drivers\CDANTSRV.EXE
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
d:\alcohol 52\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\program files\BenQ\BenQ Tilt-Wheel Mouse\4.0\ACQHIDCL.DAT
c:\program files\Mouse Driver\KMCONFIG.exe
c:\program files\Mouse Driver\KMProcess.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\progra~1\NEOSTR~1\NeostradaTP.exe
c:\progra~1\NEOSTR~1\ComComp.exe
.
**************************************************************************
.
Completion time: 2009-01-02 12:43:57 - machine was rebooted
ComboFix-quarantined-files.txt  2009-01-02 11:43:32

Pre-Run: 1˙137˙549˙312 bajt˘w wolnych
Post-Run: 1,593,286,656 bajt˘w wolnych

400   --- E O F ---   2008-05-10 07:13:13


Sdfix:
Kod: Zaznacz wszystko
[b]SDFix: Version 1.240 [/b]
Run by Adam Rusin on 2009-01-02 at 11:57

Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


[b]Checking Files [/b]:

Trojan Files Found:

C:\WINDOWS\system32\nsa86.dll    - Deleted
C:\WINDOWS\pskt.ini - Deleted
C:\WINDOWS\system32\adssite-remove.exe - Deleted
C:\WINDOWS\system32\drivers\svchost.exe - Deleted
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe - Deleted
C:\WINDOWS\system32\rightonadz-uninst.exe - Deleted





Removing Temp Files

[b]ADS Check [/b]:



                                 [b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-02 12:07:05
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="D:\Alcohol 52\"
"h0"=dword:00000001
"ujdew"=hex:b6,78,ac,df,1b,f9,b1,cd,31,43,89,e8,3a,16,54,b5,2a,f0,1c,49,b6,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="D:\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:19,3b,6a,07,45,1a,50,53,d3,c3,41,0f,84,af,b5,b0,58,49,c7,ce,7a,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,52,9e,85,f2,6b,56,d6,21,e6,a4,b0,96,92,2f,0f,b0,e4,..
"khjeh"=hex:ad,c0,54,b7,61,24,d0,69,0c,56,71,41,c3,1d,0e,0d,90,d0,a1,5a,3b,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:b2,65,c1,24,1f,90,c4,5e,29,0d,3c,be,83,d5,c1,a6,51,83,99,d8,7c,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:45,13,58,9d,f8,c7,88,6c,23,04,86,58,53,6d,a2,cb,a0,d0,d2,11,ac,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:4a,e4,f3,d5,89,c9,16,05,8a,1b,9f,df,96,0c,fa,4e,12,e0,44,cd,b4,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:4a,e4,f3,d5,89,c9,16,05,8a,1b,9f,df,96,0c,fa,4e,12,e0,44,cd,b4,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="D:\Alcohol 52\"
"h0"=dword:00000001
"ujdew"=hex:b6,78,ac,df,1b,f9,b1,cd,31,43,89,e8,3a,16,54,b5,2a,f0,1c,49,b6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="D:\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:19,3b,6a,07,45,1a,50,53,d3,c3,41,0f,84,af,b5,b0,58,49,c7,ce,7a,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,52,9e,85,f2,6b,56,d6,21,e6,a4,b0,96,92,2f,0f,b0,e4,..
"khjeh"=hex:ad,c0,54,b7,61,24,d0,69,0c,56,71,41,c3,1d,0e,0d,90,d0,a1,5a,3b,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:b2,65,c1,24,1f,90,c4,5e,29,0d,3c,be,83,d5,c1,a6,51,83,99,d8,7c,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:45,13,58,9d,f8,c7,88,6c,23,04,86,58,53,6d,a2,cb,a0,d0,d2,11,ac,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:4a,e4,f3,d5,89,c9,16,05,8a,1b,9f,df,96,0c,fa,4e,12,e0,44,cd,b4,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:4a,e4,f3,d5,89,c9,16,05,8a,1b,9f,df,96,0c,fa,4e,12,e0,44,cd,b4,..

scanning hidden registry entries ...

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2901510C-068C-B9B0-4B1D-1CBAD1DF16E6}]
"naefgfjldnamlmhkdcmfhpcgdegf"=hex:69,61,70,62,6c,6a,6d,67,61,6f,6a,6e,6c,69,65,70,66,67,00,00
"oaoehfdffiahefldheplhlpgoomlme"=hex:6a,61,63,63,67,6a,66,6b,64,6f,66,63,70,68,6e,6a,6b,6d,65,70,00,..

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services [/b]:




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"D:\\PROGRAMY\\Gadu-Gadu\\gg.exe"="D:\\PROGRAMY\\Gadu-Gadu\\gg.exe:*:Disabled:Gadu-Gadu - program glowny"
"D:\\PROGRAMY\\BearShare\\BearShare.exe"="D:\\PROGRAMY\\BearShare\\BearShare.exe:*:Disabled:BearShare"
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater"
"D:\\Spik\\Spik.exe"="D:\\Spik\\Spik.exe:*:Enabled:Spik"
"C:\\Documents and Settings\\WLASCICIEL\\Pulpit\\race\\racer\\racer.exe"="C:\\Documents and Settings\\WLASCICIEL\\Pulpit\\race\\racer\\racer.exe:*:Enabled:racer"
"D:\\race\\racer\\racer.exe"="D:\\race\\racer\\racer.exe:*:Enabled:racer"
"D:\\race\\racer\\tracked.exe"="D:\\race\\racer\\tracked.exe:*:Enabled:tracked"
"E:\\racer\\racer.exe"="E:\\racer\\racer.exe:*:Enabled:racer"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\Program Files\\BearShare\\BearShare.exe"="C:\\Program Files\\BearShare\\BearShare.exe:*:Disabled:BearShare"
"D:\\GRY\\NFSU\\Speed.exe"="D:\\GRY\\NFSU\\Speed.exe:*:Enabled:Speed"
"D:\\ADAm\\race\\racer\\racer.exe"="D:\\ADAm\\race\\racer\\racer.exe:*:Enabled:racer"
"C:\\Program Files\\Wierszownik\\data\\bin\\mysqld-nt.exe"="C:\\Program Files\\Wierszownik\\data\\bin\\mysqld-nt.exe:*:Disabled:mysqld-nt"
"D:\\GRY\\play\\c4.exe"="D:\\GRY\\play\\c4.exe:*:Enabled:c4"
"D:\\ADAm\\race\\racer\\tracked.exe"="D:\\ADAm\\race\\racer\\tracked.exe:*:Enabled:tracked"
"C:\\Program Files\\VoipStunt.com\\VoipStunt\\VoipStunt.exe"="C:\\Program Files\\VoipStunt.com\\VoipStunt\\VoipStunt.exe:*:Enabled:VoipStunt"
"D:\\GRY\\YSFLIGHT\\YSFLIGHT\\fsmaino.exe"="D:\\GRY\\YSFLIGHT\\YSFLIGHT\\fsmaino.exe:*:Enabled:fsmaino"
"D:\\PROGRAMY\\eMule\\emule.exe"="D:\\PROGRAMY\\eMule\\emule.exe:*:Enabled:eMule"
"D:\\GRY\\FlightGear\\bin\\win32\\fgfs.exe"="D:\\GRY\\FlightGear\\bin\\win32\\fgfs.exe:*:Enabled:fgfs"
"D:\\GRY\\FlightGear\\FlightGear\\bin\\win32\\fgfs.exe"="D:\\GRY\\FlightGear\\FlightGear\\bin\\win32\\fgfs.exe:*:Enabled:fgfs"
"D:\\GRY\\twierdza\\Stronghold Crusader.exe"="D:\\GRY\\twierdza\\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader"
"D:\\GRY\\NFSU2\\speed2.exe"="D:\\GRY\\NFSU2\\speed2.exe:*:Enabled:speed2"
"D:\\GRY\\piˆka\\AnstossAction.exe"="D:\\GRY\\piˆka\\AnstossAction.exe:*:Enabled:ANSTOSS action"
"D:\\GRY\\Comanche 4\\c4.exe"="D:\\GRY\\Comanche 4\\c4.exe:*:Enabled:c4"
"D:\\PROGRAMY\\Phone\\Skype.exe"="D:\\PROGRAMY\\Phone\\Skype.exe:*:Enabled:Skype"
"D:\\ADAm\\FlightGear\\bin\\win32\\fgfs.exe"="D:\\ADAm\\FlightGear\\bin\\win32\\fgfs.exe:*:Enabled:fgfs"
"D:\\GRY\\Airfix\\Dogfighter.exe"="D:\\GRY\\Airfix\\Dogfighter.exe:*:Enabled:Dogfighter"
"D:\\Alacer\\alacer.exe"="D:\\Alacer\\alacer.exe:*:Enabled:Alacer"
"D:\\GRY\\Microsoft Flight Simulator 2002\\fs2002.exe"="D:\\GRY\\Microsoft Flight Simulator 2002\\fs2002.exe:*:Enabled:Microsoft Flight Simulator Module"
"D:\\GRY\\GAME SPY ACADRE\\Aphex.exe"="D:\\GRY\\GAME SPY ACADRE\\Aphex.exe:*:Enabled:GameSpy Arcade"
"D:\\GRY\\Serious Sam Drugie Starcie\\Bin\\DedicatedServer.exe"="D:\\GRY\\Serious Sam Drugie Starcie\\Bin\\DedicatedServer.exe:*:Enabled:DedicatedServer"
"D:\\GRY\\Serious Sam Drugie Starcie\\Bin\\SeriousSam.exe"="D:\\GRY\\Serious Sam Drugie Starcie\\Bin\\SeriousSam.exe:*:Disabled:SeriousSam"
"D:\\GRY\\Colin McRae Rally 04\\cmr4.exe"="D:\\GRY\\Colin McRae Rally 04\\cmr4.exe:*:Enabled:Colin McRae Rally 04 Application"
"D:\\Gadu-Gadu\\gg.exe"="D:\\Gadu-Gadu\\gg.exe:*:Enabled:Gadu-Gadu - program gˆ˘wny"
"D:\\GRY\\empire earth\\Empire Earth.exe"="D:\\GRY\\empire earth\\Empire Earth.exe:*:Enabled:Empire Earth"
"D:\\GRY\\GTR2\\GTR2Dedicated.exe"="D:\\GRY\\GTR2\\GTR2Dedicated.exe:*:Enabled:GTR2 - FIA GT Racing Game"
"D:\\GRY\\GTR2\\GTR2.exe"="D:\\GRY\\GTR2\\GTR2.exe:*:Enabled:GTR2 - FIA GT Racing Game"
"C:\\Program Files\\Tlen.pl\\tlen.exe"="C:\\Program Files\\Tlen.pl\\tlen.exe:*:Enabled:Komunikator Tlen.pl"
"D:\\Microsoft Games\\FS2002\\fs2002.exe"="D:\\Microsoft Games\\FS2002\\fs2002.exe:*:Enabled:Microsoft Flight Simulator Module"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"D:\\GRY\\Combat Wings - Bitwa o Angli©\\game.exe"="D:\\GRY\\Combat Wings - Bitwa o Angli©\\game.exe:*:Enabled:game"
"D:\\GRY\\Juiced\\Juiced.exe"="D:\\GRY\\Juiced\\Juiced.exe:*:Enabled:Juiced"
"D:\\GRY\\ProjectTorque\\ProjectTorque.bin"="D:\\GRY\\ProjectTorque\\ProjectTorque.bin:*:Enabled:LevelR"
"C:\\ijji\\ENGLISH\\u_skid.exe"="C:\\ijji\\ENGLISH\\u_skid.exe:*:Enabled:<ijji Downloader>"
"D:\\NFS hot Pursuit 2\\NfsHP2.ori"="D:\\NFS hot Pursuit 2\\NfsHP2.ori:*:Enabled:NfsHP2"
"D:\\PROGRAMY\\Opera\\Opera.exe"="D:\\PROGRAMY\\Opera\\Opera.exe:*:Enabled:Opera Internet Browser"
"D:\\Hamachi\\hamachi.exe"="D:\\Hamachi\\hamachi.exe:*:Enabled:Hamachi Client"
"D:\\konnekt\\konnekt.exe"="D:\\konnekt\\konnekt.exe:*:Enabled:Konnekt - Core"
"D:\\Live for speed\\LFS.exe"="D:\\Live for speed\\LFS.exe:*:Enabled:LFS"
"C:\\Program Files\\BitTorrent_DNA\\dna.exe"="C:\\Program Files\\BitTorrent_DNA\\dna.exe:*:Enabled:BitTorrent DNA"
"D:\\BitTorrent\\bittorrent.exe"="D:\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"D:\\uTorrent\\utorrent.exe"="D:\\uTorrent\\utorrent.exe:*:Enabled:uTorrent"
"D:\\AQQ\\AQQ.exe"="D:\\AQQ\\AQQ.exe:*:Enabled:P2P AQQ"
"D:\\3dsmax7\\3dsmax.exe"="D:\\3dsmax7\\3dsmax.exe:*:Enabled:3ds max 7"
"C:\\Program Files\\backburner 2\\monitor.exe"="C:\\Program Files\\backburner 2\\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\\Program Files\\backburner 2\\manager.exe"="C:\\Program Files\\backburner 2\\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\\Program Files\\backburner 2\\server.exe"="C:\\Program Files\\backburner 2\\server.exe:*:Enabled:backburner 2.3 server"
"D:\\Counter-Strike 1.6\\hl.exe"="D:\\Counter-Strike 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\sciagniete\\Counter-Strike_Source_FINAL_READ_NFO-EMPORiO\\emp-css\\srcds.exe"="D:\\sciagniete\\Counter-Strike_Source_FINAL_READ_NFO-EMPORiO\\emp-css\\srcds.exe:*:Enabled:srcds"
"D:\\MTADM\\server\\MTA Server.exe"="D:\\MTADM\\server\\MTA Server.exe:*:Enabled:MTA Server"
"D:\\racer\\racer.exe"="D:\\racer\\racer.exe:*:Enabled:racer"
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"D:\\Pliki do SA I INNE\\LFS\\LFS.exe"="D:\\Pliki do SA I INNE\\LFS\\LFS.exe:*:Enabled:LFS"
"D:\\Xfire\\xfire.exe"="D:\\Xfire\\xfire.exe:*:Enabled:Xfire"
"C:\\Documents and Settings\\WLASCICIEL\\Ustawienia lokalne\\Temp\\Rar$EX00.656\\LFStat_v0.3.1.27.exe"="C:\\Documents and Settings\\WLASCICIEL\\Ustawienia lokalne\\Temp\\Rar$EX00.656\\LFStat_v0.3.1.27.exe:*:Enabled:LFStat_v0.3.1.27"
"D:\\Counter strike extreme\\cstrike.exe"="D:\\Counter strike extreme\\cstrike.exe:*:Enabled:XTCS Counter-Strike 1.6 Final Release"
"D:\\Counter strike extreme\\hlds.exe"="D:\\Counter strike extreme\\hlds.exe:*:Enabled:HLDS Launcher"
"D:\\The Stig Rally 04\\cmr4.exe"="D:\\The Stig Rally 04\\cmr4.exe:*:Enabled:Colin McRae Rally 04 Application"
"D:\\rFactor\\rFactor.exe"="D:\\rFactor\\rFactor.exe:*:Enabled:rFactor"
"D:\\LFS X\\LFS.exe"="D:\\LFS X\\LFS.exe:*:Enabled:LFS"
"D:\\konnekcior\\konnekt.exe"="D:\\konnekcior\\konnekt.exe:*:Enabled:Konnekt - Core"
"D:\\Teamspeak2_RC2 server\\server_windows.exe"="D:\\Teamspeak2_RC2 server\\server_windows.exe:*:Enabled:Server"
"D:\\CS 1.6\\hl.exe"="D:\\CS 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\CS 1.6\\hlds.exe"="D:\\CS 1.6\\hlds.exe:*:Enabled:HLDS Launcher"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"D:\\racer\\tracked.exe"="D:\\racer\\tracked.exe:*:Enabled:tracked"
"D:\\TmNationsForever\\TmForever.exe"="D:\\TmNationsForever\\TmForever.exe:*:Enabled:TmForever"
"D:\\Counter Strike 1.6\\hl.exe"="D:\\Counter Strike 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\BMW M3 Challenge\\BMW.exe"="D:\\BMW M3 Challenge\\BMW.exe:*:Enabled:BMW M3 Challenge"
"D:\\TDU\\TestDriveUnlimited.exe"="D:\\TDU\\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited"
"D:\\Program Files\\GameSpy Arcade\\Aphex.exe"="D:\\Program Files\\GameSpy Arcade\\Aphex.exe:*:Enabled:GameSpy Arcade"
"D:\\AQQ\\WapSter AQQ\\AQQ.exe"="D:\\AQQ\\WapSter AQQ\\AQQ.exe:*:Enabled:AQQ"
"C:\\Program Files\\BitTorrent\\BitTorrent.exe"="C:\\Program Files\\BitTorrent\\BitTorrent.exe:*:Enabled:BitTorrent"
"D:\\CS\\hl.exe"="D:\\CS\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Nowe Gadu-Gadu\\gg.exe"="D:\\Nowe Gadu-Gadu\\gg.exe:*:Enabled:Nowe Gadu-Gadu beta"
"D:\\AQQ\\WapSter AQQ\\AQQ\\AQQ.exe"="D:\\AQQ\\WapSter AQQ\\AQQ\\AQQ.exe:*:Enabled:P2P AQQ"
"D:\\AQQ\\WAPSTE~1\\AQQ.exe"="D:\\AQQ\\WAPSTE~1\\AQQ.exe:*:Enabled:P2P AQQ"
"D:\\Colin McRae Rally 04\\cmr4.exe"="D:\\Colin McRae Rally 04\\cmr4.exe:*:Enabled:Colin McRae Rally 04 Application"
"D:\\IGI2\\pc\\igi2.exe"="D:\\IGI2\\pc\\igi2.exe:*:Enabled:IGI2:Covert Strike"
"D:\\Snikers\\Snikers.exe"="D:\\Snikers\\Snikers.exe:*:Enabled:Snikers"
"D:\\need for speed hot pursuit 2\\NFSHP2.exe"="D:\\need for speed hot pursuit 2\\NFSHP2.exe:*:Enabled:NFSHP2"
"D:\\LFS Z\\LfsRevLimiter.0.9.exe"="D:\\LFS Z\\LfsRevLimiter.0.9.exe:*:Enabled:LfsRevLimiter"
"D:\\LFS Z\\LFS.exe"="D:\\LFS Z\\LFS.exe:*:Enabled:LFS"
"D:\\NFSU2\\speed2.exe"="D:\\NFSU2\\speed2.exe:*:Enabled:speed2"
"D:\\FlightGear\\bin\\win32\\fgfs.exe"="D:\\FlightGear\\bin\\win32\\fgfs.exe:*:Enabled:fgfs"
"D:\\totalcmd\\TOTALCMD.EXE"="D:\\totalcmd\\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Uruchamia plik DLL jako aplikacj©"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\\Itunes\\iTunes.exe"="D:\\Itunes\\iTunes.exe:*:Enabled:iTunes"
"D:\\YSFLIGHT\\fsmaino.exe"="D:\\YSFLIGHT\\fsmaino.exe:*:Enabled:fsmaino"
"D:\\YSFLIGHT1\\fsmainsvr.exe"="D:\\YSFLIGHT1\\fsmainsvr.exe:*:Enabled:fsmainsvr"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"D:\\Microsoft Games\\Flight Simulator 9\\fs9.exe"="D:\\Microsoft Games\\Flight Simulator 9\\fs9.exe:*:Enabled:Microsoft Flight Simulator"
"C:\\WINDOWS\\system32\\dpnsvr.exe"="C:\\WINDOWS\\system32\\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\\Documents and Settings\\Adam Rusin\\Pulpit\\eMule0.49b\\eMule0.49b\\emule.exe"="C:\\Documents and Settings\\Adam Rusin\\Pulpit\\eMule0.49b\\eMule0.49b\\emule.exe:*:Enabled:eMule"
"D:\\EA GAMES\\Battlefield 1942\\BF1942.exe"="D:\\EA GAMES\\Battlefield 1942\\BF1942.exe:*:Enabled:BF1942"
"C:\\WINDOWS\\system32\\drivers\\svchost.exe"="C:\\WINDOWS\\system32\\drivers\\svchost.exe:*:Disabled:svchost"
"C:\\WINDOWS\\system32\\winlogon.exe"="C:\\WINDOWS\\system32\\winlogon.exe:*:Enabled:winlogon"
"D:\\Counter-Strike\\hlds.exe"="D:\\Counter-Strike\\hlds.exe:*:Enabled:HLDS Launcher"
"D:\\Counter-Strike\\hl.exe"="D:\\Counter-Strike\\hl.exe:*:Enabled:Half-Life Launcher"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[b]Remaining Files [/b]:


File Backups: - C:\SDFix\backups\backups.zip

[b]Files with Hidden Attributes [/b]:

Tue  8 Jul 2008     6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Sat 20 Sep 2008             0 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc670.tmp"
Thu  6 Oct 2005           428 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc671.tmp"
Sat 10 Oct 1992           627 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc672.tmp"
Sat 20 Sep 2008             0 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc673.tmp"
Sat 20 Sep 2008             0 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc674.tmp"
Sat 20 Sep 2008             0 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc675.tmp"
Sat 20 Sep 2008             0 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc676.tmp"
Sat 20 Sep 2008             0 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc677.tmp"
Sat 20 Sep 2008             0 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc678.tmp"
Sat 20 Sep 2008             0 A..H. --- "C:\RECYCLER\S-1-5-21-2993753242-1505528993-422160106-1003\Dc679.tmp"
Wed  3 May 2006       163,328 ..SHR --- "C:\WINDOWS\system32\flvDX.dll"
Mon 18 Aug 2008            13 ..SHR --- "C:\WINDOWS\system32\IEcacher.dll"
Sat 17 Nov 2007         1,594 ..SH. --- "C:\WINDOWS\system32\ilkkj.tmp"
Sun 13 Apr 2008       172,657 ..SH. --- "C:\WINDOWS\system32\ilkkj.bak2"
Thu 12 Apr 2007       172,749 ..SH. --- "C:\WINDOWS\system32\ilkkj.bak1"
Thu  1 Jan 2009        96,878 A.SH. --- "C:\WINDOWS\system32\jakiyohe.dll"
Fri 12 Oct 2007       637,805 ..SH. --- "C:\WINDOWS\system32\mfbemrsi.tmp"
Wed 21 Feb 2007        31,232 ..SHR --- "C:\WINDOWS\system32\msfDX.dll"
Fri  2 Jan 2009        95,851 A.SH. --- "C:\WINDOWS\system32\podidede.dll"
Fri  2 Jan 2009        84,637 A.SH. --- "C:\WINDOWS\system32\pukugusa.dll"
---                    61,440 A.SH. --- "C:\WINDOWS\system32\radozema.dll"
Mon 17 Dec 2007        27,648 ..SH. --- "C:\WINDOWS\system32\Smab0.dll"
Thu  1 Jan 2009        97,371 A.SH. --- "C:\WINDOWS\system32\suzeyiji.dll"
---                    61,440 A.SH. --- "C:\WINDOWS\system32\tokibete.dll"
---                    61,440 A.SH. --- "C:\WINDOWS\system32\yijeziye.dll"
Sat 10 May 2008           877 ...HR --- "C:\Documents and Settings\Adam Rusin\Dane aplikacji\SecuROM\UserData\securom_v7_01.bak"
Thu  8 Feb 2007         6,838 A..H. --- "C:\Documents and Settings\WLASCICIEL\Dane aplikacji\Microsoft\Office\Shortcut Bar\Off9A.tmp"
Sun  7 Dec 2008       269,312 ...HR --- "C:\Documents and Settings\Adam Rusin\Wapster\AQQ Folder\Profiles\thestig@aqq.eu\Dodatki\bannerkiller\upx.exe"

[b]Finished![/b]



HiJackThis:
Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:52, on 2009-01-02
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Mouse Driver\KMWDSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
D:\Alcohol 52\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\NEOSTR~1\CnxMon.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BenQ\BenQ Tilt-Wheel Mouse\4.0\ACQTMAPP.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BenQ\BenQ Tilt-Wheel Mouse\4.0\ACQHIDCL.DAT
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Mouse Driver\StartAutorun.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Mouse Driver\KMConfig.exe
C:\Program Files\QuickTime\QTTask.exe
D:\Itunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Adam Rusin\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe
C:\Program Files\Mouse Driver\KMProcess.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Vista Inspirat 2\RocketDock\RocketDock.exe
D:\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
D:\Microsoft Works\WkCalRem.exe
D:\Vista Inspirat 2\YzShadow\YzShadow.exe
D:\Widgets\YahooWidgetEngine.exe
C:\Program Files\iPod\bin\iPodService.exe
D:\Widgets\YahooWidgetEngine.exe
D:\Widgets\YahooWidgetEngine.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\PROGRA~1\NEOSTR~1\NeostradaTP.exe
C:\PROGRA~1\NEOSTR~1\ComComp.exe
C:\PROGRA~1\NEOSTR~1\Watch.exe
C:\WINDOWS\explorer.exe
D:\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: adssite - {1214451e-8bc7-f2b4-960b-44b94fafb5ca} - C:\WINDOWS\system32\nsx12.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - D:\dfzfdd\sbhelp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ACQTMOUSE] "C:\Program Files\BenQ\BenQ Tilt-Wheel Mouse\4.0\ACQTMAPP.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UVS11 Preload] D:\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Mouse Driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Itunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Adam Rusin\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [TopDesk] D:\TopDesk\topdesk.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Alcohol 52\axcmd.exe" /automount
O4 - Startup: RocketDock.lnk = D:\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = D:\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = D:\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: wkcalrem.LNK = D:\Microsoft Works\WkCalRem.exe
O4 - Startup: Y'z Shadow.lnk = D:\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Startup: Yahoo! Widget Engine.lnk = D:\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\dfzfdd\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\dfzfdd\sbhelp.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{41D4C4A1-97FA-4C30-9700-49D601AE4E78}: NameServer = 194.204.159.1 217.98.63.164
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Mouse Driver\KMWDSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 9892 bytes
MetalMan
~user
 
Posty: 7
Dołączenie: 12 Sie 2008, 19:26




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 12 gości