Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-01-2014 01 Ran by Dominik (administrator) on WIACEK on 31-01-2014 15:47:08 Running from C:\Documents and Settings\Dominik\My Documents\Downloads Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe () C:\WINDOWS\system32\WLTRYSVC.EXE (Broadcom Corporation) C:\WINDOWS\system32\BCMWLTRY.EXE (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe (Alcor Micro, Corp.) C:\Program Files\Digital Media Reader\shwicon2k.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ATI Technologies, Inc.) C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (Broadcom Corporation) C:\WINDOWS\system32\WLTRAY.EXE (Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE () C:\Documents and Settings\Dominik\Application Data\System32\svchost.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Microsoft Corporation) C:\WINDOWS\ehome\ehRecvr.exe (Microsoft Corporation) C:\WINDOWS\ehome\ehSched.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Nero AG) C:\Program Files\Nero\Update\NASvc.exe (Microsoft Corporation) C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (HP) C:\WINDOWS\system32\HPZinw12.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (ClickMeIn Limited) C:\Program Files\VuuPC\Connectivity.exe (ClickMeIn Limited) C:\Program Files\VuuPC\RemoteEngine.exe (ClickMeIn Limited) C:\Program Files\VuuPC\RemoteEngineHelper.exe (ClickMeIn Limited) C:\Program Files\VuuPC\RemoteEngineHelper.exe () C:\Program Files\fst_pl_46\fst_pl_46.exe () C:\Documents and Settings\Dominik\Local Settings\Application Data\fst_pl_46\upfst_pl_46.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ehTray] - C:\WINDOWS\ehome\ehtray.exe [64512 2005-08-06] (Microsoft Corporation) HKLM\...\Run: [] - [x] HKLM\...\Run: [SunKist] - C:\Program Files\Digital Media Reader\shwicon2k.exe [139264 2004-05-26] (Alcor Micro, Corp.) HKLM\...\Run: [SynTPLpr] - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [98394 2004-10-08] (Synaptics, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [688218 2004-10-08] (Synaptics, Inc.) HKLM\...\Run: [ATIPTA] - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [344064 2005-06-28] (ATI Technologies, Inc.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\WINDOWS\system32\WLTRAY HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-02-19] (Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [NBAgent] - C:\Program Files\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1493288 2011-09-20] (Nero AG) HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [fst_pl_46] - C:\Program Files\fst_pl_46\fst_pl_46.exe [3997680 2014-01-30] () HKLM\...\Run: [upfst_pl_46.exe] - C:\Documents and Settings\Dominik\Local Settings\Application Data\fst_pl_46\upfst_pl_46.exe [3153904 2014-01-30] () Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd) HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation) HKCU\...\Run: [ALLUpdate] - C:\Program Files\ALLPlayer\ALLUpdate.exe [2995712 2013-07-19] (ALLPlayer Group Ltd.) HKCU\...\Run: [System Network Service] - C:\Documents and Settings\Dominik\Application Data\System32\svchost.exe [951808 2014-01-23] () MountPoints2: {4faffcba-eb29-11e2-8efc-0014a54318d4} - E:\SETUP.EXE Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk ShortcutTarget: HP Photosmart Premier Fast Start.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=150 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: ALLYouTubeDownloader - {61DB16C5-B733-43F4-872E-B20DC9E72740} - C:\Program Files\ALLYouTubeDownloader\ALLYouTubeDownloader.dll (ALLCinema Ltd.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: IplexToALLPlayer - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\Program Files\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 62.179.1.63 62.179.1.62 Chrome: ======= CHR HomePage: hxxp://www.gazeta.pl/0,0.html?p=150 CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\32.0.1700.102\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\32.0.1700.102\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\32.0.1700.102\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.149\npGoogleUpdate3.dll No File CHR Extension: (Dokumenty Google) - C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-12] CHR Extension: (Dysk Google) - C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-07-12] CHR Extension: (YouTube) - C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-12] CHR Extension: (Szukaj w Google) - C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-12] CHR Extension: (Google Wallet) - C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-30] CHR Extension: (Gmail) - C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-07-12] ========================== Services (Whitelisted) ================= S3 HP Port Resolver; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE [81920 2005-05-20] (Hewlett-Packard Company) S3 HP Status Server; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE [73728 2004-10-16] (Hewlett-Packard Company) R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-12-28] (Oracle Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [235216 2013-09-06] (McAfee, Inc.) R2 McrdSvc; C:\WINDOWS\ehome\mcrdsvc.exe [99328 2005-08-06] (Microsoft Corporation) R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [641832 2011-09-23] (Nero AG) R2 RemoteEngineService; C:\Program Files\VuuPC\remoteengine.exe [2967568 2014-01-28] (ClickMeIn Limited) R2 VuuPCConnectivity; C:\Program Files\VuuPC\Connectivity.exe [4747280 2014-01-28] (ClickMeIn Limited) R2 wltrysvc; C:\WINDOWS\System32\bcmwltry.exe [847983 2005-02-17] (Broadcom Corporation) ==================== Drivers (Whitelisted) ==================== R0 abp480n5; C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS [23552 2004-08-10] (Microsoft Corporation) R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [17801 2013-07-12] (Meetinghouse Data Communications) R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [39424 2004-08-11] (Advanced Micro Devices) S3 AMDMSRIO; C:\Documents and Settings\Dominik\Local Settings\Temp\Safe To Delete 3_0_4_8\amdmsrio.sys [32804 2002-08-19] (AMD, Inc.) R3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [371712 2005-02-11] (Broadcom Corporation) R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2013-07-12] (Disc Soft Ltd) S3 EMCFILT; C:\WINDOWS\System32\Drivers\EMcFilt.sys [29824 2004-06-23] (Alcor Micro Corp.) R3 HSFHWATI; C:\WINDOWS\System32\DRIVERS\HSFHWATI.sys [200192 2004-12-15] (Conexant Systems, Inc.) R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [1038208 2004-12-15] (Conexant Systems, Inc.) S3 mxnic; C:\WINDOWS\System32\DRIVERS\mxnic.sys [19968 2001-08-17] (Macronix International Co., Ltd. ) S1 P3; C:\WINDOWS\System32\DRIVERS\p3.sys [46848 2008-04-14] (Microsoft Corporation) R3 yukonwxp; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [230400 2005-03-30] (Marvell) U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) S3 UIUSys; system32\drivers\UIUSys.sys [x] U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== NETSVC: MHN -> C:\Windows\System32\mhn.dll (Microsoft Corporation) ==================== One Month Created Files and Folders ======== 2014-01-31 15:47 - 2014-01-31 15:47 - 00000000 ____D C:\FRST 2014-01-31 15:44 - 2014-01-31 15:44 - 00000000 ____D C:\Program Files\fst_pl_46 2014-01-31 15:44 - 2014-01-31 15:44 - 00000000 ____D C:\Documents and Settings\Dominik\Local Settings\Application Data\fst_pl_46 2014-01-31 15:44 - 2014-01-31 15:44 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\FREESOFTTODAY 2014-01-31 15:43 - 2014-01-31 15:43 - 00000916 _____ C:\Documents and Settings\Dominik\Desktop\Continue AnyProtect Installation.lnk 2014-01-31 15:40 - 2014-01-31 15:40 - 00001080 _____ C:\Documents and Settings\Dominik\Desktop\My VuuPC.lnk 2014-01-31 15:40 - 2014-01-31 15:40 - 00000000 ____D C:\Documents and Settings\Dominik\Start Menu\Programs\VuuPC 2014-01-31 15:39 - 2014-01-31 15:43 - 00000000 ____D C:\Program Files\VuuPC 2014-01-25 15:42 - 2014-01-30 17:59 - 00046080 _____ C:\Documents and Settings\Dominik\Desktop\Dane.xls 2014-01-16 17:28 - 2014-01-16 17:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2914368$ 2014-01-16 17:26 - 2014-01-16 17:28 - 00004834 _____ C:\WINDOWS\KB2914368.log 2014-01-12 19:38 - 2014-01-27 23:19 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Reologia ==================== One Month Modified Files and Folders ======= 2014-01-31 15:47 - 2014-01-31 15:47 - 00000000 ____D C:\FRST 2014-01-31 15:44 - 2014-01-31 15:44 - 00000000 ____D C:\Program Files\fst_pl_46 2014-01-31 15:44 - 2014-01-31 15:44 - 00000000 ____D C:\Documents and Settings\Dominik\Local Settings\Application Data\fst_pl_46 2014-01-31 15:44 - 2014-01-31 15:44 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\FREESOFTTODAY 2014-01-31 15:43 - 2014-01-31 15:43 - 00000916 _____ C:\Documents and Settings\Dominik\Desktop\Continue AnyProtect Installation.lnk 2014-01-31 15:43 - 2014-01-31 15:39 - 00000000 ____D C:\Program Files\VuuPC 2014-01-31 15:40 - 2014-01-31 15:40 - 00001080 _____ C:\Documents and Settings\Dominik\Desktop\My VuuPC.lnk 2014-01-31 15:40 - 2014-01-31 15:40 - 00000000 ____D C:\Documents and Settings\Dominik\Start Menu\Programs\VuuPC 2014-01-31 15:27 - 2013-07-12 17:06 - 00001038 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-31 14:45 - 2013-07-12 20:30 - 00573674 _____ C:\WINDOWS\system32\PerfStringBackup.TMP 2014-01-31 14:16 - 2005-01-10 02:10 - 01216988 _____ C:\WINDOWS\WindowsUpdate.log 2014-01-31 14:14 - 2013-07-12 17:06 - 00001034 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-31 14:14 - 2005-01-09 18:03 - 00000157 _____ C:\WINDOWS\wiadebug.log 2014-01-31 14:14 - 2005-01-09 18:03 - 00000050 _____ C:\WINDOWS\wiaservc.log 2014-01-31 14:13 - 2005-01-10 02:19 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2014-01-31 09:08 - 2013-07-13 00:09 - 00000178 ___SH C:\Documents and Settings\Dominik\ntuser.ini 2014-01-31 09:08 - 2005-01-10 02:19 - 00032596 _____ C:\WINDOWS\SchedLgU.Txt 2014-01-31 08:53 - 2013-07-14 13:36 - 00117737 _____ C:\WINDOWS\KB973768.log 2014-01-30 17:59 - 2014-01-25 15:42 - 00046080 _____ C:\Documents and Settings\Dominik\Desktop\Dane.xls 2014-01-29 20:02 - 2013-12-08 21:50 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Laboratorium 2014-01-29 17:35 - 2013-07-12 17:07 - 00001819 _____ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk 2014-01-27 23:19 - 2014-01-12 19:38 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Reologia 2014-01-26 22:00 - 2013-07-12 21:03 - 00065536 _____ C:\WINDOWS\system32\config\OAlerts.evt 2014-01-25 14:22 - 2005-01-10 00:48 - 00000628 _____ C:\WINDOWS\win.ini 2014-01-23 19:48 - 2013-12-13 23:47 - 00299262 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat 2014-01-23 19:48 - 2013-12-13 23:47 - 00299262 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-3960371301-936395131-3903304965-1006-0.dat 2014-01-23 08:52 - 2013-11-13 19:39 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Materiały i cywilizacje 2014-01-22 07:07 - 2013-12-18 20:38 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Chemia polimerów 2 2014-01-21 20:08 - 2013-12-08 21:51 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Ceramika funkcjonalna 2014-01-20 07:35 - 2013-12-20 11:55 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Praca magisterska 2014-01-16 17:33 - 2013-08-20 09:50 - 00000000 ____D C:\WINDOWS\system32\MRT 2014-01-16 17:29 - 2013-07-14 13:38 - 83425928 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-01-16 17:28 - 2014-01-16 17:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2914368$ 2014-01-16 17:28 - 2014-01-16 17:26 - 00004834 _____ C:\WINDOWS\KB2914368.log 2014-01-16 17:28 - 2005-01-09 18:00 - 01142485 _____ C:\WINDOWS\iis6.log 2014-01-16 17:28 - 2005-01-09 18:00 - 01025553 _____ C:\WINDOWS\FaxSetup.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00499065 _____ C:\WINDOWS\ocgen.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00476784 _____ C:\WINDOWS\tsoc.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00352856 _____ C:\WINDOWS\comsetup.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00327496 _____ C:\WINDOWS\msmqinst.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00211666 _____ C:\WINDOWS\ntdtcsetup.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00193118 _____ C:\WINDOWS\netfxocm.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00116982 _____ C:\WINDOWS\plusoc.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00116163 _____ C:\WINDOWS\MedCtrOC.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00063568 _____ C:\WINDOWS\ocmsn.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00057608 _____ C:\WINDOWS\ehOCGen.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00053686 _____ C:\WINDOWS\tabletoc.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00051391 _____ C:\WINDOWS\msgsocm.log 2014-01-16 17:28 - 2005-01-09 18:00 - 00001374 _____ C:\WINDOWS\imsins.log 2014-01-15 20:17 - 2013-10-24 19:56 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Technologia wysokiej próżni 2014-01-14 18:42 - 2013-11-04 22:49 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Projekt 2014-01-14 17:37 - 2005-01-10 00:48 - 00001170 _____ C:\WINDOWS\system32\wpa.dbl 2014-01-12 19:14 - 2013-08-28 11:56 - 00000000 ____D C:\Documents and Settings\Dominik\Desktop\Volvo 2014-01-06 13:36 - 2005-01-10 02:07 - 00000000 ____D C:\WINDOWS\Registration 2014-01-03 11:33 - 2013-08-01 10:58 - 00000000 ____D C:\Documents and Settings\Dominik\My Documents\My Scans 2014-01-01 17:19 - 2013-07-13 00:09 - 00000000 ____D C:\Documents and Settings\Dominik Some content of TEMP: ==================== C:\Documents and Settings\Dominik\Local Settings\Temp\bitool.dll C:\Documents and Settings\Dominik\Local Settings\Temp\hpzmsi01.exe C:\Documents and Settings\Dominik\Local Settings\Temp\hpzscr01.exe C:\Documents and Settings\Dominik\Local Settings\Temp\ICReinstall_nsq3CA.tmp.exe C:\Documents and Settings\Dominik\Local Settings\Temp\ICReinstall_Setup.exe C:\Documents and Settings\Dominik\Local Settings\Temp\LyricsMonkey_1060-1053_v116.exe C:\Documents and Settings\Dominik\Local Settings\Temp\nsz3DD.tmp.exe C:\Documents and Settings\Dominik\Local Settings\Temp\ose00000.exe C:\Documents and Settings\Dominik\Local Settings\Temp\setup_wm.exe C:\Documents and Settings\Dominik\Local Settings\Temp\UIUCU2.EXE C:\Documents and Settings\Dominik\Local Settings\Temp\UpdUninstall.exe ==================== Bamital & volsnap Check ================= C:\WINDOWS\explorer.exe [2013-07-12 22:40] - [2008-04-14 21:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\WINDOWS\system32\winlogon.exe [2013-07-12 22:45] - [2008-04-14 21:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\WINDOWS\system32\svchost.exe [2013-07-12 22:45] - [2008-04-14 21:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\WINDOWS\system32\services.exe [2013-07-12 22:44] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\WINDOWS\system32\User32.dll [2013-07-12 22:45] - [2008-04-14 21:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\WINDOWS\system32\userinit.exe [2013-07-12 22:45] - [2008-04-14 21:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\WINDOWS\system32\rpcss.dll [2013-07-12 22:44] - [2009-02-09 11:53] - 0401408 ____A (Microsoft Corporation) a37311d9d628c1042a2836731787f0f3 ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected. C:\WINDOWS\system32\Drivers\volsnap.sys [2013-07-12 22:45] - [2008-04-14 20:31] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================