Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-08-2013 Ran by jacek_ (administrator) on 26-08-2013 12:58:02 Running from C:\Documents and Settings\jacek_\Pulpit Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 6 Boot Mode: Normal ==================== Processes (Whitelisted) =================== () C:\WINDOWS\System32\WLTRYSVC.EXE (Dell Inc.) C:\WINDOWS\System32\bcmwltry.exe (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (SigmaTel, Inc.) C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE (Dell Inc.) C:\WINDOWS\system32\WLTRAY.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\cli.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ATICCC] - C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe [90112 2006-05-10] () HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [3076144 2011-09-06] (ESET) HKLM\...\Run: [SigmatelSysTrayApp] - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-05-10] (SigmaTel, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761947 2006-03-08] (Synaptics, Inc.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\WINDOWS\system32\WLTRAY.exe [1392640 2007-03-16] (Dell Inc.) HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k [x] Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.) HKLM\...\Command Processor: <======= ATTENTION MountPoints2: {4f095286-d29a-11e2-a821-0019b963b85b} - F:\AutoRun.exe MountPoints2: {4f095289-d29a-11e2-a821-0019b963b85b} - F:\AutoRun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home StartMenuInternet: IEXPLORE.EXE - %programfiles%\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: ALLYouTubeDownloader - {61DB16C5-B733-43F4-872E-B20DC9E72740} - C:\PROGRA~1\ALLYOU~1\ALLYOU~1.DLL (ALLCinema Ltd.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKCU -&Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU -&Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation) Handler: ipp - No CLSID Value - Handler: msdaipp - No CLSID Value - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\jacek_\Dane aplikacji\Mozilla\Firefox\Profiles\it7vqg3w.default FF Homepage: about:home FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&CUI=UN11350788751532420&UM=1&q= FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Documents and Settings\jacek_\Dane aplikacji\Mozilla\Firefox\Profiles\it7vqg3w.default\searchplugins\conduit.xml FF Extension: IplextoALL - C:\Documents and Settings\jacek_\Dane aplikacji\Mozilla\Firefox\Profiles\it7vqg3w.default\Extensions\IplextoALL@ALLPlayer.org.xpi FF Extension: YouTubetoALL - C:\Documents and Settings\jacek_\Dane aplikacji\Mozilla\Firefox\Profiles\it7vqg3w.default\Extensions\YouTubetoALL@ALLPlayer.org.xpi FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird ========================== Services (Whitelisted) ================= R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [974944 2011-09-06] (ESET) R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [1253376 2007-03-16] (Dell Inc.) ==================== Drivers (Whitelisted) ==================== R1 AmdK8; C:\Windows\System32\DRIVERS\AmdK8.sys [36864 2006-07-01] (Advanced Micro Devices) R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl5.sys [604928 2007-03-16] (Broadcom Corporation) R2 eamon; C:\Windows\System32\DRIVERS\eamon.sys [154136 2011-08-09] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [118104 2011-08-04] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [147480 2011-08-04] (ESET) R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [39824 2011-08-04] (ESET) R1 epfwtdi; C:\Windows\System32\DRIVERS\epfwtdi.sys [61936 2011-08-04] (ESET) S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R3 STHDA; C:\Windows\System32\drivers\sthda.sys [1222840 2007-05-10] (SigmaTel, Inc.) S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [x] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [x] S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [x] S4 IntelIde; No ImagePath S3 SNPSTD3; system32\DRIVERS\snpstd3.sys [x] S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [x] U1 WS2IFSL; U3 uxtdypow; \??\C:\DOCUME~1\jacek_\USTAWI~1\Temp\uxtdypow.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-26 12:56 - 2013-08-26 12:56 - 00027444 _____ C:\Documents and Settings\jacek_\Pulpit\Extras.Txt 2013-08-26 12:55 - 2013-08-26 12:55 - 00046948 _____ C:\Documents and Settings\jacek_\Pulpit\OTL.Txt 2013-08-26 12:51 - 2013-08-26 12:51 - 00004579 _____ C:\Documents and Settings\jacek_\Pulpit\gmer.log 2013-08-26 12:10 - 2013-08-26 12:10 - 01070979 _____ (Farbar) C:\Documents and Settings\jacek_\Pulpit\FRST.exe 2013-08-26 12:06 - 2013-08-26 12:06 - 00377856 _____ C:\Documents and Settings\jacek_\Pulpit\xveoifum.exe 2013-08-26 12:05 - 2013-08-26 12:05 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\jacek_\Pulpit\OTL.exe 2013-08-26 12:03 - 2013-08-26 12:03 - 00000481 _____ C:\WINDOWS\setupapi.log 2013-08-17 10:41 - 2013-08-17 18:31 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-08-26 12:57 - 2013-08-26 12:57 - 00000000 ____D C:\FRST 2013-08-26 12:56 - 2013-08-26 12:56 - 00027444 _____ C:\Documents and Settings\jacek_\Pulpit\Extras.Txt 2013-08-26 12:56 - 2013-02-28 13:56 - 00000000 ____D C:\Documents and Settings\jacek_\Pulpit 2013-08-26 12:55 - 2013-08-26 12:55 - 00046948 _____ C:\Documents and Settings\jacek_\Pulpit\OTL.Txt 2013-08-26 12:51 - 2013-08-26 12:51 - 00004579 _____ C:\Documents and Settings\jacek_\Pulpit\gmer.log 2013-08-26 12:20 - 2013-02-28 13:37 - 00370933 _____ C:\WINDOWS\WindowsUpdate.log 2013-08-26 12:15 - 2013-02-28 14:29 - 00000159 _____ C:\WINDOWS\wiadebug.log 2013-08-26 12:15 - 2013-02-28 14:29 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-08-26 12:15 - 2013-02-28 13:46 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-08-26 12:11 - 2013-02-28 15:00 - 00524288 _____ C:\WINDOWS\system32\config\ACEEvent.evt 2013-08-26 12:11 - 2013-02-28 13:56 - 00000188 ___SH C:\Documents and Settings\jacek_\ntuser.ini 2013-08-26 12:11 - 2013-02-28 13:46 - 00032554 _____ C:\WINDOWS\SchedLgU.Txt 2013-08-26 12:10 - 2013-08-26 12:10 - 01070979 _____ (Farbar) C:\Documents and Settings\jacek_\Pulpit\FRST.exe 2013-08-26 12:06 - 2013-08-26 12:06 - 00377856 _____ C:\Documents and Settings\jacek_\Pulpit\xveoifum.exe 2013-08-26 12:05 - 2013-08-26 12:05 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\jacek_\Pulpit\OTL.exe 2013-08-26 12:03 - 2013-08-26 12:03 - 00000481 _____ C:\WINDOWS\setupapi.log 2013-08-26 11:37 - 2013-03-08 09:58 - 00000000 ____D C:\WINDOWS\Minidump 2013-08-26 11:37 - 2013-02-28 13:56 - 00000000 ____D C:\Documents and Settings\jacek_ 2013-08-26 11:01 - 2013-02-28 17:37 - 00000000 ____D C:\Documents and Settings\jacek_\Moje dokumenty\Pobieranie 2013-08-26 11:01 - 2013-02-28 13:56 - 00000000 ___RD C:\Documents and Settings\jacek_\Moje dokumenty 2013-08-26 11:00 - 2013-02-28 17:48 - 00000000 ____D C:\Documents and Settings\jacek_\Pulpit\GOŚKA 2013-08-26 10:59 - 2013-02-28 13:56 - 00000000 __RHD C:\Documents and Settings\jacek_\Dane aplikacji 2013-08-26 10:58 - 2013-02-28 14:52 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-08-26 10:58 - 2013-02-28 14:18 - 00000000 ____D C:\WINDOWS\twain_32 2013-08-26 10:58 - 2013-02-28 13:56 - 00000000 ___RD C:\Documents and Settings\jacek_\Menu Start\Programy 2013-08-25 17:28 - 2013-02-28 17:30 - 00000000 ____D C:\Documents and Settings\jacek_\Pulpit\JACEK 2013-08-25 10:48 - 2013-02-28 17:03 - 00131072 _____ C:\WINDOWS\system32\config\OAlerts.evt 2013-08-22 10:07 - 2002-09-29 00:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2013-08-18 09:14 - 2013-03-09 09:28 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-17 18:31 - 2013-08-17 10:41 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-15 15:30 - 2013-02-28 13:56 - 00000000 ___RD C:\Documents and Settings\jacek_\Moje dokumenty\Moja muzyka 2013-08-07 23:00 - 2013-02-28 14:25 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit Files to move or delete: ==================== C:\DOCUME~1\jacek_\USTAWI~1\Temp\AskSLib.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\down.3320.browser_addon_setup.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\fp_pl_pfs_installer.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\SkypeSetup.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\Tsu08C933F1.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\{B37CCAE9-2767-48A3-AA48-6F45689FE81F}\Custom.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\{B37CCAE9-2767-48A3-AA48-6F45689FE81F}\Setup.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\{B37CCAE9-2767-48A3-AA48-6F45689FE81F}\_Setup.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\AboutPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\AddPbk.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\AddrBookPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\AddrBookSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\AddrBookUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\AtCodec.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\ATR2SMgr.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\CallAppPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\CallLogSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\CallLogUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\CallSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\CallUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\Common.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\core.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\DataServicePlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\DeviceAppPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\DeviceMgrUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\DeviceSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\DiagnosisPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\DialUpPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\DialupUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\LayoutPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\LiveUpdateInterface.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\mcciwin32.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\MenuMgrPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\mobilepartner.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\msvcp60.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\mt.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NDISAPI.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NDISPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NetConnectPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NetConnectSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NetInfoRecordUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NetInfoSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NetInfoUIExPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NetSettingPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NetSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\NotifyServicePlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\OSAdapt.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\OSCall.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\OSDialup.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\OSNDIS.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\OSPowerMgr.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\PluginContainer.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\Proxy.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\sdk.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\SettingUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\SmsAppPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\SmsSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\SMSUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\StatusBarMgrPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\STKPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\STKSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\subinacl.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\ToolBarMgrPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\Trace.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\USSDSrvPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\USSDUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\Win7Support.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\XCodec.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\XFramePlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\XStartScreen.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\qtlib\libgcc_s_dw2-1.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\qtlib\mingwm10.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\qtlib\QtCore4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\qtlib\QtGui4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\qtlib\QtNetwork4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\qtlib\QtXml4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\plugins\imageformats\qgif4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\plugins\imageformats\qico4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\plugins\imageformats\qjpeg4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\plugins\imageformats\qmng4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\plugins\imageformats\qtiff4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\common\plugins\codecs\qcncodecs4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\core.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\DialupUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\LayoutPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\LiveUpdateInterface.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\MainpagePlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\MenuMgrPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\NetSettingPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\QtNetwork4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\StatusBarMgrPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\ToolBarMgrPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\USSDUIPlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\XFramePlugin.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\HttpInterface.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\libgcc_s_dw2-1.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\LiveUpd.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\mingwm10.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\ouc.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\QtCore4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\QtGui4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\QtNetwork4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\QueryStrategy.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\RunLiveUpd.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\RunOuc.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\plugins\imageformats\qgif4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\UpdateDog\plugins\imageformats\qico4.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\Driver\devsetup32.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\Driver\devsetup64.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\Driver\DriverSetup.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\Driver\DriverUninstall.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\Driver\LocateDevice.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\Driver\Driver\X86\hwgpssensor.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\Driver\Driver\X86\WdfCoInstaller01007.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\Driver\Driver\X64\hwgpssensor.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\Driver\Driver\X64\WdfCoInstaller01007.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\AutoRun\AutoRunSetup.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\UTPS\C264\AutoRun\AutoRunUninstall.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\MSS\3.0.318.3\mcbrwsr2.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\MSS\3.0.318.3\McInstallerRes.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\MSS\3.0.318.3\McInstallerRes_LD.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\MSS\3.0.318.3\McInstallerStartup.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\MSS\3.0.318.3\McUICnt.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\MSS\3.0.318.3\SecurityScanner.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\is1890775716\13089591_Setup.EXE C:\DOCUME~1\jacek_\USTAWI~1\Temp\is1890775716\20670473_Setup.EXE C:\DOCUME~1\jacek_\USTAWI~1\Temp\is1890775716\218851_Setup.EXE C:\DOCUME~1\jacek_\USTAWI~1\Temp\is1890775716\QtraxInstaller.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\is-V97ND.tmp\ALLYouTubeDownloader.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\is-V97ND.tmp\napiprojekt.exe C:\DOCUME~1\jacek_\USTAWI~1\Temp\is-QIU9D.tmp\Aquarius.dll C:\DOCUME~1\jacek_\USTAWI~1\Temp\is-QIU9D.tmp\LMResource.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2004-08-04 00:44] - [2008-04-14 23:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2004-08-04 00:44] - [2008-04-14 23:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2004-08-04 00:44] - [2008-04-14 23:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2004-08-04 00:44] - [2008-04-14 23:51] - 0109056 ____A (Microsoft Corporation) 3e3ae424e27c4cefe4cab368c7b570ea C:\Windows\System32\User32.dll [2004-08-04 00:44] - [2008-04-14 23:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2004-08-04 00:44] - [2008-04-14 23:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2004-08-04 00:36] - [2008-04-14 22:31] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================