Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-02-2014 Ran by Luqie (administrator) on DUDZIK-FD4F7216 on 20-02-2014 11:33:37 Running from C:\Documents and Settings\Luqie\Moje dokumenty\Pobieranie Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files\EslWire\service\WireHelperSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Creative Technology Ltd) C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Valve Corporation) D:\Steam\Steam.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (BitTorrent Inc.) C:\Documents and Settings\Luqie\Dane aplikacji\uTorrent\uTorrent.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [P17Helper] - C:\WINDOWS\system32\P17.dll [64512 2005-05-03] () HKLM\...\Run: [UpdReg] - C:\WINDOWS\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2014-01-01] (AVAST Software) HKLM\...\Run: [amd_dc_opt] - C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [15677728 2013-06-21] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [223008 2013-06-21] (NVIDIA Corporation) HKLM\...\Run: [CTSysVol] - C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe [57344 2005-10-31] (Creative Technology Ltd) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Luqie\Dane aplikacji\Mozilla\Firefox\Profiles\69vw0xd2.default FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Extension: United States English Spellchecker - C:\Documents and Settings\Luqie\Dane aplikacji\Mozilla\Firefox\Profiles\69vw0xd2.default\Extensions\en-US@dictionaries.addons.mozilla.org [2014-02-12] FF Extension: Media Hint - C:\Documents and Settings\Luqie\Dane aplikacji\Mozilla\Firefox\Profiles\69vw0xd2.default\Extensions\mediahint@jetpack.xpi [2014-01-06] FF Extension: Adblock Plus - C:\Documents and Settings\Luqie\Dane aplikacji\Mozilla\Firefox\Profiles\69vw0xd2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-01] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-01] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] ========================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-01] (AVAST Software) S4 BRSptSvc; C:\Documents and Settings\All Users\Dane aplikacji\BitRaider\BRSptSvc.exe [477960 2014-02-02] (BitRaider, LLC) R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [614416 2013-06-11] () S4 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [9216 2014-01-05] (Hi-Rez Studios) S4 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-12-18] (Oracle Corporation) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-01-01] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [54832 2014-01-01] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-01-01] () R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [775952 2014-01-01] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [410528 2014-01-01] (AVAST Software) R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57672 2014-01-01] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [180248 2014-01-01] () R0 ESLWireAC; C:\WINDOWS\System32\drivers\ESLWireACD.sys [932744 2014-02-15] () R3 irsir; C:\WINDOWS\System32\DRIVERS\irsir.sys [18688 2001-08-17] (Microsoft Corporation) R0 nvata; C:\WINDOWS\System32\DRIVERS\nvata.sys [105344 2006-09-21] (NVIDIA Corporation) R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [52736 2006-08-07] (NVIDIA Corporation) R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [18944 2006-08-07] (NVIDIA Corporation) R3 P17; C:\WINDOWS\System32\drivers\P17.sys [1389056 2005-07-07] (Creative Technology Ltd.) R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation) S3 BRDriver; \??\c:\Documents and Settings\All Users\Dane aplikacji\BitRaider\BRDriver.sys [X] S3 grgecrye; No ImagePath S4 IntelIde; No ImagePath U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-20 11:33 - 2014-02-20 11:33 - 00000000 ____D () C:\FRST 2014-02-15 19:41 - 2014-02-15 19:41 - 00932744 _____ () C:\WINDOWS\system32\Drivers\ESLWireACD.sys 2014-02-15 19:36 - 2014-02-16 18:45 - 00000000 ____D () C:\Documents and Settings\Luqie\Moje dokumenty\ESL Match Media 2014-02-15 00:28 - 2014-02-15 00:28 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-13 23:33 - 2014-02-13 23:33 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$ 2014-02-13 23:10 - 2014-02-13 23:10 - 00011683 _____ () C:\WINDOWS\KB2909921-IE8.log 2014-02-13 23:09 - 2014-02-13 23:10 - 00004338 _____ () C:\WINDOWS\KB2909210-IE8.log 2014-02-13 22:52 - 2014-02-13 23:33 - 00013441 _____ () C:\WINDOWS\KB2916036.log 2014-02-12 22:39 - 2014-02-12 22:39 - 00000000 ____D () C:\Program Files\MetaGeek 2014-02-12 22:39 - 2014-02-12 22:39 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\MetaGeek,_LLC 2014-02-12 22:39 - 2014-02-12 22:39 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\MetaGeek 2014-02-11 22:48 - 2014-02-11 22:48 - 00000000 ____D () C:\WINDOWS\Sun 2014-02-07 22:58 - 2014-02-15 19:39 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-07 22:58 - 2014-02-07 22:58 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Mozilla 2014-02-07 13:14 - 2014-02-07 13:14 - 00000000 __SHD () C:\Documents and Settings\Luqie\PrivacIE 2014-02-07 13:07 - 2014-02-20 10:11 - 00000000 ___RD () C:\Documents and Settings\Luqie\Pulpit\  2014-02-04 18:34 - 2014-02-04 18:34 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\ESL_Wire_Plugin_Container 2014-02-04 18:28 - 2014-02-17 22:02 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\ESL Wire Game Client 2014-02-04 18:28 - 2014-02-04 18:28 - 00000649 _____ () C:\Documents and Settings\All Users\Pulpit\ESL Wire.lnk 2014-02-04 18:28 - 2014-02-04 18:28 - 00000000 ____D () C:\Program Files\EslWire 2014-02-04 18:28 - 2014-02-04 18:28 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\ESL Wire 2014-02-02 11:57 - 2014-02-02 11:57 - 00000000 __SHD () C:\found.001 2014-02-02 00:24 - 2014-02-02 00:24 - 00000000 ____D () C:\Documents and Settings\Luqie\Dane aplikacji\MPC-HC 2014-02-02 00:23 - 2014-02-02 00:23 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack 2014-02-02 00:23 - 2013-12-01 14:10 - 00218200 _____ () C:\WINDOWS\system32\unrar.dll 2014-02-01 16:18 - 2014-02-01 16:49 - 00006144 _____ () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-31 15:27 - 2014-02-02 15:56 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\BitRaider 2014-01-30 22:25 - 2014-01-30 22:25 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\Sun 2014-01-30 21:32 - 2014-01-30 21:40 - 00000355 _____ () C:\WINDOWS\nsw.log 2014-01-30 18:25 - 2014-01-30 18:25 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-01-30 18:25 - 2014-01-30 18:25 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Java 2014-01-30 18:25 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2014-01-30 18:25 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2014-01-30 18:25 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2014-01-30 18:25 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2014-01-30 18:25 - 2013-12-18 20:46 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2014-01-30 18:24 - 2014-01-30 18:25 - 00005724 _____ () C:\WINDOWS\system32\jupdate-1.7.0_51-b13.log 2014-01-30 18:21 - 2014-01-30 18:25 - 00000000 ____D () C:\Program Files\Java 2014-01-30 18:21 - 2014-01-30 18:21 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Sun 2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D () C:\Documents and Settings\Luqie\Dane aplikacji\Sun 2014-01-30 14:52 - 2014-01-30 14:52 - 00000000 ____D () C:\Program Files\Unlocker 2014-01-30 14:52 - 2014-01-30 14:52 - 00000000 ____D () C:\Documents and Settings\Luqie\Menu Start\Programy\Unlocker 2014-01-27 02:57 - 2014-02-13 02:13 - 00401136 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-842925246-1532298954-839522115-1004-0.dat 2014-01-27 02:57 - 2014-02-13 02:13 - 00303786 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat 2014-01-27 01:09 - 2014-01-27 01:12 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\Dxtory Software 2014-01-27 01:09 - 2014-01-27 01:09 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Dxtory2.0 2014-01-27 01:09 - 2011-05-23 23:23 - 03166720 _____ (Dxtory Software) C:\WINDOWS\system32\DxtoryCodec.dll 2014-01-26 14:49 - 2014-01-26 14:49 - 00000000 ____D () C:\Documents and Settings\Luqie\Moje dokumenty\Star Wars - The Old Republic 2014-01-23 12:25 - 2014-01-23 12:25 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\SWTOR 2014-01-23 00:45 - 2014-01-23 00:45 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\SWTORPerf 2014-01-23 00:45 - 2014-01-23 00:45 - 00000000 ____D () C:\Documents and Settings\All Users\Dokumenty\BitRaider 2014-01-22 23:50 - 2014-01-22 23:50 - 00000553 _____ () C:\Documents and Settings\All Users\Pulpit\Star Wars - The Old Republic.lnk 2014-01-22 23:50 - 2014-01-22 23:50 - 00000000 ____D () C:\Program Files\Common Files\BioWare 2014-01-22 23:49 - 2014-01-22 23:50 - 00013777 _____ () C:\Documents and Settings\Luqie\Moje dokumenty\Install STAR WARS The Old Republic.log 2014-01-22 23:47 - 2014-01-22 23:47 - 00005119 _____ () C:\WINDOWS\KB2914368.log 2014-01-22 23:47 - 2014-01-22 23:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$ ==================== One Month Modified Files and Folders ======= 2014-02-20 11:33 - 2014-02-20 11:33 - 00000000 ____D () C:\FRST 2014-02-20 11:33 - 2014-01-07 23:37 - 00000000 ____D () C:\Documents and Settings\Luqie\Dane aplikacji\uTorrent 2014-02-20 11:33 - 2014-01-01 00:39 - 00000000 ____D () C:\Documents and Settings\Luqie\Moje dokumenty\Pobieranie 2014-02-20 11:29 - 2014-01-01 00:46 - 00010360 _____ () C:\WINDOWS\system32\nvAppTimestamps 2014-02-20 10:33 - 2013-12-31 23:49 - 01189875 _____ () C:\WINDOWS\WindowsUpdate.log 2014-02-20 10:15 - 2014-01-09 13:21 - 00000000 ____D () C:\Documents and Settings\Luqie\Dane aplikacji\AIMP3 2014-02-20 10:11 - 2014-02-07 13:07 - 00000000 ___RD () C:\Documents and Settings\Luqie\Pulpit\  2014-02-20 09:23 - 2014-01-01 00:44 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-02-20 09:23 - 2014-01-01 00:44 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-02-20 09:22 - 2014-01-01 00:04 - 00032370 _____ () C:\WINDOWS\SchedLgU.Txt 2014-02-20 09:22 - 2014-01-01 00:04 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-02-20 07:18 - 2014-01-01 00:11 - 00000188 ___SH () C:\Documents and Settings\Luqie\ntuser.ini 2014-02-19 21:31 - 2014-01-01 00:11 - 00000000 ____D () C:\Documents and Settings\Luqie\Pulpit 2014-02-18 12:14 - 2014-01-01 00:52 - 00000362 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job 2014-02-17 22:46 - 2014-01-01 13:24 - 00000000 ____D () C:\Documents and Settings\Luqie\Dane aplikacji\TS3Client 2014-02-17 22:02 - 2014-02-04 18:28 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\ESL Wire Game Client 2014-02-16 18:45 - 2014-02-15 19:36 - 00000000 ____D () C:\Documents and Settings\Luqie\Moje dokumenty\ESL Match Media 2014-02-15 19:41 - 2014-02-15 19:41 - 00932744 _____ () C:\WINDOWS\system32\Drivers\ESLWireACD.sys 2014-02-15 19:39 - 2014-02-07 22:58 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-15 19:37 - 2014-01-01 00:35 - 00000223 __RSH () C:\boot.ini 2014-02-15 19:37 - 2004-08-04 13:00 - 00000528 _____ () C:\WINDOWS\win.ini 2014-02-15 19:37 - 2004-08-04 13:00 - 00000227 _____ () C:\WINDOWS\system.ini 2014-02-15 00:28 - 2014-02-15 00:28 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-14 14:17 - 2014-01-01 00:40 - 00000000 ____D () C:\WINDOWS\Microsoft.NET 2014-02-13 23:33 - 2014-02-13 23:33 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$ 2014-02-13 23:33 - 2014-02-13 22:52 - 00013441 _____ () C:\WINDOWS\KB2916036.log 2014-02-13 23:33 - 2014-01-01 00:40 - 00936307 _____ () C:\WINDOWS\FaxSetup.log 2014-02-13 23:33 - 2014-01-01 00:40 - 00474832 _____ () C:\WINDOWS\ocgen.log 2014-02-13 23:33 - 2014-01-01 00:40 - 00365582 _____ () C:\WINDOWS\tsoc.log 2014-02-13 23:33 - 2014-01-01 00:40 - 00326453 _____ () C:\WINDOWS\comsetup.log 2014-02-13 23:33 - 2014-01-01 00:40 - 00197558 _____ () C:\WINDOWS\ntdtcsetup.log 2014-02-13 23:33 - 2014-01-01 00:40 - 00144618 _____ () C:\WINDOWS\iis6.log 2014-02-13 23:33 - 2014-01-01 00:40 - 00058830 _____ () C:\WINDOWS\ocmsn.log 2014-02-13 23:33 - 2014-01-01 00:40 - 00047583 _____ () C:\WINDOWS\msgsocm.log 2014-02-13 23:33 - 2014-01-01 00:40 - 00001374 _____ () C:\WINDOWS\imsins.log 2014-02-13 23:33 - 2014-01-01 00:38 - 00754919 _____ () C:\WINDOWS\setupapi.log 2014-02-13 23:33 - 2014-01-01 00:17 - 00179788 _____ () C:\WINDOWS\updspapi.log 2014-02-13 23:27 - 2014-01-01 00:40 - 01246584 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-02-13 23:27 - 2004-08-04 13:00 - 00554124 _____ () C:\WINDOWS\system32\perfh015.dat 2014-02-13 23:27 - 2004-08-04 13:00 - 00103936 _____ () C:\WINDOWS\system32\perfc015.dat 2014-02-13 23:20 - 2014-01-07 23:04 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-02-13 23:18 - 2014-01-07 23:03 - 85946576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-02-13 23:10 - 2014-02-13 23:10 - 00011683 _____ () C:\WINDOWS\KB2909921-IE8.log 2014-02-13 23:10 - 2014-02-13 23:09 - 00004338 _____ () C:\WINDOWS\KB2909210-IE8.log 2014-02-13 23:10 - 2014-01-08 19:14 - 00000000 ____D () C:\WINDOWS\ie8updates 2014-02-13 23:10 - 2014-01-01 00:40 - 00001374 _____ () C:\WINDOWS\imsins.BAK 2014-02-13 02:13 - 2014-01-27 02:57 - 00401136 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-842925246-1532298954-839522115-1004-0.dat 2014-02-13 02:13 - 2014-01-27 02:57 - 00303786 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat 2014-02-12 22:39 - 2014-02-12 22:39 - 00000000 ____D () C:\Program Files\MetaGeek 2014-02-12 22:39 - 2014-02-12 22:39 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\MetaGeek,_LLC 2014-02-12 22:39 - 2014-02-12 22:39 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\MetaGeek 2014-02-12 22:39 - 2014-01-01 00:40 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2014-02-12 22:39 - 2014-01-01 00:40 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2014-02-12 22:39 - 2014-01-01 00:11 - 00000000 ___HD () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji 2014-02-12 19:10 - 2014-01-01 00:31 - 00000000 ____D () C:\WINDOWS\system32\ias 2014-02-11 22:48 - 2014-02-11 22:48 - 00000000 ____D () C:\WINDOWS\Sun 2014-02-08 14:14 - 2004-08-04 13:00 - 00002422 _____ () C:\WINDOWS\system32\wpa.dbl 2014-02-07 22:58 - 2014-02-07 22:58 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Mozilla 2014-02-07 22:58 - 2014-01-01 00:38 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2014-02-07 13:15 - 2014-01-01 00:38 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-02-07 13:15 - 2014-01-01 00:38 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-02-07 13:14 - 2014-02-07 13:14 - 00000000 __SHD () C:\Documents and Settings\Luqie\PrivacIE 2014-02-07 13:14 - 2014-01-01 00:11 - 00000000 ____D () C:\Documents and Settings\Luqie 2014-02-06 04:38 - 2013-10-25 01:52 - 00920064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wininet.dll 2014-02-06 04:38 - 2004-08-04 13:00 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-02-06 00:08 - 2014-01-08 19:15 - 00522240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll 2014-02-06 00:08 - 2014-01-08 19:14 - 11113472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieframe.dll 2014-02-06 00:08 - 2014-01-08 19:14 - 02006016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iertutil.dll 2014-02-06 00:08 - 2014-01-08 19:14 - 00743424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll 2014-02-06 00:08 - 2014-01-08 19:14 - 00630272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeeds.dll 2014-02-06 00:08 - 2014-01-08 19:14 - 00247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll 2014-02-06 00:08 - 2014-01-08 19:14 - 00055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2014-02-06 00:08 - 2014-01-08 19:14 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll 2014-02-06 00:08 - 2013-10-25 01:52 - 06021120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll 2014-02-06 00:08 - 2013-10-25 01:52 - 01216000 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\urlmon.dll 2014-02-06 00:08 - 2013-10-25 01:52 - 00759296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll 2014-02-06 00:08 - 2013-10-25 01:52 - 00611840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstime.dll 2014-02-06 00:08 - 2013-10-25 01:52 - 00184320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iepeers.dll 2014-02-06 00:08 - 2013-10-25 01:52 - 00105984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\url.dll 2014-02-06 00:08 - 2013-10-25 01:52 - 00067072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtmled.dll 2014-02-06 00:08 - 2009-03-08 14:09 - 00387584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedkcs32.dll 2014-02-06 00:08 - 2009-03-08 04:39 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-02-06 00:08 - 2009-03-08 04:34 - 01469440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcpl.cpl 2014-02-06 00:08 - 2009-03-08 04:34 - 00206848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\occache.dll 2014-02-06 00:08 - 2009-03-08 04:34 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licmgr10.dll 2014-02-06 00:08 - 2009-03-08 04:33 - 00025600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsproxy.dll 2014-02-06 00:08 - 2009-03-08 04:33 - 00018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\corpol.dll 2014-02-06 00:08 - 2009-03-08 04:32 - 02006016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-02-06 00:08 - 2009-03-08 04:32 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-02-06 00:08 - 2009-03-08 04:31 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 06021120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 01469440 ____N (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-02-06 00:08 - 2004-08-04 13:00 - 01216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 00611840 ____N (Microsoft Corporation) C:\WINDOWS\system32\mstime.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 00387584 ____N (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 00206848 ____N (Microsoft Corporation) C:\WINDOWS\system32\occache.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 00184320 ____N (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 00067072 ____N (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 00043520 ____N (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 00025600 ____N (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2014-02-06 00:08 - 2004-08-04 13:00 - 00018944 ____N (Microsoft Corporation) C:\WINDOWS\system32\corpol.dll 2014-02-05 23:29 - 2009-03-08 04:32 - 00174592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe 2014-02-05 23:29 - 2004-08-04 13:00 - 00385024 ____N (Microsoft Corporation) C:\WINDOWS\system32\html.iec 2014-02-05 23:29 - 2004-08-04 13:00 - 00174592 ____N (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-02-05 19:52 - 2014-01-01 00:26 - 00000584 _____ () C:\WINDOWS\system32\settingsbkup.sfm 2014-02-05 19:52 - 2014-01-01 00:26 - 00000584 _____ () C:\WINDOWS\system32\settings.sfm 2014-02-05 19:48 - 2014-01-01 00:20 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Creative 2014-02-05 19:48 - 2014-01-01 00:19 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-02-05 19:47 - 2014-01-01 00:16 - 00000000 ____D () C:\WINDOWS\system32\ReinstallBackups 2014-02-04 18:34 - 2014-02-04 18:34 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\ESL_Wire_Plugin_Container 2014-02-04 18:28 - 2014-02-04 18:28 - 00000649 _____ () C:\Documents and Settings\All Users\Pulpit\ESL Wire.lnk 2014-02-04 18:28 - 2014-02-04 18:28 - 00000000 ____D () C:\Program Files\EslWire 2014-02-04 18:28 - 2014-02-04 18:28 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\ESL Wire 2014-02-02 15:56 - 2014-01-31 15:27 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\BitRaider 2014-02-02 11:57 - 2014-02-02 11:57 - 00000000 __SHD () C:\found.001 2014-02-02 00:24 - 2014-02-02 00:24 - 00000000 ____D () C:\Documents and Settings\Luqie\Dane aplikacji\MPC-HC 2014-02-02 00:24 - 2014-01-01 00:11 - 00000000 __RHD () C:\Documents and Settings\Luqie\Dane aplikacji 2014-02-02 00:23 - 2014-02-02 00:23 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack 2014-02-01 16:49 - 2014-02-01 16:18 - 00006144 _____ () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-30 22:25 - 2014-01-30 22:25 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\Sun 2014-01-30 21:40 - 2014-01-30 21:32 - 00000355 _____ () C:\WINDOWS\nsw.log 2014-01-30 18:25 - 2014-01-30 18:25 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-01-30 18:25 - 2014-01-30 18:25 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Java 2014-01-30 18:25 - 2014-01-30 18:24 - 00005724 _____ () C:\WINDOWS\system32\jupdate-1.7.0_51-b13.log 2014-01-30 18:25 - 2014-01-30 18:21 - 00000000 ____D () C:\Program Files\Java 2014-01-30 18:21 - 2014-01-30 18:21 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Sun 2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D () C:\Documents and Settings\Luqie\Dane aplikacji\Sun 2014-01-30 14:52 - 2014-01-30 14:52 - 00000000 ____D () C:\Program Files\Unlocker 2014-01-30 14:52 - 2014-01-30 14:52 - 00000000 ____D () C:\Documents and Settings\Luqie\Menu Start\Programy\Unlocker 2014-01-30 14:52 - 2014-01-01 00:11 - 00000000 ___RD () C:\Documents and Settings\Luqie\Menu Start\Programy 2014-01-27 02:57 - 2014-01-01 00:04 - 00000000 ___HD () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji 2014-01-27 01:12 - 2014-01-27 01:09 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\Dxtory Software 2014-01-27 01:09 - 2014-01-27 01:09 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Dxtory2.0 2014-01-26 14:49 - 2014-01-26 14:49 - 00000000 ____D () C:\Documents and Settings\Luqie\Moje dokumenty\Star Wars - The Old Republic 2014-01-26 14:49 - 2014-01-01 00:11 - 00000000 ___RD () C:\Documents and Settings\Luqie\Moje dokumenty 2014-01-23 12:25 - 2014-01-23 12:25 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\SWTOR 2014-01-23 00:45 - 2014-01-23 00:45 - 00000000 ____D () C:\Documents and Settings\Luqie\Ustawienia lokalne\Dane aplikacji\SWTORPerf 2014-01-23 00:45 - 2014-01-23 00:45 - 00000000 ____D () C:\Documents and Settings\All Users\Dokumenty\BitRaider 2014-01-23 00:45 - 2014-01-01 00:40 - 00000000 ___RD () C:\Documents and Settings\All Users\Dokumenty 2014-01-22 23:50 - 2014-01-22 23:50 - 00000553 _____ () C:\Documents and Settings\All Users\Pulpit\Star Wars - The Old Republic.lnk 2014-01-22 23:50 - 2014-01-22 23:50 - 00000000 ____D () C:\Program Files\Common Files\BioWare 2014-01-22 23:50 - 2014-01-22 23:49 - 00013777 _____ () C:\Documents and Settings\Luqie\Moje dokumenty\Install STAR WARS The Old Republic.log 2014-01-22 23:47 - 2014-01-22 23:47 - 00005119 _____ () C:\WINDOWS\KB2914368.log 2014-01-22 23:47 - 2014-01-22 23:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$ Some content of TEMP: ==================== C:\Documents and Settings\Luqie\Ustawienia lokalne\Temp\BRSVC_8801078_hlp.exe C:\Documents and Settings\Luqie\Ustawienia lokalne\Temp\EslWireSetup-1.17.3.7769-x86.exe C:\Documents and Settings\Luqie\Ustawienia lokalne\Temp\HiPatchSelfUpdateWindow.exe C:\Documents and Settings\Luqie\Ustawienia lokalne\Temp\HiRezLauncherControls.dll C:\Documents and Settings\Luqie\Ustawienia lokalne\Temp\vcredist_x86.exe ==================== Bamital & volsnap Check ================= C:\WINDOWS\explorer.exe [2004-08-04 13:00] - [2008-04-14 22:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\WINDOWS\system32\winlogon.exe [2004-08-04 13:00] - [2008-04-14 22:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\WINDOWS\system32\svchost.exe [2004-08-04 13:00] - [2008-04-14 22:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\WINDOWS\system32\services.exe [2004-08-04 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\WINDOWS\system32\User32.dll [2004-08-04 13:00] - [2008-04-14 22:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\WINDOWS\system32\userinit.exe [2004-08-04 13:00] - [2008-04-14 22:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\WINDOWS\system32\rpcss.dll [2004-08-04 13:00] - [2009-02-09 11:53] - 0401408 ____A (Microsoft Corporation) a37311d9d628c1042a2836731787f0f3 ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected. C:\WINDOWS\system32\Drivers\volsnap.sys [2004-08-04 13:00] - [2008-04-14 21:31] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================