Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-08-2013 Ran by Administrator (administrator) on 28-08-2013 17:50:13 Running from C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Atheros) C:\WINDOWS\system32\acs.exe (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe () C:\Documents and Settings\All Users\Dane aplikacji\IBUpdaterService\ibsvc.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe () C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe (Prolific Technology Inc.) C:\WINDOWS\system32\IoctlSvc.exe () C:\WINDOWS\system32\PnkBstrA.exe () C:\WINDOWS\system32\PnkBstrB.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [19573352 2010-09-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13880424 2011-01-07] (NVIDIA Corporation) HKLM\...\Run: [nwiz] - C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1753192 2010-11-04] () HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [1443072 2008-02-20] (ESET) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-08-07] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated) HKLM\...\Run: [dideap] - C:\Documents and Settings\Administrator\Dane aplikacji\dideap.dll [155648 2013-07-05] (Broadcom Corporation) HKLM\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) HKCU\...\Run: [DAEMON Tools Lite] - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x] HKCU\...\Run: [Overwolf] - C:\Program Files\Overwolf\Overwolf.exe -silent [x] HKCU\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKCU\...\Run: [MSConfig] - C:\Documents and Settings\Administrator\leajbjp.exe [49671168 2013-02-10] () HKCU\...\Run: [PC Performer43885.exe] - C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1C0.tmp [6077 2013-07-08] () <===== ATTENTION HKCU\...\Run: [RGSC] - F:\gta\Rockstar Games Social Club\RGSCLauncher.exe /silent [x] MountPoints2: {5f525b56-1352-11e0-9fe7-806d6172696f} - K:\Autorun.exe HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Nero\Lib\NMFirstStart.exe [ 2008-02-28] (Nero AG) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\TP-LINK Wireless Configuration Utility.lnk ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://alawar.pl URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://pl.v9.com/?utm_source=b&utm_medium=nps SearchScopes: HKLM - DefaultScope {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59} URL = http://search.imesh.com/web?src=ieb&systemid=1&q={searchTerms} SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=119370&babsrc=SP_ss_gin2g&mntrId=843664700222AC86 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=119370&babsrc=SP_ss_gin2g&mntrId=843664700222AC86 SearchScopes: HKCU - {1F096B29-E9DA-4D64-8D63-936BE7762CC5} URL = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=84369321000000000000001d7d96b835&tlver=1.4.19.19&affID=19949 SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59} URL = http://search.imesh.com/web?src=ieb&systemid=1&q={searchTerms} SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9} URL = http://www.daemon-search.com/search/web?q={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678 SearchScopes: HKCU - {B0913AE6-ECE6-49BA-B228-404620E2EE20} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=FC81F599-06B1-4456-9A4A-499B3E0CAB17&apn_sauid=C4C7E94C-10BD-4383-88E0-D366A6A99878 BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Bcool Class - {8FC51463-2E71-7EC4-737B-DABC51BCF47E} - C:\Documents and Settings\All Users\Dane aplikacji\Bcool\bhoclass.dll () BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll No File BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) Toolbar: HKLM - No Name - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - No File Toolbar: HKLM - No Name - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File Toolbar: HKLM - No Name - !{30F9B915-B755-4826-820B-08FBA6BD249D} - No File Toolbar: HKLM - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No File Toolbar: HKLM - No Name - !{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: ipp - No CLSID Value - Handler: msdaipp - No CLSID Value - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog5 03 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog9 01 mswsock.dll File Not found () Winsock: Catalog9 02 mswsock.dll File Not found () Winsock: Catalog9 03 mswsock.dll File Not found () Winsock: Catalog9 04 mswsock.dll File Not found () Winsock: Catalog9 05 mswsock.dll File Not found () Winsock: Catalog9 06 mswsock.dll File Not found () Winsock: Catalog9 07 mswsock.dll File Not found () Winsock: Catalog9 08 mswsock.dll File Not found () Winsock: Catalog9 09 mswsock.dll File Not found () Winsock: Catalog9 10 mswsock.dll File Not found () Winsock: Catalog9 11 mswsock.dll File Not found () Winsock: Catalog9 12 mswsock.dll File Not found () Winsock: Catalog9 13 mswsock.dll File Not found () Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default FF user.js: detected! => C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\user.js FF SelectedSearchEngine: Google FF Homepage: https://www.google.pl/webhp?hl=pl&tab=ww FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll No File FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.12.709 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.709 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\searchplugins\babylon.xml FF SearchPlugin: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\searchplugins\BrowserProtect.xml FF SearchPlugin: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\searchplugins\conduit.xml FF SearchPlugin: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\searchplugins\delta.xml FF SearchPlugin: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\searchplugins\iMeshWebSearch.xml FF SearchPlugin: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\searchplugins\mywebsearch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\iMeshWebSearch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\v9.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\allegro-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\fbc-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\merlin-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\pwn-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\wikipedia-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\wp-pl.xml FF Extension: No Name - C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: Bcool - C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\Extensions\4fcb20dba350c@4fcb20dba3544.info FF Extension: Battlefield Play4Free - C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\Extensions\battlefieldplay4free@ea.com FF Extension: Conduit Engine - C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\Extensions\engine@conduit.com FF Extension: Babylon - C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\Extensions\ffxtlbr@babylon.com FF Extension: Vividas player plugin - C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\Extensions\player@vividas.com FF Extension: uTorrentBar Community Toolbar - C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\Extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} FF Extension: No Name - C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\7l4w3xdc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [jqs@sun.com] C:\Program Files\Java\jre6\lib\deploy\jqs\ff FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff Chrome: ======= CHR Extension: (Docs) - C:\DOCUME~1\ADMINI~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\DOCUME~1\ADMINI~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\DOCUME~1\ADMINI~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\DOCUME~1\ADMINI~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Bcool) - C:\DOCUME~1\ADMINI~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\kblmphpogdfcdifooapmpfigpjdipnhd\1.0_0 CHR Extension: (Gmail) - C:\DOCUME~1\ADMINI~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\crxBB.tmp CHR HKLM\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbar.crx CHR HKLM\...\Chrome\Extension: [kblmphpogdfcdifooapmpfigpjdipnhd] - C:\Documents and Settings\All Users\Dane aplikacji\Bcool\kblmphpogdfcdifooapmpfigpjdipnhd.crx CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Documents and Settings\Administrator\Pulpit\Toolbars\Skype for Chromium\skype_chrome_extension.crx ========================== Services (Whitelisted) ================= R2 ACS; C:\WINDOWS\system32\acs.exe [499796 2011-03-31] (Atheros) S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [19200 2008-02-20] (ESET) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [472320 2008-02-20] (ESET) R2 IBUpdaterService; C:\Documents and Settings\All Users\Dane aplikacji\IBUpdaterService\ibsvc.exe [622336 2013-07-08] () S3 jswpsapi; C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WPS\jswpsapi.exe [360529 2011-03-31] (wireless) S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 Nla; C:\Windows\System32\mswsock.dll [246784 2008-06-20] () S2 NOD32FiXTemDono; C:\WINDOWS\nod32fixtemdono.reg [568 2008-03-03] () S3 npggsvc; C:\WINDOWS\system32\GameMon.des [4598592 2012-04-18] (INCA Internet Co., Ltd.) R2 NVIDIA Performance Driver Service; C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [3575808 2008-12-11] () S3 OverwolfUpdaterService; C:\Program Files\Overwolf\OverwolfUpdater.exe [16600 2012-10-17] (Overwolf Ltd) R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [75064 2011-02-08] () R2 PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [214520 2011-12-28] () R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x] ==================== Drivers (Whitelisted) ==================== S3 Ambfilt; C:\Windows\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative) R3 AR9271; C:\Windows\System32\DRIVERS\athuw.sys [1763584 2011-07-28] (Atheros Communications, Inc.) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2013-04-26] () R2 eamon; C:\Windows\System32\DRIVERS\eamon.sys [39944 2008-02-20] (ESET) R1 easdrv; C:\Windows\System32\DRIVERS\easdrv.sys [29704 2008-02-20] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [71176 2008-02-20] (ESET) R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [30728 2008-02-20] (ESET) R1 epfwtdi; C:\Windows\System32\DRIVERS\epfwtdi.sys [54280 2008-02-20] (ESET) S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R3 JSWSCIMD; C:\Windows\System32\DRIVERS\jswscimd.sys [57440 2011-03-31] (Atheros Communications, Inc.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2013-04-26] () S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 Monfilt; C:\Windows\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.) R3 NVHDA; C:\Windows\System32\drivers\nvhda32.sys [100456 2010-11-12] (NVIDIA Corporation) R1 prodrv06; C:\Windows\System32\drivers\prodrv06.sys [52128 2003-10-10] (Protection Technology) R0 prohlp02; C:\Windows\System32\drivers\prohlp02.sys [62720 2003-10-10] (Protection Technology) R0 prosync1; C:\Windows\System32\drivers\prosync1.sys [6944 2003-09-06] (Protection Technology) S3 RTLTEAMING; C:\Windows\System32\DRIVERS\RTLTEAMING.SYS [29440 2009-10-12] (Realtek Semiconductor Corporation) S3 RTLVLAN; C:\Windows\System32\DRIVERS\RTLVLAN.SYS [17536 2009-02-16] (Realtek Semiconductor Corporation ) R2 RtNdPt5x; C:\Windows\System32\DRIVERS\RtNdPt5x.sys [22016 2008-07-09] (Realtek Semiconductor Corporation ) S3 s3legacy; C:\Windows\System32\DRIVERS\s3legacy.sys [65664 2001-08-17] (Microsoft Corporation) R0 sfhlp01; C:\Windows\System32\drivers\sfhlp01.sys [4832 2003-09-06] (Protection Technology) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2011-02-02] () R3 WSIMD; C:\Windows\System32\DRIVERS\wsimd.sys [58208 2011-03-31] (Atheros Communications, Inc.) U3 a57fihj5; C:\Windows\System32\Drivers\a57fihj5.sys [0 ] (Microsoft Corporation) S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [x] S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x] S4 IntelIde; No ImagePath S3 sony_ssm.sys; \??\C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\sony_ssm.sys [x] U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-28 17:49 - 2013-08-28 17:49 - 00000000 ____D C:\FRST 2013-08-28 16:22 - 2013-08-28 16:22 - 00101752 _____ C:\Documents and Settings\Administrator\Pulpit\OTL.Txt 2013-08-28 16:22 - 2013-08-28 16:22 - 00040090 _____ C:\Documents and Settings\Administrator\Pulpit\Extras.Txt 2013-08-28 16:15 - 2013-08-28 16:15 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Administrator\Pulpit\OTL.exe 2013-08-28 14:41 - 2013-08-28 14:41 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-08-28 14:41 - 2013-08-28 14:41 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\Malwarebytes 2013-08-28 14:41 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2013-08-09 00:15 - 2013-08-09 00:15 - 00098304 _____ C:\WINDOWS\Minidump\Mini080913-01.dmp 2013-08-08 11:28 - 2013-08-08 11:28 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\takie tamn 2013-08-08 11:25 - 2013-08-08 11:27 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\Gimbaza ;D 2013-08-07 12:10 - 2013-08-07 12:14 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\.minecraftzyczu 2013-08-07 12:09 - 2013-08-07 12:10 - 03727418 _____ (Zyczu) C:\Documents and Settings\Administrator\Pulpit\MinecraftZyczu.exe 2013-08-07 11:58 - 2013-08-28 15:15 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\.minecraft 2013-08-07 11:50 - 2013-08-07 11:53 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\Mapy 2013-08-07 11:50 - 2012-10-20 09:58 - 00246760 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2013-08-07 11:50 - 2012-10-20 09:58 - 00174056 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2013-08-07 11:50 - 2012-10-20 09:58 - 00174056 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2013-08-06 16:28 - 2013-08-07 11:58 - 00000000 __SHD C:\WINDOWS\system32\AI_RecycleBin 2013-08-06 16:22 - 2013-08-06 16:22 - 00000000 ____D C:\Documents and Settings\Administrator\minecraft 2013-08-04 18:51 - 2013-08-04 18:51 - 00098304 _____ C:\WINDOWS\Minidump\Mini080413-01.dmp 2013-07-31 20:09 - 2013-07-31 20:09 - 00003624 ____N C:\bootsqm.dat 2013-07-30 16:10 - 2013-07-30 16:10 - 00098304 _____ C:\WINDOWS\Minidump\Mini073013-02.dmp 2013-07-30 14:36 - 2013-07-30 14:35 - 00098304 _____ C:\WINDOWS\Minidump\Mini073013-01.dmp ==================== One Month Modified Files and Folders ======= 2013-08-28 17:50 - 2010-12-29 15:06 - 00000000 ___RD C:\Documents and Settings\Administrator\Pulpit 2013-08-28 17:49 - 2013-08-28 17:49 - 00000000 ____D C:\FRST 2013-08-28 17:49 - 2010-12-30 19:59 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie 2013-08-28 17:29 - 2011-02-02 19:24 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat 2013-08-28 17:05 - 2011-01-06 11:22 - 00001050 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-28 16:59 - 2012-06-10 11:34 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-08-28 16:57 - 2011-02-25 16:57 - 00000370 _____ C:\WINDOWS\Tasks\Updater.job 2013-08-28 16:22 - 2013-08-28 16:22 - 00101752 _____ C:\Documents and Settings\Administrator\Pulpit\OTL.Txt 2013-08-28 16:22 - 2013-08-28 16:22 - 00040090 _____ C:\Documents and Settings\Administrator\Pulpit\Extras.Txt 2013-08-28 16:15 - 2013-08-28 16:15 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Administrator\Pulpit\OTL.exe 2013-08-28 15:48 - 2010-12-29 15:06 - 00000000 __RHD C:\Documents and Settings\Administrator\Dane aplikacji 2013-08-28 15:15 - 2013-08-07 11:58 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\.minecraft 2013-08-28 14:41 - 2013-08-28 14:41 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-08-28 14:41 - 2013-08-28 14:41 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\Malwarebytes 2013-08-28 14:41 - 2010-12-29 15:53 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji 2013-08-28 14:41 - 2010-12-29 15:53 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2013-08-28 14:23 - 2011-01-06 11:22 - 00001046 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-28 14:23 - 2010-12-29 15:06 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-08-28 14:22 - 2012-11-26 19:25 - 00524288 _____ C:\WINDOWS\system32\config\ACS.evt 2013-08-28 14:22 - 2010-12-29 15:06 - 00032294 _____ C:\WINDOWS\SchedLgU.Txt 2013-08-28 14:22 - 2010-12-29 15:02 - 01750482 _____ C:\WINDOWS\WindowsUpdate.log 2013-08-28 14:09 - 2011-01-06 11:22 - 00000000 ____D C:\Program Files\Google 2013-08-27 10:38 - 2010-12-29 15:06 - 00000188 ___SH C:\Documents and Settings\Administrator\ntuser.ini 2013-08-26 10:05 - 2001-07-21 23:17 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2013-08-22 15:56 - 2013-03-08 17:23 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-22 15:56 - 2012-04-29 16:20 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-21 21:59 - 2012-06-10 11:34 - 00692104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2013-08-21 21:59 - 2011-05-22 10:11 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2013-08-20 22:44 - 2012-10-21 19:03 - 00445437 _____ C:\WINDOWS\setupapi.log 2013-08-19 16:32 - 2010-12-29 15:06 - 00000000 ___RD C:\Documents and Settings\Administrator\Moje dokumenty 2013-08-18 14:59 - 2012-04-29 15:40 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\uTorrent 2013-08-09 00:15 - 2013-08-09 00:15 - 00098304 _____ C:\WINDOWS\Minidump\Mini080913-01.dmp 2013-08-08 11:34 - 2011-12-03 23:22 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\My Games 2013-08-08 11:29 - 2012-10-21 19:49 - 00017349 _____ C:\WINDOWS\wmsetup.log 2013-08-08 11:28 - 2013-08-08 11:28 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\takie tamn 2013-08-08 11:27 - 2013-08-08 11:25 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\Gimbaza ;D 2013-08-08 10:45 - 2010-12-29 15:36 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-08-08 10:44 - 2012-06-28 19:02 - 00000000 ____D C:\Program Files\Electronic Arts 2013-08-07 12:14 - 2013-08-07 12:10 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\.minecraftzyczu 2013-08-07 12:10 - 2013-08-07 12:09 - 03727418 _____ (Zyczu) C:\Documents and Settings\Administrator\Pulpit\MinecraftZyczu.exe 2013-08-07 11:58 - 2013-08-06 16:28 - 00000000 __SHD C:\WINDOWS\system32\AI_RecycleBin 2013-08-07 11:53 - 2013-08-07 11:50 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\Mapy 2013-08-07 11:49 - 2011-08-20 08:24 - 00000000 ____D C:\Program Files\Java 2013-08-07 00:58 - 2012-10-29 16:33 - 00000216 _____ C:\WINDOWS\wiadebug.log 2013-08-07 00:58 - 2012-10-29 16:33 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-08-06 16:22 - 2013-08-06 16:22 - 00000000 ____D C:\Documents and Settings\Administrator\minecraft 2013-08-06 16:22 - 2010-12-29 15:06 - 00000000 ____D C:\Documents and Settings\Administrator 2013-08-06 14:10 - 2011-02-19 19:03 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\Skype 2013-08-04 18:51 - 2013-08-04 18:51 - 00098304 _____ C:\WINDOWS\Minidump\Mini080413-01.dmp 2013-07-31 20:09 - 2013-07-31 20:09 - 00003624 ____N C:\bootsqm.dat 2013-07-30 16:10 - 2013-07-30 16:10 - 00098304 _____ C:\WINDOWS\Minidump\Mini073013-02.dmp 2013-07-30 16:10 - 2012-01-10 18:03 - 00000000 ____D C:\WINDOWS\Minidump 2013-07-30 14:35 - 2013-07-30 14:36 - 00098304 _____ C:\WINDOWS\Minidump\Mini073013-01.dmp Files to move or delete: ==================== C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1C0.tmp C:\Documents and Settings\Administrator\leajbjp.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\aoe3-112-polish.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\AutoRun.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\AutoRunGUI.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\busunint.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD10.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD11.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD12.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD13.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD14.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD15.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD16.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD17.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD18.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD19.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD1A.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD1AF.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD1B.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD1C.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD1C2.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD1D.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD1E.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD1F.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD2.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD20.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD2040.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD21.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD22.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD23.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD24.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD3.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD349.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD4.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD5.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD6.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD7.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD8.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAD9.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EADA.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EADB.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EADC.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EADD.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EADE.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EADF.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\EAInstall.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\eauninstall.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\firefoxjre_exe.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\gg10.upgr.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\ICReinstall_DownloadManagerSetup.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\ICReinstall_TeamSpeak3-Client-win32_Downloader.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\ipl19F.tmp.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\jansi-32-git-Bukkit-1.4.6-R0.3-5-g82c58b5-b2590jnks.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\msvcr80.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\restorer1.0.0.1.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\setup_fsu_cid.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\Shortcut_SweetImSetup.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\SimPack.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\SkypeSetup.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\standalonepatcher.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\SWFXXLRT.DLL C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\syuy2.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\The Sims Life Stories_uninst.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\uninst1.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\UninstallEADM.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\unrar.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\zlib1.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\_is14BF.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\_is1ED8.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\_is2805.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\_is2D4D.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\_is78.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\_isD5C.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\_isFDA.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\~nsu.tmp\Au_.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{DF3423A1-D005-49F3-A81F-51EA5B5B917E}\ISSetup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{DF3423A1-D005-49F3-A81F-51EA5B5B917E}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{DC73659C-F4C1-442E-AE9E-F02950C25CB7}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{CF5F1D8D-7DF2-44C8-9BB0-52D54F45BCC6}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\GoogleCrashHandler.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\GoogleCrashHandler64.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\GoogleUpdate.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\GoogleUpdateBroker.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\GoogleUpdateOnDemand.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\GoogleUpdateSetup.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdate.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_am.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ar.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_bg.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_bn.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ca.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_cs.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_da.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_de.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_el.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_en-GB.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_en.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_es-419.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_es.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_et.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_fa.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_fi.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_fil.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_fr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_gu.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_hi.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_hr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_hu.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_id.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_is.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_it.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_iw.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ja.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_kn.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ko.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_lt.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_lv.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ml.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_mr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ms.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_nl.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_no.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_pl.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_pt-BR.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_pt-PT.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ro.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ru.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_sk.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_sl.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_sr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_sv.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_sw.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ta.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_te.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_th.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_tr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_uk.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_ur.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_vi.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_zh-CN.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\goopdateres_zh-TW.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\npGoogleUpdate3.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\psmachine.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{BD6CE1CC-F2F0-4BA3-A34A-A5A94D6C7563}\psuser.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{75224FC0-098C-4053-A6F7-3A2B3EF615CE}\Sims3Setup.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{6DC84079-CDA4-485A-BFC5-24121557B533}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{6B1D237F-AB14-4574-9041-FE28B1899036}\ISSetup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{6B1D237F-AB14-4574-9041-FE28B1899036}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{5C3528BD-146E-402A-8EED-F6A619DB4E82}\ISSetup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{5C3528BD-146E-402A-8EED-F6A619DB4E82}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{4E804204-C05B-4362-8AFC-1C3542533458}\ISSetup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{4E804204-C05B-4362-8AFC-1C3542533458}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\GoogleCrashHandler.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\GoogleCrashHandler64.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\GoogleUpdate.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\GoogleUpdateBroker.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\GoogleUpdateOnDemand.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\GoogleUpdateSetup.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdate.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_am.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ar.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_bg.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_bn.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ca.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_cs.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_da.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_de.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_el.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_en-GB.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_en.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_es-419.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_es.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_et.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_fa.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_fi.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_fil.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_fr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_gu.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_hi.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_hr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_hu.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_id.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_is.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_it.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_iw.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ja.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_kn.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ko.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_lt.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_lv.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ml.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_mr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ms.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_nl.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_no.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_pl.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_pt-BR.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_pt-PT.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ro.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ru.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_sk.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_sl.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_sr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_sv.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_sw.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ta.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_te.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_th.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_tr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_uk.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_ur.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_vi.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_zh-CN.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\goopdateres_zh-TW.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\npGoogleUpdate3.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\psmachine.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{424FC097-5DC0-4EB1-9CE9-1E500F612000}\psuser.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{3F70BC96-21E7-40B3-A3B0-ED1FEDCF3B2A}\ISSetup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{3F70BC96-21E7-40B3-A3B0-ED1FEDCF3B2A}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{35FA48F4-2351-46F3-AC40-6E598130A02D}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{357D9BEC-C3E4-4AEF-B639-341717BA55EC}\{319D91C6-3D44-436C-9F79-36C0D22372DC}\InstallHelper.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{23A31317-5A69-4776-BDBD-F1146F17CB2E}\ISSetup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{23A31317-5A69-4776-BDBD-F1146F17CB2E}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{1D3B8CAD-1981-4C76-BB6F-273CF7273F48}\{319D91C6-3D44-436C-9F79-36C0D22372DC}\InstallHelper.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{17A82E5C-E81E-49CA-A27C-8C5E7664A631}\ISSetup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\{17A82E5C-E81E-49CA-A27C-8C5E7664A631}\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\_dsFD9.tmp\demo32.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\_ds2804.tmp\demo32.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\VSD3098.tmp\dxredist\dxcheck.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\nslA5C.tmp\System.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\mtka_tmp\Alf.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\mtka_tmp\DFA.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\mtka_tmp\paul.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\mtka_tmp\rldata.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\mtka_tmp\secupacker_launcher.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MaAgent.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MAAuthProc.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MACLICX13.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MACLicX15.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MACSMANAGER.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MaCSMgr.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MaCSProHook.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\mapshapi.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\mapwij10.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MaSyncP.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MaWAMP.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MAWebControl.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MaWMP.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MPXBox.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\MtpAccess.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\UserShare.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\XSYNCClt.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\UpdateClient\MAFileUpdate.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdate.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdateBoot.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\MarkAny\ContentSafer\UpdateClient\MaUpdateClient.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\jna-Administrator\jna5569374524620199212.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP009.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP008.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP007.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP006.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP005.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP004.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP003.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP002.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP001.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\IXP000.TMP\VCREDI~3.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\ispB6.tmp\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\isp8D3.tmp\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\isp628.tmp\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\isp1A2.tmp\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\isp17D.tmp\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\isp1273.tmp\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\isp108D.tmp\_Setup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is1890775716\1105389_Setup.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is1890775716\DeltaTB.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is1095167443\455343_Setup.EXE C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is1095167443\DeltaTB.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is1095167443\QtraxInstaller.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is-VIEHD.tmp\itdownload.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is-VIEHD.tmp\_isetup\_shfoldr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is-EQ8PP.tmp\itdownload.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is-EQ8PP.tmp\_isetup\_shfoldr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is-7J6NR.tmp\itdownload.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is-7J6NR.tmp\_isetup\_shfoldr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is-51LL1.tmp\itdownload.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\is-51LL1.tmp\_isetup\_shfoldr.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\e8d32420-7ae1-4814-a668-6fb4eb026a15\CliSecureRT.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\DSOClient\D3DX9_43.DLL C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\DSOClient\FMODEX.DLL C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\DSOClient\FMOD_EVENT.DLL C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\DSOClient\FMOD_EVENT_NET.DLL C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\dotnetfx3530729.01\1033\dotnetfx35\x86\dotnetfx35langpack_x86pl.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\d6ebea43-a7f6-428d-ab33-ddb1ea1983ec\CliSecureRT.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\bye1A4.tmp\Disk1\setup.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\bus949B\BUSolution.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\a12825bd-15c9-4154-8729-0436821e9c1e\CliSecureRT.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\7ZipSfx.002\uTorrent.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\7ZipSfx.002\v9ht.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\7ZipSfx.001\v9ht.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\7ZipSfx.000\uTorrent.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\7ZipSfx.000\v9ht.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\7ZipSfx.000\zlib1.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\4.dir\InstallFlashPlayer.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\23.dir\InstallFlashPlayer.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\BabMaint.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\BExternal.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\BUSolution.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\BUSUninstall.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\ccp.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\ChromeToolbarSetup.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\CrxInstaller.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\GUninstaller.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\IEHelper.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\MyBabylonTB.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\Setup.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\1FDFD0CE-BAB0-7891-9FEA-34627C1CAA4C\Latest\sqlite3.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\0fc9221e-2e41-47bc-a46c-7d9bb48dcf66\CliSecureRT.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\._msigeplugin61\GoogleEarth.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\._msigeplugin61\program files\Google\Google Earth\plugin\earthps.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\._msigeplugin61\program files\Google\Google Earth\plugin\geplugin.exe C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\._msigeplugin61\program files\Google\Google Earth\plugin\ge_expat.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\._msigeplugin61\program files\Google\Google Earth\plugin\googleearth_free.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\._msigeplugin61\program files\Google\Google Earth\plugin\msvcp100.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\._msigeplugin61\program files\Google\Google Earth\plugin\msvcr100.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\._msigeplugin61\program files\Google\Google Earth\plugin\npgeplugin.dll C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\._msigeplugin61\program files\Google\Google Earth\plugin\plugin_ax.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2004-08-04 00:44] - [2008-04-14 19:21] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2004-08-04 00:44] - [2008-04-14 19:21] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2004-08-04 00:44] - [2008-04-14 19:21] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2004-08-04 00:44] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\Windows\System32\User32.dll [2004-08-04 00:44] - [2008-04-14 19:20] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2004-08-04 00:44] - [2008-04-14 19:21] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2004-08-04 00:36] - [2008-04-14 18:01] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================