Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by toto (administrator) on TOTOLAPEK on 05-10-2013 00:40:27 Running from C:\Users\toto\Downloads\Nowy folder Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== () C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe (Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\drivers\x86\HerculesDJControlMP3.EXE (Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Ashampoo Development GmbH & Co. KG) C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe (Hercules®) C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe (Hercules®) C:\Program Files\Hercules\Audio\DJ Console Series\cpl2\HDJSeries2CPL.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe () C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_Vista.exe (Microsoft Corporation) C:\Windows\system32\wuauclt.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\system32\wuauclt.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [288040 2010-04-05] (Alps Electric Co., Ltd.) HKLM\...\Run: [Ashampoo Anti-Malware Guard] - C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe [3314176 2010-08-26] (Ashampoo Development GmbH & Co. KG) HKLM\...\Run: [Hercules DJ Series TrayAgent] - C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe [2914640 2013-05-10] (Hercules®) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) ==================== Internet (Whitelisted) ==================== BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Chrome: ======= CHR RestoreOnStartup: "hxxp://www.google.pl/" CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\toto\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\toto\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\toto\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\toto\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Freemake Video Converter) - C:\Users\toto\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\toto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Gmail) - C:\Users\toto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx ========================== Services (Whitelisted) ================= R2 AAMWService; C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe [1313184 2011-08-17] () R2 AAMW_WSC_Service_Vista; C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_Vista.exe [52616 2010-03-02] () R2 HerculesDJControlMP3; C:\Program Files\Hercules\Audio\DJ Console Series\drivers\x86\HerculesDJControlMP3.EXE [37376 2013-05-21] (Hercules®) R2 NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [4821296 2013-06-11] (Native Instruments GmbH) ==================== Drivers (Whitelisted) ==================== R3 AAMWRegFilter; C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter32.sys [18584 2010-01-20] () R3 ASW3Scan; C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS32.sys [17816 2010-06-16] () S3 Bulk; C:\Windows\System32\Drivers\HDJBulk.sys [220464 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) S3 HDJMidi; C:\Windows\System32\DRIVERS\HDJMidi.sys [241968 2013-05-21] (© Guillemot R&D, 2013. All rights reserved.) S3 ta6avs; C:\Windows\System32\Drivers\ta6avs.sys [347496 2012-12-18] (Native Instruments GmbH) S3 ta6usb_svc; C:\Windows\System32\Drivers\ta6usb.sys [77160 2012-12-18] (Native Instruments GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-05 00:42 - 2013-10-05 00:42 - 00602112 _____ (OldTimer Tools) C:\Users\toto\Downloads\OTL (1).exe 2013-10-05 00:41 - 2013-10-05 00:41 - 00602112 _____ (OldTimer Tools) C:\Users\toto\Downloads\OTL.exe 2013-10-05 00:41 - 2013-10-05 00:41 - 00602112 _____ (OldTimer Tools) C:\Users\toto\Downloads\OTL.com 2013-10-05 00:39 - 2013-10-05 00:39 - 00000000 ____D C:\FRST 2013-10-05 00:38 - 2013-10-05 00:38 - 00000000 ____D C:\Users\toto\Downloads\Nowy folder 2013-10-05 00:07 - 2013-10-05 00:07 - 00007609 _____ C:\Users\toto\AppData\Local\Resmon.ResmonCfg 2013-10-02 00:23 - 2013-10-02 00:23 - 00000000 ____D C:\Users\toto\Desktop\10minimix 2013-09-25 23:34 - 2013-09-25 23:39 - 243781632 _____ C:\Users\toto\Downloads\Rodzinka.pl.S05E08.PL.WEBRip.XviD-TROD4T.avi 2013-09-24 01:07 - 2013-09-24 01:07 - 00000000 ____D C:\Users\toto\Downloads\Kurs-SK 2013-09-24 00:38 - 2013-09-24 00:47 - 243806208 _____ C:\Users\toto\Downloads\Rodzinka.pl.S05E07.PL.WEBRip.XviD-TROD4T.avi 2013-09-24 00:21 - 2013-09-24 01:03 - 1225340376 _____ C:\Users\toto\Downloads\Kurs-SK.rar 2013-09-23 14:12 - 2013-09-23 14:42 - 1045430272 _____ C:\Users\toto\Downloads\Lot.PL.720p.part2.rar 2013-09-23 13:41 - 2013-09-23 14:12 - 1045430272 _____ C:\Users\toto\Downloads\Lot.PL.720p.part1.rar 2013-09-23 13:22 - 2013-09-23 13:40 - 647502952 _____ C:\Users\toto\Downloads\Lot.PL.720p.part3.rar 2013-09-18 23:03 - 2013-09-18 23:03 - 00067858 _____ C:\Users\toto\Downloads\Millerowie.Wer.e.the.Millers.2013.HDRip.XviD-BiDA.txt 2013-09-18 19:44 - 2013-09-18 20:05 - 735620336 _____ C:\Users\toto\Downloads\Millerowie.Wer.e.the.Millers.2013.HDRip.XviD-BiDA.avi 2013-09-16 21:58 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-16 21:58 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-16 21:58 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-16 21:58 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-16 21:58 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-16 21:58 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-16 21:58 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-14 17:20 - 2013-09-14 17:20 - 00000000 ____D C:\Users\toto\Desktop\nowy secior 2013-09-14 15:37 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-14 15:37 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-14 15:37 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-14 15:37 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-14 15:37 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-14 15:37 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-14 15:37 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-14 15:37 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-07 20:15 - 2013-09-07 20:16 - 00000000 ____D C:\Users\toto\Desktop\trap ==================== One Month Modified Files and Folders ======= 2013-10-05 00:42 - 2013-10-05 00:42 - 00602112 _____ (OldTimer Tools) C:\Users\toto\Downloads\OTL (1).exe 2013-10-05 00:41 - 2013-10-05 00:41 - 00602112 _____ (OldTimer Tools) C:\Users\toto\Downloads\OTL.exe 2013-10-05 00:41 - 2013-10-05 00:41 - 00602112 _____ (OldTimer Tools) C:\Users\toto\Downloads\OTL.com 2013-10-05 00:39 - 2013-10-05 00:39 - 00000000 ____D C:\FRST 2013-10-05 00:38 - 2013-10-05 00:38 - 00000000 ____D C:\Users\toto\Downloads\Nowy folder 2013-10-05 00:11 - 2011-04-12 07:08 - 00697912 _____ C:\Windows\system32\perfh015.dat 2013-10-05 00:11 - 2011-04-12 07:08 - 00134990 _____ C:\Windows\system32\perfc015.dat 2013-10-05 00:11 - 2010-11-20 23:01 - 01549696 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-05 00:07 - 2013-10-05 00:07 - 00007609 _____ C:\Users\toto\AppData\Local\Resmon.ResmonCfg 2013-10-05 00:07 - 2013-07-17 10:17 - 01446270 _____ C:\Windows\WindowsUpdate.log 2013-10-05 00:06 - 2013-07-17 10:52 - 00001032 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-04 23:53 - 2013-07-17 10:52 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-04 23:53 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-04 23:52 - 2009-07-14 06:53 - 00013776 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-04 23:43 - 2013-09-03 20:30 - 00000000 ____D C:\Users\toto\AppData\Roaming\Notepad++ 2013-10-04 23:43 - 2013-09-03 20:30 - 00000000 ____D C:\Program Files\Notepad++ 2013-10-04 21:38 - 2013-07-17 10:53 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-03 00:09 - 2009-07-14 06:39 - 00053390 _____ C:\Windows\setupact.log 2013-10-02 00:23 - 2013-10-02 00:23 - 00000000 ____D C:\Users\toto\Desktop\10minimix 2013-09-30 17:05 - 2009-07-14 06:34 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-30 17:05 - 2009-07-14 06:34 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-25 23:39 - 2013-09-25 23:34 - 243781632 _____ C:\Users\toto\Downloads\Rodzinka.pl.S05E08.PL.WEBRip.XviD-TROD4T.avi 2013-09-24 01:07 - 2013-09-24 01:07 - 00000000 ____D C:\Users\toto\Downloads\Kurs-SK 2013-09-24 01:03 - 2013-09-24 00:21 - 1225340376 _____ C:\Users\toto\Downloads\Kurs-SK.rar 2013-09-24 00:47 - 2013-09-24 00:38 - 243806208 _____ C:\Users\toto\Downloads\Rodzinka.pl.S05E07.PL.WEBRip.XviD-TROD4T.avi 2013-09-23 14:42 - 2013-09-23 14:12 - 1045430272 _____ C:\Users\toto\Downloads\Lot.PL.720p.part2.rar 2013-09-23 14:12 - 2013-09-23 13:41 - 1045430272 _____ C:\Users\toto\Downloads\Lot.PL.720p.part1.rar 2013-09-23 13:40 - 2013-09-23 13:22 - 647502952 _____ C:\Users\toto\Downloads\Lot.PL.720p.part3.rar 2013-09-18 23:03 - 2013-09-18 23:03 - 00067858 _____ C:\Users\toto\Downloads\Millerowie.Wer.e.the.Millers.2013.HDRip.XviD-BiDA.txt 2013-09-18 20:05 - 2013-09-18 19:44 - 735620336 _____ C:\Users\toto\Downloads\Millerowie.Wer.e.the.Millers.2013.HDRip.XviD-BiDA.avi 2013-09-18 19:44 - 2013-07-17 15:15 - 00000000 ____D C:\Program Files\JDownloader 2013-09-17 23:25 - 2009-07-14 06:33 - 00267936 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-16 23:27 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\pl-PL 2013-09-14 17:20 - 2013-09-14 17:20 - 00000000 ____D C:\Users\toto\Desktop\nowy secior 2013-09-07 20:16 - 2013-09-07 20:15 - 00000000 ____D C:\Users\toto\Desktop\trap Some content of TEMP: ==================== C:\Users\toto\AppData\Local\Temp\ICReinstall_JDownloaderSetup.exe C:\Users\toto\AppData\Local\Temp\sfamcc00001.dll C:\Users\toto\AppData\Local\Temp\sfextra.dll C:\Users\toto\AppData\Local\Temp\xmlUpdater.exe C:\Users\toto\AppData\Local\Temp\{EB81FC99-95B4-4ED2-9606-BCC838638264}-29.0.1547.62_29.0.1547.57_chrome_updater.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-01 15:41 ==================== End Of Log ============================