Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014 Ran by mojojo (administrator) on MOJOJO-KOMPUTER on 07-01-2014 18:03:35 Running from C:\Users\mojojo\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\SamsungFastStart\SmartRestarter.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2149160 2010-05-21] (Synaptics Incorporated) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [761024 2013-12-13] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Badoo Desktop] - C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe HKCU\...\Run: [SSync] - C:\Users\mojojo\AppData\Roaming\SSync\SSync.exe [36864 2013-04-09] () HKCU\...\Run: [Steam] - D:\Program Files (x86)\steam\Steam.exe [1823656 2013-12-11] (Valve Corporation) HKCU\...\Run: [OMESupervisor] - C:\Users\mojojo\AppData\Local\omesuperv.exe [2239256 2013-12-24] () HKCU\...\Run: [IPLA!] - C:\Program Files (x86)\ipla\ipla.exe [21321312 2013-12-05] (Redefine Sp z o.o.) HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\mojojo\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKCU\...\Run: [SCheck] - C:\Users\mojojo\AppData\Roaming\SCheck\SCheck.exe [37376 2013-12-09] () HKCU\...\Run: [Snoozer] - C:\Users\mojojo\AppData\Roaming\Snz\Snz.exe [1209624 2013-12-24] () HKCU\...\Run: [Intermediate] - C:\Users\mojojo\AppData\Roaming\Intermediate\Intermediate.exe [37376 2013-12-09] () AppInit_DLLs: C:\Windows\System32\nvinitx.dll [266448 2013-05-12] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [214448 2013-05-12] (NVIDIA Corporation) Startup: C:\Users\mojojo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk ShortcutTarget: IMVU.lnk -> C:\Users\mojojo\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.fbdownloader.com/?channel=msus200fbdgy6 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.v9.com/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=1372003647 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://search.fbdownloader.com/search.php?channel=msus200fbdgy6&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKCU - {8A244612-A1F7-11E0-95C0-E71F4824019B} URL = http://badoo.com/startpage/?source=bsb&q={searchTerms} SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://search.fbdownloader.com/search.php?channel=msus200fbdgy6&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: IEToolbar.BHO - {1d970ed5-3eda-438d-bffd-715931e2775b} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: OfferMosquito - {82B16A3D-F03E-4565-A532-666B219C9A53} - C:\Users\mojojo\AppData\Local\ext_offermosquito\OfferMosquitoIEPlaceholder.dll (Bebo Media Ltd) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: W2PBrowser Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: ChromeFrame BHO - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files (x86)\Google\Chrome Frame\Application\31.0.1650.63\npchrome_frame.dll (Google Inc.) Toolbar: HKLM-x32 - MoneyMillionaire Toolbar - {d28c7e56-2cc6-415c-8727-d71334085926} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - No File Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation) Handler-x32: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files (x86)\Google\Chrome Frame\Application\31.0.1650.63\npchrome_frame.dll (Google Inc.) Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Chrome: ======= CHR HomePage: hxxp://samsung.msn.com/ CHR RestoreOnStartup: "chrome://newtab/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Unity Player) - C:\Users\mojojo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (James White) - C:\Users\mojojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3_0 CHR Extension: (YouTube) - C:\Users\mojojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Classic Games) - C:\Users\mojojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbofnbeakdognkanffmpldbjgkblljkh\0.0.0.4_0 CHR Extension: (Talking Tom Cat 2) - C:\Users\mojojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lenalfnmlbapkomcbobjfdmlbbmdpeef\2.3.1_0 CHR Extension: (Planner 5D) - C:\Users\mojojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcafejemebbngbglfoinpoaannbihjna\1.2.0.4_0 CHR Extension: (Google Wallet) - C:\Users\mojojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR Extension: (Adblock Pro) - C:\Users\mojojo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch\2.8_0 CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\mojojo\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx CHR HKLM-x32\...\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files (x86)\Deskperience\Word Capture\wcxChrome.crx ==================== Services (Whitelisted) ================= R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1358944 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 Hamachi2Svc; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2210640 2013-11-29] (LogMeIn Inc.) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-08-21] () S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () S2 DiscountfinderService; "C:\ProgramData\Odkrywca Rabatów\DFService.exe" [x] ==================== Drivers (Whitelisted) ==================== R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 WinRing0_1_2_0; \??\D:\Program Files (x86)\iVeeSoft\iGame Capture\Driver\WinRing0x64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-07 18:03 - 2014-01-07 18:04 - 00016198 _____ C:\Users\mojojo\Downloads\FRST.txt 2014-01-07 18:03 - 2014-01-07 18:03 - 00000000 ____D C:\FRST 2014-01-07 18:00 - 2014-01-07 18:01 - 01931762 _____ (Farbar) C:\Users\mojojo\Downloads\FRST64.exe 2014-01-07 17:17 - 2014-01-07 17:17 - 00000000 ____H C:\ProgramData\cm-lock 2014-01-02 16:53 - 2014-01-02 16:53 - 02167296 _____ C:\Users\mojojo\Downloads\W03-SZ-Modele zarzadzania syst.ppt 2013-12-29 22:35 - 2013-12-29 22:35 - 00001535 _____ C:\Users\mojojo\AppData\Local\recently-used.xbel 2013-12-29 21:51 - 2013-12-29 21:53 - 00000000 ____D C:\Program Files\GIMP 2 2013-12-28 13:27 - 2013-12-10 21:12 - 00722370 ____N C:\Users\mojojo\Downloads\_00_1.jpeg 2013-12-28 13:27 - 2013-12-10 21:12 - 00526841 ____N C:\Users\mojojo\Downloads\12.jpeg 2013-12-28 13:26 - 2013-12-28 13:27 - 01124634 _____ C:\Users\mojojo\Downloads\zadanie_na_zarzadzanie.zip 2013-12-27 22:02 - 2013-12-27 22:04 - 00000000 ____D C:\Users\mojojo\Desktop\Nowy folder (4) 2013-12-25 18:22 - 2013-12-25 18:22 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\Snz 2013-12-25 18:22 - 2013-12-25 18:22 - 00000000 ____D C:\Users\mojojo\AppData\Local\ext_offermosquito 2013-12-24 23:31 - 2013-12-24 23:31 - 00000000 _____ C:\dummy.wav 2013-12-24 20:44 - 2013-12-24 20:44 - 02239256 _____ C:\Users\mojojo\AppData\Local\omesuperv.exe 2013-12-23 21:28 - 2013-12-23 21:28 - 00000000 ____D C:\Users\mojojo\Documents\SimCity 2013-12-23 21:12 - 2013-12-23 21:12 - 00000912 _____ C:\Users\Public\Desktop\SimCity™.lnk 2013-12-23 21:12 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2013-12-23 21:12 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2013-12-23 21:12 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2013-12-23 21:12 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2013-12-23 21:12 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2013-12-23 21:12 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2013-12-23 21:12 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2013-12-22 17:56 - 2013-12-22 17:56 - 00000000 ____D C:\Users\mojojo\.mm 2013-12-22 17:40 - 2013-12-22 18:50 - 00000000 ____D C:\ProgramData\Odkrywca Rabatów 2013-12-22 17:40 - 2013-12-22 17:40 - 00000000 ____D C:\Program Files\WinPcap 2013-12-22 12:46 - 2013-12-22 12:46 - 00000000 ____D C:\ProgramData\SystemRequirementsLab 2013-12-22 12:46 - 2013-12-22 12:46 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab 2013-12-20 15:47 - 2013-12-29 22:05 - 00000000 ____D C:\Users\mojojo\Desktop\Nowy folder (3) 2013-12-20 10:49 - 2014-01-07 17:19 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\newnext.me 2013-12-20 10:49 - 2013-12-20 15:57 - 00000000 ____D C:\Users\mojojo\AppData\Local\Mobogenie 2013-12-20 10:49 - 2013-12-20 15:42 - 00000069 _____ C:\Users\mojojo\daemonprocess.txt 2013-12-20 10:49 - 2013-12-20 11:20 - 00000000 ____D C:\Users\mojojo\AppData\Local\genienext 2013-12-20 10:49 - 2013-12-20 10:49 - 00000000 ____D C:\Users\mojojo\Documents\Mobogenie 2013-12-20 10:49 - 2013-12-20 10:49 - 00000000 ____D C:\Users\mojojo\AppData\Local\cache 2013-12-20 10:49 - 2013-12-20 10:49 - 00000000 ____D C:\Users\mojojo\.android 2013-12-20 10:48 - 2013-12-20 15:57 - 00000000 ____D C:\Program Files (x86)\Mobogenie 2013-12-20 02:36 - 2013-12-20 02:36 - 00000000 ____D C:\Users\mojojo\Desktop\Nowy folder (2) 2013-12-20 02:15 - 2013-12-20 02:15 - 00000000 ____D C:\Program Files (x86)\CodeMeter 2013-12-18 17:42 - 2013-12-26 12:46 - 00001027 _____ C:\Windows\SysWOW64\debug.log 2013-12-18 14:56 - 2013-12-18 14:56 - 00000000 ____D C:\Program Files (x86)\PlayReady 2013-12-18 14:47 - 2014-01-07 17:19 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\ipla 2013-12-18 14:47 - 2013-12-18 15:35 - 00000000 ____D C:\ProgramData\ipla 2013-12-18 14:47 - 2013-12-18 14:47 - 00000911 _____ C:\Users\Public\Desktop\ipla.lnk 2013-12-18 14:47 - 2013-12-18 14:47 - 00000000 ____D C:\ProgramData\RDRM 2013-12-18 14:46 - 2013-12-18 14:49 - 00000000 ____D C:\Program Files (x86)\ipla 2013-12-18 14:46 - 2013-12-18 14:46 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll 2013-12-18 14:46 - 2013-12-18 14:46 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2013-12-17 12:33 - 2013-12-29 22:40 - 00000000 ____D C:\Users\mojojo\Desktop\obrazki 2013-12-16 21:33 - 2013-12-16 21:33 - 00003202 _____ C:\Windows\System32\Tasks\{EAFB1597-BC08-4E10-A3E9-92C8ACFA2340} 2013-12-13 21:57 - 2013-12-13 21:58 - 00000000 ____D C:\Users\mojojo\Desktop\plyta 2013-12-13 21:08 - 2013-12-23 22:45 - 00000000 ____D C:\Users\mojojo\Desktop\Nowy folder 2013-12-12 02:09 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-12 02:09 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-12 02:09 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-12 02:09 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-12 02:07 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 02:07 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 02:07 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 02:07 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-12 02:07 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-12 02:07 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-12 02:07 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 02:07 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 02:07 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-12 02:07 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-12 02:07 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 02:07 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 02:07 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-12 02:07 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-12 02:07 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-12 02:07 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-12 02:07 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-12 02:07 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 02:07 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-12 02:07 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-12 02:07 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-12 02:07 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 02:07 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 02:07 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-12 02:07 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-12 02:07 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 02:07 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 02:07 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-12 02:07 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-12 02:07 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-12 02:07 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 23:14 - 1997-08-26 12:06 - 00315904 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe 2013-12-11 17:53 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 17:53 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 17:53 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 17:53 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 17:53 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 17:53 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 17:53 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 17:53 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 17:53 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 17:53 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 17:53 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 17:53 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 17:53 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 17:53 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 17:53 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 17:53 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 17:53 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 17:53 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 17:53 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys ==================== One Month Modified Files and Folders ======= 2014-01-07 18:04 - 2014-01-07 18:03 - 00016198 _____ C:\Users\mojojo\Downloads\FRST.txt 2014-01-07 18:03 - 2014-01-07 18:03 - 00000000 ____D C:\FRST 2014-01-07 18:01 - 2014-01-07 18:00 - 01931762 _____ (Farbar) C:\Users\mojojo\Downloads\FRST64.exe 2014-01-07 17:57 - 2013-06-03 20:05 - 00001048 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-07 17:26 - 2010-12-29 15:47 - 01173687 _____ C:\Windows\WindowsUpdate.log 2014-01-07 17:25 - 2009-07-14 05:45 - 00014144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-07 17:25 - 2009-07-14 05:45 - 00014144 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-07 17:23 - 2013-06-03 20:35 - 00000000 ____D C:\ProgramData\MFAData 2014-01-07 17:21 - 2013-11-20 16:08 - 00000000 ____D C:\Users\mojojo\AppData\Local\LogMeIn Hamachi 2014-01-07 17:19 - 2013-12-20 10:49 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\newnext.me 2014-01-07 17:19 - 2013-12-18 14:47 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\ipla 2014-01-07 17:17 - 2014-01-07 17:17 - 00000000 ____H C:\ProgramData\cm-lock 2014-01-07 17:17 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-07 17:17 - 2009-07-14 05:51 - 00087674 _____ C:\Windows\setupact.log 2014-01-07 12:34 - 2010-12-29 00:10 - 00328114 _____ C:\Windows\PFRO.log 2014-01-07 01:12 - 2013-11-06 17:12 - 00000292 _____ C:\Windows\Tasks\FoxTab.job 2014-01-06 20:12 - 2013-06-21 18:21 - 00000000 ____D C:\Program Files (x86)\Origin 2014-01-04 21:22 - 2010-12-29 16:23 - 00737980 _____ C:\Windows\system32\perfh015.dat 2014-01-04 21:22 - 2010-12-29 16:23 - 00154636 _____ C:\Windows\system32\perfc015.dat 2014-01-04 21:22 - 2009-07-14 06:13 - 01662556 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-02 16:53 - 2014-01-02 16:53 - 02167296 _____ C:\Users\mojojo\Downloads\W03-SZ-Modele zarzadzania syst.ppt 2013-12-29 22:46 - 2013-06-08 16:55 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\Skype 2013-12-29 22:40 - 2013-12-17 12:33 - 00000000 ____D C:\Users\mojojo\Desktop\obrazki 2013-12-29 22:40 - 2013-08-22 20:48 - 00000000 ____D C:\Users\mojojo\.gimp-2.8 2013-12-29 22:35 - 2013-12-29 22:35 - 00001535 _____ C:\Users\mojojo\AppData\Local\recently-used.xbel 2013-12-29 22:05 - 2013-12-20 15:47 - 00000000 ____D C:\Users\mojojo\Desktop\Nowy folder (3) 2013-12-29 21:53 - 2013-12-29 21:51 - 00000000 ____D C:\Program Files\GIMP 2 2013-12-28 13:27 - 2013-12-28 13:26 - 01124634 _____ C:\Users\mojojo\Downloads\zadanie_na_zarzadzanie.zip 2013-12-27 22:04 - 2013-12-27 22:02 - 00000000 ____D C:\Users\mojojo\Desktop\Nowy folder (4) 2013-12-26 12:46 - 2013-12-18 17:42 - 00001027 _____ C:\Windows\SysWOW64\debug.log 2013-12-25 18:22 - 2013-12-25 18:22 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\Snz 2013-12-25 18:22 - 2013-12-25 18:22 - 00000000 ____D C:\Users\mojojo\AppData\Local\ext_offermosquito 2013-12-25 18:22 - 2013-07-13 10:07 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\Intermediate 2013-12-25 18:21 - 2013-06-03 20:05 - 00000000 ____D C:\Users\mojojo\AppData\Local\Google 2013-12-24 23:31 - 2013-12-24 23:31 - 00000000 _____ C:\dummy.wav 2013-12-24 20:44 - 2013-12-24 20:44 - 02239256 _____ C:\Users\mojojo\AppData\Local\omesuperv.exe 2013-12-23 22:45 - 2013-12-13 21:08 - 00000000 ____D C:\Users\mojojo\Desktop\Nowy folder 2013-12-23 22:44 - 2013-06-13 11:52 - 00000000 ____D C:\Users\mojojo\AppData\Local\CrashDumps 2013-12-23 21:28 - 2013-12-23 21:28 - 00000000 ____D C:\Users\mojojo\Documents\SimCity 2013-12-23 21:28 - 2013-06-21 18:22 - 00000000 ____D C:\ProgramData\Origin 2013-12-23 21:28 - 2013-06-21 12:59 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-12-23 21:12 - 2013-12-23 21:12 - 00000912 _____ C:\Users\Public\Desktop\SimCity™.lnk 2013-12-22 18:50 - 2013-12-22 17:40 - 00000000 ____D C:\ProgramData\Odkrywca Rabatów 2013-12-22 17:56 - 2013-12-22 17:56 - 00000000 ____D C:\Users\mojojo\.mm 2013-12-22 17:56 - 2013-06-03 19:49 - 00000000 ____D C:\Users\mojojo 2013-12-22 17:40 - 2013-12-22 17:40 - 00000000 ____D C:\Program Files\WinPcap 2013-12-22 12:46 - 2013-12-22 12:46 - 00000000 ____D C:\ProgramData\SystemRequirementsLab 2013-12-22 12:46 - 2013-12-22 12:46 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab 2013-12-21 15:31 - 2013-11-20 16:09 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\.minecraft 2013-12-20 16:24 - 2013-10-25 19:35 - 00000000 ____D C:\Users\mojojo\Desktop\pazdziernik 2013-12-20 15:57 - 2013-12-20 10:49 - 00000000 ____D C:\Users\mojojo\AppData\Local\Mobogenie 2013-12-20 15:57 - 2013-12-20 10:48 - 00000000 ____D C:\Program Files (x86)\Mobogenie 2013-12-20 15:42 - 2013-12-20 10:49 - 00000069 _____ C:\Users\mojojo\daemonprocess.txt 2013-12-20 11:20 - 2013-12-20 10:49 - 00000000 ____D C:\Users\mojojo\AppData\Local\genienext 2013-12-20 10:49 - 2013-12-20 10:49 - 00000000 ____D C:\Users\mojojo\Documents\Mobogenie 2013-12-20 10:49 - 2013-12-20 10:49 - 00000000 ____D C:\Users\mojojo\AppData\Local\cache 2013-12-20 10:49 - 2013-12-20 10:49 - 00000000 ____D C:\Users\mojojo\.android 2013-12-20 02:36 - 2013-12-20 02:36 - 00000000 ____D C:\Users\mojojo\Desktop\Nowy folder (2) 2013-12-20 02:15 - 2013-12-20 02:15 - 00000000 ____D C:\Program Files (x86)\CodeMeter 2013-12-18 17:45 - 2013-09-12 11:20 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-18 17:45 - 2013-09-12 11:20 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-18 15:35 - 2013-12-18 14:47 - 00000000 ____D C:\ProgramData\ipla 2013-12-18 14:56 - 2013-12-18 14:56 - 00000000 ____D C:\Program Files (x86)\PlayReady 2013-12-18 14:49 - 2013-12-18 14:46 - 00000000 ____D C:\Program Files (x86)\ipla 2013-12-18 14:47 - 2013-12-18 14:47 - 00000911 _____ C:\Users\Public\Desktop\ipla.lnk 2013-12-18 14:47 - 2013-12-18 14:47 - 00000000 ____D C:\ProgramData\RDRM 2013-12-18 14:46 - 2013-12-18 14:46 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll 2013-12-18 14:46 - 2013-12-18 14:46 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2013-12-17 20:27 - 2013-06-05 20:43 - 00000000 ____D C:\Users\mojojo\AppData\Roaming\PhotoScape 2013-12-17 18:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-16 21:33 - 2013-12-16 21:33 - 00003202 _____ C:\Windows\System32\Tasks\{EAFB1597-BC08-4E10-A3E9-92C8ACFA2340} 2013-12-16 21:31 - 2013-06-08 17:21 - 00000000 ____D C:\Users\mojojo\Documents\Youcam 2013-12-15 01:24 - 2013-07-30 22:44 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 01:22 - 2013-07-13 12:13 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-13 21:58 - 2013-12-13 21:57 - 00000000 ____D C:\Users\mojojo\Desktop\plyta 2013-12-13 15:42 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-12 16:11 - 2009-07-14 05:45 - 05023024 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-12 02:08 - 2013-08-19 21:27 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-10 21:12 - 2013-12-28 13:27 - 00722370 ____N C:\Users\mojojo\Downloads\_00_1.jpeg 2013-12-10 21:12 - 2013-12-28 13:27 - 00526841 ____N C:\Users\mojojo\Downloads\12.jpeg 2013-12-08 15:07 - 2009-07-14 06:08 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT Some content of TEMP: ==================== C:\Users\mojojo\AppData\Local\Temp\65422uninstall.exe C:\Users\mojojo\AppData\Local\Temp\a2zLyrics_1060-8102_v122.exe C:\Users\mojojo\AppData\Local\Temp\bdfilters.dll C:\Users\mojojo\AppData\Local\Temp\bitool.dll C:\Users\mojojo\AppData\Local\Temp\bi_cleaner.exe C:\Users\mojojo\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\mojojo\AppData\Local\Temp\crtB4BF.tmp.exe C:\Users\mojojo\AppData\Local\Temp\FastDownload.exe C:\Users\mojojo\AppData\Local\Temp\ipl94E3.tmp.exe C:\Users\mojojo\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\mojojo\AppData\Local\Temp\mconduitinstaller.exe C:\Users\mojojo\AppData\Local\Temp\mism.exe C:\Users\mojojo\AppData\Local\Temp\SkypeSetup.exe C:\Users\mojojo\AppData\Local\Temp\Sqlite3.dll C:\Users\mojojo\AppData\Local\Temp\SRLDetectionLibrary7548733065284226804.dll C:\Users\mojojo\AppData\Local\Temp\swt-win32-3349.dll C:\Users\mojojo\AppData\Local\Temp\utt8E23.tmp.exe C:\Users\mojojo\AppData\Local\Temp\_is88ED.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-01 14:19 ==================== End Of Log ============================