Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-10-2013 Ran by PC (administrator) on RODZINAK on 31-10-2013 13:07:01 Running from C:\Users\PC\Downloads Windows 8 Enterprise (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe () C:\Program Files (x86)\NapiProjekt\napisy.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [GG] - C:\Users\PC\AppData\Local\GG\Application\gghub.exe [4009024 2013-09-02] (GG Network S.A.) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\PC\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\avastui.exe [3567800 2013-10-24] (AVAST Software) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x08A1D5FECFC9CE01 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] Chrome: ======= CHR HomePage: hxxp:// CHR RestoreOnStartup: "hxxp://{2975877E-D985-4994-92F9-B10C19E0293F}&mid=455727cf72fd47d39d339128c070202f-5cf069177ffef2074e2379ec93cbfd65efc9814e&lang=pl&ds=gm011&coid=avgtbdisgm&pr=sa&d=2013-10-24 22:02:16&v=" CHR Extension: (Google Docs) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (avast! Online Security) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2005.45_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ CHR Extension: (Gmail) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-24] (AVAST Software) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-24] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-10-24] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-24] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-24] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-24] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-10-24] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-24] () S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider) S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider) R3 RTL8023x64; C:\Windows\system32\DRIVERS\Rtnic64.sys [51712 2012-06-02] (Realtek Semiconductor Corporation ) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 ewusbnet; \SystemRoot\system32\DRIVERS\ewusbnet.sys [x] S3 hwdatacard; \SystemRoot\system32\DRIVERS\ewusbmdm.sys [x] S3 hwusbdev; \SystemRoot\system32\DRIVERS\ewusbdev.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-31 13:05 - C:\Users\PC\Downloads\BitTorrent( 2013-10-15 18:59 - 2013-10-15 18:58 - 00000000 ____D C:\Users\PC\AppData\Local\Google 2013-10-15 18:59 - 2013-08-30 16:15 - 00000000 ____D C:\Program Files (x86)\Google 2013-10-15 18:47 - 2013-10-15 18:47 - 00000000 ____D C:\Users\PC\AppData\Roaming\Macromedia 2013-10-15 15:36 - 2013-10-15 15:36 - 00001442 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-15 15:36 - 2013-10-15 15:36 - 00000020 ___SH C:\Users\PC\ntuser.ini 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\Ustawienia lokalne 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\Szablony 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\Moje dokumenty 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\Menu Start 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\Documents\Moje wideo 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\Documents\Moje obrazy 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\Documents\Moja muzyka 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\Dane aplikacji 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\AppData\Local\Historia 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 _SHDL C:\Users\PC\AppData\Local\Dane aplikacji 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 ____D C:\Users\PC\AppData\Roaming\Adobe 2013-10-15 15:36 - 2013-10-15 15:36 - 00000000 ____D C:\Users\PC\AppData\Local\VirtualStore 2013-10-15 15:33 - 2013-08-26 09:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-15 15:27 - 2013-08-26 09:26 - 00000000 ____D C:\Program Files (x86)\Mobile Partner 2013-10-13 10:38 - 2013-08-30 16:16 - 00093184 ____H C:\Users\Natusia i Pablo\Desktop\photothumb.db 2013-10-12 16:42 - 2013-08-30 16:15 - 00000000 ____D C:\Users\Natusia i Pablo\AppData\Roaming\PhotoScape 2013-10-10 20:28 - 2013-10-10 20:28 - 00281544 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-10 15:49 - 2013-08-26 11:29 - 00000000 ____D C:\Windows\system32\MRT 2013-10-10 15:49 - 2013-08-26 10:41 - 00003818 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-10 15:48 - 2013-08-26 11:29 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-04 14:44 - 2013-08-26 09:44 - 00000000 ____D C:\Users\Natusia i Pablo\AppData\Local\Mozilla 2013-10-02 02:38 - 2012-07-26 09:14 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-02 02:38 - 2012-07-26 09:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Natusia i Pablo\AppData\Local\Temp\GoogleSetup.exe C:\Users\Natusia i Pablo\AppData\Local\Temp\setup_fsu_cid.exe C:\Users\Natusia i Pablo\AppData\Local\Temp\uninst1.exe C:\Users\PC\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-30 15:29 ==================== End Of Log ============================