Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-12-2014 Ran by Magda (administrator) on MAGDA-KOMPUTER on 05-12-2014 18:23:04 Running from C:\Users\Magda\Downloads Loaded Profile: Magda (Available profiles: Magda) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Polski (Polska) Internet Explorer Version 9 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-16] (AVAST Software) HKU\S-1-5-21-378606110-1790107904-230257270-1000\...\Run: [Tok-Cirrhatus] => "C:\Users\Magda\AppData\Local\smss.exe" HKU\S-1-5-21-378606110-1790107904-230257270-1000\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-21-378606110-1790107904-230257270-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) CHR HKU\S-1-5-21-378606110-1790107904-230257270-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-378606110-1790107904-230257270-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl/ SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll No File BHO: No Name -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> No File BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{3E8D1742-8665-45EE-8468-B8E888FCD8F5}: [NameServer] 8.8.8.8 FireFox: ======== FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-01-16] Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.wp.pl/" CHR Profile: C:\Users\Magda\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avast Online Security) - C:\Users\Magda\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-03-03] CHR Extension: (Google Wallet) - C:\Users\Magda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-13] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-16] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-16] (AVAST Software) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-08-16] () R0 aswKbd; C:\Windows\system32\Drivers\aswKbd.sys [21576 2013-03-07] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-08-16] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-08-16] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-08-16] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-11-21] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [414520 2014-08-16] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [71944 2014-08-16] (AVAST Software) R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [56080 2013-12-19] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-08-16] () R1 ccnfd_1_10_0_2; system32\drivers\ccnfd_1_10_0_2.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-05 18:23 - 2014-12-05 18:23 - 00007088 _____ () C:\Users\Magda\Downloads\FRST.txt 2014-12-05 18:22 - 2014-12-05 18:23 - 00000000 ____D () C:\FRST 2014-12-05 18:20 - 2014-12-05 18:21 - 01110016 _____ (Farbar) C:\Users\Magda\Downloads\FRST.exe 2014-12-05 18:20 - 2014-12-05 18:20 - 00000000 _____ () C:\Windows\setuperr.log 2014-12-05 18:20 - 2014-12-05 18:20 - 00000000 _____ () C:\Windows\setupact.log 2014-12-04 22:59 - 2014-12-04 23:10 - 00000000 ____D () C:\Program Files\Digital Image Recovery 2014-12-04 22:59 - 2014-12-04 22:59 - 00000912 _____ () C:\Users\Magda\Desktop\Digital Image Recovery.lnk 2014-12-04 22:59 - 2014-12-04 22:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Digital Image Recovery 2014-12-04 22:57 - 2014-12-04 22:57 - 00754240 _____ ( ) C:\Users\Magda\Downloads\Digital-Image-Recovery(11446)-dp.exe 2014-12-04 22:57 - 2014-12-04 22:57 - 00592335 _____ () C:\Users\Magda\Downloads\dir(dobreprogramy.pl).zip 2014-12-04 21:32 - 2014-12-04 21:33 - 16245128 _____ (Elex do Brasil Participações Ltda) C:\Users\Magda\Downloads\yet_another_cleaner_sk_50537.exe 2014-11-28 19:16 - 2014-11-28 19:17 - 01800400 _____ () C:\Users\Magda\Downloads\Warzywa i owoce.3gp 2014-11-28 19:07 - 2014-11-28 19:08 - 05787277 _____ () C:\Users\Magda\Downloads\Centrum Usmiechu - Zdrowia Smaki.3gp 2014-11-28 18:53 - 2014-11-28 19:00 - 18751058 _____ () C:\Users\Magda\Downloads\Świat Małej Księżniczki -Nie lubię warzyw-.3gp 2014-11-27 20:39 - 2014-11-27 20:39 - 01153024 _____ () C:\Users\Magda\Downloads\zdrowe odżywianie(2).ppt 2014-11-27 20:37 - 2014-11-27 20:37 - 01153024 _____ () C:\Users\Magda\Downloads\zdrowe odżywianie.ppt 2014-11-27 19:59 - 2014-11-27 19:59 - 02851204 _____ () C:\Users\Magda\Downloads\Zasady prawidłowego żywienia (1).pptx 2014-11-27 19:57 - 2014-11-27 19:57 - 03014144 _____ () C:\Users\Magda\Downloads\sniadanie_daje_moc.ppt 2014-11-27 19:56 - 2014-11-27 19:57 - 06202368 _____ () C:\Users\Magda\Downloads\Porady dla rodzicow.ppt 2014-11-25 15:04 - 2014-11-25 15:05 - 06282752 _____ () C:\Users\Magda\Downloads\wybieram_zdrowie_i_zdrowe_odzywianie.ppt 2014-11-25 15:03 - 2014-11-25 15:03 - 05690880 _____ () C:\Users\Magda\Downloads\prawidlowe_zywienie_uczniow (2).ppt 2014-11-25 14:22 - 2014-11-25 14:22 - 07055360 _____ () C:\Users\Magda\Downloads\odzywianie.ppt 2014-11-25 14:18 - 2014-11-25 14:19 - 05158546 _____ () C:\Users\Magda\Downloads\sniadanie-daje-moc-sp-132.pptx 2014-11-24 20:08 - 2014-11-24 20:14 - 93283038 _____ () C:\Users\Magda\Downloads\07 Slalom 1983.avi 2014-11-22 18:04 - 2014-11-22 18:04 - 00546816 _____ () C:\Users\Magda\Downloads\stawiam_na_sniadanie (1).ppt 2014-11-22 18:02 - 2014-11-22 18:03 - 05690880 _____ () C:\Users\Magda\Downloads\prawidlowe_zywienie_uczniow (1).ppt 2014-11-20 18:01 - 2014-11-20 18:01 - 05688832 _____ () C:\Users\Magda\Downloads\prawidlowe_zywienie_uczniow.ppt 2014-11-20 17:58 - 2014-11-20 17:59 - 07572074 _____ () C:\Users\Magda\Downloads\wiem co jem.ppsx 2014-11-16 09:53 - 2014-11-16 09:53 - 00546816 _____ () C:\Users\Magda\Downloads\stawiam_na_sniadanie.ppt 2014-11-12 18:19 - 2014-11-12 18:19 - 01134080 _____ () C:\Users\Magda\Downloads\rozne_oblicza_cukru.ppt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-05 18:08 - 2013-01-16 11:22 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-05 17:43 - 2013-01-16 12:28 - 00001036 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-12-05 17:28 - 2013-01-16 11:21 - 03880034 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-05 17:28 - 2009-09-04 06:55 - 00675958 _____ () C:\Windows\system32\perfh019.dat 2014-12-05 17:28 - 2009-09-04 06:55 - 00132516 _____ () C:\Windows\system32\perfc019.dat 2014-12-05 17:28 - 2009-09-04 06:44 - 00697912 _____ () C:\Windows\system32\perfh015.dat 2014-12-05 17:28 - 2009-09-04 06:44 - 00134990 _____ () C:\Windows\system32\perfc015.dat 2014-12-05 17:19 - 2013-01-16 11:11 - 01214247 _____ () C:\Windows\WindowsUpdate.log 2014-12-05 13:15 - 2013-01-16 12:28 - 00001032 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-12-05 13:15 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-04 22:30 - 2013-09-30 20:45 - 00000000 ____D () C:\Users\Magda\AppData\Roaming\Skype 2014-12-03 22:13 - 2014-02-27 20:22 - 00000000 ___RD () C:\Program Files\Skype 2014-12-03 22:13 - 2013-09-30 20:45 - 00000000 ____D () C:\ProgramData\Skype 2014-11-26 22:08 - 2013-01-16 11:22 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-11-26 22:08 - 2013-01-16 11:22 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-26 20:51 - 2014-03-03 22:47 - 00002095 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-11-21 20:11 - 2013-01-16 18:14 - 00779536 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2014-11-14 18:13 - 2013-01-16 13:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2014-11-14 18:13 - 2013-01-16 13:48 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-11-06 16:54 - 2009-07-14 05:53 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-05 14:30 ==================== End Of Log ============================