Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-01-2015 03 Ran by Mikołaj at 2015-01-04 20:34:15 Run:1 Running from C:\Users\Mikołaj\Desktop\Downloads\FRST Loaded Profile: Mikołaj (Available profiles: Mikołaj) Boot Mode: Normal ============================================== Content of fixlist: ***************** ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR Extension: (Prezentacje Google) - C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-20] CHR Extension: (Dokumenty Google) - C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-20] CHR Extension: (Dysk Google) - C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-20] CHR Extension: (YouTube) - C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-20] CHR Extension: (Szukaj w Google) - C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-20] CHR Extension: (Arkusze Google) - C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-20] CHR Extension: (Google Wallet) - C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-20] CHR Extension: (Gmail) - C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-20] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-09-11] (Advanced Micro Devices, Inc.) [File not signed] R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed] R4 IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [X] 2015-01-03 22:47 - 2015-01-03 22:47 - 00000000 ___SD () C:\ComboFix 2015-01-03 22:47 - 2015-01-03 22:47 - 00000000 ____D () C:\Qoobox 2015-01-03 22:47 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-01-03 22:47 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-01-03 22:47 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-01-03 22:47 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-01-03 22:47 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-01-03 22:47 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-01-03 22:47 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-01-03 22:47 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-12-25 20:23 - 2014-12-25 20:23 - 00000000 ____D () C:\ProgramData\1078601655 2014-12-25 12:35 - 2014-12-25 12:35 - 00000000 ____D () C:\Users\Mikołaj\AppData\Roaming\RHEng 2014-12-25 12:35 - 2014-12-25 12:35 - 00000000 ____D () C:\Users\Mikołaj\AppData\Roaming\OpenCandy 2015-01-03 23:50 - 2009-07-14 05:45 - 00013584 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-03 23:50 - 2009-07-14 05:45 - 00013584 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 emptytemp: ***************** "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek directory not found. C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake directory not found. C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf directory not found. C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo directory not found. C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf directory not found. C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap directory not found. C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => Moved successfully. C:\Users\Mikołaj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia directory not found. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => Key deleted successfully. C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx => Moved successfully. AMD FUEL Service => Service stopped successfully. AMD FUEL Service => Service deleted successfully. ASGT => Service stopped successfully. ASGT => Service deleted successfully. IOMap => Unable to stop service IOMap => Error deleting Service C:\ComboFix => Moved successfully. C:\Qoobox => Moved successfully. C:\Windows\PEV.exe => Moved successfully. C:\Windows\MBR.exe => Moved successfully. C:\Windows\NIRCMD.exe => Moved successfully. C:\Windows\SWREG.exe => Moved successfully. C:\Windows\SWSC.exe => Moved successfully. C:\Windows\sed.exe => Moved successfully. C:\Windows\grep.exe => Moved successfully. C:\Windows\zip.exe => Moved successfully. C:\ProgramData\1078601655 => Moved successfully. C:\Users\Mikołaj\AppData\Roaming\RHEng => Moved successfully. C:\Users\Mikołaj\AppData\Roaming\OpenCandy => Moved successfully. Could not move "C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0" => Scheduled to move on reboot. Could not move "C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0" => Scheduled to move on reboot. EmptyTemp: => Removed 1.5 GB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-01-04 20:36:08)<= C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 => Is moved successfully. C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 => Is moved successfully. ==== End of Fixlog 20:36:08 ====