Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-07-2013 04 Ran by Kouzi (administrator) on 11-07-2013 13:40:54 Running from C:\Users\Kouzi\Desktop\OTL Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: English(US) Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe () C:\ProgramData\DatacardService\DCService.exe (Avid Technology, Inc.) C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe () C:\Program Files (x86)\Common Files\Protexis\License Service\PSIService.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe () C:\Program Files (x86)\blueconnect\blueconnect.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (Creative Technology Ltd.) C:\Program Files (x86)\Creative\Creative Live! Cam\VideoFX\StartFX.exe (Creative Technology Ltd.) C:\Windows\V0270Mon.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Huawei Technologies Co., Ltd.) C:\Users\Kouzi\AppData\Roaming\blueconnect\ouc.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\SysWOW64\conime.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1584184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [egui] - "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice [2919168 2010-11-04] (ESET) HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [221184 2005-02-16] (InstallShield Software Corporation) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [138240 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [HW_OPENEYE_OUC_blueconnect] - "C:\Program Files (x86)\blueconnect\UpdateDog\ouc.exe" [110592 2009-12-31] (Huawei Technologies Co., Ltd.) MountPoints2: F - F:\APPInst.exe MountPoints2: {107e9733-36a4-11df-aaac-00248cbc597e} - F:\APPInst.exe MountPoints2: {70d75888-aa94-11de-a6a4-00248cbc597e} - .\Encryption Tool\MaxtorEncryption.exe MountPoints2: {78cfa852-3b59-11e1-9be2-00248cbc597e} - G:\AutoRun.exe MountPoints2: {85b89b08-bb96-11e2-98e6-00248cbc597e} - H:\LGAutoRun.exe MountPoints2: {911f48ba-b6f6-11e2-9da6-00248cbc597e} - H:\AutoRun.exe MountPoints2: {9579ed3a-d97f-11e0-8536-00248cbc597e} - G:\AutoRun.exe MountPoints2: {9579ed7b-d97f-11e0-8536-00248cbc597e} - H:\AutoRun.exe MountPoints2: {a229bf8b-2d77-11e1-b4c7-00248cbc597e} - H:\AutoRun.exe MountPoints2: {a3545479-4009-11df-b1e2-00248cbc597e} - F:\autorun.exe MountPoints2: {a9beafba-5d86-11e1-a7dd-00248cbc597e} - H:\AutoRun.exe MountPoints2: {bcde8c3b-6b53-11e1-86a9-00248cbc597e} - I:\AutoRun.exe MountPoints2: {f4d9a039-1f62-11e1-a37e-00248cbc597e} - H:\AutoRun.exe HKLM-x32\...\Run: [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start [81920 2005-02-16] (InstallShield Software Corporation) HKLM-x32\...\Run: [DigidesignMMERefresh] - "C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe" [77824 2010-05-05] (Avid Technology, Inc.) HKLM-x32\...\Run: [AVFX Engine] - "C:\Program Files (x86)\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [24576 2006-08-16] (Creative Technology Ltd.) HKLM-x32\...\Run: [V0270Mon.exe] - C:\Windows\V0270Mon.exe [32768 2006-09-26] (Creative Technology Ltd.) HKLM-x32\...\Run: [DataCardMonitor] - C:\Program Files (x86)\blueconnect\DataCardMonitor.exe [253952 2011-09-07] (Huawei Technologies Co., Ltd.) HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-11] (Microsoft Corporation) HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-11] (Microsoft Corporation) SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation) SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKLM SearchScopes: DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search/web?q={searchTerms} BHO-x32: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5