Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-11-2013 Ran by magdalena (administrator) on MAGDALENA-PC on 25-11-2013 14:46:33 Running from C:\Users\magdalena\Desktop Microsoft® Windows Vista™ Home Basic Service Pack 1 (X86) OS Language: English(US) Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\Program Files\SMINST\BLService.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe () C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1049896 2008-04-17] (Synaptics, Inc.) HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [54840 2007-05-09] (Hewlett-Packard) HKLM\...\Run: [hpWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [488752 2008-04-15] (Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [tuto4pc_pl_17] - [x] HKLM\...\Run: [20131121] - C:\Program Files\AVAST Software\Avast\Setup\emupdate\cb149475-b515-4441-8bde-94921ba3f288.exe [180184 2013-11-25] (AVAST Software) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Policies\system: [DisableLockWorkstation] 0 HKCU\...\Policies\system: [DisableChangePassword] 0 HKCU\...\Policies\Explorer: [NoLogoff] 0 MountPoints2: F - F:\AutoRun.exe MountPoints2: G - G:\AutoRun.exe MountPoints2: {21280626-690b-11df-ae24-001f1655816d} - F:\AutoRun.exe MountPoints2: {21280648-690b-11df-ae24-001f1655816d} - F:\AutoRun.exe MountPoints2: {2e70de88-d90c-11df-acb9-001f1655816d} - F:\BMW///sedistabela.exe MountPoints2: {2e70deba-d90c-11df-acb9-001f1655816d} - G:\LaunchU3.exe -a MountPoints2: {3ac138a7-a717-11df-8e3b-001f1655816d} - F:\AutoRun.exe MountPoints2: {40f27b5c-6b46-11df-8ff7-001f1655816d} - F:\AutoRun.exe MountPoints2: {5d6fbe5f-1ae9-11de-8d1e-001f1655816d} - F:\xdglur.bat MountPoints2: {8b86b146-f786-11de-a9f4-001f1655816d} - F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe MountPoints2: {b3529509-b524-11df-b898-001f1655816d} - F:\APPInst.exe MountPoints2: {ba3b6d08-d0b9-11df-8728-001f1655816d} - F:\AutoRun.exe MountPoints2: {e0e28688-2982-11e0-93eb-001f1655816d} - C:\Program Files\BearShare Applications\BearShare\BearShare.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_pl&c=91&bd=Pavilion&pf=cnnb HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_pl&c=91&bd=Pavilion&pf=cnnb HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_pl&c=91&bd=Pavilion&pf=cnnb SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: DivX Plus Web Player HTML5