Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-01-2014 01 Ran by Kasia (administrator) on KOZERA-FADFCE0D on 02-01-2014 21:14:48 Running from C:\Documents and Settings\Kasia\Pulpit Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 6 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe (ArcaBit) C:\Program Files\ArcaBit\Common\ArcaConfSV.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (ArcaBit) C:\Program Files\ArcaBit\ArcaTools\ArcaBackup\ArcaBackupService.exe (ArcaBit) C:\Program Files\ArcaBit\ArcaUpdate\update.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (IObit) C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (TRACEBoard) C:\Program Files\MultitablicaBoard\TRACEBoardSrv.exe (MySQL AB) C:\xampp\mysql\bin\mysqld.exe (TRACEBoard) C:\Program Files\MultitablicaBoard\TRACEBoardSrv.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe (ArcaBit) C:\Program Files\ArcaBit\ArcaVir\ArcaMainSV.exe (WIBU-SYSTEMS AG) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\loggingserver.exe (ArcaBit) C:\Program Files\ArcaBit\Common\ArcaTasksService.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Agere Systems) C:\WINDOWS\AGRSMMSG.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe () C:\Program Files\Neostrada TP\CnxMon.exe (THOMSON Telecom Belgium) C:\Program Files\Thomson\SpeedTouch USB\dragdiag.exe (France Télécom R&D) C:\Program Files\Neostrada TP\TaskBarIcon.exe () C:\Program Files\Winamp\winampa.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\AVG Secure Search\vprot.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (ArcaBit) C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (GG Network S.A.) C:\Documents and Settings\Kasia\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (GG Network S.A.) C:\Documents and Settings\Kasia\Ustawienia lokalne\Dane aplikacji\GG\Application\ggapp.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Opera Software) C:\Program Files\Opera\opera.exe () C:\Program Files\WinRAR\WinRAR.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\WINDOWS\system32\winmine.exe (CNET Download.com) C:\Documents and Settings\Kasia\Pulpit\cbsidlm-cbsi145-USB_Info-ORG-10371115.exe () C:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\dlm362.tmp\mobogenie1204.exe () C:\Program Files\outobox\updateoutobox.exe (MyPCBackup.com) C:\Program Files\MyPC Backup\MyPC Backup.exe () C:\Program Files\ArcaBit\ArcaAgent\ArcaRemoteSvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BluetoothAuthenticationAgent] - rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent HKLM\...\Run: [AGRSMMSG] - C:\WINDOWS\AGRSMMSG.exe [89541 2006-06-29] (Agere Systems) HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [71216 2007-03-14] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [52256 2007-01-08] () HKLM\...\Run: [WooCnxMon] - C:\Program Files\Neostrada TP\CnxMon.exe [24576 2003-10-16] () HKLM\...\Run: [SpeedTouch USB Diagnostics] - C:\Program Files\Thomson\SpeedTouch USB\dragdiag.exe [866816 2004-01-26] (THOMSON Telecom Belgium) HKLM\...\Run: [WOOTASKBARICON] - C:\Program Files\Neostrada TP\TaskBarIcon.exe [53248 2003-10-16] (France Télécom R&D) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [37888 2009-07-01] () HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [35760 2011-01-31] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2471448 2013-12-09] () HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] () HKLM\...\Run: [ArcaClean] - C:\Program Files\ArcaBit\ArcaVir\ArcaClean.exe [58248 2013-11-02] (ArcaBit) HKLM\...\Run: [AvMenu] - C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe [529160 2013-05-15] (ArcaBit) HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [20143688 2013-12-17] (Realtek Semiconductor Corp.) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152 2006-02-19] (Hewlett-Packard Development Company, L.P.) HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Transcode Engine\plugins\mc_demux_mp2_ds.ax] - "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\DivX\DivX Transcode Engine\plugins\mc_demux_mp2_ds.ax",DllRegisterServer Winlogon\Notify\AtiExtEvent: C:\Windows\system32\Ati2evxx.dll (ATI Technologies Inc.) HKCU\...\Run: [Adobe Reader Synchronizer] - C:\Program Files\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe [1272704 2013-09-03] (Adobe Systems Incorporated) HKCU\...\Run: [GG] - C:\Documents and Settings\Kasia\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe [4047424 2013-12-13] (GG Network S.A.) HKCU\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe [1266712 2013-05-31] (AVG Secure Search) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5625624 2013-12-20] (SUPERAntiSpyware) HKCU\...\Policies\Explorer: [NoInstrumentation] 1 MountPoints2: {04559cb8-b98f-11de-aaed-001d921d8c85} - G:\setup.exe AUTORUN=1 MountPoints2: {71b4f0c4-bbfb-11de-aaf7-001d921d8c85} - G:\Install.exe MountPoints2: {ba84cddb-c6dd-11de-ab17-001d921d8c85} - G:\AutoTransfer.exe HKU\Administrator\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe [ 2013-05-31] (AVG Secure Search) HKU\Administrator\...\RunOnce: [Report] - C:\AdwCleaner[S2].txt [ 2012-08-03] () AppInit_DLLs: C:\Program Files\Sk-Enhancer\psupport.dll [ 2013-10-06] () IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\browsemngr.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browsermngr.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\bundlesweetimsetup.exe: [Debugger] tasklist.exe IFEO\cltmngsvc.exe: [Debugger] tasklist.exe IFEO\delta babylon.exe: [Debugger] tasklist.exe IFEO\delta tb.exe: [Debugger] tasklist.exe IFEO\delta2.exe: [Debugger] tasklist.exe IFEO\deltainstaller.exe: [Debugger] tasklist.exe IFEO\deltasetup.exe: [Debugger] tasklist.exe IFEO\deltatb.exe: [Debugger] tasklist.exe IFEO\deltatb_2501-c733154b.exe: [Debugger] tasklist.exe IFEO\iminentsetup.exe: [Debugger] tasklist.exe IFEO\rjatydimofu.exe: [Debugger] tasklist.exe IFEO\sweetimsetup.exe: [Debugger] tasklist.exe IFEO\tbdelta.exetoolbar783881609.exe: [Debugger] tasklist.exe Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) Startup: C:\Documents and Settings\Kasia\Menu Start\Programy\Autostart\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll [485376 2013-10-09] () <===== ATTENTION HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll <===== ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchbomb.info/?pid=499&r=2013/11/23&hid=7829060231762345277&lg=EN&cc=PL&unqvl=42 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchbomb.info/?pid=499&r=2013/11/23&hid=7829060231762345277&lg=EN&cc=PL&unqvl=42 URLSearchHook: HKCU - Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Neostrada TP\SearchPageURL.dll () SearchScopes: HKLM - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchbomb.info/?l=1&q={searchTerms}&pid=499&r=2013/11/23&hid=7829060231762345277&lg=EN&cc=PL&unqvl=42 SearchScopes: HKCU - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchbomb.info/?l=1&q={searchTerms}&pid=499&r=2013/11/23&hid=7829060231762345277&lg=EN&cc=PL&unqvl=42 SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://supertoolbar.ask.com/redirect?client=ie&tb=VD&o=14778&src=crm&q={searchTerms}&locale=en_US SearchScopes: HKCU - {73ccfd25-abe2-4bdf-ac5d-28a470a4d234} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={3774CAFC-51CB-11E1-B211-001D921D8C85} SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={10AAA403-162D-4D85-A047-219B46CE3147}&mid=e939065c686347d099add154d4b6c95c-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=pl&ds=xn011&pr=sa&d=2012-11-24 19:00:32&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKCU - {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = http://home.myplaycity.com/results.php?category=web&s={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033 SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchbomb.info/?l=1&q={searchTerms}&pid=499&r=2013/11/23&hid=7829060231762345277&lg=EN&cc=PL&unqvl=42 SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://www.startsearcher.com/?q={searchTerms}&src=IE SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 BHO: DivX Plus Web Player HTML5