Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-01-2014 01 Ran by xxx (administrator) on KRZYSIEK on 15-01-2014 16:05:36 Running from C:\Users\xxx\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (AMD) C:\Windows\System32\atieclxx.exe (ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\agcp.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\agcp.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (AIMP DevTeam) C:\Program Files (x86)\AIMP3\AIMP3.exe () C:\Users\xxx\Downloads\s9synujb.exe () C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] () HKLM-x32\...\Run: [DivXUpdate] - "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC) HKLM-x32\...\Runonce: [GrpConv] - grpconv.exe -o [x] HKCU\...\Run: [Mobile Partner] - C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe [591872 2013-04-06] () HKCU\...\Run: [Facebook Update] - C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe [220016 2013-12-31] (Facebook Inc.) HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_170_Plugin.exe -update plugin [839560 2013-12-11] (Adobe Systems Incorporated) MountPoints2: E - E:\AutoRun.exe MountPoints2: F - F:\AutoRun.exe MountPoints2: {2ccc1c17-ff1c-11e0-b290-f46d04860daf} - F:\LaunchU3.exe -a MountPoints2: {472b2c5a-9f06-11e2-83c4-001e101f4e71} - E:\AutoRun.exe MountPoints2: {472b2c95-9f06-11e2-83c4-001e101fb681} - E:\AutoRun.exe MountPoints2: {4aa4cef3-9f6b-11e2-8885-f46d04860daf} - E:\AutoRun.exe MountPoints2: {63d3b3bd-0976-11e3-a814-f46d04860daf} - E:\LGAutoRun.exe MountPoints2: {788ed14b-3b41-11e3-b0fc-f46d04860daf} - E:\AutoRun.exe MountPoints2: {788ed15d-3b41-11e3-b0fc-f46d04860daf} - E:\AutoRun.exe MountPoints2: {788ed1ac-3b41-11e3-b0fc-f46d04860daf} - E:\AutoRun.exe MountPoints2: {788ed1f1-3b41-11e3-b0fc-f46d04860daf} - E:\AutoRun.exe MountPoints2: {80074e1a-5ccb-11e3-86aa-f46d04860daf} - H:\LGAutoRun.exe MountPoints2: {91744e57-55cc-11e2-9dd6-485d60ea12c2} - E:\iLinker.exe MountPoints2: {a92fc934-4608-11e2-964d-485d60ea12c2} - E:\AutoRun.exe MountPoints2: {a92fc949-4608-11e2-964d-485d60ea12c2} - E:\AutoRun.exe MountPoints2: {afe81f03-4eaa-11e2-84fa-485d60ea12c2} - F:\AutoRun.exe MountPoints2: {c5f0831d-801e-11e2-a9b0-001e101f63cf} - F:\AutoRun.exe HKU\Gość\...\Run: [Mobile Partner] - C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe [591872 2013-04-06] () AppInit_DLLs-x32: c:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll [ ] () ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {47AE1BA9-0BD1-44F4-88AE-45F8F7B605EF} URL = http://www.basicserve.com/?prt=bscsrvlink1&sp=&keywords={searchTerms} SearchScopes: HKCU - {69ABAE4C-47BC-4EAD-A2B3-ED08ED617830} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=ct3135048 BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: DivX Plus Web Player HTML5