Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-01-2014 Ran by Zurawski (administrator) on AAA-F4EB14868E7 on 19-01-2014 14:55:33 Running from C:\Documents and Settings\Zurawski\Pulpit Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 6 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Download link for 64-Bit Version: Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: ==================== Processes (Whitelisted) =================== (Atheros) C:\WINDOWS\system32\acs.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (VIA Technologies, Inc.) C:\WINDOWS\system32\KaraokeSer.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (VIA Technologies, Inc.) C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe () C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (IObit) C:\Program Files\IObit\Game Booster 3\gbtray.exe () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\\deploy\LoLLauncher.exe () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\\deploy\LolClient.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HDAudDeck] - C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [41032304 2010-12-27] (VIA Technologies, Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM\...\Run: [A9B90D] - C:\WINDOWS\system32\29EDD5\A9B90D.EXE [1406935 2013-09-27] () HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [TWCU] - C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe [561263 2009-12-28] () HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54576 2009-11-18] (Hewlett-Packard) HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [15711008 2013-11-11] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMCTray.dll [209184 2013-11-11] (NVIDIA Corporation) HKLM\...\Run: [nwiz] - C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2602784 2013-11-11] () HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3673696 2013-08-01] (Disc Soft Ltd) HKCU\...\Run: [NextLive] - C:\Documents and Settings\Zurawski\Dane aplikacji\\nengine.dll [1283584 2013-11-14] (NewNextDotMe) HKCU\...\Run: [spoolsv32] - "C:\WINDOWS\system32\javaw.exe" -jar "C:\Documents and Settings\Zurawski\Dane aplikacji\Win32\spoolsv32.jar" Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk ShortcutTarget: Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk -> C:\Program Files\SAGEM WiFi manager\WLANUTL.EXE ( ) Startup: C:\Documents and Settings\Zurawski\Menu Start\Programy\Autostart\A9B90D.lnk ShortcutTarget: A9B90D.lnk -> C:\WINDOWS\system32\29EDD5\A9B90D.EXE () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} DPF: {CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Documents and Settings\Zurawski\Dane aplikacji\Mozilla\Firefox\Profiles\08ltct9c.default FF user.js: detected! => C:\Documents and Settings\Zurawski\Dane aplikacji\Mozilla\Firefox\Profiles\08ltct9c.default\user.js FF NewTab: hxxp:// FF SearchEngineOrder.1: qvo6 FF Homepage: FF Plugin: - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin:,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin:,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin:,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin:,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin:;version=1 - C:\Program Files\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin: - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: Update;version=3 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Update;version=9 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\qvo6.xml FF Extension: vis - C:\Documents and Settings\Zurawski\Dane aplikacji\Mozilla\Firefox\Profiles\08ltct9c.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM [2013-10-27] FF Extension: uTorrentControl_v6 - C:\Documents and Settings\Zurawski\Dane aplikacji\Mozilla\Firefox\Profiles\08ltct9c.default\Extensions\{96f454ea-9d38-474f-b504-56193e00c1a5} [2013-10-25] FF Extension: DownloadHelper - C:\Documents and Settings\Zurawski\Dane aplikacji\Mozilla\Firefox\Profiles\08ltct9c.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-11-04] FF Extension: Adblock Plus - C:\Documents and Settings\Zurawski\Dane aplikacji\Mozilla\Firefox\Profiles\08ltct9c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-25] FF Extension: QuickJava - C:\Documents and Settings\Zurawski\Dane aplikacji\Mozilla\Firefox\Profiles\08ltct9c.default\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi [2014-01-13] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} [2013-12-20] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: [] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-11-24] FF HKCU\...\Firefox\Extensions: [] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-11-24] ========================== Services (Whitelisted) ================= R2 ACS; C:\WINDOWS\system32\acs.exe [499796 2009-09-21] (Atheros) R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-01-13] (Oracle Corporation) R2 KaraokeService; C:\Windows\system32\KaraokeSer.exe [88688 2010-12-22] (VIA Technologies, Inc.) R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R3 AR9271; C:\Windows\System32\DRIVERS\athuw.sys [1714176 2010-01-04] (Atheros Communications, Inc.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-09-14] (Disc Soft Ltd) S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2009-08-05] (HP) S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2009-08-05] (HP) S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2009-08-05] (HP) R3 L1c; C:\Windows\System32\DRIVERS\l1c51x86.sys [65136 2011-03-22] (Atheros Communications, Inc.) R3 NVHDA; C:\Windows\System32\drivers\nvhda32.sys [128672 2013-06-16] (NVIDIA Corporation) S3 SG762_XP; C:\Windows\System32\DRIVERS\WlanBZXP.sys [450560 2007-01-10] (ZyDAS Technology Corporation) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [2804720 2010-12-22] (VIA Technologies, Inc.) R3 WinRing0_1_2_0; C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys [14416 2010-11-01] ( R3 WSIMD; C:\Windows\System32\DRIVERS\wsimd.sys [58208 2009-09-21] (Atheros Communications, Inc.) R3 ZDPSp50; C:\Windows\System32\Drivers\ZDPSp50.sys [17664 2007-01-16] (Printing Communications Assoc., Inc. 