qScan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-01-2014 01 Ran by Robert (administrator) on STACONARNY on 30-01-2014 17:34:42 Running from C:\Documents and Settings\Robert\Pulpit\skanery Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) =================== (Diskeeper® Corporation) C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\WINDOWS\system32\PnkBstrA.exe (ClickMeIn Limited) C:\Program Files\VuuPC\Connectivity.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win32.exe (IObit) C:\Program Files\IObit\Game Booster 3\gbtray.exe (Wargaming.net) D:\wot\WorldOfTanks.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5110672 2013-09-12] (ESET) Winlogon\Notify\WgaLogon: WgaLogon.dll [X] HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKCU\...\Run: [NextLive] - C:\Documents and Settings\Robert\Dane aplikacji\newnext.me\nengine.dll [1283584 2014-01-06] (NewNextDotMe) HKCU\...\Policies\Explorer: [HideSCAHealth] 1 MountPoints2: {c9e94e04-899f-11e3-af0a-001fe2656671} - J:\cdstart.exe HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe [ 2007-06-01] (Nero AG) HKU\Gośka\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2007-07-18] (Hewlett-Packard Company) HKU\Gośka\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [ 2007-06-01] (Nero AG) HKU\Gośka(2)\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2007-07-18] (Hewlett-Packard Company) HKU\Gośka(2)\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [ 2007-06-01] (Nero AG) HKU\Gośka(2)\...\Run: [RGSC] - G:\gta 4\GTA4\Rockstar Games Social Club\RGSCLauncher.exe [ 2008-11-14] (Take-Two Interactive Software, Inc.) HKU\Gość\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2007-07-18] (Hewlett-Packard Company) HKU\Gość\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [ 2007-06-01] (Nero AG) ==================== Internet (Whitelisted) ==================== ProxyServer: www.facebook.pl HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=SAMSUNG_HD502IJ_S13TJ90QB21856&ts=1355671989 SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=aa684a77-8344-459b-a777-6cc241c978fe&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}&installDate={installDate} SearchScopes: HKLM - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchrocket.info/?l=1&q={searchTerms}&pid=700&r=2013/05/28&hid=2570990793&lg=EN&cc=PL&unqvl=16 SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=aa684a77-8344-459b-a777-6cc241c978fe&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}&installDate={installDate} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=4C8E001FE2656671&affID=119357&tsp=4983 SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=23C2E87D-3350-40F1-AEE1-39983D6B799F&apn_sauid=6C6520A8-ECEB-4137-ACCA-B3DA8427F7F0 BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx () BHO: DivX Plus Web Player HTML5