Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 Ran by anna (administrator) on XP on 30-03-2014 01:20:28 Running from C:\Documents and Settings\anna\Moje dokumenty\Downloads\Programs Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (Creative Technology Ltd) C:\WINDOWS\system32\CTsvcCDA.exe (Sony Ericsson Mobile Communications) C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe (Sony Ericsson Mobile Communications) C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe () C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe () C:\Program Files\CyberLink\Shared files\RichVideo.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Desktop.exe (TeamViewer GmbH) c:\program files\teamviewer\version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe (AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Creative Technology Ltd) C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd) C:\WINDOWS\system32\CTXFIHLP.EXE (Creative Technology Ltd.) C:\WINDOWS\V0420Mon.exe (CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (Creative Technology Ltd) C:\WINDOWS\SYSTEM32\CTXFISPI.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\update\realsched.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (IVONA Software Sp. z o.o.) C:\Program Files\IVONA\IVONA ControlCenter\IVONA ControlCenter.exe (Tonec Inc.) C:\Documents and Settings\anna\Moje dokumenty\Downloads\Compressed\Internet Download Manager 6.08.9\Internet Download Manager 6.08.9\Crack\IDMan.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Tonec Inc.) C:\Documents and Settings\anna\Moje dokumenty\Downloads\Compressed\Internet Download Manager 6.08.9\Internet Download Manager 6.08.9\Crack\IEMonitor.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Adobe) C:\Documents and Settings\anna\Dane aplikacji\Adobe\Playpanel\Adobe Playpanel.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (AVG) C:\Program Files\AVG\AVG PC TuneUp\OneClick.exe (AVG) C:\Program Files\AVG\AVG PC TuneUp\TUDefragBackend32.exe (Farbar) C:\Documents and Settings\anna\Moje dokumenty\Downloads\Programs\FRST_2.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [VolPanel] - C:\Program Files\Creative\Volume Panel\VolPanlu.exe [233576 2008-08-06] (Creative Technology Ltd) HKLM\...\Run: [CTHelper] - C:\WINDOWS\CTHELPER.EXE [17920 2006-05-24] (Creative Technology Ltd) HKLM\...\Run: [CTxfiHlp] - C:\WINDOWS\SYSTEM32\CTXFIHLP.EXE [25600 2009-06-04] (Creative Technology Ltd) HKLM\...\Run: [V0420Mon.exe] - C:\WINDOWS\V0420Mon.exe [32768 2007-04-30] (Creative Technology Ltd.) HKLM\...\Run: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [UpdateLBPShortCut] - C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM\...\Run: [RemoteControl8] - C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [91432 2009-04-15] (CyberLink Corp.) HKLM\...\Run: [PDVD8LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [50472 2009-04-15] (CyberLink Corp.) HKLM\...\Run: [UpdatePPShortCut] - C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2009-02-17] (CyberLink Corp.) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [15494464 2012-02-29] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\SYSTEM32\NvMCTray.dll [108352 2012-02-29] (NVIDIA Corporation) HKLM\...\Run: [nwiz] - C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [1634112 2012-03-01] () HKLM\...\Run: [BluetoothAuthenticationAgent] - rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2516296 2010-03-25] (CANON INC.) HKLM\...\Run: [CanonSolutionMenuEx] - C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.) HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] () HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-03-29] (AVAST Software) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-10-27] (RealNetworks, Inc.) HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4971024 2014-03-19] (AVG Technologies CZ, s.r.o.) HKLM\...\Policies\Explorer: [NoCDBurning] 0 HKU\S-1-5-21-1935655697-602162358-682003330-1004\...\Run: [ALLUpdate] - C:\Program Files\ALLPlayer\ALLUpdate.exe [3000680 2013-11-01] (ALLPlayer Group Ltd.) HKU\S-1-5-21-1935655697-602162358-682003330-1004\...\Run: [AQQ] - C:\Program Files\WapSter\WapSter AQQ\AQQ.exe [8432128 2014-03-05] (AQQ Sp. z o.o.) HKU\S-1-5-21-1935655697-602162358-682003330-1004\...\Run: [GG] - C:\Documents and Settings\anna\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe [4028480 2014-03-20] (GG Network S.A.) HKU\S-1-5-21-1935655697-602162358-682003330-1004\...\Run: [IVONA ControlCenter] - C:\Program Files\IVONA\IVONA ControlCenter\IVONA ControlCenter.exe [2251128 2013-06-11] (IVONA Software Sp. z o.o.) HKU\S-1-5-21-1935655697-602162358-682003330-1004\...\Run: [IDMan] - C:\Documents and Settings\anna\Moje dokumenty\Downloads\Compressed\Internet Download Manager 6.08.9\Internet Download Manager 6.08.9\Crack\IDMan.exe [3825232 2014-02-05] (Tonec Inc.) HKU\S-1-5-21-1935655697-602162358-682003330-1004\...\Run: [KSS] - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202328 2012-12-07] (Kaspersky Lab ZAO) HKU\S-1-5-21-1935655697-602162358-682003330-1004\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-1935655697-602162358-682003330-1004\...\MountPoints2: {a4c994b5-aaf4-11e0-8fad-001e101f5507} - M:\AutoRun.exe Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Playpanel.lnk ShortcutTarget: Adobe Playpanel.lnk -> C:\WINDOWS\Installer\{69967F97-E880-44B9-8383-5278BBC8809B}\Adobe_Playpanel.ex_1E7E95B53A024F3695AE7B9EB4A54E1D.exe (Flexera Software LLC) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=153 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope 2BC0B2411C6E4A3E8E2171633DBEB2D5 URL = http://www.delta-search.com/?q={searchTerms}&affID=119816&babsrc=SP_ss&mntrId=24b33ac4000000000000001d7de7bec8 SearchScopes: HKCU - 2BC0B2411C6E4A3E8E2171633DBEB2D5 URL = http://www.delta-search.com/?q={searchTerms}&affID=119816&babsrc=SP_ss&mntrId=24b33ac4000000000000001d7de7bec8 SearchScopes: HKCU - {97F234E2-855F-41D2-A0A9-6985FD9DA3AA} URL = http://www.dymasearch.com/search.php?src=tops&q={SearchTerms} SearchScopes: HKCU - {A74F6A2F-A454-4E43-BA64-648153B09CC7} URL = http://search.softonic.com/MON00005/tb_v1?q={searchTerms}&SearchSource=4&cc=&r=390 BHO: IDM integration (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Documents and Settings\anna\Moje dokumenty\Downloads\Compressed\Internet Download Manager 6.08.9\Internet Download Manager 6.08.9\Crack\IDMIECC.dll (Internet Download Manager, Tonec Inc.) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: DivX Plus Web Player HTML5