Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-02-2014 Ran by Martuś (administrator) on MARTUS-PC on 05-02-2014 15:34:21 Running from E:\Downloads Microsoft® Windows Vista™ Home Premium (X86) OS Language: Polish Internet Explorer Version 7 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Kingsoft Corporation) E:\Program Files\kingsoft\kingsoft antivirus\kxescore.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (The Firebird Project) C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe (Symantec Corporation) C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPO\TempoSVC.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (The Firebird Project) C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe () C:\Users\Martuś\AppData\Local\fst_pl_31\upfst_pl_31.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe () C:\Program Files\TOSHIBA\Utilities\KeNotify.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPO\Toshiba.Tempo.UI.TrayApplication.exe () C:\Program Files\Winamp\winampa.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\fst_pl_19\fst_pl_19.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (TOSHIBA) C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Google Inc.) C:\Users\Martuś\AppData\Local\Google\Update\GoogleUpdate.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Kingsoft Corporation) E:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosAVRC.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Google Inc.) C:\Users\Martuś\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martuś\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martuś\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martuś\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martuś\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martuś\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martuś\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosOBEX.exe (TOSHIBA CORPORATION.) C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtProc.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-07-13] (Microsoft Corporation) HKLM\...\Run: [KeNotify] - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [34352 2006-11-06] () HKLM\...\Run: [SVPWUTIL] - C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [438272 2006-03-22] (TOSHIBA) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4702208 2007-09-03] (Realtek Semiconductor) HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [411192 2007-03-29] (TOSHIBA Corporation) HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [55416 2006-12-07] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [509496 2007-04-03] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [538744 2007-05-22] (TOSHIBA Corporation) HKLM\...\Run: [NDSTray.exe] - NDSTray.exe HKLM\...\Run: [topi] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [581632 2007-07-10] (TOSHIBA) HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1826816 2007-08-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [Camera Assistant Software] - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [413696 2007-04-10] (Chicony) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [180224 2006-09-11] (Alps Electric Co., Ltd.) HKLM\...\Run: [Toshiba Registration] - C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe [571024 2007-02-19] (Toshiba) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [174872 2007-02-12] (Intel Corporation) HKLM\...\Run: [Symantec PIF AlertEng] - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [583048 2008-01-29] (Symantec Corporation) HKLM\...\Run: [Toshiba TEMPO] - C:\Program Files\Toshiba TEMPO\Toshiba.Tempo.UI.TrayApplication.exe [103824 2007-10-29] (Toshiba Europe GmbH) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [36352 2008-04-01] () HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdSync.exe [215552 2006-11-02] (Microsoft Corporation) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader\Reader_sl.exe [35736 2011-01-30] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-10] (Adobe Systems Incorporated) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1230704 2011-03-21] () HKLM\...\Run: [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard) HKLM\...\Run: [] - [X] HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.) HKLM\...\Run: [kxesc] - E:\program files\kingsoft\kingsoft antivirus\kxetray.exe [1217712 2012-12-29] (Kingsoft Corporation) HKLM\...\Run: [fst_pl_31] - [X] HKLM\...\Run: [fst_pl_19] - C:\Program Files\fst_pl_19\fst_pl_19.exe [11671024 2013-12-18] () HKLM\...\RunOnce: [upfst_pl_31.exe] - C:\Users\Martuś\AppData\Local\fst_pl_31\upfst_pl_31.exe -runonce [3153904 2014-01-02] () HKU\.DEFAULT\...\RunOnce: [] - C:\Windows\system32\OSK.exe [182272 2006-11-02] (Microsoft Corporation) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\Run: [TOSCDSPD] - TOSCDSPD.EXE HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation) HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\Run: [Google Update] - C:\Users\Martuś\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-02-09] (Google Inc.) HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: J - J:\LaunchU3.exe -a HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {2c9bb19b-1404-11e0-96e8-00037ab6e403} - "K:\WD SmartWare.exe" autoplay=true HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {5c949cff-e33c-11dd-83b5-001b38b4ff6c} - K:\setup.exe HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {615ced03-e59c-11e0-a0fe-00037ab6e403} - f2kmj.exe HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {9412c554-8cf2-11de-9584-00037ab6e403} - D:\AUTORUN.EXE HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {ac6b1f9b-3bf2-11e0-a65e-00037ab6e403} - K:\Startme.exe HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {bc91a88b-03b7-11e2-b4ee-00037ab6e403} - J:\f2kmj.exe HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {c55479db-7ff9-11de-b6e1-00037ab6e403} - D:\setup.exe HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {c770a6af-0faf-11dd-befe-001b38b4ff6c} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe f HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {c770a6b3-0faf-11dd-befe-001b38b4ff6c} - H:\USBNB.exe HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {d30347f0-6234-11e2-b1c4-00037ab6e403} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fOtEN.exE HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {f2371ef6-f860-11de-9df9-00037ab6e403} - I:\Setup.exe HKU\S-1-5-21-3485203417-2420686941-307345420-1000\...\MountPoints2: {f49e504d-d6c3-11e0-b15e-00037ab6e403} - J:\f2kmj.exe Startup: C:\Users\Martuś\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9851 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.pl HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9851 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.pl SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {AE098360-0BC7-4916-905A-1E2A85C02928} URL = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:*:IE-SearchBox&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7; SearchScopes: HKCU - {AE098360-0BC7-4916-905A-1E2A85C02928} URL = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:*:IE-SearchBox&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7; BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: DivX Plus Web Player HTML5