Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-04-2014 01 Ran by Vision (administrator) on JANKOWIA-186EB5 on 18-04-2014 19:08:13 Running from D:\ Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe (Cherished Technololgy LIMITED) C:\Documents and Settings\All Users\Dane aplikacji\WPM\wprotectmanager.exe (ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe () c:\support\couponsupport.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (Advanced Micro Devices Inc.) D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe () C:\Documents and Settings\Vision\Dane aplikacji\defaulttab\defaulttab\dtupdate.exe (Mobile Leader Co.,Ltd.) C:\WINDOWS\system32\ScsiCommandService2.exe (cake bake) C:\Program Files\Web Cake\WebCakeDesktop.Updater.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe () C:\Program Files\Mobogenie\DaemonProcess.exe () C:\Program Files\Mobogenie\MgAssist.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [StartCCC] => D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2012-03-09] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20145368 2013-10-04] (Realtek Semiconductor Corp.) HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k HKLM\...\Run: [mobilegeni daemon] => C:\Program Files\Mobogenie\DaemonProcess.exe [748736 2014-04-18] () Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.) HKU\.DEFAULT\...\RunOnce: [FlashPlayerUpdate] - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_8_800_168_Plugin.exe [815496 2013-09-12] (Adobe Systems Incorporated) HKU\.DEFAULT\...\RunOnce: [Del697718] - cmd.exe /Q /D /c del "C:\WINDOWS\TEMP\0.del" HKU\.DEFAULT\...\RunOnce: [Del1131015] - cmd.exe /Q /D /c del "C:\WINDOWS\TEMP\0.del" HKU\.DEFAULT\...\RunOnce: [Del1304015] - cmd.exe /Q /D /c del "C:\WINDOWS\TEMP\0.del" HKU\.DEFAULT\...\RunOnce: [Del38866406] - cmd.exe /Q /D /c del "C:\WINDOWS\TEMP\0.del" HKU\.DEFAULT\...\RunOnce: [Del46286937] - cmd.exe /Q /D /c del "C:\WINDOWS\TEMP\0.del" HKU\S-1-5-21-1757981266-2111687655-682003330-1003\...\Run: [NextLive] => C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Vision\Dane aplikacji\newnext.me\nengine.dll",EntryPoint -m l HKU\S-1-5-21-1757981266-2111687655-682003330-1003\...\MountPoints2: {c94a7373-feaa-11e2-bc3f-ec3678798fc0} - G:\LGAutoRun.exe Lsa: [Authentication Packages] msv1_0 nwprovau GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mysearchresults.com/?c=3524&t=01 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=9C31D43D7E352E65&affID=119357&tsp=5018 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.delta-homes.com/?type=hp&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T URLSearchHook: HKLM - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} URLSearchHook: HKLM - SiteFinder - {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files\SiteFinder\SiteFinder.dll (Site Finder) SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T&q={searchTerms} SearchScopes: HKLM - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm067^YYA^pl&si=flvrunner&ptb=0CEC2D9D-C253-4C17-86AF-838D314B492F&ind=2013082115&n=77fd3203&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T&ts=1380233162&type=default&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T&q={searchTerms} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - 553827E3D394476AB53D690392740B28 URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T&ts=1380233162&type=default&q={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=9C31D43D7E352E65&affID=119357&tsp=5018 SearchScopes: HKCU - {15A5E16B-DC86-4277-B694-EDD037508938} URL = http://www.idg.pl?q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T&q={searchTerms} SearchScopes: HKCU - {54A1E7BB-CA67-46C5-85E9-6ADA3B2C19AA} URL = http://www.idg.pl?q={searchTerms} SearchScopes: HKCU - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm067^YYA^pl&si=flvrunner&ptb=0CEC2D9D-C253-4C17-86AF-838D314B492F&ind=2013082115&n=77fd3203&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = SearchScopes: HKCU - {89383D8F-0E54-4FD8-B1D8-12FAAC097801} URL = http://www.mysearchresults.com/search?c=3524&t=01&q={searchTerms} SearchScopes: HKCU - {D7BCFF01-E62C-4C4E-840F-E65A0EFB0DED} URL = http://www.idg.pl?q={searchTerms} SearchScopes: HKCU - {D91B2B18-4420-49A2-AF37-7E8B2F2DF8E4} URL = http://www.idg.pl?q={searchTerms} SearchScopes: HKCU - {F420DFA1-E687-4ACB-8F69-387137D18705} URL = http://www.idg.pl?q={searchTerms} BHO: DoWenSaVe - {4BC58949-7F92-E476-8A98-CAB427051D0A} - C:\Documents and Settings\All Users\Dane aplikacji\DoWenSaVe\7Lj0.dll () BHO: SaiVeLots - {58F86BAC-1199-0275-89F0-A22D70D3A36A} - C:\Documents and Settings\All Users\Dane aplikacji\SaiVeLots\J.dll () BHO: SaveSense - {71e129ff-6c2a-4984-818c-7e2c998b8d99} - C:\Documents and Settings\Vision\Ustawienia lokalne\Dane aplikacji\SaveSense\SaveSenseIE.dll (SaveSense) BHO: DefaultTab Browser Helper - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Documents and Settings\Vision\Dane aplikacji\defaulttab\defaulttab\DefaultTabBHO.dll (Search Results LLC.) BHO: WatcHItoAdBllocKE - {99B3E000-0379-FA9D-D350-BB8863F2C19F} - C:\Documents and Settings\All Users\Dane aplikacji\WatcHItoAdBllocKE\uA8ZEZIH.dll () BHO: 50CoUponus - {DD2FE438-BA9A-9B3D-41C8-1A887EA8CE4E} - C:\Documents and Settings\All Users\Dane aplikacji\50CoUponus\eDG8.dll () Toolbar: HKLM - SiteFinder - {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files\SiteFinder\SiteFinder.dll (Site Finder) ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ] Tcpip\Parameters: [DhcpNameServer] 192.168.11.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default FF user.js: detected! => C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\user.js FF NewTab: hxxp://www.delta-homes.com/newtab/?type=nt&ts=1388676594&from=wpm0102&uid=TOSHIBAXMQ01ABD050_X259C3R4TXXX259C3R4T FF DefaultSearchEngine: Ask Web Search FF SearchEngineOrder.1: Mysearchdial FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: Ask Web Search FF Homepage: google.pl FF Keyword.URL: hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=12F46A28-9AD8-4A1A-9012-65101665E0A7&n=780bb33f&ind=2014032703&p2=^ZC^xdm941^YYA^pl&searchfor= FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll No File FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.dpliveupdate.com/DealPlyLive Update;version=3 - C:\Program Files\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd) FF Plugin: @tools.dpliveupdate.com/DealPlyLive Update;version=9 - C:\Program Files\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Documents and Settings\Vision\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation) FF SearchPlugin: C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\searchplugins\ask-web-search.xml FF SearchPlugin: C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\searchplugins\bingp.xml FF SearchPlugin: C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\searchplugins\Mysearchdial.xml FF Extension: CursorMania - C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\Extensions\7lffxtbr@CursorMania_7l.com [2014-03-27] FF Extension: AollCHeaipPrice - C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\Extensions\adpjve@uegkpw-.edu [2014-04-03] FF Extension: 50CoUponus - C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\Extensions\bftwkrb@vwxwk.co.uk [2013-12-31] FF Extension: Plus-HD-4.9 - C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\Extensions\d019febe-eb2b-4057-a3f2-7def88f2c9cd@1cced8ec-0ffe-43ea-b4b2-fbce5de8e9a4.com [2014-03-07] FF Extension: WatcHItoAdBllocKE - C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\Extensions\j5cqkeyy@j-swbpmo.edu [2014-02-03] FF Extension: Site Finder - C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\Extensions\sitefinder@sitefinder.com [2014-03-23] FF Extension: SaiVeLots - C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\Extensions\xldtaeaj6u16a@mtkkdlbcgvx.com [2013-12-31] FF Extension: SaveSense - C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\Extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23} [2014-02-06] FF Extension: Stylish - C:\Documents and Settings\Vision\Dane aplikacji\Mozilla\Firefox\Profiles\4niax6zq.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2014-01-31] FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] Chrome: ======= CHR HomePage: hxxp://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0EtAyDtB0EyCyDzy0AtCzztN0D0Tzu0SyBtCtCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1067736396&ir= CHR RestoreOnStartup: "hxxp://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0EtAyDtB0EyCyDzy0AtCzztN0D0Tzu0SyBtCtCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1067736396&ir=" CHR Extension: (AollCHeaipPrice) - C:\Documents and Settings\Vision\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ddghgfpefkageoikjddkggffenffhhbh [2014-04-03] CHR Extension: (No Name) - C:\Documents and Settings\Vision\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\lgigkbmnhjgiipmfgmhoaonngpkdamnm [2013-12-11] CHR Extension: (No Name) - C:\Documents and Settings\Vision\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf [2013-12-12] CHR Extension: (Helper extension) - C:\Documents and Settings\Vision\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nchpfiddbhbdnagofhkjlaiaejmkdcla [2013-08-26] CHR Extension: (DivX Plus Web Player HTML5