Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-09-2014 Ran by Administrator (administrator) on HP53842451610 on 11-09-2014 16:54:45 Running from C:\Documents and Settings\Administrator\Pulpit Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Cherished Technololgy LIMITED) C:\Documents and Settings\All Users\Dane aplikacji\IePluginServices\PluginService.exe (ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\accoca.exe () C:\Program Files\SupTab\HpUI.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe () C:\Program Files\SupTab\Loader32.exe () C:\Program Files\ScreenShooter\screenshooter.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Intel Corporation) C:\Program Files\Intel\AMT\LMS.exe () C:\Program Files\DFX\DFX.exe (ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\acevents.exe (PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin (Intel Corporation) C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe () C:\Program Files\DFX\Universal\Apps\DfxSharedApp32.exe () C:\Program Files\DFX\Universal\Apps\dfxItunesSong.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Opera Software) C:\Program Files\Opera\opera.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [251512 2014-08-31] () HKLM\...\Run: [HotKeysCmds] => C:\WINDOWS\system32\hkcmd.exe [251512 2014-08-31] () HKLM\...\Run: [Persistence] => C:\WINDOWS\system32\igfxpers.exe [251512 2014-08-31] () HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [251512 2014-08-31] () HKLM\...\Run: [picon] => C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [251512 2014-08-31] () HKLM\...\Run: [PDF Complete] => C:\Program Files\PDF Complete\pdfsty.exe [251512 2014-08-31] () HKLM\...\Run: [accrdsub] => C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [251512 2014-08-31] () HKLM\...\Run: [SetRefresh] => C:\Program Files\Compaq\SetRefresh\SetRefresh.exe [251512 2014-08-31] () HKLM\...\Run: [Recguard] => C:\WINDOWS\Sminst\Recguard.exe [251512 2014-08-31] () HKLM\...\Run: [Reminder] => C:\WINDOWS\Creator\Remind_XP.exe [251512 2014-08-31] () HKLM\...\Run: [ACUMon] => C:\Program Files\Cisco Systems\Aironet Client Monitor\ACUMon.Exe [251512 2014-08-31] () HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [251512 2014-08-31] () HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [251512 2014-08-31] () HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [251512 2014-08-31] () HKLM\...\Run: [ADSK DLMSession] => C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [251512 2014-08-31] () HKLM\...\Run: [MP10_EnsureFileVer] => C:\WINDOWS\inf\unregmp2.exe [208896 2008-04-14] (Microsoft Corporation) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask .exe [421888 2012-10-25] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [251512 2014-08-31] () HKLM\...\Run: [fst_pl_190] => [X] HKLM\...\Run: [upfst_pl_190.exe] => C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\fst_pl_190\upfst_pl_190.exe -runhelper Winlogon\Notify\ackpbsc: C:\WINDOWS\system32\ackpbsc.dll (ActivIdentity) Winlogon\Notify\acunlock: C:\Program Files\ActivIdentity\ActivClient\acunlock.dll (ActivIdentity) HKLM\...99B7938DA9E4}\LocalServer32: [Default-wmiprvse] <==== ATTENTION! HKU\.DEFAULT\...\RunOnce: [FlashPlayerUpdate] => C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_14_0_0_145_ActiveX.exe -update activex HKU\S-1-5-21-3094104702-925323197-3564856798-500\...\Run: [Spotify] => C:\Documents and Settings\Administrator\Dane aplikacji\Spotify\Spotify.exe [251512 2014-08-31] () HKU\S-1-5-21-3094104702-925323197-3564856798-500\...\Run: [ALLUpdate] => C:\Program Files\ALLPlayer\ALLUpdate.exe [251512 2014-08-31] () HKU\S-1-5-21-3094104702-925323197-3564856798-500\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [251512 2014-08-31] () HKU\S-1-5-21-3094104702-925323197-3564856798-500\...\Run: [Google Update] => C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [251512 2014-08-31] () HKU\S-1-5-21-3094104702-925323197-3564856798-500\...\Run: [uTorrent] => C:\Documents and Settings\Administrator\Dane aplikacji\uTorrent\uTorrent .exe [1322832 2014-07-07] (BitTorrent Inc.) HKU\S-1-5-21-3094104702-925323197-3564856798-500\...\Run: [Spotify Web Helper] => C:\Documents and Settings\Administrator\Dane aplikacji\Spotify\Data\SpotifyWebHelper.exe [251512 2014-08-31] () HKU\S-1-5-21-3094104702-925323197-3564856798-500\...\Run: [screenshooter] => C:\Program Files\ScreenShooter\screenshooter.exe [606208 2010-09-03] () HKU\S-1-5-21-3094104702-925323197-3564856798-500\...\Run: [GoogleChromeAutoLaunch_245400442DF7A252BDC0B491EAB93F18] => C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe [251512 2014-08-31] () Startup: C:\Documents and Settings\Administrator\Menu Start\Programy\Autostart\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DFX.lnk ShortcutTarget: DFX.lnk -> C:\Program Files\DFX\DFX.exe () ShellIconOverlayIdentifiers: AutoCAD Digital Signatures Icon Overlay Handler -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll (Autodesk, Inc.) ShellIconOverlayIdentifiers: GGDriveOverlay1 -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: GGDriveOverlay2 -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: GGDriveOverlay3 -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: GGDriveOverlay4 -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} BHO: TheHDvid-Codec V10 -> {11111111-1111-1111-1111-110611331115} -> C:\Program Files\TheHDvid-Codec V10\TheHDvid-Codec V10-bho.dll (home) BHO: DivX Plus Web Player HTML5