Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014 Ran by mojojo at 2014-01-07 22:34:44 Run:1 Running from C:\Users\mojojo\Downloads\Nowy folder Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [761024 2013-12-13] () HKCU\...\Run: [Badoo Desktop] - C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe HKCU\...\Run: [SSync] - C:\Users\mojojo\AppData\Roaming\SSync\SSync.exe [36864 2013-04-09] () HKCU\...\Run: [OMESupervisor] - C:\Users\mojojo\AppData\Local\omesuperv.exe [2239256 2013-12-24] () HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\mojojo\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKCU\...\Run: [SCheck] - C:\Users\mojojo\AppData\Roaming\SCheck\SCheck.exe [37376 2013-12-09] () HKCU\...\Run: [Snoozer] - C:\Users\mojojo\AppData\Roaming\Snz\Snz.exe [1209624 2013-12-24] () HKCU\...\Run: [Intermediate] - C:\Users\mojojo\AppData\Roaming\Intermediate\Intermediate.exe [37376 2013-12-09] () Startup: C:\Users\mojojo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk Task: {237830F4-2EE9-4F1B-A202-7B9267910DF3} - System32\Tasks\QtraxPlayer => C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe [2013-09-13] (Microsoft Corporation) Task: {6191ED3B-3AB0-49B7-85E9-A5E390E35655} - System32\Tasks\{0CD87B15-CF3F-4EEE-BC63-28679996E99D} => D:\Program Files (x86)\Mirillis\Action!\Action.exe Task: {648C2BCE-D24D-48FF-9DC7-5019D7A80801} - System32\Tasks\FoxTab => C:\Users\mojojo\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\FoxTab.job => C:\Users\mojojo\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.fbdownloader.com/?channel=msus200fbdgy6 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.v9.com/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=1372003647 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://search.fbdownloader.com/search.php?channel=msus200fbdgy6&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=SAMSUNGXHM321HI_S2HZJ9DB207916&ts=0 SearchScopes: HKCU - {8A244612-A1F7-11E0-95C0-E71F4824019B} URL = http://badoo.com/startpage/?source=bsb&q={searchTerms} SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://search.fbdownloader.com/search.php?channel=msus200fbdgy6&q={searchTerms} BHO-x32: IEToolbar.BHO - {1d970ed5-3eda-438d-bffd-715931e2775b} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: OfferMosquito - {82B16A3D-F03E-4565-A532-666B219C9A53} - C:\Users\mojojo\AppData\Local\ext_offermosquito\OfferMosquitoIEPlaceholder.dll (Bebo Media Ltd) Toolbar: HKLM-x32 - MoneyMillionaire Toolbar - {d28c7e56-2cc6-415c-8727-d71334085926} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\mojojo\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx S2 DiscountfinderService; "C:\ProgramData\Odkrywca Rabatów\DFService.exe" [x] S3 WinRing0_1_2_0; \??\D:\Program Files (x86)\iVeeSoft\iGame Capture\Driver\WinRing0x64.sys [x] C:\dummy.wav C:\Program Files (x86)\Mobogenie C:\ProgramData\Odkrywca Rabatów C:\Users\mojojo\.android C:\Users\mojojo\daemonprocess.txt C:\Users\mojojo\AppData\Local\omesuperv.exe C:\Users\mojojo\AppData\Local\ext_offermosquito C:\Users\mojojo\AppData\Local\cache C:\Users\mojojo\AppData\Local\genienext C:\Users\mojojo\AppData\Local\Mobogenie C:\Users\mojojo\AppData\Roaming\newnext.me C:\Users\mojojo\AppData\Roaming\Intermediate C:\Users\mojojo\AppData\Roaming\SCheck C:\Users\mojojo\AppData\Roaming\Snz C:\Users\mojojo\AppData\Roaming\SSync C:\Users\mojojo\Documents\Mobogenie Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Badoo Desktop => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\SSync => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\OMESupervisor => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\SCheck => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Snoozer => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Intermediate => Value deleted successfully. C:\Users\mojojo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{237830F4-2EE9-4F1B-A202-7B9267910DF3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{237830F4-2EE9-4F1B-A202-7B9267910DF3} => Key deleted successfully. C:\Windows\System32\Tasks\QtraxPlayer => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\QtraxPlayer => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6191ED3B-3AB0-49B7-85E9-A5E390E35655} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6191ED3B-3AB0-49B7-85E9-A5E390E35655} => Key deleted successfully. C:\Windows\System32\Tasks\{0CD87B15-CF3F-4EEE-BC63-28679996E99D} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0CD87B15-CF3F-4EEE-BC63-28679996E99D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{648C2BCE-D24D-48FF-9DC7-5019D7A80801} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{648C2BCE-D24D-48FF-9DC7-5019D7A80801} => Key deleted successfully. C:\Windows\System32\Tasks\FoxTab => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FoxTab => Key deleted successfully. C:\Windows\Tasks\FoxTab.job => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8A244612-A1F7-11E0-95C0-E71F4824019B} => Key deleted successfully. HKCR\CLSID\{8A244612-A1F7-11E0-95C0-E71F4824019B} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d970ed5-3eda-438d-bffd-715931e2775b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{1d970ed5-3eda-438d-bffd-715931e2775b} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{82B16A3D-F03E-4565-A532-666B219C9A53} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{82B16A3D-F03E-4565-A532-666B219C9A53} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{d28c7e56-2cc6-415c-8727-d71334085926} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{d28c7e56-2cc6-415c-8727-d71334085926} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp => Key deleted successfully. C:\Users\mojojo\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx => Moved successfully. DiscountfinderService => Service deleted successfully. WinRing0_1_2_0 => Service deleted successfully. C:\dummy.wav => Moved successfully. C:\Program Files (x86)\Mobogenie => Moved successfully. C:\ProgramData\Odkrywca Rabatów => Moved successfully. C:\Users\mojojo\.android => Moved successfully. C:\Users\mojojo\daemonprocess.txt => Moved successfully. C:\Users\mojojo\AppData\Local\omesuperv.exe => Moved successfully. C:\Users\mojojo\AppData\Local\ext_offermosquito => Moved successfully. C:\Users\mojojo\AppData\Local\cache => Moved successfully. C:\Users\mojojo\AppData\Local\genienext => Moved successfully. C:\Users\mojojo\AppData\Local\Mobogenie => Moved successfully. C:\Users\mojojo\AppData\Roaming\newnext.me => Moved successfully. C:\Users\mojojo\AppData\Roaming\Intermediate => Moved successfully. C:\Users\mojojo\AppData\Roaming\SCheck => Moved successfully. C:\Users\mojojo\AppData\Roaming\Snz => Moved successfully. C:\Users\mojojo\AppData\Roaming\SSync => Moved successfully. C:\Users\mojojo\Documents\Mobogenie => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====