Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-01-2014 Ran by Łukasz at 2014-01-29 14:33:22 Run:1 Running from C:\Users\Łukasz\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [761024 2013-12-13] () HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0 HKLM\...\Policies\Explorer: [HideSCAHealth] 0 HKCU\...\Policies\Explorer: [TaskbarNoNotification] 0 HKCU\...\Policies\Explorer: [HideSCAHealth] 0 SearchScopes: HKLM-x32 - DefaultScope {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = http://search.speedbit.com/search.aspx?s=CCVb105&q={searchTerms} SearchScopes: HKLM-x32 - {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = http://search.speedbit.com/search.aspx?s=CCVb105&q={searchTerms} SearchScopes: HKCU - {1631341D-82DA-421E-A3D5-B425A02B2E25} URL = http://websearch.ask.com/redirect?client=ie&tb=CLM&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=&apn_uid=150121FB-A444-4E97-B64D-F553BBD78B86&apn_sauid=86012D41-73F7-4DFD-88EE-8C2D3C54AEF7& SearchScopes: HKCU - {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = http://search.speedbit.com/search.aspx?s=CCVb105&q={searchTerms} Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Task: {04663755-BE83-4B37-ABB5-96C48BB93175} - System32\Tasks\{304C2C91-82CE-4C1E-B7AE-C790F0A71129} => Iexplore.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=5.8.0.154&LastError=12007 Task: {D81E16CB-A6E1-48E9-BEA1-5ADCDE1066AA} - System32\Tasks\{AB84BF47-2ECE-488E-9E61-361FF0CEAC88} => Iexplore.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=5.8.0.154&LastError=12007 S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [x] C:\Program Files (x86)\Mobogenie C:\ProgramData\mscieiuu.exe C:\ProgramData\msjgsji.exe C:\ProgramData\msjvoio.exe C:\ProgramData\Norton C:\Users\Łukasz\.android C:\Users\Łukasz\daemonprocess.txt C:\Users\Łukasz\AppData\Local\genienext C:\Users\Łukasz\AppData\Local\Mobogenie C:\Users\Łukasz\AppData\Roaming\*.exe CMD: sc config MpsSvc start= auto CMD: sc config wscsvc start= delayed-auto CMD: sc config wuauserv start= delayed-auto Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ***************** [2288] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe => Process closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\TaskbarNoNotification => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\TaskbarNoNotification => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7F4EFF06-7032-458e-AE16-1C1D8255C28A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1631341D-82DA-421E-A3D5-B425A02B2E25} => Key deleted successfully. HKCR\CLSID\{1631341D-82DA-421E-A3D5-B425A02B2E25} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A} => Key deleted successfully. HKCR\CLSID\{7F4EFF06-7032-458e-AE16-1C1D8255C28A} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully. HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{04663755-BE83-4B37-ABB5-96C48BB93175} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{04663755-BE83-4B37-ABB5-96C48BB93175} => Key deleted successfully. C:\Windows\System32\Tasks\{304C2C91-82CE-4C1E-B7AE-C790F0A71129} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{304C2C91-82CE-4C1E-B7AE-C790F0A71129} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D81E16CB-A6E1-48E9-BEA1-5ADCDE1066AA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D81E16CB-A6E1-48E9-BEA1-5ADCDE1066AA} => Key deleted successfully. C:\Windows\System32\Tasks\{AB84BF47-2ECE-488E-9E61-361FF0CEAC88} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AB84BF47-2ECE-488E-9E61-361FF0CEAC88} => Key deleted successfully. VBoxNetFlt => Service deleted successfully. C:\Program Files (x86)\Mobogenie => Moved successfully. C:\ProgramData\mscieiuu.exe => Moved successfully. C:\ProgramData\msjgsji.exe => Moved successfully. C:\ProgramData\msjvoio.exe => Moved successfully. C:\ProgramData\Norton => Moved successfully. C:\Users\Łukasz\.android => Moved successfully. C:\Users\Łukasz\daemonprocess.txt => Moved successfully. C:\Users\Łukasz\AppData\Local\genienext => Moved successfully. C:\Users\Łukasz\AppData\Local\Mobogenie => Moved successfully. C:\Users\Łukasz\AppData\Roaming\*.exe => Moved successfully. ========= sc config MpsSvc start= auto ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= sc config wscsvc start= delayed-auto ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= sc config wuauserv start= delayed-auto ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====