Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-01-2014 01 Ran by Pawel at 2014-01-31 02:06:24 Run:1 Running from C:\Users\Pawel\Desktop\fixit Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Users\Pawel\AppData\Local\fst_pl_30\upfst_pl_30.exe HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM-x32\...\Run: [GPUTemp] - C:\Users\Pawel\AppData\Local\Temp\GPUTemp.exe [1305312 2014-01-08] () HKLM-x32\...\RunOnce: [upfst_pl_30.exe] - C:\Users\Pawel\AppData\Local\fst_pl_30\upfst_pl_30.exe -runonce [3153904 2014-01-02] () HKCU\...\Run: [NextLive] - C:\Users\Pawel\AppData\Roaming\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe) AppInit_DLLs: c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll => File Not Found AppInit_DLLs-x32: c:\progra~3\bitguard\271769~1.27\{c16c1~1\bitguard.dll => File Not Found SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = Toolbar: HKLM-x32 - TelevisionFanatic - {c98d5b61-b0ea-4d48-9839-1079d352d880} - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\64bar.dll No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File FF Plugin-x32: @TelevisionFanatic.com/Plugin - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\NP64Stub.dll No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\sweet-page.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml Task: {8949A0D6-CCEC-4311-AFFF-D83E69662C06} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{2BE1742F-66C4-4E04-8D6B-C132715408C2}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{2BE1742F-66C4-4E04-8D6B-C132715408C2}.exe S2 Update Jump Flip; "C:\Program Files (x86)\Jump Flip\updateJumpFlip.exe" [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] U3 tmlwf; U3 tmwfp; S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [x] C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml C:\Program Files (x86)\Mobogenie C:\ProgramData\WPM C:\Users\Pawel\daemonprocess.txt C:\Users\Pawel\AppData\Local\cache C:\Users\Pawel\AppData\Local\genienext C:\Users\Pawel\AppData\Local\Mobogenie C:\Users\Pawel\AppData\Local\Temp\*.exe C:\Users\Pawel\AppData\Local\Temp\*.dll C:\Users\Pawel\AppData\Roaming\newnext.me C:\Users\Pawel\Desktop\Continue AnyProtect Installation.lnk C:\Users\Pawel\Documents\Mobogenie ***************** [2920] C:\Users\Pawel\AppData\Local\fst_pl_30\upfst_pl_30.exe => Process closed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Setwallpaper => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GPUTemp => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\upfst_pl_30.exe => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. "c:\\progra~3\\bitguard\\271769~1.27\\{c16c1~1\\loader.dll" => Value Data removed successfully. "c:\\progra~3\\bitguard\\271769~1.27\\{c16c1~1\\bitguard.dll" => Value Data removed successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully. HKCR\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{c98d5b61-b0ea-4d48-9839-1079d352d880} => Value not found. HKCR\Wow6432Node\CLSID\{c98d5b61-b0ea-4d48-9839-1079d352d880} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully. HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found. HKCR\PROTOCOLS\Handler\linkscanner => Key deleted successfully. HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => Key deleted successfully. HKCR\Wow6432Node\PROTOCOLS\Handler\linkscanner => Key not found. HKCR\Wow6432Node\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => Key deleted successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@TelevisionFanatic.com/Plugin => Key deleted successfully. C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\NP64Stub.dll not found. "C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml" => not found. C:\Program Files (x86)\mozilla firefox\searchplugins\sweet-page.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8949A0D6-CCEC-4311-AFFF-D83E69662C06} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8949A0D6-CCEC-4311-AFFF-D83E69662C06} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Key deleted successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. Update Jump Flip => Service deleted successfully. catchme => Service deleted successfully. tmlwf => Service deleted successfully. tmwfp => Service deleted successfully. VBoxNetFlt => Service deleted successfully. C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml => Moved successfully. C:\Program Files (x86)\Mobogenie => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\Users\Pawel\daemonprocess.txt => Moved successfully. C:\Users\Pawel\AppData\Local\cache => Moved successfully. C:\Users\Pawel\AppData\Local\genienext => Moved successfully. C:\Users\Pawel\AppData\Local\Mobogenie => Moved successfully. "C:\Users\Pawel\AppData\Local\Temp\*.exe" => File/Directory not found. "C:\Users\Pawel\AppData\Local\Temp\*.dll" => File/Directory not found. C:\Users\Pawel\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Pawel\Desktop\Continue AnyProtect Installation.lnk => Moved successfully. C:\Users\Pawel\Documents\Mobogenie => Moved successfully. ==== End of Fixlog ====