Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by samsung at 2014-04-06 14:56:35 Run:1 Running from C:\Users\samsung\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.awesomehp.com/?type=sc&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1393109296&from=amt&uid=TOSHIBAXMQ01ABD032_52V2S7A4SXX52V2S7A4S&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [bbffdhejhaoiflnpooogkckfdcmmjppn] - C:\Program Files (x86)\FTDownloader.com\FTDownloader10.crx [2013-05-10] CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx [2014-02-23] DPF: HKLM-x32 {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKU\S-1-5-21-4209209786-2917733824-1122995674-1001\...\Run: [ares] - "C:\Program Files (x86)\Ares\Ares.exe" -h HKU\S-1-5-21-4209209786-2917733824-1122995674-1001\...\Run: [NextLive] - C:\windows\SysWOW64\rundll32.exe "C:\Users\samsung\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l Task: {241A6FB2-3CC9-4489-964F-D10D3BE66004} - System32\Tasks\AmiUpdXp => C:\Users\samsung\AppData\Local\SwvUpdater\Updater.exe [2014-02-23] Task: C:\windows\Tasks\AmiUpdXp.job => C:\Users\samsung\AppData\Local\SwvUpdater\Updater.exe C:\extensions.ini C:\Program Files (x86)\FTDownloader.com C:\Program Files (x86)\MediaViewV1 C:\Program Files (x86)\MediaViewerV1 C:\Program Files (x86)\MediaWatchV1 C:\Program Files (x86)\Mozilla Firefox C:\Users\samsung\AppData\Local\CrashDumps C:\Users\samsung\AppData\Local\genienext C:\Users\samsung\AppData\Local\PutLockerDownloader C:\Users\samsung\AppData\Local\SwvUpdater C:\Users\samsung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop C:\Users\samsung\AppData\Roaming\awesomehp C:\Users\samsung\AppData\Roaming\Babylon C:\Users\samsung\AppData\Roaming\Mozilla C:\Users\samsung\AppData\Roaming\newnext.me C:\Users\samsung\AppData\Roaming\SupTab C:\Windows\SysWOW64\GroupPolicy\GPT.INI Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reboot: ***************** HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. C:\windows\system32\GroupPolicy\Machine => Moved successfully. C:\windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bbffdhejhaoiflnpooogkckfdcmmjppn => Key deleted successfully. "C:\Program Files (x86)\FTDownloader.com\FTDownloader10.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma => Key deleted successfully. C:\Users\samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKU\S-1-5-21-4209209786-2917733824-1122995674-1001\Software\Microsoft\Windows\CurrentVersion\Run\\ares => Value deleted successfully. HKU\S-1-5-21-4209209786-2917733824-1122995674-1001\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{241A6FB2-3CC9-4489-964F-D10D3BE66004} => Key not found. C:\Windows\System32\Tasks\AmiUpdXp not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AmiUpdXp => Key not found. C:\windows\Tasks\AmiUpdXp.job not found. C:\extensions.ini => Moved successfully. "C:\Program Files (x86)\FTDownloader.com" => File/Directory not found. C:\Program Files (x86)\MediaViewV1 => Moved successfully. C:\Program Files (x86)\MediaViewerV1 => Moved successfully. C:\Program Files (x86)\MediaWatchV1 => Moved successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. C:\Users\samsung\AppData\Local\CrashDumps => Moved successfully. C:\Users\samsung\AppData\Local\genienext => Moved successfully. C:\Users\samsung\AppData\Local\PutLockerDownloader => Moved successfully. "C:\Users\samsung\AppData\Local\SwvUpdater" => File/Directory not found. C:\Users\samsung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop => Moved successfully. C:\Users\samsung\AppData\Roaming\awesomehp => Moved successfully. C:\Users\samsung\AppData\Roaming\Babylon => Moved successfully. C:\Users\samsung\AppData\Roaming\Mozilla => Moved successfully. C:\Users\samsung\AppData\Roaming\newnext.me => Moved successfully. C:\Users\samsung\AppData\Roaming\SupTab => Moved successfully. C:\Windows\SysWOW64\GroupPolicy\GPT.INI => Moved successfully. ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====