Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 22-11-2013 01 Ran by Marta at 2013-11-22 22:03:52 Run:1 Running from C:\Users\Marta\Desktop\Nowy folder (2) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\...\Run: [Facebook Update] - C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-11-18] (Facebook Inc.) HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe C:\Program Files (x86)\Mobogenie SearchScopes: HKCU - {BC2A20AF-53F9-4C2C-85D1-C40E10091EF0} URL = http://websearch.ask...DF-CC0102EDACE7 Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File CHR RestoreOnStartup: "hxxp://www.google.pl/", "hxxp://home.sweetim.com/?crg=3.1010000&st=10&barid={2C5ACA6A-580F-4CBF-B9C4-1F9CBEE5C544}", "hxxp://www.google.com" CHR DefaultSearchURL: (SweetIM Search) - http://search.sweeti...4-1F9CBEE5C544} CHR DefaultSuggestURL: (SweetIM Search) - "suggest_url": "", CHR HKLM-x32\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\Marta\AppData\Local\Temp\ccex.crx C:\Users\Marta\AppData\Local\Temp\ccex.crx CHR HKLM-x32\...\Chrome\Extension: [jhjjdgbhohaallcimgcmakfiobacimkm] - C:\Program Files (x86)\BuzzSearch\jhjjdgbhohaallcimgcmakfiobacimkm.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x] 2013-11-21 19:44 - 2013-11-22 21:02 - 00000000 ____D C:\Users\Marta\AppData\Local\Mobogenie 2013-11-21 19:44 - 2013-11-22 20:57 - 00001033 _____ C:\Users\Marta\daemonprocess.txt 2013-11-21 19:44 - 2013-11-22 00:30 - 00000000 ____D C:\Users\Marta\AppData\Local\cache 2013-11-21 19:44 - 2013-11-21 19:44 - 00000000 ____D C:\Users\Marta\Documents\Mobogenie C:\Users\Marta\AppData\Local\Temp\rtdrvmon.exe ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. C:\Program Files (x86)\Mobogenie => Moved successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BC2A20AF-53F9-4C2C-85D1-C40E10091EF0} => Key deleted successfully. HKCR\CLSID\{BC2A20AF-53F9-4C2C-85D1-C40E10091EF0} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully. HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. CHR RestoreOnStartup: "hxxp://www.google.pl/", "hxxp://home.sweetim.com/?crg=3.1010000&st=10&barid={2C5ACA6A-580F-4CBF-B9C4-1F9CBEE5C544}", "hxxp://www.google.com" ==> The Chrome "Settings" can be used to fix the entry. CHR DefaultSearchURL: (SweetIM Search) - http://search.sweeti...4-1F9CBEE5C544} ==> The Chrome "Settings" can be used to fix the entry. CHR DefaultSuggestURL: (SweetIM Search) - "suggest_url": "", ==> The Chrome "Settings" can be used to fix the entry. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bejbohlohkkgompgecdcbbglkpjfjgdj => Key deleted successfully. "C:\Users\Marta\AppData\Local\Temp\ccex.crx" => File/Directory not found. "C:\Users\Marta\AppData\Local\Temp\ccex.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jhjjdgbhohaallcimgcmakfiobacimkm => Key deleted successfully. "C:\Program Files (x86)\BuzzSearch\jhjjdgbhohaallcimgcmakfiobacimkm.crx" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. pccsmcfd => Service deleted successfully. C:\Users\Marta\AppData\Local\Mobogenie => Moved successfully. C:\Users\Marta\daemonprocess.txt => Moved successfully. C:\Users\Marta\AppData\Local\cache => Moved successfully. C:\Users\Marta\Documents\Mobogenie => Moved successfully. C:\Users\Marta\AppData\Local\Temp\rtdrvmon.exe => Moved successfully. ==== End of Fixlog ====