Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 02-01-2014 01 Ran by asd at 2014-01-03 23:21:34 Run:1 Running from D:\Krzysiek Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files\Mobogenie\DaemonProcess.exe () C:\Documents and Settings\asd\nhrij.exe HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe [761536 2014-01-02] () HKCU\...\Run: [nhrij] - C:\Documents and Settings\asd\nhrij.exe [49152 2013-11-06] () HKCU\...\Run: [NextLive] - C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\asd\Dane aplikacji\newnext.me\nengine.dll",EntryPoint -m l HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=510EF81A671828A6&affID=119357&tt=110913_221&tsp=5002 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=510EF81A671828A6&affID=119357&tt=110913_221&tsp=5002 SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689 URL = SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=510EF81A671828A6&affID=119357&tt=110913_221&tsp=5002 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear R2 PirritUpdater; C:\Program Files\Pirrit\AutoUpdater.exe [55296 2013-11-28] () S2 SystemTimer; S1 cjcqjpiu; \??\C:\WINDOWS\system32\drivers\cjcqjpiu.sys [x] S3 GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [x] S3 NTACCESS; \??\F:\NTACCESS.sys [x] S3 PCAMPR5; \??\C:\WINDOWS\system32\PCAMPR5.SYS [x] S3 SetupNTGLM7X; \??\F:\NTGLM7X.sys [x] S3 taphss; system32\DRIVERS\taphss.sys [x] C:\Documents and Settings\asd\nhrij.exe C:\Documents and Settings\asd\syslinux.exe C:\Documents and Settings\asd\.android C:\Documents and Settings\asd\daemonprocess.txt C:\Documents and Settings\asd\Dane aplikacji\newnext.me C:\Documents and Settings\asd\Dane aplikacji\Pirrit C:\Documents and Settings\asd\Dane aplikacji\Systweak C:\Documents and Settings\asd\Moje dokumenty\Mobogenie C:\Documents and Settings\asd\Ustawienia lokalne\Dane aplikacji\cache C:\Documents and Settings\asd\Ustawienia lokalne\Dane aplikacji\genienext C:\Documents and Settings\asd\Ustawienia lokalne\Dane aplikacji\Mobogenie C:\Documents and Settings\All Users\Dane aplikacji\Common Files C:\Documents and Settings\All Users\Dane aplikacji\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F} C:\Documents and Settings\All Users\Dane aplikacji\Tarma Installer C:\Documents and Settings\All Users\Dane aplikacji\TEMP C:\Program Files\Mobogenie C:\Program Files\Pirrit CMD: for /d %f in (C:\FOUND.*) do rd /s /q "%f" Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f ***************** [352] C:\Program Files\Mobogenie\DaemonProcess.exe => Process closed successfully. [1964] C:\Documents and Settings\asd\nhrij.exe => Process closed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\nhrij => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. PirritUpdater => Service deleted successfully. SystemTimer => Service deleted successfully. cjcqjpiu => Service deleted successfully. GMSIPCI => Service deleted successfully. NTACCESS => Service deleted successfully. PCAMPR5 => Service deleted successfully. SetupNTGLM7X => Service deleted successfully. taphss => Service deleted successfully. C:\Documents and Settings\asd\nhrij.exe => Moved successfully. C:\Documents and Settings\asd\syslinux.exe => Moved successfully. C:\Documents and Settings\asd\.android => Moved successfully. Could not move "C:\Documents and Settings\asd\daemonprocess.txt" => Scheduled to move on reboot. C:\Documents and Settings\asd\Dane aplikacji\newnext.me => Moved successfully. C:\Documents and Settings\asd\Dane aplikacji\Pirrit => Moved successfully. C:\Documents and Settings\asd\Dane aplikacji\Systweak => Moved successfully. C:\Documents and Settings\asd\Moje dokumenty\Mobogenie => Moved successfully. C:\Documents and Settings\asd\Ustawienia lokalne\Dane aplikacji\cache => Moved successfully. C:\Documents and Settings\asd\Ustawienia lokalne\Dane aplikacji\genienext => Moved successfully. C:\Documents and Settings\asd\Ustawienia lokalne\Dane aplikacji\Mobogenie => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Common Files => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F} => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Tarma Installer => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\TEMP => Moved successfully. "C:\Program Files\Mobogenie" directory move: Could not move "C:\Program Files\Mobogenie" directory. => Scheduled to move on reboot. C:\Program Files\Pirrit => Moved successfully. ========= for /d %f in (C:\FOUND.*) do rd /s /q "%f" ========= ========= End of CMD: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-01-03 23:22:34)<= C:\Documents and Settings\asd\daemonprocess.txt => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. ==== End of Fixlog ====