Could you let me know how the computer is behaving after this
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKU\S-1-5-21-2312140610-3093738394-554808494-1000\...\Run: [StartNow Search Protect] => "C:\Program Files (x86)\StartNow Toolbar\search_protect.exe" /RELAY /REPORT /PROTECT
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2312140610-3093738394-554808494-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1418247491&from=cor&uid=HitachiXHTS547564A9E384_J2180053H05ZHDH05ZHDX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1418247491&from=cor&uid=HitachiXHTS547564A9E384_J2180053H05ZHDH05ZHDX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1418247491&from=cor&uid=HitachiXHTS547564A9E384_J2180053H05ZHDH05ZHDX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1418247491&from=cor&uid=HitachiXHTS547564A9E384_J2180053H05ZHDH05ZHDX&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2312140610-3093738394-554808494-1000 -> {0388404D-6072-4CEB-B521-8F090FEAEE57} URL = http://klit.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.3.0&install_country=PL&install_date=20111014&user_guid=F6460DD530214C9AAAD74D62472B23DD&machine_id=d5547a51585469a973b16cad29bc03f8&browser=IE&os=win&os_version=6.1-x64-SP1&iesrc={referrer:source}
SearchScopes: HKU\S-1-5-21-2312140610-3093738394-554808494-1000 -> {65570E13-F247-4657-97B8-DAE4F77B75B6} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=0C1D3270-3F25-4A79-98AB-D6AAD91E4975&apn_sauid=1A4F9BD6-F65E-45AD-BEEE-44016D34781F
SearchScopes: HKU\S-1-5-21-2312140610-3093738394-554808494-1000 -> {A67DB1D5-E7D7-44FB-B1D3-87BE25F87450} URL = http://services.zinio.com/search?s={searchTerms}&rf=sonyslices
SearchScopes: HKU\S-1-5-21-2312140610-3093738394-554808494-1000 -> {ABD93EAF-D775-BC54-E63B-2804F22FD156} URL = http://search.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=startnow&provider_code=&partner_id=999&product_id=10&affiliate_id=&channel=&toolbar_id=&toolbar_version=&install_country=&install_date=20120904&user_guid=F6460DD530214C9AAAD74D62472B23DD&machine_id=d5547a51585469a973b16cad29bc03f8&browser=IE&os=win&os_version=6.1-x64-SP1&iesrc={referrer:source}
SearchScopes: HKU\S-1-5-21-2312140610-3093738394-554808494-1000 -> {C7DCD23C-5143-44B1-9F28-14F9797B11AF} URL = http://start.funmoods.com/results.php?f=4&a=ddrnw&q={searchTerms}
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1418247491&from=cor&uid=HitachiXHTS547564A9E384_J2180053H05ZHDH05ZHDX
R1 {c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64; C:\Windows\System32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys [61072 2014-09-03] (StdLib)
Task: {5E54ACF9-69BD-42B5-826A-569A965F573B} - System32\Tasks\Hoolapp For Android => C:\Users\Judyta\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {5E61AA82-45B9-4C85-A614-C89BAF0309E4} - System32\Tasks\Hoolapp Init => C:\Users\Judyta\AppData\Roaming\HOOLAP~1\Hoolapp.exe <==== ATTENTION
S1 ccnfd_1_10_0_4; system32\drivers\ccnfd_1_10_0_4.sys [X]
C:\Program Files (x86)\Mobogenie
C:\Program Files (x86)\StartNow Toolbar
C:\Windows\System32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys
C:\Users\Judyta\AppData\Roaming\HOOLAP~1
C:\Users\Judyta\AppData\Local\Temp\is420858837
C:\Users\Judyta\AppData\Local\Temp\~dlFA78
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.