﻿Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015
Ran by Marta at 2015-01-30 12:46:22 Run:1
Running from C:\Users\Marta\Downloads
Loaded Profiles: UpdatusUser & Marta (Available profiles: UpdatusUser & Marta)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter\Uninstall SpyHunter.lnk
Task: {B8BAA54C-A0A7-4E60-AD1F-4265AC8DBA21} - System32\Tasks\At1 => C:\Users\Marta\AppData\Roaming\BCWorker.exe <==== ATTENTION
Task: C:\Windows\Tasks\At1.job => C:\Users\Marta\AppData\Roaming\BCWorker.exe
C:\Users\Marta\AppData\Roaming\BCWorker.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [debmkdhphjfcbaomiknnceliiclnpmfg] - C:\Program Files (x86)\Jump Flip\debmkdhphjfcbaomiknnceliiclnpmfg.crx [Not Found]
C:\Program Files (x86)\Jump Flip
CHR HKU\S-1-5-21-423685702-225076681-3893953433-1002\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Marta\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-01-06]
CHR HKU\S-1-5-21-423685702-225076681-3893953433-1002\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path
CHR HomePage: Default -> hxxp://isearch.?type=hppppppppp
CHR DefaultSearchURL: Default -> http://isearch.web/?type=dspp&q={searchTerms}
C:\Windows\Tasks\At1.job
CHR Extension: (Internet Program) - C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbahljckiigflncclhoikcdboljmmdcm [2015-01-29]
BHO-x32: Internet Program -> {ff0021ad-2cc3-4e0d-8e3c-b4153a64a495} -> C:\Program Files (x86)\Internet Program\Extensions\ff0021ad-2cc3-4e0d-8e3c-b4153a64a495.dll ()
C:\Program Files (x86)\Internet Program
EmptyTemp:
*****************

C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter\Uninstall SpyHunter.lnk => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B8BAA54C-A0A7-4E60-AD1F-4265AC8DBA21}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B8BAA54C-A0A7-4E60-AD1F-4265AC8DBA21}" => Key deleted successfully.
C:\Windows\System32\Tasks\At1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\At1" => Key deleted successfully.
C:\Windows\Tasks\At1.job => Moved successfully.
"C:\Users\Marta\AppData\Roaming\BCWorker.exe" => File/Directory not found.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\debmkdhphjfcbaomiknnceliiclnpmfg" => Key deleted successfully.
"C:\Program Files (x86)\Jump Flip" => File/Directory not found.
"HKU\S-1-5-21-423685702-225076681-3893953433-1002\SOFTWARE\Google\Chrome\Extensions\apdfllckaahabafndbhieahigkjlhalf" => Key deleted successfully.
C:\Users\Marta\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx => Moved successfully.
"HKU\S-1-5-21-423685702-225076681-3893953433-1002\SOFTWARE\Google\Chrome\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh" => Key deleted successfully.
Chrome HomePage deleted successfully.
Chrome DefaultSearchURL not detected.
"C:\Windows\Tasks\At1.job" => File/Directory not found.
C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbahljckiigflncclhoikcdboljmmdcm => Moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ff0021ad-2cc3-4e0d-8e3c-b4153a64a495}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{ff0021ad-2cc3-4e0d-8e3c-b4153a64a495}" => Key deleted successfully.
C:\Program Files (x86)\Internet Program => Moved successfully.
EmptyTemp: => Removed 177.8 MB temporary data.


The system needed a reboot. 

==== End of Fixlog 12:47:23 ====