Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 05-01-2014 Ran by Admin at 2014-01-07 22:33:43 Run:1 Running from C:\Users\Admin\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [] - [x] HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKCU\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\Admin\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKCU\...\Policies\Explorer: [] R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-07] (Cherished Technololgy LIMITED) HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-page.com/?type=hp&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1389050743&from=cor&uid=HitachiXHTS723225L9A362_090214FC3D00NJG4K9HDX&q={searchTerms} C:\Program Files\Free YouTube Downloader C:\Program Files\Mobogenie C:\ProgramData\WPM C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free YouTube Downloader C:\Users\Admin\.android C:\Users\Admin\daemonprocess.txt C:\Users\Admin\AppData\Local\genienext C:\Users\Admin\AppData\Local\Mobogenie C:\Users\Admin\AppData\Roaming\newnext.me C:\Users\Admin\Documents\Mobogenie C:\Users\Admin\Downloads\FreeYouTubeDownloaderInstallerIC.exe CMD: netsh advfirewall reset ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Value deleted successfully. Wpm => Service deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. C:\Program Files\Free YouTube Downloader => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free YouTube Downloader => Moved successfully. C:\Users\Admin\.android => Moved successfully. C:\Users\Admin\daemonprocess.txt => Moved successfully. C:\Users\Admin\AppData\Local\genienext => Moved successfully. C:\Users\Admin\AppData\Local\Mobogenie => Moved successfully. C:\Users\Admin\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Admin\Documents\Mobogenie => Moved successfully. C:\Users\Admin\Downloads\FreeYouTubeDownloaderInstallerIC.exe => Moved successfully. ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= ==== End of Fixlog ====