Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-01-2014 Ran by Monika at 2014-01-10 08:17:50 Run:1 Running from C:\Users\Monika\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {B6609A44-1449-4E53-AA48-4D43F14A5491} - System32\Tasks\AmiUpdXp => C:\Users\Monika\AppData\Local\SwvUpdater\Updater.exe [2013-12-11] (Amonetizé Ltd) Task: C:\windows\Tasks\AmiUpdXp.job => C:\Users\Monika\AppData\Local\SwvUpdater\Updater.exe HKLM-x32\...\Run: [NWEReboot] - [x] HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKCU\...\Run: [ISUSPM] - "C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe" -scheduler HKCU\...\Run: [NextLive] - C:\windows\SysWOW64\rundll32.exe "C:\Users\Monika\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://idg.pl/start HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=147 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=147 SearchScopes: HKCU - DefaultScope {969AF36E-0CE4-4F3C-8AA3-EE72556C182A} URL = http://www.idg.pl?q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=2E6E8A039ACB1212&affID=119357&tt=160713_91114&tsp=4945 SearchScopes: HKCU - {969AF36E-0CE4-4F3C-8AA3-EE72556C182A} URL = http://www.idg.pl?q={searchTerms} Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File BHO-x32: Webexp Enhanced - {f7444c6b-3578-46e1-abbd-d03999042fe6} - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha6238\ie\WebexpEnhancedV1alpha6238.dll () FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha6238.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha6238\ff CHR HKLM-x32\...\Chrome\Extension: [boabmhagdlngcpliiindolpjoljjggla] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha6238\ch\WebexpEnhancedV1alpha6238.crx C:\Program Files (x86)\Mobogenie C:\Users\Monika\.android C:\Users\Monika\daemonprocess.txt C:\Users\Monika\AppData\Local\cache C:\Users\Monika\AppData\Local\genienext C:\Users\Monika\AppData\Local\Mobogenie C:\Users\Monika\AppData\Roaming\eCyber C:\Users\Monika\AppData\Roaming\iSafe C:\Users\Monika\AppData\Roaming\newnext.me C:\Users\Monika\Documents\Mobogenie ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B6609A44-1449-4E53-AA48-4D43F14A5491} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B6609A44-1449-4E53-AA48-4D43F14A5491} => Key deleted successfully. C:\Windows\System32\Tasks\AmiUpdXp => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AmiUpdXp => Key deleted successfully. C:\windows\Tasks\AmiUpdXp.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NWEReboot => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{969AF36E-0CE4-4F3C-8AA3-EE72556C182A} => Key deleted successfully. HKCR\CLSID\{969AF36E-0CE4-4F3C-8AA3-EE72556C182A} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully. HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f7444c6b-3578-46e1-abbd-d03999042fe6} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{f7444c6b-3578-46e1-abbd-d03999042fe6} => Key deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@WebexpEnhancedV1alpha6238.net => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\boabmhagdlngcpliiindolpjoljjggla => Key deleted successfully. C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha6238\ch\WebexpEnhancedV1alpha6238.crx => Moved successfully. C:\Program Files (x86)\Mobogenie => Moved successfully. C:\Users\Monika\.android => Moved successfully. C:\Users\Monika\daemonprocess.txt => Moved successfully. C:\Users\Monika\AppData\Local\cache => Moved successfully. C:\Users\Monika\AppData\Local\genienext => Moved successfully. C:\Users\Monika\AppData\Local\Mobogenie => Moved successfully. C:\Users\Monika\AppData\Roaming\eCyber => Moved successfully. C:\Users\Monika\AppData\Roaming\iSafe => Moved successfully. C:\Users\Monika\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Monika\Documents\Mobogenie => Moved successfully. ==== End of Fixlog ====