Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-05-2014 Ran by Tadeusz at 2014-05-05 11:33:22 Run:1 Running from C:\Users\Tadeusz\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** (Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe S2 6ea8c3d5; "C:\WINDOWS\system32\rundll32.exe" "c:\progra~3\prowebi\ProwebiSvc.dll",service HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [761536 2014-01-07] () HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [fst_pl_106] => C:\Program Files (x86)\fst_pl_106\fst_pl_106.exe [3984880 2014-04-22] () HKU\S-1-5-21-1538742642-4175228606-3249170137-1001\...\Run: [NextLive] => C:\WINDOWS\SysWOW64\rundll32.exe "C:\Users\Tadeusz\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKU\S-1-5-21-1538742642-4175228606-3249170137-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1538742642-4175228606-3249170137-1001\...\Run: [Desk 365] => C:\Program Files (x86)\Desk 365\desk365.exe [1013808 2014-02-01] (337 Technology Limited.) AppInit_DLLs: C:\PROGRA~2\GS-ENA~1\ASSIST~2.DLL => C:\Program Files (x86)\GS-Enabler\Assistant_x64.dll [4229120 2014-01-23] () AppInit_DLLs: C:\PROGRA~3\Prowebi\PROWEB~1.DLL => C:\ProgramData\Prowebi\Prowebi_x64.dll [4585472 2014-03-16] () Task: {1DC91A70-4EA3-4005-935F-D7E6E06F260B} - System32\Tasks\WinZipDriverUpdater_UPDATES => C:\Program Files (x86)\WinZip Driver Updater\winzipdu.exe [2013-07-11] (WinZip Computing, S.L. (WinZip Computing)) Task: {49DE4BFA-563C-4BD2-B20B-179152026EC9} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe [2014-02-01] (337 Technology Limited.) <==== ATTENTION Task: {74BC48B5-BDC5-4CF9-9DCA-0A8B010BA5FA} - System32\Tasks\WinZipDriverUpdaterRunAtStartup => C:\Program Files (x86)\WinZip Driver Updater\winzipdu.exe [2013-07-11] (WinZip Computing, S.L. (WinZip Computing)) Task: {A82C0E60-6282-4CA1-A0DD-075200CF7CC3} - System32\Tasks\GS-Enabler-S-993492499 => c:\programdata\house of soft\gs-enabler\GS-Enabler.exe <==== ATTENTION Task: {F57043A6-110A-419D-A02F-9029504512F6} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\updater.exe [2013-12-18] () <==== ATTENTION Task: C:\WINDOWS\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\GS-Enabler-S-993492499.job => c:\programdata\house of soft\gs-enabler\GS-Enabler.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\WinZipDriverUpdater_UPDATES.job => C:\Program Files (x86)\WinZip Driver Updater\winzipdu.exe ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.awesomehp.com/?type=sc&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 ShortcutWithArgument: C:\Users\Tadeusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.awesomehp.com/?type=sc&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 ShortcutWithArgument: C:\Users\Tadeusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.awesomehp.com/?type=sc&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 ShortcutWithArgument: C:\Users\Tadeusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.awesomehp.com/?type=sc&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 ShortcutWithArgument: C:\Users\Tadeusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.awesomehp.com/?type=sc&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1390349093&from=cor&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.awesomehp.com/web/?type=ds&ts=1391269165&from=ild&uid=WDCXWD5000BEVT-26A0RT0_WD-WXC1A201342513425&q={searchTerms} Hosts: 54.204.28.26 nikdaiaidiiiogaidkkekcmokcgcdeac CHR HKLM-x32\...\Chrome\Extension: [pkndmigholgfjlniaohblojbhgjbkakn] - C:\Users\Tadeusz\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx [2014-01-22] GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION C:\ProgramData\Microsoft\Windows\Start Menu\Programs\free_soft_to_day C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365 C:\Users\Tadeusz\AppData\Roaming\newnext.me C:\Users\Tadeusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie C:\Users\Tadeusz\AppData\Roaming\Microsoft\Windows\SendTo\Desk 365.lnk Reboot: ***************** [1608] C:\ProgramData\WPM\wprotectmanager.exe => Process closed successfully. 6ea8c3d5 => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_pl_106 => Value deleted successfully. HKU\S-1-5-21-1538742642-4175228606-3249170137-1001\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKU\S-1-5-21-1538742642-4175228606-3249170137-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value deleted successfully. HKU\S-1-5-21-1538742642-4175228606-3249170137-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Desk 365 => Value deleted successfully. "C:\PROGRA~2\GS-ENA~1\ASSIST~2.DLL" => Value Data removed successfully. "C:\PROGRA~3\Prowebi\PROWEB~1.DLL" => Value Data removed successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1DC91A70-4EA3-4005-935F-D7E6E06F260B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DC91A70-4EA3-4005-935F-D7E6E06F260B} => Key deleted successfully. C:\Windows\System32\Tasks\WinZipDriverUpdater_UPDATES => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinZipDriverUpdater_UPDATES => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{49DE4BFA-563C-4BD2-B20B-179152026EC9} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{49DE4BFA-563C-4BD2-B20B-179152026EC9} => Key deleted successfully. C:\Windows\System32\Tasks\Desk 365 RunAsStdUser => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{74BC48B5-BDC5-4CF9-9DCA-0A8B010BA5FA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{74BC48B5-BDC5-4CF9-9DCA-0A8B010BA5FA} => Key deleted successfully. C:\Windows\System32\Tasks\WinZipDriverUpdaterRunAtStartup => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinZipDriverUpdaterRunAtStartup => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A82C0E60-6282-4CA1-A0DD-075200CF7CC3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A82C0E60-6282-4CA1-A0DD-075200CF7CC3} => Key deleted successfully. C:\Windows\System32\Tasks\GS-Enabler-S-993492499 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GS-Enabler-S-993492499 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F57043A6-110A-419D-A02F-9029504512F6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F57043A6-110A-419D-A02F-9029504512F6} => Key deleted successfully. C:\Windows\System32\Tasks\bench-sys => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bench-sys => Key deleted successfully. C:\WINDOWS\Tasks\bench-sys.job => Moved successfully. C:\WINDOWS\Tasks\GS-Enabler-S-993492499.job => Moved successfully. C:\WINDOWS\Tasks\WinZipDriverUpdater_UPDATES.job => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Tadeusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Tadeusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Tadeusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\Tadeusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pkndmigholgfjlniaohblojbhgjbkakn => Key deleted successfully. C:\Users\Tadeusz\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx => Moved successfully. C:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully. C:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\free_soft_to_day => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365 => Moved successfully. C:\Users\Tadeusz\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Tadeusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie => Moved successfully. C:\Users\Tadeusz\AppData\Roaming\Microsoft\Windows\SendTo\Desk 365.lnk => Moved successfully. The system needed a reboot. ==== End of Fixlog ====