Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-09-2014 01 Ran by SYSTEM at 2014-09-08 20:51:27 Run:1 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** S2 Winmgmt; C:\Users\Kuba\AppData\Local\Temp\Low\mqmqiflf8z.faa [332020 2014-04-01] (Microsoft Corporation) S2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [118056 2014-04-23] (Elex do Brasil Participaçoes Ltda) S2 MgAssistService; C:\Program Files (x86)\Mobogenie\MgAssist.exe [70848 2014-04-17] () S3 iSafeKrnl; C:\Program Files (x86)\iSafe\iSafeKrnl.sys [232960 2014-04-23] (Elex do Brasil Participaçoes Ltda) S1 iSafeKrnlKit; C:\Program Files (x86)\iSafe\iSafeKrnlKit.sys [66048 2014-04-23] (Elex do Brasil Participaçoes Ltda) S1 iSafeNetFilter; C:\Program Files (x86)\iSafe\iSafeNetFilter.sys [48128 2014-04-23] (Elex do Brasil Participaçoes Ltda) S3 iSafeKrnlBoot; \??\system32\DRIVERS\iSafeKrnlBoot.sys [X] HKLM-x32\...\Run: [tuto4pc_pl_17] => [X] HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [761536 2014-01-06] () HKLM-x32\...\Run: [GPULoader] => C:\Program Files (x86)\VLC Player GPU+\GPULog.exe [1303776 2013-12-13] () HKLM-x32\...\Run: [GPUTemp] => C:\Users\Kuba\AppData\Local\Temp\GPUTemp.exe [1312136 2014-01-09] () HKU\Kuba\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\Kuba\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l Startup: C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hfrev9h.lnk GroupPolicy: Group Policy on Chrome detected <======= ATTENTION C:\ProgramData\2992199F9A C:\Users\Kuba\daemonprocess.txt C:\Users\Kuba\AppData\Local\Temp ***************** Winmgmt => Service restored successfully. iSafeService => Service deleted successfully. MgAssistService => Service deleted successfully. iSafeKrnl => Service deleted successfully. iSafeKrnlKit => Service deleted successfully. iSafeNetFilter => Service deleted successfully. iSafeKrnlBoot => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\tuto4pc_pl_17 => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GPULoader => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GPUTemp => value deleted successfully. HKU\Kuba\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => value deleted successfully. C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hfrev9h.lnk => Moved successfully. C:\Windows\System32\GroupPolicy\Machine => Moved successfully. C:\Windows\System32\GroupPolicy\GPT.ini => Moved successfully. C:\ProgramData\2992199F9A => Moved successfully. C:\Users\Kuba\daemonprocess.txt => Moved successfully. C:\Users\Kuba\AppData\Local\Temp => Moved successfully. ==== End of Fixlog ====