Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 12-10-2014 Ran by Monika at 2014-10-12 21:08:56 Run:1 Running from C:\Users\Monika\Downloads Loaded Profile: Monika (Available profiles: Monika) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R1 {825c5be7-672f-4c14-9929-48a3a5e1a660}w; C:\Windows\System32\drivers\{825c5be7-672f-4c14-9929-48a3a5e1a660}w.sys [52928 2014-06-30] (StdLib) R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw.sys [52928 2014-05-22] (StdLib) R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w.sys [52928 2014-06-18] (StdLib) HKU\S-1-5-21-1264134706-63761012-746677018-1000\...\Run: [NextLive] => C:\Windows\system32\rundll32.exe "C:\Users\Monika\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l BootExecute: autocheck autochk * auto_reactivate \\?\Volume{ae7c3b46-7879-11e3-87cd-806e6f6e6963}\bootwiz\asrm.bin SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Task: {58972628-D167-4630-91E9-792F4671E2FC} - System32\Tasks\{48DE3E24-0AD2-4E72-BE15-FF589BB2EE2F} => G:\mobilenavigator\MobileNavigator.exe Task: {8A9D976C-654B-4C79-A389-984D8C6A08E6} - System32\Tasks\{0AD98648-70BF-4833-816F-C3B099E4F375} => G:\mobilenavigator\MobileNavigator.exe Task: {B62A20E8-81D2-45EE-947B-CD5A0ED810DD} - System32\Tasks\FoxTab => C:\Users\Monika\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {E5559E67-281F-4BB3-87D0-E843A0C4A8F6} - System32\Tasks\{276B106C-5263-4A7A-9363-20088552A97E} => G:\mobilenavigator\MobileNavigator.exe Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Monika\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION C:\Program Files\Mobogenie3 C:\Program Files\Rock Turner C:\Users\Monika\AppData\Local\Mobogenie C:\Users\Monika\AppData\Roaming\Mobogenie C:\Users\Monika\AppData\Roaming\newnext.me C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie C:\Users\Monika\Documents\Mobogenie C:\Windows\System32\drivers\{825c5be7-672f-4c14-9929-48a3a5e1a660}w.sys C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw.sys C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w.sys Folder: C:\Windows\system32\GroupPolicy DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 CMD: sc config "PLAY ONLINE. RunOuc" start= demand EmptyTemp: ***************** Processes closed successfully. {825c5be7-672f-4c14-9929-48a3a5e1a660}w => Service stopped successfully. {825c5be7-672f-4c14-9929-48a3a5e1a660}w => Service deleted successfully. {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw => Service stopped successfully. {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw => Service deleted successfully. {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w => Service stopped successfully. {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w => Service deleted successfully. HKU\S-1-5-21-1264134706-63761012-746677018-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => value deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{58972628-D167-4630-91E9-792F4671E2FC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58972628-D167-4630-91E9-792F4671E2FC}" => Key deleted successfully. C:\Windows\System32\Tasks\{48DE3E24-0AD2-4E72-BE15-FF589BB2EE2F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{48DE3E24-0AD2-4E72-BE15-FF589BB2EE2F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8A9D976C-654B-4C79-A389-984D8C6A08E6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9D976C-654B-4C79-A389-984D8C6A08E6}" => Key deleted successfully. C:\Windows\System32\Tasks\{0AD98648-70BF-4833-816F-C3B099E4F375} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0AD98648-70BF-4833-816F-C3B099E4F375}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B62A20E8-81D2-45EE-947B-CD5A0ED810DD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B62A20E8-81D2-45EE-947B-CD5A0ED810DD}" => Key deleted successfully. C:\Windows\System32\Tasks\FoxTab => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FoxTab" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E5559E67-281F-4BB3-87D0-E843A0C4A8F6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E5559E67-281F-4BB3-87D0-E843A0C4A8F6}" => Key deleted successfully. C:\Windows\System32\Tasks\{276B106C-5263-4A7A-9363-20088552A97E} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{276B106C-5263-4A7A-9363-20088552A97E}" => Key deleted successfully. C:\Windows\Tasks\FoxTab.job => Moved successfully. C:\Program Files\Mobogenie3 => Moved successfully. C:\Program Files\Rock Turner => Moved successfully. C:\Users\Monika\AppData\Local\Mobogenie => Moved successfully. C:\Users\Monika\AppData\Roaming\Mobogenie => Moved successfully. C:\Users\Monika\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie => Moved successfully. C:\Users\Monika\Documents\Mobogenie => Moved successfully. C:\Windows\System32\drivers\{825c5be7-672f-4c14-9929-48a3a5e1a660}w.sys => Moved successfully. C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw.sys => Moved successfully. C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w.sys => Moved successfully. ========================= Folder: C:\Windows\system32\GroupPolicy ======================== ====== End of Folder: ====== HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => Key Deleted Successfully. ========= sc config "PLAY ONLINE. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= EmptyTemp: => Removed 104.1 MB temporary data. The system needed a reboot. ==== End of Fixlog ====