Fix result of Farbar Recovery Scan Tool (x64) Version: 25-05-2015 Ran by Meg at 2015-05-25 22:47:50 Run:1 Running from C:\Users\Meg\Downloads Loaded Profiles: Meg (Available Profiles: Meg) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: HKLM-x32\...\Run: [Driver Genius] => [X] HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\Meg\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\...\Run: [Tiny download manager] => "C:\Users\Meg\AppData\Local\DM\TinyDM.exe" /M HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1420019463&from=wpm12311&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1420019463&from=wpm12311&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1394281731&from=cor&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1394281731&from=cor&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1420019463&from=wpm12311&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1420019463&from=wpm12311&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1394281731&from=cor&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1394281731&from=cor&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1402681045&from=wpm0612&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1420019463&from=wpm12311&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1420019463&from=wpm12311&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1402681045&from=wpm0612&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1394281731&from=cor&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1394281731&from=cor&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1394281731&from=cor&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1394281731&from=cor&uid=TOSHIBAXMK2565GSXN_11V1PBYQTXX11V1PBYQT&q={searchTerms} SearchScopes: HKU\S-1-5-21-3394211285-2232929740-4212499475-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3394211285-2232929740-4212499475-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3394211285-2232929740-4212499475-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3394211285-2232929740-4212499475-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3394211285-2232929740-4212499475-1000 -> {AE4FECE8-B724-4A91-ABB7-157552E539B8} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3394211285-2232929740-4212499475-1000 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3394211285-2232929740-4212499475-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll No File Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll No File R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [602112 2015-05-20] (Windows SysTool) [] <==== ATTENTION Task: {9088C4A7-73AE-4709-A8A8-0D5408393A14} - System32\Tasks\DigitalSite => C:\Users\Meg\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {CDB902AE-365E-4AB0-8B4E-19BFE98A852C} - System32\Tasks\Digital Sites => C:\Users\Meg\AppData\Roaming\DIGITA~2\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\Digital Sites.job => C:\Users\Meg\AppData\Roaming\DIGITA~2\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\Meg\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION EmptyTemp: ***************** Processes closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Driver Genius => value Removed successfully HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => value Removed successfully HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Tiny download manager => value Removed successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key Removed successfully HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key Removed successfully HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value Removed successfully "HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key Removed successfully HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. "HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => key Removed successfully HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. "HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key Removed successfully HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. "HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AE4FECE8-B724-4A91-ABB7-157552E539B8}" => key Removed successfully HKCR\CLSID\{AE4FECE8-B724-4A91-ABB7-157552E539B8} => key not found. "HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}" => key Removed successfully HKCR\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => key not found. "HKU\S-1-5-21-3394211285-2232929740-4212499475-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => key Removed successfully HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} => value Removed successfully "HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}" => key Removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} => value Removed successfully "HKCR\Wow6432Node\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}" => key Removed successfully WindowsMangerProtect => Service Removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9088C4A7-73AE-4709-A8A8-0D5408393A14}" => key Removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9088C4A7-73AE-4709-A8A8-0D5408393A14}" => key Removed successfully C:\Windows\System32\Tasks\DigitalSite => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigitalSite" => key Removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CDB902AE-365E-4AB0-8B4E-19BFE98A852C}" => key Removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CDB902AE-365E-4AB0-8B4E-19BFE98A852C}" => key Removed successfully C:\Windows\System32\Tasks\Digital Sites => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Digital Sites" => key Removed successfully C:\Windows\Tasks\Digital Sites.job => Moved successfully. C:\Windows\Tasks\DigitalSite.job => Moved successfully. EmptyTemp: => Removed 411.3 MB temporary data. The system needed a reboot. ==== End of Fixlog 22:49:07 ====