Fix result of Farbar Recovery Scan Tool (x64) Version:26-07-2015 Ran by Pierre at 2015-07-27 12:12:55 Run:1 Running from C:\Users\Pierre\Downloads Loaded Profiles: Pierre (Available Profiles: Pierre & Charline) Boot Mode: Normal ============================================== fixlist content: ***************** start CloseProcesses: Hosts: CreateRestorePoint: HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKU\S-1-5-21-527946215-2594331359-894958616-1000\...\Run: [Wahoo] => C:\Users\Pierre\AppData\Local\WahOO\WahOO.exe [4298992 2015-02-11] () HKU\S-1-5-21-527946215-2594331359-894958616-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Pierre\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.) HKU\S-1-5-21-527946215-2594331359-894958616-1000\...\Run: [60C7.tmp] => C:\Users\Pierre\AppData\Local\Temp\60C7.tmp.mod [466944 2015-07-22] ( ) <===== ATTENTION SearchScopes: HKU\S-1-5-21-527946215-2594331359-894958616-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 2015-07-22 22:35 - 2014-04-02 11:43 - 00000268 _____ C:\Windows\Tasks\AutoKMS.job 2013-03-01 11:28 - 2013-03-01 11:28 - 0000069 _____ () C:\Users\Pierre\AppData\Roaming\Camdata.ini 2013-03-01 11:28 - 2013-03-01 11:28 - 0000408 _____ () C:\Users\Pierre\AppData\Roaming\CamLayout.ini 2013-03-01 11:28 - 2013-03-01 11:28 - 0000408 _____ () C:\Users\Pierre\AppData\Roaming\CamShapes.ini C:\Users\Pierre\AppData\Local\Temp\60C7.tmp.mod Task: {8B7A4349-2FFB-49B2-A01B-1336666A1458} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe C:\Windows\AutoKMS\AutoKMS.exe Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe AlternateDataStreams: C:\Windows:7731F0471C5C51D2 FirewallRules: [TCP Query User{D3D8FD5B-6474-4A81-8B04-FCD3DDB66B68}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe FirewallRules: [UDP Query User{64FBF9B9-2A62-48E5-82EF-AE98A80B2775}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe EmptyTemp: end ***************** Processes closed successfully. C:\Windows\System32\Drivers\etc\hosts => moved successfully. Hosts restored successfully. Restore point was successfully created. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => value removed successfully "C:\Program Files (x86)\Mobogenie\DaemonProcess.exe" => File/Folder not found. HKU\S-1-5-21-527946215-2594331359-894958616-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Wahoo => value removed successfully HKU\S-1-5-21-527946215-2594331359-894958616-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => value removed successfully HKU\S-1-5-21-527946215-2594331359-894958616-1000\Software\Microsoft\Windows\CurrentVersion\Run\\60C7.tmp => value not found. HKU\S-1-5-21-527946215-2594331359-894958616-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully C:\Windows\Tasks\AutoKMS.job => moved successfully. C:\Users\Pierre\AppData\Roaming\Camdata.ini => moved successfully. C:\Users\Pierre\AppData\Roaming\CamLayout.ini => moved successfully. C:\Users\Pierre\AppData\Roaming\CamShapes.ini => moved successfully. "C:\Users\Pierre\AppData\Local\Temp\60C7.tmp.mod" => File/Folder not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8B7A4349-2FFB-49B2-A01B-1336666A1458}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B7A4349-2FFB-49B2-A01B-1336666A1458}" => key removed successfully C:\Windows\System32\Tasks\AutoKMS => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => key removed successfully "C:\Windows\AutoKMS\AutoKMS.exe" => File/Folder not found. C:\Windows\Tasks\AutoKMS.job not found. C:\Windows => ":7731F0471C5C51D2" ADS removed successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{D3D8FD5B-6474-4A81-8B04-FCD3DDB66B68}C:\windows\kmsemulator.exe => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{64FBF9B9-2A62-48E5-82EF-AE98A80B2775}C:\windows\kmsemulator.exe => value removed successfully EmptyTemp: => 4.1 GB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 12:13:33 ====