Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-10-2014 01 Ran by mrukk at 2014-10-02 21:49:23 Run:1 Running from C:\Users\mrukk\Desktop Loaded Profile: mrukk (Available profiles: mrukk) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM-x32\...\Run: [] => [X] HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-2253055635-1566063098-3438977135-1001\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON GroupPolicy: Group Policy on Chrome detected <======= ATTENTION FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] Task: {513AC4F2-F651-4192-A54F-DBFB018871D2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {B6222F43-504D-408A-91B7-7C5DF8246766} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe C:\sh4ldr C:\shldr C:\shldr.mbr C:\spyhunter.fix C:\Program Files (x86)\Enigma Software Group C:\Program Files (x86)\Lavasoft C:\Program Files (x86)\GoSavve C:\Program Files (x86)\YouttubbeeAdBlloCkE C:\ProgramData\7678176e9a8d3a03 C:\ProgramData\GoSavve C:\ProgramData\Pokki C:\ProgramData\YouttubbeeAdBlloCkE C:\Users\HomeGroupUser$ C:\Users\Administrator C:\Users\Gość C:\Users\mrukk\AppData\Local\Chromatic Browser C:\Users\mrukk\AppData\Local\Comodo C:\Users\mrukk\AppData\Local\Pokki C:\Users\mrukk\AppData\Local\Torch C:\Users\mrukk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acer Games.lnk C:\Users\mrukk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk C:\Users\mrukk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk C:\Users\mrukk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lavasoft Ad-aware 6 C:\Users\mrukk\Downloads\SpyHunter 4.16.5.4290 [Eng]+patch.rar C:\Users\mrukk\Downloads\Thumbs.db C:\WINDOWS\SysWOW64\GroupPolicy\GPT.INI EmptyTemp: ***************** Processes closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully. HKU\S-1-5-21-2253055635-1566063098-3438977135-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Pokki => Value not found. C:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully. C:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3" => Key deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9" => Key deleted successfully. gupdate => Service deleted successfully. gupdatem => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{513AC4F2-F651-4192-A54F-DBFB018871D2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{513AC4F2-F651-4192-A54F-DBFB018871D2}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B6222F43-504D-408A-91B7-7C5DF8246766}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B6222F43-504D-408A-91B7-7C5DF8246766}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully. C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully. C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully. C:\sh4ldr => Moved successfully. C:\shldr => Moved successfully. C:\shldr.mbr => Moved successfully. C:\spyhunter.fix => Moved successfully. C:\Program Files (x86)\Enigma Software Group => Moved successfully. C:\Program Files (x86)\Lavasoft => Moved successfully. C:\Program Files (x86)\GoSavve => Moved successfully. C:\Program Files (x86)\YouttubbeeAdBlloCkE => Moved successfully. C:\ProgramData\7678176e9a8d3a03 => Moved successfully. C:\ProgramData\GoSavve => Moved successfully. C:\ProgramData\Pokki => Moved successfully. C:\ProgramData\YouttubbeeAdBlloCkE => Moved successfully. C:\Users\HomeGroupUser$ => Moved successfully. C:\Users\Administrator => Moved successfully. C:\Users\Gość => Moved successfully. C:\Users\mrukk\AppData\Local\Chromatic Browser => Moved successfully. C:\Users\mrukk\AppData\Local\Comodo => Moved successfully. "C:\Users\mrukk\AppData\Local\Pokki" => File/Directory not found. C:\Users\mrukk\AppData\Local\Torch => Moved successfully. "C:\Users\mrukk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acer Games.lnk" => File/Directory not found. "C:\Users\mrukk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk" => File/Directory not found. "C:\Users\mrukk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk" => File/Directory not found. C:\Users\mrukk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lavasoft Ad-aware 6 => Moved successfully. C:\Users\mrukk\Downloads\SpyHunter 4.16.5.4290 [Eng]+patch.rar => Moved successfully. C:\Users\mrukk\Downloads\Thumbs.db => Moved successfully. C:\WINDOWS\SysWOW64\GroupPolicy\GPT.INI => Moved successfully. EmptyTemp: => Removed 1019.7 MB temporary data. The system needed a reboot. ==== End of Fixlog ====