Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-01-2015 Ran by Lila i Leoś at 2015-01-13 10:35:21 Run:1 Running from C:\Users\Lila i Leoś\Desktop\novość\vir Loaded Profile: Lila i Leoś (Available profiles: Piotr & Lila i Leoś) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: CHR HomePage: Default -> hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871 CHR StartupUrls: Default -> "hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871" CHR DefaultSearchKeyword: Default -> omiga-plus FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\omiga-plus.xml HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hppp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hppp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hppp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hppp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-4010961823-3175815874-2470197352-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hppp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871 HKU\S-1-5-21-4010961823-3175815874-2470197352-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hppp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871&q={searchTerms} SearchScopes: HKU\S-1-5-21-4010961823-3175815874-2470197352-1004 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871&q={searchTerms} SearchScopes: HKU\S-1-5-21-4010961823-3175815874-2470197352-1004 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420384816&from=cor&uid=WDCXWD1600BEVT-22ZCT0_WD-WXF0EA9NF871NF871&q={searchTerms} SearchScopes: HKU\S-1-5-21-4010961823-3175815874-2470197352-1004 -> {BDF61FAE-9D19-40F0-8F34-688DEB334CA9} URL = http://securedsearch.lavasoft.com/results.php?pr=vmn&id=webcompa&ent=ch_WCYID10005_searchprotect_150106&q={searchTerms} Task: {0763D332-922D-4F75-875F-9737ACAB4518} - System32\Tasks\{92BD45AA-F9D1-4401-A5D3-FBE94F33CC69} => pcalua.exe -a C:\Sterowniki\sp56036.exe -d C:\Sterowniki Task: {1DD74D9B-4544-46CA-ACA3-03EB03C7AA3C} - System32\Tasks\{8B3A637E-C34B-4706-9A4B-6B0B6B66DACA} => pcalua.exe -a C:\Sterowniki\sp54972.exe -d C:\Sterowniki Task: {4F722DFE-8CD3-4C7F-8B59-07F5B4333507} - System32\Tasks\{8973FED7-90FF-4549-AFD2-E03AECCBD3F9} => pcalua.exe -a C:\Sterowniki\sp54746.exe -d C:\Sterowniki Task: {A323FA2C-2C35-40C2-9FDF-8DCA642F88BA} - System32\Tasks\{83C99E33-DAE7-4F55-B7C9-D3338F7ACBFA} => pcalua.exe -a C:\Sterowniki\sp57965.exe -d C:\Sterowniki Task: {E1A22F5F-A272-46F7-9BA8-D5A55F575EE6} - System32\Tasks\{5B21E07D-D17B-4DCA-99BE-F277A37152E1} => pcalua.exe -a C:\Sterowniki\sp53753.exe -d C:\Sterowniki C:\Program Files (x86)\XTab C:\ProgramData\IHProtectUpDate C:\ProgramData\WindowsMangerProtect C:\Users\Lila i Leoś\AppData\Local\CrashDumps C:\Users\Lila i Leoś\AppData\Roaming\omiga-plus C:\Users\Lila i Leoś\AppData\Roaming\WebTest C:\Users\Piotr\AppData\Local\CrashDumps C:\Users\Piotr\AppData\Roaming\rmi Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f EmptyTemp: ***************** Processes closed successfully. Error: (0) Failed to create a restore point. Chrome HomePage deleted successfully. Chrome StartupUrls deleted successfully. Chrome DefaultSearchKeyword deleted successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\omiga-plus.xml => Moved successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-4010961823-3175815874-2470197352-1004\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-4010961823-3175815874-2470197352-1004\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKU\S-1-5-21-4010961823-3175815874-2470197352-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-4010961823-3175815874-2470197352-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-4010961823-3175815874-2470197352-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}" => Key deleted successfully. HKCR\CLSID\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0763D332-922D-4F75-875F-9737ACAB4518}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0763D332-922D-4F75-875F-9737ACAB4518}" => Key deleted successfully. C:\Windows\System32\Tasks\{92BD45AA-F9D1-4401-A5D3-FBE94F33CC69} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{92BD45AA-F9D1-4401-A5D3-FBE94F33CC69}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1DD74D9B-4544-46CA-ACA3-03EB03C7AA3C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DD74D9B-4544-46CA-ACA3-03EB03C7AA3C}" => Key deleted successfully. C:\Windows\System32\Tasks\{8B3A637E-C34B-4706-9A4B-6B0B6B66DACA} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8B3A637E-C34B-4706-9A4B-6B0B6B66DACA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4F722DFE-8CD3-4C7F-8B59-07F5B4333507}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F722DFE-8CD3-4C7F-8B59-07F5B4333507}" => Key deleted successfully. C:\Windows\System32\Tasks\{8973FED7-90FF-4549-AFD2-E03AECCBD3F9} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8973FED7-90FF-4549-AFD2-E03AECCBD3F9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A323FA2C-2C35-40C2-9FDF-8DCA642F88BA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A323FA2C-2C35-40C2-9FDF-8DCA642F88BA}" => Key deleted successfully. C:\Windows\System32\Tasks\{83C99E33-DAE7-4F55-B7C9-D3338F7ACBFA} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{83C99E33-DAE7-4F55-B7C9-D3338F7ACBFA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E1A22F5F-A272-46F7-9BA8-D5A55F575EE6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1A22F5F-A272-46F7-9BA8-D5A55F575EE6}" => Key deleted successfully. C:\Windows\System32\Tasks\{5B21E07D-D17B-4DCA-99BE-F277A37152E1} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5B21E07D-D17B-4DCA-99BE-F277A37152E1}" => Key deleted successfully. C:\Program Files (x86)\XTab => Moved successfully. C:\ProgramData\IHProtectUpDate => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\Users\Lila i Leoś\AppData\Local\CrashDumps => Moved successfully. C:\Users\Lila i Leoś\AppData\Roaming\omiga-plus => Moved successfully. C:\Users\Lila i Leoś\AppData\Roaming\WebTest => Moved successfully. C:\Users\Piotr\AppData\Local\CrashDumps => Moved successfully. C:\Users\Piotr\AppData\Roaming\rmi => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 439.6 MB temporary data. The system needed a reboot. ==== End of Fixlog 10:35:38 ====