Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-01-2015 Ran by hp at 2015-01-13 10:57:44 Run:1 Running from C:\Users\hp\Downloads Loaded Profile: hp (Available profiles: hp) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: CHR HomePage: Default -> hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420807008&from=cor&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1C10J4899J4899 CHR StartupUrls: Default -> "hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420807008&from=cor&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1C10J4899J4899" CHR DefaultSearchKeyword: Default -> omiga-plus FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\r0b4gam5.default-1398015625036\extensions\fftoolbar2014@etech.com HKU\S-1-5-21-1804019565-2671705643-3176753893-1000\...\Run: [uTorrent] => "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED HKU\S-1-5-21-1804019565-2671705643-3176753893-1000\...\RunOnce: [Adobe Speed Launcher] => 1420912912 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com Task: {3DBDAB1F-5A9E-4410-A5AB-1A6FEEEEEB6C} - System32\Tasks\{F9197757-C919-468A-B36A-8B2C8D32E2BF} => pcalua.exe -a C:\Users\hp\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=cor Task: {90F7DD4F-40DB-4356-87C1-E7CD09B4ACBC} - System32\Tasks\{34263E96-713E-4670-A8D9-99B5FA726AF4} => pcalua.exe -a C:\Users\hp\AppData\Local\Temp\Temp1_revouninstaller.zip\revouninstaller-portable\Revouninstaller.exe C:\Program Files (x86)\Opera C:\Program Files (x86)\XTab C:\Users\hp\AppData\Local\Opera Software C:\Users\hp\AppData\Roaming\Opera Software C:\Users\hp\Desktop\ukryte ikony\Adobe Reader 9.lnk C:\Users\hp\Desktop\ukryte ikony\avast! Free Antivirus.lnk C:\Users\hp\Desktop\ukryte ikony\WildTangent Games App - hp.lnk Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{41A039C8-007B-4277-83B3-B55D3A908598}" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{41A039C8-007B-4277-83B3-B55D3A908598}" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. Chrome HomePage deleted successfully. Chrome StartupUrls deleted successfully. Chrome DefaultSearchKeyword not detected. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\fftoolbar2014@etech.com => value deleted successfully. HKU\S-1-5-21-1804019565-2671705643-3176753893-1000\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value deleted successfully. HKU\S-1-5-21-1804019565-2671705643-3176753893-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Adobe Speed Launcher => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3DBDAB1F-5A9E-4410-A5AB-1A6FEEEEEB6C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DBDAB1F-5A9E-4410-A5AB-1A6FEEEEEB6C}" => Key deleted successfully. C:\Windows\System32\Tasks\{F9197757-C919-468A-B36A-8B2C8D32E2BF} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F9197757-C919-468A-B36A-8B2C8D32E2BF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{90F7DD4F-40DB-4356-87C1-E7CD09B4ACBC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{90F7DD4F-40DB-4356-87C1-E7CD09B4ACBC}" => Key deleted successfully. C:\Windows\System32\Tasks\{34263E96-713E-4670-A8D9-99B5FA726AF4} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{34263E96-713E-4670-A8D9-99B5FA726AF4}" => Key deleted successfully. C:\Program Files (x86)\Opera => Moved successfully. C:\Program Files (x86)\XTab => Moved successfully. C:\Users\hp\AppData\Local\Opera Software => Moved successfully. C:\Users\hp\AppData\Roaming\Opera Software => Moved successfully. C:\Users\hp\Desktop\ukryte ikony\Adobe Reader 9.lnk => Moved successfully. C:\Users\hp\Desktop\ukryte ikony\avast! Free Antivirus.lnk => Moved successfully. C:\Users\hp\Desktop\ukryte ikony\WildTangent Games App - hp.lnk => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{41A039C8-007B-4277-83B3-B55D3A908598}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{41A039C8-007B-4277-83B3-B55D3A908598}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 80.2 MB temporary data. The system needed a reboot. ==== End of Fixlog 10:59:27 ====