Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-02-2015 01 Ran by User at 2015-02-05 13:30:48 Run:1 Running from C:\Users\User\Desktop Loaded Profiles: User (Available profiles: User & UpdatusUser) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: Task: {A6CC8B56-B41C-4228-96A1-10D34946E422} - System32\Tasks\juixzej => C:\Users\User\AppData\Local\Temp\hglomif.exe [2015-02-04] () <==== ATTENTION C:\ProgramData\oiukxod.html C:\Users\User\Documents\!Decrypt-All-Files-pogkqql.bmp C:\Users\User\Documents\!Decrypt-All-Files-pogkqql.txt Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f CMD: sc config "PLAY ONLINE. RunOuc" start= disabled EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A6CC8B56-B41C-4228-96A1-10D34946E422}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A6CC8B56-B41C-4228-96A1-10D34946E422}" => Key deleted successfully. C:\Windows\System32\Tasks\juixzej => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\juixzej" => Key deleted successfully. C:\ProgramData\oiukxod.html => Moved successfully. C:\Users\User\Documents\!Decrypt-All-Files-pogkqql.bmp => Moved successfully. C:\Users\User\Documents\!Decrypt-All-Files-pogkqql.txt => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= sc config "PLAY ONLINE. RunOuc" start= disabled ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= EmptyTemp: => Removed 774.3 MB temporary data. The system needed a reboot. ==== End of Fixlog 13:32:00 ====