Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01 Ran by PC at 2015-02-20 14:05:52 Run:1 Running from C:\Users\PC\Desktop\programy do usuniecia huntera Loaded Profiles: PC (Available profiles: PC) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-1765589224-887387816-2075540833-1000\...\Run: [SoftonicAssistant] => "C:\Users\PC\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe" HKU\S-1-5-21-1765589224-887387816-2075540833-1000\...\MountPoints2: {9497dbae-90f6-11e4-83c7-00a0c6000000} - J:\AutoRun.exe Task: {0638C36D-BE9F-44B9-9807-E1797F53CC6F} - System32\Tasks\{2357E72E-B93F-4FE8-A5FB-EA468755C856} => pcalua.exe -a C:\Users\PC\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=cor <==== ATTENTION Task: {2D779EDE-6E56-4A76-9B42-65791634C53A} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-01-26] (Enigma Software Group USA, LLC.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com SearchScopes: HKU\S-1-5-21-1765589224-887387816-2075540833-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = C:\Program Files (x86)\Google C:\Users\PC\AppData\Local\Opera Software C:\Users\PC\AppData\Roaming\Opera Software C:\Users\PC\Downloads\*(*)-dp*.exe Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKU\S-1-5-21-1765589224-887387816-2075540833-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SoftonicAssistant => value deleted successfully. "HKU\S-1-5-21-1765589224-887387816-2075540833-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9497dbae-90f6-11e4-83c7-00a0c6000000}" => Key deleted successfully. HKCR\CLSID\{9497dbae-90f6-11e4-83c7-00a0c6000000} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0638C36D-BE9F-44B9-9807-E1797F53CC6F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0638C36D-BE9F-44B9-9807-E1797F53CC6F}" => Key deleted successfully. C:\Windows\System32\Tasks\{2357E72E-B93F-4FE8-A5FB-EA468755C856} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2357E72E-B93F-4FE8-A5FB-EA468755C856}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D779EDE-6E56-4A76-9B42-65791634C53A} => Key not found. C:\Windows\System32\Tasks\SpyHunter4Startup not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpyHunter4Startup => Key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. "HKU\S-1-5-21-1765589224-887387816-2075540833-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. C:\Program Files (x86)\Google => Moved successfully. C:\Users\PC\AppData\Local\Opera Software => Moved successfully. C:\Users\PC\AppData\Roaming\Opera Software => Moved successfully. C:\Users\PC\Downloads\*(*)-dp*.exe => Moved successfully. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 644.1 MB temporary data. The system needed a reboot. ==== End of Fixlog 14:07:23 ====