Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-04-2015 Ran by Mama at 2015-04-28 11:31:51 Run:2 Running from G:\diag Loaded Profiles: Mama (Available profiles: user & Mama) Boot Mode: Normal ============================================== Content of fixlist: ***************** ShortcutTarget: AllroadAudi.zip.lnk -> C:\ProgramData\{5fbdcd42-a6dd-ae98-5fbd-dcd42a6d350a}\AllroadAudi.zip.exe (No File) ShortcutTarget: GIANTS_Editor_5.0.1_win32.rar.lnk -> C:\ProgramData\{7095f087-c8c0-d377-7095-5f087c8cc21f}\GIANTS_Editor_5.0.1_win32.rar.exe (No File) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simp...e3-bab2c67b894e SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://q.search-simp...q={searchTerms} S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X] C:\WINDOWS\Minidump\042815-26640-01.dmp C:\Users\user\Downloads\Microsoft-Office(25796)-dp.exe C:\ProgramData\DowNNSSaVe C:\ProgramData\BiitSaver C:\ProgramData\RanddomPrice C:\ProgramData\Extreme Blocker Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** C:\ProgramData\{5fbdcd42-a6dd-ae98-5fbd-dcd42a6d350a}\AllroadAudi.zip.exe not found. C:\ProgramData\{7095f087-c8c0-d377-7095-5f087c8cc21f}\GIANTS_Editor_5.0.1_win32.rar.exe not found. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. xhunter1 => Service deleted successfully. C:\WINDOWS\Minidump\042815-26640-01.dmp => Moved successfully. C:\Users\user\Downloads\Microsoft-Office(25796)-dp.exe => Moved successfully. C:\ProgramData\DowNNSSaVe => Moved successfully. C:\ProgramData\BiitSaver => Moved successfully. C:\ProgramData\RanddomPrice => Moved successfully. C:\ProgramData\Extreme Blocker => Moved successfully. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 3.3 GB temporary data. The system needed a reboot. ==== End of Fixlog 11:33:25 ====