Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-04-2015 04 Ran by Haneczka at 2015-04-16 14:51:26 Run:1 Running from C:\Users\Hania\Downloads Loaded Profiles: Haneczka (Available profiles: Haneczka) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: Task: {8FDE39BB-6871-44B9-8A92-D4A8F7BBFC81} - System32\Tasks\Gamma Task Menager Cleaner => C:\Program Files (x86)\Gamma Task Menager\ gtrsecure.exe [2015-04-04] (SecureSoft) Task: {A96C207B-3468-4711-8462-31ABF5FB52B5} - System32\Tasks\Win Installer => C:\Users\Hania\AppData\Local\Updater\winupd.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files (x86)\AVG C:\Program Files (x86)\Gamma Task Menager C:\Program Files (x86)\Mozilla Firefox\distribution C:\Program Files (x86)\PathModule C:\Program Files (x86)\RelaySoft C:\Program Files (x86)\Zoom Hover Enlarge photos Beta C:\ProgramData\6503224410389159353 C:\ProgramData\MFAData C:\Users\Hania\AppData\Local\MFAData C:\Users\Hania\AppData\Roaming\8FE7.tmp C:\Users\Hania\AppData\Roaming\8FE7.tmp.exe C:\Users\Hania\AppData\Roaming\94C9.tmp C:\Users\Hania\AppData\Roaming\94C9.tmp.exe C:\Users\Hania\AppData\Roaming\em_64x64.ico C:\Users\Hania\AppData\Roaming\TuneUp Software Reg: reg delete HKCU\Software\Google\Chrome /f Reg: reg delete HKCU\Software\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} /f Reg: reg delete HKCU\Software\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f RemoveProxy: EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8FDE39BB-6871-44B9-8A92-D4A8F7BBFC81}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FDE39BB-6871-44B9-8A92-D4A8F7BBFC81}" => Key deleted successfully. C:\Windows\System32\Tasks\Gamma Task Menager Cleaner => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Gamma Task Menager Cleaner" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A96C207B-3468-4711-8462-31ABF5FB52B5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A96C207B-3468-4711-8462-31ABF5FB52B5}" => Key deleted successfully. C:\Windows\System32\Tasks\Win Installer => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Win Installer" => Key deleted successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully. C:\Program Files (x86)\AVG => Moved successfully. C:\Program Files (x86)\Gamma Task Menager => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\distribution => Moved successfully. C:\Program Files (x86)\PathModule => Moved successfully. C:\Program Files (x86)\RelaySoft => Moved successfully. C:\Program Files (x86)\Zoom Hover Enlarge photos Beta => Moved successfully. C:\ProgramData\6503224410389159353 => Moved successfully. C:\ProgramData\MFAData => Moved successfully. C:\Users\Hania\AppData\Local\MFAData => Moved successfully. C:\Users\Hania\AppData\Roaming\8FE7.tmp => Moved successfully. C:\Users\Hania\AppData\Roaming\8FE7.tmp.exe => Moved successfully. C:\Users\Hania\AppData\Roaming\94C9.tmp => Moved successfully. C:\Users\Hania\AppData\Roaming\94C9.tmp.exe => Moved successfully. C:\Users\Hania\AppData\Roaming\em_64x64.ico => Moved successfully. C:\Users\Hania\AppData\Roaming\TuneUp Software => Moved successfully. ========= reg delete HKCU\Software\Google\Chrome /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete HKCU\Software\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete HKCU\Software\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully. HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully. HKU\S-1-5-21-3708558119-1453270157-3961042179-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully. HKU\S-1-5-21-3708558119-1453270157-3961042179-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully. ========= End of RemoveProxy: ========= EmptyTemp: => Removed 441 MB temporary data. The system needed a reboot. ==== End of Fixlog 14:52:12 ====