Код:
CreateRestorePoint:
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8px41v2LYlisPSeaFDpP-vmGTytZxwOx9e9uM5ZCfsLg5hyDk6qe3MPlf32XhZ3z0VkoGA513kJag,,
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8px41v2LYlisPSeaFDpP-vmGTytZxwOx9e9uM5ZCfsLg5hyDk6qe3MPlf32XhZ3z0VkoGA513kJag,,
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
HKU\S-1-5-21-1060284298-1284227242-1606980848-1006\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "about:newtab" <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
SearchScopes: HKLM -> {F4137D40-259A-4FB3-B780-F8C39B303C41} URL = hxxp://yandex.ru/yandsearch?clid=2101082&text={searchTerms}
SearchScopes: HKU\S-1-5-19 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
SearchScopes: HKU\S-1-5-20 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
SearchScopes: HKU\S-1-5-20 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1060284298-1284227242-1606980848-1006 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1060284298-1284227242-1606980848-1006 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bJ0TU3s5xiGQXpG5V0HM2PYwbt_rBUy3Bh1IkqzxmD9FRG1ANc3Lgj4L0RQr4QoT3EIesTz3PxCw,,&q={searchTerms}
FF SearchPlugin: C:\Documents and Settings\user-asu\Application Data\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\findit.xml [2015-12-10]
FF Extension: No Name - C:\Documents and Settings\user-asu\Application Data\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\[email protected] [2015-09-25] [not signed]
CHR HomePage: Default -> hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8bSLmonTHuxqaoKKB0gM2KLd5DIwO73HOGA5uiwReTjltFqfWhYiXeI1_ogzrU-bCz5PR8E2eJRVg,,
CHR DefaultSearchURL: Default -> hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSlN_zld4Bewb56CxE2VJE-QYebND2OXZoKskSeNOVYJeAkewyn0Nyj9xrYBfNX9SgdkFJlpngywXmgnSsm23TkvdNnk4zG8be1PggnSrxF_fEitNl_bhruyTMe1k8U9Q11qJZ6FcAUduepIRfqTi97nehvMf0JlFzv7OjPVMK7w,,&q={searchTerms}
CHR DefaultSearchKeyword: Default -> feed.sonic-search.com
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
S4 ApplicationHosting; C:\Documents and Settings\All Users\Application Data\\ApplicationHosting\\ApplicationHosting.exe -f "C:\Documents and Settings\All Users\Application Data\\ApplicationHosting\\ApplicationHosting.dat" -l -a
2014-08-08 13:41 - 2014-08-08 13:41 - 0000006 ____C () C:\Documents and Settings\user-asu\Application Data\smw_inst
Task: C:\WINDOWS\Tasks\RocketTab Update Task.job => C:\Program Files\Search Extensions\uninstall.exe <==== ATTENTION
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\amigo" /f
EmptyTemp:
Reboot:
и сохраните как fixlist.txt в папку с Farbar Recovery Scan Tool.