Fix result of Farbar Recovery Scan Tool (x64) Version: 19-08-2017 Ran by Bart (19-08-2017 14:50:55) Run:1 Running from C:\Users\Bart\Desktop Loaded Profiles: Bart (Available Profiles: Bart) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: CreateRestorePoint: Task: {5A533448-197A-452B-855A-B45A9D814314} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\Windows\TEMP\{4E423159-21E8-43C9-97A5-723E542E003C}.exe <==== ATTENTION Task: {E693DC6B-53FE-405B-8471-025C5B293491} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION Task: {FECC5E8A-E5A7-465F-AF14-7C205080B453} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{CD2B490C-969E-4769-9274-C0802A66C55E}.exe <==== ATTENTION Task: C:\Windows\Tasks\A0EECDFC-B485-47CA-8AE4-6DB2B0B2691F.job => C:\Program Files (x86)\YueAckU\j45lXIS.dll <==== ATTENTION Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\Windows\TEMP\{4E423159-21E8-43C9-97A5-723E542E003C}.exe <==== ATTENTION Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{CD2B490C-969E-4769-9274-C0802A66C55E}.exe <==== ATTENTION C:\Program Files (x86)\YourFileDownloader C:\Program Files (x86)\YueAckU HKLM-x32\...\Run: [] => [X] HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-4238196658-422620013-1050771535-1000\...\Run: [Devisdmo] => C:\Users\Bart\AppData\Roaming\aeev-1-0\espsrv.exe HKU\S-1-5-21-4238196658-422620013-1050771535-1000\...\Run: [Deviound] => C:\Users\Bart\AppData\Roaming\aeev-1-0\expsroxy.exe HKU\S-1-5-21-4238196658-422620013-1050771535-1000\...\Run: [svchostwn] => "%SystemRoot%\System32\WScript.exe" "C:\Users\Bart\AppData\Roaming\svchost store files\start64.vbs" //B "%1" %* HKU\S-1-5-21-4238196658-422620013-1050771535-1000\...\Run: [svchostws] => "%SystemRoot%\System32\WScript.exe" "C:\Users\Bart\AppData\Roaming\svchost local files\start.vbs" //B "%1" %* AppInit_DLLs: C:\ProgramData\Hotfresh\Toughsoft.dll => C:\ProgramData\Hotfresh\Toughsoft.dll [343552 2017-08-06] () Startup: C:\Users\Bart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchostwn.vbs [2017-08-09] () Startup: C:\Users\Bart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchostws.vbs [2017-08-07] () C:\Users\Bart\AppData\Roaming\aeev-1-0 C:\Users\Bart\AppData\Roaming\svchost store files C:\Users\Bart\AppData\Roaming\svchost local files C:\ProgramData\Hotfresh C:\Users\Bart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchostwn.vbs C:\Users\Bart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchostws.vbs GroupPolicy: Restriction - Chrome <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION Tcpip\..\Interfaces\{96CC1913-6F1B-4B3E-AC07-9DFA56944743}: [NameServer] 82.163.142.8,95.211.158.136 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYvGyvSgUEGR396YOlls81sgcivlf5qUvj6-5-iMFM2KOjiNYR2bp5xIfptIf8ApJs0nPJ_Blx9dAg7k7qZVWDfy8rPSbpncwqu9nWq_t6kyYRtHAAmJSehyWC3w2n2FilVHl5thp5PFSu4yIxAnSmGR8IXlw,,&q={searchTerms} SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091 SearchScopes: HKU\S-1-5-21-4238196658-422620013-1050771535-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={A7837AA3-2B92-4216-A713-670611466DBC}&mid=850056166ce147d0bfc6316fe5f6b463-3201bf0c8793f208631c6fe875066179091793a7&lang=pl&ds=xn011&pr=sa&d=2012-11-30 12:37:40&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-4238196658-422620013-1050771535-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091 SearchScopes: HKU\S-1-5-21-4238196658-422620013-1050771535-1000 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYvGyvSgUEGR396YOlls81sgcivlf5qUvj6-5-iMFM2KOjiNYR2bp5xIfptIf8ApJs0nPJ_Blx9dAg7k7qZVWDfy8rPSbpncwqu9nWq_t6kyYRtHAAmJSehyWC3w2n2FilVHl5thp5PFSu4yIxAnSmGR8IXlw,,&q={searchTerms} BHO: No Name -> {C0D38E5A-7CF8-4105-8FE8-31B81443A114} -> No File BHO: No Name -> {F4F34E6A-5C2C-AF27-DA53-C43B16B839D6} -> No File BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File BHO-x32: No Name -> {dcfb5bfe-1f58-4b1d-96a7-3c7bbae51b36} -> No File Toolbar: HKU\S-1-5-21-4238196658-422620013-1050771535-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File S4 backlh; C:\ProgramData\Logic Cramble\set.exe [3780096 2017-08-07] () [File not signed] <==== ATTENTION R2 RjlvBUc0gHzE Updater; C:\Program Files (x86)\RjlvBUc0gHzE Updater\RjlvBUc0gHzE Updater.exe [313344 2017-08-06] () [File not signed] S2 Hotfresh; C:\ProgramData\\Hotfresh\\Hotfresh.exe shuz -f "C:\ProgramData\\Hotfresh\\Hotfresh.dat" -l -a C:\ProgramData\Logic Cramble C:\Program Files (x86)\RjlvBUc0gHzE Updater C:\ProgramData\\Hotfresh\ C:\ProgramData\Hotfresh C:\ProgramData\Hotfreshs R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61120 2014-04-05] (StdLib) 2017-08-07 12:43 - 2017-08-07 12:43 - 000604928 _____ (Reimage) C:\Users\Bart\Downloads\ReimageRepair (1).exe 2017-08-07 11:00 - 2017-08-07 16:37 - 000000140 _____ C:\Windows\Reimage.ini 2017-08-07 11:00 - 2017-08-07 11:00 - 000604928 _____ (Reimage) C:\Users\Bart\Downloads\ReimageRepair.exe 2017-08-06 18:57 - 2017-08-06 18:57 - 000000000 ____D C:\Program Files (x86)\Nine 2017-08-06 18:54 - 2017-08-07 14:34 - 000000000 ____D C:\Program Files (x86)\YueAckU 2017-08-06 18:54 - 2017-08-07 14:34 - 000000000 ____D C:\Program Files (x86)\YtuAskU2 2017-08-06 18:54 - 2017-08-07 14:34 - 000000000 ____D C:\Program Files (x86)\YpuAskUn 2017-08-06 18:54 - 2017-08-07 14:34 - 000000000 ____D C:\Program Files (x86)\YeuAskIE 2017-08-06 18:54 - 2017-08-07 14:34 - 000000000 ____D C:\Program Files (x86)\FastDataX 2017-08-06 18:54 - 2017-08-06 18:54 - 000000000 ____D C:\ProgramData\71ade274-1d13-0 2017-08-06 18:54 - 2017-08-06 18:54 - 000000000 ____D C:\ProgramData\71ade274-1a77-1 2017-08-06 18:53 - 2017-08-06 18:53 - 000000000 ____D C:\ProgramData\4e31fc97-08f5-1 2017-08-06 18:53 - 2017-08-06 18:53 - 000000000 ____D C:\ProgramData\4e31fc97-04a1-0 017-08-06 18:49 - 2017-08-07 12:38 - 000015606 _____ C:\Windows\SysWOW64\findit.xml 2017-08-06 18:49 - 2017-08-06 18:49 - 007324160 _____ () C:\Users\Bart\AppData\Local\agent.dat 2017-08-06 18:49 - 2017-08-06 18:49 - 001899067 _____ () C:\Users\Bart\AppData\Local\Beta-Bam.tst 2017-07-02 10:57 - 2017-07-02 10:57 - 000000000 ____H () C:\Users\Bart\AppData\Local\BIT8812.tmp 2017-08-06 18:49 - 2017-08-06 18:49 - 000070800 _____ () C:\Users\Bart\AppData\Local\Config.xml 2017-08-06 18:48 - 2017-08-06 18:49 - 000016512 _____ () C:\Users\Bart\AppData\Local\InstallationConfiguration.xml 2017-08-06 18:48 - 2017-08-06 18:48 - 000140800 _____ () C:\Users\Bart\AppData\Local\installer.dat 2017-08-06 18:49 - 2017-08-06 18:49 - 001895382 _____ () C:\Users\Bart\AppData\Local\Instrong.bin 2017-08-06 18:49 - 2017-08-06 18:49 - 000018432 _____ () C:\Users\Bart\AppData\Local\Main.dat 2017-08-06 18:49 - 2017-08-06 18:49 - 000005568 _____ () C:\Users\Bart\AppData\Local\md.xml 2017-08-06 18:49 - 2017-08-06 18:49 - 000126464 _____ () C:\Users\Bart\AppData\Local\noah.dat 2017-08-06 18:48 - 2017-08-07 12:38 - 001847296 _____ () C:\Users\Bart\AppData\Local\po.db 2017-08-06 18:49 - 2017-08-06 18:49 - 000278510 _____ () C:\Users\Bart\AppData\Local\Quotesantax.tst DeleteKey: HKCU\Software\Mozilla DeleteKey: HKCU\Software\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Mozilla DeleteKey: HKLM\SOFTWARE\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla DeleteKey: HKLM\SOFTWARE\Wow6432Node\mozilla.org DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins C:\Users\Bart\AppData\Local\Mozilla C:\Users\Bart\AppData\Roaming\Mozilla C:\Users\Bart\AppData\Roaming\Profiles C:\Program Files (x86)\Google C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome C:\Users\Bart\AppData\Local\Google DeleteKey: HKCU\Software\Google DeleteKey: HKLM\SOFTWARE\Google DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google CMD: ipconfig /flushdns CMD: netsh advfirewall reset CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Bart\AppData\Local CMD: dir /a C:\Users\Bart\AppData\LocalLow CMD: dir /a C:\Users\Bart\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5A533448-197A-452B-855A-B45A9D814314} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A533448-197A-452B-855A-B45A9D814314} => key removed successfully C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_HP_rmv => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E693DC6B-53FE-405B-8471-025C5B293491} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E693DC6B-53FE-405B-8471-025C5B293491} => key removed successfully C:\Windows\System32\Tasks\YourFile DownloaderUpdate => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YourFile DownloaderUpdate => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FECC5E8A-E5A7-465F-AF14-7C205080B453} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FECC5E8A-E5A7-465F-AF14-7C205080B453} => key removed successfully C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv => key removed successfully C:\Windows\Tasks\A0EECDFC-B485-47CA-8AE4-6DB2B0B2691F.job => moved successfully C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => moved successfully C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => moved successfully "C:\Program Files (x86)\YourFileDownloader" => not found. C:\Program Files (x86)\YueAckU => moved successfully HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key removed successfully HKU\S-1-5-21-4238196658-422620013-1050771535-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Devisdmo => value removed successfully HKU\S-1-5-21-4238196658-422620013-1050771535-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Deviound => value removed successfully HKU\S-1-5-21-4238196658-422620013-1050771535-1000\Software\Microsoft\Windows\CurrentVersion\Run\\svchostwn => value removed successfully HKU\S-1-5-21-4238196658-422620013-1050771535-1000\Software\Microsoft\Windows\CurrentVersion\Run\\svchostws => value removed successfully "C:\ProgramData\Hotfresh\Toughsoft.dll" => Value data removed successfully. C:\Users\Bart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchostwn.vbs => moved successfully C:\Users\Bart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchostws.vbs => moved successfully C:\Users\Bart\AppData\Roaming\aeev-1-0 => moved successfully C:\Users\Bart\AppData\Roaming\svchost store files => moved successfully C:\Users\Bart\AppData\Roaming\svchost local files => moved successfully C:\ProgramData\Hotfresh => moved successfully "C:\Users\Bart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchostwn.vbs" => not found. "C:\Users\Bart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchostws.vbs" => not found. C:\Windows\system32\GroupPolicy\Machine => moved successfully C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully HKLM\SOFTWARE\Policies\Google => key removed successfully HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{96CC1913-6F1B-4B3E-AC07-9DFA56944743}\\NameServer => value removed successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\ielnksrch => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => key not found. HKU\S-1-5-21-4238196658-422620013-1050771535-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => key removed successfully HKLM\Software\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => key not found. HKU\S-1-5-21-4238196658-422620013-1050771535-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => key removed successfully HKLM\Software\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => key not found. HKU\S-1-5-21-4238196658-422620013-1050771535-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} => key removed successfully HKLM\Software\Classes\CLSID\{ielnksrch} => key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114} => key removed successfully HKLM\Software\Classes\CLSID\{C0D38E5A-7CF8-4105-8FE8-31B81443A114} => key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4F34E6A-5C2C-AF27-DA53-C43B16B839D6} => key removed successfully HKLM\Software\Classes\CLSID\{F4F34E6A-5C2C-AF27-DA53-C43B16B839D6} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dcfb5bfe-1f58-4b1d-96a7-3c7bbae51b36} => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{dcfb5bfe-1f58-4b1d-96a7-3c7bbae51b36} => key not found. HKU\S-1-5-21-4238196658-422620013-1050771535-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => value removed successfully HKLM\Software\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => key not found. HKLM\System\CurrentControlSet\Services\backlh => key removed successfully backlh => service removed successfully HKLM\System\CurrentControlSet\Services\RjlvBUc0gHzE Updater => key removed successfully RjlvBUc0gHzE Updater => service removed successfully HKLM\System\CurrentControlSet\Services\Hotfresh => key removed successfully Hotfresh => service removed successfully C:\ProgramData\Logic Cramble => moved successfully C:\Program Files (x86)\RjlvBUc0gHzE Updater => moved successfully "C:\ProgramData\\Hotfresh" => not found. "C:\ProgramData\Hotfresh" => not found. C:\ProgramData\Hotfreshs => moved successfully wStLibG64 => Service stopped successfully. HKLM\System\CurrentControlSet\Services\wStLibG64 => key removed successfully wStLibG64 => service removed successfully C:\Users\Bart\Downloads\ReimageRepair (1).exe => moved successfully C:\Windows\Reimage.ini => moved successfully C:\Users\Bart\Downloads\ReimageRepair.exe => moved successfully C:\Program Files (x86)\Nine => moved successfully "C:\Program Files (x86)\YueAckU" => not found. C:\Program Files (x86)\YtuAskU2 => moved successfully C:\Program Files (x86)\YpuAskUn => moved successfully C:\Program Files (x86)\YeuAskIE => moved successfully C:\Program Files (x86)\FastDataX => moved successfully C:\ProgramData\71ade274-1d13-0 => moved successfully C:\ProgramData\71ade274-1a77-1 => moved successfully C:\ProgramData\4e31fc97-08f5-1 => moved successfully C:\ProgramData\4e31fc97-04a1-0 => moved successfully 017-08-06 18:49 - 2017-08-07 12:38 - 000015606 _____ C:\Windows\SysWOW64\findit.xml => Error: No automatic fix found for this entry. C:\Users\Bart\AppData\Local\agent.dat => moved successfully C:\Users\Bart\AppData\Local\Beta-Bam.tst => moved successfully C:\Users\Bart\AppData\Local\BIT8812.tmp => moved successfully C:\Users\Bart\AppData\Local\Config.xml => moved successfully C:\Users\Bart\AppData\Local\InstallationConfiguration.xml => moved successfully C:\Users\Bart\AppData\Local\installer.dat => moved successfully C:\Users\Bart\AppData\Local\Instrong.bin => moved successfully C:\Users\Bart\AppData\Local\Main.dat => moved successfully C:\Users\Bart\AppData\Local\md.xml => moved successfully C:\Users\Bart\AppData\Local\noah.dat => moved successfully C:\Users\Bart\AppData\Local\po.db => moved successfully C:\Users\Bart\AppData\Local\Quotesantax.tst => moved successfully HKCU\Software\Mozilla => key not found. HKCU\Software\MozillaPlugins => key removed successfully HKLM\SOFTWARE\Mozilla => key removed successfully HKLM\SOFTWARE\MozillaPlugins => key removed successfully HKLM\SOFTWARE\Wow6432Node\Mozilla => key removed successfully HKLM\SOFTWARE\Wow6432Node\mozilla.org => key not found. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => key removed successfully "C:\Users\Bart\AppData\Local\Mozilla" => not found. C:\Users\Bart\AppData\Roaming\Mozilla => moved successfully "C:\Users\Bart\AppData\Roaming\Profiles" => not found. C:\Program Files (x86)\Google => moved successfully "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome" => not found. C:\Users\Bart\AppData\Local\Google => moved successfully HKCU\Software\Google => key removed successfully HKLM\SOFTWARE\Google => key not found. HKLM\SOFTWARE\Wow6432Node\Google => key removed successfully ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= Volume in drive C has no label. Volume Serial Number is E05F-0CF6 Directory of C:\Program Files 2017-08-18 18:00