Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 30-10-2014 01 Ran by Admin at 2014-10-31 12:03:03 Run:1 Running from C:\Users\Admin\Downloads Loaded Profile: Admin (Available profiles: Admin) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R2 fc67e7a0; c:\Program Files (x86)\DeltaFix\DeltaFix.dll [3978752 2014-10-28] () [File not signed] R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [425104 2014-02-26] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION S1 dqnalkcg; \??\C:\Windows\system32\drivers\dqnalkcg.sys [X] S1 gtkiqgdu; \??\C:\Windows\system32\drivers\gtkiqgdu.sys [X] S1 nezmxysv; \??\C:\Windows\system32\drivers\nezmxysv.sys [X] S1 rktwjmur; \??\C:\Windows\system32\drivers\rktwjmur.sys [X] S1 wrntpzhx; \??\C:\Windows\system32\drivers\wrntpzhx.sys [X] S1 yauaqdfq; \??\C:\Windows\system32\drivers\yauaqdfq.sys [X] HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe Task: {7D279029-D5BD-47B3-BE2A-10F18B71F2C3} - System32\Tasks\GoforFilesUpdate => C:\Program Files (x86)\GoforFiles\GFFUpdater.exe <==== ATTENTION GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=sc&from=wpm0226&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&ts=1393429378 ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=sc&from=wpm0226&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&ts=1393429378 ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=sc&from=wpm0226&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&ts=1393429378 ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=sc&from=wpm0226&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&ts=1393429378 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&ts=1393429378&type=default&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181&d=20140924 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181&d=20140924 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391856833&from=exp&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181&d=20140924 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391856833&from=exp&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&q={searchTerms} URLSearchHook: HKLM-x32 - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1QzutByE0F0DyDtBzy0EtD0BzzyBzy0DtDyDtN0D0Tzu0CyCyCyEtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=824961340&ir= SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1QzutByE0F0DyDtBzy0EtD0BzzyBzy0DtDyDtN0D0Tzu0CyCyCyEtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=824961340&ir= SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1QzutByE0F0DyDtBzy0EtD0BzzyBzy0DtDyDtN0D0Tzu0CyCyCyEtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=824961340&ir= SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: RandomPrice -> {e825a11c-db79-4872-87d2-f14763c1e324} -> C:\ProgramData\RandomPrice\2B6Fp3lvComr6N.x64.dll () BHO-x32: RandomPrice -> {e825a11c-db79-4872-87d2-f14763c1e324} -> C:\ProgramData\RandomPrice\2B6Fp3lvComr6N.dll () FF HKLM-x32\...\Firefox\Extensions: [shortcutff@gmail.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\tn6mwzn8.default\extensions\shortcutff@gmail.com C:\Program Files (x86)\Adblocker C:\Program Files (x86)\DeltaFix C:\Program Files (x86)\Mozilla Firefox\plugins C:\Program Files (x86)\WinZipper C:\ProgramData\d195380caa514720 C:\ProgramData\RandomPrice C:\ProgramData\Trusted Publisher C:\ProgramData\WPM C:\Users\HomeGroupUser$ C:\Users\Administrator C:\Users\Gość C:\Users\Admin\AppData\Local\17712 C:\Users\Admin\AppData\Local\27683 C:\Users\Admin\AppData\Local\Chromatic Browser C:\Users\Admin\AppData\Local\Comodo C:\Users\Admin\AppData\Local\genienext C:\Users\Admin\AppData\Local\Google C:\Users\Admin\AppData\Local\Torch C:\Users\Admin\AppData\Roaming\337Games C:\Users\Admin\AppData\Roaming\Babylon C:\Users\Admin\AppData\Roaming\Bonanza C:\Users\Admin\AppData\Roaming\DVDVideoSoft C:\Users\Admin\AppData\Roaming\GoforFiles C:\Users\Admin\AppData\Roaming\Systweak C:\Users\Admin\AppData\Roaming\Thinstall C:\Users\Admin\AppData\Roaming\WinZipper C:\Users\Admin\Downloads\django-unchained-eng-4770000.exe C:\Users\Admin\Downloads\Portable EXCEL 2003 PL._5fantastic.pl_.exe C:\Users\Admin\Downloads\setup.exe C:\Windows\Base64.dll C:\Windows\clfct.dll C:\Windows\jimglib.dll C:\Windows\sassr.dat C:\Windows\sysk32.dll C:\Windows\SysWow64\hfpapi.dll C:\Windows\SysWow64\sinvfct.dll C:\awh*.tmp Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{75B1EA5E-B09C-B960-322E-21187775557D}" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{75B1EA5E-B09C-B960-322E-21187775557D}" /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{016DC87C-94D1-045D-B108-53564C412C2B}" /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f Reg: reg query "HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command" /s Folder: C:\Users\Admin\IGC Folder: C:\Users\Admin\AppData\Roaming\IGC Folder: C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\Extensions CMD: type "C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\Preferences" CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Admin\AppData\Local CMD: dir /a C:\Users\Admin\AppData\LocalLow CMD: dir /a C:\Users\Admin\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. fc67e7a0 => Service deleted successfully. winzipersvc => Service not found. dqnalkcg => Service deleted successfully. gtkiqgdu => Service deleted successfully. nezmxysv => Service deleted successfully. rktwjmur => Service deleted successfully. wrntpzhx => Service deleted successfully. yauaqdfq => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7D279029-D5BD-47B3-BE2A-10F18B71F2C3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D279029-D5BD-47B3-BE2A-10F18B71F2C3}" => Key deleted successfully. C:\Windows\System32\Tasks\GoforFilesUpdate => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoforFilesUpdate" => Key deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}" => Key deleted successfully. "HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e825a11c-db79-4872-87d2-f14763c1e324}" => Key not found. "HKCR\CLSID\{e825a11c-db79-4872-87d2-f14763c1e324}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e825a11c-db79-4872-87d2-f14763c1e324}" => Key not found. "HKCR\Wow6432Node\CLSID\{e825a11c-db79-4872-87d2-f14763c1e324}" => Key deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\shortcutff@gmail.com => value deleted successfully. C:\Program Files (x86)\Adblocker => Moved successfully. C:\Program Files (x86)\DeltaFix => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\plugins => Moved successfully. C:\Program Files (x86)\WinZipper => Moved successfully. C:\ProgramData\d195380caa514720 => Moved successfully. C:\ProgramData\RandomPrice => Moved successfully. C:\ProgramData\Trusted Publisher => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\Users\HomeGroupUser$ => Moved successfully. C:\Users\Administrator => Moved successfully. C:\Users\Gość => Moved successfully. C:\Users\Admin\AppData\Local\17712 => Moved successfully. C:\Users\Admin\AppData\Local\27683 => Moved successfully. C:\Users\Admin\AppData\Local\Chromatic Browser => Moved successfully. C:\Users\Admin\AppData\Local\Comodo => Moved successfully. C:\Users\Admin\AppData\Local\genienext => Moved successfully. C:\Users\Admin\AppData\Local\Google => Moved successfully. C:\Users\Admin\AppData\Local\Torch => Moved successfully. C:\Users\Admin\AppData\Roaming\337Games => Moved successfully. C:\Users\Admin\AppData\Roaming\Babylon => Moved successfully. C:\Users\Admin\AppData\Roaming\Bonanza => Moved successfully. C:\Users\Admin\AppData\Roaming\DVDVideoSoft => Moved successfully. C:\Users\Admin\AppData\Roaming\GoforFiles => Moved successfully. C:\Users\Admin\AppData\Roaming\Systweak => Moved successfully. C:\Users\Admin\AppData\Roaming\Thinstall => Moved successfully. C:\Users\Admin\AppData\Roaming\WinZipper => Moved successfully. C:\Users\Admin\Downloads\django-unchained-eng-4770000.exe => Moved successfully. C:\Users\Admin\Downloads\Portable EXCEL 2003 PL._5fantastic.pl_.exe => Moved successfully. C:\Users\Admin\Downloads\setup.exe => Moved successfully. C:\Windows\Base64.dll => Moved successfully. C:\Windows\clfct.dll => Moved successfully. C:\Windows\jimglib.dll => Moved successfully. C:\Windows\sassr.dat => Moved successfully. C:\Windows\sysk32.dll => Moved successfully. C:\Windows\SysWow64\hfpapi.dll => Moved successfully. C:\Windows\SysWow64\sinvfct.dll => Moved successfully. C:\awh*.tmp => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{75B1EA5E-B09C-B960-322E-21187775557D}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{75B1EA5E-B09C-B960-322E-21187775557D}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{016DC87C-94D1-045D-B108-53564C412C2B}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg query "HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command (domy˜lny) REG_SZ "C:\Program Files (x86)\Opera\Launcher.exe" ========= End of Reg: ========= ========================= Folder: C:\Users\Admin\IGC ======================== ====== End of Folder: ====== ========================= Folder: C:\Users\Admin\AppData\Roaming\IGC ======================== 2014-10-28 12:52 - 2014-10-28 12:52 - 0000000 ____D () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer 2014-10-28 12:52 - 2014-10-28 12:52 - 0000440 _____ () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\Measure.ini 2014-10-28 12:52 - 2014-10-28 12:52 - 0000026 _____ () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\Reasons.ini 2014-10-28 12:52 - 2014-10-28 12:52 - 0012360 _____ () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\ViewerConfig.xml 2014-10-28 12:52 - 2014-10-28 12:52 - 0000000 ____D () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\eximg 2014-10-28 12:52 - 2014-10-28 12:52 - 0000289 _____ () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\eximg\nextimage.png 2014-10-28 12:52 - 2014-10-28 12:52 - 0000286 _____ () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\eximg\nextimage_i.png 2014-10-28 12:52 - 2014-10-28 12:52 - 0000307 _____ () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\eximg\openimage.png 2014-10-28 12:52 - 2014-10-28 12:52 - 0000301 _____ () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\eximg\openimage_i.png 2014-10-28 12:52 - 2014-10-28 12:52 - 0000273 _____ () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\eximg\previmage.png 2014-10-28 12:52 - 2014-10-28 12:52 - 0000271 _____ () C:\Users\Admin\AppData\Roaming\IGC\Brava! FreeDWG Viewer\eximg\previmage_i.png ====== End of Folder: ====== ========================= Folder: C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\Extensions ======================== Directory Not Found ========= type "C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\Preferences" ========= ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= ========= End of CMD: ========= ========= dir /a C:\Users\Admin\AppData\Local ========= ========= End of CMD: ========= ========= dir /a C:\Users\Admin\AppData\LocalLow ========= ========= End of CMD: ========= ========= dir /a C:\Users\Admin\AppData\Roaming ========= ========= End of CMD: ========= EmptyTemp: => Removed 2.2 GB temporary data. The system needed a reboot. ==== End of Fixlog ====