Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-11-2014 Ran by Tim at 2014-11-02 17:11:59 Run:2 Running from C:\Users\Tim\Desktop Loaded Profile: Tim (Available profiles: Tim) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKU\S-1-5-21-2008462518-3471571786-2155850046-1000\...\Run: [CMD] => cmd.exe /c start http://extendedunlimited.org && exit <===== ATTENTION S2 248642b4; c:\Program Files (x86)\PC_Booster\AssistantSvc.dll [174928 2014-08-04] () [File not signed] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] CMD: type C:\Windows\System32\Tasks\RocketTab Task: {C97C5433-76B4-4364-8E8F-3185484BE531} - System32\Tasks\RocketTab => C:\Windows\system32\cmd.exe [2010-11-21] (Microsoft Corporation) <==== ATTENTION Task: {D6F03F95-BC4F-44AC-AEFD-96AD3A9FC9B7} - System32\Tasks\RocketTab Update Task => C:\Program Files (x86)\Search Extensions\uninstall.exe <==== ATTENTION Task: {EB02381F-D652-4B1C-894A-712498C62C51} - \Microsoft\Windows\MUI\LPRemove No Task File <==== ATTENTION Task: {F15C06CF-4F8D-41EF-9E5B-1B4E492B98B2} - System32\Tasks\{188A75D0-A367-46C6-A784-9DBEE6A8FB84} => Chrome.exe http://ui.skype.com/ui/0/6.11.0.102/en/go/help.faq.installer?source=lightinstaller&LastError=1618 GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://astromenda.com/?f=1&a=ast_ir_14_44_ch&cd=2XzuyEtN2Y1L1QzutA0CtDyByBtCyBtDtC0Azzzz0AtBzy0BtN0D0Tzu0StCtDtAtBtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzzzyyCyE0DzztBtGtAyD0FyDtGyD0AzyyDtGyCyCzztBtGyD0AyD0D0E0F0EyByB0B0Dzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtC0Ezz0Fzz0BtDtGyE0AtA0CtGyEzy0E0BtGzy0Dzy0AtG0ByE0AyDyCyB0FzzyB0B0Dzy2Q&cr=151942868&ir= HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istart123.com/web/?type=ds&ts=1407110462&from=wpc&uid=HGSTXHTS545032A7E680_131018TM8B134T3Y6VTMX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istart123.com/web/?type=ds&ts=1407110462&from=wpc&uid=HGSTXHTS545032A7E680_131018TM8B134T3Y6VTMX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istart123.com/web/?type=ds&ts=1407110462&from=wpc&uid=HGSTXHTS545032A7E680_131018TM8B134T3Y6VTMX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istart123.com/web/?type=ds&ts=1407110462&from=wpc&uid=HGSTXHTS545032A7E680_131018TM8B134T3Y6VTMX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = SearchScopes: HKCU - DefaultScope {A9CBE41D-2036-4DE3-BECE-586D3C8D53C0} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ir_14_44_ch&cd=2XzuyEtN2Y1L1QzutA0CtDyByBtCyBtDtC0Azzzz0AtBzy0BtN0D0Tzu0StCtDtAtBtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzzzyyCyE0DzztBtGtAyD0FyDtGyD0AzyyDtGyCyCzztBtGyD0AyD0D0E0F0EyByB0B0Dzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtC0Ezz0Fzz0BtDtGyE0AtA0CtGyEzy0E0BtGzy0Dzy0AtG0ByE0AyDyCyB0FzzyB0B0Dzy2Q&cr=151942868&ir= SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3321537&octid=EB_ORIGINAL_CTID&ISID=M2B5B9ABB-3605-494C-823F-D03D06A4C54F&SearchSource=58&CUI=&UM=6&UP=SP09B49DD0-2C7A-41EE-A6A1-198E8A4C28B8&q={searchTerms}&SSPV= SearchScopes: HKCU - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = https://uk.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} SearchScopes: HKCU - {A9CBE41D-2036-4DE3-BECE-586D3C8D53C0} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ir_14_44_ch&cd=2XzuyEtN2Y1L1QzutA0CtDyByBtCyBtDtC0Azzzz0AtBzy0BtN0D0Tzu0StCtDtAtBtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzzzyyCyE0DzztBtGtAyD0FyDtGyD0AzyyDtGyCyCzztBtGyD0AyD0D0E0F0EyByB0B0Dzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtC0Ezz0Fzz0BtDtGyE0AtA0CtGyEzy0E0BtGzy0Dzy0AtG0ByE0AyDyCyB0FzzyB0B0Dzy2Q&cr=151942868&ir= FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll No File FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File CHR StartMenuInternet: Google Chrome - chrome.exe C:\Program Files (x86)\CoupExteinsioN C:\Program Files (x86)\NextCoup C:\Program Files (x86)\PC_Booster C:\ProgramData\.windows.sys C:\ProgramData\71c2c357dfa911ca C:\ProgramData\APN C:\ProgramData\CoupExteinsioN C:\ProgramData\GoSaave C:\ProgramData\NextCoup C:\ProgramData\PriCeCHoopo C:\ProgramData\TakkeTHeCouPon C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP C:\Windows\msdownld.tmp C:\Windows\SysWOW64\setup.exe RemoveDirectory: C:\Users\Tim\Desktop\FRST-OlderVersion Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BRS" /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{248642b4} /f CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Tim\AppData\Local CMD: dir /a C:\Users\Tim\AppData\LocalLow CMD: dir /a C:\Users\Tim\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. HKU\S-1-5-21-2008462518-3471571786-2155850046-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CMD => value deleted successfully. 248642b4 => Service deleted successfully. esgiguard => Service deleted successfully. ========= type C:\Windows\System32\Tasks\RocketTab ========= Runs your RocketTab software. 2014-10-22T01:59:51.848 true HighestAvailable Tim-PC\Tim InteractiveToken IgnoreNew false false true true false PT10M PT1H true false true true false false false PT0S 7 cmd.exe /C start "" "C:\Program Files (x86)\Search Extensions\Client.exe" /Preferred=true C:\Program Files (x86)\Search Extensions ========= End of CMD: ========= "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C97C5433-76B4-4364-8E8F-3185484BE531}" => Error deleting key. The key could be protected. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C97C5433-76B4-4364-8E8F-3185484BE531}" => Error deleting key. The key could be protected. C:\Windows\System32\Tasks\RocketTab => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RocketTab" => Error deleting key. The key could be protected. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D6F03F95-BC4F-44AC-AEFD-96AD3A9FC9B7}" => Error deleting key. The key could be protected. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D6F03F95-BC4F-44AC-AEFD-96AD3A9FC9B7}" => Error deleting key. The key could be protected. C:\Windows\System32\Tasks\RocketTab Update Task => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RocketTab Update Task" => Error deleting key. The key could be protected. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{EB02381F-D652-4B1C-894A-712498C62C51}" => Error deleting key. The key could be protected. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB02381F-D652-4B1C-894A-712498C62C51}" => Error deleting key. The key could be protected. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MUI\LPRemove" => Error deleting key. The key could be protected. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F15C06CF-4F8D-41EF-9E5B-1B4E492B98B2}" => Error deleting key. The key could be protected. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F15C06CF-4F8D-41EF-9E5B-1B4E492B98B2}" => Error deleting key. The key could be protected. C:\Windows\System32\Tasks\{188A75D0-A367-46C6-A784-9DBEE6A8FB84} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{188A75D0-A367-46C6-A784-9DBEE6A8FB84}" => Error deleting key. The key could be protected. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}" => Key deleted successfully. "HKCR\CLSID\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key deleted successfully. "HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}" => Key deleted successfully. "HKCR\CLSID\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A9CBE41D-2036-4DE3-BECE-586D3C8D53C0}" => Key deleted successfully. "HKCR\CLSID\{A9CBE41D-2036-4DE3-BECE-586D3C8D53C0}" => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0" => Key deleted successfully. "HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc" => Key deleted successfully. C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll not found. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. C:\Program Files (x86)\CoupExteinsioN => Moved successfully. C:\Program Files (x86)\NextCoup => Moved successfully. C:\Program Files (x86)\PC_Booster => Moved successfully. C:\ProgramData\.windows.sys => Moved successfully. C:\ProgramData\71c2c357dfa911ca => Moved successfully. C:\ProgramData\APN => Moved successfully. C:\ProgramData\CoupExteinsioN => Moved successfully. C:\ProgramData\GoSaave => Moved successfully. C:\ProgramData\NextCoup => Moved successfully. C:\ProgramData\PriCeCHoopo => Moved successfully. C:\ProgramData\TakkeTHeCouPon => Moved successfully. C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP => Moved successfully. C:\Windows\msdownld.tmp => Moved successfully. C:\Windows\SysWOW64\setup.exe => Moved successfully. Could not remove "C:\Users\Tim\Desktop\FRST-OlderVersion" => Scheduled to remove on reboot. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BRS" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{248642b4} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 9818-A29B Katalog: C:\Program Files 29/10/2014 00:43 . 29/10/2014 00:43 .. 28/10/2014 21:41 AVAST Software 28/10/2014 20:30 CCleaner 16/08/2014 16:08 Common Files 14/07/2009 04:54 174 desktop.ini 28/10/2014 20:07 DVD Maker 02/09/2014 23:34 Enigma Software Group 27/10/2014 23:51 Image-Line 03/12/2013 14:20 Intel 02/11/2014 09:06 Internet Explorer 03/12/2013 15:25 Microsoft Office 22/08/2014 15:17 Microsoft Silverlight 14/07/2009 05:32 MSBuild 16/10/2014 20:34 NVIDIA Corporation 14/07/2009 05:32 Reference Assemblies 03/12/2013 14:43 Synaptics 14/07/2009 05:09 Uninstall Information 29/10/2014 00:43 VideoLAN 28/10/2014 20:07 Windows Defender 28/10/2014 20:07 Windows Journal 28/10/2014 20:07 Windows Mail 28/10/2014 20:07 Windows Media Player 14/07/2009 05:32 Windows NT 28/10/2014 20:07 Windows Photo Viewer 21/11/2010 03:31 Windows Portable Devices 28/10/2014 20:07 Windows Sidebar 03/12/2013 13:49 WinRAR 1 plik(¢w) 174 bajt¢w 27 katalog(¢w) 228,120,887,296 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 9818-A29B Katalog: C:\Program Files (x86) 02/11/2014 17:12 . 02/11/2014 17:12 .. 29/10/2014 00:38 Ahead 28/10/2014 19:14 AIMP3 04/08/2014 03:13 ASIO4ALL v2 15/10/2014 14:07 Common Files 04/08/2014 14:51 DAEMON Tools Lite 14/07/2009 04:54 174 desktop.ini 04/08/2014 03:12 DSPRobotics 28/10/2014 01:01 Google 08/08/2014 22:31 GreenTree Applications 27/10/2014 23:51 Image-Line 02/11/2014 09:20 InstallShield Installation Information 03/12/2013 14:20 Intel 02/11/2014 09:06 Internet Explorer 28/10/2014 21:43 Java 03/12/2013 14:38 Lenovo 30/10/2014 12:56 Microsoft Games for Windows - LIVE 03/12/2013 15:27 Microsoft Office 22/08/2014 15:17 Microsoft Silverlight 03/12/2013 15:27 Microsoft Visual Studio 03/12/2013 15:25 Microsoft Visual Studio 8 03/12/2013 15:27 Microsoft Works 03/12/2013 15:34 Microsoft.NET 03/12/2013 15:27 MSBuild 24/08/2014 17:20 NCH Software 16/10/2014 20:24 NVIDIA Corporation 02/11/2014 09:20 OSCAR Editor X7 03/08/2014 22:39 OscarEditor 03/12/2013 14:31 Realtek 14/07/2009 05:32 Reference Assemblies 30/10/2014 12:36 Rockstar Games 06/10/2014 12:19 Skype 27/10/2014 23:54 Sony 15/08/2014 18:40 Sony Mobile 02/11/2014 15:27 Steam 29/10/2014 10:34 SystemRequirementsLab 14/07/2009 04:57 Uninstall Information 28/10/2014 00:33 VideoLAN 28/10/2014 20:07 Windows Defender 28/10/2014 20:07 Windows Mail 28/10/2014 20:07 Windows Media Player 14/07/2009 05:32 Windows NT 28/10/2014 20:07 Windows Photo Viewer 21/11/2010 03:31 Windows Portable Devices 28/10/2014 20:07 Windows Sidebar 1 plik(¢w) 174 bajt¢w 45 katalog(¢w) 228,120,879,104 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 9818-A29B Katalog: C:\ProgramData 02/11/2014 17:12 . 02/11/2014 17:12 .. 16/08/2014 16:08 34BE82C4-E596-4e99-A191-52C6199EBF69 16/08/2014 16:06 Apple 15/08/2014 18:08 Apple Computer 14/07/2009 05:08 Application Data [C:\ProgramData] 28/10/2014 21:41 AVAST Software 03/09/2014 00:52 Codemasters 04/08/2014 15:09 DAEMON Tools Lite 14/07/2009 05:08 Desktop [C:\Users\Public\Desktop] 14/07/2009 05:08 Documents [C:\Users\Public\Documents] 11/08/2014 15:49 EA Core 12/08/2014 23:37 EA Logs 11/08/2014 15:49 Electronic Arts 14/07/2009 05:08 Favorites [C:\Users\Public\Favorites] 29/08/2014 21:58 Happy2SAAVeo 28/09/2014 16:57 ijacghhikfpcfmoeliihbaoohjbiiplj 04/08/2014 04:06 Microsoft 03/12/2013 15:28 Microsoft Help 24/08/2014 17:03 NCH Software 29/08/2014 21:58 NeewSavverr 28/10/2014 20:20 402 ntuser.pol 30/10/2014 09:08 NVIDIA 16/10/2014 20:24 NVIDIA Corporation 28/10/2014 21:43 Oracle 04/08/2014 15:45 Orbit 28/10/2014 00:32 Origin 06/08/2014 13:46 Package Cache 03/09/2014 12:22 RanidaoemPPrice 06/10/2014 12:19 Skype 03/12/2013 14:54 Sony Corporation 15/08/2014 18:40 Sony Mobile 14/07/2009 05:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 15/10/2014 02:31 Steam 03/08/2014 19:39 Sun 03/08/2014 19:40 SystemRequirementsLab 14/07/2009 05:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 04/08/2014 00:00 Trusted Publisher 04/08/2014 22:35 WarThunder 1 plik(¢w) 402 bajt¢w 38 katalog(¢w) 228,120,879,104 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Tim\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 9818-A29B Katalog: C:\Users\Tim\AppData\Local 31/10/2014 22:53 . 31/10/2014 22:53 .. 28/08/2014 18:00 4A Games 15/08/2014 18:07 Apple 15/08/2014 18:09 Apple Computer 03/12/2013 13:32 Application Data [C:\Users\Tim\AppData\Local] 03/12/2013 14:59 Apps 03/08/2014 23:59 Chromatic Browser 03/08/2014 23:59 Comodo 15/08/2014 19:36 Deployment 03/08/2014 16:57 Diagnostics 07/10/2014 19:28 ElevatedDiagnostics 15/08/2014 19:32 EmieSiteList 15/08/2014 19:32 EmieUserList 11/08/2014 16:04 ESN 20/09/2014 01:25 110,944 GDIPFONTCACHEV1.DAT 28/10/2014 01:02 Google 03/12/2013 13:32 History [C:\Users\Tim\AppData\Local\Microsoft\Windows\History] 02/11/2014 14:03 5,496,311 IconCache.db 22/08/2014 17:33 Intel_Corporation 14/10/2014 01:00 0 LumaEmu 28/08/2014 17:20 Microsoft 03/12/2013 15:24 Microsoft Help 03/12/2013 15:47 NVIDIA 16/10/2014 20:25 NVIDIA Corporation 04/08/2014 00:00 Packages 04/08/2014 01:23 PAYDAY 2 04/08/2014 22:35 Programs 28/10/2014 20:48 PunkBuster 31/10/2014 23:09 Rockstar Games 03/09/2014 23:41 Setup Integrity Check 25/09/2014 18:29 SKIDROW 04/08/2014 01:02 Skype 28/08/2014 00:21 Sony 02/11/2014 17:12 Temp 03/12/2013 13:32 Temporary Internet Files [C:\Users\Tim\AppData\Local\Microsoft\Windows\Temporary Internet Files] 03/08/2014 23:59 Torch 04/08/2014 18:29 Ubisoft Game Launcher 03/12/2013 13:33 VirtualStore 04/08/2014 22:35 WarThunder 3 plik(¢w) 5,607,255 bajt¢w 37 katalog(¢w) 228,120,875,008 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Tim\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 9818-A29B Katalog: C:\Users\Tim\AppData\LocalLow 25/08/2014 01:01 . 25/08/2014 01:01 .. 26/04/2014 20:05 Microsoft 10/08/2014 21:23 SKS 03/08/2014 19:36 Sun 22/10/2014 01:58 {2343D924-DA07-9F20-B264-2A219CCE41AA} 25/08/2014 01:01 {26110178-BD65-22FD-7DFD-22DE5C7E4A90} 11/08/2014 02:26 {57BCCFDC-C599-8090-2E4C-9EF32BFD7370} 18/08/2014 12:11 {B07E87CF-366E-8343-3FF7-41951025AF04} 0 plik(¢w) 0 bajt¢w 9 katalog(¢w) 228,120,875,008 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Tim\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 9818-A29B Katalog: C:\Users\Tim\AppData\Roaming 30/10/2014 23:01 . 30/10/2014 23:01 .. 20/12/2013 23:39 Adobe 02/11/2014 17:06 AIMP3 16/08/2014 15:18 Apple Computer 28/10/2014 21:44 AVAST Software 30/10/2014 12:32 DAEMON Tools Lite 25/04/2014 14:48 DarkSoulsII 10/08/2014 20:54 FlowStone 03/12/2013 13:33 Identities 10/08/2014 20:54 Image-Line 03/12/2013 14:37 InstallShield 12/04/2011 08:28 Media Center Programs 17/10/2014 19:39 Microsoft 08/08/2014 01:43 NVIDIA 04/08/2014 01:01 OpenCandy 28/10/2014 21:57 Origin 27/08/2014 23:42 Publish Providers 30/10/2014 23:01 SecuROM 04/08/2014 00:02 SendSpace 28/10/2014 19:15 Skype 27/08/2014 23:46 Sony 03/12/2013 14:56 Sony Corporation 11/10/2014 15:24 Steam 07/08/2014 01:57 The Creative Assembly 31/10/2014 23:09 uTorrent 31/10/2014 22:51 vlc 04/08/2014 22:22 Wargaming.net 28/10/2014 20:14 44 WB.CFG 03/12/2013 13:49 WinRAR 1 plik(¢w) 44 bajt¢w 29 katalog(¢w) 228,120,870,912 bajt¢w wolnych ========= End of CMD: ========= EmptyTemp: => Removed 953.1 MB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-11-02 17:13:54)<= C:\Users\Tim\Desktop\FRST-OlderVersion => Removed successfully. ==== End of Fixlog ====