Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-02-2015 02 Ran by 1 at 2015-02-12 23:36:42 Run:1 Running from C:\Users\1\Downloads Loaded Profiles: 1 (Available profiles: 1) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R1 {16a92140-918d-4afb-9edb-46f22437bb10}w64; C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}w64.sys [48792 2015-01-25] (StdLib) R1 {3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64; C:\Windows\System32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys [48792 2015-01-28] (StdLib) R1 {641e52b1-3179-43ed-8bcb-f688871e52b0}w64; C:\Windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64.sys [48792 2015-01-20] (StdLib) R1 {915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64; C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64.sys [48792 2015-01-22] (StdLib) R1 {bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64; C:\Windows\System32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys [48792 2015-01-09] (StdLib) R1 {ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}w64; C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}w64.sys [48792 2015-01-13] (StdLib) R1 {ecd6aae4-019c-44b2-a0e5-570904275d66}w64; C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64.sys [48792 2015-01-16] (StdLib) R1 {f81878fa-25e9-442d-8ada-79658b6520f2}w64; C:\Windows\System32\drivers\{f81878fa-25e9-442d-8ada-79658b6520f2}w64.sys [48792 2015-01-10] (StdLib) R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158864 2014-12-29] (XTab system) R2 Util Dynamo Combo; C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe [366832 2015-02-04] () R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [473088 2015-01-10] (Fuyu LIMITED) [File not signed] S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X] HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\...\Run: [ChomikBox] => C:\Program Files (x86)\ChomikBox\ChomikBox.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hppp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hppp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1420871780&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1420871780&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hppp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hppp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1420871780&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1420871780&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6&q={searchTerms} HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6&q={searchTerms} HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hppp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6 HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hppp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6 HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6&q={searchTerms} SearchScopes: HKU\S-1-5-21-2654220689-2568901334-3418674353-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6&q={searchTerms} SearchScopes: HKU\S-1-5-21-2654220689-2568901334-3418674353-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6&q={searchTerms} BHO-x32: Dynamo Combo 1.0.0.7 -> {986c37a1-7b65-476f-80dc-54f80bd4b0d6} -> C:\Program Files (x86)\Dynamo Combo\DynamoComboBHO.dll (Dynamo Combo) Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKU\S-1-5-21-2654220689-2568901334-3418674353-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File CHR HomePage: Default -> hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6 CHR StartupUrls: Default -> "hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420871792&from=cor&uid=ST320LT012-9WS14C_S0V8FKG6XXXXS0V8FKG6" CHR DefaultSearchKeyword: Default -> omiga-plus C:\Program Files (x86)\Dynamo Combo C:\Program Files (x86)\XTab C:\ProgramData\WindowsMangerProtect C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GoodGameEmpire.lnk C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire C:\Users\1\Desktop\GRY\GoodGameEmpire.lnk C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}w64.sys C:\Windows\System32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys C:\Windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64.sys C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64.sys C:\Windows\System32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}w64.sys C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64.sys C:\Windows\System32\drivers\{f81878fa-25e9-442d-8ada-79658b6520f2}w64.sys CMD: sc config WinDefend start= demand EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. {16a92140-918d-4afb-9edb-46f22437bb10}w64 => Unable to stop service {16a92140-918d-4afb-9edb-46f22437bb10}w64 => Service deleted successfully. {3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64 => Service stopped successfully. {3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64 => Service deleted successfully. {641e52b1-3179-43ed-8bcb-f688871e52b0}w64 => Unable to stop service {641e52b1-3179-43ed-8bcb-f688871e52b0}w64 => Service deleted successfully. {915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64 => Unable to stop service {915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64 => Service deleted successfully. {bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64 => Unable to stop service {bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64 => Service deleted successfully. {ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}w64 => Unable to stop service {ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}w64 => Service deleted successfully. {ecd6aae4-019c-44b2-a0e5-570904275d66}w64 => Unable to stop service {ecd6aae4-019c-44b2-a0e5-570904275d66}w64 => Service deleted successfully. {f81878fa-25e9-442d-8ada-79658b6520f2}w64 => Unable to stop service {f81878fa-25e9-442d-8ada-79658b6520f2}w64 => Service deleted successfully. IHProtect Service => Service deleted successfully. Util Dynamo Combo => Unable to stop service Util Dynamo Combo => Service deleted successfully. WindowsMangerProtect => Service deleted successfully. nvvad_WaveExtensible => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => value deleted successfully. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Windows\CurrentVersion\Run\\EA Core => value deleted successfully. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value deleted successfully. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ChomikBox => value deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{986c37a1-7b65-476f-80dc-54f80bd4b0d6}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{986c37a1-7b65-476f-80dc-54f80bd4b0d6}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key not found. HKU\S-1-5-21-2654220689-2568901334-3418674353-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. Chrome HomePage not detected. Chrome StartupUrls not detected. Chrome DefaultSearchKeyword not detected. "C:\Program Files (x86)\Dynamo Combo" directory move: C:\Program Files (x86)\Dynamo Combo\DynamoCombo.ico => Moved successfully. C:\Program Files (x86)\Dynamo Combo\DynamoComboBHO.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\kpgkaimemdlpgfgohekgcjddinhmphfb.crx => Moved successfully. C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe => Moved successfully. C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.InstallState => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb46f22437bb10.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb46f22437bb1064.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb64.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f11bbe6d501ea.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f11bbe6d501ea64.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f64.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb64.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b0.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b064.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\7za.exe => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b4.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b461409471b1c3.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b461409471b1c364.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b464.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\bau => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\bf5001a3ae7a4910925a.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\bf5001a3ae7a4910925a64.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\BrowserAdapter.7z => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter.exe => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter64.exe => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.PurBrowse.zip => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.PurBrowse64.exe => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\ebd8d0c0e0224b76a1f2.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\ebd8d0c0e0224b76a1f264.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e5.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e5570904275d66.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e5570904275d6664.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e564.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\eula.txt => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\f81878fa25e9442d8ada.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\f81878fa25e9442d8ada64.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\sqlite3.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\tmp268F.tmp => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\tmp6DD4.tmp => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\tmp79DE.tmp => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\tmpAB43.tmp => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\tmpBF8D.tmp => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\tmpFFD9.tmp => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.InstallState => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\{bf5001a3-ae7a-4910-925a-5060ef2c0508}.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\{bf5001a3-ae7a-4910-925a-5060ef2c0508}64.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}64.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\{f81878fa-25e9-442d-8ada-79658b6520f2}64.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BOAS.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BrowserAdapter.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.CompatibilityChecker.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.ExpExt.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.FFUpdate.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.GCUpdate.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.OptChecker.dll => Moved successfully. C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.PurBrowse.dll => Moved successfully. Could not move "C:\Program Files (x86)\Dynamo Combo" directory. => Scheduled to move on reboot. C:\Program Files (x86)\XTab => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 => Moved successfully. C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GoodGameEmpire.lnk => Moved successfully. C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire => Moved successfully. C:\Users\1\Desktop\GRY\GoodGameEmpire.lnk => Moved successfully. C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}w64.sys => Moved successfully. C:\Windows\System32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys => Moved successfully. C:\Windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64.sys => Moved successfully. C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64.sys => Moved successfully. C:\Windows\System32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys => Moved successfully. C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}w64.sys => Moved successfully. C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64.sys => Moved successfully. C:\Windows\System32\drivers\{f81878fa-25e9-442d-8ada-79658b6520f2}w64.sys => Moved successfully. ========= sc config WinDefend start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= EmptyTemp: => Removed 3.9 GB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-02-12 23:40:50)<= C:\Program Files (x86)\Dynamo Combo => Is moved successfully. ==== End of Fixlog 23:40:50 ====