Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 15-04-2015 02 Ran by User at 2015-04-15 16:06:31 Run:2 Running from C:\Documents and Settings\User\Desktop\frst Loaded Profiles: User (Available profiles: User & Ania i Grześ) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R2 Update Greener Web; C:\Program Files\Greener Web\updateGreenerWeb.exe [318752 2014-06-29] () R2 Util Greener Web; C:\Program Files\Greener Web\bin\utilGreenerWeb.exe [318752 2014-06-29] () S1 iSafeKrnlMon; \??\C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys [X] S4 WindowsMangerProtect; C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect\ProtectWindowsManager.exe [473088 2014-12-26] (Fuyu LIMITED) [File not signed] Task: C:\WINDOWS\Tasks\64e02fd5-38d4-4796-99b5-94f9ce61e8e9-1.job => C:\Program Files\SavePass\SavePass-codedownloader.exeE/lVhSU /rcbYrfph=task /ZpBCgxxtc='SavePass' /opKZNk=57050 /CjftjJ='001504' /JlFutVD='0' /xsGyTcGOL='0' /uEdfKzwvS=3C1D0284B59B46099EBF9B6E9B4DB9F7IE /TRIdwDGm=2a6fa4d6fca1f2f51cc66965dd418d08 /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1403270371 /YSZaXHc=http:/stats.datagenserv.com /hSYjiK=http:/errors.datagenserv.com /jpelGLu=http:/js.datagenserv.com /tQQrCEVl=opera /VLUYScLFK=http:/js.clientdemocloud.com /JKizC /bOpFcHBjn='{asw:[2, 12582980, 0]}' /JGGFP='http:/update.datagenserv.com/ie_code_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\64e02fd5-38d4-4796-99b5-94f9ce61e8e9-4.job => C:\Program Files\SavePass\64e02fd5-38d4-4796-99b5-94f9ce61e8e9-4.exeq/yiYpEh /ZpBCgxxtc='SavePass' /fekQtsK C:\Program Files\SavePass\57050.xpi' /opKZNk=57050 /CjftjJ='001504' /JlFutVD='0' /xsGyTcGOL='0' /uEdfKzwvS=3C1D0284B59B46099EBF9B6E9B4DB9F7IE /TRIdwDGm=2a6fa4d6fca1f2f51cc66965dd418d08 /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1403270371 /YSZaXHc=http:/stats.datagenserv.com /hSYjiK=http:/errors.datagenserv.com /jTZPGdj=300 /iHOqOSqX=587fea1b-1c76-43c0-8b29-3c3da78e2485@2309207e-4ba6-42d8-b8a2-3b0a22e052b5.com /CIoZrUwqh=0.94 /rWNAvk=a587fea1b1c7643c08b293c3da78e24852309207e4ba642d8b8a23b0a22e052b5com57050 /DSfhfiuz=https:/w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/57050.rdf /cIstfpesq='SavePass' /xpLdKr='Just Save!' /kRdSKzd='OutBrowse' /tQQrCEVl=opera /bOpFcHBjn='{asw:[2, 12582980, 0]}' /JKizC /SaWjDhp /eyWjDj /JGGFP='http:/update.datagenserv.com/ff_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\bench-sys.job => C:\Program Files\Bench\Updater\updater.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\bench-Updater removing.job => XN EG /verysilent SYSTEM This will uninstall Updater <==== ATTENTION Task: C:\WINDOWS\Tasks\ffc1b485-31d9-46a5-a2fb-3de6a491d187-1.job => C:\Program Files\HQ-V1.4\HQ-V1.4-codedownloader.exe>/lVhSU /rcbYrfph=task /ZpBCgxxtc='HQ-V1.4' /opKZNk=58362 /CjftjJ='001553' /JlFutVD='0' /xsGyTcGOL='0' /uEdfKzwvS=9D5BD2C10EC341E3ADB65532CC207B80IE /TRIdwDGm=1c54ce95e4bfb8cc49a64f36322e09ee /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1403270331 /YSZaXHc=http:/stats.datagenserv.com /hSYjiK=http:/errors.datagenserv.com /jpelGLu=http:/js.datagenserv.com /tQQrCEVl=opera /VLUYScLFK=http:/js.clientdemocloud.com /JKizC /bOpFcHBjn='{asw:[2, 68, 0]}' /JGGFP='http:/update.datagenserv.com/ie_code_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\ffc1b485-31d9-46a5-a2fb-3de6a491d187-4.job => C:\Program Files\HQ-V1.4\ffc1b485-31d9-46a5-a2fb-3de6a491d187-4.exeŚ/yiYpEh /ZpBCgxxtc='HQ-V1.4' /fekQtsK C:\Program Files\HQ-V1.4\58362.xpi' /opKZNk=58362 /CjftjJ='001553' /JlFutVD='0' /xsGyTcGOL='0' /uEdfKzwvS=9D5BD2C10EC341E3ADB65532CC207B80IE /TRIdwDGm=1c54ce95e4bfb8cc49a64f36322e09ee /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1403270331 /YSZaXHc=http:/stats.datagenserv.com /hSYjiK=http:/errors.datagenserv.com /jTZPGdj=300 /iHOqOSqX=508d4e2f-a469-421d-a294-135dbb84fe1b@f7b17943-cc9e-4d4a-b223-0bd1e7cfc871.com /CIoZrUwqh=0.94 /rWNAvk=a508d4e2fa469421da294135dbb84fe1bf7b17943cc9e4d4ab2230bd1e7cfc871com58362 /DSfhfiuz=https:/w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/58362.rdf /cIstfpesq='HQ-V1.4' /xpLdKr='Turn YouTube videos to High Definition by default' /kRdSKzd='HQV1.4' /tQQrCEVl=opera /bOpFcHBjn='{asw:[2, 68, 0]}' /JKizC /SaWjDhp /eyWjDj /JGGFP='http:/update.datagenserv.com/ff_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\fun4us_notification_service.job => C:\Documents and Settings\User\Local Settings\Application Data\fun4us\fun4us_notification_service.exeâ/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='fun4us' /appid='73143' /srcid='2913' /bic='c3e994a2586ba8d7cc5eb266dcb010a6' /verifier='53dccb8e06c7bee9385adaae092f10fb' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif Task: C:\WINDOWS\Tasks\fun4us_updating_service.job => C:\Documents and Settings\User\Local Settings\Application Data\fun4us\fun4us_updating_service.exe§ /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=fun4us_updating_service /funurl=http:/stats.buildomserv.com HKLM\...\Run: [fst_pl_145] => [X] HKLM\...\Run: [upfst_pl_145.exe] => C:\Documents and Settings\User\Local Settings\Application Data\fst_pl_145\upfst_pl_145.exe -runhelper HKU\S-1-5-21-527237240-706699826-725345543-1003\...\MountPoints2: {90ed4f3f-8623-11e4-b085-001c231eb7f9} - E:\Startme.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ShortcutWithArgument: C:\Documents and Settings\User\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX ShortcutWithArgument: C:\Documents and Settings\User\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX ShortcutWithArgument: C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1403270212&from=obw&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1403270212&from=obw&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} HKU\S-1-5-21-527237240-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-527237240-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} SearchScopes: HKU\S-1-5-21-527237240-706699826-725345543-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll No File FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\delta-homes.xml [2014-12-29] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF HKLM\...\Firefox\Extensions: [detgdp@gmail.com] - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w4ibkb2u.default\extensions\detgdp@gmail.com CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [2014-08-04] C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect C:\Documents and Settings\User\Application Data\ColorTable C:\Documents and Settings\User\Application Data\i7OPoKuArNBT C:\Documents and Settings\User\Application Data\lTW1Bf6xfjnC C:\Documents and Settings\User\Local Settings\Application Data\fun4us C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome C:\Program Files\Greener Web C:\Program Files\WinZipper C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7 Folder: C:\Program Files\Mozilla Firefox Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins\@Microsoft.com/DownloadManager,version=1.1 /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. Update Greener Web => Service deleted successfully. Util Greener Web => Service deleted successfully. iSafeKrnlMon => Service deleted successfully. WindowsMangerProtect => Service deleted successfully. C:\WINDOWS\Tasks\64e02fd5-38d4-4796-99b5-94f9ce61e8e9-1.job not found. C:\WINDOWS\Tasks\64e02fd5-38d4-4796-99b5-94f9ce61e8e9-4.job not found. C:\WINDOWS\Tasks\bench-sys.job => Moved successfully. C:\WINDOWS\Tasks\bench-Updater removing.job => Moved successfully. C:\WINDOWS\Tasks\ffc1b485-31d9-46a5-a2fb-3de6a491d187-1.job => Moved successfully. C:\WINDOWS\Tasks\ffc1b485-31d9-46a5-a2fb-3de6a491d187-4.job => Moved successfully. C:\WINDOWS\Tasks\fun4us_notification_service.job => Moved successfully. C:\WINDOWS\Tasks\fun4us_updating_service.job => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\fst_pl_145 => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\upfst_pl_145.exe => value deleted successfully. "HKU\S-1-5-21-527237240-706699826-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{90ed4f3f-8623-11e4-b085-001c231eb7f9}" => Key deleted successfully. HKCR\CLSID\{90ed4f3f-8623-11e4-b085-001c231eb7f9} => Key not found. C:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully. C:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. C:\Documents and Settings\User\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Documents and Settings\User\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-527237240-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-527237240-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-527237240-706699826-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}" => Key deleted successfully. "HKCR\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6}" => Key deleted successfully. "HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0" => Key deleted successfully. "HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => Key deleted successfully. "HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => Key deleted successfully. C:\Program Files\mozilla firefox\browser\searchplugins\delta-homes.xml => Moved successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\detgdp@gmail.com => value deleted successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck" => Key deleted successfully. Could not move "C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx" => Scheduled to move on reboot. C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect => Moved successfully. C:\Documents and Settings\User\Application Data\ColorTable => Moved successfully. C:\Documents and Settings\User\Application Data\i7OPoKuArNBT => Moved successfully. C:\Documents and Settings\User\Application Data\lTW1Bf6xfjnC => Moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\fun4us => Moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome => Moved successfully. C:\Program Files\Greener Web => Moved successfully. C:\Program Files\WinZipper => Moved successfully. C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7 => Moved successfully. ========================= Folder: C:\Program Files\Mozilla Firefox ======================== 2015-04-08 14:54 - 2015-04-08 14:58 - 0020592 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll 2015-04-08 14:54 - 2015-04-08 14:58 - 0000667 _____ () C:\Program Files\Mozilla Firefox\application.ini 2015-04-08 14:54 - 2015-04-08 14:58 - 0109680 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\breakpadinjector.dll 2015-04-08 14:55 - 2015-04-08 14:58 - 0283248 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashreporter.exe 2015-04-08 14:55 - 2014-11-26 20:18 - 0004382 _____ () C:\Program Files\Mozilla Firefox\crashreporter.ini 2015-04-08 14:55 - 2010-05-26 21:41 - 2106216 _____ (Microsoft Corporation) C:\Program Files\Mozilla Firefox\D3DCompiler_43.dll 2015-04-08 14:55 - 2015-02-25 14:27 - 3466856 _____ (Microsoft Corporation) C:\Program Files\Mozilla Firefox\d3dcompiler_47.dll 2015-04-08 14:55 - 2015-02-25 14:27 - 0000093 _____ () C:\Program Files\Mozilla Firefox\dependentlibs.list 2015-04-08 14:55 - 2015-04-08 14:58 - 0376944 _____ (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe 2015-04-08 14:55 - 2015-04-08 14:58 - 0000899 _____ () C:\Program Files\Mozilla Firefox\freebl3.chk 2015-04-08 14:55 - 2015-04-08 14:58 - 0330864 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\freebl3.dll 2015-04-08 14:55 - 2015-04-08 14:58 - 10397296 _____ (The ICU Project) C:\Program Files\Mozilla Firefox\icudt52.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 1079920 _____ (The ICU Project) C:\Program Files\Mozilla Firefox\icuin52.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 0825456 _____ (The ICU Project) C:\Program Files\Mozilla Firefox\icuuc52.dll 2015-04-08 14:55 - 2014-12-29 12:14 - 0021010 _____ () C:\Program Files\Mozilla Firefox\install.log 2015-04-08 14:55 - 2015-04-08 14:57 - 0042096 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\libEGL.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 0871536 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\libGLESv2.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 0148080 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\maintenanceservice.exe 2015-04-08 14:55 - 2015-04-08 14:57 - 0185432 _____ (Mozilla Corporation) C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe 2015-04-08 14:55 - 2015-04-08 14:57 - 0017008 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\mozalloc.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 0104048 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\mozglue.dll 2015-04-08 14:55 - 2015-02-25 14:27 - 0455328 _____ (Microsoft Corporation) C:\Program Files\Mozilla Firefox\msvcp120.dll 2015-04-08 14:55 - 2015-02-25 14:27 - 0970912 _____ (Microsoft Corporation) C:\Program Files\Mozilla Firefox\msvcr120.dll 2015-04-08 14:55 - 2015-03-25 20:35 - 0013494 _____ () C:\Program Files\Mozilla Firefox\my.cfg 2015-04-08 14:55 - 2015-04-08 14:57 - 1675888 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\nss3.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 0415344 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\nssckbi.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 0000899 _____ () C:\Program Files\Mozilla Firefox\nssdbm3.chk 2015-04-08 14:55 - 2015-04-08 14:57 - 0093808 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\nssdbm3.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 11399262 _____ () C:\Program Files\Mozilla Firefox\omni.ja 2015-04-08 14:55 - 2015-04-08 14:57 - 0000143 _____ () C:\Program Files\Mozilla Firefox\platform.ini 2015-04-08 14:55 - 2015-04-08 14:57 - 0267888 _____ (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe 2015-04-08 14:55 - 2015-04-08 14:57 - 0172144 _____ (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-hang-ui.exe 2015-04-08 14:55 - 2015-04-08 14:57 - 0002288 _____ () C:\Program Files\Mozilla Firefox\precomplete 2015-04-08 14:55 - 2015-04-08 14:57 - 0000662 _____ () C:\Program Files\Mozilla Firefox\removed-files 2015-04-08 14:55 - 2015-04-08 14:57 - 0205424 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\sandboxbroker.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 0000899 _____ () C:\Program Files\Mozilla Firefox\softokn3.chk 2015-04-08 14:55 - 2015-04-08 14:57 - 0153200 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\softokn3.dll 2015-04-08 14:55 - 2015-04-08 14:57 - 0298096 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\updater.exe 2015-04-08 14:55 - 2014-11-26 20:19 - 0001200 _____ () C:\Program Files\Mozilla Firefox\updater.ini 2015-04-08 14:55 - 2014-11-26 16:02 - 0000132 _____ () C:\Program Files\Mozilla Firefox\update-settings.ini 2015-04-08 14:55 - 2015-04-08 14:57 - 0002260 _____ () C:\Program Files\Mozilla Firefox\voucher.bin 2015-04-08 14:55 - 2015-04-08 14:57 - 0132720 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\webapprt-stub.exe 2015-04-08 14:55 - 2015-04-08 14:57 - 0091032 _____ (Mozilla Corporation) C:\Program Files\Mozilla Firefox\webapp-uninstaller.exe 2015-04-08 14:55 - 2015-04-08 14:57 - 0127088 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\wow_helper.exe 2015-04-08 14:55 - 2015-04-08 14:57 - 35088496 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\xul.dll 2015-04-08 14:54 - 2015-04-08 14:58 - 0000000 ____D () C:\Program Files\Mozilla Firefox\browser 2015-04-08 14:54 - 2015-04-08 14:58 - 0157429 _____ () C:\Program Files\Mozilla Firefox\browser\blocklist.xml 2015-04-08 14:54 - 2014-11-26 16:09 - 0000040 _____ () C:\Program Files\Mozilla Firefox\browser\chrome.manifest 2015-04-08 14:54 - 2014-11-26 20:18 - 0000880 _____ () C:\Program Files\Mozilla Firefox\browser\crashreporter-override.ini 2015-04-08 14:54 - 2015-04-08 14:58 - 13394950 _____ () C:\Program Files\Mozilla Firefox\browser\omni.ja 2015-04-08 14:54 - 2015-04-08 14:58 - 0000000 ____D () C:\Program Files\Mozilla Firefox\browser\components 2015-04-08 14:54 - 2015-04-08 14:58 - 0050800 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\browser\components\browsercomps.dll 2015-04-08 14:54 - 2014-11-26 16:09 - 0000034 _____ () C:\Program Files\Mozilla Firefox\browser\components\components.manifest 2015-04-08 14:54 - 2015-04-08 14:54 - 0000000 ____D () C:\Program Files\Mozilla Firefox\browser\defaults 2015-04-08 14:54 - 2015-04-08 14:54 - 0000000 ____D () C:\Program Files\Mozilla Firefox\browser\defaults\preferences 2015-04-08 14:54 - 2015-03-25 19:32 - 0000088 _____ () C:\Program Files\Mozilla Firefox\browser\defaults\preferences\my-prefs.js 2015-04-08 14:54 - 2015-04-08 14:54 - 0000000 ____D () C:\Program Files\Mozilla Firefox\browser\extensions 2015-04-08 14:54 - 2015-04-08 14:58 - 0000000 ____D () C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} 2015-04-08 14:54 - 2014-11-26 14:44 - 0001850 _____ () C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png 2015-04-08 14:54 - 2015-04-08 14:58 - 0001325 _____ () C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf 2015-04-08 14:55 - 2015-04-15 16:10 - 0000000 ____D () C:\Program Files\Mozilla Firefox\browser\searchplugins 2015-04-08 14:55 - 2014-11-26 20:18 - 0002273 _____ () C:\Program Files\Mozilla Firefox\browser\searchplugins\allegro-pl.xml 2015-04-08 14:55 - 2014-11-26 20:18 - 0018087 _____ () C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml 2015-04-08 14:55 - 2015-01-14 01:58 - 0026531 _____ () C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml 2015-04-08 14:55 - 2014-11-26 20:18 - 0001192 _____ () C:\Program Files\Mozilla Firefox\browser\searchplugins\merlin-pl.xml 2015-04-08 14:55 - 2014-11-26 20:18 - 0002075 _____ () C:\Program Files\Mozilla Firefox\browser\searchplugins\pwn-pl.xml 2015-04-08 14:55 - 2014-11-26 20:18 - 0009353 _____ () C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-pl.xml 2015-04-08 14:55 - 2014-11-26 20:18 - 0001238 _____ () C:\Program Files\Mozilla Firefox\browser\searchplugins\wolnelektury-pl.xml 2015-04-08 14:55 - 2014-11-26 20:18 - 0007889 _____ () C:\Program Files\Mozilla Firefox\browser\searchplugins\wp-pl.xml 2015-04-08 14:55 - 2015-04-08 14:55 - 0000000 ____D () C:\Program Files\Mozilla Firefox\defaults 2015-04-08 14:55 - 2015-04-08 14:55 - 0000000 ____D () C:\Program Files\Mozilla Firefox\defaults\pref 2015-04-08 14:55 - 2014-11-26 18:31 - 0000250 _____ () C:\Program Files\Mozilla Firefox\defaults\pref\channel-prefs.js 2015-04-08 14:55 - 2015-04-08 14:55 - 0000000 ____D () C:\Program Files\Mozilla Firefox\dictionaries 2015-04-08 14:55 - 2014-11-26 20:18 - 0245042 _____ () C:\Program Files\Mozilla Firefox\dictionaries\pl.aff 2015-04-08 14:55 - 2015-02-25 14:27 - 4405286 _____ () C:\Program Files\Mozilla Firefox\dictionaries\pl.dic 2015-04-08 14:55 - 2015-04-08 14:55 - 0000000 ____D () C:\Program Files\Mozilla Firefox\gmp-clearkey 2015-04-08 14:55 - 2015-04-08 14:58 - 0000000 ____D () C:\Program Files\Mozilla Firefox\gmp-clearkey\0.1 2015-04-08 14:55 - 2015-04-08 14:58 - 0187504 _____ (Mozilla Foundation) C:\Program Files\Mozilla Firefox\gmp-clearkey\0.1\clearkey.dll 2015-04-08 14:55 - 2015-04-08 14:58 - 0000258 _____ () C:\Program Files\Mozilla Firefox\gmp-clearkey\0.1\clearkey.info 2015-04-08 14:55 - 2015-04-08 16:19 - 0000000 ____D () C:\Program Files\Mozilla Firefox\uninstall 2015-04-08 14:55 - 2015-04-08 14:57 - 0923400 _____ (Mozilla Corporation) C:\Program Files\Mozilla Firefox\uninstall\helper.exe 2015-04-08 14:55 - 2014-12-29 12:14 - 0000322 _____ () C:\Program Files\Mozilla Firefox\uninstall\shortcuts_log.ini 2015-04-08 14:55 - 2014-12-29 12:14 - 0002101 _____ () C:\Program Files\Mozilla Firefox\uninstall\uninstall.log 2015-04-08 14:55 - 2015-04-08 16:19 - 0000000 _____ () C:\Program Files\Mozilla Firefox\uninstall\uninstall.update 2015-04-08 14:55 - 2015-04-08 14:58 - 0000000 ____D () C:\Program Files\Mozilla Firefox\webapprt 2015-04-08 14:55 - 2015-04-08 14:57 - 0085582 _____ () C:\Program Files\Mozilla Firefox\webapprt\omni.ja 2015-04-08 14:55 - 2015-04-08 14:57 - 0000495 _____ () C:\Program Files\Mozilla Firefox\webapprt\webapprt.ini ====== End of Folder: ====== ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= The operation completed successfully ========= End of Reg: ========= ========= reg delete HKCU\Software\Google\Chrome /f ========= The operation completed successfully ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google\Chrome /f ========= The operation completed successfully ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins\@Microsoft.com/DownloadManager,version=1.1 /f ========= The operation completed successfully ========= End of Reg: ========= EmptyTemp: => Removed 1.6 GB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-04-15 16:14:54)<= "C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx" => File could not move. ==== End of Fixlog 16:14:56 ====