Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-02-2014 01 Ran by win7 at 2014-02-12 19:22:04 Run:1 Running from C:\Users\win7\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** (Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe (Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe () C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe () C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\loggingserver.exe (Systweak Inc) C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe (Akamai Technologies, Inc.) C:\Users\win7\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\win7\AppData\Local\Akamai\netsession_win.exe () C:\Program Files (x86)\AVG Secure Search\vprot.exe (Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe () C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG Secure Search\vprot.exe [2552856 2014-02-03] () HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1648264 2013-04-25] (Ask) HKLM-x32\...\Run: [Regedit32] - C:\Windows\SysWOW64\regedit.exe [398336 2009-07-14] (Microsoft Corporation) HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [746176 2013-11-01] () HKU\S-1-5-21-2985978322-4174081002-1716717453-1000\...\Run: [Akamai NetSession Interface] - C:\Users\win7\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKU\S-1-5-21-2985978322-4174081002-1716717453-1000\...\Run: [Regedit32] - C:\Windows\system32\regedit.exe HKU\S-1-5-21-2985978322-4174081002-1716717453-1000\...\Run: [Softonic for Windows] - C:\Users\win7\AppData\Local\Softonic\Softonic.exe [4140016 2014-01-17] (Softonic) HKU\S-1-5-21-2985978322-4174081002-1716717453-1001\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - C:\Program Files (x86)\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe [1266712 2013-05-31] (AVG Secure Search) HKU\S-1-5-21-2985978322-4174081002-1716717453-1001\...\Run: [AVG-Secure-Search-Update_JUNE2013_HP] - C:\Program Files (x86)\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_HP.exe [1266712 2013-06-07] (AVG Secure Search) AppInit_DLLs: c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll => C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\loader.dll [1958880 2013-11-18] () AppInit_DLLs-x32: c:\PROGRA~3\BitGuard\271832~1.68\{C16C1~1\BitGuard.dll => C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll [3618304 2013-11-18] () HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1383242864&from=cor&uid=ST500DM002-1BD142_Z2AYQQQAXXXXZ2AYQQQA HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.babylon.com/?affID=119370&tt=190313_wo1&babsrc=HP_ss_gin2g&mntrId=C2683085A98D4FF2 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1383242864&from=cor&uid=ST500DM002-1BD142_Z2AYQQQAXXXXZ2AYQQQA HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1383242864&from=cor&uid=ST500DM002-1BD142_Z2AYQQQAXXXXZ2AYQQQA HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1383242864&from=cor&uid=ST500DM002-1BD142_Z2AYQQQAXXXXZ2AYQQQA URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1383242864&from=cor&uid=ST500DM002-1BD142_Z2AYQQQAXXXXZ2AYQQQA&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1383242864&from=cor&uid=ST500DM002-1BD142_Z2AYQQQAXXXXZ2AYQQQA&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1383242864&from=cor&uid=ST500DM002-1BD142_Z2AYQQQAXXXXZ2AYQQQA&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1383242864&from=cor&uid=ST500DM002-1BD142_Z2AYQQQAXXXXZ2AYQQQA&q={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&affID=119370&tt=190313_wo1&babsrc=SP_ss&mntrId=C2683085A98D4FF2 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1383242864&from=cor&uid=ST500DM002-1BD142_Z2AYQQQAXXXXZ2AYQQQA&q={searchTerms} SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={6AB6ACED-1D8F-45DD-A76C-6E8A9DE04C63}&mid=da1fee0c96d44f9081720844c4f27dcc-4546c5d6091a027045a53985070398a815c2493c&lang=pl&ds=ax011&pr=&d=2012-10-08 16:03:16&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKCU - {AAF47223-F7F5-4ED8-BF00-7E27C8A91EF1} URL = http://www.claro-search.com/?q={searchTerms}&affID=110824&tt=4312_6&babsrc=SP_ss&mntrId=c268b1fa0000000000003085a98d4ff2 SearchScopes: HKCU - {F7FD647C-5D47-4225-9A9F-0C6A64B116C2} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=3B8798F8-C8CB-44C5-ABB4-B9137B1BC065&apn_sauid=37078711-FDCC-41BA-AA84-8BB4D085D8C7 BHO-x32: Claro LTD Helper Object - {000F18F2-09EB-4A59-82B2-5AE4184C39C3} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll (Montera Technologeis LTD) BHO-x32: mixidj Helper Object - {4D6A9BBF-402C-4301-B1EF-28D04F71D761} - C:\Program Files (x86)\mixidj\mixidj\1.8.4.1\bh\mixidj.dll (MixiDJ) BHO-x32: SaveSense - {71e129ff-6c2a-4984-818c-7e2c998b8d99} - C:\Users\win7\AppData\Local\SaveSense\SaveSenseIE.dll (SaveSense) BHO-x32: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\17.3.0.49\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com) BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) BHO-x32: BonanzaDeals - {fe063412-bea4-4d76-8ed3-183be6220d17} - C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE.dll (BonanzaDeals) Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\17.3.0.49\AVG Secure Search_toolbar.dll (AVG Secure Search) Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - Claro LTD Toolbar - {9E131A93-EED7-4BEB-B015-A0ADB30B5646} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\claroTlbr.dll (Montera Technologeis LTD) Toolbar: HKLM-x32 - MixiDJ Toolbar - {CA9B9C89-4662-4ADC-9C23-A452BECD5D19} - C:\Program Files (x86)\mixidj\mixidj\1.8.4.1\mixidjTlbr.dll (MixiDJ) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll (AVG Secure Search) CHR HKLM-x32\...\Chrome\Extension: [boipimhfjpakfgckhbljjengakjhkcbp] - C:\Users\win7\AppData\Roaming\CRMixiDJTB\mixiDJ.crx [2013-02-05] CHR HKLM-x32\...\Chrome\Extension: [ccncljhbalbbkkfgopogabimepmfkmff] - C:\Program Files (x86)\BatBrowse\ccncljhbalbbkkfgopogabimepmfkmff.crx [2013-02-05] CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\win7\AppData\Roaming\BabSolution\CR\Delta.crx [2013-02-05] CHR HKLM-x32\...\Chrome\Extension: [kpepfkjapeclaafmhoelccknpfedainn] - C:\Program Files (x86)\mixidj\mixidj\1.8.4.1\mixidj.crx [2012-11-13] CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\17.3.0.49\avg.crx [2014-01-08] Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [320000] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Task: {1D1A4A87-F1BD-430D-8204-D2699A5DFC2D} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2012-12-10] (Systweak Inc) <==== ATTENTION Task: {26F7DDB7-39D8-4A3B-BF4D-4ECD13B5480E} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-01] (BonanzaDeals) <==== ATTENTION Task: {2A85C3C4-8A96-4F33-826A-A91621107D02} - System32\Tasks\PC Performer => C:\Program Files (x86)\PC Performer\PCPerformer.exe <==== ATTENTION Task: {3311B86D-77D2-41EA-8921-FE93EAB34DA8} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2012-12-10] (Systweak Inc) <==== ATTENTION Task: {41BEE9AE-7D80-4102-9E4C-22D84DFCB814} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2013-04-25] () Task: {423BC4A1-F70D-48D0-9201-76C4712A94C2} - System32\Tasks\{E6E5484E-F187-426C-BCB3-730EDD4F0C0A} => Firefox.exe http://ui.skype.com/ui/0/6.0.0.120.259/pl/abandoninstall?page=tsMain Task: {46E82F5B-4CEC-4DC3-86FC-C2194BE347EA} - System32\Tasks\Adobe Flash Player Updater Task: {56C1C39B-44E3-4365-80C2-8827DB5E8294} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-01] (BonanzaDeals) <==== ATTENTION Task: {6DA06F35-1A95-4370-BD33-9FF60F9B64E7} - System32\Tasks\{A14CFDBB-71D4-4AD1-96D2-2B1EC4EFFCBB} => D:\LoL\League of Legends\RADS\system\rads_user_kernel.exe Task: {744E036A-4C2C-4521-B32B-F5025C12D8B6} - System32\Tasks\AdobeFlashPlayerUpdate 2 Task: {782503AE-CD0D-4A71-A3FE-58FBEF60194B} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION Task: {9FC8135C-4545-4E25-916E-C0800C077891} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2012-12-10] (Systweak Inc) <==== ATTENTION Task: {ACB3845D-DD62-4482-85A9-5A714B561206} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe Task: {D87897EE-CF28-4707-BA4D-4FCFCA59F2B6} - System32\Tasks\BonanzaDealsUpdate => C:\Program <==== ATTENTION Task: {FDBD43D7-A5A7-48F1-A76F-3BAAFD90F496} - System32\Tasks\AdobeFlashPlayerUpdate Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ? Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe <==== ATTENTION Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe <==== ATTENTION Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Google Update Helper (x32 Version: 1.3.23.0 - BonanzaDeals) Hidden <==== ATTENTION S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-11-01] (BonanzaDeals) S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-11-01] (BonanzaDeals) R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [578264 2011-12-21] (Pandora.TV) R2 Update BatBrowse; C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe [80160 2014-02-05] () R2 Util BatBrowse; C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe [80160 2014-02-05] () R2 vToolbarUpdater17.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [1771544 2014-01-08] (AVG Secure Search) R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-02] (Cherished Technololgy LIMITED) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\98560968.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\98560968.sys => ""="Driver" testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION! C:\Users\win7\*.exe C:\Users\win7\AppData\Roaming\BabSolution C:\Users\win7\AppData\Roaming\Babylon C:\Users\win7\AppData\Roaming\DLKNFUF83457 C:\Users\win7\AppData\Roaming\File Scout C:\Users\win7\AppData\Roaming\KJN13S4UVR5HV C:\Users\win7\AppData\Roaming\VMFNTN8945 C:\Users\win7\AppData\Local\{5D70B5D6-274D-4B71-AEFE-1DDD443CC7CB} C:\Users\win7\AppData\Local\SaveSense C:\Users\win7\AppData\Local\SaveSenseLive C:\Users\win7\AppData\Local\Temp\{0DB35E2A-15AD-49B0-BC01-46DD3D366862}.exe C:\Users\win7\Desktop\Wyczyść rejestr za darmo!.lnk C:\Users\win7\Downloads\avast.Free.Antivirus_2014_9.0.2013.292 (37071).exe C:\Users\win7\Downloads\Gadwin-PrintScreen(12471).exe C:\Users\win7\Downloads\ps_setup.exe C:\Users\win7\Downloads\setup_przyspiesz_ndw556hqu.exe C:\Windows\system32\Drivers\iuzzblbf.sys C:\Windows\system32\Drivers\jfmspnpr.sys C:\Windows\system32\Drivers\tteiapif.sys C:\Windows\system32\Drivers\hrgccsil.sys Folder: C:\Users\win7\AppData\Roaming\BoL Folder: C:\Users\win7\AppData\Roaming\XulTest ***************** [1516] C:\ProgramData\WPM\wprotectmanager.exe => Process closed successfully. [1252] C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe => Process closed successfully. [1768] C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe => Process closed successfully. [2352] C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe => Process closed successfully. [2420] C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe => Process closed successfully. [2844] C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\loggingserver.exe => Process closed successfully. C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe => No running process found [1224] C:\Users\win7\AppData\Local\Akamai\netsession_win.exe => Process closed successfully. [3484] C:\Users\win7\AppData\Local\Akamai\netsession_win.exe => Process closed successfully. C:\Users\win7\AppData\Local\Akamai\netsession_win.exe => No running process found [4536] C:\Program Files (x86)\AVG Secure Search\vprot.exe => Process closed successfully. [4692] C:\Program Files (x86)\Ask.com\Updater\Updater.exe => Process closed successfully. [4220] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe => Process closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\vProt => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Regedit32 => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKU\S-1-5-21-2985978322-4174081002-1716717453-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => Value deleted successfully. HKU\S-1-5-21-2985978322-4174081002-1716717453-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Regedit32 => Value deleted successfully. HKU\S-1-5-21-2985978322-4174081002-1716717453-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Softonic for Windows => Value deleted successfully. HKU\S-1-5-21-2985978322-4174081002-1716717453-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_JUNE2013_TB => Value deleted successfully. HKU\S-1-5-21-2985978322-4174081002-1716717453-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_JUNE2013_HP => Value deleted successfully. "c:\\progra~3\\bitguard\\271832~1.68\\{c16c1~1\\loader.dll" => Value Data removed successfully. "c:\\PROGRA~3\\BitGuard\\271832~1.68\\{C16C1~1\\BitGuard.dll" => Value Data removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AAF47223-F7F5-4ED8-BF00-7E27C8A91EF1} => Key deleted successfully. HKCR\CLSID\{AAF47223-F7F5-4ED8-BF00-7E27C8A91EF1} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F7FD647C-5D47-4225-9A9F-0C6A64B116C2} => Key deleted successfully. HKCR\CLSID\{F7FD647C-5D47-4225-9A9F-0C6A64B116C2} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000F18F2-09EB-4A59-82B2-5AE4184C39C3} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{000F18F2-09EB-4A59-82B2-5AE4184C39C3} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D6A9BBF-402C-4301-B1EF-28D04F71D761} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{4D6A9BBF-402C-4301-B1EF-28D04F71D761} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{71e129ff-6c2a-4984-818c-7e2c998b8d99} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{fe063412-bea4-4d76-8ed3-183be6220d17} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{9E131A93-EED7-4BEB-B015-A0ADB30B5646} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{9E131A93-EED7-4BEB-B015-A0ADB30B5646} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{CA9B9C89-4662-4ADC-9C23-A452BECD5D19} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{CA9B9C89-4662-4ADC-9C23-A452BECD5D19} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Key deleted successfully. HKCR\Wow6432Node\PROTOCOLS\Handler\viprotocol => Key deleted successfully. HKCR\Wow6432Node\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\boipimhfjpakfgckhbljjengakjhkcbp => Key deleted successfully. C:\Users\win7\AppData\Roaming\CRMixiDJTB\mixiDJ.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ccncljhbalbbkkfgopogabimepmfkmff => Key deleted successfully. "C:\Program Files (x86)\BatBrowse\ccncljhbalbbkkfgopogabimepmfkmff.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde => Key deleted successfully. "C:\Users\win7\AppData\Roaming\BabSolution\CR\Delta.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kpepfkjapeclaafmhoelccknpfedainn => Key deleted successfully. C:\Program Files (x86)\mixidj\mixidj\1.8.4.1\mixidj.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof => Key deleted successfully. C:\ProgramData\AVG Secure Search\ChromeExt\17.3.0.49\avg.crx => Moved successfully. Winsock: Catalog5 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll Winsock: Catalog entry Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [320000] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" => Not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D1A4A87-F1BD-430D-8204-D2699A5DFC2D} => Key not found. C:\Windows\System32\Tasks\RegClean Pro => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{26F7DDB7-39D8-4A3B-BF4D-4ECD13B5480E} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26F7DDB7-39D8-4A3B-BF4D-4ECD13B5480E} => Error deleting key C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2A85C3C4-8A96-4F33-826A-A91621107D02} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A85C3C4-8A96-4F33-826A-A91621107D02} => Error deleting key C:\Windows\System32\Tasks\PC Performer => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Performer => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3311B86D-77D2-41EA-8921-FE93EAB34DA8} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3311B86D-77D2-41EA-8921-FE93EAB34DA8} => Error deleting key C:\Windows\System32\Tasks\RegClean Pro_UPDATES => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41BEE9AE-7D80-4102-9E4C-22D84DFCB814} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41BEE9AE-7D80-4102-9E4C-22D84DFCB814} => Error deleting key C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{423BC4A1-F70D-48D0-9201-76C4712A94C2} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{423BC4A1-F70D-48D0-9201-76C4712A94C2} => Error deleting key C:\Windows\System32\Tasks\{E6E5484E-F187-426C-BCB3-730EDD4F0C0A} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E6E5484E-F187-426C-BCB3-730EDD4F0C0A} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{46E82F5B-4CEC-4DC3-86FC-C2194BE347EA} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{46E82F5B-4CEC-4DC3-86FC-C2194BE347EA} => Error deleting key C:\Windows\System32\Tasks\Adobe Flash Player Updater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{56C1C39B-44E3-4365-80C2-8827DB5E8294} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{56C1C39B-44E3-4365-80C2-8827DB5E8294} => Error deleting key C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6DA06F35-1A95-4370-BD33-9FF60F9B64E7} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DA06F35-1A95-4370-BD33-9FF60F9B64E7} => Error deleting key C:\Windows\System32\Tasks\{A14CFDBB-71D4-4AD1-96D2-2B1EC4EFFCBB} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A14CFDBB-71D4-4AD1-96D2-2B1EC4EFFCBB} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{744E036A-4C2C-4521-B32B-F5025C12D8B6} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{744E036A-4C2C-4521-B32B-F5025C12D8B6} => Error deleting key C:\Windows\System32\Tasks\AdobeFlashPlayerUpdate 2 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2 => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{782503AE-CD0D-4A71-A3FE-58FBEF60194B} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{782503AE-CD0D-4A71-A3FE-58FBEF60194B} => Error deleting key C:\Windows\System32\Tasks\BitGuard => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BitGuard => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9FC8135C-4545-4E25-916E-C0800C077891} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9FC8135C-4545-4E25-916E-C0800C077891} => Error deleting key C:\Windows\System32\Tasks\RegClean Pro_DEFAULT => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ACB3845D-DD62-4482-85A9-5A714B561206} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ACB3845D-DD62-4482-85A9-5A714B561206} => Error deleting key C:\Windows\System32\Tasks\Game_Booster_AutoUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Game_Booster_AutoUpdate => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D87897EE-CF28-4707-BA4D-4FCFCA59F2B6} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D87897EE-CF28-4707-BA4D-4FCFCA59F2B6} => Error deleting key C:\Windows\System32\Tasks\BonanzaDealsUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FDBD43D7-A5A7-48F1-A76F-3BAAFD90F496} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FDBD43D7-A5A7-48F1-A76F-3BAAFD90F496} => Error deleting key C:\Windows\System32\Tasks\AdobeFlashPlayerUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate => Error deleting key C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\RegClean Pro_DEFAULT.job => Moved successfully. C:\Windows\Tasks\RegClean Pro_UPDATES.job => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}\\SystemComponent => Value deleted successfully. bonanzadealslive => Service deleted successfully. bonanzadealslivem => Service deleted successfully. PanService => Service deleted successfully. Update BatBrowse => Service deleted successfully. Util BatBrowse => Service deleted successfully. vToolbarUpdater17.3.0 => Service deleted successfully. Wpm => Service deleted successfully. catchme => Service deleted successfully. EagleX64 => Service deleted successfully. WinRing0_1_2_0 => Service deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\98560968.sys => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\98560968.sys => Key deleted successfully. Operacja ukoäczona pomy˜lnie. C:\Users\win7\*.exe => Moved successfully. C:\Users\win7\AppData\Roaming\BabSolution => Moved successfully. C:\Users\win7\AppData\Roaming\Babylon => Moved successfully. C:\Users\win7\AppData\Roaming\DLKNFUF83457 => Moved successfully. C:\Users\win7\AppData\Roaming\File Scout => Moved successfully. C:\Users\win7\AppData\Roaming\KJN13S4UVR5HV => Moved successfully. C:\Users\win7\AppData\Roaming\VMFNTN8945 => Moved successfully. C:\Users\win7\AppData\Local\{5D70B5D6-274D-4B71-AEFE-1DDD443CC7CB} => Moved successfully. C:\Users\win7\AppData\Local\SaveSense => Moved successfully. C:\Users\win7\AppData\Local\SaveSenseLive => Moved successfully. "C:\Users\win7\AppData\Local\Temp\{0DB35E2A-15AD-49B0-BC01-46DD3D366862}.exe" => File/Directory not found. C:\Users\win7\Desktop\Wyczyść rejestr za darmo!.lnk => Moved successfully. C:\Users\win7\Downloads\avast.Free.Antivirus_2014_9.0.2013.292 (37071).exe => Moved successfully. C:\Users\win7\Downloads\Gadwin-PrintScreen(12471).exe => Moved successfully. C:\Users\win7\Downloads\ps_setup.exe => Moved successfully. C:\Users\win7\Downloads\setup_przyspiesz_ndw556hqu.exe => Moved successfully. C:\Windows\system32\Drivers\iuzzblbf.sys => Moved successfully. C:\Windows\system32\Drivers\jfmspnpr.sys => Moved successfully. C:\Windows\system32\Drivers\tteiapif.sys => Moved successfully. C:\Windows\system32\Drivers\hrgccsil.sys => Moved successfully. ========================= Folder: C:\Users\win7\AppData\Roaming\BoL ======================== 2013-08-20 17:10 - 2013-10-13 11:20 - 0000474 _____ () C:\Users\win7\AppData\Roaming\BoL\Config.xml 2013-08-21 18:37 - 2013-08-21 18:37 - 0000000 _____ () C:\Users\win7\AppData\Roaming\BoL\dump.txt 2013-08-20 17:10 - 2013-10-13 11:20 - 0347545 _____ () C:\Users\win7\AppData\Roaming\BoL\ldata.bol 2013-08-20 17:10 - 2013-10-13 11:20 - 0025304 _____ () C:\Users\win7\AppData\Roaming\BoL\ndata.bol 2013-10-12 22:20 - 2013-10-12 22:20 - 0028448 _____ () C:\Users\win7\AppData\Roaming\BoL\pic.png ====== End of Folder: ====== ========================= Folder: C:\Users\win7\AppData\Roaming\XulTest ======================== 2013-10-31 15:16 - 2013-10-31 15:16 - 0000000 ____D () C:\Users\win7\AppData\Roaming\XulTest\Firefox 2013-10-31 15:16 - 2013-10-31 15:16 - 0000000 ____D () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles 2013-10-31 15:16 - 2014-02-07 08:56 - 0000000 ____D () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default 2013-10-31 15:16 - 2013-10-31 15:16 - 0000111 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\profiles.ini 2013-10-31 15:16 - 2014-02-07 08:56 - 0065536 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\cert8.db 2013-10-31 15:16 - 2014-02-07 08:54 - 0000201 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\compatibility.ini 2013-10-31 15:16 - 2014-02-07 08:54 - 0524288 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\cookies.sqlite 2013-10-31 15:16 - 2014-02-07 08:54 - 0032768 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\cookies.sqlite-shm 2013-10-31 15:16 - 2014-02-07 08:56 - 1869176 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\cookies.sqlite-wal 2013-10-31 18:02 - 2013-10-31 18:02 - 0196608 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\formhistory.sqlite 2013-10-31 15:16 - 2014-02-07 08:56 - 0016384 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\key3.db 2014-02-04 17:38 - 2014-02-04 17:38 - 0000169 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\localstore-safe.rdf 2013-10-31 15:16 - 2013-10-31 15:16 - 0000169 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\localstore.rdf 2013-10-31 15:16 - 2014-02-07 08:54 - 0000057 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\marionette.log 2013-10-31 15:16 - 2014-02-07 08:54 - 0000000 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\parent.lock 2013-10-31 15:16 - 2014-02-04 17:40 - 0065536 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\permissions.sqlite 2013-10-31 15:32 - 2014-02-04 18:22 - 10485760 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\places.sqlite 2014-02-05 13:17 - 2014-02-06 15:11 - 0032768 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\places.sqlite-shm 2014-02-05 13:17 - 2014-02-05 13:17 - 0000000 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\places.sqlite-wal 2014-02-06 21:55 - 2014-02-06 21:55 - 0006567 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\pluginreg.dat 2014-02-07 08:56 - 2014-02-07 08:56 - 0001859 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\prefs.js 2013-10-31 15:16 - 2013-10-31 15:16 - 0016384 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\secmod.db 2014-01-10 15:25 - 2014-01-10 15:25 - 0000001 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\Telemetry.FailedProfileLocks.txt 2013-10-31 15:16 - 2013-10-31 15:16 - 0000029 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\times.json 2013-10-31 15:32 - 2014-02-07 08:56 - 0098304 _____ () C:\Users\win7\AppData\Roaming\XulTest\Firefox\Profiles\qhmpjaju.default\webappsstore.sqlite ====== End of Folder: ====== ==== End of Fixlog ====