Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01 Ran by user at 2014-04-08 15:58:40 Run:2 Running from C:\Users\user\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files\Mega Browse\bin\utilMegaBrowse.exe () C:\Program Files\Mega Browse\updateMegaBrowse.exe () C:\Program Files\Mega Browse\bin\FilterApp_C.exe S2 bonanzadealslive; C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2014-01-13] (BonanzaDeals) S3 bonanzadealslivem; C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2014-01-13] (BonanzaDeals) R2 ca82e1a5; C:\Program Files\Optimizer Pro\OptProCrashSvc.dll [220800 2014-04-07] () S2 PirritDesktop; C:\Users\user\AppData\Local\PirritSuggestor\PirritService.exe [52568 2014-02-14] () S2 PirritUpdater; C:\Program Files\Pirrit\AutoUpdater.exe [55296 2014-01-10] () R2 Update Mega Browse; C:\Program Files\Mega Browse\updateMegaBrowse.exe [350496 2014-04-04] () R2 Util Mega Browse; C:\Program Files\Mega Browse\bin\utilMegaBrowse.exe [350496 2014-04-07] () S2 WinRST; C:\Program Files\WinRST\WinRST.exe [59904 2014-02-26] () S2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-13] (Cherished Technololgy LIMITED) R1 wStLibG; C:\Windows\System32\drivers\wStLibG.sys [52928 2014-04-07] (StdLib) S3 cpuz134; \??\C:\Users\user\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X] R3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\Run: [fst_pl_96] - [X] HKU\S-1-5-21-101661676-3665781825-895367130-1000\...\Run: [LiveSupport] - "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log HKU\S-1-5-21-101661676-3665781825-895367130-1000\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\user\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKU\S-1-5-21-101661676-3665781825-895367130-1000\...\Run: [Optimizer Pro] - C:\Program Files\Optimizer Pro\OptProLauncher.exe [135160 2014-01-28] (PC Utilities Software Limited) AppInit_DLLs: c:\progra~1\optimi~1\optpro~2.dll => C:\Program Files\Optimizer Pro\OptProCrash.dll [4110808 2014-04-07] () ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC ProxyServer: http=http://127.0.0.1:9880 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-page.com/?type=hp&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC&q={searchTerms} URLSearchHook: HKLM - Winamp Toolbar Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.) URLSearchHook: HKCU - Winamp Toolbar Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC&q={searchTerms} SearchScopes: HKLM - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20140105145753022&tb_oid=05-01-2014&tb_mrud=05-01-2014 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1389564027&from=cor&uid=ST500LT012-1DG142_W3P0TLLCXXXXW3P0TLLC&q={searchTerms} SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20140105145753022&tb_oid=05-01-2014&tb_mrud=05-01-2014 BHO: Mega Browse - {4e6cd411-ce62-4584-97ff-6afbcf6900af} - C:\Program Files\Mega Browse\MegaBrowsebho.dll (Mega Browse) BHO: IEExtension.Extension - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.) Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () Toolbar: HKCU - Winamp Toolbar - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.) Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () CHR Extension: (No Name) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml [2014-01-13] CHR HKLM\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2014-01-12] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Task: {0145FED3-CDBD-431B-9B04-0933E0224BA0} - System32\Tasks\BonanzaDealsUpdate => C:\Program <==== ATTENTION Task: {1613FEAB-F8C5-430C-A51A-7E400BBCC778} - System32\Tasks\SomotoUpdateCheckerAutoStart => C:\Users\user\AppData\Local\FilesFrog Update Checker\update_checker.exe [2013-10-17] (Somoto) <==== ATTENTION Task: {99556109-4501-44FA-A7E9-0B0F5B6D693C} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2014-01-13] (BonanzaDeals) <==== ATTENTION Task: {ED856101-DC94-4C40-AD74-D5A04491AC7A} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2014-01-13] (BonanzaDeals) <==== ATTENTION Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe <==== ATTENTION Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe <==== ATTENTION C:\Program Files\BBlockUTubeAd C:\Program Files\BonanzaDealsLive C:\Program Files\Enigma Software Group C:\Program Files\Mobogenie C:\Program Files\predm C:\Program Files\WinRST C:\ProgramData\eec33f7f144d96af C:\ProgramData\BBlockUTubeAd C:\ProgramData\BonanzaDealsLive C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 C:\Users\user\AppData\Local\{6303A451-8642-457B-A55E-60A00DB72522} C:\Users\user\AppData\Local\BIT2C6A.tmp C:\Users\user\AppData\Local\genienext C:\Users\user\AppData\Local\Lollipop C:\Users\user\AppData\Local\Torch C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop C:\Users\user\AppData\Roaming\Mozilla C:\Users\user\AppData\Roaming\newnext.me C:\Users\user\Downloads\SpyHunter-Installer.exe C:\Windows\455F074C814E4520B69B5584BD90400C.TMP C:\Windows\system32\LogFiles C:\Windows\system32\Drivers\wStLibG.sys Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reboot: ***************** C:\Program Files\Mega Browse\bin\utilMegaBrowse.exe => No running process found C:\Program Files\Mega Browse\updateMegaBrowse.exe => No running process found C:\Program Files\Mega Browse\bin\FilterApp_C.exe => No running process found bonanzadealslive => Service not found. bonanzadealslivem => Service not found. ca82e1a5 => Service not found. PirritDesktop => Service not found. PirritUpdater => Unable to stop service PirritUpdater => Service not found. Update Mega Browse => Service not found. Util Mega Browse => Service not found. WinRST => Unable to stop service WinRST => Service not found. Wpm => Service not found. wStLibG => Service not found. cpuz134 => Service not found. esgiguard => Service not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\fst_pl_96 => Value not found. HKU\S-1-5-21-101661676-3665781825-895367130-1000\Software\Microsoft\Windows\CurrentVersion\Run\\LiveSupport => Value not found. HKU\S-1-5-21-101661676-3665781825-895367130-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value not found. HKU\S-1-5-21-101661676-3665781825-895367130-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => Value not found. "c:\\progra~1\\optimi~1\\optpro~2.dll" => Value Data not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Public\Desktop\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => File not found. C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => File not found. C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => File not found. C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => File not found. C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => File not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} => Value not found. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} => Value not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e6cd411-ce62-4584-97ff-6afbcf6900af} => Key not found. HKCR\CLSID\{4e6cd411-ce62-4584-97ff-6afbcf6900af} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d} => Key deleted successfully. HKCR\CLSID\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} => Value not found. HKCR\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} => Value deleted successfully. HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} => Value not found. HKCR\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} => Value deleted successfully. HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} => Key not found. C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo => Key deleted successfully. "C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0145FED3-CDBD-431B-9B04-0933E0224BA0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0145FED3-CDBD-431B-9B04-0933E0224BA0} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1613FEAB-F8C5-430C-A51A-7E400BBCC778} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1613FEAB-F8C5-430C-A51A-7E400BBCC778} => Key deleted successfully. C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SomotoUpdateCheckerAutoStart => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{99556109-4501-44FA-A7E9-0B0F5B6D693C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99556109-4501-44FA-A7E9-0B0F5B6D693C} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ED856101-DC94-4C40-AD74-D5A04491AC7A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED856101-DC94-4C40-AD74-D5A04491AC7A} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore => Key deleted successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => Moved successfully. C:\Program Files\BBlockUTubeAd => Moved successfully. C:\Program Files\BonanzaDealsLive => Moved successfully. C:\Program Files\Enigma Software Group => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. C:\Program Files\predm => Moved successfully. C:\Program Files\WinRST => Moved successfully. C:\ProgramData\eec33f7f144d96af => Moved successfully. C:\ProgramData\BBlockUTubeAd => Moved successfully. C:\ProgramData\BonanzaDealsLive => Moved successfully. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2" => File/Directory not found. C:\Users\user\AppData\Local\{6303A451-8642-457B-A55E-60A00DB72522} => Moved successfully. C:\Users\user\AppData\Local\BIT2C6A.tmp => Moved successfully. C:\Users\user\AppData\Local\genienext => Moved successfully. C:\Users\user\AppData\Local\Lollipop => Moved successfully. C:\Users\user\AppData\Local\Torch => Moved successfully. C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals => Moved successfully. C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker => Moved successfully. C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop => Moved successfully. C:\Users\user\AppData\Roaming\Mozilla => Moved successfully. C:\Users\user\AppData\Roaming\newnext.me => Moved successfully. C:\Users\user\Downloads\SpyHunter-Installer.exe => Moved successfully. C:\Windows\455F074C814E4520B69B5584BD90400C.TMP => Moved successfully. "C:\Windows\System32\LogFiles" directory move: C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\Terminal-Services-Core.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\Terminal-Services-IP-Virtualization.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\Terminal-Services-RPC-Client.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\Terminal-Services-Unified-APIs.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession7.etl => Moved successfully. C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl => Moved successfully. C:\Windows\System32\LogFiles\Scm\05ee699f-ab25-42d8-8781-558c5d1d2fad => Moved successfully. C:\Windows\System32\LogFiles\Scm\06e0ccaf-938c-4e4b-a414-8db5c2a081d2 => Moved successfully. C:\Windows\System32\LogFiles\Scm\071d41b6-8806-4eb0-b661-6cb67be6e86e => Moved successfully. C:\Windows\System32\LogFiles\Scm\099cfbe1-b554-45b8-8a98-3809c5966e04 => Moved successfully. C:\Windows\System32\LogFiles\Scm\0b515222-cc3f-47ee-875b-c5552d4bfec6 => Moved successfully. C:\Windows\System32\LogFiles\Scm\0d9b5d92-3a22-486d-a887-3aa21597cf27 => Moved successfully. C:\Windows\System32\LogFiles\Scm\0e12083c-0335-49db-9542-ba1ec6d83ecc => Moved successfully. C:\Windows\System32\LogFiles\Scm\18e6d428-d26c-4169-bedf-3b5bddc952f6 => Moved successfully. C:\Windows\System32\LogFiles\Scm\1a1bd201-4c90-45f3-b3a6-45aae4722b89 => Moved successfully. C:\Windows\System32\LogFiles\Scm\1bd29dd8-770c-49d6-b26a-572905e9fbe9 => Moved successfully. C:\Windows\System32\LogFiles\Scm\1de0d43a-f9c4-45ed-abe2-f304614fc5d0 => Moved successfully. C:\Windows\System32\LogFiles\Scm\1ec9510d-a439-4950-9399-b6399edf9ea7 => Moved successfully. C:\Windows\System32\LogFiles\Scm\2285022f-5224-40da-a853-7935181b090d => Moved successfully. C:\Windows\System32\LogFiles\Scm\2375f586-1009-41fb-b54e-30d8af2b781d => Moved successfully. C:\Windows\System32\LogFiles\Scm\24fa84a0-e087-48ec-bc51-2b9c4c815d78 => Moved successfully. C:\Windows\System32\LogFiles\Scm\2b0148cc-b201-460a-8560-8779024eb519 => Moved successfully. C:\Windows\System32\LogFiles\Scm\2bd05ba6-988d-4bd3-a9cd-9a39f80af524 => Moved successfully. C:\Windows\System32\LogFiles\Scm\2c59ecaf-3a27-4640-9f4b-519b05bdd70f => Moved successfully. C:\Windows\System32\LogFiles\Scm\319e7c09-e322-4c38-a837-1b58999c4e72 => Moved successfully. C:\Windows\System32\LogFiles\Scm\34471c3a-e09b-44e6-b29c-7d522f184c96 => Moved successfully. C:\Windows\System32\LogFiles\Scm\367f930a-a3db-4112-b1f1-50e92a171c88 => Moved successfully. C:\Windows\System32\LogFiles\Scm\4040e761-8758-4007-b2fe-142b24bf4b16 => Moved successfully. C:\Windows\System32\LogFiles\Scm\4284b6cf-a42c-464e-88db-2f87ca6b513c => Moved successfully. C:\Windows\System32\LogFiles\Scm\48aca596-6ff3-4263-9156-4343469e9bd5 => Moved successfully. C:\Windows\System32\LogFiles\Scm\495d2714-67e7-4086-b5bc-9c011e8c49c5 => Moved successfully. C:\Windows\System32\LogFiles\Scm\503ddd6c-73d6-4ffd-9ae7-6c6555337df4 => Moved successfully. C:\Windows\System32\LogFiles\Scm\50fb5a03-0e1e-48de-b8a1-bee9d7d2cd0f => Moved successfully. C:\Windows\System32\LogFiles\Scm\5b184694-64c3-4633-94c5-945b3fa561d6 => Moved successfully. C:\Windows\System32\LogFiles\Scm\5c2c622f-70e9-4194-a7da-033e827365ad => Moved successfully. C:\Windows\System32\LogFiles\Scm\5fa94bd9-07e9-4800-b49b-4b8c647075cb => Moved successfully. C:\Windows\System32\LogFiles\Scm\60158c7a-6808-42cd-95ee-afd9a57925db => Moved successfully. C:\Windows\System32\LogFiles\Scm\6375cc1c-d975-48d2-9cd5-63db19b10d4a => Moved successfully. C:\Windows\System32\LogFiles\Scm\6aef0c98-2cb4-4b67-8c70-4c977c7355cc => Moved successfully. C:\Windows\System32\LogFiles\Scm\6b7ac694-8d6d-481b-9dd8-2a3a741ada6d => Moved successfully. C:\Windows\System32\LogFiles\Scm\731e9c62-95b5-4c8c-ab64-4cc591c9ff5b => Moved successfully. C:\Windows\System32\LogFiles\Scm\73259f86-29d6-42ff-b1e7-634f6e40d4f8 => Moved successfully. C:\Windows\System32\LogFiles\Scm\7c88bacc-c212-4a01-a2da-a794319998e0 => Moved successfully. C:\Windows\System32\LogFiles\Scm\7d3c7871-a917-4ef0-82e8-5f0a96423051 => Moved successfully. C:\Windows\System32\LogFiles\Scm\81976f42-eaaa-431b-9aac-aa39564253a6 => Moved successfully. C:\Windows\System32\LogFiles\Scm\84e61ef5-d595-4f18-92b9-746573dba027 => Moved successfully. C:\Windows\System32\LogFiles\Scm\8905ecd8-016f-4dc2-90e6-a5f1fa6a841a => Moved successfully. C:\Windows\System32\LogFiles\Scm\9334c323-f100-4656-9ba0-e4aa69c0f9c2 => Moved successfully. C:\Windows\System32\LogFiles\Scm\9373eb19-340d-4a6d-98ee-f6b4257c099b => Moved successfully. C:\Windows\System32\LogFiles\Scm\938e275a-17ed-442c-aadb-df43cfc1378c => Moved successfully. C:\Windows\System32\LogFiles\Scm\9b75c702-ea13-406a-badb-6c588ee4375b => Moved successfully. C:\Windows\System32\LogFiles\Scm\9efacbe6-a797-4905-a0c6-014cd3000dbb => Moved successfully. C:\Windows\System32\LogFiles\Scm\9f54b95f-5096-4803-ae61-e9b3ac5b616d => Moved successfully. C:\Windows\System32\LogFiles\Scm\a1cfa52f-06f2-418d-addb-cd6456d66f43 => Moved successfully. C:\Windows\System32\LogFiles\Scm\a2cfb6f3-b3ae-4971-8e29-c415be22d2e5 => Moved successfully. C:\Windows\System32\LogFiles\Scm\a316e645-1c56-45a6-bd6a-7dca79778090 => Moved successfully. C:\Windows\System32\LogFiles\Scm\a36630b7-fed6-4543-8195-69d2c53c01ac => Moved successfully. C:\Windows\System32\LogFiles\Scm\a6394592-54ce-4e93-8d64-1a068f462632 => Moved successfully. C:\Windows\System32\LogFiles\Scm\aa6b3abc-c8dc-42d1-9b8d-df736a3d54c2 => Moved successfully. C:\Windows\System32\LogFiles\Scm\ab771a9f-fb0f-4fa1-8b5f-48186615901e => Moved successfully. C:\Windows\System32\LogFiles\Scm\afcea5e5-975d-4f81-9025-e99bdf64925f => Moved successfully. C:\Windows\System32\LogFiles\Scm\b40f8115-b364-4483-a055-ed5de643f0ae => Moved successfully. C:\Windows\System32\LogFiles\Scm\b9bee219-c29e-4310-819c-147a5a0e045e => Moved successfully. C:\Windows\System32\LogFiles\Scm\ba472c1f-f1c6-409c-91ed-0198e8c25e69 => Moved successfully. C:\Windows\System32\LogFiles\Scm\bba67ad0-4ba0-4b44-827b-ff419b70c057 => Moved successfully. C:\Windows\System32\LogFiles\Scm\c90440a0-6d8f-423f-8f42-83eef05ce708 => Moved successfully. C:\Windows\System32\LogFiles\Scm\cc55d3e5-2637-4e70-ac8b-5a5271e17eda => Moved successfully. C:\Windows\System32\LogFiles\Scm\d21f6024-191f-4454-bbbc-09a650da2549 => Moved successfully. C:\Windows\System32\LogFiles\Scm\d622195c-d680-4fea-9c56-59660c7c9e94 => Moved successfully. C:\Windows\System32\LogFiles\Scm\d8bb5b7f-d0ca-4f67-a3d7-73e1d05f63da => Moved successfully. C:\Windows\System32\LogFiles\Scm\de8699d2-8a05-42f7-8a85-5162af47d26a => Moved successfully. C:\Windows\System32\LogFiles\Scm\de8bae53-2809-4f75-85ef-427d364b9b2c => Moved successfully. C:\Windows\System32\LogFiles\Scm\e26c95e5-2e9f-4bd7-ab9f-34575cc4793d => Moved successfully. C:\Windows\System32\LogFiles\Scm\e3dbd6a0-34f5-41bf-923a-1d9027cfb7ef => Moved successfully. C:\Windows\System32\LogFiles\Scm\e6c093d2-69bd-4796-9629-615eb5f8eabb => Moved successfully. C:\Windows\System32\LogFiles\Scm\e6f3a527-8b0b-43fa-94eb-584032761924 => Moved successfully. C:\Windows\System32\LogFiles\Scm\e79b2998-8f63-451a-a56d-26edc0a5098a => Moved successfully. C:\Windows\System32\LogFiles\Scm\e8164c0d-216c-4b6b-9eb8-31bf958b8014 => Moved successfully. C:\Windows\System32\LogFiles\Scm\ea8c3d04-a44d-4ae3-9de4-e60cda3836c1 => Moved successfully. C:\Windows\System32\LogFiles\Scm\edf4c104-2658-49a8-a5dc-74fa84e5ba8f => Moved successfully. C:\Windows\System32\LogFiles\Scm\f1369a11-e983-4458-b390-712efa1cba44 => Moved successfully. C:\Windows\System32\LogFiles\Scm\f2b57a14-f376-4364-8891-b56efd0621f5 => Moved successfully. C:\Windows\System32\LogFiles\Scm\f93c7104-998a-4a38-b935-775a3138b3c3 => Moved successfully. C:\Windows\System32\LogFiles\Scm\ff50383b-d17c-4fe3-b123-d90beb85856f => Moved successfully. C:\Windows\System32\LogFiles\Scm\ffb8486a-9861-4b82-be38-c7f8fb1b6605 => Moved successfully. C:\Windows\System32\LogFiles\Scm\SCM.EVM => Moved successfully. C:\Windows\System32\LogFiles\Scm\SCM.EVM.1 => Moved successfully. C:\Windows\System32\LogFiles\Scm\SCM.EVM.2 => Moved successfully. C:\Windows\System32\LogFiles\Scm\SCM.EVM.3 => Moved successfully. C:\Windows\System32\LogFiles\Scm\SCM.EVM.4 => Moved successfully. C:\Windows\System32\LogFiles\PunkBuster\pbsvc.log => Moved successfully. C:\Windows\System32\LogFiles\PunkBuster\PnkBstrA.log => Moved successfully. C:\Windows\System32\LogFiles\PunkBuster\PnkBstrB.log => Moved successfully. C:\Windows\System32\LogFiles\HTTPERR\httperr1.log => Moved successfully. C:\Windows\System32\LogFiles\AIT\AitEventLog.etl.001 => Moved successfully. C:\Windows\System32\LogFiles\AIT\AitEventLog.etl.002 => Moved successfully. C:\Windows\System32\LogFiles\AIT\AitEventLog.etl.003 => Moved successfully. C:\Windows\System32\LogFiles\AIT\AitEventLog.etl.004 => Moved successfully. Could not move "C:\Windows\System32\LogFiles" directory. => Scheduled to move on reboot. C:\Windows\system32\Drivers\wStLibG.sys => Moved successfully. ========= reg delete HKCU\Software\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\mozilla.org /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-04-08 16:03:06)<= "C:\Windows\System32\LogFiles" => Directory could not move. ==== End of Fixlog ====