Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-01-2015 Ran by Dorota at 2015-01-08 10:57:34 Run:3 Running from C:\Users\Dorota\Desktop Loaded Profile: Dorota (Available profiles: Dorota) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R1 {1fceab11-b7eb-4010-811f-3f56268f9366}t; C:\Windows\System32\drivers\{1fceab11-b7eb-4010-811f-3f56268f9366}t.sys [55816 2014-12-30] (StdLib) R1 {2b4f8230-394e-4951-9495-bafd44d837da}t; C:\Windows\System32\drivers\{2b4f8230-394e-4951-9495-bafd44d837da}t.sys [55816 2014-12-27] (StdLib) R1 {3211ae5b-d056-4176-9f6e-b51496f003f1}t; C:\Windows\System32\drivers\{3211ae5b-d056-4176-9f6e-b51496f003f1}t.sys [55816 2014-12-14] (StdLib) R1 {34cccceb-a541-48ac-a26b-92818f06439d}t; C:\Windows\System32\drivers\{34cccceb-a541-48ac-a26b-92818f06439d}t.sys [55816 2015-01-02] (StdLib) R1 {47a3b56f-80e6-4ea5-8093-7656ffd5c11a}t; C:\Windows\System32\drivers\{47a3b56f-80e6-4ea5-8093-7656ffd5c11a}t.sys [55816 2014-12-15] (StdLib) R1 {8aefbcaf-640f-4dca-9a92-ed05ee387238}t; C:\Windows\System32\drivers\{8aefbcaf-640f-4dca-9a92-ed05ee387238}t.sys [55816 2014-12-21] (StdLib) R1 {97daceee-c4d3-4ae1-975b-b77d85ce2d13}t; C:\Windows\System32\drivers\{97daceee-c4d3-4ae1-975b-b77d85ce2d13}t.sys [55816 2014-12-23] (StdLib) R1 {993baf86-643c-42e9-95e5-094f337533f0}t; C:\Windows\System32\drivers\{993baf86-643c-42e9-95e5-094f337533f0}t.sys [55816 2014-12-17] (StdLib) R1 {9eaa49e2-6918-49c4-9a04-be590dd80dc6}t; C:\Windows\System32\drivers\{9eaa49e2-6918-49c4-9a04-be590dd80dc6}t.sys [55816 2015-01-05] (StdLib) R2 Update DigiHelp; C:\Program Files\DigiHelp\updateDigiHelp.exe [529128 2015-01-07] () R2 Util DigiHelp; C:\Program Files\DigiHelp\bin\utilDigiHelp.exe [529128 2015-01-07] () R2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [470704 2014-12-17] (Taiwan Shui Mu Chih Ching Technology Limited.) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] Task: {1FDE0B1D-38E5-4E14-BCF0-132E3A8EA860} - System32\Tasks\pricemetertask => C:\Users\Dorota\AppData\Local\PriceMeter\pricemeter.exe <==== ATTENTION Task: {A8BB7BB6-3E16-4072-92A5-93BE64064E8A} - System32\Tasks\pricemeterdownloader => C:\Users\Dorota\AppData\Local\PriceMeter\pricemeterd.exe [2014-05-06] (PriceMeter) <==== ATTENTION Task: {C6928140-D30F-470B-8253-D540717E41AB} - System32\Tasks\pricemeterwatcher => C:\Users\Dorota\AppData\Local\PriceMeter\pricemeterw.exe [2014-05-04] (PriceMeter) <==== ATTENTION HKLM\...\Run: [fst_pl_127] => [X] HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\...\Run: [PriceMeterW] => C:\Users\Dorota\AppData\Local\PriceMeter\pricemeterw.exe [287232 2014-05-04] (PriceMeter) HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\...\Run: [AdobeBridge] => [X] AppInit_DLLs: C:\PROGRA~1\SupTab\SEARCH~1.DLL => C:\Program Files\SupTab\SearchProtect32.dll [91248 2014-05-08] (Skytech Co., Ltd.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1419844097&from=wpm12262&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=1402162438&from=tt4u&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1419844097&from=wpm12262&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=1402162438&from=tt4u&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84&q={searchTerms} HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1419844097&from=wpm12262&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84&q={searchTerms} HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1419844097&from=wpm12262&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84 HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1419844097&from=wpm12262&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84 HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1419844097&from=wpm12262&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1402162438&from=tt4u&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1402162438&from=tt4u&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1402162438&from=tt4u&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84&q={searchTerms} SearchScopes: HKU\S-1-5-21-1113750723-2783305751-3862205039-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419844097&from=wpm12262&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84&q={searchTerms} SearchScopes: HKU\S-1-5-21-1113750723-2783305751-3862205039-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419844097&from=wpm12262&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84&q={searchTerms} SearchScopes: HKU\S-1-5-21-1113750723-2783305751-3862205039-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={DE289BFE-EFC6-4173-8DB3-5012550C5C4C}&mid=b4acfa79299247d2bc4ed16b53160544-6d6a121b0d2c7c6e45c51db57f8bd774ff757963&lang=en&ds=px011&coid=avgtbdispx&cmpid=&pr=sa&d=2014-06-19 10:56:34&v=18.1.9.799&pid=safeguard&sg=&sap=dsp&q={searchTerms} BHO: DigiHelp 1.0.0.6 -> {5bee7be9-df29-4c14-a18e-2bdd06205e29} -> C:\Program Files\DigiHelp\DigiHelpBHO.dll (DigiHelp) CHR HKLM\...\Chrome\Extension: [noajmlkipclmeolfcnflkjhijkigpfjh] - C:\Users\Dorota\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx [2014-12-29] CHR HKLM\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Dorota\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-06-07] CHR StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe http://www.delta-homes.com/?type=sc&ts=1419844097&from=wpm12262&uid=ST3500320AS_9QM2XW84XXXX9QM2XW84 C:\Program Files\DigiHelp C:\Program Files\SupTab C:\ProgramData\WindowsProtectManger C:\Users\Dorota\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Dorota\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\Dorota\AppData\Roaming\Opera Software\Opera Stable\Local Storage\*localstorage* C:\Users\Dorota\AppData\Roaming\eCyber C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Windows\System32\drivers\{1fceab11-b7eb-4010-811f-3f56268f9366}t.sys C:\Windows\System32\drivers\{2b4f8230-394e-4951-9495-bafd44d837da}t.sys C:\Windows\System32\drivers\{3211ae5b-d056-4176-9f6e-b51496f003f1}t.sys C:\Windows\System32\drivers\{34cccceb-a541-48ac-a26b-92818f06439d}t.sys C:\Windows\System32\drivers\{47a3b56f-80e6-4ea5-8093-7656ffd5c11a}t.sys C:\Windows\System32\drivers\{8aefbcaf-640f-4dca-9a92-ed05ee387238}t.sys C:\Windows\System32\drivers\{97daceee-c4d3-4ae1-975b-b77d85ce2d13}t.sys C:\Windows\System32\drivers\{993baf86-643c-42e9-95e5-094f337533f0}t.sys C:\Windows\System32\drivers\{9eaa49e2-6918-49c4-9a04-be590dd80dc6}t.sys Reg: reg add "HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command" /ve /t REG_SZ /d "\"C:\Program Files\Opera\Launcher.exe"" /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f ***************** Processes closed successfully. Restore point was successfully created. {1fceab11-b7eb-4010-811f-3f56268f9366}t => Unable to stop service {1fceab11-b7eb-4010-811f-3f56268f9366}t => Service deleted successfully. {2b4f8230-394e-4951-9495-bafd44d837da}t => Unable to stop service {2b4f8230-394e-4951-9495-bafd44d837da}t => Service deleted successfully. {3211ae5b-d056-4176-9f6e-b51496f003f1}t => Unable to stop service {3211ae5b-d056-4176-9f6e-b51496f003f1}t => Service deleted successfully. {34cccceb-a541-48ac-a26b-92818f06439d}t => Unable to stop service {34cccceb-a541-48ac-a26b-92818f06439d}t => Service deleted successfully. {47a3b56f-80e6-4ea5-8093-7656ffd5c11a}t => Unable to stop service {47a3b56f-80e6-4ea5-8093-7656ffd5c11a}t => Service deleted successfully. {8aefbcaf-640f-4dca-9a92-ed05ee387238}t => Unable to stop service {8aefbcaf-640f-4dca-9a92-ed05ee387238}t => Service deleted successfully. {97daceee-c4d3-4ae1-975b-b77d85ce2d13}t => Unable to stop service {97daceee-c4d3-4ae1-975b-b77d85ce2d13}t => Service deleted successfully. {993baf86-643c-42e9-95e5-094f337533f0}t => Unable to stop service {993baf86-643c-42e9-95e5-094f337533f0}t => Service deleted successfully. {9eaa49e2-6918-49c4-9a04-be590dd80dc6}t => Unable to stop service {9eaa49e2-6918-49c4-9a04-be590dd80dc6}t => Service deleted successfully. Update DigiHelp => Unable to stop service Update DigiHelp => Service deleted successfully. Util DigiHelp => Unable to stop service Util DigiHelp => Service deleted successfully. winzipersvc => Service deleted successfully. esgiguard => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1FDE0B1D-38E5-4E14-BCF0-132E3A8EA860} => Key not found. C:\Windows\System32\Tasks\pricemetertask => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pricemetertask" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A8BB7BB6-3E16-4072-92A5-93BE64064E8A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8BB7BB6-3E16-4072-92A5-93BE64064E8A}" => Key deleted successfully. C:\Windows\System32\Tasks\pricemeterdownloader => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pricemeterdownloader" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6928140-D30F-470B-8253-D540717E41AB} => Key not found. C:\Windows\System32\Tasks\pricemeterwatcher => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pricemeterwatcher" => Key deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\fst_pl_127 => value deleted successfully. HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Windows\CurrentVersion\Run\\PriceMeterW => value deleted successfully. HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value deleted successfully. "C:\PROGRA~1\SupTab\SEARCH~1.DLL" => Value Data removed successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-1113750723-2783305751-3862205039-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5bee7be9-df29-4c14-a18e-2bdd06205e29}" => Key deleted successfully. "HKCR\CLSID\{5bee7be9-df29-4c14-a18e-2bdd06205e29}" => Key deleted successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh" => Key deleted successfully. C:\Users\Dorota\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx => Moved successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma" => Key deleted successfully. C:\Users\Dorota\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx => Moved successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. "C:\Program Files\DigiHelp" directory move: C:\Program Files\DigiHelp\DigiHelp.ico => Moved successfully. C:\Program Files\DigiHelp\DigiHelpBHO.dll => Moved successfully. C:\Program Files\DigiHelp\memgfpjkclkffgjbbigbgilbjgjogghh.crx => Moved successfully. C:\Program Files\DigiHelp\updateDigiHelp.exe => Moved successfully. C:\Program Files\DigiHelp\updateDigiHelp.InstallState => Moved successfully. C:\Program Files\DigiHelp\bin\1fceab11b7eb4010811f.dll => Moved successfully. C:\Program Files\DigiHelp\bin\1fceab11b7eb4010811f64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\2b4f8230394e49519495.dll => Moved successfully. C:\Program Files\DigiHelp\bin\2b4f8230394e4951949564.dll => Moved successfully. C:\Program Files\DigiHelp\bin\3211ae5bd05641769f6e.dll => Moved successfully. C:\Program Files\DigiHelp\bin\3211ae5bd05641769f6e64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\34cccceba54148aca26b.dll => Moved successfully. C:\Program Files\DigiHelp\bin\34cccceba54148aca26b64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\47a3b56f80e64ea58093.dll => Moved successfully. C:\Program Files\DigiHelp\bin\47a3b56f80e64ea5809364.dll => Moved successfully. C:\Program Files\DigiHelp\bin\7za.exe => Moved successfully. C:\Program Files\DigiHelp\bin\8aefbcaf640f4dca9a92.dll => Moved successfully. C:\Program Files\DigiHelp\bin\8aefbcaf640f4dca9a9264.dll => Moved successfully. C:\Program Files\DigiHelp\bin\97daceeec4d34ae1975b.dll => Moved successfully. C:\Program Files\DigiHelp\bin\97daceeec4d34ae1975b64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\993baf86643c42e995e5.dll => Moved successfully. C:\Program Files\DigiHelp\bin\993baf86643c42e995e564.dll => Moved successfully. C:\Program Files\DigiHelp\bin\9eaa49e2691849c49a04.dll => Moved successfully. C:\Program Files\DigiHelp\bin\9eaa49e2691849c49a0464.dll => Moved successfully. C:\Program Files\DigiHelp\bin\BrowserAdapter.7z => Moved successfully. C:\Program Files\DigiHelp\bin\DigiHelp.BrowserAdapter.exe => Moved successfully. C:\Program Files\DigiHelp\bin\DigiHelp.BrowserAdapter64.exe => Moved successfully. C:\Program Files\DigiHelp\bin\DigiHelp.PurBrowse.exe => Moved successfully. C:\Program Files\DigiHelp\bin\DigiHelp.PurBrowse.zip => Moved successfully. C:\Program Files\DigiHelp\bin\sqlite3.dll => Moved successfully. C:\Program Files\DigiHelp\bin\tmp2A88.tmp => Moved successfully. C:\Program Files\DigiHelp\bin\tmpDC40.tmp => Moved successfully. C:\Program Files\DigiHelp\bin\tmpFEB8.tmp => Moved successfully. C:\Program Files\DigiHelp\bin\utilDigiHelp.exe => Moved successfully. C:\Program Files\DigiHelp\bin\utilDigiHelp.InstallState => Moved successfully. C:\Program Files\DigiHelp\bin\{1fceab11-b7eb-4010-811f-3f56268f9366}.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{1fceab11-b7eb-4010-811f-3f56268f9366}64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{2b4f8230-394e-4951-9495-bafd44d837da}.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{2b4f8230-394e-4951-9495-bafd44d837da}64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{3211ae5b-d056-4176-9f6e-b51496f003f1}.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{3211ae5b-d056-4176-9f6e-b51496f003f1}64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{34cccceb-a541-48ac-a26b-92818f06439d}.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{34cccceb-a541-48ac-a26b-92818f06439d}64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{47a3b56f-80e6-4ea5-8093-7656ffd5c11a}.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{47a3b56f-80e6-4ea5-8093-7656ffd5c11a}64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{8aefbcaf-640f-4dca-9a92-ed05ee387238}.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{8aefbcaf-640f-4dca-9a92-ed05ee387238}64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{97daceee-c4d3-4ae1-975b-b77d85ce2d13}.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{97daceee-c4d3-4ae1-975b-b77d85ce2d13}64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{993baf86-643c-42e9-95e5-094f337533f0}.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{993baf86-643c-42e9-95e5-094f337533f0}64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{9eaa49e2-6918-49c4-9a04-be590dd80dc6}.dll => Moved successfully. C:\Program Files\DigiHelp\bin\{9eaa49e2-6918-49c4-9a04-be590dd80dc6}64.dll => Moved successfully. C:\Program Files\DigiHelp\bin\TEMP\mfs80F3.tmp => Moved successfully. C:\Program Files\DigiHelp\bin\TEMP\mfsA2EC.tmp => Moved successfully. C:\Program Files\DigiHelp\bin\TEMP\mfsC5C8.tmp => Moved successfully. C:\Program Files\DigiHelp\bin\plugins\DigiHelp.Bromon.dll => Moved successfully. C:\Program Files\DigiHelp\bin\plugins\DigiHelp.BroStats.dll => Moved successfully. C:\Program Files\DigiHelp\bin\plugins\DigiHelp.BrowserAdapter.dll => Moved successfully. C:\Program Files\DigiHelp\bin\plugins\DigiHelp.CompatibilityChecker.dll => Moved successfully. C:\Program Files\DigiHelp\bin\plugins\DigiHelp.ExpExt.dll => Moved successfully. C:\Program Files\DigiHelp\bin\plugins\DigiHelp.FFUpdate.dll => Moved successfully. C:\Program Files\DigiHelp\bin\plugins\DigiHelp.GCUpdate.dll => Moved successfully. C:\Program Files\DigiHelp\bin\plugins\DigiHelp.IEUpdate.dll => Moved successfully. C:\Program Files\DigiHelp\bin\plugins\DigiHelp.PurBrowse.dll => Moved successfully. Could not move "C:\Program Files\DigiHelp" directory. => Scheduled to move on reboot. C:\Program Files\SupTab => Moved successfully. C:\ProgramData\WindowsProtectManger => Moved successfully. C:\Users\Dorota\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Dorota\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\Dorota\AppData\Roaming\Opera Software\Opera Stable\Local Storage\*localstorage* => Moved successfully. C:\Users\Dorota\AppData\Roaming\eCyber => Moved successfully. C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\Windows\System32\drivers\{1fceab11-b7eb-4010-811f-3f56268f9366}t.sys => Moved successfully. C:\Windows\System32\drivers\{2b4f8230-394e-4951-9495-bafd44d837da}t.sys => Moved successfully. C:\Windows\System32\drivers\{3211ae5b-d056-4176-9f6e-b51496f003f1}t.sys => Moved successfully. C:\Windows\System32\drivers\{34cccceb-a541-48ac-a26b-92818f06439d}t.sys => Moved successfully. C:\Windows\System32\drivers\{47a3b56f-80e6-4ea5-8093-7656ffd5c11a}t.sys => Moved successfully. C:\Windows\System32\drivers\{8aefbcaf-640f-4dca-9a92-ed05ee387238}t.sys => Moved successfully. C:\Windows\System32\drivers\{97daceee-c4d3-4ae1-975b-b77d85ce2d13}t.sys => Moved successfully. C:\Windows\System32\drivers\{993baf86-643c-42e9-95e5-094f337533f0}t.sys => Moved successfully. C:\Windows\System32\drivers\{9eaa49e2-6918-49c4-9a04-be590dd80dc6}t.sys => Moved successfully. ========= reg add "HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command" /ve /t REG_SZ /d "\"C:\Program Files\Opera\Launcher.exe"" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-01-08 11:05:09)<= C:\Program Files\DigiHelp => Is moved successfully. ==== End of Fixlog 11:05:09 ====