Fix result of Farbar Recovery Scan Tool (x86) Version:29-10-2015 Ran by Krzysztof (2015-10-30 09:46:01) Run:1 Running from C:\Documents and Settings\Krzysztof\My Documents\Pobrane Loaded Profiles: Krzysztof (Available Profiles: Krzysztof & Gość & Administrator) Boot Mode: Safe Mode (minimal) ============================================== fixlist content: ***************** CloseProcesses: R2 aroductpeo; C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe [46592 2015-10-29] () [File not signed] R2 Concom; C:\Program Files\Concom\Concom.exe [379904 2015-10-25] () [File not signed] <==== ATTENTION S2 globalUpdate; C:\Program Files\globalUpdate\Update\globalupdate.exe [68608 2015-10-29] (globalUpdate) [File not signed] <==== ATTENTION S3 globalUpdatem; C:\Program Files\globalUpdate\Update\globalupdate.exe [68608 2015-10-29] (globalUpdate) [File not signed] <==== ATTENTION R1 QMIEProtect; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMIEProtect.sys [49976 2015-08-18] () R2 QQPCRTP; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCRTP.exe [301728 2015-09-15] (Tencent) R2 QQSysMon; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQSysMon.sys [108472 2015-09-26] (电脑管家) R2 SSFK; C:\Program Files\SFK\SSFK.exe [458400 2015-09-26] (TODO: <公司名>) S3 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator.sys [114520 2000-12-31] (Tencent) S3 TAOFrame; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TAOFrame.exe [293856 2015-09-26] (Tencent) R1 TAOKernelDriver; C:\WINDOWS\System32\Drivers\TAOKernelXP.sys [139064 2015-09-26] (Tencent Technology(Shenzhen) Company Limited) R3 TFsFlt; C:\WINDOWS\System32\Drivers\TFsFlt.sys [150072 2015-09-26] (电脑管家) R1 TSCPM; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\tscpm.sys [43448 2015-09-26] (电脑管家) R1 TSDefenseBt; C:\WINDOWS\System32\DRIVERS\TSDefenseBt.sys [14008 2015-09-26] (Tencent) R0 TsFltMgr; C:\WINDOWS\System32\drivers\TsFltMgr.sys [124792 2015-09-26] (电脑管家) R1 TSKSP; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSKsp.sys [204920 2015-09-26] (电脑管家) S3 TSSK; C:\WINDOWS\System32\tssk.sys [67896 2015-09-26] (电脑管家) R1 TSSysKit; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSSysKit.sys [101560 2015-09-26] (电脑管家) R2 WdsManPro; C:\Documents and Settings\All Users\Application Data\2WdsManPro2\WdsManPro.exe [442504 2015-09-26] (DTools LIMITED) S1 ppfd_vt_1_10_0_24; system32\drivers\ppfd_vt_1_10_0_24.sys [X] S1 wwfd_vt_1_10_0_24; system32\drivers\wwfd_vt_1_10_0_24.sys [X] Task: C:\WINDOWS\Tasks\469fcbcc-315d-4dd5-9804-212abb2e3cb9-1-6.job => C:\Program Files\GoHD\469fcbcc-315d-4dd5-9804-212abb2e3cb9-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-1-6.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-10_user.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-10.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-3.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-3.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-5.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-6.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-7.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\6d0ac05c-4429-4e4d-bcea-abd79f29b20e-1-6.job => C:\Program Files\CinemaP-1.9cV26.09\6d0ac05c-4429-4e4d-bcea-abd79f29b20e-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-6.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-7.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-4.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-4.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-5.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-6.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-7.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-1-6.job => C:\Program Files\SavePass 1.1\a4573ab7-8417-4109-8219-08f1d1efe114-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-1-7.job => C:\Program Files\SavePass 1.1\a4573ab7-8417-4109-8219-08f1d1efe114-1-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-4.job => C:\Program Files\SavePass 1.1\a4573ab7-8417-4109-8219-08f1d1efe114-4.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-5.job => C:\Program Files\SavePass 1.1\a4573ab7-8417-4109-8219-08f1d1efe114-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Advanced System~Protector.job => C:\Program Files\ASP\AspManager.exe Task: C:\WINDOWS\Tasks\Cukoqje4zpacXzv1vzrLABj8CQG.job => C:\Documents and Settings\Krzysztof\Application Data\Cukoqje4zpacXzv1vzrLABj8CQG.exe Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\IaKVQlxEQ3T35j.job => C:\Documents and Settings\Krzysztof\Application Data\IaKVQlxEQ3T35j.exe Task: C:\WINDOWS\Tasks\PKFkn4RDDh2SIS8ZZ.job => C:\Documents and Settings\Krzysztof\Application Data\PKFkn4RDDh2SIS8ZZ.exe Task: C:\WINDOWS\Tasks\SimpleFiles Update Service.job => C:\Program Files\SimpleFilesUpdater\SimpleFilesUpdater.exehxxp:/simple-files.com Task: C:\WINDOWS\Tasks\temp_50278e6d-151b-4cf5-9e8d-31ed23fbc614-10_user.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-10.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Xmas.job => C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Xmas\xBin\Xmas.dll HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service" HKLM\...\Run: [] => [X] HKLM\...\Run: [ QQPCTray] => "C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCTray.exe" /regrun HKLM\...\Run: [gmsd_pl_005010096] => [X] HKLM\...\Run: [mbot_pl_014010096] => [X] HKLM\...\Run: [mbot_pl_014010102] => [X] HKLM\...\Run: [upmbot_pl_014010102.exe] => C:\Documents and Settings\Krzysztof\Local Settings\Application Data\mbot_pl_014010102\upmbot_pl_014010102.exe -runhelper HKLM\...\Run: [SunJavaUpdateSched] => "C:\Program Files\Java\jre7\bin\jusched.exe" HKLM\...\Winlogon: [Shell] explorer.exe, [x ] () HKU\S-1-5-21-1960408961-682003330-839522115-1004\...\Run: [BingSvc] => C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation) ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMGCShellExt.dll [2015-09-26] (Tencent) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File CustomCLSID: HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CustomCLSID: HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Documents and Settings\Krzysztof\Application Data\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=95751091_hao_pg HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1443293666&z=a872e2bb7050c3b9111ef6agaz0zdc8o0t3c0q0q2q&from=amt&uid=hitachixhts545025b9sa02_100719pbl200csh200zvx HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.hao123.com/?tn=95751091_hao_pg hxxp://www.gazeta.pl/0,0.html?p=156 HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1443293666&z=a872e2bb7050c3b9111ef6agaz0zdc8o0t3c0q0q2q&from=amt&uid=hitachixhts545025b9sa02_100719pbl200csh200zvx HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "hxxp://www.only-search.com/?babsrc=NT_kms&affID=132174" <======= ATTENTION SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-1960408961-682003330-839522115-1004 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-1960408961-682003330-839522115-1004 -> {36D00200-6447-4870-A80F-C551B17BDE8F} URL = hxxp://www.only-search.com/?babsrc=SP_kms&affID=132174&q={searchTerms}&r=965 SearchScopes: HKU\S-1-5-21-1960408961-682003330-839522115-1004 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - iexplore.exe FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-29] (globalUpdate) FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-29] (globalUpdate) GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION StartMenuInternet: chrome.exe - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.istartsurf.com/?type=sc&ts=1443295299&z=796cc5cf51a969ca0186f3egczdz4c1odt6w6gde8t&from=face&uid=HitachiXHTS545025B9SA02_100719PBL200CSH200ZVX Facebook Update Helper (Version: 1.2.205.0 - Google Inc.) Hidden AV: 电脑管家系统防护 (Enabled - Up to date) {9AAC524A-BF34-49b0-91D2-71838CBB8110} DeleteKey: HKCU\Software\Google\Chrome\Extensions DeleteKey: HKLM\SOFTWARE\Google\Chrome\Extensions DeleteKey: HKLM\SOFTWARE\Mozilla\Firefox\Extensions DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^IMVU.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^Logitech . Rejestracja produktu.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OptimumLink.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OptimumPCtoTV.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^ybcrlnsnniggidoderh.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EvtMgr6 DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GG DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Jing DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ORAHSSSessionManager DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TP-Link USB Printer Controller DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaP-1.9cV26.09 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV26.09 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoHD DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1 DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes CMD: for %i in ("C:\Program Files\globalUpdate\Update\1.3.25.0\*.dll") do regsvr32 /u /s %i CMD: for %i in ("C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\*.dll") do regsvr32 /u /s %i C:\Documents and Settings\All Users\Application Data\2WdsManPro2 C:\Documents and Settings\All Users\Application Data\TEMP C:\Documents and Settings\All Users\Start Menu\电脑管家.lnk C:\Documents and Settings\All Users\Start Menu\强力卸载电脑上的软件 .lnk C:\Documents and Settings\Gość\Favorites\Links\*.url C:\Documents and Settings\Gość\Start Menu\7Burn.lnk C:\Documents and Settings\Gość\Start Menu\Programs\FileZilla FTP Client C:\Documents and Settings\Krzysztof\sqlite3.dll C:\Documents and Settings\Krzysztof\Application Data\cTEckRNVP8 C:\Documents and Settings\Krzysztof\Application Data\Cukoqje4zpacXzv1vzrLABj8CQG C:\Documents and Settings\Krzysztof\Application Data\IaKVQlxEQ3T35j C:\Documents and Settings\Krzysztof\Application Data\NevoSoft Gameslog.txt C:\Documents and Settings\Krzysztof\Application Data\PKFkn4RDDh2SIS8ZZ C:\Documents and Settings\Krzysztof\Application Data\GG C:\Documents and Settings\Krzysztof\Desktop\Continue kED installation.lnk C:\Documents and Settings\Krzysztof\Favorites\Bing.url C:\Documents and Settings\Krzysztof\Favorites\Discover Bing.url C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN*.url C:\Documents and Settings\Krzysztof\Favorites\Microsoft Websites\Microsoft Showcase.url C:\Documents and Settings\Krzysztof\Favorites\Microsoft Websites\Microsoft.com.url C:\Documents and Settings\Krzysztof\Favorites\Links\go.microsoft.com-fwlink-LinkId=121315.url C:\Documents and Settings\Krzysztof\Favorites\Links\ieonline.microsoft.com-#ieslice.url C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites*.url C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe.config C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook C:\Documents and Settings\Krzysztof\Local Settings\Application Data\globalUpdate C:\Documents and Settings\Krzysztof\Local Settings\Application Data\mbot_pl_014010102 C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Microsoft\BingSvc C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Xmas C:\Documents and Settings\Krzysztof\Start Menu\Programs\腾讯软件 C:\Program Files\path5.ini C:\Program Files\5C8CAC0A-1443294427-5799-9460-C2325843CB2C C:\Program Files\ASP C:\Program Files\CinemaP-1.9cV26.09 C:\Program Files\CinemaPlus-3.2cV26.09 C:\Program Files\Concom C:\Program Files\globalUpdate C:\Program Files\GoHD C:\Program Files\Mozilla Firefox\browser\searchplugins C:\Program Files\Mozilla Firefox\plugins C:\Program Files\Object Browser C:\Program Files\RayDld C:\Program Files\SavePass 1.1 C:\Program Files\SFK C:\Program Files\SimpleFilesUpdater C:\Program Files\Tencent C:\Program Files\Common Files\Tencent C:\WINDOWS\DUMP*.tmp C:\WINDOWS\QMNetworkMgr.ini C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\WINDOWS\pss\McAfee Security Scan Plus.lnkCommon Startup C:\WINDOWS\pss\IMVU.lnkStartup C:\WINDOWS\pss\Logitech . Rejestracja produktu.lnkStartup C:\WINDOWS\pss\OpenOffice.org 3.2.lnkStartup C:\WINDOWS\pss\OptimumLink.lnkStartup C:\WINDOWS\pss\OptimumPCtoTV.lnkStartup C:\WINDOWS\pss\ybcrlnsnniggidoderh.lnkStartup C:\WINDOWS\System32\tssk.sys C:\WINDOWS\system32\Drivers\TAOAccelerator.sys C:\WINDOWS\System32\Drivers\TAOKernelXP.sys C:\WINDOWS\System32\Drivers\TFsFlt.sys C:\WINDOWS\System32\Drivers\TsFltMgr.sys C:\WINDOWS\System32\Drivers\TSDefenseBt.sys Folder: C:\extensions CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files\Common Files" CMD: dir /a "C:\Documents and Settings\All Users\Application Data" CMD: dir /a "C:\Documents and Settings\Krzysztof\Application Data" CMD: dir /a "C:\Documents and Settings\Krzysztof\Local Settings\Application Data" ***************** Processes closed successfully. aroductpeo => service removed successfully. Concom => service removed successfully. globalUpdate => service removed successfully. globalUpdatem => service removed successfully. QMIEProtect => service removed successfully. QQPCRTP => service removed successfully. QQSysMon => service removed successfully. SSFK => service removed successfully. TAOAccelerator => service removed successfully. TAOFrame => service removed successfully. TAOKernelDriver => service removed successfully. TFsFlt => service removed successfully. TSCPM => service not found. TSDefenseBt => service removed successfully. TsFltMgr => Unable to stop service. TsFltMgr => service removed successfully. TSKSP => service not found. TSSK => service removed successfully. TSSysKit => service not found. WdsManPro => service removed successfully. ppfd_vt_1_10_0_24 => service removed successfully. wwfd_vt_1_10_0_24 => service removed successfully. C:\WINDOWS\Tasks\469fcbcc-315d-4dd5-9804-212abb2e3cb9-1-6.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-1-6.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-10_user.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-3.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-5.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-6.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-7.job => moved successfully C:\WINDOWS\Tasks\6d0ac05c-4429-4e4d-bcea-abd79f29b20e-1-6.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-6.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-7.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-4.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-5.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-6.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-7.job => moved successfully C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-1-6.job => moved successfully C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-1-7.job => moved successfully C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-4.job => moved successfully C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-5.job => moved successfully C:\WINDOWS\Tasks\Advanced System~Protector.job => moved successfully C:\WINDOWS\Tasks\Cukoqje4zpacXzv1vzrLABj8CQG.job => moved successfully C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => moved successfully C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => moved successfully C:\WINDOWS\Tasks\IaKVQlxEQ3T35j.job => moved successfully C:\WINDOWS\Tasks\PKFkn4RDDh2SIS8ZZ.job => moved successfully C:\WINDOWS\Tasks\SimpleFiles Update Service.job => moved successfully C:\WINDOWS\Tasks\temp_50278e6d-151b-4cf5-9e8d-31ed23fbc614-10_user.job => moved successfully C:\WINDOWS\Tasks\Xmas.job => moved successfully "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP" => key removed successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP" => key removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ QQPCTray => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\gmsd_pl_005010096 => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mbot_pl_014010096 => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mbot_pl_014010102 => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\upmbot_pl_014010102.exe => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value not found. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value restored successfully HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Run\\BingSvc => value removed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\.QMDeskTopGCIcon" => key removed successfully. "HKCR\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6}" => key removed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. "HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}" => key removed successfully. "HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}" => key removed successfully. "HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}" => key removed successfully. "HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}" => key removed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => value removed successfully. HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully. HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\SearchAssistant => value removed successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ielnksrch" => key removed successfully. HKCR\CLSID\ielnksrch => key not found. HKU\S-1-5-21-1960408961-682003330-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully. "HKU\S-1-5-21-1960408961-682003330-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{36D00200-6447-4870-A80F-C551B17BDE8F}" => key removed successfully. HKCR\CLSID\{36D00200-6447-4870-A80F-C551B17BDE8F} => key not found. "HKU\S-1-5-21-1960408961-682003330-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}" => key removed successfully. HKCR\CLSID\{ielnksrch} => key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully "HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => key removed successfully. C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll => moved successfully "HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => key removed successfully. C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll => not found. C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully "HKLM\SOFTWARE\Policies\Google" => key removed successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => value restored successfully HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D40F6104-6988-47C0-93F2-A66D5DA120A2}\\SystemComponent => value removed successfully. AV: 电脑管家系统防护 (Enabled - Up to date) {9AAC524A-BF34-49b0-91D2-71838CBB8110} => removed successfully. HKCU\Software\Google\Chrome\Extensions => could not remove at first attempt (ErrorCode: C0000121), see next line. HKCU\Software\Google\Chrome\Extensions => key removed successfully. HKLM\SOFTWARE\Google\Chrome\Extensions => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Google\Chrome\Extensions => key removed successfully. HKLM\SOFTWARE\Mozilla\Firefox\Extensions => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^IMVU.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^Logitech . Rejestracja produktu.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OptimumLink.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OptimumPCtoTV.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^ybcrlnsnniggidoderh.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EvtMgr6 => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GG => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Jing => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ORAHSSSessionManager => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TP-Link USB Printer Controller => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC} => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaP-1.9cV26.09 => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV26.09 => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoHD => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1 => key removed successfully. HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List => key removed successfully. HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List => key removed successfully. HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main => could not remove at first attempt (ErrorCode: C0000121), see next line. HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main => key removed successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main => key not found. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main => key removed successfully. HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes => key removed successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes => key not found. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes => could not remove at first attempt (ErrorCode: C0000121), see next line. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes => key removed successfully. ========= for %i in ("C:\Program Files\globalUpdate\Update\1.3.25.0\*.dll") do regsvr32 /u /s %i ========= ========= End of CMD: ========= ========= for %i in ("C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\*.dll") do regsvr32 /u /s %i ========= ========= End of CMD: ========= C:\Documents and Settings\All Users\Application Data\2WdsManPro2 => moved successfully C:\Documents and Settings\All Users\Application Data\TEMP => moved successfully C:\Documents and Settings\All Users\Start Menu\电脑管家.lnk => moved successfully C:\Documents and Settings\All Users\Start Menu\强力卸载电脑上的软件 .lnk => moved successfully =========== "C:\Documents and Settings\Gość\Favorites\Links\*.url" ========== C:\Documents and Settings\Gość\Favorites\Links\Free Hotmail.url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\ieonline.microsoft.com-#ieslice.url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\Suggested Sites (2).url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\Suggested Sites (3).url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\Suggested Sites.url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\Web Slice Gallery.url => moved successfully ========= End -> "C:\Documents and Settings\Gość\Favorites\Links\*.url" ======== C:\Documents and Settings\Gość\Start Menu\7Burn.lnk => moved successfully C:\Documents and Settings\Gość\Start Menu\Programs\FileZilla FTP Client => moved successfully C:\Documents and Settings\Krzysztof\sqlite3.dll => moved successfully C:\Documents and Settings\Krzysztof\Application Data\cTEckRNVP8 => moved successfully C:\Documents and Settings\Krzysztof\Application Data\Cukoqje4zpacXzv1vzrLABj8CQG => moved successfully C:\Documents and Settings\Krzysztof\Application Data\IaKVQlxEQ3T35j => moved successfully C:\Documents and Settings\Krzysztof\Application Data\NevoSoft Gameslog.txt => moved successfully C:\Documents and Settings\Krzysztof\Application Data\PKFkn4RDDh2SIS8ZZ => moved successfully C:\Documents and Settings\Krzysztof\Application Data\GG => moved successfully "C:\Documents and Settings\Krzysztof\Desktop\Continue kED installation.lnk" => not found. C:\Documents and Settings\Krzysztof\Favorites\Bing.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Discover Bing.url => moved successfully =========== "C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN*.url" ========== C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN Autos.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN Entertainment.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN Lifestyle.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN Money.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSNBC News.url => moved successfully ========= End -> "C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN*.url" ======== C:\Documents and Settings\Krzysztof\Favorites\Microsoft Websites\Microsoft Showcase.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Microsoft Websites\Microsoft.com.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\go.microsoft.com-fwlink-LinkId=121315.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\ieonline.microsoft.com-#ieslice.url => moved successfully =========== "C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites*.url" ========== C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (10).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (11).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (12).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (13).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (14).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (15).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (16).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (17).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (18).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (19).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (2).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (20).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (21).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (22).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (23).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (24).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (25).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (26).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (27).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (28).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (29).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (3).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (30).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (31).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (32).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (33).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (34).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (35).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (36).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (37).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (38).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (39).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (4).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (40).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (41).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (42).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (43).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (44).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (45).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (46).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (47).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (48).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (49).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (5).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (50).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (51).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (52).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (53).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (54).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (55).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (56).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (57).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (58).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (59).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (6).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (60).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (61).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (62).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (63).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (64).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (7).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (8).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (9).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites.url => moved successfully ========= End -> "C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites*.url" ======== C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe.config => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\globalUpdate => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\mbot_pl_014010102 => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Microsoft\BingSvc => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Xmas => moved successfully C:\Documents and Settings\Krzysztof\Start Menu\Programs\腾讯软件 => moved successfully C:\Program Files\path5.ini => moved successfully C:\Program Files\5C8CAC0A-1443294427-5799-9460-C2325843CB2C => moved successfully "C:\Program Files\ASP" => not found. C:\Program Files\CinemaP-1.9cV26.09 => moved successfully C:\Program Files\CinemaPlus-3.2cV26.09 => moved successfully C:\Program Files\Concom => moved successfully C:\Program Files\globalUpdate => moved successfully C:\Program Files\GoHD => moved successfully C:\Program Files\Mozilla Firefox\browser\searchplugins => moved successfully C:\Program Files\Mozilla Firefox\plugins => moved successfully "C:\Program Files\Object Browser" => not found. C:\Program Files\RayDld => moved successfully C:\Program Files\SavePass 1.1 => moved successfully C:\Program Files\SFK => moved successfully "C:\Program Files\SimpleFilesUpdater" => not found. C:\Program Files\Tencent => moved successfully C:\Program Files\Common Files\Tencent => moved successfully =========== "C:\WINDOWS\DUMP*.tmp" ========== C:\WINDOWS\DUMP365d.tmp => moved successfully ========= End -> "C:\WINDOWS\DUMP*.tmp" ======== C:\WINDOWS\QMNetworkMgr.ini => moved successfully C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => moved successfully C:\WINDOWS\pss\McAfee Security Scan Plus.lnkCommon Startup => moved successfully "C:\WINDOWS\pss\IMVU.lnkStartup" => not found. C:\WINDOWS\pss\Logitech . Rejestracja produktu.lnkStartup => moved successfully C:\WINDOWS\pss\OpenOffice.org 3.2.lnkStartup => moved successfully C:\WINDOWS\pss\OptimumLink.lnkStartup => moved successfully C:\WINDOWS\pss\OptimumPCtoTV.lnkStartup => moved successfully C:\WINDOWS\pss\ybcrlnsnniggidoderh.lnkStartup => moved successfully C:\WINDOWS\System32\tssk.sys => moved successfully C:\WINDOWS\system32\Drivers\TAOAccelerator.sys => moved successfully C:\WINDOWS\System32\Drivers\TAOKernelXP.sys => moved successfully C:\WINDOWS\System32\Drivers\TFsFlt.sys => moved successfully C:\WINDOWS\System32\Drivers\TsFltMgr.sys => moved successfully C:\WINDOWS\System32\Drivers\TSDefenseBt.sys => moved successfully ========================= Folder: C:\extensions ======================== 2015-10-23 08:09 - 2015-10-23 08:09 - 0000000 ____D () C:\extensions\bingsearch.full@microsoft.com 2015-10-23 08:09 - 2015-10-23 08:09 - 0005494 _____ () C:\extensions\bingsearch.full@microsoft.com\bootstrap.js 2015-10-23 08:09 - 2015-10-23 08:09 - 0000023 _____ () C:\extensions\bingsearch.full@microsoft.com\chrome.manifest 2015-10-23 08:09 - 2015-10-23 08:09 - 0002989 _____ () C:\extensions\bingsearch.full@microsoft.com\icon.png 2015-10-23 08:09 - 2015-10-23 08:09 - 0000744 _____ () C:\extensions\bingsearch.full@microsoft.com\install.rdf 2015-10-23 08:09 - 2015-10-23 08:09 - 0013777 _____ () C:\extensions\bingsearch.full@microsoft.com\search-settings.jsm ====== End of Folder: ====== ========= dir /a "C:\Program Files" ========= Volume in drive C is BOOTCAMP Volume Serial Number is D8BF-6409 Directory of C:\Program Files 2015-10-30 09:46