Fix result of Farbar Recovery Scan Tool (x64) Version: 17-09-2016 Ran by Przemek (17-09-2016 21:56:16) Run:5 Running from C:\Users\Przemek\Downloads Loaded Profiles: Przemek (Available Profiles: Przemek) Boot Mode: Safe Mode (minimal) ============================================== fixlist content: ***************** CloseProcesses: S2 Citdhwa; "C:\Users\Przemek\AppData\Roaming\AzigcWig\Geeswu.exe" -cms [X] S2 HpSvc; C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll [X] <==== ATTENTION S2 Kuaizip Update Checker; C:\Program Files (x86)\KuaiZip\X86\kuaizipUpdateChecker.dll [X] S2 KuaizipUpdateChecker; C:\Program Files\¿ìѹ\X86\kuaizipUpdateChecker.dll [X] S1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-09-15] (REALiX(tm)) S2 KuaiZipDrive; C:\Windows\system32\drivers\KuaiZipDrive.sys [92872 2016-09-17] (WinMount International Inc) S2 KuaiZipDrive2; C:\Windows\system32\drivers\KuaiZipDrive2.sys [93072 2016-09-17] (WinMount International Inc) <==== ATTENTION R1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [81792 2016-08-29] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== ATTENTION S2 ComputerZLock; \??\C:\Program Files (x86)\LuDaShi\ComputerZLock_x64.sys [X] <==== ATTENTION S3 ComputerZ_x64; \??\C:\Program Files (x86)\LuDaShi\ComputerZ_x64.sys [X] <==== ATTENTION NETSVCx32: HpSvc -> C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll ==> No File Task: {0AF14ECA-B2B9-48B5-A34E-89D8306FE486} - System32\Tasks\UCBrowserUpdaterCore => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION Task: {A76297F3-3BBC-4275-84B0-6D9234D1A7E4} - System32\Tasks\Microsoft\Windows\Multimedia\Manager => C:\Users\Przemek\AppData\Roaming\Adobe\Manager.exe Task: {B04AFB75-99CB-4F38-A91A-E99E2D52BC56} - System32\Tasks\UCBrowserUpdater => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION Task: {DA8D609C-E26D-48D0-AC5A-7BA3F5FBC530} - System32\Tasks\ComputerZ-Tray => C:\Program Files (x86)\LuDaShi\ComputerZTray.exe <==== ATTENTION Task: {DEFAEC10-5A75-418F-8063-D04C84888430} - System32\Tasks\KuaiZip_Update => C:\PROGRA~1\F85A~1\X86\Update.exe <==== ATTENTION Task: {F37800E9-3BA8-4E7E-B6AD-98ABD7A0E413} - System32\Tasks\Microsoft\Windows\Multimedia\ReportSender => C:\Users\Przemek\ReportSender\ReportSender.exe Task: C:\Windows\Tasks\UCBrowserUpdater.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION Task: C:\Windows\Tasks\UCBrowserUpdaterCore.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION HKLM-x32\...\Run: [win_en_77] => "C:\Program Files (x86)\win_en_77\win_en_77.exe" HKLM-x32\...\Run: [app] => C:\Program Files (x86)\sbqh\uc.exe HKLM\...\RunOnce: [GrpConv] => grpconv -o HKLM-x32\...\RunOnce: [{AA6E0D33-1840-4D0A-98EA-E7B4E82016DC}] => cmd.exe /C start /D "C:\Users\Przemek\AppData\Local\Temp\{AA6E0D33-1840-4D0A-98EA-E7B4E82016DC}" /B {9B3387C1-398F-42AD-A67A-85C6283565EB}.exe -accepteula -accepteulaksn -postboot <===== ATTENTION HKU\S-1-5-21-1027309677-2631733394-661215758-1000\...\Run: [Installer] => C:\Users\Przemek\AppData\Local\Temp\is-64H6C.tmp\51490.exe /autorun <===== ATTENTION ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\¿ìѹ\X64\KZipShell.dll No File ShellIconOverlayIdentifiers: [KzShlobj2] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F3} => C:\Program Files (x86)\KuaiZip\X64\KZipShell.dll No File SearchScopes: HKU\S-1-5-21-1027309677-2631733394-661215758-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Toolbar: HKU\S-1-5-21-1027309677-2631733394-661215758-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File GroupPolicy: Restriction - Chrome <======= ATTENTION GroupPolicyScripts: Restriction <======= ATTENTION GroupPolicyScripts-x32: Restriction <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ShortcutWithArgument: C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://navsmart.info ShortcutWithArgument: C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://navsmart.info ShortcutWithArgument: C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Przemek\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://navsmart.info ShortcutWithArgument: C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://navsmart.info ShortcutWithArgument: C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Przemek\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://navsmart.info ShortcutWithArgument: C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://navsmart.info ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Przemek\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://navsmart.info ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Przemek\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" FirewallRules: [{69CAB555-BA9E-4731-882F-DFC2126E450D}] => (Allow) C:\Users\Przemek\AppData\Local\Temp\is-64H6C.tmp\download\MiniThunderPlatform.exe FirewallRules: [{4235CDA7-3945-4CBF-8977-ED1CA8A03CB9}] => (Allow) C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe FirewallRules: [{F3741A6B-EAC4-4B83-9F15-2D7A76B913E6}] => (Allow) C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe FirewallRules: [{4F15D172-C36B-4CCC-AB50-FC685F80901D}] => (Allow) C:\Program Files (x86)\UCBrowser\Application\Downloader\download\MiniThunderPlatform.exe HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\75420476.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\75420476.sys => ""="Driver" DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 DeleteKey: HKLM\SOFTWARE\Microsoft\Microsoft Antimalware DeleteKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins C:\Program Files (x86)\Temp C:\ProgramData\mntemp C:\ProgramData\AVAST Software C:\ProgramData\Avg C:\ProgramData\Avira C:\ProgramData\IObit C:\ProgramData\ProductData C:\ProgramData\Thunder Network C:\ProgramData\UniqueId C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ttwifi C:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师 C:\Users\Przemek\AppData\Local\Ckotoghzunle C:\Users\Przemek\AppData\Local\Tempfolder C:\Users\Przemek\AppData\Local\UCBrowser C:\Users\Przemek\AppData\Local\Zemana C:\Users\Przemek\AppData\LocalLow\Company C:\Users\Przemek\AppData\LocalLow\IObit C:\Users\Przemek\AppData\LocalLow\Octogear Games C:\Users\Przemek\AppData\Roaming\agent.dat C:\Users\Przemek\AppData\Roaming\Installer.dat C:\Users\Przemek\AppData\Roaming\Main.dat C:\Users\Przemek\AppData\Roaming\Adobe C:\Users\Przemek\AppData\Roaming\Hemkajdoa C:\Users\Przemek\AppData\Roaming\IObit C:\Users\Przemek\AppData\Roaming\KuaiZip C:\Users\Przemek\AppData\Roaming\Ludashi C:\Users\Przemek\AppData\Roaming\Macromedia C:\Users\Przemek\AppData\Roaming\Mozilla C:\Users\Przemek\AppData\Roaming\Origin C:\Users\Przemek\AppData\Roaming\Softlink C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\UC浏览器.lnk C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\UC浏览器.lnk C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìÑ1.lnk C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìѹ.lnk C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器 C:\Users\Przemek\Downloads\*.crdownload C:\Users\Public\Thunder Network C:\Windows\libcurl-4.dll C:\Windows\libeay32.dll C:\Windows\libwinpthread-1.dll C:\Windows\Azart C:\Windows\IObit C:\Windows\system32\Drivers\KuaiZipDrive.sys C:\Windows\system32\Drivers\KuaiZipDrive2.sys C:\Windows\system32\Drivers\ucguard.sys C:\Windows\SysWOW64\atrc.dll C:\Windows\SysWOW64\authmgr.dll C:\Windows\SysWOW64\clntxres.dll C:\Windows\SysWOW64\colorcvt.dll C:\Windows\SysWOW64\cook.dll C:\Windows\SysWOW64\drv1.dll C:\Windows\SysWOW64\drv2.dll C:\Windows\SysWOW64\drvc.dll C:\Windows\SysWOW64\GameCenter.exe.config C:\Windows\SysWOW64\GameXP.exe.config C:\Windows\SysWOW64\MUpdater.exe.config C:\Windows\SysWOW64\pncrt.dll C:\Windows\SysWOW64\pnen3260.dll C:\Windows\SysWOW64\raac.dll C:\Windows\SysWOW64\ramfformat.dll C:\Windows\SysWOW64\ramrender.dll C:\Windows\SysWOW64\rarender.dll C:\Windows\SysWOW64\rmfformat.dll C:\Windows\SysWOW64\rv10.dll C:\Windows\SysWOW64\rv20.dll C:\Windows\SysWOW64\rv30.dll C:\Windows\SysWOW64\rv40.dll C:\Windows\SysWOW64\rvrender.dll C:\Windows\SysWOW64\sipr.dll C:\Windows\SysWOW64\smplfsys.dll C:\Windows\SysWOW64\vidsite.dll C:\Windows\SysWOW64\vp6vfw.dll C:\Windows\SysWOW64\Drivers\HWiNFO64A.SYS EmptyTemp: ***************** Processes closed successfully. Citdhwa => service not found. HpSvc => service not found. Kuaizip Update Checker => service not found. KuaizipUpdateChecker => service not found. HWiNFO32 => service not found. KuaiZipDrive => service not found. KuaiZipDrive2 => service not found. UCGuard => service removed successfully ComputerZLock => service removed successfully ComputerZ_x64 => service removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs HpSvc => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0AF14ECA-B2B9-48B5-A34E-89D8306FE486}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0AF14ECA-B2B9-48B5-A34E-89D8306FE486}" => key removed successfully C:\Windows\System32\Tasks\UCBrowserUpdaterCore => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UCBrowserUpdaterCore" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A76297F3-3BBC-4275-84B0-6D9234D1A7E4}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A76297F3-3BBC-4275-84B0-6D9234D1A7E4}" => key removed successfully C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\Manager => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\Manager" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B04AFB75-99CB-4F38-A91A-E99E2D52BC56}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B04AFB75-99CB-4F38-A91A-E99E2D52BC56}" => key removed successfully C:\Windows\System32\Tasks\UCBrowserUpdater => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UCBrowserUpdater" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DA8D609C-E26D-48D0-AC5A-7BA3F5FBC530}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA8D609C-E26D-48D0-AC5A-7BA3F5FBC530}" => key removed successfully C:\Windows\System32\Tasks\ComputerZ-Tray => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ComputerZ-Tray" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DEFAEC10-5A75-418F-8063-D04C84888430}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DEFAEC10-5A75-418F-8063-D04C84888430}" => key removed successfully C:\Windows\System32\Tasks\KuaiZip_Update => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KuaiZip_Update" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F37800E9-3BA8-4E7E-B6AD-98ABD7A0E413}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F37800E9-3BA8-4E7E-B6AD-98ABD7A0E413}" => key removed successfully C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\ReportSender => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\ReportSender" => key removed successfully C:\Windows\Tasks\UCBrowserUpdater.job => moved successfully C:\Windows\Tasks\UCBrowserUpdaterCore.job => moved successfully HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\win_en_77 => value removed successfully HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\app => value removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\GrpConv => value removed successfully HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\{AA6E0D33-1840-4D0A-98EA-E7B4E82016DC} => value removed successfully HKU\S-1-5-21-1027309677-2631733394-661215758-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Installer => value removed successfully "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\KzShlobj" => key removed successfully "HKCR\CLSID\{AAA0C5B8-933F-4200-93AD-B143D7FFF9F2}" => key removed successfully "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\KzShlobj2" => key removed successfully "HKCR\CLSID\{AAA0C5B8-933F-4200-93AD-B143D7FFF9F3}" => key removed successfully HKU\S-1-5-21-1027309677-2631733394-661215758-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully HKU\S-1-5-21-1027309677-2631733394-661215758-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. C:\Windows\system32\GroupPolicy\Machine => moved successfully C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully "C:\Windows\system32\GroupPolicy\Machine" => not found. C:\Windows\SysWOW64\GroupPolicy\Machine => moved successfully "HKLM\SOFTWARE\Policies\Google" => key removed successfully C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk => Shortcut argument removed successfully. C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument removed successfully. C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument removed successfully. C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument removed successfully. C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => Shortcut argument removed successfully. C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => Shortcut argument removed successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => Shortcut argument removed successfully. C:\Users\Public\Desktop\Google Chrome.lnk => Shortcut argument removed successfully. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{69CAB555-BA9E-4731-882F-DFC2126E450D} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4235CDA7-3945-4CBF-8977-ED1CA8A03CB9} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F3741A6B-EAC4-4B83-9F15-2D7A76B913E6} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4F15D172-C36B-4CCC-AB50-FC685F80901D} => value removed successfully "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\75420476.sys" => key removed successfully "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\75420476.sys" => key removed successfully HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => could not remove at first attempt (ErrorCode: C0000121), see next line. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => key removed successfully HKLM\SOFTWARE\Microsoft\Microsoft Antimalware => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Microsoft\Microsoft Antimalware => key removed successfully HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths => key removed successfully HKLM\SOFTWARE\Wow6432Node\Mozilla => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\Mozilla => key removed successfully HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => key removed successfully C:\Program Files (x86)\Temp => moved successfully C:\ProgramData\mntemp => moved successfully C:\ProgramData\AVAST Software => moved successfully C:\ProgramData\Avg => moved successfully C:\ProgramData\Avira => moved successfully C:\ProgramData\IObit => moved successfully C:\ProgramData\ProductData => moved successfully C:\ProgramData\Thunder Network => moved successfully C:\ProgramData\UniqueId => moved successfully C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip => moved successfully C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ttwifi => moved successfully C:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师 => moved successfully C:\Users\Przemek\AppData\Local\Ckotoghzunle => moved successfully C:\Users\Przemek\AppData\Local\Tempfolder => moved successfully C:\Users\Przemek\AppData\Local\UCBrowser => moved successfully C:\Users\Przemek\AppData\Local\Zemana => moved successfully C:\Users\Przemek\AppData\LocalLow\Company => moved successfully C:\Users\Przemek\AppData\LocalLow\IObit => moved successfully C:\Users\Przemek\AppData\LocalLow\Octogear Games => moved successfully C:\Users\Przemek\AppData\Roaming\agent.dat => moved successfully C:\Users\Przemek\AppData\Roaming\Installer.dat => moved successfully C:\Users\Przemek\AppData\Roaming\Main.dat => moved successfully C:\Users\Przemek\AppData\Roaming\Adobe => moved successfully C:\Users\Przemek\AppData\Roaming\Hemkajdoa => moved successfully C:\Users\Przemek\AppData\Roaming\IObit => moved successfully C:\Users\Przemek\AppData\Roaming\KuaiZip => moved successfully C:\Users\Przemek\AppData\Roaming\Ludashi => moved successfully C:\Users\Przemek\AppData\Roaming\Macromedia => moved successfully C:\Users\Przemek\AppData\Roaming\Mozilla => moved successfully C:\Users\Przemek\AppData\Roaming\Origin => moved successfully C:\Users\Przemek\AppData\Roaming\Softlink => moved successfully C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\UC浏览器.lnk => moved successfully C:\Users\Przemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\UC浏览器.lnk => moved successfully C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìÑ1.lnk => moved successfully C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\¿ìѹ.lnk => moved successfully C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器 => moved successfully =========== "C:\Users\Przemek\Downloads\*.crdownload" ========== C:\Users\Przemek\Downloads\Unconfirmed 237672.crdownload => moved successfully C:\Users\Przemek\Downloads\Unconfirmed 539171.crdownload => moved successfully ========= End -> "C:\Users\Przemek\Downloads\*.crdownload" ======== C:\Users\Public\Thunder Network => moved successfully C:\Windows\libcurl-4.dll => moved successfully C:\Windows\libeay32.dll => moved successfully C:\Windows\libwinpthread-1.dll => moved successfully C:\Windows\Azart => moved successfully C:\Windows\IObit => moved successfully C:\Windows\system32\Drivers\KuaiZipDrive.sys => moved successfully C:\Windows\system32\Drivers\KuaiZipDrive2.sys => moved successfully C:\Windows\system32\Drivers\ucguard.sys => moved successfully C:\Windows\SysWOW64\atrc.dll => moved successfully C:\Windows\SysWOW64\authmgr.dll => moved successfully C:\Windows\SysWOW64\clntxres.dll => moved successfully C:\Windows\SysWOW64\colorcvt.dll => moved successfully C:\Windows\SysWOW64\cook.dll => moved successfully C:\Windows\SysWOW64\drv1.dll => moved successfully C:\Windows\SysWOW64\drv2.dll => moved successfully C:\Windows\SysWOW64\drvc.dll => moved successfully C:\Windows\SysWOW64\GameCenter.exe.config => moved successfully C:\Windows\SysWOW64\GameXP.exe.config => moved successfully C:\Windows\SysWOW64\MUpdater.exe.config => moved successfully C:\Windows\SysWOW64\pncrt.dll => moved successfully C:\Windows\SysWOW64\pnen3260.dll => moved successfully C:\Windows\SysWOW64\raac.dll => moved successfully C:\Windows\SysWOW64\ramfformat.dll => moved successfully C:\Windows\SysWOW64\ramrender.dll => moved successfully C:\Windows\SysWOW64\rarender.dll => moved successfully C:\Windows\SysWOW64\rmfformat.dll => moved successfully C:\Windows\SysWOW64\rv10.dll => moved successfully C:\Windows\SysWOW64\rv20.dll => moved successfully C:\Windows\SysWOW64\rv30.dll => moved successfully C:\Windows\SysWOW64\rv40.dll => moved successfully C:\Windows\SysWOW64\rvrender.dll => moved successfully C:\Windows\SysWOW64\sipr.dll => moved successfully C:\Windows\SysWOW64\smplfsys.dll => moved successfully C:\Windows\SysWOW64\vidsite.dll => moved successfully C:\Windows\SysWOW64\vp6vfw.dll => moved successfully C:\Windows\SysWOW64\Drivers\HWiNFO64A.SYS => moved successfully =========== EmptyTemp: ========== BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12595912 B Java, Flash, Steam htmlcache => 178054622 B Windows/system/drivers => 0 B Edge => 0 B Chrome => 587704 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B NetworkService => 0 B Przemek => 14595980 B RecycleBin => 146272 B EmptyTemp: => 196.4 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 21:56:23 ====