Users shortcut scan result (x86) Version: 01-02-2015 Ran by XX at 2015-02-02 17:35:33 Running from C:\ Boot Mode: Normal ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Centrum obsługi HP.lnk -> C:\Program Files\HP\Digital Imaging\bin\Hpqdirec.exe (Hewlett-Packard Company) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Program Updates.lnk -> C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk -> C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AB0000000001}\SC_Reader.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anki.lnk -> C:\Program Files\Anki\anki.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk -> C:\Program Files\CDBurnerXP\cdbxpp.exe (Canneverbe Limited) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gadu-Gadu 10.lnk -> C:\Program Files\Gadu-Gadu 10\gg.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk -> C:\Windows\Installer\{90850415-6000-11D3-8CFE-0150048383C9}\wrdvicon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Virtual PC.lnk -> C:\Program Files\Microsoft Virtual PC\Virtual PC.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rejestracja programu I.R.I.S. OCR.lnk -> C:\Program Files\HP\Digital Imaging\DocProc\regipe.exe (I.R.I.S. Image Recognition Integarted Systems) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk -> C:\Windows\System32\WindowsAnytimeUpgradeUI.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\YouTube Accelerator.lnk -> C:\Program Files\YouTube Accelerator\YouTubeAccelerator.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live\Bezpieczeństwo rodzinne usługi Windows Live.lnk -> C:\Windows\Installer\{3856DA80-86D2-4EBF-B33E-9F2C54BC9AC4}\fssicon.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client\TeamSpeak 3 Client.lnk -> C:\Program Files\TeamSpeak 3 Client\ts3client_win32.exe (TeamSpeak Systems GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client\Uninstall.lnk -> C:\Program Files\TeamSpeak 3 Client\Uninstall.exe (TeamSpeak Systems GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla\STOPzilla.lnk -> C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam Support Center.lnk -> C:\Windows\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C92.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony\Sony PC Companion\Sony PC Companion 2.1.lnk -> C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk -> C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer\San Andreas Multiplayer.lnk -> C:\Program Files\Rockstar Games\GTA San Andreas\samp.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer\Uninstall.lnk -> C:\Program Files\Rockstar Games\GTA San Andreas\SAMPUninstall.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real\RealPlayer Converter.lnk -> C:\Program Files\Real\RealPlayer\realconverter.exe (RealNetworks, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real\RealPlayer Trimmer.lnk -> C:\Program Files\Real\RealPlayer\realtrimmer.exe (RealNetworks, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero\Nero ControlCenter 4.lnk -> C:\Program Files\Nero\Nero ControlCenter 4\ncc.exe (Nero AG) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero\Nero 9\Nero StartSmart Essentials.lnk -> C:\Program Files\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe (Nero AG) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\Silverlight.Configuration.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Groove 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\GrooveIcon.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office InfoPath 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office OneNote 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Certyfikat cyfrowy dla projektów VBA.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Diagnostyka pakietu Microsoft Office.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Microsoft Clip Organizer.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Microsoft Office 2007 Ustawienia języka.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Microsoft Office Picture Manager.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2\Metin2.lnk -> D:\GameforgeLive\GameforgeLive.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Deinstalacja programu Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk -> C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk -> C:\Windows\System32\recdisc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LocK-A-FoLdeR\LocK-A-FoLdeR.lnk -> C:\Program Files\LocK-A-FoLdeR\lock-a-folder.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LocK-A-FoLdeR\Readme.lnk -> C:\Program Files\LocK-A-FoLdeR\Readme.txt (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LocK-A-FoLdeR\Uninstall.lnk -> C:\Program Files\LocK-A-FoLdeR\Uninstall.exe (Gurjit Singh) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends\League of Legends.lnk -> D:\lol.launcher.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\Centrum obsługi HP.lnk -> C:\Program Files\HP\Digital Imaging\bin\Hpqdirec.exe (Hewlett-Packard Company) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Update.lnk -> C:\Program Files\HP\HP Software Update\HPWUCli.exe (Hewlett-Packard) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\Zakup materiałów eksploatacyjnych HP.lnk -> C:\Program Files\HP\HPSSUPPLY\hpqSSupply.exe (Hewlett-Packard Development Company L.P.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Photosmart Essential 3.5\HP Photosmart Essential 3.5.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe (Hewlett-Packard Development Co. L.P.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Photosmart Essential 3.5\Odinstaluj HP Photosmart Essential 3.5.lnk -> C:\Program Files\HP\Digital Imaging\photosmartessential\hpzscr01.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone\Hearthstone.lnk -> D:\Hearthstone\Hearthstone Beta Launcher.exe (Blizzard Entertainment) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter\GDSMux.lnk -> C:\Program Files\K-Lite Codec Pack\Filters\Haali\gdsmux.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter\Uninstall.lnk -> C:\Program Files\K-Lite Codec Pack\Filters\Haali\uninstall.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Drive.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe (Google) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader 5.0\Foxit Reader 5.0.lnk -> C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader 5.0\Uninstall Foxit Reader 5.0.lnk -> C:\Program Files\Foxit Software\Foxit Reader\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick\DVD Flick.lnk -> C:\Program Files\DVD Flick\dvdflick.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick\Uninstall DVD Flick.lnk -> C:\Program Files\DVD Flick\unins000.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick\Help and Support\Changelog.lnk -> C:\Program Files\DVD Flick\changelog.txt (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick\Help and Support\GNU GPL License.lnk -> C:\Program Files\DVD Flick\license.txt (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick\Help and Support\Guide.lnk -> C:\Program Files\DVD Flick\guide\index_en.html (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick\Help and Support\Readme.lnk -> C:\Program Files\DVD Flick\readme.txt (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dual Package\Dual Package.lnk -> C:\Program Files\LG Soft India Pvt Ltd\Dual Package\bin\Dual Package.exe (LG Electronics) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\DivX Plus Player.lnk -> C:\Program Files\DivX\DivX Plus Player\DivX Plus Player.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk -> C:\Program Files\CCleaner\uninst.exe (Piriform Ltd) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net\Battle.net.lnk -> C:\Program Files\Battle.net\Battle.net Launcher.exe (Blizzard Entertainment) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviToDvdFree\AviToDvdFree on the Web.lnk -> C:\Program Files\AviToDvdFree\AviToDvdFree.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviToDvdFree\AviToDvdFree.lnk -> C:\Program Files\AviToDvdFree\avitodvd.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviToDvdFree\Uninstall AviToDvdFree.lnk -> C:\Program Files\AviToDvdFree\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Angielska dokumentacja.lnk -> C:\Program Files\AviSynth 2.5\Docs\English\index.htm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Folder wtyczek.lnk -> C:\Program Files\AviSynth 2.5\plugins () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Licencja po polsku.lnk -> C:\Program Files\AviSynth 2.5\License Translations\gpl-pl.txt (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Licencja.lnk -> C:\Program Files\AviSynth 2.5\gpl.txt (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Odinstaluj AviSynth.lnk -> C:\Program Files\AviSynth 2.5\Uninstall.exe (The Public) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Polska dokumentacja.lnk -> C:\Program Files\AviSynth 2.5\Docs\Polish\index.htm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Przykładowe skrypty.lnk -> C:\Program Files\AviSynth 2.5\Examples () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Avira Free Antivirus Help.lnk -> C:\Program Files\Avira\AntiVir Desktop\avwin.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Avira on the Internet.lnk -> C:\Program Files\Avira\AntiVir Desktop\weblink.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Start Avira Free Antivirus.lnk -> C:\Program Files\Avira\AntiVir Desktop\avcenter.exe (Avira Operations GmbH & Co. KG) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avi2Dvd\Avi2Dvd.lnk -> C:\Program Files\Avi2Dvd\Avi2Dvd.exe (TrustFm) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avi2Dvd\Uninstall.lnk -> C:\Program Files\Avi2Dvd\uninst.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avi2Dvd\Website.lnk -> C:\Program Files\Avi2Dvd\Avi2Dvd.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG\AVG 2015.lnk -> C:\Program Files\AVG\AVG2015\avgui.exe (AVG Technologies CZ, s.r.o.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autonomiczny składnik AVG LinkScanner\AVG 2012.lnk -> C:\Program Files\AVG\AVG2012\avgui.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk -> C:\Windows\System32\displayswitch.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk -> C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4Media\Video Editor 2\4Media Video Editor 2.lnk -> C:\Program Files\4Media\Video Editor 2\videoeditor.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4Media\Video Editor 2\4Media Video Editor Help.lnk -> C:\Program Files\4Media\Video Editor 2\videoeditor.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4Media\Video Editor 2\Uninstall.lnk -> C:\Program Files\4Media\Video Editor 2\Uninstall.exe () Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\AVG 2015.lnk -> C:\Program Files\AVG\AVG2015\avgui.exe (AVG Technologies CZ, s.r.o.) Shortcut: C:\Users\Public\Desktop\Battle.net.lnk -> C:\Program Files\Battle.net\Battle.net Launcher.exe (Blizzard Entertainment) Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\Public\Desktop\Hearthstone.lnk -> D:\Hearthstone\Hearthstone Beta Launcher.exe (Blizzard Entertainment) Shortcut: C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation) Shortcut: C:\Users\XX\Start Menu\Programs\SpyHunter\SpyHunter.lnk -> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe (Enigma Software Group USA, LLC.) Shortcut: C:\Users\XX\Desktop\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\XX\Desktop\LocK-A-FoLdeR.lnk -> C:\Program Files\LocK-A-FoLdeR\lock-a-folder.exe () Shortcut: C:\Users\XX\Desktop\mouserate-s.lnk -> C:\Mouse Rate Checker 1.1b\mouserate-s.exe ( ) Shortcut: C:\Users\XX\Desktop\SpyHunter.lnk -> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe (Enigma Software Group USA, LLC.) Shortcut: C:\Users\XX\Desktop\toiowo\NOWA muzyka\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.chm () Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe () Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries\SteelSeries Engine\Diablo III Headset User Guide.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeries_Diablo_III_Headset_Guide.pdf (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries\SteelSeries Engine\Diablo III Mouse User Guide.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeries_Diablo_III_Mouse_Guide.pdf (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries\SteelSeries Engine\Sensei User Guide.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine\Sensei_UserGuide.pdf (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries\SteelSeries Engine\SteelSeries Engine User Guide.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine_UserGuide.pdf (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries\SteelSeries Engine\SteelSeries Engine.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries\SteelSeries Engine\SteelSeries Firmware Update Tool.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine\SSEFix.exe (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries\SteelSeries Engine\Uninstall SteelSeries Engine.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine\uninst.exe (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk -> D:\Steam\Steam.exe (Valve Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MKJogo\MK IM\MK LOL.lnk -> C:\Program Files\MKJogo\MK IM\Bin\MKIM.exe () Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MKJogo\MK IM\Uninstall.lnk -> C:\Program Files\MKJogo\MK IM\Bin\uInst.exe (MK) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView\Command line Options.lnk -> C:\Program Files\IrfanView\i_options.txt (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView\IrfanView 4.36.lnk -> C:\Program Files\IrfanView\i_view32.exe (Irfan Skiljan) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView\IrfanView Help.lnk -> C:\Program Files\IrfanView\i_view32.chm () Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView\Uninstall IrfanView.lnk -> C:\Program Files\IrfanView\iv_uninstall.exe (Irfan Skiljan, IrfanView) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk -> C:\Program Files\CCleaner\uninst.exe (Piriform Ltd) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\SendTo\AVS Mobile Uploader.lnk -> C:\Program Files\Common Files\AVSMedia\MobileUploader\AVSMobileUploader.exe (Online Media Technologies Ltd.) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\SendTo\AVS Video Burner.lnk -> C:\Program Files\Common Files\AVSMedia\BurnerService\AVSVideoBurner.exe (Online Media Technologies Ltd.) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Windows\SendTo\AVS Video Uploader.lnk -> C:\Program Files\Common Files\AVSMedia\VideoUploader\AVSVideoUploader.exe (Online Media Technologies Ltd.) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Office\Niedawny\Badenheim-ładna historia.LNK -> C:\Users\XX\Documents\Badenheim-ładna historia.mdb (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Office\Niedawny\mix.LNK -> C:\Users\XX\Desktop\mix (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Office\Niedawny\Moje dokumenty.LNK -> C:\Users\XX\Documents () Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Office\Niedawny\My Webs.LNK -> C:\Users\XX\Documents\My Webs (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Office\Niedawny\Poradnik.doc.LNK -> C:\Users\XX\Desktop\mix\Poradnik.doc (No File) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\4Media Video Editor 2.lnk -> C:\Program Files\4Media\Video Editor 2\videoeditor.exe () Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AviToDvdFree.lnk -> C:\Program Files\AviToDvdFree\avitodvd.exe () Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Foxit Reader 5.0.lnk -> C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader.exe () Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\League of Legends.lnk -> D:\lol.launcher.exe () Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\XX\AppData\Roaming\Adobe\Workflow\working.lnk -> C:\Users\XX\Documents\Version Cue (No File) Shortcut: C:\Users\XX\AppData\Roaming\Adobe\Workflow\workinghidden.lnk -> C:\Users\XX\Documents\Version Cue\myprojectshidden (No File) Shortcut: C:\Users\XX\AppData\Local\Microsoft\Windows\GameExplorer\{EC69BB09-CFB0-4BDE-AE59-5D5F02A80FD9}\PlayTasks\0\Zagraj.lnk -> D:\Steam\steamapps\common\Half-Life\hl.exe (Valve) Shortcut: C:\Users\XX\AppData\Local\Microsoft\Windows\GameExplorer\{E7D11D7F-D96B-4518-882F-51F8DEF0479A}\PlayTasks\0\Zagraj.lnk -> D:\Steam\steamapps\kacpik156\counter-strike\hl.exe (No File) Shortcut: C:\Users\XX\AppData\Local\Microsoft\Windows\GameExplorer\{E47534A3-1722-44C2-B3BB-A6B9A1ED8C92}\PlayTasks\0\Zagraj.lnk -> C:\Program Files\Rockstar Games\GTA San Andreas\gta_sa.exe (No File) Shortcut: C:\Users\XX\AppData\Local\Microsoft\Windows\GameExplorer\{0AC81D66-5297-4705-8079-6260E4986C4A}\PlayTasks\0\Zagraj.lnk -> D:\Steam\steamapps\kacpik156\counter-strike\hl.exe (No File) ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\Favorites\Web Pages\Film.com.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /targetview:_rpbrowser hxxp://www.film.com ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\Favorites\Web Pages\RealGames.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /targetview:_rpbrowser hxxp://eu.real.com/games ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\Favorites\Web Pages\Zylom.com.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /targetview:_rpbrowser hxxp://www.zylom.com ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\Favorites\Video\Live TV News.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /targetview:_rpbrowser hxxp://eu.real.com/live-news/ ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\Favorites\Video\Music Videos.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /targetview:_rpbrowser hxxp://eu.real.com/music/videos ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\Favorites\Video\RealVideo.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /targetview:_rpbrowser hxxp://eu.real.com/video ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\Favorites\Radio\RealMusic.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /targetview:_rpbrowser hxxp://eu.real.com/music ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) -> /showgadgets ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla\Uninstall STOPzilla.lnk -> C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.) -> /uninstall ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony\Sony PC Companion\Odinstalowywanie programu.lnk -> C:\Program Files\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe (Sony) -> -uninst -runfromtemp ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Kies\Uninstall Kies.lnk -> C:\Program Files\InstallShield Installation Information\{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}\setup.exe (Samsung Electronics Co., Ltd. ) -> /removeonly ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real\RealPlayer.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /launch:start_menu ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero\Nero Online Upgrade.lnk -> C:\Program Files\Nero\Nero 9\Nero Online Upgrade\NeroOnlineUpgrade.exe (Nero AG) -> ShowOffer ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestore ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\DirectVobSub.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\vsfilter.dll",DirectVobSub ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow audio decoder.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\ffdshow\ffdshow.ax",configureAudio ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow DXVA video decoder.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\ffdshow\ffdshow.ax",configureDXVA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow VFW interface.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Windows\system32\ff_vfw.dll",configureVFW ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow video decoder.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\ffdshow\ffdshow.ax",configure ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\Haali Media Splitter.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\Haali\splitter.ax",Configure ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\Xvid encoder.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Windows\system32\xvidvfw.dll",Configure ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC\HTC Driver\Uninstall HTC Driver.lnk -> C:\Windows\System32\msiexec.exe (Microsoft Corporation) -> /x {6D6664A9-3342-4948-9B7E-034EFE366F0F} ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter\Media Splitter Settings.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> splitter.ax,Configure ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Docs.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe (Google) -> --new_document ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Sheets.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe (Google) -> --new_spreadsheet ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Slides.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe (Google) -> --new_presentation ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dual Package\Uninstall Dual Package.lnk -> C:\Program Files\InstallShield Installation Information\{37365259-9D37-4FBE-9204-08B4034623B6}\setup.exe (InstallShield Software Corporation) -> /L0x0009 /removeonly ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\Check for Updates.lnk -> C:\Program Files\DivX\DivX Control Panel\DivXControlPanelLauncher.exe (DivX, Inc.) -> /start=update ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\Codec Settings.lnk -> C:\Program Files\DivX\DivX Control Panel\DivXControlPanelLauncher.exe (DivX, Inc.) -> /start=decoder ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\DivX Plus Converter.lnk -> C:\Program Files\DivX\DivX Plus Converter\DivXConverterLauncher.exe (DivX, Inc.) -> SW_SHOWNORMAL ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\Register.lnk -> C:\Program Files\DivX\DivX Control Panel\DivXControlPanelLauncher.exe (DivX, Inc.) -> /start=registration ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.1\main.lua.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) -> C:\Program Files\Cheat Engine 6.1\main.lua ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\CCC - Kreator.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.exe (ATI Technologies Inc.) -> Start Wizard ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\CCC - zaawansowany.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.exe (ATI Technologies Inc.) -> Start Dashboard ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\CCC.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.exe (ATI Technologies Inc.) -> Start CCC ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\Pomoc.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.exe (ATI Technologies Inc.) -> Start Help -help ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\Uruchom ponownie wykonywanie.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.) -> Restart ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira.lnk -> C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) -> /showMiniGui ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4Media\Video Editor 2\Buy.lnk -> C:\Program Files\4Media\Video Editor 2\videoeditor_buy.exe () -> -buyurl ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Public\Desktop\Avira.lnk -> C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) -> /showMiniGui ShortcutWithArgument: C:\Users\XX\Start Menu\Programs\SpyHunter\SpyHunter Emergency Startup.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.com" ShortcutWithArgument: C:\Users\XX\Start Menu\Programs\SpyHunter\Uninstall.lnk -> C:\Users\XX\AppData\Roaming\Enigma Software Group\sh_installer.exe (Enigma Software Group USA, LLC.) -> -r sh ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\History\10674059_616549631788910_1773190228_n.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /startpos:00:00:00.0 file://C:/Users/XX/Videos/RealPlayer Downloads/10674059_616549631788910_1773190228_n.mp4 ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\History\Alexander__-_Myslovitz.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /startpos:00:00:00.0 file://E:/Alexander__-_Myslovitz.mp3 ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Real\RealPlayer\History\Aya_rl_-_Skora.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /startpos:00:00:00.0 file://E:/Aya_rl_-_Skora.mp3 ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView\IrfanView - Thumbnails.lnk -> C:\Program Files\IrfanView\i_view32.exe (Irfan Skiljan) -> /thumbs ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\XX\AppData\Roaming\Microsoft\Windows\SendTo\Skype.lnk -> C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) -> /sendto: InternetURL: C:\ProgramData\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\VOIPlay\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\VOIPlay\sounds\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\VOIPlay\sounds\default\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\VOIPlay\skins\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\VOIPlay\skins\default\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Symantec\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Symantec\Definitions\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Symantec\Definitions\SymcData\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Symantec\Definitions\SymcData\VirusDefs-2.5-E\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Symantec\Definitions\SymcData\VirusDefs-2.5-E\20130128.004\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\STOPzilla!\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\STOPzilla!\VIPRE\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\SteelSeries\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\SteelSeries\SteelSeries Engine\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\SteelSeries\SteelSeries Engine\Tips\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\SteelSeries\SteelSeries Engine\Tips\Japanese\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\SteelSeries\SteelSeries Engine\Tips\Japanese\TipsPanel\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\SteelSeries\SteelSeries Engine\Localization\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\SteelSeries\SteelSeries Engine\Database\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Sony\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Sony\Sony PC Companion\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Sony\Sony PC Companion\{DCC2224A-2CE2-4EC4-A3C7-478274F2A82B}\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Sony\Sony PC Companion\{DCC2224A-2CE2-4EC4-A3C7-478274F2A82B}\Avanquest Bluetooth SDK\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Sony\Sony PC Companion\PCCompanionInfo\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Skype\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Skype\Plugins\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Skype\Plugins\Plugins\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\NortonInstaller\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\NortonInstaller\Logs\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\NortonInstaller\Logs\12-15-2011-19h36m52s\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\NortonInstaller\Logs\02-04-2011-15h40m12s\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Norton\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Nero\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Nero\OnlineServices\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Nero\OnlineServices\MetaData\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Microsoft\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator\About YouTube Accelerator.url -> hxxp://www.youtubeaccelerator.com/help/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks\Strona WWW programu World of Tanks.url -> hxxp://www.worldoftanks.eu InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam Support Center.url -> hxxp://support.steampowered.com/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon\넥슨.url -> hxxp://www.nexon.com/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2\Metin2 Online.url -> hxxp://www.metin2.pl InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick\Help and Support\DVD Flick on the Web.url -> hxxp://www.dvdflick.net InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> hxxp://www.piriform.com/ccleaner InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\AviSynth Online.url -> hxxp://www.avisynth.org InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Download Plugins.url -> hxxp://www.avisynth.org/warpenterprises/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Strona główna AviSynth.url -> hxxp://www.avisynth.org InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5\Ściągnij wtyczki.url -> hxxp://www.avisynth.org/warpenterprises/ InternetURL: C:\ProgramData\Microsoft\RAC\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Microsoft\RAC\StateData\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Microsoft\RAC\PublishedData\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Microsoft\eHome\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Microsoft\eHome\thmb\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MFAData\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Screenshare\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Screenshare\Session History\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Screenshare\Session History\Utilities\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Screenshare\Session History\Utilities\assets\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Screenshare\Movies\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Photo_Manager_8\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Photo_Manager_8\Default\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Common\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Common\Online Services Info\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Common\Online Services Info\0809\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Common\Online Services Info\0809\redaktion\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Common\Online Services Info\0809\master\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\MAGIX\Common\Database\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\InstallMate\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\InstallMate\{AA8E1652-91AF-47E0-A50B-D98D716D34A4}\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT 2.0\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT 2.0\data\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Movies\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\J6400\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\J4680\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\J4660\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\J4500\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\generic\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\D730\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\D2600\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\D2500\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\C6300\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\C5500\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\C5300\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\B8800\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\B8500\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\8500\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\HP\LGT\Data\Models\Images\6500\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\DivX\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\DivX\Setup\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\DivX\Setup\EULAs\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\DivX\Setup\EULAs\consumer\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Battle.net\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\Battle.net\Agent\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\avg9\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\avg9\scanlogs\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\AVG Secure Search\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\AVG Secure Search\ChromeExt\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\ProgramData\AVG Secure Search\ChromeExt\18.1.0.443\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Videos\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Videos\RealPlayer Downloads\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKJogo\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKJogo\Im\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKJogo\Im\Comm\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKJogo\Im\3071286\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKJogo\Im\3071286\Local\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKGame\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKGame\LOL\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKGame\LOL\Comm\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKGame\Im\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKGame\Im\Comm\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKGame\Im\100024\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MKGame\Im\100024\Local\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MK-LOL\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MK-LOL\ScreenShots\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\MK-LOL\ScreenShots\AirShot\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\dvd\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\dvd\dvd\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\dvd\dvd\VIDEO_TS\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\Anki\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\Anki\Użytkownik 1\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Documents\Anki\Użytkownik 1\collection.media\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\Counter-Strike Global Offensive.url -> steam://rungameid/730 InternetURL: C:\Users\XX\Desktop\Counter-Strike.url -> steam://rungameid/10 InternetURL: C:\Users\XX\Desktop\toiowo\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\toiowo\NOWA muzyka\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\toiowo\NOWA muzyka\POMPKA\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\siłka FILMIKI\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\Nowy folder\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\Nowy folder\Nowy folder\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\Nowy folder\Nowy folder\cfg\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\nm\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\najlepsza składanka\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\muzyka\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\music\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\mp3\HELP_DECRYPT.URL -> 0 InternetURL: C:\Users\XX\Desktop\Malestia.pl client 20.12.2014\HELP_DECRYPT.URL -> 0 InternetURL: C:\Users\XX\Desktop\Malestia.pl client 20.12.2014\Malestia.pl client 20.12.2014\HELP_DECRYPT.URL -> 0 InternetURL: C:\Users\XX\Desktop\Malestia.pl client 20.12.2014\Malestia.pl client 20.12.2014\upload\HELP_DECRYPT.URL -> 0 InternetURL: C:\Users\XX\Desktop\Malestia.pl client 20.12.2014\Malestia.pl client 20.12.2014\mark\HELP_DECRYPT.URL -> 0 InternetURL: C:\Users\XX\Desktop\do samochodu\HELP_DECRYPT.URL -> 0 InternetURL: C:\Users\XX\Desktop\do samochodu\next\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\config (1)\gamerconfig.url -> hxxp://www.gamerconfig.eu InternetURL: C:\Users\XX\Desktop\config\gamerconfig.url -> hxxp://www.gamerconfig.eu InternetURL: C:\Users\XX\Desktop\cfg\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\cfg\cfg\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\Desktop\29szt\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\wargaming.net\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\wargaming.net\WorldOfTanks\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\wargaming.net\WorldOfTanks\custom_data\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\TS3Client\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\SteelSeries\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\SteelSeries\SteelSeries Engine\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Skype\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Skype\naburokasajaki\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Skype\milosz9797\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Skype\kosikredki4\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Skype\edward.asdas\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Skype\dygiedygie\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Skype\caprediem97\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Samsung\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Samsung\Kies\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Real\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Real\RealPlayer\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Real\RealPlayer\device\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Real\RealPlayer\device\e986ba89009946db43338b6f99868607\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Real\RealPlayer\db\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Opera\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Opera\CProgram FilesOpera\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Opera\CProgram FilesOpera\sessions\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\OpenFM\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\OpenFM\SkinDir\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\OpenFM\SkinDir\Metallica\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\OpenFM\SkinDir\Metallica\2.4.20\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\OpenFM\SkinDir\Metallica\2.4.20\flash\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Nero\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Nero\OnlineServices\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Nero\OnlineServices\FeedManager\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Mozilla\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Mozilla\Firefox\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\ozo60zrd.default\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\ozo60zrd.default\indexedDB\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\ozo60zrd.default\indexedDB\chrome\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\ozo60zrd.default\indexedDB\chrome\idb\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Mozilla\Firefox\Profiles\ozo60zrd.default\extensions\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url -> hxxp://gameoapp.com/?utm_source=gameo&utm_medium=Dlink&utm_campaign=ic15_PL InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Counter-Strike Global Offensive.url -> steam://rungameid/730 InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Counter-Strike.url -> steam://rungameid/10 InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade\GameSpy Arcade Help.url -> hxxp://www.gamespyarcade.com/help/ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade\GameSpy Arcade Website.url -> hxxp://www.gamespyarcade.com/ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade\GameSpy.com Gaming's Homepage.url -> hxxp://www.gamespy.com/ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade\Register GameSpy Arcade.url -> hxxp://www.gamespyarcade.com/register/ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> hxxp://www.ccleaner.com/ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Szablony\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\FrontPage\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\FrontPage\State\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Document Building Blocks\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Microsoft\Document Building Blocks\1045\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\GoldenGate\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2012.11.24.20.13.56.963\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\e9b4279a958eb733b970de5b6668ae82\HELP_DECRYPT.URL -> 0 InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\e6ea0a17f01a4ecec6b8548224d1f941\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\cf5fe015cdf876ba349ba53f642f7f3a\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\c85014c0741904e20066804fdf01d3b0\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\c48f00103b8247d5d299ef98d4492311\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\b13a551d1d8dca3dc0185851d161319b\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\98b9aae9c62198387cf1256d878cf5e4\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\8da1bdf8beddfc60bad4485b862a2b73\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\8bbca50ba35ed364eaac31f23e62fbae\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\89e5f729ccd36c783bff4c68d626ec87\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\7e3c73fb18841988b0defc2d548bda7f\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\6b590a554104971b48f75f0ce4c0e810\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\6aca35b6b56b848963670de8b0293a15\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\65d4807030f160b6d14c8799dd0ca0d3\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\51f2b7b14433aa22c67d1f4fc18943cd\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\4edffc937470dac55538639ebb718500\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\42b0225aa1481b3d841b2fd5a61d382a\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\3aeafa6c08047998004c05522f30b06b\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\37eda29ed2e320c50178b483e0f6863d\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\3668d1bef60c9aa0726b368b62000442\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\1fe3f1f99769ab16da991ae3d352ba13\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\1a086b419d05d33408310694b45f7158\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\08755b55149979e5c0b2c0f9ac735a8b\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\9944528.2011.11.24.14.21.48.375\Skins\068034424698f39fa82c070bf1445b24\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.10.09.08.19.21.788\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.10.09.08.19.21.788\Skins\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.10.09.08.19.21.788\Skins\cd74f0d8422dbe4479be7e305c99dccb\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.10.09.08.19.21.788\Skins\6fdac5df7689ad3adf002c6738ea0f69\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.10.09.08.19.21.788\Skins\5710b68c58e235982c97ae260b2c7350\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.10.09.08.19.21.788\Skins\3e8407e6f16222c99c5fcc30c7fa4a9d\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.06.09.15.54.55.792\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.06.09.15.54.55.792\Skins\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.06.09.15.54.55.792\Skins\bb37d64cf4cb70d453f7895a475b905f\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.06.09.15.54.55.792\Skins\6fdac5df7689ad3adf002c6738ea0f69\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.04.26.19.46.15.447\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.04.26.19.46.15.447\Skins\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.04.26.19.46.15.447\Skins\6fdac5df7689ad3adf002c6738ea0f69\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.04.24.18.49.16.484\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.04.24.18.49.16.484\Skins\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\4746063.2010.04.24.18.49.16.484\Skins\6fdac5df7689ad3adf002c6738ea0f69\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\39942909.2013.05.15.15.45.22.016\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\39942909.2013.05.15.15.45.22.016\Skins\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\39942909.2013.05.15.15.45.22.016\Skins\e0e95c02ef7aeef1c53d7bac3f98aafb\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\39942909.2013.05.15.15.45.22.016\Skins\d5211ea8082fa3205b9c54ab3c95330b\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\39942909.2013.05.15.15.45.22.016\Skins\a6a0348e2930b1ecfad8682b2e91f61f\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\39942909.2013.05.15.15.45.22.016\Skins\8504781cef9a5339945247ba1a49db6a\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\39942909.2013.05.15.15.45.22.016\Skins\595f4308503d2cd9806e38e83e9a74ea\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\_userdata\destroyed\39942909.2013.05.15.15.45.22.016\Skins\3da8d4b23e0d9dd8bc88d5f68d45a040\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\9944528\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\4746063\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\4746063\Skins\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\4746063\Skins\e6ea0a17f01a4ecec6b8548224d1f941\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\4746063\Skins\cf5fe015cdf876ba349ba53f642f7f3a\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Gadu-Gadu 10\44395803\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\FileZilla\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\DVD Flick\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\com.w3i.FlipToast\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\com.w3i.FlipToast\Local Store\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Balmora.pl\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Balmora.pl\mark\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\AvitoDvd\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\avidemux\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Audacity\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Audacity\Chains\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Adobe\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Adobe\Stock Photos CS3\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\Adobe\Flash Player\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\4Media\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\4Media\Video Editor 2\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\4Media\Video Editor 2\addir\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\4Media\Video Editor 2\addir\m-video-editor2\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\4Media\Video Editor 2\addir\m-video-editor2\gettingstarted\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\4Media\Video Editor 2\addir\m-video-editor2\gettingstarted\images\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Roaming\.minecraft\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\LocalLow\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\LocalLow\Sun\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\LocalLow\Sun\Java\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\LocalLow\Sun\Java\Deployment\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\LocalLow\CertifiedToolsToolbar\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\LocalLow\CertifiedToolbar\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\LocalLow\bearsharemediabartb\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Skype\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Skype\Apps\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\screenSHU\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\screenSHU\files\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Pokki\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Pokki\Pokkies\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\PMB Files\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\PMB Files\cert\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Opera\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Opera\Opera\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Opera\Opera\icons\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Opera\CProgram FilesOpera\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Opera\CProgram FilesOpera\icons\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Nokia\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Nokia\Nokia Ovi Player\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Nokia\Nokia Ovi Player\Art\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Nokia\Nokia Data Store\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Nokia\Nokia Data Store\DataBase\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Mozilla\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Mozilla\Firefox\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Mozilla\Firefox\Profiles\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Mozilla\Firefox\Profiles\ozo60zrd.default\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Windows Media\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Windows Media\12.0\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Windows Mail\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Windows Mail\Stationery\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Windows Mail\Backup\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Windows Mail\Backup\old\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Photo Acquisition\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Media Player\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Media Player\Pamięć podręczna grafiki\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Media Player\Pamięć podręczna grafiki\LocalMLS\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Internet Explorer\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\ehome\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Microsoft\Device Metadata\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Picasa2Albums\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Picasa2\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Picasa2\db3\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Storage\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\databases\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.pl_0.indexeddb.leveldb\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_portal.abczdrowie.pl_0.indexeddb.leveldb\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Extensions\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\7.3_0\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\7.3_0\img\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\databases\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Geckofx\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Geckofx\1.9\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Geckofx\1.9\DefaultProfile\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Blizzard Entertainment\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Blizzard Entertainment\System Survey\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Blizzard\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Blizzard\Hearthstone\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\BearShare\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\BearShare\Data\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Battle.net\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\AVG Secure Search\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\AVG Secure Search\SiteSafety\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Ares\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ InternetURL: C:\Users\XX\AppData\Local\Ares\My Shared Folder\HELP_DECRYPT.URL -> hxxp://paytoc4gtpn5czl2.tostotor.com/1Qhk1aQ ==================== End of log =============================