Fix result of Farbar Recovery Scan Tool (x86) Version:29-10-2015 Ran by Krzysztof (2015-10-30 09:46:01) Run:1 Running from C:\Documents and Settings\Krzysztof\My Documents\Pobrane Loaded Profiles: Krzysztof (Available Profiles: Krzysztof & Gość & Administrator) Boot Mode: Safe Mode (minimal) ============================================== fixlist content: ***************** CloseProcesses: R2 aroductpeo; C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe [46592 2015-10-29] () [File not signed] R2 Concom; C:\Program Files\Concom\Concom.exe [379904 2015-10-25] () [File not signed] <==== ATTENTION S2 globalUpdate; C:\Program Files\globalUpdate\Update\globalupdate.exe [68608 2015-10-29] (globalUpdate) [File not signed] <==== ATTENTION S3 globalUpdatem; C:\Program Files\globalUpdate\Update\globalupdate.exe [68608 2015-10-29] (globalUpdate) [File not signed] <==== ATTENTION R1 QMIEProtect; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMIEProtect.sys [49976 2015-08-18] () R2 QQPCRTP; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCRTP.exe [301728 2015-09-15] (Tencent) R2 QQSysMon; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQSysMon.sys [108472 2015-09-26] (电脑管家) R2 SSFK; C:\Program Files\SFK\SSFK.exe [458400 2015-09-26] (TODO: <公司名>) S3 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator.sys [114520 2000-12-31] (Tencent) S3 TAOFrame; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TAOFrame.exe [293856 2015-09-26] (Tencent) R1 TAOKernelDriver; C:\WINDOWS\System32\Drivers\TAOKernelXP.sys [139064 2015-09-26] (Tencent Technology(Shenzhen) Company Limited) R3 TFsFlt; C:\WINDOWS\System32\Drivers\TFsFlt.sys [150072 2015-09-26] (电脑管家) R1 TSCPM; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\tscpm.sys [43448 2015-09-26] (电脑管家) R1 TSDefenseBt; C:\WINDOWS\System32\DRIVERS\TSDefenseBt.sys [14008 2015-09-26] (Tencent) R0 TsFltMgr; C:\WINDOWS\System32\drivers\TsFltMgr.sys [124792 2015-09-26] (电脑管家) R1 TSKSP; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSKsp.sys [204920 2015-09-26] (电脑管家) S3 TSSK; C:\WINDOWS\System32\tssk.sys [67896 2015-09-26] (电脑管家) R1 TSSysKit; C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSSysKit.sys [101560 2015-09-26] (电脑管家) R2 WdsManPro; C:\Documents and Settings\All Users\Application Data\2WdsManPro2\WdsManPro.exe [442504 2015-09-26] (DTools LIMITED) S1 ppfd_vt_1_10_0_24; system32\drivers\ppfd_vt_1_10_0_24.sys [X] S1 wwfd_vt_1_10_0_24; system32\drivers\wwfd_vt_1_10_0_24.sys [X] Task: C:\WINDOWS\Tasks\469fcbcc-315d-4dd5-9804-212abb2e3cb9-1-6.job => C:\Program Files\GoHD\469fcbcc-315d-4dd5-9804-212abb2e3cb9-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-1-6.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-10_user.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-10.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-3.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-3.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-5.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-6.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-7.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\6d0ac05c-4429-4e4d-bcea-abd79f29b20e-1-6.job => C:\Program Files\CinemaP-1.9cV26.09\6d0ac05c-4429-4e4d-bcea-abd79f29b20e-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-6.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-7.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-4.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-4.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-5.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-6.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-7.job => C:\Program Files\Object Browser\7ac4ca75-d021-44c5-ba78-4c00550bafe6-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-1-6.job => C:\Program Files\SavePass 1.1\a4573ab7-8417-4109-8219-08f1d1efe114-1-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-1-7.job => C:\Program Files\SavePass 1.1\a4573ab7-8417-4109-8219-08f1d1efe114-1-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-4.job => C:\Program Files\SavePass 1.1\a4573ab7-8417-4109-8219-08f1d1efe114-4.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-5.job => C:\Program Files\SavePass 1.1\a4573ab7-8417-4109-8219-08f1d1efe114-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Advanced System~Protector.job => C:\Program Files\ASP\AspManager.exe Task: C:\WINDOWS\Tasks\Cukoqje4zpacXzv1vzrLABj8CQG.job => C:\Documents and Settings\Krzysztof\Application Data\Cukoqje4zpacXzv1vzrLABj8CQG.exe Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\IaKVQlxEQ3T35j.job => C:\Documents and Settings\Krzysztof\Application Data\IaKVQlxEQ3T35j.exe Task: C:\WINDOWS\Tasks\PKFkn4RDDh2SIS8ZZ.job => C:\Documents and Settings\Krzysztof\Application Data\PKFkn4RDDh2SIS8ZZ.exe Task: C:\WINDOWS\Tasks\SimpleFiles Update Service.job => C:\Program Files\SimpleFilesUpdater\SimpleFilesUpdater.exehxxp:/simple-files.com Task: C:\WINDOWS\Tasks\temp_50278e6d-151b-4cf5-9e8d-31ed23fbc614-10_user.job => C:\Program Files\CinemaPlus-3.2cV26.09\50278e6d-151b-4cf5-9e8d-31ed23fbc614-10.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Xmas.job => C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Xmas\xBin\Xmas.dll HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service" HKLM\...\Run: [] => [X] HKLM\...\Run: [ QQPCTray] => "C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCTray.exe" /regrun HKLM\...\Run: [gmsd_pl_005010096] => [X] HKLM\...\Run: [mbot_pl_014010096] => [X] HKLM\...\Run: [mbot_pl_014010102] => [X] HKLM\...\Run: [upmbot_pl_014010102.exe] => C:\Documents and Settings\Krzysztof\Local Settings\Application Data\mbot_pl_014010102\upmbot_pl_014010102.exe -runhelper HKLM\...\Run: [SunJavaUpdateSched] => "C:\Program Files\Java\jre7\bin\jusched.exe" HKLM\...\Winlogon: [Shell] explorer.exe, [x ] () HKU\S-1-5-21-1960408961-682003330-839522115-1004\...\Run: [BingSvc] => C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation) ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMGCShellExt.dll [2015-09-26] (Tencent) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File CustomCLSID: HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CustomCLSID: HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Documents and Settings\Krzysztof\Application Data\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=95751091_hao_pg HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1443293666&z=a872e2bb7050c3b9111ef6agaz0zdc8o0t3c0q0q2q&from=amt&uid=hitachixhts545025b9sa02_100719pbl200csh200zvx HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.hao123.com/?tn=95751091_hao_pg hxxp://www.gazeta.pl/0,0.html?p=156 HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1443293666&z=a872e2bb7050c3b9111ef6agaz0zdc8o0t3c0q0q2q&from=amt&uid=hitachixhts545025b9sa02_100719pbl200csh200zvx HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "hxxp://www.only-search.com/?babsrc=NT_kms&affID=132174" <======= ATTENTION SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-1960408961-682003330-839522115-1004 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-1960408961-682003330-839522115-1004 -> {36D00200-6447-4870-A80F-C551B17BDE8F} URL = hxxp://www.only-search.com/?babsrc=SP_kms&affID=132174&q={searchTerms}&r=965 SearchScopes: HKU\S-1-5-21-1960408961-682003330-839522115-1004 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUSyDMFv8NAOf72g_52TO1Q8T9E1z2NFGDHko4e8BbYNV6e-AVbiqCN2a0fQhKzKTNQTY9Tmtm8gq3gdyIIACRX4xZCnmDTMzrVdBCl1wGaSuGqFTt2SOrkLvi9FyG4ABhng,,&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - iexplore.exe FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-29] (globalUpdate) FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-10-29] (globalUpdate) GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION StartMenuInternet: chrome.exe - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.istartsurf.com/?type=sc&ts=1443295299&z=796cc5cf51a969ca0186f3egczdz4c1odt6w6gde8t&from=face&uid=HitachiXHTS545025B9SA02_100719PBL200CSH200ZVX Facebook Update Helper (Version: 1.2.205.0 - Google Inc.) Hidden AV: 电脑管家系统防护 (Enabled - Up to date) {9AAC524A-BF34-49b0-91D2-71838CBB8110} DeleteKey: HKCU\Software\Google\Chrome\Extensions DeleteKey: HKLM\SOFTWARE\Google\Chrome\Extensions DeleteKey: HKLM\SOFTWARE\Mozilla\Firefox\Extensions DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^IMVU.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^Logitech . Rejestracja produktu.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OptimumLink.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OptimumPCtoTV.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^ybcrlnsnniggidoderh.lnk DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EvtMgr6 DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GG DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Jing DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ORAHSSSessionManager DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TP-Link USB Printer Controller DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaP-1.9cV26.09 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV26.09 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoHD DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1 DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes CMD: for %i in ("C:\Program Files\globalUpdate\Update\1.3.25.0\*.dll") do regsvr32 /u /s %i CMD: for %i in ("C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\*.dll") do regsvr32 /u /s %i C:\Documents and Settings\All Users\Application Data\2WdsManPro2 C:\Documents and Settings\All Users\Application Data\TEMP C:\Documents and Settings\All Users\Start Menu\电脑管家.lnk C:\Documents and Settings\All Users\Start Menu\强力卸载电脑上的软件 .lnk C:\Documents and Settings\Gość\Favorites\Links\*.url C:\Documents and Settings\Gość\Start Menu\7Burn.lnk C:\Documents and Settings\Gość\Start Menu\Programs\FileZilla FTP Client C:\Documents and Settings\Krzysztof\sqlite3.dll C:\Documents and Settings\Krzysztof\Application Data\cTEckRNVP8 C:\Documents and Settings\Krzysztof\Application Data\Cukoqje4zpacXzv1vzrLABj8CQG C:\Documents and Settings\Krzysztof\Application Data\IaKVQlxEQ3T35j C:\Documents and Settings\Krzysztof\Application Data\NevoSoft Gameslog.txt C:\Documents and Settings\Krzysztof\Application Data\PKFkn4RDDh2SIS8ZZ C:\Documents and Settings\Krzysztof\Application Data\GG C:\Documents and Settings\Krzysztof\Desktop\Continue kED installation.lnk C:\Documents and Settings\Krzysztof\Favorites\Bing.url C:\Documents and Settings\Krzysztof\Favorites\Discover Bing.url C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN*.url C:\Documents and Settings\Krzysztof\Favorites\Microsoft Websites\Microsoft Showcase.url C:\Documents and Settings\Krzysztof\Favorites\Microsoft Websites\Microsoft.com.url C:\Documents and Settings\Krzysztof\Favorites\Links\go.microsoft.com-fwlink-LinkId=121315.url C:\Documents and Settings\Krzysztof\Favorites\Links\ieonline.microsoft.com-#ieslice.url C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites*.url C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe.config C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook C:\Documents and Settings\Krzysztof\Local Settings\Application Data\globalUpdate C:\Documents and Settings\Krzysztof\Local Settings\Application Data\mbot_pl_014010102 C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Microsoft\BingSvc C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Xmas C:\Documents and Settings\Krzysztof\Start Menu\Programs\腾讯软件 C:\Program Files\path5.ini C:\Program Files\5C8CAC0A-1443294427-5799-9460-C2325843CB2C C:\Program Files\ASP C:\Program Files\CinemaP-1.9cV26.09 C:\Program Files\CinemaPlus-3.2cV26.09 C:\Program Files\Concom C:\Program Files\globalUpdate C:\Program Files\GoHD C:\Program Files\Mozilla Firefox\browser\searchplugins C:\Program Files\Mozilla Firefox\plugins C:\Program Files\Object Browser C:\Program Files\RayDld C:\Program Files\SavePass 1.1 C:\Program Files\SFK C:\Program Files\SimpleFilesUpdater C:\Program Files\Tencent C:\Program Files\Common Files\Tencent C:\WINDOWS\DUMP*.tmp C:\WINDOWS\QMNetworkMgr.ini C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\WINDOWS\pss\McAfee Security Scan Plus.lnkCommon Startup C:\WINDOWS\pss\IMVU.lnkStartup C:\WINDOWS\pss\Logitech . Rejestracja produktu.lnkStartup C:\WINDOWS\pss\OpenOffice.org 3.2.lnkStartup C:\WINDOWS\pss\OptimumLink.lnkStartup C:\WINDOWS\pss\OptimumPCtoTV.lnkStartup C:\WINDOWS\pss\ybcrlnsnniggidoderh.lnkStartup C:\WINDOWS\System32\tssk.sys C:\WINDOWS\system32\Drivers\TAOAccelerator.sys C:\WINDOWS\System32\Drivers\TAOKernelXP.sys C:\WINDOWS\System32\Drivers\TFsFlt.sys C:\WINDOWS\System32\Drivers\TsFltMgr.sys C:\WINDOWS\System32\Drivers\TSDefenseBt.sys Folder: C:\extensions CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files\Common Files" CMD: dir /a "C:\Documents and Settings\All Users\Application Data" CMD: dir /a "C:\Documents and Settings\Krzysztof\Application Data" CMD: dir /a "C:\Documents and Settings\Krzysztof\Local Settings\Application Data" ***************** Processes closed successfully. aroductpeo => service removed successfully. Concom => service removed successfully. globalUpdate => service removed successfully. globalUpdatem => service removed successfully. QMIEProtect => service removed successfully. QQPCRTP => service removed successfully. QQSysMon => service removed successfully. SSFK => service removed successfully. TAOAccelerator => service removed successfully. TAOFrame => service removed successfully. TAOKernelDriver => service removed successfully. TFsFlt => service removed successfully. TSCPM => service not found. TSDefenseBt => service removed successfully. TsFltMgr => Unable to stop service. TsFltMgr => service removed successfully. TSKSP => service not found. TSSK => service removed successfully. TSSysKit => service not found. WdsManPro => service removed successfully. ppfd_vt_1_10_0_24 => service removed successfully. wwfd_vt_1_10_0_24 => service removed successfully. C:\WINDOWS\Tasks\469fcbcc-315d-4dd5-9804-212abb2e3cb9-1-6.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-1-6.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-10_user.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-3.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-5.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-6.job => moved successfully C:\WINDOWS\Tasks\50278e6d-151b-4cf5-9e8d-31ed23fbc614-7.job => moved successfully C:\WINDOWS\Tasks\6d0ac05c-4429-4e4d-bcea-abd79f29b20e-1-6.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-6.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-1-7.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-4.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-5.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-6.job => moved successfully C:\WINDOWS\Tasks\7ac4ca75-d021-44c5-ba78-4c00550bafe6-7.job => moved successfully C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-1-6.job => moved successfully C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-1-7.job => moved successfully C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-4.job => moved successfully C:\WINDOWS\Tasks\a4573ab7-8417-4109-8219-08f1d1efe114-5.job => moved successfully C:\WINDOWS\Tasks\Advanced System~Protector.job => moved successfully C:\WINDOWS\Tasks\Cukoqje4zpacXzv1vzrLABj8CQG.job => moved successfully C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => moved successfully C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => moved successfully C:\WINDOWS\Tasks\IaKVQlxEQ3T35j.job => moved successfully C:\WINDOWS\Tasks\PKFkn4RDDh2SIS8ZZ.job => moved successfully C:\WINDOWS\Tasks\SimpleFiles Update Service.job => moved successfully C:\WINDOWS\Tasks\temp_50278e6d-151b-4cf5-9e8d-31ed23fbc614-10_user.job => moved successfully C:\WINDOWS\Tasks\Xmas.job => moved successfully "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP" => key removed successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP" => key removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ QQPCTray => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\gmsd_pl_005010096 => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mbot_pl_014010096 => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mbot_pl_014010102 => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\upmbot_pl_014010102.exe => value removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value not found. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value restored successfully HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Run\\BingSvc => value removed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\.QMDeskTopGCIcon" => key removed successfully. "HKCR\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6}" => key removed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. "HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}" => key removed successfully. "HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}" => key removed successfully. "HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}" => key removed successfully. "HKU\S-1-5-21-1960408961-682003330-839522115-1004_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}" => key removed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => value removed successfully. HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully. HKU\S-1-5-21-1960408961-682003330-839522115-1004\Software\Microsoft\Internet Explorer\Main\\SearchAssistant => value removed successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ielnksrch" => key removed successfully. HKCR\CLSID\ielnksrch => key not found. HKU\S-1-5-21-1960408961-682003330-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully. "HKU\S-1-5-21-1960408961-682003330-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{36D00200-6447-4870-A80F-C551B17BDE8F}" => key removed successfully. HKCR\CLSID\{36D00200-6447-4870-A80F-C551B17BDE8F} => key not found. "HKU\S-1-5-21-1960408961-682003330-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}" => key removed successfully. HKCR\CLSID\{ielnksrch} => key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully "HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => key removed successfully. C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll => moved successfully "HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => key removed successfully. C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll => not found. C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully "HKLM\SOFTWARE\Policies\Google" => key removed successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => value restored successfully HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D40F6104-6988-47C0-93F2-A66D5DA120A2}\\SystemComponent => value removed successfully. AV: 电脑管家系统防护 (Enabled - Up to date) {9AAC524A-BF34-49b0-91D2-71838CBB8110} => removed successfully. HKCU\Software\Google\Chrome\Extensions => could not remove at first attempt (ErrorCode: C0000121), see next line. HKCU\Software\Google\Chrome\Extensions => key removed successfully. HKLM\SOFTWARE\Google\Chrome\Extensions => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Google\Chrome\Extensions => key removed successfully. HKLM\SOFTWARE\Mozilla\Firefox\Extensions => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^IMVU.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^Logitech . Rejestracja produktu.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OptimumLink.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^OptimumPCtoTV.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Krzysztof^Start Menu^Programs^Startup^ybcrlnsnniggidoderh.lnk => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EvtMgr6 => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GG => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Jing => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ORAHSSSessionManager => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched => key removed successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TP-Link USB Printer Controller => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC} => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaP-1.9cV26.09 => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV26.09 => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoHD => key removed successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1 => key removed successfully. HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List => key removed successfully. HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List => key removed successfully. HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main => could not remove at first attempt (ErrorCode: C0000121), see next line. HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main => key removed successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main => key not found. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main => key removed successfully. HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes => key removed successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes => key not found. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes => could not remove at first attempt (ErrorCode: C0000121), see next line. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes => key removed successfully. ========= for %i in ("C:\Program Files\globalUpdate\Update\1.3.25.0\*.dll") do regsvr32 /u /s %i ========= ========= End of CMD: ========= ========= for %i in ("C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\*.dll") do regsvr32 /u /s %i ========= ========= End of CMD: ========= C:\Documents and Settings\All Users\Application Data\2WdsManPro2 => moved successfully C:\Documents and Settings\All Users\Application Data\TEMP => moved successfully C:\Documents and Settings\All Users\Start Menu\电脑管家.lnk => moved successfully C:\Documents and Settings\All Users\Start Menu\强力卸载电脑上的软件 .lnk => moved successfully =========== "C:\Documents and Settings\Gość\Favorites\Links\*.url" ========== C:\Documents and Settings\Gość\Favorites\Links\Free Hotmail.url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\ieonline.microsoft.com-#ieslice.url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\Suggested Sites (2).url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\Suggested Sites (3).url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\Suggested Sites.url => moved successfully C:\Documents and Settings\Gość\Favorites\Links\Web Slice Gallery.url => moved successfully ========= End -> "C:\Documents and Settings\Gość\Favorites\Links\*.url" ======== C:\Documents and Settings\Gość\Start Menu\7Burn.lnk => moved successfully C:\Documents and Settings\Gość\Start Menu\Programs\FileZilla FTP Client => moved successfully C:\Documents and Settings\Krzysztof\sqlite3.dll => moved successfully C:\Documents and Settings\Krzysztof\Application Data\cTEckRNVP8 => moved successfully C:\Documents and Settings\Krzysztof\Application Data\Cukoqje4zpacXzv1vzrLABj8CQG => moved successfully C:\Documents and Settings\Krzysztof\Application Data\IaKVQlxEQ3T35j => moved successfully C:\Documents and Settings\Krzysztof\Application Data\NevoSoft Gameslog.txt => moved successfully C:\Documents and Settings\Krzysztof\Application Data\PKFkn4RDDh2SIS8ZZ => moved successfully C:\Documents and Settings\Krzysztof\Application Data\GG => moved successfully "C:\Documents and Settings\Krzysztof\Desktop\Continue kED installation.lnk" => not found. C:\Documents and Settings\Krzysztof\Favorites\Bing.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Discover Bing.url => moved successfully =========== "C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN*.url" ========== C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN Autos.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN Entertainment.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN Lifestyle.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN Money.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSNBC News.url => moved successfully ========= End -> "C:\Documents and Settings\Krzysztof\Favorites\MSN Websites\MSN*.url" ======== C:\Documents and Settings\Krzysztof\Favorites\Microsoft Websites\Microsoft Showcase.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Microsoft Websites\Microsoft.com.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\go.microsoft.com-fwlink-LinkId=121315.url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\ieonline.microsoft.com-#ieslice.url => moved successfully =========== "C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites*.url" ========== C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (10).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (11).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (12).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (13).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (14).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (15).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (16).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (17).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (18).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (19).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (2).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (20).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (21).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (22).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (23).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (24).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (25).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (26).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (27).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (28).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (29).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (3).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (30).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (31).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (32).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (33).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (34).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (35).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (36).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (37).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (38).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (39).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (4).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (40).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (41).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (42).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (43).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (44).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (45).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (46).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (47).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (48).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (49).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (5).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (50).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (51).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (52).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (53).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (54).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (55).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (56).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (57).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (58).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (59).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (6).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (60).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (61).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (62).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (63).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (64).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (7).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (8).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites (9).url => moved successfully C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites.url => moved successfully ========= End -> "C:\Documents and Settings\Krzysztof\Favorites\Links\Suggested Sites*.url" ======== C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Planetjob.exe.config => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Facebook => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\globalUpdate => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\mbot_pl_014010102 => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Microsoft\BingSvc => moved successfully C:\Documents and Settings\Krzysztof\Local Settings\Application Data\Xmas => moved successfully C:\Documents and Settings\Krzysztof\Start Menu\Programs\腾讯软件 => moved successfully C:\Program Files\path5.ini => moved successfully C:\Program Files\5C8CAC0A-1443294427-5799-9460-C2325843CB2C => moved successfully "C:\Program Files\ASP" => not found. C:\Program Files\CinemaP-1.9cV26.09 => moved successfully C:\Program Files\CinemaPlus-3.2cV26.09 => moved successfully C:\Program Files\Concom => moved successfully C:\Program Files\globalUpdate => moved successfully C:\Program Files\GoHD => moved successfully C:\Program Files\Mozilla Firefox\browser\searchplugins => moved successfully C:\Program Files\Mozilla Firefox\plugins => moved successfully "C:\Program Files\Object Browser" => not found. C:\Program Files\RayDld => moved successfully C:\Program Files\SavePass 1.1 => moved successfully C:\Program Files\SFK => moved successfully "C:\Program Files\SimpleFilesUpdater" => not found. C:\Program Files\Tencent => moved successfully C:\Program Files\Common Files\Tencent => moved successfully =========== "C:\WINDOWS\DUMP*.tmp" ========== C:\WINDOWS\DUMP365d.tmp => moved successfully ========= End -> "C:\WINDOWS\DUMP*.tmp" ======== C:\WINDOWS\QMNetworkMgr.ini => moved successfully C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => moved successfully C:\WINDOWS\pss\McAfee Security Scan Plus.lnkCommon Startup => moved successfully "C:\WINDOWS\pss\IMVU.lnkStartup" => not found. C:\WINDOWS\pss\Logitech . Rejestracja produktu.lnkStartup => moved successfully C:\WINDOWS\pss\OpenOffice.org 3.2.lnkStartup => moved successfully C:\WINDOWS\pss\OptimumLink.lnkStartup => moved successfully C:\WINDOWS\pss\OptimumPCtoTV.lnkStartup => moved successfully C:\WINDOWS\pss\ybcrlnsnniggidoderh.lnkStartup => moved successfully C:\WINDOWS\System32\tssk.sys => moved successfully C:\WINDOWS\system32\Drivers\TAOAccelerator.sys => moved successfully C:\WINDOWS\System32\Drivers\TAOKernelXP.sys => moved successfully C:\WINDOWS\System32\Drivers\TFsFlt.sys => moved successfully C:\WINDOWS\System32\Drivers\TsFltMgr.sys => moved successfully C:\WINDOWS\System32\Drivers\TSDefenseBt.sys => moved successfully ========================= Folder: C:\extensions ======================== 2015-10-23 08:09 - 2015-10-23 08:09 - 0000000 ____D () C:\extensions\bingsearch.full@microsoft.com 2015-10-23 08:09 - 2015-10-23 08:09 - 0005494 _____ () C:\extensions\bingsearch.full@microsoft.com\bootstrap.js 2015-10-23 08:09 - 2015-10-23 08:09 - 0000023 _____ () C:\extensions\bingsearch.full@microsoft.com\chrome.manifest 2015-10-23 08:09 - 2015-10-23 08:09 - 0002989 _____ () C:\extensions\bingsearch.full@microsoft.com\icon.png 2015-10-23 08:09 - 2015-10-23 08:09 - 0000744 _____ () C:\extensions\bingsearch.full@microsoft.com\install.rdf 2015-10-23 08:09 - 2015-10-23 08:09 - 0013777 _____ () C:\extensions\bingsearch.full@microsoft.com\search-settings.jsm ====== End of Folder: ====== ========= dir /a "C:\Program Files" ========= Volume in drive C is BOOTCAMP Volume Serial Number is D8BF-6409 Directory of C:\Program Files 2015-10-30 09:46 . 2015-10-30 09:46 .. 2015-09-27 13:15 20717d47-27d3-4fd5-849d-70bab7fdb68a 2015-10-13 17:39 Adobe 2015-09-27 13:15 aeafcc87-810f-4dcb-a286-bd94d8f90ac3 2012-01-08 21:01 ALLPlayer 2011-11-18 13:35 Apple Software Update 2014-02-18 15:39 Atlassian 2012-07-26 23:59 Autodesk 2012-01-04 22:04 Boot Camp 2015-09-27 13:15 c620fa05-8fd3-422d-8b48-6fb2e023fb34 2015-10-29 21:06 c6fdae68-5b2b-49d1-904d-708dc40b305a 2011-10-23 21:41 CasualGameBox 2012-01-08 20:42 CCleaner 2011-01-19 12:19 Cisco Systems 2015-10-30 09:34 Common Files 2010-08-05 03:53 ComPlus Applications 2015-09-27 13:15 de2a3e96-eab7-4ac0-815d-d28e00b7f723 2010-08-05 04:22 DIFX 2015-10-30 09:40 Emsisoft Anti-Malware 2015-09-27 13:15 f9138745-f797-4a7e-98f2-acd48c761d2f 2015-09-26 20:23 Feed Notifier 2015-10-16 08:16 FileZilla FTP Client 2010-08-24 14:58 FoxArc Screen Capture 2015-10-13 17:40 Free Sound Recorder 2015-09-27 13:15 gmsd_pl_005010096 2015-05-06 17:22 Google 2015-07-16 08:24 Hewlett-Packard 2015-07-16 08:24 HP 2010-08-26 14:26 ICTV 2010-08-05 04:24 IDT 2015-05-28 19:19 InstallShield Installation Information 2000-12-31 23:00 Internet Explorer 2015-10-30 09:34 Java 2012-01-08 20:40 jv16 PowerTools 2011 2014-07-01 14:51 K-Lite Codec Pack 2015-04-02 07:17 kED 2015-09-27 13:15 mbot_pl_014010096 2014-02-16 14:01 Messenger 2012-09-24 16:24 Microsoft 2015-05-31 18:38 Microsoft ATS 2010-10-06 08:52 Microsoft CAPICOM 2.1.0.2 2010-08-05 03:56 microsoft frontpage 2010-08-04 15:07 Microsoft Office 2015-10-23 08:10 Microsoft Silverlight 2010-08-04 15:07 Microsoft Visual Studio 2010-10-06 08:48 Microsoft Works 2012-08-15 16:12 Microsoft XNA 2015-09-26 20:44 Microsoft.NET 2014-11-21 11:04 Mioplanet 2010-08-05 04:25 Motorola 2001-01-01 03:26 Movie Maker 2015-10-05 11:56 Mozilla Firefox 2000-12-31 23:01 Mozilla Maintenance Service 2010-08-04 15:07 MSBuild 2010-08-05 03:52 MSN 2010-08-05 03:52 MSN Gaming Zone 2010-12-25 08:19 MSXML 4.0 2010-08-23 11:29 MSXML 6.0 2014-12-27 19:54 NCH Software 2013-08-23 16:06 NetMeeting 2011-03-02 12:53 Norton Security Scan 2011-03-02 12:50 NortonInstaller 2015-07-03 13:39 Notepad++ 2013-06-28 09:55 NotePage 2010-08-05 04:21 NVIDIA Corporation 2010-08-05 03:52 Online Services 2014-08-07 14:02 OpenVPN Technologies 2015-03-19 14:14 Opera 2001-01-01 03:00 Outlook Express 2013-06-06 19:26 PDFCreator 2011-05-16 15:17 PFConfig 2015-02-03 14:43 PITy 2015-09-26 20:32 predm 2014-12-27 19:58 QuickTime 2011-11-20 18:09 RealArcade 2010-08-05 04:25 Realtek 2010-12-27 09:19 Reference Assemblies 2015-04-13 08:24 Skype 2011-11-08 22:03 TuneUp Utilities 2012 2010-08-05 04:16 Uninstall Information 2011-01-19 12:23 VpnProxy 2013-08-23 16:09 Windows Media Player 2013-08-23 16:06 Windows NT 2010-08-05 03:55 WindowsUpdate 2014-02-16 14:01 WinRAR 2010-09-13 14:33 WinSCP 2015-09-23 21:28 Xenocode 2010-08-05 03:56 xerox 2013-08-22 16:32 Yahoo! 0 File(s) 0 bytes 90 Dir(s) 7685193728 bytes free ========= End of CMD: ========= ========= dir /a "C:\Program Files\Common Files" ========= Volume in drive C is BOOTCAMP Volume Serial Number is D8BF-6409 Directory of C:\Program Files\Common Files 2015-10-30 09:46 . 2015-10-30 09:46 .. 2015-06-03 12:22 Adobe 2015-02-25 10:46 Adobe-BackupByPhotoshopPortable 2012-05-30 11:51 Apple 2011-11-08 19:48 AVSMedia 2012-09-02 22:52 DESIGNER 2011-01-19 12:19 Deterministic Networks 2010-09-09 15:42 France Telecom 2013-02-28 15:35 Hewlett-Packard 2015-03-31 21:50 HP 2012-05-15 12:28 InstallShield 2011-11-08 21:28 LogiShrd 2012-07-22 22:27 Macrovision Shared 2000-12-31 23:00 McAfee 2014-07-18 15:47 Mercury Interactive 2015-09-26 20:44 Microsoft Shared 2010-08-05 03:54 MSSoap 2012-06-26 19:15 Oberon Media 2010-08-04 20:41 ODBC 2010-08-05 03:54 Services 2015-04-13 08:24 Skype 2010-08-04 20:41 SpeechEngines 2012-07-17 22:04 SWiSHzone.com 2013-08-26 10:12 System 2013-08-21 01:23 Wise Installation Wizard 0 File(s) 0 bytes 26 Dir(s) 7685193728 bytes free ========= End of CMD: ========= ========= dir /a "C:\Documents and Settings\All Users\Application Data" ========= Volume in drive C is BOOTCAMP Volume Serial Number is D8BF-6409 Directory of C:\Documents and Settings\All Users\Application Data 2015-10-30 09:46 . 2015-10-30 09:46 .. 2011-06-14 23:44 aliasworlds 2014-09-23 20:38 57 Ament.ini 2012-01-04 21:47 Apple 2010-08-16 06:13 Apple Computer 2013-08-22 09:31 Ashampoo 2012-07-26 23:51 Autodesk 2000-12-31 23:01 AVAST Software 2013-11-12 11:45 Big Fish 2013-07-30 20:50 Big Fish Games 2013-11-12 11:45 BigFishCache 2013-07-10 21:45 BigFishGamesCache 2012-01-29 00:17 casualArts 2012-09-23 16:53 Common Files 2012-08-16 12:42 Corel 2012-07-27 07:56 CorelDRAW Graphics Suite X5 2012-07-26 22:53 CorelDRAW Graphics Suite X6 2012-11-11 16:59 DailyMagic 2010-08-04 20:41 62 desktop.ini 2015-04-16 09:16 Devart 2015-09-26 20:23 DWdsManProD 2012-11-10 19:39 Elephant Games 2015-09-27 12:06 Emsisoft 2011-01-04 14:38 FarmFrenzy3 2011-10-22 22:17 FarmFrenzy_Vikings 2015-03-20 20:49 firebird 2012-07-22 22:39 FLEXnet 2015-06-21 16:30 FreeHideIP 2010-12-28 21:55 Fugazo 2012-01-07 20:42 Gadu-Gadu 10 2013-02-10 11:41 GG 2013-08-08 16:23 GoBit Games 2012-06-24 21:24 Gogii 2014-09-26 07:06 HP 2015-07-16 08:46 HP Product Assistant 2010-12-30 16:01 hps 2015-03-31 21:56 14048 hpzinstall.log 2012-10-01 08:03 IsolatedStorage 2014-04-08 16:15 Komputerowa Gratka 2011-11-08 21:27 Logishrd 2014-05-18 23:03 Malwarebytes 2012-02-02 20:40 Maximize Games 2014-07-10 12:35 McAfee 2012-01-12 20:57 MediaArt 2013-08-23 16:24 Microsoft 2015-09-26 20:44 Microsoft Help 2012-07-22 22:28 147 Microsoft.SqlServer.Compact.351.32.bc 2012-04-26 06:30 Mozilla 2012-06-28 21:42 MumboJumbo 2014-12-24 10:33 NCH Software 2011-03-02 12:53 Norton 2011-03-02 12:50 NortonInstaller 2012-07-08 21:47 Oberon Media 2011-12-19 23:27 Odian Games 2012-06-09 14:14 OpenFM 2012-06-01 22:41 Orchid Games 2001-01-01 00:01 Package Cache 2012-03-01 15:43 PITy 2012-03-21 20:14 PlayFirst 2011-12-30 23:03 PlayPond 2012-07-08 21:49 Playrix Entertainment 2012-07-27 07:57 Protexis 2012-07-27 09:09 regid.1986-12.com.adobe 2012-02-25 23:32 rionix 2010-12-08 14:03 ScreenVCR 2015-09-26 20:20 ShopperPro 2015-06-18 16:03 Skype 2011-07-18 15:13 Skype Extras 2012-01-29 22:43 SpecialBit 2012-06-15 22:00 SulusGames 2010-09-27 20:21 Sun 2011-01-03 20:49 TaxMachine 2015-09-27 10:28 Tencent 2012-01-30 21:06 Top Evidence 2011-11-08 20:29 TuneUp Software 2011-08-09 14:53 Windows Genuine Advantage 2013-08-22 16:32 Yahoo! 2015-09-26 20:26 178 {262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat 2011-11-08 20:28 {32364CEA-7855-4A3C-B674-53D8E9B97936} 2012-01-04 21:48 {429CAD59-35B1-4DBC-BB6D-1DB246563521} 5 File(s) 14492 bytes 76 Dir(s) 7685189632 bytes free ========= End of CMD: ========= ========= dir /a "C:\Documents and Settings\Krzysztof\Application Data" ========= Volume in drive C is BOOTCAMP Volume Serial Number is D8BF-6409 Directory of C:\Documents and Settings\Krzysztof\Application Data 2015-10-30 09:46 . 2015-10-30 09:46 .. 2014-02-11 21:10 .mono 2015-09-26 20:54 11732 2012-06-23 15:32 2monkeys 2012-06-26 18:01 A2 Entertainment 2015-06-08 09:13 Adobe 2012-04-12 16:40 132 Adobe GIF Format CS5 Prefs 2012-04-27 07:26 132 Adobe PNG Format CS5 Prefs 2012-01-28 01:45 Alawar Entertainment 2012-08-14 20:47 AlawarEntertainment 2011-11-08 23:01 aliasworlds 2011-11-18 17:51 Apple Computer 2015-03-20 21:40 ArcSoft 2012-06-27 22:08 Artifex Mundi 2013-03-09 14:18 Artogon 2013-08-22 14:22 Ashampoo 2012-07-26 22:51 Autodesk 2011-12-30 18:26 Awem 2013-03-23 18:00 BlamGames 2015-02-02 12:14 BlueLabsSoftware 2011-11-16 17:27 CallingID 2012-01-29 00:17 casualArts 2012-04-12 10:32 com.adobe.downloadassistant.AdobeDownloadAssistant 2012-07-27 07:56 Corel 2012-11-11 16:59 DailyMagic 2012-03-22 23:04 Dark Blue Games 2013-11-09 13:14 DarkManor 2014-11-21 11:05 Desktop Apps 2010-08-04 20:41 62 desktop.ini 2015-04-16 09:17 Devart 2012-08-15 16:36 DominiGames 2010-12-22 15:56 DonationCoder 2014-03-16 11:46 e-Deklaracje 2014-03-16 11:46 e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 2012-05-28 22:23 Eipix 2013-03-09 15:57 Elephant Games 2015-05-28 19:04 ElevatedDiagnostics 2011-11-08 22:38 Enlightenus2SE_BFG 2012-03-12 21:12 EntwinedSoD 2013-03-10 14:16 ERS Game Studios 2014-02-16 11:55 FabrykaGier 2014-07-18 15:28 FabrykaGierNew 2013-03-10 11:00 FarmerJane 2015-10-19 09:04 FileZilla 2012-03-15 22:13 FlowerOfImmortality 2012-01-19 21:47 FlyWheelGames 2015-09-24 13:48 Free Sound Recorder 2015-06-21 16:30 FreeHideIP 2012-04-24 19:18 Freeze Tag 2012-06-21 20:05 Friday's games 2012-02-09 21:15 Funswitch 2012-01-27 23:32 Fuzzy Bug Interactive 2012-03-10 20:44 GameInvest 2012-08-15 09:48 GameMill Entertainment 2012-07-13 08:55 GHISLER 2012-06-27 22:18 Ghost Ship Studios 2011-11-20 18:25 GlarySoft 2011-01-12 11:04 Google 2011-03-11 00:29 gtk-2.0 2012-03-11 21:33 Happy Chef 2011-11-08 20:37 HdO Adventure 2010-11-12 14:10 Help 2015-07-16 08:22 109 Hewlett-PackardHP PSC 1500 series1427835367_API.log 2015-07-16 08:22 2057 Hewlett-PackardHP PSC 1500 series1427835367_PROTOCOL.log 2015-07-16 08:22 597 Hewlett-PackardHP PSC 1500 series1427835367_UI.log 2012-04-02 20:46 Hidden Objects Romance 2012-02-24 22:56 HitPoint Studios 2015-07-16 08:22 HP 2015-07-16 08:44 2102 HPSU_48BitScanUpdate.log 2015-07-16 10:42 HpUpdate 2010-08-05 04:16 Identities 2015-10-28 13:40 Image Zone Express 2012-10-01 08:03 IsolatedStorage 2012-01-25 21:37 Kestrel 2012-04-29 21:41 Lazy Turtle Games 2010-08-11 07:26 Leadertech 2013-07-30 21:04 Legacy Games 2012-06-26 20:39 LegacyInteractive 2010-12-28 22:11 LittleGamesCompany 2010-08-11 07:27 Logitech 2012-01-20 12:05 Loop Terminarz 2014-02-15 20:59 Macromedia 2011-12-26 23:02 MagicIndie 2013-08-21 13:49 Malwarebytes 2012-11-10 20:39 Mariaglorum 2012-02-02 20:40 Maximize Games 2014-12-30 18:59 Media Player Classic 2012-01-12 20:57 MediaArt 2015-03-23 13:09 Microsoft 2015-03-14 09:38 ModelViews 2011-12-26 23:47 Monkey Barrel Games 2014-09-26 07:54 Mozilla 2012-01-29 22:49 MumboJumbo 2012-07-30 11:32 MySQL-Front 2012-06-24 21:17 MysteriousCaseOfJekyllAndHyde 2012-01-14 00:18 Namco 2014-12-24 10:33 NCH Software 2015-09-24 13:47 New Version Available 2015-07-03 13:39 Notepad++ 2015-04-18 19:49 npm 2015-04-18 19:49 npm-cache 2012-07-08 21:47 Oberon Media 2011-12-19 23:27 Odian Games 2011-03-01 10:27 OpenCube Inc 2012-02-24 08:51 OpenFM 2013-08-20 12:10 Opera 2015-03-19 14:14 Opera Software 2014-06-28 10:33 Oracle 2012-02-11 21:19 Orneon 2015-07-16 08:44 22067 PatchUpdate_HP_CounterReport_Update_HPSU.log 2012-01-25 22:34 Phantasmat_bf_se1 2012-08-15 14:50 PlataGames 2012-01-28 00:40 PlayFavoriteGames 2012-03-21 20:14 PlayFirst 2012-06-25 23:25 PlayPond 2013-03-09 16:17 Playrix Entertainment 2012-08-27 09:49 Plus Internet 2015-04-16 13:55 PSpad 2013-07-11 22:24 PuzzleLab 2013-07-11 22:04 Realore 2013-12-17 10:21 RealWorld 2012-01-23 23:34 ShamanGS 2012-06-29 18:48 Silverback Productions 2015-10-27 18:39 Skype 2014-02-16 13:40 skypePM 2010-10-01 22:59 SmartDraw 2012-01-12 22:07 SMIGames 2012-06-14 22:49 Specialbit 2012-07-04 17:27 Star-Tools 2015-04-17 14:59 Subversion 2012-01-08 18:39 SulusGames 2010-09-27 20:19 Sun 2012-06-24 13:50 SunRay Games 2011-12-20 00:28 SunwardGames 2015-09-27 10:43 sweet-page 2011-11-08 21:43 22 Sys2662.Config.Repository.bin 2012-06-29 19:11 tabagames 2010-11-24 12:48 Talkback 2015-05-26 08:52 TeamViewer 2015-09-26 20:11 Tencent 2011-12-27 22:46 Teyon 2012-01-14 23:55 TikisLab 2012-01-30 21:06 Top Evidence 2015-04-17 15:11 TortoiseSVN 2011-11-08 20:29 TuneUp Software 2014-02-11 21:23 Unity 2015-07-16 08:32 42575 Update_HP_RedboxHprblog_HPSU.log 2012-06-24 17:22 Vast Studios 2012-01-11 23:00 Vogat Interactive 2010-12-09 16:15 WinRAR 2010-09-13 14:42 600 winscp.rnd 2012-06-02 22:35 World-LooM 2013-08-22 16:32 Yahoo! 11 File(s) 70455 bytes 143 Dir(s) 7685181440 bytes free ========= End of CMD: ========= ========= dir /a "C:\Documents and Settings\Krzysztof\Local Settings\Application Data" ========= Volume in drive C is BOOTCAMP Volume Serial Number is D8BF-6409 Directory of C:\Documents and Settings\Krzysztof\Local Settings\Application Data 2015-10-30 09:46 . 2015-10-30 09:46 .. 2015-09-27 13:14 5C8CAC0A-1443301797-5799-9460-C2325843CB2C 2015-10-13 17:38 Adobe 2013-02-14 09:01 Amazon 2010-08-05 04:19 Apple 2011-11-18 16:27 Apple Computer 2015-03-20 21:33 ArcSoft 2012-07-22 23:01 Autodesk 2013-08-27 16:07 avgchrome 2012-07-26 22:32 cache 2010-12-15 00:03 Color-Brush 2015-09-26 20:15 CrashRpt 2015-10-21 08:12 664 d3d9caps.dat 2015-09-23 21:29 25600 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2010-12-22 15:56 58 DonationCoder_ScreenshotCaptor_InstallInfo.dat 2015-03-20 21:30 Downloaded Installations 2013-03-23 18:51 Farmington Tales 2010-11-03 23:20 Game Mill Files 2015-10-06 08:43 91816 GDIPFONTCACHEV1.DAT 2015-09-27 12:55 gmsd_pl_005010096 2015-09-27 10:27 Google 2010-11-12 14:10 Help 2015-03-31 21:14 Hewlett-Packard 2014-09-23 20:39 HP 2015-03-25 19:43 4841210 IconCache.db 2010-09-14 12:08 Identities 2015-09-26 20:15 Installer 2011-02-07 10:35 KaDonk 2011-10-07 17:28 Kookos 2011-08-04 11:20 Logishrd 2014-07-18 15:56 Mercury Interactive 2015-10-29 20:49 Microsoft 2010-08-04 15:02 Microsoft Help 2013-03-01 14:08 Mozilla 2011-01-14 02:31 Namco 2010-12-20 00:07 Oberon Games 2011-03-01 10:27 OpenCube Inc 2012-06-29 23:26 Opera 2015-03-19 14:14 Opera Software 2010-12-30 12:55 PCHealth 2014-06-03 16:35 600 PUTTY.RND 2011-11-16 14:33 Qurb4 2014-06-09 11:11 3416 recently-used.xbel 2001-01-01 00:03 Skype 2013-12-09 11:26 Sun 2010-12-30 08:57 TechSmith 2015-03-23 13:09 Temp 2015-04-17 15:10 TortoiseSVN 2015-05-28 19:07 TSVNCache 2015-05-28 20:05 Unity 2013-02-14 09:08 webkit 2010-12-08 14:00 WMTools Downloaded Files 2013-10-11 08:25 Xenocode 2010-08-22 21:18 Yahoo 2011-08-03 06:38 Yahoo! 2010-09-17 20:35 {32A3A4F2-B792-11D6-A78A-00B0D0150120} 2012-10-01 08:03 _ 7 File(s) 4963364 bytes 51 Dir(s) 7685177344 bytes free ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog 09:46:38 ====