﻿Fix result of Farbar Recovery Scan Tool (x64) Version:09-12-2015
Ran by Anna (2015-12-10 22:23:03) Run:1
Running from C:\Users\Anna\Desktop
Loaded Profiles: Anna (Available Profiles: Anna)
Boot Mode: Normal
==============================================

fixlist content:
*****************
C:\Program Files (x86)\Tencent
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service"
FirewallRules: [{72E4B78F-AE3E-40A1-B0D0-EDE048F60790}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCmgrInstallGuide.exe
FirewallRules: [{E3F1067E-11A2-443A-ABF2-58585EB015E8}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCTray.exe
FirewallRules: [{CEC81030-FE23-465D-B1BF-238EEAD028E8}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCMgr.exe
FirewallRules: [{178A7647-F66D-42C2-BAD1-F8F92CCD86A4}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCRTP.exe
FirewallRules: [{5BE98EB6-43EF-4C09-960B-568060419F77}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMDL.exe
FirewallRules: [{B8E91A53-B0B2-4417-AA32-13DF025E8D84}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\bugreport.exe
FirewallRules: [{3F7B8377-0EAB-40F4-B184-CB33C2D7AA01}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCFileOpen.exe
FirewallRules: [{7E923D69-44AC-4082-8ACD-8A457293C6F0}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCLeakScan.exe
FirewallRules: [{48BD9F7D-C34F-4EE8-99DD-7EAF6B9BAC42}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPConfig.exe
FirewallRules: [{BB0FDEC6-B43F-465C-86DC-F2EE8266AF06}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCSoftMgr.exe
FirewallRules: [{07A761E4-2F5F-4B97-972E-F80D170B755B}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\plugins\QMNetMon\QQPCNetFlow.exe
FirewallRules: [{5EA4F46C-AC74-4FAF-9DAC-EA382D4AD0EF}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCBTU.exe
FirewallRules: [{3C9BF956-D50D-46BB-837B-2DAD0CCF4F50}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCClinic.exe
FirewallRules: [{6619DE11-2490-4E9F-A442-66F2A2DE0B44}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCLaunch.exe
FirewallRules: [{E7DC6D57-6176-4621-8AC9-6F954F2EB260}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMUpdate\QQPCMgrUpdate.exe
FirewallRules: [{AFCDF9A6-C836-4052-899C-2B5E5EA764B4}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCSoftGame.exe
FirewallRules: [{11C3039D-DC05-4BA1-B005-23708464F68A}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCSysOptimize.exe
FirewallRules: [{BBD9430F-D0B8-4A82-B6EC-B0CED513AAD8}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCUpdateAVLib.exe
FirewallRules: [{DD7BED09-1893-4956-A133-9C2D3D3D7085}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQRepair.exe
FirewallRules: [{B849E86E-FC87-4A00-AC3B-8BBB6FE62C31}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\Uninst.exe
FirewallRules: [{A6E53233-5A77-4E4F-88F6-06C2AE7D2937}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCPatch.exe
FirewallRules: [{4C67E699-B173-44A2-8A42-4550FB4F79C1}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\TpkUpdate.exe
FirewallRules: [{D7F773BF-D84C-4364-8D13-7B085314FE31}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMRouterMgr.exe
FirewallRules: [{A1213ED6-99B9-4993-B3B6-754876265964}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMAccountProtection.exe
FirewallRules: [{FF77157A-4AC1-429D-B2C6-A42F14D07F6D}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMAdBlock.exe
FirewallRules: [{248177EF-D094-476D-B2DC-C9B971006769}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
FirewallRules: [{E9329714-F265-4296-A70A-76AE7A6A5551}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe
AV: ???????? (Enabled - Up to date) {6F9C3F92-B625-0E47-F0B1-447602EC65F5}
AS: ???????? (Enabled - Up to date) {D4FDDE76-901F-01C9-CA01-7F04796B2F48}
C:\Program Files (x86)\Wooden Sea
HKLM-x32\...\Run: [Tencent] => C:\Program Files (x86)\Tencent\Tencent.exe [188416 2015-12-06] (Tencent)
HKLM-x32\...\Run: [ QQPCTray] => C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCTray.exe [355296 2015-12-10] (Tencent)
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMGCShellExt64.dll [2015-12-10] (Tencent)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.999.com/i.html
HKU\S-1-5-21-1992219592-4194980054-726992377-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.999.com/i.html
SearchScopes: HKU\S-1-5-21-1992219592-4194980054-726992377-1001 -> {94A783A3-EE88-411C-BA29-FAA1BB4A77B9} URL = hxxps://search.yahoo.com/search?fr=chr- ... =888596&p={searchTerms}
BHO: ????????? -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\TSWebMon64.dat [2015-12-10] (Tencent)
BHO-x32: Wooden Seal 1.0.0.7 -> {7a0ab196-76b2-4ee2-858e-7efdc93c3a47} -> C:\Program Files (x86)\Wooden Seal\WoodenSealbho.dll [2015-07-29] (Wooden Seal)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\IEXPLORE.EXE hxxp://www.mysites123.com/?type=sc&ts=1 ... PKYANPKYAN
FF NewTab: hxxp://www.mysites123.com/newtab/?type= ... PKYANPKYAN
FF Homepage: hxxp://www.mysites123.com/?type=hp&ts=1 ... PKYANPKYAN
FF Extension: Newtab - C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\Extensions\deskCutv2@gmail.com [2015-12-10] [not signed]
FF Extension: YahooToolsProtected - C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\Extensions\yahooprotected@gmail.com [2015-12-10] [not signed]
FF Extension: Wooden Seal 1.0.1 - C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\Extensions\{9ea97561-14d1-416f-8eaf-ce73a13a8574}.xpi [2015-12-10] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\extensions\deskCutv2@gmail.com
FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\extensions\yahooprotected@gmail.com
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.mysites123.com/?type=sc&ts=1 ... PKYANPKYAN
CHR StartupUrls: Default -> "hxxp://www.mysites123.com/?type=hp&ts=1449762539&z=78402b03cddc93832e6dc8bgbz2z8tfm8qfo3w8zbg&from=amt&uid=WDCXWD10JPCX-24UE4T0_WD-WX41A15PKYANPKYAN"
CHR DefaultSearchURL: Default -> hxxp://www.mysites123.com/web/?type=ds& ... ANPKYAN&q={searchTerms}
CHR DefaultSearchKeyword: Default -> mysites123
CHR Extension: (????????) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm [2015-12-10]
StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.mysites123.com/?type=sc&ts=1 ... PKYANPKYAN
OPR Extension: (Wooden Seal) - C:\Users\Anna\AppData\Roaming\Opera Software\Opera Stable\Extensions\coondjkcbpemfddhhkapbegnbojdofce [2015-12-10]
StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.mysites123.com/?type=sc&ts=1 ... PKYANPKYAN
R2 QQPCRTP; C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQPCRTP.exe [301728 2015-12-10] (Tencent)
R3 TAOFrame; C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\TAOFrame.exe [297952 2015-12-10] (Tencent)
S2 Update Wooden Seal; C:\Program Files (x86)\Wooden Seal\updateWoodenSeal.exe [659696 2015-12-10] ()
R2 WindowsMangerProtect; C:\ProgramData\Tmp0x0x\ProtectWindowsManager.exe [344232 2015-12-10] (Sysinternals process Explorer) <==== ATTENTION
R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe -s [X]
C:\ProgramData\Tmp0x0x
R2 Util Wooden Seal; no ImagePath
R1 QMUdisk; C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMUdisk64.sys [79160 2015-11-16] (Tencent)
R2 QQSysMonX64; C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QQSysMonX64.sys [138040 2015-12-10] (????)
R1 softaal; C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\softaal64.sys [35128 2015-12-10] (Tencent)
R3 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator64.sys [88632 2015-12-10] (Tencent)
R1 TAOKernelDriver; C:\Windows\System32\Drivers\TAOKernel64.sys [274232 2015-12-10] (Tencent Technology(Shenzhen) Company Limited)
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [87864 2015-12-10] (????)
R3 TS888x64; C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\TS888x64.sys [28984 2015-12-10] (Tencent)
S1 TSDefenseBt; C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\TSDefenseBT64.sys [28984 2015-12-10] (Tencent)
R1 TSSysKit; C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\TSSysKit64.sys [87352 2015-12-10] (????)
C:\Windows\System32\Drivers\TAOKernel64.sys
C:\Windows\system32\Drivers\TAOAccelerator64.sys
R1 {03fe1e82-27a8-4c9c-9858-83f6dd0428dc}Gw64; C:\Windows\System32\drivers\{03fe1e82-27a8-4c9c-9858-83f6dd0428dc}Gw64.sys [48784 2015-12-10] (StdLib)
C:\Windows\System32\drivers\{03fe1e82-27a8-4c9c-9858-83f6dd0428dc}Gw64.sys
C:\ProgramData\TXQMPC
2015-12-10 16:56 - 2015-12-10 16:56 - 00000000 ____D C:\Program Files\Common Files\Tencent
2015-12-10 16:56 - 2015-12-10 16:54 - 00274232 _____ (Tencent Technology(Shenzhen) Company Limited) C:\Windows\system32\Drivers\TAOKernel64.sys
2015-12-10 16:56 - 2015-12-10 16:54 - 00088632 _____ (Tencent) C:\Windows\system32\Drivers\TAOAccelerator64.sys
C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????
2015-12-10 16:55 - 2015-12-10 16:54 - 00087864 _____ (????) C:\Windows\system32\Drivers\TFsFltX64.sys
C:\Users\Anna\AppData\Roaming\Tencent
2015-12-10 16:54 - 2015-12-10 16:58 - 00000000 ____D C:\ProgramData\Tencent
C:\Users\Anna\AppData\Roaming\mysites123
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
EmptyTemp:
*****************


"C:\Program Files (x86)\Tencent" folder move:

Could not move "C:\Program Files (x86)\Tencent" => Scheduled to move on reboot.

"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP" => key removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{72E4B78F-AE3E-40A1-B0D0-EDE048F60790} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E3F1067E-11A2-443A-ABF2-58585EB015E8} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CEC81030-FE23-465D-B1BF-238EEAD028E8} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{178A7647-F66D-42C2-BAD1-F8F92CCD86A4} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5BE98EB6-43EF-4C09-960B-568060419F77} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B8E91A53-B0B2-4417-AA32-13DF025E8D84} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3F7B8377-0EAB-40F4-B184-CB33C2D7AA01} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7E923D69-44AC-4082-8ACD-8A457293C6F0} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{48BD9F7D-C34F-4EE8-99DD-7EAF6B9BAC42} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BB0FDEC6-B43F-465C-86DC-F2EE8266AF06} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{07A761E4-2F5F-4B97-972E-F80D170B755B} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5EA4F46C-AC74-4FAF-9DAC-EA382D4AD0EF} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3C9BF956-D50D-46BB-837B-2DAD0CCF4F50} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6619DE11-2490-4E9F-A442-66F2A2DE0B44} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E7DC6D57-6176-4621-8AC9-6F954F2EB260} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AFCDF9A6-C836-4052-899C-2B5E5EA764B4} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{11C3039D-DC05-4BA1-B005-23708464F68A} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BBD9430F-D0B8-4A82-B6EC-B0CED513AAD8} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DD7BED09-1893-4956-A133-9C2D3D3D7085} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B849E86E-FC87-4A00-AC3B-8BBB6FE62C31} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A6E53233-5A77-4E4F-88F6-06C2AE7D2937} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4C67E699-B173-44A2-8A42-4550FB4F79C1} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D7F773BF-D84C-4364-8D13-7B085314FE31} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A1213ED6-99B9-4993-B3B6-754876265964} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FF77157A-4AC1-429D-B2C6-A42F14D07F6D} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{248177EF-D094-476D-B2DC-C9B971006769} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E9329714-F265-4296-A70A-76AE7A6A5551} => value removed successfully
AV: ???????? (Enabled - Up to date) {6F9C3F92-B625-0E47-F0B1-447602EC65F5} => removed successfully
AS: ???????? (Enabled - Up to date) {D4FDDE76-901F-01C9-CA01-7F04796B2F48} => removed successfully
"C:\Program Files (x86)\Wooden Sea" => not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Tencent => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ QQPCTray => value could not remove.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\.QMDeskTopGCIcon" => key removed successfully
"HKCR\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6}" => key removed successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Error setting value.
HKU\S-1-5-21-1992219592-4194980054-726992377-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Error setting value.
"HKU\S-1-5-21-1992219592-4194980054-726992377-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{94A783A3-EE88-411C-BA29-FAA1BB4A77B9}" => key removed successfully
HKCR\CLSID\{94A783A3-EE88-411C-BA29-FAA1BB4A77B9} => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}" => key removed successfully
"HKCR\CLSID\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7a0ab196-76b2-4ee2-858e-7efdc93c3a47}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{7a0ab196-76b2-4ee2-858e-7efdc93c3a47}" => key removed successfully
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully
Firefox "newtab" removed successfully
Firefox "homepage" removed successfully
C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\Extensions\deskCutv2@gmail.com => moved successfully
C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\Extensions\deskCutv2@gmail.com => path removed successfully
C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\Extensions\yahooprotected@gmail.com => moved successfully
C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\Extensions\yahooprotected@gmail.com => path removed successfully
C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\y1a2ib66.default\Extensions\{9ea97561-14d1-416f-8eaf-ce73a13a8574}.xpi => moved successfully
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\deskCutv2@gmail.com => value removed successfully
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\yahooprotected@gmail.com => value removed successfully
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => value restored successfully
Chrome StartupUrls => removed successfully
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSearchKeyword => removed successfully
C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm => moved successfully
HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => value restored successfully
C:\Users\Anna\AppData\Roaming\Opera Software\Opera Stable\Extensions\coondjkcbpemfddhhkapbegnbojdofce => moved successfully
HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command\\Default => value restored successfully
QQPCRTP => Unable to stop service.
QQPCRTP => service could not remove
TAOFrame => service removed successfully
Update Wooden Seal => Unable to stop service.
Update Wooden Seal => service removed successfully
WindowsMangerProtect => Unable to stop service.
WindowsMangerProtect => service removed successfully
SSFK => service removed successfully
C:\ProgramData\Tmp0x0x => moved successfully
Util Wooden Seal => service removed successfully
QMUdisk => Unable to stop service.
QMUdisk => service removed successfully
QQSysMonX64 => Unable to stop service.
QQSysMonX64 => service could not remove
softaal => Unable to stop service.
softaal => service removed successfully
TAOAccelerator => Unable to stop service.
TAOAccelerator => service removed successfully
TAOKernelDriver => Unable to stop service.
TAOKernelDriver => service removed successfully
TFsFlt => Unable to stop service.
TFsFlt => service could not remove
TS888x64 => Unable to stop service.
TS888x64 => service removed successfully
TSDefenseBt => service could not remove
TSSysKit => Unable to stop service.
TSSysKit => service removed successfully
C:\Windows\System32\Drivers\TAOKernel64.sys => moved successfully
C:\Windows\system32\Drivers\TAOAccelerator64.sys => moved successfully
{03fe1e82-27a8-4c9c-9858-83f6dd0428dc}Gw64 => Unable to stop service.
{03fe1e82-27a8-4c9c-9858-83f6dd0428dc}Gw64 => service removed successfully
C:\Windows\System32\drivers\{03fe1e82-27a8-4c9c-9858-83f6dd0428dc}Gw64.sys => moved successfully
C:\ProgramData\TXQMPC => moved successfully

"C:\Program Files\Common Files\Tencent" folder move:

Could not move "C:\Program Files\Common Files\Tencent" => Scheduled to move on reboot.

"C:\Windows\system32\Drivers\TAOKernel64.sys" => not found.
"C:\Windows\system32\Drivers\TAOAccelerator64.sys" => not found.

=========== "C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????" ==========

C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\.lnk => moved successfully

========= End -> "C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????" ========

Could not move "C:\Windows\system32\Drivers\TFsFltX64.sys" => Scheduled to move on reboot.

"C:\Users\Anna\AppData\Roaming\Tencent" folder move:

Could not move "C:\Users\Anna\AppData\Roaming\Tencent" => Scheduled to move on reboot.


"C:\ProgramData\Tencent" folder move:

Could not move "C:\ProgramData\Tencent" => Scheduled to move on reboot.

C:\Users\Anna\AppData\Roaming\mysites123 => moved successfully
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat => moved successfully
EmptyTemp: => 20.3 GB temporary data Removed.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-12-10 22:26:23)

C:\Program Files (x86)\Tencent => Is moved successfully
C:\Program Files\Common Files\Tencent => Is moved successfully
C:\Windows\system32\Drivers\TFsFltX64.sys => moved successfully
C:\Users\Anna\AppData\Roaming\Tencent => Is moved successfully
C:\ProgramData\Tencent => Is moved successfully

==== End of Fixlog 22:26:23 ====