CHR - homepage:
CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url =
http://search.yahoo.com/search?fr=chr-greentree_gc&ei=utf-8&ilc=12&type=937811&p={searchTerms}
CHR - default_search_provider: suggest_url =
http://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms},
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Rosalie Blythe\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2191_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: QQ2011 (Enabled) = C:\Program Files\Common Files\Tencent\NPQSCALL\npqscall.dll
CHR - plugin: NPTXSSO Dynamic Link Library (Enabled) = C:\Program Files\Common Files\Tencent\TXSSO\1.2.1.36\Bin\npSSOAxCtrlForPTLogin.dll
CHR - plugin: Thunder DapCtrl NPAPI Plugin (Enabled) = C:\Program Files\Common Files\Thunder Network\KanKan\npDapCtrl.3.1.0.4.(269).dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: PPLive PPTV Plugin (Enabled) = C:\Program Files\Internet Explorer\PPLite\plugin\1.0.1.1717\npplugin2.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Java(TM) Platform SE 7 U5 (Enabled) = C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: RealNetworks Rhapsody Player Engine (Enabled) = C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
CHR - plugin: QQMusic (Enabled) = C:\Program Files\Tencent\QQMusic\npQzoneMusic.dll
CHR - plugin: npQQPhotoDrawEx (Enabled) = C:\Program Files\Tencent\Qzone\npQQPhotoDrawEx.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpplugin.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1166636.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - Extension: YouTube = C:\Users\Rosalie Blythe\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Showwall \u660E\u661F\u52D5\u6F2B\u684C\u5E03 = C:\Users\Rosalie Blythe\AppData\Local\Google\Chrome\User Data\Default\Extensions\cimpccflpmccajjbiloadclfaelnegbf\1.2_0\
CHR - Extension: Google Search = C:\Users\Rosalie Blythe\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Hello Kitty = C:\Users\Rosalie Blythe\AppData\Local\Google\Chrome\User Data\Default\Extensions\mioiobnjjjgemkflahplehgpkbjcojld\1.1_0\
CHR - Extension: AVG Do Not Track = C:\Users\Rosalie Blythe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: Unblock Youku = C:\Users\Rosalie Blythe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnfnkhpgegpcingjbfihlkjeighnddk\2.6.1.5_0\
CHR - Extension: Gmail = C:\Users\Rosalie Blythe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2013/02/15 12:27:53 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (VideoUrlSniffer Class) - {00000ADA-7E0D-47C1-986C-F017D09C4304} - C:\Users\Public\Thunder Network\XMP4\Core\Program\VideoUrlSniffer.2.0.3.100.(71).dll (深圳市迅雷网络技术有限公司)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (BrowserHelper) - {4BF2CB0E-658A-442B-AC83-A64EC2150BFC} - C:\ProgramData\PPBrowserHelper\BHO\TipsBHO.dll (TODO: <Company name>)
O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ѸÀ×ÏÂÔØÖ§³Ö) - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.2.3.3254.dll (深圳市迅雷网络技术有限公司)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files\Olympus\ib\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Olympus ib] C:\Program Files\Olympus\ib\olycamdetect.exe (OLYMPUS IMAGING CORP.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WD Drive Unlocker] C:\Program Files\Western Digital\WD Apps\WDDriveAutoUnlock.exe (Western Digital)
O4 - HKLM..\Run: [WD Quick View] C:\Program Files\Western Digital\WD SmartWare\WDDMStatus.exe (Western Digital Technologies, Inc.)
O4 - HKU\S-1-5-21-2146718395-4068598169-1799883407-1005..\Run: [PPAP] C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe (PPLive Corporation)
O4 - HKU\S-1-5-21-2146718395-4068598169-1799883407-1005..\Run: [PPS Accelerator] D:\PPS.tv\PPStream\PPSAP.exe (PPStream Inc)
O4 - HKU\S-1-5-21-2146718395-4068598169-1799883407-1005..\Run: [XMP] "C:\Users\Public\THUNDE~1\XMP4\Core\Program\XMP.exe" /embedding /sstartfrom Startup101 File not found
O4 - HKLM..\RunOnce: [Launcher] C:\WINDOWS\SMINST\Launcher.exe (soft thinks)
O4 - Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Rosalie Blythe\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Rosalie Blythe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Rosalie Blythe\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: OldEnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2146718395-4068598169-1799883407-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2146718395-4068598169-1799883407-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2146718395-4068598169-1799883407-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2146718395-4068598169-1799883407-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-2146718395-4068598169-1799883407-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: &使用&迅雷下载 - C:\Program Files\Thunder Network\Thunder\BHO\geturl.htm ()
O8 - Extra context menu item: &使用&迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\BHO\getAllurl.htm ()
O8 - Extra context menu item: 使用迅雷看看播放器播放 - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenu.htm ()
O9 - Extra 'Tools' menuitem : 启动迅雷看看播放器 - {14c1d00e-0b92-4379-880b-444fa2d740dd} - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolMenu.htm ()
O9 - Extra Button: 迅雷看看播放器 - {24c1d00e-0b92-4379-880b-444fa2d740dd} - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolBar.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Key error. File not found
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Key error. File not found
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPTV\PPLive.exe (PPLive Corporation)
O9 - Extra 'Tools' menuitem : PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPTV\PPLive.exe (PPLive Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-2146718395-4068598169-1799883407-1005\..Trusted Ranges: Range1 ([http] in Local intranet)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 204.197.191.194 38.117.85.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{54C2B5EC-D81C-4B8C-9CB0-B146A3BC081D}: DhcpNameServer = 204.197.191.194 38.117.85.2
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\KuGoo {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\Program Files\KuGou\KGMusic\KuGoo3DownXControl.ocx (广州酷狗计算机科技有限公司)
O18 - Protocol\Handler\KuGoo3 {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\Program Files\KuGou\KGMusic\KuGoo3DownXControl.ocx (广州酷狗计算机科技有限公司)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O24 - Desktop WallPaper: C:\Users\Rosalie Blythe\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Rosalie Blythe\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/16 13:06:48 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/02/15 17:14:59 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Rosalie Blythe\Desktop\OTL.exe
[2013/02/15 17:03:22 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/02/15 17:03:12 | 000,000,000 | ---D | C] -- C:\JRT
[2013/02/15 17:01:43 | 000,547,384 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Rosalie Blythe\Desktop\JRT.exe
[2013/02/15 14:28:31 | 000,000,000 | ---D | C] -- C:\Users\Rosalie Blythe\AppData\Local\ElevatedDiagnostics
[2013/02/15 12:46:21 | 000,000,000 | ---D | C] -- C:\Users\Rosalie Blythe\AppData\Local\HP
[2013/02/15 12:33:38 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/02/15 11:56:09 | 000,000,000 | ---D | C] -- C:\Users\Rosalie Blythe\AppData\Roaming\PeerNetworking
[2013/02/15 11:37:07 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/02/15 11:37:06 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/02/15 11:37:05 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/02/15 11:36:24 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013/02/15 11:35:47 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/02/15 11:33:58 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/02/15 11:28:19 | 005,033,715 | R--- | C] (Swearware) -- C:\Users\Rosalie Blythe\Desktop\ComboFix.exe
[2013/02/13 20:42:01 | 000,000,000 | ---D | C] -- C:\Program Files\YTD Toolbar(47)
[2013/02/13 20:42:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot(33)
[2013/02/09 18:02:41 | 000,000,000 | ---D | C] -- C:\Users\Rosalie Blythe\Desktop\mbar-1.01.0.1020
[2013/02/09 17:22:23 | 000,000,000 | ---D | C] -- C:\Users\Rosalie Blythe\Desktop\RK_Quarantine
[2013/02/09 10:53:40 | 000,003,072 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\zh-TW\stcusb.sys.mui
[2013/02/09 10:53:40 | 000,003,072 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\zh-TW\pscr.sys.mui
[2013/02/09 10:53:40 | 000,003,072 | ---- | C] (SCM Microsystems) -- C:\Windows\System32\drivers\zh-TW\SCR111.sys.mui
[2013/02/09 10:53:40 | 000,003,072 | ---- | C] (OMNIKEY AG) -- C:\Windows\System32\drivers\zh-TW\cmbp0wdm.sys.mui
[2013/02/09 10:53:40 | 000,003,072 | ---- | C] (Gemplus) -- C:\Windows\System32\drivers\zh-TW\gpr400.sys.mui
[2013/02/09 10:53:40 | 000,002,560 | ---- | C] (OMNIKEY) -- C:\Windows\System32\drivers\zh-TW\cxbp0wdm.sys.mui
[2013/02/09 10:53:39 | 000,003,072 | ---- | C] (Gemplus) -- C:\Windows\System32\drivers\zh-TW\grserial.sys.mui
[2013/02/09 10:52:33 | 000,003,072 | ---- | C] (N-trig Innovative Technologies) -- C:\Windows\System32\drivers\zh-TW\ntrigdigi.sys.mui
[2013/02/09 10:52:30 | 000,004,096 | ---- | C] (Marvell) -- C:\Windows\System32\drivers\zh-TW\yk60x86.sys.mui
[2013/02/09 10:46:26 | 000,005,120 | ---- | C] (Agere Systems) -- C:\Windows\System32\drivers\zh-TW\ltmdmnt.sys.mui
[2013/02/09 10:46:17 | 000,005,120 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\zh-TW\BrSerId.sys.mui
[2013/02/09 10:46:17 | 000,002,048 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\zh-TW\BrParwdm.sys.mui
[2013/02/09 10:46:04 | 000,000,000 | ---D | C] -- C:\Windows\System32\0404
[2013/02/09 10:44:56 | 000,000,000 | ---D | C] -- C:\Windows\System32\0C04
[2013/02/09 10:44:48 | 000,000,000 | ---D | C] -- C:\Windows\zh-TW
[2013/02/09 10:43:37 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\zh-HK
[2013/02/09 10:40:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\zh-TW
[2013/02/09 10:40:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\zh-CHT
[2013/02/09 10:40:11 | 000,000,000 | ---D | C] -- C:\Windows\System32\Windows System Resource Manager
[2013/02/09 10:23:58 | 000,000,000 | ---D | C] -- C:\Windows\System32\Vistalizator
[2013/02/09 09:44:12 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2013/02/02 02:30:02 | 000,000,000 | ---D | C] -- C:\found.001
[2013/02/01 13:56:29 | 000,000,000 | ---D | C] -- C:\Users\Rosalie Blythe\Desktop\TVBOXNOW 宮
[2013/01/21 08:10:32 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG January 2013 Campaign
========== Files - Modified Within 30 Days ==========
[2013/02/15 17:25:00 | 000,000,428 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{45D4C764-4362-407E-9FCE-066735E027A3}.job
[2013/02/15 17:15:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Rosalie Blythe\Desktop\OTL.exe
[2013/02/15 17:02:07 | 000,547,384 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Rosalie Blythe\Desktop\JRT.exe
[2013/02/15 16:56:12 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/15 16:50:03 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/15 16:50:02 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/15 16:49:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/02/15 16:45:19 | 000,000,104 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013/02/15 16:35:39 | 000,587,671 | ---- | M] () -- C:\Users\Rosalie Blythe\Desktop\adwcleaner0.exe
[2013/02/15 15:47:16 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/15 14:01:27 | 000,450,208 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/02/15 13:28:21 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2013/02/15 13:21:13 | 000,631,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/02/15 13:21:13 | 000,118,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/02/15 12:46:28 | 000,000,057 | ---- | M] () -- C:\ProgramData\Ament.ini
[2013/02/15 12:27:53 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013/02/15 11:56:31 | 000,024,109 | ---- | M] () -- C:\Users\Rosalie Blythe\AppData\Roaming\UserTile.png
[2013/02/15 11:30:44 | 005,033,715 | R--- | M] (Swearware) -- C:\Users\Rosalie Blythe\Desktop\ComboFix.exe
[2013/02/13 17:03:08 | 000,000,047 | ---- | M] () -- C:\Users\Rosalie Blythe\AppData\Roaming\CoreAVC.ini
[2013/02/10 14:25:06 | 000,000,680 | ---- | M] () -- C:\Users\Rosalie Blythe\AppData\Local\d3d9caps.dat
[2013/02/10 01:39:39 | 000,068,585 | ---- | M] () -- C:\Users\Rosalie Blythe\Desktop\未命名.jpg
[2013/02/09 16:07:27 | 013,711,621 | ---- | M] () -- C:\Users\Rosalie Blythe\Desktop\mbar-1.01.0.1020.zip
[2013/02/09 13:38:41 | 000,000,584 | RHS- | M] () -- C:\Users\Rosalie Blythe\ntuser.pol
[2013/02/09 13:38:39 | 000,000,210 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2013/02/09 10:53:40 | 000,003,072 | ---- | M] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\zh-TW\stcusb.sys.mui
[2013/02/09 10:53:40 | 000,003,072 | ---- | M] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\zh-TW\pscr.sys.mui
[2013/02/09 10:53:40 | 000,003,072 | ---- | M] (SCM Microsystems) -- C:\Windows\System32\drivers\zh-TW\SCR111.sys.mui
[2013/02/09 10:53:40 | 000,003,072 | ---- | M] (OMNIKEY AG) -- C:\Windows\System32\drivers\zh-TW\cmbp0wdm.sys.mui
[2013/02/09 10:53:40 | 000,003,072 | ---- | M] (Gemplus) -- C:\Windows\System32\drivers\zh-TW\grserial.sys.mui
[2013/02/09 10:53:40 | 000,003,072 | ---- | M] (Gemplus) -- C:\Windows\System32\drivers\zh-TW\gpr400.sys.mui
[2013/02/09 10:53:40 | 000,002,560 | ---- | M] (OMNIKEY) -- C:\Windows\System32\drivers\zh-TW\cxbp0wdm.sys.mui
[2013/02/09 10:52:33 | 000,003,072 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\System32\drivers\zh-TW\ntrigdigi.sys.mui
[2013/02/09 10:52:30 | 000,004,096 | ---- | M] (Marvell) -- C:\Windows\System32\drivers\zh-TW\yk60x86.sys.mui
[2013/02/09 10:46:26 | 000,005,120 | ---- | M] (Agere Systems) -- C:\Windows\System32\drivers\zh-TW\ltmdmnt.sys.mui
[2013/02/09 10:46:17 | 000,005,120 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\zh-TW\BrSerId.sys.mui
[2013/02/09 10:46:17 | 000,002,048 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\zh-TW\BrParwdm.sys.mui
[2013/02/09 10:44:04 | 000,116,092 | ---- | M] () -- C:\Users\Rosalie Blythe\Desktop\re.jpg
[2013/02/09 09:44:13 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2013/02/01 12:29:17 | 000,027,681 | ---- | M] () -- C:\Users\Rosalie Blythe\Desktop\cEbm9.jpg
[2013/01/31 18:25:53 | 000,000,962 | ---- | M] () -- C:\Users\Rosalie Blythe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/01/31 18:25:42 | 000,000,948 | ---- | M] () -- C:\Users\Rosalie Blythe\Desktop\Dropbox.lnk
[2013/01/21 17:24:19 | 000,000,298 | ---- | M] () -- C:\Windows\tasks\ROC_REG_JAN_DELETE.job
========== Files Created - No Company Name ==========
[2013/02/15 16:43:57 | 000,000,104 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013/02/15 16:34:09 | 000,587,671 | ---- | C] () -- C:\Users\Rosalie Blythe\Desktop\adwcleaner0.exe
[2013/02/15 12:46:28 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2013/02/15 11:56:10 | 000,024,109 | ---- | C] () -- C:\Users\Rosalie Blythe\AppData\Roaming\UserTile.png
[2013/02/15 11:37:07 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/02/15 11:37:06 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/02/15 11:37:06 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/02/15 11:37:06 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/02/15 11:37:05 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/02/10 01:39:39 | 000,068,585 | ---- | C] () -- C:\Users\Rosalie Blythe\Desktop\未命名.jpg
[2013/02/09 16:04:32 | 013,711,621 | ---- | C] () -- C:\Users\Rosalie Blythe\Desktop\mbar-1.01.0.1020.zip
[2013/02/09 10:41:53 | 000,116,092 | ---- | C] () -- C:\Users\Rosalie Blythe\Desktop\re.jpg
[2013/02/01 12:29:02 | 000,027,681 | ---- | C] () -- C:\Users\Rosalie Blythe\Desktop\cEbm9.jpg
[2013/01/21 08:10:40 | 000,000,298 | ---- | C] () -- C:\Windows\tasks\ROC_REG_JAN_DELETE.job
[2012/11/12 20:46:57 | 000,000,204 | ---- | C] () -- C:\Windows\System32\secustat.dat
[2012/10/31 23:53:22 | 002,298,768 | ---- | C] () -- C:\Windows\System32\kindling.dll
[2012/10/27 07:04:54 | 000,000,680 | ---- | C] () -- C:\Users\Rosalie Blythe\AppData\Local\d3d9caps.dat
[2012/05/07 11:51:10 | 000,000,047 | ---- | C] () -- C:\Users\Rosalie Blythe\AppData\Roaming\CoreAVC.ini
[2012/04/23 21:09:30 | 000,010,240 | ---- | C] () -- C:\Users\Rosalie Blythe\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/23 20:39:53 | 000,000,584 | RHS- | C] () -- C:\Users\Rosalie Blythe\ntuser.pol
[2012/01/20 17:29:25 | 000,000,095 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2011/06/11 15:53:18 | 000,018,760 | ---- | C] () -- C:\Windows\System32\QQVistaHelper.dll
[2011/05/15 02:13:53 | 000,000,020 | ---- | C] () -- C:\Windows\System32\pub_store.dat
[2011/03/21 16:15:18 | 000,000,210 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/09/30 21:24:17 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
========== ZeroAccess Check ==========
[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 12:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 01:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 01:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/04/20 15:07:02 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\Ad-Aware Antivirus
[2012/04/20 18:09:48 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\Auslogics
[2010/04/04 21:41:34 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\AVG9
[2010/09/30 16:35:38 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\Blitware
[2010/12/25 18:26:15 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\GetRightToGo
[2012/09/13 16:26:09 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\KuGou7
[2010/04/10 18:26:35 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\PlayFirst
[2011/09/01 18:02:51 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\PPLive
[2012/04/20 17:11:06 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\PPStream
[2010/04/02 11:39:54 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\Snapfish
[2010/09/30 21:43:48 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\Soluto
[2010/10/15 17:38:39 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\SuperMP3Download
[2012/04/14 18:45:07 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\Tencent
[2011/06/23 17:54:01 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\UDown
[2012/04/09 01:14:36 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\uTorrent
[2010/04/05 17:53:52 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\WildTangent
[2011/05/20 21:06:19 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\WinBatch
[2012/04/20 19:30:41 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\Wise Disk Cleaner
[2011/07/09 12:13:02 | 000,000,000 | ---D | M] -- C:\Users\Ada Suk Yi Ma\AppData\Roaming\Youtube Downloader HD
[2013/01/12 09:47:31 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013/01/12 09:47:31 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2012/12/12 19:47:56 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\AVG2013
[2012/11/12 20:46:57 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\BITS
[2013/02/15 00:16:11 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Dropbox
[2012/11/12 20:46:56 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\FlashgetSetup
[2013/02/15 13:40:12 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Kugou7
[2012/11/06 16:33:47 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\KuGou8
[2012/07/15 14:36:46 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\PPLive
[2013/02/15 13:40:12 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\ppStream
[2010/08/06 17:08:09 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Snapfish
[2013/02/09 09:06:16 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Tencent
[2012/12/08 08:27:32 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\uTorrent
[2012/04/20 15:50:34 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\Ad-Aware Antivirus
[2012/08/08 19:28:50 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\Application Data
[2012/04/20 16:10:16 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\Auslogics
[2012/08/19 10:03:42 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\Kugou7
[2012/09/23 15:47:07 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\KuGou8
[2012/08/08 19:31:38 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\PPLive
[2012/08/09 07:46:47 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\ppStream
[2010/04/18 14:54:45 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\Snapfish
[2011/05/23 10:21:26 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\Soluto
[2011/11/02 22:50:49 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\Tencent
[2011/06/08 20:48:04 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\TypingMaster7
[2012/07/12 18:33:02 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\uTorrent
[2010/10/08 23:32:59 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\WildTangent
[2011/04/17 17:28:20 | 000,000,000 | ---D | M] -- C:\Users\Kitty\AppData\Roaming\Youtube Downloader HD
[2012/12/15 14:22:17 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\AVG2013
[2013/02/15 16:55:42 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\Dropbox
[2012/09/13 16:26:39 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\Kugou7
[2012/10/28 19:32:08 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\KuGou8
[2013/02/15 11:56:09 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\PeerNetworking
[2012/05/12 19:59:34 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\PPLive
[2013/02/10 17:45:52 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\ppStream
[2012/06/09 14:52:26 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\QQMusicUpdate
[2012/12/12 17:08:50 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\TuneUp Software
[2012/12/16 12:53:11 | 000,000,000 | ---D | M] -- C:\Users\Rosalie Blythe\AppData\Roaming\uTorrent
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012/12/15 23:42:03 | 000,001,189 | ---- | M] ()(C:\Users\Rosalie Blythe\Application Data\Microsoft\Internet Explorer\Quick Launch\??迅雷看看播放器.lnk) -- C:\Users\Rosalie Blythe\Application Data\Microsoft\Internet Explorer\Quick Launch\启动迅雷看看播放器.lnk
[2012/05/12 19:56:07 | 000,001,189 | ---- | C] ()(C:\Users\Rosalie Blythe\Application Data\Microsoft\Internet Explorer\Quick Launch\??迅雷看看播放器.lnk) -- C:\Users\Rosalie Blythe\Application Data\Microsoft\Internet Explorer\Quick Launch\启动迅雷看看播放器.lnk
[2011/03/29 14:25:40 | 000,000,036 | ---- | M] ()(C:\Windows\System32\??) -- C:\Windows\System32\ᰐť
[2011/03/29 14:25:40 | 000,000,036 | ---- | C] ()(C:\Windows\System32\??) -- C:\Windows\System32\ᰐť
[2010/11/17 03:07:36 | 000,000,036 | ---- | M] ()(C:\Windows\System32\?α) -- C:\Windows\System32\䎀α
[2010/11/17 03:07:36 | 000,000,036 | ---- | C] ()(C:\Windows\System32\?α) -- C:\Windows\System32\䎀α
[2010/10/11 14:51:50 | 000,000,036 | ---- | M] ()(C:\Windows\System32\??) -- C:\Windows\System32\쿠˳
[2010/10/11 14:51:50 | 000,000,036 | ---- | C] ()(C:\Windows\System32\??) -- C:\Windows\System32\쿠˳
[2010/10/03 14:27:16 | 000,000,036 | ---- | M] ()(C:\Windows\System32\??) -- C:\Windows\System32\꿠Ī
[2010/10/03 14:27:16 | 000,000,036 | ---- | C] ()(C:\Windows\System32\??) -- C:\Windows\System32\꿠Ī
[2010/08/11 18:12:34 | 000,000,036 | ---- | M] ()(C:\Windows\System32\??) -- C:\Windows\System32\땘̢
[2010/08/11 18:12:34 | 000,000,036 | ---- | C] ()(C:\Windows\System32\??) -- C:\Windows\System32\땘̢
[2010/08/04 16:16:09 | 000,000,036 | ---- | M] ()(C:\Windows\System32\禠?) -- C:\Windows\System32\禠ŏ
[2010/08/04 16:16:09 | 000,000,036 | ---- | C] ()(C:\Windows\System32\禠?) -- C:\Windows\System32\禠ŏ
[2010/07/06 17:40:58 | 000,000,036 | ---- | M] ()(C:\Windows\System32\??) -- C:\Windows\System32\겸Ł
[2010/07/06 17:40:58 | 000,000,036 | ---- | C] ()(C:\Windows\System32\??) -- C:\Windows\System32\겸Ł
[2010/06/27 18:01:23 | 000,000,036 | ---- | M] ()(C:\Windows\System32\??) -- C:\Windows\System32\ᙀќ
[2010/06/27 18:01:23 | 000,000,036 | ---- | C] ()(C:\Windows\System32\??) -- C:\Windows\System32\ᙀќ
[2010/06/13 18:54:59 | 000,000,036 | ---- | M] ()(C:\Windows\System32\??) -- C:\Windows\System32\ࣈŀ
[2010/06/13 18:54:59 | 000,000,036 | ---- | C] ()(C:\Windows\System32\??) -- C:\Windows\System32\ࣈŀ
[2010/06/03 03:36:15 | 000,000,036 | ---- | M] ()(C:\Windows\System32\讀?) -- C:\Windows\System32\讀Ŀ
[2010/06/03 03:36:15 | 000,000,036 | ---- | C] ()(C:\Windows\System32\讀?) -- C:\Windows\System32\讀Ŀ
[2010/05/03 05:06:31 | 000,000,036 | ---- | M] ()(C:\Windows\System32\??) -- C:\Windows\System32\ᨘĪ
[2010/05/03 05:06:31 | 000,000,036 | ---- | C] ()(C:\Windows\System32\??) -- C:\Windows\System32\ᨘĪ
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\迅雷?件) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\迅雷软件
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\???件) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
< End of report >