Carmen__Tsamg
Posts: 103 +0
[2013/02/08 18:02:36 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013/02/08 17:52:13 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/02/08 17:05:30 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/02/08 17:05:30 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/02/08 17:05:30 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/02/08 17:05:22 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/02/08 17:04:18 | 005,030,592 | R--- | C] (Swearware) -- C:\Users\Kitty Tsang\Desktop\ComboFix.exe
[2013/02/08 16:28:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Kitty Tsang\Desktop\OTL.exe
[2013/02/08 16:25:40 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\Desktop\mbar
[2013/02/08 16:08:35 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\Desktop\RK_Quarantine
[2013/02/08 15:45:38 | 000,547,275 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Kitty Tsang\Desktop\JRT.exe
[2013/02/08 02:53:15 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\Bart_Ubing
[2013/02/08 02:52:29 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\CRE
[2013/02/08 02:47:49 | 000,661,504 | ---- | C] (Bart Ubing) -- C:\Users\Kitty Tsang\Desktop\Windows_7_Logon_screen_editor_by_bcubing.exe
[2013/02/07 17:33:09 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\Kitty Tsang\Desktop\dds.com
[2013/02/07 17:30:40 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\Desktop\SecurityCheck
[2013/02/07 00:20:39 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\騰訊軟體
[2013/02/06 23:58:56 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\{CE18F04E-3F8F-4FD8-A23C-70FB5DAD9580}
[2013/02/06 11:09:21 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/02/06 10:35:44 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/02/06 10:35:19 | 000,000,000 | ---D | C] -- C:\JRT
[2013/02/05 16:06:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/02/02 15:45:47 | 000,000,000 | ---D | C] -- C:\Program Files\FreeFixer
[2013/02/01 12:19:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/01/29 21:54:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
[2013/01/29 21:54:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDFCreator
[2013/01/29 21:52:50 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\Updater21802
[2013/01/29 21:21:59 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logon Loader
[2013/01/29 21:11:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logon Loader
[2013/01/29 21:11:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Logon Loader
[2013/01/24 14:44:36 | 000,000,000 | ---D | C] -- C:\found.002
[2013/01/11 21:11:36 | 000,035,328 | ---- | C] (IncrediMail, Ltd.) -- C:\Windows\SysNative\ImHttpComm.dll
[2013/01/11 21:11:36 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ARFC
[2013/01/11 21:10:10 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\PutLockerDownloader
[2013/01/11 21:09:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PutLockerDownloader
[2013/01/11 21:09:54 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PutLockerDownloader.com
[2013/01/11 21:09:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PutLockerDownloader.com
[1 C:\Users\Kitty Tsang\Desktop\*.tmp files -> C:\Users\Kitty Tsang\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/08 18:23:17 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/08 18:23:17 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/08 18:22:00 | 000,000,466 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2013/02/08 18:21:21 | 001,202,004 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/02/08 18:21:21 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/02/08 18:21:21 | 000,378,104 | ---- | M] () -- C:\Windows\SysNative\prfh0404.dat
[2013/02/08 18:21:21 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/02/08 18:21:21 | 000,099,568 | ---- | M] () -- C:\Windows\SysNative\prfc0404.dat
[2013/02/08 18:17:00 | 000,000,538 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/08 18:16:21 | 000,000,534 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/08 18:15:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/02/08 18:15:53 | 3151,417,344 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/08 18:14:01 | 000,000,121 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013/02/08 17:44:00 | 000,000,526 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/08 17:31:12 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/02/08 17:04:22 | 005,030,592 | R--- | M] (Swearware) -- C:\Users\Kitty Tsang\Desktop\ComboFix.exe
[2013/02/08 16:28:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Kitty Tsang\Desktop\OTL.exe
[2013/02/08 16:22:36 | 013,711,621 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\mbar-1.01.0.1020.zip
[2013/02/08 16:15:01 | 000,782,336 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\RogueKiller.exe
[2013/02/08 15:45:42 | 000,547,275 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Kitty Tsang\Desktop\JRT.exe
[2013/02/08 15:45:27 | 000,582,209 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\adwcleaner.exe
[2013/02/08 02:51:54 | 000,002,360 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\ASELF.lang
[2013/02/08 02:47:50 | 000,661,504 | ---- | M] (Bart Ubing) -- C:\Users\Kitty Tsang\Desktop\Windows_7_Logon_screen_editor_by_bcubing.exe
[2013/02/07 17:33:10 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\Kitty Tsang\Desktop\dds.com
[2013/02/07 00:17:12 | 000,018,760 | ---- | M] () -- C:\Windows\SysWow64\QQVistaHelper.dll
[2013/02/06 22:31:13 | 000,000,047 | ---- | M] () -- C:\Users\Kitty Tsang\AppData\Roaming\CoreAVC.ini
[2013/02/06 15:58:00 | 000,000,460 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Kitty Tsang.job
[2013/02/05 16:06:57 | 000,002,230 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/02/03 16:21:26 | 000,002,192 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\迅雷7.lnk
[2013/02/02 16:15:18 | 000,001,046 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\PPStream.lnk
[2013/02/02 15:04:04 | 000,211,560 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[2013/01/30 22:15:20 | 000,002,951 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\Microsoft Excel 2010.lnk
[2013/01/30 22:15:14 | 000,002,937 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\Microsoft PowerPoint 2010.lnk
[2013/01/30 22:15:00 | 000,001,242 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\Paint.lnk
[2013/01/29 21:58:31 | 000,000,866 | ---- | M] () -- C:\Windows\SysWow64\InstallUtil.InstallLog
[2013/01/29 21:41:02 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/01/24 10:02:30 | 000,037,720 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/01/11 22:04:40 | 000,000,000 | ---- | M] () -- C:\Users\Kitty Tsang\Documents\貝多芬第九號交響曲:貝多芬快樂頌.flv
[2013/01/11 02:36:14 | 000,000,000 | ---- | M] () -- C:\Users\Kitty Tsang\Documents\(HQ 192kb).flv
[2013/01/10 00:16:55 | 000,455,384 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[1 C:\Users\Kitty Tsang\Desktop\*.tmp files -> C:\Users\Kitty Tsang\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/08 18:13:52 | 000,000,121 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013/02/08 17:05:30 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/02/08 17:05:30 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/02/08 17:05:30 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/02/08 17:05:30 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/02/08 17:05:30 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/02/08 16:22:24 | 013,711,621 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\mbar-1.01.0.1020.zip
[2013/02/08 16:15:00 | 000,782,336 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\RogueKiller.exe
[2013/02/08 15:45:26 | 000,582,209 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\adwcleaner.exe
[2013/02/08 02:51:53 | 000,002,360 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\ASELF.lang
[2013/02/05 16:06:57 | 000,002,230 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/02/02 16:15:18 | 000,001,046 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\PPStream.lnk
[2013/02/02 15:06:27 | 000,000,538 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/02 15:06:24 | 000,000,534 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/30 22:15:20 | 000,002,951 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\Microsoft Excel 2010.lnk
[2013/01/30 22:15:14 | 000,002,937 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\Microsoft PowerPoint 2010.lnk
[2013/01/30 22:15:00 | 000,001,242 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\Paint.lnk
[2013/01/30 22:14:37 | 000,002,192 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\迅雷7.lnk
[2013/01/29 21:54:55 | 000,087,040 | ---- | C] () -- C:\Windows\SysNative\pdfcmnnt.dll
[2013/01/29 00:41:04 | 000,000,866 | ---- | C] () -- C:\Windows\SysWow64\InstallUtil.InstallLog
[2013/01/11 22:04:22 | 000,000,000 | ---- | C] () -- C:\Users\Kitty Tsang\Documents\貝多芬第九號交響曲:貝多芬快樂頌.flv
[2013/01/11 21:11:36 | 001,261,936 | ---- | C] () -- C:\Windows\SysNative\dmwu.exe
[2013/01/11 02:36:14 | 000,000,000 | ---- | C] () -- C:\Users\Kitty Tsang\Documents\(HQ 192kb).flv
[2012/12/24 23:31:42 | 002,299,360 | ---- | C] () -- C:\Windows\SysWow64\kindling.dll
[2012/09/24 22:49:21 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2012/06/14 20:15:44 | 000,000,033 | ---- | C] () -- C:\Users\Kitty Tsang\AppData\Roaming\turing_files.ini
[2012/04/28 12:03:54 | 000,211,560 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/04/01 13:29:46 | 000,000,091 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2012/03/24 20:34:49 | 000,000,047 | ---- | C] () -- C:\Users\Kitty Tsang\AppData\Roaming\CoreAVC.ini
[2012/03/20 18:01:22 | 000,000,190 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2012/01/24 00:50:46 | 000,009,506 | ---- | C] () -- C:\Windows\UN070618.INI
[2011/08/13 01:05:36 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2011/07/28 11:52:17 | 000,000,020 | ---- | C] () -- C:\Windows\SysWow64\pub_store.dat
[2011/07/17 21:40:36 | 000,018,760 | ---- | C] () -- C:\Windows\SysWow64\QQVistaHelper.dll
[2011/07/15 10:17:49 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011/07/15 10:17:49 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/07/15 10:17:48 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/07/15 10:17:48 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/07/15 10:17:48 | 000,073,216 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/07/15 05:25:24 | 001,220,378 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/17 05:21:03 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011/04/17 05:15:22 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011/04/17 05:15:20 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011/04/17 05:15:17 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/11/08 17:18:21 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2012/11/08 17:18:21 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2012/06/10 18:35:50 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Audacity
[2012/11/06 16:26:37 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\AVG2013
[2013/01/24 13:51:36 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Dropbox
[2012/12/02 13:54:41 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\ExpressFiles
[2012/11/01 13:55:19 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Kugou7
[2013/02/06 05:26:10 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\KuGou8
[2012/08/01 08:24:09 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\OpenOffice.org
[2012/05/04 15:50:22 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PCDr
[2012/03/23 18:45:07 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PPLive
[2013/02/08 14:00:35 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PPStream
[2012/03/24 00:18:54 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PwrMgr
[2012/04/07 15:19:54 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\QQMusicUpdate
[2012/04/12 17:08:43 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\SoftGrid Client
[2012/11/06 16:17:58 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\TuneUp Software
[2012/08/27 19:12:19 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Youtube Downloader HD
[2012/07/23 22:15:26 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Youtube to MP3 Converter
[2012/08/08 19:05:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Application Data
[2012/04/20 15:51:20 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Auslogics
[2012/11/09 00:20:07 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\AVG2013
[2013/02/07 19:51:03 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Dropbox
[2012/05/04 22:15:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\duowan
[2013/02/02 15:45:59 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FreeFixer
[2012/10/31 21:28:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\KuGou7
[2013/02/05 09:24:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\KuGou8
[2012/03/20 15:54:40 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenOffice.org
[2011/08/23 22:01:06 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PCDr
[2012/08/08 19:07:27 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PPLive
[2012/11/25 19:25:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PPStream
[2011/07/15 05:32:22 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PwrMgr
[2012/10/06 00:53:59 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\QQMusicUpdate
[2012/04/01 14:34:29 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\SoftGrid Client
[2012/10/06 00:57:07 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Tencent
[2011/08/15 11:35:23 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Tific
[2011/07/15 05:25:53 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TP
[2011/08/07 00:42:27 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Update
[2012/04/20 23:50:35 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Wise Disk Cleaner
[2012/04/20 23:50:35 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Wise Registry Cleaner
[2012/08/23 08:57:51 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Youtube Downloader HD
[2012/08/23 01:34:34 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Youtube to MP3 Converter
========== Purity Check ==========
[2013/02/08 17:52:13 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/02/08 17:05:30 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/02/08 17:05:30 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/02/08 17:05:30 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/02/08 17:05:22 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/02/08 17:04:18 | 005,030,592 | R--- | C] (Swearware) -- C:\Users\Kitty Tsang\Desktop\ComboFix.exe
[2013/02/08 16:28:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Kitty Tsang\Desktop\OTL.exe
[2013/02/08 16:25:40 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\Desktop\mbar
[2013/02/08 16:08:35 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\Desktop\RK_Quarantine
[2013/02/08 15:45:38 | 000,547,275 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Kitty Tsang\Desktop\JRT.exe
[2013/02/08 02:53:15 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\Bart_Ubing
[2013/02/08 02:52:29 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\CRE
[2013/02/08 02:47:49 | 000,661,504 | ---- | C] (Bart Ubing) -- C:\Users\Kitty Tsang\Desktop\Windows_7_Logon_screen_editor_by_bcubing.exe
[2013/02/07 17:33:09 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\Kitty Tsang\Desktop\dds.com
[2013/02/07 17:30:40 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\Desktop\SecurityCheck
[2013/02/07 00:20:39 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\騰訊軟體
[2013/02/06 23:58:56 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\{CE18F04E-3F8F-4FD8-A23C-70FB5DAD9580}
[2013/02/06 11:09:21 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/02/06 10:35:44 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/02/06 10:35:19 | 000,000,000 | ---D | C] -- C:\JRT
[2013/02/05 16:06:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/02/02 15:45:47 | 000,000,000 | ---D | C] -- C:\Program Files\FreeFixer
[2013/02/01 12:19:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/01/29 21:54:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
[2013/01/29 21:54:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDFCreator
[2013/01/29 21:52:50 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\Updater21802
[2013/01/29 21:21:59 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logon Loader
[2013/01/29 21:11:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logon Loader
[2013/01/29 21:11:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Logon Loader
[2013/01/24 14:44:36 | 000,000,000 | ---D | C] -- C:\found.002
[2013/01/11 21:11:36 | 000,035,328 | ---- | C] (IncrediMail, Ltd.) -- C:\Windows\SysNative\ImHttpComm.dll
[2013/01/11 21:11:36 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ARFC
[2013/01/11 21:10:10 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Local\PutLockerDownloader
[2013/01/11 21:09:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PutLockerDownloader
[2013/01/11 21:09:54 | 000,000,000 | ---D | C] -- C:\Users\Kitty Tsang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PutLockerDownloader.com
[2013/01/11 21:09:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PutLockerDownloader.com
[1 C:\Users\Kitty Tsang\Desktop\*.tmp files -> C:\Users\Kitty Tsang\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/08 18:23:17 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/08 18:23:17 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/08 18:22:00 | 000,000,466 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2013/02/08 18:21:21 | 001,202,004 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/02/08 18:21:21 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/02/08 18:21:21 | 000,378,104 | ---- | M] () -- C:\Windows\SysNative\prfh0404.dat
[2013/02/08 18:21:21 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/02/08 18:21:21 | 000,099,568 | ---- | M] () -- C:\Windows\SysNative\prfc0404.dat
[2013/02/08 18:17:00 | 000,000,538 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/08 18:16:21 | 000,000,534 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/08 18:15:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/02/08 18:15:53 | 3151,417,344 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/08 18:14:01 | 000,000,121 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013/02/08 17:44:00 | 000,000,526 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/08 17:31:12 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/02/08 17:04:22 | 005,030,592 | R--- | M] (Swearware) -- C:\Users\Kitty Tsang\Desktop\ComboFix.exe
[2013/02/08 16:28:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Kitty Tsang\Desktop\OTL.exe
[2013/02/08 16:22:36 | 013,711,621 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\mbar-1.01.0.1020.zip
[2013/02/08 16:15:01 | 000,782,336 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\RogueKiller.exe
[2013/02/08 15:45:42 | 000,547,275 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Kitty Tsang\Desktop\JRT.exe
[2013/02/08 15:45:27 | 000,582,209 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\adwcleaner.exe
[2013/02/08 02:51:54 | 000,002,360 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\ASELF.lang
[2013/02/08 02:47:50 | 000,661,504 | ---- | M] (Bart Ubing) -- C:\Users\Kitty Tsang\Desktop\Windows_7_Logon_screen_editor_by_bcubing.exe
[2013/02/07 17:33:10 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\Kitty Tsang\Desktop\dds.com
[2013/02/07 00:17:12 | 000,018,760 | ---- | M] () -- C:\Windows\SysWow64\QQVistaHelper.dll
[2013/02/06 22:31:13 | 000,000,047 | ---- | M] () -- C:\Users\Kitty Tsang\AppData\Roaming\CoreAVC.ini
[2013/02/06 15:58:00 | 000,000,460 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Kitty Tsang.job
[2013/02/05 16:06:57 | 000,002,230 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/02/03 16:21:26 | 000,002,192 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\迅雷7.lnk
[2013/02/02 16:15:18 | 000,001,046 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\PPStream.lnk
[2013/02/02 15:04:04 | 000,211,560 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[2013/01/30 22:15:20 | 000,002,951 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\Microsoft Excel 2010.lnk
[2013/01/30 22:15:14 | 000,002,937 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\Microsoft PowerPoint 2010.lnk
[2013/01/30 22:15:00 | 000,001,242 | ---- | M] () -- C:\Users\Kitty Tsang\Desktop\Paint.lnk
[2013/01/29 21:58:31 | 000,000,866 | ---- | M] () -- C:\Windows\SysWow64\InstallUtil.InstallLog
[2013/01/29 21:41:02 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/01/24 10:02:30 | 000,037,720 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/01/11 22:04:40 | 000,000,000 | ---- | M] () -- C:\Users\Kitty Tsang\Documents\貝多芬第九號交響曲:貝多芬快樂頌.flv
[2013/01/11 02:36:14 | 000,000,000 | ---- | M] () -- C:\Users\Kitty Tsang\Documents\(HQ 192kb).flv
[2013/01/10 00:16:55 | 000,455,384 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[1 C:\Users\Kitty Tsang\Desktop\*.tmp files -> C:\Users\Kitty Tsang\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/08 18:13:52 | 000,000,121 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013/02/08 17:05:30 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/02/08 17:05:30 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/02/08 17:05:30 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/02/08 17:05:30 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/02/08 17:05:30 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/02/08 16:22:24 | 013,711,621 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\mbar-1.01.0.1020.zip
[2013/02/08 16:15:00 | 000,782,336 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\RogueKiller.exe
[2013/02/08 15:45:26 | 000,582,209 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\adwcleaner.exe
[2013/02/08 02:51:53 | 000,002,360 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\ASELF.lang
[2013/02/05 16:06:57 | 000,002,230 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/02/02 16:15:18 | 000,001,046 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\PPStream.lnk
[2013/02/02 15:06:27 | 000,000,538 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/02 15:06:24 | 000,000,534 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/30 22:15:20 | 000,002,951 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\Microsoft Excel 2010.lnk
[2013/01/30 22:15:14 | 000,002,937 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\Microsoft PowerPoint 2010.lnk
[2013/01/30 22:15:00 | 000,001,242 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\Paint.lnk
[2013/01/30 22:14:37 | 000,002,192 | ---- | C] () -- C:\Users\Kitty Tsang\Desktop\迅雷7.lnk
[2013/01/29 21:54:55 | 000,087,040 | ---- | C] () -- C:\Windows\SysNative\pdfcmnnt.dll
[2013/01/29 00:41:04 | 000,000,866 | ---- | C] () -- C:\Windows\SysWow64\InstallUtil.InstallLog
[2013/01/11 22:04:22 | 000,000,000 | ---- | C] () -- C:\Users\Kitty Tsang\Documents\貝多芬第九號交響曲:貝多芬快樂頌.flv
[2013/01/11 21:11:36 | 001,261,936 | ---- | C] () -- C:\Windows\SysNative\dmwu.exe
[2013/01/11 02:36:14 | 000,000,000 | ---- | C] () -- C:\Users\Kitty Tsang\Documents\(HQ 192kb).flv
[2012/12/24 23:31:42 | 002,299,360 | ---- | C] () -- C:\Windows\SysWow64\kindling.dll
[2012/09/24 22:49:21 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2012/06/14 20:15:44 | 000,000,033 | ---- | C] () -- C:\Users\Kitty Tsang\AppData\Roaming\turing_files.ini
[2012/04/28 12:03:54 | 000,211,560 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/04/01 13:29:46 | 000,000,091 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2012/03/24 20:34:49 | 000,000,047 | ---- | C] () -- C:\Users\Kitty Tsang\AppData\Roaming\CoreAVC.ini
[2012/03/20 18:01:22 | 000,000,190 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2012/01/24 00:50:46 | 000,009,506 | ---- | C] () -- C:\Windows\UN070618.INI
[2011/08/13 01:05:36 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2011/07/28 11:52:17 | 000,000,020 | ---- | C] () -- C:\Windows\SysWow64\pub_store.dat
[2011/07/17 21:40:36 | 000,018,760 | ---- | C] () -- C:\Windows\SysWow64\QQVistaHelper.dll
[2011/07/15 10:17:49 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011/07/15 10:17:49 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/07/15 10:17:48 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/07/15 10:17:48 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/07/15 10:17:48 | 000,073,216 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/07/15 05:25:24 | 001,220,378 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/17 05:21:03 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011/04/17 05:15:22 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011/04/17 05:15:20 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011/04/17 05:15:17 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/11/08 17:18:21 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2012/11/08 17:18:21 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2012/06/10 18:35:50 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Audacity
[2012/11/06 16:26:37 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\AVG2013
[2013/01/24 13:51:36 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Dropbox
[2012/12/02 13:54:41 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\ExpressFiles
[2012/11/01 13:55:19 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Kugou7
[2013/02/06 05:26:10 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\KuGou8
[2012/08/01 08:24:09 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\OpenOffice.org
[2012/05/04 15:50:22 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PCDr
[2012/03/23 18:45:07 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PPLive
[2013/02/08 14:00:35 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PPStream
[2012/03/24 00:18:54 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\PwrMgr
[2012/04/07 15:19:54 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\QQMusicUpdate
[2012/04/12 17:08:43 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\SoftGrid Client
[2012/11/06 16:17:58 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\TuneUp Software
[2012/08/27 19:12:19 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Youtube Downloader HD
[2012/07/23 22:15:26 | 000,000,000 | ---D | M] -- C:\Users\Kitty Tsang\AppData\Roaming\Youtube to MP3 Converter
[2012/08/08 19:05:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Application Data
[2012/04/20 15:51:20 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Auslogics
[2012/11/09 00:20:07 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\AVG2013
[2013/02/07 19:51:03 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Dropbox
[2012/05/04 22:15:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\duowan
[2013/02/02 15:45:59 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\FreeFixer
[2012/10/31 21:28:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\KuGou7
[2013/02/05 09:24:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\KuGou8
[2012/03/20 15:54:40 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenOffice.org
[2011/08/23 22:01:06 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PCDr
[2012/08/08 19:07:27 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PPLive
[2012/11/25 19:25:13 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PPStream
[2011/07/15 05:32:22 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PwrMgr
[2012/10/06 00:53:59 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\QQMusicUpdate
[2012/04/01 14:34:29 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\SoftGrid Client
[2012/10/06 00:57:07 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Tencent
[2011/08/15 11:35:23 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Tific
[2011/07/15 05:25:53 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\TP
[2011/08/07 00:42:27 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Update
[2012/04/20 23:50:35 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Wise Disk Cleaner
[2012/04/20 23:50:35 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Wise Registry Cleaner
[2012/08/23 08:57:51 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Youtube Downloader HD
[2012/08/23 01:34:34 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Youtube to MP3 Converter
========== Purity Check ==========