Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

laptop running slow [Solved]


  • This topic is locked This topic is locked

#16
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK final stretch, could you run a fresh OTL scan please to see what remains. How is the computer now ?
  • 0

Advertisements


#17
nigella

nigella

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 216 posts
OTL logfile created on: 23/06/2013 14:05:22 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\lesley\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

893.69 Mb Total Physical Memory | 278.09 Mb Available Physical Memory | 31.12% Memory free
2.00 Gb Paging File | 0.94 Gb Available in Paging File | 46.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.98 Gb Total Space | 70.88 Gb Free Space | 51.00% Space Free | Partition Type: NTFS
Drive D: | 10.07 Gb Total Space | 1.75 Gb Free Space | 17.38% Space Free | Partition Type: NTFS

Computer Name: LESLEY-PC | User Name: lesley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/06/19 21:08:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\lesley\Desktop\OTL.exe
PRC - [2013/06/15 02:28:44 | 000,825,808 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2013/05/22 10:23:58 | 000,101,552 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\20.4.0.40\ccsvchst.exe
PRC - [2012/12/18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2009/07/16 14:43:04 | 000,241,664 | ---- | M] () -- C:\Program Files\T-Mobile Mobile Broadband Manager\AssistantServices.exe
PRC - [2009/07/16 14:42:20 | 000,132,608 | ---- | M] () -- C:\Program Files\T-Mobile Mobile Broadband Manager\UIExec.exe
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/10/06 17:54:52 | 000,365,952 | ---- | M] () -- C:\Program Files\SMINST\BLService.exe
PRC - [2008/06/13 15:26:54 | 002,498,560 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.exe


========== Modules (No Company Name) ==========

MOD - [2013/06/15 02:28:42 | 000,393,168 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\27.0.1453.116\ppgooglenaclpluginchrome.dll
MOD - [2013/06/15 02:28:40 | 004,051,408 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\27.0.1453.116\pdf.dll
MOD - [2013/06/15 02:27:48 | 001,597,392 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\27.0.1453.116\ffmpegsumo.dll
MOD - [2013/05/17 20:09:27 | 001,801,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\2a0bdb3ab5d40efcf07ac933e3b9c8e4\System.Deployment.ni.dll
MOD - [2013/05/17 20:09:23 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\3da65115bf9debbf564861f6b123a2e4\System.Configuration.ni.dll
MOD - [2013/05/16 19:33:14 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e9ea3e70247b4aa4a8b260426db3aa6b\System.Windows.Forms.ni.dll
MOD - [2013/05/16 19:26:54 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2673a8a481ae675588349b79b521cec1\PresentationFramework.ni.dll
MOD - [2013/05/16 19:25:22 | 012,219,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\a3968930e9e2ae833447b0a280082073\PresentationCore.ni.dll
MOD - [2013/05/16 19:23:57 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fe2a238282c6fedc2a21b3dd25885437\WindowsBase.ni.dll
MOD - [2013/01/11 20:08:22 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f042f66c2ad8fd5b8c34fa22cd22079e\System.Management.ni.dll
MOD - [2013/01/11 17:50:49 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b5df40c22ab563a816103629e2ca99d4\System.Runtime.Remoting.ni.dll
MOD - [2013/01/11 17:50:22 | 000,627,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\36dc923935a96557c81daa014e7e2ba8\System.EnterpriseServices.ni.dll
MOD - [2013/01/11 17:50:22 | 000,280,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\36dc923935a96557c81daa014e7e2ba8\System.EnterpriseServices.Wrapper.dll
MOD - [2013/01/11 17:49:52 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\d995a0e7d64a874cddea6294caaa2539\System.Transactions.ni.dll
MOD - [2013/01/11 17:42:35 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\7d59f2903b3f994f38b160cd32ccd1a0\System.Xml.ni.dll
MOD - [2013/01/11 17:40:54 | 001,593,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll
MOD - [2013/01/11 17:38:49 | 006,621,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\0f5a23bb73681b6388daccd8e250ba66\System.Data.ni.dll
MOD - [2013/01/11 17:38:19 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\4d2c890606d2a3a43a90684115bfccfc\PresentationFramework.Aero.ni.dll
MOD - [2013/01/11 17:33:01 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll
MOD - [2013/01/11 17:32:38 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll
MOD - [2012/05/30 07:51:08 | 000,699,280 | R--- | M] () -- C:\Program Files\Norton 360\Engine\20.4.0.40\wincfi39.dll
MOD - [2012/05/25 04:25:00 | 000,921,600 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2011/09/27 08:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/07/16 14:42:20 | 000,132,608 | ---- | M] () -- C:\Program Files\T-Mobile Mobile Broadband Manager\UIExec.exe
MOD - [2009/04/11 07:28:21 | 000,368,640 | ---- | M] () -- C:\Windows\System32\msjetoledb40.dll
MOD - [2009/04/11 03:04:15 | 000,113,664 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
MOD - [2009/03/30 05:42:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/03/30 05:42:17 | 002,933,760 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2008/10/01 00:56:06 | 000,032,768 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\Content.XmlSerializers.dll
MOD - [2008/10/01 00:52:02 | 000,007,168 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\RemotingClient.dll
MOD - [2008/10/01 00:52:00 | 000,057,344 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll
MOD - [2008/10/01 00:51:52 | 000,118,784 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\ECLibrary.dll
MOD - [2008/10/01 00:51:52 | 000,010,240 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingClients.dll
MOD - [2008/10/01 00:51:36 | 000,040,960 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingServer.dll
MOD - [2008/10/01 00:51:36 | 000,028,672 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingMessages.dll
MOD - [2008/10/01 00:51:36 | 000,005,632 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingInterface.dll
MOD - [2008/06/13 15:26:54 | 002,498,560 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
MOD - [2007/08/14 21:59:54 | 006,365,184 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\QtGui4.dll
MOD - [2007/07/12 21:55:52 | 000,131,072 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2007/07/12 21:55:28 | 001,581,056 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\QtCore4.dll


========== Services (SafeList) ==========

SRV - [2013/06/11 21:21:36 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/22 10:23:58 | 000,101,552 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe -- (N360)
SRV - [2012/12/18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/07/20 18:21:59 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/07/16 14:43:04 | 000,241,664 | ---- | M] () [Auto | Running] -- C:\Program Files\T-Mobile Mobile Broadband Manager\AssistantServices.exe -- (UI Assistant Service)
SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/10/06 17:54:52 | 000,365,952 | ---- | M] () [Auto | Running] -- C:\Program Files\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/02/03 20:00:00 | 000,129,992 | ---- | M] (EasyBits Sofware AS) [Auto | Running] -- C:\Windows\System32\ezsvc7.dll -- (ezSharedSvc)
SRV - [2008/01/21 03:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\lesley\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2013/06/19 18:53:05 | 000,142,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2013/05/31 17:58:19 | 001,002,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130531.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2013/05/23 06:25:28 | 000,934,488 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\N360\1404000.028\symefa.sys -- (SymEFA)
DRV - [2013/05/22 17:40:20 | 001,611,992 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130622.007\NAVEX15.SYS -- (NAVEX15)
DRV - [2013/05/22 17:40:18 | 000,093,272 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130622.007\NAVENG.SYS -- (NAVENG)
DRV - [2013/05/21 06:02:00 | 000,367,704 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\N360\1404000.028\symds.sys -- (SymDS)
DRV - [2013/05/18 12:15:59 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2013/05/17 15:30:54 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130621.001\IDSvix86.sys -- (IDSVix86)
DRV - [2013/05/16 06:02:14 | 000,603,224 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\N360\1404000.028\srtsp.sys -- (SRTSP)
DRV - [2013/04/25 01:43:56 | 000,352,344 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\1404000.028\symtdiv.sys -- (SYMTDIv)
DRV - [2013/04/16 03:41:14 | 000,134,744 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\1404000.028\ccsetx86.sys -- (ccSet_N360)
DRV - [2013/03/05 02:39:19 | 000,175,264 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\1404000.028\ironx86.sys -- (SymIRON)
DRV - [2013/03/05 02:21:35 | 000,032,344 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\1404000.028\srtspx.sys -- (SRTSPX)
DRV - [2013/01/31 02:00:00 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/08/12 13:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVNET)
DRV - [2010/08/12 13:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2009/09/05 17:55:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/24 16:51:38 | 000,101,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbdev.sys -- (hwusbdev)
DRV - [2009/07/23 21:01:00 | 009,791,072 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/06/22 21:01:02 | 000,112,128 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009/06/22 20:38:24 | 000,102,912 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009/05/22 09:08:38 | 000,022,528 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Unknown] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2009/05/22 09:08:38 | 000,018,816 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2009/05/22 09:04:04 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/05/22 09:04:04 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/05/22 09:04:04 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009/05/22 09:04:04 | 000,009,728 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter)
DRV - [2008/10/03 04:39:28 | 000,222,208 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2008/05/09 20:17:32 | 000,043,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2008/04/24 23:51:46 | 000,014,848 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008/01/21 03:32:45 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32)
DRV - [2007/10/18 00:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/06/19 01:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/04/23 10:50:50 | 000,025,896 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | System | Running] -- C:\Windows\System32\drivers\RtlProt.sys -- (RtlProt)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{494B132A-A82E-440B-9955-53AD3F339A0E}: "URL" = http://uk.search.yah...p06&type=ie2008

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://http://www.ya...ilc=8.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{494B132A-A82E-440B-9955-53AD3F339A0E}: "URL" = http://uk.search.yah...p06&type=ie2008
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKCU\..\SearchScopes\{E0B517E4-80FD-4573-A094-E9C99A34CEB0}: "URL" = http://search.yahoo....=utf-8&fr=b1ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....ch?fr=ffsp1&p="
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/?ilc=8"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315
FF - prefs.js..extensions.enabledItems: [email protected]:4.1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..keyword.URL: "http://uk.search.yah...h?fr=mcafee&p="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\T-Mobile Mobile Broadband Manager\addon [2010/06/12 15:06:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2013/06/06 20:13:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\coFFPlgn\ [2013/06/23 12:46:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\IPSFFPlgn\ [2013/05/18 16:00:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/05 20:56:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/06/20 22:32:13 | 000,000,000 | ---D | M]

[2009/06/27 13:34:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lesley\AppData\Roaming\Mozilla\Extensions
[2013/06/20 22:32:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\extensions
[2009/09/02 22:19:11 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/03 14:53:15 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/06/26 00:05:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/06/26 00:05:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2010/06/12 15:06:02 | 000,000,000 | ---D | M] (Bytemobile Optimization Client) -- C:\PROGRAM FILES\T-MOBILE MOBILE BROADBAND MANAGER\ADDON
File not found (No name found) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\COFFPLGN
File not found (No name found) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPLGN
File not found (No name found) -- C:\USERS\LESLEY\APPDATA\LOCAL\{337D5158-7284-4835-B7AF-CE4F08F7D7C2}
[2010/08/03 19:20:49 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/08/03 19:20:49 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/08/03 19:20:50 | 000,000,759 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2013/05/31 20:26:44 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2010/08/03 19:20:50 | 000,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: McAfee (Enabled)
CHR - default_search_provider: search_url = http://uk.search.yah...p={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - Extension: Docs = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\
CHR - Extension: Google Drive = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: FreeHDSport.TV = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnnidmnbdkmhfkjgdnngciimpdgohok\1.1_0\
CHR - Extension: YouTube = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: SiteAdvisor = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.2.1341_0\
CHR - Extension: Norton Identity Protection = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0\
CHR - Extension: Smiley Bar for Facebook = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\mocblcnaofikinigmceddfghppkkjbog\1.0.0.0_0\
CHR - Extension: Gmail = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/06/22 00:11:44 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [UIExec] C:\Program Files\T-Mobile Mobile Broadband Manager\UIExec.exe ()
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-GB\local\search.html ()
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll/206 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F2B3000-315B-4E23-A67B-FBFDEE106A0D}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CE65EEA7-EC85-45B6-A237-D1A115EDD8C8}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\System32\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/22 00:25:40 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/06/22 00:25:00 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013/06/21 23:38:53 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/06/21 23:38:53 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/06/21 23:38:52 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/06/21 23:37:59 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013/06/21 23:20:31 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/06/21 23:18:40 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/06/21 23:12:50 | 005,081,922 | R--- | C] (Swearware) -- C:\Users\lesley\Desktop\ComboFix.exe
[2013/06/21 20:40:11 | 000,000,000 | ---D | C] -- C:\Users\lesley\AppData\Local\{B6291640-3391-451F-A4DC-06A4EBB93FE0}
[2013/06/21 20:05:56 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/06/21 20:04:51 | 000,000,000 | ---D | C] -- C:\JRT
[2013/06/20 22:29:13 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/06/19 21:06:30 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\lesley\Desktop\OTL.exe
[2013/06/13 21:58:20 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/06/13 21:58:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/06/13 21:58:04 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/06/13 21:58:02 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013/06/13 21:57:55 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/06/13 21:57:53 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/06/13 21:57:52 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/06/13 21:57:44 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013/06/13 20:59:01 | 000,000,000 | ---D | C] -- C:\dac79b0d534fcc35a522be
[2013/06/12 18:59:43 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printcom.dll
[2013/06/12 18:59:30 | 003,603,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013/06/12 18:59:29 | 003,551,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013/06/12 18:58:51 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certutil.exe
[2013/06/12 18:58:49 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certenc.dll
[2013/06/12 18:57:56 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptdlg.dll
[2013/06/04 21:02:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger

========== Files - Modified Within 30 Days ==========

[2013/06/23 14:06:08 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/23 14:03:07 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/23 12:57:38 | 000,000,248 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2013/06/23 12:52:44 | 000,048,222 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2013/06/23 12:52:41 | 000,048,222 | ---- | M] () -- C:\ProgramData\nvModes.001
[2013/06/23 12:51:12 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/23 12:44:55 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/23 12:44:55 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/23 12:44:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/23 12:05:59 | 000,648,201 | ---- | M] () -- C:\Users\lesley\Desktop\adwcleaner.exe
[2013/06/23 10:15:45 | 000,008,484 | ---- | M] () -- C:\Users\lesley\AppData\Local\d3d9caps.dat
[2013/06/22 00:11:44 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013/06/21 23:14:16 | 005,081,922 | R--- | M] (Swearware) -- C:\Users\lesley\Desktop\ComboFix.exe
[2013/06/20 22:13:30 | 000,001,927 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Chrome.lnk
[2013/06/19 21:08:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\lesley\Desktop\OTL.exe
[2013/06/19 20:02:14 | 000,002,015 | ---- | M] () -- C:\Users\Public\Desktop\Norton 360.lnk
[2013/06/19 19:53:45 | 002,339,343 | ---- | M] () -- C:\Windows\System32\drivers\N360\1404000.028\Cat.DB
[2013/06/19 19:52:16 | 000,014,818 | ---- | M] () -- C:\Windows\System32\drivers\N360\1404000.028\VT20130115.021
[2013/06/19 19:33:10 | 000,001,927 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/06/19 18:53:05 | 000,142,496 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2013/06/19 18:53:05 | 000,007,611 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2013/06/19 18:53:05 | 000,000,805 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF
[2013/06/11 21:19:59 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013/06/11 21:19:59 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/06/09 23:47:50 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForlesley.job
[2013/06/06 21:09:59 | 000,609,196 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/06/06 21:09:59 | 000,108,672 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/06/04 21:02:57 | 000,000,940 | ---- | M] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2013/06/04 21:02:56 | 000,000,964 | ---- | M] () -- C:\Users\lesley\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2013/06/04 07:36:13 | 000,000,172 | ---- | M] () -- C:\Windows\System32\drivers\N360\1404000.028\isolate.ini
[2013/05/31 20:34:04 | 000,003,624 | ---- | M] () -- C:\{DDE5FF53-A04B-420D-80BE-8B3583E579F7}
[2013/05/25 12:39:41 | 000,008,704 | ---- | M] () -- C:\Users\lesley\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2013/06/23 11:53:31 | 000,648,201 | ---- | C] () -- C:\Users\lesley\Desktop\adwcleaner.exe
[2013/06/21 23:38:53 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/06/21 23:38:53 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/06/21 23:38:52 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/06/21 23:38:52 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/06/21 23:38:52 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/06/20 22:13:30 | 000,001,927 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Chrome.lnk
[2013/06/04 21:02:57 | 000,000,940 | ---- | C] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2013/06/04 21:02:56 | 000,000,964 | ---- | C] () -- C:\Users\lesley\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2013/05/31 20:34:03 | 000,003,624 | ---- | C] () -- C:\{DDE5FF53-A04B-420D-80BE-8B3583E579F7}
[2010/08/02 23:32:15 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uremomix.dll
[2010/08/02 21:30:10 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iqisozidohugi.dll
[2010/08/02 19:28:10 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\udulibikixe.dll
[2010/08/01 23:05:19 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\okujecuxiq.dll
[2010/08/01 21:02:58 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iyekuyepebeham.dll
[2010/08/01 14:29:05 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ocaxobeditexete.dll
[2010/08/01 02:28:58 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ewigobabamisa.dll
[2010/08/01 00:26:58 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\evejopevogani.dll
[2010/07/31 22:24:58 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\eleqocefuwej.dll
[2010/07/31 04:31:02 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\udobalepinubesi.dll
[2010/07/30 22:15:30 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ubifuyiw.dll
[2010/07/30 20:13:08 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\udebotax.dll
[2010/07/30 18:11:09 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\owepejid.dll
[2010/07/30 14:42:45 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ilonepoza.dll
[2010/07/30 12:40:45 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\epapozadu.dll
[2010/07/29 23:44:36 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ewufayoqevi.dll
[2010/07/29 21:42:15 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ajuzaxeqetalajo.dll
[2010/07/29 19:40:57 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iqisagubi.dll
[2010/07/29 14:36:49 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ememomixefenoy.dll
[2010/07/29 12:35:07 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\azasanukukub.dll
[2010/07/29 10:32:50 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ijisozid.dll
[2010/07/28 23:51:13 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ivafiyas.dll
[2010/07/28 21:48:50 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\otodovuj.dll
[2010/07/28 19:46:50 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\aqudumok.dll
[2010/07/27 22:52:47 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uvepamep.dll
[2010/07/26 23:39:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ofoguzele.dll
[2010/07/26 23:25:13 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ubetenim.dll
[2010/07/26 21:23:16 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\eloyicubucamot.dll
[2010/07/25 23:40:15 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ekimamerih.dll
[2010/07/25 21:38:14 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uzeroyowuyazam.dll
[2010/07/25 19:36:14 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uzoqikuwafonutul.dll
[2010/07/25 17:34:14 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ojegejopevo.dll
[2010/07/25 14:20:34 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ezegoweli.dll
[2010/07/25 01:07:22 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\icitegixiv.dll
[2010/07/25 00:35:00 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ufeyijevula.dll
[2010/07/24 22:33:14 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\acitiwuvubomure.dll
[2010/07/23 23:43:19 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\olabepaguh.dll
[2010/07/23 21:38:04 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iconasowovone.dll
[2010/07/23 19:06:15 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ewovuhox.dll
[2010/07/22 23:52:17 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\apojepope.dll
[2010/07/22 00:23:50 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uhuyujup.dll
[2010/07/21 22:54:55 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ijepamep.dll
[2010/07/21 21:06:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\adudilak.dll
[2010/07/21 20:54:07 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\eruyewiducena.dll
[2010/07/20 23:10:01 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iwefumak.dll
[2010/07/20 21:08:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iputaduxotoyeful.dll
[2010/07/19 23:42:56 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\utaxasuxomod.dll
[2010/07/19 21:37:53 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\enaxijokiqovab.dll
[2010/07/19 18:28:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\exitoced.dll
[2010/07/19 00:22:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ufoyoxajij.dll
[2010/07/18 22:20:22 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\umevumeged.dll
[2010/07/17 21:54:38 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\oquvuwox.dll
[2010/07/17 19:52:41 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ahegokidonotudok.dll
[2010/07/17 17:48:28 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\enomihudu.dll
[2010/07/16 22:37:41 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ilawelijosi.dll
[2010/07/16 20:35:40 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ibopikeb.dll
[2010/07/16 17:16:02 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ifixoqirac.dll
[2010/07/15 23:55:22 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ebiwukaza.dll
[2010/07/15 21:53:23 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\odorafoxosivolup.dll
[2010/07/14 22:31:55 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ajehoyop.dll
[2010/07/14 22:13:56 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\efidusex.dll
[2010/07/13 22:23:45 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\evohecew.dll
[2010/07/13 20:21:44 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ufepulukelikuf.dll
[2010/07/13 18:19:43 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\evuderirif.dll
[2010/07/13 00:56:10 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ohubemojokesiy.dll
[2010/07/12 22:54:09 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ecogugek.dll
[2010/07/12 20:52:09 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ebeberer.dll
[2010/07/11 23:41:04 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ixebuxidetayol.dll
[2010/07/11 21:29:27 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\emiyugup.dll
[2010/07/11 19:27:27 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ufosuxidigibavuk.dll
[2010/07/11 16:00:57 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ezejiyerezuqah.dll
[2010/07/10 23:53:11 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ohazopes.dll
[2010/07/10 21:51:11 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\uxaxemex.dll
[2010/07/10 19:49:10 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\upukulej.dll
[2010/07/10 12:43:02 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\amorowov.dll
[2010/07/09 17:28:08 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\iresozoq.dll
[2010/07/02 20:20:42 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\aruwuroviqo.dll
[2010/07/02 18:18:41 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\efuyiyukejub.dll
[2010/05/29 19:16:00 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\inojupiliyojo.dll
[2010/05/28 19:52:00 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\ipidobuvogepu.dll
[2010/04/08 23:16:00 | 000,023,090 | ---- | C] () -- C:\Users\lesley\AppData\Local\ipobohid.dll
[2010/04/07 21:07:39 | 000,023,090 | ---- | C] () -- C:\Users\lesley\AppData\Local\ibeciquc.dll
[2010/01/30 22:08:18 | 000,008,484 | ---- | C] () -- C:\Users\lesley\AppData\Local\d3d9caps.dat
[2010/01/15 17:28:53 | 000,000,120 | ---- | C] () -- C:\Users\lesley\AppData\Local\Amaloxubacepexo.dat
[2010/01/15 17:28:53 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\Jnidakusadiyu.bin
[2010/01/15 17:25:11 | 000,000,020 | ---- | C] () -- C:\Users\lesley\AppData\Roaming\mvhgkr.dat
[2010/01/15 17:25:07 | 000,000,004 | ---- | C] () -- C:\Users\lesley\AppData\Roaming\avdrn.dat
[2009/10/12 17:55:41 | 000,008,704 | ---- | C] () -- C:\Users\lesley\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/24 20:18:00 | 000,048,222 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/06/24 20:10:48 | 000,048,222 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/04/14 17:49:08 | 000,000,248 | ---- | C] () -- C:\ProgramData\hpqp.ini

========== ZeroAccess Check ==========

[2006/11/02 13:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Files - Unicode (All) ==========
[2013/05/14 18:25:13 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/14 18:25:13 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/12 19:52:18 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƣ䃘Ƣ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/12 19:52:18 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƣ䃘Ƣ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/10 16:17:05 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƛ䃘ƛ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/10 16:17:05 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƛ䃘ƛ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/08 11:32:02 | 000,000,000 | ---D | M](C:\ProgramData\?i?i?????????????????????????) -- C:\ProgramData\䏨ǐ䃘ǐ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/08 11:32:02 | 000,000,000 | ---D | M](C:\ProgramData\?i?i?????????????????????????) -- C:\ProgramData\䏨ǐ䃘ǐ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/07 16:09:29 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/07 16:09:29 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/03 19:45:09 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǡ䃘Ǡ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/03 19:45:09 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǡ䃘Ǡ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/01 12:18:52 | 000,000,000 | ---D | M](C:\ProgramData\?y?y?????????????????????????) -- C:\ProgramData\䏨y䃘y浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/05/01 12:18:52 | 000,000,000 | ---D | M](C:\ProgramData\?y?y?????????????????????????) -- C:\ProgramData\䏨y䃘y浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/30 11:46:09 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/30 11:46:09 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/27 15:17:44 | 000,000,000 | ---D | M](C:\ProgramData\?E?E?????????????????????????) -- C:\ProgramData\䏨Ē䃘Ē浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/27 15:17:44 | 000,000,000 | ---D | M](C:\ProgramData\?E?E?????????????????????????) -- C:\ProgramData\䏨Ē䃘Ē浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/25 15:24:14 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ǽ䃘ǽ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/25 15:24:14 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ǽ䃘ǽ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/23 20:14:45 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/23 20:14:45 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/23 18:30:35 | 000,000,000 | ---D | M](C:\ProgramData\?.?.0) -- C:\ProgramData\䐀.䂰.0
[2013/04/23 18:30:35 | 000,000,000 | ---D | M](C:\ProgramData\?.?.0) -- C:\ProgramData\䐀.䂰.0
[2013/04/23 13:04:02 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ȥ䃘ȥ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/23 13:04:02 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ȥ䃘ȥ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/22 10:15:25 | 000,000,000 | ---D | M](C:\ProgramData\?{?{?????????????????????????) -- C:\ProgramData\䏨{䃘{浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/22 10:15:25 | 000,000,000 | ---D | M](C:\ProgramData\?{?{?????????????????????????) -- C:\ProgramData\䏨{䃘{浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/19 17:44:49 | 000,000,000 | ---D | M](C:\ProgramData\?O?O?????????????????????????) -- C:\ProgramData\䏨Ǒ䃘Ǒ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/19 17:44:49 | 000,000,000 | ---D | M](C:\ProgramData\?O?O?????????????????????????) -- C:\ProgramData\䏨Ǒ䃘Ǒ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/18 19:07:21 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Lj䃘Lj浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/18 19:07:21 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Lj䃘Lj浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/16 14:47:10 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/16 14:47:10 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/16 10:35:30 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/16 10:35:30 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/13 16:01:40 | 000,000,000 | ---D | M](C:\ProgramData\?~?~?????????????????????????) -- C:\ProgramData\䏨~䃘~浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/13 16:01:40 | 000,000,000 | ---D | M](C:\ProgramData\?~?~?????????????????????????) -- C:\ProgramData\䏨~䃘~浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/11 19:23:44 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀ǻ䂰ǻ0
[2013/04/11 19:23:44 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀ǻ䂰ǻ0
[2013/04/11 19:09:16 | 000,000,000 | ---D | M](C:\ProgramData\?G?G0) -- C:\ProgramData\䐀Ǥ䂰Ǥ0
[2013/04/11 19:09:16 | 000,000,000 | ---D | M](C:\ProgramData\?G?G0) -- C:\ProgramData\䐀Ǥ䂰Ǥ0
[2013/04/11 13:41:53 | 000,000,000 | ---D | M](C:\ProgramData\?u?u?????????????????????????) -- C:\ProgramData\䏨ǘ䃘ǘ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/11 13:41:53 | 000,000,000 | ---D | M](C:\ProgramData\?u?u?????????????????????????) -- C:\ProgramData\䏨ǘ䃘ǘ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/10 16:40:10 | 000,000,000 | ---D | M](C:\ProgramData\?c?c?????????????????????????) -- C:\ProgramData\䏨ć䃘ć浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/10 16:40:10 | 000,000,000 | ---D | M](C:\ProgramData\?c?c?????????????????????????) -- C:\ProgramData\䏨ć䃘ć浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/09 10:23:25 | 000,000,000 | ---D | M](C:\ProgramData\[email protected][email protected]?????????????????????????) -- C:\ProgramData\䏨@䃘@浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/09 10:23:25 | 000,000,000 | ---D | M](C:\ProgramData\[email protected][email protected]?????????????????????????) -- C:\ProgramData\䏨@䃘@浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/08 12:09:52 | 000,000,000 | ---D | M](C:\ProgramData\?|?|0) -- C:\ProgramData\䐀ǀ䂰ǀ0
[2013/04/08 12:09:52 | 000,000,000 | ---D | M](C:\ProgramData\?|?|0) -- C:\ProgramData\䐀ǀ䂰ǀ0
[2013/04/07 14:20:44 | 000,000,000 | ---D | M](C:\ProgramData\?g?g?????????????????????????) -- C:\ProgramData\䏨ǧ䃘ǧ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/07 14:20:44 | 000,000,000 | ---D | M](C:\ProgramData\?g?g?????????????????????????) -- C:\ProgramData\䏨ǧ䃘ǧ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/05 20:20:50 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ȃ䃘ȃ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/05 20:20:50 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ȃ䃘ȃ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/02 16:00:37 | 000,000,000 | ---D | M](C:\ProgramData\?.?.?????????????????????????) -- C:\ProgramData\䏨.䃘.浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/02 16:00:37 | 000,000,000 | ---D | M](C:\ProgramData\?.?.?????????????????????????) -- C:\ProgramData\䏨.䃘.浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/01 16:02:43 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/01 16:02:43 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/01 00:11:16 | 000,000,000 | ---D | M](C:\ProgramData\?-?-?????????????????????????) -- C:\ProgramData\䏨-䃘-浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/04/01 00:11:16 | 000,000,000 | ---D | M](C:\ProgramData\?-?-?????????????????????????) -- C:\ProgramData\䏨-䃘-浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/31 13:42:41 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/31 13:42:41 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/30 21:01:18 | 000,000,000 | ---D | M](C:\ProgramData\?A?A?????????????????????????) -- C:\ProgramData\䏨Ą䃘Ą浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/30 21:01:18 | 000,000,000 | ---D | M](C:\ProgramData\?A?A?????????????????????????) -- C:\ProgramData\䏨Ą䃘Ą浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/29 12:29:45 | 000,000,000 | ---D | M](C:\ProgramData\?o?o?????????????????????????) -- C:\ProgramData\䏨ǫ䃘ǫ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/29 12:29:45 | 000,000,000 | ---D | M](C:\ProgramData\?o?o?????????????????????????) -- C:\ProgramData\䏨ǫ䃘ǫ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/27 23:37:55 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƴ䃘Ƴ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/27 23:37:55 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƴ䃘Ƴ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/26 13:25:42 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨”䃘”浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/26 13:25:42 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨”䃘”浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/25 20:44:09 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/25 20:44:09 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/22 20:22:39 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƿ䃘ƿ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/22 20:22:39 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƿ䃘ƿ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/14 10:00:04 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‡䃘‡浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/14 10:00:04 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‡䃘‡浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/12 12:55:27 | 000,000,000 | ---D | M](C:\ProgramData\?H?H?????????????????????????) -- C:\ProgramData\䏨Ĥ䃘Ĥ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/12 12:55:27 | 000,000,000 | ---D | M](C:\ProgramData\?H?H?????????????????????????) -- C:\ProgramData\䏨Ĥ䃘Ĥ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/08 17:58:28 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨DZ䃘DZ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/08 17:58:28 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨DZ䃘DZ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/04 18:23:59 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ʀ䃘Ʀ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/04 18:23:59 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ʀ䃘Ʀ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/03 14:57:03 | 000,000,000 | ---D | M](C:\ProgramData\?(?(?????????????????????????) -- C:\ProgramData\䏨(䃘(浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/03 14:57:03 | 000,000,000 | ---D | M](C:\ProgramData\?(?(?????????????????????????) -- C:\ProgramData\䏨(䃘(浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/03 02:13:34 | 000,000,000 | ---D | M](C:\ProgramData\?u?u0) -- C:\ProgramData\䐀ǚ䂰ǚ0
[2013/03/03 02:13:34 | 000,000,000 | ---D | M](C:\ProgramData\?u?u0) -- C:\ProgramData\䐀ǚ䂰ǚ0
[2013/03/01 20:01:38 | 000,000,000 | ---D | M](C:\ProgramData\?}?}?????????????????????????) -- C:\ProgramData\䏨}䃘}浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/03/01 20:01:38 | 000,000,000 | ---D | M](C:\ProgramData\?}?}?????????????????????????) -- C:\ProgramData\䏨}䃘}浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/28 14:02:51 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Š䃘Š浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/28 14:02:51 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Š䃘Š浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/25 20:01:21 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/25 20:01:21 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/25 13:02:47 | 000,000,000 | ---D | M](C:\ProgramData\?3?3?????????????????????????) -- C:\ProgramData\䏨3䃘3浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/25 13:02:47 | 000,000,000 | ---D | M](C:\ProgramData\?3?3?????????????????????????) -- C:\ProgramData\䏨3䃘3浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/24 16:45:24 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƹ䃘ƹ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/24 16:45:24 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƹ䃘ƹ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/23 20:10:14 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ǿ䃘ǿ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/23 20:10:14 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ǿ䃘ǿ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/23 00:02:32 | 000,000,000 | ---D | M](C:\ProgramData\?9?9?????????????????????????) -- C:\ProgramData\䏨9䃘9浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/23 00:02:32 | 000,000,000 | ---D | M](C:\ProgramData\?9?9?????????????????????????) -- C:\ProgramData\䏨9䃘9浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/21 12:18:59 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/21 12:18:59 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/18 13:02:40 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/18 13:02:40 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/17 14:38:06 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/17 14:38:06 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/16 14:59:20 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/16 14:59:20 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/15 17:57:00 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/15 17:57:00 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/14 18:26:24 | 000,000,000 | ---D | M](C:\ProgramData\?+?+?????????????????????????) -- C:\ProgramData\䏨+䃘+浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/14 18:26:24 | 000,000,000 | ---D | M](C:\ProgramData\?+?+?????????????????????????) -- C:\ProgramData\䏨+䃘+浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/14 00:30:07 | 000,000,000 | ---D | M](C:\ProgramData\?a?a?????????????????????????) -- C:\ProgramData\䏨ǟ䃘ǟ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/14 00:30:07 | 000,000,000 | ---D | M](C:\ProgramData\?a?a?????????????????????????) -- C:\ProgramData\䏨ǟ䃘ǟ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/12 11:07:38 | 000,000,000 | ---D | M](C:\ProgramData\?S?S?????????????????????????) -- C:\ProgramData\䏨Ŝ䃘Ŝ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/12 11:07:38 | 000,000,000 | ---D | M](C:\ProgramData\?S?S?????????????????????????) -- C:\ProgramData\䏨Ŝ䃘Ŝ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/12 09:55:53 | 000,000,000 | ---D | M](C:\ProgramData\?o?o0) -- C:\ProgramData\䐀ǒ䂰ǒ0
[2013/02/12 09:55:53 | 000,000,000 | ---D | M](C:\ProgramData\?o?o0) -- C:\ProgramData\䐀ǒ䂰ǒ0
[2013/02/11 00:26:41 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀ȇ䂰ȇ0
[2013/02/11 00:26:41 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀ȇ䂰ȇ0
[2013/02/10 16:02:57 | 000,000,000 | ---D | M](C:\ProgramData\?u?u?????????????????????????) -- C:\ProgramData\䏨ǜ䃘ǜ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/10 16:02:57 | 000,000,000 | ---D | M](C:\ProgramData\?u?u?????????????????????????) -- C:\ProgramData\䏨ǜ䃘ǜ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/10 01:21:50 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/10 01:21:50 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/09 15:01:17 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨Đ䃘Đ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/09 15:01:17 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨Đ䃘Đ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/07 14:01:32 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨–䃘–浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/07 14:01:32 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨–䃘–浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/05 20:33:11 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/05 20:33:11 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/03 14:34:21 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/03 14:34:21 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/02 17:16:31 | 000,000,000 | ---D | M](C:\ProgramData\?=?=?????????????????????????) -- C:\ProgramData\䏨=䃘=浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/02/02 17:16:31 | 000,000,000 | ---D | M](C:\ProgramData\?=?=?????????????????????????) -- C:\ProgramData\䏨=䃘=浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/31 11:34:35 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨›䃘›浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/31 11:34:35 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨›䃘›浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/30 16:41:30 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƕ䃘Ƕ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/30 16:41:30 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƕ䃘Ƕ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/29 17:10:35 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǻ䃘Ǻ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/29 17:10:35 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǻ䃘Ǻ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/29 08:51:01 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀ț䂰ț0
[2013/01/29 08:51:01 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀ț䂰ț0
[2013/01/27 15:34:31 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/27 15:34:31 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/26 14:07:12 | 000,000,000 | ---D | M](C:\ProgramData\?1?1?????????????????????????) -- C:\ProgramData\䏨1䃘1浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/26 14:07:12 | 000,000,000 | ---D | M](C:\ProgramData\?1?1?????????????????????????) -- C:\ProgramData\䏨1䃘1浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/24 22:27:55 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƽ䃘ƽ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/24 22:27:55 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƽ䃘ƽ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/23 17:55:52 | 000,000,000 | ---D | M](C:\ProgramData\?O?O?????????????????????????) -- C:\ProgramData\䏨Ǭ䃘Ǭ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/23 17:55:52 | 000,000,000 | ---D | M](C:\ProgramData\?O?O?????????????????????????) -- C:\ProgramData\䏨Ǭ䃘Ǭ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/22 19:38:30 | 000,000,000 | ---D | M](C:\ProgramData\?t?t0) -- C:\ProgramData\䐀ŧ䂰ŧ0
[2013/01/22 19:38:30 | 000,000,000 | ---D | M](C:\ProgramData\?t?t0) -- C:\ProgramData\䐀ŧ䂰ŧ0
[2013/01/22 16:59:46 | 000,000,000 | ---D | M](C:\ProgramData\?F?F?????????????????????????) -- C:\ProgramData\䏨F䃘F浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/22 16:59:46 | 000,000,000 | ---D | M](C:\ProgramData\?F?F?????????????????????????) -- C:\ProgramData\䏨F䃘F浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/21 17:50:50 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨NJ䃘NJ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/21 17:50:50 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨NJ䃘NJ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/20 12:54:51 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/20 12:54:51 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/17 17:16:20 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨™䃘™浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/17 17:16:20 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨™䃘™浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/17 00:51:10 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƨ䃘ƨ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/17 00:51:10 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƨ䃘ƨ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/14 23:59:51 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǹ䃘Ǹ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/14 23:59:51 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǹ䃘Ǹ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/14 19:37:37 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǵ䃘Ǵ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/14 19:37:37 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǵ䃘Ǵ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/13 13:54:50 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ǝ䃘ǝ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/13 13:54:50 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ǝ䃘ǝ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/12 17:50:33 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/12 17:50:33 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/12 11:56:34 | 000,000,000 | ---D | M](C:\ProgramData\?u?u0) -- C:\ProgramData\䐀ǜ䂰ǜ0
[2013/01/12 11:56:34 | 000,000,000 | ---D | M](C:\ProgramData\?u?u0) -- C:\ProgramData\䐀ǜ䂰ǜ0
[2013/01/11 17:33:40 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǯ䃘Ǯ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/11 17:33:40 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǯ䃘Ǯ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/08 08:16:27 | 000,000,000 | ---D | M](C:\ProgramData\?A?A0) -- C:\ProgramData\䐀Ǟ䂰Ǟ0
[2013/01/08 08:16:27 | 000,000,000 | ---D | M](C:\ProgramData\?A?A0) -- C:\ProgramData\䐀Ǟ䂰Ǟ0
[2013/01/07 16:54:18 | 000,000,000 | ---D | M](C:\ProgramData\?5?5?????????????????????????) -- C:\ProgramData\䏨5䃘5浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/07 16:54:18 | 000,000,000 | ---D | M](C:\ProgramData\?5?5?????????????????????????) -- C:\ProgramData\䏨5䃘5浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/06 16:26:50 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨œ䃘œ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/06 16:26:50 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨œ䃘œ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/04 17:22:45 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‹䃘‹浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/04 17:22:45 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‹䃘‹浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/02 20:53:19 | 000,000,000 | ---D | M](C:\ProgramData\?T?T?????????????????????????) -- C:\ProgramData\䏨Ʈ䃘Ʈ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/02 20:53:19 | 000,000,000 | ---D | M](C:\ProgramData\?T?T?????????????????????????) -- C:\ProgramData\䏨Ʈ䃘Ʈ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/01 01:59:09 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2013/01/01 01:59:09 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/30 17:55:09 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/30 17:55:09 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/29 13:05:41 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨DŽ䃘DŽ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/29 13:05:41 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨DŽ䃘DŽ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/28 16:54:48 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨lj䃘lj浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/28 16:54:48 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨lj䃘lj浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/27 15:16:15 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨†䃘†浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/27 15:16:15 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨†䃘†浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/26 16:30:09 | 000,000,000 | ---D | M](C:\ProgramData\?t?t?????????????????????????) -- C:\ProgramData\䏨t䃘t浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/26 16:30:09 | 000,000,000 | ---D | M](C:\ProgramData\?t?t?????????????????????????) -- C:\ProgramData\䏨t䃘t浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/25 15:38:28 | 000,000,000 | ---D | M](C:\ProgramData\?S?S?????????????????????????) -- C:\ProgramData\䏨Ş䃘Ş浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/25 15:38:28 | 000,000,000 | ---D | M](C:\ProgramData\?S?S?????????????????????????) -- C:\ProgramData\䏨Ş䃘Ş浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/23 18:34:56 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‘䃘‘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/23 18:34:56 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‘䃘‘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/23 18:18:20 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ȉ䃘Ȉ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/23 18:18:20 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ȉ䃘Ȉ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/21 22:43:00 | 000,000,000 | ---D | M](C:\ProgramData\?H?H?????????????????????????) -- C:\ProgramData\䏨H䃘H浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/21 22:43:00 | 000,000,000 | ---D | M](C:\ProgramData\?H?H?????????????????????????) -- C:\ProgramData\䏨H䃘H浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/19 22:01:44 | 000,000,000 | ---D | M](C:\ProgramData\? ? ?????????????????????????) -- C:\ProgramData\䏨 䃘 浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/19 22:01:44 | 000,000,000 | ---D | M](C:\ProgramData\? ? ?????????????????????????) -- C:\ProgramData\䏨 䃘 浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/19 21:14:30 | 000,000,000 | ---D | M](C:\ProgramData\?A?A?????????????????????????) -- C:\ProgramData\䏨Ǎ䃘Ǎ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/19 21:14:30 | 000,000,000 | ---D | M](C:\ProgramData\?A?A?????????????????????????) -- C:\ProgramData\䏨Ǎ䃘Ǎ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/18 00:45:40 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/18 00:45:40 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/16 21:47:04 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƶ䃘Ƶ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/16 21:47:04 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƶ䃘Ƶ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/15 19:47:53 | 000,000,000 | ---D | M](C:\ProgramData\?8?8?????????????????????????) -- C:\ProgramData\䏨8䃘8浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/15 19:47:53 | 000,000,000 | ---D | M](C:\ProgramData\?8?8?????????????????????????) -- C:\ProgramData\䏨8䃘8浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/14 12:56:15 | 000,000,000 | ---D | M](C:\ProgramData\?2?2?????????????????????????) -- C:\ProgramData\䏨2䃘2浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/14 12:56:15 | 000,000,000 | ---D | M](C:\ProgramData\?2?2?????????????????????????) -- C:\ProgramData\䏨2䃘2浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/13 13:09:14 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‚䃘‚浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/13 13:09:14 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‚䃘‚浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/12 19:16:52 | 000,000,000 | ---D | M](C:\ProgramData\?u?u?????????????????????????) -- C:\ProgramData\䏨ǖ䃘ǖ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/12 19:16:52 | 000,000,000 | ---D | M](C:\ProgramData\?u?u?????????????????????????) -- C:\ProgramData\䏨ǖ䃘ǖ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/12 12:38:06 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/12 12:38:06 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/11 21:02:54 | 000,000,000 | ---D | M](C:\ProgramData\?A?A?????????????????????????) -- C:\ProgramData\䏨A䃘A浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/11 21:02:54 | 000,000,000 | ---D | M](C:\ProgramData\?A?A?????????????????????????) -- C:\ProgramData\䏨A䃘A浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/11 10:28:45 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀Ǣ䂰Ǣ0
[2012/12/11 10:28:45 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀Ǣ䂰Ǣ0
[2012/12/10 21:23:07 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/10 21:23:07 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/10 20:55:56 | 000,000,000 | ---D | M](C:\ProgramData\?J?J?????????????????????????) -- C:\ProgramData\䏨J䃘J浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/10 20:55:56 | 000,000,000 | ---D | M](C:\ProgramData\?J?J?????????????????????????) -- C:\ProgramData\䏨J䃘J浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/10 20:29:03 | 000,000,000 | ---D | M](C:\ProgramData\?U?U?????????????????????????) -- C:\ProgramData\䏨U䃘U浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/10 20:29:03 | 000,000,000 | ---D | M](C:\ProgramData\?U?U?????????????????????????) -- C:\ProgramData\䏨U䃘U浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/09 17:52:49 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/09 17:52:49 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/09 17:34:12 | 000,000,000 | ---D | M](C:\ProgramData\?g?g?????????????????????????) -- C:\ProgramData\䏨ǥ䃘ǥ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/09 17:34:12 | 000,000,000 | ---D | M](C:\ProgramData\?g?g?????????????????????????) -- C:\ProgramData\䏨ǥ䃘ǥ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/08 21:44:24 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƪ䃘ƪ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/08 21:44:24 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƪ䃘ƪ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/08 09:38:29 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀Š䂰Š0
[2012/12/08 09:38:29 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䐀Š䂰Š0
[2012/12/06 21:15:17 | 000,000,000 | ---D | M](C:\ProgramData\?!?!?????????????????????????) -- C:\ProgramData\䏨ǃ䃘ǃ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/06 21:15:17 | 000,000,000 | ---D | M](C:\ProgramData\?!?!?????????????????????????) -- C:\ProgramData\䏨ǃ䃘ǃ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/05 21:29:10 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ˆ䃘ˆ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/05 21:29:10 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ˆ䃘ˆ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/05 21:09:13 | 000,000,000 | ---D | M](C:\ProgramData\?j?j?????????????????????????) -- C:\ProgramData\䏨ǰ䃘ǰ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/05 21:09:13 | 000,000,000 | ---D | M](C:\ProgramData\?j?j?????????????????????????) -- C:\ProgramData\䏨ǰ䃘ǰ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/04 20:15:45 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/04 20:15:45 | 000,000,000 | ---D | M](C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/04 10:52:28 | 000,000,000 | ---D | M](C:\ProgramData\??0) -- C:\ProgramData\䐀䂰0
[2012/12/04 10:52:28 | 000,000,000 | ---D | M](C:\ProgramData\??0) -- C:\ProgramData\䐀䂰0
[2012/12/03 19:50:52 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǣ䃘Ǣ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/03 19:50:52 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǣ䃘Ǣ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/03 19:28:20 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ȓ䃘Ȓ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/03 19:28:20 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ȓ䃘Ȓ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/02 18:16:42 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ž䃘ž浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/02 18:16:42 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ž䃘ž浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/02 00:07:09 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƻ䃘ƻ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/12/02 00:07:09 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƻ䃘ƻ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/30 20:54:26 | 000,000,000 | ---D | M](C:\ProgramData\?U?U?????????????????????????) -- C:\ProgramData\䏨Ǔ䃘Ǔ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/30 20:54:26 | 000,000,000 | ---D | M](C:\ProgramData\?U?U?????????????????????????) -- C:\ProgramData\䏨Ǔ䃘Ǔ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/29 20:11:38 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Dz䃘Dz浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/29 20:11:38 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Dz䃘Dz浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/28 21:04:17 | 000,000,000 | ---D | M](C:\ProgramData\?z?z?????????????????????????) -- C:\ProgramData\䏨z䃘z浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/28 21:04:17 | 000,000,000 | ---D | M](C:\ProgramData\?z?z?????????????????????????) -- C:\ProgramData\䏨z䃘z浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/27 21:12:30 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨“䃘“浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/27 21:12:30 | 000,000,000 | ---D | M](C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨“䃘“浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/27 07:49:23 | 000,000,000 | ---D | M](C:\ProgramData\?c?c0) -- C:\ProgramData\䐀č䂰č0
[2012/11/27 07:49:23 | 000,000,000 | ---D | M](C:\ProgramData\?c?c0) -- C:\ProgramData\䐀č䂰č0
[2012/11/26 20:22:09 | 000,000,000 | ---D | M](C:\ProgramData\?K?K?????????????????????????) -- C:\ProgramData\䏨Ǩ䃘Ǩ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
[2012/11/26 20:22:09 | 000,000,000 | ---D | M](C:\ProgramData\?K?K?????????????????????????) -- C:\ProgramData\䏨Ǩ䃘Ǩ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?z?z?????????????????????????) -- C:\ProgramData\䏨z䃘z浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?y?y?????????????????????????) -- C:\ProgramData\䏨y䃘y浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?u?u0) -- C:\ProgramData\䐀ǚ䂰ǚ0
(C:\ProgramData\?u?u0) -- C:\ProgramData\䐀ǜ䂰ǜ0
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?u?u?????????????????????????) -- C:\ProgramData\䏨ǖ䃘ǖ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?u?u?????????????????????????) -- C:\ProgramData\䏨ǜ䃘ǜ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?u?u?????????????????????????) -- C:\ProgramData\䏨ǘ䃘ǘ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?U?U?????????????????????????) -- C:\ProgramData\䏨Ǔ䃘Ǔ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?U?U?????????????????????????) -- C:\ProgramData\䏨U䃘U浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?t?t0) -- C:\ProgramData\䐀ŧ䂰ŧ0
(C:\ProgramData\?T?T?????????????????????????) -- C:\ProgramData\䏨Ʈ䃘Ʈ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?t?t?????????????????????????) -- C:\ProgramData\䏨t䃘t浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?S?S?????????????????????????) -- C:\ProgramData\䏨Ş䃘Ş浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?S?S?????????????????????????) -- C:\ProgramData\䏨Ŝ䃘Ŝ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?o?o0) -- C:\ProgramData\䐀ǒ䂰ǒ0
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?O?O?????????????????????????) -- C:\ProgramData\䏨Ǭ䃘Ǭ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?o?o?????????????????????????) -- C:\ProgramData\䏨ǫ䃘ǫ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?O?O?????????????????????????) -- C:\ProgramData\䏨Ǒ䃘Ǒ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?K?K?????????????????????????) -- C:\ProgramData\䏨Ǩ䃘Ǩ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?j?j?????????????????????????) -- C:\ProgramData\䏨ǰ䃘ǰ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?J?J?????????????????????????) -- C:\ProgramData\䏨J䃘J浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\??0) -- C:\ProgramData\䐀䂰0
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?i?i?????????????????????????) -- C:\ProgramData\䏨ǐ䃘ǐ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?H?H?????????????????????????) -- C:\ProgramData\䏨Ĥ䃘Ĥ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?H?H?????????????????????????) -- C:\ProgramData\䏨H䃘H浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?G?G0) -- C:\ProgramData\䐀Ǥ䂰Ǥ0
(C:\ProgramData\?g?g?????????????????????????) -- C:\ProgramData\䏨ǥ䃘ǥ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?g?g?????????????????????????) -- C:\ProgramData\䏨ǧ䃘ǧ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?F?F?????????????????????????) -- C:\ProgramData\䏨F䃘F浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?E?E?????????????????????????) -- C:\ProgramData\䏨Ē䃘Ē浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨Đ䃘Đ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?c?c0) -- C:\ProgramData\䐀č䂰č0
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?c?c?????????????????????????) -- C:\ProgramData\䏨ć䃘ć浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?A?A0) -- C:\ProgramData\䐀Ǟ䂰Ǟ0
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?a?a?????????????????????????) -- C:\ProgramData\䏨ǟ䃘ǟ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?A?A?????????????????????????) -- C:\ProgramData\䏨Ą䃘Ą浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?A?A?????????????????????????) -- C:\ProgramData\䏨Ǎ䃘Ǎ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?A?A?????????????????????????) -- C:\ProgramData\䏨A䃘A浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?9?9?????????????????????????) -- C:\ProgramData\䏨9䃘9浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?8?8?????????????????????????) -- C:\ProgramData\䏨8䃘8浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?5?5?????????????????????????) -- C:\ProgramData\䏨5䃘5浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?3?3?????????????????????????) -- C:\ProgramData\䏨3䃘3浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?2?2?????????????????????????) -- C:\ProgramData\䏨2䃘2浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?1?1?????????????????????????) -- C:\ProgramData\䏨1䃘1浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?=?=?????????????????????????) -- C:\ProgramData\䏨=䃘=浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?+?+?????????????????????????) -- C:\ProgramData\䏨+䃘+浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?~?~?????????????????????????) -- C:\ProgramData\䏨~䃘~浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?}?}?????????????????????????) -- C:\ProgramData\䏨}䃘}浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?|?|0) -- C:\ProgramData\䐀ǀ䂰ǀ0
(C:\ProgramData\?{?{?????????????????????????) -- C:\ProgramData\䏨{䃘{浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\[email protected][email protected]?????????????????????????) -- C:\ProgramData\䏨@䃘@浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\????0) -- C:\ProgramData\䐀ț䂰ț0
(C:\ProgramData\????0) -- C:\ProgramData\䐀ȇ䂰ȇ0
(C:\ProgramData\????0) -- C:\ProgramData\䐀ǻ䂰ǻ0
(C:\ProgramData\????0) -- C:\ProgramData\䐀Ǣ䂰Ǣ0
(C:\ProgramData\????0) -- C:\ProgramData\䐀Š䂰Š0
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƹ䃘ƹ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǯ䃘Ǯ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƶ䃘Ƶ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ȥ䃘ȥ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƴ䃘Ƴ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƿ䃘ƿ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƪ䃘ƪ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƨ䃘ƨ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ʀ䃘Ʀ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ȓ䃘Ȓ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƣ䃘Ƣ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ǿ䃘ǿ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǹ䃘Ǹ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨NJ䃘NJ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƛ䃘ƛ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨lj䃘lj浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ȉ䃘Ȉ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ƕ䃘Ƕ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǵ䃘Ǵ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ǝ䃘ǝ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨DŽ䃘DŽ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨DZ䃘DZ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ȃ䃘ȃ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǻ䃘Ǻ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǡ䃘Ǡ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Ǣ䃘Ǣ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ǽ䃘ǽ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƽ䃘ƽ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ƻ䃘ƻ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ž䃘ž浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨œ䃘œ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨›䃘›浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨™䃘™浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨–䃘–浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨”䃘”浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨“䃘“浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‘䃘‘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‹䃘‹浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨Š䃘Š浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨ˆ䃘ˆ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‡䃘‡浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨†䃘†浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?????????????????????????????) -- C:\ProgramData\䏨‚䃘‚浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?-?-?????????????????????????) -- C:\ProgramData\䏨-䃘-浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\???????????????????????????) -- C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?.?.0) -- C:\ProgramData\䐀.䂰.0
(C:\ProgramData\?.?.?????????????????????????) -- C:\ProgramData\䏨.䃘.浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?(?(?????????????????????????) -- C:\ProgramData\䏨(䃘(浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\?!?!?????????????????????????) -- C:\ProgramData\䏨ǃ䃘ǃ浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
(C:\ProgramData\? ? ?????????????????????????) -- C:\ProgramData\䏨 䃘 浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮

========== Alternate Data Streams ==========

@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:D287FACF

< End of report >


It seams a bit quicker
  • 0

#18
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK I will try to use Combofix to remove all the old infections still present

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File:: 
 C:\Users\lesley\AppData\Local\iqisozidohugi.dll
C:\Users\lesley\AppData\Local\udulibikixe.dll
C:\Users\lesley\AppData\Local\okujecuxiq.dll
C:\Users\lesley\AppData\Local\iyekuyepebeham.dll
C:\Users\lesley\AppData\Local\ocaxobeditexete.dll
C:\Users\lesley\AppData\Local\ewigobabamisa.dll
C:\Users\lesley\AppData\Local\evejopevogani.dll
C:\Users\lesley\AppData\Local\eleqocefuwej.dll
C:\Users\lesley\AppData\Local\udobalepinubesi.dll
C:\Users\lesley\AppData\Local\ubifuyiw.dll
C:\Users\lesley\AppData\Local\udebotax.dll
C:\Users\lesley\AppData\Local\owepejid.dll
C:\Users\lesley\AppData\Local\ilonepoza.dll
C:\Users\lesley\AppData\Local\epapozadu.dll
C:\Users\lesley\AppData\Local\ewufayoqevi.dll
C:\Users\lesley\AppData\Local\ajuzaxeqetalajo.dll
C:\Users\lesley\AppData\Local\iqisagubi.dll 
C:\Users\lesley\AppData\Local\ememomixefenoy.dll
C:\Users\lesley\AppData\Local\azasanukukub.dll
C:\Users\lesley\AppData\Local\ijisozid.dll
C:\Users\lesley\AppData\Local\ivafiyas.dll
C:\Users\lesley\AppData\Local\otodovuj.dll
C:\Users\lesley\AppData\Local\aqudumok.dll
C:\Users\lesley\AppData\Local\uvepamep.dll
C:\Users\lesley\AppData\Local\ofoguzele.dll
C:\Users\lesley\AppData\Local\ubetenim.dll
C:\Users\lesley\AppData\Local\eloyicubucamot.dll
C:\Users\lesley\AppData\Local\ekimamerih.dll
C:\Users\lesley\AppData\Local\uzeroyowuyazam.dll
C:\Users\lesley\AppData\Local\uzoqikuwafonutul.dll
C:\Users\lesley\AppData\Local\ojegejopevo.dll
C:\Users\lesley\AppData\Local\ezegoweli.dll
C:\Users\lesley\AppData\Local\icitegixiv.dll
C:\Users\lesley\AppData\Local\ufeyijevula.dll
C:\Users\lesley\AppData\Local\acitiwuvubomure.dll
C:\Users\lesley\AppData\Local\olabepaguh.dll
C:\Users\lesley\AppData\Local\iconasowovone.dll
C:\Users\lesley\AppData\Local\ewovuhox.dll
C:\Users\lesley\AppData\Local\apojepope.dll
C:\Users\lesley\AppData\Local\uhuyujup.dll
C:\Users\lesley\AppData\Local\ijepamep.dll
C:\Users\lesley\AppData\Local\adudilak.dll
C:\Users\lesley\AppData\Local\eruyewiducena.dll
C:\Users\lesley\AppData\Local\iwefumak.dll
C:\Users\lesley\AppData\Local\iputaduxotoyeful.dll
C:\Users\lesley\AppData\Local\utaxasuxomod.dll
C:\Users\lesley\AppData\Local\enaxijokiqovab.dll
C:\Users\lesley\AppData\Local\exitoced.dll
C:\Users\lesley\AppData\Local\ufoyoxajij.dll
C:\Users\lesley\AppData\Local\umevumeged.dll
C:\Users\lesley\AppData\Local\oquvuwox.dll
C:\Users\lesley\AppData\Local\ahegokidonotudok.dll
C:\Users\lesley\AppData\Local\enomihudu.dll
C:\Users\lesley\AppData\Local\ilawelijosi.dll
C:\Users\lesley\AppData\Local\ibopikeb.dll
C:\Users\lesley\AppData\Local\ifixoqirac.dll
[20C:\Users\lesley\AppData\Local\ebiwukaza.dll
C:\Users\lesley\AppData\Local\odorafoxosivolup.dll
C:\Users\lesley\AppData\Local\ajehoyop.dll
C:\Users\lesley\AppData\Local\efidusex.dll
C:\Users\lesley\AppData\Local\evohecew.dll
C:\Users\lesley\AppData\Local\ufepulukelikuf.dll
C:\Users\lesley\AppData\Local\evuderirif.dll
C:\Users\lesley\AppData\Local\ohubemojokesiy.dll
C:\Users\lesley\AppData\Local\ecogugek.dll
C:\Users\lesley\AppData\Local\ebeberer.dll
C:\Users\lesley\AppData\Local\ixebuxidetayol.dll
C:\Users\lesley\AppData\Local\emiyugup.dll
C:\Users\lesley\AppData\Local\ufosuxidigibavuk.dll
C:\Users\lesley\AppData\Local\ezejiyerezuqah.dll
C:\Users\lesley\AppData\Local\ohazopes.dll
C:\Users\lesley\AppData\Local\uxaxemex.dll
C:\Users\lesley\AppData\Local\upukulej.dll
C:\Users\lesley\AppData\Local\amorowov.dll
C:\Users\lesley\AppData\Local\iresozoq.dll
C:\Users\lesley\AppData\Local\aruwuroviqo.dll
C:\Users\lesley\AppData\Local\efuyiyukejub.dll
C:\Users\lesley\AppData\Local\inojupiliyojo.dll
C:\Users\lesley\AppData\Local\ipidobuvogepu.dll
C:\Users\lesley\AppData\Local\ipobohid.dll
C:\Users\lesley\AppData\Local\ibeciquc.dll
C:\Users\lesley\AppData\Local\d3d9caps.dat
C:\Users\lesley\AppData\Local\Amaloxubacepexo.dat
C:\Users\lesley\AppData\Local\Jnidakusadiyu.bin
C:\Users\lesley\AppData\Roaming\mvhgkr.dat
C:\Users\lesley\AppData\Roaming\avdrn.dat

Folder:: 
C:\ProgramData\䏨䃘浡䘠汩獥䵜䅣敦⁥敓畣楲祴匠慣屮⸳⸰㠲尵瑦潣普杩椮楮
C:\ProgramData\䐀.䂰.0
C:\ProgramData\䐀ț䂰ț0
C:\ProgramData\䐀ȇ䂰ȇ0
C:\ProgramData\䐀ǻ䂰ǻ0
C:\ProgramData\䐀Ǣ䂰Ǣ0
C:\ProgramData\䐀䂰0
C:\ProgramData\䐀ǀ䂰ǀ0
C:\ProgramData\䐀Ǟ䂰Ǟ0
C:\ProgramData\䐀č䂰č0
C:\ProgramData\䐀Ǥ䂰Ǥ0
C:\ProgramData\䐀䂰0
C:\ProgramData\䐀ǒ䂰ǒ0
C:\ProgramData\䐀ŧ䂰ŧ0
C:\ProgramData\䐀ǚ䂰ǚ0 
 


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • 0

#19
nigella

nigella

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 216 posts
I just tried to save it and it said that unicode elements would be lost if I continued, I am going to change ANSI to unicode, is this the right thing to do?
  • 0

#20
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Preferable would be Unicode for the Chinese folders .. But lets try this instead

Save as ansi and run CFScript then:


1.Open Folder Options by clicking the Start button, clicking Control Panel, clicking Appearance and Personalization, and then clicking Folder Options.

2.Click the View tab.

3.Under Advanced settings, click Show hidden files and folders, and then click OK.
[attachment=65189:Capture.JPG]

Then go to C:\Programdata

Right click all the folders with Chinese characters and select delete
  • 0

#21
nigella

nigella

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 216 posts
I've actually selected Unicode and I'm running it
  • 0

#22
nigella

nigella

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 216 posts
CombiFix was running and at stage 50 and the laptop came up with a blue screen of death! shall I run combifix again (ANSI version of the fix script)
  • 0

#23
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Yes please but remove the Chinese elements. Then manually delete the Chinese folders
  • 0

#24
nigella

nigella

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 216 posts
I Saved it as an ANSI file too so the unicode is already taken out
  • 0

#25
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Okey dokey :)
  • 0

Advertisements


#26
nigella

nigella

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 216 posts
I have a warning that Norton 360 antivirus and antispyware are running but when I look at task manager there is no process running. is it ok to run?
  • 0

#27
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Yep, let her run.. But do not allow Norton to stop or quarantine anything
  • 0

#28
nigella

nigella

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 216 posts
ComboFix 13-06-21.02 - lesley 23/06/2013 18:06:38.3.1 - x86
Microsoft Windows Vista Home Basic 6.0.6002.2.1252.44.1033.18.894.227 [GMT 1:00]
Running from: c:\users\lesley\Desktop\ComboFix.exe
Command switches used :: c:\users\lesley\Desktop\CFScript.txt
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\lesley\AppData\Local\acitiwuvubomure.dll"
"c:\users\lesley\AppData\Local\adudilak.dll"
"c:\users\lesley\AppData\Local\ahegokidonotudok.dll"
"c:\users\lesley\AppData\Local\ajehoyop.dll"
"c:\users\lesley\AppData\Local\ajuzaxeqetalajo.dll"
"c:\users\lesley\AppData\Local\Amaloxubacepexo.dat"
"c:\users\lesley\AppData\Local\amorowov.dll"
"c:\users\lesley\AppData\Local\apojepope.dll"
"c:\users\lesley\AppData\Local\aqudumok.dll"
"c:\users\lesley\AppData\Local\aruwuroviqo.dll"
"c:\users\lesley\AppData\Local\azasanukukub.dll"
"c:\users\lesley\AppData\Local\d3d9caps.dat"
"c:\users\lesley\AppData\Local\ebeberer.dll"
"c:\users\lesley\AppData\Local\ecogugek.dll"
"c:\users\lesley\AppData\Local\efidusex.dll"
"c:\users\lesley\AppData\Local\efuyiyukejub.dll"
"c:\users\lesley\AppData\Local\ekimamerih.dll"
"c:\users\lesley\AppData\Local\eleqocefuwej.dll"
"c:\users\lesley\AppData\Local\eloyicubucamot.dll"
"c:\users\lesley\AppData\Local\ememomixefenoy.dll"
"c:\users\lesley\AppData\Local\emiyugup.dll"
"c:\users\lesley\AppData\Local\enaxijokiqovab.dll"
"c:\users\lesley\AppData\Local\enomihudu.dll"
"c:\users\lesley\AppData\Local\epapozadu.dll"
"c:\users\lesley\AppData\Local\eruyewiducena.dll"
"c:\users\lesley\AppData\Local\evejopevogani.dll"
"c:\users\lesley\AppData\Local\evohecew.dll"
"c:\users\lesley\AppData\Local\evuderirif.dll"
"c:\users\lesley\AppData\Local\ewigobabamisa.dll"
"c:\users\lesley\AppData\Local\ewovuhox.dll"
"c:\users\lesley\AppData\Local\ewufayoqevi.dll"
"c:\users\lesley\AppData\Local\exitoced.dll"
"c:\users\lesley\AppData\Local\ezegoweli.dll"
"c:\users\lesley\AppData\Local\ezejiyerezuqah.dll"
"c:\users\lesley\AppData\Local\ibeciquc.dll"
"c:\users\lesley\AppData\Local\ibopikeb.dll"
"c:\users\lesley\AppData\Local\icitegixiv.dll"
"c:\users\lesley\AppData\Local\iconasowovone.dll"
"c:\users\lesley\AppData\Local\ifixoqirac.dll"
"c:\users\lesley\AppData\Local\ijepamep.dll"
"c:\users\lesley\AppData\Local\ijisozid.dll"
"c:\users\lesley\AppData\Local\ilawelijosi.dll"
"c:\users\lesley\AppData\Local\ilonepoza.dll"
"c:\users\lesley\AppData\Local\inojupiliyojo.dll"
"c:\users\lesley\AppData\Local\ipidobuvogepu.dll"
"c:\users\lesley\AppData\Local\ipobohid.dll"
"c:\users\lesley\AppData\Local\iputaduxotoyeful.dll"
"c:\users\lesley\AppData\Local\iqisagubi.dll"
"c:\users\lesley\AppData\Local\iqisozidohugi.dll"
"c:\users\lesley\AppData\Local\iresozoq.dll"
"c:\users\lesley\AppData\Local\ivafiyas.dll"
"c:\users\lesley\AppData\Local\iwefumak.dll"
"c:\users\lesley\AppData\Local\ixebuxidetayol.dll"
"c:\users\lesley\AppData\Local\iyekuyepebeham.dll"
"c:\users\lesley\AppData\Local\Jnidakusadiyu.bin"
"c:\users\lesley\AppData\Local\ocaxobeditexete.dll"
"c:\users\lesley\AppData\Local\odorafoxosivolup.dll"
"c:\users\lesley\AppData\Local\ofoguzele.dll"
"c:\users\lesley\AppData\Local\ohazopes.dll"
"c:\users\lesley\AppData\Local\ohubemojokesiy.dll"
"c:\users\lesley\AppData\Local\ojegejopevo.dll"
"c:\users\lesley\AppData\Local\okujecuxiq.dll"
"c:\users\lesley\AppData\Local\olabepaguh.dll"
"c:\users\lesley\AppData\Local\oquvuwox.dll"
"c:\users\lesley\AppData\Local\otodovuj.dll"
"c:\users\lesley\AppData\Local\owepejid.dll"
"c:\users\lesley\AppData\Local\ubetenim.dll"
"c:\users\lesley\AppData\Local\ubifuyiw.dll"
"c:\users\lesley\AppData\Local\udebotax.dll"
"c:\users\lesley\AppData\Local\udobalepinubesi.dll"
"c:\users\lesley\AppData\Local\udulibikixe.dll"
"c:\users\lesley\AppData\Local\ufepulukelikuf.dll"
"c:\users\lesley\AppData\Local\ufeyijevula.dll"
"c:\users\lesley\AppData\Local\ufosuxidigibavuk.dll"
"c:\users\lesley\AppData\Local\ufoyoxajij.dll"
"c:\users\lesley\AppData\Local\uhuyujup.dll"
"c:\users\lesley\AppData\Local\umevumeged.dll"
"c:\users\lesley\AppData\Local\upukulej.dll"
"c:\users\lesley\AppData\Local\utaxasuxomod.dll"
"c:\users\lesley\AppData\Local\uvepamep.dll"
"c:\users\lesley\AppData\Local\uxaxemex.dll"
"c:\users\lesley\AppData\Local\uzeroyowuyazam.dll"
"c:\users\lesley\AppData\Local\uzoqikuwafonutul.dll"
"c:\users\lesley\AppData\Roaming\avdrn.dat"
"c:\users\lesley\AppData\Roaming\mvhgkr.dat"
.
.
((((((((((((((((((((((((( Files Created from 2013-05-23 to 2013-06-23 )))))))))))))))))))))))))))))))
.
.
2013-06-23 17:28 . 2013-06-23 17:28 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2013-06-23 17:28 . 2013-06-23 17:28 -------- d-----w- c:\users\roger\AppData\Local\temp
2013-06-23 17:28 . 2013-06-23 17:28 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-06-23 17:28 . 2013-06-23 17:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-06-23 17:15 . 2013-06-23 17:25 0 ---ha-w- c:\users\lesley\BITE5D6.tmp
2013-06-21 19:05 . 2013-06-21 19:05 -------- d-----w- c:\windows\ERUNT
2013-06-21 19:04 . 2013-06-21 19:05 -------- d-----w- C:\JRT
2013-06-20 21:29 . 2013-06-20 21:29 -------- d-----w- C:\_OTL
2013-06-13 20:58 . 2013-05-16 22:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-06-13 20:58 . 2013-05-16 23:34 149656 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2013-06-13 20:58 . 2013-05-16 22:20 420864 ----a-w- c:\windows\system32\vbscript.dll
2013-06-13 20:58 . 2013-05-16 22:24 768512 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-06-13 20:58 . 2013-05-16 22:23 194048 ----a-w- c:\program files\Internet Explorer\IEShims.dll
2013-06-13 20:58 . 2013-05-16 22:21 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2013-06-13 19:59 . 2013-06-13 20:00 -------- d-----w- C:\dac79b0d534fcc35a522be
2013-06-12 17:59 . 2013-05-08 03:40 914792 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-12 17:59 . 2013-05-08 01:58 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2013-06-12 17:59 . 2013-05-02 04:04 443904 ----a-w- c:\windows\system32\win32spl.dll
2013-06-12 17:59 . 2013-05-02 04:03 37376 ----a-w- c:\windows\system32\printcom.dll
2013-06-12 17:59 . 2013-05-02 22:03 3603832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-12 17:59 . 2013-05-02 22:03 3551096 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-06-12 17:58 . 2013-04-24 01:46 812544 ----a-w- c:\windows\system32\certutil.exe
2013-06-12 17:58 . 2013-04-24 04:00 985600 ----a-w- c:\windows\system32\crypt32.dll
2013-06-12 17:58 . 2013-04-24 04:00 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-06-12 17:58 . 2013-04-24 04:00 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-06-12 17:58 . 2013-04-24 04:00 41984 ----a-w- c:\windows\system32\certenc.dll
2013-06-12 17:57 . 2013-04-17 12:30 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2013-06-12 17:39 . 2013-06-19 18:52 -------- d-----w- c:\windows\system32\drivers\N360\1404000.028
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-19 17:53 . 2013-05-18 14:51 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2013-06-11 20:19 . 2012-11-25 15:42 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-11 20:19 . 2011-07-25 09:37 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-18 00:04 . 2013-05-18 00:04 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE311580-FF0D-4291-BF70-1AB910C04240}\offreg.dll
2013-05-13 06:19 . 2013-05-17 18:54 7016152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE311580-FF0D-4291-BF70-1AB910C04240}\mpengine.dll
2013-05-02 12:55 . 2011-09-25 19:23 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-02 01:06 . 2013-02-19 16:08 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-15 14:20 . 2013-05-15 22:47 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-13 10:56 . 2013-05-15 22:47 37376 ----a-w- c:\windows\system32\cdd.dll
2013-04-09 01:36 . 2013-05-15 22:45 2049024 ----a-w- c:\windows\system32\win32k.sys
2013-04-08 23:12 . 2012-06-25 23:04 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-04-08 23:12 . 2011-08-04 17:14 782240 ----a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-09-30 972080]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2012-05-25 6595928]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-24 468264]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-07 210216]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"UIExec"="c:\program files\T-Mobile Mobile Broadband Manager\UIExec.exe" [2009-07-16 132608]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"QuickTime Task"="c:\program files\MpcStar\Codecs\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Chrome.lnk - c:\program files\Google\Chrome\Application\chrome.exe [2010-12-1 825808]
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-6-13 2498560]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Mozilla Firefox.lnk]
backup=c:\windows\pss\Mozilla Firefox.lnkCommon Startup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk
backupExtension=Common Startup
.
[HKLM\~\startupfolder\C:^Users^lesley^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
path=c:\users\lesley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backupExtension=Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Badoo Desktop]
2011-03-31 19:46 1012224 ----a-w- c:\programdata\Badoo\Badoo Desktop\1.3.12.904\Badoo.Desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX8400 Series]
2007-04-12 06:00 182272 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATICEE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 23:24 54840 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
2008-09-30 23:56 972080 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2008-04-15 21:51 488752 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-01-16 17:22 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 17:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2012-05-25 03:25 6595928 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2012-03-08 17:50 4280184 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 14:28 421888 ----a-w- c:\program files\MpcStar\Codecs\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
2009-02-23 13:05 111856 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-08 08:48 1238352 ----a-w- c:\program files\Steam\steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2007-12-24 22:55 222504 ------w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:33 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
2009-02-23 13:05 111856 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - BMLoad
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-19 18:07 1165776 ----a-w- c:\program files\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-25 20:21]
.
2013-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 00:06]
.
2013-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-01 00:06]
.
2013-06-23 c:\windows\Tasks\HPCeeScheduleForlesley.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-10-25 18:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://http://www.yahoo.com/?ilc=8.yahoo.com
mStart Page = hxxp://www.yahoo.com/?ilc=8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchAssistant =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AOL Toolbar Search - c:\programdata\AOL\ieToolbar\resources\en-GB\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/?ilc=8
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=mcafee&p=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-23 18:28
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\20.4.0.40\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-06-23 18:34:22
ComboFix-quarantined-files.txt 2013-06-23 17:34
ComboFix2.txt 2013-06-21 23:24
.
Pre-Run: 76,016,570,368 bytes free
Post-Run: 75,974,873,088 bytes free
.
- - End Of File - - 5B46CCEAD5297F722291F6E516977FE6
588AE8F0C685C02BA11F30D9CD7E61A0


and I've deleted all the Chinese folders/files
  • 0

#29
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Excellent, long winded but we got there :) Any outstanding problems ?
  • 0

#30
nigella

nigella

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 216 posts
It doesn't look like it thanks :-)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP