Googled for the past 2 days for fixing this but after trying numerous method this hao123.com still cant be fixed. After opening both mozilla firefox and IE browser the hompage gets redirected to hao123.com. Saw the solution here but i not dare to try anything as i saw the expert here stated the method is purely for the specific pc. Please do help me to solve this as this is quite annoyed to see my IE & firefox homepage is hao123.com. Thanks in advance
OTL logfile created on: 10/8/2014 9:06:41 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\zenny\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.94 Gb Total Physical Memory | 2.39 Gb Available Physical Memory | 60.53% Memory free
7.89 Gb Paging File | 5.44 Gb Available in Paging File | 68.98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 244.96 Gb Total Space | 71.77 Gb Free Space | 29.30% Space Free | Partition Type: NTFS
Drive D: | 49.28 Gb Total Space | 49.16 Gb Free Space | 99.75% Space Free | Partition Type: NTFS
Drive E: | 62.50 Gb Total Space | 60.85 Gb Free Space | 97.36% Space Free | Partition Type: NTFS
Drive G: | 220.70 Gb Total Space | 180.62 Gb Free Space | 81.84% Space Free | Partition Type: NTFS
Computer Name: ZENNY-PC | User Name: zenny | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/10/08 21:02:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\zenny\Desktop\OTL.exe
PRC - [2014/10/08 18:17:00 | 000,315,520 | ---- | M] (Elex do Brasil Participações Ltda) -- C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
PRC - [2014/10/08 18:10:07 | 000,118,048 | ---- | M] (Elex do Brasil Participações Ltda) -- C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
PRC - [2014/10/08 18:09:57 | 000,118,048 | ---- | M] (Elex do Brasil Participações Ltda) -- C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe
PRC - [2014/09/26 13:55:56 | 000,480,848 | ---- | M] (Baidu Inc.) -- G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\bpls.exe
PRC - [2014/09/26 13:55:48 | 001,575,504 | ---- | M] (Baidu Inc.) -- G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\bdyyService.exe
PRC - [2014/09/26 13:55:46 | 000,340,560 | ---- | M] (Baidu Inc.) -- G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\bdyyProtect.exe
PRC - [2014/09/26 13:55:08 | 000,913,488 | ---- | M] (Baidu.com, Inc.) -- G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\bdbtray.exe
PRC - [2014/09/26 13:54:52 | 000,933,968 | ---- | M] () -- G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\BaiduPlayer.exe
PRC - [2014/09/25 20:21:04 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014/09/10 23:21:40 | 001,870,000 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
PRC - [2014/08/20 11:27:22 | 001,240,496 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- C:\Program Files (x86)\QvodPlayer\QvodTerminal.exe
PRC - [2014/06/27 11:52:26 | 002,088,408 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2014/06/24 15:38:12 | 000,014,256 | ---- | M] () -- C:\ProgramData\QvodPlayer\QvodWebBase\1.0.0.52\QvodWebService.exe
PRC - [2014/06/24 10:42:12 | 004,101,576 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2014/06/24 10:41:42 | 001,738,168 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) -- E:\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) -- E:\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2014/05/12 07:24:34 | 006,970,168 | ---- | M] (Malwarebytes Corporation) -- E:\Malwarebytes Anti-Malware\mbam.exe
PRC - [2014/04/25 14:12:20 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2013/12/10 16:07:32 | 001,101,152 | ---- | M] (百度在线网络技术(北京)有限公司) -- C:\Program Files (x86)\Common Files\Baidu\BaiduProtect\1.1.0.34\BaiduProtect.exe
PRC - [2013/11/28 17:25:16 | 001,332,672 | ---- | M] (www.guangsu.cn) -- C:\Program Files (x86)\gssoft\gswb\2.7.1.3126\Config.exe
PRC - [2013/05/11 18:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/20 01:53:16 | 000,365,376 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2012/07/20 01:53:10 | 000,277,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2012/07/06 05:23:34 | 000,166,720 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
PRC - [2012/05/21 00:26:26 | 000,291,648 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2011/06/30 02:52:34 | 001,074,496 | ---- | M] (D-Link Corp.) -- C:\Program Files (x86)\D-Link\DWA-140 revB\AirNCFG.exe
PRC - [2010/07/13 06:39:24 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\D-Link\DWA-140 revB\ANIWConnService.exe
PRC - [2008/03/06 03:00:12 | 001,560,576 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files (x86)\RALINK\Common\RaUI.exe
PRC - [2008/02/23 10:10:38 | 000,054,272 | ---- | M] () -- C:\Program Files (x86)\RALINK\Common\RalinkRegistryWriter.exe
========== Modules (No Company Name) ==========
MOD - [2014/10/08 18:10:08 | 000,065,696 | ---- | M] () -- C:\Program Files (x86)\Elex-tech\YAC\zlib1.dll
MOD - [2014/10/08 18:10:05 | 000,092,320 | ---- | M] () -- C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll
MOD - [2014/10/08 18:09:56 | 000,179,200 | ---- | M] () -- C:\Program Files (x86)\Elex-tech\YAC\libpng.dll
MOD - [2014/09/26 13:59:00 | 000,581,712 | ---- | M] () -- G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\lu.dll
MOD - [2014/09/26 13:58:54 | 000,374,352 | ---- | M] () -- G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\live.dll
MOD - [2014/09/26 13:57:50 | 001,732,176 | ---- | M] () -- G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\BDPlayerEX.dll
MOD - [2014/09/26 13:54:52 | 000,933,968 | ---- | M] () -- G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\BaiduPlayer.exe
MOD - [2014/09/25 20:21:03 | 003,715,184 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2014/09/10 23:21:40 | 016,825,520 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
MOD - [2014/06/24 15:38:12 | 000,014,256 | ---- | M] () -- C:\ProgramData\QvodPlayer\QvodWebBase\1.0.0.52\QvodWebService.exe
MOD - [2014/05/13 12:04:48 | 000,167,768 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
MOD - [2014/05/13 12:04:46 | 000,109,400 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2014/05/13 12:04:42 | 000,416,600 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2013/08/13 13:58:07 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\D-Link\DWA-140 revB\ANPDApi.dll
MOD - [2012/11/29 06:13:52 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/11/29 06:13:30 | 001,242,512 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/05/14 02:58:00 | 000,294,912 | ---- | M] () -- C:\Program Files (x86)\D-Link\DWA-140 revB\wlanapp.dll
========== Services (SafeList) ==========
SRV:64bit: - [2014/04/09 21:13:48 | 000,289,256 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe -- (McComponentHostService)
SRV:64bit: - [2013/12/07 04:52:10 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012/06/20 11:10:34 | 000,634,632 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel®
SRV:64bit: - [2010/04/07 08:30:38 | 000,031,272 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\AppleChargerSrv.exe -- (AppleChargerSrv)
SRV:64bit: - [2009/07/14 09:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 09:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014/10/08 18:10:07 | 000,118,048 | ---- | M] (Elex do Brasil Participações Ltda) [Auto | Running] -- C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe -- (iSafeService)
SRV - [2014/09/25 20:21:03 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/09/25 18:21:10 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/07/01 05:46:52 | 000,542,400 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/05/12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- E:\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014/05/12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- E:\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2014/04/17 09:32:42 | 001,861,936 | ---- | M] (Palo Alto Networks) [Auto | Running] -- E:\Palo Alto Networks\GlobalProtect\PanGPS.exe -- (PanGPS)
SRV - [2013/12/31 02:58:57 | 000,174,024 | ---- | M] (ShenZhen Xunlei Networking Technologies,LTD) [Auto | Running] -- C:\Program Files (x86)\Common Files\Thunder Network\ServicePlatform\XLSP.dll -- (XLServicePlatform)
SRV - [2013/12/10 16:07:32 | 001,101,152 | ---- | M] (百度在线网络技术(北京)有限公司) [Auto | Running] -- C:\Program Files (x86)\Common Files\Baidu\BaiduProtect\1.1.0.34\BaiduProtect.exe -- (BDSGRTP)
SRV - [2013/11/28 17:25:16 | 001,332,672 | ---- | M] (www.guangsu.cn) [Auto | Running] -- C:\Program Files (x86)\gssoft\gswb\2.7.1.3126\Config.exe -- (GSService)
SRV - [2013/05/11 18:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/20 01:53:16 | 000,365,376 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012/07/20 01:53:10 | 000,277,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012/07/09 00:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/07/06 05:23:34 | 000,166,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2010/07/13 06:39:24 | 000,053,248 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\D-Link\DWA-140 revB\ANIWConnService.exe -- (D_Link_DWA-140_WPS)
SRV - [2009/06/11 05:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/02/23 10:10:38 | 000,054,272 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RALINK\Common\RalinkRegistryWriter.exe -- (RalinkRegistryWriter)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014/10/08 20:28:02 | 000,122,584 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2014/10/08 18:15:55 | 000,045,224 | ---- | M] (Elex do Brasil Participações Ltda) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iSafeKrnlBoot.sys -- (iSafeKrnlBoot)
DRV:64bit: - [2014/09/22 20:13:46 | 000,049,320 | ---- | M] (Elex do Brasil Participações Ltda) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\iSafeNetFilter.sys -- (iSafeNetFilter)
DRV:64bit: - [2014/05/12 07:26:10 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2014/05/12 07:25:56 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2014/04/17 09:27:54 | 000,036,352 | ---- | M] (Palo Alto Networks) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pangpd.sys -- (PanGpd)
DRV:64bit: - [2013/12/10 15:53:24 | 000,168,264 | ---- | M] (Baidu) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\bd0004.sys -- (bd0004)
DRV:64bit: - [2013/12/10 15:53:24 | 000,104,264 | ---- | M] (Baidu) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\bd0001.sys -- (bd0001)
DRV:64bit: - [2013/12/07 05:52:14 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013/12/07 04:21:44 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013/09/24 22:53:50 | 000,094,208 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012/12/14 06:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/10/26 01:01:20 | 000,022,680 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AppleCharger.sys -- (AppleCharger)
DRV:64bit: - [2012/08/22 05:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/07/03 07:16:02 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012/05/21 00:25:32 | 000,789,824 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012/05/21 00:25:32 | 000,357,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012/05/21 00:25:32 | 000,019,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2011/12/02 18:38:08 | 000,239,208 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2011/09/29 17:30:34 | 000,646,248 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/04/29 06:20:30 | 001,617,472 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Dnetr28ux.sys -- (netr28ux)
DRV:64bit: - [2009/07/14 09:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/14 09:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 09:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 09:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 09:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 09:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 09:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/11 04:35:38 | 000,707,072 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364)
DRV:64bit: - [2009/06/11 04:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/11 04:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/11 04:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/11 04:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/03/07 10:10:10 | 000,015,872 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\anodlwfx.sys -- (anodlwf)
DRV:64bit: - [2007/10/10 05:54:40 | 000,371,200 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7064.sys -- (rt70x64)
DRV - [2014/10/08 18:16:10 | 000,065,704 | ---- | M] (Elex do Brasil Participações Ltda) [Kernel | System | Running] -- C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys -- (iSafeKrnlR3)
DRV - [2014/10/08 18:16:05 | 000,099,496 | ---- | M] (Elex do Brasil Participações Ltda) [Kernel | System | Running] -- C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys -- (iSafeKrnlKit)
DRV - [2014/10/08 18:16:02 | 000,248,488 | ---- | M] (Elex do Brasil Participações Ltda) [File_System | System | Running] -- C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys -- (iSafeKrnl)
DRV - [2009/07/14 09:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9}
IE:64bit: - HKLM\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = http://www.google.co...q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9}
IE - HKLM\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = http://www.google.co...q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/en-sg/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FE 29 10 ED F3 E2 CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9}
IE - HKCU\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = http://www.google.co...q={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:32.0.3
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@qvod.com/QvodShare: C:\Program Files (x86)\QvodPlayer\npShareModule_x64.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@baidu.com/npBdyyPlugin: G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\npbdyy.dll ()
FF - HKLM\Software\MozillaPlugins\@baidu.com/npxbdyy: G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\npxbdyy.dll ()
FF - HKLM\Software\MozillaPlugins\@funshion.com/npFunshion: C:\Users\zenny\funshion\funshiontools\npFunshion.dll File not found
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@qvod.com/QvodInsert: C:\Program Files (x86)\QvodPlayer\npQvodInsert.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKLM\Software\MozillaPlugins\@qvod.com/QvodShare: C:\Program Files (x86)\QvodPlayer\npShareModule.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@xfplay.com/xfplay: C:\Program Files (x86)\xfplay\npxfweb.dll (http://www.xfplay.com)
FF - HKLM\Software\MozillaPlugins\@xunlei.com/DapCtrl: C:\Program Files (x86)\Common Files\Thunder Network\KanKan\npDapCtrl.3.1.0.7.(560).dll (ShenZhen Thunder Networking Technologies Ltd.)
FF - HKLM\Software\MozillaPlugins\@xunlei.com/npxluser: C:\Program Files (x86)\Common Files\Thunder Network\UserAgent\npxluser2.0.2.3.dll File not found
FF - HKLM\Software\MozillaPlugins\@xunlei.com/npxunlei;version=1.0.0.2: G:\Program Files (x86)\Thunder Network\Thunder\Data\npxunlei1.0.0.2.dll ( )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@qvod.com/QvodInsert: C:\Program Files (x86)\QvodPlayer\npQvodInsert.dll (Shenzhen QVOD Technology Co.,Ltd)
FF - HKCU\Software\MozillaPlugins\@xunlei.com/npxluser: C:\Program Files (x86)\Common Files\Thunder Network\UserAgent\npxluser2.0.2.3.dll File not found
FF - HKCU\Software\MozillaPlugins\@xunlei.com/npxunlei;version=1.0.0.2: G:\Program Files (x86)\Thunder Network\Thunder\Data\npxunlei1.0.0.2.dll ( )
FF - HKCU\Software\MozillaPlugins\KuaiWanInsert: C:\Program Files (x86)\QvodPlayer\AddIn\KWWebgame\npKWWebGame.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}: C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014/04/04 18:36:14 | 000,010,691 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2013/05/20 14:18:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zenny\AppData\Roaming\Mozilla\Extensions
[2013/12/11 12:09:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zenny\AppData\Roaming\Mozilla\Firefox\Profiles\pogtaohm.default\extensions
[2013/12/11 12:09:16 | 000,000,000 | ---D | M] (Funshion Player Extension) -- C:\Users\zenny\AppData\Roaming\Mozilla\Firefox\Profiles\pogtaohm.default\extensions\{D119EDE5-84F2-4204-927D-D8811DC193B9}
[2014/10/07 22:51:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zenny\AppData\Roaming\Mozilla\Firefox\Profiles\q5qn4sq4.default-1412692487582\extensions
[2013/09/02 13:08:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zenny\AppData\Roaming\Mozilla\Firefox\Profilespogtaohm.default\extensions
[2013/09/02 13:08:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\zenny\AppData\Roaming\Mozilla\Firefox\Profilespogtaohm.default\extensions\staged
[2014/10/08 20:53:39 | 000,002,393 | ---- | M] () -- C:\Users\zenny\AppData\Roaming\Mozilla\Firefox\Profiles\q5qn4sq4.default-1412692487582\searchplugins\Google.xml
[2014/06/18 21:44:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/09/25 20:21:04 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\zenny\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\zenny\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\zenny\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\zenny\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\zenny\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\zenny\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\zenny\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009/06/11 05:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (ѸÀ×ÏÂÔØÖ§³Ö) - {004B0726-A010-4ABF-8556-FCDB7F1FCA1E} - G:\Program Files (x86)\Thunder Network\Thunder\BHO\XunleiBHO647.9.17.4698.dll (深圳市迅雷网络技术有限公司)
O2:64bit: - BHO: (QvodExtend) - {A8502600-B272-4F68-A67B-A0305D46D298} - C:\ProgramData\QvodPlayer\QvodExtend\5.0.100.0\QvodExtend_x64.dll (Shenzhen QVOD Technology Co.,Ltd)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (7CCA744D-8A17-62A0-F7AA-A540136CF894 Class) - {7CCA744D-8A17-62A0-F7AA-A540136CF894} - C:\Program Files (x86)\QvodPlayer\AddIn\{7CCA744D-8A17-62A0-F7AA-A540136CF894}\QvodAddr.dll ()
O2 - BHO: (no name) - {A8502600-B272-4F68-A67B-A0305D46D297} - No CLSID value found.
O2 - BHO: (ѸÀ×ÏÂÔØÖ§³Ö×é¼þ) - {DE05CF4A-7B0A-4775-B5E5-396244938679} - G:\Program Files (x86)\Thunder Network\Thunder\Thunder BHO Platform\np_tdieplat.dll (深圳市迅雷网络技术有限公司)
O4:64bit: - HKLM..\Run: [GlobalProtect] E:\Palo Alto Networks\GlobalProtect\PanGPA.exe (Palo Alto Networks)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [D-Link D-Link DWA-140] C:\Program Files (x86)\D-Link\DWA-140 revB\AirNCFG.exe (D-Link Corp.)
O4 - HKLM..\Run: [IMSS] C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe (Intel Corporation)
O4 - HKLM..\Run: [QvodTerminal] C:\Program Files (x86)\QvodPlayer\QvodTerminal.exe (Shenzhen QVOD Technology Co.,Ltd)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [BaiduMEDIA] G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\BaiduPlayer.exe ()
O4 - HKCU..\Run: [BaiduMEDIASERVICE] G:\Program Files (x86)\Baidu\BaiduPlayer\4.0.1.85\bdyyService.exe (Baidu Inc.)
O4 - HKCU..\Run: [bdcalendar] C:\Users\zenny\AppData\Roaming\baidu\bdcalendar\1_1_0_186\bdcalendar.exe /autorun File not found
O4 - HKCU..\Run: [TTWeather] "C:\Program Files (x86)\TTWeather\TTWeather.exe" /autorun File not found
O4 - HKCU..\Run: [weatherTips] "C:\Program Files (x86)\TTWeather\weatherTips.exe" /autorun File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O9 - Extra 'Tools' menuitem : 启动迅雷看看播放器 - {14c1d00e-0b92-4379-880b-444fa2d740dd} - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolMenu.htm ()
O9 - Extra Button: 启动迅雷看看播放器 - {24c1d00e-0b92-4379-880b-444fa2d740dd} - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolBar.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 202.156.1.16 218.186.2.16 218.186.2.6
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0018A5F5-90A2-4C02-9591-B93B4975D56D}: DhcpNameServer = 202.156.1.16 218.186.2.16 218.186.2.6
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5288348E-5BCB-498D-8A84-D8944532E2CD}: DhcpNameServer = 202.156.1.16 218.186.2.16 218.186.2.6
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/10/08 21:02:51 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\zenny\Desktop\OTL.exe
[2014/10/08 20:43:47 | 000,049,320 | ---- | C] (Elex do Brasil Participações Ltda) -- C:\Windows\SysNative\drivers\iSafeNetFilter.sys
[2014/10/08 20:43:47 | 000,045,224 | ---- | C] (Elex do Brasil Participações Ltda) -- C:\Windows\SysNative\drivers\iSafeKrnlBoot.sys
[2014/10/08 20:43:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC
[2014/10/08 20:43:46 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\log
[2014/10/08 20:43:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elex-tech
[2014/10/08 20:43:35 | 000,000,000 | ---D | C] -- C:\Users\zenny\AppData\Roaming\Elex-tech
[2014/10/07 23:37:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2014/10/07 23:36:59 | 000,021,040 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe
[2014/10/07 23:36:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2014/10/07 23:36:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2014/10/07 22:07:07 | 000,000,000 | ---D | C] -- C:\ProgramData\GridinSoft
[2014/10/07 21:37:44 | 000,000,000 | ---D | C] -- C:\Users\zenny\AppData\Roaming\BindIconDir
[2014/10/07 21:33:23 | 000,000,000 | ---D | C] -- C:\Users\zenny\AppData\Roaming\Baidu
[2014/10/07 21:33:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Baidu
[2014/10/07 20:51:30 | 000,122,584 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/10/07 20:51:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/10/07 20:51:00 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/10/07 20:51:00 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/10/07 20:51:00 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/10/07 20:51:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/10/07 20:40:31 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/10/07 20:31:14 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/10/06 22:22:03 | 000,000,000 | ---D | C] -- C:\Users\zenny\Desktop\Cat.Run.2.2014.720p.BluRay.x264.DTS-HDWinG
[2014/10/06 20:22:56 | 000,168,264 | ---- | C] (Baidu) -- C:\Windows\SysNative\drivers\bd0004.sys
[2014/10/06 20:22:39 | 000,104,264 | ---- | C] (Baidu) -- C:\Windows\SysNative\drivers\bd0001.sys
[2014/10/06 20:22:39 | 000,041,800 | ---- | C] (Baidu) -- C:\Windows\SysNative\bd64_x64.dll
[2014/10/06 20:22:39 | 000,039,056 | ---- | C] (Baidu) -- C:\Windows\SysNative\bd64_x86.dll
[2014/10/06 20:22:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Baidu
[2014/10/06 20:21:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BaiduPlayer
[2014/10/06 00:41:39 | 000,000,000 | ---D | C] -- C:\Users\zenny\Desktop\Hercules.Reborn.2014.720p.BluRay.X264-iNVANDRAREN[rarbg]
[2014/10/05 15:56:10 | 000,000,000 | ---D | C] -- C:\Users\zenny\AppData\Roaming\WinRAR
[2014/10/05 15:56:02 | 000,000,000 | ---D | C] -- C:\Users\zenny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014/10/05 15:56:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014/10/05 15:55:54 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2014/10/05 15:16:23 | 000,000,000 | ---D | C] -- C:\Users\zenny\Desktop\IC stuffs
[2014/10/02 21:34:48 | 000,000,000 | ---D | C] -- C:\Users\zenny\Desktop\Blended.2014.BluRay.720p.DTS.x264-CHD
[2014/09/29 21:31:43 | 000,000,000 | ---D | C] -- C:\Users\zenny\Desktop\Brick.Mansions.2014.BluRay.720p.x264.DTS-HDWinG
[2014/09/23 20:26:14 | 000,000,000 | ---D | C] -- C:\Users\zenny\Desktop\Jarhead.2.Field.of.Fire.2014.BluRay.720p.DTS.x264-CHD
[2014/09/21 02:05:41 | 000,000,000 | ---D | C] -- C:\Users\zenny\Desktop\Captain.America.The.Winter.Soldier.2014.BluRay.720p.DTS.x264-CHD
[2014/09/21 01:03:26 | 000,000,000 | ---D | C] -- C:\iResearch
[2014/09/21 01:03:15 | 000,000,000 | ---D | C] -- C:\Users\zenny\AppData\Roaming\iy
========== Files - Modified Within 30 Days ==========
[2014/10/08 21:03:45 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/10/08 21:02:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\zenny\Desktop\OTL.exe
[2014/10/08 20:43:47 | 000,001,902 | ---- | M] () -- C:\Users\Public\Desktop\YAC.lnk
[2014/10/08 20:32:27 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/10/08 20:32:26 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/10/08 20:28:02 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/10/08 20:27:04 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/10/08 20:26:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/10/08 20:26:54 | 3175,981,056 | -HS- | M] () -- C:\hiberfil.sys
[2014/10/08 18:15:55 | 000,045,224 | ---- | M] (Elex do Brasil Participações Ltda) -- C:\Windows\SysNative\drivers\iSafeKrnlBoot.sys
[2014/10/08 00:21:02 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/10/07 23:42:48 | 000,001,042 | ---- | M] () -- C:\Users\zenny\AppData\Roaming\coreavc.ini
[2014/10/07 23:37:01 | 000,001,379 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2014/10/07 21:38:16 | 000,000,392 | ---- | M] () -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\360°²È«µ¼º½.lnk
[2014/10/07 20:51:02 | 000,000,613 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/10/06 20:21:55 | 000,001,012 | ---- | M] () -- C:\Users\Public\Desktop\BaiduPlayer.lnk
[2014/09/27 02:41:15 | 2680,127,575 | ---- | M] () -- C:\Users\zenny\Desktop\X-Men Days of Future Past 2014 720p BluRay DTS x264-DNL.mkv
[2014/09/27 01:20:36 | 000,017,639 | -H-- | M] () -- C:\Users\zenny\Desktop\4B40EB265F7CD06886C4130DC65CA96333FDDC87.torrent
[2014/09/25 19:13:33 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/09/22 20:13:46 | 000,049,320 | ---- | M] (Elex do Brasil Participações Ltda) -- C:\Windows\SysNative\drivers\iSafeNetFilter.sys
========== Files Created - No Company Name ==========
[2014/10/08 20:43:47 | 000,001,902 | ---- | C] () -- C:\Users\Public\Desktop\YAC.lnk
[2014/10/07 23:37:01 | 000,001,391 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2014/10/07 23:37:01 | 000,001,379 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2014/10/07 21:38:16 | 000,000,392 | ---- | C] () -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\360°²È«µ¼º½.lnk
[2014/10/07 20:51:02 | 000,000,613 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/10/06 20:21:55 | 000,001,012 | ---- | C] () -- C:\Users\Public\Desktop\BaiduPlayer.lnk
[2014/09/27 01:20:50 | 2680,127,575 | ---- | C] () -- C:\Users\zenny\Desktop\X-Men Days of Future Past 2014 720p BluRay DTS x264-DNL.mkv
[2014/09/27 01:20:43 | 000,017,639 | -H-- | C] () -- C:\Users\zenny\Desktop\4B40EB265F7CD06886C4130DC65CA96333FDDC87.torrent
[2014/08/24 23:42:36 | 000,003,760 | ---- | C] () -- C:\Users\zenny\PanPortalCfg_fd8237ba3c63fd73189dbfe98a3955c.dat
[2013/12/31 02:59:37 | 000,000,020 | ---- | C] () -- C:\Windows\SysWow64\pub_store.dat
[2013/12/29 22:31:48 | 000,000,598 | ---- | C] () -- C:\Windows\SysWow64\bdsecushr.dat
[2013/12/07 05:38:38 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013/12/07 05:38:38 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013/12/06 16:44:26 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2013/08/13 13:57:41 | 000,302,080 | ---- | C] () -- C:\Windows\lwd.exe
[2013/05/28 08:45:34 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2013/05/20 14:40:12 | 000,001,042 | ---- | C] () -- C:\Users\zenny\AppData\Roaming\coreavc.ini
[2013/05/20 12:09:32 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013/05/20 12:08:17 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013/05/20 12:08:17 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013/05/20 12:08:17 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2013/05/20 11:41:46 | 000,771,962 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/05/20 11:37:59 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
========== ZeroAccess Check ==========
[2009/07/14 12:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2009/07/14 09:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009/07/14 09:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 09:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 09:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 09:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/12/30 00:09:59 | 000,000,000 | -HSD | M] -- C:\Users\zenny\AppData\Roaming\2345Explorer
[2014/06/07 01:58:04 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\Animals
[2013/07/06 18:31:11 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\Awesomium
[2014/10/07 21:38:24 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\Baidu
[2014/10/07 21:38:15 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\BindIconDir
[2014/10/07 22:43:46 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\CloudMedia
[2014/06/05 20:51:54 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\DataRepair
[2014/10/08 20:43:35 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\Elex-tech
[2014/05/31 03:20:42 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\FunAir
[2014/10/07 21:01:31 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\Funshion
[2014/09/21 01:03:15 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\iy
[2014/04/29 21:31:52 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\xfplayer
[2013/12/31 02:59:08 | 000,000,000 | ---D | M] -- C:\Users\zenny\AppData\Roaming\Xunlei
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2014/10/06 20:47:25 | 007,336,335 | ---- | M] ()(C:\Users\zenny\Desktop\?????-???.mp3) -- C:\Users\zenny\Desktop\月半小夜曲-陈乐基.mp3
[2014/10/06 20:22:20 | 000,001,945 | ---- | M] ()(C:\Users\Public\Desktop\??.lnk) -- C:\Users\Public\Desktop\快播.lnk
[2014/10/06 20:22:20 | 000,001,945 | ---- | C] ()(C:\Users\Public\Desktop\??.lnk) -- C:\Users\Public\Desktop\快播.lnk
[2014/10/06 20:22:20 | 000,001,941 | ---- | M] ()(C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\??.lnk) -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\快播.lnk
[2014/10/06 20:22:20 | 000,001,941 | ---- | C] ()(C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\??.lnk) -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\快播.lnk
[2014/10/06 20:22:20 | 000,000,000 | ---D | C](C:\ProgramData\Microsoft\Windows\Start Menu\Programs\????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\快播软件
[2014/10/05 23:30:19 | 505,575,519 | ---- | M] ()(C:\Users\zenny\Desktop\????.Z.Nation.S01E04.????.HDTVrip.1024X576.mkv) -- C:\Users\zenny\Desktop\僵尸国度.Z.Nation.S01E04.中英字幕.HDTVrip.1024X576.mkv
[2014/10/05 23:15:42 | 505,575,519 | ---- | C] ()(C:\Users\zenny\Desktop\????.Z.Nation.S01E04.????.HDTVrip.1024X576.mkv) -- C:\Users\zenny\Desktop\僵尸国度.Z.Nation.S01E04.中英字幕.HDTVrip.1024X576.mkv
[2014/10/05 15:56:32 | 007,336,335 | ---- | C] ()(C:\Users\zenny\Desktop\?????-???.mp3) -- C:\Users\zenny\Desktop\月半小夜曲-陈乐基.mp3
[2014/10/01 21:30:07 | 1945,158,196 | ---- | M] ()(C:\Users\zenny\Desktop\?6v??????,???www.6vhao.com???????.720p.BD????.mp4) -- C:\Users\zenny\Desktop\【6v电影域名被盗,新地址www.6vhao.com】母亲外出之夜.720p.BD中英双字.mp4
[2014/10/01 20:09:03 | 1945,158,196 | ---- | C] ()(C:\Users\zenny\Desktop\?6v??????,???www.6vhao.com???????.720p.BD????.mp4) -- C:\Users\zenny\Desktop\【6v电影域名被盗,新地址www.6vhao.com】母亲外出之夜.720p.BD中英双字.mp4
[2014/09/28 22:04:49 | 1157,300,820 | ---- | M] ()(C:\Users\zenny\Desktop\??????????.720p.HD?????6v??????,???www.6vhao.net?.mp4) -- C:\Users\zenny\Desktop\白发魔女传之明月天国.720p.HD国语中字【6v电影域名被盗,新地址www.6vhao.net】.mp4
[2014/09/28 21:44:59 | 1157,300,820 | ---- | C] ()(C:\Users\zenny\Desktop\??????????.720p.HD?????6v??????,???www.6vhao.net?.mp4) -- C:\Users\zenny\Desktop\白发魔女传之明月天国.720p.HD国语中字【6v电影域名被盗,新地址www.6vhao.net】.mp4
[2014/09/15 23:09:39 | 2155,173,743 | ---- | M] ()(C:\Users\zenny\Desktop\????.BD1280??????.mp4) -- C:\Users\zenny\Desktop\落魄大厨.BD1280超清中英双字.mp4
[2014/09/15 21:44:05 | 2155,173,743 | ---- | C] ()(C:\Users\zenny\Desktop\????.BD1280??????.mp4) -- C:\Users\zenny\Desktop\落魄大厨.BD1280超清中英双字.mp4
[2014/09/15 21:15:06 | 2132,872,818 | ---- | M] ()(C:\Users\zenny\Desktop\????.HD1280??????.mp4) -- C:\Users\zenny\Desktop\沉睡魔咒.HD1280超清中英双字.mp4
[2014/09/15 20:37:44 | 2132,872,818 | ---- | C] ()(C:\Users\zenny\Desktop\????.HD1280??????.mp4) -- C:\Users\zenny\Desktop\沉睡魔咒.HD1280超清中英双字.mp4
[2014/09/13 15:31:26 | 2263,291,287 | ---- | M] ()(C:\Users\zenny\Desktop\MR??.HD1280??????.mp4) -- C:\Users\zenny\Desktop\MR边缘.HD1280超清英语中字.mp4
[2014/09/13 14:55:32 | 2263,291,287 | ---- | C] ()(C:\Users\zenny\Desktop\MR??.HD1280??????.mp4) -- C:\Users\zenny\Desktop\MR边缘.HD1280超清英语中字.mp4
[2014/08/24 02:11:20 | 1158,867,455 | ---- | M] ()(C:\Users\zenny\Desktop\???2????.BD????1280???6v??????,???www.6vhao.com?.rmvb) -- C:\Users\zenny\Desktop\铁甲衣2浴血奋战.BD中英双字1280高清【6v电影域名被盗,新地址www.6vhao.com】.rmvb
[2014/08/24 01:08:59 | 1158,867,455 | ---- | C] ()(C:\Users\zenny\Desktop\???2????.BD????1280???6v??????,???www.6vhao.com?.rmvb) -- C:\Users\zenny\Desktop\铁甲衣2浴血奋战.BD中英双字1280高清【6v电影域名被盗,新地址www.6vhao.com】.rmvb
[2014/08/06 21:34:56 | 1251,265,606 | ---- | M] ()(C:\Users\zenny\Desktop\R?????2:?ZF??.HD1280??????.mp4) -- C:\Users\zenny\Desktop\R类清除计划2:无ZF状态.HD1280高清英语中字.mp4
[2014/08/06 21:22:59 | 1251,265,606 | ---- | C] ()(C:\Users\zenny\Desktop\R?????2:?ZF??.HD1280??????.mp4) -- C:\Users\zenny\Desktop\R类清除计划2:无ZF状态.HD1280高清英语中字.mp4
[2014/05/27 23:11:24 | 1399,289,541 | ---- | M] ()(C:\Users\zenny\Desktop\[????www.dy2018.com]?????BD????.rmvb) -- C:\Users\zenny\Desktop\[电影天堂www.dy2018.com]盟军夺宝队BD中英双字.rmvb
[2014/05/27 22:35:15 | 1399,289,541 | ---- | C] ()(C:\Users\zenny\Desktop\[????www.dy2018.com]?????BD????.rmvb) -- C:\Users\zenny\Desktop\[电影天堂www.dy2018.com]盟军夺宝队BD中英双字.rmvb
[2014/05/11 00:58:19 | 000,001,003 | ---- | M] ()(C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\????.lnk) -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\影音先锋.lnk
[2014/05/11 00:58:19 | 000,000,979 | ---- | M] ()(C:\Users\zenny\Desktop\????.lnk) -- C:\Users\zenny\Desktop\影音先锋.lnk
[2014/04/27 19:09:01 | 000,001,003 | ---- | C] ()(C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\????.lnk) -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\影音先锋.lnk
[2014/04/27 19:09:01 | 000,000,979 | ---- | C] ()(C:\Users\zenny\Desktop\????.lnk) -- C:\Users\zenny\Desktop\影音先锋.lnk
[2014/04/19 14:28:12 | 000,001,056 | ---- | M] ()(C:\Users\zenny\Desktop\???????.lnk) -- C:\Users\zenny\Desktop\迅雷看看播放器.lnk
[2014/04/19 14:28:12 | 000,001,056 | ---- | C] ()(C:\Users\zenny\Desktop\???????.lnk) -- C:\Users\zenny\Desktop\迅雷看看播放器.lnk
[2014/01/27 20:24:11 | 000,001,317 | ---- | M] ()(C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\??.lnk) -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\风行.lnk
[2013/12/30 15:54:18 | 000,001,161 | ---- | M] ()(C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\????2013.lnk) -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\百度音乐2013.lnk
[2013/12/30 15:54:18 | 000,001,161 | ---- | C] ()(C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\????2013.lnk) -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\百度音乐2013.lnk
[2013/09/24 12:57:35 | 000,001,317 | ---- | C] ()(C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\??.lnk) -- C:\Users\zenny\Application Data\Microsoft\Internet Explorer\Quick Launch\风行.lnk
(C:\Users\zenny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????2013) -- C:\Users\zenny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\百度音乐2013
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\迅雷软件
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\影音先锋
< End of report >