Trojan.GenericKD.3018907_0ffa45bbb0

SoftwareBundler:Win32/Chindo (Microsoft), UDS:DangerousObject.Multi.Generic (Kaspersky), Suspicious.Cloud.9 (Symantec), Trojan.GenericKD.3018907 (AdAware), Trojan.NSIS.StartPage.FD, mzpefinder_pcap_fi...
Blog rating:2 out of5 with5 ratings

Trojan.GenericKD.3018907_0ffa45bbb0

by malwarelabrobot on May 17th, 2017 in Malware Descriptions.

SoftwareBundler:Win32/Chindo (Microsoft), UDS:DangerousObject.Multi.Generic (Kaspersky), Suspicious.Cloud.9 (Symantec), Trojan.GenericKD.3018907 (AdAware), Trojan.NSIS.StartPage.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 0ffa45bbb070fd21152782e8a39335e3
SHA1: b6f3b65a640293b6f6b3aeaa2e12cc09f76df060
SHA256: 635fde7f9ebc149d6ab2c471d2128eb4ddaa7476eca82cb704a409777390bfbd
SSDeep: 3072:fqBFJLzgOJJNuJ09nGa0KenZhNs76D0Ir8m 7C1rHP/CSDhEZ4KvEfoa02nK:yPdZQ69mKkhDDp8mV1rPaSlEZ4 Ek8K
Size: 190055 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2009-06-19 00:33:12
Analyzed on: Windows7 SP1 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

stats_uploader.exe:3056
V8._85296_20150814221218.exe:1980
xReport.exe:3796
xReport.exe:1584
QQBrowser.exe:2524
QQBrowser.exe:856
QQBrowser.exe:1804
QQBrowser.exe:3396
QQBrowser.exe:2968
QQBrowser.exe:2296
QQBrowser.exe:1872
QQBrowser.exe:1452
QQBrowser.exe:2972
QQBrowser.exe:812
QQBrowser.exe:3052
QQBrowser.exe:2952
BaiduPlayer5SetupSilent_363.exe:2636
netsh.exe:2224
netsh.exe:1732
PerfTraceService.exe:2220
regsvr32.exe:4028
PlayerApp.exe:2496

The Trojan injects its code into the following process(es):

Browser_V5.5.7852.9_r_4640_(Build1512022057).exe:3236
%original file name%.exe:1976
xUpdate.exe:1668
BDPlayerTray.exe:3432

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process Browser_V5.5.7852.9_r_4640_(Build1512022057).exe:3236 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\custom.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\12dc664d-0442-4570-a7c8-f3aa22922cec.com.png (252 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\extension\noads.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\chrome.7z (1344211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\tmall.com.png (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\background_lib.js (129 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\amazon.png (507 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\youku.com.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\fame.png (444 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\resources.pak (92927 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Uninstall.exe (9133 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\uclauncher-x86.exe (1139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\en-in\share.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_100_percent.pak (1931 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\taobao.com.png (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\chrome.packed.7z (59963 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\06.png (354 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\baidu.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\index.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\taobao.png (389 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome.dll (157305 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\tmall.com.png (200 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Languages\chs.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\uclauncher-xp.exe (1499 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\14.png (488 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\zh-CN\external_extensions.json (934 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\lazy_index.js (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\youku.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\new-tab-icon.png (113 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\libmp3lame.dll (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\sogou.com.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\news_pre_render.js (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\18.png (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\lecture.png (282 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\config.dat (2939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\font\font_8jda4sp0bz8pk3xr.ttf (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\VisualElements\Logo.png (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\data\city.json (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\login_view\alipay.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\UCProxySDK.dll (4489 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\game.png (340 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\id-ID\external_extensions.json (493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\extension\taohuoyuan.png (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\lazy_lib.js (57 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\marketing\1001.ico (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\UCBrowser.exe (2987 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\youku.com.png (764 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\background.js (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Locales\en-US.pak (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\zh-cn\config.dat (2939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\7z.dll (1841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\07.png (305 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\id\config.dat (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\baidu.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\font\font_8jda4sp0bz8pk3xr.woff (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\life.png (475 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\d3dcompiler_47.dll (13439 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\6.1.2107.204.manifest (250 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\update_task.exe (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\sogou.com.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\setup_ex_.cab (441 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_watcher.dll (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\pt-br\start.dat (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\taobao.com.png (304 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\config.dat (124 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\setup.exe (17426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Bin\ChannelU.dll (26363496 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\VisualElements\SmallLogo.png (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\new_tab_icon.png (113 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\snapshot_blob.bin (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\icon\48.jpg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\taobao.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\pt-BR\external_extensions.json (493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\libGLESv2.dll (5192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\wallpaper\moon.jpg (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\subscribe.png (398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Locales\zh-CN.pak (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\00.png (436 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\news\refresh.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\ucdrv-x86.sys (42 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\ru\share.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\stats_uploader.exe (612 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\config.ini (195 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Update\curl-ca-bundle.crt (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\baidu.com.png (426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\ru\start.dat (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\uclauncher-x64.exe (1499 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\bing.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\wow_installer.prefs (235 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\google.com.hk.png (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_child.dll (183256 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\n_01.png (509 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\id\share.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\start.dat (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\login_view\weibo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\VERSION (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\google.com.png (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\es-419\config.dat (124 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Languages\settings.xml (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\bing.com.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\ucdrv-xp.sys (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_elf.dll (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\custom.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\icon\48.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\rec.png (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\wallpaper\default.jpg (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\es-419\start.dat (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\social.png (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\courgette.dll (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\ucdrv-x64.sys (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\09.png (328 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\extension\renren.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\01.png (544 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\etao.com.png (335 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\libEGL.dll (88 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\shop.png (350 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\en-in\config.dat (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Update\InstalledConfig.xml (713 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\google.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\12dc664d-0442-4570-a7c8-f3aa22922cec.com.png (479 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\aavc.ini (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\browsing_data_remover.exe (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\desktop\facebook.ico (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_200_percent.pak (2987 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\config_updater.dll (2939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\baidu.com.png (682 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\wallpaper\rain.jpg (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\react_lib.js (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\news.png (205 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\uc123.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\video.png (368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\updater.dll (8643 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\es-419\share.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\pt-br\share.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\hrkill.exe (1931 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\zh-cn\start.dat (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Backup\UCBrowser.exe (2987 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\external_extensions.json (493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\multiple.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\13.png (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\icon\16.png (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\UCService.exe (1139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\PepperFlash\manifest.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\wow_installer.switches.txt (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\zh-cn\share.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\wallpaper\snow.jpg (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\bing.com.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\start.dat (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\en-in\start.dat (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\data\pc_newtab_recommendation.json (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\ru\config.dat (124 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\03.png (305 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\02.png (294 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\other.png (180 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\en-IN\external_extensions.json (621 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\20.png (480 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\login_view\qq.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\icudtl.dat (19407 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\UCBrowserSetup.exe (70898 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\icon\128.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\7z.dll (2939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\default.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\share.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\desktop\tmall_points.ico (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\delegate_execute.exe (1499 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\google.com.png (521 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\stats_uploader.exe (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\04.png (645 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\16.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\login_view\taobao.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\etaohaitao.com.png (438 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\share.dat (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\pp_helper.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\19.png (367 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\pt-br\config.dat (124 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\theme_tool.exe (1139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\PepperFlash\pepflashplayer.dll (69197 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\index.js (114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\id\start.dat (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\wow_helper.exe (80 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\natives_blob.bin (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\_locales\en\messages.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\libexif.dll (419 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Update\UpdateOption.xml (189 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\n_00.png (286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\UCAgent.exe (8056 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\etao.com.png (252 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\molt_tool.exe (851 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\config.ini (0 bytes)

The process V8._85296_20150814221218.exe:1980 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\WebpDecodeFilter.dll (2128 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\installed_arrow.png (176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\skin\LightStripes.gt (94 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\theme.png (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_active_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_ceil.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_game.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\js\base.js (4 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\js\base.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{A1D7EDF6-6151-4F2D-B39E-01D6FABE0325}.qrx (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\xperf.exe (5001 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___s.click.taobao.com_khr1bAy.jpg (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_recommendcelltag_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\index.html (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\picker_ceil_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\dr.dll (601 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_active_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\image.png (5 bytes)
%Program Files%\Tencent\QQBrowser\MouseGesture.dll (56 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\img\search.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_sogou.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcr90.dll (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\infobar_close_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\app_active.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\qblogo.png (868 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#app.ico (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\img\del2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\history2.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\history_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\mainlist.ze (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_video.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\DB\homepage.db (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\init.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\init.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\sliderman.1.3.7.js (19 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\tab_bg_white.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\QBUtils.dll (12336 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\favicon\index.html#skin.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\blue.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\down.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\DB\history.db (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\background.html (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\msvcm90.dll (2129 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\wifi_dialog_close_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_floor_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_video_active.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\js\api.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\searchbar_searchengine_arrow.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\app_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_game_hover.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab91B4.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\installed_arrow.png (176 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_soso.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\https___mail.qq.com_.jpg (16 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\js\global.js (394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{132A61AD-1025-4629-960D-B21EE8BAABB3}.qrx (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_google.png (919 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_recommendcelltag.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_active_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{C74EB4B8-B51A-4BF7-A213-E29859D69D83}.qrx (15 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\account_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\icon.png (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_newcelltag_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\closeBtnSearchbar.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\background.js (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\blue.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\default.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\img\up-down.png (999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\favicon\index.html#account.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\css\style.css (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\plugin2.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{ACC06D2A-2285-4ed9-B4E4-0F3198501410}.qrx (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{3349050F-829E-4bb2-AACF-03E3A6B68677} (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\reader.html (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_offlineurl.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{6970B802-2F13-4038-B620-33B0211D26A0} (99 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}_1\QBSafe.dll (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Adblock\whitelist.ze (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\addressbar_blank.png (5 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\image\infobar_offlineurl.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\default-icon.png (1 bytes)
%Program Files%\Tencent\QQBrowser\navi.ico (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\init.js (4 bytes)
%Program Files%\Tencent\QQBrowser\QBExtensionFramework.dll (3918 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\infobar_close_normal.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___tq.qq.com_qbrcenter_index.html_adtag=8gongge.jpg (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\accountInfoBar.html (794 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_hover_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\tssafeedit.dat (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{3E9C7A5B-D249-4C28-A451-53E1024AD354} (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633 (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\picker_floor.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_toast_unlocked.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\tool.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\index.html (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___www.3366.com__ADTAG=cop.QQbrowser.8new.jpg (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\app_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\small.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}.qrx (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_video.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\tab_bg_blank.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\background.js (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\QQTrace.ini (3 bytes)
%Program Files%\Tencent\QQBrowser\Html\certerror.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___browser.qq.com_new_wechat1.0.html_type=1.jpg (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_374AF031F22A1FC086DCBA0C50021437 (1504 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\tab_bg_blank.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_baidu.png (870 bytes)
C:\Users\"%CurrentUserName%"\Desktop\~Q浏览器.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_hover_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\app.js (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account\down.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\atbk2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\index.html (1 bytes)
%Program Files%\Tencent\QQBrowser\Assistant.dll (2321 bytes)
%Program Files%\Tencent\QQBrowser\service\xperf.exe (2105 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\picker_ceil.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\wifi_dialog_cancel_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\tab_bg_blank.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\index.html (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image (4 bytes)
%Program Files%\Tencent\QQBrowser\manifest.json (261 bytes)
%Program Files%\Tencent\QQBrowser\Html\lib\jquery.min.js (92 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\{43789A6F-8316-54A6-96D4-87874B9CC177} (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\plugin2.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_bing.png (442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\account\up.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}.qrx (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\plugin3.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\icon_not_recommended.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\bkg.gif (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\account.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcp90.dll (3934 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\Microsoft.VC90.CRT\msvcr90.dll (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___www.3366.com__ADTAG=cop.QQbrowser.8new.jpg (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\icon_suggested_action.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\hse.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_game_hover.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\down.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\picker_ceil.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_game.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_video_hover.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db\history.db (108 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_video_hover.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_newcelltag_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\image.png (5 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\img\del.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\business.js (9 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\css\ycalendar.css (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\img\checkbox.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\night.png (546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_blank_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___s.click.taobao.com_khr1bAy.jpg (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\image\accountInfo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_active_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{CAA4306F-826C-4c1b-8FC6-571F84949DB4} (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_selected_white.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\app_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\addressbar_white.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\shadow-bottom.png (2 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\history_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\lib\jquery.mCustomScrollbar.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\business.js (8 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\plugin3.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{7E2975A3-E661-42F2-8614-A9D18CBB20FE}.qrx (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\nsis_skin.gt (106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowserFrame.dll (13493 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#history.ico (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\favicon\index.html#account.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_white_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\app.js (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\checkbox.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_hover_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\inforBar.html (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb (4 bytes)
%Program Files%\Tencent\QQBrowser\QQBrowser.exe (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\uninst.exe (3649 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\manifest.json (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Downloader.dll (4010 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\MouseGesture.dll (872 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\arrowdown_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\css\app.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\bkg.gif (22 bytes)
%Program Files%\Tencent\QQBrowser\Html\error.html (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\accountInfo.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\up-down.png (999 bytes)
%Program Files%\Tencent\QQBrowser\service\perfctrl.dll (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin_active.png (1 bytes)
%Program Files%\Tencent\QQBrowser\QQBrowserSecurityCenter.exe (673 bytes)
%Program Files%\Tencent\QQBrowser\Dialogs.dll (7385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\closeBtnSearchbar.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\icon.fw.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\searchbar_searchengine_arrow.png (1 bytes)
%Program Files%\Tencent\QQBrowser\service\7z.exe (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_video_active.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___tq.qq.com_qbrcenter_index.html_adtag=8gongge.jpg (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\css\base.css (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\manifest.json (197 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\qblogo.png (868 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\QQBrowserLiveup.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\addressbar_white.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\site_text.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\articlecontent.css (12 bytes)
%Program Files%\Tencent\QQBrowser\resources.pri (3 bytes)
%Program Files%\Tencent\QQBrowser\Downloader.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Adblock\{43789A6F-8316-54A6-96D4-87874B9CC177} (5 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\css\history.css (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\index.ini (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件\QQ浏览器\QQ浏览器.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\whitelist.ze (1 bytes)
%Program Files%\Tencent\QQBrowser\WebpDecodeFilter.dll (673 bytes)
%Program Files%\Tencent\QQBrowser\Html\lib\jquery.mCustomScrollbar.concat.min.js (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{B00DFF21-511E-4249-BCB9-EECC370D796B} (430 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#skin.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{7E2975A3-E661-42F2-8614-A9D18CBB20FE}.qrx (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\error.html (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Adblock\wbg.png (136 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\icon_not_recommended.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_recommendcelltag.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___www.qq.com__pgv_ref=qqBrowserPC.jpg (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\reader.html (30 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\history_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\favicon\index.html#app.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\certerror.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\screen.css (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\img\atbk1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\image\infobar_close_normal.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\Private-icon.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_hover_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\background.html (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\up-down.png (999 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_recommendcelltag_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{3E9C7A5B-D249-4C28-A451-53E1024AD354} (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\addressbar_white.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\jquery.mCustomScrollbar.concat.min.js (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\addressbar_blank.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\index.ini (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\app.js (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\perfctrl.dll (3447 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\checkbox.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\green.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\index.html (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\app.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\history_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_toast_locked.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{A1D7EDF6-6151-4F2D-B39E-01D6FABE0325}.qrx (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\loading.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account\down.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\installed_arrow.png (176 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\js\global.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_selected_blank.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\event\bg.png (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Resource.dll (1365 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\js\inforBar.js (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\css\style.css (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar91B5.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_toast_unlocked.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{00000000-0000-0000-0000-000000000000}\jquery.js (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{B00D20E2-207A-431A-9712-E1279792681B} (89 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\7z.exe (1209 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\warn-dialog-close.png (295 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_mask.png (923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\msvcp90.dll (6900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\PerfTraceService.exe (2934 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\js\init.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{E5914276-7752-43C4-9723-50EE9CF51AD8}.qrx (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_fav.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\api.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown.png (1 bytes)
%Program Files%\Tencent\QQBrowser\nsis_skin.gt (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\content.js (30 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_game_active.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\PrScrn.dll (2517 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{44A126BF-51C2-48AD-A593-94B50071EB64}.qrx (39 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\del2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_soso.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\del.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_selected_blank_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_video.png (3 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_hover_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\search.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_white.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\app.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\video\vd.ini (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\js\inforBar.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\large_installed_arrow.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\plugin1.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\QBUtils.dll (12287 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\small.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\jquery.easing.js (3 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\image\infobar_login.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\hse.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{5062F1C6-D76B-43c8-ADAE-D060662C6546}\extplayer.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\text_light.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\api.js (3 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\icon_suggested_action.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\image\infobar_fav.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\sliderman.1.3.7.js (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\search.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\site_text.png (5 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_toast_locked.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\small.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\search_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{6970B802-2F13-4038-B620-33B0211D26A0} (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\pixel.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\pixel.gif (43 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\js\tool.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\text_light.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QBExtensionFramework.dll (3766 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}_1\manifest.json (256 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\icon_suggested_action.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.easing.js (3 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_newcelltag.png (1 bytes)
%Program Files%\Tencent\QQBrowser\BugReport.exe (2321 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\account\down.png (971 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\event\bg.png (28 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_selected_blank.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\qqbrowser_home.jpg (14 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\loading.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\css\style.css (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\msvcr90.dll (8224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{CD36E3DB-304A-48EF-A8A2-D873F608D2AE}.qrx (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\screen.css (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\loading.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\Config.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\large_installed_arrow.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\certerror.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\theme_ie.png (15 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\history2.js (21 bytes)
%Program Files%\Tencent\QQBrowser\Html\lib\ycalendar.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\small.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\atbk1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_login.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_active_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_newcelltag.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\css\style.css (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{CAA4306F-826C-4c1b-8FC6-571F84949DB4} (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_active_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\night.png (546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_ceil_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_game_hover.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{3349050F-829E-4bb2-AACF-03E3A6B68677} (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\warn-dialog-close.png (295 bytes)
%Program Files%\Tencent\QQBrowser\QBSafe.dll (454 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_toast_unlocked.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\picker_floor_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{C74EB4B8-B51A-4BF7-A213-E29859D69D83}.qrx (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\plugin1.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}.qrx (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\image\infobar_close_active.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_selected_white_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db\homepage.db (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account\up.png (971 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\hse.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_recommendcelltag_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\qqtrack.xml (4 bytes)
%Program Files%\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcm90.dll (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\Microsoft.VC90.CRT\msvcp90.dll (3361 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\global.js (394 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\global.js (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_google.png (919 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\search_btn.png (1 bytes)
%Program Files%\Tencent\QQBrowser\QRCode.dll (31 bytes)
%Program Files%\Tencent\QQBrowser\QQBrowserLiveup.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\sogou_web.png (5 bytes)
C:\Users\"%CurrentUserName%"\Desktop\上网导航.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_active.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\pixel.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\bggradient_day.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\default-icon.png (1 bytes)
C:\Users\"%CurrentUserName%"\Desktop\QQ浏览器.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\Private-icon.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UserPinnedTemp\~Q浏览器.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\security.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowserSecurityCenter.exe (2015 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_selected_blank_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Video\vd.ini (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___qzone.qq.com_.jpg (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\tool.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\business.js (9 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\image\infobar_close_normal.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{132A61AD-1025-4629-960D-B21EE8BAABB3}.qrx (17 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\js\init.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UserPinnedTemp\QQ浏览器.lnk (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\close.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{B00DFF21-511E-4249-BCB9-EECC370D796B} (430 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\tab_bg_white.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___qzone.qq.com_.jpg (12 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\image\security.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\css\ycalendar.css (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\searchbar_searchengine_arrow.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\sogou_web.png (5 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\history.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\api.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\img\down.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_blank.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\pink.png (716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\large_installed_arrow.png (1 bytes)
%Program Files%\Tencent\QQBrowser\PrScrn.dll (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\license.txt (17 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\arrowdown_hover_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db\random.db (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\wbg.png (136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_bing.png (442 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\wifi_dialog_continue_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\history.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\tssafeedit.dat (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\imgSearch.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件\QQ浏览器\~Q浏览器.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\QBInstaller.dll (1275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\global.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\bgsearch_day.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\css\style.css (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\history_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\js\injectReader.js (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\del2.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12\QBSafe.dll (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account\up.png (971 bytes)
%Program Files%\Tencent\QQBrowser\uninst.exe (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\css\style.css (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\uninstallBtn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\css\style.css (6 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\account_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\EventTracing.dll (39 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\yellow.png (626 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12\manifest.json (256 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\small_installed_arrow.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\articlecontent.css (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.min.js (92 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\sliderman.1.3.7.js (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\QQ浏览器.lnk (2 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_active_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{B00D20E2-207A-431A-9712-E1279792681B} (89 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\image\icon.png (487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\gray.png (501 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\qqbrowser_home.jpg (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___speed.qq.com_act_a20141103plan_.jpg (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Adblock\mainlist.ze (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin_active.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_hover_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\default.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_selected_white_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\error.html (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\history2.js (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\EventTracing.dll (1326 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\css\style.css (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\resources.pri (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\small.png (2 bytes)
%Program Files%\Tencent\QQBrowser\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{00000000-0000-0000-0000-000000000000}\jquery.js (92 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\inforBar.html (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___speed.qq.com_act_a20141103plan_.jpg (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\css\ycalendar.css (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\wifi_dialog_cancel_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}.qrx (244 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\img\closeBtnSearchbar.png (1 bytes)
%Program Files%\Tencent\QQBrowser\service\qqtrack.xml (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\shadow-bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\theme.png (25 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\app_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\service\QQTrace.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QBUtils.dll (17689 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\index.html (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\tab_bg_white.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowserLiveup.exe (3502 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\js\business.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\qqtrack.xml (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\favicon\index.html#history.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\default-icon.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\theme.png (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\green.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\plugin2.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_baidu.png (870 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_recommendcelltag.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\css\base.css (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\wifi_dialog_close_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\qblogo.png (868 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_soso.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Dialogs.dll (10771 bytes)
%Program Files%\Tencent\QQBrowser\Html\lib\template.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_active_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\ycalendar.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\imgSearch.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\small_installed_arrow.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\init.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QRCode.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account_active.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\js\api.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\template.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}.qrx (364 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.mCustomScrollbar.css (9 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\arrowdown.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\history\img\atbk2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\pink.png (716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UserPinnedTemp (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_baidu.png (870 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\bggradient_day.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\shadow-bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\qqtrack.xml (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\js\injectReader.js (19 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\wifi_dialog_close_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\atbk2.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\index.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{CD36E3DB-304A-48EF-A8A2-D873F608D2AE}.qrx (30 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\css\app.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.mCustomScrollbar.concat.min.js (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{44A126BF-51C2-48AD-A593-94B50071EB64}.qrx (39 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\wifi_dialog_cancel_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\icon.fw.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_hover_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_newcelltag.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\search_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\css\history.css (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\https___mail.qq.com_.jpg (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___www.qq.com__pgv_ref=qqBrowserPC.jpg (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\icon_not_recommended.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\QQ浏览器.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_sogou.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\site_text.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\private.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_close_active.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\plugin1.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_sogou.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\arrowdown_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\picker_floor.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\NetWork.dll (2602 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\small_installed_arrow.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\css\app.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{E5914276-7752-43C4-9723-50EE9CF51AD8}.qrx (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_hover_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\jquery.min.js (92 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\DB\random.db (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\arrowdown_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\jquery.mCustomScrollbar.css (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\arrowdown_hover_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\Microsoft.VC90.CRT\msvcp90.dll (3934 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\favicon\index.html#app.ico (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\index.html (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{ACC06D2A-2285-4ed9-B4E4-0F3198501410}.qrx (12 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\bkg.gif (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_active_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\text_light.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_bing.png (442 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\favicon\index.html#skin.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\wifi_dialog_continue_btn.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\lib\jquery.easing.js (3 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\warn-dialog-close.png (295 bytes)
%Program Files%\Tencent\QQBrowser\QQBrowserFrame.dll (11518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\navi.ico (15 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_floor.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_close_normal.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\bgsearch_day.jpg (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#account.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowser.exe (1661 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~Q浏览器.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\arrowdown.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\TridentCore.dll (9754 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\yellow.png (626 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\history_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\history.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\private.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin (8 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_selected_white.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\js\search.js (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\global.js (394 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1212 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\api.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_google.png (919 bytes)
%Program Files%\Tencent\QQBrowser\Html\images\Private-icon.png (3 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\image\infobar_close_active.png (1 bytes)
%Program Files%\Tencent\QQBrowser\service\PerfTraceService.exe (1707 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\CustomerJoinPlan.txt (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\content.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\template.js (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\arrowdown_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\uninstallBtn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_hover_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Infobar\image\infobar_close_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\app\images\uninstallBtn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\close.png (1 bytes)
%Program Files%\Tencent\QQBrowser\skin\LightStripes.gt (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\css\history.css (8 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\theme_ie.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\event\bg.png (28 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\picker_floor_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\BugReport.exe (7256 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\image\infobar_close_hover.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\js\business.js (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_mask.png (923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\theme_ie.png (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_video_active.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_374AF031F22A1FC086DCBA0C50021437 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\manifest.json (5 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_newcelltag_ie.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\plugin3.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_game_active.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\small.html (2 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\addressbar_blank.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown_hover_ie.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\private.html (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\ycalendar.js (4 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manifest.json (197 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\accountInfoBar.html (794 bytes)
%Program Files%\Tencent\QQBrowser\Resource.dll (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\default.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\QQ浏览器.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\search.js (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\skin\picker_ceil_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img (4 bytes)
%Program Files%\Tencent\QQBrowser\app.ico (284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\gray.png (501 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\business.js (8 bytes)
%Program Files%\Tencent\QQBrowser\QBUtils.dll (12336 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\dr.dll (864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_game_active.png (3 bytes)
%Program Files%\Tencent\QQBrowser\NetWork.dll (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_close_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_mask.png (923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\del.png (1 bytes)
%Program Files%\Tencent\QQBrowser\TridentCore.dll (7345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}.qrx (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{5062F1C6-D76B-43c8-ADAE-D060662C6546}\extplayer.js (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\atbk1.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\img\app.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\manage\favicon\index.html#history.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_game.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\Microsoft.VC90.CRT\msvcr90.dll (4840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Assistant.dll (6284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_toast_locked.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\search.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account_active.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\infobar_close_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\wifi_dialog_continue_btn.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\app_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manifest.json (197 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock.png (1 bytes)
%Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_video_hover.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___browser.qq.com_new_wechat1.0.html_type=1.jpg (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\close.png (1 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{CD36E3DB-304A-48EF-A8A2-D873F608D2AE}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\WebpDecodeFilter.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\screen.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\inforBar.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\articlecontent.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\checkbox.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_hover_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\large_installed_arrow.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UserPinnedTemp\QQ浏览器.lnk (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_ceil.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_game.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\qqbrowser_home.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_white.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{A1D7EDF6-6151-4F2D-B39E-01D6FABE0325}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_game_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_active_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db\homepage.db (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Downloader.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\{43789A6F-8316-54A6-96D4-87874B9CC177} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\small.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\tab_bg_white.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\atbk1.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\init.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}_1\QBSafe.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_video_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\bkg.gif (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_mask.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_bing.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\up-down.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_newcelltag.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\css\style.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.mCustomScrollbar.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\infobar_close_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_active_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{C74EB4B8-B51A-4BF7-A213-E29859D69D83}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\image.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#app.ico (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\pink.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\history_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_baidu.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\mainlist.ze (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\plugin1.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{B00DFF21-511E-4249-BCB9-EECC370D796B} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\init.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\night.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\sliderman.1.3.7.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_toast_unlocked.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Resource.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{CD36E3DB-304A-48EF-A8A2-D873F608D2AE}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\global.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_ceil_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\qblogo.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.mCustomScrollbar.concat.min.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{44A126BF-51C2-48AD-A593-94B50071EB64}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\xperf.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\PrScrn.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\icon.fw.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_hover_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\hse.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\down.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\css\history.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\search_btn.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_blank_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\wifi_dialog_close_btn.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_floor_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\event (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_sogou.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\site_text.png (0 bytes)
C:\Users\"%CurrentUserName%"\Desktop\QQ浏览器.lnk~RF1494fe.TMP (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\app_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\searchbar_searchengine_arrow.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_game_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\app_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar91B5.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowserFrame.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\index.ini (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\NetWork.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\Private-icon.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_soso.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\PerfTraceService.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_toast_locked.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#skin.ico (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{7E2975A3-E661-42F2-8614-A9D18CBB20FE}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowserSecurityCenter.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\msvcm90.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{132A61AD-1025-4629-960D-B21EE8BAABB3}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\tool.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\api.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\CustomerJoinPlan.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_google.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_recommendcelltag.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.easing.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{132A61AD-1025-4629-960D-B21EE8BAABB3}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db\random.db (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{C74EB4B8-B51A-4BF7-A213-E29859D69D83}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\uninst.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\bggradient_day.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_newcelltag_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{ACC06D2A-2285-4ed9-B4E4-0F3198501410}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_active_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\certerror.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\imgSearch.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\background.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\blue.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\css\ycalendar.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___browser.qq.com_new_wechat1.0.html_type=1.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\plugin2.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\navi.ico (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\background.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{3349050F-829E-4bb2-AACF-03E3A6B68677} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\api.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_offlineurl.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{CAA4306F-826C-4c1b-8FC6-571F84949DB4} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_floor.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_close_normal.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UserPinnedTemp\QQ浏览器.lnk~RF1492ec.TMP (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{ACC06D2A-2285-4ed9-B4E4-0F3198501410}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\addressbar_blank.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\bgsearch_day.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#account.ico (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\video (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowser.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_blank.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{3E9C7A5B-D249-4C28-A451-53E1024AD354} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\infobar_close_normal.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\license.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\skin\ThirdParty.gt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\wbg.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\perfctrl.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\accountInfo.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\qqtrack.xml (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\index.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\app.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\history.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\skin\DarkStripes.gt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\icon.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{44A126BF-51C2-48AD-A593-94B50071EB64}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\loading.gif (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\closeBtnSearchbar.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{6970B802-2F13-4038-B620-33B0211D26A0} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\js\base.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account\down.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\installed_arrow.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\index.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{A1D7EDF6-6151-4F2D-B39E-01D6FABE0325}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_close_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___www.3366.com__ADTAG=cop.QQbrowser.8new.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\tssafeedit.dat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\whitelist.ze (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\js\inforBar.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\reader.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\sogou_web.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\template.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\QBInstaller.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\global.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\QQTrace.ini (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\history_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\js\injectReader.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QRCode.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{B00D20E2-207A-431A-9712-E1279792681B} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\warn-dialog-close.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\text_light.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件\QQ浏览器\QQ浏览器.lnk~RF14928e.TMP (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\close.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\shadow-bottom.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\del2.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\theme_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{5062F1C6-D76B-43c8-ADAE-D060662C6546} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\event\bg.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\accountInfoBar.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\wifi_dialog_cancel_btn.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{E5914276-7752-43C4-9723-50EE9CF51AD8}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\tab_bg_blank.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\business.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account_active.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\BugReport.exe (0 bytes)
%Program Files%\Tencent\QQBrowser\manifest.json (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\skin\LightStripes.gt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_recommendcelltag_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\msvcp90.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\EventTracing.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.min.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\skin (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\content.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account\up.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\manifest.json (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\small_installed_arrow.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\plugin3.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\css\style.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab91B4.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___speed.qq.com_act_a20141103plan_.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown_hover_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\MouseGesture.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Dialogs.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\security.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\atbk2.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manifest.json (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\error.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\history2.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UserPinnedTemp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\video\vd.ini (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\business.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{E5914276-7752-43C4-9723-50EE9CF51AD8}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\default.ico (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\uninstallBtn.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\search.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_video_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UserPinnedTemp\QQ浏览器.lnk~RF14950e.TMP (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\TridentCore.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db\history.db (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\gray.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\yellow.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\small.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{00000000-0000-0000-0000-000000000000}\jquery.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\resources.pri (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\app.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\ycalendar.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_video.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___s.click.taobao.com_khr1bAy.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___qzone.qq.com_.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\dr.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\index.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_fav.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_hover_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\Config.xml (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\icon_not_recommended.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\qqtrack.xml (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_close_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___tq.qq.com_qbrcenter_index.html_adtag=8gongge.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\del.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QBUtils.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\private.html (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\https___mail.qq.com_.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowserLiveup.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{5062F1C6-D76B-43c8-ADAE-D060662C6546}\extplayer.js (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\green.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\7z.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\addressbar_white.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}_1 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\pixel.gif (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___www.qq.com__pgv_ref=qqBrowserPC.jpg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\css\base.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\manifest.json (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\default-icon.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\theme.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QBExtensionFramework.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Assistant.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\QQ浏览器.lnk~RF14950e.TMP (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}_1\manifest.json (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\icon_suggested_action.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\msvcr90.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{7E2975A3-E661-42F2-8614-A9D18CBB20FE}.qrx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\css\app.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\nsis_skin.gt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\infobar_close_hover.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\wifi_dialog_continue_btn.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_login.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#history.ico (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\css\style.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{00000000-0000-0000-0000-000000000000} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\search.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_white_ie.png (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html (0 bytes)

The process %original file name%.exe:1976 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\22.gif (325300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\7185bdf1gw1f05vpdktqrg20go0a5u10[1].gif (306430 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Browser_V5.5.7852.9_r_4640_(Build1512022057).exe (26349 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\7185bdf1gw1f05vp3ys4ig20s60i07ww[1].gif (1036496 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\21.gif (1101124 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\ZipDLL.dll (3791 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\Base64.dll (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\BaiduPlayer5SetupSilent_363.exe (146246 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433[1].exe (24208 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\Inetc.dll (40 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\V8._85296_20150814221218.exe (41066 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\OK (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1EC.tmp (0 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\BDUnInstall.exe (0 bytes)
%Program Files%\Tencent\QQBrowser\uninst.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\URL Parts Error (0 bytes)

The process xReport.exe:3796 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\baidu\BDPlayer\5.1.1.9\msvcp120.dll (458 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BDPlayer\conf\ReportInfo.dat (190 bytes)

The process xReport.exe:1584 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BDPlayer\conf\ReportInfo.dat (180 bytes)

The process QQBrowser.exe:2524 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Skin\001-Cool Air.gt (252503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Skin\LightStripes.gt (601 bytes)

The process QQBrowser.exe:856 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12\QBSafe.dll (454 bytes)

The process QQBrowser.exe:3396 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\Tencent\QQBrowser\QBSafe.dll (454 bytes)
C:\Windows\Tasks\QQBrowser Udpater Task(Core).job (280 bytes)
C:\Windows\Tasks\QQBrowser Udpater Task.job (276 bytes)

The process QQBrowser.exe:2968 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\update.ini (106 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\cli63E1.tmp.qbl (1098 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\cli5D2C.tmp.qbl (11807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\cli75BD.tmp.qbl (194 bytes)
%Program Files%\Tencent\QQBrowser\QQBrowserFrame.dll (49 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\cli5D2C.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\cli63E1.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\cli75BD.tmp (0 bytes)

The process QQBrowser.exe:2296 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\dr_packet.dat (728 bytes)

The process QQBrowser.exe:1872 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\dr_packet.dat (328 bytes)
%Program Files%\Tencent\QQBrowser\dr.dll (86 bytes)

The process QQBrowser.exe:1452 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\Tencent\QQBrowser\Assistant.dll (430 bytes)

The process QQBrowser.exe:2972 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\Tencent\QQBrowser\QQBrowserConfig.dat (114 bytes)

The process QQBrowser.exe:812 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\dr_packet.dat (424 bytes)

The process QQBrowser.exe:2952 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\repeal.xml (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\O3PNY3RBV9AO0PU2B5L8.temp (3 bytes)

The process BaiduPlayer5SetupSilent_363.exe:2636 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_add_url.xml (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\imglist.setting.checkbox.png (928 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_imageadjust_image.xml (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\rmvb.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.connect.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\yes.png (17 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_imageadjust_color.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\codecs\MpaDec.ax (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\pncrt.dll (287 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\SRT.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\new_version.png (16 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MTS.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\addurl.combobox.btn.dropdown.png (835 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\fileinfo.dll (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.screenshot.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_mouse.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.thumbnail.main.png (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_playlist_online.xml (765 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\color.xml (196 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\msvcp120.dll (455 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\asf.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.menu.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\codecs\RealMediaSplitter.ax (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.stop.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\bk.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.imageadjust.logo.png (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\flv.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\codecs\CoreAAC.ax (328 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_play.xml (918 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_subtitle.xml (281 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.caption.png (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bugreport_BDPlayer.ini (255 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\btn_bk.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.cancel.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.setting.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.playcontroller.channel1.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.main.open.png (15 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\SSA.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.close.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_playlist.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\IntelQuickSyncDecoder.dll (347 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_playcontroller.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.main.menu.png (12 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.hotkey.tab.png (241 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.sys.restore.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.screenshot.thumbnail.line.png (947 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\progress_front.png (18 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\wma.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\string.xml (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.imageadjust.option.select.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MP2V.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_playlist_popbox.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\close.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.help.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mp3.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.feedback.png (5 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.playcontroller.separator.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\3gp.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\imglist.setting.radio.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.imageadjust.channel1.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\vob.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.tools.png (4 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_setting.xml (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.sys.max.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bdcommon.dll (427 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_screenshort.xml (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\ffsrv.exe (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\xReport.exe (171 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_playlist_local.xml (856 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.open.png (5 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\imglist.setting.tree.expand.png (248 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_display.xml (700 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.delete.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\progress_bk.png (18 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.setting.png (7 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\title_bk.png (4 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.nottopmost.png (4 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\scroll.v.playlist.bg.png (144 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\PlayerApp.exe (400 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.fullscreen.close.png (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\font.xml (810 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\font.xml (166 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.playlist.show.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\msvcr120.dll (970 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\addurl.combobox.edit.bg.png (435 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\codecs\real\cook.dll (74 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.fullscreen.open.png (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\codecs\VEFilter.ax (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.logo.line.png (936 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MPEG4.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bdxview.dll (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_screenshot.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\xnet.dll (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\m2ts.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\scroll.setting.thumb.v.png (375 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\onlinevideo_error.png (6 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\edit.setting.border.png (973 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_sound.xml (706 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe (456 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.main.mask.png (174 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bugreport_Tray.ini (255 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.playlist.hide.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\update_line.png (947 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\skin.xml (840 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_file.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.menu.sub.more.png (964 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\WEBM.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\window_expand.png (22 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.player.shadow.png (4 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\avresample-lav-2.dll (161 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\avi.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_playlist_bubble.xml (306 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.main.logo.png (256 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bdlog.dll (39 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.png (973 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\menu_tray.xml (880 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.messagebox.body.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_basic.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.topmost.png (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.imageadjust.channel2.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\window_ask.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico (173 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\xUpdate.exe (999 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\ASS.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.row.play.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\no.png (17 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\ts.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\style.xml (12 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.messagebox.caption.png (4 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.file.png (930 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_main_playwnd.xml (106 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.row.close.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\FFVideo.ax (983 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\FFSplitter.ax (500 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_play.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.row.open.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.thumbnail.highlight.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.logo.png (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\scroll.setting.bg.v.png (931 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MOV.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayerTray.exe (1923 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\codecs\FLVSplitter.ax (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.playlist.png (166 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.play.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\FFAudio.ax (266 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\wmv.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\codecs\AudioSwitcher.ax (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.volume.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\M4V.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MOD.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.menu.item.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_hotkey.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\style.xml (331 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.thumbnail.timebk.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\update_check.png (19 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.row.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\pva.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\f4v.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.separation.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.ok.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\TPS.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\BDWebcore.dll (780 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.player.2.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\imglist.setting.checkbox.partselect.png (412 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.play.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_main.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\avutil-lav-54.dll (431 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.playcontroller.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\tp.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.close.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\progress_front.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.playcontroller.channel2.png (176 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_messagebox.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\avformat-lav-56.dll (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\BDUnInstall.exe (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mpg.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bdxplayer.dll (70 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\menu_playlist.xml (4 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.imageadjust.option.unselect.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.exit.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\M2P.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\effect.xml (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\OnlineVideo.ini (73 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.playlist.caption.png (249 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_tools.xml (516 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.line.png (924 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images.xml (20 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.volume.open.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.main.tools.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\scroll.v.playlist.thumb.png (299 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_file.xml (942 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.main.audio.logo.png (251 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\progress_bk.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\codecs\VSFilter.dll (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mpeg.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.thumbnail.arrow.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\avcodec-lav-56.dll (780 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\SWF.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.sys.min.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.about.png (29 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\menu_main.xml (10 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.2.png (955 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\DIVX.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.imageadjust.thumb.png (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_update.xml (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\xmanager.dll (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.messagebox.close.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\bpc.ico (15 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\menu_player.xml (8 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_subtitle.xml (719 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_about.xml (825 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\codecs\real\drvc.dll (275 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.player.png (161 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_image_adjust.xml (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\swscale-lav-3.dll (481 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.screen.thumbnail.picbk.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.tab.png (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mkv.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\rm.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\skin.xml (17 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\bsed.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\filters.xml (11 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_main_mask.xml (2 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_thumbnail.xml (536 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bdxlogic.dll (158 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.pause.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bugreport.exe (189 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.imageadjust.reset.png (3 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.messagebox.line.png (947 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.playcontroller.thumb.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.select.png (268 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.sys.close.png (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\avfilter-lav-5.dll (189 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mp4.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\DAT.ico (26 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\latest_version.png (15 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\OpenMediaUrl.exe (1 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\bk.png (9 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bugreport_Update.ini (255 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\libbluray.dll (254 bytes)

The process xUpdate.exe:1668 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BDPlayer\update\BDPlayer5.6.2.16_145.exe.bdtp (1014852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BindTaskSys\SysData\XTask.db (395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BindTaskSys\SysData\XTask.db-journal (15428 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Baidu\BCommon\XDownlaodConfig.ini (1191 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BDPlayer\update\BDPlayer5.6.2.16_145.exe.bdre (4312 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BindTaskSys\SysData\XTask.db-journal (0 bytes)

The process regsvr32.exe:4028 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\Tencent\QQBrowser\WebpDecodeFilter.dll (139 bytes)
%Program Files%\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcr90.dll (655 bytes)

The process PlayerApp.exe:2496 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\百度影音5\卸载百度影音5.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\百度影音5.lnk (4 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\百度影音5\百度影音5.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\Desktop\百度影音5.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BDPlayer\conf\TaskBar\百度影音5.lnk (2 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar (0 bytes)

The process BDPlayerTray.exe:3432 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\baidu\BDPlayer\5.1.1.9\msvcr120.dll (974 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bdcommon.dll (430 bytes)
%Program Files%\baidu\BDPlayer\5.1.1.9\bdlog.dll (40 bytes)

Registry activity

The process Browser_V5.5.7852.9_r_4640_(Build1512022057).exe:3236 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Tracing\Browser_V5_RASAPI32]
"EnableConsoleTracing" = "0"
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Tracing\Browser_V5_RASMANCS]
"MaxFileSize" = "1048576"
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\Browser_V5_RASAPI32]
"MaxFileSize" = "1048576"

[HKLM\SOFTWARE\Microsoft\Tracing\Browser_V5_RASMANCS]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\Browser_V5_RASAPI32]
"FileTracingMask" = "4294901760"
"EnableFileTracing" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\Browser_V5_RASMANCS]
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 44 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Tracing\Browser_V5_RASMANCS]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\Browser_V5_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\Browser_V5_RASMANCS]
"FileTracingMask" = "4294901760"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process stats_uploader.exe:3056 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Tracing\stats_uploader_RASMANCS]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\stats_uploader_RASAPI32]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\stats_uploader_RASMANCS]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\stats_uploader_RASAPI32]
"EnableConsoleTracing" = "0"
"ConsoleTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Tracing\stats_uploader_RASMANCS]
"MaxFileSize" = "1048576"

[HKLM\SOFTWARE\Microsoft\Tracing\stats_uploader_RASAPI32]
"MaxFileSize" = "1048576"
"FileTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 46 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Tracing\stats_uploader_RASMANCS]
"FileTracingMask" = "4294901760"
"ConsoleTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process V8._85296_20150814221218.exe:1980 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\SignatureList]
"accountInfoBar.html" = "AY9EPX/xn4 koiwdV53GGkKRrHlPe7dM7IW095EVLW9EcDFnd3D265K4Q97AvSL1mXyed eU6run704RFnvWsteF2Kz1i2/PqgFmx2uHgcq/eNCgvSwJWAh8fOxdtupX4PCMNt5bTfniQeDl1nzt VR9bLAfthB2NSQNbTssemk="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\manage\js]
"global.js" = "F1x bElWW0KAVW8dze0Mbr/Dm6CoJGRHw9Hyx1RReWDG/gXkjcQdXk a46Axg2sDjSzwOpra92NNO7ANhXE2f070FE9R4JQlb/7EiMo34Yuv2ik9RgJGDod4aT/h9hBhC2S9yWne0JH7Nr/mbFU8Mb88RrN0Q7POMH3VHicGxxo="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\quickaccess\js]
"api.js" = "KdzpiPPafc//mqIv/5 XJLoPFho3ixPxjdBXo7fUMneJIFwT70jZTYldVYFnNHeL75MbZIrnRbIYTfxe7Pn8oDaTs4SCaf6q8dQXmJ9ssO80MuxeP0ndCXW5IOoqPZoJ3wyDTzNrqihWlm/ ozzmC6tlQNwpaledwco9hHv3Kac="

[HKCU\Software\Tencent\QQBrowser\Launch]
"SkinUpdateFlag" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2]
"FavoritesChanges" = "1"

[HKLM\SOFTWARE\Tencent\QQBrowser]
"INSTLANG" = "1033"

[HKCU\Software\Tencent\QQBrowser\Common]
"MainPageDIY_" = "30391306"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25]
"Operational" = "1"
"ManifestVersion" = "2"

[HKLM\SOFTWARE\Tencent\QQBrowser]
"s2" = "4"
"s1" = "4"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}]
"CommandOrder" = "1"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\lib]
"ycalendar.js" = "Ib0wShmBpOPdR6WIXozuGPAYmfhw HqOZEc9lU wePCCZVQ6YfBPhdNrdduMjhS5hB3SnrGR577LroR1Y2Rv4mlpMvc090e40OzXs/knSRxzb3rCvfZPwpa/HlTAtP47aP6I75ecIT0dIl/vPovsR1gjWfVFjfvcmILiHbwDA4="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25]
"Name" = "内页面"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\quickaccess\js]
"search.js" = "IOSc1vtqyq1U7w6ERKIDsLRpv4mCbXTIw/HKw13cRHxcexU7Lrlv64EHual89dNwbkQbQh5Vc4vQlubP2vKuq9yzILTIElywHb4C6Uf6xd26zYypsUK1RjKoffD8wVvBW9Vlj37VbAXxhI8K4Q8ZZk00jCUKlBc9Gh3bbxdA0Gs="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\manage\js]
"init.js" = "PFyqkS14Ezzwwz3NzSYKgQGIhRXUTnt6ktpq OCUoyT9x96JDR5tWlyWvGn/S8QtChKnWJ4ieyeVWXLQUrQGG5lEDl33J3dmOavy3OUOcvX8XpPA3BcX5XgT1VHlb3zNVVQaT0TPyzBF3SD2OEBbSxfyUQgtDaSBe0RsaU7Xnb0="

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\BackgroundPage]
"LoadingTime" = "LoadAsInited"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\quickaccess\js]
"global.js" = "SeN/CHriBIVnAjdwU6fW8AHF Y5sYGuTkrIwtRsftkTb2xJMtrUsGn1IuvZYyuHQDvkeFojs9MobGSEuJ Cj1S94nQrvzQbV8hd2sS2j27SmIQHTJjaC478N4KYEvvLFu84D1tWaEUfLCXZkhjwTcNPsC45ORTPKG6hzgqeccMM="

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\ContentScripts\DocumentIdle_0]
"AllFrames" = "1"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12]
"Version" = "8.0.0.12"

[HKCU\Software\Tencent\QQBrowser\extensions8]
"CommandOrder" = "1"

[HKCU\Software\Tencent\QQBrowser\PrivateCfg]
"EnableZombieReport" = "1"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\SignatureList]
"content.js" = "HT1aXFiSWWlckk7HXoJkwioM1SSPnbDaXAKb3oOmdxHYpJDFZoUmdiVxYpDM4q3nhXWNdlgFJwH88gmJBpR EYUVMlJRLk6nW0WTWFpoKuGv5 bv3Fafms133G5ygK61lv0xigm9vitf72LDM0wpESsg8yMdDmk1uvrCbYE3Swg="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25]
"Operational" = "1"

[HKCU\Software\Tencent\QQBrowser\InstallInfo]
"NewInstall" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QQBrowser]
"URLInfoAbout" = "http://www.qq.com"

[HKCU\Software\Tencent\QQBrowser\Advanced]
"EnableUEData" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2]
"Favorites" = "00 0A 01 00 00 14 00 1F 80 C8 27 34 1F 10 5C 10"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\manage\js]
"business.js" = "IuxI4T0J7Bik5qY6/aqfPYonejaosMlt7RKPN2HAI58nqalyzaR3NKDmDMBsP/GLsP/n4EEmigqfaXfhw1XVPuoKRupEmWoBrFcuX0YxFI/tTm8jQjjGQnoyTA0sowMVrFwfL ATf0Id2A3Ld1g7RvjnRX1DRtsnCMsCqrERJjk="

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\BackgroundPage]
"Path" = "background.html"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12\BackgroundDll]
"LoadingTime" = "LoadAsInited"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25]
"ManifestVersion" = "2"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}]
"CommandOrder" = "2"

[HKCU\Software\Tencent\QQBrowser\Launch]
"AbpCalcFlag" = "1"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25]
"RequiredMinVersion" = "8.0.0.2261"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\lib]
"jquery.easing.js" = "TmbGZQQC93Sgo2FdztxQ0d9XKSQvW71Fi7BWXGb3/Y FVjxcrUPmKaPobqD7KbZMw7CHfrtxoraOME53bkqu7WtNB48Toe29QgontHYDQgrkR9tTzIz8ByGm187nfwmjMQ/pazCml7IhkVNcTRuiUBILtPyb5I8Dg6vKCCa8fcU="

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\SignatureList]
"background.js" = "F9mIz66B1YB2KiWHfg8OtENAgX96C/1LO0KjQQHIR31aEaHLE5tPl fwJZigG8Q6ZhhcxmJ3KXTQWzo63lWn8vSkbn4pdwgVMT2Or3vBeRoD97hKndLnvyZ4QoTWvOskDzcBA5mzrDV9Yp5x1R/Z5lNfFH3FL0d1CPq TAfTet4="

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12]
"Operational" = "1"

[HKCU\Software\Tencent\QQBrowser\Common]
"MainPageDIY" = "ZgAuAGoAaQBzAHMAMwA2ADAALgBjAG4AAAAaAAAA"

[HKCU\Software\Tencent\QQBrowser\InstallInfo]
"InstallModeForExtension" = "1"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25]
"STYLE" = "104"

[HKLM\SOFTWARE\Tencent\QQBrowser]
"InstallDir" = "%Program Files%\Tencent\QQBrowser"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25]
"STYLE" = "64"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\ContentScripts\DocumentIdle_0]
"JS" = "content.js"

[HKCU\Software\Tencent\QQBrowser\InstallInfo]
"DefaultBrowserFirstRun" = "0"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}]
"currentVersion" = "8.0.3.25"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12]
"ManifestVersion" = "2"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\manage]
"index.html" = "Uy0EzM9E6A oW0Z32PTfsdnTQKM8SYLC8Svtt17Rtqz fslfu4Rf0azo0648ksrzDNSmiBlKk0iB2FCsYtC5RZOxmCgxpG0rk16BRJ1Gpf8hQmkpWSTzx2IR MAZgb7CqIwwhGHPzE3qF1k4bVaBita wVueecTJfn4gHFZ1bLg="

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}]
"currentVersion" = "8.0.0.25"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25]
"Name" = "账号助手"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesChanges" = "10"

[HKLM\SOFTWARE\Tencent\QQBrowser]
"EXE" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant]
"ExecutablesToExclude" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\SignatureList]
"background.html" = "Fm2eUg6wC00HcJHVm5J5S9WbzmEVSNFdyD8in0PXbYIUFYHWK zhaV9u182EDyOlZuGJx5fLb0VPFyexkuUSnj4ULw1KjUvqMjtjvPcMlgxIOsZ2m2jqwbJsRGPbXSLKCMKqq uFRju5vweuSqBckjVRLe4ndm/ewMWuI7GJUkQ="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html]
"certerror.html" = "Quu5ifaZbhsH6hfNNjsEbMi71iGFPa 7qoPsbDB85tzNJhbuwap kINuU5JVUFuy7ab/H63S1Y9kCw eo6zOs2bZvrgxEv8DGHhKa832zqs6fjzTX BFb6/uP1kQr9kAIzY jkBspKr9vZIFKnmKfjTFFlvSX3lQxR9BTuyhiN8="

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesResolve" = "CC 02 00 00 4C 00 00 00 01 14 02 00 00 00 00 00"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}]
"CommandOrder" = "0"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25]
"ID" = "{807849B3-40D8-42E3-8001-D541FD7CEBFB}"

[HKCU\Software\Tencent\QQBrowser]
"HomePageCfg" = "1"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\manage\history]
"history2.js" = "EYdPibxwSOsOqWp65 q m9YPkG2qiUUGpCPnvRau01UVBjkeEsX12Uy5TmZV0QiqFodnvBKS8uPPdSDAtWYh46mlNAugPtYfiEf7rdH5i9IKkjarXT3vqrc8m dOB2sBwi35rGtSx5Q mNco60nlRGZ/4BbXHVO9e4liF3omtHU="

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25]
"RequiredMinVersion" = "8.0.0.0"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12\BackgroundDll]
"Path" = "QBSafe.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QQBrowser]
"UninstallString" = "%Program Files%\Tencent\QQBrowser\uninst.exe"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25]
"Desc" = "账号助手"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\quickaccess]
"index.html" = "DG53S6RFyw43Ype9xROtxTn4z5b3SsHMzH8/wVLXZciV6q4kwtV3RzjBgYe7MiTfATyKVDf5DqI/mqQCIpYrr1JN6EXZR81dwwgj70KhNn/9WcjMdpBvKxRLCjl82LcKMlx91xsdg6Dt6Oy2gDhDopfRX1ThZ2OFvfdSyp4OHQo="

[HKCU\Software\Tencent\QQBrowser\Launch]
"InstallQuickSetting" = "0"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12]
"Desc" = "QBSafe"

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted\C:\Users\"%CurrentUserName%"\AppData\Local\Temp]
"V8._85296_20150814221218.exe" = "1"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}]
"currentVersion" = "8.0.0.12"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QQBrowser]
"Publisher" = "腾讯科技(深圳)有限公司"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12]
"ID" = "{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}"

[HKLM\SOFTWARE\Tencent\QQBrowser]
"Version" = "8.2.3638.400"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12]
"STYLE" = "80"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\manage\js]
"api.js" = "CTLNX2nY1O7mQDlrx81saZ A/b3cld1PV1aWjfRWB9Uk7nMqUgRWUwgVmyvWg9gkM0yW1MsoF6XNwlLBdc8okJ8kImN9HQxCfo4NuKEahbCA1RnudXB pCuvw3EEMiY ORP/YDMicZcSXjtSnvP3UDhaX THBQVVts I5sLdd5g="
"tool.js" = "K4IAXHGyqD8uA sLEGlFibFQFep8I HkPC6DghtA9hoTdT1tLMSTsbcae2i84ApCOoZfk1C2pUFZKm zTVVUv9o4P9Oozg9nnWh57vtG7ZXh3mv8qIRGwwANrzOQ rITxZOxWcTUTD8qZm E8LlIN0BrJJKq4Pp9GeSDBv4bMoc="

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25]
"Version" = "8.0.0.25"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\quickaccess\js]
"init.js" = "HS Wucfrv 6MUQNZq0WGl6Yw8Ly2dg hvt5V24pB0sowDcogYJpVFP7lyYpqkEWURP1N0mBL8t qCq70Zi/U/E2y7YbqDiQlmwkkHeUSHMVnfCk5anb9ybtcI//8CWC67XXLFO0oRjvc9PsAQHdcDriLEMx3DzYDxb ZLFaswiU="

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12]
"RequiredMinVersion" = "8.1.0.0"

[HKCU\Software\Tencent\QQBrowser\Launch]
"Learned" = "1"

[HKCU\Software\Tencent\QQBrowser]
"(Default)" = "%Program Files%\Tencent\QQBrowser"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25]
"Version" = "8.0.3.25"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25]
"ID" = "{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}"

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\SignatureList\js]
"inforBar.js" = "S232TIJBgUGMXlTdOQRla7UFcRwmODl7HS6sTy2LB9xtBKNjcUUfpZCPrXF11mEjmXkG04wEItvpPgr70sOc1/mxQ92eYR7k/8G5ajwkGW/ IBjUUsSE0sTzHIxwQExAFa8newkyrRqF jHkN1n4BZKdzwbw f0TqwXpiJUe/z0="

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2]
"FavoritesVersion" = "2"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\lib]
"jquery.min.js" = "CHRzStLFVzowFpds/NlgIauwssen3//6We9cKfzF4H4Vd0hTu rRxAgWBSZOvL3qB MA5m1oDYbyEFquZhoip7CWckTQo6 S dUFfDJATgzAhGnGQPvY1xAeDuKT9mHvkWXV8QiJu5ZgSSuggmwXioU5HomYw1dNanbdvDS7rss="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html]
"error.html" = "Gs5We3VMGdtvsJGT6u6MMVvDt3zSWVVCEh8CKo8BudWeZgocGRxZCxnUzIBcEspzCp9h2OFGwf4FTuDYG9Mf1MROlJx1oTz9uXnHk/JNRuCTn/dHBXBTqu6XR1tj6OqL7gKQ3svK/Mexy4lBO/PSgypdugTHFgugTpMadvZRDAE="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\lib]
"jquery.mCustomScrollbar.concat.min.js" = "FEhORzx0GxacyZAVElwZHrgrANsncYw61M/NU 0QHFBgGjRJpqYWNkmYr RKq2WX0f/FJok0GTgzs8/6dhyMZytR PdWyBo75CPRNtP9mOif95Zo4easLJYCBcI5g2c0D5pRYPoiHsPikFHkAJqRvrN6hSayUrzNSKTswWIuyb0="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\manage\app]
"app.js" = "G/xQAG9BNoueIWTF1B/FXI65sQFTqDtYNE0FVw5XsDx85Ijs IGfdoTBG7Py NEEoLHisu1f8t1F3PxhFNk DpdtGLy8bva44n6ej3FvOKk8n0KXPpT5IyCV8qs3EkNZaXZdk9rqBhdZQUdUDJDVnJ0iRs1nyTryHc9C8yzksaM="

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"Favorites" = "00 7C 01 00 00 14 00 1F 80 C8 27 34 1F 10 5C 10"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\manage\app]
"sliderman.1.3.7.js" = "RkIvek G9RI Q9/NEOdxEh/ynLS5sJRj/vlO2PrWACyN8sI9vf695W/3CP d/Jr59MnJV2sK2YzNz6txbNvhpSI6S3MTO8Z3UJIBleKth0bLzeGpI4dTaAsMMam3QXyux3g7jkzADCCb5iHY8RLV c6W8sEprWrpGZNIRzFvOcs="

[HKLM\SOFTWARE\Tencent\QQBrowser]
"SupplyID" = "85296"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QQBrowser]
"DisplayVersion" = "8.2.3638.400"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesVersion" = "2"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\lib]
"template.js" = "RzgJqwNHJ4N8sJDEKasrvKhYoIjrKXGKh3qo6y3p7Bx3eQjIDn1gNlluXXutWcLSBX23i7mSbXxa6km5He 5qAf5eFTYPlcyzJ1efN6K7LGNsOYTGrjFWBGg57GhUneVMDCg1l8ncB214UhBIQPO6KZ2/tvVX4d0a6nCIXqOTdc="

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html]
"private.html" = "K xv/ifPeX60jeD65vv gUoqtdQCKyrPu3G9CV9ZgkzifnKYT2HlMs77KUqIBos6Ta5uCGG4ausc030WTKPfMuL9EjmW7FoJZIZgTcWa mx0 gaAmsoMZHsvq/IVS6SDzsQ/mOiHy60uAr1RKyo62yEJn9wW8JYFqpfIUaAznfU="

[HKCU\Software\Tencent\QQBrowser\extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25]
"HomeUrl" = "http://app.browser.qq.com?id={309147A1-5CA9-4082-BAB3-BF9020CDE0C2}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2]
"FavoritesResolve" = "28 03 00 00 4C 00 00 00 01 14 02 00 00 00 00 00"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html]
"small.html" = "WhbKXbpTC/qXxBxGyDkPJ/ZidAPRqwpAIJ8PLBPltgCg1UOLWJ0KKlk30VAlBy8LToz1KY9tESfeyRr1Qj0S8uwj1uskS7BS Nv9rCDKYGKMcDtyfGr2PeKzp2Zm5lch76FJqhupbdr96BGzQfyKYi 6 F3Ih/Slsdzs3XdO9Ik="

[HKCU\Software\Tencent\QQBrowser\Launch]
"MainPageType" = "2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QQBrowser]
"DisplayName" = "QQ浏览器8.2"

[HKCU\Software\Tencent\QQBrowser\extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\SignatureList\Html\quickaccess\js]
"business.js" = "WwyVRnDKaHIVi7OS82cBQkBlZMsrWmAnPcwnoCg2R4t8EtSPDXSP0xhBttAipCfJaV6zLzkC21QRx1LrESQKdh3KvGzvw9O2dHm9Xj Ugulv8wtWsfMDS FQyAGC z0jMV4dBQooJplN1ncZteRXwjISn0jBdDc3CUac1LbU3CI="

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QQBrowser]
"DisplayIcon" = "%Program Files%\Tencent\QQBrowser\app.ico"

[HKCU\Software\Tencent\QQBrowser\PrivateCfg]
"TC_CFT_Bits3" = "71656520"

[HKCU\Software\Tencent\QQBrowser\extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12]
"Name" = "QBSafe"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Tencent\QQBrowser]
"S2"
"S1"

[HKCU\Software\Tencent\QQBrowser\Launch]
"EnableUEData"

The process %original file name%.exe:1976 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Tracing\0ffa45bbb070fd21152782e8a39335e3_RASMANCS]
"EnableConsoleTracing" = "0"
"FileTracingMask" = "4294901760"
"MaxFileSize" = "1048576"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\0ffa45bbb070fd21152782e8a39335e3_RASMANCS]
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Tracing\0ffa45bbb070fd21152782e8a39335e3_RASAPI32]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\0ffa45bbb070fd21152782e8a39335e3_RASMANCS]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\0ffa45bbb070fd21152782e8a39335e3_RASAPI32]
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Tracing\0ffa45bbb070fd21152782e8a39335e3_RASMANCS]
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\0ffa45bbb070fd21152782e8a39335e3_RASAPI32]
"FileTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3E 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Tracing\0ffa45bbb070fd21152782e8a39335e3_RASAPI32]
"EnableConsoleTracing" = "0"
"ConsoleTracingMask" = "4294901760"

"MaxFileSize" = "1048576"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process QQBrowser.exe:856 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 41 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
"AutoDetect" = "1"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process QQBrowser.exe:1804 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Tencent\QQBrowser\Launch]
"LaunchOpenPageType" = "1"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

The process QQBrowser.exe:3396 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

The process QQBrowser.exe:2968 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Tracing\QQBrowser_RASMANCS]
"ConsoleTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Tracing\QQBrowser_RASAPI32]
"MaxFileSize" = "1048576"
"FileTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\QQBrowser_RASMANCS]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\QQBrowser_RASAPI32]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\QQBrowser_RASMANCS]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\QQBrowser_RASAPI32]
"FileDirectory" = "%windir%\tracing"

"EnableConsoleTracing" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\QQBrowser_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3F 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Tracing\QQBrowser_RASMANCS]
"MaxFileSize" = "1048576"
"FileTracingMask" = "4294901760"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process QQBrowser.exe:2296 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 42 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
"AutoDetect" = "1"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process QQBrowser.exe:1872 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 40 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
"AutoDetect" = "1"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process QQBrowser.exe:1452 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\QQBrowser.Protocol]
"(Default)" = "QQBrowser Protocol"

[HKCR\Tencent.QQBrowser.Default\.exe\shell\open\command]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe %*"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQBrowser.exe]
"DisableExceptionChainValidation" = "0"

[HKCR\QQBrowser.File\DefaultIcon]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe,0"

[HKCR\QQBrowser.Protocol\shell\open\command]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe -- %1"

[HKCR\QQBrowser.File\shell\open\command]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe -- %1"

[HKLM\System\CurrentControlSet\Control\WMI\Security]
"a083b31f-8832-4593-97ce-95c482533167" = "01 00 04 80 14 00 00 00 24 00 00 00 00 00 00 00"

[HKCR\Tencent.QQBrowser.Default\.exe\shell]
"(Default)" = "open"

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities\FileAssociations]
".xhtml" = "QQBrowser.File"

[HKLM\System\CurrentControlSet\Control\WMI\Security]
"4ba0b957-882b-4625-a213-0349b865e6aa" = "01 00 04 80 14 00 00 00 24 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities\URLAssociations]
"http" = "QQBrowser.Protocol"

[HKLM\SOFTWARE\RegisteredApplications]
"QQBrowser" = "Software\Tencent\QQBrowser\Capabilities"

[HKCU\Software\Tencent\QQBrowser\InstallInfo]
"FirstLaunch" = "1"

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities\FileAssociations]
".xht" = "QQBrowser.File"

[HKCR\QQBrowser.Protocol\shell]
"(Default)" = "open"

[HKLM\System\CurrentControlSet\Control\WMI\Security]
"5abb9909-bb1c-4766-94a2-dc34220d0391" = "01 00 04 80 14 00 00 00 24 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Tencent\QQBrowser\CurrentVersion\App Paths\QQBrowser.exe]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe"

[HKCR\QQBrowser.Protocol\DefaultIcon]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe,0"

[HKCR\QQBrowser.File]
"URL Protocol" = ""

[HKCR\QQBrowser.File\shell]
"(Default)" = "open"

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities\FileAssociations]
".mht" = "QQBrowser.File"
".mhtml" = "QQBrowser.File"

[HKCR\Tencent.QQBrowser.Default\.exe\shell\run\command]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe %*"

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities\FileAssociations]
".shtml" = "QQBrowser.File"

[HKCR\QQBrowser.File]
"AppUserModelID" = "Tencent.QQBrowser.Default"

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities\URLAssociations]
"ftp" = "QQBrowser.Protocol"

[HKCR\QQBrowser.Protocol]
"URL Protocol" = ""

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities\FileAssociations]
".htm" = "QQBrowser.File"

[HKCR\QQBrowser.Protocol]
"AppUserModelID" = "Tencent.QQBrowser.Default"

[HKCU\Software\Tencent\QQBrowser\InstallInfo]
"DefaultBrower" = "%Program Files%\Internet Explorer\iexplore.exe"

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities\FileAssociations]
".html" = "QQBrowser.File"

[HKCR\QQBrowser.File]
"(Default)" = "QQBrowser HTML Document"

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities\URLAssociations]
"https" = "QQBrowser.Protocol"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QQBrowser.exe]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser"

[HKLM\System\CurrentControlSet\Control\WMI\Security]
"fe298bd4-04d8-4bf8-9422-77d6b66b255f" = "01 00 04 80 14 00 00 00 24 00 00 00 00 00 00 00"

[HKCU\Software\Tencent\QQBrowser\http\shell\open\command]
"(Default)" = "%Program Files%\Google\Chrome\Application\chrome.exe -- %1"

[HKLM\System\CurrentControlSet\Control\WMI\Security]
"deafbc7e-fb81-4499-a39f-e8e7ec2b3ad1" = "01 00 04 80 14 00 00 00 24 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Tencent\QQBrowser\Capabilities]
"ApplicationName" = "QQBrowser"
"ApplicationDescription" = "QQBrowser"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Tencent\QQBrowser\PrivateCfg]
"DisablePtLogin_740"

[HKLM\SOFTWARE\RegisteredApplications]
"QQBrowser"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQBrowser.exe]
"GlobalFlag"
"VerifierFlags"
"PageHeapFlags"

[HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]
"QQBrowser.exe"

The process QQBrowser.exe:2972 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice]
"Progid" = "QQBrowser.Protocol"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Classes\.html]
"(Default)" = "QQBrowser.File"

[HKCU\Software\Classes\ftp\DefaultIcon]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe,0"

[HKCU\Software\Classes\https\shell]
"(Default)" = "open"

[HKCU\Software\Classes\.shtml]
"(Default)" = "QQBrowser.File"

[HKCU\Software\Classes\ftp\shell]
"(Default)" = "open"

[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice]
"Progid" = "QQBrowser.Protocol"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice]
"Progid" = "QQBrowser.Protocol"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
"Progid" = "QQBrowser.File"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
"Progid" = "QQBrowser.File"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
"Progid" = "QQBrowser.File"

[HKCU\Software\Classes\http\DefaultIcon]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe,0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer]
"GlobalAssocChangedCounter" = "204"

[HKCU\Software\Classes\ftp\shell\open\command]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe -- %1"

[HKCU\Software\Classes\.xhtml]
"(Default)" = "QQBrowser.File"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\.xht]
"(Default)" = "QQBrowser.File"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
"Progid" = "QQBrowser.File"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
"Progid" = "QQBrowser.File"

[HKCU\Software\Classes\.htm]
"(Default)" = "QQBrowser.File"

[HKCU\Software\Classes\https\DefaultIcon]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe,0"

[HKCU\Software\Classes\https\shell\open\command]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe -- %1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
"Progid" = "QQBrowser.File"

[HKCU\Software\Classes\http\shell\open\command]
"(Default)" = "%Program Files%\Tencent\QQBrowser\QQBrowser.exe -- %1"

[HKCU\Software\Classes\http\shell]
"(Default)" = "open"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
"Progid" = "QQBrowser.File"

The Trojan deletes the following registry key(s):

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process QQBrowser.exe:812 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 43 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
"AutoDetect" = "1"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process QQBrowser.exe:3052 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

The process BaiduPlayer5SetupSilent_363.exe:2636 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\BAIDU\BDPlayer\InstallPath]
"Version" = "5.1.1.9"
"InstallTime" = "2017-05-16 12:33:27"

[HKCU\Software\Microsoft\Direct3D\MostRecentApplication]
"Name" = "BaiduPlayer5SetupSilent_363.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BDPlayer]
"HelpLink" = "http://www.baidu.com"
"DisplayName" = "百度影音5"

[HKLM\SOFTWARE\BAIDU\BDPlayer]
"ChannelID" = "363"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BDPlayer]
"UninstallString" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDUninstall.exe"

[HKLM\SOFTWARE\BAIDU\BDPlayer]
"FirstInstallTime" = "2017-05-16 12:33:27"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BDPlayer]
"DisplayVersion" = "5.1.1.9"
"Publisher" = "百度在线网络技术(北京)有限公司"
"DisplayIcon" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe"

[HKLM\SOFTWARE\BAIDU\BDPlayer\InstallPath]
"Path" = "%Program Files%\baidu\BDPlayer\5.1.1.9"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BDPlayer]
"URLUpdateInfo" = "http://www.baidu.com"
"URLInfoAbout" = "http://www.baidu.com"

The process netsh.exe:2224 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

The process netsh.exe:1732 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-103" = "Microsoft Corporation"
"eapqec.dll,-102" = "1.0"
"tsgqec.dll,-101" = "Provides RD Gateway enforcement for NAP"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E\@%SystemRoot%\system32]
"tsgqec.dll,-103" = "Microsoft Corporation"
"tsgqec.dll,-100" = "RD Gateway Quarantine Enforcement Client"
"napipsec.dll,-2" = "Provides IPsec based enforcement for Network Access Protection"
"napipsec.dll,-3" = "Microsoft Corporation"
"napipsec.dll,-1" = "IPsec Relying Party"
"napipsec.dll,-4" = "1.0"
"tsgqec.dll,-102" = "1.0"
"dhcpqec.dll,-103" = "1.0"
"dhcpqec.dll,-102" = "Microsoft Corporation"
"dhcpqec.dll,-101" = "Provides DHCP based enforcement for NAP"
"dhcpqec.dll,-100" = "DHCP Quarantine Enforcement Client"

The process xUpdate.exe:1668 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Tracing\xUpdate_RASMANCS]
"EnableConsoleTracing" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\xUpdate_RASMANCS]
"MaxFileSize" = "1048576"
"ConsoleTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"
"FileTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\xUpdate_RASAPI32]
"EnableFileTracing" = "0"
"EnableConsoleTracing" = "0"
"FileTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 45 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Tracing\xUpdate_RASAPI32]
"MaxFileSize" = "1048576"
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\xUpdate_RASMANCS]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\xUpdate_RASAPI32]
"FileDirectory" = "%windir%\tracing"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process PerfTraceService.exe:2220 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\PerfTraceService]
"TypesSupported" = "7"
"EventMessageFile" = "%Program Files%\Tencent\QQBrowsÆ­"

The process regsvr32.exe:4028 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\Interface\{E577DC7C-F3A8-4A79-A2B0-8E0A79FFA45B}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCU\Software\Tencent\QQBrowser\IE8\MIME\Database\Content Type\image/webp\bits]
"0" = "04 00 00 00 FF FF FF FF 52 49 46 46"

[HKCR\TypeLib\{5FD70451-714E-495A-9F17-450AEF3AA35E}\1.0\HELPDIR]
"(Default)" = "%Program Files%\Tencent\QQBrowser"

[HKCR\WEBPFilter.CoWEBPFilter]
"(Default)" = "WEBPFilter CoWEBPFilter"

[HKCR\WEBPFilter.CoWEBPFilter\CurVer]
"(Default)" = "WEBPFilter CoWEBPFilter.1"

[HKCR\WEBPFilter.CoWEBPFilter.1\CLSID]
"(Default)" = "{A981255C-6123-4487-B21A-9CF468EB3FC7}"

[HKCU\Software\Tencent\QQBrowser\IE8\MIME\Database\Content Type\image/webp]
"Image Filter CLSID" = "{A981255C-6123-4487-B21A-9CF468EB3FC7}"

[HKCR\MIME\Database\Content Type\image/webp]
"CLSID" = "{25336920-03F9-11cf-8FD0-00AA00686F13}"

[HKCR\AppID\WebpDecodeFilter.DLL]
"AppID" = "{A629F59C-66C9-4775-901A-A017530E3958}"

[HKCR\.webp]
"Content Type" = "image/webp"

[HKCR\WebpDecodeFilter.WebpImageDecodeFilt.1\CLSID]
"(Default)" = "{A981255C-6123-4487-B21A-9CF468EB3FC7}"

[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}\ProgID]
"(Default)" = "WEBPFilter.CoWEBPFilter.1"

[HKCR\WEBPFilter.CoWEBPFilter.1]
"(Default)" = "WEBPFilter CoWEBPFilter"

[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}]
"(Default)" = "WEBPFilter.CoWEBPFilter"

[HKCR\MIME\Database\Content Type\image/webp]
"Image Filter CLSID" = "{A981255C-6123-4487-B21A-9CF468EB3FC7}"

[HKCR\WebpDecodeFilter.WebpImageDecodeFilt.1]
"(Default)" = "WebpImageDecodeFilter Class"

[HKCR\Interface\{E577DC7C-F3A8-4A79-A2B0-8E0A79FFA45B}]
"(Default)" = "IWebpImageDecodeFilter"

[HKCR\WebpDecodeFilter.WebpImageDecodeFilter]
"(Default)" = "WebpImageDecodeFilter Class"

[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}\VersionIndependentProgID]
"(Default)" = "WEBPFilter.CoWEBPFilter"

[HKCR\Interface\{E577DC7C-F3A8-4A79-A2B0-8E0A79FFA45B}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}]
"AppID" = "{A629F59C-66C9-4775-901A-A017530E3958}"

[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}\TypeLib]
"(Default)" = "{A981255C-6123-4487-B21A-9CF468EB3FC7}"

[HKCR\.webp]
"PerceivedType" = "image"

[HKCR\MIME\Database\Content Type\image/webp\bits]
"0" = "04 00 00 00 FF FF FF FF 52 49 46 46"

[HKCR\TypeLib\{5FD70451-714E-495A-9F17-450AEF3AA35E}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{E577DC7C-F3A8-4A79-A2B0-8E0A79FFA45B}\TypeLib]
"(Default)" = "{5FD70451-714E-495A-9F17-450AEF3AA35E}"

[HKCU\Software\Tencent\QQBrowser\IE8\MIME\Database\Content Type\image/webp]
"CLSID" = "{25336920-03F9-11cf-8FD0-00AA00686F13}"

[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}\InprocServer32]
"(Default)" = "%Program Files%\Tencent\QQBrowser\WebpDecodeFilter.dll"

[HKCR\Interface\{E577DC7C-F3A8-4A79-A2B0-8E0A79FFA45B}\TypeLib]
"Version" = "1.0"

[HKCR\AppID\{A629F59C-66C9-4775-901A-A017530E3958}]
"(Default)" = "WebpDecodeFilter"

[HKCR\WEBPFilter.CoWEBPFilter\CLSID]
"(Default)" = "{E577DC7C-F3A8-4A79-A2B0-8E0A79FFA45B}"

[HKCR\WebpDecodeFilter.WebpImageDecodeFilter\CLSID]
"(Default)" = "{A981255C-6123-4487-B21A-9CF468EB3FC7}"

[HKCR\WebpDecodeFilter.WebpImageDecodeFilter\CurVer]
"(Default)" = "WebpDecodeFilter.WebpImageDecodeFilt.1"

[HKCR\TypeLib\{5FD70451-714E-495A-9F17-450AEF3AA35E}\1.0\0\win32]
"(Default)" = "%Program Files%\Tencent\QQBrowser\WebpDecodeFilter.dll"

[HKCU\Software\Tencent\QQBrowser\IE8\MIME\Database\Content Type\image/webp]
"Extension" = ".webp"

[HKCR\MIME\Database\Content Type\image/webp]
"Extension" = ".webp"

[HKCR\TypeLib\{5FD70451-714E-495A-9F17-450AEF3AA35E}\1.0]
"(Default)" = "webpdecodefilter 1.0 Type Library"

The Trojan deletes the following registry key(s):

[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}\TypeLib]
[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}]
[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}\InprocServer32]
[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}\VersionIndependentProgID]
[HKCR\CLSID\{A981255C-6123-4487-B21A-9CF468EB3FC7}\ProgID]

The process PlayerApp.exe:2496 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\.pmp\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.rmi\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.mod\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg4\UserChoice]
"Progid" = "BDPlayer.mpeg4"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".dat" = "BDPlayer.dat"

[HKCR\.smk]
"(Default)" = "BDPlayer.smk"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tp]
"Progid" = "BDPlayer.tp"

[HKCR\BDPlayer.dts\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.aac]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ssa\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.3g2\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mla" = "BDPlayer.mla"
".IVF" = "BDPlayer.ivf"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flic\UserChoice]
"Progid" = "BDPlayer.flic"

[HKCR\BDPlayer.mod]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ratDVD\UserChoice]
"Progid" = "BDPlayer.ratDVD"

[HKCR\.wav]
"BDPlayer.bak" = "WMP11.AssocFile.WAV"

[HKCR\BDPlayer.qt]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.avi\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\avi.ico"

[HKCR\.3g2]
"BDPlayer.bak" = "WMP11.AssocFile.3G2"

[HKCR\BDPlayer.ac3\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.rpm\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.m4p\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.mov]
"(Default)" = "BDPlayer.mov"

[HKCR\BDPlayer.amr]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mp2\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rpm\UserChoice]
"Progid" = "BDPlayer.rpm"

[HKCR\BDPlayer.m4a\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.rpm\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.rt\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.hlv\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv\UserChoice]
"Progid" = "BDPlayer.flv"

[HKCR\BDPlayer.fli]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".flv" = "BDPlayer.flv"

[HKCR\.mpe]
"(Default)" = "BDPlayer.mpe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp5]
"Progid" = "BDPlayer.mp5"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2]
"Progid" = "BDPlayer.3gp2"

[HKCR\BDPlayer.flv]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.wmv\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.divx\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mpeg" = "BDPlayer.mpeg"

[HKCR\BDPlayer.scm\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.mpe\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".FLC" = "BDPlayer.flc"

[HKCR\.hlv\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".TAK" = "BDPlayer.tak"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rpm\UserChoice]
"Progid" = "BDPlayer.rpm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli\UserChoice]
"Progid" = "BDPlayer.fli"

[HKCR\BDPlayer.asm\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".FLI" = "BDPlayer.fli"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob\UserChoice]
"Progid" = "BDPlayer.vob"

[HKCR\BDPlayer.mod\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MOD.ico"

[HKCR\BDPlayer.mp3\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.m4v\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.mp5\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram]
"Progid" = "BDPlayer.ram"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".SSA" = "BDPlayer.ssa"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scm\UserChoice]
"Progid" = "BDPlayer.scm"

[HKCR\BDPlayer.ogg]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".rp" = "BDPlayer.rp"

[HKCR\.ogm\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
"Progid" = "BDPlayer.mp2v"

[HKCR\BDPlayer.ogg\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.smi\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.m4b\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.3gpp\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.rmvb\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.mov]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.rm\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf]
"Progid" = "BDPlayer.asf"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice]
"Progid" = "BDPlayer.mts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webm]
"Progid" = "BDPlayer.webm"

[HKCR\BDPlayer.mp4\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogx\UserChoice]
"Progid" = "BDPlayer.ogx"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scm\UserChoice]
"Progid" = "BDPlayer.scm"

[HKCR\BDPlayer.wma\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\wma.ico"

[HKCR\BDPlayer.mids\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb]
"Progid" = "BDPlayer.rmvb"

[HKCR\.mpeg\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ratDVD]
"Progid" = "BDPlayer.ratDVD"

[HKCR\.ass]
"(Default)" = "BDPlayer.ass"

[HKCR\BDPlayer.csf]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.rmi]
"BDPlayer.bak" = "WMP11.AssocFile.MIDI"

[HKCR\BDPlayer.asf]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.wv]
"(Default)" = "BDPlayer.wv"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice]
"Progid" = "BDPlayer.3g2"

[HKCR\BDPlayer.mid\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.cda]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\UserChoice]
"Progid" = "BDPlayer.cda"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".flic" = "BDPlayer.flic"

[HKCR\.smi\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ivm\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.ssa]
"(Default)" = "BDPlayer.ssa"

[HKCR\.rp\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.flc\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.mid\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.mpeg\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.amr]
"(Default)" = "BDPlayer.amr"

[HKCR\BDPlayer.mla\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".APE" = "BDPlayer.ape"

[HKCR\.m4v]
"(Default)" = "BDPlayer.m4v"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
"Progid" = "BDPlayer.mpeg"

[HKCR\.dts\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ogm\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr]
"Progid" = "BDPlayer.amr"

[HKCR\.ts]
"BDPlayer.bak" = "WMP11.AssocFile.TTS"

[HKCR\BDPlayer.mid\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.wav]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.wmp]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mts\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MTS.ico"

[HKCR\BDPlayer.3gpp\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.flc]
"(Default)" = "BDPlayer.flc"

[HKCR\.mp4\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amv\UserChoice]
"Progid" = "BDPlayer.amv"

[HKCR\BDPlayer.wm\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.3gp2\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesChanges" = "9"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp6\UserChoice]
"Progid" = "BDPlayer.vp6"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ivf\UserChoice]
"Progid" = "BDPlayer.ivf"

[HKCR\.m2ts]
"BDPlayer.bak" = "WMP11.AssocFile.M2TS"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".wma" = "BDPlayer.wma"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\UserChoice]
"Progid" = "BDPlayer.mkv"

[HKCR\BDPlayer.qt\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.flac]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.divx\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ofr\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".csf" = "BDPlayer.csf"

[HKCR\.d2v]
"(Default)" = "BDPlayer.d2v"

[HKCR\.mp2v]
"BDPlayer.bak" = "WMP11.AssocFile.MPEG"

[HKCR\BDPlayer.flv\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\flv.ico"

[HKCR\BDPlayer.wmv]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.3gpp]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.pva\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ass\UserChoice]
"Progid" = "BDPlayer.ass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlmv\UserChoice]
"Progid" = "BDPlayer.xlmv"

[HKCR\BDPlayer.ogm\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.m2p\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.tp\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
"Progid" = "BDPlayer.mpv2"

[HKCR\BDPlayer.tod]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\UserChoice]
"Progid" = "BDPlayer.mod"

[HKCR\BDPlayer.avi\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.m4b\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.scm\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
"Progid" = "BDPlayer.mpg"

[HKCR\BDPlayer.fli\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob\UserChoice]
"Progid" = "BDPlayer.vob"

[HKCR\BDPlayer.f4v\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".TTA" = "BDPlayer.tta"
".FLAC" = "BDPlayer.flac"

[HKCR\.mpv2]
"(Default)" = "BDPlayer.mpv2"

[HKCR\BDPlayer.aac\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.mp3\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ratDVD\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.pva]
"(Default)" = "BDPlayer.pva"

[HKCR\BDPlayer.wmp\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.mla]
"(Default)" = "BDPlayer.mla"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".ratDVD" = "BDPlayer.ratDVD"

[HKCR\BDPlayer.mp5\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".M4A" = "BDPlayer.m4a"

[HKCR\BDPlayer.d2v\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.mid]
"(Default)" = "BDPlayer.mid"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".m4p" = "BDPlayer.m4p"
".dsm" = "BDPlayer.dsm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra]
"Progid" = "BDPlayer.ra"

[HKCR\.3gp2]
"BDPlayer.bak" = "WMP11.AssocFile.3G2"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil\UserChoice]
"Progid" = "BDPlayer.smil"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".ivm" = "BDPlayer.ivm"

[HKCR\.bik]
"(Default)" = "BDPlayer.bik"

[HKCR\BDPlayer.ass\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.mpa\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.vob\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t]
"Progid" = "BDPlayer.m2t"

[HKCR\.m4p]
"(Default)" = "BDPlayer.m4p"

[HKCR\.m2v]
"BDPlayer.bak" = "WMP11.AssocFile.MPEG"

[HKCR\.bik\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rpm]
"Progid" = "BDPlayer.rpm"

[HKCR\.3g2]
"(Default)" = "BDPlayer.3g2"

[HKCR\BDPlayer.bik\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.ogg]
"(Default)" = "BDPlayer.ogg"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pss\UserChoice]
"Progid" = "BDPlayer.pss"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tod\UserChoice]
"Progid" = "BDPlayer.tod"

[HKCR\BDPlayer.ssa\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\SSA.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ssa\UserChoice]
"Progid" = "BDPlayer.ssa"

[HKCR\.mpeg4]
"(Default)" = "BDPlayer.mpeg4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm\UserChoice]
"Progid" = "BDPlayer.rm"

[HKCR\BDPlayer.m2p]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
"Progid" = "BDPlayer.mpa"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".PMP" = "BDPlayer.pmp"

[HKCR\BDPlayer.m2a\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.m4a]
"BDPlayer.bak" = "WMP11.AssocFile.M4A"

[HKCR\.amv]
"(Default)" = "BDPlayer.amv"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pss\UserChoice]
"Progid" = "BDPlayer.pss"

[HKCR\.ts\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".avi" = "BDPlayer.avi"

[HKCR\BDPlayer.3g2\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm\UserChoice]
"Progid" = "BDPlayer.rm"

[HKCR\.asm\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mpeg4" = "BDPlayer.mpeg4"

[HKCR\.tta\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ivm]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.3g2]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.rp\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.vob\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.3gpp\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.mpeg]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.rmi\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.ape]
"(Default)" = "BDPlayer.ape"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa]
"Progid" = "BDPlayer.mpa"

[HKCR\BDPlayer.webm\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v]
"Progid" = "BDPlayer.mp2v"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asm]
"Progid" = "BDPlayer.asm"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".3g2" = "BDPlayer.3g2"

[HKCR\.mpa]
"BDPlayer.bak" = "WMP11.AssocFile.MPEG"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2]
"Progid" = "BDPlayer.3g2"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
"Progid" = "BDPlayer.wav"

[HKCR\.m2t\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr\UserChoice]
"Progid" = "BDPlayer.amr"

[HKCR\BDPlayer.mkv]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.wmv]
"BDPlayer.bak" = "WMP11.AssocFile.WMV"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dat]
"Progid" = "BDPlayer.dat"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogv\UserChoice]
"Progid" = "BDPlayer.ogv"

[HKCR\BDPlayer.wav\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.aac]
"BDPlayer.bak" = "WMP11.AssocFile.ADTS"

[HKCR\BDPlayer.mka\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.mka\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.ivm\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.tpr\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.flic\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr\UserChoice]
"Progid" = "BDPlayer.amr"

[HKCR\BDPlayer.ogv\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smk]
"Progid" = "BDPlayer.smk"

[HKCR\.mpg\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.m2p]
"(Default)" = "BDPlayer.m2p"

[HKCR\BDPlayer.mpeg\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mpeg.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.d2v\UserChoice]
"Progid" = "BDPlayer.d2v"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ofr\UserChoice]
"Progid" = "BDPlayer.ofr"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogv\UserChoice]
"Progid" = "BDPlayer.ogv"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice]
"Progid" = "BDPlayer.3gp2"

[HKCR\BDPlayer.mpv2\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil\UserChoice]
"Progid" = "BDPlayer.smil"

[HKCR\BDPlayer.cda\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".amv" = "BDPlayer.amv"

[HKCR\.wma\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.csf\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv]
"Progid" = "BDPlayer.mkv"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".pva" = "BDPlayer.pva"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
"Progid" = "BDPlayer.m1v"

[HKCR\BDPlayer.tak]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.amr\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.ape\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.mkv\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ofr\UserChoice]
"Progid" = "BDPlayer.ofr"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".m1v" = "BDPlayer.m1v"

[HKCR\BDPlayer.mpe\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.mid\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tpr\UserChoice]
"Progid" = "BDPlayer.tpr"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
"Progid" = "BDPlayer.mp4"

[HKCR\BDPlayer.m2a\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scm]
"Progid" = "BDPlayer.scm"

[HKCR\BDPlayer.tp\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rp]
"Progid" = "BDPlayer.rp"

[HKCR\.flc\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.mts]
"(Default)" = "BDPlayer.mts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov]
"Progid" = "BDPlayer.mov"

[HKCR\BDPlayer.wm\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pss]
"Progid" = "BDPlayer.pss"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pmp\UserChoice]
"Progid" = "BDPlayer.pmp"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mts" = "BDPlayer.mts"

[HKCR\BDPlayer.ratDVD\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.mts\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.ogv\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
"Progid" = "BDPlayer.mid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm\UserChoice]
"Progid" = "BDPlayer.ogm"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".ASS" = "BDPlayer.ass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.d2v]
"Progid" = "BDPlayer.d2v"

[HKCR\BDPlayer.srt\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\SRT.ico"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".3gp" = "BDPlayer.3gp"

[HKCR\.mov]
"BDPlayer.bak" = "WMP11.AssocFile.MOV"

[HKCR\BDPlayer.dat\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\DAT.ico"

[HKCR\BDPlayer.ogx\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.wv\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.wma\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".asf" = "BDPlayer.asf"

[HKCR\.avi]
"(Default)" = "BDPlayer.avi"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda]
"Progid" = "BDPlayer.cda"

[HKCR\BDPlayer.m2v\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.wmp\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hlv\UserChoice]
"Progid" = "BDPlayer.hlv"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm\UserChoice]
"Progid" = "BDPlayer.ogm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice]
"Progid" = "BDPlayer.3gp"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csf\UserChoice]
"Progid" = "BDPlayer.csf"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".asm" = "BDPlayer.asm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma]
"Progid" = "BDPlayer.wma"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mids" = "BDPlayer.mids"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webm\UserChoice]
"Progid" = "BDPlayer.webm"

[HKCR\.dts]
"(Default)" = "BDPlayer.dts"

[HKCR\.wmv\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DTS\UserChoice]
"Progid" = "BDPlayer.dts"

[HKCR\.avsts\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ac3\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.mpv2\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.wv]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flic]
"Progid" = "BDPlayer.flic"

[HKCR\.wma]
"(Default)" = "BDPlayer.wma"

[HKCR\BDPlayer.rt]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.flac]
"(Default)" = "BDPlayer.flac"

[HKCR\BDPlayer.ts\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\ts.ico"

[HKCR\BDPlayer.3gp\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
"Progid" = "BDPlayer.avi"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".wm" = "BDPlayer.wm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smk\UserChoice]
"Progid" = "BDPlayer.smk"

[HKCR\.mp2\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mpa]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.pva\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\pva.ico"

[HKCR\.mpeg4\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.f4v]
"Progid" = "BDPlayer.f4v"

[HKCR\.3gp]
"BDPlayer.bak" = "WMP11.AssocFile.3GP"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2p\UserChoice]
"Progid" = "BDPlayer.m2p"

[HKCR\.SCM]
"(Default)" = "BDPlayer.scm"

[HKCR\BDPlayer.ts\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.mpeg4\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v]
"Progid" = "BDPlayer.m2v"

[HKCR\BDPlayer.m2ts\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities]
"ApplicationName" = "百度影音播放器"

[HKCR\.tpr]
"(Default)" = "BDPlayer.tpr"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smk\UserChoice]
"Progid" = "BDPlayer.smk"

[HKCR\BDPlayer.wv\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\RegisteredApplications]
"BDPlayer5" = "Software\Baidu\BDPlayer5\Capabilities"

[HKCR\.wmv]
"(Default)" = "BDPlayer.wmv"

[HKCR\BDPlayer.rmi]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.d2v\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.flac\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.flic]
"(Default)" = "BDPlayer.flic"

[HKCR\.3gp\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.pss\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.asm]
"(Default)" = "BDPlayer.asm"

[HKCR\.vp6]
"(Default)" = "BDPlayer.vp6"

[HKCR\BDPlayer.rmvb\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\rmvb.ico"

[HKCR\BDPlayer.asf\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.flac\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.rt\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.mpv2\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.d2v\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.pva\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.mka]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".MID" = "BDPlayer.mid"

[HKCR\BDPlayer.rpm\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.m4b]
"(Default)" = "BDPlayer.m4b"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".SRT" = "BDPlayer.srt"

[HKCR\BDPlayer.wm\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".wmp" = "BDPlayer.wmp"

[HKCR\.m4p\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.asm\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.m2t]
"BDPlayer.bak" = "WMP11.AssocFile.M2TS"

[HKCR\BDPlayer.srt]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".wmv" = "BDPlayer.wmv"

[HKCR\.3g2\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mod\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.csf\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.pss\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.csf]
"(Default)" = "BDPlayer.csf"

[HKCR\BDPlayer.3gp2\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.asm]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.d2v]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.flic\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.mp3]
"(Default)" = "BDPlayer.mp3"

[HKCR\BDPlayer.mpv2]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p\UserChoice]
"Progid" = "BDPlayer.m4p"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pva\UserChoice]
"Progid" = "BDPlayer.pva"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb\UserChoice]
"Progid" = "BDPlayer.rmvb"

[HKCR\.mov\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hlv\UserChoice]
"Progid" = "BDPlayer.hlv"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".m4v" = "BDPlayer.m4v"

[HKCR\BDPlayer.dsm]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.3gp\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\3gp.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2p]
"Progid" = "BDPlayer.m2p"

[HKCR\BDPlayer.xlmv]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".AAC" = "BDPlayer.aac"

[HKCR\BDPlayer.smi\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.mp3]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webm\UserChoice]
"Progid" = "BDPlayer.webm"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".M4B" = "BDPlayer.m4b"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DTS\UserChoice]
"Progid" = "BDPlayer.dts"

[HKCR\BDPlayer.flv\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bik]
"Progid" = "BDPlayer.bik"

[HKCR\BDPlayer.mpga\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.m4b]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2a\UserChoice]
"Progid" = "BDPlayer.m2a"

[HKCR\BDPlayer.ape\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".ogv" = "BDPlayer.ogv"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb\UserChoice]
"Progid" = "BDPlayer.rmvb"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape]
"Progid" = "BDPlayer.ape"

[HKCR\.m2v]
"(Default)" = "BDPlayer.m2v"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlmv]
"Progid" = "BDPlayer.xlmv"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".ogx" = "BDPlayer.ogx"
".OGG" = "BDPlayer.ogg"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rt]
"Progid" = "BDPlayer.rt"

[HKCR\.tp\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ra\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.xlmv\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".ogm" = "BDPlayer.ogm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2a\UserChoice]
"Progid" = "BDPlayer.m2a"

[HKCR\BDPlayer.divx]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mp4\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".pss" = "BDPlayer.pss"

[HKCR\BDPlayer.f4v\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\f4v.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPGA\UserChoice]
"Progid" = "BDPlayer.mpga"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx\UserChoice]
"Progid" = "BDPlayer.divx"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mids\UserChoice]
"Progid" = "BDPlayer.mids"

[HKCR\BDPlayer.mpa\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.ram\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.webm\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ass\UserChoice]
"Progid" = "BDPlayer.ass"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mpe" = "BDPlayer.mpe"

[HKCR\BDPlayer.ivf]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mpg" = "BDPlayer.mpg"

[HKCR\BDPlayer.ass\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\ASS.ico"

[HKCR\BDPlayer.wv\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".SMI" = "BDPlayer.smi"

[HKCR\BDPlayer.rm\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.ogm]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac]
"Progid" = "BDPlayer.aac"

[HKCR\BDPlayer.mov\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.tta\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.avi]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".CDA" = "BDPlayer.cda"

[HKCR\BDPlayer.wav\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.flic\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".ts" = "BDPlayer.ts"

[HKCR\BDPlayer.rp\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".m2p" = "BDPlayer.m2p"

[HKCR\.mpga]
"(Default)" = "BDPlayer.mpga"

[HKCR\.rmvb]
"(Default)" = "BDPlayer.rmvb"

[HKCR\.ogx\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.xlmv\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.rmvb\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p\UserChoice]
"Progid" = "BDPlayer.m4p"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".tp" = "BDPlayer.tp"

[HKCR\BDPlayer.3gpp\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.dat]
"(Default)" = "BDPlayer.dat"

[HKCR\.ogm]
"(Default)" = "BDPlayer.ogm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv\UserChoice]
"Progid" = "BDPlayer.flv"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mp5" = "BDPlayer.mp5"
".mp4" = "BDPlayer.mp4"

[HKCR\BDPlayer.xlmv\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka]
"Progid" = "BDPlayer.mka"

[HKCR\.rt]
"(Default)" = "BDPlayer.rt"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".MP2" = "BDPlayer.mp2"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg]
"Progid" = "BDPlayer.mpeg"

[HKCR\BDPlayer.vp7\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mpv2" = "BDPlayer.mpv2"

[HKCR\BDPlayer.ogv\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.m2v\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.flic\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.ram]
"(Default)" = "BDPlayer.ram"

[HKCR\BDPlayer.mpg]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".SMK" = "BDPlayer.smk"

[HKCR\.webm]
"(Default)" = "BDPlayer.webm"

[HKCR\BDPlayer.m2t\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\M2P.ico"

[HKCR\.ofr]
"(Default)" = "BDPlayer.ofr"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
"Progid" = "BDPlayer.wm"

[HKCR\.tpr\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPGA\UserChoice]
"Progid" = "BDPlayer.mpga"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc\UserChoice]
"Progid" = "BDPlayer.flc"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg4\UserChoice]
"Progid" = "BDPlayer.mpeg4"

[HKCR\BDPlayer.mla\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.flac\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts]
"Progid" = "BDPlayer.ts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\UserChoice]
"Progid" = "BDPlayer.m2ts"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".smil" = "BDPlayer.smil"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ofr]
"Progid" = "BDPlayer.ofr"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".amr" = "BDPlayer.amr"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wv\UserChoice]
"Progid" = "BDPlayer.wv"

[HKCR\.xlmv]
"(Default)" = "BDPlayer.xlmv"

[HKCR\BDPlayer.mp3\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mp3.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx\UserChoice]
"Progid" = "BDPlayer.divx"

[HKCR\.flv]
"(Default)" = "BDPlayer.flv"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tak]
"Progid" = "BDPlayer.tak"

[HKCR\BDPlayer.smil\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.webm\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\WEBM.ico"

[HKCR\.3gp]
"(Default)" = "BDPlayer.3gp"

[HKCR\BDPlayer.ra\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.mkv\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mkv.ico"

[HKCR\.srt\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
"Progid" = "BDPlayer.aifc"

[HKCR\BDPlayer.tod\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg4]
"Progid" = "BDPlayer.mpeg4"

[HKCR\BDPlayer.rmvb\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".MP3" = "BDPlayer.mp3"

[HKCR\.ac3]
"(Default)" = "BDPlayer.ac3"

[HKCR\BDPlayer.m4v]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.mp2]
"BDPlayer.bak" = "WMP11.AssocFile.MP3"

[HKCR\.smil]
"(Default)" = "BDPlayer.smil"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b]
"Progid" = "BDPlayer.m4b"

[HKCR\BDPlayer.m2v\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape\UserChoice]
"Progid" = "BDPlayer.ape"

[HKCR\.ra\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2]
"Progid" = "BDPlayer.mpv2"

[HKCR\BDPlayer.rt\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe]
"Progid" = "BDPlayer.mpe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg]
"Progid" = "BDPlayer.ogg"

[HKCR\BDPlayer.ratDVD]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.m4a]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.aac\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.cda\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flic\UserChoice]
"Progid" = "BDPlayer.flic"

[HKCR\BDPlayer.mpa\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.asf]
"BDPlayer.bak" = "WMP11.AssocFile.ASF"

[HKCR\BDPlayer.m2p\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bik\UserChoice]
"Progid" = "BDPlayer.bik"

[HKCR\.mpv2]
"BDPlayer.bak" = "WMP11.AssocFile.MPEG"

[HKCR\BDPlayer.mpv2\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.mpe\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.asf\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\asf.ico"

[HKCR\BDPlayer.ra]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ssa]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.wma]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p]
"Progid" = "BDPlayer.m4p"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amv]
"Progid" = "BDPlayer.amv"

[HKCR\.mp4]
"(Default)" = "BDPlayer.mp4"

[HKCR\BDPlayer.m4v\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bik\UserChoice]
"Progid" = "BDPlayer.bik"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
"Progid" = "BDPlayer.rmi"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\UserChoice]
"Progid" = "BDPlayer.ts"

[HKCR\BDPlayer.cda\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp5\UserChoice]
"Progid" = "BDPlayer.mp5"

[HKCR\BDPlayer.wma\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.mp2v\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.srt\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.ogx]
"(Default)" = "BDPlayer.ogx"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2a]
"Progid" = "BDPlayer.m2a"

[HKCR\BDPlayer.tak\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".AC3" = "BDPlayer.ac3"

[HKCR\.rt\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.tpr]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ivm\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.amv\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.mpg]
"BDPlayer.bak" = "WMP11.AssocFile.MPEG"

[HKCR\BDPlayer.f4v]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.m4p\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.m2v\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.vob\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpga]
"Progid" = "BDPlayer.mpga"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp]
"Progid" = "BDPlayer.3gp"

[HKCR\BDPlayer.vp6\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.m2t]
"(Default)" = "BDPlayer.m2t"

[HKCR\BDPlayer.flc]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.mp5]
"(Default)" = "BDPlayer.mp5"

[HKCR\.cda]
"BDPlayer.bak" = "WMP11.AssocFile.CDA"

[HKCR\BDPlayer.asf\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.csf\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ivf\UserChoice]
"Progid" = "BDPlayer.ivf"

[HKCR\BDPlayer.mpg\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srt\UserChoice]
"Progid" = "BDPlayer.srt"

[HKCR\BDPlayer.pva\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.vp6]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.rm\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.amv]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mla]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.ogg\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.pmp\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".scm" = "BDPlayer.scm"

[HKCR\BDPlayer.bik]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp7\UserChoice]
"Progid" = "BDPlayer.vp7"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avsts\UserChoice]
"Progid" = "BDPlayer.avsts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mids\UserChoice]
"Progid" = "BDPlayer.mids"

[HKCR\BDPlayer.m4b\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.mpeg4\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.mp5]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ivf\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".BIK" = "BDPlayer.bik"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape\UserChoice]
"Progid" = "BDPlayer.ape"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AC3\UserChoice]
"Progid" = "BDPlayer.ac3"

[HKCR\BDPlayer.webm]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
"Progid" = "BDPlayer.wmv"

[HKCR\BDPlayer.mts]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.avsts]
"(Default)" = "BDPlayer.avsts"

[HKCR\BDPlayer.smk\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp7\UserChoice]
"Progid" = "BDPlayer.vp7"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OGG\UserChoice]
"Progid" = "BDPlayer.ogg"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avsts\UserChoice]
"Progid" = "BDPlayer.avsts"

[HKCR\.mid]
"BDPlayer.bak" = "WMP11.AssocFile.MIDI"

[HKCR\BDPlayer.f4v\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2]
"Progid" = "BDPlayer.mp2"

[HKCR\BDPlayer.ape]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wv]
"Progid" = "BDPlayer.wv"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tpr\UserChoice]
"Progid" = "BDPlayer.tpr"

[HKCR\.wma]
"BDPlayer.bak" = "WMP11.AssocFile.WMA"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi]
"Progid" = "BDPlayer.smi"

[HKCR\BDPlayer.mpga]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amv\UserChoice]
"Progid" = "BDPlayer.amv"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srt]
"Progid" = "BDPlayer.srt"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
"Progid" = "BDPlayer.mp2"

[HKCR\BDPlayer.rpm\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.ogx]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.m1v]
"BDPlayer.bak" = "WMP11.AssocFile.MPEG"

[HKCR\BDPlayer.pmp]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".dts" = "BDPlayer.dts"

[HKCR\BDPlayer.flc\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.flic]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.m1v\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.rp]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tp\UserChoice]
"Progid" = "BDPlayer.tp"

[HKCR\.avi\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tp\UserChoice]
"Progid" = "BDPlayer.tp"

[HKCR\.vp7]
"(Default)" = "BDPlayer.vp7"

[HKCR\BDPlayer.dat]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts]
"Progid" = "BDPlayer.mts"

[HKCR\.m4v]
"BDPlayer.bak" = "WMP11.AssocFile.MP4"

[HKCR\BDPlayer.ts]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts]
"Progid" = "BDPlayer.m2ts"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".M2A" = "BDPlayer.m2a"

[HKCR\BDPlayer.smil\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.ram\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTA\UserChoice]
"Progid" = "BDPlayer.tta"

[HKCR\BDPlayer.m2p\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.tak\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.pss\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.ivf]
"(Default)" = "BDPlayer.ivf"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v]
"Progid" = "BDPlayer.m1v"

[HKCR\BDPlayer.mpga\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.dsm\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.mov\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MOV.ico"

[HKCR\BDPlayer.pva]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ivm]
"Progid" = "BDPlayer.ivm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
"Progid" = "BDPlayer.wma"

[HKCR\.aac]
"(Default)" = "BDPlayer.aac"

[HKCR\BDPlayer.m1v\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmp]
"Progid" = "BDPlayer.wmp"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".QT" = "BDPlayer.qt"

[HKCR\.divx]
"(Default)" = "BDPlayer.divx"

[HKCR\BDPlayer.dsm\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b\UserChoice]
"Progid" = "BDPlayer.m4b"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srt\UserChoice]
"Progid" = "BDPlayer.srt"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mla\UserChoice]
"Progid" = "BDPlayer.mla"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesResolve" = "CC 02 00 00 4C 00 00 00 01 14 02 00 00 00 00 00"

[HKCR\BDPlayer.m4v\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.amr\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.vob]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm]
"Progid" = "BDPlayer.ogm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra\UserChoice]
"Progid" = "BDPlayer.ra"

[HKCR\BDPlayer.mp5\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.vp7]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mp2\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.wav]
"(Default)" = "BDPlayer.wav"

[HKCR\BDPlayer.hlv]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mpeg\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.qt]
"(Default)" = "BDPlayer.qt"

[HKCR\.mp2v\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mkv\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FLAC\UserChoice]
"Progid" = "BDPlayer.flac"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob]
"Progid" = "BDPlayer.vob"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mka" = "BDPlayer.mka"
".RT" = "BDPlayer.rt"

[HKCR\.mka]
"(Default)" = "BDPlayer.mka"

[HKCR\BDPlayer.flc\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp6]
"Progid" = "BDPlayer.vp6"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csf\UserChoice]
"Progid" = "BDPlayer.csf"

[HKCR\BDPlayer.wmp\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra\UserChoice]
"Progid" = "BDPlayer.ra"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dat\UserChoice]
"Progid" = "BDPlayer.dat"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice]
"Progid" = "BDPlayer.mov"

[HKCR\BDPlayer.ivf\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.ogx\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".MOD" = "BDPlayer.mod"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogx]
"Progid" = "BDPlayer.ogx"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v\UserChoice]
"Progid" = "BDPlayer.m2v"

[HKCR\BDPlayer.dat\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.dsm]
"(Default)" = "BDPlayer.dsm"

[HKCR\BDPlayer.m2ts\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\m2ts.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlmv\UserChoice]
"Progid" = "BDPlayer.xlmv"

[HKCR\BDPlayer.rpm]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
"Progid" = "BDPlayer.mp3"

[HKCR\.pmp]
"(Default)" = "BDPlayer.pmp"

[HKCR\.mpg]
"(Default)" = "BDPlayer.mpg"

[HKCR\BDPlayer.smil\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.aifc\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qt]
"Progid" = "BDPlayer.qt"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2p\UserChoice]
"Progid" = "BDPlayer.m2p"

[HKCR\.m4a\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.mp2]
"(Default)" = "BDPlayer.mp2"

[HKCR\BDPlayer.ts\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".ram" = "BDPlayer.ram"

[HKCR\BDPlayer.m4b\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.mpe]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.wav\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.qt\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.mpa]
"(Default)" = "BDPlayer.mpa"

[HKCR\.smi]
"(Default)" = "BDPlayer.smi"

[HKCR\.ogv\OpenWithProgIDs]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.mpa\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.srt\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asm\UserChoice]
"Progid" = "BDPlayer.asm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mla]
"Progid" = "BDPlayer.mla"

[HKCR\BDPlayer.rm\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\rm.ico"

[HKCR\BDPlayer.wm]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.m2a\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.ra]
"(Default)" = "BDPlayer.ra"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".VP6" = "BDPlayer.vp6"
".vp7" = "BDPlayer.vp7"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTA\UserChoice]
"Progid" = "BDPlayer.tta"

[HKCR\.m2ts]
"(Default)" = "BDPlayer.m2ts"

[HKCR\.mp2v]
"(Default)" = "BDPlayer.mp2v"

[HKCR\.smk\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.rmi\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.vp7\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.vp6\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mp5\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac]
"Progid" = "BDPlayer.flac"

[HKCR\.3gpp]
"(Default)" = "BDPlayer.3gpp"

[HKCR\BDPlayer.mod\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil]
"Progid" = "BDPlayer.smil"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pva\UserChoice]
"Progid" = "BDPlayer.pva"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"Favorites" = "00 7C 01 00 00 14 00 1F 80 C8 27 34 1F 10 5C 10"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm]
"Progid" = "BDPlayer.wm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli\UserChoice]
"Progid" = "BDPlayer.fli"

[HKCR\BDPlayer.tod\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.pss]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.m4a\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.ivm]
"(Default)" = "BDPlayer.ivm"

[HKCR\.ac3\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.tp]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv]
"Progid" = "BDPlayer.wmv"

[HKCR\BDPlayer.m2v]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogv]
"Progid" = "BDPlayer.ogv"

[HKCR\BDPlayer.ac3\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.dsm\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
"Progid" = "BDPlayer.m4v"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
"Progid" = "BDPlayer.mpe"

[HKCR\.rpm]
"(Default)" = "BDPlayer.rpm"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".3gpp" = "BDPlayer.3gpp"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tod\UserChoice]
"Progid" = "BDPlayer.tod"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ivm\UserChoice]
"Progid" = "BDPlayer.ivm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rp\UserChoice]
"Progid" = "BDPlayer.rp"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FLAC\UserChoice]
"Progid" = "BDPlayer.flac"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".tod" = "BDPlayer.tod"

[HKCR\.ratDVD\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ratDVD\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.3gp2]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mp2v]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.dts]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.m2t\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dat\UserChoice]
"Progid" = "BDPlayer.dat"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi\UserChoice]
"Progid" = "BDPlayer.smi"

[HKCR\BDPlayer.mpeg4]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.bik\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.wv\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.ass\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tta]
"Progid" = "BDPlayer.tta"

[HKCR\.m1v]
"(Default)" = "BDPlayer.m1v"

[HKCR\BDPlayer.m1v]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dts]
"Progid" = "BDPlayer.dts"

[HKCR\BDPlayer.amv\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ivm\UserChoice]
"Progid" = "BDPlayer.ivm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rp\UserChoice]
"Progid" = "BDPlayer.rp"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp]
"Progid" = "BDPlayer.3gpp"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3]
"Progid" = "BDPlayer.mp3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pmp\UserChoice]
"Progid" = "BDPlayer.pmp"

[HKCR\BDPlayer.ofr\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi\UserChoice]
"Progid" = "BDPlayer.smi"

[HKCR\BDPlayer.m2t]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.aac\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.IVF\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.hlv\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".vob" = "BDPlayer.vob"

[HKCR\BDPlayer.avsts\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".3gp2" = "BDPlayer.3gp2"
".mpa" = "BDPlayer.mpa"

[HKCR\BDPlayer.rm]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ogx\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.3gp2\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.mids\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.pmp\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.tak\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.mpe]
"BDPlayer.bak" = "WMP11.AssocFile.MPEG"

[HKCR\BDPlayer.smil]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OGG\UserChoice]
"Progid" = "BDPlayer.ogg"

[HKCR\.f4v]
"(Default)" = "BDPlayer.f4v"

[HKCR\BDPlayer.mka\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.scm]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v]
"Progid" = "BDPlayer.m4v"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\UserChoice]
"Progid" = "BDPlayer.m2t"

[HKCR\.dsm\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".m2ts" = "BDPlayer.m2ts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ssa]
"Progid" = "BDPlayer.ssa"

[HKCR\.tp]
"(Default)" = "BDPlayer.tp"

[HKCR\.m1v\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.dat\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.mp4]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.mkv]
"(Default)" = "BDPlayer.mkv"

[HKCR\BDPlayer.ogg\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.avi\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avsts]
"Progid" = "BDPlayer.avsts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mids]
"Progid" = "BDPlayer.mids"

[HKCR\.mts]
"BDPlayer.bak" = "WMP11.AssocFile.M2TS"

[HKCR\.tod]
"(Default)" = "BDPlayer.tod"

[HKCR\BDPlayer.ram]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ofr]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ogg\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".WAV" = "BDPlayer.wav"

[HKCR\.mp3]
"BDPlayer.bak" = "WMP11.AssocFile.MP3"

[HKCR\BDPlayer.mov\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a]
"Progid" = "BDPlayer.m4a"

[HKCR\.pss]
"(Default)" = "BDPlayer.pss"

[HKCR\BDPlayer.ogv]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.mla\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mp2v" = "BDPlayer.mp2v"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer]
"GlobalAssocChangedCounter" = "100"

[HKCR\BDPlayer.mp2\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm]
"Progid" = "BDPlayer.rm"

[HKCR\BDPlayer.m2ts]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mla\UserChoice]
"Progid" = "BDPlayer.mla"

[HKCR\BDPlayer.asm\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mkv" = "BDPlayer.mkv"

[HKCR\.mts\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rt\UserChoice]
"Progid" = "BDPlayer.rt"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".RMI" = "BDPlayer.rmi"

[HKCR\BDPlayer.fli\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.aifc]
"(Default)" = "BDPlayer.aifc"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.f4v\UserChoice]
"Progid" = "BDPlayer.f4v"

[HKCR\.ogv]
"(Default)" = "BDPlayer.ogv"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".aifc" = "BDPlayer.aifc"

[HKCR\BDPlayer.dts\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".TPR" = "BDPlayer.tpr"

[HKCR\.flv\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asm\UserChoice]
"Progid" = "BDPlayer.asm"

[HKCR\.m2a\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg]
"Progid" = "BDPlayer.mpg"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rt\UserChoice]
"Progid" = "BDPlayer.rt"

[HKCR\BDPlayer.ram\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.ivf\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp6\UserChoice]
"Progid" = "BDPlayer.vp6"

[HKCR\BDPlayer.mids\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".divx" = "BDPlayer.divx"

[HKCR\.asf]
"(Default)" = "BDPlayer.asf"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".rmvb" = "BDPlayer.rmvb"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ass]
"Progid" = "BDPlayer.ass"

[HKCR\BDPlayer.tpr\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.avsts\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.amv\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pmp]
"Progid" = "BDPlayer.pmp"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tak\UserChoice]
"Progid" = "BDPlayer.tak"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid]
"Progid" = "BDPlayer.mid"

[HKCR\.ssa\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.asf\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.tta]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities]
"ApplicationDescription" = "百度影音播放器"

[HKCR\.3gpp]
"BDPlayer.bak" = "WMP11.AssocFile.3GP"

[HKCR\BDPlayer.vob\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\vob.ico"

[HKCR\BDPlayer.mids]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".webm" = "BDPlayer.webm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wv\UserChoice]
"Progid" = "BDPlayer.wv"

[HKCR\BDPlayer.m4a\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.avsts]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.xlmv\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tak\UserChoice]
"Progid" = "BDPlayer.tak"

[HKCR\.wmp]
"(Default)" = "BDPlayer.wmp"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4]
"Progid" = "BDPlayer.mp4"

[HKCR\.mpga\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ssa\UserChoice]
"Progid" = "BDPlayer.ssa"

[HKCR\BDPlayer.ac3]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".ra" = "BDPlayer.ra"

[HKCR\.f4v\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.pss\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\Applications\BDPlayer.exe\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.3gp\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".WV" = "BDPlayer.wv"

[HKCR\BDPlayer.qt\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.m4p]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice]
"Progid" = "BDPlayer.aac"

[HKCR\.srt]
"(Default)" = "BDPlayer.srt"

[HKCR\.rp]
"(Default)" = "BDPlayer.rp"

[HKCR\.avi]
"BDPlayer.bak" = "WMP11.AssocFile.AVI"

[HKCR\.tak\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.flv\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.scm\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.dts\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pva]
"Progid" = "BDPlayer.pva"

[HKCR\.aifc\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.vp7\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.wmv\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogx\UserChoice]
"Progid" = "BDPlayer.ogx"

[HKCR\BDPlayer.aifc\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.wm]
"(Default)" = "BDPlayer.wm"

[HKCR\BDPlayer.mp4\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mp4.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx]
"Progid" = "BDPlayer.divx"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".avsts" = "BDPlayer.avsts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi]
"Progid" = "BDPlayer.avi"

[HKCR\BDPlayer.amv\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".OFR" = "BDPlayer.ofr"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.f4v\UserChoice]
"Progid" = "BDPlayer.f4v"

[HKCR\.mka\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.mp4]
"BDPlayer.bak" = "WMP11.AssocFile.MP4"

[HKCR\BDPlayer.m2p\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\M2P.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav]
"Progid" = "BDPlayer.wav"

[HKCR\.mod]
"(Default)" = "BDPlayer.mod"

[HKCR\BDPlayer.mpeg4\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MPEG4.ico"

[HKCR\.fli\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka\UserChoice]
"Progid" = "BDPlayer.mka"

[HKCR\BDPlayer.mp2v\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.m4v\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli]
"Progid" = "BDPlayer.fli"

[HKCR\BDPlayer.flac\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M4A\UserChoice]
"Progid" = "BDPlayer.m4a"

[HKCR\.smil\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.pmp\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.vp6\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.aifc]
"BDPlayer.bak" = "WMP11.AssocFile.AIFF"

[HKCR\.ts]
"(Default)" = "BDPlayer.ts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc]
"Progid" = "BDPlayer.flc"

[HKCR\.wm\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ass\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice]
"Progid" = "BDPlayer.3gpp"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka\UserChoice]
"Progid" = "BDPlayer.mka"

[HKCR\BDPlayer.tp\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\TP.ico"

[HKCR\BDPlayer.tta\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.m2ts\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc\UserChoice]
"Progid" = "BDPlayer.flc"

[HKCR\BDPlayer.mpg\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.aac\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.d2v\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.qt\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.mids]
"(Default)" = "BDPlayer.mids"

[HKCR\BDPlayer.ape\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.mids\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ass]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mpe\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv]
"Progid" = "BDPlayer.flv"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ac3]
"Progid" = "BDPlayer.ac3"

[HKCR\BDPlayer.rp\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.wmv\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\wmv.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi]
"Progid" = "BDPlayer.rmi"

[HKCR\.wav\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.mp2v\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MP2V.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hlv]
"Progid" = "BDPlayer.hlv"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".mov" = "BDPlayer.mov"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod]
"Progid" = "BDPlayer.mod"

[HKCR\BDPlayer.mts\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.ratDVD]
"(Default)" = "BDPlayer.ratDVD"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AC3\UserChoice]
"Progid" = "BDPlayer.ac3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qt\UserChoice]
"Progid" = "BDPlayer.qt"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".f4v" = "BDPlayer.f4v"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKCR\BDPlayer.vp6\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.mp3\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.mp2]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.webm\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.fli]
"(Default)" = "BDPlayer.fli"

[HKCR\BDPlayer.aifc\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.tod\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.3gp]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\UserChoice]
"Progid" = "BDPlayer.mkv"

[HKCR\BDPlayer.fli\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".m2v" = "BDPlayer.m2v"

[HKCR\BDPlayer.tod\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".m2t" = "BDPlayer.m2t"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tod]
"Progid" = "BDPlayer.tod"

[HKCR\BDPlayer.rmvb]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.m4a]
"(Default)" = "BDPlayer.m4a"

[HKCR\BDPlayer.ssa\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.wmp\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.m2ts\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmp\UserChoice]
"Progid" = "BDPlayer.wmp"

[HKCR\BDPlayer.ra\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
"Progid" = "BDPlayer.asf"

[HKCR\BDPlayer.amr\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.amr\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram\UserChoice]
"Progid" = "BDPlayer.ram"

[HKCR\BDPlayer.ogm\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.3gp2]
"(Default)" = "BDPlayer.3gp2"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".RPM" = "BDPlayer.rpm"

[HKCR\.3gp2\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.ram\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".MPGA" = "BDPlayer.mpga"

[HKCR\.vob]
"(Default)" = "BDPlayer.vob"

[HKCR\BDPlayer.3g2\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\.ape\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.mpeg]
"(Default)" = "BDPlayer.mpeg"

[HKCR\BDPlayer.mid]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.smk]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ivf]
"Progid" = "BDPlayer.ivf"

[HKCR\.vp7\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmp\UserChoice]
"Progid" = "BDPlayer.wmp"

[HKCR\BDPlayer.scm\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.m1v\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram\UserChoice]
"Progid" = "BDPlayer.ram"

[HKCR\BDPlayer.m4p\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.wm]
"BDPlayer.bak" = "WMP11.AssocFile.ASF"

[HKCR\.rm]
"(Default)" = "BDPlayer.rm"

[HKCR\BDPlayer.mkv\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsm]
"Progid" = "BDPlayer.dsm"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b\UserChoice]
"Progid" = "BDPlayer.m4b"

[HKCR\BDPlayer.smi\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".hlv" = "BDPlayer.hlv"

[HKCR\BDPlayer.mpga\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsm\UserChoice]
"Progid" = "BDPlayer.dsm"

[HKCR\.ivm\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesVersion" = "2"

[HKCR\BDPlayer.smk\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\BDPlayer.smk\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.mla\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.ofr\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp5\UserChoice]
"Progid" = "BDPlayer.mp5"

[HKCR\BDPlayer.tpr\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.m2t\shell\open\command]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe --from=shell --url=%1"

[HKCR\.csf\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.m2a]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\BDPlayer.tta\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCR\BDPlayer.hlv\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.divx\shell\open]
"(Default)" = "用 百度影音5 打开(&P)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tpr]
"Progid" = "BDPlayer.tpr"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".rm" = "BDPlayer.rm"

[HKCR\.rmi]
"(Default)" = "BDPlayer.rmi"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsm\UserChoice]
"Progid" = "BDPlayer.dsm"

[HKCR\BDPlayer.smi]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csf]
"Progid" = "BDPlayer.csf"

[HKCR\.mpeg]
"BDPlayer.bak" = "WMP11.AssocFile.MPEG"

[HKCR\BDPlayer.divx\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\DIVX.ico"

[HKCR\BDPlayer.aifc]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKCR\.hlv]
"(Default)" = "BDPlayer.hlv"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".d2v" = "BDPlayer.d2v"

[HKCR\.tak]
"(Default)" = "BDPlayer.tak"

[HKCR\BDPlayer.mpg\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mpg.ico"

[HKCR\BDPlayer.rmi\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\.tta]
"(Default)" = "BDPlayer.tta"

[HKCR\.mod]
"BDPlayer.bak" = "WMP11.AssocFile.MPEG"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ratDVD\UserChoice]
"Progid" = "BDPlayer.ratDVD"

[HKCR\.m2a]
"(Default)" = "BDPlayer.m2a"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.d2v\UserChoice]
"Progid" = "BDPlayer.d2v"

[HKCR\BDPlayer.avsts\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCR\BDPlayer.bik\DefaultIcon]
"(Default)" = "%Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qt\UserChoice]
"Progid" = "BDPlayer.qt"

[HKCR\.dat\OpenWithProgids]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.ofr\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc]
"Progid" = "BDPlayer.aifc"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp7]
"Progid" = "BDPlayer.vp7"

[HKCR\.cda\OpenWithProgIds]
"BDPlayer.exe" = "Type: REG_SZ, Length: 0"

[HKCR\.cda]
"(Default)" = "BDPlayer.cda"

[HKLM\SOFTWARE\BAIDU\BDPlayer5\Capabilities\FileAssociations]
".xlmv" = "BDPlayer.xlmv"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDPlayer_AutoRun" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayerTray.exe"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ratDVD\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bik\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp5\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tp\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ivf\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg4\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asm\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rt\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pva\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hlv\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DTS\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rpm\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp7\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avsts\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mids\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scm\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smk\UserChoice]
"Progid"

[HKLM\SOFTWARE\RegisteredApplications]
"BDPlayer5"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2a\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ass\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTA\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tod\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp6\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srt\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mla\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.f4v\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webm\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.d2v\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dat\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FLAC\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csf\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ssa\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogx\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M4A\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qt\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2p\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AC3\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmp\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amv\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pss\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsm\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ivm\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rp\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPGA\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pmp\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tak\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wv\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlmv\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flic\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ofr\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogv\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tpr\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OGG\UserChoice]
"Progid"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
"Progid"

The process BDPlayerTray.exe:3432 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

Dropped PE files

MD5 File path
e93b5a4fd5050116a84cf52011c516c1 c:\Program Files\Tencent\QQBrowser\Assistant.dll
4c86d70ab39a65776f5dd5702da9b509 c:\Program Files\Tencent\QQBrowser\BugReport.exe
16880d4c14c8aa0b4a1b0ec82b9f6cb3 c:\Program Files\Tencent\QQBrowser\Dialogs.dll
4d49497ce2c51461b42af928a91e3260 c:\Program Files\Tencent\QQBrowser\Downloader.dll
10d98bc99fb31673330239b88174973e c:\Program Files\Tencent\QQBrowser\EventTracing.dll
d34a527493f39af4491b3e909dc697ca c:\Program Files\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcm90.dll
4c39358ebdd2ffcd9132a30e1ec31e16 c:\Program Files\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcp90.dll
cdbe9690cf2b8409facad94fac9479c9 c:\Program Files\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcr90.dll
77b80794e7726eade4fe30954e2e5847 c:\Program Files\Tencent\QQBrowser\MouseGesture.dll
73640253f394c6dd6940fc1fe222cd92 c:\Program Files\Tencent\QQBrowser\NetWork.dll
f1e9d5f32467dd034f828bcc293e7ad9 c:\Program Files\Tencent\QQBrowser\PrScrn.dll
88f2d2382cce7ec315ca6860ff0c4075 c:\Program Files\Tencent\QQBrowser\QBExtensionFramework.dll
16ae0a59da95783599969cb2a8cd7b0d c:\Program Files\Tencent\QQBrowser\QBSafe.dll
268905b968aace3dbaf5dd97391071e9 c:\Program Files\Tencent\QQBrowser\QBUtils.dll
c3e4c6aaedb957ba059b51c1d2403c93 c:\Program Files\Tencent\QQBrowser\QQBrowser.exe
68eb386277ed0c2e4a13b6c5731f236e c:\Program Files\Tencent\QQBrowser\QQBrowserFrame.dll
acd46c8f29be4cc5f659b87f115c740c c:\Program Files\Tencent\QQBrowser\QQBrowserLiveup.exe
38977583aa8131702dd06a022a94476c c:\Program Files\Tencent\QQBrowser\QQBrowserSecurityCenter.exe
f3df05cd6c209c05c5415af6bc9e7199 c:\Program Files\Tencent\QQBrowser\QRCode.dll
528fd48653019ba6629ec9d9db2cd6a9 c:\Program Files\Tencent\QQBrowser\Resource.dll
e826d419df589357d43554c7f0c0e39c c:\Program Files\Tencent\QQBrowser\TridentCore.dll
12650137ef731c4f2967bd670287e357 c:\Program Files\Tencent\QQBrowser\WebpDecodeFilter.dll
699f0052d0c959f1a5b7c3926cce11fa c:\Program Files\Tencent\QQBrowser\dr.dll
a51d90f2f9394f5ea0a3acae3bd2b219 c:\Program Files\Tencent\QQBrowser\service\7z.exe
1b47580cce6db40a3f389ebd6250795f c:\Program Files\Tencent\QQBrowser\service\PerfTraceService.exe
e625e19acadb88eeaefd2f15cbc757f2 c:\Program Files\Tencent\QQBrowser\service\perfctrl.dll
8267d1cba70f87018d89bbb2bbbfdc03 c:\Program Files\Tencent\QQBrowser\service\xperf.exe
9ed4bdccc465222477805ca2df443596 c:\Program Files\Tencent\QQBrowser\tssafeedit.dat
9e98a28eb052436ddd886d31bae3fa1c c:\Program Files\baidu\BDPlayer\5.1.1.9\BDPlayer.exe
75103f9effdf709fc8f2548ecf39cefb c:\Program Files\baidu\BDPlayer\5.1.1.9\BDPlayerTray.exe
2597d45148235b2958f8fd6166f28666 c:\Program Files\baidu\BDPlayer\5.1.1.9\BDWebcore.dll
98e0bfb9f5d7e894bfd0b8347a760277 c:\Program Files\baidu\BDPlayer\5.1.1.9\FFAudio.ax
99d64d510d6a9cf3d4b35ec3c4dae179 c:\Program Files\baidu\BDPlayer\5.1.1.9\FFSplitter.ax
5cb8ef1e4d7c6e00e6298dd932e876cf c:\Program Files\baidu\BDPlayer\5.1.1.9\FFVideo.ax
2f8bf7b7bb60625b84d333a7e39944fb c:\Program Files\baidu\BDPlayer\5.1.1.9\IntelQuickSyncDecoder.dll
fa27e0a28527bcbb1b0434566e0ebb77 c:\Program Files\baidu\BDPlayer\5.1.1.9\OpenMediaUrl.exe
76af45eb35e2a5192a92fada8c16aab6 c:\Program Files\baidu\BDPlayer\5.1.1.9\PlayerApp.exe
a3a86d1ae771381bee3ed99bc08b3662 c:\Program Files\baidu\BDPlayer\5.1.1.9\avcodec-lav-56.dll
6833b6e05d2559dcbc4c224d3f0744b6 c:\Program Files\baidu\BDPlayer\5.1.1.9\avfilter-lav-5.dll
3250ca6fb2753dc8aa3dc0980db796f8 c:\Program Files\baidu\BDPlayer\5.1.1.9\avformat-lav-56.dll
a5600d8d5cf82fc2c6746f6a8f2142d3 c:\Program Files\baidu\BDPlayer\5.1.1.9\avresample-lav-2.dll
99de62d3e488e808d8a2c97081dfa819 c:\Program Files\baidu\BDPlayer\5.1.1.9\avutil-lav-54.dll
23be28e724ad20eac255eae1ef245d8d c:\Program Files\baidu\BDPlayer\5.1.1.9\bdcommon.dll
5a645642c53e287e60deaa81eb82377f c:\Program Files\baidu\BDPlayer\5.1.1.9\bdlog.dll
102a1039c2a9678518b5734f964fb34c c:\Program Files\baidu\BDPlayer\5.1.1.9\bdxlogic.dll
1e5a78d11d33250e41a22c9f923d16af c:\Program Files\baidu\BDPlayer\5.1.1.9\bdxplayer.dll
1ba063952c75a0824152d8311453d84c c:\Program Files\baidu\BDPlayer\5.1.1.9\bdxview.dll
00cadf917243eba532cae5b443e9b4f4 c:\Program Files\baidu\BDPlayer\5.1.1.9\bugreport.exe
0facb9af0f2db15ff1c122d3912ebdf7 c:\Program Files\baidu\BDPlayer\5.1.1.9\codecs\AudioSwitcher.ax
43693b826cc75b25c00443c398fbadc4 c:\Program Files\baidu\BDPlayer\5.1.1.9\codecs\CoreAAC.ax
74202e220a8e3e15e78342883e01e3ce c:\Program Files\baidu\BDPlayer\5.1.1.9\codecs\FLVSplitter.ax
6356cf87dcaec250e4f8ea509a6c8de9 c:\Program Files\baidu\BDPlayer\5.1.1.9\codecs\MpaDec.ax
f075f75818649aec518368d0ce243b86 c:\Program Files\baidu\BDPlayer\5.1.1.9\codecs\RealMediaSplitter.ax
e07f7761fc3ebf851b461517d88633c0 c:\Program Files\baidu\BDPlayer\5.1.1.9\codecs\VEFilter.ax
3f21bc0af3e228a17cc340f9c215e141 c:\Program Files\baidu\BDPlayer\5.1.1.9\codecs\VSFilter.dll
763146c0f6090fad64f2eead0c8cff81 c:\Program Files\baidu\BDPlayer\5.1.1.9\codecs\real\cook.dll
5e2088c262d7eec20cbb98c0590f759e c:\Program Files\baidu\BDPlayer\5.1.1.9\codecs\real\drvc.dll
b81c2b0821d2791f0d8a2231468c4962 c:\Program Files\baidu\BDPlayer\5.1.1.9\ffsrv.exe
3be86f5a8f3c8695b15b6815b645512e c:\Program Files\baidu\BDPlayer\5.1.1.9\fileinfo.dll
7a15d3c1a52fd228bdf8e0420998fcb9 c:\Program Files\baidu\BDPlayer\5.1.1.9\libbluray.dll
fd5cabbe52272bd76007b68186ebaf00 c:\Program Files\baidu\BDPlayer\5.1.1.9\msvcp120.dll
034ccadc1c073e4216e9466b720f9849 c:\Program Files\baidu\BDPlayer\5.1.1.9\msvcr120.dll
24135e695aaa9ed3cb0016f094a1ec85 c:\Program Files\baidu\BDPlayer\5.1.1.9\pncrt.dll
bebedf69eb577f0856a57bf6e6ce5de9 c:\Program Files\baidu\BDPlayer\5.1.1.9\swscale-lav-3.dll
59111e6e54d150e7674c808eba53902a c:\Program Files\baidu\BDPlayer\5.1.1.9\xReport.exe
7ef132767873cc3722a934c98c1665fc c:\Program Files\baidu\BDPlayer\5.1.1.9\xUpdate.exe
0ef763e21d463ad7aebdae71dc379b68 c:\Program Files\baidu\BDPlayer\5.1.1.9\xmanager.dll
e1c419dc4c188ccb90d573a32c47fc4b c:\Program Files\baidu\BDPlayer\5.1.1.9\xnet.dll
d819753030d9c355b85cf36ee3266411 c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433[1].exe
0fe441c8331ebe24dbc9d16177df24a4 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\BaiduPlayer5SetupSilent_363.exe
d819753030d9c355b85cf36ee3266411 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Browser_V5.5.7852.9_r_4640_(Build1512022057).exe
15907c8e335563c313de6d7c86df99e5 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\V8._85296_20150814221218.exe
f0e3845fefd227d7f1101850410ec849 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\Base64.dll
50fdadda3e993688401f6f1108fabdb4 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\Inetc.dll
00a0194c20ee912257df53bfe258ee4a c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\System.dll
2dc35ddcabcb2b24919b9afae4ec3091 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\ZipDLL.dll
16ae0a59da95783599969cb2a8cd7b0d c:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12\QBSafe.dll
4c39358ebdd2ffcd9132a30e1ec31e16 c:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\Microsoft.VC90.CRT\msvcp90.dll
cdbe9690cf2b8409facad94fac9479c9 c:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\Microsoft.VC90.CRT\msvcr90.dll
268905b968aace3dbaf5dd97391071e9 c:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\QBUtils.dll
4c39358ebdd2ffcd9132a30e1ec31e16 c:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\Microsoft.VC90.CRT\msvcp90.dll
cdbe9690cf2b8409facad94fac9479c9 c:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\Microsoft.VC90.CRT\msvcr90.dll
268905b968aace3dbaf5dd97391071e9 c:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\QBUtils.dll
acd46c8f29be4cc5f659b87f115c740c c:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\QQBrowserLiveup.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

No information is available.

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 23414 23552 4.51428 dd4fbe36a428138cf367ad0780b2d5a5
.rdata 28672 4496 4608 3.59023 4e7f519777030dd2f0ea0d2092babed3
.data 36864 3774360 1024 3.20074 3f3791a671d7e3b37b55f9b9d4c54c5c
.ndata 3813376 36864 0 0 d41d8cd98f00b204e9800998ecf8427e
.rsrc 3850240 16456 16896 2.38038 13c0cd4a042be7a3758f0cf8f7b073ec

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://ww1.sinaimg.cn.gccdn.net/large/7185bdf1gw1f05vp3ys4ig20s60i07ww.gif
hxxp://ww1.sinaimg.cn.gccdn.net/large/7185bdf1gw1f05vpdktqrg20go0a5u10.gif
hxxp://orp5.n.shifen.com/p.gif?app=baiduplayer5&pccode=C_0-D_0-M_0050563BAEAC-V_10F5F7ED&r=131394116079720000&op=install&ver=5.1.1.9&ch=363&module=BaiduPlayer5SetupSilent_363
hxxp://tiger.mig.tencent-cloud.net/accept?authcode=1771558448&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819&supplyid=85296&IEVer=9&osVer=6.1.1&osDigit=32&psver=3&appId=3&cver=8.2.3638.400
hxxp://orp5.n.shifen.com/p.gif?app=baiduplayer5&pccode=C_0-D_0-M_0050563BAEAC-V_10F5F7ED&r=131394116181120000&op=lauch&ext=toolbar&ver=5.1.1.9&ch=363&module=BDPlayerTray
hxxp://x2.tcdn.qq.com/qbfilepush/qqbrowser/cloudctrl/production/1415626007_8983.txt?&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819
hxxp://down.qq.com/browser/btr/qqbrowser/ps/production/65_13_2013-11-28.CompatList?&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819
hxxp://203.205.151.214/soft.imtt.qq.com/browser/btr/qqbrowser/ps/production/65_13_2013-11-28.CompatList?mkey=591ae180da60d437&f=6606&c=0&&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819&p=.CompatList
hxxp://down.qq.com/browser/qqbrowser/cloudctrl/production/1411441978_1508.{B3D2254B-BB47-4d2f-B015-CDDE79BAD110}?&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819
hxxp://203.205.151.213/soft.imtt.qq.com/browser/qqbrowser/cloudctrl/production/1411441978_1508.{B3D2254B-BB47-4d2f-B015-CDDE79BAD110}?mkey=591ae182da60d437&f=6606&c=0&&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819&p=.{B3D2254B-BB47-4d2f-B015-CDDE79BAD110}
hxxp://e8218.dscb1.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c=
hxxp://tank.mig.tencent-cloud.net/
hxxp://e8218.dscb1.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEHFwvZPPPxia5kUrUUxJNA4=
hxxp://dns.union.uc.cn/pcbrowser/down.php?pid=4640
hxxp://umcdn.uc.cn.w.alikunlun.com/down/4640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.exe 188.254.86.253
hxxp://wow.uc.cn.danuoyi.alicdn.com/biz-data/sec/channel/test/config/av_config.ini 195.27.31.253
hxxp://dns.union.uc.cn/pcbrowser/down.php?type=dll&pid=4640
hxxp://wow.uc.cn.danuoyi.alicdn.com/down/4640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.dll 195.27.31.253
hxxp://update.p2sp.n.shifen.com/BDPlayer/5.1.1.9_363.xml
hxxp://player.video.n.shifen.com/Browser/DLCfg.png
hxxp://bos.jomodns.com/v1/baiduplayer/player/BDPlayer5.6.2.16_145.exe
hxxp://183.91.33.51/boscdn.bpc.baidu.com/v1/baiduplayer/player/BDPlayer5.6.2.16_145.exe
hxxp://gpla1.wac.v2cdn.net/CRL/Omniroot2025.crl
hxxp://ww3.sinaimg.cn/large/7185bdf1gw1f05vpdktqrg20go0a5u10.gif 151.249.91.213
hxxp://wow.uc.cn/biz-data/sec/channel/test/config/av_config.ini 195.27.31.253
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= 23.46.123.27
hxxp://boscdn.bpc.baidu.com/v1/baiduplayer/player/BDPlayer5.6.2.16_145.exe 59.38.112.38
hxxp://umcdn.uc.cn/down/4640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.exe 188.254.86.253
hxxp://cdp1.public-trust.com/CRL/Omniroot2025.crl 93.184.220.20
hxxp://down2.uc.cn/pcbrowser/down.php?type=dll&pid=4640 123.150.188.19
hxxp://stat.v.baidu.com/p.gif?app=baiduplayer5&pccode=C_0-D_0-M_0050563BAEAC-V_10F5F7ED&r=131394116079720000&op=install&ver=5.1.1.9&ch=363&module=BaiduPlayer5SetupSilent_363 112.80.248.40
hxxp://stat.v.baidu.com/p.gif?app=baiduplayer5&pccode=C_0-D_0-M_0050563BAEAC-V_10F5F7ED&r=131394116181120000&op=lauch&ext=toolbar&ver=5.1.1.9&ch=363&module=BDPlayerTray 112.80.248.40
hxxp://soft.imtt.qq.com/browser/btr/qqbrowser/ps/production/65_13_2013-11-28.CompatList?&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819 103.7.30.45
hxxp://down2.uc.cn/pcbrowser/down.php?pid=4640 123.150.188.19
hxxp://res.imtt.qq.com/qbfilepush/qqbrowser/cloudctrl/production/1415626007_8983.txt?&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819 203.205.158.60
hxxp://ikan.baidu.com/Browser/DLCfg.png 111.202.114.114
hxxp://ps.browser.qq.com/accept?authcode=1771558448&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819&supplyid=85296&IEVer=9&osVer=6.1.1&osDigit=32&psver=3&appId=3&cver=8.2.3638.400 103.7.30.156
hxxp://ww4.sinaimg.cn/large/7185bdf1gw1f05vp3ys4ig20s60i07ww.gif 151.249.91.54
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEHFwvZPPPxia5kUrUUxJNA4= 23.46.123.27
hxxp://qbwup.imtt.qq.com/ 14.17.37.155
hxxp://update.p2sp.baidu.com/BDPlayer/5.1.1.9_363.xml 123.125.112.24
hxxp://soft.imtt.qq.com/browser/qqbrowser/cloudctrl/production/1411441978_1508.{B3D2254B-BB47-4d2f-B015-CDDE79BAD110}?&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819 103.7.30.45
hxxp://umcdn.uc.cn/down/4640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.dll 188.254.86.253
browser.etl.desktop.qq.com 119.147.201.16
pc5.gtimg.com 203.205.158.63
media.p2sp.baidu.com 220.181.57.105
tmedia.p2sp.baidu.com 123.125.113.30
www.qq.com 2.21.89.43
s.p2sp.baidu.com 123.125.113.30


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers
ET POLICY PE EXE or DLL Windows file download HTTP
ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected
ET TROJAN VMProtect Packed Binary Inbound via HTTP - Likely Hostile

Traffic

POST / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: qbwup.imtt.qq.com
Content-Length: 366
Cache-Control: no-cache

...n..,<LV.qbpcstatf.stat}...K.....crypt...
list<char>....-
...(:.y.e....:.'.........^.I.T..8..w#....2\.D..Q.N..Q.W..-.c.....2l.....A.Q*...[[Ng.
.r....*.
...i.....k.
x......w...{
..fq.>.#.:%.L..e7QI..>....2b..((..~H....Fpl0.
a.z......2.-a.&..Q.%....v......d..c..kQ~..>.f>..e...(....!.{).=...J....o..Bb..x..r.`...O.*..&...B.@z..@..op.......<.P...R.).m8J..F....
HTTP/1.1 200 OK
Content-Length: 54
Content-Type: application/multipart-formdata
Date: Tue, 16 May 2017 09:34:04 GMT
Server: HTTP Load Balancer/1.0
...6..,<LV.qbpcstatf.stat}.............int32..........HTTP/1.1 200 
OK..Content-Length: 54..Content-Type: application/multipart-formdata..
Date: Tue, 16 May 2017 09:34:04 GMT..Server: HTTP Load Balancer/1.0...
..6..,<LV.qbpcstatf.stat}.............int32............


GET /soft.imtt.qq.com/browser/btr/qqbrowser/ps/production/65_13_2013-11-28.CompatList?mkey=591ae180da60d437&f=6606&c=0&&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819&p=.CompatList HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: 203.205.151.214
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: 3Gdown_DK
Connection: keep-alive
Date: Tue, 16 May 2017 09:33:43 GMT
Cache-Control: max-age=0
Last-Modified: Thu, 28 Nov 2013 07:13:06 GMT
Content-Type: application/octet-stream
Content-Length: 6712
X-Cache-Lookup: Hit From Disktank
Access-Control-Allow-Origin: *
..#.F...#K.`../.....k7.8.!w..^rs.w...g.f......IJ..!%... .GK.....Q4....
.....C...?.fd[r^..w...V.v.....s... .....C.[..p....i*&#/.S...As..rM.PXH
}....WAAm....^`.A..6.d.eHH2....\.i..q.*.....w..G.......:P&7.u...rcZ..[
..._.'....}.rq5.Z..%...D.];..j0.........$5.c&..$c.#.]...l[........7...
....w..|..q.L...........o.....WC....H..y..U!@3...e..a.."m..........-x.
..`.:Z......|~k6...v..zOk2D.[.;r],=..4..KT}.....J.u....?0...>....?.
.]..@.AG.^.C...,6;.<.J0...5...Mv.9a..,.rn..b...2.........'4.....Y..
.....9.X.#.O.,...S...@..B..z .....R]l..Q-.u.a...V....X-...A..:W..4.U..
a.....)\....p$>.[.....RBd.....9.7#.l.X.!.A...._<..twM....;..{%W.
.z].. Ch.........y.L..&~Q<c.x..."n...A9.R..7.x......|.j......,K.!H~
... Z...}..Q...D%2...'..EO....x..6A#.t.5.....; u...>....m..eY....uE
Qf.x...u.kB.`...[..M.X......8..gh.p.o...-z.FT5.......<..O.f..j.2..W
..........N.t....|.....%.^..7.g..2wZ.`:.R....vU...!P.L.N.X...OJk.b....
k...&!xE.a.;.......D...A.'. )......H%C.O.P...s@ .p.....~..H~'.y2pL.@(.
F.w.-50k..?..."u.i5..u.h......@.;...\.30g...3....dS..-<..1....%l...
*.h....hZ6.e........&*A....|..xp.c...JbL...@2......^.p..6....h....N1]%
=..9.@..eW....2 .Cv..m.......#.o2A..c"..........Z.wi...0..G..'...b....
.;.ut /x"B.J.h..(U..H.D......q......8.m..N..h.Gd.3M....Y\*..;4g...=.E.
....^Q....I..../.\.....c.3b=zZ8..J*......jv.Pn..>..s.8..W>...D.$
.H.d...W......K.:Rj...g..K.....p#. .b....!m.|.$.x, :u..}...B...;...<
;.<T\..9nS"...m.I....w............t..._..;T......^.......].'.*.l.&g
t;...*..@s._.d..}h....#..X......6.....&.b..........I_.b....f>.s

<<< skipped >>>

GET /p.gif?app=baiduplayer5&pccode=C_0-D_0-M_0050563BAEAC-V_10F5F7ED&r=131394116079720000&op=install&ver=5.1.1.9&ch=363&module=BaiduPlayer5SetupSilent_363 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727))
Host: stat.v.baidu.com
Accept: */*
Connection: close


HTTP/1.1 200 OK
Date: Tue, 16 May 2017 09:33:29 GMT
Content-Type: image/gif
Transfer-Encoding: chunked
Connection: close
Set-Cookie: BAIDUID=98837330AC3D369578087780099E99B0:FG=1; expires=Wed, 16-May-18 09:33:29 GMT; max-age=31536000; path=/; domain=.baidu.com; version=1
P3P: CP=" OTI DSP COR IVA OUR IND COM "
Server: Apache
tracecode: 20093335460383832074051617
Set-Cookie: BAIDUID=8D4BDBE257751AF42E28FB16A882D317:FG=1; expires=Wed, 16-May-18 09:33:29 GMT; max-age=31536000; path=/; domain=.baidu.com; version=1
P3P: CP=" OTI DSP COR IVA OUR IND COM "
0..


GET /v1/baiduplayer/player/BDPlayer5.6.2.16_145.exe HTTP/1.1
Host: boscdn.bpc.baidu.com
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
Range: bytes=0-15
Connection: Keep-Alive


HTTP/1.1 302 Found
Server: SRS/2.0
Date: Tue, 16 Aug 2017 09:34:25 GMT
Content-Length: 0
Content-Type: text/html
Connection: close
Cache-Control: no-cache
Location: hXXp://183.91.33.51/boscdn.bpc.baidu.com/v1/baiduplayer/player/BDPlayer5.6.2.16_145.exe
: Thu, 18 May 2017 08:21:07 GMT..Age: 90798..Content-Range: bytes 0-15
/59265928..Accept-Ranges: bytes..x-bce-debug-id: MTAuMjA1LjkyLjQ5Ok1vb
iwgMjAgRmViIDIwMTcgMTY6MjA6NTkgQ1NUOjEyNTkyMzE2MzE=..x-bce-request-id:
b378d320-ecf8-4bb1-9add-0df7de7e9ec1..Ohc-Response-Time: 1 0 0 0 0 0.
.MZ................


GET /v1/baiduplayer/player/BDPlayer5.6.2.16_145.exe HTTP/1.1
Host: boscdn.bpc.baidu.com
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
Range: bytes=0-15
Connection: Keep-Alive


HTTP/1.1 206 Partial Content
Server: JSP3/2.0.14
Date: Tue, 16 May 2017 09:34:22 GMT
Content-Type: application/x-msdownload
Content-Length: 16
Connection: close
ETag: "-04042e41b293b61c9dca3f285f86ca7d"
Last-Modified: Mon, 20 Feb 2017 06:39:01 GMT
Expires: Thu, 18 May 2017 08:21:07 GMT
Age: 90795
Content-Range: bytes 0-15/59265928
Accept-Ranges: bytes
x-bce-debug-id: MTAuMjA1LjkyLjQ5Ok1vbiwgMjAgRmViIDIwMTcgMTY6MjA6NTkgQ1NUOjEyNTkyMzE2MzE=
x-bce-request-id: b378d320-ecf8-4bb1-9add-0df7de7e9ec1
Ohc-Response-Time: 1 0 0 0 0 0
MZ................


POST / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: qbwup.imtt.qq.com
Content-Length: 438
Cache-Control: no-cache

......,<LV.qbpcstatf.stat}.........crypt...
list<char>....u
...p:.y.e....:.'.........^.I.T..8..w#....2\.D..Q.N..Q.W..-.c..... ......A.Q*...[[Ng.
.r....*.
...i.....k.
x......w...{
..fq.>.#.:%.L..e7QI..>....2b..((..~H....Fpl0.
a.z......2.-a.&..Q.%....v...p.UM.6Am..w...E......../. .sJ.F..m...e.........:....]..O
.L........;y.Tse.j..@eT.C[F|V~..(....8..y.[J.
..Z.=.V.A
0...N.6V
..4S&Qn\.:y..q...6....k..l"S..kliw.z.D........y.v.J...
HTTP/1.1 200 OK
Content-Length: 54
Content-Type: application/multipart-formdata
Date: Tue, 16 May 2017 09:33:59 GMT
Server: HTTP Load Balancer/1.0
...6..,<LV.qbpcstatf.stat}.............int32..........HTTP/1.1 200 
OK..Content-Length: 54..Content-Type: application/multipart-formdata..
Date: Tue, 16 May 2017 09:33:59 GMT..Server: HTTP Load Balancer/1.0...
..6..,<LV.qbpcstatf.stat}.............int32............


GET /p.gif?app=baiduplayer5&pccode=C_0-D_0-M_0050563BAEAC-V_10F5F7ED&r=131394116181120000&op=lauch&ext=toolbar&ver=5.1.1.9&ch=363&module=BDPlayerTray HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727))
Host: stat.v.baidu.com
Accept: */*
Connection: close


HTTP/1.1 200 OK
Date: Tue, 16 May 2017 09:33:38 GMT
Content-Type: image/gif
Transfer-Encoding: chunked
Connection: close
Set-Cookie: BAIDUID=2D365B46F78E06FC27CA228FAA4C36EF:FG=1; expires=Wed, 16-May-18 09:33:38 GMT; max-age=31536000; path=/; domain=.baidu.com; version=1
P3P: CP=" OTI DSP COR IVA OUR IND COM "
Server: Apache
tracecode: 20186941040383832074051617
Set-Cookie: BAIDUID=A7F162EA7C657BC26F6BF0B34FA31124:FG=1; expires=Wed, 16-May-18 09:33:38 GMT; max-age=31536000; path=/; domain=.baidu.com; version=1
P3P: CP=" OTI DSP COR IVA OUR IND COM "
0..


GET /large/7185bdf1gw1f05vp3ys4ig20s60i07ww.gif HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: ww4.sinaimg.cn
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Tue, 16 May 2017 09:33:11 GMT
Server: PWS/8.2.0.7
X-Px: ms h0-s45.p1-arn ( h0-s34.p1-arn), ms h0-s34.p1-arn ( h0-s1662.p0-kix), ht-d h0-s1662.p0-kix.cdngp.net
Cache-Control: max-age=7776000
Expires: Thu, 10 Aug 2017 14:42:13 GMT
Age: 327059
Accept-Ranges: bytes
Content-Length: 17013252
Content-Type: image/gif
Last-Modified: Mon, 08 Jul 2013 18:06:40 GMT
X-Via-CDN: f=TXCDN,s=151.249.91.54,c=194.242.96.218
Connection: keep-alive
GIF89a............U&..N.._......... ..(....pj&...... "...... VJ3...,1.
.......o..../:E.%.....@..f/..f.Ojg.....O;9....U4$.........n...Q.Q.f.XN
4......{.............v'..}xN".. ...Zbj.|e.vg..z))1.K N ..4x..p#.......
........sf;...%:hL6..i.......kI.3f$...4i........1.f3....xu>=16!...^
..n.sV};.S%.<.ca...t....CCI..N......ojm....T.pfd.w....w...TN3......
.$w5<.......0W..J....i8..N.pG.oSOOV11:.z.......^........wVPg\Bu.#..
D.wdpfY`.......m.==1..:(..Rt.......jb.D(X9)...f33..L...l............_.
V......ff....uZb..!!*...333......8Si....Tb{....;..!......fPMC..4RH...7
...<G.x..39vR?......m;..............s.x......T4.m........dWk.}.....
..hQ#......o7thF.p2RKJ.wN..l..........".8...k2[..8..82)2!#.....L.....p
..~vwy{.....cC9.....6..kfZ\::B.?B.H}...`8.....WN...)))...l........|;'.
........2{..n|i&...p.fK!.......,...............H......*\.......N.H....
.3j...... C..I....(S.D.....0c..I....8s.....O.`...J....H.*].....P.J.J..
T.X.j......`....U...h..].....p...K....x............L...... ^......#;.C
.....3k.......%..M.....S.^......c.....^..s....0.......GG.... _........
..7....O....;h......O.....WO......y.;...........?............}.&....6.
b.=(a...haQ.N....v.!r.......H..(.V..,.A_}).(..4.8.:..Q"a&.R..?6.D.D6
..5&...-....PF)....h....F..0..e......U@.W.......L d......pLp$.52...V..
...n......&d.v..a....b....!.l..<Fn#d......d...<Wbzh......}....T.
. k.z.Z._..j v...hi....a...(b.... .TQd.Mp.N....L0@.QM. .Q....:...Zx...
.;#.....u:|...\....."V...Y.i: \Z....`m...#N.!....$..b.w.. ...x...w.`.}
.....fw..'.v/.Y..hbXV.f.p.........y..p....B......;z. ......PG.....

<<< skipped >>>

GET /Browser/DLCfg.png HTTP/1.1
Host: ikan.baidu.com
Accept: */*
Connection: close


HTTP/1.1 200 OK
Date: Tue, 16 May 2017 09:34:18 GMT
Content-Type: image/png
Content-Length: 167
Last-Modified: Tue, 16 Aug 2016 06:22:58 GMT
Connection: close
ETag: "57b2b142-a7"
Set-Cookie: BAIDUID=90B739E93941C85CF69718B7FA714F3B:FG=1; expires=Wed, 16-May-18 09:34:18 GMT; max-age=31536000; path=/; domain=.baidu.com; version=1
P3P: CP=" OTI DSP COR IVA OUR IND COM "
Server: Apache
Accept-Ranges: bytes
[Cloud]..Enable=1..Always=1..Skip=1..CloudSpeedL1=200..SeedCount=10..C
loudSpeedL2=30..MinFetch=3..PreBuffer=1..PreDownload=0..CareLog=0..Dra
gLimit=200..[P2P]..Exit=0....


GET /BDPlayer/5.1.1.9_363.xml HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727))
Host: update.p2sp.baidu.com
Accept: */*
Connection: close


HTTP/1.1 200 OK
Date: Tue, 16 May 2017 09:34:18 GMT
Server: WSGIServer/0.1 Python/2.7.3
Content-type: text/html; charset=utf8
Content-Length: 767
Connection: close
<?xml version="1.0" encoding="UTF-8"?>..<root>...<upgra
de>.. <p2purl>bdhd://59265928|5E85A35C0A630F71C80E4D9B
26FF3C50|BDPlayer5.6.2.16_145.exe</p2purl>....<p2surl>http
://boscdn.bpc.baidu.com/v1/baiduplayer/player/BDPlayer5.6.2.16_145.exe
</p2surl>....<md5>7DC36684ADBF09AEB84B2F74BD9FE5AB</md5
>....<param>/S /Q /AUTOUPDATE</param>....<changelog&
gt;\n1...........................................\n2.............ASF..
............................\n3.........................,.............
........\n4....................................................\n5....
...............bug........................</changelog>....<mo
de>Auto</mode>.. <bindtitle>....................
....</bindtitle>.. <ver>5.6.2.16</ver>..
<show>1</show>...</upgrade>..</root>....


GET /soft.imtt.qq.com/browser/qqbrowser/cloudctrl/production/1411441978_1508.{B3D2254B-BB47-4d2f-B015-CDDE79BAD110}?mkey=591ae182da60d437&f=6606&c=0&&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819&p=.{B3D2254B-BB47-4d2f-B015-CDDE79BAD110} HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: 203.205.151.213
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: 3Gdown_DK
Connection: keep-alive
Date: Tue, 16 May 2017 09:33:45 GMT
Cache-Control: max-age=0
Last-Modified: Tue, 23 Sep 2014 03:12:59 GMT
Content-Type: application/octet-stream
Content-Length: 2144
X-Cache-Lookup: Hit From Disktank
Access-Control-Allow-Origin: *
T.Qx.n.-.-.....n-.FY...1.\...X.......L...v.m< 7...G.....5..J....O(.
%.:U.. u.p.^..Q............47.x.t..{R4.b...... ......U....{.7.....A.A.
.i.........K.....IPU........Q.....%o..!:m.. ...6U1X.).....n..d........
..D.Z.O.on@B.8k]..AB2....nI..G.H. p. ......5}>.g..H....8M..!s....|5
.}.....7.?..RJ.`.*?qQ.[E.........u|.....'..kV..Z.....w..R...x..0.]...`
.8h...;...SbLa.1.....PU.:..<s...5..)G....].PN ...a.A.X..n...X[^)...
......Q..........<.0H,~Hg9.*.,.1.]..pdo/)h^u...c...x. u.PJ..;..E.?.
v..u.S..wdoF.pt.W..n......{o...g....|...uji.N.....i...5Q_..cA.HG...BG.
....6.a....,. ....T.3w....ZLn.[<.}...S.......(...N.)?n~...{.._!h}A.
...C.2.P.....7L...&...L...s2.*.p..i.....2....*....>..... yP........
..x..... K.'@.PH.....x.0`;.M.Te.g{..7X.f......:g....V..!..T..........n
.X.r=..2..u....C..q.`..B9..$...V5..>....Q_........~.....-u.Xt..jb..
.GhUm{....U.{.........Q.....?....B..y.)d......."..G..v..g...B9/.(.....
....l.. ..!dsa....I....?........,.X).\..X..O.].Vck../........Q.....6.N
...5}>.g.`...H.R.M..;........6..<......J.....>E....#wB. ..8..
.}.X&..Z*?.c.W_[.....l.b.D&k.3......qz{..$a.p.4.F;.....|.....\R.....|7
.eW.....P..J....#zkE....zv._bf..*z......$.r..17..5o.y..Ci...6y.....o..
...zj.6cZ-..{...e./...9..n....f...I...p..N....D.7..(..5[....0.#.`$....
}.H....a .bFib.......W*....w.t..G..s2.*.p. ~../...8...1)C;?.@$...O..B.
1...M..PI......\...1..4A..!6M..;......$.r..17..5o.y..Ci...6y.....o....
.zj.6cZ-..{...e./...9..n....f...I...p..N....D.7..(..5[....0.#.`$....}.
...d...[..zv._bf...o..#..D!.D .\f.5ZvWFE..zv._bf..zv._bf;....}i...

<<< skipped >>>

GET /CRL/Omniroot2025.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Sat, 16 Nov 2013 06:15:02 GMT
If-None-Match: "200da-5b6-4eb453c33260e"
User-Agent: Microsoft-CryptoAPI/6.1
Host: cdp1.public-trust.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: application/x-pkcs7-crl
Date: Tue, 16 May 2017 09:34:26 GMT
Etag: "200da-f1d-54f1f50c67acc"
Last-Modified: Tue, 09 May 2017 23:00:01 GMT
Server: ECS (fcn/418B)
X-Cache: HIT
Content-Length: 3869
0...0......0...*.H........0Z1.0...U....IE1.0...U....Baltimore1.0...U..
..CyberTrust1"0 ..U....Baltimore CyberTrust Root..170509201635Z..17080
4201635Z0..`0....'k...120111220757Z0....'k...120111220847Z0....'.C..13
0130174530Z0....'....130807173059Z0....'....140122185220Z0....'....140
212185542Z0....'yr..150701184507Z0....'#...100303201301Z0....''q..1004
14175202Z0....'L...110224181251Z0....'Pn..110309142119Z0....'....10021
6203312Z0....'#...100303201213Z0....'3#..100908172555Z0....''n..101208
175627Z0....''m..101208175749Z0....''p..101208175916Z0....'H...1101141
62156Z0#...'X>..110815145134Z0.0...U.......0#...'Z2..110818184101Z0
.0...U.......0....'g...120111164333Z0....'g...120111164409Z0....'g...1
20111164519Z0....'....100216213519Z0....''s..100414175225Z0....''k..10
0414181839Z0....'3"..100908172705Z0....'3$..100908172728Z0....''o..101
208175645Z0....''l..101208175727Z0....'H...110119195142Z0....'Nz..1103
02154045Z0....'c...111207220933Z0....'g...120111164445Z0....''r..10041
4175143Z0....'8...101012182723Z0....'e...120111163041Z0....'VJ..110714
160903Z0....'s...130123162633Z0....'....130904190524Z0....'....1310242
14319Z0....'....140129172435Z0....'....140129172453Z0....'....13102421
4310Z0....'....131101204601Z0....'....140219171632Z0....'.^..140409155
638Z0....'i...140709171930Z0....'/:..141119193302Z0....'J...1506031846
05Z0....'k...150603185020Z0....'k...150603185058Z0....'k...15060318513
1Z0....'k...120111220827Z0....'8...140716191203Z0....'....131219195909
Z0....'....140219171545Z0....'k...151105070000Z0....'q...160126173

<<< skipped >>>

GET /biz-data/sec/channel/test/config/av_config.ini HTTP/1.1
Accept: */*
Content-Length: 0
User-Agent: ChannelPromptDownloader
Host: wow.uc.cn
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: Tengine
Content-Type: application/octet-stream
Content-Length: 32
Connection: keep-alive
Date: Tue, 16 May 2017 08:25:17 GMT
x-oss-request-id: 591AB76D004C455622C41DFD
Accept-Ranges: bytes
ETag: "54038E4A450A3F429405CCBE0DBFCFAE"
Last-Modified: Fri, 24 Feb 2017 08:50:01 GMT
x-oss-object-type: Normal
x-oss-hash-crc64ecma: 10919123851284209732
Content-MD5: VAOOSkUKP0KUBcy Db/Prg==
x-oss-server-time: 2
Via: cache26.l2hk1[0,304-0,H], cache26.l2hk1[1,0], cache1.de1[0,200-0,H], cache9.de1[0,0]
Age: 4126
X-Cache: HIT TCP_MEM_HIT dirn:4:267288821
X-Swift-SaveTime: Tue, 16 May 2017 09:09:43 GMT
X-Swift-CacheTime: 3600
Timing-Allow-Origin: *
EagleId: c31b1fd114949272434063990e
[base]..anti=1..set_d=1..set_m=0HTTP/1.1 200 OK..Server: Tengine..Cont
ent-Type: application/octet-stream..Content-Length: 32..Connection: ke
ep-alive..Date: Tue, 16 May 2017 08:25:17 GMT..x-oss-request-id: 591AB
76D004C455622C41DFD..Accept-Ranges: bytes..ETag: "54038E4A450A3F429405
CCBE0DBFCFAE"..Last-Modified: Fri, 24 Feb 2017 08:50:01 GMT..x-oss-obj
ect-type: Normal..x-oss-hash-crc64ecma: 10919123851284209732..Content-
MD5: VAOOSkUKP0KUBcy Db/Prg==..x-oss-server-time: 2..Via: cache26.l2hk
1[0,304-0,H], cache26.l2hk1[1,0], cache1.de1[0,200-0,H], cache9.de1[0,
0]..Age: 4126..X-Cache: HIT TCP_MEM_HIT dirn:4:267288821..X-Swift-Save
Time: Tue, 16 May 2017 09:09:43 GMT..X-Swift-CacheTime: 3600..Timing-A
llow-Origin: *..EagleId: c31b1fd114949272434063990e..[base]..anti=1..s
et_d=1..set_m=0..


GET /browser/qqbrowser/cloudctrl/production/1411441978_1508.{B3D2254B-BB47-4d2f-B015-CDDE79BAD110}?&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: soft.imtt.qq.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 302 Found
Server: nws 1.2.15
Connection: close
Date: Tue, 16 May 2017 09:33:43 GMT
Expires: Tue, 16 May 2017 09:33:43 GMT
Cache-Control: max-age=0
Content-Length: 0
Location: hXXp://203.205.151.213/soft.imtt.qq.com/browser/qqbrowser/cloudctrl/production/1411441978_1508.{B3D2254B-BB47-4d2f-B015-CDDE79BAD110}?mkey=591ae182da60d437&f=6606&c=0&&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819&p=.{B3D2254B-BB47-4d2f-B015-CDDE79BAD110}


GET /v1/baiduplayer/player/BDPlayer5.6.2.16_145.exe HTTP/1.1
Host: boscdn.bpc.baidu.com
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
Range: bytes=0-59265927
Connection: Keep-Alive


HTTP/1.1 206 Partial Content
Server: JSP3/2.0.14
Date: Tue, 16 May 2017 09:34:23 GMT
Content-Type: application/x-msdownload
Content-Length: 59265928
Connection: close
ETag: "-04042e41b293b61c9dca3f285f86ca7d"
Last-Modified: Mon, 20 Feb 2017 06:39:01 GMT
Expires: Thu, 18 May 2017 08:21:07 GMT
Age: 90796
Content-Range: bytes 0-59265927/59265928
Accept-Ranges: bytes
x-bce-debug-id: MTAuMjA1LjkyLjQ5Ok1vbiwgMjAgRmViIDIwMTcgMTY6MjA6NTkgQ1NUOjEyNTkyMzE2MzE=
x-bce-request-id: b378d320-ecf8-4bb1-9add-0df7de7e9ec1
Ohc-Response-Time: 1 0 0 0 0 0
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$........u....y...y.
..y.?.....y..E....y..E....y..E....y.?.....y.?.....y...x.q.y..F....y..F
....y..F....y.......y..F....y.Rich..y.........................PE..L...
...X.................$....}....."........@....@.......................
................@..........................c..H3..H...@....p..(.w.....
.....8.......@.......F..8...............................@............@
...............................text..._#.......$.................. ..`
.rdata.. v...@...x...(..............@..@.data............,............
......@....rsrc...(.w..p....w.................@..@.reloc.......@......
................@..B..................................................
......................................................................
......................................................................
......................................................................
....................................................1P......h`0K......
Y.....h.0K......Y.....h.1K......Y.....hp1K......Y.....h`1K......Y.....
.....h.2K......Y.................(.P..6...h.2K..c...Y............X/P..
....h 2K..C...Y............./P......h02K..#...Y...........j.../P..t...
h@2K......Y.........j..l0P..T...hP2K......Y.........S...........U.k..l
$...j.h..K.d.....PS......O.3.P.E.d.....j.hd.K...2P......j.h..K...2P..E
......n....E...C..E......E......E.......oE....3P......... 3P.j.h..K..0
3P..E......#...j.h..K...3P..E........E......E......E......E.......

<<< skipped >>>

GET /down/4640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.dll HTTP/1.1
Accept: */*
Connection: Keep-Alive
User-Agent: ChannelPromptDownloader
Cache-Control: no-cache
Host: umcdn.uc.cn


HTTP/1.1 200 OK
Server: Tengine
Content-Type: application/octet-stream
Content-Length: 53410192
Connection: keep-alive
Date: Thu, 11 May 2017 18:49:36 GMT
x-oss-request-id: 5914B240C13CD75B4A4F8D9B
Accept-Ranges: bytes
ETag: "D76F2D8D51D9D7D26C75FE3BF4CC5249"
Last-Modified: Wed, 08 Mar 2017 07:25:11 GMT
x-oss-object-type: Normal
x-oss-hash-crc64ecma: 18016613896755670337
x-oss-storage-class: Standard
Cache-Control: max-age=7776000
Content-MD5: 128tjVHZ19Jsdf479MxSSQ==
x-oss-server-time: 79
Via: cache19.l2sg1[471,200-0,M], cache12.l2sg1[472,0], cache6.de1[0,200-0,H], cache2.de1[2,0]
Age: 398669
X-Cache: HIT TCP_HIT dirn:1:507730825
X-Swift-SaveTime: Thu, 11 May 2017 18:49:37 GMT
X-Swift-CacheTime: 2592000
Timing-Allow-Origin: *
EagleId: c31b1fca14949272451443963e
MZ......................@...................................(.........
..!..L.!This program cannot be run in DOS mode....$.......^!...@t..@t.
.@t......@t.....f@t......@t.!.w..@t.!.p..@t.!.q.<@t.t.q..@t...q..@t
..8...@t..8...@t..@u..@t...}..@t...t..@t......@t..@...@t...v..@t.Rich.
@t.................PE..L......X...........!.....F...|,......!.......`.
.............................. /......!/...@.........................p
...l............`.... ..............3..../.........T..................
.t...........@............`.. ............................text...mE...
....F.................. ..`.rdata.......`.......J..............@..@.da
ta...$"..........................@.t.j.V..........^].....U...M...VW..b
.........;.u=.........s..U........B.#..E......@.=....u;.B.3._^]..._3.^
]...............;.u..........s..._..@..^]...R................U..V.u..F
...F.u..v......j.V........3.^].........U..V.u..F...F.u........jhV.....
...3.^]..........U..j.h.>..d.....PQV.....3.P.E.d........u..F.\....F
.......8....F.$....F......N..E......f(...N..E...Z(...N(.E...N(...FL...
..E...N\.FX..7(.....M.d......Y^..]......U..j.h.?..d.....PV.....3.P.E.d
........v\.........E......NL..t....P.=....u..A..u.j..P...Q...v(......v
.......v..........E......N...t...Q.P..M.d......Y^..]........U...M...VW
..b.........;.u6.........s..E..M......@.=...........A.3._^]..._3.^]...
..............@...;.u..........s..................;.u5.........s..U...
.....B.#..E......@.=....u..B.3._^]..._..@..^]...Q...z...R.._3.^]......
....U..V.u..F...F.u....)...h....V.U......3.^].......U..j.hl?..d...

<<< skipped >>>

GET /browser/btr/qqbrowser/ps/production/65_13_2013-11-28.CompatList?&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: soft.imtt.qq.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 302 Found
Server: nws 1.2.15
Connection: close
Date: Tue, 16 May 2017 09:33:41 GMT
Expires: Tue, 16 May 2017 09:33:41 GMT
Cache-Control: max-age=0
Content-Length: 0
Location: hXXp://203.205.151.214/soft.imtt.qq.com/browser/btr/qqbrowser/ps/production/65_13_2013-11-28.CompatList?mkey=591ae180da60d437&f=6606&c=0&&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819&p=.CompatList


GET /qbfilepush/qqbrowser/cloudctrl/production/1415626007_8983.txt?&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: res.imtt.qq.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: X2_Platform
Connection: keep-alive
Date: Tue, 16 May 2017 09:33:38 GMT
Cache-Control: max-age=86400
Expires: Wed, 17 May 2017 09:33:38 GMT
Last-Modified: Mon, 10 Nov 2014 13:26:48 GMT
Content-Type: text/plain
Content-Length: 45413
X-NWS-LOG-UUID: 072d4433-eb24-4a5e-8ac7-784e4e83ab87
Access-Control-Allow-Origin:  *
X-Cache-Lookup: Hit From Disktank
PK........k..BM..2............bggradient_day.png}Si..a...C... .c...9..
...-..Z....5.|.Njf.3S....d..?....G.....#.AB#..W..."...Y.%...%...y..{..
..-/......*...s..-.]...{W9.L...c...J.|@.R.PM.y...,U.....W_..*..b<^.
..N.yVG).]....Uj..)..H..T1...x*.C.m.g.\. l.AfZ..*j.<.....a...4F..,.
((...D2f..uI9V....C....m..*.l.. ..D.G1.2.u..`4b. ..p...Q..I...MPa..m..
..)......%)L"H4..EKt.P.`.A(.8...Zq1'Q1-'..P.../0a..9H.)...,0.[Vq.)...
6..CbT..t(.....?.e;.......E..0@.@.#......9L..@I......],.../..0d.0B....
...V,.NN.(...v.,Wt.C.z....G..E......1.@1..............8..K....q....@`.
.z...P...Lq/XQ....../.Ed3.?.Y).fG.;.VN:..p....P.5.....w.'yb..y.......`
d.t.[.]Z.u...6z......YS..f8?......'[..0v.H...........#-....Q...s....E;
.9.,9..x...C]N..j.7}N...fi..Y.5..2|....o..k{.m.9....aB.r....s...lz|KJN
...<....mK._o.....`..d......Z.}......a..8k...Y..........x...M..4%V.
<.2Gw....4$.<G...h...XW.h....O.J.....x.s..;.w...-.s3N.M.K..~N?..
....K....l.....-.@....?.._3.g.G.......~.......]...KoP....{_8...d...D[.
..%m......7...3>.[....v.J.*}..r...^*y9.e....,..PK........k..B...c..
..........bgsearch_day.jpg.U.L.e........z.........*u.......,.u3...N...
..P...(.......&n..9.....'.......N7M.n...s...<.].i........?~..w7....
....\...].(47.~D....U..@J./...y....v......V.hE...j3v.v.M.UF.......*..W
......?m.*.A..puucUc.=pC.uK8p.-K.}.......K.%].]m.m.h ..vS{...N......F.
.E.....>..5zx{(... /..U.L..Ri...b1.xs..l.....tam...|.?=.......:....
.:a:.......*C.......l.l....Hw{....=r...G ...;..P;... B7G..!c....'..1..
.'.mk...D...'..4ww...@$ts....s.rG.=.h......M3Y....."7.:x...^.u....

<<< skipped >>>

GET /down/4640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.exe HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: umcdn.uc.cn
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: Tengine
Content-Type: application/octet-stream
Content-Length: 404880
Connection: keep-alive
Date: Tue, 16 May 2017 09:34:00 GMT
x-oss-request-id: 591AC788111091295C6D7CE4
Accept-Ranges: bytes
ETag: "D819753030D9C355B85CF36EE3266411"
Last-Modified: Wed, 08 Mar 2017 07:25:11 GMT
x-oss-object-type: Normal
x-oss-hash-crc64ecma: 5000225178610041071
x-oss-storage-class: Standard
Cache-Control: max-age=7776000
Content-MD5: 2Bl1MDDZw1W4XPNu4yZkEQ==
x-oss-server-time: 334
Via: cache7.l2sg1[734,200-0,M], cache12.l2sg1[735,0], cache8.ru1[1684,200-0,M], cache6.ru1[1696,0]
X-Cache: MISS TCP_MISS dirn:-2:-2
X-Swift-SaveTime: Tue, 16 May 2017 09:34:01 GMT
X-Swift-CacheTime: 2592000
Timing-Allow-Origin: *
EagleId: bcfe56ce14949272397237744e
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.........h..{...{..
.{..q....{..q...A{..q....{...%...{...%...{...%...{.......{.. "...{....
...{.......{...{...{..R%...{..W%...{...{...{..R%...{..Rich.{..........
PE..L......X.....................t....................@...............
...........p.......6....@.................................x...........
.................3...0..l7..`l..T....................m.......l..@.....
.......................................text...........................
.... ..`.rdata..............................@..@.data....1............
..............@....gfids..D...........................@..@.tls........
........................@....rsrc...............................@..@.r
eloc..l7...0...8..................@..B................................
......................................................................
......................................................................
.............................................8...h..D......Y..........
........%..h .D......Y..................c..h0.D......Y.V. ;E........PV
...E......hl.D..v...Y^.V.P;E........PV...E......h{.D..P...Y^.V.t;E....
....PV...E......h..D..*...Y^.V..;E....`...PV...E......h..D......Y^.V..
;E....:...PV. .E..z...h..D......Y^.V..;E........PV.@.E..T...h..D......
Y^.V..;E........PV.`.E......h..D......Y^.V..;E........PV...E......h..D
..l...Y^.V..;E........PV...E......h..D..F...Y^.V..;E....|...PV...E....
..h..D.. ...Y^.V..<E....V...PV...E......h..D......Y^.V.,<E..

<<< skipped >>>

POST / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: qbwup.imtt.qq.com
Content-Length: 398
Cache-Control: no-cache

......,<LV.qbpcstatf.stat}...k.....crypt...
list<char>....M
...H:.y.e....:.'.........^.I.T..8..w#....2\.D..Q.N..Q.W..-.c..#S...Y....A.Q*...[[Ng.
.r....*.
...i.....k.
x......w...{
..fq.>.#.:%.L..e7QI..>....2b..((..~H....Fpl0.
a.z......2.-a.&..Q.%....v......d..c..kQ~..>.f>..e...(....!.{).=...J._e...xIF.$.8S..U...p.$
.6..HEBE......!Y......s/.u.........".....s.
..\z....7......2g.|.n*......
HTTP/1.1 200 OK
Content-Length: 54
Content-Type: application/multipart-formdata
Date: Tue, 16 May 2017 09:33:56 GMT
Server: HTTP Load Balancer/1.0
...6..,<LV.qbpcstatf.stat}.............int32............


POST / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: qbwup.imtt.qq.com
Content-Length: 398
Cache-Control: no-cache

......,<LV.qbpcstatf.stat}...k.....crypt...
list<char>....M
...H:.y.e....:.'.........^.I.T..8..w#....2\.D..Q.N..Q.W..-.c.ZL-!.......A.Q*...[[Ng.
.r....*.
...i.....k.
x......w...{
..fq.>.#.:%.L..e7QI..>....2b..((..~H....Fpl0.
a.z......2.-a.&..Q.%....v......d..c..kQ~..>.f>..e...(....!.{).=...J._e...xIF
y..._..)
&.6.}Nq....!v....w..H.6..HEBE./..|......m....[....6.rp...s!.\...k..3...K..px....
HTTP/1.1 200 OK
Content-Length: 54
Content-Type: application/multipart-formdata
Date: Tue, 16 May 2017 09:33:57 GMT
Server: HTTP Load Balancer/1.0
...6..,<LV.qbpcstatf.stat}.............int32............


GET /pcbrowser/down.php?pid=4640 HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: down2.uc.cn
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 302 Moved Temporarily
Server: nginx
Date: Tue, 16 May 2017 09:33:58 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.3.10
Set-Cookie: PHPSESSID=1l88cp0kq89mjl325v3ufkk4q2; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: hXXp://umcdn.uc.cn/down/4640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.exe
0..HTTP/1.1 302 Moved Temporarily..Server: nginx..Date: Tue, 16 May 20
17 09:33:58 GMT..Content-Type: text/html..Transfer-Encoding: chunked..
Connection: keep-alive..X-Powered-By: PHP/5.3.10..Set-Cookie: PHPSESSI
D=1l88cp0kq89mjl325v3ufkk4q2; path=/..Expires: Thu, 19 Nov 1981 08:52:
00 GMT..Cache-Control: no-store, no-cache, must-revalidate, post-check
=0, pre-check=0..Pragma: no-cache..Location: hXXp://umcdn.uc.cn/down/4
640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.e
xe..0..


GET /pcbrowser/down.php?type=dll&pid=4640 HTTP/1.1
Accept: */*
Content-Length: 0
User-Agent: ChannelPromptDownloader
Host: down2.uc.cn
Cache-Control: no-cache


HTTP/1.1 302 Moved Temporarily
Server: nginx
Date: Tue, 16 May 2017 09:34:04 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.3.10
Set-Cookie: PHPSESSID=tu5ak2l2ske415l5ngvinmrj56; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: hXXp://umcdn.uc.cn/down/4640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.dll
0..HTTP/1.1 302 Moved Temporarily..Server: nginx..Date: Tue, 16 May 20
17 09:34:04 GMT..Content-Type: text/html..Transfer-Encoding: chunked..
Connection: keep-alive..X-Powered-By: PHP/5.3.10..Set-Cookie: PHPSESSI
D=tu5ak2l2ske415l5ngvinmrj56; path=/..Expires: Thu, 19 Nov 1981 08:52:
00 GMT..Cache-Control: no-store, no-cache, must-revalidate, post-check
=0, pre-check=0..Pragma: no-cache..Location: hXXp://umcdn.uc.cn/down/4
640/UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433.d
ll..0..


GET /accept?authcode=1771558448&guid=FFC0F22A-CF55-8C7B-BAC8-09866D954819&supplyid=85296&IEVer=9&osVer=6.1.1&osDigit=32&psver=3&appId=3&cver=8.2.3638.400 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) QQBrowser/6.0
Host: ps.browser.qq.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Content-Length: 11237
Content-Type: application/json;charset=utf-8
Cache-Control: no-cache
Pragma: no-cache
{"tasklist":["{"appId":"3","cmdCode":3404,"tas
kId":3404,"ver":25252,"url":"http://stdl%2
Eqq.com/stdl/qbfilepush/qqbrowser/cloudctrl/production/1
438571713_5287.txt?","taskKind":1,"uin":""
,"svrMsg":"{}","md5":""}","{"appId%2
2:"3","cmdCode":3406,"taskId":3406,"ver"%3
A65983,"url":"http://stdl.qq.com/stdl/qbfilepu
sh/qqbrowser/cloudctrl/production/1463643770_5350.txt?%2
2,"taskKind":1,"uin":"","svrMsg":"{}
","md5":""}","{"appId":"3","cmdCode"
:1020,"taskId":20001,"ver":7,"url":"http%2
53A%2F%2Fdl_dir.qq.com%2Finvc%2Ftt%2Fps%2F1020%3F%
22,"taskKind":1,"uin":"","svrMsg":"{%7
D","md5":""}","{"appId":"3","cmdCode%2
2:1100,"taskId":20003,"ver":77,"url":"http
%3A%2F%2Fpc5.gtimg.com%2Fbtr%2Fqqbrowser%2Fps%2F1100
%2F34_75_2013-04-03.zip%3F","taskKind":1,"
uin":"","svrMsg":"{}","md5":""}"
,"{"appId":"3","cmdCode":2104,"taskId":200
07,"ver":27,"url":"http%3A%2F%2Fpc5.gtimg.
com%2Fbtr%2Fqqbrowser%2Fps%2F2104%2F57_27_2012-06-15
.dat%3F","taskKind":1,"uin":"","svrM

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= HTTP/1.1
Cache-Control: max-age = 584393
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 13 Oct 2016 04:26:54 GMT
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.10.2
Content-Type: application/ocsp-response
Content-Length: 1763
content-transfer-encoding: binary
Cache-Control: max-age=389579, public, no-transform, must-revalidate
Last-Modified: Sat, 13 May 2017 21:43:38 GMT
Expires: Sat, 20 May 2017 21:43:38 GMT
Date: Tue, 16 May 2017 09:33:45 GMT
Connection: keep-alive
0..........0..... .....0......0...0.......WI.....L.c=...r..7Z..2017051
3214338Z0s0q0I0... ...................B.>.I.$&.....e......0..C9...3
13..R...%V.......K3.....20170513214338Z....20170520214338Z0...*.H.....
........k....5.......X;.{..E2.E...'i.q....A.%.|.<.>....I..NCG...
q.lt0@. $.c...SF............^.}w..x....z.{...X.z..........*.J7.L..../.
r*. ...=.?...&.c...j.b .....".Dd.. ...BE.?.._..'.^.`:.V.l.i|...9a..z.S
.V.z-..0......{.LP.T.O.d....'Sip^<?.f....L...@./......?wOt......0..
.0...0..........^..)......<...T.0...*.H........0..1.0...U....US1.0.
..U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2
006 VeriSign, Inc. - For authorized use only1E0C..U...<VeriSign Cla
ss 3 Public Primary Certification Authority - G50...161122000000Z..171
214235959Z0..1.0...U....US1.0...U....Symantec Corporation1.0...U....Sy
mantec Trust Network1?0=..U...6Symantec Class 3 PCA - G5 OCSP Responde
r Certificate 50.."0...*.H.............0.............................m
..|........1rUZN.b.......t. d......O...NY.lR..k .Q.z.g.4(,...Rp.7...0C
.j.)Z........ ~..3...x.b.-..... S^0<6...!.(..2}...T.fX}...6...(...1
...#..H..|`.yy.<B.z.q$......u.-..K.!......y..8..--....?.,.[.[...5.e
.4.....D..t.;....).J....\fV..G.........0...0...U.......0.0l..U. .e0c0a
..`.H...E....0R0&.. .........hXXp://VVV.symauth.com/cps0(.. .......0..
.hXXp://VVV.symauth.com/rpa0...U.%..0... .......0...U...........0... .
....0......0"..U....0...0.1.0...U....TGV-OFF-500...U.......WI.....L.c=
...r..7Z0...U.#..0.....e......0..C9...3130...*.H.............<w

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEHFwvZPPPxia5kUrUUxJNA4= HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.10.2
Content-Type: application/ocsp-response
Content-Length: 1660
content-transfer-encoding: binary
Cache-Control: max-age=450793, public, no-transform, must-revalidate
Last-Modified: Sun, 14 May 2017 14:45:09 GMT
Expires: Sun, 21 May 2017 14:45:09 GMT
Date: Tue, 16 May 2017 09:33:51 GMT
Connection: keep-alive
0..x......q0..m.. .....0.....^0..Z0.........8.Y......*u...&.A..2017051
4144509Z0s0q0I0... ...................F....0.yV......{&.K......&......
.qp...?...E QLI4.....20170514144509Z....20170521144509Z0...*.H........
.....2 .i.2....y v...(Z<|d.(.. ....p..[.....F....k...Dn....(C*.5I.^
..Hf.......:..o..W.D}.8.....Gik.9....z..rA....4E..W.W....J.%W...u.X.V.
e.._U.k...A...4..p.0........y.....j.'..E...W$.....O$\p..%.....a?....^.
........l.N....d7..... .w8[F!pH..6.#.c....'I....1...._....0...0...0...
.......h..o&.......WC..0...*.H........0..1.0...U....US1.0...U....VeriS
ign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at h
ttps://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Code Sign
ing 2010 CA0...161213000000Z..211231235959Z0D1B0@..U...9Symantec Class
3 Code Signing 2010 CA SHA1 OCSP Responder0.."0...*.H.............0..
........{.~......9......W*8:Y.`.b8.4....:.]6;..V...]'6......Mi.._.....
l.....!,.F|..?&....1.y............Cudi(.Ron.._T.p ..a....'!.0.Z.......
......n@A.5.&..Z.Bo...L.....e.`..4........4.........<.".q..n.,..$..
...C....n.v..*.3.,:..{...R. ...1.s..jF..q...a.f..@.../..........0...0.
..U.......0.0f..U. ._0]0[..`.H...E....0L0#.. .........hXXps://d.symcb.
com/cps0%.. .......0...hXXps://d.symcb.com/rpa0...U.%..0... .......0..
.U...........0... .....0......0"..U....0...0.1.0...U....TGV-OFF-650...
U.........8.Y......*u...&.A0...U.#..0.......{&.K......&.....0...*.H...
...........O..s3..[.....:Y......c..L...:...4EZ.x.I..m.7.B`.t.A....56f.
......W<>.Lr.,...........".T.......Q..] "A.pV......J...JK[.3

<<< skipped >>>

GET /large/7185bdf1gw1f05vpdktqrg20go0a5u10.gif HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: ww3.sinaimg.cn
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Tue, 16 May 2017 09:33:28 GMT
Server: PWS/8.2.0.7
X-Px: ms h0-s34.p1-arn ( h0-s45.p1-arn), ht-d h0-s45.p1-arn.cdngp.net
Cache-Control: max-age=7776000
Expires: Tue, 18 Jul 2017 09:48:31 GMT
Age: 2331897
Accept-Ranges: bytes
Content-Length: 5124538
Content-Type: image/gif
Last-Modified: Mon, 08 Jul 2013 18:06:40 GMT
X-Via-CDN: f=TXCDN,s=151.249.91.213,c=194.242.96.218
Connection: keep-alive
GIF89aX.m.....Qx......v..Y...b.......1b.p......m....8w.k...........j..
P........K......e.n......x.z........*v.\..8h....r........&...b.<...
..............x|. ]..........!a.#W.^.."c....5........*...........G..D.
..........z..Y..)s.:..D~..\....z..E........S.........k.......B.....R..
M~....3l.^........}.."..t..t............c....... z....4w.......j...[..
..*.._.....!r.$k.Y...i.r..c{.......N..3..6........B.....`..!j.F..P...{
.......@.....l...l.....s.B...t....G...............|.....Y..........Cw.
.k.......{..c........1q.1{....1..4..l...f.......c........I............
e.\..*..!........y..B.....d..;............z.... ..L...b..k....l.......
.#j..q.9........`..].........|....*m..d.Q........R.....|..6|..T.......
R.....O...........q..Dy.Q..!d..].3..)..d......t.o..)u.8m..b.-j. k.....
..s........L..!.......,....X.m.....#@.@......*\......#J.Hp....3j......
C..I....(S.\...K.._..I.............@...J.(QDH.*].....P.J.J....X.j....
..`.:5J....h."......pY..K....x.....oL...O..V.....*^......#.EL.0....K..
.....C..L.....]r.(zo...9....v...;..M.4...o..nr..... _...s...;gN.3....k
.^.{d..Y...?......._.......G._..}.....?......6_.....m(................
....1....a.!G..Fa.o}.!.(.............}*.h#r3..#f0.(c...(...........CF.
G..P6...q.G.KRR...\>..pW.fe..}.\.h>if.d..d...y....ig.r...Lo..[..
.)(....goc..]....h..~..D}....4.......ic.R.h.q~.X..Bj.b.BT...........W.
L..kE..E..[............,...E.B...,].V[.. =....b.........f.mE..ZnJ..K..
*..na..[....i.H.F.-.....F...........z.....(..........0H.w,.. i.0. ....
6....#...F(.L.....q.4. ....D....,-.<...H?..4..:f..FG.b.8R.4...\

<<< skipped >>>

The Trojan connects to the servers at the folowing location(s):

%original file name%.exe_1976:

.text
`.rdata
@.data
.ndata
.rsrc
uDSSh
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
KERNEL32.dll
ExitWindowsEx
USER32.dll
GDI32.dll
SHFileOperationA
ShellExecuteA
SHELL32.dll
RegEnumKeyA
RegCreateKeyExA
RegCloseKey
RegDeleteKeyA
RegOpenKeyExA
ADVAPI32.dll
COMCTL32.dll
ole32.dll
VERSION.dll
verifying installer: %d%%
hXXp://nsis.sf.net/NSIS_Error
... %d%%
~nsu.tmp
%u.%u%s%s
RegDeleteKeyExA
%s=%s
*?|<>/":
Browser_V5.5.7852.9_r_4640_(Build1512022057).exe
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\Inetc.dll
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp
-0.3 *2'(/&
-.3*2'/&
.LB ICA
Q.FG?$
\\?\unc\
zcÁ
65708<8`9
<'</<5<;<|<
5 5$5(5,5
}GO%u
%Program Files%\Tencent\QQBrowser\uninst.exe
stall.exe
uninst.exe
DUNIN~1.EXE
a5u10.gif
\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp
1760120
c:\%original file name%.exe
%Program Files%\Winamp
C:\Users\"%CurrentUserName%"\AppData\Local\Temp
%original file name%.exe
ers\"%CurrentUserName%"\AppData\Local\Temp\nssF1EC.tmp
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\
!"#$%&'()* ,
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>

%original file name%.exe_1976_rwx_10004000_00001000:

callback%d

BDPlayerTray.exe_3432:

.text
`.rdata
@.data
.rsrc
@.reloc
F\ FTP
8%u(j
Nt.Nt
x=%d,y=%d,w=%d,h=%d
1.2.40
l:%d,t:%d,r:%d,b:%d
&#xX;
</%s>
%s="%s"
%s='%s'
<![CDATA[%s]]>
<!--%s-->
version="%s"
encoding="%s"
standalone="%s"
%s %s
%s:%d
%s:%d %s
1,1,-1,-1
hotkey
password
hotkeyctrl
skin%d
sub%d
0,0,%d,%d
-%d,%d,-%d,%d
%d,-%d,%d,-%d
0,-%d,%d,-0
-%d,0,-0,%d
%d,%d,%d,%d
crtextnormal
crtextsel
crtexthover
crtext
RegCreateKeyTransactedW
RegOpenKeyTransactedW
RegDeleteKeyTransactedW
RegDeleteKeyExW
bdcommon.dll
bdxctrl.dll
IMsgBox
IxCanvasShowDelegate
IxMsgDispatcher
bdxmain.dll
bdxview.dll
IBDCmdCenter
bdxlogic.dll
bdxplayer.dll
NULL row buffer for row %ld, pass %d
libpng error: %s, offset=%d
libpng error no. %s: %s
libpng warning no. %s: %s
libpng error: %s
libpng warning: %s
Buffer error in compressed datastream in %s chunk
Incomplete compressed datastream in %s chunk
Data error in compressed datastream in %s chunk
Unknown zTXt compression type %d
gamma = (%d/100000)
gx=%f, gy=%f, bx=%f, by=%f
wx=%f, wy=%f, rx=%f, ry=%f
incorrect gamma=(%d/100000)
iTXt chunk not supported.
Bogus message code %d
Invalid component ID %d in SOS
IDCT output block size %d not supported
Wrong JPEG library version: library is %d, caller expects %d
Unsupported JPEG data precision %d
Invalid memory pool code %d
Invalid progressive parameters at scan script entry %d
Invalid progressive parameters Ss=%d Se=%d Ah=%d Al=%d
Invalid scan script at entry %d
JPEG parameter struct mismatch: library thinks size is %u, caller expects %u
Improper call to JPEG library in state %d
Buffer passed to JPEG library is too small
Unsupported color conversion request
Too many color components: %d, max %d
Bogus DAC value 0x%x
Bogus DAC index %d
Bogus DQT index %d
Bogus DHT index %d
Empty JPEG image (DNL not supported)
Maximum supported image dimension is %u pixels
Cannot transcode due to multiple use of quantization table %d
Backing store not supported
Huffman table 0xx was not defined
Not a JPEG file: starts with 0xx 0xx
Quantization table 0xx was not defined
Cannot quantize more than %d color components
Insufficient memory (case %d)
Cannot quantize to more than %d colors
Cannot quantize to fewer than %d colors
Unsupported JPEG process: SOF type 0xx
Failed to create temporary file %s
Unsupported marker type 0xx
Unknown APP0 marker (not JFIF), length %u
Adobe APP14 marker: version %d, flags 0xx 0xx, transform %d
Define Arithmetic Table 0xx: 0xx
Unknown APP14 marker (not Adobe), length %u
Define Quantization Table %d precision %d
Define Huffman Table 0xx
Freed EMS handle %u
Define Restart Interval %u
Obtained EMS handle %u
JFIF APP0 marker: version %d.d, density %dx%d %d
= = = = = = = =
JFIF extension marker: type 0xx, length %u
Warning: thumbnail image size does not match data length %u
Miscellaneous marker 0xx, length %u
with %d x %d thumbnail image
%4u %4u %4u %4u %4u %4u %4u %4u
Unexpected marker 0xx
Quantizing to %d colors
Quantizing to %d = %d*%d*%d colors
At marker 0xx, recovery action %d
Selected %d colors for quantization
Smoothing not supported with nonstandard sampling ratios
RST%d
Component %d: %dhx%dv q=%d
Start Of Frame 0xx: width=%u, height=%u, components=%d
Start Of Scan: %d components
Ss=%d, Se=%d, Ah=%d, Al=%d
Component %d: dc=%d ac=%d
Opened temporary file %s
Closed temporary file %s
JFIF extension marker: palette thumbnail image, length %u
JFIF extension marker: JPEG-compressed thumbnail image, length %u
Unrecognized component IDs %d %d %d, assuming YCbCr
JFIF extension marker: RGB thumbnail image, length %u
Obtained XMS handle %u
Freed XMS handle %u
Inconsistent progression sequence for component %d coefficient %d
Unknown Adobe color transform code %d
Corrupt JPEG data: %u extraneous bytes before marker 0xx
Warning: unknown JFIF revision number %d.d
Corrupt JPEG data: found marker 0xx instead of RST%d
%ld%c
d:\clientci\workspace\yingyinlite_compile_5.1.1\yingyinlite\bin\Release_Win32\pdb\BDPlayerTray.pdb
MSVCP120.dll
GetProcessHeap
KERNEL32.dll
EnumThreadWindows
GetKeyState
GetKeyNameTextW
MapVirtualKeyW
USER32.dll
RegCloseKey
RegOpenKeyExW
RegDeleteKeyW
RegQueryInfoKeyW
RegEnumKeyExW
RegCreateKeyExW
ADVAPI32.dll
ole32.dll
ShellExecuteW
SHELL32.dll
OLEAUT32.dll
SHLWAPI.dll
OffsetViewportOrgEx
GDI32.dll
COMCTL32.dll
MSIMG32.dll
MSVCR120.dll
_calloc_crt
_crt_debugger_hook
__crtUnhandledException
__crtTerminateProcess
__crtGetShowWindowMode
_amsg_exit
_wcmdln
__crtSetUnhandledExceptionFilter
GdiplusShutdown
GdipSetStringFormatHotkeyPrefix
gdiplus.dll
WINMM.dll
VERSION.dll
.?AV?$CBkCreator@VCBkHotkey@@@@
.?AVCBkHotkey@@
.?AV?$CWindowImpl@VCBkHotkey@@V?$CHotKeyCtrlT@VCWindow@ATL@@@WTL@@V?$CWinTraitsOR@$0IA@$0A@V?$CWinTraits@$0FGAAAAAA@$0A@@ATL@@@ATL@@@ATL@@
.?AV?$CWindowImplBaseT@V?$CHotKeyCtrlT@VCWindow@ATL@@@WTL@@V?$CWinTraitsOR@$0IA@$0A@V?$CWinTraits@$0FGAAAAAA@$0A@@ATL@@@ATL@@@ATL@@
.?AV?$CWindowImplRoot@V?$CHotKeyCtrlT@VCWindow@ATL@@@WTL@@@ATL@@
.?AV?$CHotKeyCtrlT@VCWindow@ATL@@@WTL@@
.?AV?$CBkCreator@VCBkHotKeyCtrl@@@@
.?AVCBkHotKeyCtrl@@
%U4]06Pr
G0.hk
W7^.Jv
~I.PR!I
m[.PM
{^.OW
F%Fg=2
/.qrz
%URWip
..3 ..3!3.3"3.3#3.3$3.3&3.3'3.3(2-2*2-3 3-3 3.3,3.3-3.3.2.302-212-21323232323.325/413/31//02///2///1/0/1101/011/111-113-111,212*232*222)343'3.3&/02$111"500"625 232
%.s"(0
/4<"16>`/5=
1 &{2/-6111
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
<assemblyIdentity type='Win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' processorArchitecture='X86' publicKeyToken='6595b64144ccf1df' language='*' />
77U7x7~7
67X7
1!2*2?273@3
8 8$8(8,80848
2-2L2}2D3
9(979\9~9
= =$=(=,=0=4=
9 9$9(9,9094989<9
6 6$6(6,606
; ;$;(;,;
.jpeg
\string.xml
\font.xml
\color.xml
\images.xml
\render.xml
\style.xml
Invalid WM_COPYDATA, length = %d, first null = %d
Invalid WM_COPYDATA, length = %d
lym:Process Command Line %s
BaiduBrowserMsgWnd\%d
user32.dll
pipe
style.xml
effect.xml
string.xml
skin.xml
error @ %s:%d (lasterror=%u, hr=0x%X)
path=%s
nValue=%d
BDPlayer.dat
delete, ret=%d, dwError=%d
msimg32.dll
BKHotKey
msctls_hotkey32
uxtheme.dll
create %s(%d) failed with error %d: %s
import
%s\%s
PERFORMANCE(%S) : %f ms
} %s(%s)
%s(%s) {
55A30E17-5B6E-4D53-9E0E-F20B6B308287
89A08041-0E78-494C-B1A5-920FC74AF790
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
WAdvapi32.dll
bdbugreport_%u
\bugreport.exe
"%s" --smname=%s
menu_tray.xml
BDPlayer.exe
\BDPlayer.exe
\xUpdate.exe
%d.%d.%d.%d
\res\icon\Player.ico
\xReport.exe
"%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayerTray.exe"
%Program Files%\baidu\BDPlayer\5.1.1.9\bugreport.exe
bdbugreport_3432

PerfTraceService.exe_1548:

.text
`.rdata
@.data
.rsrc
@.reloc
l$X9.vE
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
operator
GetProcessWindowStation
USER32.DLL
tdh.dll
e:\SlaveDepot\beyond_slave\branch8_union_rc_rep\beyond\bin\pdb\Release\PerfTraceService.pdb
KERNEL32.dll
RegCreateKeyW
RegCloseKey
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
SHELL32.dll
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
WS2_32.dll
GetCPInfo
GetConsoleOutputCP
GetProcessHeap
zcÁ
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
7%7S7a7
3=3
>&>,>2>:>
8Œ8v8
;3;<;)=8=,>
KERNEL32.DLL
mscoree.dll
[%s](%lu):
PerfTrace.ini
DebugMsg
EVENT_RECORD address : %d, UserDataLength : %d
PerfTrackInfo : Name : %s, Id : %d
Start Event : Name : %s, Id : %d
InFlightEvents number : %d
Match Event : Name : %s, Id : %d
{x-x-x-xx-xxxxxx}
Port
TypesSupported
QQTrace.ini
TraceConfig.xml
qqtrack.xml
advapi32.dll
IsVervionEnalbe failed , OSVersion : %d
IsTypeEnable failed, trace type %d
7z.exe
::CreateProcess failed, ErrCode : %d, cmd : %s
::SetPriorityClass failed, ErrCode : %d
File path too long ! %s, %s
share dir path too long ! %s, %s
CopyFile failed, ErrCode : %d
begin ReloadConfig tread, ReloadTime : %d
CreateThread failed, ErrCode %d
OpenTrace failed , ErrCode : %d
Session-4BA0B957-882B-4625-A213-0349B865E6AA
%d/%d/%d %d:%d:%d
event id :%d, duration :%f ms, start time :%s
ScenarioId %s take a long time
QQTrace-UserSession-8D2FEC41-08A1-4c4b-AB00-F67DD5761ACC
-start %s -on %s -BufferSize %d -MinBuffers %d -MaxBuffers %d
-on %s -BufferSize %d -MinBuffers %d -MaxBuffers %d -stackwalk %s
-stop -stop %s
-flush -flush "%s"
-flush -f "%s" -flush "%s" -f "%s"
RunXperf Error ! (%d)
%s\%s%s.%d-d-d.d-d-d-%d.etl
-merge "%s" "%s" "%s"
Myredir-B48C0CD8-8D7A-45ee-90EB-B1FCCD3F5E1A
"%s" %s
CreateProcess failed (%d)
DeleteFile %s Failed : %d
xperf.exe
QQTraceUserSession.etl
QQTraceNTSession.etl
%d.%d.%d.%d
oXmlDoc.Load(lpszConfigFileName) || !oXmlDoc.IsValid() failed
oXmlDoc.IsValid() failed
IDispatch error #%d
%Program Files%\Tencent\QQBrowser\Service\PerfTraceService.exe

Browser_V5.5.7852.9_r_4640_(Build1512022057).exe_3236:

.text
`.rdata
@.data
.gfids
@.tls
.rsrc
@.reloc
j.Yf;
_tcPVj@
.PjRW
PSSSSSSh
atlthunk.dll
operator
operator ""
GetProcessWindowStation
%S#[k
\\.\PhysicalDrive%d
\\.\IDE21201.VXD
ERROR: Could not open IDE21201.VXD file
\\.\Scsi%d:
Drive%dModelNumber
Drive%dSerialNumber
DriveÜontrollerRevisionNumber
DriveÜontrollerBufferSize
Drive%dType
X-X-X-X-X-X
-- %s --
%%X
RegCreateKeyTransactedW
RegOpenKeyTransactedW
RegDeleteKeyTransactedW
D:\UCChannel\ucchannel\Release\ChannelU.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.CRT$XCA
.CRT$XCAA
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data
.data$r
.gfids$x
.gfids$y
.tls$
.tls$ZZZ
.rsrc$01
.rsrc$02
KERNEL32.dll
USER32.dll
RegOpenKeyExW
RegDeleteKeyW
RegCloseKey
RegQueryInfoKeyW
RegEnumKeyExW
RegCreateKeyExW
ADVAPI32.dll
SHFileOperationW
ShellExecuteW
ShellExecuteExW
SHELL32.dll
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
COMCTL32.dll
HttpQueryInfoW
HttpOpenRequestW
HttpSendRequestW
WININET.dll
PSAPI.DLL
IPHLPAPI.DLL
WINTRUST.dll
VERSION.dll
GetProcessHeap
GetCPInfo
.?AVCHttpDownload@@
ChannelDllUrl=hXXp://down2.uc.cn/pcbrowser/down.php?type=dll
version=6.1.2107.204
ReportUrl=hXXp://mmstat.ucweb.com/
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
<assemblyIdentity type='win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' processorArchitecture='x86' publicKeyToken='6595b64144ccf1df' language='*' />
4"4(4,424
5:5_5'656
5(565>5{5
8$8(8,808
2,2:2@2[2
8 8-838:8[8
0%0U0g0
=#=?=\=|=
8$8/84898]8
8%9s9
11C1R1a1p1
:,;0;4;8;
< <$<(<,<
= =$=(=,=0=4=8=<=
: :<:@:`:
kernel32.dll
mscoree.dll
msvcrt.dll
ext-ms-win-ntuser-windowstation-l1-1-0
portuguese-brazilian
aavc.ini
UCBrowser.exe
hXXp://wow.uc.cn/biz-data/sec/channel/test/config/av_config.ini
UCBrowserSetup.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
kxetray.exe
kxescore.exe
kislive.exe
kskinmgr.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hXXp://mmstat.ucweb.com/
d\\.\%c:
\\.\PHYSICALDRIVE%d
bluesky.4.1.6.1.1
READ_URL_ERROR
READ_CHANNEL_BASE_URL_ERROR
PASS_PARAM_ERROR
EXTRACT_CHROMEPACKED7ZFILE_ERROR
UN7Z_TO_CHROME7Z_ERROR
UN7Z_TO_CHROMEBIN_ERROR
EXTRACT_TO_SETUPEXE_ERROR
UNCAB_TO_SETUPEXE_ERROR
RENAME_CHROME_FOLDER_ERROR
COPY_CHROME_FOLDER_ERROR
COPY_SETUPEXE_FILE_ERROR
RUN_SETUPEXE_FILE_ERROR
HTTP/1.1
Content-Length: %d
ChannelU.exe
ChannelDllUrl
PackageBaseUrl
ReportUrl
6.0.1121.13
config.ini
ChannelU.dll
hXXp://
\\.\X:
%d%d%d%d
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
Advapi32.dll
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Browser_V5.5.7852.9_r_4640_(Build1512022057).exe
UCWeb Inc.
1.0.11.0
Copyright 2008-2016 UCWeb Inc. All rights reserved.

xUpdate.exe_1668:

.text
`.rdata
@.data
.rsrc
@.reloc
F\ FTP
Nt.Nt
x=%d,y=%d,w=%d,h=%d
1.2.40
l:%d,t:%d,r:%d,b:%d
&#xX;
</%s>
%s="%s"
%s='%s'
<![CDATA[%s]]>
<!--%s-->
version="%s"
encoding="%s"
standalone="%s"
1.3.6.1.4.1.311.2.1.12
1.2.840.113549.1.9.5
1.2.840.113549.1.9.6
hXXp://
HTTP/1.1
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727))
crtext
RegOpenKeyTransactedW
RegDeleteKeyTransactedW
RegDeleteKeyExW
</p2surl>
<p2surl>
1,1,-1,-1
hotkey
password
hotkeyctrl
skin%d
sub%d
0,0,%d,%d
-%d,%d,-%d,%d
%d,-%d,%d,-%d
0,-%d,%d,-0
-%d,0,-0,%d
%d,%d,%d,%d
crtextnormal
crtextsel
crtexthover
%s %s
%s:%d
%s:%d %s
bdcommon.dll
bdxctrl.dll
IMsgBox
IxCanvasShowDelegate
IxMsgDispatcher
bdxmain.dll
bdxview.dll
IBDCmdCenter
bdxlogic.dll
bdxplayer.dll
NULL row buffer for row %ld, pass %d
libpng error no. %s: %s
libpng error: %s
libpng error: %s, offset=%d
libpng warning: %s
libpng warning no. %s: %s
Data error in compressed datastream in %s chunk
Buffer error in compressed datastream in %s chunk
Incomplete compressed datastream in %s chunk
Unknown zTXt compression type %d
gamma = (%d/100000)
wx=%f, wy=%f, rx=%f, ry=%f
gx=%f, gy=%f, bx=%f, by=%f
incorrect gamma=(%d/100000)
iTXt chunk not supported.
Bogus message code %d
Invalid component ID %d in SOS
IDCT output block size %d not supported
Wrong JPEG library version: library is %d, caller expects %d
Unsupported JPEG data precision %d
Invalid memory pool code %d
Invalid progressive parameters at scan script entry %d
Invalid progressive parameters Ss=%d Se=%d Ah=%d Al=%d
Invalid scan script at entry %d
JPEG parameter struct mismatch: library thinks size is %u, caller expects %u
Improper call to JPEG library in state %d
Buffer passed to JPEG library is too small
Unsupported color conversion request
Too many color components: %d, max %d
Bogus DAC value 0x%x
Bogus DAC index %d
Bogus DQT index %d
Bogus DHT index %d
Empty JPEG image (DNL not supported)
Maximum supported image dimension is %u pixels
Cannot transcode due to multiple use of quantization table %d
Backing store not supported
Huffman table 0xx was not defined
Not a JPEG file: starts with 0xx 0xx
Quantization table 0xx was not defined
Cannot quantize more than %d color components
Insufficient memory (case %d)
Cannot quantize to more than %d colors
Cannot quantize to fewer than %d colors
Unsupported JPEG process: SOF type 0xx
Failed to create temporary file %s
Unsupported marker type 0xx
Unknown APP0 marker (not JFIF), length %u
Adobe APP14 marker: version %d, flags 0xx 0xx, transform %d
Define Arithmetic Table 0xx: 0xx
Unknown APP14 marker (not Adobe), length %u
Define Quantization Table %d precision %d
Define Huffman Table 0xx
Freed EMS handle %u
Define Restart Interval %u
Obtained EMS handle %u
JFIF APP0 marker: version %d.d, density %dx%d %d
= = = = = = = =
JFIF extension marker: type 0xx, length %u
Warning: thumbnail image size does not match data length %u
Miscellaneous marker 0xx, length %u
with %d x %d thumbnail image
%4u %4u %4u %4u %4u %4u %4u %4u
Unexpected marker 0xx
Quantizing to %d colors
Quantizing to %d = %d*%d*%d colors
At marker 0xx, recovery action %d
Selected %d colors for quantization
Smoothing not supported with nonstandard sampling ratios
RST%d
Component %d: %dhx%dv q=%d
Start Of Frame 0xx: width=%u, height=%u, components=%d
Start Of Scan: %d components
Ss=%d, Se=%d, Ah=%d, Al=%d
Component %d: dc=%d ac=%d
Opened temporary file %s
Closed temporary file %s
JFIF extension marker: palette thumbnail image, length %u
JFIF extension marker: JPEG-compressed thumbnail image, length %u
Unrecognized component IDs %d %d %d, assuming YCbCr
JFIF extension marker: RGB thumbnail image, length %u
Obtained XMS handle %u
Freed XMS handle %u
Inconsistent progression sequence for component %d coefficient %d
Unknown Adobe color transform code %d
Corrupt JPEG data: %u extraneous bytes before marker 0xx
Warning: unknown JFIF revision number %d.d
Corrupt JPEG data: found marker 0xx instead of RST%d
%ld%c
d:\clientci\workspace\yingyinlite_compile_5.1.1\yingyinlite\bin\Release_Win32\pdb\xUpdate.pdb
TaskOperation
xnet.dll
WINTRUST.dll
MSVCP120.dll
GetProcessHeap
KERNEL32.dll
GetKeyState
EnumThreadWindows
GetKeyNameTextW
MapVirtualKeyW
USER32.dll
RegCloseKey
RegOpenKeyExW
RegDeleteKeyW
RegQueryInfoKeyW
ADVAPI32.dll
ole32.dll
ShellExecuteW
SHELL32.dll
OLEAUT32.dll
SHLWAPI.dll
OffsetViewportOrgEx
GDI32.dll
COMCTL32.dll
MSIMG32.dll
MSVCR120.dll
_calloc_crt
_crt_debugger_hook
__crtUnhandledException
__crtTerminateProcess
__crtGetShowWindowMode
_amsg_exit
_wcmdln
__crtSetUnhandledExceptionFilter
GdiplusShutdown
GdipSetStringFormatHotkeyPrefix
gdiplus.dll
WINMM.dll
CryptMsgClose
CertGetNameStringW
CertFreeCertificateContext
CertFindCertificateInStore
CertCloseStore
CryptMsgGetParam
CRYPT32.dll
WS2_32.dll
.?AV?$CAtlExeModuleT@VCFrameworkModule@@@ATL@@
.?AV?$CBkCreator@VCBkHotkey@@@@
.?AVCBkHotkey@@
.?AV?$CWindowImpl@VCBkHotkey@@V?$CHotKeyCtrlT@VCWindow@ATL@@@WTL@@V?$CWinTraitsOR@$0IA@$0A@V?$CWinTraits@$0FGAAAAAA@$0A@@ATL@@@ATL@@@ATL@@
.?AV?$CWindowImplBaseT@V?$CHotKeyCtrlT@VCWindow@ATL@@@WTL@@V?$CWinTraitsOR@$0IA@$0A@V?$CWinTraits@$0FGAAAAAA@$0A@@ATL@@@ATL@@@ATL@@
.?AV?$CWindowImplRoot@V?$CHotKeyCtrlT@VCWindow@ATL@@@WTL@@@ATL@@
.?AV?$CHotKeyCtrlT@VCWindow@ATL@@@WTL@@
.?AV?$CBkCreator@VCBkHotKeyCtrl@@@@
.?AVCBkHotKeyCtrl@@
%U4]06Pr
G0.hk
W7^.Jv
~I.PR!I
m[.PM
{^.OW
F%Fg=2
/.qrz
%URWip
..3 ..3!3.3"3.3#3.3$3.3&3.3'3.3(2-2*2-3 3-3 3.3,3.3-3.3.2.302-212-21323232323.325/413/31//02///2///1/0/1101/011/111-113-111,212*232*222)343'3.3&/02$111"500"625 232
%.s"(0
/4<"16>`/5=
1 &{2/-6111
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
<assemblyIdentity type='Win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' processorArchitecture='X86' publicKeyToken='6595b64144ccf1df' language='*' />
5%5U5_5
:3;:;?;|;
4$4;4^4{4
6$6)676=6
7!777=7`7
<!<&< <;<
<$=-=3=1?9???
5]5`5
2 2$2(2,2
6$6,646@6
.jpeg
\string.xml
\font.xml
\color.xml
\images.xml
\render.xml
\style.xml
CryptMsgGetParam failed with %x
CryptQueryObject failed with %x
Program Name : %s
MoreInfo Link : %s
Publisher Link : %s
CertFindCertificateInStore failed with %x
TimeStamp Certificate:
Signer Certificate:
Date of TimeStamp : d/d/d d:d
CertGetNameString failed.
Issuer Name: %s
Subject Name: %s
CryptDecodeObject failed with %x
The file "%s" is not signed.
The file "%s" is signed and the signature was verified.
An unknown error occurred trying to verify the signature of the "%s" file.
Error is: 0x%x.
import
%s\%s
bdbugreport_%u
\bugreport.exe
"%s" --smname=%s
Mscoree.dll
WAdvapi32.dll
OLEAUT32.DLL
77A88052-9A79-454C-B4A1-623FC84AF772
55A20E14-5467-4DB3-AEEE-F20D63D98067
error @ %s:%d (lasterror=%u, hr=0x%X)
{4E519EC8-2470-45fb-AAB5-1E3A67ACCB77}
check download file,exist:%d,md5same:%d,signok:%d
fetch update info,%s
check local file,exist:%d,md5same:%d,signok:%d
parse update info,localexist:%d
window_update.xml
get task info error,api code:%d,task code:%d
update.dat
uxtheme.dll
msimg32.dll
BKHotKey
msctls_hotkey32
create %s(%d) failed with error %d: %s
PERFORMANCE(%S) : %f ms
} %s(%s)
%s(%s) {
%s%s%s%s
%s "%s"
Invalid WM_COPYDATA, length = %d
Invalid WM_COPYDATA, length = %d, first null = %d
BaiduBrowserMsgWnd\%d
user32.dll
pipe
effect.xml
skin.xml
style.xml
ProcessCmdLine,%s
string.xml
\update.ini
hXXp://update.p2sp.baidu.com/
CheckUrl
"%Program Files%\baidu\BDPlayer\5.1.1.9\xUpdate.exe" --version=5.1.1.9 --channel=363 --mode=slient
%Program Files%\baidu\BDPlayer\5.1.1.9\bugreport.exe
bdbugreport_1668


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    stats_uploader.exe:3056
    V8._85296_20150814221218.exe:1980
    xReport.exe:3796
    xReport.exe:1584
    QQBrowser.exe:2524
    QQBrowser.exe:856
    QQBrowser.exe:1804
    QQBrowser.exe:3396
    QQBrowser.exe:2968
    QQBrowser.exe:2296
    QQBrowser.exe:1872
    QQBrowser.exe:1452
    QQBrowser.exe:2972
    QQBrowser.exe:812
    QQBrowser.exe:3052
    QQBrowser.exe:2952
    BaiduPlayer5SetupSilent_363.exe:2636
    netsh.exe:2224
    netsh.exe:1732
    PerfTraceService.exe:2220
    regsvr32.exe:4028
    PlayerApp.exe:2496

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\manifest.json (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\custom.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\12dc664d-0442-4570-a7c8-f3aa22922cec.com.png (252 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\extension\noads.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\chrome.7z (1344211 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\tmall.com.png (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\background_lib.js (129 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\amazon.png (507 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\youku.com.png (653 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\fame.png (444 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\resources.pak (92927 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Uninstall.exe (9133 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\uclauncher-x86.exe (1139 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\en-in\share.dat (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_100_percent.pak (1931 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\taobao.com.png (290 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\chrome.packed.7z (59963 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\06.png (354 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\baidu.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\index.html (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\taobao.png (389 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome.dll (157305 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\tmall.com.png (200 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Languages\chs.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\uclauncher-xp.exe (1499 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\14.png (488 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\zh-CN\external_extensions.json (934 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\lazy_index.js (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\youku.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\new-tab-icon.png (113 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\libmp3lame.dll (851 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\sogou.com.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\news_pre_render.js (26 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\18.png (283 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\lecture.png (282 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\config.dat (2939 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\font\font_8jda4sp0bz8pk3xr.ttf (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\VisualElements\Logo.png (27 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\data\city.json (419 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\login_view\alipay.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\UCProxySDK.dll (4489 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\game.png (340 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\id-ID\external_extensions.json (493 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\extension\taohuoyuan.png (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\lazy_lib.js (57 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\marketing\1001.ico (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\UCBrowser.exe (2987 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\youku.com.png (764 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\background.js (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Locales\en-US.pak (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\zh-cn\config.dat (2939 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\7z.dll (1841 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\07.png (305 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\id\config.dat (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\baidu.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\font\font_8jda4sp0bz8pk3xr.woff (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\life.png (475 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\d3dcompiler_47.dll (13439 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\6.1.2107.204.manifest (250 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\update_task.exe (851 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\sogou.com.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\setup_ex_.cab (441 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_watcher.dll (851 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\pt-br\start.dat (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\taobao.com.png (304 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\config.dat (124 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\setup.exe (17426 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Bin\ChannelU.dll (26363496 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\VisualElements\SmallLogo.png (27 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\new_tab_icon.png (113 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\snapshot_blob.bin (851 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\icon\48.jpg (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\taobao.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\pt-BR\external_extensions.json (493 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\libGLESv2.dll (5192 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\wallpaper\moon.jpg (38 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\subscribe.png (398 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Locales\zh-CN.pak (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\00.png (436 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\news\refresh.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\ucdrv-x86.sys (42 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\ru\share.dat (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\stats_uploader.exe (612 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\config.ini (195 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Update\curl-ca-bundle.crt (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\baidu.com.png (426 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\ru\start.dat (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\uclauncher-x64.exe (1499 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\bing.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\wow_installer.prefs (235 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\google.com.hk.png (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_child.dll (183256 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\n_01.png (509 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\id\share.dat (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\start.dat (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\login_view\weibo.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\VERSION (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\google.com.png (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\es-419\config.dat (124 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Languages\settings.xml (103 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\bing.com.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\ucdrv-xp.sys (44 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_elf.dll (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\custom.png (122 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\icon\48.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\rec.png (454 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\wallpaper\default.jpg (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\es-419\start.dat (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\social.png (290 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\courgette.dll (419 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Drivers\ucdrv-x64.sys (50 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\09.png (328 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\extension\renren.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\01.png (544 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\etao.com.png (335 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\libEGL.dll (88 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\shop.png (350 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\en-in\config.dat (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Update\InstalledConfig.xml (713 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\google.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\12dc664d-0442-4570-a7c8-f3aa22922cec.com.png (479 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\aavc.ini (32 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\browsing_data_remover.exe (419 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\desktop\facebook.ico (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\chrome_200_percent.pak (2987 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\config_updater.dll (2939 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\baidu.com.png (682 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\wallpaper\rain.jpg (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\react_lib.js (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\news.png (205 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\uc123.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\video.png (368 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\updater.dll (8643 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\es-419\share.dat (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\pt-br\share.dat (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\hrkill.exe (1931 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\zh-cn\start.dat (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Backup\UCBrowser.exe (2987 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\external_extensions.json (493 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\multiple.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\13.png (816 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\icon\16.png (939 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\UCService.exe (1139 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\PepperFlash\manifest.json (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\wow_installer.switches.txt (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\zh-cn\share.dat (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\wallpaper\snow.jpg (32 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\bing.com.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\start.dat (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\en-in\start.dat (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\data\pc_newtab_recommendation.json (52 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\ru\config.dat (124 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\03.png (305 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\02.png (294 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\recommend_section\other.png (180 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\en-IN\external_extensions.json (621 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\20.png (480 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\login_view\qq.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\icudtl.dat (19407 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\UCBrowserSetup.exe (70898 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\icon\128.png (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\7z.dll (2939 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\search_logo\default.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\share.dat (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\desktop\tmall_points.ico (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\delegate_execute.exe (1499 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\new_tab_search\google.com.png (521 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\stats_uploader.exe (419 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\04.png (645 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\16.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\login_view\taobao.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\etaohaitao.com.png (438 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\share.dat (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\bookmarks\pp_helper.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\19.png (367 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\pt-br\config.dat (124 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\theme_tool.exe (1139 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\PepperFlash\pepflashplayer.dll (69197 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\new_tab\index.js (114 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Configs\id\start.dat (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\wow_helper.exe (80 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\natives_blob.bin (851 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\_locales\en\messages.json (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\libexif.dll (419 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Update\UpdateOption.xml (189 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\Extensions\preset\hfahjeoiihhilkhgpknbhgcgjiejgecf\default\images\weather_icon\n_00.png (286 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\6.1.2107.204\UCAgent.exe (8056 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\Share\icons\searchbar\etao.com.png (252 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\UCChannel\Package\Chrome-bin\molt_tool.exe (851 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\WebpDecodeFilter.dll (2128 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\installed_arrow.png (176 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\skin\LightStripes.gt (94 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\theme.png (25 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_active_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_ceil.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_game.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\js\base.js (4 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\js\base.js (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{A1D7EDF6-6151-4F2D-B39E-01D6FABE0325}.qrx (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\xperf.exe (5001 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___s.click.taobao.com_khr1bAy.jpg (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_recommendcelltag_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\index.html (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\picker_ceil_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\dr.dll (601 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_active_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\image.png (5 bytes)
    %Program Files%\Tencent\QQBrowser\MouseGesture.dll (56 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\img\search.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images (4 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_sogou.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcr90.dll (4185 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\infobar_close_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\app_active.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\qblogo.png (868 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#app.ico (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\img\del2.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\history2.js (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\history_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\mainlist.ze (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_video.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\DB\homepage.db (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\init.js (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\init.js (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\sliderman.1.3.7.js (19 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\tab_bg_white.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\QBUtils.dll (12336 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\favicon\index.html#skin.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\blue.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\down.png (960 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\DB\history.db (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\background.html (122 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\msvcm90.dll (2129 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\wifi_dialog_close_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_floor_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_video_active.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\js\api.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\searchbar_searchengine_arrow.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\app_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_game_hover.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab91B4.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\installed_arrow.png (176 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_soso.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\https___mail.qq.com_.jpg (16 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\js\global.js (394 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{132A61AD-1025-4629-960D-B21EE8BAABB3}.qrx (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_google.png (919 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_recommendcelltag.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_active_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{C74EB4B8-B51A-4BF7-A213-E29859D69D83}.qrx (15 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\account_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\icon.png (487 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_newcelltag_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\closeBtnSearchbar.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\background.js (31 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\blue.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\default.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\img\up-down.png (999 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\favicon\index.html#account.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\css\style.css (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\plugin2.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{ACC06D2A-2285-4ed9-B4E4-0F3198501410}.qrx (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{3349050F-829E-4bb2-AACF-03E3A6B68677} (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\reader.html (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_offlineurl.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{6970B802-2F13-4038-B620-33B0211D26A0} (99 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}_1\QBSafe.dll (454 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Adblock\whitelist.ze (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\addressbar_blank.png (5 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\image\infobar_offlineurl.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\default-icon.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\navi.ico (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\init.js (4 bytes)
    %Program Files%\Tencent\QQBrowser\QBExtensionFramework.dll (3918 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\infobar_close_normal.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___tq.qq.com_qbrcenter_index.html_adtag=8gongge.jpg (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\accountInfoBar.html (794 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_hover_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\tssafeedit.dat (41 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{3E9C7A5B-D249-4C28-A451-53E1024AD354} (2 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\picker_floor.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_toast_unlocked.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\tool.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\index.html (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___www.3366.com__ADTAG=cop.QQbrowser.8new.jpg (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\app_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\small.html (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}.qrx (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_video.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\tab_bg_blank.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\background.js (31 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\QQTrace.ini (3 bytes)
    %Program Files%\Tencent\QQBrowser\Html\certerror.html (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___browser.qq.com_new_wechat1.0.html_type=1.jpg (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_374AF031F22A1FC086DCBA0C50021437 (1504 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\tab_bg_blank.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_baidu.png (870 bytes)
    C:\Users\"%CurrentUserName%"\Desktop\~Q浏览器.tmp (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_hover_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\app.js (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account\down.png (971 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\atbk2.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\index.html (1 bytes)
    %Program Files%\Tencent\QQBrowser\Assistant.dll (2321 bytes)
    %Program Files%\Tencent\QQBrowser\service\xperf.exe (2105 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\picker_ceil.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\wifi_dialog_cancel_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\tab_bg_blank.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\index.html (601 bytes)
    %Program Files%\Tencent\QQBrowser\manifest.json (261 bytes)
    %Program Files%\Tencent\QQBrowser\Html\lib\jquery.min.js (92 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\{43789A6F-8316-54A6-96D4-87874B9CC177} (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\plugin2.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_bing.png (442 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\account\up.png (971 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}.qrx (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\plugin3.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\icon_not_recommended.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\bkg.gif (22 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\account.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcp90.dll (3934 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\Microsoft.VC90.CRT\msvcr90.dll (4185 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___www.3366.com__ADTAG=cop.QQbrowser.8new.jpg (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\icon_suggested_action.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\hse.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_game_hover.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\down.png (960 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\picker_ceil.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_game.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_video_hover.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db\history.db (108 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_video_hover.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_newcelltag_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\image.png (5 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\img\del.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\business.js (9 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\css\ycalendar.css (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\img\checkbox.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\night.png (546 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_blank_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___s.click.taobao.com_khr1bAy.jpg (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\image\accountInfo.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_active_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{CAA4306F-826C-4c1b-8FC6-571F84949DB4} (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_selected_white.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\app_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\addressbar_white.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\shadow-bottom.png (2 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\history_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\lib\jquery.mCustomScrollbar.css (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\business.js (8 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\plugin3.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{7E2975A3-E661-42F2-8614-A9D18CBB20FE}.qrx (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\nsis_skin.gt (106 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowserFrame.dll (13493 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#history.ico (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\favicon\index.html#account.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_white_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\app.js (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\checkbox.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_hover_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\inforBar.html (800 bytes)
    %Program Files%\Tencent\QQBrowser\QQBrowser.exe (723 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\uninst.exe (3649 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\manifest.json (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Downloader.dll (4010 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\MouseGesture.dll (872 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\arrowdown_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\css\app.css (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\bkg.gif (22 bytes)
    %Program Files%\Tencent\QQBrowser\Html\error.html (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\accountInfo.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\up-down.png (999 bytes)
    %Program Files%\Tencent\QQBrowser\service\perfctrl.dll (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin_active.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\QQBrowserSecurityCenter.exe (673 bytes)
    %Program Files%\Tencent\QQBrowser\Dialogs.dll (7385 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\closeBtnSearchbar.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\icon.fw.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\searchbar_searchengine_arrow.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\service\7z.exe (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_video_active.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___tq.qq.com_qbrcenter_index.html_adtag=8gongge.jpg (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\css\base.css (2 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manifest.json (197 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\qblogo.png (868 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\QQBrowserLiveup.exe (1425 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\addressbar_white.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\site_text.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\articlecontent.css (12 bytes)
    %Program Files%\Tencent\QQBrowser\resources.pri (3 bytes)
    %Program Files%\Tencent\QQBrowser\Downloader.dll (3073 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Adblock\{43789A6F-8316-54A6-96D4-87874B9CC177} (5 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\css\history.css (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\index.ini (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件\QQ浏览器\QQ浏览器.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\whitelist.ze (1 bytes)
    %Program Files%\Tencent\QQBrowser\WebpDecodeFilter.dll (673 bytes)
    %Program Files%\Tencent\QQBrowser\Html\lib\jquery.mCustomScrollbar.concat.min.js (37 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{B00DFF21-511E-4249-BCB9-EECC370D796B} (430 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#skin.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{7E2975A3-E661-42F2-8614-A9D18CBB20FE}.qrx (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\error.html (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Adblock\wbg.png (136 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\icon_not_recommended.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_recommendcelltag.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___www.qq.com__pgv_ref=qqBrowserPC.jpg (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\reader.html (30 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\history_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\favicon\index.html#app.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\certerror.html (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\screen.css (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\img\atbk1.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\image\infobar_close_normal.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\Private-icon.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_hover_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\background.html (122 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\up-down.png (999 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_recommendcelltag_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{3E9C7A5B-D249-4C28-A451-53E1024AD354} (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\addressbar_white.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\jquery.mCustomScrollbar.concat.min.js (37 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\addressbar_blank.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\index.ini (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\app.js (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\perfctrl.dll (3447 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\checkbox.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\green.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\index.html (86 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\app.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\history_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_toast_locked.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{A1D7EDF6-6151-4F2D-B39E-01D6FABE0325}.qrx (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\loading.gif (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account\down.png (971 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\installed_arrow.png (176 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\js\global.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_selected_blank.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\event\bg.png (28 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Resource.dll (1365 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\js\inforBar.js (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\css\style.css (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar91B5.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_toast_unlocked.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{00000000-0000-0000-0000-000000000000}\jquery.js (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{B00D20E2-207A-431A-9712-E1279792681B} (89 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\7z.exe (1209 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\warn-dialog-close.png (295 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_mask.png (923 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\msvcp90.dll (6900 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\PerfTraceService.exe (2934 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\js\init.js (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{E5914276-7752-43C4-9723-50EE9CF51AD8}.qrx (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_fav.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\api.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\nsis_skin.gt (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\content.js (30 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_game_active.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\PrScrn.dll (2517 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{44A126BF-51C2-48AD-A593-94B50071EB64}.qrx (39 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\del2.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_soso.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\del.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_selected_blank_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_video.png (3 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_hover_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\search.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_white.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\app.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\video\vd.ini (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\js\inforBar.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\large_installed_arrow.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\plugin1.png (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\QBUtils.dll (12287 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\small.html (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\jquery.easing.js (3 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\image\infobar_login.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\hse.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{5062F1C6-D76B-43c8-ADAE-D060662C6546}\extplayer.js (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\text_light.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\api.js (3 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\icon_suggested_action.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\image\infobar_fav.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\sliderman.1.3.7.js (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\search.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\site_text.png (5 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_toast_locked.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\small.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\search_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{6970B802-2F13-4038-B620-33B0211D26A0} (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\pixel.gif (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\pixel.gif (43 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\js\tool.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\text_light.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QBExtensionFramework.dll (3766 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}_1\manifest.json (256 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\icon_suggested_action.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.easing.js (3 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_newcelltag.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\BugReport.exe (2321 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\account\down.png (971 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\event\bg.png (28 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_selected_blank.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\qqbrowser_home.jpg (14 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\loading.gif (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\css\style.css (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Microsoft.VC90.CRT\msvcr90.dll (8224 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{CD36E3DB-304A-48EF-A8A2-D873F608D2AE}.qrx (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\screen.css (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\loading.gif (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\Config.xml (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\large_installed_arrow.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\certerror.html (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\theme_ie.png (15 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\history2.js (21 bytes)
    %Program Files%\Tencent\QQBrowser\Html\lib\ycalendar.js (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\small.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\atbk1.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_login.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_active_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_newcelltag.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\css\style.css (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{CAA4306F-826C-4c1b-8FC6-571F84949DB4} (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\unlock_active_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\night.png (546 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_ceil_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_game_hover.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{3349050F-829E-4bb2-AACF-03E3A6B68677} (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\warn-dialog-close.png (295 bytes)
    %Program Files%\Tencent\QQBrowser\QBSafe.dll (454 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_toast_unlocked.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\picker_floor_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{C74EB4B8-B51A-4BF7-A213-E29859D69D83}.qrx (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\plugin1.png (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}.qrx (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\image\infobar_close_active.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_selected_white_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db\homepage.db (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account\up.png (971 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\hse.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_recommendcelltag_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\service\qqtrack.xml (4 bytes)
    %Program Files%\Tencent\QQBrowser\Microsoft.VC90.CRT\msvcm90.dll (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\Microsoft.VC90.CRT\msvcp90.dll (3361 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\global.js (394 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\global.js (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_google.png (919 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\search_btn.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\QRCode.dll (31 bytes)
    %Program Files%\Tencent\QQBrowser\QQBrowserLiveup.exe (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\sogou_web.png (5 bytes)
    C:\Users\"%CurrentUserName%"\Desktop\上网导航.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_active.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\pixel.gif (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\bggradient_day.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\default-icon.png (1 bytes)
    C:\Users\"%CurrentUserName%"\Desktop\QQ浏览器.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\Private-icon.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UserPinnedTemp\~Q浏览器.tmp (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\security.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowserSecurityCenter.exe (2015 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_selected_blank_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Video\vd.ini (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___qzone.qq.com_.jpg (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\tool.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\js\business.js (9 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\image\infobar_close_normal.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{132A61AD-1025-4629-960D-B21EE8BAABB3}.qrx (17 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\js\init.js (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UserPinnedTemp\QQ浏览器.lnk (4 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\close.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\{B00DFF21-511E-4249-BCB9-EECC370D796B} (430 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\tab_bg_white.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___qzone.qq.com_.jpg (12 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\image\security.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\css\ycalendar.css (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\searchbar_searchengine_arrow.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\sogou_web.png (5 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\history.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\api.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\img\down.png (960 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\manifest.json (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_selected_blank.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\pink.png (716 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\large_installed_arrow.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\PrScrn.dll (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\license.txt (17 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\arrowdown_hover_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\db\random.db (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Adblock\wbg.png (136 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_bing.png (442 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\wifi_dialog_continue_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\history.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\tssafeedit.dat (41 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\imgSearch.png (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件\QQ浏览器\~Q浏览器.tmp (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\QBInstaller.dll (1275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\global.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\HomePage\0\website\bgsearch_day.jpg (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\css\style.css (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\history_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\js\injectReader.js (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\del2.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12\QBSafe.dll (454 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account\up.png (971 bytes)
    %Program Files%\Tencent\QQBrowser\uninst.exe (2105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\css\style.css (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\uninstallBtn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\css\style.css (6 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\account_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\EventTracing.dll (39 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\yellow.png (626 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}\8.0.0.12\manifest.json (256 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\small_installed_arrow.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\css\articlecontent.css (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.min.js (92 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\sliderman.1.3.7.js (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\QQ浏览器.lnk (2 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_active_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\{B00D20E2-207A-431A-9712-E1279792681B} (89 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\image\icon.png (487 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\gray.png (501 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\qqbrowser_home.jpg (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___speed.qq.com_act_a20141103plan_.jpg (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Adblock\mainlist.ze (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin_active.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_hover_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\default.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_selected_white_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\error.html (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\history2.js (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\EventTracing.dll (1326 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\css\style.css (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\resources.pri (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\lock_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\small.png (2 bytes)
    %Program Files%\Tencent\QQBrowser\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{00000000-0000-0000-0000-000000000000}\jquery.js (92 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\inforBar.html (800 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___speed.qq.com_act_a20141103plan_.jpg (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\css\ycalendar.css (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\wifi_dialog_cancel_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{0508DF1F-2AB6-4fac-A99E-45BBBF24E1E6}.qrx (244 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\img\closeBtnSearchbar.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\service\qqtrack.xml (4 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\shadow-bottom.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\theme.png (25 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\app_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\service\QQTrace.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QBUtils.dll (17689 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\index.html (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\tab_bg_white.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowserLiveup.exe (3502 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\js\business.js (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\qqtrack.xml (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\favicon\index.html#history.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\manifest.json (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\default-icon.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\theme.png (25 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\green.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\plugin2.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_baidu.png (870 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_recommendcelltag.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\css\base.css (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\wifi_dialog_close_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\qblogo.png (868 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_soso.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Dialogs.dll (10771 bytes)
    %Program Files%\Tencent\QQBrowser\Html\lib\template.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_active_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\ycalendar.js (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\imgSearch.png (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\small_installed_arrow.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\js\init.js (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QRCode.dll (31 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\account_active.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\js\api.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\template.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}.qrx (364 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.mCustomScrollbar.css (9 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\arrowdown.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\history\img\atbk2.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\pink.png (716 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_baidu.png (870 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\bggradient_day.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\shadow-bottom.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\qqtrack.xml (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\js\injectReader.js (19 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\wifi_dialog_close_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\atbk2.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\index.html (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{CD36E3DB-304A-48EF-A8A2-D873F608D2AE}.qrx (30 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\css\app.css (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\jquery.mCustomScrollbar.concat.min.js (37 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{44A126BF-51C2-48AD-A593-94B50071EB64}.qrx (39 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\wifi_dialog_cancel_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\icon.fw.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete_hover_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\quicklink_newcelltag.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\search_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\css\history.css (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\https___mail.qq.com_.jpg (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Thumb\http___www.qq.com__pgv_ref=qqBrowserPC.jpg (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\icon_not_recommended.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\QQ浏览器.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\images\searchlogo_24_sogou.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\site_text.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\private.html (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_close_active.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\plugin1.png (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_sogou.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\arrowdown_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\picker_floor.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\NetWork.dll (2602 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\small_installed_arrow.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\css\app.css (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{E5914276-7752-43C4-9723-50EE9CF51AD8}.qrx (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_hover_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\jquery.min.js (92 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\DB\random.db (10 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\arrowdown_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\jquery.mCustomScrollbar.css (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\arrowdown_hover_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\Microsoft.VC90.CRT\msvcp90.dll (3934 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\favicon\index.html#app.ico (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\index.html (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\Temp\{ACC06D2A-2285-4ed9-B4E4-0F3198501410}.qrx (12 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\bkg.gif (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\lock_active_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\text_light.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\searchlogo_24_bing.png (442 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\favicon\index.html#skin.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\wifi_dialog_continue_btn.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\lib\jquery.easing.js (3 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\warn-dialog-close.png (295 bytes)
    %Program Files%\Tencent\QQBrowser\QQBrowserFrame.dll (11518 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\navi.ico (15 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\picker_floor.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_close_normal.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\homepage\0\website\bgsearch_day.jpg (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\favicon\index.html#account.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\QQBrowser.exe (1661 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~Q浏览器.tmp (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\delete_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\arrowdown.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\TridentCore.dll (9754 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\yellow.png (626 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\history_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\history.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\delete_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\private.html (3 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\skin_selected_white.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\js\search.js (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\global.js (394 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1212 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\api.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\images\searchlogo_24_google.png (919 bytes)
    %Program Files%\Tencent\QQBrowser\Html\images\Private-icon.png (3 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\image\infobar_close_active.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\service\PerfTraceService.exe (1707 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\CustomerJoinPlan.txt (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\content.js (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\lib\template.js (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\arrowdown_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\uninstallBtn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\lock_hover_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Infobar\image\infobar_close_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\app\images\uninstallBtn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\close.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\skin\LightStripes.gt (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\css\history.css (8 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\theme_ie.png (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\event\bg.png (28 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\picker_floor_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\delete.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\grid\unlock_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\BugReport.exe (7256 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}\8.0.0.25\image\infobar_close_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\js\business.js (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\skin_mask.png (923 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\skin\theme_ie.png (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Liveup\Temp\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_video_active.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_374AF031F22A1FC086DCBA0C50021437 (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\manifest.json (5 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\quicklink_newcelltag_ie.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\app\images\plugin3.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_game_active.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\small.html (2 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\addressbar_blank.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\arrowdown_hover_ie.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\private.html (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\lib\ycalendar.js (4 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manifest.json (197 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\accountInfoBar.html (794 bytes)
    %Program Files%\Tencent\QQBrowser\Resource.dll (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\default.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\QQ浏览器.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\js\search.js (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\skin\picker_ceil_hover.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\app.ico (284 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{B9C6ADA1-8B36-4c8d-97E5-1F89AE3A5341}\images\gray.png (501 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\js\business.js (8 bytes)
    %Program Files%\Tencent\QQBrowser\QBUtils.dll (12336 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\dr.dll (864 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\dock_game_active.png (3 bytes)
    %Program Files%\Tencent\QQBrowser\NetWork.dll (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Infobar\image\infobar_close_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\skin\skin_mask.png (923 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\del.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\TridentCore.dll (7345 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}.qrx (2105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\Extensions8\{5062F1C6-D76B-43c8-ADAE-D060662C6546}\extplayer.js (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\history\img\atbk1.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\img\app.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\manage\favicon\index.html#history.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\quickaccess\img\dock_game.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\InstModules\Microsoft.VC90.CRT\msvcr90.dll (4840 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\bin\Assistant.dll (6284 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\quickaccess\img\grid\quicklink_toast_locked.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\history\img\search.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\account_active.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{309147A1-5CA9-4082-BAB3-BF9020CDE0C2}_1\image\infobar_close_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\app\images\wifi_dialog_continue_btn.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\Temp\{807849B3-40D8-42E3-8001-D541FD7CEBFB}_1\Html\manage\img\app_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manifest.json (197 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\grid\unlock.png (1 bytes)
    %Program Files%\Tencent\QQBrowser\Html\quickaccess\img\dock_video_hover.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\12au144633\appdata\thumb\http___browser.qq.com_new_wechat1.0.html_type=1.jpg (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Extensions8\{807849B3-40D8-42E3-8001-D541FD7CEBFB}\8.0.3.25\Html\manage\img\close.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\22.gif (325300 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\7185bdf1gw1f05vpdktqrg20go0a5u10[1].gif (306430 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Browser_V5.5.7852.9_r_4640_(Build1512022057).exe (26349 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\7185bdf1gw1f05vp3ys4ig20s60i07ww[1].gif (1036496 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\21.gif (1101124 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\ZipDLL.dll (3791 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\Base64.dll (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\BaiduPlayer5SetupSilent_363.exe (146246 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\System.dll (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\UCBrowser_V6.1.2107.204_4640_(Build1703071827)_ChannelU_03081433[1].exe (24208 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nssF1ED.tmp\Inetc.dll (40 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\V8._85296_20150814221218.exe (41066 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\msvcp120.dll (458 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BDPlayer\conf\ReportInfo.dat (190 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Skin\001-Cool Air.gt (252503 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\Skin\LightStripes.gt (601 bytes)
    C:\Windows\Tasks\QQBrowser Udpater Task(Core).job (280 bytes)
    C:\Windows\Tasks\QQBrowser Udpater Task.job (276 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\update.ini (106 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\cli63E1.tmp.qbl (1098 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\cli5D2C.tmp.qbl (11807 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\ClientUpdate\cli75BD.tmp.qbl (194 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\dr_packet.dat (728 bytes)
    %Program Files%\Tencent\QQBrowser\QQBrowserConfig.dat (114 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Tencent\QQBrowser\repeal.xml (31 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\O3PNY3RBV9AO0PU2B5L8.temp (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_add_url.xml (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\imglist.setting.checkbox.png (928 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_imageadjust_image.xml (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\rmvb.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.connect.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\yes.png (17 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_imageadjust_color.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\codecs\MpaDec.ax (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\pncrt.dll (287 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\SRT.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\new_version.png (16 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MTS.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\addurl.combobox.btn.dropdown.png (835 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\fileinfo.dll (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.screenshot.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_mouse.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.thumbnail.main.png (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_playlist_online.xml (765 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\color.xml (196 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\asf.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.menu.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\codecs\RealMediaSplitter.ax (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.stop.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\bk.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.imageadjust.logo.png (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\flv.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\codecs\CoreAAC.ax (328 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_play.xml (918 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_subtitle.xml (281 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.caption.png (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\bugreport_BDPlayer.ini (255 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\btn_bk.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.cancel.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.setting.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.playcontroller.channel1.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.main.open.png (15 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\SSA.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.close.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_playlist.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\IntelQuickSyncDecoder.dll (347 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_playcontroller.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.main.menu.png (12 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.hotkey.tab.png (241 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.sys.restore.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.screenshot.thumbnail.line.png (947 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\progress_front.png (18 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\wma.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\string.xml (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.imageadjust.option.select.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MP2V.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_playlist_popbox.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\close.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.help.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mp3.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.feedback.png (5 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.playcontroller.separator.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\3gp.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\imglist.setting.radio.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.imageadjust.channel1.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\vob.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.tools.png (4 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_setting.xml (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.sys.max.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\bdcommon.dll (427 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_screenshort.xml (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\ffsrv.exe (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\xReport.exe (171 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_playlist_local.xml (856 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.open.png (5 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\imglist.setting.tree.expand.png (248 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_display.xml (700 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.delete.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\progress_bk.png (18 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.setting.png (7 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\title_bk.png (4 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.nottopmost.png (4 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\scroll.v.playlist.bg.png (144 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\PlayerApp.exe (400 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.fullscreen.close.png (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\font.xml (810 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\font.xml (166 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.playlist.show.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\msvcr120.dll (970 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\addurl.combobox.edit.bg.png (435 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\codecs\real\cook.dll (74 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.fullscreen.open.png (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\codecs\VEFilter.ax (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.logo.line.png (936 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MPEG4.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\bdxview.dll (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_screenshot.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\xnet.dll (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\m2ts.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\scroll.setting.thumb.v.png (375 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\onlinevideo_error.png (6 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\edit.setting.border.png (973 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_sound.xml (706 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayer.exe (456 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.main.mask.png (174 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\bugreport_Tray.ini (255 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.playlist.hide.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\update_line.png (947 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\skin.xml (840 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_file.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.menu.sub.more.png (964 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\WEBM.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\window_expand.png (22 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.player.shadow.png (4 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\avresample-lav-2.dll (161 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\avi.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_playlist_bubble.xml (306 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.main.logo.png (256 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\bdlog.dll (39 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.png (973 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\menu_tray.xml (880 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.messagebox.body.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_basic.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.tools.topmost.png (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.imageadjust.channel2.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\window_ask.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\Player.ico (173 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\xUpdate.exe (999 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\ASS.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.row.play.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\no.png (17 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\ts.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\style.xml (12 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.messagebox.caption.png (4 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.file.png (930 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_main_playwnd.xml (106 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.row.close.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\FFVideo.ax (983 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\FFSplitter.ax (500 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_play.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.row.open.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.thumbnail.highlight.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.logo.png (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\scroll.setting.bg.v.png (931 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MOV.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayerTray.exe (1923 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\codecs\FLVSplitter.ax (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.playlist.png (166 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.play.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\FFAudio.ax (266 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\wmv.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\codecs\AudioSwitcher.ax (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.volume.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\M4V.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\MOD.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.menu.item.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_hotkey.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\style.xml (331 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.thumbnail.timebk.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\update_check.png (19 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.row.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\pva.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\f4v.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playlist.separation.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.ok.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\TPS.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\BDWebcore.dll (780 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.player.2.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\imglist.setting.checkbox.partselect.png (412 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.play.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_main.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\avutil-lav-54.dll (431 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.playcontroller.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\tp.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.close.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\progress_front.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.playcontroller.channel2.png (176 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_messagebox.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\avformat-lav-56.dll (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\BDUnInstall.exe (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mpg.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\bdxplayer.dll (70 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\menu_playlist.xml (4 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.imageadjust.option.unselect.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.exit.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\M2P.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\effect.xml (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\OnlineVideo.ini (73 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.playlist.caption.png (249 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_tools.xml (516 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.line.png (924 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images.xml (20 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.volume.open.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.main.tools.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\scroll.v.playlist.thumb.png (299 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_hotkey_file.xml (942 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.main.audio.logo.png (251 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\progress_bk.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\codecs\VSFilter.dll (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mpeg.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.thumbnail.arrow.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\avcodec-lav-56.dll (780 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\SWF.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.sys.min.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.about.png (29 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\menu_main.xml (10 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.setting.2.png (955 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\DIVX.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.imageadjust.thumb.png (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_update.xml (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\xmanager.dll (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.messagebox.close.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\bpc.ico (15 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\menu_player.xml (8 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\tab_setting_subtitle.xml (719 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_about.xml (825 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\codecs\real\drvc.dll (275 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.player.png (161 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_image_adjust.xml (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\swscale-lav-3.dll (481 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.screen.thumbnail.picbk.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.setting.tab.png (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mkv.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\rm.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\skin.xml (17 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\bsed.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\filters.xml (11 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_main_mask.xml (2 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\window_thumbnail.xml (536 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\bdxlogic.dll (158 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.playcontroller.pause.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\bugreport.exe (189 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.imageadjust.reset.png (3 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\bg.messagebox.line.png (947 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\slider.playcontroller.thumb.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\icon.menu.select.png (268 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\images\btn.sys.close.png (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\avfilter-lav-5.dll (189 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\mp4.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\icon\DAT.ico (26 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\update\latest_version.png (15 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\OpenMediaUrl.exe (1 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\res\themes\default\MediaUrlHelp\images\bk.png (9 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\bugreport_Update.ini (255 bytes)
    %Program Files%\baidu\BDPlayer\5.1.1.9\libbluray.dll (254 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BDPlayer\update\BDPlayer5.6.2.16_145.exe.bdtp (1014852 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BindTaskSys\SysData\XTask.db (395 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BindTaskSys\SysData\XTask.db-journal (15428 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Baidu\BCommon\XDownlaodConfig.ini (1191 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BDPlayer\update\BDPlayer5.6.2.16_145.exe.bdre (4312 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\百度影音5\卸载百度影音5.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\百度影音5.lnk (4 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\百度影音5\百度影音5.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\Desktop\百度影音5.lnk (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Baidu\BDPlayer\conf\TaskBar\百度影音5.lnk (2 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BDPlayer_AutoRun" = "%Program Files%\baidu\BDPlayer\5.1.1.9\BDPlayerTray.exe"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

Average: 2 (5 votes)

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now