Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Hotmail account blocked


  • Please log in to reply

#1
mozzer11

mozzer11

    Member

  • Member
  • PipPipPip
  • 423 posts
Went to sign in to my Hotmail today and it's says my account has been blocked. I'm worried that I might be infected with a RAT as I change my hotmail password often and can't see any other way someone could access it. Can someone see if I have any malicious stuff on my pc? thanks.
My otl log:

OTL logfile created on: 08/04/2011 22:05:49 - Run 3
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Jamie\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 10.06 Gb Free Space | 13.50% Space Free | Partition Type: NTFS

Computer Name: JAMMO | User Name: Jamie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/24 12:24:34 | 000,072,936 | ---- | M] (SANDBOXIE L.T.D) -- C:\Program Files\Sandboxie\SbieSvc.exe
PRC - [2011/03/21 11:17:56 | 000,068,928 | ---- | M] (Nalpeiron Ltd.) -- C:\WINDOWS\system32\NLSSRV32.EXE
PRC - [2011/03/21 11:17:44 | 000,196,928 | ---- | M] (Nitro PDF Software) -- C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
PRC - [2011/03/18 18:53:19 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2011/03/18 18:53:06 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/02/11 19:37:58 | 002,548,552 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2011/02/11 19:37:53 | 001,803,224 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011/02/07 02:09:13 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jamie\My Documents\Downloads\OTL.exe
PRC - [2010/11/22 23:05:35 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/11/22 23:05:35 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010/11/22 23:05:35 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010/03/04 23:38:00 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2010/01/14 22:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002/04/24 20:04:24 | 000,090,112 | ---- | M] (BT, Inc.) -- C:\WINDOWS\system32\gsicon.exe


========== Modules (SafeList) ==========

MOD - [2011/02/11 19:38:49 | 000,285,480 | ---- | M] (COMODO) -- C:\WINDOWS\system32\guard32.dll
MOD - [2011/02/07 02:09:13 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jamie\My Documents\Downloads\OTL.exe
MOD - [2010/08/23 17:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (TipCtrl)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/03/24 12:24:34 | 000,072,936 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2011/03/21 11:17:56 | 000,068,928 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\WINDOWS\system32\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2011/03/21 11:17:44 | 000,196,928 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe -- (NitroDriverReadSpool)
SRV - [2011/02/11 19:37:53 | 001,803,224 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2010/11/22 23:05:35 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/11/22 23:05:35 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/10/16 01:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/03/18 17:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state)
SRV - [2010/03/18 14:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 14:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2010/03/04 23:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)


========== Driver Services (SafeList) ==========

DRV - [2011/03/24 12:24:30 | 000,126,696 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Program Files\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2011/02/23 17:04:32 | 000,013,496 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2011/02/11 19:38:49 | 000,094,784 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2011/02/11 19:38:48 | 000,239,368 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2011/02/11 19:38:48 | 000,027,576 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2010/12/08 14:12:02 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2010/11/22 23:05:35 | 000,126,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010/11/22 23:05:35 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/10/21 10:45:18 | 000,025,216 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2010/10/21 10:45:16 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2010/10/21 10:45:16 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2010/09/17 16:40:06 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2010/07/28 11:27:36 | 006,108,776 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2010/05/12 13:23:04 | 000,016,896 | ---- | M] (Danish Wireless Design A/S) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FlashUSB.sys -- (FlashUSB)
DRV - [2010/05/05 03:45:04 | 004,807,680 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2010/05/03 07:49:18 | 000,225,232 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2010/04/12 09:44:34 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2010/02/25 18:51:02 | 000,025,216 | ---- | M] (The OpenVPN Project) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)
DRV - [2009/11/18 00:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/11/18 00:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009/11/12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009/08/22 19:25:00 | 000,009,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys -- (RivaTuner32)
DRV - [2009/05/11 12:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009/05/11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2008/10/30 00:05:58 | 000,031,896 | ---- | M] (DemoForge, LLC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dfmirage.sys -- (dfmirage)
DRV - [2008/04/13 22:06:06 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/01/11 14:52:18 | 010,398,208 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)
DRV - [2007/07/20 18:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2006/11/10 14:08:50 | 000,024,064 | ---- | M] () [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ATITool.sys -- (ATITool)
DRV - [2004/08/22 17:31:48 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\d347prt.sys -- (d347prt)
DRV - [2004/08/22 17:31:10 | 000,155,136 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\d347bus.sys -- (d347bus)
DRV - [2002/05/14 11:15:20 | 000,252,883 | ---- | M] (GlobespanVirata Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gwausb.sys -- (wanusb)
DRV - [2002/03/22 10:01:06 | 000,027,147 | ---- | M] (GlobespanVirata Inc.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\gafwload.sys -- (gafwload)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en-US.start2....en-US:official"
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/11/07 03:12:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/27 20:01:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 18:28:17 | 000,000,000 | ---D | M]

[2010/11/08 03:31:09 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jamie\Application Data\Mozilla\Extensions
[2010/11/08 03:31:09 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jamie\Application Data\Mozilla\Extensions\[email protected]
[2011/03/25 18:28:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\v6wproif.default\extensions
[2010/09/03 00:53:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\v6wproif.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/06 00:28:11 | 000,000,000 | ---D | M] ("StumbleUpon") -- C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\v6wproif.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2010/10/20 16:33:24 | 000,002,569 | ---- | M] () -- C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\v6wproif.default\searchplugins\askcom.xml
[2011/03/27 20:01:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/02 20:16:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/23 02:06:30 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JAMIE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\V6WPROIF.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
[2011/03/18 18:53:24 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/09/15 05:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/02/24 03:33:04 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [GSICONEXE] C:\WINDOWS\System32\gsicon.exe (BT, Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LogMeIn GUI] File not found
O4 - HKLM..\Run: [RemHelp] C:\WINDOWS\System32\remhelp.exe ()
O4 - HKLM..\Run: [RivaTunerStartupDaemon] C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: internet ([]about in Internet)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcp...ols/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zon...kr.cab56986.cab (Checkers Class)
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} http://uk.midas.game...l/kingcomie.cab (king.com)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zon...1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1283385001734 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1286578378953 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Jamie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jamie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/31 04:04:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/07 18:55:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Application Data\ManyCam
[2011/04/07 18:33:05 | 000,000,000 | ---D | C] -- C:\Program Files\Sandboxie
[2011/04/07 18:33:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Sandboxie
[2011/04/05 20:06:59 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2011/04/04 01:57:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Application Data\IObit
[2011/04/04 01:57:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Smart Defrag 2
[2011/04/04 01:57:26 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2011/04/04 01:54:25 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Jamie\Recent
[2011/04/04 01:22:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\My Documents\Drakensang
[2011/04/04 01:18:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Drakensang
[2011/04/04 01:00:51 | 000,000,000 | ---D | C] -- C:\Program Files\Drakensang
[2011/03/31 05:58:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Desktop\Dragon Age II
[2011/03/31 05:06:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Start Menu\Programs\Techno eJay 4
[2011/03/31 05:04:58 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Components
[2011/03/31 05:04:43 | 000,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2011/03/31 05:04:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\speech
[2011/03/31 05:04:15 | 000,348,160 | ---- | C] (eJay AG) -- C:\WINDOWS\System32\eJ_UniDialog.ocx
[2011/03/31 05:04:15 | 000,286,720 | ---- | C] (Ejay AG) -- C:\WINDOWS\System32\EjWaveEditorCtrl.ocx
[2011/03/31 05:04:15 | 000,100,864 | ---- | C] (zwei) -- C:\WINDOWS\System32\eJ_Explorer.ocx
[2011/03/31 05:04:15 | 000,077,824 | ---- | C] (eJay Entertainment GmbH) -- C:\WINDOWS\System32\eJ_Enumerator.dll
[2011/03/31 05:04:14 | 000,236,032 | ---- | C] (Abysmal Software) -- C:\WINDOWS\System32\devil.dll
[2011/03/31 05:04:14 | 000,159,744 | ---- | C] (Dart Communications) -- C:\WINDOWS\System32\DartSock.dll
[2011/03/31 05:04:14 | 000,106,496 | ---- | C] (Dart Communications) -- C:\WINDOWS\System32\DartWeb.dll
[2011/03/31 05:04:14 | 000,036,864 | ---- | C] (eJay) -- C:\WINDOWS\System32\eJayWMExport.dll
[2011/03/31 05:04:10 | 000,000,000 | ---D | C] -- C:\eJay
[2011/03/31 04:59:22 | 000,097,280 | ---- | C] (Common Controls Replacement Project (CCRP)) -- C:\WINDOWS\System32\ccrpbds5.dll
[2011/03/29 19:51:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Start Menu\Programs\VirtualDJ
[2011/03/29 19:50:58 | 000,000,000 | ---D | C] -- C:\Program Files\VirtualDJ
[2011/03/29 19:50:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\My Documents\VirtualDJ
[2011/03/29 19:41:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\My Documents\The Lord of the Rings Online
[2011/03/29 19:41:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Local Settings\Application Data\The Lord of the Rings Online
[2011/03/29 00:10:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Codemasters
[2011/03/28 23:29:54 | 000,000,000 | ---D | C] -- C:\Program Files\Codemasters
[2011/03/27 23:19:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Application Data\Nitro PDF
[2011/03/27 23:19:16 | 000,026,432 | ---- | C] (Nitro PDF Software) -- C:\WINDOWS\System32\nitrolocalmon.dll
[2011/03/27 23:19:16 | 000,017,728 | ---- | C] (Nitro PDF Software) -- C:\WINDOWS\System32\nitrolocalui.dll
[2011/03/27 23:18:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2011/03/27 23:18:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nitro PDF
[2011/03/27 23:18:50 | 000,000,000 | ---D | C] -- C:\Program Files\Nitro PDF
[2011/03/27 23:17:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Application Data\Downloaded Installations
[2011/03/27 19:26:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2011/03/27 19:26:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\EA Core
[2011/03/26 23:13:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Local Settings\Application Data\storage
[2011/03/26 23:13:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
[2011/03/26 13:55:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment
[2011/03/21 11:17:56 | 000,068,928 | ---- | C] (Nalpeiron Ltd.) -- C:\WINDOWS\System32\NLSSRV32.EXE
[2011/03/17 19:12:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Local Settings\Application Data\Spotify
[2011/03/17 19:12:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jamie\Application Data\Spotify
[2011/03/17 19:12:25 | 000,000,000 | ---D | C] -- C:\Program Files\Spotify
[2011/02/03 18:24:15 | 000,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys
[2011/02/03 18:24:15 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys
[2010/10/20 01:57:47 | 000,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2010/10/20 01:57:46 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2010/10/20 01:57:46 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2010/10/20 01:57:46 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll
[2 C:\Documents and Settings\Jamie\*.tmp files -> C:\Documents and Settings\Jamie\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/08 18:02:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/08 16:26:30 | 000,044,544 | ---- | M] () -- C:\Documents and Settings\Jamie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/08 00:34:09 | 000,001,500 | ---- | M] () -- C:\WINDOWS\Sandboxie.ini
[2011/04/07 18:33:05 | 000,000,766 | ---- | M] () -- C:\Documents and Settings\Jamie\Desktop\Sandboxed Web Browser.lnk
[2011/04/07 18:33:05 | 000,000,766 | ---- | M] () -- C:\Documents and Settings\Jamie\Application Data\Microsoft\Internet Explorer\Quick Launch\Sandboxed Web Browser.lnk
[2011/04/07 16:40:21 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/04 01:18:55 | 000,001,600 | ---- | M] () -- C:\Documents and Settings\Jamie\Desktop\Drakensang.lnk
[2011/04/01 03:40:19 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Jamie\Desktop\Fahfoshhh.lnk
[2011/03/31 17:52:46 | 000,496,458 | ---- | M] () -- C:\WINDOWS\t_eJay4.inf
[2011/03/31 06:23:46 | 000,000,865 | ---- | M] () -- C:\Documents and Settings\Jamie\Desktop\Dragon Age 2 by TPTB.lnk
[2011/03/31 05:06:39 | 000,001,427 | ---- | M] () -- C:\Documents and Settings\Jamie\Desktop\Techno eJay 4.lnk
[2011/03/29 22:56:39 | 000,150,792 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/29 19:51:09 | 000,000,721 | ---- | M] () -- C:\Documents and Settings\Jamie\Desktop\VirtualDJ Home FREE.lnk
[2011/03/29 17:47:51 | 000,000,984 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk
[2011/03/29 17:41:49 | 000,041,984 | ---- | M] () -- C:\Documents and Settings\Jamie\My Documents\JulieCV.doc
[2011/03/29 00:10:53 | 000,001,904 | ---- | M] () -- C:\Documents and Settings\Jamie\Desktop\The Lord of the Rings Online.lnk
[2011/03/27 23:19:08 | 000,001,770 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Nitro PDF Professional.lnk
[2011/03/27 16:20:14 | 000,495,404 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/27 16:20:14 | 000,085,172 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/21 11:17:56 | 000,068,928 | ---- | M] (Nalpeiron Ltd.) -- C:\WINDOWS\System32\NLSSRV32.EXE
[2011/03/21 11:15:56 | 000,017,728 | ---- | M] (Nitro PDF Software) -- C:\WINDOWS\System32\nitrolocalui.dll
[2011/03/21 11:15:54 | 000,026,432 | ---- | M] (Nitro PDF Software) -- C:\WINDOWS\System32\nitrolocalmon.dll
[2011/03/20 23:40:21 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\Jamie\Desktop\JoeeeCV.doc
[2 C:\Documents and Settings\Jamie\*.tmp files -> C:\Documents and Settings\Jamie\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/07 18:33:12 | 000,000,766 | ---- | C] () -- C:\Documents and Settings\Jamie\Desktop\Sandboxed Web Browser.lnk
[2011/04/07 18:33:12 | 000,000,766 | ---- | C] () -- C:\Documents and Settings\Jamie\Application Data\Microsoft\Internet Explorer\Quick Launch\Sandboxed Web Browser.lnk
[2011/04/07 18:33:10 | 000,001,500 | ---- | C] () -- C:\WINDOWS\Sandboxie.ini
[2011/04/04 01:57:33 | 000,029,520 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/04/04 01:57:33 | 000,013,496 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/04/04 01:18:55 | 000,001,600 | ---- | C] () -- C:\Documents and Settings\Jamie\Desktop\Drakensang.lnk
[2011/04/01 03:40:19 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Jamie\Desktop\Fahfoshhh.lnk
[2011/03/31 17:52:46 | 000,496,458 | ---- | C] () -- C:\WINDOWS\t_eJay4.inf
[2011/03/31 06:22:45 | 000,000,865 | ---- | C] () -- C:\Documents and Settings\Jamie\Desktop\Dragon Age 2 by TPTB.lnk
[2011/03/31 05:06:39 | 000,001,427 | ---- | C] () -- C:\Documents and Settings\Jamie\Desktop\Techno eJay 4.lnk
[2011/03/31 05:04:14 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\eJayxQuell.ax
[2011/03/31 05:04:14 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\eJayxWaveDest.ax
[2011/03/31 05:04:14 | 000,029,696 | ---- | C] () -- C:\WINDOWS\System32\pthread.dll
[2011/03/29 19:51:09 | 000,000,721 | ---- | C] () -- C:\Documents and Settings\Jamie\Desktop\VirtualDJ Home FREE.lnk
[2011/03/29 17:47:51 | 000,000,984 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk
[2011/03/29 17:41:49 | 000,041,984 | ---- | C] () -- C:\Documents and Settings\Jamie\My Documents\JulieCV.doc
[2011/03/29 00:10:53 | 000,001,904 | ---- | C] () -- C:\Documents and Settings\Jamie\Desktop\The Lord of the Rings Online.lnk
[2011/03/27 23:19:08 | 000,001,892 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Nitro PDF Professional.lnk
[2011/03/27 23:19:08 | 000,001,770 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Nitro PDF Professional.lnk
[2011/03/20 23:11:44 | 000,036,352 | ---- | C] () -- C:\Documents and Settings\Jamie\Desktop\JoeeeCV.doc
[2011/03/17 19:12:39 | 000,000,672 | ---- | C] () -- C:\Documents and Settings\Jamie\Start Menu\Programs\Spotify.lnk
[2011/02/23 16:34:55 | 017,405,187 | ---- | C] () -- C:\Program Files\DATA3.CAB
[2011/02/23 15:34:56 | 1782,579,200 | ---- | C] () -- C:\Program Files\DATA2.CAB
[2011/02/23 14:36:45 | 1782,579,200 | ---- | C] () -- C:\Program Files\DATA1.CAB
[2011/02/06 18:42:10 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/01/03 16:37:44 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2011/01/03 14:51:50 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/12/25 09:46:53 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\CommonDL.dll
[2010/12/25 09:46:53 | 000,002,413 | ---- | C] () -- C:\WINDOWS\System32\lgAxconfig.ini
[2010/12/10 07:03:08 | 000,123,450 | ---- | C] () -- C:\Documents and Settings\Jamie\Application Data\icarus-dxdiag.xml
[2010/11/30 23:46:40 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2010/11/25 17:10:17 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Jamie\Application Data\PnkBstrK.sys
[2010/11/07 19:27:36 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Jamie\Local Settings\Application Data\fusioncache.dat
[2010/10/31 01:08:51 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Jamie\Local Settings\Application Data\housecall.guid.cache
[2010/10/20 01:57:50 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2010/10/16 02:15:20 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2010/10/01 16:15:49 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/06 23:16:42 | 000,000,641 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/08/31 05:49:11 | 000,044,544 | ---- | C] () -- C:\Documents and Settings\Jamie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/31 05:05:34 | 000,080,416 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010/08/31 05:02:43 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/08/31 04:55:39 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/08/31 04:17:45 | 000,025,088 | ---- | C] () -- C:\WINDOWS\System32\CoInst.dll
[2010/08/31 04:17:34 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\gspnDll.dll
[2010/08/31 04:17:34 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\instDll.dll
[2010/08/31 04:17:34 | 000,013,237 | ---- | C] () -- C:\WINDOWS\wwdslcfg.ini
[2010/06/14 17:51:44 | 000,000,033 | ---- | C] () -- C:\WINDOWS\lg.ini
[2009/09/16 18:27:58 | 000,508,224 | ---- | C] () -- C:\WINDOWS\System32\ICCProfiles.dll
[2009/07/14 18:15:00 | 000,178,432 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2006/11/10 14:08:50 | 000,024,064 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATITool.sys
[2005/12/15 15:01:12 | 000,120,949 | -H-- | C] () -- C:\Documents and Settings\Jamie\Application Data\Jamielog.dat
[1996/04/03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010/11/26 20:57:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/11/28 00:48:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/01/23 04:28:17 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\DSS
[2011/03/27 19:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EA Core
[2011/03/27 19:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2010/11/07 19:02:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hi-Rez Studios
[2010/12/25 09:48:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2011/03/27 23:18:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2010/11/23 06:34:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2011/03/28 15:59:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/09/22 19:50:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010/08/31 05:07:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Soulseek
[2010/12/15 02:11:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/03/31 03:09:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
[2010/11/16 18:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/03/04 23:37:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\.minecraft
[2010/10/30 16:59:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\AnvSoft
[2010/11/28 04:10:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\Auslogics
[2010/11/26 20:57:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\Canneverbe Limited
[2011/03/27 23:17:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\Downloaded Installations
[2010/09/25 04:10:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\FixerLabs
[2010/09/06 23:13:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\Foxit Software
[2011/04/04 01:57:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\IObit
[2011/04/08 21:57:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\ManyCam
[2011/03/08 05:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\Mount&Blade Warband
[2011/03/27 23:19:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\Nitro PDF
[2011/03/02 02:56:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\Sony Online Entertainment
[2011/04/05 22:05:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\Spotify
[2010/12/20 02:35:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\STV Software
[2010/11/07 19:29:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\Turbine
[2011/04/04 00:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jamie\Application Data\uTorrent

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >

Edited by mozzer11, 08 April 2011 - 03:51 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP