This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] My document opens about 5 times upon startup

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I start my computer up, "My Documents" opens about 5 times, and my "C:\" drive opens once.
This happens upon every startup.
Also, I have weird processes running such as 12linNZ.exe (12linNZ is the name of my user account, so this is weird).
No notable errors or anything appear.

This only started happening after my sister used my laptop.
This means only one of the following could have caused the problem;
-Something from Facebook gave me the virus (She saved 2 images from facebook)
-A USB she owns gave me the virus
-A downloaded attachment from her school email from one of her teachers gave me the virus

HijackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:14:06 PM, on 30/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\ifxspmgt.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\IfxPsdSv.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
C:\Program Files\Infineon\Security Platform Software\SpTna.exe
C:\WINDOWS\PLFSetI.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\DOCUME~1\12linnz\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet.cgs.vic.edu.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
F3 - REG:win.ini: load=C:\DOCUME~1\12linnz\LOCALS~1\services.exe
F3 - REG:win.ini: run=explorer.exe C:\WINDOWS\System\regedit.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\smss.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IFXSPMGT] C:\WINDOWS\system32\ifxspmgt.exe /NotifyLogon
O4 - HKLM\..\Run: [PLFSetI] C:\WINDOWS\PLFSetI.exe
O4 - HKLM\..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [12LINNZ] C:\WINDOWS\win.pif
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [12linnz] C:\DOCUME~1\12linnz\LOCALS~1\Temp\Tmp.com
O4 - HKLM\..\Policies\Explorer\Run: [(Default)] C:\WINDOWS\winlogon.exe
O4 - HKCU\..\Policies\Explorer\Run: [(Default)] win.com C:\WINDOWS\system32\msdp32.dll
O4 - HKUS\S-1-5-18\..\Run: [SYSTEM] C:\WINDOWS\TEMP\Tmp.com (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [(Default)] win.com C:\WINDOWS\system32\msdp32.dll (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [SYSTEM] C:\WINDOWS\TEMP\Tmp.com (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [(Default)] win.com C:\WINDOWS\system32\msdp32.dll (User 'Default user')
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://intranet.cgs.vic.edu.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = cgs.vic.edu.au
O17 - HKLM\Software\..\Telephony: DomainName = cgs.vic.edu.au
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = cgs.vic.edu.au
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = cgs.vic.edu.au
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1ca04639e7fec1c) (gupdate1ca04639e7fec1c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MsNet Service (MsNet) - - C:\WINDOWS\Fonts\font.bat
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\WINDOWS\system32\IfxPsdSv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe

–
End of file - 12053 bytes
Hi lin0056, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.



This looks like it may have come from an infected USB device. Please do not attach any such device to the computer. We will deal with them later. How many do you have and what drive letters are they usually assigned?


Download OTListIt2 to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.


Thanks
I only have 1 USB drive.
It is 8GB FAT.
USB's are usually at drive E.

OTL Extras logfile created on: 31/07/2009 3:06:27 PM - Run 1
OTL by OldTimer - Version 3.0.10.3 Folder = C:\Documents and Settings\12linnz\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.93 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 73.42% Memory free
3.78 Gb Paging File | 3.42 Gb Available in Paging File | 90.44% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 71.53 Gb Free Space | 47.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: 12LINNZ
Current User Name: 12LinNZ
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\System32\drivers\etc\networks.exe File not found
.wsh [@ = wshtfile] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"4500:UDP" = 4500:UDP:*:Enabled:IPsec (IKE NAT-T)
"500:UDP" = 500:UDP:*:Enabled:IPsec (IKE)
"135:TCP" = 135:TCP:*:Enabled:RPC Endpoint Mapper and DCOM infrastructure
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS4 Server
"3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51000:TCP" = 51000:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51001:TCP" = 51001:TCP:*:Enabled:Adobe Version Cue CS4 Server

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Disabled:Studio program file – (Pinnacle Systems)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" = C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:*:Enabled:Adobe Version Cue CS4 Server – (Adobe Systems Incorporated)
"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" = C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe:*:Enabled:Visual Studio Remote Debugging Monitor – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi – (Pinnacle Systems)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{034759DA-E21A-4795-BFB3-C66D17FAD183}" = Sophos Anti-Virus
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1461AA33-AB75-4E27-A832-CA0328AD7FAA}" = LEGO MINDSTORMS Edu NXT - English Language Pack
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 13
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{32C7D34A-4ADF-46F1-9E75-A3E446A76D10}" = LEGO MINDSTORMS Edu NXT Software v1.1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Acer Crystal Eye webcam
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{4511EB07-EE29-4BF1-9B90-CE40F12B16CD}" = ClickView Player
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4731AE86-B72B-4589-A152-E67F536B6B0A}" = Crocodile Physics 1.51
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{5EB90C06-964F-4195-B83E-BD7E55C88415}" = Pinnacle Video Driver
"{607398CF-354B-4E21-B1BC-549424BFD04C}" = TIPCI
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{729D7318-FF65-4E8C-B32B-DA2AFA76F591}" = ITEFIR
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{87B36E04-476A-44AD-A971-0BE951995954}" = Crocodile Chemistry 1.5
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99B66D96-5BB2-42DF-BF7C-432285A1E5A5}" = LEGO MINDSTORMS NXT Driver
"{A128921B-D03F-4BFB-8141-C365AA48D660}" = Adobe Setup
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2881E09-38DB-4F79-9135-00FDA01768A7}" = Adobe Creative Suite 4 Design Premium
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_912" = Adobe Acrobat 9.1.2 - CPSID_49166
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B6537896-A156-4015-BD5C-7A80C85C78AB}" = activBook Reader
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{D041EB9E-890A-4098-8F94-51DA194AC72A}" = Pinnacle Studio 12
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.59.528
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E9AF380B-40FA-4D83-A5C7-A80D9BB8E566}" = LEGO MINDSTORMS NXT Edu Migration Package
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F73D65D9-5319-4F48-AD21-BD5BB8C9135B}" = Infineon TPM Professional Package
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF11005D-CBC8-45D5-A288-25C7BB304121}" = Sophos Remote Management System
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acer Acer Bio Protection 6.0.00.17" = Acer Bio Protection

ATL 6.0.00.17
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_55230b0b70661df0f212e88f0b655f7" = Adobe Creative Suite 4 Design Premium
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18
"CrystalReports7" = Seagate Crystal Reports for ESRI
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"InstallShield_{607398CF-354B-4E21-B1BC-549424BFD04C}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"LManager" = Launch Manager
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.1)" = Mozilla Firefox (3.5.1)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PaperCut NG Client_is1" = PaperCut NG Client 6.3
"PowerISO" = PowerISO
"PROPLUS" = Microsoft Office Professional Plus 2007
"StarLogo TNG" = StarLogo TNG
"Starry Night EDU" = Starry Night EDU
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 25/07/2009 4:27:12 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

Error - 25/07/2009 4:33:03 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

Error - 25/07/2009 4:38:55 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

Error - 25/07/2009 4:44:46 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

Error - 25/07/2009 4:50:37 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

Error - 25/07/2009 4:56:29 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

Error - 25/07/2009 5:02:20 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

Error - 25/07/2009 5:08:11 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

Error - 25/07/2009 5:14:03 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

Error - 25/07/2009 5:19:53 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3

[ System Events ]
Error - 24/07/2009 6:30:06 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 24/07/2009 7:22:49 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 24/07/2009 7:22:51 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 24/07/2009 7:37:53 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.

Error - 24/07/2009 8:07:54 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.

Error - 24/07/2009 9:07:54 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 119 minutes. NtpClient has no source of accurate
time.

Error - 24/07/2009 11:07:54 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 239 minutes. NtpClient has no source of accurate
time.

Error - 24/07/2009 11:30:36 PM | Computer Name = 12LINNZ | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CGS due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 25/07/2009 3:07:52 AM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 479 minutes. NtpClient has no source of accurate
time.

Error - 25/07/2009 8:34:15 AM | Computer Name = 12LINNZ | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CGS due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.


< End of report >

OTL logfile created on: 31/07/2009 3:06:27 PM - Run 1
OTL by OldTimer - Version 3.0.10.3 Folder = C:\Documents and Settings\12linnz\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.93 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 73.42% Memory free
3.78 Gb Paging File | 3.42 Gb Available in Paging File | 90.44% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 71.53 Gb Free Space | 47.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: 12LINNZ
Current User Name: 12LinNZ
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\svchost.exe ( )
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\ifxspmgt.exe (Infineon Technologies AG)
PRC - C:\WINDOWS\System32\IFXTCS.exe (Infineon Technologies AG)
PRC - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\IfxPsdSv.exe (Infineon Technologies AG)
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc)
PRC - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe (Sophos Plc)
PRC - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc)
PRC - C:\Program Files\Sophos\Remote Management System\RouterNT.exe (Sophos Plc)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\12LINNZ.exe ( )
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe (Arachnoid Biometrics Identification Group Corp.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\PLFSetI.exe ()
PRC - C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\Infineon\Security Platform Software\PSDrt.exe (Infineon Technologies AG)
PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Infineon\Security Platform Software\SpTna.exe (Infineon Technologies AG)
PRC - C:\WINDOWS\System32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Documents and Settings\12linnz\Local Settings\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\12linnz\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
SRV - (Adobe Version Cue CS4 [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (btwdins [Auto | Running]) – C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1ca04639e7fec1c [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IFXSpMgtSrv [Auto | Running]) – C:\WINDOWS\System32\ifxspmgt.exe (Infineon Technologies AG)
SRV - (IFXTCS [Auto | Running]) – C:\WINDOWS\System32\IFXTCS.exe (Infineon Technologies AG)
SRV - (IGBASVC [Auto | Running]) – C:\Program Files\Acer\Acer Bio Protection\BASVC.exe ()
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Irmon [Auto | Running]) – C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PersonalSecureDriveService [Auto | Running]) – C:\WINDOWS\System32\IfxPsdSv.exe (Infineon Technologies AG)
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SAVAdminService [Unknown | Running]) – C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc)
SRV - (SAVService [Unknown | Running]) – C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc)
SRV - (Sophos Agent [Auto | Running]) – C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe (Sophos Plc)
SRV - (Sophos AutoUpdate Service [Auto | Running]) – C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc)
SRV - (Sophos Message Router [Auto | Running]) – C:\Program Files\Sophos\Remote Management System\RouterNT.exe (Sophos Plc)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (adfs [Auto | Running]) – C:\WINDOWS\System32\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (AlfaFF [Boot | Running]) – C:\WINDOWS\system32\Drivers\AlfaFF.sys (Alfa Corporation)
DRV - (b57w2k [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (btaudio [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTDriver [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWDNDIS [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\btwhid.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (DKbFltr [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\DKbFltr.sys (Dritek System Inc.)
DRV - (DritekPortIO [System | Running]) – C:\Program Files\Launch Manager\DPortIO.sys (Dritek System Inc.)
DRV - (FPSensor [Auto | Running]) – C:\WINDOWS\System32\Drivers\FPSensor.sys (LTT)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\igxpmp32.sys (Intel Corporation)
DRV - (IFXTPM [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\IFXTPM.SYS (Infineon Technologies AG)
DRV - (Int15 [Auto | Running]) – C:\WINDOWS\System32\drivers\int15.sys ()
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\System32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ITEIRDA [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ITEirda.sys (ITE Tech. Inc.)
DRV - (MarvinBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NETw5x32 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\NETw5x32.sys (Intel Corporation)
DRV - (NTIDrvr [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (PersonalSecureDrive [System | Running]) – C:\WINDOWS\System32\drivers\psd.sys (Infineon Technologies AG)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (SAVOnAccessControl [System | Running]) – C:\WINDOWS\System32\DRIVERS\savonaccesscontrol.sys (Sophos Plc)
DRV - (SAVOnAccessFilter [System | Running]) – C:\WINDOWS\System32\DRIVERS\savonaccessfilter.sys (Sophos Plc)
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SNP2UVC [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\snp2uvc.sys ()
DRV - (SophosBootDriver [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\SophosBootDriver.sys (Sophos Plc)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (tifm21 [On_Demand | Running]) – C:\WINDOWS\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (UBHelper [Boot | Running]) – C:\WINDOWS\System32\drivers\UBHelper.sys ()
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - ({95808DC4-FA4A-4c74-92FE-5B863F82066B} [Auto | Running]) – C:\Program Files\CyberLink\PowerDVD\000.fcl (Cyberlink Corp.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://intranet.cgs.vic.edu.au
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.85
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {5B52016C-D097-4aec-BE61-9F129D8FDDBA}:2.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.1
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.gopher: ""
FF - prefs.js..network.proxy.backup.gopher_port: 0
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: 0
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: 0
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 9666
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.socks: "localhost"
FF - prefs.js..network.proxy.socks_port: 9050
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 9666

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/11/05 10:35:48 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2007/12/20 01:48:36 | 00,081,920 | RHS- | M] ( )
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/17 23:12:11 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/07/26 19:15:29 | 00,000,000 | —D | M]

[2009/07/14 16:52:58 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Extensions
[2009/07/14 16:52:58 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/30 01:08:36 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Firefox\Profiles\to5o5mwc.default\extensions
[2009/07/15 21:47:08 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Firefox\Profiles\to5o5mwc.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2009/07/22 20:39:53 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Firefox\Profiles\to5o5mwc.default\extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}
[2009/07/14 16:52:16 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/07/17 23:12:11 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/17 23:12:06 | 00,023,544 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/07/17 23:12:06 | 00,137,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/17 23:12:07 | 00,065,016 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/10/14 21:33:30 | 00,095,600 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/06/24 21:27:00 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/06/24 21:27:00 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/24 21:27:00 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/06/24 21:27:00 | 00,002,344 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/06/24 21:27:00 | 00,002,371 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/06/24 21:27:00 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/06/24 21:27:00 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [12LINNZ] C:\WINDOWS\win.pif ( )
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IFXSPMGT] C:\WINDOWS\System32\ifxspmgt.exe (Infineon Technologies AG)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager File not found
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\WINDOWS\PLFSetI.exe ()
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [ZPdtWzdVitaKey MC3000] C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe (Arachnoid Biometrics Identification Group Corp.)
O4 - HKCU..\Run: [12linnz] C:\Documents and Settings\12linnz\Local Settings\Temp\Tmp.com ( )
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
F3 - HKCU WinNT: Load - (C:\DOCUME~1\12linnz\LOCALS~1\services.exe) - C:\Documents and Settings\12linnz\Local Settings\services File not found
F3 - HKCU WinNT: Run - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
F3 - HKCU WinNT: Run - (C:\WINDOWS\System\regedit.exe) - C:\WINDOWS\System\regedit.exe ( )
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL File not found
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra 'Tools' menuitem : Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: edu.au ([intranet.cgs.vic] http in Local intranet)
O15 - HKLM\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: edu.au ([intranet.cgs.vic] http in Local intranet)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = cgs.vic.edu.au
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: System - (C:\WINDOWS\svchost.exe) - C:\WINDOWS\svchost.exe ( )
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\smss.exe) - C:\WINDOWS\smss.exe ( )
O20 - HKLM Winlogon: GinaDLL - (C:\Program) - File not found
O20 - HKLM Winlogon: GinaDLL - (Files\Acer\Acer) - File not found
O20 - HKLM Winlogon: GinaDLL - (Bio) - File not found
O20 - HKLM Winlogon: GinaDLL - (Protection\CompPtc.dll) - File not found
O20 - HKCU Winlogon: Shell - (C:\DOCUME~1\12linnz\LOCALS~1\explorer.exe) - C:\Documents and Settings\12linnz\Local Settings\explorer File not found
O20 - HKCU Winlogon: System - (C:\WINDOWS\System\wininit.com) - C:\WINDOWS\System\wininit.com ( )
O20 - Winlogon\Notify\AWinNotifyVitaKey MC3000: DllName - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - C:\WINDOWS\system32\command.cmd
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/20 11:33:41 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/12/20 01:48:36 | 00,081,920 | -HS- | M] ( ) - C:\AutoRun.exe – [ NTFS ]
O32 - AutoRun File - [2009/07/26 19:06:35 | 00,000,099 | -HS- | M] () - C:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\Shell - "" = Autorun
O33 - MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\Shell\Auto\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\Shell - "" = Autorun
O33 - MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\Shell\Auto\command - "" = C:\AutoRun.exe – [2007/12/20 01:48:36 | 00,081,920 | -HS- | M] ( )
O33 - MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\Shell\AutoRun\command - "" = E:\SysWin32.exe – File not found
O33 - MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\Shell\explorer\command - "" = E:\SysWin32.exe – File not found
O33 - MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\Shell\open\command - "" = E:\SysWin32.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (pgdfgsvc) - C:\WINDOWS\System32\pgdfgsvc.exe (Sysinternals - www.sysinternals.com)
O34 - HKLM BootExecute: © - File not found
O34 - HKLM BootExecute: (1) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[2009/07/31 15:04:27 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\12linnz\Desktop\OTL.exe
[2009/07/30 23:13:52 | 00,001,734 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\HijackThis.lnk
[2009/07/28 11:11:34 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\winlogon.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\SYSTEM.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\svchost.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\smss.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\services.exe
[2009/07/26 19:06:35 | 00,000,099 | -HS- | C] () – C:\autorun.inf
[2009/07/26 19:06:20 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System32\command.cmd
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\win.pif
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System32\msdp32.dll
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System32\12LINNZ.exe
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System\wininit.com
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System\regedit.exe
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\12LinNZ.exe
[2009/07/26 19:06:19 | 00,081,920 | -HS- | C] ( ) – C:\AutoRun.exe
[2009/07/24 13:38:37 | 00,853,787 | —- | C] (Macromedia, Inc.) – C:\Documents and Settings\12linnz\Desktop\Neave Tetris.exe
[2009/07/24 09:47:05 | 00,000,000 | —D | C] – C:\Program Files\Enable Software
[2009/07/24 09:24:26 | 00,000,630 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\µTorrent.lnk
[2009/07/24 09:24:26 | 00,000,000 | —D | C] – C:\Program Files\uTorrent
[2009/07/24 09:24:00 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\uTorrent
[2009/07/22 20:35:19 | 00,466,944 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\u95.exe
[2009/07/17 09:53:42 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\Bluetooth Exchange Folder
[2009/07/16 14:24:53 | 00,017,408 | —- | C] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/16 14:23:53 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\DivX
[2009/07/16 14:20:53 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Google
[2009/07/16 10:21:19 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/07/16 10:20:27 | 00,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2009/07/16 10:18:16 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/07/16 10:18:14 | 00,459,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/07/16 10:18:13 | 00,383,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/07/16 10:18:13 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/07/16 10:18:13 | 00,052,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/07/16 10:18:12 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/07/16 10:18:11 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieudinit.exe
[2009/07/16 10:18:10 | 02,455,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dat
[2009/07/16 10:18:10 | 00,991,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/07/16 10:18:05 | 06,066,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/07/15 18:13:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2009/07/15 16:48:51 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009/07/15 16:43:37 | 00,000,000 | —D | C] – C:\WINDOWS\WBEM
[2009/07/15 16:41:57 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2009/07/15 16:41:47 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
[2009/07/15 16:41:23 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
[2009/07/15 16:11:00 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Microsoft Help
[2009/07/15 15:14:29 | 00,056,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\secur32.dll
[2009/07/15 15:14:28 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kernel32.dll
[2009/07/15 15:14:09 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\schannel.dll
[2009/07/15 15:14:00 | 00,177,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msctfime.ime
[2009/07/15 15:13:25 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/07/15 15:13:25 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/07/15 15:13:25 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/07/15 15:13:24 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/07/15 15:13:24 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/07/15 15:13:24 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/07/15 15:13:23 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/07/15 15:13:23 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/07/15 15:13:23 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/07/15 15:13:15 | 00,345,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\localspl.dll
[2009/07/15 15:13:05 | 00,161,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdtcuiu.dll
[2009/07/15 15:13:05 | 00,091,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mtxoci.dll
[2009/07/15 15:13:05 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mtxclu.dll
[2009/07/15 15:13:04 | 00,956,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdtctm.dll
[2009/07/15 15:13:04 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdtclog.dll
[2009/07/15 15:11:18 | 00,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 9 Pro.lnk
[2009/07/15 15:09:38 | 08,461,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2009/07/15 15:09:17 | 00,585,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2009/07/15 15:09:15 | 00,354,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winhttp.dll
[2009/07/15 15:08:50 | 00,286,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gdi32.dll
[2009/07/15 15:08:23 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/07/15 15:08:22 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/07/15 15:08:21 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/07/15 14:37:37 | 00,000,409 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\Downloads.lnk
[2009/07/15 09:00:37 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Fuji Xerox
[2009/07/14 23:26:44 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Malwarebytes
[2009/07/14 23:26:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/07/14 23:22:49 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/07/14 22:16:08 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/07/14 22:16:08 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/07/14 22:16:08 | 01,614,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/07/14 22:16:08 | 01,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/07/14 22:16:08 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/07/14 22:16:08 | 00,927,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/07/14 22:16:08 | 00,792,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/07/14 22:16:08 | 00,666,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/07/14 22:16:08 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/07/14 22:16:08 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/07/14 22:16:08 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/07/14 22:16:08 | 00,435,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/07/14 22:16:08 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/07/14 22:16:08 | 00,361,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/07/14 22:16:08 | 00,295,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/07/14 22:16:08 | 00,182,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/07/14 22:16:08 | 00,167,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\appmgmts.dll
[2009/07/14 22:16:08 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/07/14 22:16:08 | 00,108,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/07/14 22:16:08 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/07/14 22:16:08 | 00,082,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/07/14 22:16:08 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/07/14 22:16:08 | 00,053,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/07/14 22:16:08 | 00,036,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/07/14 22:16:08 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/07/14 22:16:08 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/07/14 22:16:08 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/07/14 22:16:08 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/07/14 22:16:08 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/07/14 22:16:08 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/07/14 22:16:08 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/07/14 22:16:08 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/07/14 22:16:08 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/07/14 22:16:08 | 00,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/07/14 22:16:08 | 00,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/07/14 22:16:08 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/07/14 22:16:08 | 00,000,000 | —D | C] – C:\WINDOWS\System32\dllcache\cache
[2009/07/14 22:05:56 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/07/14 22:04:43 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/07/14 21:05:49 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\My Received Files
[2009/07/14 21:05:24 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\My Chat Logs
[2009/07/14 20:43:45 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\WinRAR
[2009/07/14 19:23:38 | 00,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/07/14 19:23:38 | 00,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/07/14 19:17:20 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Nexon
[2009/07/14 19:15:58 | 00,001,836 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/07/14 19:15:20 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Google
[2009/07/14 19:15:08 | 00,000,000 | —D | C] – C:\Program Files\WinRAR
[2009/07/14 19:14:39 | 00,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2009/07/14 19:14:39 | 00,000,000 | —D | C] – C:\Program Files\PowerISO
[2009/07/14 19:12:41 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2009/07/14 19:12:40 | 00,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/07/14 19:12:38 | 00,000,000 | —D | C] – C:\Program Files\Google
[2009/07/14 18:40:02 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSWINSCK.OCX
[2009/07/14 18:38:43 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/07/14 18:37:01 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/14 18:15:08 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Apple Computer
[2009/07/14 18:14:58 | 00,001,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/07/14 18:14:55 | 00,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2009/07/14 18:14:55 | 00,023,400 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\drivers\GEARAspiWDM.sys
[2009/07/14 18:14:38 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/07/14 18:14:34 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/07/14 18:14:34 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/07/14 18:14:16 | 00,000,000 | —D | C] – C:\Program Files\Bonjour
[2009/07/14 18:13:57 | 00,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/07/14 18:13:38 | 00,000,000 | —D | C] – C:\Program Files\QuickTime
[2009/07/14 18:13:34 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/07/14 18:13:21 | 00,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/07/14 18:13:21 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Apple
[2009/07/14 18:13:18 | 00,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2009/07/14 18:13:08 | 02,060,288 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2009/07/14 18:13:08 | 00,039,424 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\drivers\usbaapl.sys
[2009/07/14 18:12:28 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2009/07/14 18:12:27 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/07/14 18:11:56 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Apple Computer
[2009/07/14 18:11:06 | 00,000,000 | —D | C] – C:\Program Files\Combined Community Codec Pack
[2009/07/14 18:10:52 | 00,000,000 | —D | C] – C:\Program Files\Messenger Plus! Live
[2009/07/14 18:07:59 | 00,000,000 | R–D | C] – C:\Documents and Settings\12linnz\My Documents\My Videos
[2009/07/14 18:04:32 | 00,000,419 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\School Work.lnk
[2009/07/14 17:57:38 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Sophos
[2009/07/14 17:54:42 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/07/14 17:53:53 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/07/14 17:53:40 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/07/14 17:53:33 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/07/14 17:53:06 | 00,000,000 | —D | C] – C:\Program Files\Windows Live
[2009/07/14 17:49:20 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/07/14 17:48:58 | 00,105,544 | —- | C] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/07/14 17:48:54 | 00,001,548 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\CCleaner.lnk
[2009/07/14 17:48:52 | 00,000,000 | —D | C] – C:\Program Files\CCleaner
[2009/07/14 17:47:33 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\Downloads
[2009/07/14 17:01:11 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\FIFAOnline2
[2009/07/14 16:54:23 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Macromedia
[2009/07/14 16:52:39 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/07/14 16:52:32 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Mozilla
[2009/07/14 16:52:31 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Mozilla
[2009/07/14 16:52:18 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/07/14 16:52:14 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/07/14 16:47:55 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/14 16:47:55 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/14 16:47:55 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/14 16:47:19 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\School Work
[2009/07/14 16:46:42 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Sun
[2009/07/14 16:41:01 | 00,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidusb.sys
[2009/07/14 16:41:01 | 00,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2009/07/14 15:52:39 | 02,117,596 | -H– | C] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\IconCache.db
[2009/07/14 15:52:08 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Adobe
[2009/07/14 15:51:36 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Adobe
[2009/07/14 15:51:27 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Infineon
[2009/07/14 15:50:51 | 00,000,782 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\Windows Media Player.lnk
[2009/07/14 15:50:46 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Identities
[2009/07/14 15:50:42 | 00,000,000 | R–D | C] – C:\Documents and Settings\12linnz\My Documents\My Pictures
[2009/07/14 15:50:42 | 00,000,000 | R–D | C] – C:\Documents and Settings\12linnz\My Documents\My Music
[2009/07/14 15:50:21 | 00,000,000 | –SD | C] – C:\Documents and Settings\12linnz\Application Data\Microsoft
[2009/07/14 15:50:21 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Microsoft
[2009/07/14 14:43:25 | 00,004,444 | —- | C] () – C:\WINDOWS\System32\pid.PNF
[2009/07/14 12:09:40 | 07,366,144 | —- | C] () – C:\Documents and Settings\12linnz\My Documents\FO2 Database 2009March15.xls
[2009/07/14 12:09:40 | 01,655,808 | —- | C] () – C:\Documents and Settings\12linnz\My Documents\LP Calculator - FlyHigh.xls
[2008/11/24 11:13:30 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/11/20 14:38:49 | 00,000,020 | —- | C] () – C:\WINDOWS\CrocPhys.INI
[2008/11/20 14:38:17 | 00,000,072 | —- | C] () – C:\WINDOWS\CrocChem.INI
[2008/11/20 11:15:57 | 00,013,952 | —- | C] () – C:\WINDOWS\System32\drivers\UBHelper.sys
[2008/11/20 11:15:03 | 00,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMPEG2.dll
[2008/11/20 11:15:03 | 00,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMP3.dll
[2008/11/20 11:15:03 | 00,001,024 | RH– | C] () – C:\WINDOWS\System32\NTICDMK7.dll
[2008/11/05 09:12:45 | 00,000,021 | —- | C] () – C:\WINDOWS\crocclip.ini
[2008/10/24 11:53:32 | 00,000,154 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/10/24 11:50:32 | 00,018,944 | —- | C] ( ) – C:\WINDOWS\System32\IMPLODE.DLL
[2008/10/24 11:50:30 | 00,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2008/10/22 14:06:13 | 00,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4953.dll
[2008/10/22 14:03:33 | 01,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2008/10/22 14:03:33 | 00,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[2008/10/22 14:03:33 | 00,028,032 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2008/10/22 14:03:27 | 00,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2008/10/22 14:02:59 | 00,000,055 | —- | C] () – C:\WINDOWS\PidList.ini
[2008/10/22 13:39:57 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\VMC3KAPI.dll
[2008/04/01 07:25:46 | 00,831,488 | —- | C] () – C:\WINDOWS\System32\divx_xx0a.dll
[2008/03/22 06:30:08 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/03/22 06:28:54 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/03/22 06:28:54 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/03/22 06:28:20 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/09/11 12:24:28 | 02,842,624 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2007/09/11 12:12:28 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2007/01/26 16:32:18 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\drivers\int15.sys
[2007/01/26 01:04:12 | 00,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2007/01/26 01:04:12 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2006/02/28 22:00:00 | 00,000,582 | —- | C] () – C:\WINDOWS\win.ini
[2006/02/28 22:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2005/02/17 12:41:32 | 00,000,603 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 12:41:30 | 00,000,593 | —- | C] () – C:\WINDOWS\System32\btcss.dll.manifest
[2003/07/21 07:42:22 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\abZlib.dll
[2001/12/26 14:12:30 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\multiplex_vcd.dll
[2001/11/14 13:56:00 | 01,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/09/03 21:46:38 | 00,110,592 | —- | C] () – C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 14:33:56 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 20:04:36 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1998/12/15 03:00:00 | 00,021,986 | —- | C] () – C:\WINDOWS\crwd32.ini
[1996/06/08 05:07:14 | 00,043,008 | —- | C] () – C:\WINDOWS\System32\ltfil60n.dll
[1996/06/08 05:07:14 | 00,019,456 | —- | C] () – C:\WINDOWS\System32\lfwpg60n.dll
[1996/06/08 05:07:12 | 00,046,080 | —- | C] () – C:\WINDOWS\System32\lftif60n.dll
[1996/06/08 05:07:12 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\lftga60n.dll
[1996/06/08 05:07:12 | 00,019,456 | —- | C] () – C:\WINDOWS\System32\lfwmf60n.dll
[1996/06/08 05:07:10 | 00,110,080 | —- | C] () – C:\WINDOWS\System32\lfpng60n.dll
[1996/06/08 05:07:10 | 00,023,552 | —- | C] () – C:\WINDOWS\System32\lfpcx60n.dll
[1996/06/08 05:07:10 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\lfpsd60n.dll
[1996/06/08 05:07:08 | 00,022,528 | —- | C] () – C:\WINDOWS\System32\lfpct60n.dll
[1996/06/08 05:07:08 | 00,018,432 | —- | C] () – C:\WINDOWS\System32\lfmsp60n.dll
[1996/06/08 05:07:08 | 00,017,920 | —- | C] () – C:\WINDOWS\System32\lfmac60n.dll
[1996/06/08 05:07:06 | 00,176,128 | —- | C] () – C:\WINDOWS\System32\lffax60n.dll
[1996/06/08 05:07:04 | 00,141,824 | —- | C] () – C:\WINDOWS\System32\lfcmp60n.dll
[1996/06/08 05:07:04 | 00,022,528 | —- | C] () – C:\WINDOWS\System32\lfeps60n.dll
[1996/06/08 05:07:04 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\lfbmp60n.dll

========== Files - Modified Within 30 Days ==========

[2009/07/31 15:04:33 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\12linnz\Desktop\OTL.exe
[2009/07/31 14:53:48 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/07/31 14:53:47 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/07/31 14:53:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/31 14:53:13 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/31 13:28:01 | 00,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/07/31 01:40:09 | 02,117,596 | -H– | M] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\IconCache.db
[2009/07/30 23:13:52 | 00,001,734 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\HijackThis.lnk
[2009/07/28 23:54:24 | 00,017,408 | —- | M] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/26 19:06:35 | 00,000,099 | -HS- | M] () – C:\autorun.inf
[2009/07/26 15:44:17 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/07/25 19:17:56 | 00,001,514 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Backup.lnk
[2009/07/24 09:24:26 | 00,000,630 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\µTorrent.lnk
[2009/07/23 10:15:34 | 00,000,712 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
[2009/07/16 20:21:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/07/16 10:21:57 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/15 18:13:44 | 00,105,544 | —- | M] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/07/15 17:11:33 | 00,525,272 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/15 17:11:33 | 00,444,798 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/15 17:11:33 | 00,072,698 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/15 17:07:07 | 02,223,656 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/15 16:34:39 | 00,000,582 | —- | M] () – C:\WINDOWS\win.ini
[2009/07/15 15:11:18 | 00,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 9 Pro.lnk
[2009/07/15 14:37:37 | 00,000,409 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\Downloads.lnk
[2009/07/14 23:16:57 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/07/14 23:15:37 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.msn
[2009/07/14 23:15:37 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/07/14 22:06:01 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/07/14 19:15:58 | 00,001,836 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/07/14 19:14:39 | 00,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2009/07/14 18:40:03 | 00,057,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MSWINSCK.OCX
[2009/07/14 18:14:58 | 00,001,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/07/14 18:13:57 | 00,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/07/14 18:07:56 | 00,000,782 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\Windows Media Player.lnk
[2009/07/14 18:04:32 | 00,000,419 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\School Work.lnk
[2009/07/14 17:48:54 | 00,001,548 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\CCleaner.lnk
[2009/07/14 16:52:39 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/07/14 16:52:18 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/07/14 14:44:25 | 00,000,624 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2009/07/14 14:43:25 | 00,004,444 | —- | M] () – C:\WINDOWS\System32\pid.PNF

========== LOP Check ==========

[2009/07/24 09:24:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\12linnz\Application Data
[2009/07/14 15:51:27 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\Infineon
[2009/07/14 19:17:20 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\Nexon
[2009/07/24 09:26:54 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\uTorrent
[2009/07/15 18:13:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/07/14 18:14:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/20 14:16:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\abReader_Desktop
[2008/11/21 11:19:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ALM
[2008/11/20 11:19:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/11/21 15:09:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/10/22 13:55:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Infineon
[2009/07/15 18:13:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2008/11/05 14:18:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\National Instruments
[2008/11/20 10:55:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/11/20 10:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Plus
[2008/11/20 13:43:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Ultimate
[2008/10/24 11:43:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sophos
[2008/11/20 10:55:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Studio 12
[2009/07/16 20:21:01 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2006/02/28 22:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/31 14:53:48 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/07/31 14:53:47 | 00,000,882 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/07/31 13:28:01 | 00,000,886 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009/07/31 14:53:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


< End of report >
Hi lin0056,

µTorrent
You have µTorrent, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it. It's not the program itself that is the problem, but the material that is downloaded with it. It usually come from an unknown source.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.




Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log

Any better?
ComboFix 09-07-29.04 - 12LinNZ 31/07/2009 17:16.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.1977.1411 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.exe
C:\Autorun.inf
c:\documents and settings\12linnz\Local Settings\explorer.exe
c:\documents and settings\12linnz\Local Settings\services.exe
c:\documents and settings\12linnz\Local Settings\smss.exe
c:\documents and settings\12linnz\Local Settings\svchost.exe
c:\documents and settings\12linnz\Local Settings\winlogon.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\.exe
c:\windows\12LinNZ.exe
c:\windows\services.exe
c:\windows\smss.exe
c:\windows\svchost.exe
c:\windows\system.exe
c:\windows\winlogon.exe

—– BITS: Possible infected sites —–

hxxp://cgsremote6
.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.

2009-07-28 14:46 . 2009-07-28 14:46 1878984 —-a-w- c:\documents and settings\12linnz\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-07-27 11:28 . 2008-11-21 06:11 38200 —-a-w- c:\documents and settings\12linnz\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-07-26 09:06 . 2007-12-19 15:48 81920 –sh–r- c:\windows\system32\command.cmd
2009-07-26 09:06 . 2007-12-19 15:48 81920 –sh–r- c:\windows\win.pif
2009-07-26 09:06 . 2007-12-19 15:48 81920 –sh–r- c:\windows\system32\msdp32.dll
2009-07-26 09:06 . 2007-12-19 15:48 81920 –sh–r- c:\windows\system32\12LINNZ.exe
2009-07-26 09:06 . 2007-12-19 15:48 81920 –sh–r- c:\windows\system\wininit.com
2009-07-26 09:06 . 2007-12-19 15:48 81920 –sh–r- c:\windows\system\regedit.exe
2009-07-23 23:47 . 2009-07-23 23:47 ——– d—–w- c:\program files\Enable Software
2009-07-23 23:24 . 2009-07-23 23:24 ——– d—–w- c:\program files\uTorrent
2009-07-23 23:24 . 2009-07-23 23:26 ——– d—–w- c:\documents and settings\12linnz\Application Data\uTorrent
2009-07-16 23:53 . 2009-07-16 23:53 ——– d—–w- c:\documents and settings\12linnz\Bluetooth Software
2009-07-16 10:21 . 2009-07-16 10:21 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-16 04:23 . 2009-07-16 04:23 ——– d—–w- c:\documents and settings\12linnz\Application Data\DivX
2009-07-16 00:18 . 2009-04-29 04:55 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-07-16 00:18 . 2009-04-29 04:55 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-16 00:18 . 2009-04-29 04:55 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-07-16 00:18 . 2009-04-29 04:55 383488 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2009-07-16 00:18 . 2009-04-29 04:55 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2009-07-16 00:18 . 2009-04-28 09:05 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2009-07-16 00:18 . 2008-07-09 14:25 2455488 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2009-07-16 00:18 . 2009-04-29 04:55 6066176 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-07-15 08:13 . 2009-07-15 08:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-15 06:48 . 2009-07-15 07:06 ——– d—–w- c:\windows\SxsCaPendDel
2009-07-15 06:11 . 2009-07-15 06:11 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Microsoft Help
2009-07-15 06:10 . 2009-07-18 22:57 ——– d—–w- c:\documents and settings\saaa
2009-07-15 05:14 . 2009-02-03 19:59 56832 -c—-w- c:\windows\system32\dllcache\secur32.dll
2009-07-15 05:14 . 2009-03-21 14:06 989696 -c—-w- c:\windows\system32\dllcache\kernel32.dll
2009-07-15 05:14 . 2008-12-05 06:54 144896 -c—-w- c:\windows\system32\dllcache\schannel.dll
2009-07-15 05:09 . 2008-06-17 19:02 8461312 -c—-w- c:\windows\system32\dllcache\shell32.dll
2009-07-15 05:09 . 2009-04-15 14:51 585216 -c—-w- c:\windows\system32\dllcache\rpcrt4.dll
2009-07-15 05:09 . 2008-12-16 12:30 354304 -c—-w- c:\windows\system32\dllcache\winhttp.dll
2009-07-15 05:08 . 2008-10-23 12:36 286720 -c—-w- c:\windows\system32\dllcache\gdi32.dll
2009-07-15 05:08 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-07-15 05:08 . 2008-04-21 12:08 215552 -c—-w- c:\windows\system32\dllcache\wordpad.exe
2009-07-14 13:26 . 2009-07-14 13:26 ——– d—–w- c:\documents and settings\12linnz\Application Data\Malwarebytes
2009-07-14 13:26 . 2009-07-14 13:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-14 09:28 . 2009-07-14 09:28 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-07-14 09:17 . 2009-07-14 09:17 ——– d—–w- c:\documents and settings\12linnz\Application Data\Nexon
2009-07-14 09:15 . 2009-07-14 09:15 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-07-14 09:15 . 2009-07-14 09:22 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Google
2009-07-14 09:14 . 2009-07-14 09:14 ——– d—–w- c:\program files\PowerISO
2009-07-14 09:12 . 2009-07-14 09:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-14 09:12 . 2009-07-14 09:15 ——– d—–w- c:\program files\Google
2009-07-14 08:38 . 2009-07-14 08:38 ——– d–h–w- c:\windows\PIF
2009-07-14 08:37 . 2009-07-14 08:37 ——– d—–w- c:\program files\Trend Micro
2009-07-14 08:15 . 2009-07-14 12:32 ——– d—–w- c:\documents and settings\12linnz\Application Data\Apple Computer
2009-07-14 08:12 . 2009-07-14 12:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-07-14 08:11 . 2009-07-14 08:15 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Apple Computer
2009-07-14 08:11 . 2009-07-14 08:11 ——– d—–w- c:\program files\Combined Community Codec Pack
2009-07-14 08:10 . 2009-07-14 08:10 ——– d—–w- c:\program files\Messenger Plus! Live
2009-07-14 07:57 . 2009-07-14 07:57 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Sophos
2009-07-14 07:57 . 2009-07-29 11:26 ——– d—–w- c:\documents and settings\12linnz\Tracing
2009-07-14 07:54 . 2009-07-14 07:54 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-14 07:53 . 2009-07-14 07:54 ——– d—–w- c:\program files\Microsoft
2009-07-14 07:53 . 2009-07-14 07:53 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-14 07:53 . 2009-07-14 07:54 ——– d—–w- c:\program files\Windows Live
2009-07-14 07:49 . 2009-07-14 07:49 ——– d—–w- c:\program files\Common Files\Windows Live
2009-07-14 07:48 . 2009-07-15 08:13 105544 —-a-w- c:\documents and settings\12linnz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-14 07:48 . 2009-07-14 07:48 ——– d—–w- c:\program files\CCleaner
2009-07-14 06:52 . 2009-07-14 06:52 0 —-a-w- c:\windows\nsreg.dat
2009-07-14 06:52 . 2009-07-14 06:52 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Mozilla
2009-07-14 06:47 . 2009-07-14 06:47 ——– d-s—w- c:\documents and settings\12linnz\UserData
2009-07-14 06:47 . 2009-07-14 07:54 ——– d—–r- c:\documents and settings\12linnz\Documents
2009-07-14 06:47 . 2009-07-14 06:47 152576 —-a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-14 06:41 . 2008-04-13 14:15 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2009-07-14 06:41 . 2008-04-13 14:15 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-07-14 05:52 . 2009-07-26 08:55 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Adobe
2009-07-14 05:51 . 2009-07-14 05:51 ——– d—–w- c:\documents and settings\12linnz\Application Data\Infineon

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 09:15 . 2008-10-24 01:40 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-15 06:55 . 2008-10-24 01:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-15 06:35 . 2008-10-24 01:32 ——– d—–w- c:\program files\Microsoft Works
2009-07-14 08:14 . 2009-07-14 08:14 ——– d—–w- c:\program files\iTunes
2009-07-14 08:14 . 2009-07-14 08:14 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-14 08:14 . 2009-07-14 08:14 ——– d—–w- c:\program files\iPod
2009-07-14 08:14 . 2009-07-14 08:12 ——– d—–w- c:\program files\Common Files\Apple
2009-07-14 08:14 . 2009-07-14 08:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-14 08:14 . 2009-07-14 08:14 ——– d—–w- c:\program files\Bonjour
2009-07-14 08:14 . 2009-07-14 08:13 ——– d—–w- c:\program files\QuickTime
2009-07-14 08:13 . 2009-07-14 08:13 ——– d—–w- c:\program files\Apple Software Update
2009-07-14 06:47 . 2008-11-05 00:35 ——– d—–w- c:\program files\Java
2009-06-05 03:57 . 2009-06-05 03:57 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 01:42 . 2009-07-14 08:13 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-05 01:42 . 2009-07-14 08:13 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-07-17 13:12 . 2009-07-14 06:52 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2007-12-19 15:48 . 2009-07-26 09:06 81920 –sh–r- c:\windows\12LinNZ.exe
2007-12-19 15:48 . 2009-07-26 09:06 81920 –sh–r- c:\windows\win.pif
2007-12-19 15:48 . 2009-07-26 09:06 81920 –sh–r- c:\windows\Fonts\font.bat
2007-12-19 15:48 . 2009-07-26 09:06 81920 –sh–r- c:\windows\system\regedit.exe
2007-12-19 15:48 . 2009-07-26 09:06 81920 –sh–r- c:\windows\system\wininit.com
2007-12-19 15:48 . 2009-07-26 09:06 81920 –sh–r- c:\windows\system32\12LINNZ.exe
2007-12-19 15:48 . 2009-07-26 09:06 81920 –sh–r- c:\windows\system32\command.cmd
2007-12-19 15:48 . 2009-07-26 09:06 81920 –sh–r- c:\windows\system32\msdp32.dll
2007-12-19 15:48 . 2009-07-26 09:06 81920 –sh–r- c:\windows\Web\Picture.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"12LinNZ"="c:\docume~1\12linnz\LOCALS~1\Temp\Tmp.com" [2007-12-19 81920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2008-10-22 3680768]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1028096]
"IFXSPMGT"="c:\windows\system32\ifxspmgt.exe" [2007-07-23 677144]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-04 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-04 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-04 141848]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-05-02 870920]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"12LINNZ"="c:\windows\win.pif" [2007-12-19 81920]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-07 16862208]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"(Default)"="c:\docume~1\12linnz\LOCALS~1\winlogon.exe" [2007-12-19 81920]

[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"(Default)"="win.com" - c:\windows\system32\win.com [2006-02-28 18432]

[HKEY_USERS\.DEFAULT\software\microsoft\windows\Currentversion\policies\explorer\Run]
"(Default)"="win.com" - c:\windows\system32\win.com [2006-02-28 18432]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2009-6-11 245760]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-11 576104]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"System"="c:\windows\System\wininit.com"
"Shell"="c:\docume~1\12linnz\LOCALS~1\explorer.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="c:\docume~1\12linnz\LOCALS~1\svchost.exe"
"Userinit"="c:\windows\system32\userinit.exe,c:\docume~1\12linnz\LOCALS~1\smss.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-10-22 03:39 3076096 —-a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=c:\docume~1\12linnz\LOCALS~1\services.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\drivers\AlfaFF.sys [22/10/2008 1:39 PM 43184]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [24/07/2007 7:59 AM 38816]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [24/10/2008 11:38 AM 110848]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [24/10/2008 11:38 AM 38528]
R2 FPSensor;LTT-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\drivers\FPSensor.sys [22/10/2008 1:39 PM 20352]
R2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [22/10/2008 1:39 PM 3481600]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [8/05/2009 1:12 AM 80936]
R2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [20/11/2008 2:32 PM 98304]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [24/07/2007 7:59 AM 41216]
R3 ITEIRDA;ITE Infrared Device Driver;c:\windows\system32\drivers\ITEirda.sys [22/10/2008 1:59 PM 24576]
S2 gupdate1ca04639e7fec1c;Google Update Service (gupdate1ca04639e7fec1c);c:\program files\Google\Update\GoogleUpdate.exe [14/07/2009 7:15 PM 133104]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15/08/2008 4:46 AM 284016]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [20/11/2008 2:32 PM 14976]
.
Contents of the 'Scheduled Tasks' folder

2009-07-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]

2009-07-31 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-14 09:12]

2009-07-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-14 09:15]

2009-07-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-14 09:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://intranet.cgs.vic.edu.au
uInternet Settings,ProxyOverride = local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\12linnz\Application Data\Mozilla\Firefox\Profiles\to5o5mwc.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
.
——- File Associations ——-
.
txtfile=c:\windows\system32\drivers\etc\networks.exe %1
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-31 17:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sophos Message Router]
"ImagePath"="\"c:\program files\Sophos\Remote Management System\RouterNT.exe\" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MsNet]
"ImagePath"="c:\windows\Fonts\font.bat"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,d5,b8,a1,a9,7e,
87,6a,94,e2,63,26,f1,3f,c8,ff,68,df,94,86,26,a5,12,0f,c0,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,71,1a,61,44,db,
a8,82,97,6a,9c,d6,61,af,45,84,18,83,7b,73,fe,35,7f,b9,26,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,47,40,97,61,c4,
c9,a5,79,ff,7c,85,e0,43,d4,0e,fe,21,4d,f0,17,f6,e7,28,88,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,a3,17,83,07,a1,
83,8c,66,86,8c,21,01,be,91,eb,e7,0e,78,df,c8,9b,41,00,e2,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,97,2c,97,8b,a4,
1d,07,01,f5,1d,4d,73,a8,13,5c,05,20,5d,a8,2f,c8,f1,7c,ec,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:50,93,e5,ab,ec,6a,4e,ab,24,86,c7,1b,af,
30,21,d9,df,20,58,62,78,6b,cf,c8,5d,e6,b2,f6,ed,49,0d,ba,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,52,78,a1,7b,1a,
5c,ba,51,fb,a7,78,e6,12,2f,9a,ea,d5,67,83,e0,bf,40,66,d3,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,71,46,b7,8f,9c,
88,cf,5c,01,3a,48,fc,e8,04,4a,f1,90,cc,56,9e,a7,3b,4a,9a,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:b2,46,9a,e2,1b,fe,1b,94,e0,3d,bd,d0,c7,
c8,8d,aa,f6,0f,4e,58,98,5b,89,c9,67,07,14,4c,8f,87,0d,9a,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,a6,b2,47,1f,90,
b6,4a,42,3d,ce,ea,26,2d,45,aa,78,73,ef,c4,29,16,3b,93,0d,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,c5,95,af,cf,7c,
50,87,ac,2a,b7,cc,b5,b9,7f,41,e7,46,1e,1f,67,d1,64,b3,dd,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,b0,19,c8,08,c2,
74,8d,60,6c,43,2d,1e,aa,22,2f,9c,2c,76,91,5e,93,cf,2a,25,6c,43,2d,1e,aa,22,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1104)
c:\program files\Acer\Acer Bio Protection\CompPtc.dll
c:\program files\Acer\Acer Bio Protection\CustomRes.dll
c:\windows\system32\NBMatS1SDK.DLL
c:\program files\Acer\Acer Bio Protection\WinNotify.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'lsass.exe'(1160)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(1748)
c:\windows\system32\btmmhook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\IfxPsdSv.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Sophos\Remote Management System\ManagementAgentNT.exe
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\Sophos\Remote Management System\RouterNT.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\program files\Infineon\Security Platform Software\PSDrt.exe
c:\program files\Infineon\Security Platform Software\SpTNA.exe
c:\docume~1\12linnz\LOCALS~1\Temp\RtkBtMnt.exe
c:\windows\system32\12LINNZ.exe
c:\windows\system32\12LINNZ.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-07-31 17:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-31 07:27

Pre-Run: 76,704,391,168 bytes free
Post-Run: 76,800,761,856 bytes free

410 — E O F — 2009-07-16 00:22


My Documents didn't open up this time.
My C:/ directory still opened though.
Also, I can't view hidden folders and file extensions.
Hi lin0056,

Ok, thanks. Let's see what we are up against.

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time, into the "Suspicious files to scan" box on the top of the page:
  • Please ensure the scan is complete and the results saved before submitting the next one.

    c:\windows\system\regedit.exe
    c:\windows\system32\12LINNZ.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :filefind
    regedit.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post back with
  • VirScan results
  • SystemLook log

Thanks
VirSCAN.org Scanned Report :
Scanned time : 2009/08/01 10:51:00 (EST)
Scanner results: 92% Scanner(34/37) found malware!
File Name : regedit.exe
File Size : 81920 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 8f12b944d38a5f51b1273516b5cb9bca
SHA1 : b7ed8e5e0e3d59cbac0dbcf1a1b3dd01c0c175d8
Online report : http://virscan.org/report/d18edf8fa2192657…2b6f231a81.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090731163245 2009-07-31 0.37 Virus.Win32.AutoRun.lr!IK
AhnLab V3 2009.07.31.04 2009.07.31 2009-07-31 1.17 Win-Trojan/Autorun.77824
AntiVir 8.2.0.238 7.1.5.57 2009-07-31 0.34 TR/Autorun.LS
Antiy 2.0.18 20090729.2652900 2009-07-29 0.12 Virus/Win32.AutoRun.lr
Arcavir 2009 200907311811 2009-07-31 0.04 Trojan.Autorun.Lr
Authentium 5.1.1 200907311707 2009-07-31 1.15 W32/Worm.XIA (Exact)
AVAST! 4.7.4 090731-0 2009-07-31 0.01 Win32:AutoRun-HD
AVG 8.5.288 270.13.38/2274 2009-07-31 0.31 Worm/Delf.GXW
BitDefender 7.81008.3870071 7.26922 2009-08-01 3.37 Trojan.VB.AutoRun.R
CA (VET) 9.0.0.143 31.6.6649 2009-08-01 8.58 Win32/SillyAutorun.GB worm.
ClamAV 0.95.2 9639 2009-07-31 0.03 -
Comodo 3.10 1828 2009-07-31 0.70 Worm.Win32.AutoRun.~AET
CP Secure 1.1.0.715 2009.08.01 2009-08-01 11.48 W32.AutoRun.lr
Dr.Web 4.44.0.9170 2009.07.31 2009-07-31 4.95 Win32.HLLW.Autoruner.531
F-Prot 4.4.4.56 20090731 2009-07-31 1.14 W32/Worm.XIA (exact)
F-Secure 7.02.73807 2009.07.29.10 2009-07-29 7.52 Worm.Win32.AutoRun.aaj [AVP]
Fortinet 2.81-3.120 10.665 2009-07-31 0.20 W32/AutoRun.AAJ!worm
GData 19.6791/19.421 20090731 2009-07-31 4.70 Worm.Win32.AutoRun.aaj [Engine:A]
ViRobot 20090730 2009.07.30 2009-07-30 0.41 -
Ikarus T3.1.01.64 2009.07.31.73137 2009-07-31 4.03 Virus.Win32.AutoRun.lr
JiangMin 11.0.800 2009.07.31 2009-07-31 3.64 Trojan/DiskAutorun.ade
Kaspersky 5.5.10 2009.07.31 2009-07-31 0.06 Worm.Win32.AutoRun.aaj
KingSoft 2009.2.5.15 2009.7.31.18 2009-07-31 0.52 Win32.Troj.Autorun.lr.77824
McAfee 5.3.00 5694 2009-07-31 2.99 W32/Autorun.worm.i.gen
Microsoft 1.4903 2009.07.31 2009-07-31 4.89 Trojan:Win32/Ronki!rts
Norman 6.01.09 6.01.00 2009-07-31 4.01 W32/AutoRun.ENW
Panda 9.05.01 2009.07.31 2009-07-31 1.91 Trj/Autorun.NX
Trend Micro 8.700-1004 6.336.12 2009-07-31 0.02 WORM_AUTORUN.YY
Quick Heal 10.00 2009.07.30 2009-07-30 1.03 Worm.AutoRun.lr
Rising 20.0 21.40.44.00 2009-07-31 0.78 Worm.Win32.VB.ua
Sophos 2.89.1 4.44 2009-08-01 2.77 W32/AutoRun-DO
Sunbelt 5301 5301 2009-07-30 1.25 Bulk Trojan
Symantec 1.3.0.24 20090731.004 2009-07-31 0.07 W32.SillyFDC
nProtect 20090731.01 4987030 2009-07-31 6.77 Trojan.VB.AutoRun.R
The Hacker 6.3.4.3 v00374 2009-07-30 0.67 Trojan/Dropper.lr
VBA32 3.12.10.9 20090730.1435 2009-07-30 1.80 Worm.Win32.AutoRun.aaj
VirusBuster 4.5.11.10 10.110.1/1825217 2009-07-31 2.25 -

VirSCAN.org Scanned Report :
Scanned time : 2009/08/01 10:59:16 (EST)
Scanner results: 92% Scanner(34/37) found malware!
File Name : 12LINNZ.exe
File Size : 81920 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 8f12b944d38a5f51b1273516b5cb9bca
SHA1 : b7ed8e5e0e3d59cbac0dbcf1a1b3dd01c0c175d8
Online report : http://virscan.org/report/c1498381b0dbeaf1…c9b8c85570.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090731163245 2009-07-31 0.34 Virus.Win32.AutoRun.lr!IK
AhnLab V3 2009.07.31.04 2009.07.31 2009-07-31 0.86 Win-Trojan/Autorun.77824
AntiVir 8.2.0.238 7.1.5.57 2009-07-31 0.19 TR/Autorun.LS
Antiy 2.0.18 20090729.2652900 2009-07-29 0.12 Virus/Win32.AutoRun.lr
Arcavir 2009 200907311811 2009-07-31 0.04 Trojan.Autorun.Lr
Authentium 5.1.1 200907311707 2009-07-31 1.16 W32/Worm.XIA (Exact)
AVAST! 4.7.4 090731-0 2009-07-31 0.01 Win32:AutoRun-HD
AVG 8.5.288 270.13.38/2274 2009-07-31 0.33 Worm/Delf.GXW
BitDefender 7.81008.3870071 7.26922 2009-08-01 3.37 Trojan.VB.AutoRun.R
CA (VET) 9.0.0.143 31.6.6649 2009-08-01 6.07 Win32/SillyAutorun.GB worm.
ClamAV 0.95.2 9639 2009-07-31 0.03 -
Comodo 3.10 1829 2009-07-31 0.80 Worm.Win32.AutoRun.~AET
CP Secure 1.1.0.715 2009.08.01 2009-08-01 11.69 W32.AutoRun.lr
Dr.Web 4.44.0.9170 2009.07.31 2009-07-31 5.00 Win32.HLLW.Autoruner.531
F-Prot 4.4.4.56 20090731 2009-07-31 1.16 W32/Worm.XIA (exact)
F-Secure 7.02.73807 2009.07.29.10 2009-07-29 6.33 Worm.Win32.AutoRun.aaj [AVP]
Fortinet 2.81-3.120 10.665 2009-07-31 0.15 W32/AutoRun.AAJ!worm
GData 19.6792/19.421 20090801 2009-08-01 4.74 Worm.Win32.AutoRun.aaj [Engine:A]
ViRobot 20090730 2009.07.30 2009-07-30 0.41 -
Ikarus T3.1.01.64 2009.07.31.73137 2009-07-31 4.04 Virus.Win32.AutoRun.lr
JiangMin 11.0.800 2009.07.31 2009-07-31 4.83 Trojan/DiskAutorun.ade
Kaspersky 5.5.10 2009.07.31 2009-07-31 0.06 Worm.Win32.AutoRun.aaj
KingSoft 2009.2.5.15 2009.7.31.18 2009-07-31 0.73 Win32.Troj.Autorun.lr.77824
McAfee 5.3.00 5694 2009-07-31 3.00 W32/Autorun.worm.i.gen
Microsoft 1.4903 2009.07.31 2009-07-31 4.95 Trojan:Win32/Ronki!rts
Norman 6.01.09 6.01.00 2009-07-31 4.02 W32/AutoRun.ENW
Panda 9.05.01 2009.07.31 2009-07-31 1.80 Trj/Autorun.NX
Trend Micro 8.700-1004 6.336.12 2009-07-31 0.02 WORM_AUTORUN.YY
Quick Heal 10.00 2009.07.30 2009-07-30 1.43 Worm.AutoRun.lr
Rising 20.0 21.40.44.00 2009-07-31 0.94 Worm.Win32.VB.ua
Sophos 2.89.1 4.44 2009-08-01 2.74 W32/AutoRun-DO
Sunbelt 5301 5301 2009-07-30 1.02 Bulk Trojan
Symantec 1.3.0.24 20090731.004 2009-07-31 0.05 W32.SillyFDC
nProtect 20090731.01 4987030 2009-07-31 6.20 Trojan.VB.AutoRun.R
The Hacker 6.3.4.3 v00375 2009-07-31 0.66 Trojan/Dropper.lr
VBA32 3.12.10.9 20090730.1435 2009-07-30 1.83 Worm.Win32.AutoRun.aaj
VirusBuster 4.5.11.10 10.110.1/1825217 2009-07-31 2.26 -

SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 11:01 on 01/08/2009 by 12LinNZ (Administrator - Elevation successful)

========== filefind ==========

Searching for "regedit.exe"
C:\WINDOWS\$NtServicePackUninstall$\regedit.exe —–c 146432 bytes [04:49 23/10/2008] [12:00 28/02/2006] 783AFC80383C176B22DBF8333343992D
C:\WINDOWS\regedit.exe –a— 146432 bytes [12:00 28/02/2006] [19:42 13/04/2008] 058710B720282CA82B909912D3EF28DB
C:\WINDOWS\ServicePackFiles\i386\regedit.exe —— 146432 bytes [19:42 13/04/2008] [19:42 13/04/2008] 058710B720282CA82B909912D3EF28DB
C:\WINDOWS\system\regedit.exe -r-hs- 81920 bytes [09:06 26/07/2009] [15:48 19/12/2007] 8F12B944D38A5F51B1273516B5CB9BCA

-=End Of File=-
Hi lin0056,

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTL
F3 - HKCU WinNT: Load - (C:\DOCUME~1\12linnz\LOCALS~1\services.exe) - C:\Documents and Settings\12linnz\Local Settings\services File not found
F3 - HKCU WinNT: Run - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
F3 - HKCU WinNT: Run - (C:\WINDOWS\System\regedit.exe) - C:\WINDOWS\System\regedit.exe ( )
O20 - HKLM Winlogon: System - (C:\WINDOWS\svchost.exe) - C:\WINDOWS\svchost.exe ( )
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\smss.exe) - C:\WINDOWS\smss.exe ( )
O20 - HKCU Winlogon: Shell - (C:\DOCUME~1\12linnz\LOCALS~1\explorer.exe) - C:\Documents and Settings\12linnz\Local Settings\explorer File not found
O20 - HKCU Winlogon: System - (C:\WINDOWS\System\wininit.com) - C:\WINDOWS\System\wininit.com ( )
O33 - MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\Shell - "" = Autorun
O33 - MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\Shell\Auto\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\Shell - "" = Autorun
O33 - MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\Shell\Auto\command - "" = C:\AutoRun.exe – [2007/12/20 01:48:36 | 00,081,920 | -HS- | M] ( )
O33 - MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\Shell\AutoRun\command - "" = E:\SysWin32.exe – File not found
O33 - MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\Shell\explorer\command - "" = E:\SysWin32.exe – File not found
O33 - MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\Shell\open\command - "" = E:\SysWin32.exe – File not found

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Next

Please read through these instructions to familarize yourself with what to expect when the tool runs.

We will be using Combofix again but we will run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/My_document_opens_about_5_times_upon_startup_t105685.html

KillAll::

Collect::[4]
c:\windows\12LinNZ.exe
c:\windows\win.pif
c:\windows\Fonts\font.bat
c:\windows\system\regedit.exe
c:\windows\system\wininit.com
c:\windows\system32\12LINNZ.exe
c:\windows\system32\command.cmd
c:\windows\system32\msdp32.dll
c:\windows\Web\Picture.exe
c:\windows\Fonts\font.bat

RegNull::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"12LinNZ"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"12LINNZ"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"(Default)"=-
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"(Default)"=-
[HKEY_USERS\.DEFAULT\software\microsoft\windows\Currentversion\policies\explorer\Run]
"(Default)"=-
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MsNet]

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Please post back with
  • OTL log
  • combofix log
How's the computer now?

Thanks
========== OTL ==========
Registry value HEKY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load not found.
File (explorer.exe) - C:\WINDOWS\explorer.exe not found.
Registry value HEKY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Run not found.
C:\WINDOWS\System\regedit.exe moved successfully.
Registry value HEKY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Run not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System:C:\WINDOWS\svchost.exe scheduled to be deleted on reboot.
File C:\WINDOWS\svchost.exe not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\WINDOWS\smss.exe scheduled to be deleted on reboot.
File C:\WINDOWS\smss.exe not found.
Registry delete failed. HEKY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\DOCUME~1\12linnz\LOCALS~1\explorer.exe scheduled to be deleted on reboot.
Registry delete failed. HEKY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System:C:\WINDOWS\System\wininit.com scheduled to be deleted on reboot.
C:\WINDOWS\System\wininit.com moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57a0d8d6-7030-11de-ad3d-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57a0d8d6-7030-11de-ad3d-806d6172696f}\ not found.
C:\AutoRun.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57a0d8d6-7030-11de-ad3d-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92731639-74ba-11de-ad51-00a0d1ad1f81}\ not found.
File E:\SysWin32.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92731639-74ba-11de-ad51-00a0d1ad1f81}\ not found.
File E:\SysWin32.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92731639-74ba-11de-ad51-00a0d1ad1f81}\ not found.
File E:\SysWin32.exe not found.

OTL by OldTimer - Version 3.0.10.3 log created on 08012009_185754

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System:C:\WINDOWS\svchost.exe scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\WINDOWS\smss.exe scheduled to be deleted on reboot.
Registry delete failed. :HEKY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\DOCUME~1\12linnz\LOCALS~1\explorer.exe scheduled to be deleted on reboot.
Registry delete failed. :HEKY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System:C:\WINDOWS\System\wininit.com scheduled to be deleted on reboot.

ComboFix 09-07-31.04 - 12LinNZ 01/08/2009 19:03.4.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.1977.1355 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\12linnz\Desktop\CFScript.txt
AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
* Created a new restore point

file zipped: c:\windows\12LinNZ.exe
file zipped: c:\windows\Fonts\font.bat
file zipped: c:\windows\system\regedit.exe
file zipped: c:\windows\system\wininit.com
file zipped: c:\windows\system32\12LINNZ.exe
file zipped: c:\windows\system32\command.cmd
file zipped: c:\windows\system32\msdp32.dll
file zipped: c:\windows\Web\Picture.exe
file zipped: c:\windows\win.pif
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.exe
C:\autorun.inf
c:\windows\12LinNZ.exe
c:\windows\Fonts\font.bat
c:\windows\system\regedit.exe
c:\windows\system\wininit.com
c:\windows\system32\12LINNZ.exe
c:\windows\system32\command.cmd
c:\windows\system32\msdp32.dll
c:\windows\system32\sfcfiles.dll
c:\windows\Web\Picture.exe
c:\windows\win.pif

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MsNet


((((((((((((((((((((((((( Files Created from 2009-07-01 to 2009-08-01 )))))))))))))))))))))))))))))))
.

2009-08-01 08:57 . 2009-08-01 08:57 ——– d—–w- C:\_OTL
2009-07-28 14:46 . 2009-07-28 14:46 1878984 —-a-w- c:\documents and settings\12linnz\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-07-27 11:28 . 2008-11-21 06:11 38200 —-a-w- c:\documents and settings\12linnz\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-07-23 23:47 . 2009-07-23 23:47 ——– d—–w- c:\program files\Enable Software
2009-07-23 23:24 . 2009-07-23 23:24 ——– d—–w- c:\program files\uTorrent
2009-07-23 23:24 . 2009-07-23 23:26 ——– d—–w- c:\documents and settings\12linnz\Application Data\uTorrent
2009-07-16 23:53 . 2009-07-16 23:53 ——– d—–w- c:\documents and settings\12linnz\Bluetooth Software
2009-07-16 10:21 . 2009-07-16 10:21 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-16 04:23 . 2009-07-16 04:23 ——– d—–w- c:\documents and settings\12linnz\Application Data\DivX
2009-07-16 00:18 . 2009-04-29 04:55 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-07-16 00:18 . 2009-04-29 04:55 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-16 00:18 . 2009-04-29 04:55 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-07-16 00:18 . 2009-04-29 04:55 383488 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2009-07-16 00:18 . 2009-04-29 04:55 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2009-07-16 00:18 . 2009-04-28 09:05 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2009-07-16 00:18 . 2008-07-09 14:25 2455488 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2009-07-16 00:18 . 2009-04-29 04:55 6066176 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-07-15 08:13 . 2009-07-15 08:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-15 06:48 . 2009-07-15 07:06 ——– d—–w- c:\windows\SxsCaPendDel
2009-07-15 06:11 . 2009-07-15 06:11 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Microsoft Help
2009-07-15 06:10 . 2009-07-18 22:57 ——– d—–w- c:\documents and settings\saaa
2009-07-15 05:14 . 2009-02-03 19:59 56832 -c—-w- c:\windows\system32\dllcache\secur32.dll
2009-07-15 05:14 . 2009-03-21 14:06 989696 -c—-w- c:\windows\system32\dllcache\kernel32.dll
2009-07-15 05:14 . 2008-12-05 06:54 144896 -c—-w- c:\windows\system32\dllcache\schannel.dll
2009-07-15 05:09 . 2008-06-17 19:02 8461312 -c—-w- c:\windows\system32\dllcache\shell32.dll
2009-07-15 05:09 . 2009-04-15 14:51 585216 -c—-w- c:\windows\system32\dllcache\rpcrt4.dll
2009-07-15 05:09 . 2008-12-16 12:30 354304 -c—-w- c:\windows\system32\dllcache\winhttp.dll
2009-07-15 05:08 . 2008-10-23 12:36 286720 -c—-w- c:\windows\system32\dllcache\gdi32.dll
2009-07-15 05:08 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-07-15 05:08 . 2008-04-21 12:08 215552 -c—-w- c:\windows\system32\dllcache\wordpad.exe
2009-07-14 13:26 . 2009-07-14 13:26 ——– d—–w- c:\documents and settings\12linnz\Application Data\Malwarebytes
2009-07-14 13:26 . 2009-07-14 13:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-14 09:28 . 2009-07-14 09:28 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-07-14 09:17 . 2009-07-14 09:17 ——– d—–w- c:\documents and settings\12linnz\Application Data\Nexon
2009-07-14 09:15 . 2009-07-14 09:15 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-07-14 09:15 . 2009-07-14 09:22 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Google
2009-07-14 09:14 . 2009-07-14 09:14 ——– d—–w- c:\program files\PowerISO
2009-07-14 09:12 . 2009-07-14 09:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-14 09:12 . 2009-07-14 09:15 ——– d—–w- c:\program files\Google
2009-07-14 08:38 . 2009-07-14 08:38 ——– d–h–w- c:\windows\PIF
2009-07-14 08:37 . 2009-07-14 08:37 ——– d—–w- c:\program files\Trend Micro
2009-07-14 08:15 . 2009-07-14 12:32 ——– d—–w- c:\documents and settings\12linnz\Application Data\Apple Computer
2009-07-14 08:12 . 2009-07-14 12:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-07-14 08:11 . 2009-07-14 08:15 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Apple Computer
2009-07-14 08:11 . 2009-07-14 08:11 ——– d—–w- c:\program files\Combined Community Codec Pack
2009-07-14 08:10 . 2009-07-14 08:10 ——– d—–w- c:\program files\Messenger Plus! Live
2009-07-14 07:57 . 2009-07-14 07:57 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Sophos
2009-07-14 07:57 . 2009-07-29 11:26 ——– d—–w- c:\documents and settings\12linnz\Tracing
2009-07-14 07:54 . 2009-07-14 07:54 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-14 07:53 . 2009-07-14 07:54 ——– d—–w- c:\program files\Microsoft
2009-07-14 07:53 . 2009-07-14 07:53 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-14 07:53 . 2009-07-14 07:54 ——– d—–w- c:\program files\Windows Live
2009-07-14 07:49 . 2009-07-14 07:49 ——– d—–w- c:\program files\Common Files\Windows Live
2009-07-14 07:48 . 2009-07-15 08:13 105544 —-a-w- c:\documents and settings\12linnz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-14 07:48 . 2009-07-14 07:48 ——– d—–w- c:\program files\CCleaner
2009-07-14 06:52 . 2009-07-14 06:52 0 —-a-w- c:\windows\nsreg.dat
2009-07-14 06:52 . 2009-07-14 06:52 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Mozilla
2009-07-14 06:47 . 2009-07-14 06:47 ——– d-s—w- c:\documents and settings\12linnz\UserData
2009-07-14 06:47 . 2009-07-14 06:47 152576 —-a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-14 06:41 . 2008-04-13 14:15 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2009-07-14 06:41 . 2008-04-13 14:15 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-07-14 05:52 . 2009-07-26 08:55 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Adobe
2009-07-14 05:51 . 2009-07-14 05:51 ——– d—–w- c:\documents and settings\12linnz\Application Data\Infineon

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 09:15 . 2008-10-24 01:40 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-15 06:55 . 2008-10-24 01:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-15 06:35 . 2008-10-24 01:32 ——– d—–w- c:\program files\Microsoft Works
2009-07-14 08:14 . 2009-07-14 08:14 ——– d—–w- c:\program files\iTunes
2009-07-14 08:14 . 2009-07-14 08:14 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-14 08:14 . 2009-07-14 08:14 ——– d—–w- c:\program files\iPod
2009-07-14 08:14 . 2009-07-14 08:12 ——– d—–w- c:\program files\Common Files\Apple
2009-07-14 08:14 . 2009-07-14 08:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-14 08:14 . 2009-07-14 08:14 ——– d—–w- c:\program files\Bonjour
2009-07-14 08:14 . 2009-07-14 08:13 ——– d—–w- c:\program files\QuickTime
2009-07-14 08:13 . 2009-07-14 08:13 ——– d—–w- c:\program files\Apple Software Update
2009-07-14 06:47 . 2008-11-05 00:35 ——– d—–w- c:\program files\Java
2009-06-05 03:57 . 2009-06-05 03:57 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 01:42 . 2009-07-14 08:13 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-05 01:42 . 2009-07-14 08:13 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-07-17 13:12 . 2009-07-14 06:52 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

——- Sigcheck ——-

[-] 2006-02-28 12:00 14336 8F078AE4ED187AAABC0A305146DE6716 c:\windows\$NtServicePackUninstall$\svchost.exe
[-] 2008-04-13 19:42 14336 27C6D03BCDB8CFEB96B716F3D8BE3E18 c:\windows\ServicePackFiles\i386\svchost.exe
[-] 2008-04-13 19:42 14336 27C6D03BCDB8CFEB96B716F3D8BE3E18 c:\windows\system32\svchost.exe
[-] 2008-04-13 19:42 14336 27C6D03BCDB8CFEB96B716F3D8BE3E18 c:\windows\system32\dllcache\cache\svchost.exe

[-] 2006-02-28 12:00 577024 C72661F8552ACE7C5C85E16A3CF505C4 c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2008-04-13 19:42 578560 B26B135FF1B9F60C9388B4A7D16F600B c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-13 19:42 578560 B26B135FF1B9F60C9388B4A7D16F600B c:\windows\system32\user32.dll
[-] 2008-04-13 19:42 578560 B26B135FF1B9F60C9388B4A7D16F600B c:\windows\system32\dllcache\cache\user32.dll

[-] 2006-02-28 12:00 82944 2ED0B7F12A60F90092081C50FA0EC2B2 c:\windows\$NtServicePackUninstall$\ws2_32.dll
[-] 2008-04-13 19:42 82432 2CCC474EB85CEAA3E1FA1726580A3E5A c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-13 19:42 82432 2CCC474EB85CEAA3E1FA1726580A3E5A c:\windows\system32\ws2_32.dll
[-] 2008-04-13 19:42 82432 2CCC474EB85CEAA3E1FA1726580A3E5A c:\windows\system32\dllcache\cache\ws2_32.dll

[-] 2008-08-20 05:33 667648 C91E3A6EF094202F6B5CA8960DFCF243 c:\windows\$hf_mig$\KB956390\SP2QFE\wininet.dll
[-] 2008-08-20 05:30 666112 9AF5F25124FBDC36E2B510729CBA2674 c:\windows\$hf_mig$\KB956390\SP3GDR\wininet.dll
[-] 2008-08-20 04:58 666624 94418F53D2612C26DBADC04DAFBC197C c:\windows\$hf_mig$\KB956390\SP3QFE\wininet.dll
[-] 2009-04-29 04:21 668160 04BCB4F87B35502568F6CF33433543A5 c:\windows\$hf_mig$\KB969897\SP3QFE\wininet.dll
[-] 2009-04-29 04:49 828928 62CCA075F44015147B8971DAFFBCFF76 c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\wininet.dll
[-] 2008-08-20 05:38 659456 87E694D09893978F22024FEEEDF35342 c:\windows\$NtServicePackUninstall$\wininet.dll
[-] 2008-08-20 05:30 666112 9AF5F25124FBDC36E2B510729CBA2674 c:\windows\ie7\wininet.dll
[-] 2007-08-13 08:54 818688 A4A0FC92358F39538A6494C42EF99FE9 c:\windows\ie7updates\KB969897-IE7\wininet.dll
[-] 2008-04-13 19:42 666112 7A4F775ABB2F1C97DEF3E73AFA2FAEDD c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D83B0DDB c:\windows\system32\wininet.dll
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D83B0DDB c:\windows\system32\dllcache\wininet.dll
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D83B0DDB c:\windows\system32\dllcache\cache\wininet.dll

[-] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[-] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[-] 2008-04-13 14:50 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\dllcache\cache\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\drivers\tcpip.sys

[-] 2006-02-28 12:00 502272 01C3346C241652F43AED8E2149881BFE c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2008-04-13 19:42 507904 ED0EF0A136DEC83DF69F04118870003E c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-13 19:42 507904 ED0EF0A136DEC83DF69F04118870003E c:\windows\system32\winlogon.exe
[-] 2008-04-13 19:42 507904 ED0EF0A136DEC83DF69F04118870003E c:\windows\system32\dllcache\cache\winlogon.exe

[-] 2006-02-28 12:00 182912 558635D3AF1C7546D26067D5D9B6959E c:\windows\$NtServicePackUninstall$\ndis.sys
[-] 2008-04-13 14:50 182656 1DF7F42665C94B825322FAE71721130D c:\windows\ServicePackFiles\i386\ndis.sys
[-] 2008-04-13 14:50 182656 1DF7F42665C94B825322FAE71721130D c:\windows\system32\dllcache\cache\ndis.sys
[-] 2008-04-13 14:50 182656 1DF7F42665C94B825322FAE71721130D c:\windows\system32\drivers\ndis.sys

[-] 2006-02-28 12:00 29056 4448006B6BC60E6C027932CFC38D6855 c:\windows\$NtServicePackUninstall$\ip6fw.sys
[-] 2008-04-13 14:23 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\ServicePackFiles\i386\ip6fw.sys
[-] 2008-04-13 14:23 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\system32\dllcache\cache\ip6fw.sys
[-] 2008-04-13 14:23 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\system32\drivers\ip6fw.sys

[-] 2009-02-06 10:30 2066176 607352B9CB3D708C67F6039097801B5A c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 09:18 2062976 63EC865DFF6CCFC7BEF94B5C50297CAD c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
[-] 2008-08-14 09:33 2066048 4AC58F03EB94A72809949D757FC39D80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
[-] 2008-08-14 05:39 2066048 A25E9B86EFFB2AF33BF51E676B68BFB0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 09:22 2015744 DC097A896A03B8277457D228FD12D4E6 c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
[-] 2009-02-07 09:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2008-04-13 14:01 2065792 109F8E3E3C82E337BB71B6BC9B895D61 c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2009-02-06 10:32 2023936 65D4220799E6FC2CB079070A6393CC0E c:\windows\system32\ntkrnlpa.exe
[-] 2009-02-07 09:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2009-02-06 10:32 2023936 65D4220799E6FC2CB079070A6393CC0E c:\windows\system32\dllcache\cache\ntkrnlpa.exe

[-] 2009-02-07 09:35 2189184 EFE8EACE83EAAD5849A7A548FB75B584 c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 09:57 2185984 CE69DBD54221F2D40E49FF6DB77C6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
[-] 2008-08-14 10:11 2189184 EEAF32F8E15A24F62BECB1BD403BB5C5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
[-] 2008-08-14 06:11 2189184 31914172342BFF330063F343AC6958FE c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 09:58 2136064 DD31AB4B91C2605601A3C108AF57A0C9 c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2008-04-13 14:57 2188928 0C89243C7C3EE199B96FCC16990E0679 c:\windows\ServicePackFiles\i386\ntoskrnl.exe
[-] 2009-02-06 11:06 2145280 0CBA44D0938D57F334C0862424148B70 c:\windows\system32\ntoskrnl.exe
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\system32\dllcache\ntoskrnl.exe
[-] 2009-02-06 11:06 2145280 0CBA44D0938D57F334C0862424148B70 c:\windows\system32\dllcache\cache\ntoskrnl.exe

[-] 2008-04-13 19:42 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\explorer.exe
[-] 2006-02-28 12:00 1032192 A0732187050030AE399B241436565E64 c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2008-04-13 19:42 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2008-04-13 19:42 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\system32\dllcache\cache\explorer.exe

[-] 2009-02-06 11:06 110592 020CEAAEDC8EB655B6506B8C70D53BB6 c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2006-02-28 12:00 108032 C6CE6EEC82F187615D1002BB3BB50ED4 c:\windows\$NtServicePackUninstall$\services.exe
[-] 2008-04-13 19:42 108544 0E776ED5F7CC9F94299E70461B7B8185 c:\windows\ServicePackFiles\i386\services.exe
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\services.exe
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\dllcache\services.exe
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\dllcache\cache\services.exe

[-] 2006-02-28 12:00 13312 84885F9B82F4D55C6146EBF6065D75D2 c:\windows\$NtServicePackUninstall$\lsass.exe
[-] 2008-04-13 19:42 13312 BF2466B3E18E970D8A976FB95FC1CA85 c:\windows\ServicePackFiles\i386\lsass.exe
[-] 2008-04-13 19:42 13312 BF2466B3E18E970D8A976FB95FC1CA85 c:\windows\system32\lsass.exe
[-] 2008-04-13 19:42 13312 BF2466B3E18E970D8A976FB95FC1CA85 c:\windows\system32\dllcache\cache\lsass.exe

[-] 2006-02-28 12:00 15360 24232996A38C0B0CF151C2140AE29FC8 c:\windows\$NtServicePackUninstall$\ctfmon.exe
[-] 2008-04-13 19:42 15360 5F1D5F88303D4A4DBC8E5F97BA967CC3 c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-13 19:42 15360 5F1D5F88303D4A4DBC8E5F97BA967CC3 c:\windows\system32\ctfmon.exe
[-] 2008-04-13 19:42 15360 5F1D5F88303D4A4DBC8E5F97BA967CC3 c:\windows\system32\dllcache\cache\ctfmon.exe

[-] 2006-02-28 12:00 57856 7435B108B935E42EA92CA94F59C8E717 c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2008-04-13 19:42 57856 D8E14A61ACC1D4A6CD0D38AEBAC7FA3B c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2008-04-13 19:42 57856 D8E14A61ACC1D4A6CD0D38AEBAC7FA3B c:\windows\system32\spoolsv.exe
[-] 2008-04-13 19:42 57856 D8E14A61ACC1D4A6CD0D38AEBAC7FA3B c:\windows\system32\dllcache\cache\spoolsv.exe

[-] 2006-02-28 12:00 24576 39B1FFB03C2296323832ACBAE50D2AFF c:\windows\$NtServicePackUninstall$\userinit.exe
[-] 2008-04-13 19:42 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2008-04-13 19:42 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\system32\userinit.exe
[-] 2008-04-13 19:42 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\system32\dllcache\cache\userinit.exe

[-] 2006-02-28 12:00 295424 B60C877D16D9C880B952FDA04ADF16E6 c:\windows\$NtServicePackUninstall$\termsrv.dll
[-] 2008-04-13 19:42 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-04-13 19:42 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\system32\termsrv.dll
[-] 2008-04-13 19:42 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\system32\dllcache\cache\termsrv.dll

[-] 2009-03-21 09:29 991744 DA11D9D6ECBDF0F93436A4B7C13F7BEC c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2006-02-28 12:00 983552 888190E31455FAD793312F8D087146EB c:\windows\$NtServicePackUninstall$\kernel32.dll
[-] 2008-04-13 19:41 989696 C24B983D211C34DA8FCC1AC38477971D c:\windows\ServicePackFiles\i386\kernel32.dll
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\kernel32.dll
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\dllcache\kernel32.dll
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\dllcache\cache\kernel32.dll

[-] 2006-02-28 12:00 17408 1B5F6923ABB450692E9FE0672C897AED c:\windows\$NtServicePackUninstall$\powrprof.dll
[-] 2008-04-13 19:42 17408 50A166237A0FA771261275A405646CC0 c:\windows\ServicePackFiles\i386\powrprof.dll
[-] 2008-04-13 19:42 17408 50A166237A0FA771261275A405646CC0 c:\windows\system32\powrprof.dll
[-] 2008-04-13 19:42 17408 50A166237A0FA771261275A405646CC0 c:\windows\system32\dllcache\cache\powrprof.dll

[-] 2006-02-28 12:00 110080 87CA7CE6469577F059297B9D6556D66D c:\windows\$NtServicePackUninstall$\imm32.dll
[-] 2008-04-13 19:41 110080 0DA85218E92526972A821587E6A8BF8F c:\windows\ServicePackFiles\i386\imm32.dll
[-] 2008-04-13 19:41 110080 0DA85218E92526972A821587E6A8BF8F c:\windows\system32\imm32.dll
[-] 2008-04-13 19:41 110080 0DA85218E92526972A821587E6A8BF8F c:\windows\system32\dllcache\cache\imm32.dll

[-] 2006-02-28 12:00 167936 9C3C12975C97119412802B181FBEEFFE c:\windows\$NtServicePackUninstall$\appmgmts.dll
[-] 2008-04-13 19:41 167936 D8849F77C0B66226335A59D26CB4EDC6 c:\windows\ServicePackFiles\i386\appmgmts.dll
[-] 2008-04-13 19:41 167936 D8849F77C0B66226335A59D26CB4EDC6 c:\windows\system32\appmgmts.dll
[-] 2008-04-13 19:41 167936 D8849F77C0B66226335A59D26CB4EDC6 c:\windows\system32\dllcache\cache\appmgmts.dll

[-] 2006-02-20 15:04 3052032 C6E663C066E3BEA5B0BB70D87D0701E9 c:\windows\$hf_mig$\KB911164\SP2QFE\mshtml.dll
[-] 2008-08-20 05:33 3067392 20D44D1A5A406CD8E129D3D4F0B5717C c:\windows\$hf_mig$\KB956390\SP2QFE\mshtml.dll
[-] 2008-08-20 01:00 3067904 507BDA42F7DB8209C0F0B3556A043491 c:\windows\$hf_mig$\KB956390\SP3GDR\mshtml.dll
[-] 2008-08-20 04:58 3067904 BD45470B132A0F98596277323D9F2E5A c:\windows\$hf_mig$\KB956390\SP3QFE\mshtml.dll
[-] 2009-04-29 04:21 3069440 06CF679E3D24C3DF270556456A0F1EDA c:\windows\$hf_mig$\KB969897\SP3QFE\mshtml.dll
[-] 2009-04-29 00:19 3598336 C6FD770D518FB024245A0EE217D72BC1 c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\mshtml.dll
[-] 2008-08-20 05:38 3060224 B83EB71C2052E05D13D690A224357441 c:\windows\$NtServicePackUninstall$\mshtml.dll
[-] 2008-08-20 01:00 3067904 507BDA42F7DB8209C0F0B3556A043491 c:\windows\ie7\mshtml.dll
[-] 2007-08-13 08:54 3578368 C6EC2493346ED8888A549F59210A8ED3 c:\windows\ie7updates\KB969897-IE7\mshtml.dll
[-] 2008-04-13 19:42 3066880 A706E122B398FE1AB85CB9B75D044223 c:\windows\ServicePackFiles\i386\mshtml.dll
[-] 2009-04-29 04:56 3596288 2B4315EC9E3124408A2A5074C4B97700 c:\windows\system32\mshtml.dll
[-] 2009-04-29 04:56 3596288 2B4315EC9E3124408A2A5074C4B97700 c:\windows\system32\dllcache\mshtml.dll

[-] 2006-02-28 12:00 24576 EBDEE8A2EE5393890A1ACEE971C4C246 c:\windows\$NtServicePackUninstall$\kbdclass.sys
[-] 2008-04-13 14:09 24576 463C1EC80CD17420A542B7F36A36F128 c:\windows\ServicePackFiles\i386\kbdclass.sys
[-] 2008-04-13 14:09 24576 463C1EC80CD17420A542B7F36A36F128 c:\windows\system32\dllcache\cache\kbdclass.sys
[-] 2008-04-13 14:09 24576 463C1EC80CD17420A542B7F36A36F128 c:\windows\system32\drivers\kbdclass.sys
[-] 2006-02-28 12:00 24576 EBDEE8A2EE5393890A1ACEE971C4C246 c:\windows\system32\ReinstallBackups\0017\DriverFiles\i386\kbdclass.sys

[-] 2006-02-28 12:00 792064 6728270CB7DBB776ED086F5AC4C82310 c:\windows\$NtServicePackUninstall$\comres.dll
[-] 2008-04-13 19:41 792064 1280A158C722FA95A80FB7AEBE78FA7D c:\windows\ServicePackFiles\i386\comres.dll
[-] 2008-04-13 19:41 792064 1280A158C722FA95A80FB7AEBE78FA7D c:\windows\system32\comres.dll
[-] 2008-04-13 19:41 792064 1280A158C722FA95A80FB7AEBE78FA7D c:\windows\system32\dllcache\cache\comres.dll

[-] 2006-02-28 12:00 22016 74D66B3DE265E8789153414E75175F26 c:\windows\$NtServicePackUninstall$\lpk.dll
[-] 2008-04-13 19:41 22016 012DF358CEBAA23ACB26D82077820817 c:\windows\ServicePackFiles\i386\lpk.dll
[-] 2008-04-13 19:41 22016 012DF358CEBAA23ACB26D82077820817 c:\windows\system32\lpk.dll
[-] 2008-04-13 19:41 22016 012DF358CEBAA23ACB26D82077820817 c:\windows\system32\dllcache\cache\lpk.dll

[-] 2006-02-28 12:00 4224 DA1F27D85E0D1525F6621372E7B685E9 c:\windows\system32\dllcache\beep.sys
[-] 2006-02-28 12:00 4224 DA1F27D85E0D1525F6621372E7B685E9 c:\windows\system32\dllcache\cache\beep.sys
[-] 2006-02-28 12:00 4224 DA1F27D85E0D1525F6621372E7B685E9 c:\windows\system32\drivers\beep.sys

[-] 2006-02-28 12:00 2944 73C1E1F395918BC2C6DD67AF7591A3AD c:\windows\system32\dllcache\null.sys
[-] 2006-02-28 12:00 2944 73C1E1F395918BC2C6DD67AF7591A3AD c:\windows\system32\dllcache\cache\null.sys
[-] 2006-02-28 12:00 2944 73C1E1F395918BC2C6DD67AF7591A3AD c:\windows\system32\drivers\null.sys

[-] 2004-08-03 12:39 142464 841F385C6CFAF66B58FBD898722BB4F0 c:\windows\$NtServicePackUninstall$\aec.sys
[-] 2008-04-13 12:09 142592 8BED39E3C35D6A489438B8141717A557 c:\windows\ServicePackFiles\i386\aec.sys
[-] 2008-04-13 12:09 142592 8BED39E3C35D6A489438B8141717A557 c:\windows\system32\dllcache\cache\aec.sys
[-] 2008-04-13 12:09 142592 8BED39E3C35D6A489438B8141717A557 c:\windows\system32\drivers\aec.sys

[-] 2006-02-28 12:00 924432 DDF8D47ACF8FC3FE5F7F2B95C4D4D136 c:\windows\$NtServicePackUninstall$\mfc40u.dll
[-] 2008-04-13 19:41 927504 CDDD4416B2B4C7295FE3FDB6DDE57E4E c:\windows\ServicePackFiles\i386\mfc40u.dll
[-] 2008-04-13 19:41 927504 CDDD4416B2B4C7295FE3FDB6DDE57E4E c:\windows\system32\mfc40u.dll
[-] 2008-04-13 19:41 927504 CDDD4416B2B4C7295FE3FDB6DDE57E4E c:\windows\system32\dllcache\cache\mfc40u.dll

[-] 2009-02-09 10:56 401408 9222562D44021B988B9F9F62207FB6F2 c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[-] 2006-02-28 12:00 395776 5C83A4408604F737717AB96371201680 c:\windows\$NtServicePackUninstall$\rpcss.dll
[-] 2008-04-13 19:42 399360 2589FE6015A316C0F5D5112B4DA7B509 c:\windows\ServicePackFiles\i386\rpcss.dll
[-] 2009-02-09 12:10 401408 6B27A5C03DFB94B4245739065431322C c:\windows\system32\rpcss.dll
[-] 2009-02-09 12:10 401408 6B27A5C03DFB94B4245739065431322C c:\windows\system32\dllcache\rpcss.dll
[-] 2009-02-09 12:10 401408 6B27A5C03DFB94B4245739065431322C c:\windows\system32\dllcache\cache\rpcss.dll

[-] 2006-02-28 12:00 33792 95FD808E4AC22ABA025A7B3EAC0375D2 c:\windows\$NtServicePackUninstall$\msgsvc.dll
[-] 2008-04-13 19:42 33792 986B1FF5814366D71E0AC5755C88F2D3 c:\windows\ServicePackFiles\i386\msgsvc.dll
[-] 2008-04-13 19:42 33792 986B1FF5814366D71E0AC5755C88F2D3 c:\windows\system32\msgsvc.dll
[-] 2008-04-13 19:42 33792 986B1FF5814366D71E0AC5755C88F2D3 c:\windows\system32\dllcache\cache\msgsvc.dll

[-] 2006-02-28 12:00 611328 A77DFB85FAEE49D66C74DA6024EBC69B c:\windows\$NtServicePackUninstall$\comctl32.dll
[-] 2008-04-13 19:41 617472 06F247492BC786CE5C24A23E178C711A c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2008-04-13 19:41 617472 06F247492BC786CE5C24A23E178C711A c:\windows\system32\comctl32.dll
[-] 2008-04-13 19:41 617472 06F247492BC786CE5C24A23E178C711A c:\windows\system32\dllcache\cache\comctl32.dll
[-] 2006-02-28 12:00 921088 AEF3D788DBF40C7C4D204EA45EB0C505 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[-] 2006-02-28 12:00 1050624 5AF68A5E44734A082442668E9C787743 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
[-] 2008-04-13 19:42 1054208 BD38D1EBE24A46BD3EDA059560AFBA12 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

[-] 2006-02-28 12:00 11648 9859C0F6936E723E4892D7141B1327D5 c:\windows\system32\dllcache\cache\acpiec.sys
[-] 2006-02-28 12:00 11648 9859C0F6936E723E4892D7141B1327D5 c:\windows\system32\drivers\acpiec.sys

[-] 2006-02-28 12:00 5120 E8A12A12EA9088B4327D49EDCA3ADD3E c:\windows\$NtServicePackUninstall$\sfc.dll
[-] 2008-04-13 19:42 5120 96E1C926F22EE1BFBAE82901A35F6BF3 c:\windows\ServicePackFiles\i386\sfc.dll
[-] 2008-04-13 19:42 5120 96E1C926F22EE1BFBAE82901A35F6BF3 c:\windows\system32\sfc.dll
[-] 2008-04-13 19:42 5120 96E1C926F22EE1BFBAE82901A35F6BF3 c:\windows\system32\dllcache\cache\sfc.dll

[-] 2006-02-28 12:00 407040 96353FCECBA774BB8DA74A1C6507015A c:\windows\$NtServicePackUninstall$\netlogon.dll
[-] 2008-04-13 19:42 407040 1B7F071C51B77C272875C3A23E1E4550 c:\windows\ServicePackFiles\i386\netlogon.dll
[-] 2008-04-13 19:42 407040 1B7F071C51B77C272875C3A23E1E4550 c:\windows\system32\netlogon.dll
[-] 2008-04-13 19:42 407040 1B7F071C51B77C272875C3A23E1E4550 c:\windows\system32\dllcache\cache\netlogon.dll

[-] 2006-02-28 12:00 170496 92BDF74F12D6CBEC43C94D4B7F804838 c:\windows\$NtServicePackUninstall$\srsvc.dll
[-] 2008-04-13 19:42 171008 3805DF0AC4296A34BA4BF93B346CC378 c:\windows\ServicePackFiles\i386\srsvc.dll
[-] 2008-04-13 19:42 171008 3805DF0AC4296A34BA4BF93B346CC378 c:\windows\system32\srsvc.dll
[-] 2008-04-13 19:42 171008 3805DF0AC4296A34BA4BF93B346CC378 c:\windows\system32\dllcache\cache\srsvc.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-31_07.24.25 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-31 07:23 . 2008-07-04 00:35 73728 c:\windows\Temp\sophos_autoupdate1.dir\xmltok.dll
+ 2009-08-01 09:13 . 2008-07-04 00:35 73728 c:\windows\Temp\sophos_autoupdate1.dir\xmltok.dll
- 2009-07-31 07:23 . 2008-07-04 00:35 57344 c:\windows\Temp\sophos_autoupdate1.dir\xmlparse.dll
+ 2009-08-01 09:13 . 2008-07-04 00:35 57344 c:\windows\Temp\sophos_autoupdate1.dir\xmlparse.dll
+ 2009-08-01 09:13 . 2008-07-04 00:35 14336 c:\windows\Temp\sophos_autoupdate1.dir\xmlcpp.dll
- 2009-07-31 07:23 . 2008-07-04 00:35 14336 c:\windows\Temp\sophos_autoupdate1.dir\xmlcpp.dll
- 2009-07-31 07:23 . 2008-07-04 00:35 18432 c:\windows\Temp\sophos_autoupdate1.dir\SharedRes.dll
+ 2009-08-01 09:13 . 2008-07-04 00:35 18432 c:\windows\Temp\sophos_autoupdate1.dir\SharedRes.dll
- 2009-07-31 07:23 . 2008-07-04 00:35 20480 c:\windows\Temp\sophos_autoupdate1.dir\crypto.dll
+ 2009-08-01 09:13 . 2008-07-04 00:35 20480 c:\windows\Temp\sophos_autoupdate1.dir\crypto.dll
+ 2009-08-01 09:13 . 2008-07-04 00:35 45056 c:\windows\Temp\sophos_autoupdate1.dir\boost_date_time-vc71-mt-1_32.dll
- 2009-07-31 07:23 . 2008-07-04 00:35 45056 c:\windows\Temp\sophos_autoupdate1.dir\boost_date_time-vc71-mt-1_32.dll
+ 2009-08-01 09:13 . 2009-08-01 09:13 16384 c:\windows\Temp\Perflib_Perfdata_6b4.dat
+ 2009-08-01 09:13 . 2009-08-01 09:13 16384 c:\windows\Temp\Perflib_Perfdata_1c4.dat
+ 2009-08-01 09:13 . 2009-07-23 00:13 2970 c:\windows\Temp\sophos_autoupdate1.dir\scf.dat
- 2009-07-31 07:23 . 2009-07-23 00:13 2970 c:\windows\Temp\sophos_autoupdate1.dir\scf.dat
- 2009-07-31 07:23 . 2008-12-24 12:33 208896 c:\windows\Temp\sophos_autoupdate1.dir\retailer.dll
+ 2009-08-01 09:13 . 2008-12-24 12:33 208896 c:\windows\Temp\sophos_autoupdate1.dir\retailer.dll
+ 2009-08-01 09:13 . 2008-07-04 00:33 348160 c:\windows\Temp\sophos_autoupdate1.dir\MSVCR71.DLL
- 2009-07-31 07:23 . 2008-07-04 00:33 348160 c:\windows\Temp\sophos_autoupdate1.dir\MSVCR71.DLL
+ 2009-08-01 09:13 . 2008-07-04 00:34 499712 c:\windows\Temp\sophos_autoupdate1.dir\MSVCP71.DLL
- 2009-07-31 07:23 . 2008-07-04 00:34 499712 c:\windows\Temp\sophos_autoupdate1.dir\MSVCP71.DLL
+ 2009-08-01 09:13 . 2008-07-04 00:35 745472 c:\windows\Temp\sophos_autoupdate1.dir\libeay32.dll
- 2009-07-31 07:23 . 2008-07-04 00:35 745472 c:\windows\Temp\sophos_autoupdate1.dir\libeay32.dll
+ 2009-08-01 09:13 . 2008-12-23 20:47 159744 c:\windows\Temp\sophos_autoupdate1.dir\libcurl.dll
- 2009-07-31 07:23 . 2008-12-23 20:47 159744 c:\windows\Temp\sophos_autoupdate1.dir\libcurl.dll
+ 2009-08-01 09:13 . 2009-07-23 00:13 176128 c:\windows\Temp\sophos_autoupdate1.dir\CidSync.dll
- 2009-07-31 07:23 . 2009-07-23 00:13 176128 c:\windows\Temp\sophos_autoupdate1.dir\CidSync.dll
- 2009-07-31 07:23 . 2009-06-11 08:36 172032 c:\windows\Temp\sophos_autoupdate1.dir\ChannelUpdater.dll
+ 2009-08-01 09:13 . 2009-06-11 08:36 172032 c:\windows\Temp\sophos_autoupdate1.dir\ChannelUpdater.dll
+ 2009-08-01 09:13 . 2009-07-23 00:13 663552 c:\windows\Temp\sophos_autoupdate1.dir\ALUpdate.exe
- 2009-07-31 07:23 . 2009-07-23 00:13 663552 c:\windows\Temp\sophos_autoupdate1.dir\ALUpdate.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2008-10-22 3680768]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1028096]
"IFXSPMGT"="c:\windows\system32\ifxspmgt.exe" [2007-07-23 677144]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-04 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-04 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-04 141848]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-05-02 870920]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-07 16862208]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2009-6-11 245760]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-11 576104]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"System"="c:\windows\System\wininit.com"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-10-22 03:39 3076096 —-a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
"%windir%\\Network Diagnostic\\xpnetdiag.exe"= %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= c:\program files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"= c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:*:Disabled:Studio program file
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"= c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"= c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:*:Enabled:Adobe Version Cue CS4 Server
"c:\\Program Files\\Microsoft Visual Studio 8\\Common7\\IDE\\Remote Debugger\\x86\\msvsmon.exe"= c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe:*:Enabled:Visual Studio Remote Debugging Monitor
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= c:\program files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= c:\program files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"c:\\Program Files\\uTorrent\\uTorrent.exe"= c:\program files\uTorrent\uTorrent.exe:*:Enabled:µTorrent

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\GloballyOpenPorts\List]
"4500:UDP"= 4500:UDP:*:Enabled:IPsec (IKE NAT-T)
"500:UDP"= 500:UDP:*:Enabled:IPsec (IKE)
"135:TCP"= 135:TCP:*:Enabled:RPC Endpoint Mapper and DCOM infrastructure
"139:TCP"= 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"5353:TCP"= 5353:TCP:*:Enabled:Adobe CSI CS4
"3703:TCP"= 3703:TCP:*:Enabled:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:*:Enabled:Adobe Version Cue CS4 Server

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
"%windir%\\Network Diagnostic\\xpnetdiag.exe"= %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"= c:\program files\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"= c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"= c:\program files\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= c:\program files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"= c:\program files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
"c:\\Program Files\\iTunes\\iTunes.exe"= c:\program files\iTunes\iTunes.exe:*:Enabled:iTunes
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= c:\program files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"= c:\program files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary

R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\drivers\AlfaFF.sys [22/10/2008 1:39 PM 43184]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [24/07/2007 7:59 AM 38816]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [24/10/2008 11:38 AM 110848]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [24/10/2008 11:38 AM 38528]
R2 FPSensor;LTT-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\drivers\FPSensor.sys [22/10/2008 1:39 PM 20352]
R2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [22/10/2008 1:39 PM 3481600]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [8/05/2009 1:12 AM 80936]
R2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [20/11/2008 2:32 PM 98304]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [24/07/2007 7:59 AM 41216]
R3 ITEIRDA;ITE Infrared Device Driver;c:\windows\system32\drivers\ITEirda.sys [22/10/2008 1:59 PM 24576]
S2 gupdate1ca04639e7fec1c;Google Update Service (gupdate1ca04639e7fec1c);c:\program files\Google\Update\GoogleUpdate.exe [14/07/2009 7:15 PM 133104]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15/08/2008 4:46 AM 284016]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [20/11/2008 2:32 PM 14976]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter
DcomLaunch REG_MULTI_SZ DcomLaunch TermService
eapsvcs REG_MULTI_SZ eaphost
dot3svc REG_MULTI_SZ dot3svc
WudfServiceGroup REG_MULTI_SZ WUDFSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
Alerter
LmHosts

.
Contents of the 'Scheduled Tasks' folder

2009-07-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]

2009-08-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-14 09:12]

2009-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-14 09:15]

2009-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-14 09:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://intranet.cgs.vic.edu.au
uInternet Settings,ProxyOverride = local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\12linnz\Application Data\Mozilla\Firefox\Profiles\to5o5mwc.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 9666
FF - prefs.js: network.proxy.socks - localhost
FF - prefs.js: network.proxy.socks_port - 9050
FF - prefs.js: network.proxy.ssl - localhost
FF - prefs.js: network.proxy.ssl_port - 9666
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-01 19:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10.exe,-101"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10.exe"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{8D8763AB-E93B-4812-964E-F04E0008FD50}\Version]
@Denied: (A) (Everyone)

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlDbg10.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlDbg10.ocx, 1"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlDbg10.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlDbg10.ocx, 1"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""

[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1100)
c:\program files\Acer\Acer Bio Protection\CompPtc.dll
c:\program files\Acer\Acer Bio Protection\CustomRes.dll
c:\windows\system32\NBMatS1SDK.DLL
c:\program files\Acer\Acer Bio Protection\WinNotify.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'lsass.exe'(1156)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(2416)
c:\windows\system32\btmmhook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\IfxPsdSv.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Sophos\Remote Management System\ManagementAgentNT.exe
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\Sophos\Remote Management System\RouterNT.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Infineon\Security Platform Software\PSDrt.exe
c:\program files\Infineon\Security Platform Software\SpTNA.exe
c:\windows\system32\igfxext.exe
c:\docume~1\12linnz\LOCALS~1\Temp\RtkBtMnt.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\iTunes\iTunes.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\SyncServer.exe
.
**************************************************************************
.
Completion time: 2009-08-01 19:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-01 09:19
ComboFix2.txt 2009-07-31 07:27

Pre-Run: 76,734,189,568 bytes free
Post-Run: 76,718,653,440 bytes free

669 — E O F — 2009-07-16 00:22



I copied the files from my laptop onto my home computer because my internet does not work.
There seems to be many, many errors (more than before).
If you suggest re-imaging my computer is the easiest way, just let me know and I'll get it done on Monday.
These errors are becoming increasingly frustrating. When I try to connect to the internet, it says something about plug-and-play. Using an ethernet cable doesn't work either.
I've attempted to system restore to the point which ComboFix made. It's taking a very long time, though. I've been waiting over 30 minutes for it to shut down.
Hi lin0056 I wish you wouldn't have used system restore. Did you try connecting with a different browser? Did you try Firefox in it's safe mode? Click Start>All Programs>Mozilla FireFox> Mozilla FireFox(safe mode) What is the exact error message you recieve? Thanks
It's not my browser. I can't get on it at the moment but my wireless connection always says make sure your adapter is installed correctly. Also, I waited all night and it didn't shut down. It was stuck on saving your settings.
Hi lin0056,

I'm not sure how much the System Restore will effect us, but turn off your computer. Hold the On button in untill the computer shuts down.

Restart your computer. After Windows has loaded
  • Click the start button
  • Right click Mycomputer
  • click Properties
  • Click the Hardware tab
  • click Device Manager
Anything with a yellow exclamation mark?

Any errors during boot up?
Nothing with yellow exclamation marks. I get all the same errors as before as well as some new ones. There is a generic win32 errorwhich needs to close. I'm leaning towards reinaging my computer but I know I will get a virus because my school's ghost image backup has a virus on it. Any suggestions to get my Internet back? I also can't turn off my computer off during a regular shutdown or restart

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI