I only have 1 USB drive.
It is 8GB FAT.
USB's are usually at drive E.
OTL Extras logfile created on: 31/07/2009 3:06:27 PM - Run 1
OTL by OldTimer - Version 3.0.10.3 Folder = C:\Documents and Settings\12linnz\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1.93 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 73.42% Memory free
3.78 Gb Paging File | 3.42 Gb Available in Paging File | 90.44% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 71.53 Gb Free Space | 47.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: 12LINNZ
Current User Name: 12LinNZ
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\System32\drivers\etc\networks.exe File not found
.wsh [@ = wshtfile] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"4500:UDP" = 4500:UDP:*:Enabled:IPsec (IKE NAT-T)
"500:UDP" = 500:UDP:*:Enabled:IPsec (IKE)
"135:TCP" = 135:TCP:*:Enabled:RPC Endpoint Mapper and DCOM infrastructure
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS4 Server
"3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51000:TCP" = 51000:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51001:TCP" = 51001:TCP:*:Enabled:Adobe Version Cue CS4 Server
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Disabled:Studio program file – (Pinnacle Systems)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" = C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:*:Enabled:Adobe Version Cue CS4 Server – (Adobe Systems Incorporated)
"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" = C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe:*:Enabled:Visual Studio Remote Debugging Monitor – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi – (Pinnacle Systems)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{034759DA-E21A-4795-BFB3-C66D17FAD183}" = Sophos Anti-Virus
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1461AA33-AB75-4E27-A832-CA0328AD7FAA}" = LEGO MINDSTORMS Edu NXT - English Language Pack
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 13
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{32C7D34A-4ADF-46F1-9E75-A3E446A76D10}" = LEGO MINDSTORMS Edu NXT Software v1.1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Acer Crystal Eye webcam
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{4511EB07-EE29-4BF1-9B90-CE40F12B16CD}" = ClickView Player
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4731AE86-B72B-4589-A152-E67F536B6B0A}" = Crocodile Physics 1.51
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{5EB90C06-964F-4195-B83E-BD7E55C88415}" = Pinnacle Video Driver
"{607398CF-354B-4E21-B1BC-549424BFD04C}" = TIPCI
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{729D7318-FF65-4E8C-B32B-DA2AFA76F591}" = ITEFIR
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{87B36E04-476A-44AD-A971-0BE951995954}" = Crocodile Chemistry 1.5
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99B66D96-5BB2-42DF-BF7C-432285A1E5A5}" = LEGO MINDSTORMS NXT Driver
"{A128921B-D03F-4BFB-8141-C365AA48D660}" = Adobe Setup
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2881E09-38DB-4F79-9135-00FDA01768A7}" = Adobe Creative Suite 4 Design Premium
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_912" = Adobe Acrobat 9.1.2 - CPSID_49166
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B6537896-A156-4015-BD5C-7A80C85C78AB}" = activBook Reader
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{D041EB9E-890A-4098-8F94-51DA194AC72A}" = Pinnacle Studio 12
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.59.528
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E9AF380B-40FA-4D83-A5C7-A80D9BB8E566}" = LEGO MINDSTORMS NXT Edu Migration Package
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F73D65D9-5319-4F48-AD21-BD5BB8C9135B}" = Infineon TPM Professional Package
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF11005D-CBC8-45D5-A288-25C7BB304121}" = Sophos Remote Management System
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acer Acer Bio Protection 6.0.00.17" = Acer Bio Protection
ATL 6.0.00.17
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_55230b0b70661df0f212e88f0b655f7" = Adobe Creative Suite 4 Design Premium
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18
"CrystalReports7" = Seagate Crystal Reports for ESRI
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"InstallShield_{607398CF-354B-4E21-B1BC-549424BFD04C}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"LManager" = Launch Manager
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.1)" = Mozilla Firefox (3.5.1)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PaperCut NG Client_is1" = PaperCut NG Client 6.3
"PowerISO" = PowerISO
"PROPLUS" = Microsoft Office Professional Plus 2007
"StarLogo TNG" = StarLogo TNG
"Starry Night EDU" = Starry Night EDU
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 25/07/2009 4:27:12 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
Error - 25/07/2009 4:33:03 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
Error - 25/07/2009 4:38:55 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
Error - 25/07/2009 4:44:46 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
Error - 25/07/2009 4:50:37 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
Error - 25/07/2009 4:56:29 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
Error - 25/07/2009 5:02:20 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
Error - 25/07/2009 5:08:11 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
Error - 25/07/2009 5:14:03 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
Error - 25/07/2009 5:19:53 AM | Computer Name = 12LINNZ | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: cgsnt1,cgsnt1.cgs.vic.edu.au.%3
[ System Events ]
Error - 24/07/2009 6:30:06 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 24/07/2009 7:22:49 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 24/07/2009 7:22:51 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 24/07/2009 7:37:53 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.
Error - 24/07/2009 8:07:54 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.
Error - 24/07/2009 9:07:54 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 119 minutes. NtpClient has no source of accurate
time.
Error - 24/07/2009 11:07:54 PM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 239 minutes. NtpClient has no source of accurate
time.
Error - 24/07/2009 11:30:36 PM | Computer Name = 12LINNZ | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CGS due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
Error - 25/07/2009 3:07:52 AM | Computer Name = 12LINNZ | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 479 minutes. NtpClient has no source of accurate
time.
Error - 25/07/2009 8:34:15 AM | Computer Name = 12LINNZ | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CGS due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
< End of report >
OTL logfile created on: 31/07/2009 3:06:27 PM - Run 1
OTL by OldTimer - Version 3.0.10.3 Folder = C:\Documents and Settings\12linnz\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1.93 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 73.42% Memory free
3.78 Gb Paging File | 3.42 Gb Available in Paging File | 90.44% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 71.53 Gb Free Space | 47.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: 12LINNZ
Current User Name: 12LinNZ
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\svchost.exe ( )
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\ifxspmgt.exe (Infineon Technologies AG)
PRC - C:\WINDOWS\System32\IFXTCS.exe (Infineon Technologies AG)
PRC - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\IfxPsdSv.exe (Infineon Technologies AG)
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc)
PRC - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe (Sophos Plc)
PRC - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc)
PRC - C:\Program Files\Sophos\Remote Management System\RouterNT.exe (Sophos Plc)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\12LINNZ.exe ( )
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe (Arachnoid Biometrics Identification Group Corp.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\PLFSetI.exe ()
PRC - C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\Infineon\Security Platform Software\PSDrt.exe (Infineon Technologies AG)
PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Infineon\Security Platform Software\SpTna.exe (Infineon Technologies AG)
PRC - C:\WINDOWS\System32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Documents and Settings\12linnz\Local Settings\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\12linnz\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
SRV - (Adobe Version Cue CS4 [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (btwdins [Auto | Running]) – C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1ca04639e7fec1c [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IFXSpMgtSrv [Auto | Running]) – C:\WINDOWS\System32\ifxspmgt.exe (Infineon Technologies AG)
SRV - (IFXTCS [Auto | Running]) – C:\WINDOWS\System32\IFXTCS.exe (Infineon Technologies AG)
SRV - (IGBASVC [Auto | Running]) – C:\Program Files\Acer\Acer Bio Protection\BASVC.exe ()
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Irmon [Auto | Running]) – C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PersonalSecureDriveService [Auto | Running]) – C:\WINDOWS\System32\IfxPsdSv.exe (Infineon Technologies AG)
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SAVAdminService [Unknown | Running]) – C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc)
SRV - (SAVService [Unknown | Running]) – C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc)
SRV - (Sophos Agent [Auto | Running]) – C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe (Sophos Plc)
SRV - (Sophos AutoUpdate Service [Auto | Running]) – C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc)
SRV - (Sophos Message Router [Auto | Running]) – C:\Program Files\Sophos\Remote Management System\RouterNT.exe (Sophos Plc)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (adfs [Auto | Running]) – C:\WINDOWS\System32\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (AlfaFF [Boot | Running]) – C:\WINDOWS\system32\Drivers\AlfaFF.sys (Alfa Corporation)
DRV - (b57w2k [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (btaudio [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTDriver [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWDNDIS [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\btwhid.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (DKbFltr [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\DKbFltr.sys (Dritek System Inc.)
DRV - (DritekPortIO [System | Running]) – C:\Program Files\Launch Manager\DPortIO.sys (Dritek System Inc.)
DRV - (FPSensor [Auto | Running]) – C:\WINDOWS\System32\Drivers\FPSensor.sys (LTT)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\igxpmp32.sys (Intel Corporation)
DRV - (IFXTPM [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\IFXTPM.SYS (Infineon Technologies AG)
DRV - (Int15 [Auto | Running]) – C:\WINDOWS\System32\drivers\int15.sys ()
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\System32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ITEIRDA [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ITEirda.sys (ITE Tech. Inc.)
DRV - (MarvinBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NETw5x32 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\NETw5x32.sys (Intel Corporation)
DRV - (NTIDrvr [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (PersonalSecureDrive [System | Running]) – C:\WINDOWS\System32\drivers\psd.sys (Infineon Technologies AG)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (SAVOnAccessControl [System | Running]) – C:\WINDOWS\System32\DRIVERS\savonaccesscontrol.sys (Sophos Plc)
DRV - (SAVOnAccessFilter [System | Running]) – C:\WINDOWS\System32\DRIVERS\savonaccessfilter.sys (Sophos Plc)
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SNP2UVC [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\snp2uvc.sys ()
DRV - (SophosBootDriver [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\SophosBootDriver.sys (Sophos Plc)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (tifm21 [On_Demand | Running]) – C:\WINDOWS\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (UBHelper [Boot | Running]) – C:\WINDOWS\System32\drivers\UBHelper.sys ()
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - ({95808DC4-FA4A-4c74-92FE-5B863F82066B} [Auto | Running]) – C:\Program Files\CyberLink\PowerDVD\000.fcl (Cyberlink Corp.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://intranet.cgs.vic.edu.au
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.85
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {5B52016C-D097-4aec-BE61-9F129D8FDDBA}:2.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.1
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.gopher: ""
FF - prefs.js..network.proxy.backup.gopher_port: 0
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: 0
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: 0
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 9666
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.socks: "localhost"
FF - prefs.js..network.proxy.socks_port: 9050
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 9666
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/11/05 10:35:48 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2007/12/20 01:48:36 | 00,081,920 | RHS- | M] ( )
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/17 23:12:11 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/07/26 19:15:29 | 00,000,000 | —D | M]
[2009/07/14 16:52:58 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Extensions
[2009/07/14 16:52:58 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/30 01:08:36 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Firefox\Profiles\to5o5mwc.default\extensions
[2009/07/15 21:47:08 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Firefox\Profiles\to5o5mwc.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2009/07/22 20:39:53 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\mozilla\Firefox\Profiles\to5o5mwc.default\extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}
[2009/07/14 16:52:16 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/07/17 23:12:11 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/17 23:12:06 | 00,023,544 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/07/17 23:12:06 | 00,137,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/17 23:12:07 | 00,065,016 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/10/14 21:33:30 | 00,095,600 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/07/14 18:14:05 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/06/24 21:27:00 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/06/24 21:27:00 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/24 21:27:00 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/06/24 21:27:00 | 00,002,344 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/06/24 21:27:00 | 00,002,371 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/06/24 21:27:00 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/06/24 21:27:00 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [12LINNZ] C:\WINDOWS\win.pif ( )
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IFXSPMGT] C:\WINDOWS\System32\ifxspmgt.exe (Infineon Technologies AG)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager File not found
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\WINDOWS\PLFSetI.exe ()
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [ZPdtWzdVitaKey MC3000] C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe (Arachnoid Biometrics Identification Group Corp.)
O4 - HKCU..\Run: [12linnz] C:\Documents and Settings\12linnz\Local Settings\Temp\Tmp.com ( )
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
F3 - HKCU WinNT: Load - (C:\DOCUME~1\12linnz\LOCALS~1\services.exe) - C:\Documents and Settings\12linnz\Local Settings\services File not found
F3 - HKCU WinNT: Run - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
F3 - HKCU WinNT: Run - (C:\WINDOWS\System\regedit.exe) - C:\WINDOWS\System\regedit.exe ( )
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL File not found
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra 'Tools' menuitem : Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: edu.au ([intranet.cgs.vic] http in Local intranet)
O15 - HKLM\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: edu.au ([intranet.cgs.vic] http in Local intranet)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = cgs.vic.edu.au
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: System - (C:\WINDOWS\svchost.exe) - C:\WINDOWS\svchost.exe ( )
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\smss.exe) - C:\WINDOWS\smss.exe ( )
O20 - HKLM Winlogon: GinaDLL - (C:\Program) - File not found
O20 - HKLM Winlogon: GinaDLL - (Files\Acer\Acer) - File not found
O20 - HKLM Winlogon: GinaDLL - (Bio) - File not found
O20 - HKLM Winlogon: GinaDLL - (Protection\CompPtc.dll) - File not found
O20 - HKCU Winlogon: Shell - (C:\DOCUME~1\12linnz\LOCALS~1\explorer.exe) - C:\Documents and Settings\12linnz\Local Settings\explorer File not found
O20 - HKCU Winlogon: System - (C:\WINDOWS\System\wininit.com) - C:\WINDOWS\System\wininit.com ( )
O20 - Winlogon\Notify\AWinNotifyVitaKey MC3000: DllName - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - C:\WINDOWS\system32\command.cmd
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/20 11:33:41 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/12/20 01:48:36 | 00,081,920 | -HS- | M] ( ) - C:\AutoRun.exe – [ NTFS ]
O32 - AutoRun File - [2009/07/26 19:06:35 | 00,000,099 | -HS- | M] () - C:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\Shell - "" = Autorun
O33 - MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\Shell\Auto\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{313bf5ad-710e-11de-ad48-00a0d1ad1f81}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\Shell - "" = Autorun
O33 - MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\Shell\Auto\command - "" = C:\AutoRun.exe – [2007/12/20 01:48:36 | 00,081,920 | -HS- | M] ( )
O33 - MountPoints2\{57a0d8d6-7030-11de-ad3d-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\Shell\AutoRun\command - "" = E:\SysWin32.exe – File not found
O33 - MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\Shell\explorer\command - "" = E:\SysWin32.exe – File not found
O33 - MountPoints2\{92731639-74ba-11de-ad51-00a0d1ad1f81}\Shell\open\command - "" = E:\SysWin32.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (pgdfgsvc) - C:\WINDOWS\System32\pgdfgsvc.exe (Sysinternals - www.sysinternals.com)
O34 - HKLM BootExecute: © - File not found
O34 - HKLM BootExecute: (1) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[2009/07/31 15:04:27 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\12linnz\Desktop\OTL.exe
[2009/07/30 23:13:52 | 00,001,734 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\HijackThis.lnk
[2009/07/28 11:11:34 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\winlogon.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\SYSTEM.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\svchost.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\smss.exe
[2009/07/27 13:27:54 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\services.exe
[2009/07/26 19:06:35 | 00,000,099 | -HS- | C] () – C:\autorun.inf
[2009/07/26 19:06:20 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System32\command.cmd
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\win.pif
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System32\msdp32.dll
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System32\12LINNZ.exe
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System\wininit.com
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\System\regedit.exe
[2009/07/26 19:06:19 | 00,081,920 | RHS- | C] ( ) – C:\WINDOWS\12LinNZ.exe
[2009/07/26 19:06:19 | 00,081,920 | -HS- | C] ( ) – C:\AutoRun.exe
[2009/07/24 13:38:37 | 00,853,787 | —- | C] (Macromedia, Inc.) – C:\Documents and Settings\12linnz\Desktop\Neave Tetris.exe
[2009/07/24 09:47:05 | 00,000,000 | —D | C] – C:\Program Files\Enable Software
[2009/07/24 09:24:26 | 00,000,630 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\µTorrent.lnk
[2009/07/24 09:24:26 | 00,000,000 | —D | C] – C:\Program Files\uTorrent
[2009/07/24 09:24:00 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\uTorrent
[2009/07/22 20:35:19 | 00,466,944 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\u95.exe
[2009/07/17 09:53:42 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\Bluetooth Exchange Folder
[2009/07/16 14:24:53 | 00,017,408 | —- | C] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/16 14:23:53 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\DivX
[2009/07/16 14:20:53 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Google
[2009/07/16 10:21:19 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/07/16 10:20:27 | 00,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2009/07/16 10:18:16 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/07/16 10:18:14 | 00,459,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/07/16 10:18:13 | 00,383,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/07/16 10:18:13 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/07/16 10:18:13 | 00,052,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/07/16 10:18:12 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/07/16 10:18:11 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieudinit.exe
[2009/07/16 10:18:10 | 02,455,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dat
[2009/07/16 10:18:10 | 00,991,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/07/16 10:18:05 | 06,066,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/07/15 18:13:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2009/07/15 16:48:51 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009/07/15 16:43:37 | 00,000,000 | —D | C] – C:\WINDOWS\WBEM
[2009/07/15 16:41:57 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2009/07/15 16:41:47 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
[2009/07/15 16:41:23 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
[2009/07/15 16:11:00 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Microsoft Help
[2009/07/15 15:14:29 | 00,056,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\secur32.dll
[2009/07/15 15:14:28 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kernel32.dll
[2009/07/15 15:14:09 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\schannel.dll
[2009/07/15 15:14:00 | 00,177,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msctfime.ime
[2009/07/15 15:13:25 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/07/15 15:13:25 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/07/15 15:13:25 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/07/15 15:13:24 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/07/15 15:13:24 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/07/15 15:13:24 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/07/15 15:13:23 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/07/15 15:13:23 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/07/15 15:13:23 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/07/15 15:13:15 | 00,345,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\localspl.dll
[2009/07/15 15:13:05 | 00,161,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdtcuiu.dll
[2009/07/15 15:13:05 | 00,091,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mtxoci.dll
[2009/07/15 15:13:05 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mtxclu.dll
[2009/07/15 15:13:04 | 00,956,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdtctm.dll
[2009/07/15 15:13:04 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdtclog.dll
[2009/07/15 15:11:18 | 00,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 9 Pro.lnk
[2009/07/15 15:09:38 | 08,461,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2009/07/15 15:09:17 | 00,585,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2009/07/15 15:09:15 | 00,354,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winhttp.dll
[2009/07/15 15:08:50 | 00,286,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gdi32.dll
[2009/07/15 15:08:23 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/07/15 15:08:22 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/07/15 15:08:21 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/07/15 14:37:37 | 00,000,409 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\Downloads.lnk
[2009/07/15 09:00:37 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Fuji Xerox
[2009/07/14 23:26:44 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Malwarebytes
[2009/07/14 23:26:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/07/14 23:22:49 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/07/14 22:16:08 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/07/14 22:16:08 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/07/14 22:16:08 | 01,614,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/07/14 22:16:08 | 01,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/07/14 22:16:08 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/07/14 22:16:08 | 00,927,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/07/14 22:16:08 | 00,792,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/07/14 22:16:08 | 00,666,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/07/14 22:16:08 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/07/14 22:16:08 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/07/14 22:16:08 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/07/14 22:16:08 | 00,435,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/07/14 22:16:08 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/07/14 22:16:08 | 00,361,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/07/14 22:16:08 | 00,295,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/07/14 22:16:08 | 00,182,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/07/14 22:16:08 | 00,167,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\appmgmts.dll
[2009/07/14 22:16:08 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/07/14 22:16:08 | 00,108,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/07/14 22:16:08 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/07/14 22:16:08 | 00,082,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/07/14 22:16:08 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/07/14 22:16:08 | 00,053,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/07/14 22:16:08 | 00,036,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/07/14 22:16:08 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/07/14 22:16:08 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/07/14 22:16:08 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/07/14 22:16:08 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/07/14 22:16:08 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/07/14 22:16:08 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/07/14 22:16:08 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/07/14 22:16:08 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/07/14 22:16:08 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/07/14 22:16:08 | 00,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/07/14 22:16:08 | 00,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/07/14 22:16:08 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/07/14 22:16:08 | 00,000,000 | —D | C] – C:\WINDOWS\System32\dllcache\cache
[2009/07/14 22:05:56 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/07/14 22:04:43 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/07/14 21:05:49 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\My Received Files
[2009/07/14 21:05:24 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\My Chat Logs
[2009/07/14 20:43:45 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\WinRAR
[2009/07/14 19:23:38 | 00,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/07/14 19:23:38 | 00,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/07/14 19:17:20 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Nexon
[2009/07/14 19:15:58 | 00,001,836 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/07/14 19:15:20 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Google
[2009/07/14 19:15:08 | 00,000,000 | —D | C] – C:\Program Files\WinRAR
[2009/07/14 19:14:39 | 00,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2009/07/14 19:14:39 | 00,000,000 | —D | C] – C:\Program Files\PowerISO
[2009/07/14 19:12:41 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2009/07/14 19:12:40 | 00,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/07/14 19:12:38 | 00,000,000 | —D | C] – C:\Program Files\Google
[2009/07/14 18:40:02 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSWINSCK.OCX
[2009/07/14 18:38:43 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/07/14 18:37:01 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/14 18:15:08 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Apple Computer
[2009/07/14 18:14:58 | 00,001,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/07/14 18:14:55 | 00,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2009/07/14 18:14:55 | 00,023,400 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\drivers\GEARAspiWDM.sys
[2009/07/14 18:14:38 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/07/14 18:14:34 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/07/14 18:14:34 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/07/14 18:14:16 | 00,000,000 | —D | C] – C:\Program Files\Bonjour
[2009/07/14 18:13:57 | 00,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/07/14 18:13:38 | 00,000,000 | —D | C] – C:\Program Files\QuickTime
[2009/07/14 18:13:34 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/07/14 18:13:21 | 00,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/07/14 18:13:21 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Apple
[2009/07/14 18:13:18 | 00,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2009/07/14 18:13:08 | 02,060,288 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2009/07/14 18:13:08 | 00,039,424 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\drivers\usbaapl.sys
[2009/07/14 18:12:28 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2009/07/14 18:12:27 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/07/14 18:11:56 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Apple Computer
[2009/07/14 18:11:06 | 00,000,000 | —D | C] – C:\Program Files\Combined Community Codec Pack
[2009/07/14 18:10:52 | 00,000,000 | —D | C] – C:\Program Files\Messenger Plus! Live
[2009/07/14 18:07:59 | 00,000,000 | R–D | C] – C:\Documents and Settings\12linnz\My Documents\My Videos
[2009/07/14 18:04:32 | 00,000,419 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\School Work.lnk
[2009/07/14 17:57:38 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Sophos
[2009/07/14 17:54:42 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/07/14 17:53:53 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/07/14 17:53:40 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/07/14 17:53:33 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/07/14 17:53:06 | 00,000,000 | —D | C] – C:\Program Files\Windows Live
[2009/07/14 17:49:20 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/07/14 17:48:58 | 00,105,544 | —- | C] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/07/14 17:48:54 | 00,001,548 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\CCleaner.lnk
[2009/07/14 17:48:52 | 00,000,000 | —D | C] – C:\Program Files\CCleaner
[2009/07/14 17:47:33 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\Downloads
[2009/07/14 17:01:11 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\FIFAOnline2
[2009/07/14 16:54:23 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Macromedia
[2009/07/14 16:52:39 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/07/14 16:52:32 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Mozilla
[2009/07/14 16:52:31 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Mozilla
[2009/07/14 16:52:18 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/07/14 16:52:14 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/07/14 16:47:55 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/14 16:47:55 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/14 16:47:55 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/14 16:47:19 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\My Documents\School Work
[2009/07/14 16:46:42 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Sun
[2009/07/14 16:41:01 | 00,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidusb.sys
[2009/07/14 16:41:01 | 00,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2009/07/14 15:52:39 | 02,117,596 | -H– | C] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\IconCache.db
[2009/07/14 15:52:08 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Adobe
[2009/07/14 15:51:36 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Adobe
[2009/07/14 15:51:27 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Infineon
[2009/07/14 15:50:51 | 00,000,782 | —- | C] () – C:\Documents and Settings\12linnz\Desktop\Windows Media Player.lnk
[2009/07/14 15:50:46 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Application Data\Identities
[2009/07/14 15:50:42 | 00,000,000 | R–D | C] – C:\Documents and Settings\12linnz\My Documents\My Pictures
[2009/07/14 15:50:42 | 00,000,000 | R–D | C] – C:\Documents and Settings\12linnz\My Documents\My Music
[2009/07/14 15:50:21 | 00,000,000 | –SD | C] – C:\Documents and Settings\12linnz\Application Data\Microsoft
[2009/07/14 15:50:21 | 00,000,000 | —D | C] – C:\Documents and Settings\12linnz\Local Settings\Application Data\Microsoft
[2009/07/14 14:43:25 | 00,004,444 | —- | C] () – C:\WINDOWS\System32\pid.PNF
[2009/07/14 12:09:40 | 07,366,144 | —- | C] () – C:\Documents and Settings\12linnz\My Documents\FO2 Database 2009March15.xls
[2009/07/14 12:09:40 | 01,655,808 | —- | C] () – C:\Documents and Settings\12linnz\My Documents\LP Calculator - FlyHigh.xls
[2008/11/24 11:13:30 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/11/20 14:38:49 | 00,000,020 | —- | C] () – C:\WINDOWS\CrocPhys.INI
[2008/11/20 14:38:17 | 00,000,072 | —- | C] () – C:\WINDOWS\CrocChem.INI
[2008/11/20 11:15:57 | 00,013,952 | —- | C] () – C:\WINDOWS\System32\drivers\UBHelper.sys
[2008/11/20 11:15:03 | 00,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMPEG2.dll
[2008/11/20 11:15:03 | 00,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMP3.dll
[2008/11/20 11:15:03 | 00,001,024 | RH– | C] () – C:\WINDOWS\System32\NTICDMK7.dll
[2008/11/05 09:12:45 | 00,000,021 | —- | C] () – C:\WINDOWS\crocclip.ini
[2008/10/24 11:53:32 | 00,000,154 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/10/24 11:50:32 | 00,018,944 | —- | C] ( ) – C:\WINDOWS\System32\IMPLODE.DLL
[2008/10/24 11:50:30 | 00,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2008/10/22 14:06:13 | 00,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4953.dll
[2008/10/22 14:03:33 | 01,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2008/10/22 14:03:33 | 00,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[2008/10/22 14:03:33 | 00,028,032 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2008/10/22 14:03:27 | 00,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2008/10/22 14:02:59 | 00,000,055 | —- | C] () – C:\WINDOWS\PidList.ini
[2008/10/22 13:39:57 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\VMC3KAPI.dll
[2008/04/01 07:25:46 | 00,831,488 | —- | C] () – C:\WINDOWS\System32\divx_xx0a.dll
[2008/03/22 06:30:08 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/03/22 06:28:54 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/03/22 06:28:54 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/03/22 06:28:20 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/09/11 12:24:28 | 02,842,624 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2007/09/11 12:12:28 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2007/01/26 16:32:18 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\drivers\int15.sys
[2007/01/26 01:04:12 | 00,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2007/01/26 01:04:12 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2006/02/28 22:00:00 | 00,000,582 | —- | C] () – C:\WINDOWS\win.ini
[2006/02/28 22:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2005/02/17 12:41:32 | 00,000,603 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 12:41:30 | 00,000,593 | —- | C] () – C:\WINDOWS\System32\btcss.dll.manifest
[2003/07/21 07:42:22 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\abZlib.dll
[2001/12/26 14:12:30 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\multiplex_vcd.dll
[2001/11/14 13:56:00 | 01,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/09/03 21:46:38 | 00,110,592 | —- | C] () – C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 14:33:56 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 20:04:36 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1998/12/15 03:00:00 | 00,021,986 | —- | C] () – C:\WINDOWS\crwd32.ini
[1996/06/08 05:07:14 | 00,043,008 | —- | C] () – C:\WINDOWS\System32\ltfil60n.dll
[1996/06/08 05:07:14 | 00,019,456 | —- | C] () – C:\WINDOWS\System32\lfwpg60n.dll
[1996/06/08 05:07:12 | 00,046,080 | —- | C] () – C:\WINDOWS\System32\lftif60n.dll
[1996/06/08 05:07:12 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\lftga60n.dll
[1996/06/08 05:07:12 | 00,019,456 | —- | C] () – C:\WINDOWS\System32\lfwmf60n.dll
[1996/06/08 05:07:10 | 00,110,080 | —- | C] () – C:\WINDOWS\System32\lfpng60n.dll
[1996/06/08 05:07:10 | 00,023,552 | —- | C] () – C:\WINDOWS\System32\lfpcx60n.dll
[1996/06/08 05:07:10 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\lfpsd60n.dll
[1996/06/08 05:07:08 | 00,022,528 | —- | C] () – C:\WINDOWS\System32\lfpct60n.dll
[1996/06/08 05:07:08 | 00,018,432 | —- | C] () – C:\WINDOWS\System32\lfmsp60n.dll
[1996/06/08 05:07:08 | 00,017,920 | —- | C] () – C:\WINDOWS\System32\lfmac60n.dll
[1996/06/08 05:07:06 | 00,176,128 | —- | C] () – C:\WINDOWS\System32\lffax60n.dll
[1996/06/08 05:07:04 | 00,141,824 | —- | C] () – C:\WINDOWS\System32\lfcmp60n.dll
[1996/06/08 05:07:04 | 00,022,528 | —- | C] () – C:\WINDOWS\System32\lfeps60n.dll
[1996/06/08 05:07:04 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\lfbmp60n.dll
========== Files - Modified Within 30 Days ==========
[2009/07/31 15:04:33 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\12linnz\Desktop\OTL.exe
[2009/07/31 14:53:48 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/07/31 14:53:47 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/07/31 14:53:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/31 14:53:13 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/31 13:28:01 | 00,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/07/31 01:40:09 | 02,117,596 | -H– | M] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\IconCache.db
[2009/07/30 23:13:52 | 00,001,734 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\HijackThis.lnk
[2009/07/28 23:54:24 | 00,017,408 | —- | M] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/26 19:06:35 | 00,000,099 | -HS- | M] () – C:\autorun.inf
[2009/07/26 15:44:17 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/07/25 19:17:56 | 00,001,514 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Backup.lnk
[2009/07/24 09:24:26 | 00,000,630 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\µTorrent.lnk
[2009/07/23 10:15:34 | 00,000,712 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
[2009/07/16 20:21:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/07/16 10:21:57 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/15 18:13:44 | 00,105,544 | —- | M] () – C:\Documents and Settings\12linnz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/07/15 17:11:33 | 00,525,272 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/15 17:11:33 | 00,444,798 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/15 17:11:33 | 00,072,698 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/15 17:07:07 | 02,223,656 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/15 16:34:39 | 00,000,582 | —- | M] () – C:\WINDOWS\win.ini
[2009/07/15 15:11:18 | 00,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 9 Pro.lnk
[2009/07/15 14:37:37 | 00,000,409 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\Downloads.lnk
[2009/07/14 23:16:57 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/07/14 23:15:37 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.msn
[2009/07/14 23:15:37 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/07/14 22:06:01 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/07/14 19:15:58 | 00,001,836 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/07/14 19:14:39 | 00,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2009/07/14 18:40:03 | 00,057,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MSWINSCK.OCX
[2009/07/14 18:14:58 | 00,001,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/07/14 18:13:57 | 00,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/07/14 18:07:56 | 00,000,782 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\Windows Media Player.lnk
[2009/07/14 18:04:32 | 00,000,419 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\School Work.lnk
[2009/07/14 17:48:54 | 00,001,548 | —- | M] () – C:\Documents and Settings\12linnz\Desktop\CCleaner.lnk
[2009/07/14 16:52:39 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/07/14 16:52:18 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/07/14 14:44:25 | 00,000,624 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2009/07/14 14:43:25 | 00,004,444 | —- | M] () – C:\WINDOWS\System32\pid.PNF
========== LOP Check ==========
[2009/07/24 09:24:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\12linnz\Application Data
[2009/07/14 15:51:27 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\Infineon
[2009/07/14 19:17:20 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\Nexon
[2009/07/24 09:26:54 | 00,000,000 | —D | M] – C:\Documents and Settings\12linnz\Application Data\uTorrent
[2009/07/15 18:13:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/07/14 18:14:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/20 14:16:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\abReader_Desktop
[2008/11/21 11:19:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ALM
[2008/11/20 11:19:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/11/21 15:09:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/10/22 13:55:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Infineon
[2009/07/15 18:13:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2008/11/05 14:18:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\National Instruments
[2008/11/20 10:55:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/11/20 10:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Plus
[2008/11/20 13:43:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Ultimate
[2008/10/24 11:43:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sophos
[2008/11/20 10:55:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Studio 12
[2009/07/16 20:21:01 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2006/02/28 22:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/31 14:53:48 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/07/31 14:53:47 | 00,000,882 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/07/31 13:28:01 | 00,000,886 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009/07/31 14:53:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
< End of report >