Righto here goes, I ran the scan and it created 2 files the OTlistit log and an extra log. I am only going to paste the normal log, if you require the extra one too let me know
OTListIt logfile created on: 31/01/2009 22:03:08 - Run
OTListIt2 by OldTimer - Version 1.0.4.1 Folder = F:\Users\Peter\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): c:\pagefile.sys 2500 16000;e:\pagefile.sys 0 0;f:\pagefile.sys 5000 10000;
%SystemDrive% = F: | %SystemRoot% = F:\Windows | %ProgramFiles% = F:\Program Files
Drive C: | 186.28 Gb Total Space | 27.42 Gb Free Space | 14.72% Space Free | Partition Type: NTFS
Drive D: | 480.69 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 24.41 Gb Total Space | 5.39 Gb Free Space | 22.06% Space Free | Partition Type: NTFS
Drive F: | 208.46 Gb Total Space | 52.31 Gb Free Space | 25.09% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
Drive H: | 3.79 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive I: | 957.94 Mb Total Space | 542.89 Mb Free Space | 56.67% Space Free | Partition Type: FAT
Computer Name: PETE
Current User Name: Peter
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
F:\Windows\System32\wininit.exe (Microsoft Corporation)
F:\Windows\System32\lsm.exe (Microsoft Corporation)
F:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
F:\Windows\System32\SLsvc.exe (Microsoft Corporation)
F:\Windows\System32\rundll32.exe (Microsoft Corporation)
F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
F:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
F:\Windows\System32\dwm.exe (Microsoft Corporation)
F:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
F:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
F:\Windows\System32\rundll32.exe (Microsoft Corporation)
F:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
F:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
F:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe ()
F:\Windows\System32\taskeng.exe (Microsoft Corporation)
F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
F:\Windows\System32\PnkBstrA.exe ()
F:\Windows\System32\SearchIndexer.exe (Microsoft Corporation)
F:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
F:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
F:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
F:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
F:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe (Sun Microsystems, Inc.)
F:\Windows\System32\WUDFHost.exe (Microsoft Corporation)
F:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
F:\Users\Peter\Desktop\OTListIt2.exe (OldTimer Tools)
========== (O23) Win32 Services (SafeList) ==========
(AeLookupSvc [Auto | Running]) -- F:\Windows\System32\aelupsvc.dll (Microsoft Corporation)
(Appinfo [On_Demand | Stopped]) -- F:\Windows\System32\appinfo.dll (Microsoft Corporation)
(Apple Mobile Device [Auto | Running]) -- F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
(aswUpdSv [Auto | Running]) -- F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
(avast! Antivirus [Auto | Running]) -- F:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
(avast! Mail Scanner [On_Demand | Running]) -- F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
(avast! Web Scanner [On_Demand | Running]) -- F:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
(BFE [Auto | Running]) -- F:\Windows\System32\BFE.DLL (Microsoft Corporation)
(Bonjour Service [Auto | Running]) -- F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
(CertPropSvc [Unknown | Stopped]) -- F:\Windows\System32\certprop.dll (Microsoft Corporation)
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- F:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
(DFSR [On_Demand | Stopped]) -- F:\Windows\System32\dfsr.exe (Microsoft Corporation)
(DPS [Unknown | Running]) -- F:\Windows\System32\dps.dll (Microsoft Corporation)
(ehRecvr [On_Demand | Stopped]) -- F:\Windows\ehome\ehrecvr.exe (Microsoft Corporation)
(ehSched [On_Demand | Stopped]) -- F:\Windows\ehome\ehsched.exe (Microsoft Corporation)
(ehstart [Auto | Stopped]) -- F:\Windows\ehome\ehstart.dll (Microsoft Corporation)
(EMDMgmt [Auto | Running]) -- F:\Windows\System32\emdmgmt.dll (Microsoft Corporation)
(fdPHost [On_Demand | Running]) -- F:\Windows\System32\fdPHost.dll (Microsoft Corporation)
(FDResPub [Auto | Running]) -- F:\Windows\System32\FDResPub.dll (Microsoft Corporation)
(FontCache3.0.0.0 [On_Demand | Stopped]) -- F:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
(gpsvc [Unknown | Running]) -- F:\Windows\System32\gpsvc.dll (Microsoft Corporation)
(idsvc [Unknown | Stopped]) -- F:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
(IKEEXT [Auto | Running]) -- F:\Windows\System32\IKEEXT.DLL (Microsoft Corporation)
(IPBusEnum [On_Demand | Stopped]) -- F:\Windows\System32\IPBusEnum.dll (Microsoft Corporation)
(iphlpsvc [Auto | Running]) -- F:\Windows\System32\iphlpsvc.dll (Microsoft Corporation)
(iPod Service [On_Demand | Running]) -- F:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
(KtmRm [Auto | Running]) -- F:\Windows\System32\msdtckrm.dll (Microsoft Corporation)
(lltdsvc [On_Demand | Stopped]) -- F:\Windows\System32\lltdsvc.dll (Microsoft Corporation)
(Mcx2Svc [Disabled | Stopped]) -- F:\Windows\System32\Mcx2Svc.dll (Microsoft Corporation)
(MMCSS [Auto | Running]) -- F:\Windows\System32\mmcss.dll (Microsoft Corporation)
(MpsSvc [Auto | Running]) -- F:\Windows\System32\MPSSVC.dll (Microsoft Corporation)
(MSiSCSI [On_Demand | Stopped]) -- F:\Windows\System32\iscsiexe.dll (Microsoft Corporation)
(netprofm [Auto | Running]) -- F:\Windows\System32\netprofm.dll (Microsoft Corporation)
(NetTcpPortSharing [Disabled | Stopped]) -- F:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
(NlaSvc [Auto | Running]) -- F:\Windows\System32\nlasvc.dll (Microsoft Corporation)
(nsi [Auto | Running]) -- F:\Windows\System32\nsisvc.dll (Microsoft Corporation)
(nvsvc [Auto | Running]) -- F:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
(p2pimsvc [On_Demand | Stopped]) -- F:\Windows\System32\p2psvc.dll (Microsoft Corporation)
(p2psvc [On_Demand | Stopped]) -- F:\Windows\System32\p2psvc.dll (Microsoft Corporation)
(PcaSvc [Auto | Running]) -- F:\Windows\System32\pcasvc.dll (Microsoft Corporation)
(pla [On_Demand | Stopped]) -- F:\Windows\System32\pla.dll (Microsoft Corporation)
(PlugPlay [Auto | Running]) -- F:\Windows\System32\umpnpmgr.dll (Microsoft Corporation)
(PnkBstrA [Auto | Running]) -- F:\Windows\System32\PnkBstrA.exe ()
(PNRPAutoReg [On_Demand | Stopped]) -- F:\Windows\System32\p2psvc.dll (Microsoft Corporation)
(PNRPsvc [On_Demand | Stopped]) -- F:\Windows\System32\p2psvc.dll (Microsoft Corporation)
(PolicyAgent [Auto | Running]) -- F:\Windows\System32\IPSECSVC.DLL (Microsoft Corporation)
(ProfSvc [Auto | Running]) -- F:\Windows\System32\profsvc.dll (Microsoft Corporation)
(QWAVE [On_Demand | Stopped]) -- F:\Windows\System32\qwave.dll (Microsoft Corporation)
(SBSDWSCService [Auto | Running]) -- F:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
(SCardSvr [Unknown | Stopped]) -- F:\Windows\System32\SCardSvr.dll (Microsoft Corporation)
(SCPolicySvc [Unknown | Stopped]) -- F:\Windows\System32\certprop.dll (Microsoft Corporation)
(SDRSVC [On_Demand | Stopped]) -- F:\Windows\System32\sdrsvc.dll (Microsoft Corporation)
(SessionEnv [On_Demand | Stopped]) -- F:\Windows\System32\SessEnv.dll (Microsoft Corporation)
(slsvc [Auto | Running]) -- F:\Windows\System32\SLsvc.exe (Microsoft Corporation)
(SLUINotify [On_Demand | Stopped]) -- F:\Windows\System32\SLUINotify.dll (Microsoft Corporation)
(SNMPTRAP [On_Demand | Stopped]) -- F:\Windows\System32\snmptrap.exe (Microsoft Corporation)
(SstpSvc [On_Demand | Running]) -- F:\Windows\System32\sstpsvc.dll (Microsoft Corporation)
(Steam Client Service [On_Demand | Stopped]) -- F:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
(swprv [On_Demand | Stopped]) -- F:\Windows\System32\swprv.dll (Microsoft Corporation)
(SysMain [Auto | Running]) -- F:\Windows\System32\sysmain.dll (Microsoft Corporation)
(TabletInputService [Auto | Running]) -- F:\Windows\System32\TabSvc.dll (Microsoft Corporation)
(TBS [Auto | Stopped]) -- F:\Windows\System32\tbssvc.dll (Microsoft Corporation)
(THREADORDER [On_Demand | Stopped]) -- F:\Windows\System32\mmcss.dll (Microsoft Corporation)
(TrustedInstaller [Unknown | Stopped]) -- F:\Windows\servicing\TrustedInstaller.exe (Microsoft Corporation)
(UI0Detect [On_Demand | Stopped]) -- F:\Windows\System32\UI0Detect.exe (Microsoft Corporation)
(usnjsvc [On_Demand | Stopped]) -- F:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
(UxSms [Auto | Running]) -- F:\Windows\System32\uxsms.dll (Microsoft Corporation)
(vds [On_Demand | Stopped]) -- F:\Windows\System32\vds.exe (Microsoft Corporation)
(wcncsvc [On_Demand | Running]) -- F:\Windows\System32\wcncsvc.dll (Microsoft Corporation)
(WcsPlugInService [On_Demand | Stopped]) -- F:\Windows\System32\WcsPlugInService.dll (Microsoft Corporation)
(WdiServiceHost [Unknown | Stopped]) -- F:\Windows\System32\wdi.dll (Microsoft Corporation)
(WdiSystemHost [Unknown | Running]) -- F:\Windows\System32\wdi.dll (Microsoft Corporation)
(Wecsvc [On_Demand | Stopped]) -- F:\Windows\System32\wecsvc.dll (Microsoft Corporation)
(wercplsupport [On_Demand | Stopped]) -- F:\Windows\System32\wercplsupport.dll (Microsoft Corporation)
(WerSvc [Auto | Running]) -- F:\Windows\System32\wersvc.dll (Microsoft Corporation)
(WinDefend [Auto | Running]) -- F:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
(WinHttpAutoProxySvc [On_Demand | Stopped]) -- F:\Windows\System32\winhttp.dll (Microsoft Corporation)
(WinRM [On_Demand | Stopped]) -- F:\Windows\System32\WsmSvc.dll (Microsoft Corporation)
(Wlansvc [On_Demand | Stopped]) -- F:\Windows\System32\wlansvc.dll (Microsoft Corporation)
(WLSetupSvc [On_Demand | Stopped]) -- F:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
(WMPNetworkSvc [On_Demand | Running]) -- F:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
(WPCSvc [On_Demand | Stopped]) -- F:\Windows\System32\wpcsvc.dll (Microsoft Corporation)
(WPDBusEnum [Auto | Running]) -- F:\Windows\System32\wpdbusenum.dll (Microsoft Corporation)
(WSearch [Auto | Running]) -- F:\Windows\System32\SearchIndexer.exe (Microsoft Corporation)
(wuauserv [Auto | Running]) -- F:\Windows\System32\wuaueng.dll (Microsoft Corporation)
(wudfsvc [Auto | Running]) -- F:\Windows\System32\WUDFSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
(adp94xx [Disabled | Stopped]) -- F:\Windows\System32\drivers\adp94xx.sys (Adaptec, Inc.)
(adpahci [Disabled | Stopped]) -- F:\Windows\System32\drivers\adpahci.sys (Adaptec, Inc.)
(adpu160m [Disabled | Stopped]) -- F:\Windows\System32\drivers\adpu160m.sys (Adaptec, Inc.)
(adpu320 [Disabled | Stopped]) -- F:\Windows\System32\drivers\adpu320.sys (Adaptec, Inc.)
(aic78xx [Disabled | Stopped]) -- F:\Windows\System32\drivers\djsvs.sys (Adaptec, Inc.)
(aliide [Disabled | Stopped]) -- F:\Windows\System32\drivers\aliide.sys (Acer Laboratories Inc.)
(amdagp [On_Demand | Stopped]) -- F:\Windows\System32\drivers\AMDAGP.SYS (Microsoft Corporation)
(amdide [Disabled | Stopped]) -- F:\Windows\System32\drivers\amdide.sys (Microsoft Corporation)
(AmdK7 [Disabled | Stopped]) -- F:\Windows\System32\drivers\amdk7.sys (Microsoft Corporation)
(AmdK8 [Disabled | Stopped]) -- F:\Windows\System32\drivers\amdk8.sys (Microsoft Corporation)
(arc [Disabled | Stopped]) -- F:\Windows\System32\drivers\arc.sys (Adaptec, Inc.)
(arcsas [Disabled | Stopped]) -- F:\Windows\System32\drivers\arcsas.sys (Adaptec, Inc.)
(aswFsBlk [Auto | Running]) -- F:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
(aswMonFlt [Auto | Running]) -- F:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
(aswRdr [System | Running]) -- F:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
(aswSP [System | Running]) -- F:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
(aswTdi [System | Running]) -- F:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
(bowser [On_Demand | Running]) -- F:\Windows\System32\drivers\bowser.sys (Microsoft Corporation)
(BrFiltLo [On_Demand | Stopped]) -- F:\Windows\System32\drivers\BrFiltLo.sys (Brother Industries, Ltd.)
(BrFiltUp [On_Demand | Stopped]) -- F:\Windows\System32\drivers\BrFiltUp.sys (Brother Industries, Ltd.)
(Brserid [Disabled | Stopped]) -- F:\Windows\System32\drivers\BrSerId.sys (Brother Industries Ltd.)
(BrSerWdm [Disabled | Stopped]) -- F:\Windows\System32\drivers\BrSerWdm.sys (Brother Industries Ltd.)
(BrUsbMdm [Disabled | Stopped]) -- F:\Windows\System32\drivers\BrUsbMdm.sys (Brother Industries Ltd.)
(BrUsbSer [On_Demand | Stopped]) -- F:\Windows\System32\drivers\BrUsbSer.sys (Brother Industries Ltd.)
(BTHMODEM [Disabled | Stopped]) -- F:\Windows\System32\drivers\bthmodem.sys (Microsoft Corporation)
(circlass [Disabled | Stopped]) -- F:\Windows\System32\drivers\circlass.sys (Microsoft Corporation)
(CLFS [Unknown | Running]) -- F:\Windows\System32\clfs.sys (Microsoft Corporation)
(cmdide [Disabled | Stopped]) -- F:\Windows\System32\drivers\cmdide.sys (CMD Technology, Inc.)
(crcdisk [Boot | Running]) -- F:\Windows\System32\drivers\crcdisk.sys (Microsoft Corporation)
(Crusoe [Disabled | Stopped]) -- F:\Windows\System32\drivers\crusoe.sys (Microsoft Corporation)
(DfsC [System | Running]) -- F:\Windows\System32\drivers\dfsc.sys (Microsoft Corporation)
(DXGKrnl [On_Demand | Running]) -- F:\Windows\System32\drivers\dxgkrnl.sys (Microsoft Corporation)
(E1G60 [On_Demand | Stopped]) -- F:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
(e4usbaw [On_Demand | Running]) -- F:\Windows\System32\drivers\e4usbaw.sys (Analog Devices Inc.)
(Ecache [Boot | Running]) -- F:\Windows\System32\drivers\ecache.sys (Microsoft Corporation)
(elxstor [Disabled | Stopped]) -- F:\Windows\System32\drivers\elxstor.sys (Emulex)
(exfat [On_Demand | Stopped]) -- F:\Windows\System32\drivers\exfat.sys (Microsoft Corporation)
(FileInfo [Boot | Running]) -- F:\Windows\System32\drivers\fileinfo.sys (Microsoft Corporation)
(Filetrace [On_Demand | Stopped]) -- F:\Windows\System32\drivers\filetrace.sys (Microsoft Corporation)
(gagp30kx [On_Demand | Stopped]) -- F:\Windows\System32\drivers\GAGP30KX.SYS (Microsoft Corporation)
(GEARAspiWDM [On_Demand | Running]) -- F:\Windows\System32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
(HdAudAddService [On_Demand | Running]) -- F:\Windows\System32\drivers\HdAudio.sys (Microsoft Corporation)
(HDAudBus [On_Demand | Running]) -- F:\Windows\System32\drivers\hdaudbus.sys (Microsoft Corporation)
(HidBth [Disabled | Stopped]) -- F:\Windows\System32\drivers\hidbth.sys (Microsoft Corporation)
(HidIr [Disabled | Stopped]) -- F:\Windows\System32\drivers\hidir.sys (Microsoft Corporation)
(HpCISSs [Disabled | Stopped]) -- F:\Windows\System32\drivers\HpCISSs.sys (Hewlett-Packard Company)
(iaStorV [Disabled | Stopped]) -- F:\Windows\System32\drivers\iaStorV.sys (Intel Corporation)
(iirsp [Disabled | Stopped]) -- F:\Windows\System32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
(IKANLOADER2 [Auto | Stopped]) -- F:\Windows\System32\drivers\e4ldr.sys (Analog Deivces)
(IPMIDRV [Disabled | Stopped]) -- F:\Windows\System32\drivers\IPMIDrv.sys (Microsoft Corporation)
(iScsiPrt [On_Demand | Running]) -- F:\Windows\System32\drivers\msiscsi.sys (Microsoft Corporation)
(iteatapi [Disabled | Stopped]) -- F:\Windows\System32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
(iteraid [Disabled | Stopped]) -- F:\Windows\System32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
(JGOGO [Boot | Running]) -- F:\Windows\System32\drivers\JGOGO.sys (JMicron )
(JRAID [Boot | Running]) -- F:\Windows\System32\drivers\jraid.sys (JMicron Technology Corp.)
(kbdhid [Disabled | Stopped]) -- F:\Windows\System32\drivers\kbdhid.sys (Microsoft Corporation)
(lltdio [Auto | Running]) -- F:\Windows\System32\drivers\lltdio.sys (Microsoft Corporation)
(LSI_FC [Disabled | Stopped]) -- F:\Windows\System32\drivers\lsi_fc.sys (LSI Logic)
(LSI_SAS [Disabled | Stopped]) -- F:\Windows\System32\drivers\lsi_sas.sys (LSI Logic)
(LSI_SCSI [Disabled | Stopped]) -- F:\Windows\System32\drivers\lsi_scsi.sys (LSI Logic)
(luafv [Auto | Running]) -- F:\Windows\System32\drivers\luafv.sys (Microsoft Corporation)
(MBAMSwissArmy [On_Demand | Stopped]) -- F:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
(megasas [Disabled | Stopped]) -- F:\Windows\System32\drivers\megasas.sys (LSI Logic Corporation)
(monitor [On_Demand | Running]) -- F:\Windows\System32\drivers\monitor.sys (Microsoft Corporation)
(mpio [Disabled | Stopped]) -- F:\Windows\System32\drivers\mpio.sys (Microsoft Corporation)
(mpsdrv [On_Demand | Running]) -- F:\Windows\System32\drivers\mpsdrv.sys (Microsoft Corporation)
(Mraid35x [Disabled | Stopped]) -- F:\Windows\System32\drivers\Mraid35x.sys (LSI Logic Corporation)
(mrxsmb10 [On_Demand | Running]) -- F:\Windows\System32\drivers\mrxsmb10.sys (Microsoft Corporation)
(mrxsmb20 [On_Demand | Running]) -- F:\Windows\System32\drivers\mrxsmb20.sys (Microsoft Corporation)
(msahci [Disabled | Stopped]) -- F:\Windows\System32\drivers\msahci.sys (Microsoft Corporation)
(msdsm [Disabled | Stopped]) -- F:\Windows\System32\drivers\msdsm.sys (Microsoft Corporation)
(msisadrv [Boot | Running]) -- F:\Windows\System32\drivers\msisadrv.sys (Microsoft Corporation)
(MsRPC [On_Demand | Stopped]) -- F:\Windows\System32\drivers\msrpc.sys (Microsoft Corporation)
(MTsensor [On_Demand | Running]) -- F:\Windows\System32\drivers\ASACPI.sys ()
(NativeWifiP [On_Demand | Stopped]) -- F:\Windows\System32\drivers\nwifi.sys (Microsoft Corporation)
(nfrd960 [Disabled | Stopped]) -- F:\Windows\System32\drivers\nfrd960.sys (IBM Corporation)
(nsiproxy [System | Running]) -- F:\Windows\System32\drivers\nsiproxy.sys (Microsoft Corporation)
(ntrigdigi [Disabled | Stopped]) -- F:\Windows\System32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
(nvlddmkm [On_Demand | Running]) -- F:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
(nvraid [Disabled | Stopped]) -- F:\Windows\System32\drivers\nvraid.sys (NVIDIA Corporation)
(nvstor [Disabled | Stopped]) -- F:\Windows\System32\drivers\nvstor.sys (NVIDIA Corporation)
(nv_agp [On_Demand | Stopped]) -- F:\Windows\System32\drivers\NV_AGP.SYS (Microsoft Corporation)
(pcouffin [On_Demand | Stopped]) -- F:\Windows\System32\drivers\pcouffin.sys (VSO Software)
(PEAUTH [Auto | Running]) -- F:\Windows\System32\drivers\PEAuth.sys (Microsoft Corporation)
(PSched [System | Running]) -- F:\Windows\System32\drivers\pacer.sys (Microsoft Corporation)
(PxHelp20 [Boot | Running]) -- F:\Windows\System32\drivers\PxHelp20.sys (Sonic Solutions)
(ql2300 [Disabled | Stopped]) -- F:\Windows\System32\drivers\ql2300.sys (QLogic Corporation)
(ql40xx [Disabled | Stopped]) -- F:\Windows\System32\drivers\ql40xx.sys (QLogic Corporation)
(QWAVEdrv [On_Demand | Stopped]) -- F:\Windows\System32\drivers\qwavedrv.sys (Microsoft Corporation)
(RasSstp [On_Demand | Running]) -- F:\Windows\System32\drivers\rassstp.sys (Microsoft Corporation)
(RDPENCDD [System | Running]) -- F:\Windows\System32\drivers\RDPENCDD.sys (Microsoft Corporation)
(rspndr [Auto | Running]) -- F:\Windows\System32\drivers\rspndr.sys (Microsoft Corporation)
(RTL8169 [On_Demand | Running]) -- F:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
(sbp2port [Disabled | Stopped]) -- F:\Windows\System32\drivers\sbp2port.sys (Microsoft Corporation)
(secdrv [Auto | Running]) -- F:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sermouse [Disabled | Stopped]) -- F:\Windows\System32\drivers\sermouse.sys (Microsoft Corporation)
(sffdisk [Disabled | Stopped]) -- F:\Windows\System32\drivers\sffdisk.sys (Microsoft Corporation)
(sffp_mmc [On_Demand | Stopped]) -- F:\Windows\System32\drivers\sffp_mmc.sys (Microsoft Corporation)
(sffp_sd [On_Demand | Stopped]) -- F:\Windows\System32\drivers\sffp_sd.sys (Microsoft Corporation)
(sisagp [On_Demand | Stopped]) -- F:\Windows\System32\drivers\SISAGP.SYS (Microsoft Corporation)
(SiSRaid2 [Disabled | Stopped]) -- F:\Windows\System32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
(SiSRaid4 [Disabled | Stopped]) -- F:\Windows\System32\drivers\sisraid4.sys (Silicon Integrated Systems)
(Smb [System | Running]) -- F:\Windows\System32\drivers\smb.sys (Microsoft Corporation)
(spldr [Boot | Running]) -- F:\Windows\System32\drivers\spldr.sys (Microsoft Corporation)
(sptd [Boot | Running]) -- F:\Windows\System32\drivers\sptd.sys ()
(srv2 [On_Demand | Running]) -- F:\Windows\System32\drivers\srv2.sys (Microsoft Corporation)
(srvnet [On_Demand | Running]) -- F:\Windows\System32\drivers\srvnet.sys (Microsoft Corporation)
(Symc8xx [Disabled | Stopped]) -- F:\Windows\System32\drivers\symc8xx.sys (LSI Logic)
(Sym_hi [Disabled | Stopped]) -- F:\Windows\System32\drivers\sym_hi.sys (LSI Logic)
(Sym_u3 [Disabled | Stopped]) -- F:\Windows\System32\drivers\sym_u3.sys (LSI Logic)
(tcpipreg [Auto | Running]) -- F:\Windows\System32\drivers\tcpipreg.sys (Microsoft Corporation)
(tdx [System | Running]) -- F:\Windows\System32\drivers\tdx.sys (Microsoft Corporation)
(tssecsrv [On_Demand | Stopped]) -- F:\Windows\System32\drivers\tssecsrv.sys (Microsoft Corporation)
(tunmp [On_Demand | Running]) -- F:\Windows\System32\drivers\TUNMP.SYS (Microsoft Corporation)
(tunnel [On_Demand | Running]) -- F:\Windows\System32\drivers\tunnel.sys (Microsoft Corporation)
(uagp35 [On_Demand | Stopped]) -- F:\Windows\System32\drivers\UAGP35.SYS (Microsoft Corporation)
(uliagpkx [On_Demand | Stopped]) -- F:\Windows\System32\drivers\ULIAGPKX.SYS (Microsoft Corporation)
(uliahci [Disabled | Stopped]) -- F:\Windows\System32\drivers\uliahci.sys (ULi Electronics Inc.)
(UlSata [Disabled | Stopped]) -- F:\Windows\System32\drivers\ulsata.sys (Promise Technology, Inc.)
(ulsata2 [Disabled | Stopped]) -- F:\Windows\System32\drivers\ulsata2.sys (Promise Technology, Inc.)
(umbus [On_Demand | Running]) -- F:\Windows\System32\drivers\umbus.sys (Microsoft Corporation)
(USBAAPL [On_Demand | Stopped]) -- F:\Windows\System32\drivers\usbaapl.sys (Apple, Inc.)
(usbaudio [On_Demand | Running]) -- F:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
(usbcir [Disabled | Stopped]) -- F:\Windows\System32\drivers\usbcir.sys (Microsoft Corporation)
(vga [On_Demand | Stopped]) -- F:\Windows\System32\drivers\vgapnp.sys (Microsoft Corporation)
(ViaC7 [Disabled | Stopped]) -- F:\Windows\System32\drivers\viac7.sys (Microsoft Corporation)
(viaide [Disabled | Stopped]) -- F:\Windows\System32\drivers\viaide.sys (VIA Technologies, Inc.)
(volmgr [Boot | Running]) -- F:\Windows\System32\drivers\volmgr.sys (Microsoft Corporation)
(volmgrx [Boot | Running]) -- F:\Windows\System32\drivers\volmgrx.sys (Microsoft Corporation)
(vsmraid [Disabled | Stopped]) -- F:\Windows\System32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
(WacomPen [Disabled | Stopped]) -- F:\Windows\System32\drivers\wacompen.sys (Microsoft Corporation)
(Wd [Disabled | Stopped]) -- F:\Windows\System32\drivers\wd.sys (Microsoft Corporation)
(Wdf01000 [Boot | Running]) -- F:\Windows\System32\drivers\Wdf01000.sys (Microsoft Corporation)
(WmiAcpi [Disabled | Stopped]) -- F:\Windows\System32\drivers\wmiacpi.sys (Microsoft Corporation)
(ws2ifsl [Disabled | Stopped]) -- F:\Windows\System32\drivers\ws2ifsl.sys (Microsoft Corporation)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = F:\Windows\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache =
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (292023 bytes) - F:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 10057 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [JMB36X Configure] F:\WINDOWS\system32\JMRaidSetup.exe boot (JMicron Technology Corp.)
O4 - HKLM..\Run: [JMB36X IDE Setup] F:\WINDOWS\JM\JMInsIDE.exe ()
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE F:\Windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE F:\Windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKCU..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] "F:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
O4 - HKCU..\Run: [ehTray.exe] F:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Sidebar] F:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [WMPNSCFG] F:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Sites: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler: - about - F:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - F:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - F:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - F:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - F:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - F:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - F:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - F:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - F:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - F:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - F:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - F:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - F:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - F:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - F:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - F:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - F:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - F:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - F:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - F:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - F:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - F:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - F:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - res - F:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - F:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - F:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - F:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - F:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - F:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - F:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - F:\Windows\System32\urlmon.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}F:\Windows\System32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}F:\Windows\System32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\Windows\System32\browseui.dll (Microsoft Corporation)
========== HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>F:\Windows\explorer.exe (Microsoft Corporation)
"UserInit" = F:\Windows\system32\userinit.exe,
>F:\Windows\System32\userinit.exe (Microsoft Corporation)
"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>F:\Windows\System32\shell32.dll (Microsoft Corporation)
>F:\Windows\System32\sysdm.cpl (Microsoft Corporation)
========== HKLM *SecurityProviders* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = credssp.dll
>F:\Windows\System32\credssp.dll (Microsoft Corporation)
========== LSA *Authentication Packages* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>F:\Windows\System32\msv1_0.dll (Microsoft Corporation)
========== LSA *Security Packages* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,tspkg,
>F:\Windows\System32\kerberos.dll (Microsoft Corporation)
>F:\Windows\System32\msv1_0.dll (Microsoft Corporation)
>F:\Windows\System32\schannel.dll (Microsoft Corporation)
>F:\Windows\System32\wdigest.dll (Microsoft Corporation)
>F:\Windows\System32\TSpkg.dll (Microsoft Corporation)
========== Safeboot Options ==========
"AlternateShell" = cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () -- [ NTFS ]
autoplay.exe [MZ | ]
D:\autoplay.exe () -- [ CDFS ]
autorun.inf [[autorun] | open=autoplay.exe | icon=appicon.ico | | ]
D:\autorun.inf () -- [ CDFS ]
autoexec.bat [REM Dummy file for NTVDM | ]
F:\autoexec.bat () -- [ NTFS ]
autorun.inf [[AutoRun] | open=LaunchU3.exe | icon=LaunchU3.exe,0 | | [Definitions] | Launchpad=LaunchPad.exe | | [CopyFiles] | FileNumber=1 | File1=LaunchPad.zip | ]
H:\autorun.inf () -- [ CDFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{15efdcec-e629-11dc-aecb-806e6f6e6963}\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{15efdcec-e629-11dc-aecb-806e6f6e6963}\Shell\AutoRun\command]
"" = D:\autoplay.exe -- [2003/05/21 17:11:08 | 00,061,440 | R--- | M] ()
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{94ef64cd-fd76-11dc-a51b-000000000000}\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{94ef64cd-fd76-11dc-a51b-000000000000}\Shell\AutoRun\command]
"" = G:\setup.exe -- File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a310c167-edba-11dc-8ec6-000000000000}\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a310c167-edba-11dc-8ec6-000000000000}\Shell\AutoRun\command]
"" = H:\LaunchU3.exe -- [2006/02/13 19:09:04 | 00,921,600 | R--- | M] ()
========== Files/Folders - Created Within 30 Days ==========
[4 F:\Windows\*.tmp files]
[2009/01/31 17:47:27 | 00,419,328 | ---- | C] (OldTimer Tools) -- F:\Users\Peter\Desktop\OTListIt2.exe
[2009/01/31 15:22:59 | 00,000,000 | ---D | C] -- F:\ComboFix
[2009/01/31 15:22:58 | 00,318,976 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\CF5875.exe
[2009/01/31 15:22:40 | 03,048,418 | R--- | C] () -- F:\Users\Peter\Desktop\ComboFix.exe
[2009/01/31 15:10:33 | 00,318,976 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\CF3439.exe
[2009/01/31 15:05:20 | 00,318,976 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\CF2417.exe
[2009/01/31 15:01:02 | 00,318,976 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\CF1575.exe
[2009/01/31 14:55:14 | 00,318,976 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\CF438.exe
[2009/01/31 14:53:39 | 00,000,000 | ---D | C] -- F:\Qoobox
[2009/01/31 14:53:38 | 00,318,976 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\CF33.exe
[2009/01/31 14:53:18 | 00,031,744 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\swsc.exe
[2009/01/31 14:53:15 | 00,000,000 | ---D | C] -- F:\Users\Peter\AppData\Local\Adobe
[2009/01/31 04:24:34 | 00,050,864 | ---- | C] (ALWIL Software) -- F:\Windows\System32\drivers\aswTdi.sys
[2009/01/31 04:24:34 | 00,023,152 | ---- | C] (ALWIL Software) -- F:\Windows\System32\drivers\aswRdr.sys
[2009/01/31 04:24:34 | 00,001,849 | ---- | C] () -- F:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/01/31 04:24:33 | 00,097,480 | ---- | C] (ALWIL Software) -- F:\Windows\System32\AvastSS.scr
[2009/01/31 04:24:32 | 00,111,184 | ---- | C] (ALWIL Software) -- F:\Windows\System32\drivers\aswSP.sys
[2009/01/31 04:24:32 | 00,020,560 | ---- | C] (ALWIL Software) -- F:\Windows\System32\drivers\aswFsBlk.sys
[2009/01/31 04:24:16 | 01,236,208 | ---- | C] (ALWIL Software) -- F:\Windows\System32\aswBoot.exe
[2009/01/31 04:24:16 | 01,060,864 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\MFC71.dll
[2009/01/31 04:24:16 | 00,380,928 | ---- | C] () -- F:\Windows\System32\actskin4.ocx
[2009/01/31 04:24:16 | 00,051,792 | ---- | C] (ALWIL Software) -- F:\Windows\System32\drivers\aswMonFlt.sys
[2009/01/31 04:24:14 | 00,000,000 | ---D | C] -- F:\Program Files\Alwil Software
[2009/01/30 22:09:54 | 03,578,880 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\mshtml.dll
[2009/01/30 22:09:52 | 01,383,424 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\mshtml.tlb
[2009/01/30 22:04:40 | 00,002,048 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\tzres.dll
[2009/01/30 21:53:42 | 00,105,016 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/01/30 21:53:42 | 00,097,800 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\infocardapi.dll
[2009/01/30 21:53:41 | 00,622,080 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\icardagt.exe
[2009/01/30 21:53:41 | 00,043,544 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\PresentationHostProxy.dll
[2009/01/30 21:53:41 | 00,037,384 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\infocardcpl.cpl
[2009/01/30 21:53:41 | 00,011,264 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\icardres.dll
[2009/01/30 21:53:40 | 00,781,344 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\PresentationNative_v0300.dll
[2009/01/30 21:53:38 | 00,326,160 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\PresentationHost.exe
[2009/01/30 21:46:34 | 00,096,760 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\dfshim.dll
[2009/01/30 21:46:30 | 00,282,112 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\mscoree.dll
[2009/01/30 21:46:30 | 00,041,984 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\netfxperf.dll
[2009/01/30 21:46:20 | 00,158,720 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\mscorier.dll
[2009/01/30 21:46:16 | 00,083,968 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\mscories.dll
[2009/01/30 21:43:18 | 06,068,736 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\ieframe.dll
[2009/01/30 21:43:17 | 01,166,336 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\urlmon.dll
[2009/01/30 21:43:17 | 00,827,392 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wininet.dll
[2009/01/30 21:43:16 | 00,671,232 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\mstime.dll
[2009/01/30 21:43:16 | 00,270,336 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\iertutil.dll
[2009/01/30 21:43:16 | 00,028,160 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\jsproxy.dll
[2009/01/30 21:43:11 | 00,428,544 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\EncDec.dll
[2009/01/30 21:43:11 | 00,217,088 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\psisrndr.ax
[2009/01/30 21:43:10 | 00,293,376 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\psisdecd.dll
[2009/01/30 21:43:10 | 00,177,664 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\mpg2splt.ax
[2009/01/30 21:43:10 | 00,080,896 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\MSNP.ax
[2009/01/30 21:42:18 | 00,288,768 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\drivers\srv.sys
[2009/01/30 21:42:14 | 00,028,672 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\Apphlpdm.dll
[2009/01/30 21:42:13 | 04,240,384 | ---- | C] (Microsoft) -- F:\Windows\System32\GameUXLegacyGDFs.dll
[2009/01/30 21:42:10 | 00,443,392 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\win32spl.dll
[2009/01/30 21:42:08 | 00,466,944 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\netapi32.dll
[2009/01/30 21:42:07 | 02,868,736 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\mf.dll
[2009/01/30 21:42:07 | 02,386,944 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\WMVCORE.DLL
[2009/01/30 21:42:06 | 00,996,352 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\WMNetMgr.dll
[2009/01/30 21:42:06 | 00,094,720 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\logagent.exe
[2009/01/30 21:42:04 | 00,296,960 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\gdi32.dll
[2009/01/30 21:42:02 | 00,712,704 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\WindowsCodecs.dll
[2009/01/30 21:42:02 | 00,425,472 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\PhotoMetadataHandler.dll
[2009/01/30 21:42:02 | 00,347,136 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\WindowsCodecsExt.dll
[2009/01/30 21:42:00 | 02,927,104 | ---- | C] (Microsoft Corporation) -- F:\Windows\explorer.exe
[2009/01/30 21:41:57 | 00,147,456 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\Faultrep.dll
[2009/01/30 21:41:57 | 00,125,952 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wersvc.dll
[2009/01/30 21:41:54 | 00,212,480 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\drivers\mrxsmb10.sys
[2009/01/30 21:41:49 | 11,580,928 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\shell32.dll
[2009/01/30 21:41:40 | 01,191,936 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\msxml3.dll
[2009/01/30 21:41:38 | 02,032,640 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\win32k.sys
[2009/01/30 21:41:37 | 00,241,152 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\PortableDeviceApi.dll
[2009/01/30 21:41:36 | 01,645,568 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\connect.dll
[2009/01/30 21:38:32 | 03,601,464 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\ntkrnlpa.exe
[2009/01/30 21:38:32 | 03,549,240 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\ntoskrnl.exe
[2009/01/30 21:36:16 | 01,334,272 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\msxml6.dll
[2009/01/30 21:27:35 | 01,524,736 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wucltux.dll
[2009/01/30 21:27:35 | 00,051,224 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wuauclt.exe
[2009/01/30 21:27:35 | 00,043,544 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wups2.dll
[2009/01/30 21:27:34 | 01,809,944 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wuaueng.dll
[2009/01/30 21:27:09 | 00,561,688 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wuapi.dll
[2009/01/30 21:27:09 | 00,083,456 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wudriver.dll
[2009/01/30 21:27:09 | 00,034,328 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wups.dll
[2009/01/30 21:27:02 | 00,162,064 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wuwebv.dll
[2009/01/30 21:27:02 | 00,031,232 | ---- | C] (Microsoft Corporation) -- F:\Windows\System32\wuapp.exe
[2009/01/30 19:58:52 | 00,000,000 | ---D | C] -- F:\Users\Peter\AppData\Roaming\Malwarebytes
[2009/01/30 19:58:51 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- F:\Windows\System32\drivers\mbam.sys
[2009/01/30 19:58:51 | 00,000,818 | ---- | C] () -- F:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/30 19:58:49 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- F:\Windows\System32\drivers\mbamswissarmy.sys
[2009/01/30 19:58:48 | 00,000,000 | ---D | C] -- F:\ProgramData\Malwarebytes
[2009/01/30 19:58:47 | 00,000,