Any help would be greatly appreciated. OTL log below:
OTL logfile created on: 06/10/2013 19:35:50 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\geoff\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 40.02% Memory free
6.20 Gb Paging File | 3.11 Gb Available in Paging File | 50.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.34 Gb Total Space | 128.44 Gb Free Space | 58.03% Space Free | Partition Type: NTFS
Drive D: | 11.54 Gb Total Space | 2.23 Gb Free Space | 19.29% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 537.04 Gb Free Space | 57.65% Space Free | Partition Type: NTFS
Computer Name: GEOFF-LAPTOP | User Name: geoff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/10/06 19:34:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\geoff\Desktop\OTL.exe
PRC - [2013/08/30 08:47:34 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/08/30 08:47:33 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013/08/30 08:47:31 | 000,137,960 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2013/07/19 13:22:18 | 000,217,992 | ---- | M] (Google Inc.) -- C:\Users\geoff\AppData\Local\Google\Update\1.3.21.153\GoogleCrashHandler.exe
PRC - [2013/07/06 16:43:59 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2013/06/20 18:05:14 | 000,022,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/10 14:17:40 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2011/11/11 18:33:16 | 000,371,856 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\nsService.exe
PRC - [2011/11/11 18:20:34 | 000,222,352 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\nsCtrl.exe
PRC - [2011/11/02 02:00:44 | 000,090,448 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
PRC - [2010/07/04 20:51:26 | 000,017,408 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2009/12/23 22:34:20 | 000,370,688 | ---- | M] (StarWind Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2009/10/26 14:46:54 | 001,458,176 | ---- | M] (Motorola Inc.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/12/04 14:00:26 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/12/04 14:00:20 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/04/29 23:57:42 | 000,103,344 | ---- | M] (Lexmark International Inc.) -- C:\Program Files\Lexmark 2300 Series\ezprint.exe
PRC - [2007/04/29 23:55:32 | 000,205,744 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
PRC - [2007/04/29 23:54:44 | 000,537,520 | ---- | M] ( ) -- C:\Windows\System32\lxcgcoms.exe
========== Modules (No Company Name) ==========
MOD - [2013/09/14 16:01:19 | 016,177,544 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_8_800_168.dll
MOD - [2013/07/06 16:44:18 | 000,312,832 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dll
MOD - [2013/07/06 16:44:18 | 000,158,208 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
MOD - [2013/07/06 16:44:18 | 000,101,888 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dll
MOD - [2013/07/06 16:44:18 | 000,096,256 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dll
MOD - [2013/07/06 16:44:18 | 000,094,208 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dll
MOD - [2013/07/06 16:44:18 | 000,093,696 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dll
MOD - [2013/07/06 16:44:18 | 000,073,728 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dll
MOD - [2013/07/06 16:44:18 | 000,067,072 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dll
MOD - [2013/07/06 16:44:18 | 000,062,976 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dll
MOD - [2013/07/06 16:44:18 | 000,057,344 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dll
MOD - [2013/07/06 16:44:18 | 000,038,912 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dll
MOD - [2013/07/06 16:44:17 | 000,835,584 | ---- | M] () -- C:\Program Files\Opera\gstreamer\gstreamer.dll
MOD - [2011/11/11 18:35:56 | 002,463,888 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\nsAppRes409.dll
MOD - [2011/11/11 18:17:12 | 000,179,344 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\nsEngineRes409.dll
MOD - [2010/07/04 22:32:36 | 000,004,608 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2010/07/04 20:51:26 | 000,017,408 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
MOD - [2007/12/20 03:28:32 | 000,345,384 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll
MOD - [2007/12/20 03:28:20 | 000,251,288 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll
MOD - [2007/12/20 03:28:20 | 000,120,208 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll
MOD - [2007/12/20 03:28:20 | 000,038,184 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll
MOD - [2007/12/20 03:27:04 | 000,066,856 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll
MOD - [2005/12/13 16:52:02 | 000,122,880 | ---- | M] () -- C:\Program Files\Lexmark 2300 Series\lxcgdrec.dll
MOD - [2005/06/14 18:08:28 | 000,196,608 | ---- | M] () -- C:\Program Files\Lexmark 2300 Series\iptk.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService)
SRV - [2013/09/20 11:01:43 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/08/30 08:47:33 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013/08/30 08:47:31 | 000,137,960 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV - [2013/06/20 18:05:14 | 000,295,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/06/20 18:05:14 | 000,022,208 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2013/04/10 07:58:17 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/09/10 14:17:40 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/11/11 18:33:16 | 000,371,856 | ---- | M] (NovaStor) [Auto | Running] -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\nsService.exe -- (nsService)
SRV - [2011/11/08 04:40:16 | 000,217,600 | ---- | M] (NovaStor Corporation) [Auto | Stopped] -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\ManagementServer.Agent.Service.exe -- (Backup Client Agent Service)
SRV - [2009/12/23 22:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2008/12/04 14:00:26 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/01/21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/04/29 23:54:44 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxcgcoms.exe -- (lxcg_device)
SRV - [2007/03/05 18:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\VBoxNetFlt.sys -- (VBoxNetFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (awrrt28d)
DRV - [2013/08/30 08:48:13 | 000,369,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013/08/30 08:48:13 | 000,177,864 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013/08/30 08:48:13 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013/08/30 08:48:12 | 000,770,344 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013/08/30 08:48:12 | 000,204,784 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis2.sys -- (aswNdis2)
DRV - [2013/08/30 08:48:12 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2013/08/30 08:48:12 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013/08/30 08:48:11 | 000,104,752 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswFW.sys -- (aswFW)
DRV - [2013/08/30 08:48:11 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013/08/30 08:48:11 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2013/08/30 08:48:11 | 000,021,576 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd)
DRV - [2013/06/18 21:50:08 | 000,107,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2013/03/15 20:30:06 | 000,104,720 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV - [2013/03/06 23:11:20 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis.sys -- (aswNdis)
DRV - [2011/09/21 10:25:34 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\cpuz135_x32.sys -- (cpuz135)
DRV - [2011/09/02 21:54:31 | 000,436,792 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2011/07/22 17:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011/07/12 22:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/07/04 20:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2010/01/28 13:34:32 | 000,102,912 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010/01/28 13:34:32 | 000,101,120 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbdev.sys -- (hwusbdev)
DRV - [2009/12/03 01:48:35 | 000,035,328 | ---- | M] (THOMSON Telecom Belgium) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\stppp.sys -- (stppp)
DRV - [2009/12/03 01:48:35 | 000,030,464 | ---- | M] (THOMSON Telecom Belgium) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\st330.sys -- (ST330)
DRV - [2009/12/03 01:48:35 | 000,012,672 | ---- | M] (THOMSON Telecom Belgium) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\stbus.sys -- (STBUS)
DRV - [2009/10/26 15:09:06 | 001,095,936 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)
DRV - [2009/10/03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/12/30 11:57:54 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2008/11/17 15:40:22 | 003,668,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32)
DRV - [2008/01/25 01:46:40 | 000,106,496 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/01/21 03:23:20 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32)
DRV - [2007/11/29 10:39:52 | 000,008,064 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2007/11/29 10:39:42 | 000,016,896 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2007/11/29 10:39:42 | 000,008,064 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2007/11/29 10:39:40 | 000,019,328 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2007/07/11 18:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV - [2007/06/28 16:09:56 | 002,222,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32)
DRV - [2007/06/19 01:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/03/22 06:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/02/24 22:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/01/24 00:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/01/09 09:22:28 | 000,006,144 | ---- | M] (Chic) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\moufiltr.sys -- (moufiltr)
DRV - [2006/11/02 08:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)
DRV - [2003/12/08 12:53:48 | 000,053,600 | ---- | M] (THOMSON) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\alcan5wn.sys -- (alcan5wn)
DRV - [2003/12/08 12:53:46 | 000,070,688 | ---- | M] (THOMSON) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\alcaudsl.sys -- (alcaudsl)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...ilion&pf=laptop
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{692AA4F1-88E5-453F-B143-F0283628D9A9}: "URL" = http://slirsredirect...hpcnnbie7-en-gb
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{7B71AF01-8159-4640-95A7-1ED00B6C3C8C}: "URL" = http://uk.kelkoopart...tnerId=96913936
IE - HKLM\..\SearchScopes\{9ED66CF3-88D2-4163-9BBD-388D6386714A}: "URL" = http://uk.kelkoopart...tnerId=96913936
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT1098640
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.virgin.net/ie/search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...119357&tsp=4996
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask...89-1CAD3D6D5299
IE - HKCU\..\SearchScopes\{692AA4F1-88E5-453F-B143-F0283628D9A9}: "URL" = http://slirsredirect...hpcnnbie7-en-gb
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7SKPB_enGB311
IE - HKCU\..\SearchScopes\{7B71AF01-8159-4640-95A7-1ED00B6C3C8C}: "URL" = http://uk.kelkoopart...tnerId=96913936
IE - HKCU\..\SearchScopes\{9ED66CF3-88D2-4163-9BBD-388D6386714A}: "URL" = http://uk.kelkoopart...tnerId=96913936
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT1098640
IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = http://www2.inbox.co...id=80150&lng=en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www2.delta-se...19357&tsp=4996"
FF - prefs.js..extensions.enabledAddons: ffxtlbr%40delta.com:1.5.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..keyword.URL: "http://www.google.co...-8&oe=utf-8&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\geoff\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\geoff\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/09/14 14:52:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/28 20:17:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/28 20:17:16 | 000,000,000 | ---D | M]
[2009/01/19 19:33:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\geoff\AppData\Roaming\mozilla\Extensions
[2013/09/14 14:34:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\geoff\AppData\Roaming\mozilla\Firefox\Profiles\stexyhts.default\extensions
[2013/09/05 19:14:39 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\geoff\AppData\Roaming\mozilla\Firefox\Profiles\stexyhts.default\extensions\[email protected]
[2013/04/11 17:04:36 | 000,213,470 | ---- | M] () (No name found) -- C:\Users\geoff\AppData\Roaming\mozilla\firefox\profiles\stexyhts.default\extensions\[email protected]
[2012/05/17 14:16:23 | 000,002,568 | ---- | M] () -- C:\Users\geoff\AppData\Roaming\mozilla\firefox\profiles\stexyhts.default\searchplugins\askcom.xml
[2013/07/10 14:09:36 | 000,006,507 | ---- | M] () -- C:\Users\geoff\AppData\Roaming\mozilla\firefox\profiles\stexyhts.default\searchplugins\babylon.xml
[2010/01/20 12:16:28 | 000,000,939 | ---- | M] () -- C:\Users\geoff\AppData\Roaming\mozilla\firefox\profiles\stexyhts.default\searchplugins\conduit.xml
[2013/07/10 14:10:12 | 000,001,294 | ---- | M] () -- C:\Users\geoff\AppData\Roaming\mozilla\firefox\profiles\stexyhts.default\searchplugins\delta.xml
[2012/10/03 12:56:19 | 000,002,330 | ---- | M] () -- C:\Users\geoff\AppData\Roaming\mozilla\firefox\profiles\stexyhts.default\searchplugins\inbox-search.xml
[2013/04/24 13:38:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/07/07 16:33:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/10 14:36:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013/04/10 07:58:33 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/04/10 07:57:54 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/10 07:57:54 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Delta Search (Enabled)
CHR - default_search_provider: search_url = http://www2.delta-se...119357&tsp=4996
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www2.delta-se...119357&tsp=4996
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\geoff\AppData\Local\Google\Chrome\Application\30.0.1599.69\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\geoff\AppData\Local\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\geoff\AppData\Local\Google\Chrome\Application\30.0.1599.69\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Chrome ChiliCoupon = C:\Users\geoff\AppData\Local\Google\Chrome\User Data\Default\Extensions\aojkekekdddohfnopabknfjadjajdici\1.0.2_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\geoff\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\
O1 HOSTS File: ([2011/03/30 18:38:06 | 000,431,551 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14856 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Spybot - Search & Destroy\SDHelper.dll File not found
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 2300 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LXCGCATS] C:\Windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.DLL ()
O4 - HKLM..\Run: [lxcgmon.exe] C:\Program Files\Lexmark 2300 Series\lxcgmon.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\Spybot - Search & Destroy\SDHelper.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: cleverreach.com ([novastor] http in Trusted sites)
O15 - HKCU\..Trusted Domains: google-analytics.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: novastor.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: novastor.com ([]https in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C1122DA3-F798-4DC3-A956-F232C42C5C49}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/03/07 16:43:13 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 16:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O33 - MountPoints2\{0d0215e7-b8e2-11df-9137-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{0d0215e7-b8e2-11df-9137-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\KODAK_Software_Downloader.exe
O33 - MountPoints2\{1433eb48-af64-11dd-a7fd-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{1433eb48-af64-11dd-a7fd-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{1433eb59-af64-11dd-a7fd-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{1433eb59-af64-11dd-a7fd-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{14a70677-1bf5-11df-9b35-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{14a70677-1bf5-11df-9b35-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{14a706d2-1bf5-11df-9b35-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{14a706d2-1bf5-11df-9b35-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{6989e6d4-2f9b-11e0-bb21-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{6989e6d4-2f9b-11e0-bb21-001e68ddbd2a}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{892525c7-1c81-11df-ac84-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{892525c7-1c81-11df-ac84-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{911d19df-c4c4-11e0-bb62-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{911d19df-c4c4-11e0-bb62-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{911d19e9-c4c4-11e0-bb62-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{911d19e9-c4c4-11e0-bb62-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{a6158d58-9f90-11dd-93d2-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{a6158d58-9f90-11dd-93d2-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{a6158d71-9f90-11dd-93d2-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{a6158d71-9f90-11dd-93d2-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{a6158d7d-9f90-11dd-93d2-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{a6158d7d-9f90-11dd-93d2-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{a6158d7f-9f90-11dd-93d2-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{a6158d7f-9f90-11dd-93d2-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{bd0e7f40-e516-11e0-8e38-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{bd0e7f40-e516-11e0-8e38-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Autorun\autorun.exe
O33 - MountPoints2\{eec199a5-e0bc-11de-a10e-000000000000}\Shell - "" = AutoRun
O33 - MountPoints2\{eec199a5-e0bc-11de-a10e-000000000000}\Shell\AutoRun\command - "" = F:\NokiaPCIA_Autorun.exe
O33 - MountPoints2\{f8c91f54-297c-11e0-8e52-001e68ddbd2a}\Shell - "" = AutoRun
O33 - MountPoints2\{f8c91f54-297c-11e0-8e52-001e68ddbd2a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/10/06 19:34:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\geoff\Desktop\OTL.exe
[2013/10/05 22:00:58 | 000,760,937 | ---- | C] (Farbar) -- C:\Users\geoff\Desktop\MiniToolBox.exe
[2013/09/24 14:43:35 | 000,000,000 | ---D | C] -- C:\Users\geoff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2013/09/24 14:43:34 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2013/09/24 12:58:58 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/09/21 16:43:56 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013/09/21 16:33:50 | 009,186,416 | ---- | C] (SurfRight B.V.) -- C:\Users\geoff\Desktop\HitmanPro.exe
[2013/09/14 15:04:54 | 000,000,000 | ---D | C] -- C:\Users\geoff\Desktop\DIDA info
[2013/09/14 01:15:38 | 000,000,000 | ---D | C] -- C:\Users\geoff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
[2013/09/14 01:15:25 | 000,000,000 | ---D | C] -- C:\ProgramData\BitGuard
[2012/03/07 15:18:18 | 015,174,824 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\geoff\SUPERAntiSpyware.exe
[2011/08/31 16:11:56 | 005,053,688 | ---- | C] (Macrovision Corporation) -- C:\Users\geoff\IsoBurner-Setup.exe
[2010/04/14 22:01:51 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Program Files\HijackThisInstaller.exe
[5 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[5 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/10/06 19:34:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\geoff\Desktop\OTL.exe
[2013/10/06 19:32:59 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/10/06 19:32:59 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/10/06 18:42:00 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/10/06 18:27:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-504676162-3151235640-1111575767-1000UA.job
[2013/10/06 18:01:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/10/06 13:27:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-504676162-3151235640-1111575767-1000Core.job
[2013/10/06 01:42:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/10/05 22:00:58 | 000,760,937 | ---- | M] (Farbar) -- C:\Users\geoff\Desktop\MiniToolBox.exe
[2013/10/03 21:35:11 | 000,002,086 | ---- | M] () -- C:\Users\geoff\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/10/03 21:35:11 | 000,002,084 | ---- | M] () -- C:\Users\geoff\Desktop\Google Chrome.lnk
[2013/09/27 20:08:31 | 2564,476,928 | ---- | M] () -- C:\Users\geoff\Desktop\X17-58996.iso
[2013/09/26 15:05:05 | 001,358,125 | ---- | M] () -- C:\Users\geoff\Desktop\quick_start_guide_v8_avast_is_en.pdf
[2013/09/26 13:56:46 | 000,000,584 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2013/09/26 13:56:22 | 000,177,040 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2013/09/26 13:56:22 | 000,177,040 | ---- | M] () -- C:\ProgramData\nvModes.001
[2013/09/26 13:33:24 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2013/09/26 13:32:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/09/26 13:32:06 | 3219,578,880 | -HS- | M] () -- C:\hiberfil.sys
[2013/09/25 23:48:31 | 005,235,440 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/09/25 23:48:30 | 002,533,122 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/09/24 19:48:41 | 000,334,952 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/09/24 18:23:27 | 000,000,632 | RHS- | M] () -- C:\Users\geoff\ntuser.pol
[2013/09/24 14:43:35 | 000,001,057 | ---- | M] () -- C:\Users\geoff\Desktop\Revo Uninstaller.lnk
[2013/09/21 16:33:58 | 009,186,416 | ---- | M] (SurfRight B.V.) -- C:\Users\geoff\Desktop\HitmanPro.exe
[2013/09/17 20:09:45 | 004,519,156 | ---- | M] () -- C:\Users\geoff\Desktop\guide-building-website.pdf
[2013/09/14 14:52:14 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013/09/12 10:49:11 | 000,016,398 | ---- | M] () -- C:\Users\geoff\Documents\my CV.odt
[2013/09/06 19:56:54 | 000,005,098 | ---- | M] () -- C:\Users\geoff\Documents\index.html
[5 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[5 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/09/27 19:15:19 | 2564,476,928 | ---- | C] () -- C:\Users\geoff\Desktop\X17-58996.iso
[2013/09/26 15:05:04 | 001,358,125 | ---- | C] () -- C:\Users\geoff\Desktop\quick_start_guide_v8_avast_is_en.pdf
[2013/09/24 14:43:35 | 000,001,057 | ---- | C] () -- C:\Users\geoff\Desktop\Revo Uninstaller.lnk
[2013/09/17 20:09:44 | 004,519,156 | ---- | C] () -- C:\Users\geoff\Desktop\guide-building-website.pdf
[2013/09/14 18:52:46 | 000,001,868 | ---- | C] () -- C:\Users\geoff\Documents\AlcoholTracker.lnk
[2013/09/06 19:56:54 | 000,005,098 | ---- | C] () -- C:\Users\geoff\Documents\index.html
[2013/09/05 19:13:50 | 000,086,016 | ---- | C] () -- C:\Windows\System32\custmon32i.dll
[2013/06/27 21:24:41 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/06/27 01:15:33 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswSP.sys.sum
[2013/06/27 01:15:33 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/04/13 19:55:15 | 000,114,176 | ---- | C] () -- C:\Users\geoff\AppData\Roaming\BabMaint.exe
[2013/03/14 18:38:01 | 000,177,864 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2013/03/14 18:38:01 | 000,049,376 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2012/12/30 21:25:28 | 000,000,600 | ---- | C] () -- C:\Users\geoff\AppData\Local\PUTTY.RND
[2012/12/27 21:10:35 | 000,000,000 | ---- | C] () -- C:\Users\geoff\ipconfig
[2012/05/01 13:31:52 | 000,110,456 | ---- | C] () -- C:\Users\geoff\g2ax_customer_downloadhelper_win32_x86.exe
[2012/04/27 14:16:09 | 000,484,827 | ---- | C] () -- C:\Users\geoff\Remote_Support_Quick_Start.pdf
[2012/04/26 12:43:53 | 000,035,464 | ---- | C] () -- C:\Users\geoff\GoToAssist_Express_QuickStart_Guide.pdf
[2012/04/25 20:41:04 | 000,110,968 | ---- | C] () -- C:\Users\geoff\g2ax_expert_downloadhelper_win32_x86.exe
[2012/04/05 13:59:39 | 000,000,053 | RHS- | C] () -- C:\ProgramData\1.12.5.lic
[2012/03/14 22:55:29 | 001,300,744 | ---- | C] () -- C:\Users\geoff\call_that_girl_s_guide_to_remote_support.pdf
[2012/03/07 14:18:45 | 000,869,194 | ---- | C] () -- C:\Users\geoff\SecurityCheck.exe
[2011/09/19 19:11:45 | 000,000,000 | ---- | C] () -- C:\Users\geoff\mkdir
[2011/08/30 20:50:30 | 001,803,848 | ---- | C] () -- C:\Users\geoff\winzip81.exe
[2011/08/30 20:41:45 | 000,000,515 | ---- | C] () -- C:\Users\geoff\memtest86-4.0a.iso.lnk
[2011/02/05 17:50:48 | 000,000,097 | RHS- | C] () -- C:\ProgramData\1.12.0.lic
[2010/12/09 16:18:39 | 000,000,632 | RHS- | C] () -- C:\Users\geoff\ntuser.pol
[2010/08/16 16:57:51 | 000,387,313 | ---- | C] () -- C:\Users\geoff\ISORecorderV3RC1x86.zip
[2010/08/16 13:13:25 | 000,000,321 | ---- | C] () -- C:\Users\geoff\KNOPPIX_V6.0.1CD-2009-02-08-DE.iso.sha1.asc
[2010/05/30 19:48:37 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/05/19 15:09:03 | 000,177,040 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2010/05/19 15:09:03 | 000,177,040 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/04/26 19:10:30 | 000,001,492 | ---- | C] () -- C:\Program Files\Spybot - Search & Destroy.lnk
[2010/03/18 15:31:27 | 013,751,939 | ---- | C] () -- C:\Users\geoff\cjr2300EN.exe
[2009/10/10 02:51:45 | 000,008,484 | ---- | C] () -- C:\Users\geoff\AppData\Local\d3d9caps.dat
[2008/11/09 17:24:29 | 000,026,340 | ---- | C] () -- C:\Users\geoff\AppData\Roaming\UserTile.png
[2008/10/30 20:59:01 | 000,008,704 | ---- | C] () -- C:\Users\geoff\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/14 23:02:55 | 000,000,398 | ---- | C] () -- C:\Users\geoff\AppData\Roaming\wklnhst.dat
[2008/10/14 22:10:17 | 000,027,839 | ---- | C] () -- C:\Users\geoff\AppData\Roaming\nvModes.001
[2008/10/14 22:06:26 | 000,027,839 | ---- | C] () -- C:\Users\geoff\AppData\Roaming\nvModes.dat
========== ZeroAccess Check ==========
[2006/11/02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/09/05 19:15:07 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
[2012/02/22 17:30:28 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\5192
[2013/09/02 16:44:17 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Alcohol Tracker Installer
[2013/09/02 16:45:04 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\AlcoholTracker
[2010/10/23 15:12:53 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Atari
[2011/03/23 20:37:00 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Blitware
[2012/04/20 15:30:56 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\ChiliCoupon
[2013/06/27 19:20:33 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\com.dsa.cartheorytest
[2013/06/03 15:16:16 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\DriverCure
[2012/04/29 16:37:30 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Dropbox
[2013/09/05 19:13:50 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\DSite
[2013/06/03 15:16:15 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Foresight Software
[2013/08/31 17:38:58 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\GameMaker-Studio
[2010/08/15 17:40:12 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Goqi
[2012/04/20 15:30:50 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\IE ChiliCoupon
[2010/10/12 15:05:26 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Naiwob
[2009/12/04 11:33:49 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Nokia
[2010/03/16 18:42:54 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\OpenOffice.org
[2011/12/12 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Opera
[2009/12/04 11:41:04 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\PC Suite
[2008/11/09 17:24:28 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\PeerNetworking
[2011/05/28 02:07:24 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\R-TT
[2011/12/16 23:19:09 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Research In Motion
[2013/08/19 19:33:28 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\SanDisk SecureAccess
[2013/05/01 17:53:59 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\TeamViewer
[2008/10/14 23:02:56 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Template
[2011/05/10 13:29:29 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\uTorrent
[2008/10/14 19:48:43 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\WildTangent
[2011/04/19 17:08:28 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\WinBatch
[2011/08/02 14:43:02 | 000,000,000 | ---D | M] -- C:\Users\geoff\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
< End of report >