ok so here goes:
OTL logfile created on: 14/06/2012 08:02:38 - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\RICHARD\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.99 Gb Total Physical Memory | 1.64 Gb Available Physical Memory | 54.73% Memory free
6.21 Gb Paging File | 4.89 Gb Available in Paging File | 78.67% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 128.89 Gb Total Space | 27.76 Gb Free Space | 21.54% Space Free | Partition Type: NTFS
Drive D: | 2.49 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: SUE-PC | User Name: RICHARD | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/06/14 07:39:10 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\RICHARD\Desktop\OTL.exe
PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/04/04 06:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2010/12/02 11:30:20 | 000,424,104 | ---- | M] (Auslogics) -- C:\Program Files\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/09/10 14:01:28 | 000,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2008/07/26 09:25:36 | 000,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/07/26 09:23:42 | 000,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
========== Modules (No Company Name) ==========
MOD - [2010/12/02 11:30:24 | 000,348,328 | ---- | M] () -- C:\Program Files\Auslogics\Auslogics Disk Defrag\madExcept_.bpl
MOD - [2010/12/02 11:30:24 | 000,182,440 | ---- | M] () -- C:\Program Files\Auslogics\Auslogics Disk Defrag\madBasic_.bpl
MOD - [2010/12/02 11:30:24 | 000,048,808 | ---- | M] () -- C:\Program Files\Auslogics\Auslogics Disk Defrag\madDisAsm_.bpl
MOD - [2010/12/02 11:30:20 | 000,253,608 | ---- | M] () -- C:\Program Files\Auslogics\Auslogics Disk Defrag\ausshellext.dll
MOD - [2010/03/15 11:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2008/07/26 09:24:04 | 000,068,120 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LVCOMSER\LVCSPS.dll
MOD - [2007/08/24 20:28:04 | 000,249,856 | ---- | M] () -- C:\Windows\System32\igfxTMM.dll
========== Win32 Services (SafeList) ==========
SRV - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/04/04 06:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2009/03/04 12:25:12 | 000,621,056 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008/09/10 14:01:28 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2008/07/26 09:25:36 | 000,150,040 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008/07/26 09:23:42 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2008/01/18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/09 13:30:08 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS -- (MRESP50)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS -- (MRENDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS -- (MREMPR5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS -- (MREMP50)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\RICHARD\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012/06/14 07:33:34 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D0F12A0A-BDA2-4619-B2DC-BA4B9DED427D}\MpKsl7b1e7cfa.sys -- (MpKsl7b1e7cfa)
DRV - [2012/04/04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2009/04/30 23:01:36 | 000,265,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2009/04/30 22:55:58 | 002,687,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2009/04/30 22:55:34 | 000,013,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lv302af.sys -- (pepifilter)
DRV - [2009/02/09 08:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009/02/09 08:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009/02/09 08:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009/02/09 08:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008/08/26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/07/30 21:27:08 | 000,641,024 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netr28u.sys -- (netr28u)
DRV - [2008/07/26 16:26:20 | 000,041,752 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2008/07/26 09:25:02 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2008/01/18 20:25:06 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R)
DRV - [2007/11/29 03:18:12 | 000,028,432 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2007/11/29 03:17:56 | 000,036,368 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007/11/29 03:17:48 | 000,035,088 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007/04/03 11:43:28 | 001,131,136 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Ph3xIB32.sys -- (Ph3xIB32)
DRV - [2006/07/13 20:09:10 | 000,044,800 | ---- | M] (anchor chips) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DVBT_Loader.sys -- (DVBT_Loader)
DRV - [2006/06/23 12:04:42 | 000,084,992 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Geniausb.sys -- (GenDTV)
DRV - [2005/02/23 15:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afc.sys -- (Afc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{597b1823-7ff0-4cd3-8095-9d8cba514992}: "URL" =
http://search.mywebsearch.com/myweb...F_HTg&st=sb&n=77df450c&searchfor={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" =
http://dts.search-results.com/sr?src=ieb&appid=141111&systemid=426&sr=0&q={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.co.uk/
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 17 5B 9C 63 6F E8 C9 01 [binary data]
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\..\SearchScopes,DefaultScope = {3BC2E2AD-CFDB-487B-B942-9DDC2CC7309A}
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\..\SearchScopes\{3BC2E2AD-CFDB-487B-B942-9DDC2CC7309A}: "URL" =
http://www.google.co.uk/search?hl=en&q={searchTerms}&meta=&rlz=
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\..\SearchScopes\{597b1823-7ff0-4cd3-8095-9d8cba514992}: "URL" =
http://search.mywebsearch.com/myweb...F_HTg&st=sb&n=77df450c&searchfor={searchTerms}
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2004933
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\..\SearchScopes\{E7F98EF0-CA16-4372-A65E-597AE53CF89B}: "URL" =
http://search.lycos.co.uk/cgi-bin/pursuit?SITE=uk&query={searchTerms}&cat=loc
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-699681126-2153449771-921346542-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://www.google.co.uk/ig?hl=en"
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@ei.TotalRecipeSearch_14.com/Plugin: C:\Program Files\TotalRecipeSearch_14EI\Installr\1.bin\NP14EISB.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.69: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Users\RICHARD\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/12/03 19:05:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/11/11 10:41:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/26 12:51:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/17 19:55:55 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}: C:\Users\RICHARD\Program Files\DNA [2011/07/25 11:17:24 | 000,000,000 | ---D | M]
[2009/08/30 23:47:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\RICHARD\AppData\Roaming\Mozilla\Extensions
[2012/06/13 22:38:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\RICHARD\AppData\Roaming\Mozilla\Firefox\Profiles\5o4wx3be.default\extensions
[2010/12/29 13:42:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\RICHARD\AppData\Roaming\Mozilla\Firefox\Profiles\5o4wx3be.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/02/08 21:44:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2008/12/01 20:01:35 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/02/13 21:31:10 | 000,000,000 | ---D | M] (Peer2Peer-EN Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\{da21bd13-ca22-42e3-a071-98f08f1ca1e7}
[2009/07/30 23:24:36 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2009/07/30 23:24:36 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2009/07/30 23:24:36 | 000,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/02/08 16:03:38 | 000,002,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2009/07/30 23:24:36 | 000,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2012/06/13 19:51:32 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKU\S-1-5-21-699681126-2153449771-921346542-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-699681126-2153449771-921346542-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-699681126-2153449771-921346542-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-699681126-2153449771-921346542-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\NPJPI150_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Reg Error: Key error. - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Reg Error: Key error. - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Reg Error: Key error. File not found
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D}
http://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20110811073132 (PhotoboxPhotowaysUploader5 Control)
O16 - DPF: {71057C18-0507-4747-86BC-E11CE7512C5F}
https://register.btinternet.com/templates/btmailcontrol013.cab (mailhelper Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3}
https://register.btinternet.com/templates/btwebcontrol028.cab (webhelper Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19A29F77-385A-4EF3-86EA-8A2855C085FB}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DB5E5863-2C97-4681-9E54-9A87967ABF4F}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\RICHARD\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\RICHARD\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/11/02 21:00:00 | 000,000,043 | R--- | M] () - D:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (autocheck lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
CREATERESTOREPOINT
System Restore Service not available.
========== Files/Folders - Created Within 30 Days ==========
[2012/06/14 07:38:24 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\RICHARD\Desktop\OTL.exe
[2012/06/13 22:05:26 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\RICHARD\Desktop\aswMBR.exe
[2012/06/13 21:33:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Motive
[2012/06/13 20:03:17 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\temp
[2012/06/13 19:42:46 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/06/13 19:31:29 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/13 19:31:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/13 19:31:29 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/13 19:31:26 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/06/13 19:31:25 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/06/13 19:31:22 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/13 19:17:59 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{42D1F857-63E4-4D6E-8CA0-732BD8F3D92F}
[2012/06/13 04:40:36 | 000,000,000 | ---D | C] -- C:\FRST
[2012/06/10 05:55:55 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/06/10 02:10:48 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{0B4F8C43-AF5A-4695-8C0C-DC1F8A606B6C}
[2012/06/10 02:09:30 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{44429549-BE89-4F93-A852-D7454D0EA2F2}
[2012/06/09 09:29:43 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{3BDC7205-1821-45FD-AAB4-0B474F629019}
[2012/06/09 09:29:33 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{E05D646F-FEB2-49DE-8B44-A323E0C6FCF6}
[2012/06/09 09:29:23 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{C28E7BD7-FD88-4221-A013-EA84221E820B}
[2012/06/09 09:29:00 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{7AB0FF3C-6DB8-4A24-A7C6-A5E6824BEDF6}
[2012/06/08 10:26:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Trusteer
[2012/06/08 07:30:16 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{021DCF5B-2D1B-490E-97B0-5448FE125678}
[2012/06/08 07:30:06 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{79D6CC9E-9E4A-4084-97F9-2B625EE60EE1}
[2012/06/08 07:00:49 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{67AB61A9-5827-4BF5-A513-24B56D4298B3}
[2012/06/08 06:57:02 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{15236AB3-43EF-4CF6-A76A-D49FEC366118}
[2012/06/07 08:18:50 | 000,000,000 | ---D | C] -- C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2012/06/07 07:55:07 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{462A28A8-0FFE-4BF9-AC12-DD18BA0816D8}
[2012/06/07 07:54:46 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{D9A44FF3-2672-4148-B14A-DEE3B6C9D857}
[2012/06/06 19:38:54 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{2317BB19-901B-49C0-9CEF-DEF4BE92D65E}
[2012/06/06 19:38:32 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{7A7123D6-D01F-4DB3-A48F-D100808A382C}
[2012/06/06 08:06:41 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2012/06/06 07:01:18 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{B16D733F-0910-4052-A14A-78EF47BF0B5E}
[2012/06/06 06:59:29 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{B05AEDC2-DFC4-44AF-BF1D-E8E260B1AEF3}
[2012/06/05 18:39:02 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{B2B5EE89-0A98-4148-909D-79DD5F63DD72}
[2012/06/05 18:38:30 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{7BA680D6-7CEC-46EB-89D2-FEE8FD0440F6}
[2012/06/04 08:59:28 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{394C2596-33B1-4120-B629-A7498F419DC0}
[2012/06/04 08:58:46 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{BF1105F9-AFBA-438F-A645-2A91D7552FFA}
[2012/06/03 10:40:22 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{41203A1D-BC27-4EE3-93FE-7ED1BB94EFC4}
[2012/06/03 10:40:08 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{388CBD64-6C5A-41ED-BE57-F688EDA7DB7A}
[2012/06/03 10:39:58 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{403FAB59-AA07-43D3-BDA3-E7490DFAE56F}
[2012/06/03 10:39:34 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{91FF9B84-277F-4801-B83C-B001BD3BF138}
[2012/06/02 11:34:39 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{5F3BA706-6E09-4853-8698-1CFC7891CA4A}
[2012/06/02 11:34:23 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{3B8697ED-C9E5-4B86-B324-44F48F36804F}
[2012/06/01 08:51:42 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{BC0AA1DD-3277-46D2-B755-99892452DCD4}
[2012/06/01 08:51:32 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{6E9F1F48-363C-425C-8115-1058FA00985B}
[2012/06/01 08:51:22 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{A5F215C1-4ABD-49C5-BAB9-40F801DF0B19}
[2012/06/01 08:51:00 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{B57A46C1-A545-4B64-86F0-C74333943DB6}
[2012/05/31 09:57:40 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{EAB274DF-40CF-489C-95E6-82C53A2EE067}
[2012/05/31 09:57:30 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{3F10E74B-E7AF-41DE-8895-532B1F6E5B97}
[2012/05/31 09:57:20 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{3A3E836D-D374-4028-B27A-7CEBD7FB1DD6}
[2012/05/31 09:56:58 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{5184CE15-E133-4E6B-9852-8D9D9CBF4187}
[2012/05/30 10:22:58 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{FA50D60E-BA5A-44A2-8F9D-671C7A174AC6}
[2012/05/30 10:22:35 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{A159DB8B-01B4-4E53-AFE6-1F9835C5FED0}
[2012/05/29 22:22:10 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{2BEBE1DD-F884-49B5-9273-00DF18AA0A71}
[2012/05/29 22:22:01 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{24CFB5C0-07E8-4CAA-B927-349F522D0137}
[2012/05/29 22:21:51 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{25D29C40-C889-425B-9839-C8760D702DB1}
[2012/05/29 22:21:31 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{B3B39591-4BB6-4446-A4EF-40D749E91946}
[2012/05/29 08:11:37 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{B9CAA521-CDE9-4B54-AAA8-6FE53D4D0EDC}
[2012/05/29 08:11:00 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{B5EBCFE6-653B-4EF5-9746-F2ABFD05FAEA}
[2012/05/28 11:34:05 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{E866A552-047D-4F29-BA5B-7A6D24C8CE02}
[2012/05/28 11:33:55 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{92FF98D8-8AE8-4E47-90A8-406A6B685D37}
[2012/05/28 11:33:44 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{BA37723D-D11B-4A92-B0B9-468369212781}
[2012/05/28 11:33:20 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{08D197C9-36D8-47E2-B25D-938607AF56B0}
[2012/05/27 18:06:00 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{148A8163-F6F4-4D93-B498-65A45772D18F}
[2012/05/27 18:05:50 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{07536455-410D-409D-8803-590E053F1C5B}
[2012/05/27 18:05:40 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{98D05E1A-0603-4B96-9DBD-81A496A9B046}
[2012/05/27 18:05:18 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{03B896DE-1983-4DA4-B2EB-3E657F4C7D26}
[2012/05/26 21:49:18 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{537DC9EC-04F6-4584-B5A5-6321EFC6E7D4}
[2012/05/26 21:49:08 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{9952CD01-14DE-44AE-8B3A-2A3AEDD9B057}
[2012/05/26 21:48:59 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{DD506170-D032-451B-BCE0-A80C6C4FD6DB}
[2012/05/26 21:48:38 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{713DDFED-9A0F-4577-89FA-FE4C73FBE4E4}
[2012/05/26 09:48:02 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{273A49BD-5B69-4CE1-BFFC-6667B54FC493}
[2012/05/26 09:47:52 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{24ADADF3-A53E-4261-8A8E-7C33833A97DD}
[2012/05/26 09:47:42 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{69617B7D-8BAD-410F-B1EF-4F3490E22EAC}
[2012/05/26 09:46:57 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{B663FED0-0A51-4D39-8A66-5A5ED780E8FD}
[2012/05/25 21:23:39 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{564D2C9B-5D18-45A1-93F1-A6A3D7828F77}
[2012/05/25 21:23:27 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{82FF9630-32FB-4572-AAFE-4B1F7CF55C79}
[2012/05/25 21:23:06 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{4B495A38-8437-408B-BC93-6D8A11A63936}
[2012/05/25 09:06:05 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{BD5682BB-92FA-425A-8FB8-E63D73A938BD}
[2012/05/25 09:05:55 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{901428D9-ADAA-4795-98D0-4ADA52CB2657}
[2012/05/25 09:05:46 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{2A5FBC0B-3AE0-43FB-9AEE-687C67E2D1E9}
[2012/05/25 09:05:25 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{88E0B2D4-904A-47BE-BFDF-245E01DDA68A}
[2012/05/24 09:41:00 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{57F3E7D3-AF3C-46E4-AF82-D026425922D5}
[2012/05/24 09:40:39 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{D14A6279-4D80-4648-A572-37D284F2B46F}
[2012/05/23 21:40:13 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{42784BD9-A9A7-40D1-A0E8-282005027248}
[2012/05/23 09:39:40 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{40D55D38-CFB9-4F78-90D8-CD61F3079415}
[2012/05/23 09:39:19 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{71022576-CAF1-47D8-B275-52C7674FDF47}
[2012/05/22 21:05:41 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{A98A3193-B8C3-48B4-A1A1-CE4AA2A94BE1}
[2012/05/22 21:05:32 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{C479D9F7-A0CB-4BAF-B898-9180A0459437}
[2012/05/22 08:19:06 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{69D99520-0EB7-4B85-83BC-F7A7B5910672}
[2012/05/21 07:45:49 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{6A39683F-8369-4C0F-8E56-7616200F1AC6}
[2012/05/21 07:44:42 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{32784477-FA69-4961-BD87-F8816F9DE8CA}
[2012/05/20 13:31:28 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{50CD02D5-C93D-40D2-8D33-21C8DEF6B6D8}
[2012/05/20 13:31:04 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{E6CCDAC7-8528-47A7-A4C8-7C377F196E19}
[2012/05/20 13:30:53 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{AEB0231E-158E-4168-B640-44089D721B98}
[2012/05/19 20:54:44 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{4FB09B3D-537C-49BB-A79A-3A540EDC0F22}
[2012/05/19 20:54:22 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{4A57BA20-4D88-4149-9CCD-842D422A8FD4}
[2012/05/19 07:38:00 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{A66FAD5F-198E-442C-8708-06CFF9704047}
[2012/05/19 07:37:51 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{00AFC822-2559-4CFB-BB1E-BF4F28A327F7}
[2012/05/19 07:37:41 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{B497C63F-DE8C-49B7-943A-50D1F6E9E845}
[2012/05/19 07:36:35 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{7C331E82-5F1D-47FC-8B3B-1B67DEFAE839}
[2012/05/18 09:34:15 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{2D60E71A-9AF2-44C7-BDB6-7A5EE98E01EB}
[2012/05/18 09:33:54 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{E8684E91-1300-4FEB-AC71-9E289B8F9118}
[2012/05/18 09:33:44 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{AB1EB80D-ABA5-4EB1-A464-92D7F79B6F9E}
[2012/05/18 09:33:33 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{478FA274-863C-47BC-B941-3EE00E30A639}
[2012/05/17 18:56:42 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{01999E72-43E5-4B77-B8F1-49ACA6AC4326}
[2012/05/17 06:56:07 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{46137EC1-A2CD-4185-A946-B6DED68DFD6F}
[2012/05/17 06:55:55 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{E2C16130-E0A2-472E-8B0C-2C7ED4F1F8AC}
[2012/05/17 06:55:45 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{C8DD4AF3-D434-430E-871A-41E40817EF75}
[2012/05/17 06:53:24 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{A9BCBEC0-E5FA-4D36-98F6-0760796513D4}
[2012/05/16 10:57:24 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{30B2D1CF-C484-4CA7-86C0-584542F483DA}
[2012/05/16 10:57:15 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{F2696559-D762-418B-9F97-7BBB3F2A39E5}
[2012/05/16 10:57:04 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{3DC2B634-D15C-416B-B656-4B500D8EA50C}
[2012/05/16 10:56:44 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{1778644D-E175-480A-9A45-130CDB381CDE}
[2012/05/15 22:56:19 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{F69CA708-2026-4F79-8CAF-23A6A1DD54A9}
[2012/05/15 22:56:09 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{9DE86B36-57F6-419D-BCF9-5D4BD3EFAB03}
[2012/05/15 22:55:47 | 000,000,000 | ---D | C] -- C:\Users\RICHARD\AppData\Local\{83ACEFBA-6037-42B8-9432-D10A10F6A3EF}
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/06/14 07:52:32 | 000,610,772 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/06/14 07:52:32 | 000,107,174 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/06/14 07:46:05 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/14 07:39:10 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\RICHARD\Desktop\OTL.exe
[2012/06/14 07:35:06 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/14 07:33:09 | 000,004,656 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/14 07:33:09 | 000,004,656 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/14 07:32:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/13 23:30:09 | 000,000,512 | ---- | M] () -- C:\Users\RICHARD\Desktop\MBR.dat
[2012/06/13 22:06:43 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\RICHARD\Desktop\aswMBR.exe
[2012/06/13 21:27:12 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/13 19:51:32 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/06/10 10:15:54 | 000,002,243 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/06/10 10:10:53 | 000,000,680 | ---- | M] () -- C:\Users\RICHARD\AppData\Local\d3d9caps.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/13 23:30:09 | 000,000,512 | ---- | C] () -- C:\Users\RICHARD\Desktop\MBR.dat
[2012/06/13 19:31:29 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/13 19:31:29 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/13 19:31:29 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/13 19:31:29 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/13 19:31:29 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/10 05:56:19 | 000,001,826 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/06/06 16:23:46 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/20 11:27:51 | 000,454,656 | ---- | C] () -- C:\Windows\System32\PaintX.dll
[2012/02/08 16:03:53 | 000,001,594 | ---- | C] () -- C:\ProgramData\repository.xml
[2010/10/15 10:37:44 | 000,000,245 | ---- | C] () -- C:\Windows\Brpfx04a.ini
[2010/10/15 10:37:44 | 000,000,094 | ---- | C] () -- C:\Windows\brpcfx.ini
[2010/10/15 10:37:12 | 000,000,419 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2010/10/15 10:37:12 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2010/10/15 10:36:00 | 000,000,050 | ---- | C] () -- C:\Windows\System32\bridf08a.dat
[2010/10/15 10:34:01 | 000,106,496 | ---- | C] () -- C:\Windows\System32\BrMuSNMP.dll
[2010/10/15 10:34:01 | 000,000,066 | ---- | C] () -- C:\Windows\Brfaxrx.ini
[2010/10/15 10:34:00 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat
[2010/10/15 10:31:27 | 000,032,148 | ---- | C] () -- C:\Windows\maxlink.ini
========== LOP Check ==========
[2008/12/03 12:45:54 | 000,000,000 | ---D | M] -- C:\Users\charlotte\AppData\Roaming\Canon
[2012/05/07 17:06:45 | 000,000,000 | ---D | M] -- C:\Users\charlotte\AppData\Roaming\MyHeritage
[2012/02/08 20:56:32 | 000,000,000 | ---D | M] -- C:\Users\charlotte\AppData\Roaming\PerformerSoft
[2009/08/30 23:54:40 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\Auslogics
[2008/11/25 23:21:29 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\Babylon
[2010/12/30 00:24:01 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\BitTorrent
[2008/08/02 18:25:11 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\Canon
[2011/08/23 10:54:26 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\DNA
[2008/12/14 19:05:46 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\Leadertech
[2010/11/11 10:51:46 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\Nokia
[2010/11/11 10:51:49 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\PC Suite
[2012/02/08 21:43:35 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\PerformerSoft
[2010/10/21 06:50:01 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\ScanSoft
[2007/12/26 18:26:38 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\SlySoft
[2012/01/19 12:05:02 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\SmartDraw
[2007/12/22 16:42:00 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\TomTom
[2010/11/17 09:26:13 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\Windows Live Writer
[2010/10/22 08:25:01 | 000,000,000 | ---D | M] -- C:\Users\RICHARD\AppData\Roaming\Zeon
[2008/12/23 22:11:26 | 000,000,000 | ---D | M] -- C:\Users\SUE\AppData\Roaming\Auslogics
[2008/10/20 13:44:37 | 000,000,000 | ---D | M] -- C:\Users\SUE\AppData\Roaming\Canon
[2008/05/16 00:19:17 | 000,000,000 | ---D | M] -- C:\Users\SUE\AppData\Roaming\DNA
[2008/12/08 13:42:43 | 000,000,000 | ---D | M] -- C:\Users\SUE\AppData\Roaming\Leadertech
[2012/02/22 08:30:48 | 000,000,000 | ---D | M] -- C:\Users\SUE\AppData\Roaming\MyHeritage
[2012/02/08 21:43:35 | 000,000,000 | ---D | M] -- C:\Users\SUE\AppData\Roaming\PerformerSoft
[2009/04/11 16:50:05 | 000,000,000 | ---D | M] -- C:\Users\SUE\AppData\Roaming\ScanSoft
[2007/12/22 19:28:24 | 000,000,000 | ---D | M] -- C:\Users\SUE\AppData\Roaming\TomTom
[2012/06/13 23:33:22 | 000,032,656 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========