My wife's Vaio running Vista got infected with Sirefef. I need some help getting rid of it. After reading some posts here, I downloaded and ran FRST. The txt is below:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 16-07-2012 01
Ran by Carmela at 21-07-2012 21:53:48
Running from G:\
Service Pack 2 (X86) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-21 21:44 - 2012-07-21 21:45 - 00000000 ____D C:\Users\Carmela\AppData\Local\{BB4DD753-D1A2-11E1-8270-B8AC6F996F26}
2012-07-19 22:19 - 2012-07-19 22:19 - 00019709 ____A C:\Users\Carmela\Desktop\FRST.txt
2012-07-19 22:07 - 2012-07-21 21:53 - 00000000 ____D C:\FRST
2012-07-19 22:07 - 2012-07-19 21:58 - 00891630 ____A (Farbar) C:\Users\Carmela\Desktop\FRST.exe
2012-07-19 21:28 - 2011-07-16 22:21 - 00302592 ____A C:\Users\Carmela\Desktop\gmer.exe
2012-07-19 21:25 - 2012-07-19 21:25 - 00185191 ____A C:\Users\Carmela\Downloads\corfmfrg.exe.part
2012-07-19 21:25 - 2012-07-19 21:25 - 00000000 ____A C:\Users\Carmela\Downloads\corfmfrg.exe
2012-07-19 13:06 - 2012-07-19 13:06 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-19 13:03 - 2012-07-19 13:03 - 10288512 ____A (Microsoft Corporation) C:\Users\Carmela\Desktop\mseinstall.exe
2012-07-19 12:21 - 2012-07-19 12:22 - 00000000 ____D C:\Users\All Users\036DFF98169F4CFDB2D1B9DFE56C34E5
2012-07-19 12:09 - 2012-07-19 12:09 - 10288512 ____A (Microsoft Corporation) C:\Users\Carmela\Downloads\mseinstall.exe
2012-07-19 09:08 - 2012-07-19 09:09 - 00000000 ____D C:\Users\All Users\036DFF98169F4CFDB2D1B9DF2F3B707C
2012-07-19 09:07 - 2012-07-19 09:07 - 00435712 ____A C:\Users\Carmela\AppData\Roaming\wolpl.dll
2012-07-19 09:07 - 2012-07-19 09:06 - 00139264 ____A C:\Users\Carmela\AppData\Roaming\pscsas.dll
2012-07-17 18:33 - 2012-07-17 18:33 - 00000872 ____A C:\Users\Public\Desktop\Acrobat_com.lnk
2012-07-17 18:32 - 2012-07-17 18:32 - 00000000 ____D C:\Users\Carmela\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2012-07-11 14:07 - 2012-06-13 09:40 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 14:03 - 2012-06-02 05:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 14:03 - 2012-06-02 04:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 14:03 - 2012-06-02 04:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 14:03 - 2012-06-02 04:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 14:03 - 2012-06-02 04:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 14:03 - 2012-06-02 04:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 14:03 - 2012-06-02 04:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 14:03 - 2012-06-02 04:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 14:03 - 2012-06-02 04:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 14:03 - 2012-06-02 04:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 14:03 - 2012-06-02 04:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 14:03 - 2012-06-02 04:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 14:03 - 2012-06-02 04:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 14:03 - 2012-06-02 04:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 07:41 - 2012-06-08 13:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 07:41 - 2012-06-05 12:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 07:41 - 2012-06-05 12:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 07:41 - 2012-06-04 11:26 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 07:41 - 2012-06-01 20:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 07:41 - 2012-06-01 20:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-01 09:38 - 2012-07-19 13:00 - 00000528 ____A C:\Windows\System32\debug.log
2012-07-01 09:38 - 2012-07-19 10:58 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1001UA.job
2012-07-01 09:38 - 2012-07-18 17:50 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1001Core.job
2012-07-01 09:37 - 2012-07-01 09:38 - 00000000 ____D C:\Users\Carmela\AppData\Local\Facebook
2012-06-30 08:04 - 2012-06-30 08:04 - 00097593 ____A C:\test.xml
2012-06-23 07:04 - 2012-06-02 18:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-23 07:04 - 2012-06-02 18:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-23 07:04 - 2012-06-02 18:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-23 07:04 - 2012-06-02 18:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-23 07:03 - 2012-06-02 18:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-23 07:03 - 2012-06-02 18:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-23 07:03 - 2012-06-02 18:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-23 07:03 - 2012-06-02 15:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-23 07:03 - 2012-06-02 15:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-22 20:55 - 2012-06-22 20:55 - 00000000 ____D C:\Users\Carmela\AppData\Local\Macromedia
============ 3 Months Modified Files ========================
2012-07-21 21:53 - 2011-02-18 13:18 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-21 21:53 - 2009-09-18 15:10 - 00279552 ____A C:\Windows\System32\services.exe
2012-07-21 21:53 - 2006-11-02 09:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-21 21:53 - 2006-11-02 08:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-21 21:53 - 2006-11-02 08:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-19 22:19 - 2012-07-19 22:19 - 00019709 ____A C:\Users\Carmela\Desktop\FRST.txt
2012-07-19 21:58 - 2012-07-19 22:07 - 00891630 ____A (Farbar) C:\Users\Carmela\Desktop\FRST.exe
2012-07-19 21:25 - 2012-07-19 21:25 - 00185191 ____A C:\Users\Carmela\Downloads\corfmfrg.exe.part
2012-07-19 21:25 - 2012-07-19 21:25 - 00000000 ____A C:\Users\Carmela\Downloads\corfmfrg.exe
2012-07-19 20:50 - 2006-11-02 09:01 - 00032648 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-19 14:45 - 2012-04-08 21:17 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-19 13:53 - 2011-02-02 23:37 - 00002198 ____A C:\Windows\epplauncher.mif
2012-07-19 13:41 - 2011-11-05 07:36 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1000UA.job
2012-07-19 13:07 - 2008-09-07 01:39 - 01406946 ____A C:\Windows\WindowsUpdate.log
2012-07-19 13:06 - 2006-11-02 06:33 - 00721590 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-19 13:03 - 2012-07-19 13:03 - 10288512 ____A (Microsoft Corporation) C:\Users\Carmela\Desktop\mseinstall.exe
2012-07-19 13:00 - 2012-07-01 09:38 - 00000528 ____A C:\Windows\System32\debug.log
2012-07-19 13:00 - 2011-02-18 13:18 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-19 12:17 - 2008-04-18 14:31 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-07-19 12:09 - 2012-07-19 12:09 - 10288512 ____A (Microsoft Corporation) C:\Users\Carmela\Downloads\mseinstall.exe
2012-07-19 10:58 - 2012-07-01 09:38 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1001UA.job
2012-07-19 09:07 - 2012-07-19 09:07 - 00435712 ____A C:\Users\Carmela\AppData\Roaming\wolpl.dll
2012-07-19 09:06 - 2012-07-19 09:07 - 00139264 ____A C:\Users\Carmela\AppData\Roaming\pscsas.dll
2012-07-19 07:49 - 2012-05-26 16:24 - 00000680 ____A C:\Users\Carmela\AppData\Local\d3d9caps.dat
2012-07-19 07:49 - 2011-11-05 07:36 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1000Core.job
2012-07-18 17:50 - 2012-07-01 09:38 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1001Core.job
2012-07-17 18:33 - 2012-07-17 18:33 - 00000872 ____A C:\Users\Public\Desktop\Acrobat_com.lnk
2012-07-12 10:52 - 2012-04-08 21:17 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-12 10:52 - 2011-05-19 10:40 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-11 19:23 - 2006-11-02 08:47 - 00385048 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 14:04 - 2006-11-02 06:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-30 08:04 - 2012-06-30 08:04 - 00097593 ____A C:\test.xml
2012-06-16 08:10 - 2012-06-16 08:10 - 00001664 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-13 09:40 - 2012-07-11 14:07 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 13:47 - 2012-07-11 07:41 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 12:47 - 2012-07-11 07:41 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 12:47 - 2012-07-11 07:41 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 11:26 - 2012-07-11 07:41 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 18:19 - 2012-06-23 07:04 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 18:19 - 2012-06-23 07:04 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 18:19 - 2012-06-23 07:04 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 18:19 - 2012-06-23 07:03 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 18:19 - 2012-06-23 07:03 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 18:12 - 2012-06-23 07:04 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 18:12 - 2012-06-23 07:03 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-23 07:03 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:12 - 2012-06-23 07:03 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 05:07 - 2012-07-11 14:03 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:43 - 2012-07-11 14:03 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:33 - 2012-07-11 14:03 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:26 - 2012-07-11 14:03 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:25 - 2012-07-11 14:03 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:25 - 2012-07-11 14:03 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:23 - 2012-07-11 14:03 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:21 - 2012-07-11 14:03 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:20 - 2012-07-11 14:03 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:19 - 2012-07-11 14:03 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 04:19 - 2012-07-11 14:03 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 04:17 - 2012-07-11 14:03 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 04:16 - 2012-07-11 14:03 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 04:14 - 2012-07-11 14:03 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 20:04 - 2012-07-11 07:41 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:03 - 2012-07-11 07:41 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-31 22:21 - 2012-05-25 07:37 - 00097080 ____A C:\Users\Carmela\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-31 21:32 - 2010-11-12 20:41 - 00000022 ____A C:\Windows\Model.txt
2012-05-31 21:32 - 2010-11-12 20:41 - 00000000 ____A C:\Windows\Model.log
2012-05-31 21:32 - 2008-04-18 16:17 - 00083308 ____A C:\Windows\DPINST.LOG
2012-05-31 20:48 - 2012-05-31 20:48 - 00559616 ____A C:\seatoolsforwindowssetup.msi
2012-05-31 20:44 - 2012-05-31 20:43 - 06503288 ____A C:\Users\Carmela\Downloads\SOAOTH-88888887-1060.EXE
2012-05-27 22:04 - 2012-05-27 22:05 - 00174024 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-05-27 22:04 - 2012-05-27 22:05 - 00174024 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-05-26 12:41 - 2011-09-03 00:33 - 00000790 ____A C:\Users\Carmela\Desktop\AngryBirds - Shortcut.lnk
2012-05-25 23:07 - 2012-05-25 23:07 - 00010214 ____A C:\bootex 2.log
2012-05-25 07:37 - 2012-05-25 07:37 - 00000020 ___SH C:\Users\Carmela\ntuser.ini
2012-05-24 22:21 - 2006-11-02 06:22 - 54788096 ____A C:\Windows\System32\config\software_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 40108032 ____A C:\Windows\System32\config\components_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 29097984 ____A C:\Windows\System32\config\system_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 00524288 ____A C:\Windows\System32\config\default_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-05-23 14:01 - 2009-02-23 10:58 - 00006324 ____A C:\Users\Maricar\AppData\Local\d3d9caps.dat
2012-05-19 13:10 - 2012-05-19 13:10 - 00001726 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-12 14:00 - 2011-03-09 12:45 - 00001854 ____A C:\Users\Public\Desktop\Safari.lnk
2012-05-11 18:48 - 2008-01-20 22:47 - 00722836 ____A C:\Windows\PFRO.log
2012-05-03 22:29 - 2012-05-03 22:29 - 00001854 ____A C:\Users\Public\Desktop\WinZip.lnk
2012-05-01 10:03 - 2012-06-13 19:54 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-23 12:00 - 2012-06-13 19:54 - 00984064 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 12:00 - 2012-06-13 19:54 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 12:00 - 2012-06-13 19:54 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\@
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\L
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\n
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\00000001.@
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\80000000.@
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\800000cb.@
ZeroAccess:
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\@
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\L
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\n
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\00000001.@
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\80000000.@
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\800000cb.@
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-09-18 15:10] - [2012-07-21 21:53] - 0279552 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\Windows\System32\services.exe IS INFECTED. <===== ATTENTION!
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 38%
Total physical RAM: 3061.69 MB
Available physical RAM: 1889.7 MB
Total Pagefile: 6325.64 MB
Available Pagefile: 5206.21 MB
Total Virtual: 2047.88 MB
Available Virtual: 1958.73 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:225.11 GB) (Free:127.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
5 Drive g: () (Removable) (Total:1.9 GB) (Free:1.88 GB) FAT
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
==========================================================
Last Boot: 2012-07-19 13:05
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 16-07-2012 01
Ran by Carmela at 21-07-2012 21:53:48
Running from G:\
Service Pack 2 (X86) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-21 21:44 - 2012-07-21 21:45 - 00000000 ____D C:\Users\Carmela\AppData\Local\{BB4DD753-D1A2-11E1-8270-B8AC6F996F26}
2012-07-19 22:19 - 2012-07-19 22:19 - 00019709 ____A C:\Users\Carmela\Desktop\FRST.txt
2012-07-19 22:07 - 2012-07-21 21:53 - 00000000 ____D C:\FRST
2012-07-19 22:07 - 2012-07-19 21:58 - 00891630 ____A (Farbar) C:\Users\Carmela\Desktop\FRST.exe
2012-07-19 21:28 - 2011-07-16 22:21 - 00302592 ____A C:\Users\Carmela\Desktop\gmer.exe
2012-07-19 21:25 - 2012-07-19 21:25 - 00185191 ____A C:\Users\Carmela\Downloads\corfmfrg.exe.part
2012-07-19 21:25 - 2012-07-19 21:25 - 00000000 ____A C:\Users\Carmela\Downloads\corfmfrg.exe
2012-07-19 13:06 - 2012-07-19 13:06 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-19 13:03 - 2012-07-19 13:03 - 10288512 ____A (Microsoft Corporation) C:\Users\Carmela\Desktop\mseinstall.exe
2012-07-19 12:21 - 2012-07-19 12:22 - 00000000 ____D C:\Users\All Users\036DFF98169F4CFDB2D1B9DFE56C34E5
2012-07-19 12:09 - 2012-07-19 12:09 - 10288512 ____A (Microsoft Corporation) C:\Users\Carmela\Downloads\mseinstall.exe
2012-07-19 09:08 - 2012-07-19 09:09 - 00000000 ____D C:\Users\All Users\036DFF98169F4CFDB2D1B9DF2F3B707C
2012-07-19 09:07 - 2012-07-19 09:07 - 00435712 ____A C:\Users\Carmela\AppData\Roaming\wolpl.dll
2012-07-19 09:07 - 2012-07-19 09:06 - 00139264 ____A C:\Users\Carmela\AppData\Roaming\pscsas.dll
2012-07-17 18:33 - 2012-07-17 18:33 - 00000872 ____A C:\Users\Public\Desktop\Acrobat_com.lnk
2012-07-17 18:32 - 2012-07-17 18:32 - 00000000 ____D C:\Users\Carmela\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2012-07-11 14:07 - 2012-06-13 09:40 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 14:03 - 2012-06-02 05:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 14:03 - 2012-06-02 04:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 14:03 - 2012-06-02 04:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 14:03 - 2012-06-02 04:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 14:03 - 2012-06-02 04:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 14:03 - 2012-06-02 04:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 14:03 - 2012-06-02 04:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 14:03 - 2012-06-02 04:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 14:03 - 2012-06-02 04:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 14:03 - 2012-06-02 04:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 14:03 - 2012-06-02 04:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 14:03 - 2012-06-02 04:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 14:03 - 2012-06-02 04:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 14:03 - 2012-06-02 04:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 07:41 - 2012-06-08 13:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 07:41 - 2012-06-05 12:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 07:41 - 2012-06-05 12:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 07:41 - 2012-06-04 11:26 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 07:41 - 2012-06-01 20:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 07:41 - 2012-06-01 20:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-01 09:38 - 2012-07-19 13:00 - 00000528 ____A C:\Windows\System32\debug.log
2012-07-01 09:38 - 2012-07-19 10:58 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1001UA.job
2012-07-01 09:38 - 2012-07-18 17:50 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1001Core.job
2012-07-01 09:37 - 2012-07-01 09:38 - 00000000 ____D C:\Users\Carmela\AppData\Local\Facebook
2012-06-30 08:04 - 2012-06-30 08:04 - 00097593 ____A C:\test.xml
2012-06-23 07:04 - 2012-06-02 18:19 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-23 07:04 - 2012-06-02 18:19 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-23 07:04 - 2012-06-02 18:19 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-23 07:04 - 2012-06-02 18:12 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-23 07:03 - 2012-06-02 18:19 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-23 07:03 - 2012-06-02 18:19 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-23 07:03 - 2012-06-02 18:12 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-23 07:03 - 2012-06-02 15:19 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-23 07:03 - 2012-06-02 15:12 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-22 20:55 - 2012-06-22 20:55 - 00000000 ____D C:\Users\Carmela\AppData\Local\Macromedia
============ 3 Months Modified Files ========================
2012-07-21 21:53 - 2011-02-18 13:18 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-21 21:53 - 2009-09-18 15:10 - 00279552 ____A C:\Windows\System32\services.exe
2012-07-21 21:53 - 2006-11-02 09:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-21 21:53 - 2006-11-02 08:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-21 21:53 - 2006-11-02 08:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-19 22:19 - 2012-07-19 22:19 - 00019709 ____A C:\Users\Carmela\Desktop\FRST.txt
2012-07-19 21:58 - 2012-07-19 22:07 - 00891630 ____A (Farbar) C:\Users\Carmela\Desktop\FRST.exe
2012-07-19 21:25 - 2012-07-19 21:25 - 00185191 ____A C:\Users\Carmela\Downloads\corfmfrg.exe.part
2012-07-19 21:25 - 2012-07-19 21:25 - 00000000 ____A C:\Users\Carmela\Downloads\corfmfrg.exe
2012-07-19 20:50 - 2006-11-02 09:01 - 00032648 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-19 14:45 - 2012-04-08 21:17 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-19 13:53 - 2011-02-02 23:37 - 00002198 ____A C:\Windows\epplauncher.mif
2012-07-19 13:41 - 2011-11-05 07:36 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1000UA.job
2012-07-19 13:07 - 2008-09-07 01:39 - 01406946 ____A C:\Windows\WindowsUpdate.log
2012-07-19 13:06 - 2006-11-02 06:33 - 00721590 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-19 13:03 - 2012-07-19 13:03 - 10288512 ____A (Microsoft Corporation) C:\Users\Carmela\Desktop\mseinstall.exe
2012-07-19 13:00 - 2012-07-01 09:38 - 00000528 ____A C:\Windows\System32\debug.log
2012-07-19 13:00 - 2011-02-18 13:18 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-19 12:17 - 2008-04-18 14:31 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-07-19 12:09 - 2012-07-19 12:09 - 10288512 ____A (Microsoft Corporation) C:\Users\Carmela\Downloads\mseinstall.exe
2012-07-19 10:58 - 2012-07-01 09:38 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1001UA.job
2012-07-19 09:07 - 2012-07-19 09:07 - 00435712 ____A C:\Users\Carmela\AppData\Roaming\wolpl.dll
2012-07-19 09:06 - 2012-07-19 09:07 - 00139264 ____A C:\Users\Carmela\AppData\Roaming\pscsas.dll
2012-07-19 07:49 - 2012-05-26 16:24 - 00000680 ____A C:\Users\Carmela\AppData\Local\d3d9caps.dat
2012-07-19 07:49 - 2011-11-05 07:36 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1000Core.job
2012-07-18 17:50 - 2012-07-01 09:38 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2657921693-359309509-2016911747-1001Core.job
2012-07-17 18:33 - 2012-07-17 18:33 - 00000872 ____A C:\Users\Public\Desktop\Acrobat_com.lnk
2012-07-12 10:52 - 2012-04-08 21:17 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-12 10:52 - 2011-05-19 10:40 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-11 19:23 - 2006-11-02 08:47 - 00385048 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 14:04 - 2006-11-02 06:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-30 08:04 - 2012-06-30 08:04 - 00097593 ____A C:\test.xml
2012-06-16 08:10 - 2012-06-16 08:10 - 00001664 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-13 09:40 - 2012-07-11 14:07 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 13:47 - 2012-07-11 07:41 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 12:47 - 2012-07-11 07:41 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 12:47 - 2012-07-11 07:41 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 11:26 - 2012-07-11 07:41 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 18:19 - 2012-06-23 07:04 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 18:19 - 2012-06-23 07:04 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 18:19 - 2012-06-23 07:04 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 18:19 - 2012-06-23 07:03 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 18:19 - 2012-06-23 07:03 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 18:12 - 2012-06-23 07:04 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 18:12 - 2012-06-23 07:03 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-23 07:03 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:12 - 2012-06-23 07:03 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 05:07 - 2012-07-11 14:03 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:43 - 2012-07-11 14:03 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:33 - 2012-07-11 14:03 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:26 - 2012-07-11 14:03 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:25 - 2012-07-11 14:03 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:25 - 2012-07-11 14:03 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:23 - 2012-07-11 14:03 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:21 - 2012-07-11 14:03 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:20 - 2012-07-11 14:03 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:19 - 2012-07-11 14:03 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 04:19 - 2012-07-11 14:03 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 04:17 - 2012-07-11 14:03 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 04:16 - 2012-07-11 14:03 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 04:14 - 2012-07-11 14:03 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 20:04 - 2012-07-11 07:41 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 20:03 - 2012-07-11 07:41 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-31 22:21 - 2012-05-25 07:37 - 00097080 ____A C:\Users\Carmela\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-31 21:32 - 2010-11-12 20:41 - 00000022 ____A C:\Windows\Model.txt
2012-05-31 21:32 - 2010-11-12 20:41 - 00000000 ____A C:\Windows\Model.log
2012-05-31 21:32 - 2008-04-18 16:17 - 00083308 ____A C:\Windows\DPINST.LOG
2012-05-31 20:48 - 2012-05-31 20:48 - 00559616 ____A C:\seatoolsforwindowssetup.msi
2012-05-31 20:44 - 2012-05-31 20:43 - 06503288 ____A C:\Users\Carmela\Downloads\SOAOTH-88888887-1060.EXE
2012-05-27 22:04 - 2012-05-27 22:05 - 00174024 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-05-27 22:04 - 2012-05-27 22:05 - 00174024 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-05-26 12:41 - 2011-09-03 00:33 - 00000790 ____A C:\Users\Carmela\Desktop\AngryBirds - Shortcut.lnk
2012-05-25 23:07 - 2012-05-25 23:07 - 00010214 ____A C:\bootex 2.log
2012-05-25 07:37 - 2012-05-25 07:37 - 00000020 ___SH C:\Users\Carmela\ntuser.ini
2012-05-24 22:21 - 2006-11-02 06:22 - 54788096 ____A C:\Windows\System32\config\software_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 40108032 ____A C:\Windows\System32\config\components_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 29097984 ____A C:\Windows\System32\config\system_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 00524288 ____A C:\Windows\System32\config\default_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-05-24 22:21 - 2006-11-02 06:22 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-05-23 14:01 - 2009-02-23 10:58 - 00006324 ____A C:\Users\Maricar\AppData\Local\d3d9caps.dat
2012-05-19 13:10 - 2012-05-19 13:10 - 00001726 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-12 14:00 - 2011-03-09 12:45 - 00001854 ____A C:\Users\Public\Desktop\Safari.lnk
2012-05-11 18:48 - 2008-01-20 22:47 - 00722836 ____A C:\Windows\PFRO.log
2012-05-03 22:29 - 2012-05-03 22:29 - 00001854 ____A C:\Users\Public\Desktop\WinZip.lnk
2012-05-01 10:03 - 2012-06-13 19:54 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-23 12:00 - 2012-06-13 19:54 - 00984064 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 12:00 - 2012-06-13 19:54 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 12:00 - 2012-06-13 19:54 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\@
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\L
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\n
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\00000001.@
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\80000000.@
C:\Windows\Installer\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\800000cb.@
ZeroAccess:
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\@
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\L
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\n
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\00000001.@
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\80000000.@
C:\Users\Carmela\AppData\Local\{4e921e60-6908-8112-5f84-d2837c2fbdea}\U\800000cb.@
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-09-18 15:10] - [2012-07-21 21:53] - 0279552 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\Windows\System32\services.exe IS INFECTED. <===== ATTENTION!
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 38%
Total physical RAM: 3061.69 MB
Available physical RAM: 1889.7 MB
Total Pagefile: 6325.64 MB
Available Pagefile: 5206.21 MB
Total Virtual: 2047.88 MB
Available Virtual: 1958.73 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:225.11 GB) (Free:127.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
5 Drive g: () (Removable) (Total:1.9 GB) (Free:1.88 GB) FAT
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
==========================================================
Last Boot: 2012-07-19 13:05
======================= End Of Log ==========================