Scan result of Farbar Recovery Scan Tool Version: 22-08-2012
Ran by SYSTEM at 22-08-2012 12:36:19
Running from F:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2122536 2010-05-07] (Synaptics Incorporated)
HKLM\...\Run: [Stage Remote] C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe -Quiet [2034752 2011-08-08] ()
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10144288 2010-04-13] (Realtek Semiconductor)
HKLM\...\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe [3203440 2010-04-06] (Dell Inc.)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [415256 2010-07-29] (Intel Corporation)
HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel(R) Corporation)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [161304 2010-07-29] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2010-07-29] (Intel Corporation)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [2918656 2011-01-12] (ESET)
HKLM\...\Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup [483424 2012-02-01] ()
HKLM\...\Run: [AllShare Play] "C:\Program Files\Samsung\AllShare Play\utils\AllShare Play Launcher.exe" [399264 2012-07-09] (Samsung Electronics)
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()
HKLM-x32\...\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot [4144448 2010-11-10] (Dell, Inc.)
HKLM-x32\...\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35768 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup [2835443 2012-02-01] ()
HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [520330 2011-08-12] (Creative Technology Ltd)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKU\Default\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1475584 2010-11-20] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1475584 2010-11-20] (Microsoft Corporation)
HKU\Matt\...\Run: [AROReminder] C:\Program Files (x86)\ARO 2011\ARO.exe -rem [x]
HKU\Matt\...\Run: [Itibiti.exe] C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe [x]
HKU\Matt\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\Mcx1-MATT-PC\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [343552 2009-07-13] (Microsoft Corporation)
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-15] (Dell)
Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
AppInit_DLLs:
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Matt\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.1.01\AllShareFrameworkManagerDMS.exe [32768 2012-07-06] (Samsung)
3 EhttpSrv; "C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe" [42360 2011-01-12] (ESET)
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [810144 2011-01-12] (ESET)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] ()
2 N360; "C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\diMaster.dll" /prefetch:1 [309688 2012-04-12] (Symantec Corporation)
3 stllssvr; "C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe" [74392 2010-11-08] (MicroVision Development, Inc.)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2533400 2010-07-01] (Intel Corporation)
2 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [185856 2012-05-08] ()
========================== Drivers (Whitelisted) =============
1 BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20120803.001\BHDrvx64.sys [1161376 2012-08-03] (Symantec Corporation)
1 ccSet_N360; C:\Windows\system32\drivers\N360x64\0602010.005\ccSetx64.sys [167048 2011-11-04] (Symantec Corporation)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [170640 2010-12-21] (ESET)
1 eeCtrl; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-08-20] (Symantec Corporation)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [141264 2010-12-21] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [125296 2010-12-21] (ESET)
3 EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-08-21] (Symantec Corporation)
1 IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20120821.001\IDSvia64.sys [509088 2012-08-21] (Symantec Corporation)
3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20120821.002\ENG64.SYS [125600 2012-08-21] (Symantec Corporation)
3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20120821.002\EX64.SYS [2084000 2012-08-21] (Symantec Corporation)
1 SRTSP; C:\Windows\System32\Drivers\N360x64\0602010.005\SRTSP64.SYS [737912 2012-03-29] (Symantec Corporation)
1 SRTSPX; C:\Windows\system32\drivers\N360x64\0602010.005\SRTSPX64.SYS [37496 2012-03-29] (Symantec Corporation)
0 SymDS; C:\Windows\System32\drivers\N360x64\0602010.005\SYMDS64.SYS [451192 2011-08-16] (Symantec Corporation)
0 SymEFA; C:\Windows\System32\drivers\N360x64\0602010.005\SYMEFA64.SYS [1092728 2011-11-23] (Symantec Corporation)
3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2012-08-21] (Symantec Corporation)
1 SymIRON; C:\Windows\system32\drivers\N360x64\0602010.005\Ironx64.SYS [190072 2011-11-16] (Symantec Corporation)
1 SymNetS; C:\Windows\System32\Drivers\N360x64\0602010.005\SYMNETS.SYS [405624 2011-11-16] (Symantec Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-22 10:58 - 2012-08-22 10:58 - 00711240 ____A C:\Windows\isRS-000.tmp
2012-08-22 10:58 - 2012-08-22 10:58 - 00000000 ____D C:\Users\Matt\Application Data\U3
2012-08-22 10:58 - 2012-08-22 10:58 - 00000000 ____D C:\Users\Matt\AppData\Roaming\U3
2012-08-21 23:25 - 2012-08-21 23:25 - 00000000 ____D C:\Users\Matt\Local Settings\CrashDumps
2012-08-21 23:25 - 2012-08-21 23:25 - 00000000 ____D C:\Users\Matt\Local Settings\Application Data\CrashDumps
2012-08-21 23:25 - 2012-08-21 23:25 - 00000000 ____D C:\Users\Matt\AppData\Local\CrashDumps
2012-08-21 21:22 - 2012-08-21 21:31 - 00002422 ____A C:\Users\Public\Desktop\Norton Security Suite.lnk
2012-08-21 21:22 - 2012-08-21 21:31 - 00002422 ____A C:\Users\All Users\Desktop\Norton Security Suite.lnk
2012-08-21 21:22 - 2012-08-21 21:31 - 00000000 ____D C:\Windows\System32\Drivers\N360x64
2012-08-21 21:22 - 2012-08-21 21:22 - 00175736 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
2012-08-21 21:22 - 2012-08-21 21:22 - 00007488 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Users\Matt\My Documents\Symantec
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Users\Matt\Documents\Symantec
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Program Files\Symantec
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Program Files (x86)\Norton Security Suite
2012-08-21 21:20 - 2012-08-21 21:22 - 00000000 ____D C:\Users\All Users\Norton
2012-08-21 21:20 - 2012-08-21 21:22 - 00000000 ____D C:\Users\All Users\Application Data\Norton
2012-08-21 21:20 - 2012-08-21 21:20 - 00001361 ____A C:\Users\Matt\Desktop\Norton Installation Files.lnk
2012-08-21 21:20 - 2012-08-21 21:20 - 00000000 ____D C:\Users\Public\Downloads\Norton
2012-08-19 20:03 - 2012-08-19 20:03 - 00775304 ____A C:\Windows\Minidump\081912-17893-01.dmp
2012-08-19 13:31 - 2012-08-19 13:31 - 00775304 ____A C:\Windows\Minidump\081912-21855-01.dmp
2012-08-16 20:47 - 2012-08-22 10:58 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-16 20:47 - 2012-08-22 10:58 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-15 02:05 - 2012-07-06 15:07 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2012-08-15 02:04 - 2012-06-28 23:55 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-15 02:04 - 2012-06-28 23:09 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-15 02:04 - 2012-06-28 22:56 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-15 02:04 - 2012-06-28 22:49 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-15 02:04 - 2012-06-28 22:49 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-15 02:04 - 2012-06-28 22:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-15 02:04 - 2012-06-28 22:47 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-15 02:04 - 2012-06-28 22:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-15 02:04 - 2012-06-28 22:44 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-15 02:04 - 2012-06-28 22:43 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-15 02:04 - 2012-06-28 22:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-15 02:04 - 2012-06-28 22:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-15 02:04 - 2012-06-28 22:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-15 02:04 - 2012-06-28 22:35 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-15 02:04 - 2012-06-28 19:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-15 02:04 - 2012-06-28 19:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-15 02:04 - 2012-06-28 19:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-08-15 02:04 - 2012-06-28 19:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-15 02:04 - 2012-06-28 19:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-15 02:04 - 2012-06-28 19:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-15 02:04 - 2012-06-28 19:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-15 02:04 - 2012-06-28 19:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-15 02:04 - 2012-06-28 19:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-15 02:04 - 2012-06-28 19:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-15 02:04 - 2012-06-28 19:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-15 02:04 - 2012-06-28 19:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-15 02:04 - 2012-06-28 19:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-15 02:04 - 2012-06-28 18:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-15 01:46 - 2012-08-15 01:47 - 00000000 ____D C:\Users\All Users\Google
2012-08-15 01:46 - 2012-08-15 01:47 - 00000000 ____D C:\Users\All Users\Application Data\Google
2012-08-15 01:46 - 2012-08-15 01:46 - 00000000 ____D C:\Program Files\Google
2012-08-15 01:45 - 2012-08-15 01:45 - 01001264 ____A (Solid State Networks) C:\Users\Matt\Downloads\install_flashplayer11x32ax_gtba_chra_dy_aih.exe
2012-08-15 01:16 - 2012-07-18 13:15 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-15 01:16 - 2012-07-04 17:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-15 01:16 - 2012-07-04 17:13 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-08-15 01:16 - 2012-07-04 17:13 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-08-15 01:16 - 2012-07-04 16:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-08-15 01:16 - 2012-07-04 16:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-08-15 01:16 - 2012-05-14 00:26 - 00956928 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-15 01:16 - 2012-05-05 03:36 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2012-08-15 01:16 - 2012-05-05 02:46 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2012-08-15 01:16 - 2012-02-11 01:43 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2012-08-15 01:16 - 2012-02-11 01:36 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2012-08-15 01:16 - 2012-02-11 01:36 - 00067072 ____A (Microsoft Corporation) C:\Windows\splwow64.exe
2012-08-15 01:16 - 2012-02-11 00:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2012-08-12 00:49 - 2012-08-12 00:49 - 00029692 ____A (Orange Corporation) C:\Users\Matt\0.5266765910548641.exe
2012-08-11 09:46 - 2012-08-11 10:45 - 173327657 ____A C:\Users\Matt\Downloads\Rick Ross - God Forgives, I Don't (Deluxe Edition) 320 Kbps CBR.zip
2012-08-06 16:03 - 2012-08-06 16:03 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-08-06 13:57 - 2012-08-22 11:05 - 00000000 ___RD C:\Users\Matt\Dropbox
2012-08-06 13:57 - 2012-08-06 13:57 - 00001041 ____A C:\Users\Matt\Desktop\Dropbox.lnk
2012-08-06 13:53 - 2012-08-22 11:05 - 00000000 ____D C:\Users\Matt\Application Data\Dropbox
2012-08-06 13:53 - 2012-08-22 11:05 - 00000000 ____D C:\Users\Matt\AppData\Roaming\Dropbox
2012-08-06 13:53 - 2012-08-06 13:53 - 17798272 ____A (Dropbox, Inc.) C:\Users\Matt\Downloads\Dropbox 1.4.12.exe
2012-08-06 13:40 - 2012-08-22 11:06 - 00000000 ____D C:\AllShare Play
2012-08-06 13:40 - 2012-08-06 13:40 - 00000000 ____D C:\Upload
2012-08-06 13:40 - 2012-08-06 13:40 - 00000000 ____D C:\Program Files\Samsung
2012-08-06 13:39 - 2012-08-06 13:40 - 00000000 ___HD C:\Program Files\Zero G Registry
2012-08-06 13:39 - 2012-08-06 13:39 - 00000000 ___HD C:\Users\Matt\InstallAnywhere
2012-08-06 13:38 - 2012-08-06 13:39 - 82203456 ____A (Flexera Software) C:\Users\Matt\Downloads\AllSharePlay_Installer64.exe
2012-07-31 02:43 - 2012-07-31 02:43 - 00000000 ____D C:\Windows\Sun
2012-07-27 21:50 - 2012-08-02 13:47 - 09231560 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
============ 3 Months Modified Files ========================
2012-08-22 11:32 - 2011-06-16 03:41 - 01668151 ____A C:\Windows\WindowsUpdate.log
2012-08-22 11:26 - 2012-04-18 17:54 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-08-22 11:19 - 2012-07-17 12:21 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-22 11:09 - 2009-07-13 23:45 - 00021296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-22 11:09 - 2009-07-13 23:45 - 00021296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-22 11:07 - 2009-07-14 00:13 - 00780220 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-22 11:05 - 2011-09-18 10:56 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-22 11:04 - 2011-09-18 10:56 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-22 11:01 - 2011-09-22 19:14 - 00000258 _RASH C:\Users\All Users\ntuser.pol
2012-08-22 11:01 - 2011-09-22 19:14 - 00000258 _RASH C:\Users\All Users\Application Data\ntuser.pol
2012-08-22 11:00 - 2010-11-20 22:47 - 00048158 ____A C:\Windows\PFRO.log
2012-08-22 11:00 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-22 11:00 - 2009-07-13 23:51 - 00141677 ____A C:\Windows\setupact.log
2012-08-22 10:58 - 2012-08-22 10:58 - 00711240 ____A C:\Windows\isRS-000.tmp
2012-08-22 10:58 - 2012-08-16 20:47 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-22 10:58 - 2012-08-16 20:47 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-21 21:31 - 2012-08-21 21:22 - 00002422 ____A C:\Users\Public\Desktop\Norton Security Suite.lnk
2012-08-21 21:31 - 2012-08-21 21:22 - 00002422 ____A C:\Users\All Users\Desktop\Norton Security Suite.lnk
2012-08-21 21:31 - 2012-04-18 17:54 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-08-21 21:22 - 2012-08-21 21:22 - 00175736 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
2012-08-21 21:22 - 2012-08-21 21:22 - 00007488 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
2012-08-21 21:20 - 2012-08-21 21:20 - 00001361 ____A C:\Users\Matt\Desktop\Norton Installation Files.lnk
2012-08-21 21:18 - 2011-09-18 10:57 - 00002342 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-08-21 21:18 - 2011-09-18 10:57 - 00002342 ____A C:\Users\All Users\Desktop\Google Chrome.lnk
2012-08-19 20:03 - 2012-08-19 20:03 - 00775304 ____A C:\Windows\Minidump\081912-17893-01.dmp
2012-08-19 20:03 - 2012-03-03 02:45 - 530169526 ____A C:\Windows\MEMORY.DMP
2012-08-19 13:31 - 2012-08-19 13:31 - 00775304 ____A C:\Windows\Minidump\081912-21855-01.dmp
2012-08-15 06:31 - 2011-08-20 03:03 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2012-08-15 06:31 - 2011-08-20 03:03 - 00002021 ____A C:\Users\All Users\Desktop\Adobe Reader X.lnk
2012-08-15 02:25 - 2009-07-13 23:45 - 00319000 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-15 02:00 - 2012-01-09 13:39 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-15 01:46 - 2012-07-17 12:21 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-15 01:46 - 2011-09-22 11:58 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-15 01:45 - 2012-08-15 01:45 - 01001264 ____A (Solid State Networks) C:\Users\Matt\Downloads\install_flashplayer11x32ax_gtba_chra_dy_aih.exe
2012-08-12 00:49 - 2012-08-12 00:49 - 00029692 ____A (Orange Corporation) C:\Users\Matt\0.5266765910548641.exe
2012-08-11 10:45 - 2012-08-11 09:46 - 173327657 ____A C:\Users\Matt\Downloads\Rick Ross - God Forgives, I Don't (Deluxe Edition) 320 Kbps CBR.zip
2012-08-06 13:57 - 2012-08-06 13:57 - 00001041 ____A C:\Users\Matt\Desktop\Dropbox.lnk
2012-08-06 13:53 - 2012-08-06 13:53 - 17798272 ____A (Dropbox, Inc.) C:\Users\Matt\Downloads\Dropbox 1.4.12.exe
2012-08-06 13:39 - 2012-08-06 13:38 - 82203456 ____A (Flexera Software) C:\Users\Matt\Downloads\AllSharePlay_Installer64.exe
2012-08-02 13:47 - 2012-07-27 21:50 - 09231560 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-20 13:09 - 2012-03-02 22:52 - 00000047 ____A C:\Users\Matt\My Documents\light bulb text.txt
2012-07-20 13:09 - 2012-03-02 22:52 - 00000047 ____A C:\Users\Matt\Documents\light bulb text.txt
2012-07-18 13:15 - 2012-08-15 01:16 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-13 10:25 - 2009-07-14 00:08 - 00032566 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-06 15:07 - 2012-08-15 02:05 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2012-07-05 14:20 - 2011-08-17 13:31 - 00020480 ____A C:\Users\Matt\Local Settings\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-05 14:20 - 2011-08-17 13:31 - 00020480 ____A C:\Users\Matt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-05 14:20 - 2011-08-17 13:31 - 00020480 ____A C:\Users\Matt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-05 14:00 - 2012-07-07 12:17 - 38352868 ____A C:\Users\Matt\Desktop\05-28-12 Cold In Da House.wav
2012-07-05 14:00 - 2012-07-05 13:57 - 38352868 ____A C:\Users\Matt\Downloads\05-28-12 Cold In Da House.wav
2012-07-04 17:16 - 2012-08-15 01:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 17:13 - 2012-08-15 01:16 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 17:13 - 2012-08-15 01:16 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 16:16 - 2012-08-15 01:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 16:14 - 2012-08-15 01:16 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-07-03 12:46 - 2012-01-09 20:18 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-03 08:00 - 2012-07-03 08:00 - 00903168 ____A C:\Windows\System32\ContentDirectoryPresenter64.dll
2012-07-03 08:00 - 2012-07-03 08:00 - 00702464 ____A C:\Windows\SysWOW64\ContentDirectoryPresenter.dll
2012-07-03 08:00 - 2012-07-03 08:00 - 00030720 ____A C:\Windows\System32\MediaDB64.dll
2012-07-03 08:00 - 2012-07-03 08:00 - 00025600 ____A C:\Windows\SysWOW64\MediaDB.dll
2012-06-28 23:55 - 2012-08-15 02:04 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-28 23:09 - 2012-08-15 02:04 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-28 22:56 - 2012-08-15 02:04 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-28 22:49 - 2012-08-15 02:04 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-28 22:49 - 2012-08-15 02:04 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-28 22:48 - 2012-08-15 02:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-28 22:47 - 2012-08-15 02:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-28 22:45 - 2012-08-15 02:04 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-28 22:44 - 2012-08-15 02:04 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-28 22:43 - 2012-08-15 02:04 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-28 22:42 - 2012-08-15 02:04 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-28 22:40 - 2012-08-15 02:04 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-28 22:39 - 2012-08-15 02:04 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-28 22:35 - 2012-08-15 02:04 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-28 19:52 - 2012-08-15 02:04 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-28 19:27 - 2012-08-15 02:04 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-28 19:16 - 2012-08-15 02:04 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-28 19:09 - 2012-08-15 02:04 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-28 19:09 - 2012-08-15 02:04 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-28 19:08 - 2012-08-15 02:04 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-28 19:07 - 2012-08-15 02:04 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-28 19:06 - 2012-08-15 02:04 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-28 19:04 - 2012-08-15 02:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-28 19:04 - 2012-08-15 02:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-28 19:01 - 2012-08-15 02:04 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-28 19:01 - 2012-08-15 02:04 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-28 19:00 - 2012-08-15 02:04 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-28 18:57 - 2012-08-15 02:04 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-26 17:49 - 2012-06-26 17:45 - 05387407 ____A C:\Users\Matt\Downloads\absinthe-win-2.0.4.zip
2012-06-25 09:47 - 2012-06-25 09:47 - 00918016 ____A C:\Windows\System32\boost_regex-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00299520 ____A C:\Windows\System32\boost_serialization-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00158720 ____A C:\Windows\System32\boost_filesystem-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00058880 ____A C:\Windows\System32\boost_thread-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00049152 ____A C:\Windows\System32\boost_date_time-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00016896 ____A C:\Windows\System32\boost_system-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00704000 ____A C:\Windows\SysWOW64\boost_regex-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00227840 ____A C:\Windows\SysWOW64\boost_serialization-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00130048 ____A C:\Windows\SysWOW64\boost_filesystem-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00046592 ____A C:\Windows\SysWOW64\boost_thread-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00038912 ____A C:\Windows\SysWOW64\boost_date_time-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00012800 ____A C:\Windows\SysWOW64\boost_system-vc90-mt-1_47.dll
2012-06-23 01:47 - 2012-06-23 01:47 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_netaapl64_01009.Wdf
2012-06-19 18:25 - 2012-06-19 18:22 - 164950584 ____A C:\Users\Matt\Downloads\NoDJ-Freddie_Gibbs-Cold_Day_In_Hell.zip
2012-06-19 18:21 - 2012-06-19 18:20 - 87086016 ____A C:\Users\Matt\Downloads\Grind_Hard-Starlito-Ultimate_Warrior.zip
2012-06-19 18:18 - 2012-06-19 18:17 - 89618546 ____A C:\Users\Matt\Downloads\Boss_Hogg_Outlawz-Slim_Thug-Houston.zip
2012-06-19 18:16 - 2012-06-19 18:14 - 80868293 ____A C:\Users\Matt\Downloads\NoDJ-Lil_Phat-Never_Use_A_Pen_Again.zip
2012-06-19 18:10 - 2012-06-19 18:09 - 76373046 ____A C:\Users\Matt\Downloads\Unknown-Trey_Songz-Anticipation.zip
2012-06-19 18:07 - 2012-06-19 18:06 - 82546950 ____A C:\Users\Matt\Downloads\NoDJ-Trey_Songz-Anticipation_2.zip
2012-06-19 18:02 - 2012-06-19 18:00 - 106742929 ____A C:\Users\Matt\Downloads\DJ_Drama-Chris_Brown-In_My_Zone_(Rhythm_&_Streets).zip
2012-06-19 17:55 - 2012-06-19 17:55 - 01656459 ____A C:\Users\Matt\Downloads\winrar-x64-420.exe
2012-06-09 00:43 - 2012-07-12 16:14 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 23:41 - 2012-07-12 16:14 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 15:35 - 2012-06-08 15:35 - 00000454 ____A C:\user.js
2012-06-06 01:06 - 2012-07-12 16:14 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-06 01:06 - 2012-07-12 16:14 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-06 01:02 - 2012-07-12 16:14 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-06 00:05 - 2012-07-12 16:14 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-06 00:05 - 2012-07-12 16:14 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-06 00:03 - 2012-07-12 16:14 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 17:19 - 2012-06-23 21:38 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 17:19 - 2012-06-23 21:38 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 17:19 - 2012-06-23 21:38 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 17:19 - 2012-06-23 21:37 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 17:19 - 2012-06-23 21:37 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 17:15 - 2012-06-23 21:38 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 17:15 - 2012-06-23 21:37 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:19 - 2012-06-23 21:37 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:15 - 2012-06-23 21:37 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 00:50 - 2012-07-12 16:14 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-02 00:48 - 2012-07-12 16:14 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-02 00:48 - 2012-07-12 16:14 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 00:45 - 2012-07-12 16:14 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-02 00:44 - 2012-07-12 16:14 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 23:40 - 2012-07-12 16:14 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 23:40 - 2012-07-12 16:14 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 23:39 - 2012-07-12 16:14 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 23:34 - 2012-07-12 16:14 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 11:25 - 2010-11-20 22:27 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-29 19:20 - 2012-06-26 17:57 - 00000439 ____A C:\Users\Matt\Downloads\readme.txt
ZeroAccess:
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\@
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\L
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\U
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\L\00000004.@
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\L\201d3dde
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\U\00000008.@
ZeroAccess:
C:\Users\Matt\AppData\Local\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}
C:\Users\Matt\AppData\Local\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\@
C:\Users\Matt\AppData\Local\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\L
C:\Users\Matt\AppData\Local\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3892.52 MB
Available physical RAM: 3294.82 MB
Total Pagefile: 3890.72 MB
Available Pagefile: 3286.83 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:383.84 GB) NTFS
2 Drive d: (New) (CDROM) (Total:1.99 GB) (Free:0 GB) UDF
3 Drive e: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
4 Drive f: () (Removable) (Total:1.9 GB) (Free:0.08 GB) FAT32
5 Drive g: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:6.41 GB) NTFS ==>[System with boot components (obtained from reading drive)]
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 1951 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 101 MB 31 KB
Partition 2 Primary 14 GB 102 MB
Partition 3 Primary 451 GB 14 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 FAT Partition 101 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 G RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C OS NTFS Partition 451 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1950 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F FAT32 Removable 1950 MB Healthy
==================================================================================
Last Boot: 2012-08-19 15:42
======================= End Of Log ==========================
Ran by SYSTEM at 22-08-2012 12:36:19
Running from F:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2122536 2010-05-07] (Synaptics Incorporated)
HKLM\...\Run: [Stage Remote] C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe -Quiet [2034752 2011-08-08] ()
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10144288 2010-04-13] (Realtek Semiconductor)
HKLM\...\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe [3203440 2010-04-06] (Dell Inc.)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [415256 2010-07-29] (Intel Corporation)
HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel(R) Corporation)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [161304 2010-07-29] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386584 2010-07-29] (Intel Corporation)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [2918656 2011-01-12] (ESET)
HKLM\...\Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup [483424 2012-02-01] ()
HKLM\...\Run: [AllShare Play] "C:\Program Files\Samsung\AllShare Play\utils\AllShare Play Launcher.exe" [399264 2012-07-09] (Samsung Electronics)
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()
HKLM-x32\...\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot [4144448 2010-11-10] (Dell, Inc.)
HKLM-x32\...\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35768 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup [2835443 2012-02-01] ()
HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [520330 2011-08-12] (Creative Technology Ltd)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKU\Default\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1475584 2010-11-20] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1475584 2010-11-20] (Microsoft Corporation)
HKU\Matt\...\Run: [AROReminder] C:\Program Files (x86)\ARO 2011\ARO.exe -rem [x]
HKU\Matt\...\Run: [Itibiti.exe] C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe [x]
HKU\Matt\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\Mcx1-MATT-PC\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [343552 2009-07-13] (Microsoft Corporation)
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-15] (Dell)
Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
AppInit_DLLs:
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Matt\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.1.01\AllShareFrameworkManagerDMS.exe [32768 2012-07-06] (Samsung)
3 EhttpSrv; "C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe" [42360 2011-01-12] (ESET)
2 ekrn; "C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe" [810144 2011-01-12] (ESET)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] ()
2 N360; "C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\diMaster.dll" /prefetch:1 [309688 2012-04-12] (Symantec Corporation)
3 stllssvr; "C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe" [74392 2010-11-08] (MicroVision Development, Inc.)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2533400 2010-07-01] (Intel Corporation)
2 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [185856 2012-05-08] ()
========================== Drivers (Whitelisted) =============
1 BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20120803.001\BHDrvx64.sys [1161376 2012-08-03] (Symantec Corporation)
1 ccSet_N360; C:\Windows\system32\drivers\N360x64\0602010.005\ccSetx64.sys [167048 2011-11-04] (Symantec Corporation)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [170640 2010-12-21] (ESET)
1 eeCtrl; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-08-20] (Symantec Corporation)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [141264 2010-12-21] (ESET)
2 epfwwfpr; C:\Windows\System32\Drivers\epfwwfpr.sys [125296 2010-12-21] (ESET)
3 EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-08-21] (Symantec Corporation)
1 IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20120821.001\IDSvia64.sys [509088 2012-08-21] (Symantec Corporation)
3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20120821.002\ENG64.SYS [125600 2012-08-21] (Symantec Corporation)
3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20120821.002\EX64.SYS [2084000 2012-08-21] (Symantec Corporation)
1 SRTSP; C:\Windows\System32\Drivers\N360x64\0602010.005\SRTSP64.SYS [737912 2012-03-29] (Symantec Corporation)
1 SRTSPX; C:\Windows\system32\drivers\N360x64\0602010.005\SRTSPX64.SYS [37496 2012-03-29] (Symantec Corporation)
0 SymDS; C:\Windows\System32\drivers\N360x64\0602010.005\SYMDS64.SYS [451192 2011-08-16] (Symantec Corporation)
0 SymEFA; C:\Windows\System32\drivers\N360x64\0602010.005\SYMEFA64.SYS [1092728 2011-11-23] (Symantec Corporation)
3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2012-08-21] (Symantec Corporation)
1 SymIRON; C:\Windows\system32\drivers\N360x64\0602010.005\Ironx64.SYS [190072 2011-11-16] (Symantec Corporation)
1 SymNetS; C:\Windows\System32\Drivers\N360x64\0602010.005\SYMNETS.SYS [405624 2011-11-16] (Symantec Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-22 10:58 - 2012-08-22 10:58 - 00711240 ____A C:\Windows\isRS-000.tmp
2012-08-22 10:58 - 2012-08-22 10:58 - 00000000 ____D C:\Users\Matt\Application Data\U3
2012-08-22 10:58 - 2012-08-22 10:58 - 00000000 ____D C:\Users\Matt\AppData\Roaming\U3
2012-08-21 23:25 - 2012-08-21 23:25 - 00000000 ____D C:\Users\Matt\Local Settings\CrashDumps
2012-08-21 23:25 - 2012-08-21 23:25 - 00000000 ____D C:\Users\Matt\Local Settings\Application Data\CrashDumps
2012-08-21 23:25 - 2012-08-21 23:25 - 00000000 ____D C:\Users\Matt\AppData\Local\CrashDumps
2012-08-21 21:22 - 2012-08-21 21:31 - 00002422 ____A C:\Users\Public\Desktop\Norton Security Suite.lnk
2012-08-21 21:22 - 2012-08-21 21:31 - 00002422 ____A C:\Users\All Users\Desktop\Norton Security Suite.lnk
2012-08-21 21:22 - 2012-08-21 21:31 - 00000000 ____D C:\Windows\System32\Drivers\N360x64
2012-08-21 21:22 - 2012-08-21 21:22 - 00175736 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
2012-08-21 21:22 - 2012-08-21 21:22 - 00007488 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Users\Matt\My Documents\Symantec
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Users\Matt\Documents\Symantec
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Program Files\Symantec
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2012-08-21 21:22 - 2012-08-21 21:22 - 00000000 ____D C:\Program Files (x86)\Norton Security Suite
2012-08-21 21:20 - 2012-08-21 21:22 - 00000000 ____D C:\Users\All Users\Norton
2012-08-21 21:20 - 2012-08-21 21:22 - 00000000 ____D C:\Users\All Users\Application Data\Norton
2012-08-21 21:20 - 2012-08-21 21:20 - 00001361 ____A C:\Users\Matt\Desktop\Norton Installation Files.lnk
2012-08-21 21:20 - 2012-08-21 21:20 - 00000000 ____D C:\Users\Public\Downloads\Norton
2012-08-19 20:03 - 2012-08-19 20:03 - 00775304 ____A C:\Windows\Minidump\081912-17893-01.dmp
2012-08-19 13:31 - 2012-08-19 13:31 - 00775304 ____A C:\Windows\Minidump\081912-21855-01.dmp
2012-08-16 20:47 - 2012-08-22 10:58 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-16 20:47 - 2012-08-22 10:58 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-15 02:05 - 2012-07-06 15:07 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2012-08-15 02:04 - 2012-06-28 23:55 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-15 02:04 - 2012-06-28 23:09 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-15 02:04 - 2012-06-28 22:56 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-15 02:04 - 2012-06-28 22:49 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-15 02:04 - 2012-06-28 22:49 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-15 02:04 - 2012-06-28 22:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-15 02:04 - 2012-06-28 22:47 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-15 02:04 - 2012-06-28 22:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-15 02:04 - 2012-06-28 22:44 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-15 02:04 - 2012-06-28 22:43 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-15 02:04 - 2012-06-28 22:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-15 02:04 - 2012-06-28 22:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-15 02:04 - 2012-06-28 22:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-15 02:04 - 2012-06-28 22:35 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-15 02:04 - 2012-06-28 19:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-15 02:04 - 2012-06-28 19:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-15 02:04 - 2012-06-28 19:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-08-15 02:04 - 2012-06-28 19:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-15 02:04 - 2012-06-28 19:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-15 02:04 - 2012-06-28 19:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-15 02:04 - 2012-06-28 19:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-15 02:04 - 2012-06-28 19:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-15 02:04 - 2012-06-28 19:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-15 02:04 - 2012-06-28 19:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-15 02:04 - 2012-06-28 19:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-15 02:04 - 2012-06-28 19:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-15 02:04 - 2012-06-28 19:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-15 02:04 - 2012-06-28 18:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-15 01:46 - 2012-08-15 01:47 - 00000000 ____D C:\Users\All Users\Google
2012-08-15 01:46 - 2012-08-15 01:47 - 00000000 ____D C:\Users\All Users\Application Data\Google
2012-08-15 01:46 - 2012-08-15 01:46 - 00000000 ____D C:\Program Files\Google
2012-08-15 01:45 - 2012-08-15 01:45 - 01001264 ____A (Solid State Networks) C:\Users\Matt\Downloads\install_flashplayer11x32ax_gtba_chra_dy_aih.exe
2012-08-15 01:16 - 2012-07-18 13:15 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-15 01:16 - 2012-07-04 17:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-15 01:16 - 2012-07-04 17:13 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-08-15 01:16 - 2012-07-04 17:13 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-08-15 01:16 - 2012-07-04 16:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-08-15 01:16 - 2012-07-04 16:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-08-15 01:16 - 2012-05-14 00:26 - 00956928 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-15 01:16 - 2012-05-05 03:36 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2012-08-15 01:16 - 2012-05-05 02:46 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2012-08-15 01:16 - 2012-02-11 01:43 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2012-08-15 01:16 - 2012-02-11 01:36 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2012-08-15 01:16 - 2012-02-11 01:36 - 00067072 ____A (Microsoft Corporation) C:\Windows\splwow64.exe
2012-08-15 01:16 - 2012-02-11 00:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2012-08-12 00:49 - 2012-08-12 00:49 - 00029692 ____A (Orange Corporation) C:\Users\Matt\0.5266765910548641.exe
2012-08-11 09:46 - 2012-08-11 10:45 - 173327657 ____A C:\Users\Matt\Downloads\Rick Ross - God Forgives, I Don't (Deluxe Edition) 320 Kbps CBR.zip
2012-08-06 16:03 - 2012-08-06 16:03 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-08-06 13:57 - 2012-08-22 11:05 - 00000000 ___RD C:\Users\Matt\Dropbox
2012-08-06 13:57 - 2012-08-06 13:57 - 00001041 ____A C:\Users\Matt\Desktop\Dropbox.lnk
2012-08-06 13:53 - 2012-08-22 11:05 - 00000000 ____D C:\Users\Matt\Application Data\Dropbox
2012-08-06 13:53 - 2012-08-22 11:05 - 00000000 ____D C:\Users\Matt\AppData\Roaming\Dropbox
2012-08-06 13:53 - 2012-08-06 13:53 - 17798272 ____A (Dropbox, Inc.) C:\Users\Matt\Downloads\Dropbox 1.4.12.exe
2012-08-06 13:40 - 2012-08-22 11:06 - 00000000 ____D C:\AllShare Play
2012-08-06 13:40 - 2012-08-06 13:40 - 00000000 ____D C:\Upload
2012-08-06 13:40 - 2012-08-06 13:40 - 00000000 ____D C:\Program Files\Samsung
2012-08-06 13:39 - 2012-08-06 13:40 - 00000000 ___HD C:\Program Files\Zero G Registry
2012-08-06 13:39 - 2012-08-06 13:39 - 00000000 ___HD C:\Users\Matt\InstallAnywhere
2012-08-06 13:38 - 2012-08-06 13:39 - 82203456 ____A (Flexera Software) C:\Users\Matt\Downloads\AllSharePlay_Installer64.exe
2012-07-31 02:43 - 2012-07-31 02:43 - 00000000 ____D C:\Windows\Sun
2012-07-27 21:50 - 2012-08-02 13:47 - 09231560 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
============ 3 Months Modified Files ========================
2012-08-22 11:32 - 2011-06-16 03:41 - 01668151 ____A C:\Windows\WindowsUpdate.log
2012-08-22 11:26 - 2012-04-18 17:54 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-08-22 11:19 - 2012-07-17 12:21 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-22 11:09 - 2009-07-13 23:45 - 00021296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-22 11:09 - 2009-07-13 23:45 - 00021296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-22 11:07 - 2009-07-14 00:13 - 00780220 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-22 11:05 - 2011-09-18 10:56 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-22 11:04 - 2011-09-18 10:56 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-22 11:01 - 2011-09-22 19:14 - 00000258 _RASH C:\Users\All Users\ntuser.pol
2012-08-22 11:01 - 2011-09-22 19:14 - 00000258 _RASH C:\Users\All Users\Application Data\ntuser.pol
2012-08-22 11:00 - 2010-11-20 22:47 - 00048158 ____A C:\Windows\PFRO.log
2012-08-22 11:00 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-22 11:00 - 2009-07-13 23:51 - 00141677 ____A C:\Windows\setupact.log
2012-08-22 10:58 - 2012-08-22 10:58 - 00711240 ____A C:\Windows\isRS-000.tmp
2012-08-22 10:58 - 2012-08-16 20:47 - 00001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-22 10:58 - 2012-08-16 20:47 - 00001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-21 21:31 - 2012-08-21 21:22 - 00002422 ____A C:\Users\Public\Desktop\Norton Security Suite.lnk
2012-08-21 21:31 - 2012-08-21 21:22 - 00002422 ____A C:\Users\All Users\Desktop\Norton Security Suite.lnk
2012-08-21 21:31 - 2012-04-18 17:54 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-08-21 21:22 - 2012-08-21 21:22 - 00175736 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
2012-08-21 21:22 - 2012-08-21 21:22 - 00007488 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
2012-08-21 21:20 - 2012-08-21 21:20 - 00001361 ____A C:\Users\Matt\Desktop\Norton Installation Files.lnk
2012-08-21 21:18 - 2011-09-18 10:57 - 00002342 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-08-21 21:18 - 2011-09-18 10:57 - 00002342 ____A C:\Users\All Users\Desktop\Google Chrome.lnk
2012-08-19 20:03 - 2012-08-19 20:03 - 00775304 ____A C:\Windows\Minidump\081912-17893-01.dmp
2012-08-19 20:03 - 2012-03-03 02:45 - 530169526 ____A C:\Windows\MEMORY.DMP
2012-08-19 13:31 - 2012-08-19 13:31 - 00775304 ____A C:\Windows\Minidump\081912-21855-01.dmp
2012-08-15 06:31 - 2011-08-20 03:03 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2012-08-15 06:31 - 2011-08-20 03:03 - 00002021 ____A C:\Users\All Users\Desktop\Adobe Reader X.lnk
2012-08-15 02:25 - 2009-07-13 23:45 - 00319000 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-15 02:00 - 2012-01-09 13:39 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-15 01:46 - 2012-07-17 12:21 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-15 01:46 - 2011-09-22 11:58 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-15 01:45 - 2012-08-15 01:45 - 01001264 ____A (Solid State Networks) C:\Users\Matt\Downloads\install_flashplayer11x32ax_gtba_chra_dy_aih.exe
2012-08-12 00:49 - 2012-08-12 00:49 - 00029692 ____A (Orange Corporation) C:\Users\Matt\0.5266765910548641.exe
2012-08-11 10:45 - 2012-08-11 09:46 - 173327657 ____A C:\Users\Matt\Downloads\Rick Ross - God Forgives, I Don't (Deluxe Edition) 320 Kbps CBR.zip
2012-08-06 13:57 - 2012-08-06 13:57 - 00001041 ____A C:\Users\Matt\Desktop\Dropbox.lnk
2012-08-06 13:53 - 2012-08-06 13:53 - 17798272 ____A (Dropbox, Inc.) C:\Users\Matt\Downloads\Dropbox 1.4.12.exe
2012-08-06 13:39 - 2012-08-06 13:38 - 82203456 ____A (Flexera Software) C:\Users\Matt\Downloads\AllSharePlay_Installer64.exe
2012-08-02 13:47 - 2012-07-27 21:50 - 09231560 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-07-20 13:09 - 2012-03-02 22:52 - 00000047 ____A C:\Users\Matt\My Documents\light bulb text.txt
2012-07-20 13:09 - 2012-03-02 22:52 - 00000047 ____A C:\Users\Matt\Documents\light bulb text.txt
2012-07-18 13:15 - 2012-08-15 01:16 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-13 10:25 - 2009-07-14 00:08 - 00032566 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-06 15:07 - 2012-08-15 02:05 - 00552960 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
2012-07-05 14:20 - 2011-08-17 13:31 - 00020480 ____A C:\Users\Matt\Local Settings\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-05 14:20 - 2011-08-17 13:31 - 00020480 ____A C:\Users\Matt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-05 14:20 - 2011-08-17 13:31 - 00020480 ____A C:\Users\Matt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-05 14:00 - 2012-07-07 12:17 - 38352868 ____A C:\Users\Matt\Desktop\05-28-12 Cold In Da House.wav
2012-07-05 14:00 - 2012-07-05 13:57 - 38352868 ____A C:\Users\Matt\Downloads\05-28-12 Cold In Da House.wav
2012-07-04 17:16 - 2012-08-15 01:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 17:13 - 2012-08-15 01:16 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 17:13 - 2012-08-15 01:16 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 16:16 - 2012-08-15 01:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 16:14 - 2012-08-15 01:16 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-07-03 12:46 - 2012-01-09 20:18 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-03 08:00 - 2012-07-03 08:00 - 00903168 ____A C:\Windows\System32\ContentDirectoryPresenter64.dll
2012-07-03 08:00 - 2012-07-03 08:00 - 00702464 ____A C:\Windows\SysWOW64\ContentDirectoryPresenter.dll
2012-07-03 08:00 - 2012-07-03 08:00 - 00030720 ____A C:\Windows\System32\MediaDB64.dll
2012-07-03 08:00 - 2012-07-03 08:00 - 00025600 ____A C:\Windows\SysWOW64\MediaDB.dll
2012-06-28 23:55 - 2012-08-15 02:04 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-28 23:09 - 2012-08-15 02:04 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-28 22:56 - 2012-08-15 02:04 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-28 22:49 - 2012-08-15 02:04 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-28 22:49 - 2012-08-15 02:04 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-28 22:48 - 2012-08-15 02:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-28 22:47 - 2012-08-15 02:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-28 22:45 - 2012-08-15 02:04 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-28 22:44 - 2012-08-15 02:04 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-28 22:43 - 2012-08-15 02:04 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-28 22:42 - 2012-08-15 02:04 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-28 22:40 - 2012-08-15 02:04 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-28 22:39 - 2012-08-15 02:04 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-28 22:35 - 2012-08-15 02:04 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-28 19:52 - 2012-08-15 02:04 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-28 19:27 - 2012-08-15 02:04 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-28 19:16 - 2012-08-15 02:04 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-28 19:09 - 2012-08-15 02:04 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-28 19:09 - 2012-08-15 02:04 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-28 19:08 - 2012-08-15 02:04 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-28 19:07 - 2012-08-15 02:04 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-28 19:06 - 2012-08-15 02:04 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-28 19:04 - 2012-08-15 02:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-28 19:04 - 2012-08-15 02:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-28 19:01 - 2012-08-15 02:04 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-28 19:01 - 2012-08-15 02:04 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-28 19:00 - 2012-08-15 02:04 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-28 18:57 - 2012-08-15 02:04 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-26 17:49 - 2012-06-26 17:45 - 05387407 ____A C:\Users\Matt\Downloads\absinthe-win-2.0.4.zip
2012-06-25 09:47 - 2012-06-25 09:47 - 00918016 ____A C:\Windows\System32\boost_regex-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00299520 ____A C:\Windows\System32\boost_serialization-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00158720 ____A C:\Windows\System32\boost_filesystem-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00058880 ____A C:\Windows\System32\boost_thread-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00049152 ____A C:\Windows\System32\boost_date_time-vc90-mt-1_47.dll
2012-06-25 09:47 - 2012-06-25 09:47 - 00016896 ____A C:\Windows\System32\boost_system-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00704000 ____A C:\Windows\SysWOW64\boost_regex-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00227840 ____A C:\Windows\SysWOW64\boost_serialization-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00130048 ____A C:\Windows\SysWOW64\boost_filesystem-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00046592 ____A C:\Windows\SysWOW64\boost_thread-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00038912 ____A C:\Windows\SysWOW64\boost_date_time-vc90-mt-1_47.dll
2012-06-25 09:46 - 2012-06-25 09:46 - 00012800 ____A C:\Windows\SysWOW64\boost_system-vc90-mt-1_47.dll
2012-06-23 01:47 - 2012-06-23 01:47 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_netaapl64_01009.Wdf
2012-06-19 18:25 - 2012-06-19 18:22 - 164950584 ____A C:\Users\Matt\Downloads\NoDJ-Freddie_Gibbs-Cold_Day_In_Hell.zip
2012-06-19 18:21 - 2012-06-19 18:20 - 87086016 ____A C:\Users\Matt\Downloads\Grind_Hard-Starlito-Ultimate_Warrior.zip
2012-06-19 18:18 - 2012-06-19 18:17 - 89618546 ____A C:\Users\Matt\Downloads\Boss_Hogg_Outlawz-Slim_Thug-Houston.zip
2012-06-19 18:16 - 2012-06-19 18:14 - 80868293 ____A C:\Users\Matt\Downloads\NoDJ-Lil_Phat-Never_Use_A_Pen_Again.zip
2012-06-19 18:10 - 2012-06-19 18:09 - 76373046 ____A C:\Users\Matt\Downloads\Unknown-Trey_Songz-Anticipation.zip
2012-06-19 18:07 - 2012-06-19 18:06 - 82546950 ____A C:\Users\Matt\Downloads\NoDJ-Trey_Songz-Anticipation_2.zip
2012-06-19 18:02 - 2012-06-19 18:00 - 106742929 ____A C:\Users\Matt\Downloads\DJ_Drama-Chris_Brown-In_My_Zone_(Rhythm_&_Streets).zip
2012-06-19 17:55 - 2012-06-19 17:55 - 01656459 ____A C:\Users\Matt\Downloads\winrar-x64-420.exe
2012-06-09 00:43 - 2012-07-12 16:14 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 23:41 - 2012-07-12 16:14 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 15:35 - 2012-06-08 15:35 - 00000454 ____A C:\user.js
2012-06-06 01:06 - 2012-07-12 16:14 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-06 01:06 - 2012-07-12 16:14 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-06 01:02 - 2012-07-12 16:14 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-06 00:05 - 2012-07-12 16:14 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-06 00:05 - 2012-07-12 16:14 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-06 00:03 - 2012-07-12 16:14 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 17:19 - 2012-06-23 21:38 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 17:19 - 2012-06-23 21:38 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 17:19 - 2012-06-23 21:38 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 17:19 - 2012-06-23 21:37 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 17:19 - 2012-06-23 21:37 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 17:15 - 2012-06-23 21:38 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 17:15 - 2012-06-23 21:37 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:19 - 2012-06-23 21:37 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:15 - 2012-06-23 21:37 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 00:50 - 2012-07-12 16:14 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-02 00:48 - 2012-07-12 16:14 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-02 00:48 - 2012-07-12 16:14 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 00:45 - 2012-07-12 16:14 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-02 00:44 - 2012-07-12 16:14 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 23:40 - 2012-07-12 16:14 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 23:40 - 2012-07-12 16:14 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 23:39 - 2012-07-12 16:14 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 23:34 - 2012-07-12 16:14 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 11:25 - 2010-11-20 22:27 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-29 19:20 - 2012-06-26 17:57 - 00000439 ____A C:\Users\Matt\Downloads\readme.txt
ZeroAccess:
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\@
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\L
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\U
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\L\00000004.@
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\L\201d3dde
C:\Windows\Installer\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\U\00000008.@
ZeroAccess:
C:\Users\Matt\AppData\Local\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}
C:\Users\Matt\AppData\Local\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\@
C:\Users\Matt\AppData\Local\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\L
C:\Users\Matt\AppData\Local\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3892.52 MB
Available physical RAM: 3294.82 MB
Total Pagefile: 3890.72 MB
Available Pagefile: 3286.83 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:383.84 GB) NTFS
2 Drive d: (New) (CDROM) (Total:1.99 GB) (Free:0 GB) UDF
3 Drive e: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
4 Drive f: () (Removable) (Total:1.9 GB) (Free:0.08 GB) FAT32
5 Drive g: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:6.41 GB) NTFS ==>[System with boot components (obtained from reading drive)]
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 1951 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 101 MB 31 KB
Partition 2 Primary 14 GB 102 MB
Partition 3 Primary 451 GB 14 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 FAT Partition 101 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 G RECOVERY NTFS Partition 14 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C OS NTFS Partition 451 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1950 MB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F FAT32 Removable 1950 MB Healthy
==================================================================================
Last Boot: 2012-08-19 15:42
======================= End Of Log ==========================