I found your website while searching for this virus and must say, I am very impressed. This will be my go to place from now on for all things techy. I have read a few posts but am too much of noob to try and change what needs to be changed and attempt it on my own. I have downloaded FRST64 and my log is below. I thank you in advance your help.
Scan result of Farbar Recovery Scan Tool Version: 12-06-2012 02
Ran by SYSTEM at 12-06-2012 16:32:47
Running from J:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11543656 2010-10-26] (Realtek Semiconductor)
HKLM\...\Run: [UMonit] C:\windows\SysWOW64\UMonit.exe [28672 2010-11-30] ()
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [57928 2011-09-16] (LogMeIn, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [497648 2010-07-28] (Adobe Systems Incorporated)
HKLM\...\Run: [IgfxTray] C:\windows\system32\igfxtray.exe [167704 2012-01-10] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe [392984 2012-01-10] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\windows\system32\igfxpers.exe [417560 2012-01-10] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [jmekey] C:\windows\jmesoft\hotkey.exe [118784 2011-03-21] (Lenovo)
HKLM-x32\...\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe [28672 2011-03-15] ()
HKLM-x32\...\Run: [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery" [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun [139264 2011-04-20] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKU\Robert\...\Run: [Best Buy pc app] C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms [x]
HKU\Robert\...\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2011-11-11] (Apple Inc.)
HKU\Robert\...\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59240 2011-11-11] (Apple Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.1.10.1
Startup: C:\Users\Default\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\LogMeInRemoteUser\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
==================== Services (Whitelisted) ======
2 AdobeActiveFileMonitor9.0; C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [169408 2010-09-06] (Adobe Systems Incorporated)
3 BrYNSvc; "C:\Program Files (x86)\Browny02\BrYNSvc.exe" [245760 2010-01-25] (Brother Industries, Ltd.)
2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-15] ()
2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375176 2012-05-21] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147336 2012-05-21] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2011-09-16] (LogMeIn, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NitroReaderDriverReadSpool2; "C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe" [341800 2011-12-20] (Nitro PDF Software)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2655768 2010-10-05] (Intel Corporation)
========================== Drivers (Whitelisted) =============
3 AX88772; C:\Windows\System32\Drivers\AX88772.sys [79360 2011-06-01] (ASIX Electronics Corp.)
3 GeneStor; C:\Windows\System32\Drivers\GeneStor.sys [57856 2010-12-16] (GenesysLogic)
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2011-09-16] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\Drivers\lmimirr.sys [11552 2011-09-16] (LogMeIn, Inc.)
2 LMIRfsDriver; C:\Windows\System32\Drivers\LMIRfsDriver.sys [72216 2011-09-16] (LogMeIn, Inc.)
3 wsvd; C:\Windows\System32\Drivers\wsvd.sys [121840 2009-07-21] (CyberLink)
4 LMIRfsClientNP; [x]
3 NAL; \??\C:\windows\system32\Drivers\iqvw64e.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-12 12:36 - 2012-06-12 12:36 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-12 12:36 - 2012-06-12 12:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-12 07:26 - 2012-06-12 07:26 - 02565537 ____A C:\Users\Robert\Desktop\2.00 Bar 4340.pdf
2012-06-11 11:51 - 2012-06-12 10:44 - 00000000 ____D C:\Users\Robert\Documents\Boots & Coots
2012-06-08 07:29 - 2012-06-08 07:29 - 00319967 ____N C:\Users\Robert\Desktop\IMG_1940.JPG
2012-06-08 07:29 - 2012-06-08 07:24 - 00307854 ____N C:\Users\Robert\Desktop\IMG_1941.JPG
2012-06-05 08:14 - 2012-06-05 08:14 - 00226816 ____A C:\Users\Robert\Desktop\MSS ShipmentOpen order 6-05-2012.xls
2012-06-04 07:06 - 2012-06-04 07:06 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-30 10:17 - 2012-05-30 10:17 - 00223232 ____A C:\Users\Robert\Desktop\MSS ShipmentOpen order 5-30-2012.xls
2012-05-25 05:05 - 2012-05-25 05:05 - 00000000 ____D C:\Users\Robert\Documents\Diablo III
2012-05-25 05:01 - 2012-05-25 05:02 - 87207472 ____A (Intel Corporation) C:\Users\Robert\Downloads\Win7Vista_64_152254.exe
2012-05-24 12:37 - 2012-05-24 12:37 - 01411314 ____A C:\Users\Robert\Desktop\Equifax report 5-2012.pdf
2012-05-24 12:37 - 2012-05-24 12:37 - 00001123 ____A C:\Users\Robert\Desktop\Equifax report 5-2012.log
2012-05-24 10:52 - 2012-05-25 05:05 - 00000000 ____D C:\Program Files (x86)\Diablo III
2012-05-24 10:52 - 2012-05-24 10:52 - 00001193 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-22 11:38 - 2012-05-22 11:38 - 00102400 ____A C:\Users\Robert\Desktop\Copy of Blueline RFQ#8119.xls
2012-05-21 10:42 - 2012-05-21 10:42 - 01065984 ____A C:\Users\Robert\Desktop\Copy of PHYSICAL INVENTORY 5-21-2012.xls
2012-05-15 10:57 - 2012-05-15 10:57 - 00408388 ____A C:\Users\Robert\Desktop\Approved_Mill_list_by_Material 4-17-2012.pdf
============ 3 Months Modified Files and Folders =============
2012-06-12 13:21 - 2011-07-28 16:00 - 01376900 ____A C:\Windows\WindowsUpdate.log
2012-06-12 13:20 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-12 13:20 - 2009-07-13 20:51 - 00051137 ____A C:\Windows\setupact.log
2012-06-12 12:42 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\Robert
2012-06-12 12:42 - 2011-12-05 09:12 - 00000000 ____D C:\Users\Robert\Documents\Outlook Files
2012-06-12 12:39 - 2009-07-13 20:45 - 00020688 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-12 12:39 - 2009-07-13 20:45 - 00020688 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-12 12:38 - 2011-12-05 15:01 - 00000000 ____D C:\Users\Robert\AppData\Local\2801E5BF-F8F0-4A64-91C1-5F8C4DF05438.aplzod
2012-06-12 12:36 - 2012-06-12 12:36 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-12 12:36 - 2012-06-12 12:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-12 12:36 - 2012-01-31 05:52 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-12 12:36 - 2011-11-29 20:41 - 00743538 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-12 12:36 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-12 10:58 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\BlueLine
2012-06-12 10:54 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\Top-Co
2012-06-12 10:44 - 2012-06-11 11:51 - 00000000 ____D C:\Users\Robert\Documents\Boots & Coots
2012-06-12 09:26 - 2012-04-05 06:25 - 00000000 ____D C:\Users\Robert\Documents\Peak Completions
2012-06-12 09:26 - 2011-11-29 19:30 - 00000000 ____D C:\users\Robert
2012-06-12 07:26 - 2012-06-12 07:26 - 02565537 ____A C:\Users\Robert\Desktop\2.00 Bar 4340.pdf
2012-06-11 22:40 - 2011-12-03 00:18 - 00000000 ____D C:\Users\All Users\LogMeIn
2012-06-08 07:29 - 2012-06-08 07:29 - 00319967 ____N C:\Users\Robert\Desktop\IMG_1940.JPG
2012-06-08 07:24 - 2012-06-08 07:29 - 00307854 ____N C:\Users\Robert\Desktop\IMG_1941.JPG
2012-06-07 12:34 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\TAM
2012-06-06 14:02 - 2012-04-09 08:52 - 79685120 ____A C:\Users\Robert\Desktop\Copy of Form 7.2.1-5B INQUIRY Data Log.xls
2012-06-06 09:30 - 2011-12-02 22:00 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2012-06-05 12:22 - 2012-01-31 09:46 - 00000000 ____D C:\Users\Robert\AppData\Roaming\PrimoPDF
2012-06-05 08:14 - 2012-06-05 08:14 - 00226816 ____A C:\Users\Robert\Desktop\MSS ShipmentOpen order 6-05-2012.xls
2012-06-04 07:06 - 2012-06-04 07:06 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-04 07:04 - 2012-04-11 05:27 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-04 07:04 - 2011-12-05 07:24 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-01 13:58 - 2012-03-30 05:22 - 01163135 ____A C:\Users\Robert\Desktop\Prospect Database.xlsx
2012-05-30 10:17 - 2012-05-30 10:17 - 00223232 ____A C:\Users\Robert\Desktop\MSS ShipmentOpen order 5-30-2012.xls
2012-05-30 08:35 - 2011-12-03 02:16 - 00000000 ____D C:\Users\Robert\AppData\Local\Microsoft Help
2012-05-25 05:05 - 2012-05-25 05:05 - 00000000 ____D C:\Users\Robert\Documents\Diablo III
2012-05-25 05:05 - 2012-05-24 10:52 - 00000000 ____D C:\Program Files (x86)\Diablo III
2012-05-25 05:04 - 2011-07-28 16:17 - 00015824 ____A C:\Windows\System32\results.xml
2012-05-25 05:04 - 2010-11-20 19:47 - 00055790 ____A C:\Windows\PFRO.log
2012-05-25 05:02 - 2012-05-25 05:01 - 87207472 ____A (Intel Corporation) C:\Users\Robert\Downloads\Win7Vista_64_152254.exe
2012-05-24 12:37 - 2012-05-24 12:37 - 01411314 ____A C:\Users\Robert\Desktop\Equifax report 5-2012.pdf
2012-05-24 12:37 - 2012-05-24 12:37 - 00001123 ____A C:\Users\Robert\Desktop\Equifax report 5-2012.log
2012-05-24 10:52 - 2012-05-24 10:52 - 00001193 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-24 09:25 - 2012-04-05 07:23 - 00000000 ____D C:\Program Files (x86)\World of Warcraft Beta
2012-05-23 07:52 - 2012-04-30 11:31 - 00212480 ____A C:\Users\Robert\Desktop\Copy of MSS Shipment Open order Apr30.xls
2012-05-22 11:38 - 2012-05-22 11:38 - 00102400 ____A C:\Users\Robert\Desktop\Copy of Blueline RFQ#8119.xls
2012-05-21 10:42 - 2012-05-21 10:42 - 01065984 ____A C:\Users\Robert\Desktop\Copy of PHYSICAL INVENTORY 5-21-2012.xls
2012-05-21 07:18 - 2011-12-03 00:18 - 00000000 ____D C:\Program Files (x86)\LogMeIn
2012-05-21 07:17 - 2011-12-03 00:18 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-05-21 07:17 - 2011-12-03 00:18 - 00080768 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-05-21 07:17 - 2011-12-03 00:18 - 00034688 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-05-15 10:57 - 2012-05-15 10:57 - 00408388 ____A C:\Users\Robert\Desktop\Approved_Mill_list_by_Material 4-17-2012.pdf
2012-05-11 14:51 - 2011-12-12 11:16 - 00000000 ____D C:\Users\Robert\AppData\Local\ElevatedDiagnostics
2012-05-11 10:55 - 2012-05-11 10:55 - 00090416 ____A C:\Users\Robert\Desktop\Texas Sales and Tax Resale Certificate.pdf
2012-05-11 10:14 - 2011-12-03 21:59 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Apple Computer
2012-05-11 10:04 - 2012-05-11 10:04 - 00000000 ____D C:\Program Files\iTunes
2012-05-11 10:04 - 2012-05-11 10:04 - 00000000 ____D C:\Program Files\iPod
2012-05-11 10:04 - 2012-05-11 10:04 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-05-11 00:25 - 2011-07-28 16:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-11 00:25 - 2009-07-13 20:45 - 00368888 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-11 00:08 - 2011-12-03 02:16 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-11 00:08 - 2011-12-02 22:58 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-11 00:00 - 2011-02-15 02:41 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-01 12:27 - 2012-05-01 12:27 - 01122816 ____N C:\Users\Robert\Desktop\Invoice Record 5-1-12.xls
2012-04-30 11:06 - 2012-04-30 11:06 - 02730280 ____A C:\Users\Robert\Desktop\20120430094229929.pdf
2012-04-30 05:02 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-04-13 13:39 - 2011-12-06 07:24 - 00001107 ____A C:\Windows\Brpfx04a.ini
2012-04-11 05:09 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-04-11 05:07 - 2012-04-11 05:07 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2012-04-11 05:07 - 2012-04-11 05:07 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2012-04-05 07:23 - 2012-04-05 07:23 - 31727744 ____A (Blizzard Entertainment) C:\Users\Robert\Downloads\World of Warcraft Beta Setup.exe
2012-04-05 05:50 - 2012-04-05 05:50 - 00000000 ____D C:\Users\All Users\Battle.net
2012-03-30 22:05 - 2012-05-10 18:59 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 20:39 - 2012-05-10 18:59 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-03-30 20:39 - 2012-05-10 18:59 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-03-30 19:10 - 2012-05-10 18:59 - 03146240 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-30 11:24 - 2012-03-14 07:34 - 00000000 ____D C:\Users\Robert\Documents\Sterling
2012-03-30 05:21 - 2012-03-29 14:26 - 01425757 ____A C:\Users\Robert\Desktop\Prospect Database.csv
2012-03-30 03:35 - 2012-05-10 18:59 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-29 11:34 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2012-03-28 10:56 - 2012-03-28 10:56 - 00000000 ____A C:\Users\Robert\Sti_Trace.log
2012-03-28 10:55 - 2011-12-06 08:05 - 00000000 ____D C:\Users\Robert\AppData\Roaming\ControlCenter4
2012-03-23 04:57 - 2012-03-23 04:56 - 00000000 ____D C:\Users\Robert\PTR Installer 4.0.0.12824 enUS
2012-03-20 17:44 - 2012-03-20 17:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-03-20 17:44 - 2012-03-20 17:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-03-19 08:24 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\Valveworks
2012-03-16 23:58 - 2012-05-10 18:59 - 00075120 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
ZeroAccess:
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}\@
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}\L
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}\n
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 5992.44 MB
Available physical RAM: 5267.33 MB
Total Pagefile: 5990.64 MB
Available Pagefile: 5256.92 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:906.34 GB) (Free:785.53 GB) NTFS
7 Drive j: (LEXAR) (Removable) (Total:1.87 GB) (Free:1.87 GB) FAT
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 Online 1912 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 906 GB 101 MB
Partition 3 OEM 25 GB 906 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 906 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 12
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 LENOVO_PART NTFS Partition 25 GB Healthy Hidden
======================================================================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1911 MB 16 KB
======================================================================================================
Disk: 5
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J LEXAR FAT Removable 1911 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-05-28 21:58
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool Version: 12-06-2012 02
Ran by SYSTEM at 12-06-2012 16:32:47
Running from J:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11543656 2010-10-26] (Realtek Semiconductor)
HKLM\...\Run: [UMonit] C:\windows\SysWOW64\UMonit.exe [28672 2010-11-30] ()
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [57928 2011-09-16] (LogMeIn, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [497648 2010-07-28] (Adobe Systems Incorporated)
HKLM\...\Run: [IgfxTray] C:\windows\system32\igfxtray.exe [167704 2012-01-10] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe [392984 2012-01-10] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\windows\system32\igfxpers.exe [417560 2012-01-10] (Intel Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [jmekey] C:\windows\jmesoft\hotkey.exe [118784 2011-03-21] (Lenovo)
HKLM-x32\...\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe [28672 2011-03-15] ()
HKLM-x32\...\Run: [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery" [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun [139264 2011-04-20] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKU\Robert\...\Run: [Best Buy pc app] C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms [x]
HKU\Robert\...\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2011-11-11] (Apple Inc.)
HKU\Robert\...\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59240 2011-11-11] (Apple Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.1.10.1
Startup: C:\Users\Default\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\LogMeInRemoteUser\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
==================== Services (Whitelisted) ======
2 AdobeActiveFileMonitor9.0; C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [169408 2010-09-06] (Adobe Systems Incorporated)
3 BrYNSvc; "C:\Program Files (x86)\Browny02\BrYNSvc.exe" [245760 2010-01-25] (Brother Industries, Ltd.)
2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-15] ()
2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375176 2012-05-21] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147336 2012-05-21] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2011-09-16] (LogMeIn, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NitroReaderDriverReadSpool2; "C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe" [341800 2011-12-20] (Nitro PDF Software)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2655768 2010-10-05] (Intel Corporation)
========================== Drivers (Whitelisted) =============
3 AX88772; C:\Windows\System32\Drivers\AX88772.sys [79360 2011-06-01] (ASIX Electronics Corp.)
3 GeneStor; C:\Windows\System32\Drivers\GeneStor.sys [57856 2010-12-16] (GenesysLogic)
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2011-09-16] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\Drivers\lmimirr.sys [11552 2011-09-16] (LogMeIn, Inc.)
2 LMIRfsDriver; C:\Windows\System32\Drivers\LMIRfsDriver.sys [72216 2011-09-16] (LogMeIn, Inc.)
3 wsvd; C:\Windows\System32\Drivers\wsvd.sys [121840 2009-07-21] (CyberLink)
4 LMIRfsClientNP; [x]
3 NAL; \??\C:\windows\system32\Drivers\iqvw64e.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-12 12:36 - 2012-06-12 12:36 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-12 12:36 - 2012-06-12 12:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-12 07:26 - 2012-06-12 07:26 - 02565537 ____A C:\Users\Robert\Desktop\2.00 Bar 4340.pdf
2012-06-11 11:51 - 2012-06-12 10:44 - 00000000 ____D C:\Users\Robert\Documents\Boots & Coots
2012-06-08 07:29 - 2012-06-08 07:29 - 00319967 ____N C:\Users\Robert\Desktop\IMG_1940.JPG
2012-06-08 07:29 - 2012-06-08 07:24 - 00307854 ____N C:\Users\Robert\Desktop\IMG_1941.JPG
2012-06-05 08:14 - 2012-06-05 08:14 - 00226816 ____A C:\Users\Robert\Desktop\MSS ShipmentOpen order 6-05-2012.xls
2012-06-04 07:06 - 2012-06-04 07:06 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-30 10:17 - 2012-05-30 10:17 - 00223232 ____A C:\Users\Robert\Desktop\MSS ShipmentOpen order 5-30-2012.xls
2012-05-25 05:05 - 2012-05-25 05:05 - 00000000 ____D C:\Users\Robert\Documents\Diablo III
2012-05-25 05:01 - 2012-05-25 05:02 - 87207472 ____A (Intel Corporation) C:\Users\Robert\Downloads\Win7Vista_64_152254.exe
2012-05-24 12:37 - 2012-05-24 12:37 - 01411314 ____A C:\Users\Robert\Desktop\Equifax report 5-2012.pdf
2012-05-24 12:37 - 2012-05-24 12:37 - 00001123 ____A C:\Users\Robert\Desktop\Equifax report 5-2012.log
2012-05-24 10:52 - 2012-05-25 05:05 - 00000000 ____D C:\Program Files (x86)\Diablo III
2012-05-24 10:52 - 2012-05-24 10:52 - 00001193 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-22 11:38 - 2012-05-22 11:38 - 00102400 ____A C:\Users\Robert\Desktop\Copy of Blueline RFQ#8119.xls
2012-05-21 10:42 - 2012-05-21 10:42 - 01065984 ____A C:\Users\Robert\Desktop\Copy of PHYSICAL INVENTORY 5-21-2012.xls
2012-05-15 10:57 - 2012-05-15 10:57 - 00408388 ____A C:\Users\Robert\Desktop\Approved_Mill_list_by_Material 4-17-2012.pdf
============ 3 Months Modified Files and Folders =============
2012-06-12 13:21 - 2011-07-28 16:00 - 01376900 ____A C:\Windows\WindowsUpdate.log
2012-06-12 13:20 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-12 13:20 - 2009-07-13 20:51 - 00051137 ____A C:\Windows\setupact.log
2012-06-12 12:42 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\Robert
2012-06-12 12:42 - 2011-12-05 09:12 - 00000000 ____D C:\Users\Robert\Documents\Outlook Files
2012-06-12 12:39 - 2009-07-13 20:45 - 00020688 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-12 12:39 - 2009-07-13 20:45 - 00020688 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-12 12:38 - 2011-12-05 15:01 - 00000000 ____D C:\Users\Robert\AppData\Local\2801E5BF-F8F0-4A64-91C1-5F8C4DF05438.aplzod
2012-06-12 12:36 - 2012-06-12 12:36 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-12 12:36 - 2012-06-12 12:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-12 12:36 - 2012-01-31 05:52 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-12 12:36 - 2011-11-29 20:41 - 00743538 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-12 12:36 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-12 10:58 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\BlueLine
2012-06-12 10:54 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\Top-Co
2012-06-12 10:44 - 2012-06-11 11:51 - 00000000 ____D C:\Users\Robert\Documents\Boots & Coots
2012-06-12 09:26 - 2012-04-05 06:25 - 00000000 ____D C:\Users\Robert\Documents\Peak Completions
2012-06-12 09:26 - 2011-11-29 19:30 - 00000000 ____D C:\users\Robert
2012-06-12 07:26 - 2012-06-12 07:26 - 02565537 ____A C:\Users\Robert\Desktop\2.00 Bar 4340.pdf
2012-06-11 22:40 - 2011-12-03 00:18 - 00000000 ____D C:\Users\All Users\LogMeIn
2012-06-08 07:29 - 2012-06-08 07:29 - 00319967 ____N C:\Users\Robert\Desktop\IMG_1940.JPG
2012-06-08 07:24 - 2012-06-08 07:29 - 00307854 ____N C:\Users\Robert\Desktop\IMG_1941.JPG
2012-06-07 12:34 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\TAM
2012-06-06 14:02 - 2012-04-09 08:52 - 79685120 ____A C:\Users\Robert\Desktop\Copy of Form 7.2.1-5B INQUIRY Data Log.xls
2012-06-06 09:30 - 2011-12-02 22:00 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2012-06-05 12:22 - 2012-01-31 09:46 - 00000000 ____D C:\Users\Robert\AppData\Roaming\PrimoPDF
2012-06-05 08:14 - 2012-06-05 08:14 - 00226816 ____A C:\Users\Robert\Desktop\MSS ShipmentOpen order 6-05-2012.xls
2012-06-04 07:06 - 2012-06-04 07:06 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-04 07:04 - 2012-04-11 05:27 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-04 07:04 - 2011-12-05 07:24 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-01 13:58 - 2012-03-30 05:22 - 01163135 ____A C:\Users\Robert\Desktop\Prospect Database.xlsx
2012-05-30 10:17 - 2012-05-30 10:17 - 00223232 ____A C:\Users\Robert\Desktop\MSS ShipmentOpen order 5-30-2012.xls
2012-05-30 08:35 - 2011-12-03 02:16 - 00000000 ____D C:\Users\Robert\AppData\Local\Microsoft Help
2012-05-25 05:05 - 2012-05-25 05:05 - 00000000 ____D C:\Users\Robert\Documents\Diablo III
2012-05-25 05:05 - 2012-05-24 10:52 - 00000000 ____D C:\Program Files (x86)\Diablo III
2012-05-25 05:04 - 2011-07-28 16:17 - 00015824 ____A C:\Windows\System32\results.xml
2012-05-25 05:04 - 2010-11-20 19:47 - 00055790 ____A C:\Windows\PFRO.log
2012-05-25 05:02 - 2012-05-25 05:01 - 87207472 ____A (Intel Corporation) C:\Users\Robert\Downloads\Win7Vista_64_152254.exe
2012-05-24 12:37 - 2012-05-24 12:37 - 01411314 ____A C:\Users\Robert\Desktop\Equifax report 5-2012.pdf
2012-05-24 12:37 - 2012-05-24 12:37 - 00001123 ____A C:\Users\Robert\Desktop\Equifax report 5-2012.log
2012-05-24 10:52 - 2012-05-24 10:52 - 00001193 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-24 09:25 - 2012-04-05 07:23 - 00000000 ____D C:\Program Files (x86)\World of Warcraft Beta
2012-05-23 07:52 - 2012-04-30 11:31 - 00212480 ____A C:\Users\Robert\Desktop\Copy of MSS Shipment Open order Apr30.xls
2012-05-22 11:38 - 2012-05-22 11:38 - 00102400 ____A C:\Users\Robert\Desktop\Copy of Blueline RFQ#8119.xls
2012-05-21 10:42 - 2012-05-21 10:42 - 01065984 ____A C:\Users\Robert\Desktop\Copy of PHYSICAL INVENTORY 5-21-2012.xls
2012-05-21 07:18 - 2011-12-03 00:18 - 00000000 ____D C:\Program Files (x86)\LogMeIn
2012-05-21 07:17 - 2011-12-03 00:18 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-05-21 07:17 - 2011-12-03 00:18 - 00080768 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-05-21 07:17 - 2011-12-03 00:18 - 00034688 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-05-15 10:57 - 2012-05-15 10:57 - 00408388 ____A C:\Users\Robert\Desktop\Approved_Mill_list_by_Material 4-17-2012.pdf
2012-05-11 14:51 - 2011-12-12 11:16 - 00000000 ____D C:\Users\Robert\AppData\Local\ElevatedDiagnostics
2012-05-11 10:55 - 2012-05-11 10:55 - 00090416 ____A C:\Users\Robert\Desktop\Texas Sales and Tax Resale Certificate.pdf
2012-05-11 10:14 - 2011-12-03 21:59 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Apple Computer
2012-05-11 10:04 - 2012-05-11 10:04 - 00000000 ____D C:\Program Files\iTunes
2012-05-11 10:04 - 2012-05-11 10:04 - 00000000 ____D C:\Program Files\iPod
2012-05-11 10:04 - 2012-05-11 10:04 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-05-11 00:25 - 2011-07-28 16:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-11 00:25 - 2009-07-13 20:45 - 00368888 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-11 00:08 - 2011-12-03 02:16 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-11 00:08 - 2011-12-02 22:58 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-11 00:00 - 2011-02-15 02:41 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-01 12:27 - 2012-05-01 12:27 - 01122816 ____N C:\Users\Robert\Desktop\Invoice Record 5-1-12.xls
2012-04-30 11:06 - 2012-04-30 11:06 - 02730280 ____A C:\Users\Robert\Desktop\20120430094229929.pdf
2012-04-30 05:02 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-04-13 13:39 - 2011-12-06 07:24 - 00001107 ____A C:\Windows\Brpfx04a.ini
2012-04-11 05:09 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-04-11 05:07 - 2012-04-11 05:07 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2012-04-11 05:07 - 2012-04-11 05:07 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2012-04-05 07:23 - 2012-04-05 07:23 - 31727744 ____A (Blizzard Entertainment) C:\Users\Robert\Downloads\World of Warcraft Beta Setup.exe
2012-04-05 05:50 - 2012-04-05 05:50 - 00000000 ____D C:\Users\All Users\Battle.net
2012-03-30 22:05 - 2012-05-10 18:59 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 20:39 - 2012-05-10 18:59 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-03-30 20:39 - 2012-05-10 18:59 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-03-30 19:10 - 2012-05-10 18:59 - 03146240 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-30 11:24 - 2012-03-14 07:34 - 00000000 ____D C:\Users\Robert\Documents\Sterling
2012-03-30 05:21 - 2012-03-29 14:26 - 01425757 ____A C:\Users\Robert\Desktop\Prospect Database.csv
2012-03-30 03:35 - 2012-05-10 18:59 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-29 11:34 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2012-03-28 10:56 - 2012-03-28 10:56 - 00000000 ____A C:\Users\Robert\Sti_Trace.log
2012-03-28 10:55 - 2011-12-06 08:05 - 00000000 ____D C:\Users\Robert\AppData\Roaming\ControlCenter4
2012-03-23 04:57 - 2012-03-23 04:56 - 00000000 ____D C:\Users\Robert\PTR Installer 4.0.0.12824 enUS
2012-03-20 17:44 - 2012-03-20 17:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-03-20 17:44 - 2012-03-20 17:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-03-19 08:24 - 2011-12-05 12:35 - 00000000 ____D C:\Users\Robert\Documents\Valveworks
2012-03-16 23:58 - 2012-05-10 18:59 - 00075120 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
ZeroAccess:
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}\@
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}\L
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}\n
C:\Windows\Installer\{520ac729-ba6c-1932-9308-bf7399ad8b20}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 5992.44 MB
Available physical RAM: 5267.33 MB
Total Pagefile: 5990.64 MB
Available Pagefile: 5256.92 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:906.34 GB) (Free:785.53 GB) NTFS
7 Drive j: (LEXAR) (Removable) (Total:1.87 GB) (Free:1.87 GB) FAT
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 Online 1912 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 906 GB 101 MB
Partition 3 OEM 25 GB 906 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 906 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 12
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 LENOVO_PART NTFS Partition 25 GB Healthy Hidden
======================================================================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1911 MB 16 KB
======================================================================================================
Disk: 5
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J LEXAR FAT Removable 1911 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-05-28 21:58
======================= End Of Log ==========================