Forgot to run Farbar in recovery. Here's the Farbar log ran in recovery mode:
Scan result of Farbar Recovery Scan Tool Version: 20-07-2012 01
Ran by SYSTEM at 23-07-2012 23:10:24
Running from F:\
Windows 7 Professional (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [316032 2011-03-14] (Conexant systems, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [497648 2010-09-16] (Adobe Systems Incorporated)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2011-07-08] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392472 2011-07-08] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [416024 2011-07-08] (Intel Corporation)
HKLM\...\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe" [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice [4035152 2011-09-22] (ESET)
HKLM\...\Run: [TNOD UP] "C:\Program Files (x86)\TNod User & Password Finder\TNODUP.exe" /I [947200 2012-03-04] (Tukero[X]Team)
HKLM-x32\...\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [112152 2011-01-17] (Intel Corporation)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2011-06-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2903448 2011-06-06] (Adobe Systems Inc.)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448 2011-11-02] (Research In Motion Limited)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [NACAgentUI] C:\Program Files (x86)\Cisco\Cisco NAC Agent\NACAgentUI.exe [529880 2012-05-30] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3521464 2012-05-29] (Samsung Electronics Co., Ltd.)
HKU\Allen\...\Run: [Google Update] "C:\Users\Allen\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-06-17] (Google Inc.)
HKU\Allen\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKU\Allen\...\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s [958392 2012-05-29] (Samsung)
HKU\Allen\...\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-05-29] ()
HKU\Allen\...\Run: [IBM] RUNDLL32.EXE C:\Users\Allen\AppData\Local\IBM\wznnpbul.dll,DllGetClassObject [762368 2012-07-23] ()
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
==================== Services (Whitelisted) ======
2 CxAudMsg; C:\Windows\system32\CxAudMsg64.exe [198784 2010-12-17] (Conexant Systems Inc.)
2 ekrn; "C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe" [974944 2011-09-22] (ESET)
2 IBMPMSVC; C:\Windows\System32\ibmpmsvc.exe [45928 2011-02-01] (Lenovo.)
2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [45496 2010-11-24] (Lenovo Group Limited)
2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [93032 2010-04-07] (Lenovo Group Limited)
2 NACAgent; "C:\Program Files (x86)\Cisco\Cisco NAC Agent\NACAgent.exe" [1154008 2012-05-30] (Cisco Systems, Inc.)
2 Pharos Systems ComTaskMaster; "C:\PROGRA~2\PHAROS~1\Core\CTskMstr.exe" [345600 2010-01-14] (Pharos Systems International)
2 SAService; C:\Windows\SysWow64\SAsrv.exe [446592 2011-03-14] (Conexant Systems, Inc.)
2 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [28672 2011-04-18] (Lenovo Group Limited)
2 TPHKLOAD; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [114024 2010-12-03] (Lenovo Group Limited)
2 TPHKSVC; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [64440 2010-12-02] (Lenovo Group Limited)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2656280 2011-01-17] (Intel Corporation)
3 WMZuneComm; "C:\Program Files\Zune\WMZuneComm.exe" [306400 2011-08-05] (Microsoft Corporation)
3 ZuneNetworkSvc; "C:\Program Files\Zune\ZuneNss.exe" [8277728 2011-08-05] (Microsoft Corporation)
3 ZuneWlanCfgSvc; "C:\Program Files\Zune\ZuneWlanCfgSvc.exe" [467680 2011-08-05] (Microsoft Corporation)
3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
========================== Drivers (Whitelisted) =============
3 5U877; C:\Windows\System32\Drivers\5U877.sys [166016 2011-03-04] (Ricoh co.,Ltd.)
2 eamonm; C:\Windows\System32\Drivers\eamonm.sys [202576 2011-08-09] (ESET)
1 ehdrv; C:\Windows\System32\Drivers\ehdrv.sys [146432 2011-08-04] (ESET)
2 epfw; C:\Windows\System32\Drivers\epfw.sys [187632 2011-08-04] (ESET)
1 EpfwLWF; C:\Windows\System32\Drivers\EpfwLWF.sys [38288 2011-08-04] (ESET)
0 epfwwfp; C:\Windows\System32\Drivers\epfwwfp.sys [62496 2011-08-04] (ESET)
1 HWiNFO32; \??\C:\Users\Allen\Desktop\Tools\hw64_382\HWiNFO64A.SYS [28032 2011-05-22] (REALiX(tm))
3 NPF; C:\Windows\System32\Drivers\NPF.sys [47632 2009-10-20] (CACE Technologies, Inc.)
2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam64.sys [1071032 2011-06-22] (Windows (R) Win 7 DDK provider)
3 ALSysIO; \??\C:\Users\Allen\AppData\Local\Temp\ALSysIO64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-23 21:50 - 2012-07-23 21:51 - 00028813 ____A C:\Users\Allen\Desktop\FRST.txt
2012-07-23 21:49 - 2012-07-23 21:50 - 00000000 ____D C:\FRST
2012-07-23 21:48 - 2012-07-23 21:49 - 01437781 ____A (Farbar) C:\Users\Allen\Desktop\FRST64.exe
2012-07-23 21:42 - 2009-07-13 17:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe
2012-07-23 21:35 - 2012-07-23 21:35 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-23 21:35 - 2012-07-23 21:35 - 00000000 ____D C:\Users\Allen\AppData\Roaming\Malwarebytes
2012-07-23 21:35 - 2012-07-23 21:35 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-23 21:34 - 2012-07-23 21:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-23 21:34 - 2012-07-03 12:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-23 21:32 - 2012-07-23 21:34 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Allen\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-23 17:22 - 2012-07-23 17:22 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-23 12:51 - 2012-07-23 17:33 - 00000000 ____D C:\Users\Allen\AppData\Local\IBM
2012-07-23 12:45 - 2012-07-23 21:43 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-23 12:45 - 2012-07-23 19:43 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-23 00:00 - 2012-07-23 00:00 - 00000000 ____D C:\Users\Allen\Desktop\Dumbfoundead - Love Everyday EP
2012-07-20 14:50 - 2012-07-20 14:52 - 00017584 ____A C:\Users\Allen\Desktop\2004 VW GTI MPG Record.xlsx
2012-07-11 00:01 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 23:58 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-10 23:58 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-10 23:58 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-10 23:58 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-10 23:58 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-10 23:58 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-10 23:58 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-10 23:58 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-10 23:58 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-10 23:58 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-10 23:58 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-10 23:58 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-10 23:58 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-10 23:58 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 23:58 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-10 23:58 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-10 23:58 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-10 23:58 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-10 23:58 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-10 23:58 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-10 23:58 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-10 23:58 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-10 23:58 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-10 23:58 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-10 23:58 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-10 23:58 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-10 23:58 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-10 23:58 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 18:43 - 2012-07-23 15:52 - 00000000 ____D C:\Users\Allen\Desktop\SJSU Biol 115
2012-07-10 17:09 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 17:09 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 17:09 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 17:09 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 17:09 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 17:09 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 17:09 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 17:09 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 17:09 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 17:09 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 17:09 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 17:09 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 17:09 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 17:09 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 17:09 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 17:09 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 17:09 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 17:09 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 17:09 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-08 19:17 - 2012-07-23 19:43 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-06 09:27 - 2012-07-10 21:18 - 00000000 ____D C:\Users\Allen\Desktop\New folder (2)
2012-07-03 08:21 - 2012-07-03 08:21 - 00000000 ____D C:\Users\Allen\AppData\Local\Samsung
2012-07-03 08:20 - 2012-07-03 08:20 - 00000000 ____D C:\Users\Allen\Documents\samsung
2012-07-03 08:20 - 2012-07-03 08:20 - 00000000 ____D C:\Users\Allen\AppData\Roaming\Samsung
2012-07-02 22:19 - 2012-07-02 22:19 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2012-07-02 22:12 - 2012-05-20 18:09 - 00203320 ____A (DEVGURU Co., LTD.(
www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudmdm.sys
2012-07-02 22:12 - 2012-05-20 18:09 - 00099384 ____A (DEVGURU Co., LTD.(
www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudbus.sys
2012-07-02 22:11 - 2012-07-02 22:11 - 00000000 ____D C:\Program Files (x86)\MarkAny
2012-07-02 22:11 - 2012-05-23 17:50 - 04659712 ____A (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll
2012-07-02 22:11 - 2012-05-23 17:49 - 00821824 ____A (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll
2012-07-02 22:10 - 2012-07-02 22:12 - 00000000 ____D C:\Program Files (x86)\Samsung
2012-07-02 22:10 - 2012-07-02 22:11 - 00000000 ____D C:\Users\All Users\Samsung
2012-07-02 14:51 - 2012-07-22 22:07 - 00000000 ____D C:\Users\Allen\Desktop\New folder
2012-06-30 17:40 - 2012-06-30 17:45 - 00000079 ____A C:\Users\Allen\AppData\Local\CrystalDiskMark30.ini
2012-06-30 17:40 - 2012-06-30 17:40 - 00000000 ____D C:\Program Files\CrystalDiskMark
2012-06-27 18:20 - 2012-06-27 18:20 - 00000000 ____D C:\Program Files (x86)\ETS
2012-06-26 19:43 - 2012-07-21 20:34 - 00000000 ____D C:\Users\Allen\Downloads\Royal Pains - Season 4
============ 3 Months Modified Files ========================
2012-07-23 22:06 - 2011-06-17 17:09 - 01321303 ____A C:\Windows\WindowsUpdate.log
2012-07-23 22:06 - 2009-07-13 20:45 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-23 22:06 - 2009-07-13 20:45 - 00014256 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-23 22:03 - 2012-05-17 12:28 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-23 22:03 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-23 22:03 - 2009-07-13 20:51 - 00104597 ____A C:\Windows\setupact.log
2012-07-23 21:51 - 2012-07-23 21:50 - 00028813 ____A C:\Users\Allen\Desktop\FRST.txt
2012-07-23 21:49 - 2012-07-23 21:48 - 01437781 ____A (Farbar) C:\Users\Allen\Desktop\FRST64.exe
2012-07-23 21:43 - 2012-07-23 12:45 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-23 21:41 - 2011-06-17 18:01 - 00108014 ____A C:\Windows\PFRO.log
2012-07-23 21:38 - 2012-05-17 12:28 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-23 21:35 - 2012-07-23 21:35 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-23 21:34 - 2012-07-23 21:32 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Allen\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-23 21:18 - 2011-06-17 18:43 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1124499093-1064903183-2403554625-1000UA.job
2012-07-23 21:05 - 2011-06-17 18:43 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1124499093-1064903183-2403554625-1000Core.job
2012-07-23 19:43 - 2012-07-23 12:45 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-23 19:43 - 2012-07-08 19:17 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-20 14:52 - 2012-07-20 14:50 - 00017584 ____A C:\Users\Allen\Desktop\2004 VW GTI MPG Record.xlsx
2012-07-17 16:01 - 2009-07-13 21:08 - 00032624 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-16 16:26 - 2009-07-13 21:13 - 00739918 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-11 07:10 - 2009-07-13 20:45 - 04964272 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-10 23:59 - 2011-06-17 19:21 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 12:46 - 2012-07-23 21:34 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 22:19 - 2012-07-02 22:19 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2012-06-30 19:46 - 2011-06-17 17:29 - 00107248 ____A C:\Users\Allen\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-30 17:45 - 2012-06-30 17:40 - 00000079 ____A C:\Users\Allen\AppData\Local\CrystalDiskMark30.ini
2012-06-29 19:36 - 2012-01-04 13:23 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys
2012-06-29 19:36 - 2012-01-04 13:23 - 00000470 ____A C:\Windows\LkmdfCoInst.log
2012-06-18 18:09 - 2011-07-21 17:21 - 00185340 ___AH C:\Windows\SysWOW64\mlfcache.dat
2012-06-14 11:23 - 2012-06-14 11:23 - 00004595 ____A C:\Users\Allen\.recently-used.xbel
2012-06-11 19:08 - 2012-07-11 00:01 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-10 17:09 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 17:09 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-10 17:09 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 17:09 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 17:09 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 17:09 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 17:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 17:09 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-21 09:53 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 09:53 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 09:53 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 09:53 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 09:53 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-06-21 09:52 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:15 - 2012-06-21 09:53 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 09:53 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 09:52 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-10 23:58 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-10 23:58 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-10 23:58 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-10 23:58 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-10 23:58 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-10 23:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-10 23:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-10 23:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-10 23:58 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-10 23:58 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-10 23:58 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-10 23:58 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-10 23:58 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-10 23:58 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-10 23:58 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-10 23:58 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-10 23:58 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-10 23:58 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-10 23:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 23:58 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-10 23:58 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-10 23:58 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 23:58 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 23:58 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-10 23:58 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-10 23:58 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 23:58 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 23:58 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 17:09 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 17:09 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 17:09 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 17:09 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 17:09 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 17:09 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 17:09 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 17:09 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 17:09 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 11:25 - 2011-06-17 17:44 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-05-28 23:38 - 2012-05-28 23:38 - 00330240 ____A ((?)????) C:\Windows\MASetupCaller.dll
2012-05-23 17:50 - 2012-07-02 22:11 - 04659712 ____A (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll
2012-05-23 17:49 - 2012-07-02 22:11 - 00821824 ____A (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00974848 ____A C:\Windows\SysWOW64\cis-2.4.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00569344 ____A ((c) MusicCity) C:\Windows\SysWOW64\muzdecode.ax
2012-05-23 17:49 - 2012-05-23 17:49 - 00491520 ____A (Musiccity Co.Ltd.) C:\Windows\SysWOW64\muzapp.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00352256 ____A (Sample Corporation) C:\Windows\SysWOW64\MSLUR71.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00258048 ____A ((c) PeeringPortal) C:\Windows\SysWOW64\muzoggsp.ax
2012-05-23 17:49 - 2012-05-23 17:49 - 00245760 ____A (Teruten Inc.) C:\Windows\SysWOW64\MSCLib.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00200704 ____A ( (c) MusicCity) C:\Windows\SysWOW64\muzwmts.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00172032 ____A (Musiccity Co.Ltd.) C:\Windows\SysWOW64\muzapp.exe
2012-05-23 17:49 - 2012-05-23 17:49 - 00155648 ____A (Teruten Inc.) C:\Windows\SysWOW64\MSFLib.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00143360 ____A C:\Windows\SysWOW64\3DAudio.ax
2012-05-23 17:49 - 2012-05-23 17:49 - 00135168 ____A (Musiccity Co.Ltd.) C:\Windows\SysWOW64\muzaf1.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00131072 ____A ((c) MusicCity) C:\Windows\SysWOW64\muzmpgsp.ax
2012-05-23 17:49 - 2012-05-23 17:49 - 00122880 ____A ((c) MUSICCITY) C:\Windows\SysWOW64\muzeffect.ax
2012-05-23 17:49 - 2012-05-23 17:49 - 00118784 ____A ((?)????) C:\Windows\SysWOW64\MaDRM.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00110592 ____A ((c) MusicCity) C:\Windows\SysWOW64\muzmp4sp.ax
2012-05-23 17:49 - 2012-05-23 17:49 - 00090112 ____A ((?)????) C:\Windows\MAMCityDownload.ocx
2012-05-23 17:49 - 2012-05-23 17:49 - 00081920 ____A C:\Windows\SysWOW64\issacapi_bs-2.3.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00065536 ____A C:\Windows\SysWOW64\issacapi_pe-2.3.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00057344 ____A C:\Windows\SysWOW64\issacapi_se-2.3.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00057344 ____A (Marktek) C:\Windows\SysWOW64\MK_Lyric.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00057344 ____A (Marktek Inc.) C:\Windows\SysWOW64\MTXSYNCICON.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00049152 ____A ((?) ????) C:\Windows\SysWOW64\MaJGUILib.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00045320 ____A (MARKANY) C:\Windows\SysWOW64\MAMACExtract.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00045056 ____A ((?) ????) C:\Windows\SysWOW64\MaXMLProto.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00045056 ____A ((?) ????) C:\Windows\SysWOW64\MACXMLProto.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00040960 ____A (Telechips Inc.,) C:\Windows\SysWOW64\MTTELECHIP.dll
2012-05-23 17:49 - 2012-05-23 17:49 - 00030568 ____A () C:\Windows\MusiccityDownload.exe
2012-05-23 17:49 - 2012-05-23 17:49 - 00024576 ____A ((?)????) C:\Windows\SysWOW64\MASetupCleaner.exe
2012-05-21 16:21 - 2011-08-09 10:39 - 00000218 ____A C:\Windows\SysWOW64\dvmenul.tgz
2012-05-21 16:21 - 2011-08-09 10:39 - 00000204 ____A C:\Windows\SysWOW64\dvmenul.dll
2012-05-21 16:21 - 2011-08-09 10:39 - 00000114 ____A C:\Windows\SysWOW64\prsgrc.tgz
2012-05-21 16:21 - 2011-08-09 10:39 - 00000100 ____A C:\Windows\SysWOW64\prsgrc.dll
2012-05-21 16:21 - 2011-08-09 10:39 - 00000086 ____A C:\Windows\SysWOW64\ssprs.tgz
2012-05-21 16:11 - 2012-05-21 16:11 - 00001025 ____A C:\Windows\SysWOW64\o8rdv6u.tgz
2012-05-21 16:11 - 2011-08-09 10:39 - 00001025 ____A C:\Windows\SysWOW64\o8rdv6u.dll
2012-05-21 16:11 - 2011-08-09 10:39 - 00001025 ____A C:\Windows\SysWOW64\grcauth2.dll
2012-05-21 16:11 - 2011-08-09 10:39 - 00001025 ____A C:\Windows\SysWOW64\grcauth1.dll
2012-05-21 16:11 - 2011-08-09 10:39 - 00001025 ____A C:\Windows\SysWOW64\clauth2.dll
2012-05-21 16:11 - 2011-08-09 10:39 - 00001025 ____A C:\Windows\SysWOW64\clauth1.dll
2012-05-21 16:11 - 2011-08-09 10:39 - 00000072 ____A C:\Windows\SysWOW64\ssprs.dll
2012-05-20 18:09 - 2012-07-02 22:12 - 00203320 ____A (DEVGURU Co., LTD.(
www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudmdm.sys
2012-05-20 18:09 - 2012-07-02 22:12 - 00099384 ____A (DEVGURU Co., LTD.(
www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudbus.sys
2012-05-19 17:00 - 2012-05-19 17:00 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2012-05-19 16:59 - 2012-05-19 16:59 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2012-05-19 16:59 - 2011-07-11 17:21 - 00009100 ____A C:\Users\Allen\AppData\Roaming\Rim.Desktop.Exception.log
2012-05-19 16:58 - 2012-05-19 16:57 - 00005632 ____A C:\Users\Allen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-19 16:58 - 2011-07-11 17:21 - 00002464 ____A C:\Users\Allen\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-05-04 03:06 - 2012-06-13 19:11 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 19:11 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 19:11 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-13 19:11 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-13 19:11 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-13 19:12 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 19:12 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 19:12 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
ZeroAccess:
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\@
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\L
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\U
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\L\00000004.@
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\U\00000004.@
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\U\00000008.@
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\U\000000cb.@
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\U\80000000.@
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\U\80000032.@
C:\Windows\Installer\{0774f8a3-82f5-b94f-3287-01de714cd844}\U\80000064.@
ZeroAccess:
C:\Users\Allen\AppData\Local\{0774f8a3-82f5-b94f-3287-01de714cd844}
C:\Users\Allen\AppData\Local\{0774f8a3-82f5-b94f-3287-01de714cd844}\@
C:\Users\Allen\AppData\Local\{0774f8a3-82f5-b94f-3287-01de714cd844}\L
C:\Users\Allen\AppData\Local\{0774f8a3-82f5-b94f-3287-01de714cd844}\n
C:\Users\Allen\AppData\Local\{0774f8a3-82f5-b94f-3287-01de714cd844}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
Possible MBR infection:
C:\Windows\svchost.exe
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 8075.23 MB
Available physical RAM: 7272.38 MB
Total Pagefile: 8073.38 MB
Available Pagefile: 7262.78 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:288.23 GB) (Free:119.67 GB) NTFS
2 Drive e: (Lenovo_Recovery) (Fixed) (Total:9.77 GB) (Free:1.48 GB) NTFS
3 Drive f: (ALLEN KIM!!) (Removable) (Total:1.86 GB) (Free:1.57 GB) FAT
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 1910 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 288 GB 101 MB
Partition 3 Primary 9 GB 288 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 288 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E Lenovo_Reco NTFS Partition 9 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1909 MB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F ALLEN KIM!! FAT Removable 1909 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-20 10:45
======================= End Of Log ==========================