@Broni, this morning I got prompted with an adobe flash update and could not get rid of it. I looked into it then and found it was from Adobe so I went ahead and installed it. However, after the installation there was a music playing from an unknown program. Then I know my computer got contracted with a virus. I tried to use Security Essential but found it got killed by the virus. I installed a fresh copy of SE and did a scan, and it prompted the Sirefef virus. After that, my computer always shut down with that 1 min prompt. I managed to use Kaspersly Rescue Disk boot time and then latest Hitmanpro when I can have a stable windows desktop to clean the sirefef. Please review the Farbar scan report and let me know what you think. Thanks!
Scan result of Farbar Recovery Scan Tool Version: 05-07-2012 01
Ran by SYSTEM at 05-07-2012 18:40:25
Running from G:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [166424 2009-11-21] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [390680 2009-11-21] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [410136 2009-11-21] (Intel Corporation)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-16] ()
HKLM\...\Run: [TpShocks] TpShocks.exe [x]
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-03] (Synaptics Incorporated)
HKLM\...\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [62312 2010-04-20] (Lenovo Group Limited)
HKLM\...\Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [x]
HKLM\...\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [69560 2010-07-27] (Lenovo Group Limited)
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [57928 2010-01-27] (LogMeIn, Inc.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [111640 2010-03-25] ()
HKLM-x32\...\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor [1129832 2010-08-24] (Lenovo Group Limited)
HKLM-x32\...\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide [2793304 2009-10-14] ()
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [37232 2008-06-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640376 2008-06-11] (Adobe Systems Inc.)
HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-11-12] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKU\Galen\...\Run: [Akamai NetSession Interface] "C:\Users\Galen\AppData\Local\Akamai\netsession_win.exe" [4327744 2012-05-26] (Akamai Technologies, Inc)
HKU\Galen\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-03] (Google Inc.)
HKU\Galen\...\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2011-11-11] (Apple Inc.)
HKU\Galen\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [357696 2010-04-01] (DT Soft Ltd)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (UPEK Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
AppInit_DLLs: acaptuser64.dll
Lsa: [Notification Packages] scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\ScanSnap Manager.lnk
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\ScanSnap Organizer PDF??.lnk
ShortcutTarget: ScanSnap Organizer PDF??.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\Users\Galen\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 Akamai; C:\program files (x86)\common files\akamai/netsession_win_80c2ffa.dll [3417376 2012-05-29] ()
2 AlipaySecSvc; C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe [303968 2012-06-18] (Alipay Inc. )
2 AliveSvc; C:\Program Files (x86)\Common Files\alipay\AliveService\AliveService.exe [110432 2012-06-18] (Alipay Inc. )
3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe -service [1296728 2010-12-28] (www.BitComet.com)
3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [164200 2010-08-24] (Lenovo.)
2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [108392 2012-07-05] (SurfRight B.V.)
2 IBMPMSVC; C:\Windows\System32\ibmpmsvc.exe [43568 2007-05-31] (Lenovo)
2 ICBC Daemon Service; C:\Program Files (x86)\ICBCEbankTools\ICBCAntiPhishing\IcbcDaemon.exe [397216 2010-09-17] ()
2 IDriveE Service; "C:\IDrive\IDriveE Service.exe" [148936 2010-12-21] (Pro Softnet Corporation)
2 LENOVO.CAMMUTE; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [50536 2010-04-20] (Lenovo Group Limited)
2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [45496 2010-04-07] (Lenovo Group Limited)
2 LENOVO.TPKNRSVC; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [74088 2010-04-20] (Lenovo Group Limited)
2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [93032 2010-04-07] (Lenovo Group Limited)
2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375176 2012-05-21] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147336 2012-05-21] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2010-12-14] (LogMeIn, Inc.)
2 LVPrcS64; "C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe" [191000 2009-10-06] (Logitech Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2011-03-31] ()
2 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [28672 2009-10-19] (Lenovo Group Limited)
2 TomTomHOMEService; C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [92008 2010-08-24] (TomTom)
3 TPHDEXLGSVC; C:\Windows\System32\TPHDEXLG64.exe [47656 2009-10-09] (Lenovo.)
2 TPHKSVC; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [63928 2010-04-07] (Lenovo Group Limited)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2320920 2010-03-25] (Intel Corporation)
2 XLDoctor Services; C:\Program Files\Thunder Network\Thunder\Program\DctSer.exe [38704 2010-12-21] (ShenZhen Xunlei Networking Technologies,LTD)
========================== Drivers (Whitelisted) =============
3 5U877; C:\Windows\System32\Drivers\5U877.sys [163072 2009-12-14] (Ricoh co.,Ltd.)
0 DzHDD64; C:\Windows\System32\Drivers\DzHDD64.sys [30320 2010-08-24] (Lenovo.)
3 e1kexpress; C:\Windows\System32\DRIVERS\e1k62x64.sys [294064 2009-12-10] (Intel Corporation)
3 IBMPMDRV; C:\Windows\System32\Drivers\IBMPMDRV.sys [26928 2007-05-31] (Lenovo.)
3 jumi; C:\Windows\System32\Drivers\jumi.sys [15160 2010-06-03] (Windows (R) Codename Longhorn DDK provider)
1 lenovo.smi; C:\Windows\System32\DRIVERS\smiifx64.sys [15400 2008-05-12] (Lenovo Group Limited)
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2010-01-27] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\Drivers\lmimirr.sys [11552 2010-01-27] (LogMeIn, Inc.)
2 LMIRfsDriver; C:\Windows\System32\Drivers\LMIRfsDriver.sys [72216 2010-01-27] (LogMeIn, Inc.)
3 LVPr2M64; C:\Windows\System32\Drivers\LVPr2M64.sys [30232 2009-10-06] ()
3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-06] ()
3 psadd; C:\Windows\System32\Drivers\psadd.sys [40512 2010-09-21] (Lenovo (United States) Inc.)
0 Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [136744 2009-10-09] (Lenovo.)
2 smihlp; \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13840 2009-03-13] (UPEK Inc.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [503352 2010-09-22] (Duplex Secure Ltd.)
3 tcphoc; \??\C:\Program Files\Thunder Network\Thunder\XLDoctor\7.1.4.2104_1\Program\tcphoc.sys [8488 2010-12-21] ()
0 TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [23592 2009-10-09] (Lenovo.)
1 TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [13104 2010-08-24] ()
3 ALSysIO; \??\C:\Users\Galen\AppData\Local\Temp\ALSysIO64.sys [x]
4 LMIRfsClientNP; [x]
1 MpKsl627c29fc; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2F96D010-7454-4101-AEB5-6410B55378A5}\MpKsl627c29fc.sys [x]
3 PCDSRVC{127174DC-C366ED8B-06020000}_0; \??\c:\program files\pc-doctor\pcdsrvc_x64.pkms [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-05 14:17 - 2012-07-05 14:17 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-05 14:17 - 2012-07-05 14:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-05 14:01 - 2012-07-05 14:01 - 00002094 ____A C:\Windows\System32\.crusader
2012-07-05 13:49 - 2012-07-05 13:49 - 00001893 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2012-07-05 13:49 - 2012-07-05 13:49 - 00000000 ____D C:\Program Files\HitmanPro
2012-07-05 13:48 - 2012-07-05 14:01 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-07-05 13:32 - 2012-07-05 13:32 - 00000000 ____D C:\FRST
2012-07-05 09:21 - 2012-07-05 09:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF040CD3B7F904B9
2012-07-05 09:18 - 2012-07-05 09:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.078259FBB32C1E34
2012-07-05 09:12 - 2012-07-05 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC17100E5EA443EC
2012-07-05 09:04 - 2012-07-05 09:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5CF0CCEC7565E27
2012-07-05 08:56 - 2012-07-05 08:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BEB257E28C1EFEF6
2012-07-05 08:53 - 2012-07-05 08:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6080D7A29578C176
2012-07-05 08:45 - 2012-07-05 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.303D21590922E5F0
2012-07-05 08:39 - 2012-07-05 08:39 - 12621696 ____A (Microsoft Corporation) C:\Users\Galen\Desktop\mseinstall.exe
2012-07-05 07:32 - 2012-07-05 07:32 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-10 17:25 - 2012-06-10 17:25 - 00000025 ____A C:\Windows\libem.INI
2012-06-10 17:24 - 2012-06-10 17:48 - 00000000 ____D C:\Users\Galen\AppData\Roaming\BITS
2012-06-10 17:24 - 2012-06-10 17:30 - 00000380 ____A C:\Windows\SysWOW64\secustat.dat
2012-06-10 17:24 - 2012-06-10 17:30 - 00000000 ____D C:\Users\Galen\AppData\Roaming\FlashGet
2012-06-10 17:24 - 2012-06-10 17:25 - 00001184 ____A C:\Windows\SysWOW64\secushr.dat
2012-06-10 17:24 - 2012-06-10 17:24 - 00001251 ____A C:\Users\Galen\Desktop\??(FlashGet)3.lnk
2012-06-10 17:24 - 2012-06-10 17:24 - 00000000 ____D C:\Users\Galen\AppData\Roaming\FlashGetBHO
2012-06-10 17:24 - 2012-06-10 17:24 - 00000000 ____D C:\Program Files (x86)\FlashGet Network
2012-06-10 17:23 - 2012-06-10 17:24 - 00000000 ____D C:\Users\Galen\AppData\Roaming\FlashgetSetup
============ 3 Months Modified Files ========================
2012-07-05 14:36 - 2010-09-21 08:57 - 00106584 ____A C:\Windows\PFRO.log
2012-07-05 14:36 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-05 14:36 - 2009-07-13 20:51 - 00082262 ____A C:\Windows\setupact.log
2012-07-05 14:33 - 2011-09-05 19:31 - 00000472 ____A C:\Windows\Tasks\AliUpdater{054C6697-5BED-4BB8-8AC4-9DB48B974069}.job
2012-07-05 14:33 - 2010-10-03 13:45 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-05 14:33 - 2010-09-21 07:37 - 02794907 ____A C:\Windows\WindowsUpdate.log
2012-07-05 14:17 - 2011-02-06 18:13 - 00722628 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-05 14:17 - 2011-02-06 18:13 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-05 14:10 - 2009-07-13 20:45 - 00014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-05 14:10 - 2009-07-13 20:45 - 00014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-05 14:01 - 2012-07-05 14:01 - 00002094 ____A C:\Windows\System32\.crusader
2012-07-05 13:49 - 2012-07-05 13:49 - 00001893 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2012-07-05 09:21 - 2012-07-05 09:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF040CD3B7F904B9
2012-07-05 09:18 - 2012-07-05 09:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.078259FBB32C1E34
2012-07-05 09:12 - 2012-07-05 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC17100E5EA443EC
2012-07-05 09:04 - 2012-07-05 09:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5CF0CCEC7565E27
2012-07-05 08:56 - 2012-07-05 08:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BEB257E28C1EFEF6
2012-07-05 08:53 - 2012-07-05 08:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6080D7A29578C176
2012-07-05 08:45 - 2012-07-05 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.303D21590922E5F0
2012-07-05 08:39 - 2012-07-05 08:39 - 12621696 ____A (Microsoft Corporation) C:\Users\Galen\Desktop\mseinstall.exe
2012-07-05 08:32 - 2010-09-28 13:47 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1296915308-539289633-2008221298-1000UA.job
2012-07-05 07:30 - 2010-10-03 13:45 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-05 07:29 - 2012-04-05 10:17 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-05 07:29 - 2011-05-19 15:59 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-05 05:21 - 2010-09-21 08:42 - 00000332 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-07-05 05:19 - 2010-09-28 13:47 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1296915308-539289633-2008221298-1000Core.job
2012-07-01 13:50 - 2011-12-30 08:30 - 00002340 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-06-24 16:08 - 2009-07-13 21:13 - 00717324 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-17 13:13 - 2010-09-21 10:05 - 00000000 ____A C:\Windows\System32\Drivers\lvuvc.hs
2012-06-16 06:23 - 2010-09-21 10:04 - 00051666 ____A C:\Windows\System32\lvcoinst.log
2012-06-10 17:30 - 2012-06-10 17:24 - 00000380 ____A C:\Windows\SysWOW64\secustat.dat
2012-06-10 17:25 - 2012-06-10 17:25 - 00000025 ____A C:\Windows\libem.INI
2012-06-10 17:25 - 2012-06-10 17:24 - 00001184 ____A C:\Windows\SysWOW64\secushr.dat
2012-06-10 17:24 - 2012-06-10 17:24 - 00001251 ____A C:\Users\Galen\Desktop\??(FlashGet)3.lnk
2012-06-08 11:23 - 2010-09-21 08:42 - 00000528 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-06-04 20:01 - 2012-06-04 20:01 - 00001035 ____A C:\Users\Public\Desktop\????2012.lnk
2012-06-04 20:01 - 2009-07-13 18:34 - 00000504 ____A C:\Windows\win.ini
2012-05-21 16:05 - 2010-09-21 16:36 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-05-21 16:05 - 2010-09-21 16:36 - 00080768 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-05-21 16:05 - 2010-09-21 16:36 - 00034688 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-05-11 07:36 - 2010-10-09 18:49 - 00000928 ____A C:\Windows\System32\Drivers\etc\hosts.umbrella
2012-05-11 07:32 - 2010-10-17 14:56 - 00106907 ____A C:\Users\Galen\umbrella0.log
2012-05-01 12:11 - 2010-09-21 08:26 - 00113360 ____A C:\Users\Galen\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-01 12:10 - 2009-07-13 20:45 - 00429328 ____A C:\Windows\System32\FNTCACHE.DAT
2012-04-30 12:11 - 2010-10-16 10:10 - 00141312 ____A C:\Users\Galen\metadata.db
2012-04-30 05:59 - 2012-04-30 05:59 - 00002224 ____A C:\Users\Galen\Desktop\Kindle.lnk
2012-04-30 05:40 - 2010-10-16 10:06 - 00000960 ____A C:\Users\Public\Desktop\calibre - E-book management.lnk
2012-04-30 05:33 - 2012-04-30 05:33 - 46976360 ____A C:\Users\Galen\Downloads\calibre-0.8.49.msi
2012-04-25 18:58 - 2012-04-25 18:58 - 03466248 ____A (TrueCrypt Foundation) C:\Users\Galen\Desktop\TrueCrypt Setup 7.1a.exe
2012-04-20 16:31 - 2012-04-20 16:31 - 00002212 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-04-17 11:21 - 2012-04-17 11:20 - 00000037 ____A C:\Users\Galen\Desktop\moving company.txt
2012-04-16 09:41 - 2012-04-16 09:41 - 00047616 ____A C:\Windows\SysWOW64\pdf995mon64.dll
2012-04-07 07:27 - 2010-09-21 08:07 - 00025006 ____A C:\Windows\DPINST.LOG
2012-04-07 07:03 - 2012-04-07 07:03 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-04-07 07:03 - 2012-04-07 07:03 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-04-07 07:03 - 2012-04-07 07:03 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-04-07 07:03 - 2010-09-23 17:26 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-04-07 06:52 - 2012-03-19 20:03 - 00002021 ____A C:\Users\Galen\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-04-07 06:51 - 2012-04-07 06:51 - 00000460 ____A C:\Users\Galen\AppData\Local\ICBCAntiPhishing_2012_04_07.log
2012-04-07 06:44 - 2012-04-07 06:44 - 00525544 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-04-07 06:44 - 2012-04-07 06:44 - 00191264 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-04-07 06:44 - 2012-04-07 06:44 - 00172320 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-04-07 06:44 - 2012-04-07 06:44 - 00172320 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 16%
Total physical RAM: 3891.67 MB
Available physical RAM: 3265.27 MB
Total Pagefile: 3889.82 MB
Available Pagefile: 3255.43 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:117.19 GB) (Free:35.68 GB) NTFS
2 Drive e: () (Fixed) (Total:169.96 GB) (Free:126.11 GB) NTFS
3 Drive f: (Lenovo_Recovery) (Fixed) (Total:9.77 GB) (Free:3.73 GB) NTFS
4 Drive g: (CRUZER) (Removable) (Total:7.5 GB) (Free:7.21 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM_DRV) (Fixed) (Total:1.17 GB) (Free:0.39 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 7691 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1200 MB 1024 KB
Partition 2 Primary 117 GB 1201 MB
Partition 3 Primary 169 GB 118 GB
Partition 4 Primary 9 GB 288 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SYSTEM_DRV NTFS Partition 1200 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 117 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E NTFS Partition 169 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F Lenovo_Reco NTFS Partition 9 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7691 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G CRUZER FAT32 Removable 7691 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 10:25
======================= End Of Log =================
Scan result of Farbar Recovery Scan Tool Version: 05-07-2012 01
Ran by SYSTEM at 05-07-2012 18:40:25
Running from G:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [166424 2009-11-21] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [390680 2009-11-21] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [410136 2009-11-21] (Intel Corporation)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-16] ()
HKLM\...\Run: [TpShocks] TpShocks.exe [x]
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-03] (Synaptics Incorporated)
HKLM\...\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [62312 2010-04-20] (Lenovo Group Limited)
HKLM\...\Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [x]
HKLM\...\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [69560 2010-07-27] (Lenovo Group Limited)
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [57928 2010-01-27] (LogMeIn, Inc.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [111640 2010-03-25] ()
HKLM-x32\...\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor [1129832 2010-08-24] (Lenovo Group Limited)
HKLM-x32\...\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide [2793304 2009-10-14] ()
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [37232 2008-06-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640376 2008-06-11] (Adobe Systems Inc.)
HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-11-12] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKU\Galen\...\Run: [Akamai NetSession Interface] "C:\Users\Galen\AppData\Local\Akamai\netsession_win.exe" [4327744 2012-05-26] (Akamai Technologies, Inc)
HKU\Galen\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-03] (Google Inc.)
HKU\Galen\...\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2011-11-11] (Apple Inc.)
HKU\Galen\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [357696 2010-04-01] (DT Soft Ltd)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (UPEK Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
AppInit_DLLs: acaptuser64.dll
Lsa: [Notification Packages] scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\ScanSnap Manager.lnk
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\ScanSnap Organizer PDF??.lnk
ShortcutTarget: ScanSnap Organizer PDF??.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\Users\Galen\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 Akamai; C:\program files (x86)\common files\akamai/netsession_win_80c2ffa.dll [3417376 2012-05-29] ()
2 AlipaySecSvc; C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe [303968 2012-06-18] (Alipay Inc. )
2 AliveSvc; C:\Program Files (x86)\Common Files\alipay\AliveService\AliveService.exe [110432 2012-06-18] (Alipay Inc. )
3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe -service [1296728 2010-12-28] (www.BitComet.com)
3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [164200 2010-08-24] (Lenovo.)
2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [108392 2012-07-05] (SurfRight B.V.)
2 IBMPMSVC; C:\Windows\System32\ibmpmsvc.exe [43568 2007-05-31] (Lenovo)
2 ICBC Daemon Service; C:\Program Files (x86)\ICBCEbankTools\ICBCAntiPhishing\IcbcDaemon.exe [397216 2010-09-17] ()
2 IDriveE Service; "C:\IDrive\IDriveE Service.exe" [148936 2010-12-21] (Pro Softnet Corporation)
2 LENOVO.CAMMUTE; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [50536 2010-04-20] (Lenovo Group Limited)
2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [45496 2010-04-07] (Lenovo Group Limited)
2 LENOVO.TPKNRSVC; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [74088 2010-04-20] (Lenovo Group Limited)
2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [93032 2010-04-07] (Lenovo Group Limited)
2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375176 2012-05-21] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147336 2012-05-21] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2010-12-14] (LogMeIn, Inc.)
2 LVPrcS64; "C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe" [191000 2009-10-06] (Logitech Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2011-03-31] ()
2 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [28672 2009-10-19] (Lenovo Group Limited)
2 TomTomHOMEService; C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [92008 2010-08-24] (TomTom)
3 TPHDEXLGSVC; C:\Windows\System32\TPHDEXLG64.exe [47656 2009-10-09] (Lenovo.)
2 TPHKSVC; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [63928 2010-04-07] (Lenovo Group Limited)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2320920 2010-03-25] (Intel Corporation)
2 XLDoctor Services; C:\Program Files\Thunder Network\Thunder\Program\DctSer.exe [38704 2010-12-21] (ShenZhen Xunlei Networking Technologies,LTD)
========================== Drivers (Whitelisted) =============
3 5U877; C:\Windows\System32\Drivers\5U877.sys [163072 2009-12-14] (Ricoh co.,Ltd.)
0 DzHDD64; C:\Windows\System32\Drivers\DzHDD64.sys [30320 2010-08-24] (Lenovo.)
3 e1kexpress; C:\Windows\System32\DRIVERS\e1k62x64.sys [294064 2009-12-10] (Intel Corporation)
3 IBMPMDRV; C:\Windows\System32\Drivers\IBMPMDRV.sys [26928 2007-05-31] (Lenovo.)
3 jumi; C:\Windows\System32\Drivers\jumi.sys [15160 2010-06-03] (Windows (R) Codename Longhorn DDK provider)
1 lenovo.smi; C:\Windows\System32\DRIVERS\smiifx64.sys [15400 2008-05-12] (Lenovo Group Limited)
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2010-01-27] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\Drivers\lmimirr.sys [11552 2010-01-27] (LogMeIn, Inc.)
2 LMIRfsDriver; C:\Windows\System32\Drivers\LMIRfsDriver.sys [72216 2010-01-27] (LogMeIn, Inc.)
3 LVPr2M64; C:\Windows\System32\Drivers\LVPr2M64.sys [30232 2009-10-06] ()
3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-06] ()
3 psadd; C:\Windows\System32\Drivers\psadd.sys [40512 2010-09-21] (Lenovo (United States) Inc.)
0 Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [136744 2009-10-09] (Lenovo.)
2 smihlp; \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13840 2009-03-13] (UPEK Inc.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [503352 2010-09-22] (Duplex Secure Ltd.)
3 tcphoc; \??\C:\Program Files\Thunder Network\Thunder\XLDoctor\7.1.4.2104_1\Program\tcphoc.sys [8488 2010-12-21] ()
0 TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [23592 2009-10-09] (Lenovo.)
1 TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [13104 2010-08-24] ()
3 ALSysIO; \??\C:\Users\Galen\AppData\Local\Temp\ALSysIO64.sys [x]
4 LMIRfsClientNP; [x]
1 MpKsl627c29fc; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2F96D010-7454-4101-AEB5-6410B55378A5}\MpKsl627c29fc.sys [x]
3 PCDSRVC{127174DC-C366ED8B-06020000}_0; \??\c:\program files\pc-doctor\pcdsrvc_x64.pkms [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-05 14:17 - 2012-07-05 14:17 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-05 14:17 - 2012-07-05 14:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-05 14:01 - 2012-07-05 14:01 - 00002094 ____A C:\Windows\System32\.crusader
2012-07-05 13:49 - 2012-07-05 13:49 - 00001893 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2012-07-05 13:49 - 2012-07-05 13:49 - 00000000 ____D C:\Program Files\HitmanPro
2012-07-05 13:48 - 2012-07-05 14:01 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-07-05 13:32 - 2012-07-05 13:32 - 00000000 ____D C:\FRST
2012-07-05 09:21 - 2012-07-05 09:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF040CD3B7F904B9
2012-07-05 09:18 - 2012-07-05 09:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.078259FBB32C1E34
2012-07-05 09:12 - 2012-07-05 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC17100E5EA443EC
2012-07-05 09:04 - 2012-07-05 09:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5CF0CCEC7565E27
2012-07-05 08:56 - 2012-07-05 08:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BEB257E28C1EFEF6
2012-07-05 08:53 - 2012-07-05 08:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6080D7A29578C176
2012-07-05 08:45 - 2012-07-05 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.303D21590922E5F0
2012-07-05 08:39 - 2012-07-05 08:39 - 12621696 ____A (Microsoft Corporation) C:\Users\Galen\Desktop\mseinstall.exe
2012-07-05 07:32 - 2012-07-05 07:32 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-10 17:25 - 2012-06-10 17:25 - 00000025 ____A C:\Windows\libem.INI
2012-06-10 17:24 - 2012-06-10 17:48 - 00000000 ____D C:\Users\Galen\AppData\Roaming\BITS
2012-06-10 17:24 - 2012-06-10 17:30 - 00000380 ____A C:\Windows\SysWOW64\secustat.dat
2012-06-10 17:24 - 2012-06-10 17:30 - 00000000 ____D C:\Users\Galen\AppData\Roaming\FlashGet
2012-06-10 17:24 - 2012-06-10 17:25 - 00001184 ____A C:\Windows\SysWOW64\secushr.dat
2012-06-10 17:24 - 2012-06-10 17:24 - 00001251 ____A C:\Users\Galen\Desktop\??(FlashGet)3.lnk
2012-06-10 17:24 - 2012-06-10 17:24 - 00000000 ____D C:\Users\Galen\AppData\Roaming\FlashGetBHO
2012-06-10 17:24 - 2012-06-10 17:24 - 00000000 ____D C:\Program Files (x86)\FlashGet Network
2012-06-10 17:23 - 2012-06-10 17:24 - 00000000 ____D C:\Users\Galen\AppData\Roaming\FlashgetSetup
============ 3 Months Modified Files ========================
2012-07-05 14:36 - 2010-09-21 08:57 - 00106584 ____A C:\Windows\PFRO.log
2012-07-05 14:36 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-05 14:36 - 2009-07-13 20:51 - 00082262 ____A C:\Windows\setupact.log
2012-07-05 14:33 - 2011-09-05 19:31 - 00000472 ____A C:\Windows\Tasks\AliUpdater{054C6697-5BED-4BB8-8AC4-9DB48B974069}.job
2012-07-05 14:33 - 2010-10-03 13:45 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-05 14:33 - 2010-09-21 07:37 - 02794907 ____A C:\Windows\WindowsUpdate.log
2012-07-05 14:17 - 2011-02-06 18:13 - 00722628 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-05 14:17 - 2011-02-06 18:13 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-05 14:10 - 2009-07-13 20:45 - 00014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-05 14:10 - 2009-07-13 20:45 - 00014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-05 14:01 - 2012-07-05 14:01 - 00002094 ____A C:\Windows\System32\.crusader
2012-07-05 13:49 - 2012-07-05 13:49 - 00001893 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2012-07-05 09:21 - 2012-07-05 09:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF040CD3B7F904B9
2012-07-05 09:18 - 2012-07-05 09:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.078259FBB32C1E34
2012-07-05 09:12 - 2012-07-05 09:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC17100E5EA443EC
2012-07-05 09:04 - 2012-07-05 09:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5CF0CCEC7565E27
2012-07-05 08:56 - 2012-07-05 08:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BEB257E28C1EFEF6
2012-07-05 08:53 - 2012-07-05 08:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6080D7A29578C176
2012-07-05 08:45 - 2012-07-05 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.303D21590922E5F0
2012-07-05 08:39 - 2012-07-05 08:39 - 12621696 ____A (Microsoft Corporation) C:\Users\Galen\Desktop\mseinstall.exe
2012-07-05 08:32 - 2010-09-28 13:47 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1296915308-539289633-2008221298-1000UA.job
2012-07-05 07:30 - 2010-10-03 13:45 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-05 07:29 - 2012-04-05 10:17 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-05 07:29 - 2011-05-19 15:59 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-05 05:21 - 2010-09-21 08:42 - 00000332 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-07-05 05:19 - 2010-09-28 13:47 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1296915308-539289633-2008221298-1000Core.job
2012-07-01 13:50 - 2011-12-30 08:30 - 00002340 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-06-24 16:08 - 2009-07-13 21:13 - 00717324 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-17 13:13 - 2010-09-21 10:05 - 00000000 ____A C:\Windows\System32\Drivers\lvuvc.hs
2012-06-16 06:23 - 2010-09-21 10:04 - 00051666 ____A C:\Windows\System32\lvcoinst.log
2012-06-10 17:30 - 2012-06-10 17:24 - 00000380 ____A C:\Windows\SysWOW64\secustat.dat
2012-06-10 17:25 - 2012-06-10 17:25 - 00000025 ____A C:\Windows\libem.INI
2012-06-10 17:25 - 2012-06-10 17:24 - 00001184 ____A C:\Windows\SysWOW64\secushr.dat
2012-06-10 17:24 - 2012-06-10 17:24 - 00001251 ____A C:\Users\Galen\Desktop\??(FlashGet)3.lnk
2012-06-08 11:23 - 2010-09-21 08:42 - 00000528 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-06-04 20:01 - 2012-06-04 20:01 - 00001035 ____A C:\Users\Public\Desktop\????2012.lnk
2012-06-04 20:01 - 2009-07-13 18:34 - 00000504 ____A C:\Windows\win.ini
2012-05-21 16:05 - 2010-09-21 16:36 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-05-21 16:05 - 2010-09-21 16:36 - 00080768 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-05-21 16:05 - 2010-09-21 16:36 - 00034688 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-05-11 07:36 - 2010-10-09 18:49 - 00000928 ____A C:\Windows\System32\Drivers\etc\hosts.umbrella
2012-05-11 07:32 - 2010-10-17 14:56 - 00106907 ____A C:\Users\Galen\umbrella0.log
2012-05-01 12:11 - 2010-09-21 08:26 - 00113360 ____A C:\Users\Galen\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-01 12:10 - 2009-07-13 20:45 - 00429328 ____A C:\Windows\System32\FNTCACHE.DAT
2012-04-30 12:11 - 2010-10-16 10:10 - 00141312 ____A C:\Users\Galen\metadata.db
2012-04-30 05:59 - 2012-04-30 05:59 - 00002224 ____A C:\Users\Galen\Desktop\Kindle.lnk
2012-04-30 05:40 - 2010-10-16 10:06 - 00000960 ____A C:\Users\Public\Desktop\calibre - E-book management.lnk
2012-04-30 05:33 - 2012-04-30 05:33 - 46976360 ____A C:\Users\Galen\Downloads\calibre-0.8.49.msi
2012-04-25 18:58 - 2012-04-25 18:58 - 03466248 ____A (TrueCrypt Foundation) C:\Users\Galen\Desktop\TrueCrypt Setup 7.1a.exe
2012-04-20 16:31 - 2012-04-20 16:31 - 00002212 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-04-17 11:21 - 2012-04-17 11:20 - 00000037 ____A C:\Users\Galen\Desktop\moving company.txt
2012-04-16 09:41 - 2012-04-16 09:41 - 00047616 ____A C:\Windows\SysWOW64\pdf995mon64.dll
2012-04-07 07:27 - 2010-09-21 08:07 - 00025006 ____A C:\Windows\DPINST.LOG
2012-04-07 07:03 - 2012-04-07 07:03 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-04-07 07:03 - 2012-04-07 07:03 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-04-07 07:03 - 2012-04-07 07:03 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-04-07 07:03 - 2010-09-23 17:26 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-04-07 06:52 - 2012-03-19 20:03 - 00002021 ____A C:\Users\Galen\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-04-07 06:51 - 2012-04-07 06:51 - 00000460 ____A C:\Users\Galen\AppData\Local\ICBCAntiPhishing_2012_04_07.log
2012-04-07 06:44 - 2012-04-07 06:44 - 00525544 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2012-04-07 06:44 - 2012-04-07 06:44 - 00191264 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2012-04-07 06:44 - 2012-04-07 06:44 - 00172320 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2012-04-07 06:44 - 2012-04-07 06:44 - 00172320 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 16%
Total physical RAM: 3891.67 MB
Available physical RAM: 3265.27 MB
Total Pagefile: 3889.82 MB
Available Pagefile: 3255.43 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:117.19 GB) (Free:35.68 GB) NTFS
2 Drive e: () (Fixed) (Total:169.96 GB) (Free:126.11 GB) NTFS
3 Drive f: (Lenovo_Recovery) (Fixed) (Total:9.77 GB) (Free:3.73 GB) NTFS
4 Drive g: (CRUZER) (Removable) (Total:7.5 GB) (Free:7.21 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM_DRV) (Fixed) (Total:1.17 GB) (Free:0.39 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 7691 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1200 MB 1024 KB
Partition 2 Primary 117 GB 1201 MB
Partition 3 Primary 169 GB 118 GB
Partition 4 Primary 9 GB 288 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SYSTEM_DRV NTFS Partition 1200 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 117 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E NTFS Partition 169 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F Lenovo_Reco NTFS Partition 9 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7691 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G CRUZER FAT32 Removable 7691 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 10:25
======================= End Of Log =================