Xtreme4U2NV
Posts: 16 +0
Same as I've read in a few posts already, I too am infected with Sirefef, here is my inital scan result:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 18-06-2012 02
Ran by SYSTEM at 19-06-2012 15:24:03
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [NBAgent] "C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart [1234216 2010-03-26] (Nero AG)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-05] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [NPSStartup] [x]
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [29984 2008-07-09] (Nuance Communications, Inc.)
HKLM\...\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [46368 2008-07-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini" [344 2012-06-19] ()
HKLM\...\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN [2621440 2010-02-09] (Brother Industries, Ltd.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Administrator\...\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\Administrator\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17148552 2012-02-29] (Skype Technologies S.A.)
HKLM\...\Runonce: [NCInstallQueue] rundll32 netman.dll,ProcessQueue [x]
HKLM\...\Winlogon: [Userinit] userinit.exe, [x]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 64.71.255.198
================================ Services (Whitelisted) ==================
3 BrYNSvc; "C:\Program Files\Browny02\BrYNSvc.exe" [245760 2010-01-25] (Brother Industries, Ltd.)
2 CcmExec; C:\Windows\system32\CCM\CcmExec.exe [757792 2008-05-20] (Microsoft Corporation)
2 EFS; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [556544 2010-11-20] (Microsoft Corporation)
3 ehSched; C:\Windows\ehome\ehsched.exe [94720 2009-07-13] (Microsoft Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
3 Fax; C:\Windows\System32\fxssvc.exe [523264 2010-11-20] (Microsoft Corporation)
2 HsfXAudioService; C:\Windows\system32\XAudio32.dll [410624 2009-04-28] (Conexant Systems, Inc.)
3 KeyIso; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 MSDTC; C:\Windows\System32\msdtc.exe [134144 2009-07-13] (Microsoft Corporation)
3 msiserver; C:\Windows\System32\msiexec.exe /V [73216 2010-11-20] (Microsoft Corporation)
2 msoidsvc; "C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE" [1589152 2011-09-28] (Microsoft Corp.)
2 NAUpdate; "C:\Program Files\Nero\Update\NASvc.exe" [490280 2010-03-25] (Nero AG)
3 Netlogon; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 ProtectedStorage; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 RpcLocator; C:\Windows\System32\locator.exe [9216 2009-07-13] (Microsoft Corporation)
2 SamSs; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [158856 2012-02-29] (Skype Technologies)
3 smstsmgr; C:\Windows\system32\CCM\TSManager.exe /service [249888 2008-05-20] (Microsoft Corporation)
3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2009-07-13] (Microsoft Corporation)
2 Spooler; C:\Windows\System32\spoolsv.exe [317440 2010-11-20] (Microsoft Corporation)
2 sppsvc; C:\Windows\System32\sppsvc.exe [3179520 2010-11-20] (Microsoft Corporation)
3 StorSvc; C:\Windows\System32\storsvc.dll [16384 2009-07-13] (Microsoft Corporation)
3 SwitchBoard; "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [517096 2010-02-19] (Adobe Systems Incorporated)
3 UI0Detect; C:\Windows\System32\UI0Detect.exe [35840 2009-07-13] (Microsoft Corporation)
3 VaultSvc; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 vds; C:\Windows\System32\vds.exe [453632 2010-11-20] (Microsoft Corporation)
3 VSS; C:\Windows\System32\vssvc.exe [1025536 2010-11-20] (Microsoft Corporation)
3 wbengine; "C:\Windows\system32\wbengine.exe" [1203200 2010-11-20] (Microsoft Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [36608 2010-06-14] ()
3 HpqRemHid; C:\Windows\System32\DRIVERS\HpqRemHid.sys [7168 2007-07-10] (Hewlett-Packard Development Company, L.P.)
3 HSF_DPV; C:\Windows\System32\DRIVERS\HSX_DPV.sys [980992 2009-02-12] (Conexant Systems, Inc.)
3 iirsp; C:\Windows\system32\DRIVERS\iirsp.sys [41040 2009-07-13] (Intel Corp./ICP vortex GmbH)
2 mdmxsdk; C:\Windows\System32\DRIVERS\mdmxsdk.sys [12672 2006-06-17] (Conexant)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [47360 2010-06-21] (VSO Software)
3 prepdrvr; \??\C:\Windows\system32\CCM\prepdrv.sys [23584 2008-05-20] (Microsoft Corporation)
3 ROOTMODEM; C:\Windows\System32\Drivers\RootMdm.sys [8192 2009-07-13] (Microsoft Corporation)
3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL3.SYS [207360 2009-07-13] (Conexant Systems, Inc.)
3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV3.SYS [980992 2009-07-13] (Conexant Systems, Inc.)
3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT3.SYS [661504 2009-07-13] (Conexant Systems, Inc.)
3 usb_rndisx; C:\Windows\System32\DRIVERS\usb8023x.sys [15872 2009-07-13] (Microsoft Corporation)
2 XAudio; C:\Windows\System32\DRIVERS\XAudio32.sys [8704 2009-04-28] (Conexant Systems, Inc.)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-13 17:06 - 2012-06-13 17:06 - 00000700 ____A C:\Windows\PFRO.log
2012-06-13 16:55 - 2012-06-13 16:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-04 14:57 - 2012-06-13 17:30 - 00478968 ____A C:\Windows\ntbtlog.txt
2012-05-29 15:35 - 2012-06-19 11:15 - 00048384 ____A C:\Windows\setupact.log
2012-05-29 15:35 - 2012-05-29 15:35 - 00000000 ____A C:\Windows\setuperr.log
2012-05-26 13:26 - 2012-05-28 13:17 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Marine Aquarium Lite
2012-05-22 10:30 - 2012-05-22 10:30 - 00097632 ____A C:\Users\Administrator\Downloads\applicant_signature (1).pdf
2012-05-22 10:27 - 2012-05-22 10:27 - 00217209 ____A C:\Users\Administrator\Downloads\supporting_document (1).pdf
2012-05-22 10:24 - 2012-05-22 10:25 - 00071303 ____A C:\Users\Administrator\Downloads\master_student_financial_assistance_agreements (1).pdf
============ 3 Months Modified Files and Folders ===============
2012-06-19 11:16 - 2009-10-06 13:18 - 00000475 ____A C:\Windows\SMSCFG.ini
2012-06-19 11:15 - 2012-05-29 15:35 - 00048384 ____A C:\Windows\setupact.log
2012-06-19 11:15 - 2009-10-04 14:49 - 3211124736 __ASH C:\pagefile.sys
2012-06-19 11:15 - 2009-10-04 14:49 - 2408341504 __ASH C:\hiberfil.sys
2012-06-19 11:15 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-19 11:13 - 2010-12-24 18:56 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-13 17:40 - 2010-07-11 11:31 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Skype
2012-06-13 17:32 - 2010-12-24 18:56 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-13 17:30 - 2012-06-04 14:57 - 00478968 ____A C:\Windows\ntbtlog.txt
2012-06-13 17:21 - 2012-01-11 15:48 - 00000000 __SHD C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}
2012-06-13 17:15 - 2009-10-04 13:03 - 00769812 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-13 17:13 - 2010-01-21 07:44 - 01527913 ____A C:\Windows\WindowsUpdate.log
2012-06-13 17:13 - 2009-07-13 20:34 - 00015184 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-13 17:13 - 2009-07-13 20:34 - 00015184 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-13 17:06 - 2012-06-13 17:06 - 00000700 ____A C:\Windows\PFRO.log
2012-06-13 17:06 - 2012-05-09 17:30 - 00000000 __SHD C:\Config.Msi
2012-06-13 17:06 - 2009-07-13 18:37 - 00000000 ____D C:\Windows
2012-06-13 17:02 - 2012-05-17 09:59 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-13 17:02 - 2011-01-25 18:08 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-13 16:55 - 2012-06-13 16:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 16:55 - 2009-07-13 18:37 - 00000000 ___RD C:\Program Files
2012-06-13 16:48 - 2011-01-18 17:23 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-06-02 13:39 - 2009-10-05 06:02 - 00001948 _RASH C:\Users\All Users\ntuser.pol
2012-06-02 13:39 - 2009-07-13 18:37 - 00000000 ___HD C:\ProgramData
2012-05-31 14:27 - 2009-07-13 20:53 - 00032636 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-31 13:13 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\LiveKernelReports
2012-05-29 15:35 - 2012-05-29 15:35 - 00000000 ____A C:\Windows\setuperr.log
2012-05-28 13:17 - 2012-05-26 13:26 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Marine Aquarium Lite
2012-05-28 06:20 - 2010-10-22 18:36 - 00000000 ____D C:\Users\All Users\Oberon Media
2012-05-22 10:30 - 2012-05-22 10:30 - 00097632 ____A C:\Users\Administrator\Downloads\applicant_signature (1).pdf
2012-05-22 10:27 - 2012-05-22 10:27 - 00217209 ____A C:\Users\Administrator\Downloads\supporting_document (1).pdf
2012-05-22 10:25 - 2012-05-22 10:24 - 00071303 ____A C:\Users\Administrator\Downloads\master_student_financial_assistance_agreements (1).pdf
2012-05-17 10:59 - 2012-05-17 09:59 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-05-17 10:59 - 2011-05-15 01:44 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-05-09 18:10 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET
2012-05-09 17:42 - 2009-07-13 20:33 - 03825512 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-09 17:40 - 2009-07-13 23:27 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-09 17:38 - 2009-10-04 13:09 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-09 17:36 - 2010-07-21 16:59 - 55656824 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-09 17:28 - 2011-01-01 13:25 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-04 13:25 - 2012-05-04 13:25 - 00000878 ____A C:\Users\Administrator\Desktop\Sign In.url
2012-05-02 10:46 - 2012-03-01 18:56 - 00000000 ____D C:\Users\Administrator\Desktop\SCHOOL
2012-05-02 08:54 - 2012-05-02 08:53 - 00097646 ____A C:\Users\Administrator\Downloads\applicant_signature.pdf
2012-05-02 08:53 - 2012-05-02 08:53 - 00223659 ____A C:\Users\Administrator\Downloads\supporting_document.pdf
2012-05-02 08:53 - 2012-05-02 08:53 - 00072096 ____A C:\Users\Administrator\Downloads\master_student_financial_assistance_agreements.pdf
2012-04-30 08:54 - 2010-06-20 03:59 - 00000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics
2012-04-30 08:54 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\NDF
2012-04-27 18:57 - 2012-04-27 18:57 - 00013165 ____A C:\Users\Administrator\Desktop\hs_err_pid5276.log
2012-04-24 08:53 - 2012-04-01 16:05 - 00024576 ____A C:\Users\Administrator\Downloads\kennys resume copy.doc
2012-04-19 20:42 - 2012-04-19 20:42 - 00000529 ____A C:\Users\Administrator\Desktop\Home - Windows Live (2).url
2012-04-14 12:25 - 2012-04-14 12:25 - 00000000 ____D C:\Program Files\TelevisionFanaticEI
2012-04-12 05:06 - 2012-03-22 07:22 - 00017034 ____A C:\Users\Administrator\Documents\Paula Radford.docx
2012-04-11 06:04 - 2012-04-11 06:04 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-04-10 17:23 - 2012-04-10 17:23 - 00013385 ____A C:\Users\Administrator\Desktop\hs_err_pid4040.log
2012-04-08 17:18 - 2012-04-08 17:18 - 00002503 ____A C:\Users\Public\Desktop\Skype.lnk
2012-04-08 17:18 - 2012-04-08 17:18 - 00000000 ___RD C:\Program Files\Skype
2012-04-08 17:18 - 2012-04-08 17:18 - 00000000 ____D C:\Program Files\Common Files\Skype
2012-04-08 17:18 - 2010-07-11 11:30 - 00000000 ____D C:\Users\All Users\Skype
2012-04-04 17:18 - 2012-04-04 17:18 - 00014307 ____A C:\Users\Administrator\Documents\Kristy Radford.docx
2012-03-30 20:39 - 2012-05-09 17:22 - 03968368 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2012-03-30 20:39 - 2012-05-09 17:22 - 03913072 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 18:36 - 2012-05-09 17:22 - 02343424 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-30 02:23 - 2012-05-09 17:22 - 01291632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-26 05:41 - 2012-03-22 07:34 - 00014066 ____A C:\Users\Administrator\Documents\HINES-CONNOLLY_Donna[1] (1).docx
ZeroAccess:
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}\@
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}\L
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}\n
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}\U
ZeroAccess:
C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}
C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}\@
C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}\L
C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3062.37 MB
Available physical RAM: 2596.47 MB
Total Pagefile: 3060.64 MB
Available Pagefile: 2601.37 MB
Total Virtual: 2047.88 MB
Available Virtual: 1958.31 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:286.41 GB) (Free:241.44 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (HP_RECOVERY) (Fixed) (Total:11.67 GB) (Free:1.48 GB) NTFS
4 Drive f: (16GB STICK) (Removable) (Total:14.93 GB) (Free:6.47 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 1024 KB
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 286 GB 31 KB
Partition 2 Primary 11 GB 286 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 286 GB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D HP_RECOVERY NTFS Partition 11 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 14 GB 0 B
======================================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
======================================================================================================
==========================================================
Last Boot: 2012-06-13 16:28
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 18-06-2012 02
Ran by SYSTEM at 19-06-2012 15:24:03
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [150552 2009-09-23] (Intel Corporation)
HKLM\...\Run: [NBAgent] "C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart [1234216 2010-03-26] (Nero AG)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2009-09-23] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [173592 2009-09-23] (Intel Corporation)
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-05] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [NPSStartup] [x]
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [29984 2008-07-09] (Nuance Communications, Inc.)
HKLM\...\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [46368 2008-07-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini" [344 2012-06-19] ()
HKLM\...\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN [2621440 2010-02-09] (Brother Industries, Ltd.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Administrator\...\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\Administrator\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17148552 2012-02-29] (Skype Technologies S.A.)
HKLM\...\Runonce: [NCInstallQueue] rundll32 netman.dll,ProcessQueue [x]
HKLM\...\Winlogon: [Userinit] userinit.exe, [x]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 64.71.255.198
================================ Services (Whitelisted) ==================
3 BrYNSvc; "C:\Program Files\Browny02\BrYNSvc.exe" [245760 2010-01-25] (Brother Industries, Ltd.)
2 CcmExec; C:\Windows\system32\CCM\CcmExec.exe [757792 2008-05-20] (Microsoft Corporation)
2 EFS; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [556544 2010-11-20] (Microsoft Corporation)
3 ehSched; C:\Windows\ehome\ehsched.exe [94720 2009-07-13] (Microsoft Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
3 Fax; C:\Windows\System32\fxssvc.exe [523264 2010-11-20] (Microsoft Corporation)
2 HsfXAudioService; C:\Windows\system32\XAudio32.dll [410624 2009-04-28] (Conexant Systems, Inc.)
3 KeyIso; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 MSDTC; C:\Windows\System32\msdtc.exe [134144 2009-07-13] (Microsoft Corporation)
3 msiserver; C:\Windows\System32\msiexec.exe /V [73216 2010-11-20] (Microsoft Corporation)
2 msoidsvc; "C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE" [1589152 2011-09-28] (Microsoft Corp.)
2 NAUpdate; "C:\Program Files\Nero\Update\NASvc.exe" [490280 2010-03-25] (Nero AG)
3 Netlogon; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 ProtectedStorage; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 RpcLocator; C:\Windows\System32\locator.exe [9216 2009-07-13] (Microsoft Corporation)
2 SamSs; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [158856 2012-02-29] (Skype Technologies)
3 smstsmgr; C:\Windows\system32\CCM\TSManager.exe /service [249888 2008-05-20] (Microsoft Corporation)
3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2009-07-13] (Microsoft Corporation)
2 Spooler; C:\Windows\System32\spoolsv.exe [317440 2010-11-20] (Microsoft Corporation)
2 sppsvc; C:\Windows\System32\sppsvc.exe [3179520 2010-11-20] (Microsoft Corporation)
3 StorSvc; C:\Windows\System32\storsvc.dll [16384 2009-07-13] (Microsoft Corporation)
3 SwitchBoard; "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [517096 2010-02-19] (Adobe Systems Incorporated)
3 UI0Detect; C:\Windows\System32\UI0Detect.exe [35840 2009-07-13] (Microsoft Corporation)
3 VaultSvc; C:\Windows\System32\lsass.exe [22528 2011-11-16] (Microsoft Corporation)
3 vds; C:\Windows\System32\vds.exe [453632 2010-11-20] (Microsoft Corporation)
3 VSS; C:\Windows\System32\vssvc.exe [1025536 2010-11-20] (Microsoft Corporation)
3 wbengine; "C:\Windows\system32\wbengine.exe" [1203200 2010-11-20] (Microsoft Corporation)
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [36608 2010-06-14] ()
3 HpqRemHid; C:\Windows\System32\DRIVERS\HpqRemHid.sys [7168 2007-07-10] (Hewlett-Packard Development Company, L.P.)
3 HSF_DPV; C:\Windows\System32\DRIVERS\HSX_DPV.sys [980992 2009-02-12] (Conexant Systems, Inc.)
3 iirsp; C:\Windows\system32\DRIVERS\iirsp.sys [41040 2009-07-13] (Intel Corp./ICP vortex GmbH)
2 mdmxsdk; C:\Windows\System32\DRIVERS\mdmxsdk.sys [12672 2006-06-17] (Conexant)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [47360 2010-06-21] (VSO Software)
3 prepdrvr; \??\C:\Windows\system32\CCM\prepdrv.sys [23584 2008-05-20] (Microsoft Corporation)
3 ROOTMODEM; C:\Windows\System32\Drivers\RootMdm.sys [8192 2009-07-13] (Microsoft Corporation)
3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL3.SYS [207360 2009-07-13] (Conexant Systems, Inc.)
3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV3.SYS [980992 2009-07-13] (Conexant Systems, Inc.)
3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT3.SYS [661504 2009-07-13] (Conexant Systems, Inc.)
3 usb_rndisx; C:\Windows\System32\DRIVERS\usb8023x.sys [15872 2009-07-13] (Microsoft Corporation)
2 XAudio; C:\Windows\System32\DRIVERS\XAudio32.sys [8704 2009-04-28] (Conexant Systems, Inc.)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-13 17:06 - 2012-06-13 17:06 - 00000700 ____A C:\Windows\PFRO.log
2012-06-13 16:55 - 2012-06-13 16:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-04 14:57 - 2012-06-13 17:30 - 00478968 ____A C:\Windows\ntbtlog.txt
2012-05-29 15:35 - 2012-06-19 11:15 - 00048384 ____A C:\Windows\setupact.log
2012-05-29 15:35 - 2012-05-29 15:35 - 00000000 ____A C:\Windows\setuperr.log
2012-05-26 13:26 - 2012-05-28 13:17 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Marine Aquarium Lite
2012-05-22 10:30 - 2012-05-22 10:30 - 00097632 ____A C:\Users\Administrator\Downloads\applicant_signature (1).pdf
2012-05-22 10:27 - 2012-05-22 10:27 - 00217209 ____A C:\Users\Administrator\Downloads\supporting_document (1).pdf
2012-05-22 10:24 - 2012-05-22 10:25 - 00071303 ____A C:\Users\Administrator\Downloads\master_student_financial_assistance_agreements (1).pdf
============ 3 Months Modified Files and Folders ===============
2012-06-19 11:16 - 2009-10-06 13:18 - 00000475 ____A C:\Windows\SMSCFG.ini
2012-06-19 11:15 - 2012-05-29 15:35 - 00048384 ____A C:\Windows\setupact.log
2012-06-19 11:15 - 2009-10-04 14:49 - 3211124736 __ASH C:\pagefile.sys
2012-06-19 11:15 - 2009-10-04 14:49 - 2408341504 __ASH C:\hiberfil.sys
2012-06-19 11:15 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-19 11:13 - 2010-12-24 18:56 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-13 17:40 - 2010-07-11 11:31 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Skype
2012-06-13 17:32 - 2010-12-24 18:56 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-13 17:30 - 2012-06-04 14:57 - 00478968 ____A C:\Windows\ntbtlog.txt
2012-06-13 17:21 - 2012-01-11 15:48 - 00000000 __SHD C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}
2012-06-13 17:15 - 2009-10-04 13:03 - 00769812 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-13 17:13 - 2010-01-21 07:44 - 01527913 ____A C:\Windows\WindowsUpdate.log
2012-06-13 17:13 - 2009-07-13 20:34 - 00015184 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-13 17:13 - 2009-07-13 20:34 - 00015184 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-13 17:06 - 2012-06-13 17:06 - 00000700 ____A C:\Windows\PFRO.log
2012-06-13 17:06 - 2012-05-09 17:30 - 00000000 __SHD C:\Config.Msi
2012-06-13 17:06 - 2009-07-13 18:37 - 00000000 ____D C:\Windows
2012-06-13 17:02 - 2012-05-17 09:59 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-13 17:02 - 2011-01-25 18:08 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-13 16:55 - 2012-06-13 16:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 16:55 - 2009-07-13 18:37 - 00000000 ___RD C:\Program Files
2012-06-13 16:48 - 2011-01-18 17:23 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-06-02 13:39 - 2009-10-05 06:02 - 00001948 _RASH C:\Users\All Users\ntuser.pol
2012-06-02 13:39 - 2009-07-13 18:37 - 00000000 ___HD C:\ProgramData
2012-05-31 14:27 - 2009-07-13 20:53 - 00032636 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-31 13:13 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\LiveKernelReports
2012-05-29 15:35 - 2012-05-29 15:35 - 00000000 ____A C:\Windows\setuperr.log
2012-05-28 13:17 - 2012-05-26 13:26 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Marine Aquarium Lite
2012-05-28 06:20 - 2010-10-22 18:36 - 00000000 ____D C:\Users\All Users\Oberon Media
2012-05-22 10:30 - 2012-05-22 10:30 - 00097632 ____A C:\Users\Administrator\Downloads\applicant_signature (1).pdf
2012-05-22 10:27 - 2012-05-22 10:27 - 00217209 ____A C:\Users\Administrator\Downloads\supporting_document (1).pdf
2012-05-22 10:25 - 2012-05-22 10:24 - 00071303 ____A C:\Users\Administrator\Downloads\master_student_financial_assistance_agreements (1).pdf
2012-05-17 10:59 - 2012-05-17 09:59 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-05-17 10:59 - 2011-05-15 01:44 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-05-09 18:10 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET
2012-05-09 17:42 - 2009-07-13 20:33 - 03825512 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-09 17:40 - 2009-07-13 23:27 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-09 17:38 - 2009-10-04 13:09 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-09 17:36 - 2010-07-21 16:59 - 55656824 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-09 17:28 - 2011-01-01 13:25 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2012-05-04 13:25 - 2012-05-04 13:25 - 00000878 ____A C:\Users\Administrator\Desktop\Sign In.url
2012-05-02 10:46 - 2012-03-01 18:56 - 00000000 ____D C:\Users\Administrator\Desktop\SCHOOL
2012-05-02 08:54 - 2012-05-02 08:53 - 00097646 ____A C:\Users\Administrator\Downloads\applicant_signature.pdf
2012-05-02 08:53 - 2012-05-02 08:53 - 00223659 ____A C:\Users\Administrator\Downloads\supporting_document.pdf
2012-05-02 08:53 - 2012-05-02 08:53 - 00072096 ____A C:\Users\Administrator\Downloads\master_student_financial_assistance_agreements.pdf
2012-04-30 08:54 - 2010-06-20 03:59 - 00000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics
2012-04-30 08:54 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\NDF
2012-04-27 18:57 - 2012-04-27 18:57 - 00013165 ____A C:\Users\Administrator\Desktop\hs_err_pid5276.log
2012-04-24 08:53 - 2012-04-01 16:05 - 00024576 ____A C:\Users\Administrator\Downloads\kennys resume copy.doc
2012-04-19 20:42 - 2012-04-19 20:42 - 00000529 ____A C:\Users\Administrator\Desktop\Home - Windows Live (2).url
2012-04-14 12:25 - 2012-04-14 12:25 - 00000000 ____D C:\Program Files\TelevisionFanaticEI
2012-04-12 05:06 - 2012-03-22 07:22 - 00017034 ____A C:\Users\Administrator\Documents\Paula Radford.docx
2012-04-11 06:04 - 2012-04-11 06:04 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-04-10 17:23 - 2012-04-10 17:23 - 00013385 ____A C:\Users\Administrator\Desktop\hs_err_pid4040.log
2012-04-08 17:18 - 2012-04-08 17:18 - 00002503 ____A C:\Users\Public\Desktop\Skype.lnk
2012-04-08 17:18 - 2012-04-08 17:18 - 00000000 ___RD C:\Program Files\Skype
2012-04-08 17:18 - 2012-04-08 17:18 - 00000000 ____D C:\Program Files\Common Files\Skype
2012-04-08 17:18 - 2010-07-11 11:30 - 00000000 ____D C:\Users\All Users\Skype
2012-04-04 17:18 - 2012-04-04 17:18 - 00014307 ____A C:\Users\Administrator\Documents\Kristy Radford.docx
2012-03-30 20:39 - 2012-05-09 17:22 - 03968368 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2012-03-30 20:39 - 2012-05-09 17:22 - 03913072 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 18:36 - 2012-05-09 17:22 - 02343424 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-30 02:23 - 2012-05-09 17:22 - 01291632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-26 05:41 - 2012-03-22 07:34 - 00014066 ____A C:\Users\Administrator\Documents\HINES-CONNOLLY_Donna[1] (1).docx
ZeroAccess:
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}\@
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}\L
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}\n
C:\Windows\Installer\{b8293650-2372-56ae-0554-8c17749c2572}\U
ZeroAccess:
C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}
C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}\@
C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}\L
C:\Users\Administrator\AppData\Local\{b8293650-2372-56ae-0554-8c17749c2572}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 3062.37 MB
Available physical RAM: 2596.47 MB
Total Pagefile: 3060.64 MB
Available Pagefile: 2601.37 MB
Total Virtual: 2047.88 MB
Available Virtual: 1958.31 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:286.41 GB) (Free:241.44 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (HP_RECOVERY) (Fixed) (Total:11.67 GB) (Free:1.48 GB) NTFS
4 Drive f: (16GB STICK) (Removable) (Total:14.93 GB) (Free:6.47 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 1024 KB
Disk 1 Online 14 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 286 GB 31 KB
Partition 2 Primary 11 GB 286 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 286 GB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D HP_RECOVERY NTFS Partition 11 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 14 GB 0 B
======================================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
======================================================================================================
==========================================================
Last Boot: 2012-06-13 16:28
======================= End Of Log ==========================