Scan result of Farbar Recovery Scan Tool Version: 12-06-2012 02
Ran by SYSTEM at 13-06-2012 20:45:44
Running from J:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8158240 2009-10-06] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM-x32\...\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2009-07-17] (Alcor Micro Corp.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [641664 2012-04-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m [1807680 2010-02-09] ()
HKLM-x32\...\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2009-05-21] (SupportSoft, Inc.)
HKLM-x32\...\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [311296 2010-03-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [EEventManager] C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe [669520 2009-01-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [dplaysvr] C:\Windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe [x]
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-20] ()
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\Adam\...\Run: [EPSON NX510 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIA.EXE /FU "C:\Windows\TEMP\E_S4D36.tmp" /EF "HKCU" [223232 2008-11-20] (SEIKO EPSON CORPORATION)
HKU\Adam\...\Run: [lorosc] "C:\Windows\System32\rundll32.exe" "C:\Users\Adam\AppData\Roaming\lorosc.dll",CreateVolumeTextureFromFileW [340480 2012-06-10] (Analog Devices, Inc.)
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-08] (Dell)
HKLM-x32\...\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe [165184 2011-01-13] (Softthinks)
HKLM-x32\...\runonceex: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-26] (Sonic Solutions)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Startup: C:\Users\Adam\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) ======
3 AdobeActiveFileMonitor8.0; C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [169312 2009-09-18] (Adobe Systems Incorporated)
2 BBSvc; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [193816 2012-02-10] (Microsoft Corporation.)
3 BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [240408 2012-02-10] (Microsoft Corporation.)
2 Mobiola Wave Service; "C:\Program Files (x86)\Common Files\SHAPE Services\Mobiola Wave Service\MobiolaWaveService.exe" [125088 2011-04-11] ()
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-02-25] ()
3 RoxMediaDB10; "C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe" [1124848 2009-06-26] (Sonic Solutions)
2 SessionLauncher; C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
========================== Drivers (Whitelisted) =============
3 libusb0; C:\Windows\System32\Drivers\libusb0.sys [43456 2011-09-22] (
http://libusb-win32.sourceforge.net)
3 mobiolavs; C:\Windows\System32\Drivers\mobiolavs.sys [28304 2011-04-06] (SHAPE Services GmbH)
3 MOBIOLA_Wave; C:\Windows\System32\drivers\mobiolawave.sys [29120 2011-04-06] (SHAPE Services)
1 RxFilter; C:\Windows\SysWow64\Drivers\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)
1 MpKsl681ed1f5; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A4867502-B3BD-4178-9EEE-09D683013687}\MpKsl681ed1f5.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-13 20:45 - 2012-06-13 20:45 - 00000000 ____D C:\FRST
2012-06-13 16:12 - 2012-06-13 16:12 - 00000000 ____D C:\DataSafeOnline
2012-06-13 16:05 - 2012-06-13 16:05 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 16:05 - 2012-06-13 16:05 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-12 21:44 - 2012-06-12 21:44 - 00000000 ____D C:\Windows\System32\SPReview
2012-06-10 21:26 - 2012-06-10 21:26 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-10 21:18 - 2012-06-10 21:18 - 00340480 ____A (Analog Devices, Inc.) C:\Users\Adam\Application Data\lorosc.dll
2012-06-10 21:18 - 2012-06-10 21:18 - 00340480 ____A (Analog Devices, Inc.) C:\Users\Adam\AppData\Roaming\lorosc.dll
2012-06-10 21:18 - 2012-06-10 21:18 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\{B6649D83-B36B-11E1-8270-B8AC6F996F26}
2012-06-10 21:18 - 2012-06-10 21:18 - 00000000 ____D C:\Users\Adam\Local Settings\{B6649D83-B36B-11E1-8270-B8AC6F996F26}
2012-06-10 21:18 - 2012-06-10 21:18 - 00000000 ____D C:\Users\Adam\AppData\Local\{B6649D83-B36B-11E1-8270-B8AC6F996F26}
2012-06-10 21:17 - 2012-06-13 16:15 - 00000000 ____D C:\Users\Adam\Local Settings\AVSonicComConexant
2012-06-10 21:17 - 2012-06-13 16:15 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\AVSonicComConexant
2012-06-10 21:17 - 2012-06-13 16:15 - 00000000 ____D C:\Users\Adam\AppData\Local\AVSonicComConexant
2012-06-10 17:57 - 2012-06-10 17:57 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\{CF61D619-AB9D-434E-99A9-4CA6B62A5E9F}
2012-06-10 17:57 - 2012-06-10 17:57 - 00000000 ____D C:\Users\Adam\Local Settings\{CF61D619-AB9D-434E-99A9-4CA6B62A5E9F}
2012-06-10 17:57 - 2012-06-10 17:57 - 00000000 ____D C:\Users\Adam\AppData\Local\{CF61D619-AB9D-434E-99A9-4CA6B62A5E9F}
2012-06-08 20:32 - 2012-06-11 21:36 - 00000000 ____D C:\Users\Adam\Application Data\Bioshock
2012-06-08 20:32 - 2012-06-11 21:36 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Bioshock
2012-06-08 20:32 - 2012-06-08 20:41 - 00000000 ____D C:\Users\Adam\My Documents\Bioshock
2012-06-08 20:32 - 2012-06-08 20:41 - 00000000 ____D C:\Users\Adam\Documents\Bioshock
2012-06-02 17:44 - 2012-06-02 17:45 - 00001630 ____A C:\Users\Adam\Desktop\Google Talk.lnk
2012-05-30 20:14 - 2012-05-30 20:14 - 00000000 ____D C:\Users\Adam\Local Settings\Google
2012-05-30 20:14 - 2012-05-30 20:14 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\Google
2012-05-30 20:14 - 2012-05-30 20:14 - 00000000 ____D C:\Users\Adam\AppData\Local\Google
2012-05-30 20:14 - 2012-05-30 20:14 - 00000000 ____D C:\Program Files (x86)\Google
2012-05-25 16:07 - 2012-05-25 16:07 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-22 17:17 - 2012-05-22 17:17 - 00001847 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-22 17:17 - 2012-05-22 17:17 - 00001847 ____A C:\Users\All Users\Desktop\QuickTime Player.lnk
2012-05-22 17:17 - 2012-05-22 17:17 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-05-14 18:05 - 2012-05-14 18:05 - 00000000 ____D C:\Users\Adam\My Documents\Diablo III
2012-05-14 18:05 - 2012-05-14 18:05 - 00000000 ____D C:\Users\Adam\Documents\Diablo III
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Users\All Users\ATI
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Users\All Users\Application Data\ATI
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Users\All Users\Application Data\AMD
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Users\All Users\AMD
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Program Files (x86)\AMD APP
2012-05-14 18:00 - 2012-05-14 18:00 - 00000000 ____D C:\AMD
2012-05-14 17:22 - 2012-06-06 17:14 - 00000000 ____D C:\Program Files (x86)\Diablo III
2012-05-14 17:22 - 2012-05-14 17:33 - 00001191 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-14 17:22 - 2012-05-14 17:33 - 00001191 ____A C:\Users\All Users\Desktop\Diablo III.lnk
============ 3 Months Modified Files and Folders =============
2012-06-13 20:45 - 2012-06-13 20:45 - 00000000 ____D C:\FRST
2012-06-13 19:31 - 2010-08-17 20:50 - 00000000 ____D C:\Users\Adam\Local Settings\SoftThinks
2012-06-13 19:31 - 2010-08-17 20:50 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\SoftThinks
2012-06-13 19:31 - 2010-08-17 20:50 - 00000000 ____D C:\Users\Adam\AppData\Local\SoftThinks
2012-06-13 19:31 - 2010-07-10 07:59 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2012-06-13 19:31 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-13 19:31 - 2009-07-13 23:51 - 00128302 ____A C:\Windows\setupact.log
2012-06-13 17:11 - 2011-09-13 07:04 - 01020202 ____A C:\Windows\ntbtlog.txt
2012-06-13 16:23 - 2012-01-11 14:33 - 00000000 __SHD C:\Users\Adam\Local Settings\Application Data\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}
2012-06-13 16:23 - 2012-01-11 14:33 - 00000000 __SHD C:\Users\Adam\Local Settings\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}
2012-06-13 16:23 - 2012-01-11 14:33 - 00000000 __SHD C:\Users\Adam\AppData\Local\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}
2012-06-13 16:15 - 2012-06-10 21:17 - 00000000 ____D C:\Users\Adam\Local Settings\AVSonicComConexant
2012-06-13 16:15 - 2012-06-10 21:17 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\AVSonicComConexant
2012-06-13 16:15 - 2012-06-10 21:17 - 00000000 ____D C:\Users\Adam\AppData\Local\AVSonicComConexant
2012-06-13 16:13 - 2010-07-10 09:48 - 00049022 ____A C:\Windows\PFRO.log
2012-06-13 16:12 - 2012-06-13 16:12 - 00000000 ____D C:\DataSafeOnline
2012-06-13 16:07 - 2012-03-30 10:22 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-13 16:06 - 2009-07-14 00:10 - 01402828 ____A C:\Windows\WindowsUpdate.log
2012-06-13 16:05 - 2012-06-13 16:05 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 16:05 - 2012-06-13 16:05 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-13 16:05 - 2011-01-26 01:45 - 00747542 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-13 16:05 - 2011-01-26 01:45 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-13 16:02 - 2010-08-17 20:53 - 00000402 __ASH C:\Users\Adam\My Documents\desktop.ini
2012-06-13 07:42 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2012-06-13 06:44 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-13 06:44 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-13 06:43 - 2009-07-14 00:13 - 00733884 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-13 06:37 - 2009-07-13 23:45 - 00386432 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-12 22:04 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\config\TxR
2012-06-12 22:03 - 2009-07-14 02:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-06-12 22:03 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2012-06-12 22:03 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files\Windows Portable Devices
2012-06-12 22:03 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2012-06-12 22:03 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files\Windows Defender
2012-06-12 22:03 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files\DVD Maker
2012-06-12 22:03 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2012-06-12 22:03 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2012-06-12 22:03 - 2009-07-14 00:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\sppui
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\oobe
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\manifeststore
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\es-ES
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\da-DK
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\cs-CZ
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\sppui
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\Setup
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\oobe
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\migwiz
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\manifeststore
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\es-ES
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\Dism
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\da-DK
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\cs-CZ
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\AdvancedInstallers
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\servicing
2012-06-12 22:03 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\System
2012-06-12 21:51 - 2009-07-13 21:36 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2012-06-12 21:51 - 2009-07-13 21:36 - 00152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2012-06-12 21:44 - 2012-06-12 21:44 - 00000000 ____D C:\Windows\System32\SPReview
2012-06-11 21:36 - 2012-06-08 20:32 - 00000000 ____D C:\Users\Adam\Application Data\Bioshock
2012-06-11 21:36 - 2012-06-08 20:32 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Bioshock
2012-06-11 21:03 - 2010-08-18 18:52 - 00000000 ____D C:\Program Files (x86)\Steam
2012-06-10 21:26 - 2012-06-10 21:26 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-10 21:18 - 2012-06-10 21:18 - 00340480 ____A (Analog Devices, Inc.) C:\Users\Adam\Application Data\lorosc.dll
2012-06-10 21:18 - 2012-06-10 21:18 - 00340480 ____A (Analog Devices, Inc.) C:\Users\Adam\AppData\Roaming\lorosc.dll
2012-06-10 21:18 - 2012-06-10 21:18 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\{B6649D83-B36B-11E1-8270-B8AC6F996F26}
2012-06-10 21:18 - 2012-06-10 21:18 - 00000000 ____D C:\Users\Adam\Local Settings\{B6649D83-B36B-11E1-8270-B8AC6F996F26}
2012-06-10 21:18 - 2012-06-10 21:18 - 00000000 ____D C:\Users\Adam\AppData\Local\{B6649D83-B36B-11E1-8270-B8AC6F996F26}
2012-06-10 21:17 - 2012-03-30 10:22 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-10 21:17 - 2011-05-17 08:13 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-10 21:17 - 2010-08-17 20:53 - 00000000 ____D C:\Users\Adam\Local Settings\VirtualStore
2012-06-10 21:17 - 2010-08-17 20:53 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\VirtualStore
2012-06-10 21:17 - 2010-08-17 20:53 - 00000000 ____D C:\Users\Adam\AppData\Local\VirtualStore
2012-06-10 17:57 - 2012-06-10 17:57 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\{CF61D619-AB9D-434E-99A9-4CA6B62A5E9F}
2012-06-10 17:57 - 2012-06-10 17:57 - 00000000 ____D C:\Users\Adam\Local Settings\{CF61D619-AB9D-434E-99A9-4CA6B62A5E9F}
2012-06-10 17:57 - 2012-06-10 17:57 - 00000000 ____D C:\Users\Adam\AppData\Local\{CF61D619-AB9D-434E-99A9-4CA6B62A5E9F}
2012-06-08 20:41 - 2012-06-08 20:32 - 00000000 ____D C:\Users\Adam\My Documents\Bioshock
2012-06-08 20:41 - 2012-06-08 20:32 - 00000000 ____D C:\Users\Adam\Documents\Bioshock
2012-06-06 17:14 - 2012-05-14 17:22 - 00000000 ____D C:\Program Files (x86)\Diablo III
2012-06-02 17:45 - 2012-06-02 17:44 - 00001630 ____A C:\Users\Adam\Desktop\Google Talk.lnk
2012-06-02 17:42 - 2010-08-17 20:50 - 00000000 ____D C:\users\Adam
2012-05-30 20:14 - 2012-05-30 20:14 - 00000000 ____D C:\Users\Adam\Local Settings\Google
2012-05-30 20:14 - 2012-05-30 20:14 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\Google
2012-05-30 20:14 - 2012-05-30 20:14 - 00000000 ____D C:\Users\Adam\AppData\Local\Google
2012-05-30 20:14 - 2012-05-30 20:14 - 00000000 ____D C:\Program Files (x86)\Google
2012-05-25 16:07 - 2012-05-25 16:07 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-22 17:17 - 2012-05-22 17:17 - 00001847 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-05-22 17:17 - 2012-05-22 17:17 - 00001847 ____A C:\Users\All Users\Desktop\QuickTime Player.lnk
2012-05-22 17:17 - 2012-05-22 17:17 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-05-14 18:05 - 2012-05-14 18:05 - 00000000 ____D C:\Users\Adam\My Documents\Diablo III
2012-05-14 18:05 - 2012-05-14 18:05 - 00000000 ____D C:\Users\Adam\Documents\Diablo III
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Users\All Users\ATI
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Users\All Users\Application Data\ATI
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Users\All Users\Application Data\AMD
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Users\All Users\AMD
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2012-05-14 18:03 - 2012-05-14 18:03 - 00000000 ____D C:\Program Files (x86)\AMD APP
2012-05-14 18:02 - 2010-08-18 17:08 - 00000000 ____D C:\Program Files\ATI Technologies
2012-05-14 18:00 - 2012-05-14 18:00 - 00000000 ____D C:\AMD
2012-05-14 17:33 - 2012-05-14 17:22 - 00001191 ____A C:\Users\Public\Desktop\Diablo III.lnk
2012-05-14 17:33 - 2012-05-14 17:22 - 00001191 ____A C:\Users\All Users\Desktop\Diablo III.lnk
2012-05-13 21:16 - 2012-05-13 21:16 - 00000000 ____D C:\Users\All Users\Battle.net
2012-05-13 21:16 - 2012-05-13 21:16 - 00000000 ____D C:\Users\All Users\Application Data\Battle.net
2012-05-13 20:44 - 2012-05-13 11:39 - 00000000 ____D C:\Diablo-III-8370-enUS-Installer
2012-05-11 13:38 - 2012-05-10 19:21 - 00000000 ____D C:\Users\Adam\Diablo-III-8370-enUS-Installer
2012-05-10 19:08 - 2010-09-01 08:47 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\Adobe
2012-05-10 19:08 - 2010-09-01 08:47 - 00000000 ____D C:\Users\Adam\Local Settings\Adobe
2012-05-10 19:08 - 2010-09-01 08:47 - 00000000 ____D C:\Users\Adam\AppData\Local\Adobe
2012-05-09 22:53 - 2011-07-03 13:54 - 00000000 ____D C:\Users\Adam\My Documents\Finance
2012-05-09 22:53 - 2011-07-03 13:54 - 00000000 ____D C:\Users\Adam\Documents\Finance
2012-05-08 22:33 - 2010-09-07 21:20 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-08 22:33 - 2010-09-07 21:20 - 00000000 ____D C:\Users\All Users\Application Data\Microsoft Help
2012-05-08 22:33 - 2010-08-21 14:26 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-05-08 22:26 - 2010-07-10 08:05 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-08 16:57 - 2012-05-08 16:57 - 00001785 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-05-08 16:57 - 2012-05-08 16:57 - 00001785 ____A C:\Users\All Users\Desktop\iTunes.lnk
2012-05-08 16:57 - 2012-05-08 16:57 - 00000000 ____D C:\Program Files\iTunes
2012-05-08 16:57 - 2012-05-08 16:57 - 00000000 ____D C:\Program Files\iPod
2012-05-08 16:57 - 2012-05-08 16:57 - 00000000 ____D C:\Program Files (x86)\iTunes
2012-05-06 21:24 - 2012-05-06 21:24 - 00000000 ____D C:\Users\Adam\Local Settings\Octodad
2012-05-06 21:24 - 2012-05-06 21:24 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\Octodad
2012-05-06 21:24 - 2012-05-06 21:24 - 00000000 ____D C:\Users\Adam\AppData\Local\Octodad
2012-05-06 21:19 - 2012-05-06 21:19 - 00000993 ____A C:\Users\Adam\Desktop\Octodad.lnk
2012-05-06 21:19 - 2012-05-06 21:15 - 00000000 ____D C:\Program Files (x86)\Octodad
2012-05-06 21:16 - 2010-07-10 08:04 - 00396659 ____A C:\Windows\DirectX.log
2012-04-27 18:33 - 2012-03-16 17:18 - 00000000 ____D C:\Users\Adam\My Documents\Workout
2012-04-27 18:33 - 2012-03-16 17:18 - 00000000 ____D C:\Users\Adam\Documents\Workout
2012-04-26 22:41 - 2012-04-26 22:36 - 00010408 ____A C:\Users\Adam\My Documents\Beer places.docx
2012-04-26 22:41 - 2012-04-26 22:36 - 00010408 ____A C:\Users\Adam\Documents\Beer places.docx
2012-04-23 06:25 - 2009-07-14 00:08 - 00032642 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-04-19 17:20 - 2012-01-18 18:10 - 00002016 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-04-19 17:20 - 2012-01-18 18:10 - 00002016 ____A C:\Users\All Users\Desktop\Adobe Reader 9.lnk
2012-04-18 19:56 - 2012-04-18 19:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 19:56 - 2012-04-18 19:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-11 23:25 - 2009-07-13 21:34 - 00000510 ____A C:\Windows\win.ini
2012-04-06 00:22 - 2012-04-06 00:22 - 11174400 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-04-05 21:34 - 2012-04-05 21:34 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-04-05 21:34 - 2012-04-05 21:34 - 00074752 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-04-05 21:34 - 2012-04-05 21:34 - 00064512 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 16457216 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-04-05 21:33 - 2012-04-05 21:33 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 13007872 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 00054784 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-04-05 21:32 - 2012-04-05 21:32 - 00050176 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-04-05 21:23 - 2012-04-05 21:23 - 00245896 ____A C:\Windows\SysWOW64\atiapfxx.blb
2012-04-05 21:23 - 2012-04-05 21:23 - 00245896 ____A C:\Windows\System32\atiapfxx.blb
2012-04-05 21:22 - 2012-04-05 21:22 - 00159744 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-04-05 21:21 - 2010-07-06 20:54 - 00909312 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2012-04-05 21:20 - 2010-07-10 10:31 - 01067520 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\aticfx64.dll
2012-04-05 21:16 - 2012-04-05 21:16 - 00503808 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-04-05 21:16 - 2012-04-05 21:16 - 00442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-04-05 21:16 - 2012-04-05 21:16 - 00236544 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-04-05 21:14 - 2012-04-05 21:14 - 00120320 ____A (AMD) C:\Windows\System32\atitmm64.dll
2012-04-05 21:14 - 2012-04-05 21:14 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll
2012-04-05 21:14 - 2012-04-05 21:14 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2012-04-05 21:14 - 2012-04-05 21:14 - 00021504 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-04-05 21:13 - 2010-09-30 17:40 - 06800896 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2012-04-05 21:10 - 2012-04-05 21:10 - 26181632 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll
2012-04-05 21:00 - 2010-07-10 10:31 - 00064000 ____A (AMD) C:\Windows\System32\coinst.dll
2012-04-05 20:54 - 2010-07-10 10:31 - 07479296 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atidxx64.dll
2012-04-05 20:50 - 2012-04-05 20:50 - 19753984 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2012-04-05 20:35 - 2012-04-05 20:35 - 01120768 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6v.dll
2012-04-05 20:34 - 2012-04-05 20:34 - 04731904 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll
2012-04-05 20:34 - 2012-04-05 20:34 - 01831424 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll
2012-04-05 20:34 - 2010-07-10 10:31 - 06203392 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2012-04-05 20:30 - 2012-04-05 20:30 - 00051200 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalrt64.dll
2012-04-05 20:30 - 2012-04-05 20:30 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2012-04-05 20:30 - 2012-04-05 20:30 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll
2012-04-05 20:30 - 2012-04-05 20:30 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2012-04-05 20:29 - 2012-04-05 20:29 - 16090624 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticaldd64.dll
2012-04-05 20:29 - 2012-04-05 20:29 - 02631008 ____A C:\Windows\System32\atiumd6a.cap
2012-04-05 20:29 - 2012-04-05 20:29 - 00204952 ____A C:\Windows\SysWOW64\ativvsvl.dat
2012-04-05 20:29 - 2012-04-05 20:29 - 00204952 ____A C:\Windows\System32\ativvsvl.dat
2012-04-05 20:29 - 2012-04-05 20:29 - 00157144 ____A C:\Windows\SysWOW64\ativvsva.dat
2012-04-05 20:29 - 2012-04-05 20:29 - 00157144 ____A C:\Windows\System32\ativvsva.dat
2012-04-05 20:25 - 2012-04-05 20:25 - 13764096 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2012-04-05 20:23 - 2012-04-05 20:23 - 07431680 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd64.dll
2012-04-05 20:22 - 2010-07-10 10:31 - 04795904 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2012-04-05 20:21 - 2012-04-05 20:21 - 02664704 ____A C:\Windows\SysWOW64\atiumdva.cap
2012-04-05 20:11 - 2012-04-05 20:11 - 00514560 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiadlxx.dll
2012-04-05 20:11 - 2012-04-05 20:11 - 00360448 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2012-04-05 20:11 - 2012-04-05 20:11 - 00041984 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6txx.dll
2012-04-05 20:11 - 2012-04-05 20:11 - 00017408 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll
2012-04-05 20:11 - 2012-04-05 20:11 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2012-04-05 20:11 - 2012-04-05 20:11 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-04-05 20:10 - 2012-04-05 20:10 - 00343040 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-04-05 20:10 - 2012-04-05 20:10 - 00033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2012-04-05 20:09 - 2012-04-05 20:09 - 00053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-04-05 20:09 - 2012-04-05 20:09 - 00044544 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll
2012-04-05 20:09 - 2010-09-30 17:40 - 00041984 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2012-04-05 20:09 - 2010-07-10 10:31 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiuxp64.dll
2012-04-05 20:09 - 2010-07-10 10:31 - 00032256 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2012-04-05 20:06 - 2012-04-05 20:06 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll
2012-04-05 20:06 - 2012-04-05 20:06 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll
2012-04-05 20:06 - 2012-04-05 20:06 - 00053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2012-04-05 20:06 - 2012-04-05 20:06 - 00053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2012-03-31 01:05 - 2012-05-08 13:03 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-30 23:39 - 2012-05-08 13:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-03-30 23:39 - 2012-05-08 13:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-03-30 22:10 - 2012-05-08 13:03 - 03146240 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-30 16:06 - 2012-03-30 16:06 - 00000000 ____D C:\Windows\Microsoft Antimalware
2012-03-30 11:40 - 2012-03-30 11:40 - 00275280 ____A C:\Windows\Minidump\033012-24133-01.dmp
2012-03-30 11:40 - 2011-01-14 17:47 - 796683699 ____A C:\Windows\MEMORY.DMP
2012-03-30 11:40 - 2011-01-14 17:47 - 00000000 ____D C:\Windows\Minidump
2012-03-30 10:34 - 2012-03-29 20:36 - 00000000 ____D C:\Users\Adam\Application Data\Emwes
2012-03-30 10:34 - 2012-03-29 20:36 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Emwes
2012-03-30 10:22 - 2012-03-29 20:36 - 00000000 ____D C:\Users\Adam\Application Data\Dubo
2012-03-30 10:22 - 2012-03-29 20:36 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Dubo
2012-03-30 10:21 - 2012-03-30 10:21 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\{F4D48ED2-7A1D-11E1-826D-B8AC6F996F26}
2012-03-30 10:21 - 2012-03-30 10:21 - 00000000 ____D C:\Users\Adam\Local Settings\{F4D48ED2-7A1D-11E1-826D-B8AC6F996F26}
2012-03-30 10:21 - 2012-03-30 10:21 - 00000000 ____D C:\Users\Adam\AppData\Local\{F4D48ED2-7A1D-11E1-826D-B8AC6F996F26}
2012-03-30 06:35 - 2012-05-08 13:03 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-29 23:49 - 2010-08-17 21:46 - 00000000 ____D C:\Users\Adam\Application Data\Macromedia
2012-03-29 23:49 - 2010-08-17 21:46 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Macromedia
2012-03-29 23:07 - 2012-03-29 23:07 - 00000012 ____A C:\Windows\sruna.log
2012-03-29 23:07 - 2012-03-29 23:07 - 00000012 ____A C:\Windows\srun.log
2012-03-29 20:36 - 2012-03-29 20:36 - 00000000 ____D C:\Users\Adam\Application Data\Ohbo
2012-03-29 20:36 - 2012-03-29 20:36 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Ohbo
2012-03-29 18:58 - 2009-07-13 21:34 - 00000855 ___RH C:\Windows\System32\Drivers\etc\hosts
2012-03-29 12:48 - 2012-03-29 12:48 - 00100352 ____A (Kaspersky Lab) C:\Windows\System32\compstrA64.dll
2012-03-28 22:24 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\System32\sysprep
2012-03-25 05:48 - 2011-05-02 09:27 - 00000000 ____D C:\Users\Adam\Local Settings\Windows Live
2012-03-25 05:48 - 2011-05-02 09:27 - 00000000 ____D C:\Users\Adam\Local Settings\Application Data\Windows Live
2012-03-25 05:48 - 2011-05-02 09:27 - 00000000 ____D C:\Users\Adam\AppData\Local\Windows Live
2012-03-24 14:31 - 2012-03-24 14:31 - 00000000 ____D C:\Windows\SysWOW64\Adobe
2012-03-24 14:31 - 2009-07-14 00:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2012-03-20 19:44 - 2012-03-20 19:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-03-20 19:44 - 2012-03-20 19:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-03-17 02:58 - 2012-05-08 13:03 - 00075120 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
ZeroAccess:
C:\Windows\Installer\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}
C:\Windows\Installer\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}\@
C:\Windows\Installer\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}\L
C:\Windows\Installer\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}\n
C:\Windows\Installer\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}\U
ZeroAccess:
C:\Users\Adam\AppData\Local\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}
C:\Users\Adam\AppData\Local\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}\@
C:\Users\Adam\AppData\Local\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}\L
C:\Users\Adam\AppData\Local\{87a5bb94-bbe7-6adf-9d8e-ec63332537f5}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 18:19] - [2009-07-13 20:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 8151.08 MB
Available physical RAM: 7353.69 MB
Total Pagefile: 8149.23 MB
Available Pagefile: 7347.16 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:919.42 GB) (Free:559.95 GB) NTFS
7 Drive I: (RECOVERY) (Fixed) (Total:12.05 GB) (Free:5.61 GB) NTFS
8 Drive j: (PUBLIC) (Fixed) (Total:0.48 GB) (Free:0.43 GB) FAT
9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 Online 495 MB 320 KB
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 12 GB 40 MB
Partition 3 Primary 919 GB 12 GB
======================================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 FAT Partition 39 MB Healthy Hidden
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 I RECOVERY NTFS Partition 12 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 919 GB Healthy
======================================================================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 494 MB 31 KB
======================================================================================================
Disk: 5
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 J PUBLIC FAT Partition 494 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-06-08 06:21
======================= End Of Log ==========================