Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-05-2013 Ran by SYSTEM on 29-05-2013 19:24:03 Running from E:\ Windows 7 Ultimate (X86) OS Language: English(US) Internet Explorer Version 8 Boot Mode: Recovery The current controlset is ControlSet001 [b]ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.[/b] ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [163840 2007-10-11] (Alps Electric Co., Ltd.) HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe [3563520 2008-03-12] (Dell Inc.) HKLM\...\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [x] HKLM\...\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-02-28] (Nero AG) HKLM\...\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe [45108 2002-08-11] (ScanSoft, Inc.) HKLM\...\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe [36864 2002-08-11] () HKLM\...\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe [x] HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [x] HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] () HKLM\...\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence [x] HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" [136600 2010-06-18] (Sun Microsystems, Inc.) HKU\Adso\...\Run: [Auslogics BoostSpeed 4] C:\Program Files\Auslogics\Auslogics BoostSpeed\boostspeed.exe [ 2009-03-15] (Auslogics) HKU\Adso\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [x] HKU\Adso\...\Run: [TorrentEasy] "C:\Program Files\TorrentEasy\TorrentEasy.exe -autorun" [ 2011-07-05] (Arlington Enterprise Ltd) HKU\Adso\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [ 2012-02-22] (Apple Inc.) HKU\Adso\...\Run: [Yontoo Desktop] "C:\Users\Adso\AppData\Roaming\Yontoo\YontooDesktop.exe" [x] HKU\Adso\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x] HKU\Mcx1-ADSO-PC\...\RunOnce: [ctfmon.exe] ctfmon.exe /n [x] HKU\Mcx1-ADSO-PC\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe ========================== Services (Whitelisted) ================= S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] () S2 wltrysvc; C:\Windows\System32\bcmwltry.exe [2654208 2008-03-12] (Dell Inc.) S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x] S2 aswUpdSv; "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe" [x] S2 avast! Antivirus; "C:\Program Files\Alwil Software\Avast4\ashServ.exe" [x] S3 avast! Mail Scanner; "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service [x] S3 avast! Web Scanner; "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service [x] S3 ehSched; %systemroot%\ehome\ehsched.exe [x] S3 odserv; "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE" [x] S3 PeerDistSvc; %SystemRoot%\system32\peerdistsvc.dll [x] S3 SensrSvc; %SystemRoot%\system32\sensrsvc.dll [x] ==================== Drivers (Whitelisted) ==================== S3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2008-03-12] (Broadcom Corporation) S3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [65640 2010-07-12] (ITE Tech. Inc. ) S3 OA001Ufd; C:\Windows\System32\DRIVERS\OA001Ufd.sys [149208 2008-01-30] (Creative Technology Ltd.) S3 OA001Vid; C:\Windows\System32\DRIVERS\OA001Vid.sys [277624 2008-02-15] (Creative Technology Ltd.) S2 aswFsBlk; system32\DRIVERS\aswFsBlk.sys [x] S2 aswMonFlt; system32\DRIVERS\aswMonFlt.sys [x] S1 aswRdr; No ImagePath S1 aswSP; No ImagePath S1 aswTdi; No ImagePath S3 dvd43llh; System32\DRIVERS\dvd43llh.sys [x] S0 KSecDD; System32\Drivers\ksecdd.sys [x] S3 usbccgp; system32\DRIVERS\usbccgp.sys [x] S3 usbhub; system32\DRIVERS\usbhub.sys [x] S3 usbohci; \SystemRoot\system32\DRIVERS\usbohci.sys [x] S3 usbuhci; system32\DRIVERS\usbuhci.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-05-29 19:23 - 2013-05-29 19:23 - 00000000 ____D C:\FRST 2013-05-27 20:19 - 2013-05-27 20:19 - 00000000 __SHD C:\found.000 2013-05-27 17:12 - 2013-05-27 17:13 - 00000000 ____D C:\Windows\System32\config\mybackup 2013-05-22 05:35 - 2013-05-22 05:35 - 00617737 ____A C:\Users\Adso\Downloads\CB86_Manual.rar 2013-05-20 10:04 - 2013-05-20 10:05 - 00000000 ____D C:\Users\Adso\Downloads\Game.of.Thrones.S03E08.720p.HDTV.x264-EVOLVE [PublicHD] 2013-05-20 02:43 - 2013-05-20 02:43 - 00007212 ____A C:\Users\Adso\Downloads\[kat.ph]game.of.thrones.s03e08.720p.hdtv.x264.evolve.publichd.torrent 2013-05-19 04:14 - 2013-05-19 04:36 - 227106379 ___RA C:\Users\Adso\Downloads\The.Vampire.Diaries.S04E23.HDTV.x264-LOL.mp4 2013-05-19 04:10 - 2013-05-19 04:10 - 00009311 ____A C:\Users\Adso\Downloads\[kat.ph]the.vampire.diaries.s04e23.hdtv.x264.lol.eztv.torrent 2013-05-19 02:28 - 2013-05-19 03:27 - 00000000 ____D C:\Users\Adso\Downloads\The Vampire Diaries S04E22 HDTV x264-LOL[ettv] 2013-05-18 19:14 - 2013-05-18 19:14 - 00000000 ____D C:\Windows\CheckSur 2013-05-18 19:10 - 2013-05-18 19:14 - 00006266 ____A C:\Windows\IE10_main.log 2013-05-17 22:23 - 2013-05-17 22:23 - 00015937 ____A C:\Users\Adso\Downloads\[kat.ph]the.vampire.diaries.s04e22.hdtv.x264.lol.ettv.torrent 2013-05-17 11:09 - 2013-04-04 14:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-17 11:09 - 2013-04-04 14:09 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-17 11:09 - 2013-04-04 14:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-05-17 11:09 - 2013-04-04 14:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-17 11:09 - 2013-04-04 14:02 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-17 11:09 - 2013-04-04 14:01 - 00231936 ____A C:\Windows\System32\url.dll 2013-05-17 11:09 - 2013-04-04 13:59 - 00065024 ____A C:\Windows\System32\jsproxy.dll 2013-05-17 11:09 - 2013-04-04 13:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-17 11:09 - 2013-04-04 13:58 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-05-17 11:09 - 2013-04-04 13:57 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-05-17 11:09 - 2013-04-04 13:56 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-17 11:09 - 2013-04-04 13:55 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-17 11:09 - 2013-04-04 13:54 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-05-17 11:09 - 2013-04-04 13:50 - 00176640 ____A C:\Windows\System32\ieui.dll 2013-05-17 11:03 - 2013-05-05 11:25 - 00000000 ____A C:\Windows\System32\mshtml.dll 2013-05-17 11:03 - 2013-05-05 11:12 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-05-17 07:32 - 2013-04-09 19:14 - 02347520 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-17 07:32 - 2013-03-18 20:53 - 00186368 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll 2013-05-17 07:32 - 2013-03-18 19:33 - 00040960 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll 2013-05-17 07:26 - 2013-04-09 21:18 - 00728424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-17 07:26 - 2013-04-09 21:18 - 00218984 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-05-17 07:19 - 2013-02-26 21:05 - 00101720 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-05-17 07:19 - 2013-02-26 20:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-05-17 07:19 - 2013-02-26 20:55 - 00000000 ____A C:\Windows\System32\shell32.dll 2013-05-17 07:19 - 2013-02-26 20:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-05-17 07:19 - 2013-02-26 20:49 - 00047104 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-05-14 05:42 - 2013-05-14 05:42 - 00002503 ____A C:\Users\Public\Desktop\Skype.lnk 2013-05-14 05:42 - 2013-05-14 05:42 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-05-14 05:39 - 2013-05-14 05:39 - 00000000 ____D C:\Users\Adso\AppData\Local\{462EC8D2-70AF-432D-ACB8-EDFE0CA66246} 2013-05-13 14:34 - 2013-05-13 18:16 - 1563929193 ___RA C:\Users\Adso\Downloads\Game.of.Thrones.S03E07.720p.HDTV.x264-EVOLVE.mkv 2013-05-08 10:53 - 2013-05-08 16:49 - 1139524413 ___RA C:\Users\Adso\Downloads\Game.of.Thrones.S03E06.720p.HDTV.x264-IMMERSE.mkv 2013-05-08 10:01 - 2013-05-10 04:09 - 00000000 ____D C:\Users\Adso\Downloads\Beautiful Creatures (2013) 2013-05-08 10:01 - 2013-05-08 10:51 - 338077928 ___RA C:\Users\Adso\Downloads\Hart.of.Dixie.S02E21.HDTV.x264-LOL.mp4 2013-05-06 16:00 - 2013-05-10 19:01 - 00000000 ____D C:\Users\Adso\AppData\Local\{0958940B-D6CB-4A9F-B23C-FBD7B6326507} 2013-05-04 21:44 - 2013-05-04 22:18 - 250693319 ___RA C:\Users\Adso\Downloads\The.Vampire.Diaries.S04E21.HDTV.x264-2HD.mp4 2013-05-04 15:44 - 2013-05-04 15:44 - 00000000 ____D C:\Users\Adso\AppData\Local\{3CE5B961-9576-44E6-8DDA-49FA09400114} 2013-05-03 18:15 - 2013-05-03 18:15 - 00001989 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-05-03 18:13 - 2013-05-03 18:15 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-05-03 15:27 - 2013-05-04 03:28 - 00000000 ____D C:\Users\Adso\AppData\Local\{69CF6D13-E19A-4058-9FCA-3DA79C2A5B98} 2013-05-02 10:00 - 2013-05-02 15:04 - 1506329585 ___RA C:\Users\Adso\Downloads\Game.of.Thrones.S03E05.PROPER.720p.HDTV.x264-KILLERS.mkv 2013-05-02 04:17 - 2013-05-02 04:17 - 00000000 ____D C:\Users\Adso\AppData\Local\{F4A82D84-5D2B-4A58-AB34-414B428447A8} 2013-04-30 04:21 - 2013-04-30 04:21 - 00000000 ____D C:\Users\Adso\AppData\Local\{7C37E6EC-F68B-4C7A-B677-0FD571270281} 2013-04-29 01:19 - 2013-04-29 01:20 - 00000000 ____D C:\Users\Adso\AppData\Local\{6E6F16F6-B175-4BE5-BC2E-C1D32D13DD2B} ==================== One Month Modified Files and Folders ======== 2013-05-29 19:23 - 2013-05-29 19:23 - 00000000 ____D C:\FRST 2013-05-27 20:19 - 2013-05-27 20:19 - 00000000 __SHD C:\found.000 2013-05-27 17:13 - 2013-05-27 17:12 - 00000000 ____D C:\Windows\System32\config\mybackup 2013-05-25 08:41 - 2009-11-16 18:49 - 01890286 ____A C:\Windows\WindowsUpdate.log 2013-05-25 08:40 - 2012-08-15 04:42 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-05-25 08:27 - 2011-10-08 08:32 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-05-25 06:39 - 2009-07-13 20:39 - 04484672 ____A C:\Windows\setupact.log 2013-05-25 05:46 - 2009-11-16 18:33 - 00019744 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-05-25 05:46 - 2009-11-16 18:33 - 00019744 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-05-25 03:29 - 2013-04-06 08:50 - 00000000 ____D C:\Users\Adso\AppData\Roaming\Yontoo 2013-05-25 02:00 - 2010-10-18 05:45 - 00000442 ____A C:\Windows\Tasks\ParetoLogic Registration3.job 2013-05-25 00:32 - 2011-10-08 08:32 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-05-24 11:00 - 2011-10-08 07:26 - 00018224 ____A C:\Windows\IE9_main.log 2013-05-22 05:35 - 2013-05-22 05:35 - 00617737 ____A C:\Users\Adso\Downloads\CB86_Manual.rar 2013-05-22 04:03 - 2009-11-16 06:50 - 00000000 ____D C:\Users\Adso\AppData\Roaming\uTorrent 2013-05-21 04:57 - 2010-03-24 06:34 - 00000000 ____D C:\Users\Adso\AppData\Roaming\vlc 2013-05-20 10:05 - 2013-05-20 10:04 - 00000000 ____D C:\Users\Adso\Downloads\Game.of.Thrones.S03E08.720p.HDTV.x264-EVOLVE [PublicHD] 2013-05-20 02:43 - 2013-05-20 02:43 - 00007212 ____A C:\Users\Adso\Downloads\[kat.ph]game.of.thrones.s03e08.720p.hdtv.x264.evolve.publichd.torrent 2013-05-20 01:30 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-05-19 04:39 - 2010-01-15 21:57 - 03833344 __ASH C:\Users\Adso\Downloads\Thumbs.db 2013-05-19 04:36 - 2013-05-19 04:14 - 227106379 ___RA C:\Users\Adso\Downloads\The.Vampire.Diaries.S04E23.HDTV.x264-LOL.mp4 2013-05-19 04:10 - 2013-05-19 04:10 - 00009311 ____A C:\Users\Adso\Downloads\[kat.ph]the.vampire.diaries.s04e23.hdtv.x264.lol.eztv.torrent 2013-05-19 03:27 - 2013-05-19 02:28 - 00000000 ____D C:\Users\Adso\Downloads\The Vampire Diaries S04E22 HDTV x264-LOL[ettv] 2013-05-18 19:14 - 2013-05-18 19:14 - 00000000 ____D C:\Windows\CheckSur 2013-05-18 19:14 - 2013-05-18 19:10 - 00006266 ____A C:\Windows\IE10_main.log 2013-05-17 22:23 - 2013-05-17 22:23 - 00015937 ____A C:\Users\Adso\Downloads\[kat.ph]the.vampire.diaries.s04e22.hdtv.x264.lol.ettv.torrent 2013-05-17 12:32 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-05-17 11:29 - 2009-07-13 20:33 - 00411192 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-17 11:06 - 2009-11-16 18:57 - 00744818 ____A C:\Windows\System32\PerfStringBackup.INI 2013-05-17 11:05 - 2009-11-16 20:15 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-05-17 06:41 - 2012-08-15 04:42 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-05-17 06:41 - 2011-10-08 07:54 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-05-17 06:37 - 2009-11-20 01:30 - 00000000 ____D C:\ProgramData\Adobe 2013-05-17 06:32 - 2013-04-06 08:51 - 00000000 ____D C:\ProgramData\BrowserProtect 2013-05-17 06:32 - 2009-11-16 18:40 - 00054402 ____A C:\Windows\PFRO.log 2013-05-14 05:43 - 2010-06-15 08:08 - 00000000 ____D C:\Users\Adso\AppData\Roaming\Skype 2013-05-14 05:43 - 2010-06-15 08:06 - 00000000 ____D C:\ProgramData\Skype 2013-05-14 05:43 - 2009-11-16 05:13 - 00000000 ____D C:\Program Files\Windows Live 2013-05-14 05:42 - 2013-05-14 05:42 - 00002503 ____A C:\Users\Public\Desktop\Skype.lnk 2013-05-14 05:42 - 2013-05-14 05:42 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-05-14 05:42 - 2010-06-15 08:06 - 00000000 ___RD C:\Program Files\Skype 2013-05-14 05:39 - 2013-05-14 05:39 - 00000000 ____D C:\Users\Adso\AppData\Local\{462EC8D2-70AF-432D-ACB8-EDFE0CA66246} 2013-05-13 18:16 - 2013-05-13 14:34 - 1563929193 ___RA C:\Users\Adso\Downloads\Game.of.Thrones.S03E07.720p.HDTV.x264-EVOLVE.mkv 2013-05-10 19:01 - 2013-05-06 16:00 - 00000000 ____D C:\Users\Adso\AppData\Local\{0958940B-D6CB-4A9F-B23C-FBD7B6326507} 2013-05-10 04:09 - 2013-05-08 10:01 - 00000000 ____D C:\Users\Adso\Downloads\Beautiful Creatures (2013) 2013-05-08 16:49 - 2013-05-08 10:53 - 1139524413 ___RA C:\Users\Adso\Downloads\Game.of.Thrones.S03E06.720p.HDTV.x264-IMMERSE.mkv 2013-05-08 10:51 - 2013-05-08 10:01 - 338077928 ___RA C:\Users\Adso\Downloads\Hart.of.Dixie.S02E21.HDTV.x264-LOL.mp4 2013-05-08 04:36 - 2009-11-16 06:31 - 00000000 ____D C:\Users\Adso\AppData\Roaming\Adobe 2013-05-05 11:25 - 2013-05-17 11:03 - 00000000 ____A C:\Windows\System32\mshtml.dll 2013-05-05 11:12 - 2013-05-17 11:03 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-05-04 22:18 - 2013-05-04 21:44 - 250693319 ___RA C:\Users\Adso\Downloads\The.Vampire.Diaries.S04E21.HDTV.x264-2HD.mp4 2013-05-04 17:49 - 2009-11-22 17:03 - 00000000 ____D C:\Windows\ahome 2013-05-04 15:44 - 2013-05-04 15:44 - 00000000 ____D C:\Users\Adso\AppData\Local\{3CE5B961-9576-44E6-8DDA-49FA09400114} 2013-05-04 03:28 - 2013-05-03 15:27 - 00000000 ____D C:\Users\Adso\AppData\Local\{69CF6D13-E19A-4058-9FCA-3DA79C2A5B98} 2013-05-03 18:15 - 2013-05-03 18:15 - 00001989 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-05-03 18:15 - 2013-05-03 18:13 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-05-03 18:13 - 2012-01-24 01:16 - 00000000 ____D C:\Program Files\Adobe 2013-05-03 18:12 - 2009-11-20 01:19 - 00000000 ____D C:\Users\Adso\AppData\Local\Adobe 2013-05-03 15:25 - 2009-11-16 06:51 - 00000000 ____D C:\Program Files\uTorrent 2013-05-02 15:04 - 2013-05-02 10:00 - 1506329585 ___RA C:\Users\Adso\Downloads\Game.of.Thrones.S03E05.PROPER.720p.HDTV.x264-KILLERS.mkv 2013-05-02 07:28 - 2009-11-16 06:56 - 00238872 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2013-05-02 04:17 - 2013-05-02 04:17 - 00000000 ____D C:\Users\Adso\AppData\Local\{F4A82D84-5D2B-4A58-AB34-414B428447A8} 2013-04-30 04:21 - 2013-04-30 04:21 - 00000000 ____D C:\Users\Adso\AppData\Local\{7C37E6EC-F68B-4C7A-B677-0FD571270281} 2013-04-29 01:20 - 2013-04-29 01:19 - 00000000 ____D C:\Users\Adso\AppData\Local\{6E6F16F6-B175-4BE5-BC2E-C1D32D13DD2B} ==================== Known DLLs (Whitelisted) ============ [2013-05-17 07:19] - [2013-02-26 20:55] - 0000000 ____A () C:\Windows\System32\SHELL32.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 12% Total physical RAM: 4093.97 MB Available physical RAM: 3573.24 MB Total Pagefile: 4092.25 MB Available Pagefile: 3585.61 MB Total Virtual: 2047.88 MB Available Virtual: 1935.71 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:298.09 GB) (Free:53.42 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: () (Removable) (Total:3.61 GB) (Free:3.43 GB) NTFS Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 3FF9F299) Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 4 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=4 GB) - (Type=07 NTFS) Last Boot: 2010-08-20 04:30 ==================== End Of Log ============================