Ran by SYSTEM at 21-03-2013 13:01:15
Running from F:\
Windows Vista Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1584184 2008-01-20] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1560360 2008-07-10] (Synaptics, Inc.)
HKLM\...\Run: [IAAnotif] "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [182808 2008-07-20] (Intel Corporation)
HKLM-x32\...\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Gateway\traybar.exe" [638976 2008-09-09] (Chicony)
HKLM-x32\...\Run: [eRecoveryService] [x]
HKLM-x32\...\Run: [ArcSoft Connection Service] "C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Maps4PC_0c Browser Plugin Loader] C:\PROGRA~2\MAPS4P~2\bar\1.bin\0cbrmon.exe [30096 2011-09-21] (VER_COMPANY_NAME)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152544 2012-12-12] (Apple Inc.)
HKLM-x32\...\Run: [CouponXplorer Search Scope Monitor] "C:\PROGRA~2\COUPON~2\bar\1.bin\5zsrchmn.exe" /m=2 /w /h [42536 2013-02-09] (MindSpark)
HKLM-x32\...\Run: [CouponXplorer_5z Browser Plugin Loader] C:\PROGRA~2\COUPON~2\bar\1.bin\5zbrmon.exe [30096 2013-02-09] (VER_COMPANY_NAME)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\Jessica\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-10] (Microsoft Corporation)
HKU\Jessica\...\Run: [Aim6] [x]
HKU\Jessica\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\Jessica\...\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [x]
HKU\Jessica\...\Run: [KGShareApp] C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe [394752 2012-10-11] (Eastman Kodak Company)
HKU\Jessica\...\Run: [Spotify] "C:\Users\Jessica\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [4489112 2013-03-16] (Spotify Ltd)
HKU\Jessica\...\Run: [Spotify Web Helper] "C:\Users\Jessica\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1103768 2013-03-16] (Spotify Ltd)
HKU\Jessica\...\Winlogon: [Shell] explorer.exe,C:\Users\Jessica\AppData\Roaming\skype.dat [84992 2011-11-18] ()
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\ProgramData\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
ShortcutTarget: Kodak EasyShare software.lnk -> C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Jessica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ===================
2 0256671271953383mcinstcleanup; C:\Users\Jessica\AppData\Local\Temp\025667~1.EXE C:\PROGRA~2\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [1557 2010-04-22] ()
2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
2 CouponXplorer_5zService; C:\PROGRA~2\COUPON~2\bar\1.bin\5zbarsvc.exe [42504 2013-02-09] (COMPANYVERS_NAME)
2 ETService; C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe [24576 2008-06-11] ()
2 Maps4PC_0cService; C:\PROGRA~2\MAPS4P~2\bar\1.bin\0cbarsvc.exe [42504 2011-09-21] (COMPANYVERS_NAME)
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [235216 2013-02-05] (McAfee, Inc.)
2 N360; "C:\Program Files (x86)\Norton Security Suite\Engine\20.2.0.19\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton Security Suite\Engine\20.2.0.19\diMaster.dll" /prefetch:1 [535416 2012-10-11] (Symantec Corporation)
2 Viewpoint Manager Service; "C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe" [24652 2007-01-04] (Viewpoint Corporation)
==================== Drivers (Whitelisted) =====================
1 BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130301.001\BHDrvx64.sys [1388120 2013-02-07] (Symantec Corporation)
1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1402000.013\ccSetx64.sys [168096 2012-10-03] (Symantec Corporation)
1 eeCtrl; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-08-08] (Symantec Corporation)
3 EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-08-08] (Symantec Corporation)
1 IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130313.001\IDSvia64.sys [513184 2013-02-22] (Symantec Corporation)
2 int15; C:\Windows\SysWow64\Drivers\int15.sys [15392 2008-06-11] (Acer, Inc.)
3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130316.006\ENG64.SYS [126192 2013-02-24] (Symantec Corporation)
3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130316.006\EX64.SYS [2087664 2013-02-24] (Symantec Corporation)
3 O2MDRDR; C:\Windows\System32\DRIVERS\o2mdx64.sys [62296 2008-07-15] (O2Micro )
0 SI3132; C:\Windows\System32\Drivers\SI3132.sys [90664 2007-10-03] (Silicon Image, Inc)
0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [22056 2007-10-03] (Silicon Image, Inc)
0 SiRemFil; C:\Windows\System32\Drivers\SiRemFil.sys [17448 2007-10-03] (Silicon Image, Inc)
3 SRTSP; C:\Windows\System32\Drivers\N360x64\1402000.013\SRTSP64.SYS [776864 2012-10-08] (Symantec Corporation)
1 SRTSPX; C:\Windows\system32\drivers\N360x64\1402000.013\SRTSPX64.SYS [37496 2012-05-24] (Symantec Corporation)
0 SymDS; C:\Windows\System32\drivers\N360x64\1402000.013\SYMDS64.SYS [493216 2012-10-03] (Symantec Corporation)
0 SymEFA; C:\Windows\System32\drivers\N360x64\1402000.013\SYMEFA64.SYS [1133216 2012-10-03] (Symantec Corporation)
3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-02-16] (Symantec Corporation)
1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [43680 2012-08-08] (Symantec Corporation)
1 SymIRON; C:\Windows\system32\drivers\N360x64\1402000.013\Ironx64.SYS [224416 2012-07-27] (Symantec Corporation)
1 SYMTDIv; C:\Windows\System32\Drivers\N360x64\1402000.013\SYMTDIV.SYS [455840 2012-07-22] (Symantec Corporation)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2013-03-21 13:01 - 2013-03-21 13:01 - 00000000 ____D C:\FRST
2013-03-17 08:42 - 2013-03-17 08:42 - 00056712 ____A C:\Users\Jessica\Downloads\Extras.Txt
2013-03-17 08:40 - 2013-03-17 08:40 - 00166608 ____A C:\Users\Jessica\Downloads\OTL.Txt
2013-03-17 07:28 - 2013-03-17 07:28 - 00602112 ____A (OldTimer Tools) C:\Users\Jessica\Downloads\OTL.com
2013-03-17 07:22 - 2013-03-17 07:22 - 00001599 ____A C:\Users\Jessica\Desktop\aswMBR.txt
2013-03-17 07:22 - 2013-03-17 07:22 - 00000512 ____A C:\Users\Jessica\Desktop\MBR.dat
2013-03-16 18:36 - 2013-03-20 15:47 - 00000732 ____A C:\Users\Jessica\AppData\Local\d3d9caps64.dat
2013-03-16 11:23 - 2013-03-20 16:33 - 00000004 ____A C:\Users\Jessica\AppData\Roaming\skype.ini
2013-03-16 11:03 - 2013-03-20 16:03 - 00000680 ____A C:\Users\Jessica\AppData\Local\d3d9caps.dat
2013-03-13 23:01 - 2013-02-01 23:31 - 17815040 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-03-13 23:01 - 2013-02-01 22:58 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-03-13 23:01 - 2013-02-01 22:57 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-03-13 23:01 - 2013-02-01 22:48 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-03-13 23:01 - 2013-02-01 22:47 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-03-13 23:01 - 2013-02-01 22:47 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-03-13 23:01 - 2013-02-01 22:46 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-03-13 23:01 - 2013-02-01 22:43 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-03-13 23:01 - 2013-02-01 22:42 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-03-13 23:01 - 2013-02-01 22:42 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-03-13 23:01 - 2013-02-01 22:41 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-03-13 23:01 - 2013-02-01 22:40 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-03-13 23:01 - 2013-02-01 22:39 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-03-13 23:01 - 2013-02-01 22:38 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-03-13 23:01 - 2013-02-01 22:38 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-03-13 23:01 - 2013-02-01 22:34 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-03-13 23:01 - 2013-02-01 20:09 - 12321792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-03-13 23:01 - 2013-02-01 19:42 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-03-13 23:01 - 2013-02-01 19:38 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-03-13 23:01 - 2013-02-01 19:31 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-03-13 23:01 - 2013-02-01 19:30 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-03-13 23:01 - 2013-02-01 19:30 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-03-13 23:01 - 2013-02-01 19:29 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-03-13 23:01 - 2013-02-01 19:27 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-03-13 23:01 - 2013-02-01 19:26 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-03-13 23:01 - 2013-02-01 19:26 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-03-13 23:01 - 2013-02-01 19:26 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-03-13 23:01 - 2013-02-01 19:25 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-03-13 23:01 - 2013-02-01 19:23 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-03-13 23:01 - 2013-02-01 19:23 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-03-13 23:01 - 2013-02-01 19:23 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-03-13 23:01 - 2013-02-01 19:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-02-25 10:28 - 2013-02-25 10:29 - 00014185 ____A C:\Users\Jessica\Documents\Martin Budget.xlsx
2013-02-24 08:48 - 2012-08-08 17:50 - 00043680 ___RA (Symantec Corporation) C:\Windows\System32\Drivers\SymIMV.sys
==================== One Month Modified Files and Folders =======
2013-03-20 16:34 - 2008-12-10 15:49 - 01074091 ____A C:\Windows\WindowsUpdate.log
2013-03-20 16:34 - 2008-10-30 12:29 - 00000012 ____A C:\Windows\bthservsdp.dat
2013-03-20 16:34 - 2006-11-02 07:42 - 00032588 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-03-20 16:34 - 2006-11-02 07:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-03-20 16:34 - 2006-11-02 07:22 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-03-20 16:34 - 2006-11-02 07:22 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-03-20 16:33 - 2013-03-16 11:23 - 00000004 ____A C:\Users\Jessica\AppData\Roaming\skype.ini
2013-03-20 16:33 - 2012-04-15 03:15 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-03-20 16:10 - 2012-08-17 12:50 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-03-20 16:03 - 2013-03-16 11:03 - 00000680 ____A C:\Users\Jessica\AppData\Local\d3d9caps.dat
2013-03-20 15:47 - 2013-03-16 18:36 - 00000732 ____A C:\Users\Jessica\AppData\Local\d3d9caps64.dat
2013-03-20 15:46 - 2013-02-11 16:04 - 00000000 ____D C:\Users\Jessica\AppData\Roaming\Spotify
2013-03-20 15:41 - 2012-08-17 12:50 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-03-20 15:41 - 2008-12-10 16:13 - 00000000 ____A C:\Windows\System32\LogConfigTemp.xml
2013-03-19 15:47 - 2008-10-30 13:35 - 00002611 ____A C:\Users\Jessica\Desktop\Microsoft Word.lnk
2013-03-17 08:42 - 2013-03-17 08:42 - 00056712 ____A C:\Users\Jessica\Downloads\Extras.Txt
2013-03-17 08:40 - 2013-03-17 08:40 - 00166608 ____A C:\Users\Jessica\Downloads\OTL.Txt
2013-03-17 07:28 - 2013-03-17 07:28 - 00602112 ____A (OldTimer Tools) C:\Users\Jessica\Downloads\OTL.com
2013-03-17 07:22 - 2013-03-17 07:22 - 00001599 ____A C:\Users\Jessica\Desktop\aswMBR.txt
2013-03-17 07:22 - 2013-03-17 07:22 - 00000512 ____A C:\Users\Jessica\Desktop\MBR.dat
2013-03-17 06:36 - 2006-11-02 04:46 - 00703516 ____A C:\Windows\System32\PerfStringBackup.INI
2013-03-16 12:04 - 2010-04-03 06:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-03-16 12:03 - 2012-11-17 15:45 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2013-03-16 12:03 - 2012-11-17 15:45 - 00000000 ____D C:\ProgramData\Application Data\McAfee Security Scan
2013-03-16 12:03 - 2008-10-30 13:31 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-03-16 12:03 - 2008-10-30 13:31 - 00000000 ____D C:\ProgramData\Application Data\Microsoft Help
2013-03-16 12:03 - 2006-11-02 05:34 - 00000000 ____D C:\Windows\System32\spool
2013-03-16 12:03 - 2006-11-02 05:33 - 00000000 __RSD C:\Windows\Media
2013-03-16 12:03 - 2006-11-02 05:33 - 00000000 ____D C:\Windows\registration
2013-03-16 11:27 - 2008-01-20 19:26 - 00425034 ____A C:\Windows\PFRO.log
2013-03-16 11:18 - 2012-03-09 15:54 - 00000000 ____D C:\Users\Jessica\AppData\Local\CrashDumps
2013-03-14 14:56 - 2013-02-11 16:05 - 00000000 ____D C:\Users\Jessica\AppData\Local\Spotify
2013-03-13 23:03 - 2006-11-02 04:35 - 72013344 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2013-03-13 18:56 - 2012-08-17 12:51 - 00001987 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-03-13 02:23 - 2012-04-15 03:15 - 00693976 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-03-13 02:23 - 2011-05-15 08:24 - 00073432 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-03-05 03:33 - 2009-12-28 17:15 - 00000404 ____A C:\Windows\Tasks\EasyShare Registration Task.job
2013-03-03 09:14 - 2010-04-22 08:25 - 00000000 ____D C:\Windows\System32\Drivers\N360x64
2013-02-25 10:29 - 2013-02-25 10:28 - 00014185 ____A C:\Users\Jessica\Documents\Martin Budget.xlsx
2013-02-25 07:21 - 2008-10-30 13:35 - 00002569 ____A C:\Users\Jessica\Desktop\Microsoft Office Excel 2007.lnk
2013-02-24 08:52 - 2010-04-22 08:22 - 00000000 ____D C:\ProgramData\Norton
2013-02-24 08:52 - 2010-04-22 08:22 - 00000000 ____D C:\ProgramData\Application Data\Norton
2013-02-24 08:46 - 2012-07-13 16:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2012-12-11 18:12] - [2012-08-21 03:50] - 0267648 ____A (Microsoft Corporation) 582F710097B46140F5A89A19A6573D4B
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-03-06 21:00:09
Restore point made on: 2013-03-08 13:57:22
Restore point made on: 2013-03-09 05:21:23
Restore point made on: 2013-03-09 21:00:21
Restore point made on: 2013-03-10 20:38:29
Restore point made on: 2013-03-11 20:00:20
Restore point made on: 2013-03-12 20:35:12
Restore point made on: 2013-03-13 20:00:08
Restore point made on: 2013-03-13 23:00:18
Restore point made on: 2013-03-14 18:00:30
Restore point made on: 2013-03-15 20:00:20
Restore point made on: 2013-03-16 11:57:31
Restore point made on: 2013-03-17 07:15:58
Restore point made on: 2013-03-17 08:23:09
==================== Memory info ===========================
Percentage of memory in use: 10%
Total physical RAM: 3960.13 MB
Available physical RAM: 3533.84 MB
Total Pagefile: 3832.04 MB
Available Pagefile: 3607.44 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
==================== Partitions =============================
1 Drive c: (OS) (Fixed) (Total:144.04 GB) (Free:28.23 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (DATA) (Fixed) (Total:144.04 GB) (Free:143.95 GB) NTFS
4 Drive f: () (Removable) (Total:1.86 GB) (Free:1.74 GB) FAT
5 Drive x: (PQSERVICE) (Fixed) (Total:10 GB) (Free:1.56 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 1337 KB
Disk 1 Online 1902 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 10 GB 1024 KB
Partition 2 Primary 144 GB 10 GB
Partition 3 Primary 144 GB 154 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 X PQSERVICE NTFS Partition 10 GB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 144 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 D DATA NTFS Partition 144 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1902 MB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 F FAT Removable 1902 MB Healthy
=========================================================
============================== MBR Partition Table ==================
==============================
Partitions of Disk 0:
===============
Disk ID: 5F5706B2
Partition 1:
=========
Hex: 0020210027FEFFFF0008000000004001
Active: NO
Type: 27
Size: 10 GB
Partition 2:
=========
Hex: 80FEFFFF07FEFFFF0008400100680112
Active: YES
Type: 07 (NTFS)
Size: 144 GB
Partition 3:
=========
Hex: 00FEFFFF07FEFFFF0070411300700112
Active: NO
Type: 07 (NTFS)
Size: 144 GB
==============================
Partitions of Disk 1:
===============
Disk ID: 00C451D0
Partition 1:
=========
Hex: 8001010006FEFFFF400000002C6C3B00
Active: YES
Type: 06
Size: 2 GB
Last Boot: 2013-03-20 15:46
==================== End Of Log =============================