Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-01-2015 01 Ran by SYSTEM on MININT-M61A64A (14-01-2016 21:06:58) Running from g:\ Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 Boot Mode: Recovery Default: ControlSet001 [b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b] Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-04-05] (Intel Corporation) HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [1690680 2009-11-19] (Hewlett-Packard) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2074408 2010-02-26] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-28] (IDT, Inc.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2728736 2014-08-04] () HKLM\...\Run: [Eraser] => C:\Program Files\Eraser\Eraser.exe [1074112 2015-10-15] (The Eraser Project) HKLM-x32\...\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [287800 2009-11-11] ( Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-11-20] (NEC Electronics Corporation) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [111640 2009-11-04] () HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-04-20] (Cisco Systems, Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe, Winlogon\Notify\ScCertProp: wlnotify.dll [X] Winlogon\Notify\SEP-x32: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\WinLogoutNotifier.dll [X] HKU\Admin\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\System32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation) HKU\me\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd) HKU\me\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation) HKU\he\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\System32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation) Lsa: [Notification Packages] DPPassFilter scecli ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AESTFilters; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) S3 Com4QLBEx; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [0 2009-05-05] () <==== ATTENTION (zero byte File/Folder) S3 DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [704512 2009-11-11] (McAfee, Inc.) S2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462088 2009-11-24] (DigitalPersona, Inc.) S2 HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [36864 2009-11-18] (Hewlett-Packard Development Company, L.P) S2 HpFkCryptService; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [277096 2009-11-11] (McAfee, Inc.) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-17] (Malwarebytes Corporation) S2 NVWMI; C:\Windows\system32\nvwmi64.exe [2694432 2014-08-04] () S2 SepMasterService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe [137224 2011-06-18] (Symantec Corporation) S2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [0 2010-11-19] () <==== ATTENTION (zero byte File/Folder) S3 SmcService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin64\Smc.exe [2591232 2011-06-18] (Symantec Corporation) S3 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin64\snac64.exe [324528 2011-06-18] (Symantec Corporation) S2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\STacSV64.exe [244736 2010-01-28] (IDT, Inc.) S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [0 2009-07-13] () <==== ATTENTION (zero byte File/Folder) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) S2 HPSIService; C:\windows\system32\HPSIsvc.exe [X] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [141624 2014-05-13] (Motorola Solutions, Inc.) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [498512 2015-11-18] (Symantec Corporation) S1 IDSVia64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\IPSDefs\20160107.011\IDSvia64.sys [767224 2016-01-07] (Symantec Corporation) S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-06-17] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-06-17] (Malwarebytes Corporation) S3 NAVENG; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\VirusDefs\20160107.024\ENG64.SYS [138488 2015-12-05] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\VirusDefs\20160107.024\EX64.SYS [2148080 2015-12-05] (Symantec Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] () S3 rismcx64; C:\Windows\System32\DRIVERS\rismcx64.sys [59008 2009-07-20] (RICOH Company, Ltd.) S1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [58184 2009-11-11] (McAfee, Inc.) S1 RsvLock; C:\Windows\SysWow64\Drivers\RsvLock.sys [40088 2009-11-11] (McAfee, Inc.) S0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [56648 2009-11-11] (McAfee, Inc.) S0 SafeBoot; C:\Windows\SysWow64\Drivers\SafeBoot.sys [110520 2009-11-11] (McAfee, Inc.) S0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2009-06-04] (McAfee, Inc.) S0 SbAlg; C:\Windows\SysWow64\Drivers\SbAlg.sys [51800 2009-11-11] (McAfee, Inc.) S0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15688 2009-11-11] (McAfee, Inc.) S0 SbFsLock; C:\Windows\SysWow64\Drivers\SbFsLock.sys [13256 2009-11-11] (McAfee, Inc.) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1798400 2009-12-18] () S0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-09-29] (Duplex Secure Ltd.) S1 SRTSP; C:\Windows\System32\Drivers\SEP\0C01029F\136B.105\x64\SRTSP64.SYS [745592 2011-06-18] (Symantec Corporation) S1 SRTSPX; C:\Windows\System32\Drivers\SEP\0C01029F\136B.105\x64\SRTSPX64.SYS [40568 2011-06-18] (Symantec Corporation) S3 SyDvCtrl; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin64\SyDvCtrl64.sys [29664 2011-06-18] (Symantec Corporation) S0 SymDS; C:\Windows\System32\Drivers\SEP\0C01029F\136B.105\x64\SYMDS64.SYS [451192 2011-06-18] (Symantec Corporation) S0 SymEFA; C:\Windows\System32\Drivers\SEP\0C01029F\136B.105\x64\SYMEFA64.SYS [928888 2011-06-18] (Symantec Corporation) S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2013-08-06] (Symantec Corporation) S1 SymIRON; C:\Windows\System32\Drivers\SEP\0C01029F\136B.105\x64\Ironx64.SYS [170104 2011-06-18] (Symantec Corporation) S1 SYMNETS; C:\Windows\System32\Drivers\SEP\0C01029F\136B.105\x64\SYMNETS.SYS [386168 2011-06-18] (Symantec Corporation) S1 SysPlant; C:\Windows\System32\Drivers\SysPlant.sys [147632 2013-08-06] (Symantec Corporation) S1 Teefer2; C:\Windows\System32\DRIVERS\Teefer.sys [62136 2011-06-18] (Symantec Corporation) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2015-04-20] (Cisco Systems, Inc.) S1 BHDrvx64; \??\C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\BASHDefs\20151223.011\BHDrvx64.sys [X] S3 btwaudio; system32\drivers\btwaudio.sys [X] S3 btwavdt; system32\DRIVERS\btwavdt.sys [X] S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X] S3 btwrchid; system32\DRIVERS\btwrchid.sys [X] S3 mvusbews; System32\Drivers\mvusbews.sys [X] S3 usbscan; system32\DRIVERS\usbscan.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-01-14 21:06 - 2016-01-14 21:06 - 00000000 ____D C:\FRST 2016-01-11 06:17 - 2016-01-11 06:17 - 00000000 __SHD C:\found.003 2016-01-09 00:54 - 2016-01-14 10:52 - 02078292 _____ C:\Windows\ntbtlog.txt 2016-01-08 15:09 - 2016-01-08 15:09 - 00000000 __SHD C:\found.002 2016-01-08 14:22 - 2016-01-08 14:22 - 00000000 __SHD C:\found.001 2016-01-08 12:39 - 2016-01-09 00:04 - 00302557 ____N C:\Windows\Minidump\010916-54974-01.dmp 2016-01-07 05:58 - 2016-01-07 05:58 - 00090168 _____ C:\Users\me\AppData\Local\GDIPFONTCACHEV1.DAT 2016-01-07 05:48 - 2016-01-07 05:49 - 00344448 _____ C:\Windows\System32\FNTCACHE.DAT 2016-01-07 05:28 - 2016-01-07 05:29 - 14494856 _____ (Goversoft LLC) C:\PrivaZer.exe 2015-12-28 09:43 - 2010-04-28 07:49 - 00212992 _____ C:\Windows\System32\m1130wia.dll 2015-12-27 11:52 - 2015-12-27 11:52 - 00000000 ____D C:\Users\me\AppData\Roaming\Sharp 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 ____D C:\Windows\SysWOW64\SCDRV 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CUP2.DLL 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CUN.DLL 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CUJ.DLL 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CUAG.EXE 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CSTMN.HLP 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CSTMN.CHM 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CNP.DAT 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CLMSW.EXE 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CJ_DV.DAT 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CHID.DAT 2015-12-27 11:51 - 2015-12-27 11:52 - 00000000 _____ C:\Windows\System32\OD0CGD.DLL 2015-12-27 11:51 - 2010-01-15 01:40 - 02735616 _____ (Sharp Corporation) C:\Windows\System32\OD0CUR.DLL 2015-12-27 11:51 - 2010-01-15 01:40 - 00058783 _____ C:\Windows\System32\OD0CPDRV.CHM 2015-12-27 11:51 - 2010-01-15 01:40 - 00053036 _____ C:\Windows\System32\OD0CPDRV.HLP 2015-12-27 11:51 - 2010-01-15 01:40 - 00016896 _____ (SHARP Corporation) C:\Windows\System32\OD0CSTMN.DLL 2015-12-27 11:51 - 2010-01-15 01:40 - 00001124 _____ C:\Windows\System32\OD0C_RLV.DAT 2015-12-27 11:51 - 2010-01-15 01:40 - 00001070 _____ C:\Windows\System32\OD0CUWM.DAT 2015-12-27 11:51 - 2010-01-14 07:22 - 01005056 _____ (Sharp Corporation) C:\Windows\System32\OD0CUP.DLL 2015-12-27 11:51 - 2010-01-14 07:22 - 00429568 _____ (Sharp Corporation) C:\Windows\System32\OD0CUD.DLL 2015-12-27 11:51 - 2010-01-14 07:22 - 00215040 _____ (SHARP CORPORATION) C:\Windows\System32\OD0CSTMN.EXE 2015-12-27 11:51 - 2010-01-14 07:22 - 00003948 _____ C:\Windows\System32\OD0CGCT.DAT 2015-12-27 11:51 - 2010-01-14 07:22 - 00001506 _____ C:\Windows\System32\OD0CSTMN.DAT 2015-12-27 11:51 - 2010-01-14 07:22 - 00000062 _____ C:\Windows\System32\OD0CGCP.DAT 2015-12-27 11:51 - 2004-04-12 07:17 - 00045056 ____N C:\Windows\SysWOW64\_isusr2k.dll 2015-12-21 15:01 - 2016-01-07 22:00 - 00000649 _____ C:\Users\me\Desktop\PUTTY.lnk ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-01-14 11:37 - 2011-07-25 03:46 - 00000000 ____D C:\ProgramData\NVIDIA 2016-01-09 00:54 - 2009-07-13 19:20 - 00000000 ____D C:\Windows 2016-01-09 00:05 - 2013-09-13 22:18 - 00000000 ____D C:\Windows\Minidump 2016-01-07 22:00 - 2014-04-09 11:43 - 00000600 _____ C:\Users\me\AppData\Roaming\winscp.rnd 2016-01-07 21:59 - 2013-08-20 02:10 - 00065398 _____ C:\Windows\Q-Dir.ini 2016-01-07 21:58 - 2014-05-07 06:42 - 00002312 _____ C:\Users\me\Desktop\Zimbra Web Client.lnk 2016-01-07 21:49 - 2015-11-07 13:47 - 00000000 ____D C:\Users\me\AppData\Roaming\vlc 2016-01-07 21:49 - 2015-09-08 12:41 - 00000000 ____D C:\##OBLICZ 2016-01-07 21:31 - 2009-07-13 20:45 - 00020944 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-01-07 21:31 - 2009-07-13 20:45 - 00020944 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-01-07 21:29 - 2013-08-20 02:10 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-01-07 21:27 - 2009-07-13 21:13 - 00786622 _____ C:\Windows\System32\PerfStringBackup.INI 2016-01-07 21:27 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf 2016-01-07 21:24 - 2013-08-20 02:10 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-01-07 21:23 - 2010-09-23 11:37 - 00000000 ____D C:\ProgramData\HPQLOG 2016-01-07 21:23 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-01-07 20:44 - 2014-02-05 14:59 - 00002236 ____H C:\Users\me\Documents\Default.rdp 2016-01-07 20:38 - 2013-08-06 05:03 - 00000568 _____ C:\Windows\System32\config\netlogon.ftl 2016-01-07 06:07 - 2011-07-25 10:34 - 00337239 ____N C:\Windows\Minidump\010716-49701-01.dmp 2016-01-07 06:03 - 2013-08-06 05:07 - 00026264 __RSH C:\ProgramData\ntuser.pol 2016-01-07 05:44 - 2015-09-28 22:06 - 00000000 ____D C:\Users\me\AppData\Roaming\WiseUpdate 2016-01-07 05:44 - 2014-09-30 12:07 - 00000000 ____D C:\Users\me\AppData\Roaming\Wise Disk Cleaner 2016-01-07 05:44 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\ModemLogs 2015-12-27 11:51 - 2013-08-27 02:41 - 00000000 ____D C:\Users\me\AppData\Roaming\InstallShield 2015-12-27 11:51 - 2010-09-23 11:20 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2015-12-26 11:54 - 2015-08-23 04:36 - 00003204 _____ C:\Windows\System32\Tasks\HPCeeScheduleForme 2015-12-26 11:54 - 2015-08-23 04:36 - 00000344 _____ C:\Windows\Tasks\HPCeeScheduleForme.job 2015-12-22 14:39 - 2014-04-07 10:59 - 00000600 _____ C:\Users\me\AppData\Local\PUTTY.RND 2015-12-16 14:33 - 2014-08-24 21:20 - 00002194 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-12-16 14:33 - 2014-08-24 21:20 - 00002194 _____ C:\ProgramData\Desktop\Google Chrome.lnk Some files in TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\HPQSi.exe C:\Users\Admin\AppData\Local\Temp\MSNDD36.exe C:\Users\Admin\AppData\Local\Temp\_is77CE.exe C:\Users\he\AppData\Local\Temp\yd4-unyz.dll ==================== Known DLLs (Whitelisted) ========================= ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\dnsapi.dll => MD5 is legit C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE Association (Whitelisted) ============= ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 10% Total physical RAM: 8047.38 MB Available physical RAM: 7206.23 MB Total Virtual: 8045.58 MB Available Virtual: 7201.08 MB ==================== Drives ================================ Drive c: (W7Sys) (Fixed) (Total:448.47 GB) (Free:301.49 GB) NTFS ==>[system with boot components (obtained from drive)] Drive e: (HP_RECOVERY) (Fixed) (Total:15 GB) (Free:3.01 GB) NTFS ==>[system with boot components (obtained from drive)] Drive f: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.49 GB) FAT32 Drive g: (GSP1RMCPRXFRER_EN_DVD) (Removable) (Total:14.94 GB) (Free:11.73 GB) NTFS Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (SYSTEM) (Fixed) (Total:0.29 GB) (Free:0.17 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 53C1809D) Partition 1: (Active) - (Size=301 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=448.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=2 GB) - (Type=0C) ======================================================== Disk: 1 (Size: 14.9 GB) (Disk ID: 1BDCCE8A) Partition 1: (Active) - (Size=14.9 GB) - (Type=07 NTFS) LastRegBack: 2015-12-31 00:35 ==================== End of FRST.txt ============================