Malwarebytes Anti-Rootkit BETA
Database version: v2014.12.30.02
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
peeaitcheye :: PEEAITCHEYE-PC [administrator]
12/29/2014 9:56:19 PM
mbar-log-2014-12-29 (21-56-19).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 323315
Time elapsed: 4 minute(s), 9 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
------------ Kernel report ------------
12/29/2014 21:56:13
------------ Loaded modules -----------
----------- End -----------
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xfffffa80089f3620
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000076\
Lower Device Object: 0xfffffa80087e3b70
Lower Device Driver Name: \Driver\USBSTOR\
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa800780c060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP1T0L0-1\
Lower Device Object: 0xfffffa800752e060
Lower Device Driver Name: \Driver\atapi\
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa800780c060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800780cb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800780c060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800743de40, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa800752e060, DeviceName: \Device\Ide\IdeDeviceP1T0L0-1\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: C99914E6
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 204800
Partition file system is NTFS
Partition is bootable
Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 206848 Numsec = 511793152
Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 512000000 Numsec = 1024000000
Partition 3 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 1536000000 Numsec = 2371026944
Disk Size: 2000398934016 bytes
Sector size: 512 bytes
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa80089f3620, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8008851b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80089f3620, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80087e3b70, DeviceName: \Device\00000076\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: F86F2
Partition information:
Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 2048 Numsec = 2930270208
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 1500299395072 bytes
Sector size: 512 bytes
Scan finished
Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removal finished
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-12-2014
Ran by peeaitcheye (administrator) on PEEAITCHEYE-PC on 29-12-2014 22:02:58
Running from C:\Users\peeaitcheye\Desktop
Loaded Profile: peeaitcheye (Available profiles: peeaitcheye)
Platform: Windows 7 Professional (X64) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Realtek) C:\Program Files (x86)\RNX-N150UBE\11n USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\RNX-N150UBE\11n USB Wireless LAN Utility\RtWLan.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7560296 2011-12-12] (Realtek Semiconductor)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-09-30] (Advanced Micro Devices, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1733408913-109812225-2979640582-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
HKU\S-1-5-21-1733408913-109812225-2979640582-1000\Software\Microsoft\Internet Explorer\Main,Search Page =
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]
FF ProfilePath: C:\Users\peeaitcheye\AppData\Roaming\Mozilla\Firefox\Profiles\183bpjzd.default
FF Plugin-x32: Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32:,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\gcswf32.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll ()
CHR Plugin: (Chrome NaCl) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Google Gears - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\gears.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Profile: C:\Users\peeaitcheye\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\peeaitcheye\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-28]
CHR Extension: (Adblock Plus) - C:\Users\peeaitcheye\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-27]
CHR Extension: (Facebook Customizer (by Adblock Plus)) - C:\Users\peeaitcheye\AppData\Local\Google\Chrome\User Data\Default\Extensions\deoeenbkoccjaefmmhpmlegngdjohdcm [2014-12-27]
CHR Extension: (Chrome AdBlock Plus) - C:\Users\peeaitcheye\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbpbdggplehjfceendelhkobogklpngg [2014-12-27]
CHR Extension: (Google Wallet) - C:\Users\peeaitcheye\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-27]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Realtek11nSU; C:\Program Files (x86)\RNX-N150UBE\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed]
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [111208 2014-12-28] (RaMMicHaeL)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-29] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-29 21:56 - 2014-12-29 22:00 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-12-29 21:54 - 2014-12-29 22:00 - 00000000 ____D () C:\Users\peeaitcheye\Desktop\mbar
2014-12-29 21:53 - 2014-12-29 21:54 - 16448208 _____ (Malwarebytes Corp.) C:\Users\peeaitcheye\Downloads\mbar-
2014-12-28 23:31 - 2014-12-29 22:03 - 00007144 _____ () C:\Users\peeaitcheye\Desktop\FRST.txt
2014-12-28 23:31 - 2014-12-28 23:32 - 00024148 _____ () C:\Users\peeaitcheye\Desktop\Addition.txt
2014-12-28 23:18 - 2014-12-28 23:19 - 04187592 _____ (Kaspersky Lab ZAO) C:\Users\peeaitcheye\Downloads\tdsskiller.exe
2014-12-28 23:11 - 2014-12-29 22:02 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-28 23:11 - 2014-12-29 21:56 - 00096472 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-28 23:11 - 2014-12-28 23:11 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-28 23:11 - 2014-12-28 23:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-28 23:11 - 2014-12-28 23:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-28 23:11 - 2014-12-28 23:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-28 23:11 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-28 23:11 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-28 23:10 - 2014-12-28 23:11 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\peeaitcheye\Downloads\mbam-setup-
2014-12-28 23:05 - 2014-12-28 23:05 - 00008196 _____ () C:\ComboFix.txt
2014-12-28 23:01 - 2014-12-28 23:05 - 00000000 ____D () C:\Qoobox
2014-12-28 23:01 - 2011-06-25 22:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-28 23:01 - 2010-11-07 09:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-28 23:01 - 2009-04-19 20:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-28 23:01 - 2000-08-30 16:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-28 23:01 - 2000-08-30 16:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-28 23:01 - 2000-08-30 16:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-28 23:01 - 2000-08-30 16:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-28 23:01 - 2000-08-30 16:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-28 22:59 - 2014-12-28 23:05 - 00000000 ____D () C:\Windows\erdnt
2014-12-28 22:59 - 2014-12-28 22:59 - 05603624 ____R (Swearware) C:\Users\peeaitcheye\Downloads\ComboFix.exe
2014-12-28 22:54 - 2014-12-28 22:54 - 00012106 _____ () C:\Users\peeaitcheye\Downloads\Addition.txt
2014-12-28 22:53 - 2014-12-29 22:02 - 00000000 ____D () C:\FRST
2014-12-28 22:53 - 2014-12-28 22:54 - 00030070 _____ () C:\Users\peeaitcheye\Downloads\FRST.txt
2014-12-28 22:53 - 2014-12-28 22:53 - 02123264 _____ (Farbar) C:\Users\peeaitcheye\Desktop\FRST64.exe
2014-12-28 22:52 - 2014-12-28 22:52 - 01114624 _____ (Farbar) C:\Users\peeaitcheye\Downloads\FRST.exe
2014-12-28 22:43 - 2014-12-28 22:43 - 00001019 _____ () C:\Users\Public\Desktop\Unchecky.lnk
2014-12-28 22:43 - 2014-12-28 22:43 - 00000000 ____D () C:\ProgramData\Unchecky
2014-12-28 22:43 - 2014-12-28 22:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky
2014-12-28 22:43 - 2014-12-28 22:43 - 00000000 ____D () C:\Program Files (x86)\Unchecky
2014-12-27 22:48 - 2014-12-27 22:48 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Roaming\WinRAR
2014-12-27 16:16 - 2014-11-24 14:04 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-12-27 16:14 - 2014-12-27 16:14 - 01941064 _____ () C:\Users\peeaitcheye\Downloads\winrar-x64-520.exe
2014-12-27 16:14 - 2014-12-27 16:14 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-12-27 16:14 - 2014-12-27 16:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-12-27 16:14 - 2014-12-27 16:14 - 00000000 ____D () C:\Program Files\WinRAR
2014-12-27 16:13 - 2014-12-27 16:13 - 00001794 _____ () C:\Users\Public\Desktop\Vuze.lnk
2014-12-27 16:13 - 2014-12-27 16:13 - 00001794 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk
2014-12-27 16:13 - 2014-12-27 16:13 - 00000064 _____ () C:\Users\peeaitcheye\AppData\Local\092b24a5009100c0c5fc578f330d5f31
2014-12-27 16:13 - 2014-12-27 16:13 - 00000000 ____D () C:\Users\peeaitcheye\.swt
2014-12-27 16:12 - 2014-12-29 01:12 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Roaming\Azureus
2014-12-27 16:12 - 2014-12-27 16:13 - 00000000 ____D () C:\Program Files\Vuze
2014-12-27 16:08 - 2014-12-27 16:09 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Roaming\Mozilla
2014-12-27 16:08 - 2014-12-27 16:09 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Local\Mozilla
2014-12-27 16:08 - 2014-12-27 16:08 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-12-27 16:08 - 2014-12-27 16:08 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-12-27 16:08 - 2014-12-27 16:08 - 00000000 ____D () C:\ProgramData\Mozilla
2014-12-27 16:08 - 2014-12-27 16:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-27 16:08 - 2014-12-27 16:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-27 16:07 - 2014-12-27 16:07 - 00244104 _____ () C:\Users\peeaitcheye\Downloads\Firefox Setup Stub 34.0.5.exe
2014-12-27 16:01 - 2014-12-29 01:12 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Roaming\vlc
2014-12-27 16:00 - 2014-12-27 16:00 - 00001066 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-12-27 16:00 - 2014-12-27 16:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-12-27 16:00 - 2014-12-27 16:00 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-12-27 15:58 - 2014-12-27 15:58 - 00057560 _____ () C:\Users\peeaitcheye\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-27 15:58 - 2014-12-27 15:58 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Roaming\ATI
2014-12-27 15:58 - 2014-12-27 15:58 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Local\ATI
2014-12-27 15:58 - 2014-12-27 15:58 - 00000000 ____D () C:\ProgramData\ATI
2014-12-27 15:58 - 2014-12-27 15:58 - 00000000 _____ () C:\Windows\ativpsrm.bin
2014-12-27 15:57 - 2014-12-27 15:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATI Problem Report Wizard
2014-12-27 15:56 - 2014-12-27 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
2014-12-27 15:56 - 2014-12-27 15:56 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-12-27 15:41 - 2014-12-29 21:46 - 00001154 _____ () C:\Windows\PFRO.log
2014-12-27 15:41 - 2014-12-27 15:41 - 00000000 ____D () C:\Windows\AsusInstAll
2014-12-27 15:40 - 2014-12-29 22:02 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-27 15:40 - 2014-12-29 21:51 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-27 15:40 - 2014-12-27 16:45 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-12-27 15:40 - 2014-12-27 16:45 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-12-27 15:40 - 2014-12-27 16:16 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-27 15:40 - 2014-12-27 16:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-27 15:40 - 2014-12-27 16:03 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Local\Google
2014-12-27 15:40 - 2014-12-27 15:46 - 00047448 _____ () C:\Windows\Ascd_log.ini
2014-12-27 15:40 - 2014-12-27 15:46 - 00000000 ____D () C:\Windows\System32\Tasks\ASUS
2014-12-27 15:40 - 2014-12-27 15:40 - 00000000 ____D () C:\Program Files (x86)\Google
2014-12-27 15:39 - 2014-12-27 15:39 - 00016896 _____ (ASUS) C:\Windows\AsTaskSched.dll
2014-12-27 15:39 - 2014-12-27 15:39 - 00000000 ____D () C:\Windows\Chipset
2014-12-27 15:39 - 2011-02-24 22:36 - 00295296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-12-27 15:38 - 2014-12-27 15:38 - 00034677 _____ () C:\Windows\Ascd_tmp.ini
2014-12-27 15:38 - 2014-12-27 15:38 - 00001769 _____ () C:\Windows\Language_trs.ini
2014-12-27 15:37 - 2014-12-27 15:37 - 00001443 _____ () C:\Users\peeaitcheye\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-27 15:37 - 2014-12-27 15:37 - 00001409 _____ () C:\Users\peeaitcheye\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-12-27 15:37 - 2014-12-27 15:37 - 00000000 ____D () C:\Users\peeaitcheye\AppData\Local\VirtualStore
2014-12-27 15:36 - 2014-12-27 16:13 - 00000000 ____D () C:\Users\peeaitcheye
2014-12-27 15:36 - 2014-12-27 15:36 - 00000020 ___SH () C:\Users\peeaitcheye\ntuser.ini
2014-12-27 15:36 - 2009-07-13 20:54 - 00000000 ___RD () C:\Users\peeaitcheye\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-27 15:36 - 2009-07-13 20:49 - 00000000 ___RD () C:\Users\peeaitcheye\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-12-27 15:35 - 2014-12-27 15:35 - 00000000 ____D () C:\Recovery
2014-12-27 15:23 - 2014-12-27 15:23 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2014-12-27 15:22 - 2014-12-27 15:22 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2014-12-27 15:22 - 2014-12-27 15:22 - 00001313 _____ () C:\Windows\TSSysprep.log
2014-12-27 15:20 - 2014-12-29 22:00 - 00056423 _____ () C:\Windows\WindowsUpdate.log
2014-12-27 15:17 - 2014-12-27 15:36 - 00000000 ____D () C:\Windows\Panther
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-29 22:02 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-29 22:02 - 2009-07-13 20:51 - 00018799 _____ () C:\Windows\setupact.log
2014-12-29 21:55 - 2009-07-13 20:45 - 00010032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-29 21:55 - 2009-07-13 20:45 - 00010032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-29 21:51 - 2009-07-13 21:13 - 00713888 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-28 23:05 - 2009-07-13 21:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-12-28 23:05 - 2009-07-13 19:20 - 00000000 __RHD () C:\Users\Default
2014-12-28 23:04 - 2009-07-13 18:34 - 00000215 _____ () C:\Windows\system.ini
2014-12-28 15:51 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\rescache
2014-12-27 19:39 - 2009-07-13 23:47 - 00000000 ____D () C:\Program Files\Windows Journal
2014-12-27 19:39 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2014-12-27 19:39 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2014-12-27 19:39 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2014-12-27 19:39 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2014-12-27 19:39 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\system32\winrm
2014-12-27 19:39 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\system32\WCN
2014-12-27 19:39 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\system32\slmgr
2014-12-27 19:39 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2014-12-27 19:39 - 2009-07-13 21:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-12-27 19:39 - 2009-07-13 21:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-12-27 19:39 - 2009-07-13 21:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-12-27 19:39 - 2009-07-13 21:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2014-12-27 19:39 - 2009-07-13 21:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2014-12-27 19:39 - 2009-07-13 21:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\SysWOW64\com
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\system32\sysprep
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\system32\oobe
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\system32\MUI
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\system32\migwiz
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\system32\com
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\servicing
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\IME
2014-12-27 19:39 - 2009-07-13 19:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-12-27 19:38 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\SysWOW64\ro-RO
2014-12-27 19:38 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\system32\ro-RO
2014-12-27 19:37 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\SysWOW64\sysprep
2014-12-27 19:37 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup
2014-12-27 19:37 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe
2014-12-27 19:37 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\system32\Setup
2014-12-27 15:39 - 2009-07-13 21:32 - 00000000 ____D () C:\Windows\system32\restore
2014-12-27 15:35 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\system32\Recovery
2014-12-27 15:22 - 2009-07-13 20:46 - 00001774 _____ () C:\Windows\DtcInstall.log
2014-12-27 15:22 - 2009-07-13 19:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-27 15:18 - 2009-07-13 23:46 - 00000000 ____D () C:\Windows\CSC
2014-12-27 15:18 - 2009-07-13 20:45 - 00274320 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-27 15:17 - 2009-07-13 21:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-12-27 15:17 - 2009-07-13 21:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2014-12-27 15:16 - 2009-07-13 20:45 - 00000000 ____D () C:\Windows\Setup
Some content of TEMP:
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-27 17:47
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-12-2014
Ran by peeaitcheye at 2014-12-29 22:03:30
Running from C:\Users\peeaitcheye\Desktop
Boot Mode: Normal
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
ATI AVIVO64 Codecs (Version: - ATI Technologies Inc.) Hidden
ATI Catalyst Install Manager (HKLM\...\{4E594F8A-B042-B61D-DADC-08822B630781}) (Version: 3.0.795.0 - ATI Technologies, Inc.)
ATI Problem Report Wizard (Version: 3.0.795.0 - ATI Technologies) Hidden
ccc-core-static (x32 Version: 2010.0930.2237.38732 - ATI) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: - Google Inc.) Hidden
HydraVision (x32 Version: - ATI Technologies Inc.) Hidden
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: - Intel Corporation)
Malwarebytes Anti-Malware version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation)
Mozilla Firefox 34.0.5 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 en-US)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0142 - REALTEK Semiconductor Corp.)
Unchecky v0.3.5 (HKLM-x32\...\Unchecky) (Version: 0.3.5 - RaMMicHaeL)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Vuze (HKLM\...\8461-7759-5462-8226) (Version: - Azureus Software, Inc.)
WinRAR 5.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
27-12-2014 15:39:09 Windows Update
27-12-2014 15:44:41 Installed Realtek Ethernet Controller Driver
27-12-2014 15:49:00 Installed RNX-N150UBE 11n USB Wireless LAN Driver and Utility
27-12-2014 15:55:31 Device Driver Package Install: ATI Technologies Inc. Display adapters
27-12-2014 16:16:03 Windows Update
27-12-2014 19:36:12 Language Pack Removal
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 18:34 - 2014-12-29 22:02 - 00001993 ____A C:\Windows\system32\Drivers\etc\hosts # fix for traceroute and netstat display anomaly
There are 4 more lines.
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {20888339-8EE2-4ADA-84A8-FC30AAF71E64} - System32\Tasks\ASUS\i-Setup153904 => C:\Windows\Chipset\AsusSetup.exe [2010-09-07] (ASUSTeK Computer Inc.)
Task: {65E61EB1-BA0F-4E21-A358-DD09569ECDE2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-27] (Google Inc.)
Task: {7F4E1D7E-49A3-41C0-A5D5-CE7743E80A1D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-27] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2010-08-04 15:58 - 2010-08-04 15:58 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2010-09-30 22:36 - 2010-09-30 22:36 - 00270336 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-12-27 15:49 - 2009-12-09 21:20 - 00126976 _____ () C:\Program Files (x86)\RNX-N150UBE\11n USB Wireless LAN Utility\EnumDevLib.dll
2014-12-27 16:08 - 2014-11-26 08:40 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-1733408913-109812225-2979640582-500 - Administrator - Disabled)
Guest (S-1-5-21-1733408913-109812225-2979640582-501 - Limited - Disabled)
peeaitcheye (S-1-5-21-1733408913-109812225-2979640582-1000 - Administrator - Enabled) => C:\Users\peeaitcheye
==================== Faulty Device Manager Devices =============
Name: PCI Simple Communications Controller
Description: PCI Simple Communications Controller
Class Guid:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
Error: (12/27/2014 10:14:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: tasks.exe, version:, time stamp: 0x54997c8f
Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385, time stamp: 0x4a5bdbdf
Exception code: 0xe0434f4d
Fault offset: 0x0000b727
Faulting process id: 0x%9
Faulting application start time: 0xtasks.exe0
Faulting application path: tasks.exe1
Faulting module path: tasks.exe2
Report Id: tasks.exe3
Error: (12/27/2014 03:18:42 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: )
Description: The Cryptographic Services service failed to initialize the Catalog Database. The ESENT error was: -546.
Error: (12/27/2014 03:18:42 PM) (Source: ESENT) (EventID: 412) (User: )
Description: Catalog Database (520) Catalog Database: Unable to read the header of logfile C:\Windows\system32\CatRoot2\edb.log. Error -546.
Error: (12/27/2014 03:18:42 PM) (Source: ESENT) (EventID: 412) (User: )
Description: Catalog Database (520) Catalog Database: Unable to read the header of logfile C:\Windows\system32\CatRoot2\edb.log. Error -546.
System errors:
Error: (12/29/2014 09:59:33 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/29/2014 09:59:20 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/29/2014 09:59:18 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/29/2014 09:59:15 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/29/2014 09:50:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error:
Error: (12/29/2014 09:50:28 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
Error: (12/29/2014 09:49:34 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.
Error: (12/29/2014 09:48:56 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.
Error: (12/29/2014 00:25:57 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/29/2014 00:25:54 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Microsoft Office Sessions:
Error: (12/27/2014 10:14:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: tasks.exe1.0.0.054997c8fKERNELBASE.dll6.1.7600.163854a5bdbdfe0434f4d0000b727
Error: (12/27/2014 03:18:42 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: )
Description: -546
Error: (12/27/2014 03:18:42 PM) (Source: ESENT) (EventID: 412) (User: )
Description: Catalog Database520Catalog Database: C:\Windows\system32\CatRoot2\edb.log-546
Error: (12/27/2014 03:18:42 PM) (Source: ESENT) (EventID: 412) (User: )
Description: Catalog Database520Catalog Database: C:\Windows\system32\CatRoot2\edb.log-546
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz
Percentage of memory in use: 20%
Total physical RAM: 8145.97 MB
Available physical RAM: 6515.82 MB
Total Pagefile: 16290.09 MB
Available Pagefile: 14337.58 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:244.04 GB) (Free:217.61 GB) NTFS
Drive d: () (Fixed) (Total:488.28 GB) (Free:488.18 GB) NTFS
Drive e: () (Fixed) (Total:1130.59 GB) (Free:1110.44 GB) NTFS
Drive g: (Elements) (Fixed) (Total:1397.26 GB) (Free:425.25 GB) NTFS
==================== MBR & Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: C99914E6)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=244 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=488.3 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1130.6 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows XP) (Size: 1397.3 GB) (Disk ID: 000F86F2)
Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=07 NTFS)
==================== End Of Log ============================