Solved Windows 7 desktop suddenly not booting.

Status
Not open for further replies.

Irule88

New Member
Thread author
Apr 13, 2013
2
I followed this thread (http://malwaretips.com/Thread-How-to-fix-no-bootable-device-%E2%80%93-insert-boot-disk-and-press-any-key)

and the first thing didnt work, so I did the second thing. It says to post in this forum, so here I am. Yesterday it was working fine, shut it off when I went to sleep. This morning, turned it on and it told me "insert boot disk and press any key" No idea why.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-04-2013
Ran by SYSTEM at 13-04-2013 15:02:57
Running from H:\
Windows 7 Ultimate (X86) OS Language: English(US)
The current controlset is ControlSet001

ATTENTION!:=====> THE OPERATING SYSTEM IS A X64 SYSTEM BUT THE BOOT DISK THAT IS USED TO BOOT TO RECOVERY ENVIRONMENT IS A X86 SYSTEM DISK.
==================== Registry (Whitelisted) ===================

HKLM\...\Run: [RtHDVCpl] c:\program files\realtek\audio\hda\ravcpl64.exe -s [10081312 2010-02-25] (Realtek Semiconductor)
HKLM\...\Run: [rfagent] "C:\Program Files\RFA 8\rfagent64.exe" [3267736 2012-10-12] (KsL Software)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [477600 2013-01-24] (Adobe Systems Incorporated)
HKU\Har\...\Run: [F.lux] "C:\Users\Har\Local Settings\Apps\F.lux\flux.exe" /noshow [966656 2009-08-28] ()
HKU\Har\...\Run: [WeatherEye] C:\Users\Har\AppData\Local\TheWeatherNetwork\WeatherEye\WeatherEye.exe [310920 2012-08-30] (Pelmorex Media Inc.)
HKU\Har\...\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload [1509232 2013-02-13] (Samsung)
HKU\Har\...\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844144 2013-02-13] (Samsung)
HKU\Har\...\Run: [C:\Users\Har\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesAirMessage.exe -startup] C:\Users\Har\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesAirMessage.exe -startup [578560 2013-02-05] (Samsung Electronics)
HKU\Har\...\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart [19357112 2013-03-07] (Google)
HKU\Har\...\Run: [DesktopCal] C:\Program Files (x86)\DesktopCal\desktopcal.exe [935424 2011-08-04] (DesktopCal, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{47BC48D7-2554-4D5C-8517-29B6A57740BC}: [NameServer]8.8.8.8,8.8.4.4

==================== Services (Whitelisted) ===================

3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [253656 2013-03-12] (Adobe Systems Incorporated)
2 Apple Mobile Device; "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" [55184 2012-05-24] (Apple Inc.)
3 aspnet_state; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [44376 2010-03-18] (Microsoft Corporation)
2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [44808 2012-10-30] (AVAST Software)
2 BCUService; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [223464 2009-10-15] (DeviceVM, Inc.)
4 clr_optimization_v2.0.50727_64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [89920 2009-06-10] (Microsoft Corporation)
2 clr_optimization_v4.0.30319_64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [138576 2010-03-18] (Microsoft Corporation)
2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION)
2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE [163840 2007-12-16] (SEIKO EPSON CORPORATION)
2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [126464 2007-01-10] (SEIKO EPSON CORPORATION)
3 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-04] (Microsoft Corporation)
2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [350208 2010-11-20] (Microsoft Corporation)
2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [136176 2012-04-05] (Google Inc.)
3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [136176 2012-04-05] (Google Inc.)
3 gusvc; "C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe" [182768 2011-09-09] (Google)
3 idsvc; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe" [856400 2010-11-04] (Microsoft Corporation)
3 Microsoft Office Groove Audit Service; "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe" [65824 2006-10-26] (Microsoft Corporation)
2 NAUpdate; "C:\Program Files (x86)\Nero\Update\NASvc.exe" [490280 2010-03-25] (Nero AG)
4 NetMsmqActivator; "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator [124240 2010-03-18] (Microsoft Corporation)
4 NetPipeActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
4 NetTcpActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
3 odserv; "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE" [441136 2006-10-26] (Microsoft Corporation)
3 ose; "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE" [145184 2006-10-26] (Microsoft Corporation)
3 PerfHost; C:\Windows\SysWow64\perfhost.exe [20992 2009-07-13] (Microsoft Corporation)
2 ServicepointService; "C:\Program Files (x86)\Bell\Internet Service Advisor\ServicepointService.exe" [689464 2011-01-06] (Radialpoint Inc.)
3 Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService [543656 2013-03-29] (Valve Corporation)
3 SwitchBoard; "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [517096 2010-02-19] (Adobe Systems Incorporated)

==================== Drivers (Whitelisted) ====================

2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [25232 2012-10-30] (AVAST Software)
2 aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [71600 2012-10-30] (AVAST Software)
1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [54072 2012-10-15] (AVAST Software)
1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [984144 2012-10-30] (AVAST Software)
1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [370288 2012-10-30] (AVAST Software)
1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [59728 2012-10-30] (AVAST Software)
3 b06bdrv; C:\Windows\system32\DRIVERS\bxvbda.sys [468480 2009-06-10] (Broadcom Corporation)
3 b57nd60a; C:\Windows\System32\DRIVERS\b57nd60a.sys [270848 2009-06-10] (Broadcom Corporation)
2 cpuz135; \??\C:\Windows\system32\drivers\cpuz135_x64.sys [21992 2011-09-21] (CPUID)
3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-11-07] (DT Soft Ltd)
3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
3 FsUsbExDisk; \??\C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
3 gdrv; \??\C:\Windows\gdrv.sys [25640 2011-11-08] (Windows (R) Server 2003 DDK provider)
3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [10629184 2011-10-13] (Intel Corporation)
3 IntcAzAudAddService; C:\Windows\System32\drivers\RTKVHD64.sys [2276128 2010-02-25] (Realtek Semiconductor Corp.)
3 ksthunk; C:\Windows\system32\drivers\ksthunk.sys [20992 2009-07-13] (Microsoft Corporation)
3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [108656 2011-09-19] (Atheros Communications, Inc.)
3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [52320 2013-03-10] (http://libusb-win32.sourceforge.net)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()
0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [55280 2009-07-09] (Sonic Solutions)
3 RTL8167; C:\Windows\System32\DRIVERS\Rt64win7.sys [325664 2010-02-08] (Realtek )
1 SCDEmu; C:\Windows\System32\Drivers\SCDEmu.sys [126912 2012-04-18] (Power Software Ltd)
3 Ser2pl; C:\Windows\System32\DRIVERS\ser2pl64.sys [158720 2012-07-30] (Prolific Technology Inc.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2012-11-07] (Duplex Secure Ltd.)
3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [52736 2012-04-25] (Apple, Inc.)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-04-13 15:02 - 2013-04-13 15:02 - 00000000 ____D C:\FRST
2013-04-11 11:27 - 2013-04-11 11:27 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-04-10 13:33 - 2013-04-10 19:45 - 00011043 ____A C:\Users\Har\Documents\TASK SCHADUAL.xlsx
2013-04-10 13:13 - 2013-04-10 13:13 - 00001031 ____A C:\Users\Har\Desktop\Desktop Calendar.lnk
2013-04-10 13:13 - 2013-04-10 13:13 - 00000000 ____D C:\Users\Har\AppData\Roaming\DesktopCal
2013-04-10 13:13 - 2013-04-10 13:13 - 00000000 ____D C:\Program Files (x86)\DesktopCal
2013-04-10 13:12 - 2013-04-10 13:12 - 02153942 ____A C:\Users\Har\Desktop\desktopcal-setup.zip
2013-04-10 13:11 - 2013-04-10 13:11 - 00392520 ____A (Softonic ) C:\Users\Har\Downloads\SoftonicDownloader_for_deltacalendar.exe
2013-04-10 08:27 - 2013-04-10 12:08 - 00000000 ____D C:\Users\Har\Documents\ALL ELSE
2013-04-02 11:20 - 2013-04-02 11:20 - 00001957 ____A C:\Users\Har\Desktop\Medical Tests Analyzer.lnk
2013-04-02 11:20 - 2013-04-02 11:20 - 00000000 ____D C:\Program Files (x86)\SmrtX
2013-04-02 11:19 - 2013-04-02 11:19 - 05203224 ____A C:\Users\Har\Downloads\MTA.exe
2013-03-26 12:27 - 2013-04-11 15:27 - 00000000 ____D C:\Users\Har\Desktop\New Songs
2013-03-25 12:39 - 2013-03-25 12:39 - 04546560 ____A (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2013-03-23 15:20 - 2013-03-23 15:20 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-03-23 11:44 - 2013-04-01 09:13 - 00000000 ____D C:\Users\Har\Documents\Worth Reading
2013-03-21 12:46 - 2013-04-09 17:13 - 00000000 ____D C:\Users\Har\Documents\H&K BASRA
2013-03-21 11:37 - 2013-04-11 13:14 - 00000000 ____D C:\Users\Har\Documents\Mother-Surjit Kaur
2013-03-21 11:37 - 2013-04-10 08:35 - 00000000 ____D C:\Users\Har\Documents\SAP
2013-03-21 09:28 - 2013-03-21 09:28 - 00000000 ____D C:\Users\Default\AppData\LocalGoogle
2013-03-21 09:28 - 2013-03-21 09:28 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2013-03-21 09:28 - 2013-03-21 09:28 - 00000000 ____D C:\Users\Default User\AppData\LocalGoogle
2013-03-21 09:28 - 2013-03-21 09:28 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2013-03-20 11:03 - 2013-04-09 17:20 - 00000000 ____D C:\Users\Har\Documents\BANKING

==================== One Month Modified Files and Folders ========

2013-04-12 22:01 - 2011-09-09 08:31 - 01067360 ____A C:\Windows\WindowsUpdate.log
2013-04-12 22:00 - 2011-12-10 15:08 - 00000000 ____D C:\Users\Har\AppData\Local\Adobe
2013-04-12 21:27 - 2012-04-05 09:58 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-04-12 21:04 - 2012-08-11 20:56 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-04-12 17:39 - 2012-03-01 17:44 - 00000000 ____D C:\Users\Har\AppData\Roaming\uTorrent
2013-04-12 17:21 - 2011-11-19 21:50 - 00000000 ____D C:\Users\Har\AppData\Roaming\vlc
2013-04-12 14:51 - 2011-09-09 08:50 - 00000000 ____D C:\Users\Har\AppData\Local\VirtualStore
2013-04-12 14:49 - 2012-11-13 11:32 - 00037542 ____A C:\Windows\setupact.log
2013-04-12 14:49 - 2012-04-05 09:58 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-04-12 14:49 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-04-12 14:01 - 2013-01-24 14:24 - 00000000 ____D C:\Users\Har\Documents\WEDDING
2013-04-11 19:07 - 2012-04-19 10:44 - 00000000 ____D C:\ProgramData\RFA_Backups
2013-04-11 15:27 - 2013-03-26 12:27 - 00000000 ____D C:\Users\Har\Desktop\New Songs
2013-04-11 13:14 - 2013-03-21 11:37 - 00000000 ____D C:\Users\Har\Documents\Mother-Surjit Kaur
2013-04-11 13:06 - 2011-11-19 22:34 - 00000000 ____D C:\Users\Har\Documents\VOIP
2013-04-11 11:27 - 2013-04-11 11:27 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-04-10 19:45 - 2013-04-10 13:33 - 00011043 ____A C:\Users\Har\Documents\TASK SCHADUAL.xlsx
2013-04-10 16:08 - 2012-03-09 13:30 - 00000032 ____A C:\Users\Har\jagex_cl_runescape_LIVE.dat
2013-04-10 13:13 - 2013-04-10 13:13 - 00001031 ____A C:\Users\Har\Desktop\Desktop Calendar.lnk
2013-04-10 13:13 - 2013-04-10 13:13 - 00000000 ____D C:\Users\Har\AppData\Roaming\DesktopCal
2013-04-10 13:13 - 2013-04-10 13:13 - 00000000 ____D C:\Program Files (x86)\DesktopCal
2013-04-10 13:13 - 2009-07-13 19:20 - 00000000 ___RD C:\Program Files (x86)
2013-04-10 13:12 - 2013-04-10 13:12 - 02153942 ____A C:\Users\Har\Desktop\desktopcal-setup.zip
2013-04-10 13:12 - 2009-07-13 19:20 - 00000000 ___RD C:\users\Public
2013-04-10 13:11 - 2013-04-10 13:11 - 00392520 ____A (Softonic ) C:\Users\Har\Downloads\SoftonicDownloader_for_deltacalendar.exe
2013-04-10 12:08 - 2013-04-10 08:27 - 00000000 ____D C:\Users\Har\Documents\ALL ELSE
2013-04-10 08:35 - 2013-03-21 11:37 - 00000000 ____D C:\Users\Har\Documents\SAP
2013-04-10 08:28 - 2012-01-19 16:38 - 00000000 ____D C:\Users\Har\Documents\HEALTH
2013-04-09 17:20 - 2013-03-20 11:03 - 00000000 ____D C:\Users\Har\Documents\BANKING
2013-04-09 17:16 - 2013-02-15 07:04 - 00000000 ____D C:\Program Files (x86)\VirtualDJ
2013-04-09 17:15 - 2012-08-24 11:34 - 00000000 ____D C:\Users\Har\Documents\IMP. Papers
2013-04-09 17:15 - 2011-12-23 09:06 - 00000000 ____D C:\Users\Har\Documents\FTA
2013-04-09 17:13 - 2013-03-21 12:46 - 00000000 ____D C:\Users\Har\Documents\H&K BASRA
2013-04-07 10:44 - 2011-09-09 10:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-04-06 17:57 - 2012-02-22 11:46 - 00000000 ____D C:\Users\Har\Desktop\OTHER PGMs
2013-04-05 10:57 - 2012-01-07 09:39 - 00000000 ____D C:\Users\Har\Documents\JASDEEP's
2013-04-03 12:57 - 2012-03-23 13:19 - 00000000 ____D C:\ProgramData\Radialpoint
2013-04-02 19:31 - 2009-07-13 20:45 - 00014224 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-04-02 19:31 - 2009-07-13 20:45 - 00014224 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-04-02 11:20 - 2013-04-02 11:20 - 00001957 ____A C:\Users\Har\Desktop\Medical Tests Analyzer.lnk
2013-04-02 11:20 - 2013-04-02 11:20 - 00000000 ____D C:\Program Files (x86)\SmrtX
2013-04-02 11:19 - 2013-04-02 11:19 - 05203224 ____A C:\Users\Har\Downloads\MTA.exe
2013-04-02 08:13 - 2011-09-09 14:12 - 00000000 ____D C:\Users\Har\AppData\Local\Microsoft Help
2013-04-01 16:21 - 2013-02-22 13:12 - 00000000 ____D C:\Users\Har\Desktop\DANCE SONGS
2013-04-01 14:48 - 2011-09-24 14:06 - 00000000 ____D C:\Users\Har\Documents\Navdev
2013-04-01 09:13 - 2013-03-23 11:44 - 00000000 ____D C:\Users\Har\Documents\Worth Reading
2013-03-25 12:39 - 2013-03-25 12:39 - 04546560 ____A (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2013-03-24 18:30 - 2009-07-13 21:13 - 00863568 ____A C:\Windows\System32\PerfStringBackup.INI
2013-03-23 19:28 - 2012-11-07 14:16 - 00000000 ____D C:\Users\Har\Documents\Adobe
2013-03-23 19:04 - 2011-12-10 15:18 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-03-23 15:20 - 2013-03-23 15:20 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-03-22 15:01 - 2013-02-27 11:42 - 00000000 ____D C:\Users\Har\Documents\Surinder jagpal
2013-03-21 15:07 - 2011-09-09 14:43 - 00000000 ____D C:\Program Files (x86)\epson
2013-03-21 14:59 - 2012-08-24 21:00 - 00000000 ____D C:\Users\Har\Desktop\Satellite stuff
2013-03-21 14:33 - 2011-11-17 19:12 - 00000000 ____D C:\Users\Har\Documents\SUNDEV
2013-03-21 09:28 - 2013-03-21 09:28 - 00000000 ____D C:\Users\Default\AppData\LocalGoogle
2013-03-21 09:28 - 2013-03-21 09:28 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2013-03-21 09:28 - 2013-03-21 09:28 - 00000000 ____D C:\Users\Default User\AppData\LocalGoogle
2013-03-21 09:28 - 2013-03-21 09:28 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2013-03-16 21:38 - 2013-03-07 18:06 - 00000132 ____A C:\Users\Har\AppData\Roaming\Adobe PNG Format CS5 Prefs
2013-03-16 12:24 - 2012-04-05 21:38 - 00001456 ____A C:\Users\Har\AppData\Local\Adobe Save for Web 12.0 Prefs


==================== Known DLLs (Whitelisted) =================


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2011-09-10 11:12] - [2011-02-24 22:19] - 2871808 ____A (Microsoft Corporation) 332FEAB1435662FC6C672E25BEB37BE3

C:\Windows\System32\winlogon.exe
[2011-09-11 04:47] - [2010-11-20 05:25] - 0390656 ____A (Microsoft Corporation) 1151B1BAA6F350B1DB6598E0FEA7C457

C:\Windows\System32\wininit.exe
[2009-07-13 15:52] - [2009-07-13 17:39] - 0129024 ____A (Microsoft Corporation) 94355C28C1970635A31B3FE52EB7CEBA

C:\Windows\System32\svchost.exe
[2009-07-13 15:31] - [2009-07-13 17:39] - 0027136 ____A (Microsoft Corporation) C78655BC80301D76ED4FEF1C1EA40A7D

C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

C:\Windows\System32\User32.dll
[2011-09-11 04:47] - [2011-09-15 03:43] - 1008640 ____A (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79

C:\Windows\System32\userinit.exe
[2011-09-11 07:46] - [2010-11-20 05:25] - 0030720 ____A (Microsoft Corporation) BAFE84E637BF7388C96EF48D4D3FDD53

C:\Windows\System32\Drivers\volsnap.sys
[2011-09-11 04:47] - [2010-11-20 05:34] - 0295808 ____A (Microsoft Corporation) 0D08D2F3B3FF84E433346669B5E0F639


==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2013-04-04 09:32:48
Restore point made on: 2013-04-04 15:13:38
Restore point made on: 2013-04-06 18:55:36
Restore point made on: 2013-04-07 10:44:36
Restore point made on: 2013-04-11 18:59:08

==================== Memory info ===========================

Percentage of memory in use: 13%
Total physical RAM: 4061.12 MB
Available physical RAM: 3519 MB
Total Pagefile: 4059.39 MB
Available Pagefile: 3530.57 MB
Total Virtual: 2047.88 MB
Available Virtual: 1950.3 MB

==================== Partitions =============================

1 Drive c: () (Fixed) (Total:104.18 GB) (Free:21.75 GB) NTFS
2 Drive e: (New Volume) (Fixed) (Total:361.48 GB) (Free:92.96 GB) NTFS
3 Drive f: (CD_ROM) (CDROM) (Total:3.48 GB) (Free:0 GB) CDFS
5 Drive h: (CENTON USB) (Removable) (Total:15.22 GB) (Free:13.91 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.03 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 465 GB
Disk 1 Online 465 GB 1024 KB
Disk 2 No Media 0 B 0 B
Disk 3 Online 15 GB 0 B

Partitions of Disk 0:
===============

Disk ID: DB654B10

There are no partitions on this disk to show.

=========================================================

Partitions of Disk 1:
===============

Disk ID: 2EE3A623

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 104 GB 101 MB
Partition 3 Primary 361 GB 104 GB

=========================================================

Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy

=========================================================

Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 104 GB Healthy

=========================================================

Disk: 1
Partition 3
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E New Volume NTFS Partition 361 GB Healthy

=========================================================

Partitions of Disk 3:
===============

Disk ID: C3072E18

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 808 KB
Partition 1 Primary 15 GB 808 KB

=========================================================

Disk: 3
Partition 1
Type : 0C
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H CENTON USB FAT32 Removable 15 GB Healthy

=========================================================

Disk: 3
Partition 1
Type : 0C
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H CENTON USB FAT32 Removable 15 GB Healthy

=========================================================
============================== MBR Partition Table ==================

==============================
Partitions of Disk 0:
===============
Disk ID: DB654B10

==============================
Partitions of Disk 1:
===============
Disk ID: 2EE3A623

Partition 1:
=========
Hex: 8020210007DF130C0008000000200300
Active: YES
Type: 07 (NTFS)
Size: 100 MB

Partition 2:
=========
Hex: 00DF140C07FEFFFF0028030000C0050D
Active: NO
Type: 07 (NTFS)
Size: 104 GB

Partition 3:
=========
Hex: 00EFFFFF07EFFFFF00E8080D00682F2D
Active: NO
Type: 07 (NTFS)
Size: 361 GB

==============================
Partitions of Disk 3:
===============
Disk ID: C3072E18

Partition 1:
=========
Hex: 800101000CFFF3DE50060000B079E701
Active: YES
Type: 0C
Size: 15 GB


Last Boot: 2013-04-04 09:25

==================== End Of Log ============================

and

ListParts by Farbar Version: 10-03-2013
Ran by SYSTEM (administrator) on 13-04-2013 at 15:10:11
Windows 7 (X86)
Running From: H:\
Language: 0409
************************************************************

========================= Memory info ======================

Percentage of memory in use: 11%
Total physical RAM: 4061.12 MB
Available physical RAM: 3614.24 MB
Total Pagefile: 4059.39 MB
Available Pagefile: 3620.71 MB
Total Virtual: 2047.88 MB
Available Virtual: 1967.54 MB

======================= Partitions =========================

1 Drive c: () (Fixed) (Total:104.18 GB) (Free:21.75 GB) NTFS
2 Drive e: (New Volume) (Fixed) (Total:361.48 GB) (Free:92.96 GB) NTFS
3 Drive f: (CD_ROM) (CDROM) (Total:3.48 GB) (Free:0 GB) CDFS
5 Drive h: (CENTON USB) (Removable) (Total:15.22 GB) (Free:13.91 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.03 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 465 GB
Disk 1 Online 465 GB 1024 KB
Disk 2 No Media 0 B 0 B
Disk 3 Online 15 GB 0 B

Partitions of Disk 0:
===============

Disk ID: DB654B10

There are no partitions on this disk to show.

======================================================================================================

Partitions of Disk 1:
===============

Disk ID: 2EE3A623

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 104 GB 101 MB
Partition 3 Primary 361 GB 104 GB

======================================================================================================

Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy

======================================================================================================

Disk: 1
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 104 GB Healthy

======================================================================================================

Disk: 1
Partition 3
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E New Volume NTFS Partition 361 GB Healthy

======================================================================================================

Partitions of Disk 3:
===============

Disk ID: C3072E18

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 808 KB

======================================================================================================

Disk: 3
Partition 1
Type : 0C
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H CENTON USB FAT32 Removable 15 GB Healthy

======================================================================================================
============================== MBR Partition Table ==================

==============================
Partitions of Disk 0:
===============
Disk ID: DB654B10

==============================
Partitions of Disk 1:
===============
Disk ID: 2EE3A623

Partition 1:
===========
Hex: 8020210007DF130C0008000000200300
Active: YES
Type: 07 (NTFS)
Size: 100 MB

Partition 2:
===========
Hex: 00DF140C07FEFFFF0028030000C0050D
Active: NO
Type: 07 (NTFS)
Size: 104 GB

Partition 3:
===========
Hex: 00EFFFFF07EFFFFF00E8080D00682F2D
Active: NO
Type: 07 (NTFS)
Size: 361 GB

==============================
Partitions of Disk 3:
===============
Disk ID: C3072E18

Partition 1:
===========
Hex: 800101000CFFF3DE50060000B079E701
Active: YES
Type: 0C
Size: 15 GB

The boot configuration data store could not be opened.
The requested system device cannot be found.


****** End Of Log ******
 

Attachments

  • Result.txt
    4.8 KB · Views: 436
  • FRST.txt
    22.3 KB · Views: 447
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top