Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-07-2016 02
Ran by SYSTEM on MININT-550N0V5 (23-07-2016 18:01:56)
Running from L:\
Platform: Windows (TM) Code Name "Longhorn" Preinstallation Environment Service Pack 1 (X64) Language: English (United States)
Boot Mode: Recovery
Default: ControlSet001
[B]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/B]
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Winlogon: [Userinit] [X]
HKLM\...\Winlogon: [Shell] cmd.exe /k start cmd.exe [ ] () <=== ATTENTION
HKLM-x32\...\Winlogon: [Shell] [0 ] () <=== ATTENTION
BootExecute:
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 sacsvr; C:\Windows\system32\sacsvr.dll [14848 2008-01-19] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S0 FBWF; C:\Windows\System32\DRIVERS\fbwf.sys [97792 2008-01-18] (Microsoft Corporation)
S0 Ramdisk; C:\Windows\System32\DRIVERS\ramdisk.sys [27648 2008-01-18] (Microsoft Corporation)
S0 sacdrv; C:\Windows\System32\DRIVERS\sacdrv.sys [103992 2008-01-19] (Microsoft Corporation)
S0 WimFsf; C:\Windows\System32\Drivers\WimFsf.sys [61952 2008-01-18] (Microsoft Corporation)
S3 BTHMODEM; \SystemRoot\system32\drivers\bthmodem.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
NETSVC: sacsvr -> C:\Windows\system32\sacsvr.dll (Microsoft Corporation)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-23 18:01 - 2016-07-23 18:01 - 00000000 ____D C:\FRST
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
==================== Known DLLs (Whitelisted) =========================
C:\Windows\SysWOW64\advapi32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\COMDLG32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\gdi32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\IERTUTIL.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\IMAGEHLP.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\IMM32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\kernel32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\LPK.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\MSCTF.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\MSVCRT.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\NORMALIZ.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\NSI.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\OLEAUT32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\rpcrt4.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\Setupapi.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\SHELL32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\SHLWAPI.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\URLMON.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\user32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\USP10.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\WININET.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\WLDAP32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\WS2_32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\ole32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\clbcatq.dll IS MISSING <==== ATTENTION
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION
C:\Windows\explorer.exe IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\explorer.exe IS MISSING <==== ATTENTION
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe IS MISSING <==== ATTENTION
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll IS MISSING <==== ATTENTION
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe IS MISSING <==== ATTENTION
C:\Windows\System32\rpcss.dll
[2008-01-18 22:27] - [2008-01-19 00:03] - 0713728 ____A (Microsoft Corporation) FF27BE0BA7B3C48D5C99AFCB56D436C2
C:\Windows\System32\dnsapi.dll
[2008-01-18 22:20] - [2008-01-19 00:01] - 0219648 ____A (Microsoft Corporation) 9ACAE1719BFF56C8B570E3879EAA34CD
C:\Windows\SysWOW64\dnsapi.dll IS MISSING <==== ATTENTION
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
C:\Windows\System32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION
==================== Association (Whitelisted) =============
==================== Restore Points =========================
Restore point date: 2014-11-21 15:10
Restore point date: 2014-11-22 21:00
Restore point date: 2014-11-26 20:32
Restore point date: 2014-11-28 14:46
Restore point date: 2014-11-29 21:00
Restore point date: 2014-11-30 17:14
Restore point date: 2014-12-02 19:06
Restore point date: 2014-12-03 15:31
Restore point date: 2014-12-04 15:55
Restore point date: 2014-12-05 15:48
Restore point date: 2014-12-06 05:12
Restore point date: 2014-12-06 23:59
Restore point date: 2014-12-08 00:10
Restore point date: 2014-12-08 17:00
Restore point date: 2014-12-09 18:50
Restore point date: 2014-12-11 19:33
Restore point date: 2014-12-13 22:13
Restore point date: 2014-12-14 00:00
Restore point date: 2014-12-17 15:09
Restore point date: 2014-12-18 15:01
Restore point date: 2014-12-18 15:01
==================== Memory info ===========================
Percentage of memory in use: 10%
Total physical RAM: 6143.18 MB
Available physical RAM: 5503.91 MB
Total Virtual: 6141.38 MB
Available Virtual: 5490.43 MB
==================== Drives ================================
Drive c: (RECOVERY) (Fixed) (Total:15 GB) (Free:7.1 GB) NTFS
Drive d: (WD HD) (Fixed) (Total:931.51 GB) (Free:647.01 GB) NTFS
Drive f: (OS) (Fixed) (Total:683.57 GB) (Free:193.66 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive g: (GSP1RMCHPXFRER_EN_DVD) (CDROM) (Total:3.09 GB) (Free:0 GB) UDF
Drive l: () (Removable) (Total:0.96 GB) (Free:0.24 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: () (Fixed) (Total:0.07 GB) (Free:0.05 GB) FAT ==>[system with boot components (obtained from drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: B0000000)
Partition 1: (Active) - (Size=71 MB) - (Type=06)
Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=683.6 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 97A8E77D)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
========================================================
Disk: 6 (Size: 984 MB) (Disk ID: 91F72D24)
Partition 1: (Active) - (Size=984 MB) - (Type=06)
==================== End of FRST.txt ============================