Additional scan result of Farbar Recovery Scan Tool (x64) Version:24-08-2015 Ran by ANURAG (2015-08-25 12:12:59) Running from C:\Users\ANURAG\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-4184292201-4268983070-717191494-500 - Administrator - Disabled) ANURAG (S-1-5-21-4184292201-4268983070-717191494-1001 - Administrator - Enabled) => C:\Users\ANURAG Guest (S-1-5-21-4184292201-4268983070-717191494-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-4184292201-4268983070-717191494-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-4184292201-4268983070-717191494-1001\...\uTorrent) (Version: 3.4.3.40760 - BitTorrent Inc.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.12) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.3.2225 - AVAST Software) Brackets (HKLM-x32\...\{D20AE926-9B7C-45F2-9201-B161CD30350D}) (Version: 1.4 - brackets.io) CPUID CPU-Z 1.72.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Google Chrome (HKU\S-1-5-21-4184292201-4268983070-717191494-1001\...\Google Chrome) (Version: 40.0.2214.93 - Google Inc.) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation) KMSpico v9.3.1 (HKLM\...\KMSpico_is1) (Version: 9.3.1 - ) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4420.1017 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 39.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 39.0.3 (x86 en-US)) (Version: 39.0.3 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 39.0.3 - Mozilla) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.4 - Notepad++ Team) Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-4184292201-4268983070-717191494-1001_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\ANURAG\AppData\Local\Google\Chrome\Application\40.0.2214.93\delegate_execute.exe (Google Inc.) ==================== Restore Points ========================= 24-08-2015 22:19:00 avast! antivirus system restore point ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 08:04 - 2009-06-11 02:30 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {16BAF928-FB00-4A88-BE7D-07064A5F5997} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {173E5175-B093-4AA4-BD4C-C90525E8B509} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {58562DFE-DAAF-4E6F-AEAB-DB6A31660A9A} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2014-06-29] (@ByELDI) Task: {AB69BB8C-84D0-444A-A34A-68E5B0F9D751} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-08-24] (AVAST Software) Task: {B2DB0FA8-62D7-47A8-B0DE-8E8578E41F48} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation) Task: {F45FEFCD-8345-4E9D-84FF-FDCCAF3D9C30} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {FE70BE06-62D5-49EE-B3BF-B699E5FE93C3} - System32\Tasks\Microsoft Office 15 Sync Maintenance for ANURAG-PC-ANURAG ANURAG-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2012-10-01] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2012-10-01 20:36 - 2012-10-01 20:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2015-08-24 23:36 - 2015-08-24 23:36 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-08-24 23:36 - 2015-08-24 23:36 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-08-24 23:36 - 2015-08-24 23:36 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4184292201-4268983070-717191494-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ANURAG\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{D4B8FF45-5108-4A4C-9E2E-C245B7DB5D0E}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{697BE822-1198-4C00-83D7-C93BDD17CB16}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{099D91BB-FA5A-4807-8758-D13F70F3E790}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{1F786BA3-C083-4BE4-ABB2-21A48443224E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{A0238D4E-4269-4622-998A-5E97D411A502}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{0C351412-C598-4AC8-8EFA-72D437D55BC2}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{557E46EF-88AE-4932-9A58-46836B5EC9D4}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{0F724256-9B73-4BFA-8B58-3CEB77FFF8E7}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{B289FF16-5C00-4B07-93FF-7963178B1DE3}] => (Allow) C:\Users\ANURAG\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{6B15CC1D-D5E4-44EE-83F6-0B607568E2EE}] => (Allow) C:\Users\ANURAG\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{BC92B24B-9F50-416D-BD3E-8FEFA62C96F0}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{94304AF4-BEC6-4CC1-9E7F-1BFF6054F919}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{2648D908-87B8-4CD9-A2F8-924A4FA4168B}] => (Allow) LPort=1688 FirewallRules: [{E45D8034-229D-4D1B-A945-40D8EC3ED30D}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{D7A36140-B3A3-46A4-AB7B-02CAB5809D74}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{43FEE0DA-CA2B-4ABA-BF7A-CDB40987DB68}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{9E4A11E3-D3FB-485E-8A61-E792854A5970}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{38737A1D-B922-4106-8123-24B06766D3B2}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe FirewallRules: [UDP Query User{F55DD23F-8C75-43F7-ADDB-CF784E5682E8}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/25/2015 11:31:01 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2015 11:29:37 AM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: ) Description: Failed to schedule Software Protection service for re-start at 2015-09-23T17:34:37Z. Error Code: 0x80041321. Error: (08/24/2015 11:10:25 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: ) Description: Failed to schedule Software Protection service for re-start at 2015-09-23T17:34:25Z. Error Code: 0x80041321. Error: (08/24/2015 11:04:53 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: AutoPico.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.IO.IOException Stack: at System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult) at AutoPico.KMSEmulator.TCPServer.ReadCallback(System.IAsyncResult) at System.Net.LazyAsyncResult.Complete(IntPtr) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Net.ContextAwareResult.Complete(IntPtr) at System.Net.Sockets.BaseOverlappedAsyncResult.CompletionPortCallback(UInt32, UInt32, System.Threading.NativeOverlapped*) at System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32, UInt32, System.Threading.NativeOverlapped*) Error: (08/24/2015 08:16:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 07:23:59 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 06:46:28 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 02:49:53 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 02:48:40 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: ) Description: Failed to schedule Software Protection service for re-start at 2015-09-20T06:28:40Z. Error Code: 0x80041321. Error: (08/24/2015 12:13:26 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/25/2015 10:57:07 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 10:51:17 AM on ‎8/‎25/‎2015 was unexpected. Error: (08/25/2015 10:48:59 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 12:59:35 AM on ‎8/‎25/‎2015 was unexpected. Error: (08/24/2015 07:57:46 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 7:52:25 PM on ‎8/‎24/‎2015 was unexpected. Error: (08/24/2015 07:47:36 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053VSS{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F} Error: (08/24/2015 06:31:23 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 3:57:29 PM on ‎8/‎24/‎2015 was unexpected. Error: (08/24/2015 02:44:16 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (08/24/2015 02:32:10 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053wbengine{37734C4D-FFA8-4139-9AAC-60FBE55BF3DF} Error: (08/24/2015 01:07:24 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 12:22:50 PM on ‎8/‎24/‎2015 was unexpected. Error: (08/24/2015 11:52:17 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 11:41:45 AM on ‎8/‎24/‎2015 was unexpected. Error: (08/24/2015 11:32:19 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 11:27:14 AM on ‎8/‎24/‎2015 was unexpected. Microsoft Office: ========================= Error: (08/25/2015 11:31:01 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2015 11:29:37 AM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: ) Description: 0x800413212015-09-23T17:34:37Z Error: (08/24/2015 11:10:25 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: ) Description: 0x800413212015-09-23T17:34:25Z Error: (08/24/2015 11:04:53 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: AutoPico.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.IO.IOException Stack: at System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult) at AutoPico.KMSEmulator.TCPServer.ReadCallback(System.IAsyncResult) at System.Net.LazyAsyncResult.Complete(IntPtr) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Net.ContextAwareResult.Complete(IntPtr) at System.Net.Sockets.BaseOverlappedAsyncResult.CompletionPortCallback(UInt32, UInt32, System.Threading.NativeOverlapped*) at System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32, UInt32, System.Threading.NativeOverlapped*) Error: (08/24/2015 08:16:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 07:23:59 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 06:46:28 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 02:49:53 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 02:48:40 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: ) Description: 0x800413212015-09-20T06:28:40Z Error: (08/24/2015 12:13:26 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz Percentage of memory in use: 32% Total physical RAM: 3191.18 MB Available physical RAM: 2158.34 MB Total Virtual: 6380.55 MB Available Virtual: 5308.59 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:38.96 GB) (Free:9.06 GB) NTFS Drive d: () (Fixed) (Total:53.71 GB) (Free:3.26 GB) NTFS Drive e: () (Fixed) (Total:56.28 GB) (Free:24.1 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 6205C77B) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=39 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=53.7 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=56.3 GB) - (Type=07 NTFS) ==================== End of FRST.txt ============================