I have an issue similar to the previous bluescreen loop topic (dated 3/7/2013) following virus removal by Kaspersky. My desktop running Win 7 64bit now will not boot (blue screen loop). Last evening suddenly all of my applications closed out and the computer shut down. I was able to log back in with normal windows and was met with normal desktop but could not run most programs or exe files, though I could run applications like windows file manager. I then booted with Kaspersky Rescue 10 disk and ran scan (just on boot and startup items). Kaspersky found Pihar Trojan rootkit which was disinfected. I then rebooted and was met with the blue screen loop. Tried startup repair which was ineffective. Booted again with Kaspersky Rescue, ran further scan on C: which reports also finding "Trojan-Dropper.Win32.TDSS.awyc." States it cannot disinfect and recommends deletion. I skipped deletion pending further advice...I am concerned the MBR might have been damaged when Kaspersky removed the initial Pihar trojan. Just ran Frst64 which I paste below. Thanks for any help, this is way above my paygrade and I really need a hand.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2013
Ran by SYSTEM at 18-03-2013 09:57:04
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7833120 2009-05-23] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe [x]
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [16327712 2009-06-26] (NVIDIA Corporation)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.)
HKLM\...\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1580368 2010-11-03] (Logitech, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1289704 2012-09-12] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [2419512 2012-11-04] (Logitech, Inc.)
HKLM-x32\...\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2009-07-17] (Alcor Micro Corp.)
HKLM-x32\...\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup [103768 2009-09-12] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [140520 2009-06-24] (CyberLink Corp.)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254896 2012-09-17] (Sun Microsystems, Inc.)
HKU\Don\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3883856 2009-07-26] (Microsoft Corporation)
HKLM\...\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
HKLM-x32\...\runonceex: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-26] (Sonic Solutions)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer]
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Don\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Don\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
ShortcutTarget: Logitech . Product Registration.lnk -> C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
Startup: C:\Users\Don\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ===================
3 Lavasoft Ad-Aware Service; "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe" [2152720 2012-05-23] (Lavasoft Limited)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22072 2012-09-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [368896 2012-09-12] (Microsoft Corporation)
2 NitroReaderDriverReadSpool3; "C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe" [230416 2012-10-30] (Nitro PDF Software)
2 Pantech UTM Service; C:\Program Files (x86)\PCD\Pantech\EUDL\UTM\PantechService.exe [65536 2010-11-23] (TODO: <Company name>)
4 SessionLauncher; C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
==================== Drivers (Whitelisted) =====================
3 Lavasoft Kernexplorer; \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [17152 2011-11-13] ()
0 Lbd; C:\Windows\System32\Drivers\Lbd.sys [69376 2011-11-03] (Lavasoft AB)
0 MpFilter; C:\Windows\System32\Drivers\MpFilter.sys [228768 2012-08-30] (Microsoft Corporation)
2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [128456 2012-08-30] (Microsoft Corporation)
3 PTHSBUS; C:\Windows\System32\Drivers\PTHSBUS.sys [70928 2010-04-01] (DEVGURU Co., LTD.)
3 PTHSMDM; C:\Windows\System32\Drivers\PTHSMDM.sys [184976 2010-04-01] (DEVGURU Co., LTD.(www.devguru.co.kr))
3 PTHSVSP; C:\Windows\System32\Drivers\PTHSVSP.sys [184976 2010-04-01] (DEVGURU Co., LTD.(www.devguru.co.kr))
3 RTCore64; \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14648 2010-05-26] ()
1 RxFilter; C:\Windows\SysWow64\Drivers\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)
2 WinRing0_1_2_0; \??\C:\Users\Don\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries24.gadget\WinRing0x64.sys [14544 2010-09-04] (OpenLibSys.org)
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2013-03-18 09:56 - 2013-03-18 09:56 - 00000000 ____D C:\FRST
2013-03-17 15:54 - 2013-03-17 15:54 - 00000055 ____A C:\Users\Don\Application Data\mbam.context.scan
2013-03-17 15:54 - 2013-03-17 15:54 - 00000055 ____A C:\Users\Don\AppData\Roaming\mbam.context.scan
2013-03-17 14:09 - 2009-07-13 17:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe
2013-03-06 07:38 - 2013-03-06 07:38 - 00002513 ____A C:\Users\Public\Desktop\TurboTax 2012.lnk
2013-03-06 07:38 - 2013-03-06 07:38 - 00002513 ____A C:\ProgramData\Desktop\TurboTax 2012.lnk
2013-03-01 13:29 - 2013-03-01 13:29 - 00000919 ____A C:\Users\Public\Desktop\Jarte.lnk
2013-03-01 13:29 - 2013-03-01 13:29 - 00000919 ____A C:\ProgramData\Desktop\Jarte.lnk
2013-03-01 13:29 - 2013-03-01 13:29 - 00000000 ____D C:\Users\Don\Application Data\Jarte
2013-03-01 13:29 - 2013-03-01 13:29 - 00000000 ____D C:\Users\Don\AppData\Roaming\Jarte
2013-03-01 13:29 - 2013-03-01 13:29 - 00000000 ____D C:\Program Files (x86)\Jarte
2013-03-01 12:56 - 2013-03-01 12:56 - 487488267 ____A C:\Windows\MEMORY.DMP
2013-03-01 12:56 - 2013-03-01 12:56 - 00291496 ____A C:\Windows\Minidump\030113-20420-01.dmp
2013-02-23 16:25 - 2013-02-23 16:25 - 00001868 ____A C:\Users\Don\Downloads\gdec3british-invasion.fuse
2013-02-23 16:24 - 2013-02-23 16:24 - 00002102 ____A C:\Users\Don\Downloads\gdec3bourbon-street-telecaster.fuse
2013-02-23 16:23 - 2013-02-23 16:23 - 00002428 ____A C:\Users\Don\Downloads\gdec3acoustic-srv.fuse
2013-02-23 16:22 - 2013-02-23 16:22 - 00002018 ____A C:\Users\Don\Downloads\gdec3acousticfloyd-the-happiest-days-of-our-lives.fuse
2013-02-23 16:22 - 2013-02-23 16:22 - 00001524 ____A C:\Users\Don\Downloads\gdec3blues.fuse
2013-02-23 16:21 - 2013-02-23 16:21 - 00001971 ____A C:\Users\Don\Downloads\gdec3almost-buddy-guy.fuse
2013-02-23 16:21 - 2013-02-23 16:21 - 00001940 ____A C:\Users\Don\Downloads\gdec3hexdrix-blues-stack.fuse
2013-02-23 16:18 - 2013-02-23 16:18 - 00002067 ____A C:\Users\Don\Downloads\gdec3crosstown.fuse
2013-02-23 16:16 - 2013-02-23 16:16 - 00001741 ____A C:\Users\Don\Downloads\gdec3srv_little-wing.fuse
2013-02-23 16:16 - 2013-02-23 16:16 - 00001692 ____A C:\Users\Don\Downloads\gdec3kansas-2.fuse
2013-02-23 16:15 - 2013-02-23 16:15 - 00002051 ____A C:\Users\Don\Downloads\gdec3chuck-berry.fuse
==================== One Month Modified Files and Folders =======
2013-03-18 09:56 - 2013-03-18 09:56 - 00000000 ____D C:\FRST
2013-03-18 01:29 - 2012-06-07 07:57 - 00000000 ____D C:\Windows\Minidump
2013-03-18 01:29 - 2010-09-12 18:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-03-18 01:29 - 2010-05-09 18:23 - 00000000 ____D C:\Legacy
2013-03-18 01:29 - 2009-12-12 11:55 - 00000000 ____D C:\users\Don
2013-03-18 01:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2013-03-17 20:15 - 2010-11-03 03:49 - 00070085 ____A C:\aaw7boot.log
2013-03-17 19:55 - 2009-12-12 12:12 - 00000000 ____D C:\Users\Don\Tracing
2013-03-17 18:07 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sysprep
2013-03-17 18:07 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\AppCompat
2013-03-17 18:06 - 2012-02-26 07:10 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner
2013-03-17 15:54 - 2013-03-17 15:54 - 00000055 ____A C:\Users\Don\Application Data\mbam.context.scan
2013-03-17 15:54 - 2013-03-17 15:54 - 00000055 ____A C:\Users\Don\AppData\Roaming\mbam.context.scan
2013-03-17 15:13 - 2009-07-13 20:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-03-17 15:13 - 2009-07-13 20:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-03-17 15:10 - 2009-07-13 21:13 - 00779306 ____A C:\Windows\System32\PerfStringBackup.INI
2013-03-17 15:09 - 2009-07-13 21:10 - 01413514 ____A C:\Windows\WindowsUpdate.log
2013-03-17 15:05 - 2012-12-10 17:19 - 00004682 ____A C:\Windows\setupact.log
2013-03-17 15:05 - 2010-05-09 06:42 - 00000888 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-03-17 15:05 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-03-12 22:43 - 2012-04-02 19:34 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-03-12 22:31 - 2010-05-09 06:42 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-03-12 13:47 - 2012-04-02 19:34 - 00693976 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-03-12 13:47 - 2011-06-13 05:33 - 00073432 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-03-10 04:44 - 2011-04-26 16:12 - 00000064 ____A C:\Windows\SysWOW64\rp_stats.dat
2013-03-10 04:44 - 2011-04-26 16:12 - 00000044 ____A C:\Windows\SysWOW64\rp_rules.dat
2013-03-09 11:51 - 2010-02-27 16:05 - 00000000 ____D C:\Users\Don\My Documents\TurboTax
2013-03-09 11:51 - 2010-02-27 16:05 - 00000000 ____D C:\Users\Don\Documents\TurboTax
2013-03-06 07:39 - 2012-03-06 08:13 - 00000774 ____A C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2013-03-06 07:39 - 2012-03-06 08:13 - 00000774 ____A C:\ProgramData\Application Data\Microsoft.SqlServer.Compact.400.32.bc
2013-03-06 07:38 - 2013-03-06 07:38 - 00002513 ____A C:\Users\Public\Desktop\TurboTax 2012.lnk
2013-03-06 07:38 - 2013-03-06 07:38 - 00002513 ____A C:\ProgramData\Desktop\TurboTax 2012.lnk
2013-03-06 07:37 - 2010-02-27 15:42 - 00000000 ____D C:\Program Files (x86)\TurboTax
2013-03-01 13:29 - 2013-03-01 13:29 - 00000919 ____A C:\Users\Public\Desktop\Jarte.lnk
2013-03-01 13:29 - 2013-03-01 13:29 - 00000919 ____A C:\ProgramData\Desktop\Jarte.lnk
2013-03-01 13:29 - 2013-03-01 13:29 - 00000000 ____D C:\Users\Don\Application Data\Jarte
2013-03-01 13:29 - 2013-03-01 13:29 - 00000000 ____D C:\Users\Don\AppData\Roaming\Jarte
2013-03-01 13:29 - 2013-03-01 13:29 - 00000000 ____D C:\Program Files (x86)\Jarte
2013-03-01 13:28 - 2011-08-16 18:06 - 00000000 ____D C:\Users\Don\Application Data\Orbit
2013-03-01 13:28 - 2011-08-16 18:06 - 00000000 ____D C:\Users\Don\AppData\Roaming\Orbit
2013-03-01 12:56 - 2013-03-01 12:56 - 487488267 ____A C:\Windows\MEMORY.DMP
2013-03-01 12:56 - 2013-03-01 12:56 - 00291496 ____A C:\Windows\Minidump\030113-20420-01.dmp
2013-03-01 12:56 - 2009-07-13 21:08 - 00032540 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-02-23 16:25 - 2013-02-23 16:25 - 00001868 ____A C:\Users\Don\Downloads\gdec3british-invasion.fuse
2013-02-23 16:24 - 2013-02-23 16:24 - 00002102 ____A C:\Users\Don\Downloads\gdec3bourbon-street-telecaster.fuse
2013-02-23 16:23 - 2013-02-23 16:23 - 00002428 ____A C:\Users\Don\Downloads\gdec3acoustic-srv.fuse
2013-02-23 16:22 - 2013-02-23 16:22 - 00002018 ____A C:\Users\Don\Downloads\gdec3acousticfloyd-the-happiest-days-of-our-lives.fuse
2013-02-23 16:22 - 2013-02-23 16:22 - 00001524 ____A C:\Users\Don\Downloads\gdec3blues.fuse
2013-02-23 16:21 - 2013-02-23 16:21 - 00001971 ____A C:\Users\Don\Downloads\gdec3almost-buddy-guy.fuse
2013-02-23 16:21 - 2013-02-23 16:21 - 00001940 ____A C:\Users\Don\Downloads\gdec3hexdrix-blues-stack.fuse
2013-02-23 16:18 - 2013-02-23 16:18 - 00002067 ____A C:\Users\Don\Downloads\gdec3crosstown.fuse
2013-02-23 16:16 - 2013-02-23 16:16 - 00001741 ____A C:\Users\Don\Downloads\gdec3srv_little-wing.fuse
2013-02-23 16:16 - 2013-02-23 16:16 - 00001692 ____A C:\Users\Don\Downloads\gdec3kansas-2.fuse
2013-02-23 16:15 - 2013-02-23 16:15 - 00002051 ____A C:\Users\Don\Downloads\gdec3chuck-berry.fuse
2013-02-23 16:08 - 2011-08-16 18:06 - 00000000 ____D C:\Program Files (x86)\Orbitdownloader
2013-02-22 11:47 - 2010-09-12 17:35 - 00000000 ____D C:\Users\Don\My Documents\Dell 8000
2013-02-22 11:47 - 2010-09-12 17:35 - 00000000 ____D C:\Users\Don\Documents\Dell 8000
2013-02-21 05:31 - 2012-08-27 06:51 - 00000000 ____D C:\Users\Don\My Documents\Consulting
2013-02-21 05:31 - 2012-08-27 06:51 - 00000000 ____D C:\Users\Don\Documents\Consulting
ATTENTION: ========> Check for possible partition/boot infection:
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
TDL4: custom:26000022 <===== ATTENTION!
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-02-26 16:53:38
Restore point made on: 2013-03-01 21:56:35
Restore point made on: 2013-03-05 13:36:45
Restore point made on: 2013-03-06 07:37:59
Restore point made on: 2013-03-06 15:03:59
Restore point made on: 2013-03-08 23:45:56
Restore point made on: 2013-03-12 22:43:22
Restore point made on: 2013-03-17 14:58:33
Restore point made on: 2013-03-17 15:23:53
Restore point made on: 2013-03-17 19:31:48
==================== Memory info ===========================
Percentage of memory in use: 10%
Total physical RAM: 8183.12 MB
Available physical RAM: 7333.14 MB
Total Pagefile: 8181.27 MB
Available Pagefile: 7330.47 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: (OS) (Fixed) (Total:916.82 GB) (Free:732.34 GB) NTFS
2 Drive e: (KIS 2013) (CDROM) (Total:0.39 GB) (Free:0 GB) CDFS
3 Drive f: () (Removable) (Total:7.47 GB) (Free:0.17 GB) FAT32
4 Drive g: () (Removable) (Total:7.47 GB) (Free:2.37 GB) FAT32
9 Drive l: () (Removable) (Total:0.24 GB) (Free:0.14 GB) FAT
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
11 Drive y: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:9.45 GB) NTFS ==>[System with boot components (obtained from reading drive)]
ATTENTION: Malware custom entry on BCD on drive y: detected. Check for MBR/Partition infection.
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 7663 MB 0 B
Disk 2 Online 7663 MB 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Disk 6 No Media 0 B 0 B
Disk 7 Online 245 MB 0 B
Partitions of Disk 0:
Disk ID: E05EAAD9
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 14 GB 40 MB
Partition 3 Primary 916 GB 14 GB
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 10 FAT Partition 39 MB Healthy Hidden
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y RECOVERY NTFS Partition 14 GB Healthy
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 916 GB Healthy
Partitions of Disk 1:
Disk ID: 00000000
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7655 MB 22 KB
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 7655 MB Healthy
Partitions of Disk 2:
Disk ID: 00000000
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7655 MB 22 KB
Disk: 2
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 7655 MB Healthy
Partitions of Disk 7:
Disk ID: 91F72D24
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 244 MB 16 KB
Disk: 7
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 9 L FAT Removable 244 MB Healthy
============================== MBR Partition Table ==================
Partitions of Disk 0:
Disk ID: E05EAAD9
Partition 1:
Hex: 00010100DEFE3F043F00000086390100
Active: NO
Type: DE
Size: 39 MB
Partition 2:
Hex: 8019150507FEFFFF0040010000C0D401
Active: YES
Type: 07 (NTFS)
Size: 15 GB
Partition 3:
Hex: 00FEFFFF07FEFFFF0000D601B0659A72
Active: NO
Type: 07 (NTFS)
Size: 917 GB
Partitions of Disk 1:
Disk ID: 00000000
Partition 1:
Hex: 00002D000BFEFFCF2C000000A43FEF00
Active: NO
Type: 0B
Size: 7 GB
Partitions of Disk 2:
Disk ID: 00000000
Partition 1:
Hex: 00002D000BFEFFCF2C000000A43FEF00
Active: NO
Type: 0B
Size: 7 GB
Partitions of Disk 7:
Disk ID: 91F72D24
Partition 1:
Hex: 80010100060FE0D220000000E0A70700
Active: YES
Type: 06
Size: 245 MB
Last Boot: 2013-03-15 09:34
==================== End Of Log =============================