Hi, I have a problem starting windows, everything begins when I was using my laptop and I decided to shut down it, but during the proccess the battery energy runs out and the laptop was shut down abruptly, then when I start windows I get the message "windows find a critic error and will restart in a minute" every time.
So searching for an answer I found reponses to another users, so I follow instructions to the point to run frst, so I have the two txt files
in the process:
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-06-2013
Ran by SYSTEM on 20-06-2013 21:07:16
Running from F:\
Windows 7 Ultimate (X64) OS Language: Spanish Modern Sort
Internet Explorer Version 9
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe [618368 2009-07-04] (ELAN Microelectronic Corp.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7970848 2009-07-14] (Realtek Semiconductor)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice [2716216 2009-11-16] (ESET)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
HKLM-x32\...\Run: [BTMeter] C:\Program Files (x86)\Battery Meter\BTMeter.exe [623984 2009-07-02] (Dell)
HKLM-x32\...\Run: [WSED] C:\Program Files (x86)\WSED\WSED.exe [247080 2009-05-27] (Dell)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [x]
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [198160 2009-12-27] (RealNetworks, Inc.)
HKLM-x32\...\Run: [nusbantivirus] "C:\Program Files (x86)\Naevius USB Antivirus\usbantivirus.exe" -hide [x]
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640376 2008-06-12] (Adobe Systems Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKU\Irving Omar\...\Run: [Facebook Update] "C:\Users\Irving Omar\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-12-13] (Facebook Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) =================
S3 Adobe Version Cue CS4; C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [284016 2008-08-15] (Adobe Systems Incorporated)
S2 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [79360 2011-11-04] (Autodesk)
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [23296 2009-11-16] (ESET)
S2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [735960 2009-11-16] (ESET)
S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-10-18] ()
S2 mi-raysat_3dsMax2009_32; C:\Program Files (x86)\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [65536 2008-03-10] ()
S2 mi-raysat_3dsMax2009_64; C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_64server.exe [65536 2008-03-10] ()
S2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4466688 2007-11-07] (Microsoft Corporation)
S4 OracleJobSchedulerTecSal; c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe [102400 2006-02-02] ()
S4 OracleJobSchedulerXE; c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe [102400 2006-02-02] ()
S3 OracleMTSRecoveryService; C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe [57616 2006-02-02] (Oracle Corporation)
S3 OracleServiceTecSal; c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE [59064320 2006-02-02] (Oracle Corporation)
S2 OracleServiceXE; c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE [59064320 2006-02-02] (Oracle Corporation)
S3 OracleXEClrAgent; C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe [45056 2006-02-02] ()
S2 OracleXETNSListener; C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe [204800 2006-02-02] ()
S2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [13234176 2012-11-01] ()
S3 wampapache; c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe [21504 2010-10-24] (Apache Software Foundation)
S3 wampmysqld; c:\wamp\bin\mysql\mysql5.1.53\bin\mysqld.exe [7669760 2010-11-24] ()
S2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE [33280 2009-07-17] ()
S2 matlabserver; C:\MATLAB7\webserver\bin\win32\matlabserver.exe [x]
==================== Drivers (Whitelisted) ====================
S2 eamon; C:\Windows\System32\DRIVERS\eamon.sys [145336 2009-11-16] (ESET)
S1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [136584 2009-11-16] (ESET)
S2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [169080 2009-11-16] (ESET)
S3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33608 2009-06-19] (ESET)
S2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [44944 2009-11-16] (ESET)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 MSIRCOMM; C:\Windows\System32\DRIVERS\MSIRCOMM.sys [30208 2009-07-14] (Microsoft Corporation)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-07-05] (Duplex Secure Ltd.)
S3 STIrUsb; C:\Windows\System32\DRIVERS\irstusb.sys [33792 2008-01-19] (SigmaTel, Inc.)
S1 vmm; C:\Windows\system32\Controladores\vmm.sys [296816 2007-02-18] (Microsoft Corporation)
S0 vsock; C:\Windows\System32\drivers\vsock.sys [70296 2012-10-24] (VMware, Inc.)
S1 SASDIFSV; \??\C:\Users\IRVING~1\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]
S1 SASKUTIL; \??\C:\Users\IRVING~1\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-21 01:25 - 2013-06-21 01:25 - 00003288 ____N C:\bootsqm.dat
2013-06-20 21:06 - 2013-06-20 21:06 - 00000000 ____D C:\FRST
2013-06-20 02:09 - 2013-06-20 23:53 - 00000000 ____D C:\Users\Irving Omar\Desktop\Solaris 10
2013-06-20 01:52 - 2013-05-08 17:45 - 2254110720 ____A C:\Users\Irving Omar\Desktop\sol-10-u11-ga-x86-dvd.iso
2013-06-19 22:39 - 2013-06-20 23:44 - 00000000 ____D C:\Users\Irving Omar\Documents\MobaXterm
2013-06-18 16:07 - 2013-06-18 16:07 - 00002122 ____A C:\Users\Public\Desktop\Belarc Advisor.lnk
2013-06-18 16:07 - 2013-06-18 16:07 - 00000000 ____D C:\Program Files (x86)\Belarc
2013-06-18 02:54 - 2013-06-18 02:54 - 00001774 ____A C:\Users\Irving Omar\Documents\Solicitud de inscripción.htm
2013-06-18 02:53 - 2013-06-18 02:54 - 00000000 ____D C:\Users\Irving Omar\Documents\Solicitud de inscripción_archivos
2013-06-17 18:57 - 2013-06-17 18:58 - 00000000 ____D C:\Users\Irving Omar\Documents\TXM
2013-06-17 17:29 - 2013-06-17 17:29 - 00001179 ____A C:\Users\Irving Omar\Desktop\Google Talk.lnk
2013-06-17 15:31 - 2013-06-17 15:31 - 00000000 ____D C:\Users\Irving Omar\ssh
2013-06-17 15:23 - 2013-06-17 15:23 - 00000000 ____D C:\Users\Irving Omar\.eclipse
2013-06-17 15:20 - 2013-06-17 15:22 - 00000000 ____D C:\Program Files (x86)\Eclipse
2013-06-17 15:18 - 2013-06-17 15:18 - 00001164 ____A C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-06-17 15:18 - 2013-06-17 15:18 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-06-16 23:00 - 2013-06-16 23:00 - 00000579 ____A C:\Users\Public\Desktop\Cygwin Terminal.lnk
2013-06-16 22:58 - 2013-06-16 22:58 - 00001061 ____A C:\Users\Irving Omar\Desktop\Notepad++.lnk
2013-06-16 22:50 - 2013-06-16 23:00 - 00000000 ____D C:\cygwin
2013-06-14 01:24 - 2013-06-14 01:24 - 00000000 ____D C:\Program Files\7-Zip
2013-06-09 21:34 - 2013-06-09 21:34 - 00001785 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-09 21:33 - 2013-06-09 21:34 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 21:33 - 2013-06-09 21:34 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 21:33 - 2013-06-09 21:34 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 21:33 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files\iPod
2013-06-03 02:49 - 2013-06-03 02:49 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\{34D7EF03-F30A-4C7A-8FFE-3F455F43D503}
2013-05-31 05:44 - 2013-06-10 20:41 - 00000000 ____D C:\Users\Irving Omar\Documents\Resumes
2013-05-26 20:49 - 2013-05-26 20:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-25 01:29 - 2013-06-08 23:08 - 00000000 ____D C:\Program Files\My Dell
==================== One Month Modified Files and Folders =======
2013-06-21 02:57 - 2013-05-08 01:59 - 00000000 ____D C:\ProgramData\VMware
2013-06-21 02:57 - 2012-11-08 02:22 - 00000212 ____A C:\Windows\Tasks\AutoKMS.job
2013-06-21 02:56 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-21 02:56 - 2009-07-14 05:51 - 00176657 ____A C:\Windows\setupact.log
2013-06-21 02:53 - 2010-08-02 21:36 - 00001042 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-21 02:42 - 2009-07-14 06:10 - 01758736 ____A C:\Windows\WindowsUpdate.log
2013-06-21 01:44 - 2012-07-12 01:36 - 00000838 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-21 01:43 - 2009-07-14 06:08 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-21 01:25 - 2013-06-21 01:25 - 00003288 ____N C:\bootsqm.dat
2013-06-21 00:01 - 2013-01-13 04:49 - 00000000 ____D C:\Users\Irving Omar\AppData\Roaming\Skype
2013-06-21 00:00 - 2010-08-02 21:36 - 00001046 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-20 23:53 - 2013-06-20 02:09 - 00000000 ____D C:\Users\Irving Omar\Desktop\Solaris 10
2013-06-20 23:53 - 2013-05-08 02:05 - 00000000 ____D C:\Users\Irving Omar\AppData\Roaming\VMware
2013-06-20 23:53 - 2013-05-08 02:05 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\VMware
2013-06-20 23:44 - 2013-06-19 22:39 - 00000000 ____D C:\Users\Irving Omar\Documents\MobaXterm
2013-06-20 23:42 - 2010-04-28 22:54 - 00000000 ___RD C:\Users\Irving Omar\Descargas de Google Chrome
2013-06-20 22:15 - 2012-12-13 05:10 - 00000952 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2898004258-2142751285-386409930-1000UA.job
2013-06-20 21:06 - 2013-06-20 21:06 - 00000000 ____D C:\FRST
2013-06-20 18:10 - 2009-07-14 05:45 - 00031120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-20 18:10 - 2009-07-14 05:45 - 00031120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-20 04:15 - 2012-12-13 05:10 - 00000930 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2898004258-2142751285-386409930-1000Core.job
2013-06-20 01:54 - 2009-07-14 10:31 - 00745454 ____A C:\Windows\System32\perfh00A.dat
2013-06-20 01:54 - 2009-07-14 10:31 - 00154016 ____A C:\Windows\System32\perfc00A.dat
2013-06-20 01:54 - 2009-07-14 06:13 - 01669842 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-19 04:05 - 2013-01-13 04:49 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-06-19 04:05 - 2013-01-13 04:49 - 00000000 ____D C:\ProgramData\Skype
2013-06-18 16:07 - 2013-06-18 16:07 - 00002122 ____A C:\Users\Public\Desktop\Belarc Advisor.lnk
2013-06-18 16:07 - 2013-06-18 16:07 - 00000000 ____D C:\Program Files (x86)\Belarc
2013-06-18 02:54 - 2013-06-18 02:54 - 00001774 ____A C:\Users\Irving Omar\Documents\Solicitud de inscripción.htm
2013-06-18 02:54 - 2013-06-18 02:53 - 00000000 ____D C:\Users\Irving Omar\Documents\Solicitud de inscripción_archivos
2013-06-17 19:04 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-17 18:58 - 2013-06-17 18:57 - 00000000 ____D C:\Users\Irving Omar\Documents\TXM
2013-06-17 17:29 - 2013-06-17 17:29 - 00001179 ____A C:\Users\Irving Omar\Desktop\Google Talk.lnk
2013-06-17 17:29 - 2010-08-02 21:36 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-17 17:29 - 2010-02-10 23:15 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\Google
2013-06-17 15:47 - 2009-07-14 05:45 - 03380464 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-17 15:31 - 2013-06-17 15:31 - 00000000 ____D C:\Users\Irving Omar\ssh
2013-06-17 15:31 - 2009-12-25 20:33 - 00000000 ____D C:\users\Irving Omar
2013-06-17 15:28 - 2011-05-06 00:26 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\Eclipse
2013-06-17 15:28 - 2009-12-25 20:33 - 00143456 ____A C:\Users\Irving Omar\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-17 15:23 - 2013-06-17 15:23 - 00000000 ____D C:\Users\Irving Omar\.eclipse
2013-06-17 15:22 - 2013-06-17 15:20 - 00000000 ____D C:\Program Files (x86)\Eclipse
2013-06-17 15:18 - 2013-06-17 15:18 - 00001164 ____A C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-06-17 15:18 - 2013-06-17 15:18 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-06-16 23:00 - 2013-06-16 23:00 - 00000579 ____A C:\Users\Public\Desktop\Cygwin Terminal.lnk
2013-06-16 23:00 - 2013-06-16 22:50 - 00000000 ____D C:\cygwin
2013-06-16 22:58 - 2013-06-16 22:58 - 00001061 ____A C:\Users\Irving Omar\Desktop\Notepad++.lnk
2013-06-16 22:58 - 2013-03-24 19:15 - 00000000 ____D C:\Users\Irving Omar\AppData\Roaming\Notepad++
2013-06-16 22:58 - 2013-03-24 19:13 - 00000000 ____D C:\Program Files (x86)\Notepad++
2013-06-16 01:53 - 2009-12-27 23:37 - 00000000 ____D C:\Users\Irving Omar\Desktop\Juegos
2013-06-14 01:24 - 2013-06-14 01:24 - 00000000 ____D C:\Program Files\7-Zip
2013-06-12 02:49 - 2012-04-04 18:22 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 02:49 - 2011-05-18 23:01 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-10 20:41 - 2013-05-31 05:44 - 00000000 ____D C:\Users\Irving Omar\Documents\Resumes
2013-06-09 21:34 - 2013-06-09 21:34 - 00001785 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-09 21:34 - 2013-06-09 21:33 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 21:34 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 21:34 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 21:33 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files\iPod
2013-06-08 23:08 - 2013-05-25 01:29 - 00000000 ____D C:\Program Files\My Dell
2013-06-07 04:02 - 2011-07-14 17:24 - 00000000 ____D C:\wamp
2013-06-03 02:49 - 2013-06-03 02:49 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\{34D7EF03-F30A-4C7A-8FFE-3F455F43D503}
2013-06-03 02:48 - 2009-12-25 21:52 - 00000000 ____D C:\Users\Irving Omar\Tracing
2013-06-03 01:06 - 2009-12-29 22:10 - 00000000 ___HD C:\Users\Irving Omar\Documents\videos obtenidos
2013-05-28 02:21 - 2012-05-09 02:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-26 20:49 - 2013-05-26 20:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-25 01:30 - 2011-05-24 23:46 - 00000000 ____D C:\Program Files\Dell Support Center
2013-05-25 01:29 - 2009-11-04 20:19 - 00000000 ____D C:\ProgramData\PCDr
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 28%
Total physical RAM: 1976.89 MB
Available physical RAM: 1405.65 MB
Total Pagefile: 1976.89 MB
Available Pagefile: 1401.44 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:281.47 GB) (Free:166.5 GB) NTFS (Disk=0 Partition=3)
Drive f: () (Removable) (Total:1.88 GB) (Free:1.88 GB) FAT (Disk=2 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:10.39 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D6385E59)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=281 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=OF Extended)
========================================================
Disk: 2 (Size: 2 GB) (Disk ID: 00000000)
Partition 1: (Active) - (Size=2 GB) - (Type=06)
LastRegBack: 2013-06-14 02:09
==================== End Of Log ============================
and the Services.txt:
Farbar Recovery Scan Tool (x64) Version: 21-06-2013
Ran by SYSTEM at 2013-06-20 21:18:45
Running from F:\
Boot Mode: Recovery
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-14 00:19] - [2009-07-14 02:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-14 00:19] - [2009-07-14 02:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
I hope you can help and thanks for your attention
So searching for an answer I found reponses to another users, so I follow instructions to the point to run frst, so I have the two txt files
in the process:
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-06-2013
Ran by SYSTEM on 20-06-2013 21:07:16
Running from F:\
Windows 7 Ultimate (X64) OS Language: Spanish Modern Sort
Internet Explorer Version 9
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe [618368 2009-07-04] (ELAN Microelectronic Corp.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7970848 2009-07-14] (Realtek Semiconductor)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice [2716216 2009-11-16] (ESET)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
HKLM-x32\...\Run: [BTMeter] C:\Program Files (x86)\Battery Meter\BTMeter.exe [623984 2009-07-02] (Dell)
HKLM-x32\...\Run: [WSED] C:\Program Files (x86)\WSED\WSED.exe [247080 2009-05-27] (Dell)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [x]
HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [198160 2009-12-27] (RealNetworks, Inc.)
HKLM-x32\...\Run: [nusbantivirus] "C:\Program Files (x86)\Naevius USB Antivirus\usbantivirus.exe" -hide [x]
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640376 2008-06-12] (Adobe Systems Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKU\Irving Omar\...\Run: [Facebook Update] "C:\Users\Irving Omar\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-12-13] (Facebook Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) =================
S3 Adobe Version Cue CS4; C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [284016 2008-08-15] (Adobe Systems Incorporated)
S2 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [79360 2011-11-04] (Autodesk)
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [23296 2009-11-16] (ESET)
S2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [735960 2009-11-16] (ESET)
S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-10-18] ()
S2 mi-raysat_3dsMax2009_32; C:\Program Files (x86)\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [65536 2008-03-10] ()
S2 mi-raysat_3dsMax2009_64; C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_64server.exe [65536 2008-03-10] ()
S2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4466688 2007-11-07] (Microsoft Corporation)
S4 OracleJobSchedulerTecSal; c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe [102400 2006-02-02] ()
S4 OracleJobSchedulerXE; c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe [102400 2006-02-02] ()
S3 OracleMTSRecoveryService; C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe [57616 2006-02-02] (Oracle Corporation)
S3 OracleServiceTecSal; c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE [59064320 2006-02-02] (Oracle Corporation)
S2 OracleServiceXE; c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE [59064320 2006-02-02] (Oracle Corporation)
S3 OracleXEClrAgent; C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe [45056 2006-02-02] ()
S2 OracleXETNSListener; C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe [204800 2006-02-02] ()
S2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [13234176 2012-11-01] ()
S3 wampapache; c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe [21504 2010-10-24] (Apache Software Foundation)
S3 wampmysqld; c:\wamp\bin\mysql\mysql5.1.53\bin\mysqld.exe [7669760 2010-11-24] ()
S2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE [33280 2009-07-17] ()
S2 matlabserver; C:\MATLAB7\webserver\bin\win32\matlabserver.exe [x]
==================== Drivers (Whitelisted) ====================
S2 eamon; C:\Windows\System32\DRIVERS\eamon.sys [145336 2009-11-16] (ESET)
S1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [136584 2009-11-16] (ESET)
S2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [169080 2009-11-16] (ESET)
S3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33608 2009-06-19] (ESET)
S2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [44944 2009-11-16] (ESET)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 MSIRCOMM; C:\Windows\System32\DRIVERS\MSIRCOMM.sys [30208 2009-07-14] (Microsoft Corporation)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-07-05] (Duplex Secure Ltd.)
S3 STIrUsb; C:\Windows\System32\DRIVERS\irstusb.sys [33792 2008-01-19] (SigmaTel, Inc.)
S1 vmm; C:\Windows\system32\Controladores\vmm.sys [296816 2007-02-18] (Microsoft Corporation)
S0 vsock; C:\Windows\System32\drivers\vsock.sys [70296 2012-10-24] (VMware, Inc.)
S1 SASDIFSV; \??\C:\Users\IRVING~1\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]
S1 SASKUTIL; \??\C:\Users\IRVING~1\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-21 01:25 - 2013-06-21 01:25 - 00003288 ____N C:\bootsqm.dat
2013-06-20 21:06 - 2013-06-20 21:06 - 00000000 ____D C:\FRST
2013-06-20 02:09 - 2013-06-20 23:53 - 00000000 ____D C:\Users\Irving Omar\Desktop\Solaris 10
2013-06-20 01:52 - 2013-05-08 17:45 - 2254110720 ____A C:\Users\Irving Omar\Desktop\sol-10-u11-ga-x86-dvd.iso
2013-06-19 22:39 - 2013-06-20 23:44 - 00000000 ____D C:\Users\Irving Omar\Documents\MobaXterm
2013-06-18 16:07 - 2013-06-18 16:07 - 00002122 ____A C:\Users\Public\Desktop\Belarc Advisor.lnk
2013-06-18 16:07 - 2013-06-18 16:07 - 00000000 ____D C:\Program Files (x86)\Belarc
2013-06-18 02:54 - 2013-06-18 02:54 - 00001774 ____A C:\Users\Irving Omar\Documents\Solicitud de inscripción.htm
2013-06-18 02:53 - 2013-06-18 02:54 - 00000000 ____D C:\Users\Irving Omar\Documents\Solicitud de inscripción_archivos
2013-06-17 18:57 - 2013-06-17 18:58 - 00000000 ____D C:\Users\Irving Omar\Documents\TXM
2013-06-17 17:29 - 2013-06-17 17:29 - 00001179 ____A C:\Users\Irving Omar\Desktop\Google Talk.lnk
2013-06-17 15:31 - 2013-06-17 15:31 - 00000000 ____D C:\Users\Irving Omar\ssh
2013-06-17 15:23 - 2013-06-17 15:23 - 00000000 ____D C:\Users\Irving Omar\.eclipse
2013-06-17 15:20 - 2013-06-17 15:22 - 00000000 ____D C:\Program Files (x86)\Eclipse
2013-06-17 15:18 - 2013-06-17 15:18 - 00001164 ____A C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-06-17 15:18 - 2013-06-17 15:18 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-06-16 23:00 - 2013-06-16 23:00 - 00000579 ____A C:\Users\Public\Desktop\Cygwin Terminal.lnk
2013-06-16 22:58 - 2013-06-16 22:58 - 00001061 ____A C:\Users\Irving Omar\Desktop\Notepad++.lnk
2013-06-16 22:50 - 2013-06-16 23:00 - 00000000 ____D C:\cygwin
2013-06-14 01:24 - 2013-06-14 01:24 - 00000000 ____D C:\Program Files\7-Zip
2013-06-09 21:34 - 2013-06-09 21:34 - 00001785 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-09 21:33 - 2013-06-09 21:34 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 21:33 - 2013-06-09 21:34 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 21:33 - 2013-06-09 21:34 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 21:33 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files\iPod
2013-06-03 02:49 - 2013-06-03 02:49 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\{34D7EF03-F30A-4C7A-8FFE-3F455F43D503}
2013-05-31 05:44 - 2013-06-10 20:41 - 00000000 ____D C:\Users\Irving Omar\Documents\Resumes
2013-05-26 20:49 - 2013-05-26 20:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-25 01:29 - 2013-06-08 23:08 - 00000000 ____D C:\Program Files\My Dell
==================== One Month Modified Files and Folders =======
2013-06-21 02:57 - 2013-05-08 01:59 - 00000000 ____D C:\ProgramData\VMware
2013-06-21 02:57 - 2012-11-08 02:22 - 00000212 ____A C:\Windows\Tasks\AutoKMS.job
2013-06-21 02:56 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-21 02:56 - 2009-07-14 05:51 - 00176657 ____A C:\Windows\setupact.log
2013-06-21 02:53 - 2010-08-02 21:36 - 00001042 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-21 02:42 - 2009-07-14 06:10 - 01758736 ____A C:\Windows\WindowsUpdate.log
2013-06-21 01:44 - 2012-07-12 01:36 - 00000838 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-21 01:43 - 2009-07-14 06:08 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-21 01:25 - 2013-06-21 01:25 - 00003288 ____N C:\bootsqm.dat
2013-06-21 00:01 - 2013-01-13 04:49 - 00000000 ____D C:\Users\Irving Omar\AppData\Roaming\Skype
2013-06-21 00:00 - 2010-08-02 21:36 - 00001046 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-20 23:53 - 2013-06-20 02:09 - 00000000 ____D C:\Users\Irving Omar\Desktop\Solaris 10
2013-06-20 23:53 - 2013-05-08 02:05 - 00000000 ____D C:\Users\Irving Omar\AppData\Roaming\VMware
2013-06-20 23:53 - 2013-05-08 02:05 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\VMware
2013-06-20 23:44 - 2013-06-19 22:39 - 00000000 ____D C:\Users\Irving Omar\Documents\MobaXterm
2013-06-20 23:42 - 2010-04-28 22:54 - 00000000 ___RD C:\Users\Irving Omar\Descargas de Google Chrome
2013-06-20 22:15 - 2012-12-13 05:10 - 00000952 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2898004258-2142751285-386409930-1000UA.job
2013-06-20 21:06 - 2013-06-20 21:06 - 00000000 ____D C:\FRST
2013-06-20 18:10 - 2009-07-14 05:45 - 00031120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-20 18:10 - 2009-07-14 05:45 - 00031120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-20 04:15 - 2012-12-13 05:10 - 00000930 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2898004258-2142751285-386409930-1000Core.job
2013-06-20 01:54 - 2009-07-14 10:31 - 00745454 ____A C:\Windows\System32\perfh00A.dat
2013-06-20 01:54 - 2009-07-14 10:31 - 00154016 ____A C:\Windows\System32\perfc00A.dat
2013-06-20 01:54 - 2009-07-14 06:13 - 01669842 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-19 04:05 - 2013-01-13 04:49 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-06-19 04:05 - 2013-01-13 04:49 - 00000000 ____D C:\ProgramData\Skype
2013-06-18 16:07 - 2013-06-18 16:07 - 00002122 ____A C:\Users\Public\Desktop\Belarc Advisor.lnk
2013-06-18 16:07 - 2013-06-18 16:07 - 00000000 ____D C:\Program Files (x86)\Belarc
2013-06-18 02:54 - 2013-06-18 02:54 - 00001774 ____A C:\Users\Irving Omar\Documents\Solicitud de inscripción.htm
2013-06-18 02:54 - 2013-06-18 02:53 - 00000000 ____D C:\Users\Irving Omar\Documents\Solicitud de inscripción_archivos
2013-06-17 19:04 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-17 18:58 - 2013-06-17 18:57 - 00000000 ____D C:\Users\Irving Omar\Documents\TXM
2013-06-17 17:29 - 2013-06-17 17:29 - 00001179 ____A C:\Users\Irving Omar\Desktop\Google Talk.lnk
2013-06-17 17:29 - 2010-08-02 21:36 - 00000000 ____D C:\Program Files (x86)\Google
2013-06-17 17:29 - 2010-02-10 23:15 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\Google
2013-06-17 15:47 - 2009-07-14 05:45 - 03380464 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-17 15:31 - 2013-06-17 15:31 - 00000000 ____D C:\Users\Irving Omar\ssh
2013-06-17 15:31 - 2009-12-25 20:33 - 00000000 ____D C:\users\Irving Omar
2013-06-17 15:28 - 2011-05-06 00:26 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\Eclipse
2013-06-17 15:28 - 2009-12-25 20:33 - 00143456 ____A C:\Users\Irving Omar\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-17 15:23 - 2013-06-17 15:23 - 00000000 ____D C:\Users\Irving Omar\.eclipse
2013-06-17 15:22 - 2013-06-17 15:20 - 00000000 ____D C:\Program Files (x86)\Eclipse
2013-06-17 15:18 - 2013-06-17 15:18 - 00001164 ____A C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-06-17 15:18 - 2013-06-17 15:18 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-06-16 23:00 - 2013-06-16 23:00 - 00000579 ____A C:\Users\Public\Desktop\Cygwin Terminal.lnk
2013-06-16 23:00 - 2013-06-16 22:50 - 00000000 ____D C:\cygwin
2013-06-16 22:58 - 2013-06-16 22:58 - 00001061 ____A C:\Users\Irving Omar\Desktop\Notepad++.lnk
2013-06-16 22:58 - 2013-03-24 19:15 - 00000000 ____D C:\Users\Irving Omar\AppData\Roaming\Notepad++
2013-06-16 22:58 - 2013-03-24 19:13 - 00000000 ____D C:\Program Files (x86)\Notepad++
2013-06-16 01:53 - 2009-12-27 23:37 - 00000000 ____D C:\Users\Irving Omar\Desktop\Juegos
2013-06-14 01:24 - 2013-06-14 01:24 - 00000000 ____D C:\Program Files\7-Zip
2013-06-12 02:49 - 2012-04-04 18:22 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 02:49 - 2011-05-18 23:01 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-10 20:41 - 2013-05-31 05:44 - 00000000 ____D C:\Users\Irving Omar\Documents\Resumes
2013-06-09 21:34 - 2013-06-09 21:34 - 00001785 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-09 21:34 - 2013-06-09 21:33 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-09 21:34 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files\iTunes
2013-06-09 21:34 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-09 21:33 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files\iPod
2013-06-08 23:08 - 2013-05-25 01:29 - 00000000 ____D C:\Program Files\My Dell
2013-06-07 04:02 - 2011-07-14 17:24 - 00000000 ____D C:\wamp
2013-06-03 02:49 - 2013-06-03 02:49 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\{34D7EF03-F30A-4C7A-8FFE-3F455F43D503}
2013-06-03 02:48 - 2009-12-25 21:52 - 00000000 ____D C:\Users\Irving Omar\Tracing
2013-06-03 01:06 - 2009-12-29 22:10 - 00000000 ___HD C:\Users\Irving Omar\Documents\videos obtenidos
2013-05-28 02:21 - 2012-05-09 02:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-26 20:49 - 2013-05-26 20:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-25 01:30 - 2011-05-24 23:46 - 00000000 ____D C:\Program Files\Dell Support Center
2013-05-25 01:29 - 2009-11-04 20:19 - 00000000 ____D C:\ProgramData\PCDr
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 28%
Total physical RAM: 1976.89 MB
Available physical RAM: 1405.65 MB
Total Pagefile: 1976.89 MB
Available Pagefile: 1401.44 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:281.47 GB) (Free:166.5 GB) NTFS (Disk=0 Partition=3)
Drive f: () (Removable) (Total:1.88 GB) (Free:1.88 GB) FAT (Disk=2 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:10.39 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D6385E59)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=281 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=OF Extended)
========================================================
Disk: 2 (Size: 2 GB) (Disk ID: 00000000)
Partition 1: (Active) - (Size=2 GB) - (Type=06)
LastRegBack: 2013-06-14 02:09
==================== End Of Log ============================
and the Services.txt:
Farbar Recovery Scan Tool (x64) Version: 21-06-2013
Ran by SYSTEM at 2013-06-20 21:18:45
Running from F:\
Boot Mode: Recovery
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-14 00:19] - [2009-07-14 02:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-14 00:19] - [2009-07-14 02:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
I hope you can help and thanks for your attention