Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-04-2017 01
Ran by SYSTEM on MININT-ITC8NCK (17-04-2017 12:02:48)
Running from F:\
Platform: WIN_81 (X64) Language: English (United States)
Boot Mode: Recovery
ATTENTION: Could not load system hive.
The operation completed successfully.
Tutorial for Farbar Recovery Scan Tool:
FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Winlogon: [Userinit]
HKLM-x32\...\Winlogon: [Userinit]
HKLM\...\Winlogon: [Shell] [0 ] () <=== ATTENTION
HKLM-x32\...\Winlogon: [Shell] [0 ] () <=== ATTENTION
HKLM\...\InprocServer32: [Default-wbemess] <==== ATTENTION
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] <==== ATTENTION
HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-17 11:57 - 2017-04-17 12:02 - 00000000 ____D C:\FRST
2017-04-16 09:42 - 2017-04-16 21:07 - 00000000 _____ C:\Recovery.txt
2017-04-16 09:39 - 2017-04-16 09:39 - 00000001 _____ C:\BOOTNXT
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-16 09:40 - 2013-08-22 07:36 - 00000000 ____D C:\Windows\System32\migwiz
2017-04-16 09:40 - 2013-08-22 07:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-04-16 09:40 - 2013-08-22 05:36 - 00000000 ____D C:\Windows\System32\oobe
==================== Known DLLs (Whitelisted) =========================
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe IS MISSING <==== ATTENTION
C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION
C:\Windows\explorer.exe IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\explorer.exe IS MISSING <==== ATTENTION
C:\Windows\System32\svchost.exe IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\svchost.exe IS MISSING <==== ATTENTION
C:\Windows\System32\services.exe IS MISSING <==== ATTENTION
C:\Windows\System32\User32.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\User32.dll IS MISSING <==== ATTENTION
C:\Windows\System32\userinit.exe IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\userinit.exe IS MISSING <==== ATTENTION
C:\Windows\System32\rpcss.dll IS MISSING <==== ATTENTION
C:\Windows\System32\dnsapi.dll IS MISSING <==== ATTENTION
C:\Windows\SysWOW64\dnsapi.dll IS MISSING <==== ATTENTION
C:\Windows\System32\Drivers\volsnap.sys IS MISSING <==== ATTENTION
C:\Windows\System32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION
C:\Windows\System32\winsrv.dll IS MISSING <==== ATTENTION
==================== Association (Whitelisted) =============
HKLM\...\.exe: => <===== ATTENTION
HKLM\...\exefile\DefaultIcon: <===== ATTENTION
HKLM\...\exefile\shell\open\command: <===== ATTENTION
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 16%
Total physical RAM: 3970.08 MB
Available physical RAM: 3309.96 MB
Total Virtual: 3970.08 MB
Available Virtual: 3325.55 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:456.37 GB) (Free:456.07 GB) NTFS
Drive e: (2014.09.12_1238) (CDROM) (Total:0.39 GB) (Free:0 GB) UDF
Drive f: (KINGSTON) (Removable) (Total:7.26 GB) (Free:3.89 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.5 GB) (Free:0.5 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: D9789CFD)
Partition: GPT.
========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 7.3 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7.3 GB) - (Type=0C)
==================== End of FRST.txt ============================