Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-07-2016 Ran by DELL OPT 780 QUAD (2016-07-31 16:44:29) Running from C:\Users\DELL OPT 780 QUAD\Desktop Windows 10 Pro Version 1511 (X64) (2016-02-22 15:41:07) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1168797988-15592107-1468597284-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1168797988-15592107-1468597284-503 - Limited - Disabled) DELL OPT 780 QUAD (S-1-5-21-1168797988-15592107-1468597284-1000 - Administrator - Enabled) => C:\Users\DELL OPT 780 QUAD Guest (S-1-5-21-1168797988-15592107-1468597284-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1168797988-15592107-1468597284-1002 - Limited - Enabled) username (S-1-5-21-1168797988-15592107-1468597284-1011 - Administrator - Enabled) => C:\Users\username ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: IObit Malware Fighter (Disabled - Out of date) {4D381C57-3C7A-6F22-07EB-639F49E836D4} AV: Avast Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: IObit Malware Fighter (Enabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D} AS: Avast Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) "Assassin's Creed IV - Black Flag" (HKLM-x32\...\{959CF39B-F3FA-4A80-AECF-8AF6BA639276}_is1) (Version: 1.02.0.0 - ) µTorrent (HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\uTorrent) (Version: 3.4.7.42330 - BitTorrent Inc.) Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\{AA3B06B1-E89A-43C6-A26B-7109DB4BEE7B}) (Version: 12.0.7.148 - Adobe Systems, Inc) Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.0.3 - IObit) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.7 - Sereby Corporation) AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) Assassin's Creed ® III (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.00 - Ubisoft) Assassins Creed III version 5.1 (HKLM-x32\...\{B810D852-DFD6-ACIII-89A5-CC4D47756DAF}_is1) (Version: 5.1 - Black_Box) AutoIt v3.3.14.2 (HKLM-x32\...\AutoItv3) (Version: 3.3.14.2 - AutoIt Team) Avast Antivirus Gratuit (HKLM-x32\...\Avast) (Version: 12.2.2276 - AVAST Software) AVG (HKLM\...\AvgZen) (Version: 1.61.2.12974 - AVG Technologies) AVG Zen (Version: 1.61.9 - AVG Technologies) Hidden Crysis® 2 (HKLM-x32\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.0.0.0 - Electronic Arts) DirectX 9.0c Extra Files (x86, x64) (HKLM\...\{8729E65B-8C12-4A42-B1FE-E4DA7ED52855}_is1) (Version: 1.10.06.0 - Sereby Corporation) DirectX for Managed Code (HKLM\...\{FDF7187F-3960-4BEC-916D-98C9A83E3A68}_is1) (Version: 1.0.0.0 - Sereby Corporation) DuelystLauncher (HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\launcher) (Version: 0.010 - Counterplay Games Inc.) Elsword 1.0 (HKLM-x32\...\Elsword_fr_is1) (Version: 1.0 - Gameforge4d) FMW 1 (Version: 1.82.3 - AVG Technologies) Hidden Gameforge Live 2.0.12 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.12 - Gameforge) Gauntlet Slayer Edition (HKLM-x32\...\Gauntlet Slayer Edition_is1) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.103 - Google Inc.) Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Grim Dawn (HKLM-x32\...\Grim Dawn_is1) (Version: - ) HEX (HKLM-x32\...\{6EDED3CB-CAC5-4200-A534-CCA1732EAF23}_is1) (Version: - Gameforge) Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: - Tonec Inc.) IObit Malware Fighter 4 (HKLM-x32\...\IObit Malware Fighter_is1) (Version: 4.0 - IObit) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.1.0.20 - IObit) Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation) Kingdoms of Amalur Reckoning (HKLM-x32\...\Kingdoms of Amalur Reckoning_is1) (Version: - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Magic Duels (HKLM-x32\...\Steam App 316010) (Version: - Stainless Games Ltd.) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM-x32\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM-x32\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM-x32\...\M979906) (Version: - ) Microsoft .NET Framework 1.1 SP1 (HKLM\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: - ) Microsoft .NET Framework 1.1 SP1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft Office 365 - fr-fr (HKLM\...\O365HomePremRetail - fr-fr) (Version: 16.0.7070.2033 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{CC1DB186-550F-3CFE-A2A9-EBA5E5A34BC1}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{3bcf8c72-b231-4d28-9f39-3405c22d8b5a}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{4549ceb8-695a-42eb-a183-4820d542a15f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Might & Magic: Duel of Champions (HKLM-x32\...\Steam App 256410) (Version: - Blue Byte) Mozilla Firefox 43.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.61.14 - Black Tree Gaming) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7030.1021 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7030.1021 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7030.1021 - Microsoft Corporation) Hidden OpenVPN 2.3.8 (HKLM-x32\...\OpenVPN) (Version: 2.3.8 - ) Orcs Must Die! Unchained (HKLM-x32\...\{8EBA33AF-48E0-4207-A4EE-96029415AD76}_is1) (Version: - Gameforge 4D GmbH) SafeZone Stable 1.51.2220.47 (x32 Version: 1.51.2220.47 - Avast Software) Hidden Saint Seiya Soldiers Soul (HKLM-x32\...\Saint Seiya Soldiers Soul_is1) (Version: - ) Sandboxie 4.20 (64-bit) (HKLM\...\Sandboxie) (Version: 4.20 - Sandboxie Holdings, LLC) SciTE4AutoIt3 15.920.938.0 (HKLM-x32\...\SciTE4AutoIt3) (Version: 15.920.938.0 - Jos van der Zande) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.3 - IObit) TAP-Windows 9.21.1 (HKLM\...\TAP-Windows) (Version: 9.21.1 - ) The Elder Scrolls V Skyrim Dragonborn (c) Bethesda Softworks version 1 (HKLM-x32\...\The Elder Scrolls V Skyrim Dragonborn (c) Bethes~300CD4A2_is1) (Version: 1 - ) The Elder Scrolls V Skyrim version 1.0 (HKLM-x32\...\{5EFE0504-0BC4-11E1-8EDD-B32C4824019B}_is1) (Version: 1.0 - Bethesda Softworks) The Incredible Adventures of Van Helsing version 5.1 (HKLM-x32\...\{0B1CDC9A-B4DE-44D8-91D6-0BFB321BC879}_is1) (Version: 5.1 - Black_Box) Torchlight II (c) Runic Games version 1 (HKLM-x32\...\Torchlight II (c) Runic Games_is1) (Version: 1 - ) Torchlight II version 1.25.5.2 (HKLM-x32\...\Torchlight II_is1) (Version: 1.25.5.2 - Runic Games) Transmod 2 v0.8a beta (HKLM-x32\...\{F0BEAB42-1983-4DE9-0606-65D2B4C0D4C2}_is1) (Version: 0.8a beta - Torchlight FR Trad Team) TunnelBear (HKLM-x32\...\{90e7dc26-e7df-406b-af23-61df6728a9f6}) (Version: 2.3.25.0 - TunnelBear) TunnelBear (x32 Version: 2.3.25.0 - TunnelBear) Hidden Unity Web Player (x64) (All users) (HKLM\...\UnityWebPlayer) (Version: 4.6.6f2 - Unity Technologies ApS) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Warframe (HKLM-x32\...\{AAC73EE2-5111-449B-B36B-423AD24D47F6}) (Version: 1.0.0 - Digital Extremes) WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH) WinRAR 5.31 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1168797988-15592107-1468597284-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\DELL OPT 780 QUAD\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0B6CAB59-25AC-4F7F-BA6F-E0347EF53436} - System32\Tasks\SafeZone scheduled Autoupdate 1458747763 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-07-25] (Avast Software) Task: {0D7142F6-64B8-4559-A603-251411C3E182} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-07-30] (Microsoft Corporation) Task: {1684CFA4-2D5B-4F7A-85F3-B9CA3523B509} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-12] (Adobe Systems Incorporated) Task: {4F213B09-7B27-41DC-9AF7-1D1B88C876AF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-22] (Google Inc.) Task: {5E322CA8-C3E6-4DB8-BC6C-C1CAC9D117A6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-22] (Google Inc.) Task: {6FC34B2C-A8DF-4263-9B51-7AEC0971D5E2} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe Task: {954F4682-BBCF-4757-BEC8-0A7E013BEAFD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-07-29] (AVAST Software) Task: {ABE3DDD2-B34E-4AAA-A994-CA0552D9CCB2} - System32\Tasks\Uninstaller_SkipUac_DELL_OPT_780_QUAD => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-10-30] (IObit) Task: {B331DB12-E6D6-4ECE-B495-ACD3894F7FFE} - System32\Tasks\ASC9_SkipUac_DELL OPT 780 QUAD => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2015-11-10] (IObit) Task: {B730F648-9938-44C6-89A7-9CBC1A484958} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-25] (Microsoft Corporation) Task: {B8E03065-279B-491C-A033-8B08D3A13DB8} - \ASC9_PerformanceMonitor -> No File <==== ATTENTION Task: {B956599A-6D68-4365-BD34-DF986B5AE76B} - \avast! Windows 10 Start Menu helper -> No File <==== ATTENTION Task: {DA17C17C-1799-48C3-A8D6-3C0160B36269} - \CCleanerSkipUAC -> No File <==== ATTENTION Task: {E9494D1F-E2F3-411E-8B4F-8FED3525D8C5} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-25] (Microsoft Corporation) Task: {F1C667B4-8F61-4998-82E8-38A5F057C050} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-07-13] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\ASC9_SkipUac_DELL OPT 780 QUAD.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_DELL_OPT_780_QUAD.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\DELL OPT 780 QUAD\Documents\ConnexionEGK - Raccourci (2).lnk -> C:\Users\DELL OPT 780 QUAD\Documents\ConnexionEGK.bat () Shortcut: C:\Users\DELL OPT 780 QUAD\Documents\ConnexionEGK - Raccourci.lnk -> C:\Users\DELL OPT 780 QUAD\Documents\ConnexionEGK.bat () Shortcut: C:\Users\DELL OPT 780 QUAD\Desktop\ConnexionEGK - Raccourci.lnk -> C:\Users\DELL OPT 780 QUAD\Documents\ConnexionEGK.bat () ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-07-13 17:18 - 2016-07-01 05:48 - 02656408 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-07-13 17:18 - 2016-07-01 05:48 - 02656408 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-03-04 15:45 - 2015-12-07 05:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-13 17:20 - 2016-07-01 04:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-07-13 17:18 - 2016-07-01 04:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-07-13 17:18 - 2016-07-01 04:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-07-13 17:18 - 2016-07-01 04:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-07-13 17:18 - 2016-07-01 04:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-04-19 13:13 - 2016-04-19 14:31 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-05-01 11:22 - 2016-05-01 15:08 - 10256384 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll 2016-06-28 05:54 - 2016-06-28 05:55 - 03790336 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1605.1582.0_x64__8wekyb3d8bbwe\Calculator.exe 2015-12-16 09:40 - 2015-12-16 09:40 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1605.1582.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-06-03 10:01 - 2016-06-03 10:07 - 00017920 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-06-03 10:01 - 2016-06-03 10:07 - 13105152 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-06-03 10:01 - 2016-06-03 10:06 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2016-03-05 11:10 - 2016-03-05 11:27 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-07-29 03:30 - 2016-07-29 03:30 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-07-30 11:41 - 2016-07-30 11:41 - 03002880 _____ () C:\Program Files\AVAST Software\Avast\defs\16073000\algo.dll 2016-07-29 03:30 - 2016-07-29 03:30 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2016-07-31 15:31 - 2016-07-31 15:31 - 03002880 _____ () C:\Program Files\AVAST Software\Avast\defs\16073100\algo.dll 2015-11-22 13:21 - 2015-12-23 17:17 - 00625440 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll 2015-11-22 13:21 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madExcept_.bpl 2015-11-22 13:21 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madBasic_.bpl 2015-11-22 13:21 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madDisAsm_.bpl 2016-07-29 03:31 - 2016-07-29 03:31 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-11-22 13:21 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl 2015-11-22 13:21 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl 2015-11-22 13:21 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl 2016-04-19 13:13 - 2016-04-19 14:31 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 13:13 - 2016-04-19 14:31 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-06-17 21:49 - 2016-06-15 10:15 - 01745560 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libglesv2.dll 2016-06-17 21:49 - 2016-06-15 10:15 - 00091288 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\1001movie.com -> 1001movie.com IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\1001night.biz -> 1001night.biz IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\100gal.net -> 100gal.net IE restricted site: HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\100sexlinks.com -> 100sexlinks.com There are 4787 more sites. ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-11-22 07:07 - 2015-11-22 07:05 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1168797988-15592107-1468597284-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\DELL OPT 780 QUAD\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "IObit Malware Fighter" HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\StartupApproved\Run: => "Advanced SystemCare 9" HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\StartupApproved\Run: => "IDMan" HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\StartupApproved\Run: => "SandboxieControl" HKU\S-1-5-21-1168797988-15592107-1468597284-1000\...\StartupApproved\Run: => "CyberGhost" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{F6A6CA00-2EC0-4BA9-9646-11B0D8EA165A}] => (Allow) C:\Users\DELL OPT 780 QUAD\Desktop\asdjhy6as1.exe FirewallRules: [{315A246C-6B1B-4B22-A0E4-2CE2C5E9E4B1}] => (Allow) C:\Users\DELL OPT 780 QUAD\Desktop\asdjhy6as1.exe FirewallRules: [{D94A4D4C-FF33-4348-9C6D-B03CC49F7040}] => (Allow) C:\Users\DELL OPT 780 QUAD\Desktop\asdjhy6as1.exe FirewallRules: [{61CF1321-CD75-4C45-8B13-0DCC9E7BDC50}] => (Allow) C:\Users\DELL OPT 780 QUAD\Desktop\asdjhy6as1.exe FirewallRules: [{429424E1-3BC6-46A1-A209-0CF4142CB11C}] => (Allow) C:\Program Files (x86)\GameforgeLive\Games\FRA_fra\Elsword\data\x2.exe FirewallRules: [{3FAF8658-7679-4C57-A66D-E54E4895B71D}] => (Allow) C:\Program Files (x86)\GameforgeLive\Games\FRA_fra\Elsword\data\x2.exe FirewallRules: [{4576EB4C-0637-411B-A154-1B332A56CAB8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [TCP Query User{BE4B6048-C01D-48E6-9709-AE7AB347C35B}C:\users\dell opt 780 quad\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\dell opt 780 quad\appdata\roaming\utorrent\utorrent.exe FirewallRules: [UDP Query User{A56C98B7-2BE3-4BA8-ACD1-3B324A963962}C:\users\dell opt 780 quad\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\dell opt 780 quad\appdata\roaming\utorrent\utorrent.exe ==================== Restore Points ========================= 13-07-2016 22:27:36 Windows Update 18-07-2016 12:41:43 Windows Update 21-07-2016 19:28:32 TunnelBear 30-07-2016 12:50:06 zoek.exe restore point ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/31/2016 04:25:18 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (07/31/2016 03:40:08 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (07/31/2016 12:56:04 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Le programme chrome.exe version 51.0.2704.103 a cessé d'interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l'historique du problème dans le panneau de configuration Sécurité et maintenance. ID de processus : 1a9c Heure de début : 01d1eaab0c07b251 Heure de fin : 8 Chemin d'accès de l'application : C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ID de rapport : 294a3104-56b1-11e6-b835-f04da220cbcf Nom complet du package défaillant : ID de l'application relative au package défaillant : Error: (07/30/2016 10:22:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante SkypeHost.exe, version : 10.1.2123.36, horodatage : 0x56eb679c Nom du module défaillant : npggNT.des, version : 2016.4.11.1, horodatage : 0x570b4cf8 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000106cb ID du processus défaillant : 0x24a8 Heure de début de l’application défaillante : 0xSkypeHost.exe0 Chemin d’accès de l’application défaillante : SkypeHost.exe1 Chemin d’accès du module défaillant: SkypeHost.exe2 ID de rapport : SkypeHost.exe3 Nom complet du package défaillant : SkypeHost.exe4 ID de l’application relative au package défaillant : SkypeHost.exe5 Error: (07/30/2016 10:22:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante SkypeHost.exe, version : 10.1.2123.36, horodatage : 0x56eb679c Nom du module défaillant : npggNT.des, version : 2016.4.11.1, horodatage : 0x570b4cf8 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000106cb ID du processus défaillant : 0x17d8 Heure de début de l’application défaillante : 0xSkypeHost.exe0 Chemin d’accès de l’application défaillante : SkypeHost.exe1 Chemin d’accès du module défaillant: SkypeHost.exe2 ID de rapport : SkypeHost.exe3 Nom complet du package défaillant : SkypeHost.exe4 ID de l’application relative au package défaillant : SkypeHost.exe5 Error: (07/30/2016 10:22:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante SkypeHost.exe, version : 10.1.2123.36, horodatage : 0x56eb679c Nom du module défaillant : npggNT.des, version : 2016.4.11.1, horodatage : 0x570b4cf8 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000106cb ID du processus défaillant : 0x1a54 Heure de début de l’application défaillante : 0xSkypeHost.exe0 Chemin d’accès de l’application défaillante : SkypeHost.exe1 Chemin d’accès du module défaillant: SkypeHost.exe2 ID de rapport : SkypeHost.exe3 Nom complet du package défaillant : SkypeHost.exe4 ID de l’application relative au package défaillant : SkypeHost.exe5 Error: (07/30/2016 10:22:42 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante SkypeHost.exe, version : 10.1.2123.36, horodatage : 0x56eb679c Nom du module défaillant : npggNT.des, version : 2016.4.11.1, horodatage : 0x570b4cf8 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000106cb ID du processus défaillant : 0x14f4 Heure de début de l’application défaillante : 0xSkypeHost.exe0 Chemin d’accès de l’application défaillante : SkypeHost.exe1 Chemin d’accès du module défaillant: SkypeHost.exe2 ID de rapport : SkypeHost.exe3 Nom complet du package défaillant : SkypeHost.exe4 ID de l’application relative au package défaillant : SkypeHost.exe5 Error: (07/30/2016 10:22:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DELLOPT780QUAD) Description: Échec de l’activation de l’application Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 avec l’erreur : -2147023170 Pour plus d’informations, voir le journal Microsoft-Windows-TWinUI/Opérationnel. Error: (07/30/2016 10:22:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante SkypeHost.exe, version : 10.1.2123.36, horodatage : 0x56eb679c Nom du module défaillant : npggNT.des, version : 2016.4.11.1, horodatage : 0x570b4cf8 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000106cb ID du processus défaillant : 0x165c Heure de début de l’application défaillante : 0xSkypeHost.exe0 Chemin d’accès de l’application défaillante : SkypeHost.exe1 Chemin d’accès du module défaillant: SkypeHost.exe2 ID de rapport : SkypeHost.exe3 Nom complet du package défaillant : SkypeHost.exe4 ID de l’application relative au package défaillant : SkypeHost.exe5 Error: (07/30/2016 10:22:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante SkypeHost.exe, version : 10.1.2123.36, horodatage : 0x56eb679c Nom du module défaillant : npggNT.des, version : 2016.4.11.1, horodatage : 0x570b4cf8 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000106cb ID du processus défaillant : 0x1b7c Heure de début de l’application défaillante : 0xSkypeHost.exe0 Chemin d’accès de l’application défaillante : SkypeHost.exe1 Chemin d’accès du module défaillant: SkypeHost.exe2 ID de rapport : SkypeHost.exe3 Nom complet du package défaillant : SkypeHost.exe4 ID de l’application relative au package défaillant : SkypeHost.exe5 System errors: ============= Error: (07/31/2016 01:51:56 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la connexion du service Sync Host_42bac. Error: (07/31/2016 01:51:56 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Le Gestionnaire de services de contrôle a essayé d’entreprendre une action corrective (Restart the service) après la fin inattendue du service User Data Storage_42bac, mais cette action a échoué en raison de l’erreur suivante : %%1056 = Une instance du service s’exécute déjà. Error: (07/31/2016 01:51:56 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la connexion du service User Data Storage_42bac. Error: (07/31/2016 01:51:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Le service User Data Access_42bac s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 10000 millisecondes : Restart the service. Error: (07/31/2016 01:51:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Le service User Data Storage_42bac s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 10000 millisecondes : Restart the service. Error: (07/31/2016 01:51:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Le service Contact Data_42bac s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 10000 millisecondes : Restart the service. Error: (07/31/2016 01:51:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Le service Sync Host_42bac s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 10000 millisecondes : Restart the service. Error: (07/31/2016 01:51:46 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (07/30/2016 09:03:06 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{3185A766-B338-11E4-A71E-12E3F512A338}{7006698D-2974-4091-A424-85DD0B909E23}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable Error: (07/30/2016 07:29:54 PM) (Source: DCOM) (EventID: 10010) (User: DELLOPT780QUAD) Description: App.AppXck5aaxyarfx8gxrgfk6pvakmmxeqvepc.mca CodeIntegrity: =================================== Date: 2016-07-30 15:45:36.060 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-07-27 21:52:04.534 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-07-20 21:14:13.959 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-07-14 14:45:07.698 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-07-14 09:51:14.386 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-07-14 09:46:44.962 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-21 06:19:32.160 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-18 19:38:04.311 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-18 12:13:30.167 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-16 12:12:31.961 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Quad CPU Q9650 @ 3.00GHz Percentage of memory in use: 61% Total physical RAM: 4029.59 MB Available physical RAM: 1562.23 MB Total Virtual: 5109.59 MB Available Virtual: 2185.05 MB ==================== Drives ================================ Drive c: (OS W7) (Fixed) (Total:465.22 GB) (Free:316.48 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: CA68C71F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.2 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ==================== End of Addition.txt ============================