Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-05-2015 Ran by admin at 2015-05-04 16:57:17 Running from C:\Users\admin\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= admin (S-1-5-21-3769467500-3583379074-2392525900-1002 - Administrator - Enabled) => C:\Users\admin Administrator (S-1-5-21-3769467500-3583379074-2392525900-500 - Administrator - Disabled) Guest (S-1-5-21-3769467500-3583379074-2392525900-501 - Limited - Disabled) localAdmin (S-1-5-21-3769467500-3583379074-2392525900-1003 - Limited - Enabled) => C:\Users\localAdmin ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 8.2.4 - Hewlett-Packard) Hidden Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) AirPort (HKLM-x32\...\{AA68AAAE-41F0-40B5-8896-5947F5FD6889}) (Version: 5.6.1.2 - Apple Inc.) Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Bing Bar (HKLM-x32\...\{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) boostwebapp (HKLM-x32\...\{B89F2F80-17D7-471B-b091-05DF6A9039CA}) (Version: 1.1.0.31 - boostwebapp) Citrix Online Launcher (HKLM-x32\...\{F17C3DC2-2ACA-4B0E-BDBF-ACE61B14E7CD}) (Version: 1.0.183 - Citrix) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Backup and Recovery - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 1.6.0.3 - Dell Inc.) Dell Backup and Recovery (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.6.0.3 - Dell Inc.) Dell Digital Delivery (HKLM-x32\...\{BC8233D8-59BA-4D40-92B9-4FDE7452AA8B}) (Version: 3.0.3999.0 - Dell Products, LP) Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 17.0.11.2 - Synaptics Incorporated) DSC/AA Factory Installer (Version: 3.4.6299.48 - PC-Doctor, Inc.) Hidden Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden HP LaserJet 200 color MFP M276 (HKLM-x32\...\{CC38C23C-7824-4DBB-AC73-997CD0BBFEC7}) (Version: 5.0.14057.1503 - Hewlett-Packard) HP Support Solutions Framework (HKLM-x32\...\{348A1F5B-07B3-4436-9A47-FFE44EFE856E}) (Version: 11.51.0004 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) hpbDSService (x32 Version: 002.002.07399 - Hewlett-Packard) Hidden hpbM276DSService (x32 Version: 001.001.05874 - Hewlett-Packard) Hidden HPDXP (x32 Version: 3.0.26.8 - HP) Hidden HPLaserJet200color-MFPM276_HelpLearnCenter_SI (HKLM-x32\...\{0F044C7A-6EE1-4F03-90AC-329AAF2FCF12}) (Version: 1.01.0000 - Hewlett-Packard) HPLJDXPHelper (x32 Version: 020.021.004 - HP) Hidden HPLJUTCore (x32 Version: 004.005.0001 - HP) Hidden HPLJUTM276 (x32 Version: 3.00.0003 - HP) Hidden hppFaxDrvM276 (x32 Version: 003.000.00002 - Hewlett-Packard) Hidden hppLaserJetService (x32 Version: 009.027.00856 - Hewlett-Packard) Hidden hppM276LaserJetService (x32 Version: 001.019.00639 - Hewlett-Packard) Hidden hppSendFaxM276 (x32 Version: 003.000.00002 - Hewlett-Packard) Hidden hpStatusAlerts (x32 Version: 050.037.00142 - Hewlett Packard) Hidden hpStatusAlertsM276 (x32 Version: 050.034.00131 - Hewlett-Packard) Hidden Intel Experience Center - Configuration (x32 Version: 1.7.0.179 - Intel) Hidden Intel(R) Experience Center Desktop Software (HKLM-x32\...\{3608ec0a-56b4-4d9d-b038-9b3e51d72582}) (Version: 1.7.0.179 - Intel) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3277 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 3.0.1335.5) (HKLM\...\{302600C1-6BDF-4FD1-1307-148929CC1385}) (Version: 3.1.1307.0362 - Intel Corporation) Intel(R) Rapid Start Technology (HKLM-x32\...\{3D073343-CEEB-4ce7-85AC-A69A7631B5D6}) (Version: 3.0.0.1056 - Intel Corporation) Intel(R) Smart Connect Technology (HKLM\...\{9B5FD763-5074-474C-B898-24567E6450C8}) (Version: 4.2.40.2439 - Intel Corporation) Intel(R) Virtual Buttons (HKLM-x32\...\1992736F-C90A-481C-B21B-EE34CAD07387) (Version: 1.0.0.13 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{75895d95-3e4b-42b6-8440-97a0e234aeb3}) (Version: 17.0.2 - Intel Corporation) iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) LJDXPHelperUI (x32 Version: 020.021.004 - HP) Hidden Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visio Professional 2013 (HKLM-x32\...\Office15.VISPRO) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Firefox 37.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 en-US)) (Version: 37.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.4.6299.48 - PC-Doctor, Inc.) NXPProximityInstaller (HKLM-x32\...\NXPProximityInstaller) (Version: 6.5.2.0 - NXP Semiconductors) Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Pentair ScreenLogic (HKLM-x32\...\{D10B9BEF-B4DF-4719-8617-E23B1994A9D7}) (Version: 5.2.580.0 - Pentair) PocketCloud (HKLM-x32\...\{D9752C7D-A595-4687-A0D5-362E9C311C55}) (Version: 2.7.14 - Wyse Technology) Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.16.001 - Dell Inc.) QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7032 - Realtek Semiconductor Corp.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{90150000-0051-0000-0000-0000000FF1CE}_Office15.VISPRO_{8D2E04ED-3350-4ECE-9D6E-3BC9A9A93A47}) (Version: - Microsoft) Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.4 - Sophos Limited) System Requirements Lab for Intel (HKLM-x32\...\{04C4B49D-45D9-4A28-9ED1-B45CBD99B8C7}) (Version: 4.5.24.0 - Husdawg, LLC) Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUS_{BF1B3F01-93F3-4B83-93DB-132EB1AED259}) (Version: - Microsoft) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 23-04-2015 15:31:47 Scheduled Checkpoint 02-05-2015 12:27:03 Scheduled Checkpoint 04-05-2015 12:01:42 Installed Amazon Unbox Video ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {098FB0E7-6BC9-4777-80A9-508686258A06} - \PCDEventLauncherTask No Task File <==== ATTENTION Task: {1DF918A7-C1C1-4771-AFBC-E8EB183FEF6A} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {21E42583-F5C7-40F2-859B-56C15A426F07} - System32\Tasks\Intel(R) Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2013-09-08] (Intel) Task: {2E6A42AF-0A8D-4096-ADC2-07168D178054} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {41A5D631-D35D-4D6C-A4A8-3BA3B402CE28} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {51C75D18-2A83-4C3D-89BB-D1821CBCBF6E} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation) Task: {58F5A3A8-562D-49BB-A3F5-8C9EDBBC5231} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {5E64357F-6C43-4A29-9DE1-38BB098B62EC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-01] (Google Inc.) Task: {6063545E-FBA8-4673-A041-83C0812D2041} - System32\Tasks\PocketCloudVirtualChannel => C:\Program Files (x86)\Wyse\PocketCloud\WPCRDPVirtualChannelServer.exe [2013-08-22] () Task: {6761C8E6-7247-4921-8E00-737545C10468} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {75A901B4-90BA-42FB-A281-FFD164326B1E} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [2012-06-14] (Hewlett Packard) Task: {7E408E18-A48B-4006-AE95-040E858BFF4A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-01] (Google Inc.) Task: {8417F500-DF9C-4BBE-BFF9-E100D1C6BD6B} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation) Task: {867B7131-C103-4CDE-A7CB-404919AA396C} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-08-27] (Synaptics Incorporated) Task: {8804CF7D-2557-4F56-B288-9121E59B0D15} - System32\Tasks\PocketCloud => C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe [2013-08-22] () Task: {90679CE6-87FE-4CE7-B24C-BD689AB191B8} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe Task: {99456ABE-2322-400B-96AE-FA9C7D641401} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {9E28E560-E85A-4711-AA60-419E89C8840E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation) Task: {AABA3FA7-6D8F-41E5-A268-481811E08430} - \Optimize Start Menu Cache Files-S-1-5-21-3769467500-3583379074-2392525900-1002 No Task File <==== ATTENTION Task: {B1D0C745-1E4C-4301-B702-7AD2FB6AA01D} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation) Task: {B2336F9C-2C46-46D0-A9F1-91351DEBD662} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {B37A962E-C8F7-47C3-9694-7D32B7015C36} - \Optimize Start Menu Cache Files-S-1-5-21-3203721793-3198379332-896013655-6197 No Task File <==== ATTENTION Task: {B6CC475F-0B16-44A3-BB05-12D188819577} - System32\Tasks\PocketCloudUpdater => C:\Program Task: {C04F3477-8263-4F39-8271-4EBF704587BF} - \PCDoctorBackgroundMonitorTask No Task File <==== ATTENTION Task: {C69E6A07-0922-4626-8C16-931C588045C8} - \Optimize Start Menu Cache Files-S-1-5-21-3769467500-3583379074-2392525900-1001 No Task File <==== ATTENTION Task: {CE10F1A3-D676-4E25-A041-B09505A238B3} - System32\Tasks\Microsoft Office 15 Sync Maintenance for CREDERA-tsutton TSutton-XPS12.credera.com => C:\Program Files (x86)\Microsoft Office\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation) Task: {DD47A643-9ED1-4547-BE23-B2DE08922958} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-23] (Microsoft Corporation) Task: {E6FDDE11-B8E2-42A3-8C69-1B73B766B08F} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {E7444820-D0D9-4ECA-A124-1958883F8D28} - System32\Tasks\G2MUpdateTask-S-1-5-21-3203721793-3198379332-896013655-5752 => C:\Users\tsutton\AppData\Local\Citrix\GoToMeeting\2553\g2mupdate.exe [2015-04-16] (Citrix Online, a division of Citrix Systems, Inc.) Task: {EC23A670-2905-48A4-BC50-A8F3708A077D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-04-16] (Microsoft Corporation) Task: {ECD111C8-6F1A-456E-A854-BA12C57F694D} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} Task: {EFF143AB-15DF-497A-92D5-9B898D4092A7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation) Task: {F270CD14-D6D4-4695-9B6A-93F9BD7BAC5B} - System32\Tasks\Microsoft Office 15 Sync Maintenance for {a3a8717c-255a-4d6b-88be-a62a6f2ceb41} TSutton-XPS12.credera.com => C:\Program Files (x86)\Microsoft Office\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation) Task: C:\Windows\Tasks\eWIXeY4wGiRJ.job => C:\Users\tsutton\AppData\Roaming\eWIXeY4wGiRJ.exe <==== ATTENTION Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3203721793-3198379332-896013655-5752.job => C:\Users\tsutton\AppData\Local\Citrix\GoToMeeting\2553\g2mupdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2013-08-12 22:06 - 2013-08-12 22:06 - 00198120 _____ () c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe 2013-08-12 22:06 - 2013-08-12 22:06 - 00054760 _____ () c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll 2013-08-12 22:06 - 2013-08-12 22:06 - 00034792 _____ () c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll 2015-05-04 13:03 - 2015-05-04 13:03 - 00408576 _____ () c:\windows\mtnj.exe 2013-08-22 14:40 - 2013-08-22 14:40 - 00016176 _____ () C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe 2013-08-22 14:40 - 2013-08-22 14:40 - 00040240 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherServiceLib.dll 2013-08-22 14:40 - 2013-08-22 14:40 - 00046384 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherHelperLib.dll 2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2013-11-16 06:21 - 2013-08-19 13:21 - 00020256 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIcon.dll 2013-11-16 06:21 - 2013-08-19 13:21 - 00019232 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayNotBackuped.dll 2014-07-31 12:16 - 2014-07-31 12:16 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-07-31 12:16 - 2014-07-31 12:16 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-11-24 12:39 - 2014-11-24 12:39 - 00155528 _____ () C:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll 2013-11-16 06:15 - 2013-09-11 16:58 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\tsutton\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Zutadye => ""="service" ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, the associated entry will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3769467500-3583379074-2392525900-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\dell\Wallpaper_Murcielago_FINAL_RGB.JPG DNS Servers: 172.16.8.200 - 172.16.8.207 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (whitelisted) =============== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{95556FD3-8EF3-4A1D-AD5C-2F07DBD159AE}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe FirewallRules: [{23FF3FBE-B7AE-42C7-98D4-66343A1C4330}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\AetherWindowsService.exe FirewallRules: [{9AE2909C-2970-42D2-82D5-39B226B171F9}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe FirewallRules: [{E2728452-2140-46C6-9062-DADA6864FBA6}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{0381D1C5-AAAD-4DC3-9950-BFBAC50F775D}] => (Allow) LPort=2869 FirewallRules: [{C758A127-4891-4633-9C29-E2C2768DEE32}] => (Allow) LPort=1900 FirewallRules: [{5A992B7F-B104-410E-A922-C972C66139FF}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{D1BA8276-EEC3-4A36-9B22-CEC5F04DCD8E}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [{84509367-EEB0-492A-BF60-A7D883E61C94}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe FirewallRules: [{B58AC0EB-BBA2-40B2-B89E-6DC753DF916B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe FirewallRules: [{B41160AB-0C63-4C4C-A79C-B15BB9A249C9}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{0A35A761-60CB-4E46-B67A-52961205C3CE}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{29F1EC5A-4A6D-49FE-BFE8-E3273CD9A9D9}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\outlook.exe FirewallRules: [{B993F407-BFDE-4E22-AC6E-5FFE22F71804}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{D1175C85-E274-47C9-A1FF-65C0D9D46464}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{533B0C90-13CC-4E4A-B0AD-18EEABD98778}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{F53CC382-F9DE-4505-9F6E-0EC4E26F345B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{29765901-2430-4E5B-8452-1BC783F9D576}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe FirewallRules: [{04512D54-743C-4E7F-859D-A7C37470F283}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe FirewallRules: [{BE282F58-843B-4F96-A10E-33966667E393}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{1158CF74-C093-462E-92FA-3B15903BC2D7}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{59B4F5E6-E2E8-47E3-9681-C42FACDD5A97}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe FirewallRules: [{476791AB-63CA-4F99-BF2D-4503CF84B1F2}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe FirewallRules: [{858F1D0F-15DA-42FC-B92B-38057F76D7CE}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{3BC1B3AC-4B1A-4B5F-A10D-A47FB5C48454}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{0F4C34FA-DC21-44AF-8DFA-3EF4B12B8994}] => (Allow) C:\Program Files (x86)\AirPort\APAgent.exe FirewallRules: [{F218B951-A7AE-4195-983D-6786D02B425E}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{FECF8AB7-C6AD-4768-A8F2-2245650024F5}] => (Allow) C:\Program Files (x86)\HP\HP LaserJet 200 color MFP M276\bin\FaxApplications.exe FirewallRules: [{CA37D98F-740C-4729-9662-223A1905B8C3}] => (Allow) C:\Program Files (x86)\HP\HP LaserJet 200 color MFP M276\bin\DigitalWizards.exe FirewallRules: [{C19F3741-F90B-4B46-8C3D-ECAFB4AF8364}] => (Allow) C:\Program Files (x86)\HP\HP LaserJet 200 color MFP M276\Bin\HPNetworkCommunicator.exe FirewallRules: [{DA1B8049-DA1A-42F7-A2DE-0EE001E56BA3}] => (Allow) C:\Program Files (x86)\HP\HP LaserJet 200 color MFP M276\bin\EWSProxy.exe FirewallRules: [{C0FCAA8A-FD3F-4427-8E4D-EA7411E9ABA1}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe FirewallRules: [{33BA5678-B76C-4114-8382-C507CE1D7220}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{4C13324E-89A3-4B9C-B3FB-AB4526875CF6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{41285E9F-7455-4BCC-9507-F5A4AAE6BBFA}C:\program files (x86)\airport\aputil.exe] => (Block) C:\program files (x86)\airport\aputil.exe FirewallRules: [UDP Query User{BD995F1D-E380-4A53-9F34-65F903DD068F}C:\program files (x86)\airport\aputil.exe] => (Block) C:\program files (x86)\airport\aputil.exe FirewallRules: [TCP Query User{899A5A33-9ED4-444A-B524-8A7DC9EE89F8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{BD549235-2FBD-4165-9809-FDE717898D3B}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{F1BE8176-C14C-4F99-85AA-86F3CF0D8A53}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\mohqaban.EXE FirewallRules: [{552B8AD2-7BE8-456C-9B23-177460D67ABF}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\mohqaban.EXE FirewallRules: [{41A75781-82B4-486C-9F88-236303C9DA9D}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\mohqaban.EXE FirewallRules: [{FB276827-B226-47C3-988A-7E60A0BCCE8D}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\mohqaban.EXE FirewallRules: [{CBA1867D-88AB-4AD7-800F-074C70EAAF25}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\mohqaban.EXE ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/04/2015 04:53:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mohqdban.exe, version: 0.0.0.0, time stamp: 0x5547996f Faulting module name: mohqdbanu.dll, version: 0.0.0.0, time stamp: 0x55479934 Exception code: 0xc0000005 Fault offset: 0x0000a176 Faulting process id: 0x10d0 Faulting application start time: 0xmohqdban.exe0 Faulting application path: mohqdban.exe1 Faulting module path: mohqdban.exe2 Report Id: mohqdban.exe3 Faulting package full name: mohqdban.exe4 Faulting package-relative application ID: mohqdban.exe5 Error: (05/04/2015 04:53:53 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program mohqdban.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 10d0 Start Time: 01d086b48b80eaa8 Termination Time: 4294967295 Application Path: C:\ProgramData\boostwebapp\1.1.0.31\mohqdban.exe Report Id: 0d194d92-f2a8-11e4-82d4-5c514f501355 Faulting package full name: Faulting package-relative application ID: Error: (05/04/2015 04:32:23 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: Explorer.EXE Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: exception code c0000005, exception address 00007FFEE828B179 Error: (05/04/2015 03:22:21 PM) (Source: ISCTAgent) (EventID: 1000) (User: ) Description: ISCT - netDetect::AOACWLANProset::LocateAdapters Net Detect: Net Detect Supported Error Getting Adapter List Error=0x80040302\n Error: (05/04/2015 03:22:21 PM) (Source: ISCTAgent) (EventID: 1000) (User: ) Description: ISCT - netDetect::AOACWLANProset::LocateAdapters Net Detect: Net Detect Supported Error Getting Adapter List Error=0x80040302\n Error: (05/04/2015 03:06:14 PM) (Source: MsiInstaller) (EventID: 11606) (User: TSutton-XPS12) Description: Product: Sophos Virus Removal Tool -- Error 1606.Could not access network location data. Error: (05/04/2015 03:06:12 PM) (Source: MsiInstaller) (EventID: 11606) (User: TSutton-XPS12) Description: Product: Sophos Virus Removal Tool -- Error 1606.Could not access network location data. Error: (05/04/2015 03:04:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mohqdban.exe, version: 0.0.0.0, time stamp: 0x5547996f Faulting module name: mohqdbanu.dll, version: 0.0.0.0, time stamp: 0x55479934 Exception code: 0xc0000005 Fault offset: 0x0000a176 Faulting process id: 0x1584 Faulting application start time: 0xmohqdban.exe0 Faulting application path: mohqdban.exe1 Faulting module path: mohqdban.exe2 Report Id: mohqdban.exe3 Faulting package full name: mohqdban.exe4 Faulting package-relative application ID: mohqdban.exe5 Error: (05/04/2015 01:01:50 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program unbox-video-player-2.2.0.153-en.exe version 12.0.0.49974 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 10d4 Start Time: 01d08693ee027a9d Termination Time: 4294967295 Application Path: C:\Users\tsutton\Desktop\unbox-video-player-2.2.0.153-en.exe Report Id: a2a21a49-f287-11e4-82bd-5c514f501355 Faulting package full name: Faulting package-relative application ID: Error: (05/04/2015 00:57:58 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program unbox-video-player-2.2.0.153-en.exe version 12.0.0.49974 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: bc0 Start Time: 01d0868bfc20ca66 Termination Time: 4294967295 Application Path: C:\Users\tsutton\Desktop\unbox-video-player-2.2.0.153-en.exe Report Id: 184dd6c8-f287-11e4-82bd-5c514f501355 Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (05/04/2015 04:51:49 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1055) (User: NT AUTHORITY) Description: The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: a) Name Resolution failure on the current domain controller. b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller). Error: (05/04/2015 04:51:27 PM) (Source: DCOM) (EventID: 10005) (User: TSutton-XPS12) Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC} Error: (05/04/2015 04:47:39 PM) (Source: DCOM) (EventID: 10005) (User: TSutton-XPS12) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (05/04/2015 04:47:39 PM) (Source: DCOM) (EventID: 10005) (User: TSutton-XPS12) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (05/04/2015 04:47:38 PM) (Source: DCOM) (EventID: 10005) (User: TSutton-XPS12) Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC} Error: (05/04/2015 04:47:32 PM) (Source: DCOM) (EventID: 10005) (User: TSutton-XPS12) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (05/04/2015 04:47:32 PM) (Source: DCOM) (EventID: 10005) (User: TSutton-XPS12) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (05/04/2015 04:47:30 PM) (Source: DCOM) (EventID: 10005) (User: TSutton-XPS12) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (05/04/2015 04:47:30 PM) (Source: DCOM) (EventID: 10005) (User: TSutton-XPS12) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (05/04/2015 04:47:30 PM) (Source: DCOM) (EventID: 10005) (User: TSutton-XPS12) Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Microsoft Office Sessions: ========================= Error: (05/04/2015 04:53:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: mohqdban.exe0.0.0.05547996fmohqdbanu.dll0.0.0.055479934c00000050000a17610d001d086b48b80eaa8C:\ProgramData\boostwebapp\1.1.0.31\mohqdban.exeC:\ProgramData\boostwebapp\1.1.0.31\mohqdbanu.dll0dc26340-f2a8-11e4-82d4-5c514f501355 Error: (05/04/2015 04:53:53 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: mohqdban.exe0.0.0.010d001d086b48b80eaa84294967295C:\ProgramData\boostwebapp\1.1.0.31\mohqdban.exe0d194d92-f2a8-11e4-82d4-5c514f501355 Error: (05/04/2015 04:32:23 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: Explorer.EXE Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: exception code c0000005, exception address 00007FFEE828B179 Error: (05/04/2015 03:22:21 PM) (Source: ISCTAgent) (EventID: 1000) (User: ) Description: ISCT - netDetect::AOACWLANProset::LocateAdapters Net Detect: Net Detect Supported Error Getting Adapter List Error=0x80040302\n Error: (05/04/2015 03:22:21 PM) (Source: ISCTAgent) (EventID: 1000) (User: ) Description: ISCT - netDetect::AOACWLANProset::LocateAdapters Net Detect: Net Detect Supported Error Getting Adapter List Error=0x80040302\n Error: (05/04/2015 03:06:14 PM) (Source: MsiInstaller) (EventID: 11606) (User: TSutton-XPS12) Description: Product: Sophos Virus Removal Tool -- Error 1606.Could not access network location data.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (05/04/2015 03:06:12 PM) (Source: MsiInstaller) (EventID: 11606) (User: TSutton-XPS12) Description: Product: Sophos Virus Removal Tool -- Error 1606.Could not access network location data.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (05/04/2015 03:04:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: mohqdban.exe0.0.0.05547996fmohqdbanu.dll0.0.0.055479934c00000050000a176158401d086a579e9a635C:\ProgramData\boostwebapp\1.1.0.31\mohqdban.exeC:\ProgramData\boostwebapp\1.1.0.31\mohqdbanu.dllc338db78-f298-11e4-82cb-5c514f501355 Error: (05/04/2015 01:01:50 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: unbox-video-player-2.2.0.153-en.exe12.0.0.4997410d401d08693ee027a9d4294967295C:\Users\tsutton\Desktop\unbox-video-player-2.2.0.153-en.exea2a21a49-f287-11e4-82bd-5c514f501355 Error: (05/04/2015 00:57:58 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: unbox-video-player-2.2.0.153-en.exe12.0.0.49974bc001d0868bfc20ca664294967295C:\Users\tsutton\Desktop\unbox-video-player-2.2.0.153-en.exe184dd6c8-f287-11e4-82bd-5c514f501355 CodeIntegrity Errors: =================================== Date: 2015-05-04 06:23:00.192 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-04 06:22:59.521 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-04 06:22:58.849 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-04 06:22:58.111 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-04 06:22:57.280 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-04 06:22:56.561 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-04 06:22:55.778 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-04 06:22:55.090 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-04 06:22:54.449 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-04 06:22:53.824 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4500U CPU @ 1.80GHz Percentage of memory in use: 20% Total physical RAM: 8097.38 MB Available physical RAM: 6403.29 MB Total Pagefile: 9377.38 MB Available Pagefile: 7683.56 MB Total Virtual: 131072 MB Available Virtual: 131071.8 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:222.71 GB) (Free:29.25 GB) NTFS Drive d: (My Passport) (Fixed) (Total:931.48 GB) (Free:910.51 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 238.5 GB) (Disk ID: DDB755BC) Partition: GPT Partition Type. ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 6ECC7482) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== End Of Log ============================