Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02.08.2018 Ran by lilunit (09-08-2018 19:16:49) Running from C:\Users\lilunit\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2010-01-01 05:06:11) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3011760224-3171145470-2920118788-500 - Administrator - Disabled) Guest (S-1-5-21-3011760224-3171145470-2920118788-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3011760224-3171145470-2920118788-1002 - Limited - Enabled) lilunit (S-1-5-21-3011760224-3171145470-2920118788-1000 - Administrator - Enabled) => C:\Users\lilunit ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton Security (Enabled - Up to date) {E3FDBD9F-8140-1400-F32B-8B58923F7C4D} AS: Norton Security (Enabled - Up to date) {589C5C7B-A77A-1B8E-C99B-B02AE9B836F0} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton Security (Enabled) {DBC63CBA-CB2F-1558-D874-226D6CEC3B36} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Activate Norton Online Backup (HKLM-x32\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 1.1.20.0 - Symantec) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20055 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.0.3.13070 - Adobe Systems Inc.) Adobe Flash Player 29 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 29.0.0.140 - Adobe Systems Incorporated) Adobe Flash Player 30 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 30.0.0.134 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) ArcSoft Magic-i Visual Effects 2 (HKLM-x32\...\{CF2371B6-8422-49DB-908B-14B67C074667}) (Version: 2.0.11.106 - ArcSoft) ArcSoft WebCam Companion 3 (HKLM-x32\...\{1A5B672C-66B6-43C4-8265-9B1D49462EA0}) (Version: 3.0.42.340 - ArcSoft) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform) CyberLink DVD Suite Deluxe (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.3101 - CyberLink Corp.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden DirectX for Managed Code Update (Summer 2004) (HKLM-x32\...\{E9E34215-82EF-4909-BE2F-F581F0DC9062}) (Version: 9.02.2904 - Microsoft) Hidden Hardware Diagnostic Tools (HKLM\...\PC-Doctor for Windows) (Version: 6.0.5434.08 - PC-Doctor, Inc.) Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Advisor (HKLM-x32\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.3.12286.3436 - Hewlett-Packard) HP Button Manager (HKLM-x32\...\{CA634931-0CC3-4067-ABCC-7182E1DC23B7}) (Version: 3.52 - Hewlett-Packard) HP Dropbox Plugin (HKLM-x32\...\{23617173-F935-4C17-A323-EB1207F3ED49}) (Version: 36.0.31.53050 - Hewlett-Packard Co.) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.0.80 - WildTangent) HP Google Drive Plugin (HKLM-x32\...\{AFF80405-E56A-48E7-98FC-8E46E261949F}) (Version: 36.0.31.53050 - Hewlett-Packard Co.) HP MediaSmart Demo (HKLM-x32\...\{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}) (Version: 1.00.0000 - Hewlett-Packard) HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 3.0.3420 - Hewlett-Packard) HP MediaSmart Movie Themes (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 3.0.3102 - Hewlett-Packard) HP MediaSmart Music/Photo/Video (HKLM-x32\...\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 3.0.3205 - Hewlett-Packard) HP MediaSmart SmartMenu (HKLM\...\{26280024-DFB7-4967-90DB-7F9C6660D01E}) (Version: 3.0.28.2 - Hewlett-Packard) HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP OfficeJet 4650 series Basic Device Software (HKLM\...\{F68DF314-BD12-4549-941C-521CB8D16DDE}) (Version: 40.11.1122.1796 - HP Inc.) HP OfficeJet 4650 series Help (HKLM-x32\...\{20CA428A-0827-4441-BC64-5C577EA970AD}) (Version: 36.0.0 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP) HP Remote Solution (HKLM-x32\...\HP Remote Solution) (Version: 1.1.9.0 - TopSeed) HP Setup (HKLM-x32\...\{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}) (Version: 1.2.3220.3079 - Hewlett-Packard) HP Support Information (HKLM-x32\...\{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}) (Version: 10.1.0002 - Hewlett-Packard) HP Support Solutions Framework (HKLM-x32\...\{00612F78-52C4-46C0-97F0-F50B6036B5E2}) (Version: 12.9.18.3 - HP Inc.) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HP Webcam User's Guide (HKLM-x32\...\{D31612BB-C6D7-4142-96AE-16DB062354CF}) (Version: - Hewlett-Packard) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1912 - Intel Corporation) iTunes (HKLM\...\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.) Java 8 Update 181 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180181F0}) (Version: 8.0.1810.13 - Oracle Corporation) Junk Mail filter update (HKLM-x32\...\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LabelPrint (HKLM-x32\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1901 - CyberLink Corp.) Hidden LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1901 - CyberLink Corp.) LightScribe System Software (HKLM-x32\...\{DD6C316A-FE75-4FBB-9D22-4C1920232B72}) (Version: 1.18.5.1 - LightScribe) LSI PCI-SV92EX Soft Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.100 - LSI Corporation) Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes) Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation) Microsoft Live Search Toolbar (HKLM-x32\...\{DF802C05-4660-418c-970C-B988ADB1D316}) (Version: 3.0.560.0 - Microsoft Live Search Toolbar) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 61.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 61.0.2 (x64 en-US)) (Version: 61.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 58.0.2 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Norton Security (HKLM-x32\...\NGC) (Version: 22.15.0.88 - Symantec Corporation) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.0 - Frank Heindörfer, Philip Chinery) PictureMover (HKLM-x32\...\{1896E712-2B3D-45eb-BCE9-542742A51032}) (Version: 3.3.1.19 - Hewlett-Packard Company) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3101 - CyberLink Corp.) Hidden Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3101 - CyberLink Corp.) PowerDirector (HKLM-x32\...\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3101 - CyberLink Corp.) Hidden PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3101 - CyberLink Corp.) PowerRecover (HKLM-x32\...\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.1923 - CyberLink Corp.) Hidden QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) RangeMax Wireless-N USB Adapter WN111v2 (HKLM-x32\...\InstallShield_{1C0E9C6B-D4D5-4D3C-8A10-F10A3E7BEEA5}) (Version: 3.0.0.3 - NETGEAR) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5910 - Realtek Semiconductor Corp.) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.41 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.41.101 - Skype Technologies S.A.) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1164 - SUPERAntiSpyware.com) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) WN111v2 (HKLM-x32\...\{1C0E9C6B-D4D5-4D3C-8A10-F10A3E7BEEA5}) (Version: 3.0.0.3 - NETGEAR) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\buShell.dll [2018-08-05] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\buShell.dll [2018-08-05] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\buShell.dll [2018-08-05] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\buShell.dll [2018-08-05] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\buShell.dll [2018-08-05] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\buShell.dll [2018-08-05] (Symantec Corporation) ContextMenuHandlers1: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\buShell.dll [2018-08-05] (Symantec Corporation) ContextMenuHandlers1: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll -> No File ContextMenuHandlers1: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\NavShExt.dll [2018-08-05] (Symantec Corporation) ContextMenuHandlers2: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\NavShExt.dll [2018-08-05] (Symantec Corporation) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2009-09-11] (Intel Corporation) ContextMenuHandlers6: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\buShell.dll [2018-08-05] (Symantec Corporation) ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll -> No File ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ContextMenuHandlers6: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\NavShExt.dll [2018-08-05] (Symantec Corporation) FolderExtensions: [] -> {F6BF8414-962C-40FE-90F1-B80A7E72DB9A} => C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\p2pcollab.dll -> No File FolderExtensions_S-1-5-21-3011760224-3171145470-2920118788-1000: [] -> {F6BF8414-962C-40FE-90F1-B80A7E72DB9A} => C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\p2pcollab.dll -> No File ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {16682CBF-0DDD-4BB4-98AF-4AA4638295A9} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\WSCStub.exe [2018-08-05] (Symantec Corporation) Task: {25810E43-F895-4BFE-8E9C-2811C3F29C6E} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe [2018-08-05] (Symantec Corporation) Task: {29D9CEC3-0CE2-4E56-8A23-FADAB81D0D64} - System32\Tasks\{18893B81-B4A3-4AA1-930F-81C22B862023} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/7.6.0.105/en/abandoninstall?page=tsProgressBar Task: {34AB0B5B-5C41-445B-98B5-E9BEFCB287B5} - System32\Tasks\{3D44EF6E-67E0-4378-8800-38FAC5B9E4BA} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/7.6.0.105/en/abandoninstall?page=tsProgressBar Task: {35001F59-4F1F-499D-B293-306916F3E743} - \{327674D4-6037-429F-888E-4AC62FF04226} -> No File <==== ATTENTION Task: {37B7E6F1-91C1-4D98-995B-76EC226E711F} - System32\Tasks\{5E9A133B-5034-4861-A19F-21BEC989200B} => C:\Windows\system32\pcalua.exe -a C:\Users\lilunit\Downloads\HPSupportSolutionsFramework-12.5.26.37.exe -d C:\Users\lilunit\Downloads Task: {3D873ABF-E021-40ED-A409-FADB94D21732} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.) Task: {43F66DFC-3874-4106-9582-699E3CA3484D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-03-21] (Adobe Systems Incorporated) Task: {6D2D3A05-FB73-4E9B-8174-FD3E3D1B4F18} - System32\Tasks\{34AAA631-D148-4997-888C-E8CCA30E40F9} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxps://ui.skype.com/ui/0/7.29.64.102/en/privacy Task: {73019AA1-F28D-45A0-9F29-AFAE73E18EBA} - System32\Tasks\Norton Security\Norton Security Error Processor => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\SymErr.exe [2018-08-05] (Symantec Corporation) Task: {7DC563A4-DB7F-44AB-946F-797F52F24A78} - System32\Tasks\Norton Security\Norton Security Error Analyzer => C:\Program Files (x86)\Norton Security\Engine\22.15.0.88\SymErr.exe [2018-08-05] (Symantec Corporation) Task: {936EE1D9-DEAC-4E56-A201-2A344AD8C485} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd) Task: {94AFBCCB-3FFC-40B0-8130-D4AD9217D74A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.) Task: {961EAF3B-DC4F-4CFD-872E-AF9D9A7E116F} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_134_Plugin.exe [2018-08-08] (Adobe Systems Incorporated) Task: {975B72C8-E5E6-48AD-A245-E4473BEE13E0} - System32\Tasks\DVDAgent => c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe [2009-10-20] (CyberLink Corp.) Task: {9904EC1E-A475-47AE-A1A5-A7B8927F29F8} - System32\Tasks\{78BA0FC2-4BA2-438A-A962-A94E6B4458C8} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxps://ui.skype.com/ui/0/7.29.64.102/en/abandoninstall?page=tsMain Task: {9EA02334-4762-4E22-9E90-59BF49E860CC} - System32\Tasks\{B5EDA45F-4DBC-4ED6-AEA2-FE8763D4BB0D} => C:\Windows\system32\pcalua.exe -a "C:\Users\lilunit\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3NVNY94S\startuplite-setup-1.07.exe" -d C:\Users\lilunit\Desktop Task: {B66FA7B6-47E7-4E14-BB4A-EAC643E15547} - \{2E19D521-6368-4EE8-B2F4-B43E585FC1CD} -> No File <==== ATTENTION Task: {CBB25689-B792-4775-8922-3924CC11C9B1} - System32\Tasks\{09518352-7C34-4D8A-B1B5-48123F44D166} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/7.6.0.105/en/abandoninstall?page=tsProgressBar (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2012-08-02 06:37 - 2005-03-12 00:07 - 000087040 _____ () C:\Windows\System32\pdfcmnnt.dll 2016-09-01 18:12 - 2016-09-01 18:12 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-09-01 18:12 - 2016-09-01 18:12 - 001353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2018-03-22 20:21 - 2018-07-12 00:37 - 002433744 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2009-07-08 16:35 - 2009-07-08 16:35 - 000610360 _____ () C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe 2011-11-08 19:04 - 2010-02-22 18:30 - 000266240 _____ () C:\Program Files (x86)\HP Button Manager\BM.exe ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\90029288.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\90029288.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMR430 => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMR521 => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMR521.SYS => ""="Driver" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2009-06-10 16:00 - 000000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3011760224-3171145470-2920118788-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\lilunit\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 75.75.75.75 - 75.75.76.76 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: HPADVISOR => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: LogitechVideoRepair => C:\Program Files (x86)\Logitech\Video\ISStart.exe MSCONFIG\startupreg: Messenger (Yahoo!) => "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{BF2941C7-414D-4C9F-A707-77E614B2F2D2}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE FirewallRules: [{3CA640A6-972C-4F5F-87B9-77155CDACE8C}] => (Allow) C:\Program Files (x86)\iWin Games\iWinGames.exe FirewallRules: [{37905745-464A-4083-94F4-C3FBC0B623B7}] => (Allow) C:\Program Files (x86)\iWin Games\iWinGames.exe FirewallRules: [{6418C5F4-B917-42B8-8946-637384A113B0}] => (Allow) C:\Program Files (x86)\iWin Games\WebUpdater.exe FirewallRules: [{0FC2A718-9119-4787-9964-D89889907C8D}] => (Allow) C:\Program Files (x86)\iWin Games\WebUpdater.exe FirewallRules: [{3E9AEDF5-B39F-497B-BFF2-088A54D8EE4E}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe FirewallRules: [{B24626F9-2150-41CB-BBF6-96C9FC81C2DC}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe FirewallRules: [{D1A83D92-A298-48F9-9E1D-0C145C5B5545}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe FirewallRules: [{0521C9B8-51FF-4215-A835-D8460E2D6D5D}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe FirewallRules: [{089B70F9-3A65-409B-ADAE-724CC4B47BCA}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe FirewallRules: [{4B69C1A1-3A9A-46BD-AA5D-96EBF8331CA0}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe FirewallRules: [{BC77F254-9C3A-4904-B146-906C0B28BEE5}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe FirewallRules: [{22C2ACAE-816D-4842-9061-66142381140D}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe FirewallRules: [{88D1FAD8-84EA-4B55-A78C-481ACCCB625D}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\Media\DVD\TSMAgent.exe FirewallRules: [{C83B49E5-28A0-4637-B55A-283A924CF277}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe FirewallRules: [{F7BA0F6B-D306-4AA5-9805-5D6316FDF8CA}] => (Allow) c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe FirewallRules: [{D23A82D7-AD10-4AB3-9215-9B47EC1CC048}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{1C8BE3D3-0785-42C3-803D-BA90A46E8882}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{25798EA7-34B0-4683-829E-33DD83309BE8}] => (Allow) C:\Program Files (x86)\AIM\aim.exe FirewallRules: [{C3DC56DA-68E1-40C7-9C20-B282A3EBF6CF}] => (Allow) C:\Program Files (x86)\AIM\aim.exe FirewallRules: [{FFE5C16A-F536-4F5F-AAEE-A4EBE9645183}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{EE4BC948-69D4-4969-B4DB-EA64E2E88277}] => (Allow) LPort=2869 FirewallRules: [{4950DED4-DE1F-4D26-A513-5BDF2A232EAB}] => (Allow) LPort=1900 FirewallRules: [{93EA1CF5-5C50-43A0-9453-1B7554230B98}] => (Allow) C:\Program Files (x86)\FrostWire 5\FrostWire.exe FirewallRules: [{D65C73C7-6CAB-4190-B3BF-CC8A34318C6F}] => (Allow) C:\Program Files (x86)\FrostWire 5\FrostWire.exe FirewallRules: [{8FC5E8EA-1D87-4310-8E4D-F1800ECAE6BD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{001D7C63-66EF-4169-B743-160BA5037FB9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C4B85B24-DFF6-4F1C-B2C3-6166855C05BA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{F7C7DF44-5337-4AA8-8FF2-696F9DD4C690}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{020404B1-BC26-4C1C-AC55-39AE44E57744}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe FirewallRules: [{9C11F414-8E39-4EA4-8721-25E2E5B477E2}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe FirewallRules: [{96592E35-C206-47FF-9184-FD64B360BD63}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe FirewallRules: [{8BD404E6-E2F6-4B55-9BBD-7E2CD24CF277}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe FirewallRules: [{85D098BE-EF4D-4206-B62C-C1CA630D3D39}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe FirewallRules: [{8FE048A5-3938-455C-BB69-F9554214CEAC}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe FirewallRules: [TCP Query User{B0FB209F-FB39-4F78-8D6A-CFE63428A73A}C:\program files (x86)\spybot - search & destroy 2\sdfiles.exe] => (Block) C:\program files (x86)\spybot - search & destroy 2\sdfiles.exe FirewallRules: [UDP Query User{4273CF12-9D2D-4909-A759-A6AA5D26AE4F}C:\program files (x86)\spybot - search & destroy 2\sdfiles.exe] => (Block) C:\program files (x86)\spybot - search & destroy 2\sdfiles.exe FirewallRules: [{2ED3052B-F1F7-4734-B45F-6B9140B4FCC0}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{2E3A2370-9B3E-4B2F-BB24-40DD7932BE95}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{ADA2FDF2-6E99-4803-ABB3-6BE427C0A0C7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{CD76E5B4-D983-42D4-8D56-8098644634D6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{49719052-DD93-4B86-9382-45A262899C08}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{8F259A91-BE7A-466C-81E2-ACBB285DD807}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{84022751-ACCC-4680-9EA6-885088241DB4}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe FirewallRules: [{A966FE0C-F44A-45A3-B12B-FD9308B30E7F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{75E30D9A-B3D0-4CD7-9E36-2F954920CDD3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7B93157D-2F9B-4249-A202-60FB9882727A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{9F4DFC76-B57E-4E21-A531-5ACB0BDF7B9D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{BDA8BDA8-00FF-4940-B5ED-005303DBEC4B}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{85AA19D0-E493-4FC6-A947-DA7654CD23FB}] => (Allow) C:\Users\lilunit\AppData\Local\Temp\7zSCEB4.tmp\SymNRT.exe FirewallRules: [{A2DC4BCF-0F24-42E6-B141-9411599AAAB2}] => (Allow) C:\Users\lilunit\AppData\Local\Temp\7zSCEB4.tmp\SymNRT.exe FirewallRules: [{69137ABB-BAAE-46CD-8AA1-2450716E4EE9}] => (Allow) C:\Users\lilunit\AppData\Local\Temp\7zS53F1\HPDiagnosticCoreUI.exe FirewallRules: [{DF6F0650-14AA-4CC8-818E-8A450BA57FC2}] => (Allow) C:\Users\lilunit\AppData\Local\Temp\7zS53F1\HPDiagnosticCoreUI.exe FirewallRules: [{4DE384D0-C501-4D53-A907-49EF4C781BF4}] => (Allow) C:\Users\lilunit\AppData\Local\Temp\7zS54B5\HPDiagnosticCoreUI.exe FirewallRules: [{12A87AD4-7D5E-406F-927F-A6CE6F621786}] => (Allow) C:\Users\lilunit\AppData\Local\Temp\7zS54B5\HPDiagnosticCoreUI.exe FirewallRules: [{72A33516-8722-49F9-A5DD-3F25002ECFE6}] => (Allow) C:\Users\lilunit\AppData\Local\Temp\7zS6FE7\HP.EasyStart.exe FirewallRules: [{AFA867C6-480A-4B81-9926-6E315CB88316}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\bin\FaxPrinterUtility.exe FirewallRules: [{B470A19C-66BF-4337-98BC-D3DC4A41DB18}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\bin\FaxApplications.exe FirewallRules: [{D2DCABF9-B48D-4752-898F-121C289F407B}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\bin\DigitalWizards.exe FirewallRules: [{27C8F043-1E4A-4FB3-8C2E-980B23874DB7}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\bin\SendAFax.exe FirewallRules: [{8D48848C-2DE3-4C38-AC06-CC12468ACBAC}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\Bin\DeviceSetup.exe FirewallRules: [{AA0D3735-4203-4BF7-84C8-ACD7E4212FA0}] => (Allow) LPort=5357 FirewallRules: [{BC23661E-3E8D-4C76-B054-E8D1D5A65C15}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{01A5680B-BDB0-4E1C-AAB1-655BE45EE28D}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{185DC581-FFF7-4B9A-8699-62428877BD33}] => (Allow) C:\Users\lilunit\AppData\Local\Temp\7zS2471\HPDiagnosticCoreUI.exe FirewallRules: [{AC10C49A-F1DE-4E2C-92B9-729EA46CCC9D}] => (Allow) C:\Users\lilunit\AppData\Local\Temp\7zS2471\HPDiagnosticCoreUI.exe ==================== Restore Points ========================= 04-08-2018 18:17:13 Scheduled Checkpoint 08-08-2018 03:03:05 Checkpoint by HitmanPro 08-08-2018 03:04:22 Checkpoint by HitmanPro 08-08-2018 06:38:50 JRT Pre-Junkware Removal 08-08-2018 17:47:15 Removed Emsisoft Anti-Malware 08-08-2018 17:50:17 Removed Emsisoft Anti-Malware 08-08-2018 17:53:15 Removed Emsisoft Anti-Malware 08-08-2018 17:55:15 Removed Emsisoft Anti-Malware 08-08-2018 17:57:47 Removed Emsisoft Anti-Malware 08-08-2018 18:05:04 Restore Operation 09-08-2018 13:55:08 JRT Pre-Junkware Removal 09-08-2018 18:43:16 JRT Pre-Junkware Removal ==================== Faulty Device Manager Devices ============= Name: ZAM Helper Driver Description: ZAM Helper Driver Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: ZAM Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: ZAM Guard Driver Description: ZAM Guard Driver Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: ZAM_Guard Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Windows Defender: =================================== Date: 2016-08-22 01:41:28.633 Description: Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted:Current Error Code:0x80070002 Error description:The system cannot find the file specified. Signature version:0.0.0.0 Engine version:0.0.0.0 Date: 2016-06-07 03:44:14.285 Description: Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted:Current Error Code:0x80070002 Error description:The system cannot find the file specified. Signature version:0.0.0.0 Engine version:0.0.0.0 Date: 2016-06-07 01:35:19.852 Description: Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted:Current Error Code:0x80070002 Error description:The system cannot find the file specified. Signature version:0.0.0.0 Engine version:0.0.0.0 CodeIntegrity: =================================== Date: 2018-08-08 18:04:59.494 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system. Date: 2018-08-08 17:47:07.429 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Pentium(R) Dual-Core CPU E5300 @ 2.60GHz Percentage of memory in use: 41% Total physical RAM: 4085.18 MB Available physical RAM: 2400.02 MB Total Virtual: 8168.53 MB Available Virtual: 6572.08 MB ==================== Drives ================================ Drive c: (HP) (Fixed) (Total:584.25 GB) (Free:520.99 GB) NTFS Drive d: (FACTORY_IMAGE) (Fixed) (Total:11.83 GB) (Free:2.08 GB) NTFS ==>[system with boot components (obtained from drive)] \\?\Volume{8517215b-e372-11de-99f6-806e6f6e6963}\ (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596.2 GB) (Disk ID: 1549F232) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=584.2 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=11.8 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================