Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21.02.2018 Ran by [removed] (21-02-2018 23:11:05) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1709 16299.248 (X64) (2017-12-19 07:31:06) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-106698449-1581471573-1421150475-500 - Administrator - Enabled) DefaultAccount (S-1-5-21-106698449-1581471573-1421150475-503 - Limited - Disabled) grant (S-1-5-21-106698449-1581471573-1421150475-1001 - Administrator - Enabled) => C:\Users\grant Guest (S-1-5-21-106698449-1581471573-1421150475-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-106698449-1581471573-1421150475-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.20 - Adobe Systems) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.0.327 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{3D1290E6-1F77-46D5-A715-A56679C8D4E3}) (Version: 6.0.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{D0E45DEC-F4B9-4370-A9DF-66837789C2EF}) (Version: 6.0.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E3C4B99B-BE71-4C27-8E3C-4FAE3C46E1D5}) (Version: 11.0.0.30 - Apple Inc.) Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CloudNet (HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\CloudNet) (Version: 20170301 - EpicNet Inc.) <==== ATTENTION Dell Customer Connect (HKLM-x32\...\{04A41EBC-AB30-4574-A14D-E0CDFE31AB70}) (Version: 1.5.1.0 - Dell Inc.) Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP) Dell Help & Support (HKLM\...\{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.) Hidden Dell Help & Support (HKLM-x32\...\InstallShield_{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.) Dell Product Registration (HKLM-x32\...\InstallShield_{48114909-3C3B-43E6-BF98-AE9C396500A3}) (Version: 3.0.127.0 - Dell Inc.) Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 2.0.6875.668 - Dell) Dell SupportAssist Remediation (HKLM\...\{4164FBBB-3428-4EFE-863F-30CAC3ADE51A}) (Version: 3.1.2.3837 - Dell Inc.) Hidden Dell SupportAssist Remediation (HKLM-x32\...\{80642b68-d76d-4777-a9dc-4ca30647e8a8}) (Version: 3.1.2.3837 - Dell Inc.) Dell SupportAssistAgent (HKLM\...\{8D7B279C-A661-465C-9658-F62FBD6A6B91}) (Version: 2.1.3.5 - Dell) Dell Update - SupportAssist Update Plugin (HKLM\...\{2228BC43-73DA-4F9A-BEE6-8E9C15328513}) (Version: 3.1.1.3832 - Dell Inc.) Dell Update (HKLM-x32\...\{632610E3-5B12-403C-9C93-EF533ED1C113}) (Version: 1.10.5.0 - Dell Inc.) Document Capture Pro (HKLM-x32\...\{8930DCE5-510D-4476-A879-835188F7B6F4}) (Version: 1.06.0011 - Seiko Epson Corporation) Document Capture Pro OneNote Connector (HKLM-x32\...\{65FC2F65-FCD4-495C-B250-1F7C049E4A39}) (Version: 1.00.0000 - Seiko Epson Corporation) Driver Support (HKLM-x32\...\DriverSupport) (Version: 10.1.4.39 - PC Drivers HeadQuarters LP) <==== ATTENTION Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.4.0 - Seiko Epson Corporation) Epson Customer Research Participation (HKLM\...\{B26449A6-6007-4460-B4FE-C4776115BCEA}) (Version: 1.82.0000 - Seiko Epson Corporation) Epson Event Manager (HKLM-x32\...\{E4631929-CBD3-49A1-9BB7-F36E701F7C34}) (Version: 3.10.0040 - Seiko Epson Corporation) Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.53.00 - SEIKO EPSON CORPORATION) Epson PC-FAX Driver (HKLM-x32\...\EPSON PC-FAX Driver 2) (Version: - ) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON Scan OCR Component (HKLM-x32\...\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 2.30.00 - SEIKO EPSON Corp.) Epson Software Updater (HKLM-x32\...\{B55DB65D-EF6E-4E04-89D5-B03603BF681B}) (Version: 4.4.5 - SEIKO EPSON CORPORATION) EPSON WF-4630 Series Printer Uninstall (HKLM\...\EPSON WF-4630 Series) (Version: - SEIKO EPSON Corporation) Epson WF-4630 User’s Guide version 1.0 (HKLM-x32\...\UsersGuideEpson WF-4630 User’s Guide_is1) (Version: 1.0 - ) EpsonNet Print (HKLM\...\{15A0F113-BF2C-4C12-8AA8-42AE0D9AE1C9}) (Version: 3.1.2.0 - SEIKO EPSON Corporation) FastDataX 1.20 (HKLM-x32\...\FastDataX_is1) (Version: 1.20 - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden Herramientas de corrección de Microsoft Office 2016: español (HKLM\...\{90160000-001F-0C0A-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden Intel(R) Chipset Device Software (HKLM-x32\...\{61a0f1f5-c77e-4992-ba85-029f93cd8d18}) (Version: 10.1.1.27 - Intel(R) Corporation) Hidden Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.2.10900.330 - Intel Corporation) Intel(R) HID Event Filter (HKLM-x32\...\3FB06EEC-013D-4366-9918-71B97DFB84EB) (Version: 1.1.0.313 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.5.0.1015 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 22.20.16.4836 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.2.0.1020 - Intel Corporation) Intel(R) Virtual Buttons (HKLM-x32\...\1992736F-C90A-481C-B21B-EE34CAD07387) (Version: 1.1.0.21 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{3920BCB0-23AA-4D0D-93E5-404692DAF9D2}) (Version: 19.00.1621.3340 - Intel Corporation) Intel® Integrated Sensor Solution (HKLM-x32\...\{b3c2a365-876b-4588-97ce-5ab104b07d57}) (Version: 3.0.30.1076 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{66614300-cd9b-4a62-8b18-c97e9562dc3e}) (Version: 19.50.0 - Intel Corporation) Intel® Security Assist (HKLM-x32\...\{8B08DDA1-FDE7-4897-8EB6-E0B048A6D88B}) (Version: 1.0.1.618 - Intel Corporation) ISS_Drivers_x64 (HKLM\...\{7F65AED2-5B3C-40DD-996B-6F8820856F34}) (Version: 3.0.30.1076 - Intel Corporation) Hidden iTunes (HKLM\...\{94E81D4F-FB5A-4B29-B385-33896CC9BE7E}) (Version: 12.7.0.166 - Apple Inc.) Java 8 Update 161 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180161F0}) (Version: 8.0.1610.12 - Oracle Corporation) Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes) Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.7.9179.0 - Waves Audio Ltd.) Hidden Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Nanoheal Client (HKLM\...\Nanoheal Client_is1) (Version: 2.[removed].08 - Nanoheal) Outils de vérification linguistique 2016 de Microsoft Office - Français (HKLM\...\{90160000-001F-040C-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden Product Registration (HKLM\...\{48114909-3C3B-43E6-BF98-AE9C396500A3}) (Version: 3.0.127.0 - Dell Inc.) Hidden ProxyGate version 3.0.0.1180 (HKLM-x32\...\{1EC095EE-8CA3-43D6-B9F5-0C55B82ED3D7}}_is1) (Version: 3.0.0.1180 - Gold Click Ltd) <==== ATTENTION QuickBooks (HKLM-x32\...\{2B0E1E07-2F3D-4E7D-AD0A-1C74A8881B9B}) (Version: 26.0.4006.2607 - Intuit Inc.) Hidden QuickBooks Pro 2016 (HKLM-x32\...\{4338BDE2-0035-41BC-87BE-EE0AD5D48042}) (Version: 26.0.4006.2607 - Intuit Inc.) QuickBooks Runtime Redistributable (HKLM\...\{F2A4F809-2DE6-4D27-888B-4D2BB8DAF20E}) (Version: 1.00.0000 - Intuit Inc.) QuickSet64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.1.37 - Dell Inc.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8158 - Realtek Semiconductor Corp.) Realtek PC Camera Driver (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10586.11224 - Realtek Semiconductor Corp.) RogueKiller version 12.12.5.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.5.0 - Adlice Software) ShipStation Connect (HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\3aae993d1ca25c50) (Version: 4.2.1.9 - Amazon.com) Stamps.com Connect (HKLM-x32\...\{B47A6A15-5DFA-4EBD-85A6-7C9A08A0E88A}) (Version: 2.2.0.233 - Stamps.com) Hidden Stamps.com Connect (HKLM-x32\...\Stamps.com Connect) (Version: 2.2.0.233 - Stamps.com, Inc.) Update for Skype for Business 2016 (KB3115087) 64-Bit Edition (HKLM\...\{90160000-0011-0000-1000-0000000FF1CE}_Office16.PROPLUS_{C48D0508-2A21-42EA-8BC9-D387768F54F4}) (Version: - Microsoft) Update for Skype for Business 2016 (KB3115087) 64-Bit Edition (HKLM\...\{90160000-00C1-0000-1000-0000000FF1CE}_Office16.PROPLUS_{C48D0508-2A21-42EA-8BC9-D387768F54F4}) (Version: - Microsoft) Update for Skype for Business 2016 (KB3115087) 64-Bit Edition (HKLM\...\{90160000-012B-0409-1000-0000000FF1CE}_Office16.PROPLUS_{C48D0508-2A21-42EA-8BC9-D387768F54F4}) (Version: - Microsoft) VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.4.9.0 - Elaborate Bytes) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-2) (Version: 1.0.54.1 - Intel Corporation Inc.) Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.7.4.0 - Azureus Software, Inc.) WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) Zebra Setup Utilities (HKLM-x32\...\{9207A8EC-3B2D-4A4A-8BF7-957FC19BB3DE}) (Version: 1.1.9.1208 - Zebra Technologies) Hidden Zebra Setup Utilities (HKLM-x32\...\Zebra Setup Utilities) (Version: 1.1.9.1208 - Zebra Technologies) Zoom (HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\ZoomUMX) (Version: 4.0 - Zoom Video Communications, Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-106698449-1581471573-1421150475-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\grant\AppData\Local\Microsoft\OneDrive\17.005.0107.0008\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-106698449-1581471573-1421150475-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\grant\AppData\Local\Microsoft\OneDrive\17.005.0107.0008\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-106698449-1581471573-1421150475-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\grant\AppData\Local\Microsoft\OneDrive\17.005.0107.0008\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-106698449-1581471573-1421150475-1001_Classes\CLSID\{a9872fee-5a55-4ecb-9b0f-b06fedcf14d1}\localserver32 -> C:\Program Files\Waves\MaxxAudio\MaxxAudioPro.exe (Waves Audio Ltd) CustomCLSID: HKU\S-1-5-21-106698449-1581471573-1421150475-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ShellIconOverlayIdentifiers: [ 00BitrixShellExt] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506B} => -> No File ShellIconOverlayIdentifiers: [ 00BitrixShellExt_C] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506E} => C:\Program Files (x86)\Bitrix24\64\BitrixShellExt.dll -> No File ShellIconOverlayIdentifiers: [ 00BitrixShellExt_E] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506D} => C:\Program Files (x86)\Bitrix24\64\BitrixShellExt.dll -> No File ShellIconOverlayIdentifiers: [ 00BitrixShellExt_L] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506F} => C:\Program Files (x86)\Bitrix24\64\BitrixShellExt.dll -> No File ShellIconOverlayIdentifiers: [ 00BitrixShellExt_S] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506C} => C:\Program Files (x86)\Bitrix24\64\BitrixShellExt.dll -> No File ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] () ShellIconOverlayIdentifiers-x32: [ 00BitrixShellExt] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506B} => -> No File ShellIconOverlayIdentifiers-x32: [ 00BitrixShellExt_C] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506E} => C:\Program Files (x86)\Bitrix24\64\BitrixShellExt.dll -> No File ShellIconOverlayIdentifiers-x32: [ 00BitrixShellExt_E] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506D} => C:\Program Files (x86)\Bitrix24\64\BitrixShellExt.dll -> No File ShellIconOverlayIdentifiers-x32: [ 00BitrixShellExt_L] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506F} => C:\Program Files (x86)\Bitrix24\64\BitrixShellExt.dll -> No File ShellIconOverlayIdentifiers-x32: [ 00BitrixShellExt_S] -> {A11A1EE5-F9F8-4BE0-907F-D74A49CC506C} => C:\Program Files (x86)\Bitrix24\64\BitrixShellExt.dll -> No File ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] () ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat Elements\ContextMenuShim64.dll [2012-09-23] (Adobe Systems Inc.) ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (Alexander Roshal) ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki125183.inf_amd64_cb49708b33bad074\igfxDTCM.dll [2017-11-07] (Intel Corporation) ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] () ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat Elements\ContextMenuShim64.dll [2012-09-23] (Adobe Systems Inc.) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (Alexander Roshal) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0162055A-069D-4BE8-B762-CC5886CC8CCD} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2017-06-09] (Realtek Semiconductor) Task: {036E0B34-54DF-49EB-A833-86A1E702C95B} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2017-09-14] (PC-Doctor, Inc.) Task: {06B75FCA-6484-45EC-B32F-DBF30CD98B79} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {0C4CCC16-4FB5-4791-9F77-8518C3671DE6} - System32\Tasks\EPSON WF-4630 Series Update {2292D2CA-216B-4422-B12F-B1CF648FC7C4} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKLE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {150968C3-838C-4998-9AA1-699879DF6360} - System32\Tasks\tspracticing-generatorpracticing-generator => C:\Program Files (x86)\emancipation\aix.exe Task: {1510E831-F072-4A70-9593-269CD4BB8594} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [2017-12-22] (Dell Inc.) Task: {22D2CD36-B5C8-4F07-A323-347FB73B6DCB} - System32\Tasks\EPSON WF-4630 Series Invitation {B913E0E1-A336-4FF8-AEC4-97740639537E} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKLE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {2F2C602C-0325-49C5-ACA4-652AF9214802} - System32\Tasks\capitulate => C:\Program Files (x86)\Dobler\ballgame.exe Task: {38587322-9DCB-4FDD-891D-FFCB12A9D598} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe Task: {41AB0544-3CF9-4DE9-A42B-6C3B2B07225B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-11] (Google Inc.) Task: {4F69E84F-7EFA-47DA-A342-F2496075ABCB} - System32\Tasks\tsfind temperafind tempera => C:\Program Files (x86)\Dyker\aix.exe Task: {511FE00E-A0D7-48A3-9C93-1DA742795F07} - System32\Tasks\fawcett => C:\Program Files (x86)\cracked\cracked.exe Task: {65108876-DE2F-4511-85A7-1F8782325CAD} - System32\Tasks\[removed] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated) Task: {6BD5383C-E377-4AEB-92C8-F133BF477161} - System32\Tasks\find tempera => C:\Program Files (x86)\Dyker\aix.exe Task: {6F4DA408-1BC3-492C-9C1D-8B0403AE3EAC} - System32\Tasks\[removed] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated) Task: {7DE3E949-1266-4399-811C-600B52A2FD59} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.) Task: {80D9C344-FB9A-478E-B513-79493E5E1565} - System32\Tasks\Pinber ImGame Access Database => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Pinber ImGame Access Database\Pinber ImGame Access Database.dll",xGymhbut <==== ATTENTION Task: {86030A41-724C-4F2C-AF25-9D916C22AE96} - System32\Tasks\Multimedia Video Converter => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Multimedia Video Converter\Multimedia Video Converter.dll",gTyBhlxeK <==== ATTENTION Task: {8A94BC0D-AEE4-4AEF-B97C-EDC8BD2E499A} - System32\Tasks\practicing-generator => C:\Program Files (x86)\emancipation\aix.exe Task: {8CAE0DEE-D43C-43A8-85A1-0BAE747DF600} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {99E6C593-8D10-45CA-B1D9-E5BE4B6D0E6D} - System32\Tasks\Enhanced Paradise => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Enhanced Paradise\Enhanced Paradise.dll",yLKAQwtzZim <==== ATTENTION Task: {A1B9EBCF-211D-49A4-95AE-F4181F033A76} - System32\Tasks\GalaxyTebusSpring Builder => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\GalaxyTebusSpring Builder\GalaxyTebusSpring Builder.dll",lWukzR <==== ATTENTION Task: {A2A2513C-7C22-499A-85F7-4B52B171159A} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-07-31] (Microsoft Corporation) Task: {B4E59396-E513-4F87-8BBC-78C0015511A7} - System32\Tasks\tsbearing_equipbearing_equip => C:\Program Files (x86)\Dyker\ballgame.exe Task: {B9B1AC4A-BB75-48B7-9B7F-86D8D55266FA} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2016-02-19] (Intel(R) Corporation) Task: {BF532C1C-894E-4B67-B71F-B5200E00CD05} - System32\Tasks\tsfawcettfawcett => C:\Program Files (x86)\cracked\cracked.exe Task: {C39BBA88-D70C-4F22-BEAE-AC84EC09F425} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2017-09-14] (PC-Doctor, Inc.) Task: {DED97FD2-89B1-46B7-A94C-465B24A4E799} - System32\Tasks\bearing_equip => C:\Program Files (x86)\Dyker\ballgame.exe Task: {DFB4DA87-D5CD-4E23-B0BE-D5EA67657F4C} - System32\Tasks\EPSON WF-4630 Series Invitation {2292D2CA-216B-4422-B12F-B1CF648FC7C4} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKLE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {E7D9B634-89E2-4C42-8991-BCBB76056996} - System32\Tasks\Tabs => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Tabs\Tabs.dll",yxqVVi <==== ATTENTION Task: {F4E8C927-B06A-4B74-92BD-10AB3D82A6EA} - System32\Tasks\AGProxyCheck => C:\Program [Argument = Files (x86)\AnonymizerGadget\AGService.exe /recove] Task: {F924E356-4FA6-4B35-B6C0-0792BA0BA356} - System32\Tasks\tscapitulatecapitulate => C:\Program Files (x86)\Dobler\ballgame.exe Task: {FA76288C-B748-4B39-A02E-0DB5602D292B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-11] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\ Update {B913E0E1-A336-4FF8-AEC4-97740639537E}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKLE.EXE:/EXE:{B913E0E1-A336-4FF8-AEC4-97740639537E} /F:UpdateWORKGROUP\DESKTOP-679GB3N$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\EPSON WF-4630 Series Invitation {2292D2CA-216B-4422-B12F-B1CF648FC7C4}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKLE.EXE Task: C:\WINDOWS\Tasks\EPSON WF-4630 Series Invitation {B913E0E1-A336-4FF8-AEC4-97740639537E}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKLE.EXE Task: C:\WINDOWS\Tasks\EPSON WF-4630 Series Update {2292D2CA-216B-4422-B12F-B1CF648FC7C4}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKLE.EXE:/EXE:{2292D2CA-216B-4422-B12F-B1CF648FC7C4} /F:UpdateWORKGROUP\DESKTOP-679GB3N$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-09-29 06:41 - 2017-09-29 06:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2016-06-10 00:41 - 2016-06-10 00:41 - 000491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-05-17 06:36 - 2016-05-17 06:36 - 008901800 _____ () C:\Program Files\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2018-02-20 23:14 - 2015-06-01 10:47 - 002377728 _____ () C:\Program Files\GalaxyTebusSpring Builder\GalaxyTebusSpring Builder.dll 2016-09-01 17:12 - 2016-09-01 17:12 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2017-09-01 01:49 - 2017-09-01 01:49 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2018-02-20 21:46 - 2018-02-21 04:15 - 001377280 ____H () C:\WINDOWS\windefender.exe 2018-02-21 03:51 - 2016-12-26 16:37 - 000924616 _____ () C:\Program Files\Nanoheal\Client\sqlite3.dll 2018-02-21 03:51 - 2016-12-26 16:37 - 000106896 _____ () C:\Program Files\Nanoheal\Client\nfapi.dll 2018-02-21 03:51 - 2016-12-26 16:37 - 000532880 _____ () C:\Program Files\Nanoheal\Client\ProtocolFilters.dll 2018-02-13 21:38 - 2018-02-09 21:39 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2018-02-13 21:38 - 2018-02-09 21:36 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-01-31 14:47 - 2018-01-31 14:47 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-01-31 14:47 - 2018-01-31 14:47 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-01-31 14:47 - 2018-01-31 14:47 - 025135104 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2018-01-31 14:47 - 2018-01-31 14:47 - 002542592 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\skypert.dll 2018-01-31 14:47 - 2018-01-31 14:47 - 000667136 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2018-02-20 23:12 - 2018-02-21 22:53 - 000484352 _____ () C:\WINDOWS\TEMP\g7887.tmp.exe 2017-09-11 13:45 - 2017-09-11 13:45 - 000092472 _____ () C:\Program Files\iTunes\zlib1.dll 2017-09-11 13:45 - 2017-09-11 13:45 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll 2018-01-08 20:10 - 2018-01-03 02:20 - 004063064 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\libglesv2.dll 2018-01-08 20:10 - 2018-01-03 02:20 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\libegl.dll 2018-02-20 21:44 - 2018-02-20 21:44 - 003739648 _____ () C:\Windows\rss\csrss.exe 2018-02-21 17:22 - 2018-02-21 17:22 - 000538112 _____ () C:\Users\grant\AppData\Local\Temp\b7f0a41d25b94c14bb522bf9f7f8119c\YqEG4EJp.exe 2016-10-01 06:08 - 2016-10-01 06:08 - 031723696 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe 2018-02-20 21:39 - 2018-02-20 21:39 - 000012800 _____ () C:\Users\grant\AppData\Local\achpow.dll 2016-10-12 16:28 - 2016-10-12 16:28 - 040523456 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll 2017-05-03 21:00 - 2017-05-03 21:00 - 002131968 _____ () C:\Program Files (x86)\Stamps.com Connect\sdc-pn.dll 2016-10-12 00:08 - 2016-10-12 00:08 - 000118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node 2016-10-12 00:08 - 2016-10-12 00:08 - 000223232 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node 2016-10-12 00:08 - 2016-10-12 00:08 - 000117248 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node 2016-10-12 00:08 - 2016-10-12 00:08 - 000124928 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node 2016-10-12 19:11 - 2016-10-12 19:11 - 000098496 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin.dll 2016-10-12 00:08 - 2016-10-12 00:08 - 000166400 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node 2017-09-19 09:35 - 2017-09-19 09:35 - 000134008 _____ () C:\Program Files (x86)\Dell Customer Connect\ServiceTagPlusPlus.dll 2015-06-23 16:26 - 2015-06-23 16:26 - 000155888 _____ () c:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll 2017-11-21 13:50 - 2017-11-21 13:50 - 000134016 _____ () C:\Program Files (x86)\Dell Update\ServiceTagPlusPlus.dll 2016-05-16 21:50 - 2016-05-16 21:50 - 001243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nanoheal Client => "DisplayName"="Nanoheal" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nanoheal Client => "ErrorControl"="1" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nanoheal Client => "ImagePath"="C:\Program Files\Nanoheal\Client\srvc.exe" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nanoheal Client => "ObjectName"="LocalSystem" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nanoheal Client => "Start"="2" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nanoheal Client => "Type"="272" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nanoheal Client\Parameters => "Application"="C:\Program Files\Nanoheal\Client\srvc.exe" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nanoheal Client\Parameters => "AppParameters"="" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\driversupport.com -> hxxp://apps.driversupport.com IE trusted site: HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\driversupport.com -> hxxps://apps.driversupport.com ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-10-30 00:24 - 2018-02-20 23:12 - 000009256 ____N C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 gf.tools.avast.com 127.0.0.1 pair.ff.avast.com 127.0.0.1 ipm-provider.ff.avast.com 127.0.0.1 ipm-provider.ff.avast.com 127.0.0.1 ipm-provider.ff.avast.com 127.0.0.1 id.avast.com 127.0.0.1 s5355946.iavs9x.u.avast.com 127.0.0.1 s5355946.ivps9x.u.avast.com 127.0.0.1 s5355946.ivps9tiny.u.avast.com 127.0.0.1 s5355946.vpsnitro.u.avast.com 127.0.0.1 s5355946.vpsnitrotiny.u.avast.com 127.0.0.1 s5355946.iavs5x.u.avast.com 127.0.0.1 v7.stats.avast.com 127.0.0.1 v7.stats.avast.com 127.0.0.1 v7event.stats.avast.com 127.0.0.1 sm00.avast.com 127.0.0.1 submit5.avast.com 127.0.0.1 geoip.avast.com 127.0.0.1 l2932126.iavs9x.u.avast.com 127.0.0.1 l2932126.ivps9x.u.avast.com 127.0.0.1 l2932126.ivps9tiny.u.avast.com 127.0.0.1 l2932126.vpsnitro.u.avast.com 127.0.0.1 l2932126.vpsnitrotiny.u.avast.com 127.0.0.1 l2932126.iavs5x.u.avast.com 127.0.0.1 v7.stats.avast.com 127.0.0.1 v7.stats.avast.com 127.0.0.1 v7event.stats.avast.com 127.0.0.1 sm00.avast.com 127.0.0.1 submit5.avast.com 127.0.0.1 geoip.avast.com There are 211 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-106698449-1581471573-1421150475-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\dell\BlueLava_1112000xx_inspiron_wallpaper58095_16x9_72dpi_RGB.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\StartupFolder: => "QuickBooks Update Agent.lnk" HKLM\...\StartupApproved\StartupFolder: => "QuickBooks_Standard_21.lnk" HKLM\...\StartupApproved\Run: => "macworldpretends" HKLM\...\StartupApproved\Run: => "macworldmacworld" HKLM\...\StartupApproved\Run: => "macworld" HKLM\...\StartupApproved\Run: => "NanohealCApp" HKLM\...\StartupApproved\Run32: => "kassebaumunfiltered" HKLM\...\StartupApproved\Run32: => "kassebaumkassebaum" HKLM\...\StartupApproved\Run32: => "kassebaum" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\StartupFolder: => "ricostruzionericostruzione.lnk" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\StartupFolder: => "ricostruzione.lnk" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "3IHXj4TO.exe" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "pretendsmacworld" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "unfilteredkassebaum" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "mammon" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "pretendspretends" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "pretends" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "unfilteredunfiltered" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "unfiltered" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "CloudNet" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "enhancer" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "szfKlMoPVI.exe" HKU\S-1-5-21-106698449-1581471573-1421150475-1001\...\StartupApproved\Run: => "THARBEKOHH.exe" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{64DCDAE7-265E-40E4-AB17-7C123269FD05}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe FirewallRules: [{C4ED02C4-DC5B-4A91-B367-FB52ADB3B9C8}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe FirewallRules: [{4A2FCC48-6F67-4B05-8CED-79AEBB9A6EB1}] => (Allow) C:\Program Files (x86)\Epson Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{8CCE8054-CAD1-4DD1-9098-F0BD001175AE}] => (Allow) C:\Program Files (x86)\Epson Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{FDAE6556-B78A-4A18-B569-FDCB29FF6984}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{1A6DC3CC-9868-4B87-BE1C-B78E432691BB}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{A1642C2A-CD07-4628-94AC-609B85ED548A}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{100E87D2-C92E-420B-A673-BE77B36A2E01}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [{0B49C904-B31C-441D-AE2A-B7A638F7BFB2}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [{9BA60AF1-1706-47AA-8CAE-D94ED1782694}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{08056F2F-B803-45FF-B661-BBE647A85053}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{A5D166D9-BF9A-4BBD-BAAA-AE3991C23223}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E854FB6A-4B67-4535-816A-20B7A118BC4F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{A7C9D8B0-9171-4E77-BA29-744D19127D2A}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{B6D7DC8A-E663-430F-81F6-47FA13E27769}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{BE8BD5FE-02D0-455A-B787-DAAEC1889CDD}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{EFCAABBC-C0B1-4BE0-BF18-FC4EE7FE5115}] => (Allow) C:\WINDOWS\system32\rundll32.exe FirewallRules: [{945A048C-70D5-49EF-B068-8A5A0B5A6833}] => (Allow) C:\WINDOWS\system32\rundll32.exe FirewallRules: [{4F5E84A4-8F61-465B-BF0F-6612C6821FF5}] => (Allow) C:\Program Files (x86)\Dobler\ballgame.exe FirewallRules: [{4AE73E65-0810-4174-9292-FA5A66302A30}] => (Allow) C:\Program Files (x86)\Dyker\ballgame.exe FirewallRules: [{CF932703-A5D3-4697-A95F-6905865B32BF}] => (Allow) C:\Program Files (x86)\emancipation\aix.exe FirewallRules: [{30575A5A-FD79-46B0-949F-D2A185E44429}] => (Allow) C:\Program Files\Nanoheal\Client\cust.exe FirewallRules: [{950F4B02-E384-4870-BAEB-500D5A0659D4}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{4ED127A8-DB2E-4B8E-8FC0-6F58F289E0B9}] => (Allow) C:\Windows\System32\rundll32.exe ==================== Restore Points ========================= 03-02-2018 14:46:50 Dell Update: Dell Foundation Services 06-02-2018 20:05:07 Windows Update 10-02-2018 04:25:14 Windows Modules Installer 13-02-2018 21:00:47 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/21/2018 10:54:07 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: g6FAD.tmp.exe, version: 0.0.0.0, time stamp: 0x5a7beac2 Faulting module name: g6FAD.tmp.exe, version: 0.0.0.0, time stamp: 0x5a7beac2 Exception code: 0xc0000409 Fault offset: 0x0000000000007bac Faulting process id: 0x13dc Faulting application start time: 0x01d3aba178adf37d Faulting application path: C:\WINDOWS\TEMP\g6FAD.tmp.exe Faulting module path: C:\WINDOWS\TEMP\g6FAD.tmp.exe Report Id: aea13779-8be1-4f0d-8a3c-4e1fc98054c8 Faulting package full name: Faulting package-relative application ID: Error: (02/21/2018 10:49:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbam.exe, version: 3.0.0.1284, time stamp: 0x5a15ab42 Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x59a63e00 Exception code: 0xc0000005 Fault offset: 0x001aa3b6 Faulting process id: 0x13bc Faulting application start time: 0x01d3aba0f2f795a2 Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe Faulting module path: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll Report Id: 4ab07eee-d071-49f9-8abc-54787fd70c9b Faulting package full name: Faulting package-relative application ID: Error: (02/21/2018 05:31:38 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbam.exe, version: 3.0.0.1284, time stamp: 0x5a15ab42 Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x59a63e00 Exception code: 0xc0000005 Fault offset: 0x001aa3b6 Faulting process id: 0x2bac Faulting application start time: 0x01d3ab747fc62896 Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe Faulting module path: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll Report Id: 6d870896-b305-4f84-a772-3bee345d2d92 Faulting package full name: Faulting package-relative application ID: Error: (02/21/2018 05:24:21 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: g6FAD.tmp.exe, version: 0.0.0.0, time stamp: 0x5a7beac2 Faulting module name: g6FAD.tmp.exe, version: 0.0.0.0, time stamp: 0x5a7beac2 Exception code: 0xc0000409 Fault offset: 0x0000000000007bac Faulting process id: 0xaa8 Faulting application start time: 0x01d3ab7365d2f5e3 Faulting application path: C:\WINDOWS\TEMP\g6FAD.tmp.exe Faulting module path: C:\WINDOWS\TEMP\g6FAD.tmp.exe Report Id: dd1f864d-035e-47c7-9c23-933b757a4348 Faulting package full name: Faulting package-relative application ID: Error: (02/21/2018 05:23:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: starter.exe, version: 1.0.0.1, time stamp: 0x5a8e08f9 Faulting module name: ntdll.dll, version: 10.0.16299.248, time stamp: 0x3a21d961 Exception code: 0xc0000028 Fault offset: 0x00061594 Faulting process id: 0x2eb4 Faulting application start time: 0x01d3ab7343b04148 Faulting application path: C:\Users\grant\AppData\Local\Temp\ciybtfik.312\starter.exe Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll Report Id: a8b8262e-d1fe-4ccb-a4c2-44b51a337cc9 Faulting package full name: Faulting package-relative application ID: Error: (02/21/2018 05:23:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: netstream.exe, version: 8.6.0.1004, time stamp: 0x5a8dd1bc Faulting module name: netstream.exe, version: 8.6.0.1004, time stamp: 0x5a8dd1bc Exception code: 0xc0000005 Fault offset: 0x0000331c Faulting process id: 0x3394 Faulting application start time: 0x01d3ab73454c9bde Faulting application path: C:\Users\grant\AppData\Local\Temp\f4cii1ld.15u\netstream.exe Faulting module path: C:\Users\grant\AppData\Local\Temp\f4cii1ld.15u\netstream.exe Report Id: 84789a67-3fb5-4721-9561-9cd5f2192f91 Faulting package full name: Faulting package-relative application ID: Error: (02/21/2018 05:23:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: starter.exe, version: 1.0.0.1, time stamp: 0x5a8e08f9 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc00001a5 Fault offset: 0x04630e3a Faulting process id: 0x2eb4 Faulting application start time: 0x01d3ab7343b04148 Faulting application path: C:\Users\grant\AppData\Local\Temp\ciybtfik.312\starter.exe Faulting module path: unknown Report Id: fd756b2d-08d0-473e-88c9-f519673f4bff Faulting package full name: Faulting package-relative application ID: Error: (02/21/2018 05:23:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: netstream.exe, version: 8.6.0.1004, time stamp: 0x5a8dd1bc Faulting module name: netstream.exe, version: 8.6.0.1004, time stamp: 0x5a8dd1bc Exception code: 0xc0000005 Fault offset: 0x0000331c Faulting process id: 0x3388 Faulting application start time: 0x01d3ab7342f7edb2 Faulting application path: C:\Users\grant\AppData\Local\Temp\roibfb5a.xgr\netstream.exe Faulting module path: C:\Users\grant\AppData\Local\Temp\roibfb5a.xgr\netstream.exe Report Id: fe944831-e674-4e1f-958f-63231f8ed7f4 Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (02/21/2018 11:08:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (02/21/2018 11:03:18 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (02/21/2018 10:57:14 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk0\DR0. Error: (02/21/2018 10:57:14 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk0\DR0. Error: (02/21/2018 10:57:14 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk0\DR0. Error: (02/21/2018 10:57:14 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk0\DR0. Error: (02/21/2018 10:57:14 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk0\DR0. Error: (02/21/2018 10:56:52 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk0\DR0. Windows Defender: =================================== Date: 2018-02-20 21:39:18.821 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Tiggre!rfn&threatid=2147723625&enterprise=0 Name: Trojan:Win32/Tiggre!rfn ID: 2147723625 Severity: Severe Category: Trojan Path: file:_C:\Program Files (x86)\texttotalk\uninstaller.exe Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Users\grant\AppData\Local\Temp\is-VKJ16.tmp\jfk0021.exe Signature Version: AV: 1.261.1406.0, AS: 1.261.1406.0, NIS: 118.2.0.0 Engine Version: AM: 1.1.14500.5, NIS: 2.1.14202.0 Date: 2018-02-20 21:38:32.638 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=SoftwareBundler:Win32/ICLoader&threatid=222548&enterprise=0 Name: SoftwareBundler:Win32/ICLoader ID: 222548 Severity: High Category: Software Bundler Path: file:_C:\Users\grant\AppData\Local\Temp\instalelerxvid.exe Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Windows\SysWOW64\WerFault.exe Signature Version: AV: 1.261.1406.0, AS: 1.261.1406.0, NIS: 118.2.0.0 Engine Version: AM: 1.1.14500.5, NIS: 2.1.14202.0 Date: 2018-02-20 21:38:31.290 Description: Windows Defender Antivirus has detected a suspicious behavior. Name: Behavior:Win32/DroppedKnownMalware ID: 293997875 Severity: Low Category: Suspicious Behavior Path Found: file:_C:\Users\grant\AppData\Local\Temp\is-VKJ16.tmp\jfk0021.exe;process:_7564 Detection Origin: Local machine Detection Type: Suspicious Detection Source: Real-Time Protection Status: Executing Process Name: C:\Users\grant\AppData\Local\Temp\is-VKJ16.tmp\jfk0021.exe Signature ID: 41453017067075 Signature Version: AV: 1.261.1406.0, AS: 1.261.1406.0 Engine Version: 1.1.14500.5 Fidelity Label: Low Target File Name: C:\Program Files\Windows Portable Devices\CCRPDYKVVQ\JBJRHLXLTR.exe Date: 2018-02-20 21:38:29.635 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=SoftwareBundler:MSIL/Wizrem&threatid=225135&enterprise=0 Name: SoftwareBundler:MSIL/Wizrem ID: 225135 Severity: High Category: Software Bundler Path: file:_C:\Program Files\Windows Portable Devices\CCRPDYKVVQ\JBJRHLXLTR.exe Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Users\grant\AppData\Local\Temp\is-VKJ16.tmp\jfk0021.exe Signature Version: AV: 1.261.1406.0, AS: 1.261.1406.0, NIS: 118.2.0.0 Engine Version: AM: 1.1.14500.5, NIS: 2.1.14202.0 Date: 2018-02-20 21:38:27.377 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=SoftwareBundler:Win32/ICLoader&threatid=222548&enterprise=0 Name: SoftwareBundler:Win32/ICLoader ID: 222548 Severity: High Category: Software Bundler Path: file:_C:\Users\grant\AppData\Local\Temp\instalelerxvid.exe Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Windows\SysWOW64\WerFault.exe Signature Version: AV: 1.261.1406.0, AS: 1.261.1406.0, NIS: 118.2.0.0 Engine Version: AM: 1.1.14500.5, NIS: 2.1.14202.0 Date: 2018-02-02 21:13:36.774 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.261.645.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.14500.5 Error code: 0x80240016 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. Date: 2018-01-29 11:16:32.361 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.261.441.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.14500.5 Error code: 0x80072ee2 Error description: The operation timed out Date: 2018-01-29 11:16:32.360 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 118.2.0.0 Update Source: Microsoft Malware Protection Center Signature Type: Network Inspection System Update Type: Full Current Engine Version: Previous Engine Version: 2.1.14202.0 Error code: 0x80072ee2 Error description: The operation timed out Date: 2018-01-22 23:34:48.380 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.261.125.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.14500.5 Error code: 0x80072ee2 Error description: The operation timed out Date: 2018-01-22 23:34:48.379 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 118.2.0.0 Update Source: Microsoft Malware Protection Center Signature Type: Network Inspection System Update Type: Full Current Engine Version: Previous Engine Version: 2.1.14202.0 Error code: 0x80072ee2 Error description: The operation timed out CodeIntegrity: =================================== Date: 2018-02-21 22:58:28.121 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-21 22:58:28.119 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-21 22:55:40.179 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-21 22:55:40.174 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-21 22:54:48.473 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-21 22:54:48.471 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-21 18:48:09.665 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-21 18:48:09.662 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz Percentage of memory in use: 25% Total physical RAM: 16253.9 MB Available physical RAM: 12107.21 MB Total Virtual: 18685.9 MB Available Virtual: 14112.36 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:464.02 GB) (Free:183.76 GB) NTFS Drive e: (UUI) (Removable) (Total:7.53 GB) (Free:6.57 GB) FAT32 \\?\Volume{4507586a-1365-4483-ab26-5506fc6b9361}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.43 GB) FAT32 \\?\Volume{7375b5aa-475c-494d-a078-248bcfea4263}\ (WINRETOOLS) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS \\?\Volume{f493fe56-82e0-49e3-b011-80fc5deb74c3}\ () (Fixed) (Total:0 GB) (Free:0 GB) \\?\Volume{1642a316-c415-469c-ae53-63d91af1a421}\ (DELLSUPPORT) (Fixed) (Total:1.02 GB) (Free:0.49 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 476.9 GB) (Disk ID: 95A8CFA1) Partition: GPT. ======================================================== Disk: 1 (Size: 7.6 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=7.6 GB) - (Type=0C) ==================== End of Addition.txt ============================