Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-11-2020 Ran by Karol (01-12-2020 11:57:39) Running from C:\Users\Karol\Downloads Windows 7 Professional Service Pack 1 (X64) (2018-02-13 10:32:47) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1926918652-2461648831-38883309-500 - Administrator - Disabled) Guest (S-1-5-21-1926918652-2461648831-38883309-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1926918652-2461648831-38883309-1002 - Limited - Enabled) Karol (S-1-5-21-1926918652-2461648831-38883309-1000 - Administrator - Enabled) => C:\Users\Karol ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1926918652-2461648831-38883309-1000\...\uTorrent) (Version: 3.5.5.45790 - BitTorrent Inc.) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 20.013.20066 - Adobe Systems Incorporated) Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.1.102.64 - Adobe Systems Incorporated) ALLMediaServer (HKLM\...\{FE77909E-B782-4554-A92A-4D887CEF0ACC}_is1) (Version: 1.5 - ALLPlayer Ltd.) ALLPlayer (wersja 8.8.2) (HKLM\...\{68972948-F221-4267-9EB6-2EB5D913C4CF}_is1) (Version: 8.8.2 - ALLPlayer Ltd.) ALLPlayer Remote Control (HKLM-x32\...\{146BDBDD-ACD9-4B04-A286-C27471841E8E}_is1) (Version: 2.5 - ALLPlayer Group, Ltd.) Amiga SWOS version 2.19 (HKLM-x32\...\{45E70F4F-2A12-4DCE-802B-4A4F6BC7DE87}_is1) (Version: 2.19 - SWOS United e.V.) Ample Bass P II version 2.6.0 (HKLM-x32\...\{1C181D3B-41B6-4714-AB59-91E18C5EE708}_is1) (Version: 2.6.0 - Ample Sound Technology Co., Ltd.) Ample Bass P Lite II version 2.3.1 (HKLM-x32\...\{26ACA0DD-7C66-40D7-B992-CC27CA024F2A}_is1) (Version: 2.3.1 - Ample Sound Technology Co., Ltd.) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach) Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros) Audacity 2.2.2 (HKLM-x32\...\Audacity_is1) (Version: 2.2.2 - Audacity Team) Backup and Sync from Google (HKLM\...\{3A8CD593-8CF9-45B4-9932-FC41CBC14E15}) (Version: 3.53.3404.7585 - Google, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.66 - Piriform) ChomikBox (HKLM-x32\...\{8E4185CC-4FF3-46B9-A4DB-5B850B71ABC4}) (Version: 2.0.8.2 - Chomikuj.pl) DFX (HKLM-x32\...\DFX) (Version: 12.023.0.0 - Power Technology) Discord (HKU\S-1-5-21-1926918652-2461648831-38883309-1000\...\Discord) (Version: 0.0.306 - Discord Inc.) doPDF (HKLM\...\{1896977D-F518-4D39-8F18-98D584919675}) (Version: 10.8.125 - Softland) Hidden doPDF 10 (HKLM-x32\...\{8c48de0d-00f9-45e3-9a05-ba5fbb261a8d}) (Version: 10.8.125 - Softland) doPDF 10 add-in for Microsoft Office (x64) (HKLM\...\{50A1AFC8-29DA-46D8-9632-B5F9CA4B9384}) (Version: 10.8.125 - Softland) doPDF 10 add-in for Microsoft Office (x86) (HKLM-x32\...\{1A76DC64-A3EF-4475-A7FD-521DF9E6295E}) (Version: 10.8.125 - Softland) doPDF 10 Printer Driver (HKLM\...\{015C9318-A833-4B7A-9F15-38E373D50E8C}) (Version: 10.8.125 - Softland) Epic Games Launcher (HKLM-x32\...\{9E23F6C0-880F-4A3D-B389-0E2DDF453A63}) (Version: 1.1.291.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Epson Printer Connection Checker (HKLM-x32\...\{189DE071-E0BC-4BA5-8E34-83D5ED12600B}) (Version: 3.2.0.0 - Seiko Epson Corporation) ETDWare PS/2-X64 10.7.17.5_WHQL (HKLM\...\Elantech) (Version: 10.7.17.5 - ELAN Microelectronic Corp.) FL Studio 12 (HKLM-x32\...\FL Studio 12) (Version: - Image-Line) FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line) Football Manager 2017 (HKLM\...\Football Manager 2017_is1) (Version: 1.0 - ) GG (HKU\S-1-5-21-1926918652-2461648831-38883309-1000\...\GG) (Version: 12 - England Sp. z o.o.) GIMP 2.10.14 (HKLM\...\GIMP-2_is1) (Version: 2.10.14 - The GIMP Team) GK Amplification 2 LE 2.2.2 (HKLM-x32\...\{CB13830D-9A15-4D25-A55C-9E52BF57DD4B}_is1) (Version: 2.2.2 - Audiffex) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 87.0.4280.66 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.36.31 - Google LLC) Hidden Gothic (HKLM-x32\...\{758A4269-70E5-4B11-B419-F692882408A9}) (Version: 1.08 - Piranha Bytes) Guitar Pro 5.2 (HKLM-x32\...\Guitar Pro 5_is1) (Version: - Arobas Music) Guitar Pro 7 - Soundbanks (HKLM-x32\...\com.arobas-music.guitarpro7-soundbanks_is1) (Version: 1.1.123 - Arobas Music) Guitar Pro 7 (HKLM-x32\...\{BF4EDCFF-ED20-4AF6-A636-EBAC931336CD}_is1) (Version: 7.5.3.1730 - Arobas Music) Heroes of Might & Magic III - HD Edition (HKLM-x32\...\Heroes of Might & Magic III - HD Edition_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter) HP Deskjet 1050 J410 series Basic Device Software (HKLM\...\{F294770E-F869-400F-81C3-614B5F13CA54}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Deskjet 1050 J410 series Product Improvement Study (HKLM\...\{D638A23C-5C5F-4B71-A354-EC78B2BDD320}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) IK Multimedia Authorization Manager version 1.0.26 (HKLM\...\{85BC0DCB-69E5-4279-AA25-F108EF896588}_is1) (Version: 1.0.26 - IK Multimedia) IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line) Intel Driver && Support Assistant (HKLM-x32\...\{E051A413-9853-4901-AF60-176ED50E7329}) (Version: 20.10.42.5 - Intel) Hidden Intel(R) Computing Improvement Program (HKLM\...\{9C2782AC-55D3-4A41-889C-34A51A2CEB67}) (Version: 2.4.05982 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\...\{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}) (Version: 15.0.0.0059 - Intel Corporation) Intel® Driver & Support Assistant (HKLM-x32\...\{d300d10a-0615-4d4d-ba52-e859849aefce}) (Version: 20.10.42.5 - Intel) Intel® USB 3.1 Device Driver (HKLM\...\{7DFE2F7E-3154-45D6-A468-4725DE033AC8}) (Version: 15.2.30.280 - Intel Corporation) LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Lightworks (HKLM-x32\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 14.5.0.0 - EditShare) Malwarebytes version 4.2.3.96 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.2.3.96 - Malwarebytes) Microsoft .NET Framework 4.8 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.8.03761 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127 (HKLM-x32\...\{e31cb1a4-76b5-46a5-a084-3fa419e82201}) (Version: 14.24.28127.4 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) MODO BASS version 1.5.0 (HKLM\...\{C882B130-90DD-4F00-9D6B-2F58D923E92B}_is1) (Version: 1.5.0 - IK Multimedia) Mozilla Firefox 80.0 (x64 pl) (HKLM\...\Mozilla Firefox 80.0 (x64 pl)) (Version: 80.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 80.0 - Mozilla) NapiProjekt (2.2.0.2399) (HKLM-x32\...\NapiProjekt_is1) (Version: - ) Napisy24 (HKLM-x32\...\{D1985DBC-F09E-4317-91B8-932AD0FD4A27}_is1) (Version: 1.9.4 - Napisy24.pl) Narzędzia sprawdzające pakietu Microsoft Office 2013 — polski (HKLM\...\{90150000-001F-0415-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: - Native Instruments) Native Instruments Guitar Rig 5 (HKLM-x32\...\Native Instruments Guitar Rig 5) (Version: - Native Instruments) Native Instruments Guitar Rig Mobile I/O (HKLM-x32\...\Native Instruments Guitar Rig Mobile I/O) (Version: - Native Instruments) Native Instruments Guitar Rig Session I/O (HKLM-x32\...\Native Instruments Guitar Rig Session I/O) (Version: - Native Instruments) Native Instruments Rig Kontrol 3 (HKLM-x32\...\Native Instruments Rig Kontrol 3) (Version: - Native Instruments) Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: - Native Instruments) Need for Speed™ ProStreet (HKLM-x32\...\{CC419DDC-E0F0-4013-B25A-6FA036516F0D}) (Version: 1.0.1.0 - Electronic Arts) Odinstaluj drukarkę EPSON L310 Series (HKLM\...\EPSON L310 Series) (Version: - SEIKO EPSON Corporation) Office 2016 KMS Activator Ultimate v1.1 Final (HKLM\...\Office 2016 KMS Activator Ultimate v1.1 Final_is1) (Version: v1.1 Final - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Oprogramowanie Intel® PROSet/Wireless WiFi (HKLM\...\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation) PES 6 Firebird UEFA Euro 2020 wersja 2.0 (HKLM-x32\...\{3D30945A-CD80-4A98-A8CA-84B1727FCFF0}_is1) (Version: 2.0 - Sany) Platform (HKLM-x32\...\{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.) Hidden PowerISO (HKLM-x32\...\PowerISO) (Version: 7.0 - Power Software Ltd) Pro Evolution Soccer 2011 (HKLM-x32\...\Pro Evolution Soccer 2011_is1) (Version: - oZEROth2008) Pro Evolution Soccer 6 (HKLM-x32\...\{EBB794ED-D282-4334-92FB-254481EFF514}) (Version: 1.00.0000 - KONAMI) Hidden Pro Evolution Soccer 6 (HKLM-x32\...\InstallShield_{EBB794ED-D282-4334-92FB-254481EFF514}) (Version: 1.00.0000 - KONAMI) Rapture3D 2.4.8 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6413 - Realtek Semiconductor Corp.) ReaPlugs/x64 (HKLM\...\ReaPlugs) (Version: - ) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) SimCity 2000 Special Edition (HKLM-x32\...\GOGPACKSIMCITY2000_is1) (Version: 2.0.0.14 - GOG.com) Spotify (HKU\S-1-5-21-1926918652-2461648831-38883309-1000\...\Spotify) (Version: 1.1.45.621.gdddebadc - Spotify AB) Steinberg Cubase 5 (HKLM-x32\...\{4A19D6AC-ADE0-4A07-80FF-9C9812C45557}) (Version: 5.1.2 - Steinberg Media Technologies GmbH) Steinberg HALionOne Expression Set (HKLM-x32\...\{E22AD5D3-EB60-4A8F-835C-6C10E369DCE2}) (Version: 1.0.1.0 - Steinberg Media Technologies GmbH) Stronghold HD (HKLM-x32\...\GOGPACKSTRONGHOLDHD_is1) (Version: 2.0.0.3 - GOG.com) SWOS 2020 Ver.1.2 (HKLM-x32\...\SWOS 2020 Ver.1.2) (Version: 1.2 - SWOS United) TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.6.7 - TeamViewer) Update for Skype for Business 2015 (KB4484097) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{1EB78C78-BFAF-4052-BD35-9A0F99B941CC}) (Version: - Microsoft) Update for Skype for Business 2015 (KB4484097) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{1EB78C78-BFAF-4052-BD35-9A0F99B941CC}) (Version: - Microsoft) Update for Skype for Business 2015 (KB4484097) 64-Bit Edition (HKLM\...\{90150000-012B-0415-1000-0000000FF1CE}_Office15.PROPLUS_{1EB78C78-BFAF-4052-BD35-9A0F99B941CC}) (Version: - Microsoft) VIA Platforma Menedżera urządzeń (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.) VLC media player (HKLM\...\VLC media player) (Version: 3.0.8 - VideoLAN) VST Bridge 1.1 (HKLM-x32\...\VST Bridge_is1) (Version: - ) Windows Driver Package - Broadcom Bluetooth (06/15/2009 6.2.0.9000) (HKLM\...\6B8550A319DDC8B17F35F4A89988705E4592349B) (Version: 06/15/2009 6.2.0.9000 - Broadcom) Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) (HKLM\...\6B6B5E96843E55CF5CF8C7E45FB457F1FE642FF1) (Version: 07/30/2009 6.2.0.9405 - Broadcom) Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom) WinRAR 5.50 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH) Zoom (HKU\S-1-5-21-1926918652-2461648831-38883309-1000\...\ZoomUMX) (Version: 4.6 - Zoom Video Communications, Inc.) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-11-03] (Google LLC -> Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-11-03] (Google LLC -> Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-11-03] (Google LLC -> Google) ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2020-11-03] (Google LLC -> Google) ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2018-02-11] (Power Software Limited -> Power Software Ltd) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-09-13] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-09-13] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-12-01] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2020-11-03] (Google LLC -> Google) ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2018-02-11] (Power Software Limited -> Power Software Ltd) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2015-06-01] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-12-01] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2018-02-11] (Power Software Limited -> Power Software Ltd) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-09-13] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-09-13] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [msacm.vorbis] => C:\Windows\system32\vorbis.acm [1470976 2015-03-11] (HMS hxxp://hp.vector.co.jp/authors/VA012897/) [File not signed] HKLM\...\Drivers32: [msacm.vorbis] => C:\Windows\SysWOW64\vorbis.acm [1554944 2015-03-11] (HMS hxxp://hp.vector.co.jp/authors/VA012897/) [File not signed] ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\":: WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99] WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate] ==================== Loaded Modules (Whitelisted) ============= 2011-12-05 07:53 - 2011-12-05 07:53 - 000333312 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\BluetoothHS\BTHSSupplicant.dll 2011-12-05 08:20 - 2011-12-05 08:20 - 000105472 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\BluetoothHS\UsR3IoPort.dll 2020-06-04 19:16 - 2020-06-04 19:16 - 000018944 _____ (Softland) [File not signed] C:\Windows\System32\novamn10.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Version 11) (Whitelisted) ========== HKU\S-1-5-21-1926918652-2461648831-38883309-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gazeta.pl/0,0.html?p=190 HKU\S-1-5-21-1926918652-2461648831-38883309-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pl-pl/?ocid=iehp BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2019-07-18] (Microsoft Corporation -> Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2019-07-18] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation -> Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2018-02-15] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2020-03-06 10:44 - 000000889 _____ C:\Windows\system32\drivers\etc\hosts 127.0.0.1 www.r2rdownload.com 127.0.0.1 www.elephantafiles.com ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1926918652-2461648831-38883309-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Karol\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: WMPNetworkSvc => 2 MSCONFIG\Services: wscsvc => 2 MSCONFIG\Services: wuauserv => 2 ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) C:\Windows\system32\sppsvc.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) C:\Windows\system32\sppsvc.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{2BE5BF10-47A4-439F-9FF3-139281B331E7}] => (Allow) C:\Users\Karol\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{960BB979-9627-471E-B66E-1F5B58A7A184}] => (Allow) C:\Users\Karol\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{BC669730-28B3-45A6-AF29-9B20163A6DE5}] => (Allow) C:\Users\Karol\AppData\Local\Programs\Opera\48.0.2685.50\opera.exe => No File FirewallRules: [TCP Query User{05461886-15D0-4DA4-A843-0C980A95CF65}C:\users\karol\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\karol\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [UDP Query User{76F2408C-C6E3-4120-9E1F-3A6AB59A3DEF}C:\users\karol\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\karol\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{1884C8B5-136C-400E-BA96-EA03ABD1F448}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe (Hewlett Packard -> Hewlett-Packard Co.) FirewallRules: [TCP Query User{334E505D-5142-42BC-A8A3-21F666523C03}C:\users\karol\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\karol\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [UDP Query User{5680EB03-E1AB-470A-B2FE-4CFCD94A89E4}C:\users\karol\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\karol\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{174135D5-2806-4063-B2F5-139DFAA9566C}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{AEF056EB-ECD4-4D1F-9D9D-97AE26899849}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{F9CBD750-5BE7-4E05-BCCC-2504D57405A7}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{F91D7236-B231-4F4A-A366-59E3B645F9EA}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{D314585B-8653-4515-A660-1B551948058D}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{F7823012-269A-44A3-9047-B882C81D176B}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{B644F064-A1E6-4D77-8AA5-04E5B43F9DAC}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{D395DDF0-F348-4630-A4C7-3CD21E94C0A3}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{26509830-5916-4CAF-B4A3-D45D79A18559}D:\gry\cs 1.6\hl.exe] => (Allow) D:\gry\cs 1.6\hl.exe (Valve) [File not signed] FirewallRules: [UDP Query User{00713993-B0CC-4503-A15C-4DB1BFE4685C}D:\gry\cs 1.6\hl.exe] => (Allow) D:\gry\cs 1.6\hl.exe (Valve) [File not signed] FirewallRules: [{D08AC954-9EF1-4F5F-A233-4D03DF0CF64C}] => (Allow) C:\Program Files\Lightworks\lightworks.exe (EditShare EMEA (X-Edit Limited) -> ) FirewallRules: [{955D3C74-8160-4947-9E14-395CE2BDFA0B}] => (Allow) C:\Program Files\Lightworks\lightworks.exe (EditShare EMEA (X-Edit Limited) -> ) FirewallRules: [{699F67B4-32F8-4931-9CCF-26FC1DE9CEE7}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe (EditShare EMEA (X-Edit Limited) -> Editshare EMEA) FirewallRules: [{EE5A960A-0053-44EC-9787-1B63DA9F6284}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe (EditShare EMEA (X-Edit Limited) -> Editshare EMEA) FirewallRules: [TCP Query User{33742AA5-7BFB-453C-ACB2-61598EB5B78F}C:\program files (x86)\image-line\fl studio 12\fl64.exe] => (Allow) C:\program files (x86)\image-line\fl studio 12\fl64.exe (Image Line -> Image-Line) [File not signed] FirewallRules: [UDP Query User{40C51C67-EAAC-4420-B208-C65B132D663F}C:\program files (x86)\image-line\fl studio 12\fl64.exe] => (Allow) C:\program files (x86)\image-line\fl studio 12\fl64.exe (Image Line -> Image-Line) [File not signed] FirewallRules: [{C65C1BEF-5336-49FC-A9F8-1C3D39767860}] => (Allow) C:\Users\Karol\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{1842373C-17F4-4947-9918-F2CACAA2AECA}] => (Allow) C:\Users\Karol\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{0A8ACE52-4353-4AE2-8211-78CBF6268978}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{4F306721-3A35-4690-A8D9-E1C737490A4F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{18F30F60-F1A0-439E-8D5A-065E33BBF155}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{137311BB-69E1-4A71-BC48-3EABCFFEA2BC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{8E640383-3A4B-49F0-A5DE-E9508541D6E2}] => (Allow) LPort=8501 FirewallRules: [{087E0625-F71C-4104-8C54-E660B1BFFCA9}] => (Allow) LPort=8501 FirewallRules: [{C7661D18-47EA-4BF9-99C8-90BE6877CD16}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe () [File not signed] FirewallRules: [{07AAE5D7-7312-410A-B847-8F8CEE3590C7}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe () [File not signed] FirewallRules: [{3C478DA8-C5EB-4F99-B18D-C888956F3341}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{AD9F7873-4D73-4955-89D9-911EE864E33F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{0AAB5C89-186F-4542-8F5E-7C9ACE62C9ED}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{90D8CED9-E8FF-480A-8B5F-C4B9FAE66F7A}] => (Allow) C:\Users\Karol\AppData\Local\Temp\download\MiniThunderPlatform.exe (ShenZhen Thunder Networking Technologies Ltd. -> 深圳市迅雷网络技术有限公司) FirewallRules: [{2645B8E8-E1EF-41E2-991F-F4F518EE3402}] => (Allow) C:\Users\Karol\AppData\Local\Temp\download\MiniThunderPlatform.exe (ShenZhen Thunder Networking Technologies Ltd. -> 深圳市迅雷网络技术有限公司) ==================== Restore Points ========================= ==================== Faulty Device Manager Devices ============ Name: PCI Simple Communications Controller Description: PCI Simple Communications Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ======================== Application errors: ================== Error: (12/01/2020 11:43:53 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (12/01/2020 11:43:53 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (12/01/2020 11:38:28 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (12/01/2020 11:05:39 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program mbamtray.exe version 4.0.0.858 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 29c Start Time: 01d6c7b1c48d08ff Termination Time: 60000 Application Path: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe Report Id: 96f9b3e6-33bc-11eb-a6cc-dca971a0a612 Error: (12/01/2020 08:20:07 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (12/01/2020 08:20:07 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (12/01/2020 08:14:45 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (12/01/2020 07:48:50 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. System errors: ============= Error: (12/01/2020 08:13:33 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The novaPDF 10 Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (12/01/2020 08:13:33 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the novaPDF 10 Server service to connect. Error: (12/01/2020 08:09:30 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (12/01/2020 08:09:30 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 70. Error: (12/01/2020 07:53:21 AM) (Source: volsnap) (EventID: 36) (User: ) Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. Error: (12/01/2020 07:42:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The novaPDF 10 Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (12/01/2020 07:42:01 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the novaPDF 10 Server service to connect. Error: (12/01/2020 07:40:06 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The NIHardwareService service terminated unexpectedly. It has done this 1 time(s). Windows Defender: =================================== Date: 2020-03-23 10:00:46.250 Description: Windows Defender scan has been stopped before completion. Scan ID:{A87519B8-2482-47E6-A8AF-0FE3773E4A2A} Scan Type:AntiSpyware Scan Parameters:Quick Scan Date: 2009-07-10 00:03:08.771 Description: Windows Defender scan has been stopped before completion. Scan ID:{80E2C36A-0660-4DE7-A9E4-4EB864A94692} Scan Type:AntiSpyware Scan Parameters:Quick Scan Date: 2009-07-10 00:07:53.255 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version:1.271.442.0 Previous Signature Version:1.269.1075.0 Update Source:Signature Update Folder Signature Type:AntiSpyware Update Type:Delta Current Engine Version:1.1.15000.2 Previous Engine Version:1.1.14901.4 Error code:0x80070666 Error description:Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. Date: 2009-07-10 00:07:53.255 Description: Windows Defender has encountered an error trying to update the engine. New Engine Version:1.1.15000.2 Previous Engine Version:1.1.14901.4 Update Source:Signature Update Folder Error Code:0x80070666 Error description:Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. Date: 2009-07-10 00:02:42.158 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version:1.271.442.0 Previous Signature Version:1.269.1075.0 Update Source:Signature Update Folder Signature Type:AntiSpyware Update Type:Delta Current Engine Version:1.1.15000.2 Previous Engine Version:1.1.14901.4 Error code:0x80070666 Error description:Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. Date: 2009-07-10 00:02:42.158 Description: Windows Defender has encountered an error trying to update the engine. New Engine Version:1.1.15000.2 Previous Engine Version:1.1.14901.4 Update Source:Signature Update Folder Error Code:0x80070666 Error description:Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. Date: 2018-07-05 15:13:30.447 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version:1.271.442.0 Previous Signature Version:1.269.1075.0 Update Source:Signature Update Folder Signature Type:AntiSpyware Update Type:Delta Current Engine Version:1.1.15000.2 Previous Engine Version:1.1.14901.4 Error code:0x80070666 Error description:Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. ==================== Memory info =========================== BIOS: Phoenix Technologies Ltd. 02QA 11/11/2011 Motherboard: SAMSUNG ELECTRONICS CO., LTD. 300E4A/300E5A/300E7A Processor: Intel(R) Pentium(R) CPU B950 @ 2.10GHz Percentage of memory in use: 91% Total physical RAM: 4009.55 MB Available physical RAM: 347.57 MB Total Virtual: 8017.24 MB Available Virtual: 3657.72 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:116.44 GB) (Free:15.96 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:104.72 GB) (Free:56.38 GB) NTFS ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 232.9 GB) (Disk ID: 97646C29) Partition 1: (Not Active) - (Size=11.7 GB) - (Type=1C) Partition 2: (Active) - (Size=116.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=104.7 GB) - (Type=0F Extended) ==================== End of Addition.txt =======================