Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-04-2020 Ran by Gianna Catalina (26-04-2020 19:29:04) Running from C:\Users\Gianna Catalina\Desktop Windows 10 Pro 10240.16384 (X64) (2020-04-25 16:59:48) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2553645042-3655948027-308666166-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2553645042-3655948027-308666166-503 - Limited - Disabled) Gianna Catalina (S-1-5-21-2553645042-3655948027-308666166-1001 - Administrator - Enabled) => C:\Users\Gianna Catalina Guest (S-1-5-21-2553645042-3655948027-308666166-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG Antivirus (Disabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411} AS: AVG Antivirus (Disabled - Up to date) {A3C8941D-8036-3856-D9BB-709D4A2A7EAC} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) AVG AntiVirus FREE (HKLM-x32\...\AVG Antivirus) (Version: 20.2.3116 - AVG Technologies) CCleaner (HKLM\...\CCleaner) (Version: 5.65 - Piriform) Eines de correcció del Microsoft Office 2013: català (HKLM\...\{90150000-001F-0403-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Ferramentas de verificación de Microsoft Office 2013 - Galego (HKLM\...\{90150000-001F-0456-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.122 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2553645042-3655948027-308666166-1001\...\OneDriveSetup.exe) (Version: 19.232.1124.0012 - Microsoft Corporation) Nuance PDF Converter Professional 8 (HKLM\...\{BCE93D4F-0E1C-495D-8710-C753FE5924A3}) (Version: 8.10.6242 - Nuance Communications, Inc.) Nuance PDF Converter Professional 8 (HKLM-x32\...\{BCE93D4F-0E1C-495D-8710-C753FE5924A3}) (Version: 8.10.6242 - Nuance Communications, Inc.) Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7548 - Realtek Semiconductor Corp.) Revisores de Texto do Microsoft Office 2013 – Português do Brasil (HKLM\...\{90150000-001F-0416-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Scansoft PDF Professional (HKLM-x32\...\{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}) (Version: - ) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.12.98 - Synaptics Incorporated) Packages: ========= Complemento de teléfono de Microsoft -> C:\Program Files\WindowsApps\Microsoft.WindowsPhone_10.1802.311.0_x64__8wekyb3d8bbwe [2020-04-25] (Microsoft Corporation) El tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.3.193.0_x86__8wekyb3d8bbwe [2020-04-25] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.6132.0_x64__8wekyb3d8bbwe [2020-04-25] (Microsoft Studios) [MS Ad] MSN Deportes -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.3.193.0_x86__8wekyb3d8bbwe [2020-04-25] (Microsoft Corporation) [MS Ad] MSN Dinero -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.3.193.0_x86__8wekyb3d8bbwe [2020-04-25] (Microsoft Corporation) [MS Ad] MSN Noticias -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.3.193.0_x86__8wekyb3d8bbwe [2020-04-25] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2553645042-3655948027-308666166-1001_Classes\CLSID\{994DDB09-5EF2-4b68-9599-29BB1A2A6944}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated) ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2020-04-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) ContextMenuHandlers1: [PDFC7.ShellExtension] -> {877327F4-8A93-4320-932C-338069C27BEA} => C:\Program Files (x86)\Nuance\PDF Professional 8\ShellExt70.dll [2012-10-23] (Nuance Communications, Inc. -> Nuance Communications, Inc.) ContextMenuHandlers1: [Zeon.GMFCDirectShellExt] -> {C037D85B-2F6F-4B14-9E6D-26D504D9194B} => C:\Program Files (x86)\Nuance\PDF Professional 8\bin\GDirectShellExt.dll [2012-07-25] (Zeon Corporation -> Zeon International Investment Corp. ) [File not signed] ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-25] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2020-04-25] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2020-04-25] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-25] (Malwarebytes Corporation -> Malwarebytes) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2012-07-25 10:32 - 2012-07-25 10:32 - 000350880 _____ (Zeon Corporation -> Zeon International Investment Corp. ) [File not signed] C:\Program Files (x86)\Nuance\PDF Professional 8\bin\GDirectShellExt.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:AEC0AC81 [137] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\91300952.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\91300952.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 06:04 - 2015-07-10 06:02 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2553645042-3655948027-308666166-1001\Control Panel\Desktop\\Wallpaper -> E:\fotos\cel hector 04-ene-2019\20181222_131207.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{533F9296-64D0-4DB3-9C36-549708DDC573}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{8A9BB212-5962-4D95-BEC5-0072D5691BE0}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{A11DDE97-C40D-4CFB-9AB3-EAB04AF06ACC}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{F2948C55-8D50-4F37-8DE7-6AE57208F632}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{15817AF6-3E5D-4C4E-A25C-04FD1E66EEC4}C:\users\gianna catalina\appdata\local\temp\kmsnano\qemu-system-i386.exe] => (Allow) C:\users\gianna catalina\appdata\local\temp\kmsnano\qemu-system-i386.exe No File FirewallRules: [UDP Query User{4C71E44B-04ED-4409-8303-875FBFF5E5A4}C:\users\gianna catalina\appdata\local\temp\kmsnano\qemu-system-i386.exe] => (Allow) C:\users\gianna catalina\appdata\local\temp\kmsnano\qemu-system-i386.exe No File FirewallRules: [{2F369BD3-99CE-4C86-BE7F-CE258F31BD34}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= 26-04-2020 07:51:47 ZHPcleaner ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (04/26/2020 07:25:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: FRST64.exe, version: 26.4.2020.0, time stamp: 0x5ea5d88e Faulting module name: ntdll.dll, version: 10.0.10240.16384, time stamp: 0x559f384f Exception code: 0xc0000005 Fault offset: 0x0000000000074820 Faulting process id: 0x1738 Faulting application start time: 0x01d61c2a22f22bd5 Faulting application path: C:\Users\Gianna Catalina\Desktop\FRST64.exe Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll Report Id: 3cb0cf6e-ccad-4a25-b73f-8ff2eeb57256 Faulting package full name: Faulting package-relative application ID: Error: (04/26/2020 07:24:36 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-DUJPFU4) Description: Activation of app Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App failed with error: -2147023169 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (04/26/2020 07:23:42 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-DUJPFU4) Description: Activation of app Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (04/26/2020 07:19:43 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-DUJPFU4) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (04/26/2020 06:37:45 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-DUJPFU4) Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (04/26/2020 05:44:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.10240.16384, time stamp: 0x559f467c Faulting module name: Windows.UI.Xaml.dll, version: 10.0.10240.16384, time stamp: 0x559f3e90 Exception code: 0xc000027b Fault offset: 0x0000000000479d69 Faulting process id: 0xce8 Faulting application start time: 0x01d61c1c2e9bdc6f Faulting application path: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: 7aabc2d1-7335-4b62-a1df-1a4a07a8f544 Faulting package full name: Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: App Error: (04/26/2020 05:44:00 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-DUJPFU4) Description: Activation of app Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (04/26/2020 05:43:53 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program ShellExperienceHost.exe version 10.0.10240.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: fd8 Start Time: 01d61c0897e56175 Termination Time: 4294967295 Application Path: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Report Id: 5e058606-880f-11ea-9bcc-20689d53f355 Faulting package full name: Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: App System errors: ============= Error: (04/26/2020 07:20:40 PM) (Source: BTHUSB) (EventID: 5) (User: ) Description: The Bluetooth driver expected an HCI event with a certain size but did not receive it. Error: (04/26/2020 07:19:50 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-DUJPFU4) Description: The server {D63B10C5-BB46-4990-A94F-E40B9D520160} did not register with DCOM within the required timeout. Error: (04/26/2020 07:19:43 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-DUJPFU4) Description: The server CortanaUI.AppXd4tad4d57t4wtdbnnmb8v2xtzym8c1n8.mca did not register with DCOM within the required timeout. Error: (04/26/2020 07:19:42 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Sync Host_Session1 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (04/26/2020 06:37:45 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-DUJPFU4) Description: The server App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca did not register with DCOM within the required timeout. Error: (04/26/2020 04:38:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (04/26/2020 04:38:25 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\GIANNA~1\AppData\Local\Temp\ehdrv.sys Error: (04/26/2020 04:38:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Windows Defender: =================================== Date: 2020-04-25 15:52:27.245 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/GendowsBatch&threatid=2147743950&enterprise=0 Name: HackTool:Win32/GendowsBatch ID: 2147743950 Severity: High Category: Tool Path: containerfile:_C:\Windows.old\Windows\KJ\Scripts.cmd;file:_C:\Windows.old\Windows\KJ\Scripts.cmd->(BAT_PREPROC) Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Signature Version: AV: 1.313.2330.0, AS: 1.313.2330.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16900.4, NIS: 2.1.14600.4 Date: 2020-04-25 15:52:27.242 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Wpakill&threatid=2147574170&enterprise=0 Name: HackTool:Win32/Wpakill ID: 2147574170 Severity: High Category: Tool Path: file:_C:\Windows.old\Windows\KJ\Sever2008key.cmd;file:_C:\Windows.old\Windows\KJ\Sever2008R2key.cmd;file:_C:\Windows.old\Windows\KJ\Source\Windows_ServerR.cmd;file:_C:\Windows.old\Windows\KJ\Source\Windows_Vista.cmd;file:_C:\Windows.old\Windows\KJ\Source\Windows_Xp.cmd;file:_C:\Windows.old\Windows\KJ\xp_e.cmd;file:_C:\Windows.old\Windows\KJ\xp_k.cmd Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Signature Version: AV: 1.313.2330.0, AS: 1.313.2330.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16900.4, NIS: 2.1.14600.4 Date: 2020-04-25 15:52:27.234 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen&threatid=2147593794&enterprise=0 Name: HackTool:Win32/Keygen ID: 2147593794 Severity: High Category: Tool Path: file:_C:\Windows.old\Windows\KJ\Vistakey.cmd;file:_C:\Windows.old\Windows\KJ\Windows7key.cmd Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Signature Version: AV: 1.313.2330.0, AS: 1.313.2330.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16900.4, NIS: 2.1.14600.4 Date: 2020-04-25 15:52:27.143 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AutoKMS&threatid=2147685180&enterprise=0 Name: HackTool:Win32/AutoKMS ID: 2147685180 Severity: High Category: Tool Path: file:_C:\Program Files\KMSpico\cert\installAll.cmd;file:_C:\Program Files\KMSpico\scripts\UnInstall_Service.cmd Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Signature Version: AV: 1.313.2330.0, AS: 1.313.2330.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16900.4, NIS: 2.1.14600.4 Date: 2020-04-25 15:52:27.140 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win64/AutoKMS&threatid=2147723334&enterprise=0 Name: HackTool:Win64/AutoKMS ID: 2147723334 Severity: High Category: Tool Path: file:_C:\WINDOWS\SECOH-QAD.dll;file:_C:\WINDOWS\SECOH-QAD.exe Detection Origin: Local machine Detection Type: Concrete Detection Source: User Process Name: Unknown Signature Version: AV: 1.313.2330.0, AS: 1.313.2330.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16900.4, NIS: 2.1.14600.4 Date: 2020-04-25 22:45:32.320 Description: Windows Defender Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions. Date: 2020-04-25 13:55:27.689 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.199.1615.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.11701.0 Error code: 0x80070643 Error description: Fatal error during installation. Date: 2020-04-25 13:55:27.096 Description: Windows Defender has encountered an error trying to update the engine. New Engine Version: 1.1.16900.4 Previous Engine Version: 1.1.11701.0 Error Code: 0x80508007 Error description: Your computer is low on memory. Close some programs and try again, or search Help and Support for information about preventing low memory problems. ==================== Memory info =========================== BIOS: Insyde F.05 07/23/2012 Motherboard: Hewlett-Packard 1854 Processor: Intel(R) Core(TM) i3-2328M CPU @ 2.20GHz Percentage of memory in use: 82% Total physical RAM: 1948.36 MB Available physical RAM: 333.55 MB Total Virtual: 3100.36 MB Available Virtual: 1672.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:232.1 GB) (Free:191.75 GB) NTFS Drive d: () (RAMDisk) (Total:232.1 GB) (Free:191.6 GB) NTFS Drive e: () (Fixed) (Total:232.88 GB) (Free:116.53 GB) NTFS \\?\Volume{11fa6494-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.34 GB) (Free:0.1 GB) NTFS \\?\Volume{11fa6494-0000-0000-0000-401c3a000000}\ () (Fixed) (Total:0.44 GB) (Free:0.13 GB) NTFS ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 11FA6494) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=232.1 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) Partition 4: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS) ==================== End of Addition.txt =======================