Addition
Addition
2024
Ran by SUS (24-06-2024 14:12:59)
Running from E:\downloads\scoped_dir11748_1246212785
Microsoft Windows 11 Pro Version 23H2 22631.3737 (X64) (2024-05-28 11:45:24)
Boot Mode: Normal
==========================================================
(Only the adware programs with "Hidden" flag could be added to the fixlist to
unhide them. The adware programs should be uninstalled manually.)
Packages:
=========
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001_Classes\CLSID\
{0440049F-D1DC-4E46-B27B-98393D79486B}\InprocServer32 -> C:\Users\yashr\AppData\
Local\PowerToys\WinUI3Apps\PowerToys.PowerRenameExt.dll (Microsoft Corporation ->
Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001_Classes\CLSID\
{14d341c5-edb2-efea-ae43-c374d0136ff2}\localserver32 -> C:\Users\yashr\AppData\
Local\PowerToys\PowerToys.PowerLauncher.exe (Microsoft Corporation -> Microsoft
Corporation)
CustomCLSID: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001_Classes\CLSID\
{51B4D7E5-7568-4234-B4BB-47FB3C016A69}\InprocServer32 -> C:\Users\yashr\AppData\
Local\PowerToys\PowerToys.ImageResizerExt.dll (Microsoft Corporation -> Microsoft
Corporation)
CustomCLSID: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001_Classes\CLSID\
{84D68575-E186-46AD-B0CB-BAEB45EE29C0}\InprocServer32 -> C:\Users\yashr\AppData\
Local\PowerToys\WinUI3Apps\PowerToys.FileLocksmithExt.dll (Microsoft Corporation ->
Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001_Classes\CLSID\
{AD856B15-D25E-4008-AFB7-AFAA55586188}\InprocServer32 -> C:\Users\yashr\AppData\
Local\PowerToys\PowerToys.QoiThumbnailProviderCpp.dll (Microsoft Corporation ->
Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001_Classes\CLSID\
{D8034CFA-F34B-41FE-AD45-62FCBB52A6DA}\InprocServer32 -> C:\Users\yashr\AppData\
Local\PowerToys\PowerToys.MonacoPreviewHandlerCpp.dll (Microsoft Corporation ->
Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001_Classes\CLSID\
{DD5CACDA-7C2E-4997-A62A-04A597B58F76}\localserver32 -> C:\Users\yashr\AppData\
Local\PowerToys\PowerToys.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001_Classes\CLSID\
{F2847CBE-CD03-4C83-A359-1A8052C1B9D5}\InprocServer32 -> C:\Users\yashr\AppData\
Local\PowerToys\PowerToys.GcodeThumbnailProviderCpp.dll (Microsoft Corporation ->
Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001_Classes\CLSID\
{FCDD4EED-41AA-492F-8A84-31A1546226E0}\InprocServer32 -> C:\Users\yashr\AppData\
Local\PowerToys\PowerToys.SvgPreviewHandlerCpp.dll (Microsoft Corporation ->
Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\
Program Files\7-Zip\7-zip.dll [2024-05-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD}
=> C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2021-01-22]
(Comodo Security Solutions, Inc. -> COMODO)
ContextMenuHandlers2: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD}
=> C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2021-01-22]
(Comodo Security Solutions, Inc. -> COMODO)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\
Program Files\7-Zip\7-zip.dll [2024-05-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-
BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\
nvhdci.inf_amd64_a72fe1415cc3fd16\nvshext.dll [2024-06-02] (NVIDIA Corporation ->
NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\
Program Files\7-Zip\7-zip.dll [2024-05-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD}
=> C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2021-01-22]
(Comodo Security Solutions, Inc. -> COMODO)
ContextMenuHandlers2_S-1-5-21-2931057295-1006745406-1456292787-1001:
[FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Users\yashr\
AppData\Local\PowerToys\WinUI3Apps\PowerToys.FileLocksmithExt.dll [2024-05-27]
(Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3_S-1-5-21-2931057295-1006745406-1456292787-1001:
[FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Users\yashr\
AppData\Local\PowerToys\WinUI3Apps\PowerToys.FileLocksmithExt.dll [2024-05-27]
(Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3_S-1-5-21-2931057295-1006745406-1456292787-1001:
[PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Users\yashr\
AppData\Local\PowerToys\WinUI3Apps\PowerToys.PowerRenameExt.dll [2024-05-27]
(Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5_S-1-5-21-2931057295-1006745406-1456292787-1001:
[PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Users\yashr\
AppData\Local\PowerToys\WinUI3Apps\PowerToys.PowerRenameExt.dll [2024-05-27]
(Microsoft Corporation -> Microsoft Corporation)
2024-05-28 17:41 - 2024-03-20 02:50 - 000423424 _____ () [File not signed] \\?\C:\
Program Files (x86)\ASUS\ArmouryDevice\resources\app.asar.unpacked\node_modules\
ac_node_addon\build\Release\ac_node_addon.node
2024-05-28 17:41 - 2023-04-15 02:48 - 000319488 _____ () [File not signed] \\?\C:\
Program Files (x86)\ASUS\ArmouryDevice\resources\app.asar.unpacked\node_modules\
sharp\build\Release\sharp-win32-ia32.node
2024-06-24 09:07 - 2024-06-24 09:07 - 000287744 _____ () [File not signed] \\?\C:\
Users\yashr\AppData\Local\Temp\3329fd14-ff3e-4f9d-8bea-8fcc85416852.tmp.node
2024-06-24 09:07 - 2024-06-24 09:07 - 000109056 _____ () [File not signed] \\?\C:\
Users\yashr\AppData\Local\Temp\69db5a43-507b-4307-bc68-dfa36be15523.tmp.node
2024-06-24 09:07 - 2024-06-24 09:07 - 000123392 _____ () [File not signed] \\?\C:\
Users\yashr\AppData\Local\Temp\887c3054-cdf5-4d2b-99b6-9498077d4d48.tmp.node
2024-06-24 09:07 - 2024-06-24 09:07 - 000118272 _____ () [File not signed] \\?\C:\
Users\yashr\AppData\Local\Temp\8a8a5daf-42ea-4f14-ad1a-6673e47edb8d.tmp.node
2024-06-24 09:07 - 2024-06-24 09:07 - 000104960 _____ () [File not signed] \\?\C:\
Users\yashr\AppData\Local\Temp\91467cc9-26f2-4fca-b15f-1b1500cc6c11.tmp.node
2024-06-24 09:07 - 2024-06-24 09:07 - 000665088 _____ () [File not signed] \\?\C:\
Users\yashr\AppData\Local\Temp\961e15e5-732e-4d10-932a-8b2dbecfb60c.tmp.node
2024-06-24 09:07 - 2024-06-24 09:07 - 000137728 _____ () [File not signed] \\?\C:\
Users\yashr\AppData\Local\Temp\c04179e8-3141-4eb8-8c4c-14cb92686c38.tmp.node
2024-06-24 09:07 - 2024-06-24 09:07 - 000665088 _____ () [File not signed] \\?\C:\
Users\yashr\AppData\Local\Temp\e03f1ac5-0c18-4963-a953-b0197f2c2dad.tmp.node
2024-06-24 09:07 - 2024-06-24 09:07 - 000148480 _____ () [File not signed] \\?\C:\
Users\yashr\AppData\Local\Temp\ff012989-da29-43d1-af31-893275fed6f6.tmp.node
2024-06-10 23:02 - 2023-06-17 05:51 - 002787840 _____ () [File not signed] C:\
Users\yashr\AppData\Local\Programs\twinkle-tray\ffmpeg.dll
2024-06-10 23:02 - 2023-06-17 05:51 - 000468992 _____ () [File not signed] C:\
Users\yashr\AppData\Local\Programs\twinkle-tray\libegl.dll
2024-06-10 23:02 - 2023-06-17 05:51 - 007409664 _____ () [File not signed] C:\
Users\yashr\AppData\Local\Programs\twinkle-tray\libglesv2.dll
2024-06-10 23:02 - 2023-06-17 05:51 - 004873728 _____ () [File not signed] C:\
Users\yashr\AppData\Local\Programs\twinkle-tray\vk_swiftshader.dll
2023-12-08 00:56 - 2023-12-08 00:56 - 001490944 _____ () [File not signed] C:\
Users\yashr\AppData\Roaming\uTorrent Web\avcodec-58.dll
2023-12-08 00:56 - 2023-12-08 00:56 - 000949248 _____ () [File not signed] C:\
Users\yashr\AppData\Roaming\uTorrent Web\avformat-58.dll
2023-12-08 00:56 - 2023-12-08 00:56 - 000635392 _____ () [File not signed] C:\
Users\yashr\AppData\Roaming\uTorrent Web\avutil-56.dll
2023-12-08 00:56 - 2023-12-08 00:56 - 000153088 _____ () [File not signed] C:\
Users\yashr\AppData\Roaming\uTorrent Web\swresample-3.dll
2024-05-25 21:33 - 2024-04-16 11:43 - 001341952 _____ (GitHub) [File not signed]
[File is in use] C:\Users\yashr\AppData\Local\Programs\Lively Wallpaper\Octokit.dll
2024-05-25 21:33 - 2023-12-30 11:31 - 000076800 _____ (Google) [File not signed]
[File is in use] C:\Users\yashr\AppData\Local\Programs\Lively Wallpaper\
GrpcDotNetNamedPipes.dll
2024-05-25 21:33 - 2022-05-18 02:11 - 000225280 _____
(gsscoder;nemec;ericnewton76;moh-hassan) [File not signed] [File is in use] C:\
Users\yashr\AppData\Local\Programs\Lively Wallpaper\CommandLine.dll
2024-05-14 16:00 - 2024-05-26 22:30 - 000101376 _____ (Igor Pavlov) [File not
signed] C:\Program Files\7-Zip\7-zip.dll
2024-05-25 21:33 - 2023-11-04 10:32 - 000067584 _____ (Linearstar) [File not
signed] [File is in use] C:\Users\yashr\AppData\Local\Programs\Lively Wallpaper\
RawInput.Sharp.dll
2024-05-25 21:33 - 2024-05-31 23:02 - 000682496 _____ (Lively) [File not signed]
[File is in use] C:\Users\yashr\AppData\Local\Programs\Lively Wallpaper\Lively.dll
2024-05-25 21:33 - 2024-05-31 23:02 - 000115200 _____ (Lively.Common) [File not
signed] [File is in use] C:\Users\yashr\AppData\Local\Programs\Lively Wallpaper\
Lively.Common.dll
2024-05-25 21:33 - 2024-05-31 23:02 - 000007680 _____ (Lively.Common.Factories)
[File not signed] [File is in use] C:\Users\yashr\AppData\Local\Programs\Lively
Wallpaper\Lively.Common.Factories.dll
2024-05-25 21:33 - 2024-05-31 23:02 - 000038912 _____ (Lively.Common.Services)
[File not signed] [File is in use] C:\Users\yashr\AppData\Local\Programs\Lively
Wallpaper\Lively.Common.Services.dll
2024-05-25 21:33 - 2024-05-31 23:02 - 000168448 _____ (Lively.Grpc.Common) [File
not signed] [File is in use] C:\Users\yashr\AppData\Local\Programs\Lively
Wallpaper\Lively.Grpc.Common.dll
2024-05-25 21:33 - 2024-05-31 23:02 - 000048128 _____ (Lively.Models) [File not
signed] [File is in use] C:\Users\yashr\AppData\Local\Programs\Lively Wallpaper\
Lively.Models.dll
2024-05-25 21:33 - 2020-01-26 00:09 - 000005120 _____ (Matteo Pagani) [File not
signed] [File is in use] C:\Users\yashr\AppData\Local\Programs\Lively Wallpaper\
DesktopBridge.Helpers.dll
2024-05-25 21:33 - 2023-12-30 12:17 - 000939008 _____ (NLog) [File not signed]
[File is in use] C:\Users\yashr\AppData\Local\Programs\Lively Wallpaper\NLog.dll
2024-05-25 21:33 - 2021-04-02 10:14 - 000015360 _____ (OpenByte) [File not signed]
[File is in use] C:\Users\yashr\AppData\Local\Programs\Lively Wallpaper\
WinEventHook.dll
2024-05-25 21:33 - 2019-01-16 10:24 - 000032768 _____ (Soroush Falahati
(falahati.net)) [File not signed] [File is in use] C:\Users\yashr\AppData\Local\
Programs\Lively Wallpaper\UACHelper.dll
2023-12-08 00:56 - 2023-12-08 00:56 - 002554880 _____ (The OpenSSL Project,
hxxps://www.openssl.org/) [File not signed] C:\Users\yashr\AppData\Roaming\uTorrent
Web\libcrypto-1_1.dll
2023-12-08 00:56 - 2023-12-08 00:56 - 000537600 _____ (The OpenSSL Project,
hxxps://www.openssl.org/) [File not signed] C:\Users\yashr\AppData\Roaming\uTorrent
Web\libssl-1_1.dll
(If an entry is included in the fixlist, only the ADS will be removed.)
(If an entry is included in the fixlist, the registry item will be restored to
default or removed.)
HKU\S-1-5-21-2931057295-1006745406-1456292787-1001\Software\Classes\regfile: <====
ATTENTION
HKU\S-1-5-21-2931057295-1006745406-1456292787-1001\Software\Classes\.reg: =>
<==== ATTENTION
HKU\S-1-5-21-2931057295-1006745406-1456292787-1001\Software\Classes\.bat: =>
<==== ATTENTION
HKU\S-1-5-21-2931057295-1006745406-1456292787-1001\Software\Classes\.cmd: =>
<==== ATTENTION
HKU\S-1-5-21-2931057295-1006745406-1456292787-1001\Software\Microsoft\Internet
Explorer\Main,Start Page = hxxp://in.yahoo.com?fr=fp-
comodo&type=33050001005_12.2.2.7036_i_hp
SearchScopes: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001 -> DefaultScope
{8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL =
hxxp://in.search_path.yahoo.com/search_path?p={searchTerms}&fr=chr-
comodo&type=33050001005_12.2.2.7036_i_ds
SearchScopes: HKU\S-1-5-21-2931057295-1006745406-1456292787-1001 -> {8EEAC88A-079B-
4b2c-80C1-7836F79EB40A} URL = hxxp://in.search_path.yahoo.com/search_path?
p={searchTerms}&fr=chr-comodo&type=33050001005_12.2.2.7036_i_ds
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\
Program Files\Java\jre-1.8\bin\ssv.dll [2024-03-13] (Oracle America, Inc. -> Oracle
Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\
Program Files\Java\jre-1.8\bin\jp2ssv.dll [2024-03-13] (Oracle America, Inc. ->
Oracle Corporation)
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2022-05-07 10:54 - 2022-05-07 10:52 - 000000824 _____ C:\Windows\system32\drivers\
etc\hosts
Network Binding:
=============
Ethernet: COMODO Internet Security Firewall Driver -> inspect (enabled)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
Application errors:
==================
Error: (06/24/2024 09:27:35 AM) (Source: Application Error) (EventID: 1000) (User:
SUS)
Description: Faulting application name: HxTsr.exe, version: 16.0.14326.21962, time
stamp: 0x665fcafb
Faulting module name: HxOutlookBackground.dll, version: 16.0.14326.21962, time
stamp: 0x66625cb8
Exception code: 0x0071d20d
Fault offset: 0x00000000000ca741
Faulting process id: 0x0x1fe8
Faulting application start time: 0x0x1dac5eaa54c09ef
Faulting application path: C:\Program Files\WindowsApps\
microsoft.windowscommunicationsapps_16005.14326.21962.0_x64__8wekyb3d8bbwe\
HxTsr.exe
Faulting module path: C:\Program Files\WindowsApps\
microsoft.windowscommunicationsapps_16005.14326.21962.0_x64__8wekyb3d8bbwe\
HxOutlookBackground.dll
Report Id: 0e4ea19a-e681-440e-87b8-017b4e84b22e
Faulting package full name:
microsoft.windowscommunicationsapps_16005.14326.21962.0_x64__8wekyb3d8bbwe
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
System errors:
=============
Error: (06/24/2024 09:07:30 AM) (Source: DCOM) (EventID: 10001) (User: SUS)
Description: Unable to start a DCOM Server:
Microsoft.YourPhone_1.24051.101.0_x64__8wekyb3d8bbwe!
App.AppX3vhsrrrr4az9vb3h5mjdzkhtshkg5v0x.mca as Unavailable/Unavailable. The error:
"2147958031"
Happened while starting this command:
"C:\Windows\system32\backgroundTaskHost.exe" -
ServerName:App.AppXfkd8mejksk4ancwf4vtyhmkvtzn1jcbs.mca
Error: (06/24/2024 04:12:16 AM) (Source: DCOM) (EventID: 10010) (User: SUS)
Description: The server {C53A4F16-787E-42A4-B304-29EFFB4BF597} did not register
with DCOM within the required timeout.
Error: (06/24/2024 04:12:13 AM) (Source: DCOM) (EventID: 10010) (User: SUS)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register
with DCOM within the required timeout.
Error: (06/24/2024 04:12:13 AM) (Source: DCOM) (EventID: 10010) (User: SUS)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register
with DCOM within the required timeout.
Error: (06/24/2024 04:12:13 AM) (Source: DCOM) (EventID: 10010) (User: SUS)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register
with DCOM within the required timeout.
Error: (06/24/2024 04:12:13 AM) (Source: DCOM) (EventID: 10010) (User: SUS)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register
with DCOM within the required timeout.
Error: (06/24/2024 04:12:13 AM) (Source: DCOM) (EventID: 10010) (User: SUS)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register
with DCOM within the required timeout.
Error: (06/24/2024 04:12:13 AM) (Source: DCOM) (EventID: 10010) (User: SUS)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register
with DCOM within the required timeout.
Windows Defender:
================
Date: 2024-06-24 14:12:54
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted
software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/GenCBL.SIBA!
MTB&threatid=2147781940&enterprise=0
Name: Trojan:Win32/GenCBL.SIBA!MTB
Severity: Severe
Category: Trojan
Path: file:_C:\Users\yashr\AppData\Roaming\VC_redistx64.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: E:\downloads\scoped_dir11748_1246212785\FRST64.exe
Security intelligence Version: AV: 1.413.483.0, AS: 1.413.483.0, NIS: 1.413.483.0
Engine Version: AM: 1.1.24050.5, NIS: 1.1.24050.5
CodeIntegrity:
===============
Date: 2024-06-24 14:08:43
Description:
Windows is unable to verify the image integrity of the file \Device\
HarddiskVolume7\Windows\System32\guard64.dll because file hash could not be found
on the system. A recent hardware or software change might have installed a file
that is signed incorrectly or damaged, or that might be malicious software from an
unknown source.
Drive c: () (Fixed) (Total:464.86 GB) (Free:66.12 GB) (Model: WD Green SN350 500GB
2G0C) NTFS
Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) (Model:
ST500DM002-1BD142) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (games2) (Fixed) (Total:184.06 GB) (Free:157.12 GB) (Model: WDC
WD2500AAJS-65B4A0) NTFS
Drive g: () (Fixed) (Total:99.51 GB) (Free:9.9 GB) (Model: ST500DM002-1BD142) NTFS
Drive h: (games) (Fixed) (Total:201.17 GB) (Free:55 GB) (Model: ST500DM002-1BD142)
NTFS
Drive i: () (Fixed) (Total:164.98 GB) (Free:4.03 GB) (Model: ST500DM002-1BD142)
NTFS
Drive y: () (Fixed) (Total:48.82 GB) (Free:21.9 GB) (Model: WDC WD2500AAJS-65B4A0)
NTFS
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 8117FD20)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=99.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=201.2 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=165 GB) - (Type=07 NTFS)
==========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 232.9 GB) (Disk ID: 88F4A82B)
Partition 1: (Active) - (Size=48.8 GB) - (Type=42)
Partition 2: (Not Active) - (Size=184.1 GB) - (Type=42)
==========================================================
Disk: 2 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000)
Partition: GPT.