Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-03-2017 Ran by ep (14-04-2017 13:42:36) Running from C:\Users\ep\Desktop Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2017-03-06 12:21:20) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3949887993-2175357321-3906792079-500 - Administrator - Enabled) => C:\Users\Administrator ep (S-1-5-21-3949887993-2175357321-3906792079-1000 - Administrator - Enabled) => C:\Users\ep Guest (S-1-5-21-3949887993-2175357321-3906792079-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3949887993-2175357321-3906792079-1002 - Administrator - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AV: ESET Smart Security 10.0.390.0 (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70} AS: ESET Smart Security 10.0.390.0 (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD} AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC - Français (HKLM\...\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Apple Application Support (32 bits) (HKLM\...\{05E07D23-91E9-4E70-A4CC-EF505088F967}) (Version: 5.4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{90B7F915-6343-43CE-9DA7-E79E5BAC6673}) (Version: 10.3.1.2 - Apple Inc.) Apple Software Update (HKLM\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.) Bonjour (HKLM\...\{D168AAD0-6686-47C1-B599-CDD4888B9D1A}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.27 - Piriform) C-Media High Definition Audio Driver (HKLM\...\C-Media Audio Driver) (Version: - ) Conseiller de mise à niveau vers Windows 7 (HKLM\...\{9D10CB57-B085-44c3-B435-2D193BA153F0}) (Version: 2.0.5000.0 - Microsoft Corporation) eMule (HKLM\...\eMule) (Version: - ) ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - ) ESET Smart Security (HKLM\...\{D0A08C27-D088-4577-90B4-BFF20F382F4C}) (Version: 10.0.390.0 - ESET, spol. s r.o.) FonePaw Transfert iOS 2.4.0 (HKLM\...\{548859D3-48CF-4fcb-8E03-E7F488ADF2EA}_is1) (Version: 2.4.0 - FonePaw) Google Chrome (HKLM\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.) Google Update Helper (Version: 1.3.33.3 - Google Inc.) Hidden HP Deskjet 2510 series Basic Device Software (HKLM\...\{37E0BDA5-DEAD-4116-8DC0-3F5C9A202C47}) (Version: 27.0.847.0 - Hewlett-Packard Co.) HP Deskjet 2510 series Help (HKLM\...\{234DADAD-3C3C-4FB1-90A4-0AF015D56E18}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 2510 series Product Improvement Study (HKLM\...\{1DA007FA-6A47-426B-8813-91A8BC75EC7D}) (Version: 27.0.847.0 - Hewlett-Packard Co.) HP Deskjet 2510 series Setup Guide (HKLM\...\{216C7F38-4BBC-4E9A-8392-C9FA21B54386}) (Version: 27.0.0 - Hewlett Packard) HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.3341 - HP Photo Creations Powered by RocketLife) HP Update (HKLM\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) IsoBuster 2.0 (HKLM\...\IsoBuster_is1) (Version: 2.0 - Smart Projects) iTunes (HKLM\...\{6FE55512-F050-4324-A904-DE4F5291F9D1}) (Version: 12.6.0.100 - Apple Inc.) Jasc Paint Shop Pro 9 (HKLM\...\{F843C6A3-224D-4615-94F8-3C461BD9AEA0}) (Version: 9.00.0000 - Jasc Software Inc) Java 8 Update 121 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) LEd Beta 0.53 (HKLM\...\LEd_is1) (Version: - www.LaTeXEditor.org) Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) Manager (Version: 5.0.15.31893 - 2017 pdfforge GmbH. All rights reserved) Hidden Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Excel 97 (HKLM\...\Excel) (Version: - ) Microsoft Office Professionnel Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Word 97 (HKLM\...\Word8.0) (Version: - ) Mozilla Firefox 49.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 49.0.1 (x86 en-US)) (Version: 49.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 49.0.1 - Mozilla) Mozilla Thunderbird 45.8.0 (x86 fr) (HKU\S-1-5-21-3949887993-2175357321-3906792079-1000\...\Mozilla Thunderbird 45.8.0 (x86 fr)) (Version: 45.8.0 - Mozilla) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.5.1 - pdfforge GmbH) pyromaths 15.10 (HKLM\...\{076e5e70-de04-5a61-bcef-59b6a146da4b}_is1) (Version: 15.10 - Jérôme Ortais) Quicksys RegDefrag 2.9 (HKLM\...\{5D26BF7B-BEF6-477D-8FC1-0C1C159B6364}_is1) (Version: - ) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Skypeâ„¢ 7.33 (HKLM\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1240 - SUPERAntiSpyware.com) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) WinDjView 2.1 (HKLM\...\WinDjView) (Version: 2.1 - Andrew Zhezherun) WinEdt 8 (HKU\S-1-5-21-3949887993-2175357321-3906792079-1000\...\WinEdt 8) (Version: 8.1 - WinEdt Team) WinRAR 5.40 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) XnView 2.39 (HKLM\...\XnView_is1) (Version: 2.39 - Gougelet Pierre-e) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {2346C078-F693-4AB5-83FC-D9986BCA44D5} - System32\Tasks\HPCustParticipation HP Deskjet 2510 series => C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPCustPartic.exe [2012-02-01] (Hewlett-Packard Co.) Task: {3A20FF36-B5EE-4917-936A-A3231DD3D2AC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-02-02] (Adobe Systems Incorporated) Task: {4A0AB9F6-1212-4C29-86B2-90D6A95A1270} - System32\Tasks\{D04A2977-A0B8-4577-B75D-3A66B1B4B144} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.18.0.106&LastError=404 Task: {502BCFAB-6A1B-4175-B882-0CE68DFA404C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-03-09] (Google Inc.) Task: {529A16EE-93B6-4BF8-B460-7A6D8A7CBC39} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-08] (Piriform Ltd) Task: {5708242A-753B-4576-98F6-78AE16FB8E77} - System32\Tasks\{A63B5BF4-7235-4235-8530-33475D46B306} => pcalua.exe -a D:\eMule0.49c-Installer.exe Task: {7BD23D0D-7AA1-4048-AA25-BECA0C4CCDA6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-03-09] (Google Inc.) Task: {9184A986-C975-4975-B604-CAE2877A6084} - System32\Tasks\SUPERAntiSpyware Scheduled Task 642b09eb-11ea-42f2-9ae8-d209e4c0966c => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {C4A0EEAE-B194-4009-81A8-6FD8B52F1DE7} - System32\Tasks\{AB355795-0F24-4C14-B3DB-F3F6EE28F230} => pcalua.exe -a F:\setup.exe -d F:\ Task: {D66A7ABC-A000-43DB-9E53-5447A049CB73} - System32\Tasks\SUPERAntiSpyware Scheduled Task 5150490b-ced3-4a5c-8584-8d9b7f8d926a => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {E3FF54A1-CD07-45D7-AACE-803FDFEC8DE5} - System32\Tasks\{327672D3-6AD8-4EBC-97D7-C4B00EDEADB0} => pcalua.exe -a "D:\SpyBot Search & Destroy 1.5.2.20 [Par Ratiatum.com].exe" Task: {E9F15F23-97C3-4457-BB20-142066DA4957} - System32\Tasks\{61C74A96-380F-4474-B7A0-7B18C5879A05} => pcalua.exe -a C:\Windows\System\cmicnfg.cpl -c CMI Audio Config (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 5150490b-ced3-4a5c-8584-8d9b7f8d926a.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\aa547b96-fa95-4770-a091-3a1300924204.com Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 642b09eb-11ea-42f2-9ae8-d209e4c0966c.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 1997-01-27 09:00 - 1997-01-27 09:00 - 00022016 _____ () C:\Windows\system32\docobj.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2017-04-11 16:18 - 00000826 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3949887993-2175357321-3906792079-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\ep\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 109.88.203.3 - 62.197.111.140 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: !SASCORE => 2 MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: BBSvc => 3 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: PDF Architect 5 Creator => 2 MSCONFIG\Services: PDF Architect 5 Manager => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\startupfolder: C:^Users^ep^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP Deskjet 2510 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP Deskjet 2510 series.lnk.Startup MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR MSCONFIG\startupreg: Cmaudio => RunDll32 cmicnfg.cpl,CMICtrlWnd MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: Malwarebytes TrayApp => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{43FF5FB6-F6E0-4E98-A65C-F7C2A0031BDD}] => (Allow) C:\Program Files\HP\HP Deskjet 2510 series\Bin\USBSetup.exe FirewallRules: [{EA171834-00F4-4D33-8CB3-ADA520812FE9}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{6EB73D6B-97E4-4F13-8892-AAFB00961979}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{CE44FAFD-1EFF-4B4A-82E1-9A68FD67B719}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C8D79547-BD8B-47A5-9BE2-79694C74EA42}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{23CFDC27-DD87-401D-9C9A-EBE0248B7C6E}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{674B83CB-377B-49A1-8B77-9D30CE7E6DA7}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe FirewallRules: [{FD472D04-418A-455A-824F-ADF2B65112E9}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{642BD523-DFDF-43BB-92AD-64C9E8D77100}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Restore Points ========================= 13-04-2017 23:21:50 End of disinfection ==================== Faulty Device Manager Devices ============= Name: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Marvell Service: yukonw7 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/14/2017 09:09:45 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Program Files\HP\HP Deskjet 2510 series\DriverStore\Pipeline\amd64\hpinkinsAC11.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (04/14/2017 08:52:48 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (04/13/2017 11:44:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (04/13/2017 11:41:20 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program ZHPDiag3.exe version 2017.4.11.63 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 534 Start Time: 01d2b49e197be7dc Termination Time: 33 Application Path: C:\Users\ep\Downloads\eMule\Incoming\ZHPDiag3.exe Report Id: Error: (04/13/2017 11:21:50 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied. . This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {99173c0e-93a1-481f-9a14-da44454fecfe} Error: (04/13/2017 07:32:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (04/13/2017 07:26:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (04/13/2017 06:27:34 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program OTL.exe version 3.2.69.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: d04 Start Time: 01d2b4674c7ef50a Termination Time: 94 Application Path: C:\Users\ep\Downloads\OTL.exe Report Id: Error: (04/13/2017 06:08:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 49.0.1.6109, time stamp: 0x57e44563 Faulting module name: mozglue.dll, version: 49.0.1.6109, time stamp: 0x57e43eea Exception code: 0x80000003 Fault offset: 0x0000e846 Faulting process id: 0xc38 Faulting application start time: 0x01d2b46ff01f221d Faulting application path: C:\Program Files\Mozilla Firefox\plugin-container.exe Faulting module path: C:\Program Files\Mozilla Firefox\mozglue.dll Report Id: 5d0af3bd-2063-11e7-bbb4-00a1b0a087d8 Error: (04/13/2017 04:54:51 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. System errors: ============= Error: (04/14/2017 09:19:32 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout. Error: (04/14/2017 08:50:59 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT AUTHORITY) Description: Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. Error: (04/13/2017 11:42:37 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT AUTHORITY) Description: Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. Error: (04/13/2017 08:34:39 PM) (Source: Disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. Error: (04/13/2017 08:34:36 PM) (Source: Disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. Error: (04/13/2017 08:34:32 PM) (Source: Disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. Error: (04/13/2017 08:34:29 PM) (Source: Disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. Error: (04/13/2017 08:34:26 PM) (Source: Disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. Error: (04/13/2017 08:34:23 PM) (Source: Disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. Error: (04/13/2017 08:34:20 PM) (Source: Disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. CodeIntegrity: =================================== Date: 2017-03-07 03:39:30.782 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\logiciels réseaux\MRT.exe because the set of per-page image hashes could not be found on the system. Date: 2017-03-07 03:39:25.204 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\logiciels réseaux\MRT.exe because the set of per-page image hashes could not be found on the system. Date: 2017-03-07 03:39:20.344 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\logiciels réseaux\MRT.exe because the set of per-page image hashes could not be found on the system. Date: 2017-03-07 03:39:11.750 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\logiciels réseaux\MRT.exe because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz Percentage of memory in use: 32% Total physical RAM: 3327.37 MB Available physical RAM: 2238.52 MB Total Virtual: 6651 MB Available Virtual: 5591.52 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:114.48 GB) (Free:23.04 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (Nouveau nom) (Fixed) (Total:128 GB) (Free:1.58 GB) NTFS Drive e: (Nouveau nom) (Fixed) (Total:104.89 GB) (Free:2.94 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 114.5 GB) (Disk ID: EF8FEF8F) Partition 1: (Active) - (Size=114.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 232.9 GB) (Disk ID: FCD230AD) Partition 1: (Not Active) - (Size=128 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=104.9 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================