Additional scan result of Farbar Recovery Scan Tool (x64) Version:18-10-2015 Ran by joss (2015-10-21 18:18:44) Running from C:\Users\joss\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2013-12-06 07:59:51) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-526272471-1439060630-3630711136-500 - Administrator - Disabled) Guest (S-1-5-21-526272471-1439060630-3630711136-501 - Limited - Disabled) joss (S-1-5-21-526272471-1439060630-3630711136-1000 - Administrator - Enabled) => C:\Users\joss postgres (S-1-5-21-526272471-1439060630-3630711136-1002 - Limited - Enabled) => C:\Users\postgres ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-526272471-1439060630-3630711136-1002\...\uTorrent) (Version: 3.4.2.38656 - BitTorrent Inc.) Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.5.502.135 - Adobe Systems Incorporated) Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.185 - Adobe Systems Incorporated) Adobe Illustrator CC 2015 (HKLM-x32\...\{5680D629-B263-49CC-821E-3CEBD4507B51}) (Version: 19.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{7E5DC2C5-115A-322B-976C-219237FAED66}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AutoHotkey 1.0.48.05 (HKLM-x32\...\AutoHotkey) (Version: 1.0.48.05 - Chris Mallett) AVG PC TuneUp 2014 (en-US) (x32 Version: 14.0.1001.204 - AVG) Hidden AVG PC TuneUp 2014 (HKLM-x32\...\AVG PC TuneUp) (Version: 14.0.1001.204 - AVG) AVG PC TuneUp 2014 (x32 Version: 14.0.1001.204 - AVG) Hidden Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) BleachBit (HKLM-x32\...\BleachBit) (Version: 1.8 - BleachBit) BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.66.1075 - AB Team, d.o.o.) CodeBlocks (HKU\S-1-5-21-526272471-1439060630-3630711136-1000\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team) CodeBlocks (HKU\S-1-5-21-526272471-1439060630-3630711136-1002\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team) Combined Community Codec Pack 2013-11-27 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2013.11.27.0 - CCCP Project) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) CPUID CPU-Z 1.73 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CSGO Demos Manager version 2.1.0 (HKLM\...\{2CC5723B-69A1-4B82-AA32-34968284F9C3}_is1) (Version: 2.1.0 - AkiVer) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve) ESEA Client (HKU\S-1-5-21-526272471-1439060630-3630711136-1002\...\ESEA) (Version: 5.0.0.0 - E-Sports Entertainment LLC) ESL Wire 1.18.0 (HKLM\...\ESL Wire_is1) (Version: - Turtle Entertainment GmbH) FileZilla Client 3.12.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.12.0.2 - Tim Kosse) Geeks3D FurMark 1.17.0.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D) Google Chrome (HKLM-x32\...\{1B729E3D-B16D-3A41-A9AE-6AEC20C6580D}) (Version: 65.156.32831 - Google, Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.21.165 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) HLSW v1.4.0.2 (HKLM-x32\...\HLSW_is1) (Version: - Stripf Software) InstallShieldHiRezCurrent (HKLM-x32\...\{9433FC1C-7405-433C-A26D-81076293BBCE}) (Version: 3.0.0.0 - Hi-Rez Studios) Intel(R) Chipset Device Software (x32 Version: 10.0.26 - Intel(R) Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.31.1000 - Intel Corporation) Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle) K-Lite Codec Pack 10.1.5 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.1.5 - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Magicka: Wizard Wars (HKLM-x32\...\Steam App 202090) (Version: - Paradox North) Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Missing Translation (HKLM-x32\...\Steam App 395520) (Version: - AlPixel Games) Mozilla Firefox 41.0.2 (x86 fr) (HKLM-x32\...\Mozilla Firefox 41.0.2 (x86 fr)) (Version: 41.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0.2.5765 - Mozilla) MSI Afterburner 4.1.1 (HKLM-x32\...\Afterburner) (Version: 4.1.1 - MSI Co., LTD) Mumble 1.2.7 (HKLM-x32\...\{1FC198EF-5C3F-4C2A-99AC-22DE9B3FBFDE}) (Version: 1.2.7 - Thorvald Natvig) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.5 - Notepad++ Team) OCCT 4.4.1 (HKLM-x32\...\OCCT) (Version: 4.4.1 - Ocbase.com) OpenOffice 4.1.1 (HKLM-x32\...\{121727D5-FDF3-4723-BA57-EB383440ED72}) (Version: 4.11.9775 - Apache Software Foundation) paint.net (HKLM\...\{DF3A46D9-67B3-44B2-9D01-25C8BA772C8A}) (Version: 4.0.6 - dotPDN LLC) ParkControl (HKLM-x32\...\ParkControl) (Version: 1.0.0.0 - Bitsum) Path of Exile (HKLM-x32\...\Steam App 238960) (Version: - Grinding Gear Games) Platform (x32 Version: 1.42 - VIA Technologies, Inc.) Hidden PokerStars.fr (HKLM-x32\...\PokerStars.fr) (Version: - PokerStars.fr) Popcorn Time (HKU\S-1-5-21-526272471-1439060630-3630711136-1000\...\Popcorn Time) (Version: - Popcorn Official) qBittorrent 3.2.3 (HKLM-x32\...\qBittorrent) (Version: 3.2.3 - The qBittorrent project) Quake Live (HKLM-x32\...\Steam App 282440) (Version: - id Software) RadeonPro 1.0 (Build 1.1.1.0) (HKLM-x32\...\RadeonPro_is1) (Version: - ) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.27599 - Razer Inc.) Sapphire TRIXX (HKLM-x32\...\Sapphire TRIXX) (Version: - ) Sid Meier's Civilization: Beyond Earth Update v1.0.1.607 (HKLM-x32\...\U2lkTWVpZXJzQ2l2aWxpemF0aW9uQmV5b25kRWFydGg=_is1) (Version: 1 - ) Skype™ 7.12 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.12.101 - Skype Technologies S.A.) SMITE (HKLM-x32\...\Steam App 386360) (Version: - Hi-Rez Studios) StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) The Witcher 3 Wild Hunt (HKLM-x32\...\The Witcher 3 Wild Hunt_is1) (Version: 1.02 - Релиз от R.G. Steamgames) Track-o-Bot version 0.5.0 (HKLM-x32\...\Track-o-Bot_is1) (Version: 0.5.0 - spidy.ch) VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.42 - VIA Technologies, Inc.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Windows Driver Package - Microsoft (xusb21) XnaComposite (08/13/2009 2.1.0.1349) (HKLM\...\0AEBEF6F936CFE16E003F7E141631FAB754D9816) (Version: 08/13/2009 2.1.0.1349 - Microsoft) WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) ZHPFix 2015 (HKLM-x32\...\ZHPFix_is1) (Version: 2015 - Nicolas Coolman) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2015-10-19 22:03 - 00000747 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Loaded Modules (Whitelisted) ============== 2015-07-09 19:32 - 2015-07-09 19:32 - 00043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2012-06-18 17:24 - 2012-06-18 17:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll 2013-06-12 18:11 - 2014-04-26 15:04 - 01294336 _____ () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe 2015-10-14 13:31 - 2015-10-14 13:31 - 02264056 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.1.1\deploy\LoLLauncher.exe 2015-10-14 13:31 - 2015-10-14 13:31 - 04417528 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.41\deploy\LoLPatcher.exe 2014-04-26 15:14 - 2014-04-26 15:14 - 00074752 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.162\deploy\LolClient.exe 2015-06-07 10:41 - 2014-06-19 00:40 - 00219136 _____ () C:\Users\joss\Desktop\profiles\DigitalVibrance.dll 2015-09-05 03:42 - 2015-09-05 03:42 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2005-08-14 22:09 - 2005-08-14 22:09 - 00111616 _____ () C:\Program Files (x86)\Webteh\BSPlayer\plugins\oldskin.dll 2014-03-02 16:31 - 2012-04-09 01:40 - 03470848 _____ () C:\Program Files (x86)\Webteh\BSPlayer\FFDShow\ffdshow.ax 2014-03-02 16:31 - 2009-08-11 22:19 - 00797184 _____ () C:\Program Files (x86)\Webteh\BSPlayer\AC3 Filter\ac3filter.ax 2014-03-02 16:31 - 2009-08-11 22:21 - 01021440 _____ () C:\Program Files (x86)\Webteh\BSPlayer\AC3 Filter\ac3filter_intl.dll 2015-05-23 01:31 - 2013-11-27 10:20 - 01243648 _____ () C:\Program Files (x86)\Combined Community Codec Pack\Filters\LAVFilters\avformat-lav-55.dll 2015-05-23 01:31 - 2013-11-27 10:20 - 08259072 _____ () C:\Program Files (x86)\Combined Community Codec Pack\Filters\LAVFilters\avcodec-lav-55.dll 2015-05-23 01:31 - 2013-11-27 10:20 - 00361472 _____ () C:\Program Files (x86)\Combined Community Codec Pack\Filters\LAVFilters\avutil-lav-52.dll 2015-05-23 01:31 - 2013-11-27 10:22 - 00235008 _____ () C:\Program Files (x86)\Combined Community Codec Pack\Filters\LAVFilters\libbluray.dll 2014-03-02 16:31 - 2012-04-09 01:39 - 00146944 _____ () C:\Program Files (x86)\Webteh\BSPlayer\FFDShow\ff_libmad.dll 2015-10-14 13:31 - 2015-10-14 13:31 - 01596408 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.41\deploy\RiotLauncher.dll 2015-09-30 14:17 - 2015-09-30 14:17 - 04885152 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.162\deploy\Adobe AIR\Versions\1.0\Resources\WebKit.dll 2015-09-30 14:17 - 2015-09-30 14:17 - 17414304 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.162\deploy\Adobe AIR\Versions\1.0\Resources\NPSWF32.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\.DEFAULT\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\.DEFAULT\...\freerealms.com -> freerealms.com IE trusted site: HKU\.DEFAULT\...\soe.com -> soe.com IE trusted site: HKU\.DEFAULT\...\sony.com -> sony.com IE trusted site: HKU\S-1-5-19\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\S-1-5-19\...\freerealms.com -> freerealms.com IE trusted site: HKU\S-1-5-19\...\soe.com -> soe.com IE trusted site: HKU\S-1-5-19\...\sony.com -> sony.com IE trusted site: HKU\S-1-5-20\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\S-1-5-20\...\freerealms.com -> freerealms.com IE trusted site: HKU\S-1-5-20\...\soe.com -> soe.com IE trusted site: HKU\S-1-5-20\...\sony.com -> sony.com IE trusted site: HKU\S-1-5-21-526272471-1439060630-3630711136-1000\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\S-1-5-21-526272471-1439060630-3630711136-1000\...\freerealms.com -> freerealms.com IE trusted site: HKU\S-1-5-21-526272471-1439060630-3630711136-1000\...\soe.com -> soe.com IE trusted site: HKU\S-1-5-21-526272471-1439060630-3630711136-1000\...\sony.com -> sony.com IE trusted site: HKU\S-1-5-21-526272471-1439060630-3630711136-1002\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\S-1-5-21-526272471-1439060630-3630711136-1002\...\freerealms.com -> freerealms.com IE trusted site: HKU\S-1-5-21-526272471-1439060630-3630711136-1002\...\soe.com -> soe.com IE trusted site: HKU\S-1-5-21-526272471-1439060630-3630711136-1002\...\sony.com -> sony.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-526272471-1439060630-3630711136-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.0.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 0) (EnableLUA: 0) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AMD External Events Utility => 3 MSCONFIG\Services: AODService => 2 MSCONFIG\Services: BEService => 3 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: DTSRVC => 2 MSCONFIG\Services: EslWireHelper => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: HiPatchService => 2 MSCONFIG\Services: Intel(R) Capability Licensing Service Interface => 2 MSCONFIG\Services: iSafeService => 2 MSCONFIG\Services: jhi_service => 2 MSCONFIG\Services: KaraokeService => 3 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: MaConfigAgent => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: OpenVPNService => 3 MSCONFIG\Services: PdiService => 2 MSCONFIG\Services: PornTime Updater => 2 MSCONFIG\Services: RadeonPro Support Service => 3 MSCONFIG\Services: Razer Game Scanner Service => 3 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: Steam Client Service => 3 MSCONFIG\Services: Survarium-Steam Update Service => 3 MSCONFIG\Services: TuneUp.UtilitiesSvc => 3 MSCONFIG\Services: UNS => 2 MSCONFIG\Services: VIAKaraokeService => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SteelSeries Engine 3.lnk => C:\Windows\pss\SteelSeries Engine 3.lnk.CommonStartup MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AMDToggler => C:\Users\joss\Desktop\profiles\Saturation Toggler.exe MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: HDAudDeck => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r MSCONFIG\startupreg: RadeonPro => "C:\Program Files (x86)\RadeonPro\RadeonPro.exe" MSCONFIG\startupreg: Raptr => "C:\Program Files (x86)\Raptr\raptrstub.exe" --startup MSCONFIG\startupreg: Razer Synapse => "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe" MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{EE0E5820-9489-469C-AFED-2956CD15A17F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{6174277C-376B-45B7-9564-452EDD2D1382}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{34EB294A-3AE0-4103-95F1-1B41EB389B94}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{37964655-9E58-490B-9858-971697374D3D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{7180B21D-79A2-4638-9F29-8FC09C635909}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{406643C1-D116-49D2-8C82-8021AC6FFC51}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{601BDAFC-EF48-4A8D-B44A-2BE3F3D01FF4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{D5FC0818-4391-40ED-A062-DB345854F7EA}] => (Allow) LPort=5432 FirewallRules: [{17B567B2-300E-4C60-98FE-C22858A4A240}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{564A1F2F-D5DC-4510-8925-EB05A19ECD6C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{0BDB6E75-E98E-49A3-B817-DC779DFB14EC}] => (Allow) LPort=48113 FirewallRules: [{4F4D9464-247B-4A50-A273-6751D4AF0ABE}] => (Allow) LPort=48114 FirewallRules: [{423A487B-4B9C-48BE-AEB9-E7DBD0063A09}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake Live\quakelive_steam.exe FirewallRules: [{1F03FE0A-9A77-46B2-8B58-0AEAA0E406CD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake Live\quakelive_steam.exe FirewallRules: [{AACDB882-4596-457A-81A1-9426C14D8C45}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [{52BC1967-A27B-462E-B8FC-89F1A8DA2CD1}] => (Allow) C:\Program Files\EslWire\wire.exe FirewallRules: [TCP Query User{6AECF60C-67A9-4E3F-B3CC-6E591591B22A}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{7CA14C1F-3EF5-49CD-A567-87FF502FA3FF}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [{5C95D34C-F737-40C2-BBFF-04D3F8B87F1A}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe FirewallRules: [{B7E7F73F-F01A-4F7F-848A-07D2F692F758}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe FirewallRules: [{56BE6C67-18DD-44B9-BB00-5C34122D858D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Path of Exile\PathOfExileSteam.exe FirewallRules: [{FC7D26A6-C131-4067-AB77-886DA8CC922D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Path of Exile\PathOfExileSteam.exe FirewallRules: [TCP Query User{297A33B8-89F2-48CA-B348-6C6C11E203FC}C:\program files (x86)\hlsw\hlsw.exe] => (Allow) C:\program files (x86)\hlsw\hlsw.exe FirewallRules: [UDP Query User{A9E45187-B8D9-48F8-BACD-9C189FA87416}C:\program files (x86)\hlsw\hlsw.exe] => (Allow) C:\program files (x86)\hlsw\hlsw.exe FirewallRules: [TCP Query User{0B696EE8-3C42-491D-88B4-5A3A6C539711}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{BFBF77E5-88EC-4972-AE1A-6E38AAB69880}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [TCP Query User{E27A62A7-7AF0-4712-B280-FDE1F2576761}C:\program files (x86)\hlsw\hlsw.exe] => (Allow) C:\program files (x86)\hlsw\hlsw.exe FirewallRules: [UDP Query User{0825E96F-851C-4BEF-8A24-1CC18C6AAC2A}C:\program files (x86)\hlsw\hlsw.exe] => (Allow) C:\program files (x86)\hlsw\hlsw.exe FirewallRules: [{7A3B9740-8862-41BE-A222-3080E3B5190B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MagickaWizardWars\WizardWarsLauncher.exe FirewallRules: [{1CECE83E-F3A3-45EC-A485-414AD0410B7E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MagickaWizardWars\WizardWarsLauncher.exe FirewallRules: [TCP Query User{03D31746-5392-4C52-8187-91C30218A9F5}C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe FirewallRules: [UDP Query User{F88FE18A-D886-4104-B004-BE2FBD71F5FB}C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe FirewallRules: [{D4F0FCFD-4DEA-4C48-ABB2-90B93CB96214}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{CD140841-A151-4BCA-96B5-D0A88B2A6DC1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win32\dota2.exe FirewallRules: [{7907DA85-B89F-4678-9E31-F7F338CF6D85}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [{7310A705-6597-4540-9520-C45FB1805930}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe FirewallRules: [TCP Query User{F0B41069-886E-4649-9ED1-5D714DBB3DD9}C:\users\joss\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\joss\appdata\local\popcorn time\nw.exe FirewallRules: [UDP Query User{6EE0D624-4B14-4E7C-B490-30E84AF479B4}C:\users\joss\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\joss\appdata\local\popcorn time\nw.exe FirewallRules: [{3D9CF8F2-3B1E-4FEB-B7CF-7047D8E6AFED}] => (Allow) C:\Users\joss\AppData\Roaming\PT\updater.exe FirewallRules: [{5F99BF65-6038-41B9-9116-C7D99CAE00D3}] => (Allow) C:\Users\joss\AppData\Roaming\PT\updater.exe FirewallRules: [{2BE00967-600A-4E5D-BE3E-44AF270AA1CF}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe FirewallRules: [{10E151C8-3B0A-4640-A50E-5F8CBA7ED758}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe FirewallRules: [TCP Query User{0D2CAD05-86F3-4F7B-9436-30DF1D1AE5FC}C:\users\joss\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\joss\appdata\local\popcorn time\nw.exe FirewallRules: [UDP Query User{BFF9A777-CFE6-4CEC-BC7A-E5ED0C340879}C:\users\joss\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\joss\appdata\local\popcorn time\nw.exe FirewallRules: [{326EB30A-145C-426D-B187-0B5C9D25B94C}] => (Allow) C:\Program Files\Adobe\Adobe Illustrator CC 2015\Support Files\Contents\Windows\Illustrator.exe FirewallRules: [{AD4088AA-314B-4132-B93B-64A9A94632FE}] => (Allow) C:\Program Files\Adobe\Adobe Illustrator CC 2015\Support Files\Contents\Windows\Illustrator.exe FirewallRules: [{2EA8CCD7-D8C3-4EDA-B347-D62F5C387A70}] => (Allow) C:\Program Files\Adobe\Adobe Illustrator CC 2015\Support Files\Contents\Windows\Illustrator.exe FirewallRules: [{BEB88A38-F32C-41E7-815B-0745EE4BF729}] => (Allow) C:\Program Files\Adobe\Adobe Illustrator CC 2015\Support Files\Contents\Windows\Illustrator.exe FirewallRules: [{4F3DEB49-ACC6-4671-9577-A7C8A913F835}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{B7E35B8F-4BA0-4589-AFA8-E7CDFBEF892F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{2A2B41B3-4312-4C16-A6B5-8958AE3593FA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{1C914D88-E7FF-47D6-B039-87FB93D08B86}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{C48036E1-A8AF-48E4-B947-D841585C70A8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{1B867B2A-D65B-4AAE-9934-CDEA336D2D08}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{E2D1C64D-AC0E-4595-BA6E-C98FD1CAFC41}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{4C97A2C8-9050-4F38-A6DE-1A1A969C867A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [TCP Query User{36F2FDC4-BC08-474E-A4CB-1C4B3B4FB755}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [UDP Query User{A4CD436E-8C47-4B13-AFD0-3BA2299BACC7}C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\smite\binaries\win32\smite.exe FirewallRules: [{19CA5903-269D-4E07-81B1-071C339D8BFF}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{674C25E9-4FB9-41F7-ABC4-A7C3080404B9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Missing Translation\nw.exe FirewallRules: [{A275DF2B-071A-4CA2-98CD-16DFD18D9BC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Missing Translation\nw.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/21/2015 06:18:45 PM) (Source: VSS) (EventID: 12292) (User: ) Description: Volume Shadow Copy Service error: Error creating the Shadow Copy Provider COM class with CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. ]. Operation: Obtain a callable interface for this provider List interfaces for all providers supporting this context Query Shadow Copies Context: Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Class ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshot Context: 13 Snapshot Context: 13 Execution Context: Coordinator Error: (10/21/2015 06:18:45 PM) (Source: VSS) (EventID: 13) (User: ) Description: Volume Shadow Copy Service information: The COM Server with CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} and name SW_PROV cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. ] Operation: Obtain a callable interface for this provider List interfaces for all providers supporting this context Query Shadow Copies Context: Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Class ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshot Context: 13 Snapshot Context: 13 Execution Context: Coordinator Error: (10/20/2015 12:33:32 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/19/2015 09:04:53 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/19/2015 08:58:08 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\Users\joss\AppData\Local\Temp\jrt\CreateRestorePoint.exe "JRT Pre-Junkware Removal"; Description = JRT Pre-Junkware Removal; Error = 0x80042302). Error: (10/19/2015 08:58:08 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine GetProviderMgmtInterface. hr = 0x8004230f, The shadow copy provider had an unexpected error while trying to process the specified operation. . Error: (10/19/2015 08:58:08 PM) (Source: VSS) (EventID: 12292) (User: ) Description: Volume Shadow Copy Service error: Error creating the Shadow Copy Provider COM class with CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. ]. Operation: Obtain a callable interface for this provider Obtaining provider management interface Context: Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Class ID: {00000000-0000-0000-0000-000000000000} Snapshot Context: -1 Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Error: (10/19/2015 08:58:08 PM) (Source: VSS) (EventID: 13) (User: ) Description: Volume Shadow Copy Service information: The COM Server with CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} and name SW_PROV cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. ] Operation: Obtain a callable interface for this provider Obtaining provider management interface Context: Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Class ID: {00000000-0000-0000-0000-000000000000} Snapshot Context: -1 Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Error: (10/19/2015 06:36:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/19/2015 05:08:09 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (10/21/2015 12:42:07 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.207.3317.0 Update Source: %NT AUTHORITY59 Update Stage: 4.7.0205.00 Source Path: 4.7.0205.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (10/21/2015 12:41:57 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.207.3317.0 Update Source: %NT AUTHORITY59 Update Stage: 4.7.0205.00 Source Path: 4.7.0205.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (10/20/2015 12:42:17 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.207.3317.0 Update Source: %NT AUTHORITY59 Update Stage: 4.7.0205.00 Source Path: 4.7.0205.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (10/20/2015 12:32:02 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: %%1058 Error: (10/20/2015 12:31:50 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Windows Image Acquisition (WIA) service depends on the Shell Hardware Detection service which failed to start because of the following error: %%1058 Error: (10/19/2015 09:56:18 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Windows\System32\drivers\TrueSight.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (10/19/2015 09:13:22 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.207.3317.0 Update Source: %NT AUTHORITY59 Update Stage: 4.7.0205.00 Source Path: 4.7.0205.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (10/19/2015 09:03:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: %%1058 Error: (10/19/2015 09:03:09 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Windows Image Acquisition (WIA) service depends on the Shell Hardware Detection service which failed to start because of the following error: %%1058 Error: (10/19/2015 09:02:23 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Software Protection service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service. CodeIntegrity: =================================== Date: 2015-05-21 01:58:08.129 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 01:56:22.218 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\joss\AppData\Local\Temp\~nsu.tmp\Au_.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 01:56:22.140 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\ESEA\ESEA Client\uninstall.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 01:43:59.682 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 01:43:59.401 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 01:43:59.307 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 01:43:41.662 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 01:43:41.443 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 01:43:28.557 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 01:43:25.272 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3470 CPU @ 3.20GHz Percentage of memory in use: 26% Total physical RAM: 8151.61 MB Available physical RAM: 5970.33 MB Total Virtual: 16301.41 MB Available Virtual: 14042.29 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:204.47 GB) NTFS Drive d: (Philips) (CDROM) (Total:0.52 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4664F01B) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================