Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-02-2017 Ran by Yahya (10-02-2017 22:57:30) Running from C:\Users\Yahya\Desktop Windows 7 Ultimate Service Pack 1 (X64) (2017-01-21 10:40:31) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3989315629-4222968736-939265620-500 - Administrator - Disabled) Guest (S-1-5-21-3989315629-4222968736-939265620-501 - Limited - Disabled) Yahya (S-1-5-21-3989315629-4222968736-939265620-1000 - Administrator - Enabled) => C:\Users\Yahya ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET Smart Security Premium 10.0.386.0 (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70} AS: ESET Smart Security Premium 10.0.386.0 (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) beIN Activator (HKLM-x32\...\beIN Activator18.0.0.3) (Version: 18.0.0.3 - DZ-SAT) Catalyst Control Center Next Localization BR (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0226.1531.27895 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.26 - Piriform) Cheat Engine 6.5 (HKLM-x32\...\Cheat Engine 6.5_is1) (Version: - Cheat Engine) Conflict Global Storm (HKLM-x32\...\{75443B81-E1FC-4D79-80C0-5F0DF2A7F897}) (Version: 1.00.0000 - ) DkZ Studio (HKLM-x32\...\{F656DC79-013A-4683-8692-B938FC00B941}) (Version: 1.0.0.0 - abScroll (c) 2005) Driver Booster 4.2 (HKLM-x32\...\Driver Booster_is1) (Version: 4.2.0 - IObit) DriversCloud.com (64 bits) (HKLM\...\{A4FD0E13-AED9-4AE1-90DC-90D39FBF0289}) (Version: 10.0.2.0 - Cybelsoft) ESET Smart Security Premium (HKLM\...\{E1F1E8E1-90E6-4A19-A4A8-242C696B82AA}) (Version: 10.0.386.0 - ESET, spol. s r.o.) Fraps (HKLM-x32\...\Fraps) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc‎.‎) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden IDMActivator-mrelhlawany25.16 25.16 (HKLM-x32\...\IDMActivator-mrelhlawany25.16 25.16) (Version: 25.16 - mrelhlawany.com) Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: - Tonec Inc.) Java 8 Update 121 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (العربية) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1025) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.0 (HKLM-x32\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Mozilla Firefox 49.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 49.0.1 (x86 en-US)) (Version: 49.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.1 - Mozilla) NVIDIA PhysX (HKLM-x32\...\{80407BA7-7763-4395-AB98-5233F1B34E65}) (Version: 9.13.1220 - NVIDIA Corporation) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8036 - Realtek Semiconductor Corp.) RogueKiller version 12.9.7.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.9.7.0 - Adlice Software) WinRAR 5.40 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {49F8BBEF-E30C-4F5F-B53A-F30E682C4B11} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-27] (Adobe Systems Incorporated) Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => sc.execonfig upnphost start= auto Task: {B032DA79-6187-4811-BB04-086EE4C39595} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\4.2.0\Scheduler.exe [2016-12-14] (IObit) Task: {BA0DF78E-5099-47A6-8B7E-82D7E824332A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-21] (Google Inc.) Task: {C819A798-D2BC-45C4-8498-5E8402BFD1B0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-21] (Google Inc.) Task: {D68FD302-6E90-4160-A58B-276C5F0C71C3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-21] (Piriform Ltd) Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => sc.exestart sppsvc Task: {F2DDC409-5F88-47BA-9ECB-C95726BF59CF} - System32\Tasks\Driver Booster SkipUAC (Yahya) => C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DriverBooster.exe [2017-01-10] (IObit) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\beIN Activator\btskk.lnk -> C:\TempFldr\btskk.bat () Shortcut: C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\beIN Activator\clnr.lnk -> C:\TempFldr\clnr.bat () Shortcut: C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\beIN Activator\fixer_10.lnk -> C:\TempFldr\fixer_10.bat () Shortcut: C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\beIN Activator\fixer_8.lnk -> C:\TempFldr\fixer_8.bat () Shortcut: C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\beIN Activator\fx.lnk -> C:\TempFldr\fx.bat () Shortcut: C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\beIN Activator\ieClnr.lnk -> C:\TempFldr\ieClnr.bat () Shortcut: C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\beIN Activator\nssckbi.lnk -> C:\TempFldr\nssckbi.bat () Shortcut: C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\beIN Activator\prclnr10.lnk -> C:\TempFldr\prclnr10.bat () Shortcut: C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\beIN Activator\prclnr8.lnk -> C:\TempFldr\prclnr8.bat () ==================== Loaded Modules (Whitelisted) ============== 2010-01-30 02:40 - 2010-01-30 02:40 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-03-24 21:38 - 2010-03-24 21:38 - 08794976 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2015-06-25 16:34 - 2015-06-25 16:34 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll 2015-06-25 16:37 - 2015-06-25 16:37 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-06-25 16:35 - 2015-06-25 16:35 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll 2015-06-25 16:38 - 2015-06-25 16:38 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll 2015-06-25 15:53 - 2015-06-25 15:53 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll 2015-06-25 15:51 - 2015-06-25 15:51 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2017-01-21 21:21 - 2007-03-19 00:05 - 00630784 _____ () C:\Program Files (x86)\RocketDock\RocketDock.exe 2016-12-21 19:49 - 2016-12-21 19:49 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1025.dll 2017-02-02 03:11 - 2017-02-01 11:47 - 02459992 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll 2017-02-02 03:11 - 2017-02-01 11:47 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll 2017-01-21 21:21 - 2007-03-19 00:04 - 00069632 _____ () C:\Program Files (x86)\RocketDock\RocketDock.dll 2010-01-30 02:41 - 2010-01-30 02:41 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-03-24 21:17 - 2010-03-24 21:17 - 08794464 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2017-02-10 05:16 - 00001114 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost217.10.68.152 we9stun.winning-eleven.net # Stunserver 43.225.188.187 pes6gate-ec.winning-eleven.net # Pes6Stars Server ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3989315629-4222968736-939265620-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Yahya\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{45F69C9E-3400-4E91-93C2-BD03A3FC8581}] => C:\Program Files\DriversCloud.com\DriversCloud.exe FirewallRules: [{5C2892A4-ED0B-417C-A077-4DAE689BAE22}] => C:\Program Files\DriversCloud.com\DriversCloud.exe FirewallRules: [{5A21187F-1881-480C-98CD-007CE90E21BD}] => C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{0B2BDBBE-D4E0-4493-AD09-A0949CE89D63}] => C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{237D91B2-A251-46E3-A818-46436ED8F8D9}] => C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{314A660D-3D57-44C4-B35A-76B4792F2E48}] => C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{13483C99-AA68-42A4-9EE0-D6287EF3F898}] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{F800BD34-009E-49A4-9B71-00FEE2209ECB}] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [TCP Query User{076D63FA-D27B-4A33-883F-2F9E8E7A346D}E:\pes6\pes6.exe] => E:\pes6\pes6.exe FirewallRules: [UDP Query User{97FD7D43-B5C1-459D-B5F2-C4E1BA5C95D8}E:\pes6\pes6.exe] => E:\pes6\pes6.exe FirewallRules: [{BFCEB0CE-A20A-4920-BEC9-F5EBA152F6F7}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{1897C8E0-7BDE-4E87-937D-6A3A0E404FE2}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{E326BFD5-37C9-4EC0-8A6C-A97E3577F405}C:\windows\explorer.exe] => C:\windows\explorer.exe FirewallRules: [UDP Query User{5E453546-8B13-4BA2-8AFE-06A6C19FD586}C:\windows\explorer.exe] => C:\windows\explorer.exe FirewallRules: [{A6A99AB1-5CCF-4C68-99DC-A7FD611A990C}] => C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DriverBooster.exe FirewallRules: [{13E4EFEC-5FC7-45F0-906D-78DCD2D9D1C5}] => C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DriverBooster.exe FirewallRules: [{11B4B381-0826-4640-A8E4-E5A6CFEECE5E}] => C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DBDownloader.exe FirewallRules: [{6D7609A6-2DC5-4180-B61B-E541AA7AA3F3}] => C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DBDownloader.exe FirewallRules: [{E61049FD-B218-439B-8259-8F777845137A}] => C:\Program Files (x86)\IObit\Driver Booster\4.2.0\AutoUpdate.exe FirewallRules: [{B4FD0519-DC73-476A-A76E-E3AE74928358}] => C:\Program Files (x86)\IObit\Driver Booster\4.2.0\AutoUpdate.exe FirewallRules: [{17611168-3E79-4FAC-87B3-B850A07A4A68}] => E:\Downloads\Compressed\EmbratoriaG6.5.1\EmbratoriaG6.5.1\libs.exe FirewallRules: [{E6281862-85B8-467B-9E52-2710C82EC1B9}] => E:\Downloads\Compressed\EmbratoriaG6.5.1\EmbratoriaG6.5.1\libs.exe FirewallRules: [{FB3EDF9C-D065-4193-8F47-B266B73E3DD0}] => LPort=5000 FirewallRules: [{0644A154-ED1F-47FA-B4F0-CCB5287E4622}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 05-02-2017 20:37:22 Scheduled Checkpoint 06-02-2017 00:04:58 Installed Microsoft Office Enterprise 2007 06-02-2017 00:07:16 Installed Microsoft Office Professional Plus 2010 07-02-2017 00:43:23 Installed DirectX 9.0 07-02-2017 00:45:42 Installed Conflict Global Storm 07-02-2017 00:50:27 Installed DirectX 9.0 08-02-2017 22:37:46 Installed PlayReady PC Runtime amd64 ==================== Faulty Device Manager Devices ============= Name: Intel(R) ICH8 Family USB2 Enhanced Host Controller - 283A Description: Intel(R) ICH8 Family USB2 Enhanced Host Controller - 283A Class Guid: {36fc9e60-c465-11cf-8056-444553540000} Manufacturer: Intel Service: usbehci Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Event log errors: ========================= Application errors: ================== Error: (02/10/2017 07:17:12 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (02/10/2017 06:25:40 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (02/10/2017 10:32:12 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (02/10/2017 05:22:40 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (02/09/2017 08:43:18 PM) (Source: Application Error) (EventID: 1005) (User: ) Description: Windows cannot access the file for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program pes6.exe because of this error. Program: pes6.exe File: The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: 00000000 Disk type: 0 Error: (02/09/2017 08:43:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: PES6.exe, version: 1.0.0.1, time stamp: 0x4502a65a Faulting module name: PES6.exe, version: 1.0.0.1, time stamp: 0x4502a65a Exception code: 0xc0000096 Fault offset: 0x00c194c8 Faulting process id: 0x3d0 Faulting application start time: 0x01d283010021ab0d Faulting application path: E:\P.A.S.SEASON 2016.2017\PES6.exe Faulting module path: E:\P.A.S.SEASON 2016.2017\PES6.exe Report Id: 9f323f8f-eef7-11e6-a72e-00e04c36071b Error: (02/09/2017 07:51:10 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (02/09/2017 03:51:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (02/08/2017 09:01:33 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (02/08/2017 01:35:15 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. System errors: ============= Error: (02/09/2017 01:02:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The UPnP Device Host service failed to start due to the following error: The service did not start due to a logon failure. Error: (02/09/2017 01:02:41 AM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: The upnphost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). Error: (02/09/2017 01:02:41 AM) (Source: DCOM) (EventID: 10005) (User: ) Description: DCOM got error "1069" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} Error: (02/08/2017 01:35:11 AM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly. Error: (02/08/2017 01:33:44 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 01:32:45 ص on ‏08/‏02/‏2017 was unexpected. Error: (02/07/2017 07:11:18 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (02/07/2017 07:11:18 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (02/07/2017 07:11:17 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (02/07/2017 07:11:17 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (02/07/2017 07:11:16 PM) (Source: Disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz Percentage of memory in use: 30% Total physical RAM: 4095.18 MB Available physical RAM: 2851.69 MB Total Virtual: 5117.37 MB Available Virtual: 3771.73 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:117.09 GB) (Free:83.97 GB) NTFS Drive d: () (Fixed) (Total:174.32 GB) (Free:41.67 GB) NTFS Drive e: () (Fixed) (Total:174.26 GB) (Free:43.34 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 102EC61B) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=117.1 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=174.3 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=174.3 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================