Additional scan result of Farbar Recovery Scan Tool (x86) Version: 05-05-2017 01 Ran by fadi (05-05-2017 16:24:10) Running from C:\Users\fadi\Desktop Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2017-02-05 17:08:28) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2843317728-1395094010-2175450331-500 - Administrator - Disabled) fadi (S-1-5-21-2843317728-1395094010-2175450331-1001 - Administrator - Enabled) => C:\Users\fadi Guest (S-1-5-21-2843317728-1395094010-2175450331-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2843317728-1395094010-2175450331-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AV: ESET Internet Security 10.0.390.0 (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70} AS: ESET Internet Security 10.0.390.0 (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD} AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-2843317728-1395094010-2175450331-1001\...\uTorrent) (Version: 3.5.0.43580 - BitTorrent Inc.) Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Adobe Flash Player 25 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 25.0.0.148 - Adobe Systems Incorporated) Adobe Flash Player 25 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated) Canon LBP2900 (HKLM\...\Canon LBP2900) (Version: - ) ESET Internet Security (HKLM\...\{A5EC24E5-99FA-4A5D-95B4-4BAAFF8B73E5}) (Version: 10.0.386.0 - ESET, spol. s r.o.) Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 8.2.1.6871 - Foxit Software Inc.) GameRanger (HKU\S-1-5-21-2843317728-1395094010-2175450331-1001\...\GameRanger) (Version: - GameRanger Technologies) Google Chrome (HKLM\...\Google Chrome) (Version: 58.0.3029.96 - Google Inc.) Google Update Helper (Version: 1.3.33.5 - Google Inc.) Hidden Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1883 - Intel Corporation) Internet Download Manager (HKLM\...\Internet Download Manager) (Version: - Tonec Inc.) Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) MassFaces 4.2.5.142 (HKLM\...\{D7B24A43-A287-41AC-9957-F616A2B25A9D}_is1) (Version: 4.2.5.142 - Havy Alegria) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation) Mozilla Firefox 53.0 (x86 en-US) (HKLM\...\Mozilla Firefox 53.0 (x86 en-US)) (Version: 53.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.0.6312 - Mozilla) MPC-HC 1.7.10 (HKLM\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.7.10 - MPC-HC Team) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8036 - Realtek Semiconductor Corp.) RogueKiller Version 12.10.7.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.10.7.0 - Adlice Software) Stronghold Crusader (HKLM\...\{8C3727F2-8E37-49E4-820C-03B1677F53B6}) (Version: - ) Tactical Ops (HKLM\...\Tactical Ops) (Version: - ) WinRAR 5.40 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {01015167-D068-4F76-9BC4-70C2A18DBCEB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-02-22] (Google Inc.) Task: {09280CE2-DE7E-492B-B000-3BD8B58931B1} - System32\Tasks\Driver Booster SkipUAC (fadi) => C:\Program Files\IObit\Driver Booster\4.3.0\DriverBooster.exe Task: {61643A04-BC3E-4F71-83C1-28F481296CED} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-02-22] (Google Inc.) Task: {83FEB616-E9D9-4DBB-B618-CD35EE7DC0D7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-12] (Adobe Systems Incorporated) Task: {8A24109A-40D7-4DFC-8049-A340DD64E36D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-02-03] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\lol.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=mfbjfefgkhmhhdobokinbepeagbdmgei ==================== Loaded Modules (Whitelisted) ============== 2017-05-03 08:15 - 2017-05-02 01:12 - 02864984 _____ () C:\Program Files\Google\Chrome\Application\58.0.3029.96\libglesv2.dll 2017-05-03 08:15 - 2017-05-02 01:12 - 00087384 _____ () C:\Program Files\Google\Chrome\Application\58.0.3029.96\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:76650B61 [103] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2017-02-21 02:48 - 00000035 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2843317728-1395094010-2175450331-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\fadi\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 208.67.222.123 - 208.67.220.123 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{129DA10D-FF19-4B96-A082-674DE4F463EB}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{007347CF-BFBC-41F6-B856-7CC14299F37A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{7D3B8B2B-30A3-494F-8C25-C1290965E915}] => (Allow) C:\Users\fadi\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{8B2F1C3D-3E5F-4EC1-85AC-666CF5FEC2A2}] => (Allow) C:\Users\fadi\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{BBA030F9-7623-4358-A552-7FD8EC4CC08C}] => (Allow) C:\Users\fadi\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{7ADBDD4D-AA4C-46E4-B0E3-603A00ADAC47}] => (Allow) C:\Users\fadi\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{42EAC369-182F-461E-BBDA-FEF673E294FB}] => (Allow) C:\Users\fadi\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{83D42CFE-B997-496D-9C09-5C272DC90D7E}] => (Allow) C:\Users\fadi\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{276BF38C-68FE-4B5F-8000-BC42C734538E}] => (Allow) C:\Users\fadi\AppData\Local\Temp\recinstalldl\RecInst.exe FirewallRules: [{E7994156-F469-4AD2-8BDB-B597A7234B84}] => (Allow) C:\Users\fadi\AppData\Local\Temp\recinstalldl\RecInst.exe FirewallRules: [{B342B3E6-D54B-4384-9484-14644598FFDC}] => (Allow) C:\Program Files\Tencent\QQPlayer\QQPlayer.exe FirewallRules: [{024FDEDD-DAFF-400D-B512-3D5A8193A46F}] => (Allow) C:\Program Files\Tencent\QQPlayer\QQPlayer.exe FirewallRules: [{473D7771-9174-49E5-8524-1EEF933318C6}] => (Allow) C:\Program Files\Tencent\QQPlayer\QPUp.exe FirewallRules: [{87762DDD-1B93-4A05-B02C-E2663C39028E}] => (Allow) C:\Program Files\Tencent\QQPlayer\QPUp.exe FirewallRules: [{83F13472-6C8D-4C7C-9F5D-5DF5DB4A98E4}] => (Allow) C:\Program Files\Common Files\Tencent\QQDownload\118\Tencentdl.exe FirewallRules: [{A7E3B22A-490D-4D48-8C4D-FC6592B6097D}] => (Allow) C:\Program Files\Common Files\Tencent\QQDownload\118\Tencentdl.exe FirewallRules: [{15B72D70-0A1E-4F81-9498-F1472338CBB2}] => (Allow) C:\Program Files\Tencent\QQPlayer\QPToolbox.exe FirewallRules: [{0BA80C1D-5CB9-4F52-9FC3-9F22941B60E1}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{A0513DD3-31E8-4248-B78C-3F2FAD0BFA40}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{E6F2C661-E027-4997-904B-C307C1E00714}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{54A6DD38-FFBB-4410-99AB-24ABC8A0A83F}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{3E459E02-63ED-4334-B9BD-7DA0AF33013D}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{94FDAB91-7FF7-4EFA-9058-A478BACC9C49}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 24-04-2017 20:14:33 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 24-04-2017 20:15:47 Windows Update 27-04-2017 22:13:34 Driver Booster : Atheros AR5007EG Wireless Network Adapter 27-04-2017 23:01:29 Windows Update 27-04-2017 23:18:17 Installed DirectX 30-04-2017 14:24:42 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (05/04/2017 09:47:45 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (05/04/2017 11:43:55 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (05/04/2017 11:04:48 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (05/03/2017 11:10:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (05/03/2017 08:04:30 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (05/02/2017 04:19:53 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (05/01/2017 08:31:12 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: csgo.exe, version: 0.0.0.0, time stamp: 0x58ffa9a7 Faulting module name: tier0.dll, version: 0.0.0.0, time stamp: 0x58ffa998 Exception code: 0xc0000005 Fault offset: 0x000093e4 Faulting process id: 0xe4c Faulting application start time: 0x01d2c24ce6b4ccab Faulting application path: D:\Program Files\Counter-Strike Global Offensive\csgo.exe Faulting module path: D:\Program Files\Counter-Strike Global Offensive\bin\tier0.dll Report Id: 26a7dd4c-2e40-11e7-b9b8-001e33904a32 Error: (05/01/2017 08:30:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: csgo.exe, version: 0.0.0.0, time stamp: 0x58ffa9a7 Faulting module name: tier0.dll, version: 0.0.0.0, time stamp: 0x58ffa998 Exception code: 0xc0000005 Fault offset: 0x000093e4 Faulting process id: 0xe10 Faulting application start time: 0x01d2c24cddcb53d3 Faulting application path: D:\Program Files\Counter-Strike Global Offensive\csgo.exe Faulting module path: D:\Program Files\Counter-Strike Global Offensive\bin\tier0.dll Report Id: 1dbf4ed7-2e40-11e7-b9b8-001e33904a32 Error: (05/01/2017 08:30:11 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: csgo.exe, version: 0.0.0.0, time stamp: 0x58ffa9a7 Faulting module name: tier0.dll, version: 0.0.0.0, time stamp: 0x58ffa998 Exception code: 0xc0000005 Fault offset: 0x000093e4 Faulting process id: 0x167c Faulting application start time: 0x01d2c24cc0e99040 Faulting application path: D:\Program Files\Counter-Strike Global Offensive\csgo.exe Faulting module path: D:\Program Files\Counter-Strike Global Offensive\bin\tier0.dll Report Id: 01e22dd5-2e40-11e7-b9b8-001e33904a32 Error: (05/01/2017 08:28:10 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: csgo.exe, version: 0.0.0.0, time stamp: 0x58ffa9a7 Faulting module name: tier0.dll, version: 0.0.0.0, time stamp: 0x58ffa998 Exception code: 0xc0000005 Fault offset: 0x000093e4 Faulting process id: 0x1180 Faulting application start time: 0x01d2c24c77dfe659 Faulting application path: D:\Program Files\Counter-Strike Global Offensive\csgo.exe Faulting module path: D:\Program Files\Counter-Strike Global Offensive\bin\tier0.dll Report Id: b9c7c96f-2e3f-11e7-b9b8-001e33904a32 System errors: ============= Error: (05/05/2017 11:49:04 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 40. Error: (05/04/2017 11:42:17 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 11:33:23 AM on ‎5/‎4/‎2017 was unexpected. Error: (05/02/2017 04:18:47 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 4:16:50 PM on ‎5/‎2/‎2017 was unexpected. Error: (05/01/2017 04:00:52 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout. Error: (04/30/2017 04:50:22 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 4:48:38 PM on ‎4/‎30/‎2017 was unexpected. Error: (04/29/2017 12:20:11 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 11:36:18 AM on ‎4/‎29/‎2017 was unexpected. Error: (04/29/2017 05:13:21 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the wuauserv service. Error: (04/23/2017 05:37:31 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 5:36:38 AM on ‎4/‎23/‎2017 was unexpected. Error: (04/19/2017 05:24:51 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WinDefend service. Error: (04/16/2017 10:09:15 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 10:02:48 PM on ‎4/‎16/‎2017 was unexpected. CodeIntegrity: =================================== Date: 2017-04-25 21:09:31.522 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. Date: 2017-04-25 21:09:31.513 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. Date: 2017-04-25 21:09:31.502 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. Date: 2017-04-25 21:09:31.479 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. Date: 2017-04-25 21:09:31.468 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. Date: 2017-04-25 21:09:31.458 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. Date: 2017-04-13 19:31:12.471 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. Date: 2017-04-13 19:31:12.462 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. Date: 2017-04-13 19:31:12.451 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. Date: 2017-04-13 19:31:12.428 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET Internet Security\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz Percentage of memory in use: 50% Total physical RAM: 2940 MB Available physical RAM: 1443.86 MB Total Virtual: 5878.29 MB Available Virtual: 4105.33 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:97.56 GB) (Free:55.02 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:200.43 GB) (Free:190.47 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 22740B6F) Partition 1: (Active) - (Size=97.6 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=200.4 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================