Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-06-2017 Ran by win7 (15-06-2017 16:29:37) Running from C:\Users\win7\Desktop Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2016-09-02 20:06:27) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1175016655-2442003890-1713799225-500 - Administrator - Disabled) Guest (S-1-5-21-1175016655-2442003890-1713799225-501 - Limited - Disabled) win7 (S-1-5-21-1175016655-2442003890-1713799225-1000 - Administrator - Enabled) => C:\Users\win7 ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 26 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 26.0.0.126 - Adobe Systems Incorporated) Adobe Flash Player 26 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 26.0.0.126 - Adobe Systems Incorporated) Adobe Flash Player 26 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 26.0.0.126 - Adobe Systems Incorporated) Adobe Reader XI (11.0.20) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated) CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) Fix My Browsers (HKLM\...\{D61EAB8D-2488-46C8-A0EA-54C225225B6A}) (Version: 2.0 - AE Technology) FlashPeak Slimjet (HKLM\...\Slimjet) (Version: 14.0.13.0 - FlashPeak Inc.) FormatFactory 3.9.5.0 (HKLM\...\FormatFactory) (Version: 3.9.5.0 - Free Time) HxD Hex Editor version 1.7.7.0 (HKLM\...\HxD Hex Editor_is1) (Version: 1.7.7.0 - Maël Hِrz) Internet Download Manager (HKLM\...\Internet Download Manager) (Version: - Tonec Inc.) iWebcam (HKLM\...\{358F4260-27F8-4070-ACAD-CF23CE1D0F1D}) (Version: 1.0.1 - IGENETIX CORPORATION) K-Lite Mega Codec Pack 12.9.5 (HKLM\...\KLiteCodecPack_is1) (Version: 12.9.5 - KLCP) LINE (HKU\S-1-5-21-1175016655-2442003890-1713799225-1000\...\LINE) (Version: 5.0.1.1394 - LINE Corporation) Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (العربية) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1025) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50905.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) PdfGrabber 8.0 (32bit) (HKLM\...\{436B31A2-3E3B-4D6D-B589-20E7C238B7C6}) (Version: 8.0.0.46 - PixelPlanet) PicosmosTools 1.6.5.0 (HKLM\...\PicosmosTools) (Version: 1.6.5.0 - Free Time) PixelPlanet PdfPrinter 7 (32bit) (HKLM\...\{000F58F3-A544-4BB5-AF1B-761EA1C8595C}) (Version: 7.0.161 - PixelPlanet) PL-2303 USB-to-Serial (HKLM\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.00.000 - Prolific Technology INC) SeaMonkey 2.40 (x86 fr) (HKLM\...\SeaMonkey 2.40 (x86 fr)) (Version: 2.40 - Mozilla) Serial Solutions Device Driver Suite (HKLM\...\SerialSolutions) (Version: 8.1 - Brainboxes Ltd) Viber (HKU\S-1-5-21-1175016655-2442003890-1713799225-1000\...\{d924dc86-33fe-49b3-9439-8b0e69ec7216}) (Version: 6.4.2.15 - Viber Media Inc.) Viber (Version: 6.4.2.15 - Viber Media Inc.) Hidden Vivaldi (HKU\S-1-5-21-1175016655-2442003890-1713799225-1000\...\Vivaldi) (Version: 1.5.658.56 - Vivaldi) VLC media player (HKLM\...\VLC media player) (Version: 3.0.0-git - VideoLAN) WhatsApp (HKU\S-1-5-21-1175016655-2442003890-1713799225-1000\...\WhatsApp) (Version: 0.2.2732 - WhatsApp) Winamp (remove only) (HKLM\...\Winamp) (Version: - ) WinCDEmu (HKLM\...\WinCDEmu) (Version: 3.6 - Bazis) WinPcap 4.1.3 (HKLM\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 5.40 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {02506E53-B3E5-4858-A9A6-49F5A63B6EC2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {0E24D859-509C-4E20-90AB-10D2D7B64E9C} - \Juqgehuwuk Cache -> No File <==== ATTENTION Task: {1C9C9F56-19E1-49CF-AB97-DB8D6862D395} - System32\Tasks\{21D424E3-2494-41AF-858F-31A3F7E1E2DD} => pcalua.exe -a "C:\Users\win7\Downloads\Compressed\Hein 4.5\HeinInstaller.exe" -d "C:\Users\win7\Downloads\Compressed\Hein 4.5" Task: {35FFAA56-267A-43E2-BEC2-14B55DC7D8F2} - \Universal\Driver Updater\Start Driver Updater оn logon -> No File <==== ATTENTION Task: {3BFF40B7-6D53-4B5F-8EE7-096735FD481B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {47503F01-BC1E-44A5-8CDD-ADE771EEB32E} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_126_pepper.exe [2017-06-14] (Adobe Systems Incorporated) Task: {58DBCA95-B349-4D58-A05E-C95BD9F7AFD4} - System32\Tasks\{71F88C38-6FB7-46EF-97B9-F6CFDC8AC77A} => pcalua.exe -a H:\Flash\Multimedia\QQPlayer_Setup_Arabic.exe -d H:\Flash\Multimedia Task: {6BADA25C-79E0-45B7-9CD4-5ECD257C3ABA} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\Windows\system32\EOSNotify.exe [2016-06-25] (Microsoft Corporation) Task: {6CF0E6CF-9AE2-4E18-99B7-AE4B5D82C6B1} - System32\Tasks\User_Feed_Synchronization-{90CDB1C5-E53F-4D03-B7AB-E5DF61F8244B} Task: {B4AD2F28-CFF2-4B59-B1BB-26369CDEFA8B} - System32\Tasks\{4AFC6ECB-61F7-4B88-98BE-13188E68A47E} => pcalua.exe -a "H:\Flash\Adobe Reader\PDFReader.exe" -d "H:\Flash\Adobe Reader" Task: {B9710C4A-9B7F-4470-8952-02419DC2A739} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-14] (Adobe Systems Incorporated) Task: {D7D37426-6F7D-48E7-B4F3-428FD1356785} - System32\Tasks\klcp_update => C:\Program Files\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2017-02-21] () Task: {E681EC7F-566A-45ED-9D6A-1E72D9EF88EB} - System32\Tasks\{65584C30-5387-4F3C-BB48-B6795C37E5A5} => pcalua.exe -a "C:\Users\win7\Downloads\Compressed\Hein 4.4.2\HeinInstaller.exe" -d "C:\Users\win7\Downloads\Compressed\Hein 4.4.2" Task: {E6CE464E-10A4-4A67-948B-6CF8D53FE677} - \Universal\Driver Updater\Start Driver Updater automatic scanning -> No File <==== ATTENTION Task: {FD0795FB-BA91-4533-9C4B-6292F6E6B0A6} - System32\Tasks\Qiaseferdusp Engine => C:\Program Files\Weloied\ckzish.exe [2017-01-12] (Glarysoft Ltd) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\win7\Desktop\Pre_Scan_Donate.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxps://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=S3AQ8V3XRWWYN ShortcutWithArgument: C:\Users\win7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\4242a155fcc27c2b\FlashPeak Slimjet.lnk -> C:\Program Files\Slimjet\slimjet.exe (FlashPeak Inc.) -> --profile-directory=Default ==================== Loaded Modules (Whitelisted) ============== 2017-03-08 17:18 - 2017-01-03 14:50 - 00335360 _____ () C:\Program Files\K-Lite Codec Pack\Icaros\32-bit\libunarr-ics.dll 2017-06-15 01:35 - 2017-05-25 14:11 - 01728968 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2005-12-08 21:18 - 2005-12-08 21:18 - 00035328 _____ () C:\Program Files\Winamp\winampa.exe 2015-07-24 15:19 - 2015-07-24 15:19 - 00659456 _____ () C:\Program Files\Common Files\BCL Technologies\PixelPlanet7\bepprint.dll 2017-06-14 16:09 - 2017-06-14 16:09 - 20064256 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_26_0_0_126.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2017-06-14 17:00 - 00000061 _____ C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 l.heouts.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1175016655-2442003890-1713799225-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\win7\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 197.39.242.222 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{58F11CE8-9B30-4766-8804-EAC51D5440D8}] => (Allow) C:\Program Files\FormatFactory\FFModules\Encoder\Doc\EBookCodec.exe FirewallRules: [{DE72335F-6DA6-4BC5-863A-F920645D2C22}] => (Allow) C:\Program Files\FormatFactory\FormatFactory.exe FirewallRules: [{8D8DEE5A-4138-4DD6-91B6-F1EA5ACD8A1D}] => (Allow) C:\Program Files\FormatFactory\FormatFactory.exe FirewallRules: [{1DA52E68-15ED-4881-8D9F-8EE47CDE8E57}] => (Allow) C:\Program Files\FormatFactory\FFModules\Encoder\Doc\EBookCodec.exe FirewallRules: [{D414F715-CD19-4C52-9FC2-BA941077182A}] => (Allow) C:\Program Files\FormatFactory\FFModules\Package\PTInstOnline.exe FirewallRules: [{DDB6AA6A-8014-43C1-B0F4-B1733387352D}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{910E7CE5-B007-48E3-A60D-C57393BBC884}] => (Allow) C:\Users\win7\AppData\Local\Vivaldi\Application\vivaldi.exe FirewallRules: [{C68CC35C-C043-4B96-B590-1FCD45A3EFB6}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{D8AD5BD6-0070-4A23-848F-F922D153811B}C:\users\win7\downloads\compressed\stbdaemon_304\stbdaemon_304\stbdaemon_304.exe] => (Block) C:\users\win7\downloads\compressed\stbdaemon_304\stbdaemon_304\stbdaemon_304.exe FirewallRules: [UDP Query User{9621AD06-813B-4270-92C3-302493389C20}C:\users\win7\downloads\compressed\stbdaemon_304\stbdaemon_304\stbdaemon_304.exe] => (Block) C:\users\win7\downloads\compressed\stbdaemon_304\stbdaemon_304\stbdaemon_304.exe FirewallRules: [TCP Query User{A66F6B0B-F7A3-4F5C-B227-1117DEBE46DE}C:\users\win7\downloads\compressed\stbdaemon_304\stbdaemon_304\data\serverd.exe] => (Block) C:\users\win7\downloads\compressed\stbdaemon_304\stbdaemon_304\data\serverd.exe FirewallRules: [UDP Query User{DF9CD73E-29F8-4545-9B1B-25129AEC2E5F}C:\users\win7\downloads\compressed\stbdaemon_304\stbdaemon_304\data\serverd.exe] => (Block) C:\users\win7\downloads\compressed\stbdaemon_304\stbdaemon_304\data\serverd.exe FirewallRules: [{F03F5CC8-41E1-45C8-AA88-F3DD41609CA3}] => (Allow) C:\Program Files\Fishhas\Application\chrome.exe FirewallRules: [{664574D5-F268-438C-BD6F-6E162DE0B3BF}] => (Allow) C:\Users\win7\Downloads\Compressed\EmbratoriaG6.5.2\EmbratoriaG6.5.2\libs.exe FirewallRules: [{EE937058-5568-47B3-B26F-B17F41DD4773}] => (Allow) C:\Users\win7\Downloads\Compressed\EmbratoriaG6.5.2\EmbratoriaG6.5.2\libs.exe FirewallRules: [{0CAEFE5F-601D-41AA-8E6E-A4071F542A62}] => (Allow) LPort=5000 ==================== Restore Points ========================= 28-05-2017 12:48:36 نقطة التدقيق المجدولة 07-06-2017 05:25:53 نقطة التدقيق المجدولة 08-06-2017 01:54:21 Removed amuleC 11-06-2017 02:54:19 Installed Google Chrome 11-06-2017 14:55:10 JRT Pre-Junkware Removal ==================== Faulty Device Manager Devices ============= Name: Communications Port 1 Description: Communications Port 1 Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/15/2017 02:45:17 AM) (Source: SideBySide) (EventID: 59) (User: ) Description: ‏‏فشل إنشاء سياق التنشيط لـ "C:\Users\win7\Downloads\Programs\Vivaldi.1.5.658.44.exe". حدث خطأ في ملف البيان أو ملف النهج C:\Users\win7\Downloads\Programs\Vivaldi.1.5.658.44.exe في السطر 0. بناء جملة Xml غير صحيح. Error: (06/15/2017 01:22:57 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: ‏‏فشل الحصول على اتفاقية ترخيص المستخدم. hr=0xC004C008 Sku Id=c619d61c-c2f2-40c3-ab3f-c5924314b0f3 Error: (06/15/2017 01:22:57 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: ‏‏تفاصيل فشل الحصول على ترخيص. hr=0xC004C008 Error: (06/15/2017 01:19:08 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: ‏‏فشل الحصول على اتفاقية ترخيص المستخدم. hr=0xC004C008 Sku Id=c619d61c-c2f2-40c3-ab3f-c5924314b0f3 Error: (06/15/2017 01:19:08 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: ‏‏تفاصيل فشل الحصول على ترخيص. hr=0xC004C008 Error: (06/14/2017 07:14:19 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: ‏‏فشل الحصول على اتفاقية ترخيص المستخدم. hr=0xC004C008 Sku Id=c619d61c-c2f2-40c3-ab3f-c5924314b0f3 Error: (06/14/2017 07:14:19 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: ‏‏تفاصيل فشل الحصول على ترخيص. hr=0xC004C008 Error: (06/14/2017 05:02:27 PM) (Source: Software Protection Platform Service) (EventID: 1008) (User: ) Description: ‏‏فشل الحصول على شهادة المعالج الآمن. hr=0x80072EE7 Error: (06/14/2017 05:02:27 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: ‏‏تفاصيل فشل الحصول على ترخيص. hr=0x80072EE7 Error: (06/14/2017 04:31:34 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: ‏‏فشل الحصول على اتفاقية ترخيص المستخدم. hr=0xC004C008 Sku Id=c619d61c-c2f2-40c3-ab3f-c5924314b0f3 System errors: ============= Error: (06/15/2017 04:13:39 PM) (Source: Microsoft-Windows-Eventlog) (EventID: 23) (User: NT AUTHORITY) Description: ‏‏صادفت خدمة تسجيل الأحداث خطأ (res=23) أثناء تهيئة تسجيل الموارد للقناة Microsoft-Windows-Windows Firewall With Advanced Security/Firewall. Error: (06/15/2017 04:13:39 PM) (Source: Disk) (EventID: 7) (User: ) Description: ‏‏الجهاز، \Device\Harddisk0\DR0، به كتلة تالفة. Error: (06/15/2017 04:13:37 PM) (Source: Disk) (EventID: 7) (User: ) Description: ‏‏الجهاز، \Device\Harddisk0\DR0، به كتلة تالفة. Error: (06/15/2017 04:13:34 PM) (Source: Disk) (EventID: 7) (User: ) Description: ‏‏الجهاز، \Device\Harddisk0\DR0، به كتلة تالفة. Error: (06/15/2017 04:13:32 PM) (Source: Disk) (EventID: 7) (User: ) Description: ‏‏الجهاز، \Device\Harddisk0\DR0، به كتلة تالفة. Error: (06/15/2017 04:13:29 PM) (Source: Disk) (EventID: 7) (User: ) Description: ‏‏الجهاز، \Device\Harddisk0\DR0، به كتلة تالفة. Error: (06/15/2017 04:13:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: ‏‏فشل بدء تشغيل الخدمة Intel AGP Bus Filter بسبب الخطأ التالي: ‏‏يتعذر بدء تشغيل الخدمة، إما لكونها معطلة أو لعدم وجود أي أجهزة ممكّنة مرفقة بها. Error: (06/15/2017 04:13:02 PM) (Source: Disk) (EventID: 7) (User: ) Description: ‏‏الجهاز، \Device\Harddisk0\DR0، به كتلة تالفة. Error: (06/15/2017 11:45:27 AM) (Source: Microsoft-Windows-Eventlog) (EventID: 23) (User: NT AUTHORITY) Description: ‏‏صادفت خدمة تسجيل الأحداث خطأ (res=23) أثناء تهيئة تسجيل الموارد للقناة Microsoft-Windows-Windows Firewall With Advanced Security/Firewall. Error: (06/15/2017 11:45:27 AM) (Source: Disk) (EventID: 7) (User: ) Description: ‏‏الجهاز، \Device\Harddisk0\DR0، به كتلة تالفة. CodeIntegrity: =================================== Date: 2017-06-15 00:31:15.462 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-06-15 00:31:14.433 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system. Date: 2017-06-15 00:31:14.370 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system. Date: 2017-06-15 00:31:14.292 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-06-14 18:38:13.864 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-06-14 18:38:13.022 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system. Date: 2017-06-14 18:38:12.975 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system. Date: 2017-06-14 18:38:12.913 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-06-14 16:01:51.473 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-06-14 16:01:50.428 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU E6550 @ 2.33GHz Percentage of memory in use: 60% Total physical RAM: 2012.49 MB Available physical RAM: 793.51 MB Total Virtual: 4024.98 MB Available Virtual: 2618.17 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:75.13 GB) (Free:39.66 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (New Volume) (Fixed) (Total:129.88 GB) (Free:126.5 GB) NTFS Drive e: (New Volume) (Fixed) (Total:129.88 GB) (Free:129.77 GB) NTFS Drive f: (New Volume) (Fixed) (Total:130.86 GB) (Free:122.8 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 6F356F35) Partition 1: (Active) - (Size=75.1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=129.9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=129.9 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=130.9 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================