Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-11-2017 03 Ran by Sharon (12-11-2017 12:30:21) Running from C:\Users\Sharon\Desktop Windows 7 Professional Service Pack 1 (X64) (2017-10-23 02:51:34) Boot Mode: Safe Mode (with Networking) ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3754133454-3766197736-2095081909-500 - Administrator - Disabled) Guest (S-1-5-21-3754133454-3766197736-2095081909-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3754133454-3766197736-2095081909-1002 - Limited - Enabled) Sharon (S-1-5-21-3754133454-3766197736-2095081909-1001 - Administrator - Enabled) => C:\Users\Sharon ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{D811A40A-9791-497C-B9DC-2D89C8E95EA1}) (Version: 6.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{8B47B514-F5D2-4E0D-B951-6E250618A7CD}) (Version: 6.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{31A0B634-BCF4-4D3F-8336-87FEACFEE142}) (Version: 11.0.1.2 - Apple Inc.) Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.8.2318 - AVAST Software) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.36 - Piriform) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.62 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden iCloud (HKLM\...\{FF99A618-BCA5-4658-B9FF-CCF57C177610}) (Version: 7.1.0.34 - Apple Inc.) Intel(R) Network Connections 22.7.18.0 (HKLM\...\PROSetDX) (Version: 22.7.18.0 - Intel) IrfanView 4.50 (64-bit) (HKLM\...\IrfanView64) (Version: 4.50 - Irfan Skiljan) iTunes (HKLM\...\{F2517A28-8CB8-4206-B86C-5EDD4EA26682}) (Version: 12.7.1.14 - Apple Inc.) Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes) Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation) Microsoft Office 2010 Service Pack 1 (SP1) (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}) (Version: - Microsoft) Microsoft Office Professional 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox 56.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 56.0.2 (x64 en-US)) (Version: 56.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.1 - Mozilla) Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.) Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.104 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-3754133454-3766197736-2095081909-1001\...\Spotify) (Version: 1.0.66.478.g1296534d - Spotify AB) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-11] (AVAST Software) ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-11] (AVAST Software) ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2017-10-19] (Apple Inc.) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-11] (AVAST Software) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-11] (AVAST Software) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {19C443AE-94E7-4601-9820-F3B694245637} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-11-11] (AVAST Software) Task: {1BA9BCCE-2D44-4774-B741-35CD8FAF7EB1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.) Task: {20B7664E-F38F-4C90-9C0B-9FFDB408FC4C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-10-18] (Piriform Ltd) Task: {213640EE-C7F9-4D20-A40E-F447F9193E8E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-22] (Google Inc.) Task: {6CD6103D-3991-402C-87CF-5EB4CEB3B25D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-20] (Adobe Systems Incorporated) Task: {CFC7A65D-45E5-4C87-BF16-B544B8F221A3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-22] (Google Inc.) Task: {DE8C2646-8E57-4DBA-95EC-AAFE3D4A9C18} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-10-18] (Piriform Ltd) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\mydlink services plugin.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ldibdoepbjbkkcbgndfljnphngpglhbb ==================== Loaded Modules (Whitelisted) ============== 2017-10-24 17:55 - 2017-10-04 12:15 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 20:34 - 2009-06-10 15:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3754133454-3766197736-2095081909-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 75.75.76.76 - 75.75.75.75 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{506423B2-755F-4383-AD08-26A68C5739A6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{00D91CF5-8B8D-4313-93B3-E0D542D15839}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{AB2E8C01-4FC8-4F83-81D3-7AA811A13C27}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{07222C57-E865-41B6-8017-C4D2D549F887}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\sharon\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{AB449CAE-B8BA-47D8-958D-92027F146832}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\sharon\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{A34D0AE6-57D4-46D7-9162-92647999AAB5}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\sharon\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{DEF45A91-5C61-4820-BFBD-7CB1FCD76DF9}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\sharon\appdata\roaming\spotify\spotify.exe FirewallRules: [{3C4DE4AF-9A3F-4D34-8D2F-942EEC7DCFDE}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{042C2E35-242D-457E-A5FD-90A83DF96640}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{73DDA556-FBE4-4695-8AE5-9FCF6B74F489}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{72CE9576-9558-4AC6-870F-CBF903E20ED3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{B0BCEEE3-2BC0-4689-A61F-0D91BCCB00E3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{437AF8A6-CD8E-4C7E-96DF-822D7942FEC3}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Restore Points ========================= 04-11-2017 12:19:26 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 06-11-2017 21:49:58 Installed iTunes 06-11-2017 23:12:29 Installed iCloud ==================== Faulty Device Manager Devices ============= Name: PCI Simple Communications Controller Description: PCI Simple Communications Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Broadcom USH Description: Broadcom USH Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: PCI Serial Port Description: PCI Serial Port Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Security Processor Loader Driver Description: Security Processor Loader Driver Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: spldr Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: aswRvrt Description: aswRvrt Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: aswRvrt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: aswVmm Description: aswVmm Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: aswVmm Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (10/27/2017 06:10:21 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbamtray.exe, version: 3.0.0.1208, time stamp: 0x59d52b74 Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x59a63e00 Exception code: 0xc0000005 Fault offset: 0x001aa3b6 Faulting process id: 0xe8c Faulting application start time: 0x01d34f1c8897559e Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe Faulting module path: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll Report Id: cdb6409d-bb0f-11e7-9263-0024e8ca6469 Error: (10/27/2017 06:10:17 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbamservice.exe, version: 3.1.0.556, time stamp: 0x5988c3f1 Faulting module name: ntdll.dll, version: 6.1.7601.23915, time stamp: 0x59b94ee4 Exception code: 0xc0000005 Fault offset: 0x000000000004f23c Faulting process id: 0x788 Faulting application start time: 0x01d34f1c571174ab Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: cb174aad-bb0f-11e7-9263-0024e8ca6469 Error: (10/26/2017 05:36:25 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: GoogleUpdate.exe, version: 1.3.33.5, time stamp: 0x58fab261 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x70227374 Faulting process id: 0x74c Faulting application start time: 0x01d34e4ea7849641 Faulting application path: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Faulting module path: unknown Report Id: e5631e07-ba41-11e7-a09c-0024e8ca6469 Error: (10/26/2017 05:36:25 AM) (Source: Google Update) (EventID: 1) (User: NT AUTHORITY) Description: Event-ID 1 Error: (10/26/2017 05:36:22 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: armsvc.exe, version: 1.824.23.7067, time stamp: 0x59705185 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x70227374 Faulting process id: 0x658 Faulting application start time: 0x01d34e4e30339c85 Faulting application path: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe Faulting module path: unknown Report Id: e3c28d37-ba41-11e7-a09c-0024e8ca6469 Error: (10/26/2017 05:36:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mscorsvw.exe, version: 4.0.30319.1, time stamp: 0x4ba1da21 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x70227374 Faulting process id: 0xe14 Faulting application start time: 0x01d34e4e7eb51eae Faulting application path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe Faulting module path: unknown Report Id: df31c990-ba41-11e7-a09c-0024e8ca6469 Error: (10/25/2017 07:13:23 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: GoogleUpdate.exe, version: 1.3.33.5, time stamp: 0x58fab261 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x74976cc4 Faulting process id: 0xe54 Faulting application start time: 0x01d34d9308c5b08a Faulting application path: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Faulting module path: unknown Report Id: 46f2c5b9-b986-11e7-8110-0024e8ca6469 Error: (10/25/2017 07:13:23 AM) (Source: Google Update) (EventID: 1) (User: NT AUTHORITY) Description: Event-ID 1 Error: (10/25/2017 07:13:20 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: armsvc.exe, version: 1.824.23.7067, time stamp: 0x59705185 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x74976cc4 Faulting process id: 0x6a8 Faulting application start time: 0x01d34d8fbcd6ce7a Faulting application path: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe Faulting module path: unknown Report Id: 452c1ee5-b986-11e7-8110-0024e8ca6469 Error: (10/25/2017 06:42:14 AM) (Source: VSS) (EventID: 8194) (User: ) Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied. . This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {6b43a5d0-6417-452f-b791-7c758a18e9bb} System errors: ============= Error: (11/12/2017 11:55:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (11/12/2017 11:55:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (11/12/2017 11:55:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (11/12/2017 11:55:44 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. Error: (11/12/2017 11:55:32 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (11/12/2017 11:55:32 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (11/12/2017 11:55:32 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (11/12/2017 11:55:22 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. Error: (11/12/2017 11:54:06 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. Error: (11/12/2017 11:54:06 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. CodeIntegrity: =================================== Date: 2017-10-22 23:48:59.203 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-10-22 23:48:59.140 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU P9700 @ 2.80GHz Percentage of memory in use: 30% Total physical RAM: 3983.9 MB Available physical RAM: 2766.86 MB Total Virtual: 7965.99 MB Available Virtual: 6841.28 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:148.94 GB) (Free:21.67 GB) NTFS ==>[drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: A42D04A3) Partition 1: (Active) - (Size=148.9 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================