Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 Ran by Edyta (2016-04-06 20:01:59) Running from C:\Users\Edyta\Downloads Windows 10 Home Version 1511 (X64) (2016-02-23 23:52:59) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-4279228227-215742994-1318027649-500 - Administrator - Disabled) => C:\Users\Administrator DefaultAccount (S-1-5-21-4279228227-215742994-1318027649-503 - Limited - Disabled) Edyta (S-1-5-21-4279228227-215742994-1318027649-1001 - Administrator - Enabled) => C:\Users\Edyta Guest (S-1-5-21-4279228227-215742994-1318027649-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-4279228227-215742994-1318027649-1001\...\uTorrent) (Version: 3.4.3.40760 - BitTorrent Inc.) AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) Apple Application Support (32-bit) (HKLM-x32\...\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{2937FD88-C9D6-4B82-B539-37CD0A572F42}) (Version: 4.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) BankID Aplikacja Bezpieczeństwa (HKLM-x32\...\{1BDBF557-BA87-438F-9B28-AE4D836E35BA}) (Version: 7.1.0.20 - Financial ID-Technology) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CrystalDiskInfo 6.5.2 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.5.2 - Crystal Dew World) ETDWare X64 15.7.0.1_WHQL (HKLM\...\Elantech) (Version: 15.7.0.1 - ELAN Microelectronic Corp.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.110 - Google Inc.) Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.4.907.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7543 - Realtek Semiconductor Corp.) S Agent (Version: 1.0.9 - Samsung Electronics CO., LTD.) Hidden Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) SW Update (HKLM-x32\...\{577948CC-8675-4766-95EE-49731FDF6DDC}) (Version: 2.1.4 - Samsung Electronics CO., LTD.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-4279228227-215742994-1318027649-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Edyta\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4279228227-215742994-1318027649-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {53B5E90B-8177-4D90-8F5B-3776E28C290D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {632E1A9D-B5F0-45B4-A638-2356FDE95481} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-4279228227-215742994-1318027649-1001 Task: {95F83C26-7E7C-4827-9F2E-8C178CF08863} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-27] (Google Inc.) Task: {BB6AD64B-98A4-4786-8255-C7BB613FD2CD} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2012-10-25] (Samsung Electronics CO., LTD.) Task: {E648D024-D2C7-4E70-8946-B7EC7B453D7D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-27] (Google Inc.) Task: {E7EF9A87-D1F3-42ED-9E53-4AAF199A23E4} - System32\Tasks\SWUpdateAgent => C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe [2012-11-09] (Samsung Electronics CO., LTD.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-04-08 10:59 - 2015-04-08 10:59 - 00022528 _____ () C:\WINDOWS\System32\ssj1mlm.dll 2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-03-18 22:56 - 2016-03-18 22:56 - 01329936 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2016-03-27 20:29 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-03-27 20:29 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-02-25 19:42 - 2016-02-25 19:42 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-02-24 01:46 - 2016-02-24 01:46 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-03-27 20:29 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-02-24 01:46 - 2016-02-24 01:46 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-02-24 01:46 - 2016-02-24 01:46 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-02-24 01:46 - 2016-02-24 01:46 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-02-24 01:46 - 2016-02-24 01:46 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-02-25 19:42 - 2016-02-25 19:42 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-02-25 19:42 - 2016-02-25 19:42 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-04-01 12:24 - 2016-03-27 09:58 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libglesv2.dll 2016-04-01 12:24 - 2016-03-27 09:58 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\libegl.dll 2016-04-01 12:24 - 2016-03-27 09:58 - 17545880 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4279228227-215742994-1318027649-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Edyta\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\purpleworld12.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{9E54E72E-D735-4537-A3A0-82F784B8D432}] => (Allow) C:\Users\Edyta\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{B3510DB3-94CE-474C-B205-0A82B52D1259}] => (Allow) C:\Users\Edyta\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{98D092D4-EA57-4F5B-950D-F370BB050078}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{FF909057-C84E-44EB-AF86-1B20F88CD32C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{EE27EDC9-FEF6-4734-A0DE-776D221CC493}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{8437A2FB-5A32-4E1F-AD3A-9907BE7A7AB9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{93539C4D-611C-4C12-B9E3-84BFABB3C796}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{0D7092CA-5FD0-447F-B48E-1576B437FB3A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 14-03-2016 17:15:55 Windows Modules Installer 27-03-2016 21:46:49 Installed iTunes 06-04-2016 19:33:58 Restore Point Created by FRST ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/06/2016 07:34:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (04/06/2016 07:33:57 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied. . This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {4447f65b-b5c7-4b3e-84b2-ffb1b350e070} Error: (04/01/2016 12:04:16 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EDYTKA) Description: Activation of application Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147009280 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (04/01/2016 11:55:37 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: atieclxx.exe, version: 6.14.11.1199, time stamp: 0x563a76a9 Faulting module name: ntdll.dll, version: 10.0.10586.122, time stamp: 0x56cbf9dd Exception code: 0xc0000374 Fault offset: 0x00000000000ee6dc Faulting process ID: 0x1f60 Faulting application start time: 0xatieclxx.exe0 Faulting application path: atieclxx.exe1 Faulting module path: atieclxx.exe2 Report ID: atieclxx.exe3 Faulting package full name: atieclxx.exe4 Faulting package-relative application ID: atieclxx.exe5 Error: (03/29/2016 06:36:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: microsoftedgecp.exe, version: 11.0.10586.20, time stamp: 0x56540c35 Faulting module name: chakra.dll, version: 11.0.10586.162, time stamp: 0x56cd37be Exception code: 0xc0000005 Fault offset: 0x00000000000a2877 Faulting process ID: 0x27a4 Faulting application start time: 0xmicrosoftedgecp.exe0 Faulting application path: microsoftedgecp.exe1 Faulting module path: microsoftedgecp.exe2 Report ID: microsoftedgecp.exe3 Faulting package full name: microsoftedgecp.exe4 Faulting package-relative application ID: microsoftedgecp.exe5 Error: (03/28/2016 10:21:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_OneSyncSvc_109d66, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: ntdll.dll, version: 10.0.10586.122, time stamp: 0x56cbf9dd Exception code: 0xc0000008 Fault offset: 0x00000000000a8c6a Faulting process ID: 0x1004 Faulting application start time: 0xsvchost.exe_OneSyncSvc_109d660 Faulting application path: svchost.exe_OneSyncSvc_109d661 Faulting module path: svchost.exe_OneSyncSvc_109d662 Report ID: svchost.exe_OneSyncSvc_109d663 Faulting package full name: svchost.exe_OneSyncSvc_109d664 Faulting package-relative application ID: svchost.exe_OneSyncSvc_109d665 Error: (03/28/2016 06:44:34 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ETDCtrl.exe, version: 11.60.7.8, time stamp: 0x55c2ffaa Faulting module name: ETDCtrl.exe, version: 11.60.7.8, time stamp: 0x55c2ffaa Exception code: 0xc0000005 Fault offset: 0x000000000000bdb2 Faulting process ID: 0x5b4 Faulting application start time: 0xETDCtrl.exe0 Faulting application path: ETDCtrl.exe1 Faulting module path: ETDCtrl.exe2 Report ID: ETDCtrl.exe3 Faulting package full name: ETDCtrl.exe4 Faulting package-relative application ID: ETDCtrl.exe5 Error: (03/27/2016 09:47:17 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (03/27/2016 09:14:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: microsoftedgecp.exe, version: 11.0.10586.20, time stamp: 0x56540c35 Faulting module name: chakra.dll, version: 11.0.10586.103, time stamp: 0x56a849ae Exception code: 0xc0000005 Fault offset: 0x0000000000275b91 Faulting process ID: 0x282c Faulting application start time: 0xmicrosoftedgecp.exe0 Faulting application path: microsoftedgecp.exe1 Faulting module path: microsoftedgecp.exe2 Report ID: microsoftedgecp.exe3 Faulting package full name: microsoftedgecp.exe4 Faulting package-relative application ID: microsoftedgecp.exe5 Error: (03/27/2016 09:13:11 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SearchUI.exe, version: 10.0.10586.63, time stamp: 0x568b1fdc Faulting module name: ntdll.dll, version: 10.0.10586.103, time stamp: 0x56a8483f Exception code: 0xc0000008 Fault offset: 0x00000000000a8c1a Faulting process ID: 0x20cc Faulting application start time: 0xSearchUI.exe0 Faulting application path: SearchUI.exe1 Faulting module path: SearchUI.exe2 Report ID: SearchUI.exe3 Faulting package full name: SearchUI.exe4 Faulting package-relative application ID: SearchUI.exe5 System errors: ============= Error: (04/06/2016 07:38:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: %%1053 Error: (04/06/2016 07:38:36 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect. Error: (04/06/2016 07:35:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_2258cfc service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (04/06/2016 07:35:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Storage_2258cfc service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (04/06/2016 07:35:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Contact Data_2258cfc service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (04/06/2016 07:35:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Sync Host_2258cfc service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (04/06/2016 07:35:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (04/06/2016 07:34:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (04/06/2016 07:34:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Apple Mobile Device Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error: (04/06/2016 07:33:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. CodeIntegrity: =================================== Date: 2016-04-01 11:59:13.017 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-29 17:44:36.798 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-03-28 17:11:12.067 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-28 16:27:18.209 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-03-27 21:50:08.467 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-14 16:18:17.672 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-29 21:03:47.793 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-02-25 18:02:03.392 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-25 17:55:06.317 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-02-24 00:23:26.456 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz Percentage of memory in use: 21% Total physical RAM: 8077.6 MB Available physical RAM: 6324.46 MB Total Virtual: 9357.6 MB Available Virtual: 7563.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:905.18 GB) (Free:419.89 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 0B1EA754) Partition: GPT. ==================== End of Addition.txt ============================