CloseProcesses: CreateRestorePoint: Task: {5DAABC4B-88B7-4264-ACBF-078A6D1F23D8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 2017-03-29 19:04 - 2017-03-29 19:04 - 00833024 ____N () C:\windows\system32\tprdpw32.exe 2017-01-13 20:09 - 2017-01-13 20:09 - 00896512 ____N () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe C:\Users\Noah\AppData\Local\ntuserlitelist 2017-01-05 17:36 - 2017-01-05 17:36 - 00077824 ____N () C:\Users\Noah\AppData\Local\ntuserlitelist\dataup\dataup.exe 2017-01-14 19:40 - 2017-01-14 19:40 - 53460992 ____N () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\libcef.dll 2016-05-31 11:43 - 2016-05-31 11:43 - 01976832 ____N () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\libglesv2.dll 2016-05-31 11:44 - 2016-05-31 11:44 - 00075264 ____N () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\libEGL.dll 2016-09-21 23:32 - 2016-09-21 23:32 - 00224768 ____N () C:\Users\Noah\AppData\Local\ntuserlitelist\dataup\help_dll.dll 2016-06-15 17:15 - 2016-06-15 17:15 - 17599640 ____N () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\pepflashplayer.dll () C:\Windows\System32\tprdpw32.exe () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe () C:\Users\Noah\AppData\Local\ntuserlitelist\dataup\dataup.exe () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe () C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe HKLM-x32\...\Run: [cpx] => "C:\Users\Noah\AppData\Local\ntuserlitelist\cpx\cpx.exe" -starup <===== ATTENTION HKLM-x32\...\Run: [svcvmx] => C:\Users\Noah\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe [896512 2017-01-13] () R2 Dataup; C:\Users\Noah\AppData\Local\ntuserlitelist\dataup\dataup.exe [77824 2017-01-05] () [File not signed] <==== ATTENTION S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S2 realtek_amd64; "C:\Users\Noah\AppData\Local\Temp\WS\realtek_amd64.exe" [X] <==== ATTENTION S2 windowsmanagementservice; "C:\Users\Noah\AppData\Local\flrclq\ct.exe" /svc [X] <==== ATTENTION C:\Users\Noah\AppData\Local\flrclq R0 drmkpro64; C:\WINDOWS\System32\drivers\ndistpr64.sys [78112 2013-09-28] () [File not signed] <==== ATTENTION U3 idsvc; no ImagePath U3 wpcsvc; no ImagePath DeleteKey: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\Dataup 2017-04-20 21:11 - 2017-04-20 21:11 - 00000000 ____D C:\Users\Noah\AppData\Local\llssoft 2017-03-29 19:04 - 2017-03-29 19:04 - 00833024 ____N C:\WINDOWS\system32\tprdpw32.exe CMD: bitsadmin /reset /allusers CMD: netsh winsock reset catalog CMD: ipconfig /flushdns RemoveProxy: hosts: Emptytemp: [/code] [list][*]Click Format and ensure Wordwrap is unchecked. [*]Save as [b]Fixlist.txt[/b] to your Desktop (Must be in this location) [*]Run FRST/FRST64 and press the [b]Fix button[/b] just once and wait. [*]If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart. [*]The tool will make a log on the Desktop [b](Fixlog.txt).[/b] Please post it to your reply.[/list]