Done. Here is the Fixlog
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-06-2017 01
Ran by Nick (15-06-2017 17:51:20) Run:2
Running from C:\Users\Nick\Desktop
Loaded Profiles: Nick (Available Profiles: Nick)
Boot Mode: Normal
==============================================
fixlist content:
*****************
start
CloseProcesses:
CreateRestorePoint:
Task: {AB1FBBCC-78CB-44A4-82AE-2A202A5A66F4} - \AdobeAAMUpdater-1.0-valgrind-Administrator -> No File <==== ATTENTION
Task: {E0992331-57FF-4205-9C14-D01F1D455379} - \Driver Booster SkipUAC (Administrator) -> No File <==== ATTENTION
HKLM-x32\...\Run: [cpx] => "C:\Users\Nick\AppData\Local\ntuserlitelist\cpx\cpx.exe" -starup <===== ATTENTION
Unlock: C:\Users\Nick\AppData\Local\ntuserlitelist
HKLM-x32\...\Run: [svcvmx] => C:\Users\Nick\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe [884224 2017-04-21] ()
C:\Users\Nick\AppData\Local\ntuserlitelist
"drmkpro64" => service could not be unlocked. <===== ATTENTION
S2 Dataup; C:\Program Files\ntuserlitelist\dataup\dataup.exe [0 2017-06-11] () <==== ATTENTION (zero byte File/Folder) <==== ATTENTION
S2 windowsmanagementservice; C:\Users\Administrator\AppData\Local\snqbji\myojh\ct.exe [0 2017-06-11] () <==== ATTENTION (zero byte File/Folder) <==== ATTENTION
C:\Users\Administrator\AppData\Local\snqbji
R5 drmkpro64; <===== ATTENTION: Locked Service
S3 iobit_monitor_server; \??\C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\drivers\Monitor_x64.sys [X]
S3 netwlv64; \SystemRoot\system32\DRIVERS\netwlv64.sys [X]
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]
2017-06-11 10:56 - 2017-06-11 10:56 - 00001583 _____ C:\Users\Administrator\Desktop\ct.exe.lnk
2017-06-11 09:55 - 2017-06-11 09:55 - 00001295 _____ C:\Users\Administrator\Desktop\svcvmx.lnk
2017-06-10 22:09 - 2017-06-11 12:36 - 00000000 ____D C:\Program Files\ntuserlitelist
2017-06-03 08:52 - 2017-06-10 21:45 - 00000000 ____D C:\Program Files\NTUSERLITELIST.del
2017-06-03 08:39 - 2017-06-03 08:39 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\c
2017-06-03 08:39 - 2017-06-03 08:39 - 00000000 ____D C:\Users\Administrator\AppData\Local\snqbji
2017-06-03 08:39 - 2017-06-03 08:39 - 00000000 ____D C:\Users\Administrator\AppData\Local\lxkvpcq
2017-02-22 22:01 - 2012-02-13 15:41 - 0314784 _____ () C:\Users\Administrator\AppData\Local\Temp\Uninstaller-2148.exe
2017-02-22 22:05 - 2012-02-13 15:41 - 0314784 _____ () C:\Users\Administrator\AppData\Local\Temp\Uninstaller-2216.exe
2017-01-24 20:36 - 2012-02-13 15:41 - 0314784 _____ () C:\Users\Administrator\AppData\Local\Temp\Uninstaller-3864.exe
2017-01-24 20:35 - 2012-02-13 15:41 - 0314784 _____ () C:\Users\Administrator\AppData\Local\Temp\Uninstaller-4720.exe
2017-01-24 20:36 - 2012-02-13 15:41 - 0314784 _____ () C:\Users\Administrator\AppData\Local\Temp\Uninstaller-4728.exe
2017-01-24 20:34 - 2012-02-13 15:41 - 0314784 _____ () C:\Users\Administrator\AppData\Local\Temp\Uninstaller-5056.exe
2017-01-30 05:59 - 2017-01-30 05:59 - 0065280 _____ () C:\Users\Administrator\AppData\Local\Temp\utils.dll
unlock: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\drmkpro64
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\drmkpro64" /f
unlock: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\windowsmanagementservice
reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\windowsmanagementservice" /f
hosts:
Emptytemp:
*****************
Processes closed successfully.
Restore point was successfully created.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AB1FBBCC-78CB-44A4-82AE-2A202A5A66F4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB1FBBCC-78CB-44A4-82AE-2A202A5A66F4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeAAMUpdater-1.0-valgrind-Administrator => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E0992331-57FF-4205-9C14-D01F1D455379} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0992331-57FF-4205-9C14-D01F1D455379} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Administrator) => key removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\cpx => value could not remove.
"C:\Users\Nick\AppData\Local\ntuserlitelist" => was unlocked
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\svcvmx => value could not remove.
C:\Users\Nick\AppData\Local\ntuserlitelist => moved successfully
"drmkpro64" => service could not be unlocked. <===== ATTENTION => Error: No automatic fix found for this entry.
HKLM\System\CurrentControlSet\Services\Dataup => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\windowsmanagementservice => key could not remove, key could be protected
C:\Users\Administrator\AppData\Local\snqbji => moved successfully
drmkpro64 => Unable to stop service.
HKLM\System\CurrentControlSet\Services\drmkpro64 => key could not remove. Access Denied.
HKLM\System\CurrentControlSet\Services\iobit_monitor_server => key removed successfully
iobit_monitor_server => service removed successfully
HKLM\System\CurrentControlSet\Services\netwlv64 => key removed successfully
netwlv64 => service removed successfully
HKLM\System\CurrentControlSet\Services\vmci => key removed successfully
vmci => service removed successfully
HKLM\System\CurrentControlSet\Services\VMnetAdapter => key removed successfully
VMnetAdapter => service removed successfully
Could not move "C:\Users\Administrator\Desktop\ct.exe.lnk" => Scheduled to move on reboot.
Could not move "C:\Users\Administrator\Desktop\svcvmx.lnk" => Scheduled to move on reboot.
C:\Program Files\ntuserlitelist => moved successfully
C:\Program Files\NTUSERLITELIST.del => moved successfully
C:\Users\Administrator\AppData\Roaming\c => moved successfully
"C:\Users\Administrator\AppData\Local\snqbji" => not found.
C:\Users\Administrator\AppData\Local\lxkvpcq => moved successfully
C:\Users\Administrator\AppData\Local\Temp\Uninstaller-2148.exe => moved successfully
C:\Users\Administrator\AppData\Local\Temp\Uninstaller-2216.exe => moved successfully
C:\Users\Administrator\AppData\Local\Temp\Uninstaller-3864.exe => moved successfully
C:\Users\Administrator\AppData\Local\Temp\Uninstaller-4720.exe => moved successfully
C:\Users\Administrator\AppData\Local\Temp\Uninstaller-4728.exe => moved successfully
C:\Users\Administrator\AppData\Local\Temp\Uninstaller-5056.exe => moved successfully
C:\Users\Administrator\AppData\Local\Temp\utils.dll => moved successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\drmkpro64" => key could not be unlocked
========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\drmkpro64" /f =========
ERROR: Access is denied.
========= End of Reg: =========
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\windowsmanagementservice" => key was unlocked
========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\windowsmanagementservice" /f =========
ERROR: Access is denied.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10599280 B
Java, Flash, Steam htmlcache => 7012181 B
Windows/system/drivers => 25792368 B
Edge => 0 B
Chrome => 11678778 B
Firefox => 0 B
Opera => 90837063 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 27011 B
systemprofile32 => 128 B
LocalService => 490964 B
NetworkService => 1331646 B
UpdatusUser => 0 B
Nick => 336424798 B
RecycleBin => 0 B
EmptyTemp: => 469.8 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 15-06-2017 17:53:25)
"C:\Users\Administrator\Desktop\ct.exe.lnk" => Could not move
"C:\Users\Administrator\Desktop\svcvmx.lnk" => Could not move
Result of scheduled keys to remove after reboot:
HKLM\System\CurrentControlSet\Services\Dataup => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\windowsmanagementservice => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\drmkpro64 => key could not remove. Access Denied.
==== End of Fixlog 17:53:25 ====