Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Possible SmartService infection


  • Please log in to reply

#1
grdsproblem

grdsproblem

    New Member

  • Member
  • Pip
  • 8 posts

Hi, I really need some help here. My computer suddenly decided to turn off my anti-virus and just about anything that i want to play games from. (Steam and ARC) I have just installed a new graphics card that was sealed when I got it so I believe it was new and not the possible infection route. I can use a computer but also spend plenty of time playing games on my computer but I may have watched or clicked on the clickbait vids on FB at the moment (stupid I know as i keep telling all my friends not to do it) Anyways I have tried to update/ re-install my anti-virus and have tried Malwarebytes and othe AV programs. All of these will download to my computer but will not run. I have completed the Farbar scan and these are the logs. Btw these all happened about 2 days before I went on holiday for a week and while I should have asked for help then I didn't (my bad). I'm hoping someone can help me as I really don't know if i can get a clean install of these computer again. (my dad used to build them and then sold all his computers and stuff so I don't even know if he has kept the discs)

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018

Ran by robin (administrator) on ROBIN-PC (10-07-2018 20:08:49)
Running from C:\Users\robin\Desktop\Free tools
Loaded Profiles: robin (Available Profiles: robin)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM-x32\...\Run: [Avira System Speedup User Starter] => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [64096 2018-03-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2018-05-30] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3752768 2018-06-18] (Dropbox, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [f.lux] => C:\Users\robin\AppData\Local\FluxSoftware\Flux\flux.exe [1682936 2018-01-17] (f.lux Software LLC)
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46139776 2018-03-15] ()
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [Spotify Web Helper] => C:\Users\robin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [782736 2018-05-12] (Spotify Ltd)
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3201312 2018-06-09] (Valve Corporation)
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Policies\Explorer: [DisallowCpl] 1
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\MountPoints2: {2746c5cc-0f46-11e7-884e-90e6ba4f7032} - E:\Setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{74134C22-B139-4950-A9F4-BEEFD0288E23}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{9C1F6614-1893-45D7-9C93-B71051A292FD}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{E34654FF-2966-4B38-A6DD-8C8A5B581BEF}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.sky.com/
SearchScopes: HKU\S-1-5-21-1842024429-2714170209-1629358381-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={D7B0D661-1F0E-4026-8CF9-771B143800A5}&mid=3e24702b1e7047cd90ae41affcab99c1-7c8f98919273630b2f1b9f57a2c9093ee4e299f0&lang=en&ds=AVG&coid=avgtbavg&cmpid=0516avz&pr=fr&d=2016-05-16 12:06:18&v=4.2.9.726&pid=wtu&sg=&sap=dsp&q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2018-01-25] (IObit)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-07-14] (LastPass)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-04-18] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Arc\plugins\ArcPluginIE.dll [2017-07-28] (Perfect World Entertainment Inc)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-07-14] (LastPass)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-18] (Oracle Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-07-14] (LastPass)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-07-14] (LastPass)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
Toolbar: HKU\S-1-5-21-1842024429-2714170209-1629358381-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
IE Session Restore: HKU\S-1-5-21-1842024429-2714170209-1629358381-1001 -> is enabled.
DPF: HKLM-x32 {0E5F0222-96B9-11D3-8997-00104BD12D94} hxxp://www.pcpitstop.com/nirvana/controls/pcmatic.cab
 
FireFox:
========
FF DefaultProfile: 
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-07-14] (LastPass)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-18] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-07-14] (LastPass)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-06-01] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-06-01] (NVIDIA Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Arc\plugins\npArcPluginFF.dll [2017-07-28] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxps://www.facebook.com/login.php"
CHR NewTab: Default ->  Active:"chrome-extension://ojhmphdkpgbibohbnpbfiefkgieacjmh/app/index.html"
CHR DefaultSearchURL: Default -> hxxps://search.avira.com/#web/result?source=omnibar&q={searchTerms}
CHR DefaultSearchKeyword: Default -> lp
CHR DefaultSuggestURL: Default -> hxxps://search.avira.com/suggestions?q={searchTerms}&li=ff&hl=en
CHR Profile: C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default [2018-07-10]
CHR Extension: (Slides) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Docs) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (IBM Security Rapport) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof [2018-03-14]
CHR Extension: (YouTube) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Adblock Plus) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-05-16]
CHR Extension: (Google Search) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Tampermonkey) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-05-15]
CHR Extension: (Iron Man 3) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebkgohjhkmajdealpbnfimnchjepjmii [2015-07-17]
CHR Extension: (Mahjongg) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegpopcingfghbompjfejakfeaolmbop [2015-07-17]
CHR Extension: (minerBlock) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\emikbbbebcdfohonlaifafnoanocnebl [2018-07-10]
CHR Extension: (Sheets) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Google Docs Offline) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2018-07-10]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-04-02]
CHR Extension: (Lightshot (screenshot tool)) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbniclmhobmnbdlbpiphghaielnnpgdp [2018-01-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Picky Wallpapers) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\odklcfojpedohplkimfdpcamkjnhanaj [2015-08-18]
CHR Extension: (Currently) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhmphdkpgbibohbnpbfiefkgieacjmh [2016-07-17]
CHR Extension: (Weather Underground) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjejbgheonogbpfkkjigbmahaljipoej [2015-07-17]
CHR Extension: (Gmail) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-18]
CHR Extension: (Chrome Media Router) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-30]
CHR Profile: C:\Users\robin\AppData\Local\Google\Chrome\User Data\System Profile [2018-06-30]
CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [879128 2018-06-20] (Avira Operations GmbH & Co. KG)
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [224472 2018-06-20] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [224472 2018-06-20] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1164808 2018-06-20] (Avira Operations GmbH & Co. KG)
S3 ArcService; C:\Program Files (x86)\Arc\ArcService.exe [87064 2017-07-28] (Perfect World Entertainment Inc)
S3 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1149712 2016-09-13] (AVG Technologies CZ, s.r.o.)
S2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [452352 2018-05-30] (Avira Operations GmbH & Co. KG)
S2 AviraOptimizerHost; C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe [2940584 2018-03-16] (Avira Operations GmbH & Co. KG)
R2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [346528 2018-05-17] (Avira Operations GmbH & Co. KG)
S2 AviraUpdaterService; C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe [103328 2018-06-15] (Avira Operations GmbH & Co. KG)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-05-30] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-05-30] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51024 2018-06-18] (Dropbox, Inc.)
S3 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659456 2017-12-11] (Foxit Software Inc.)
S3 ImDskSvc; C:\Windows\system32\imdsksvc.exe [25720 2017-02-17] (Olof Lagerkvist)
S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [206096 2018-01-25] (IObit)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [3878728 2017-02-25] (Paramount Software UK Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-14] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-14] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2201920 2018-06-12] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3072328 2018-06-12] (Electronic Arts)
S2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [5253624 2018-05-23] (IBM Corp.)
S3 Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [155520 2015-06-10] (Avanquest Software) [File not signed]
S2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [297240 2018-04-09] (Reason Software Company Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [466096 2018-04-24] (Windscribe Limited)
S3 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
S2 AdvancedSystemCareService11; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 
S2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [64504 2017-09-23] (Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [199912 2018-05-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [153552 2018-05-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-09-23] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [78600 2017-09-23] (Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [34128 2017-09-23] (Avira Operations GmbH & Co. KG)
R2 ImDisk; C:\Windows\System32\DRIVERS\imdisk.sys [95376 2017-02-28] (Olof Lagerkvist)
S3 IUFileFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IUFileFilter.sys [21928 2017-06-06] (IObit.com)
S3 IURegProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IURegProcessFilter.sys [22416 2018-01-11] (IObit.com)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-07-10] (Malwarebytes)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 netr28x; C:\Windows\System32\DRIVERS\netr28x.sys [2473616 2014-12-10] (MediaTek Inc.)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [31168 2018-03-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [59240 2017-12-15] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [68112 2018-06-01] (NVIDIA Corporation)
S3 phantomtap; C:\Windows\System32\DRIVERS\phantomtap.sys [35664 2017-10-25] (The OpenVPN Project)
R1 RapportAegle64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportAegle64.sys [496744 2018-05-23] (IBM Corp.)
R1 RapportCerberus_1919106; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1919106.sys [1645288 2018-06-12] (IBM Corp.)
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [712488 2018-05-23] (IBM Corp.)
R0 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [340904 2018-05-23] (IBM Corp.)
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [605160 2018-05-23] (IBM Corp.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [751976 2018-05-23] (IBM Corp.)
R3 tapwindscribe0901; C:\Windows\System32\DRIVERS\tapwindscribe0901.sys [45560 2018-02-01] (The OpenVPN Project)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2017-10-08] (Zemana Ltd.)
R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-10-08] (Zemana Ltd.)
S3 GLCKIO; \??\C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\690b33e1-0462-4e84-9bea-c7552b45432a.sys [X]
S3 iobit_monitor_server; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_win7_x64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-07-10 19:57 - 2018-07-10 19:57 - 000947200 _____ C:\Users\robin\Desktop\avcertclean_1.2.0.exe
2018-07-10 19:51 - 2018-07-10 19:51 - 000002984 _____ C:\Windows\System32\Tasks\{282CA983-1786-4B1A-9AAE-2F92F8EBEF32}
2018-07-10 19:49 - 2018-07-10 19:49 - 005414912 _____ (Avira Operations GmbH & Co. KG) C:\Users\robin\Desktop\avira_en_fass0_5b44ff778f8d6__ws.exe
2018-06-30 17:24 - 2018-06-30 17:25 - 010393048 _____ (COMODO) C:\Users\robin\Desktop\ccav_installer_chid33220011.exe
2018-06-30 07:59 - 2018-07-10 20:08 - 000000000 ____D C:\FRST
2018-06-30 07:50 - 2018-06-30 07:50 - 002526736 _____ (Trend Micro Inc.) C:\Users\robin\Downloads\HousecallLauncher64.exe
2018-06-30 07:50 - 2018-06-30 07:50 - 000000036 _____ C:\Users\robin\AppData\Local\housecall.guid.cache
2018-06-30 07:26 - 2018-06-30 07:26 - 000002942 _____ C:\Windows\System32\Tasks\{1B7BAF58-7C42-47F2-96B9-BA0CF07AF434}
2018-06-29 13:22 - 2018-07-10 19:42 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-06-29 13:17 - 2018-06-29 13:17 - 005376592 _____ (Avira Operations GmbH & Co. KG) C:\Users\robin\Downloads\avira_en_av_59db815d90804__ws.exe
2018-06-21 14:47 - 2018-06-21 14:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-06-19 22:42 - 2018-06-19 22:42 - 002673793 _____ C:\Users\robin\Downloads\SSE_Airtricity_Domestic_Tariff_Table_effective_from_01_Apr_2018.pdf
2018-06-19 01:47 - 2018-06-19 01:47 - 000000222 _____ C:\Users\robin\Desktop\Neverwinter.url
2018-06-18 11:23 - 2018-06-18 11:23 - 000051024 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2018-06-18 11:23 - 2018-06-18 11:23 - 000050232 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2018-06-18 11:23 - 2018-06-18 11:23 - 000045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2018-06-18 11:23 - 2018-06-18 11:23 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2018-06-13 15:15 - 2018-06-13 15:15 - 000000000 ____D C:\ProgramData\PopCap Games
2018-06-12 18:52 - 2018-06-12 18:52 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-06-12 18:52 - 2018-06-01 09:47 - 000132680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2018-06-12 18:51 - 2018-06-12 18:51 - 000000000 ____D C:\Windows\system32\unknown
2018-06-12 18:51 - 2018-06-12 18:51 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2018-06-12 18:50 - 2018-06-02 04:06 - 040090152 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 032360304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 016999360 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2018-06-12 18:50 - 2018-06-02 04:06 - 001419200 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 001092008 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 000627240 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 000517544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 040346536 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 035250624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 031276296 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 013727800 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 003964328 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 003497024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 002014144 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6439811.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 001562208 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 001468272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6439811.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 001216448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 001157216 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000420008 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000182600 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000165136 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000159712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000142824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2018-06-12 18:50 - 2018-06-02 04:04 - 019081176 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2018-06-12 18:50 - 2018-06-02 04:04 - 017782576 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2018-06-12 18:50 - 2018-06-01 11:27 - 000227928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2018-06-12 18:50 - 2018-06-01 11:27 - 000068112 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2018-06-12 18:50 - 2018-06-01 11:27 - 000047648 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2018-06-12 18:50 - 2018-06-01 11:27 - 000000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2018-06-12 18:50 - 2018-06-01 11:27 - 000000669 _____ C:\Windows\system32\nv-vk64.json
2018-06-12 18:40 - 2018-06-12 18:40 - 000003922 _____ C:\Windows\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2018-06-12 18:40 - 000000000 ____D C:\Users\robin\ansel
2018-06-12 18:40 - 2017-12-15 03:03 - 000059240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2018-06-12 18:34 - 2018-06-25 13:33 - 000000022 _____ C:\Windows\GPU-Z.INI
2018-06-12 18:30 - 2018-06-26 22:05 - 000002978 _____ C:\Windows\System32\Tasks\GPU Tweak II
2018-06-12 18:30 - 2018-06-12 18:30 - 000001067 _____ C:\Users\Public\Desktop\ASUS GPU TweakII.lnk
2018-06-12 18:30 - 2018-06-12 18:30 - 000000000 ____D C:\Windows\Downloaded Installations
2018-06-12 18:30 - 2018-06-12 18:30 - 000000000 ____D C:\Users\robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS
2018-06-12 18:30 - 2018-06-12 18:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2018-06-12 18:30 - 2018-06-12 18:30 - 000000000 ____D C:\Program Files (x86)\ASUS
2018-06-12 18:29 - 2018-06-01 11:27 - 001688848 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2018-06-12 18:29 - 2018-06-01 09:39 - 000634152 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2018-06-12 18:29 - 2018-06-01 09:39 - 000083528 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2018-06-12 18:28 - 2017-05-11 21:43 - 001988032 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438223.dll
2018-06-12 18:28 - 2017-05-11 21:43 - 001589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438223.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 025990104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 023298224 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 020323576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 011272944 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 000904720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 000505928 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2018-06-12 18:27 - 2018-06-02 04:04 - 015691144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2018-06-12 18:27 - 2018-06-02 04:04 - 015192816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2018-06-12 18:26 - 2018-06-02 04:04 - 004613600 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2018-06-12 18:26 - 2018-06-02 04:04 - 004081440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2018-06-12 13:02 - 2018-06-12 13:05 - 000152184 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-06-12 13:02 - 2018-06-12 13:02 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-06-12 13:02 - 2018-06-12 13:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-06-11 19:15 - 2018-06-11 19:15 - 000001116 _____ C:\Users\Public\Desktop\Avira.lnk
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-07-10 20:08 - 2017-10-08 00:25 - 000067459 _____ C:\Windows\ZAM.krnl.trace
2018-07-10 20:08 - 2017-10-08 00:25 - 000038386 _____ C:\Windows\ZAM_Guard.krnl.trace
2018-07-10 20:08 - 2017-05-14 17:31 - 000000000 ____D C:\Users\robin\Desktop\Free tools
2018-07-10 19:56 - 2009-07-14 05:45 - 000017760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-07-10 19:56 - 2009-07-14 05:45 - 000017760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-07-10 19:51 - 2015-07-12 09:46 - 000000000 ____D C:\ProgramData\NVIDIA
2018-07-10 19:49 - 2009-07-14 06:13 - 000781790 _____ C:\Windows\system32\PerfStringBackup.INI
2018-07-10 19:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2018-07-10 19:45 - 2017-05-30 14:16 - 000000906 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2018-07-10 19:41 - 2017-05-30 14:16 - 000000902 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2018-07-10 19:40 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-06-29 13:20 - 2015-07-12 09:46 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-06-29 13:19 - 2018-05-15 16:38 - 000000000 ____D C:\Program Files (x86)\Steam
2018-06-29 13:18 - 2017-05-08 16:11 - 000000000 ____D C:\Users\robin\AppData\Local\CrashDumps
2018-06-29 13:14 - 2016-12-07 20:54 - 000000000 ____D C:\Users\robin\AppData\Roaming\Origin
2018-06-22 11:01 - 2017-10-05 11:36 - 000003292 _____ C:\Windows\System32\Tasks\Avira_Antivirus_Systray
2018-06-21 14:47 - 2017-05-30 14:16 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-06-20 14:36 - 2017-10-05 11:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2018-06-19 01:47 - 2018-05-15 16:51 - 000000000 ____D C:\Users\robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-06-18 19:44 - 2017-10-05 11:34 - 000000000 ____D C:\Program Files (x86)\Avira
2018-06-15 16:17 - 2015-07-12 09:42 - 000000000 ____D C:\Windows\system32\MRT
2018-06-15 16:14 - 2017-10-12 03:05 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-06-15 16:14 - 2015-07-12 09:42 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-06-13 14:27 - 2016-12-07 20:52 - 000000000 ____D C:\ProgramData\Origin
2018-06-12 19:22 - 2016-12-07 21:05 - 000000000 ____D C:\Program Files (x86)\Origin Games
2018-06-12 19:22 - 2009-07-14 06:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2018-06-12 19:04 - 2016-12-07 20:53 - 000000000 ____D C:\Program Files (x86)\Origin
2018-06-12 18:52 - 2015-07-12 09:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-06-12 18:52 - 2015-07-12 09:46 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-06-12 18:52 - 2015-07-12 09:46 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-06-12 18:51 - 2016-11-21 20:11 - 000000000 ____D C:\Users\robin\AppData\Roaming\NVIDIA
2018-06-12 18:40 - 2017-08-27 13:29 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003798 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000001416 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2018-06-12 18:40 - 2015-07-12 09:39 - 000000000 ____D C:\Users\robin
2018-06-12 18:39 - 2017-03-22 17:17 - 000000000 ____D C:\Users\robin\AppData\Local\NVIDIA Corporation
2018-06-12 18:32 - 2018-03-26 17:58 - 000000000 ____D C:\Users\Public\Speedup Sessions
2018-06-12 18:30 - 2015-07-13 11:03 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-06-12 18:22 - 2016-11-09 11:11 - 000000000 ____D C:\ProgramData\ProductData
2018-06-12 18:22 - 2015-11-19 15:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
2018-06-11 19:15 - 2015-07-12 22:34 - 000000000 ____D C:\ProgramData\Package Cache
 
==================== Files in the root of some directories =======
 
2015-07-14 19:22 - 2015-07-14 19:22 - 016581656 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2018-06-30 07:50 - 2018-06-30 07:50 - 000000036 _____ () C:\Users\robin\AppData\Local\housecall.guid.cache
2017-06-01 14:49 - 2017-06-01 14:49 - 000002169 _____ () C:\Users\robin\AppData\Local\recently-used.xbel
2017-03-19 18:13 - 2017-10-04 12:52 - 000007613 _____ () C:\Users\robin\AppData\Local\resmon.resmoncfg
2015-08-03 00:19 - 2015-08-03 00:19 - 000000000 _____ () C:\Users\robin\AppData\Local\{1CDDFEFE-2396-4356-9F17-7D3511F8B3BB}
2015-08-05 23:53 - 2015-08-05 23:53 - 000000000 _____ () C:\Users\robin\AppData\Local\{5C712DF7-A97E-4A15-ABB6-FC693BC721FF}
2015-07-31 15:18 - 2015-07-31 15:18 - 000000000 _____ () C:\Users\robin\AppData\Local\{660DCC4B-0A28-4AE3-902D-BF3558E7BDC0}
2015-08-09 04:48 - 2015-08-09 04:48 - 000000000 _____ () C:\Users\robin\AppData\Local\{A3E00A1E-B47F-4DD3-88D1-6BEF3A159611}
2017-10-11 15:04 - 2017-10-11 15:04 - 000000000 _____ () C:\Users\robin\AppData\Local\{D4A2EB80-4AF0-472D-9C97-C07DFD97709D}
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-06-17 20:30
 
==================== End of FRST.txt ============================
 
Addition text
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by robin (10-07-2018 20:09:21)
Running from C:\Users\robin\Desktop\Free tools
Windows 7 Ultimate Service Pack 1 (X64) (2015-07-12 08:39:05)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1842024429-2714170209-1629358381-500 - Administrator - Disabled)
Guest (S-1-5-21-1842024429-2714170209-1629358381-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1842024429-2714170209-1629358381-1002 - Limited - Enabled)
robin (S-1-5-21-1842024429-2714170209-1629358381-1001 - Administrator - Enabled) => C:\Users\robin
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avira Antivirus (Disabled - Out of date) {B3F630BD-538D-1B4A-14FA-14B63235278F}
AS: Avira Antivirus (Disabled - Out of date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.215 - Adobe Systems Incorporated)
Adobe Flash Player 30 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Amazon Kindle) (Version: 1.21.0.48017 - Amazon)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
ASUS GPU TweakII (HKLM-x32\...\{0075AAC2-EA9F-490E-83F7-5D5F81EB2A43}) (Version: 1.4.5.2 - ASUSTek COMPUTER INC.) Hidden
ASUS GPU TweakII (HKLM-x32\...\InstallShield_{0075AAC2-EA9F-490E-83F7-5D5F81EB2A43}) (Version: 1.4.5.2 - ASUSTek COMPUTER INC.)
AVG Zen (HKLM\...\{6DDF7DAF-58CC-44EC-B172-22CC5886E472}) (Version: 1.111.9 - AVG Technologies) Hidden
Avira (HKLM-x32\...\{606c7b25-e58d-4e72-82dd-4a0e4e163086}) (Version: 1.2.114.16977 - Avira Operations GmbH & Co. KG)
Avira (HKLM-x32\...\{C7FA948A-FC14-4316-92DC-23AF70C55A10}) (Version: 1.2.114.16977 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.36.200 - Avira Operations GmbH & Co. KG)
Avira Phantom VPN (HKLM-x32\...\Avira Phantom VPN) (Version: 2.14.1.26975 - Avira Operations GmbH & Co. KG)
Avira Safe Shopping (HKLM-x32\...\{14E3F849-589B-42DB-83C4-D856CFE94BCC}) (Version: 1.0.67.2779 - Avira Operations Gmbh & Co. KG)
Avira Safe Shopping (HKLM-x32\...\{9158dccb-03a7-493c-b07e-f47b9784425c}) (Version: 1.0.65.2672 - Avira Operations Gmbh & Co. KG) Hidden
Avira Software Updater (HKLM-x32\...\{A7F41426-5F75-4695-BE5D-B011821079A3}) (Version: 2.0.5.48230 - Avira Operations GmbH & Co. KG)
Avira System Speedup (HKLM-x32\...\Avira System Speedup_is1) (Version: 4.8.0.7455 - Avira Operations GmbH & Co. KG)
Backup and Sync from Google (HKLM\...\{4B7277C7-9CEE-45FC-B36B-19AD28281B9C}) (Version: 3.40.8921.5350 - Google, Inc.)
BBC iPlayer Downloads (HKLM-x32\...\{148784F3-3B6E-4DFA-B7A1-3400B277DAF3}) (Version: 1.14.2 - BBC)
CCleaner (HKLM\...\CCleaner) (Version: 5.37 - Piriform)
DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 398.11 - NVIDIA Corporation) Hidden
Drakensang Online (HKLM-x32\...\Drakensang Online) (Version:  - )
Dropbox (HKLM-x32\...\Dropbox) (Version: 52.4.58 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.75.1 - Dropbox, Inc.) Hidden
f.lux (HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Flux) (Version:  - f.lux Software LLC)
FastStone Image Viewer 6.2 (HKLM-x32\...\FastStone Image Viewer) (Version: 6.2 - FastStone Soft)
FMW 1 (HKLM\...\{1C3364DF-40B5-4DA4-9810-652A9A792FB1}) (Version: 1.132.1 - AVG Technologies) Hidden
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 9.0.1.1049 - Foxit Software Inc.)
GIMP 2.8.22 (HKLM\...\GIMP-2_is1) (Version: 2.8.22 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 65.0.3325.181 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.115 - Google Inc.) Hidden
GXTool (HKLM-x32\...\93D383D2-DFB3-46F1-8A08-AA6113AB39DE) (Version: 1.0 - Trust International BV)
Icecream Ebook Reader version 5.07 (HKLM-x32\...\{B8C30F0F-1F23-49E1-A3ED-44DE17660EE2}_is1) (Version: 5.07 - Icecream Apps)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 7.4.0.8 - IObit)
Java 8 Update 171 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
LastPass (uninstall only) (HKLM-x32\...\LastPass) (Version:  - LastPass)
Macrium Reflect Free Edition (HKLM\...\{595B8A7B-253D-4A4E-95C2-A823EDDD5496}) (Version: 6.3.1745 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 6.3 - Paramount Software (UK) Ltd.)
Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Mass Effect™ 2 (HKLM-x32\...\{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}) (Version: 1.2.1604.0 - Electronic Arts)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40649 (HKLM-x32\...\{35b83883-40fa-423c-ae73-2aff7e1ea820}) (Version: 12.0.40649.5 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NVIDIA 3D Vision Controller Driver 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 398.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 398.11 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.13.1.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.13.1.30 - NVIDIA Corporation)
NVIDIA Graphics Driver 398.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 398.11 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.37.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.37.4 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 10.5.20.63112 - Electronic Arts, Inc.)
Peggle (HKLM-x32\...\{715AD72D-887A-459E-988B-D4F3E87FA24B}) (Version: 1.04.0.0 - PopCap Games)
PVSonyDll (HKLM\...\{3D3E663D-4E7E-4577-A560-7ECDDD45548A}) (Version: 1.00.0001 - NVIDIA Corporation) Hidden
Rapport (HKLM-x32\...\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}) (Version: 3.5.1919.126 - Trusteer) Hidden
Serif PagePlus X7 (HKLM\...\{CB487BBA-A1AC-4B2B-80AC-DED349C897C5}) (Version: 17.0.3.28 - Serif (Europe) Ltd)
Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.15.9.201506301709 - Sony Mobile Communications Inc.)
Sony PC Companion 2.10.275 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.275 - Sony)
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Spotify (HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Spotify) (Version: 1.0.80.474.gef6b503e - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SysGauge 2.3.18 (HKLM-x32\...\SysGauge) (Version: 2.3.18 - Flexense Computing Systems Ltd.)
Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1919.126 - Trusteer)
Unchecky v1.2 (HKLM-x32\...\Unchecky) (Version: 1.2 - Reason Software Company Inc.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windscribe (HKLM-x32\...\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1) (Version: 1.81 Build 44 - Windscribe Limited)
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.150 - Zemana Ltd.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-03-15] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-03-15] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-03-15] (Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-10-08] ()
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll -> No File
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ContextMenuHandlers1: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2017-12-11] (Foxit Software Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-03-15] (Google)
ContextMenuHandlers1: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2018-01-25] (IObit)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers1: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2018-06-20] (Avira Operations GmbH & Co. KG)
ContextMenuHandlers1: [SystemSpeedupFilesMenu] -> {ef263503-8f0e-3e6a-ae2e-fe0b4b441d52} => C:\Windows\system32\mscoree.dll [2010-11-05] (Microsoft Corporation)
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll -> No File
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll -> No File
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-03-15] (Google)
ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2018-01-25] (IObit)
ContextMenuHandlers4: [SystemSpeedupFoldersMenu] -> {3d52b24d-33bb-3895-99ea-a0156f24a3f9} => C:\Windows\system32\mscoree.dll [2010-11-05] (Microsoft Corporation)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2018-06-01] (NVIDIA Corporation)
ContextMenuHandlers5: [SystemSpeedupDesktopMenu] -> {cefaf456-bc17-3f4b-b7d9-75070925911b} => C:\Windows\system32\mscoree.dll [2010-11-05] (Microsoft Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-10-08] ()
ContextMenuHandlers6: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2017-12-11] (Foxit Software Inc.)
ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2018-01-25] (IObit)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers6: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2018-06-20] (Avira Operations GmbH & Co. KG)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {12154847-6015-4A4A-A8E0-0BC14A6D9C8A} - System32\Tasks\{E745508C-7C48-4833-8CD1-FBF2DFACAA52} => C:\Program Files (x86)\Arc\ArcLauncher.exe [2017-07-28] (Perfect World Entertainment)
Task: {24021360-F1E2-488E-892E-77085812125D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {365EB785-625F-4428-BFC4-DE277C4A5AAA} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-11-08] (Piriform Ltd)
Task: {37873B39-08B1-4178-AD5D-FFCFEDD2E35A} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-05-30] (Dropbox, Inc.)
Task: {473D73B3-A037-4BC5-A4A9-5E947B386FCD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {47F5BB32-639E-4832-9EF7-8B862C2B9958} - System32\Tasks\Avira\System Speedup\TestScheduler => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [2018-03-22] (Avira Operations GmbH & Co. KG)
Task: {4CCAFA97-DA72-48A8-944C-7AE5C527BF6F} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2018-06-20] (Avira Operations GmbH & Co. KG)
Task: {665DBBD3-7E44-4A8C-A185-13A34E2CDA66} - System32\Tasks\{282CA983-1786-4B1A-9AAE-2F92F8EBEF32} => C:\Users\robin\Desktop\avira_en_fass0_5b44ff778f8d6__ws.exe [2018-07-10] (Avira Operations GmbH & Co. KG)
Task: {721CA277-CA6A-4E2A-BD0D-E4DFB6AC8434} - System32\Tasks\{1B7BAF58-7C42-47F2-96B9-BA0CF07AF434} => C:\Program Files (x86)\Steam\Steam.exe [2018-06-09] (Valve Corporation)
Task: {75C12851-5E7F-4463-8A42-4ABA2FEB053F} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-03-14] (NVIDIA Corporation)
Task: {85487D5A-1950-4F15-86A3-2710A99BC584} - System32\Tasks\Uninstaller_SkipUac_robin => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2018-03-28] (IObit)
Task: {8A0F8D44-B1F7-419C-9684-E6EE85B38C24} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\2 => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-03-28] (Oracle Corporation)
Task: {8A17E877-E81D-4CD7-81A5-E0765B35A0B9} - System32\Tasks\GPU Tweak II => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [2017-04-12] (TODO: <Company name>)
Task: {8A4248A2-611B-4FE1-B1BC-FEB50EC5BF99} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-03-14] (NVIDIA Corporation)
Task: {8B4D7B0C-9E28-4BC2-9CA1-B3E1F5487550} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\1 => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2018-06-18] (Dropbox, Inc.)
Task: {90176E31-415D-4C53-9357-3C67A83685FE} - System32\Tasks\Avira\Safe Shopping\Check => C:\Program Files (x86)\Avira\Safe Shopping\Updater\Updater.exe [2018-06-13] (Avira Operations Gmbh & Co. KG)
Task: {90988451-0E55-4DA2-9E08-06562BB1E225} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\4 => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
Task: {95197C81-C36E-401D-A93F-6A13958404D2} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-03-14] (NVIDIA Corporation)
Task: {98970E1F-AE1B-40B3-BFA0-CEB3796141CF} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-03-14] (NVIDIA Corporation)
Task: {B08301AD-ED1C-4D31-9C6E-5CF2F181B7C2} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-03-14] (NVIDIA Corporation)
Task: {B0B1D339-DA94-4C6D-87EF-981B687C6F3B} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\3 => C:\Program Files (x86)\Common Files\lpuninstall.exe [2015-07-14] (LastPass)
Task: {C297E826-97BD-4456-8F0D-9D9DB244F7AC} - System32\Tasks\{2E98E6EB-122B-4F06-827D-45859DFE9060} => C:\Program Files (x86)\Arc\ArcLauncher.exe [2017-07-28] (Perfect World Entertainment)
Task: {C655F85F-B8E7-4CF8-81B0-D842126E5785} - System32\Tasks\Avira\Safe Shopping\Update => C:\Program Files (x86)\Avira\Safe Shopping\Updater\Updater.exe [2018-06-13] (Avira Operations Gmbh & Co. KG)
Task: {CB7CF415-1DD5-4C6D-B86F-2992229800AD} - System32\Tasks\{1FC9F61C-5CE7-4A47-9E3B-D00C948504B7} => C:\Program Files (x86)\Arc\ArcLauncher.exe [2017-07-28] (Perfect World Entertainment)
Task: {CDAD47D6-C109-4C20-868B-0D2893FA2FF4} - System32\Tasks\Avira\System Speedup\Delayed Startup\robin\1 => C:\Users\robin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018-05-12] (Spotify Ltd) <==== ATTENTION
Task: {CE048D73-140A-4C72-8179-AF5517937291} - System32\Tasks\ASC11_SkipUac_robin => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {D0869D90-F0D3-4B50-8257-9965FBC3252A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-11-08] (Piriform Ltd)
Task: {D902A691-4E87-4AEB-A7F0-2C762C277CEF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-06-08] (Adobe Systems Incorporated)
Task: {DB737D28-7C34-47F1-9F48-13BE35C2795D} - System32\Tasks\Avira\Safe Shopping\Launch => C:\Program Files (x86)\Avira\Safe Shopping\Updater\Updater.exe [2018-06-13] (Avira Operations Gmbh & Co. KG)
Task: {E1F4B9E4-E2CC-4C14-9DC9-91D105FCA9CF} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-03-28] (Oracle Corporation)
Task: {EE60FCF1-E17C-4DEB-BB20-F51093FD4D5B} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-03-14] (NVIDIA Corporation)
Task: {F3831C5D-3D07-470B-8DC2-A5AAA85A509C} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-05-30] (Dropbox, Inc.)
Task: {F43F7407-7AD3-4F5A-A484-EAFE7ABF4B26} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-03-14] (NVIDIA Corporation)
Task: {F85C1A72-2F11-4A5F-8A69-577268816696} - System32\Tasks\AviraSystemSpeedupUpdate => C:\ProgramData\Avira\SystemSpeedup\Update\avira_speedup_setup_update.exe [2018-03-26] (Avira Operations GmbH & Co. KG )
Task: {F9BEE171-2CAF-402F-B52B-08A70124DC96} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-03-14] (NVIDIA Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2017-10-08 00:24 - 2017-10-08 00:24 - 000155504 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
2018-03-15 11:31 - 2018-03-15 11:31 - 046139776 _____ () C:\Program Files\Google\Drive\googledrivesync.exe
2018-07-10 19:41 - 2018-07-10 19:41 - 000113152 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\_ctypes.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000080896 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\bz2.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 001585152 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\_hashlib.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000128512 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32api.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000137728 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\pywintypes27.dll
2018-07-10 19:41 - 2018-07-10 19:41 - 000548864 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\pythoncom27.dll
2018-07-10 19:41 - 2018-07-10 19:41 - 000689664 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\unicodedata.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000438784 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32com.shell.shell.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 001489408 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\wx._core_.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 001007104 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\wx._gdi_.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 001039872 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\wx._windows_.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 001325056 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\wx._controls_.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000916992 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\wx._misc_.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 001084416 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\pysqlite2._sqlite.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000149504 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32file.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000136192 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32security.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000007680 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\hashobjs_ext.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000020992 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\thumbnails_ext.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000118784 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\usb_ext.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000047616 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\_socket.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 002224128 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\_ssl.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000014848 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\common.time34.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000023040 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32event.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000033280 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\windows.conditional.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000019968 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\windows.winwrap.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000107520 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\windows.volumes.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000223232 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32gui.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000173568 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\_elementtree.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000169472 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\pyexpat.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000048128 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32inet.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000103424 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\wx._html2.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000046080 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\_psutil_windows.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000633240 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\windows._cacheinvalidation.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 005408256 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\cello.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000010752 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\select.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000011776 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32crypt.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000301568 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\PIL._imaging.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000032256 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\_multiprocessing.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000026112 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\_yappi.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000044032 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32process.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000027648 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32pipe.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000029696 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32pdh.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000038400 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\windows.connectivity.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000071168 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\windows.device_monitor.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000020480 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32profile.pyd
2018-07-10 19:41 - 2018-07-10 19:41 - 000026624 _____ () C:\Users\robin\AppData\Local\Temp\_MEI20682\win32ts.pyd
2017-03-22 17:17 - 2018-03-14 14:05 - 001267648 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2018-03-29 14:35 - 2018-03-20 07:00 - 004435288 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libglesv2.dll
2018-03-29 14:35 - 2018-03-20 07:00 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\robin\Documents\Doughnaughty2d.ppp:SummaryInformation [215]
AlternateDataStreams: C:\Users\robin\Documents\Doughnaughty2d.ppp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\robin\Documents\Doughnaughty3d.ppp:SummaryInformation [215]
AlternateDataStreams: C:\Users\robin\Documents\Doughnaughty3d.ppp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 03:34 - 2018-06-30 08:25 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\robin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: nvsvc => 2
MSCONFIG\startupfolder: C:^Users^robin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^zSpeedup.lnk => C:\Windows\pss\zSpeedup.lnk.Startup
MSCONFIG\startupreg: Avira System Speedup User Starter => "C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: Sony PC Companion => "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
MSCONFIG\startupreg: ZAM => "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /minimized
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
01-07-2018 18:02:58 Windows Update
02-07-2018 02:40:52 Windows Update
10-07-2018 20:01:07 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
 
System errors:
=============
Error: (07/10/2018 07:44:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Unchecky service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (07/10/2018 07:44:49 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (120000 milliseconds) while waiting for the Unchecky service to connect.
 
Error: (07/10/2018 07:44:49 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (120000 milliseconds) while waiting for the NVIDIA Telemetry Container service to connect.
 
Error: (07/10/2018 07:44:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Dropbox Update Service (dbupdate) service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (07/10/2018 07:44:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (120000 milliseconds) while waiting for the Dropbox Update Service (dbupdate) service to connect.
 
Error: (07/10/2018 07:44:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (120000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.
 
Error: (07/10/2018 07:42:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (120000 milliseconds) while waiting for the Avira Service Host service to connect.
 
Error: (07/10/2018 07:42:38 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}
 and APPID 
{344ED43D-D086-4961-86A6-1106F4ACAD9B}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7 CPU 920 @ 2.67GHz
Percentage of memory in use: 31%
Total physical RAM: 12279.12 MB
Available physical RAM: 8443.76 MB
Total Virtual: 24556.4 MB
Available Virtual: 19907.14 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:223.47 GB) (Free:90.48 GB) NTFS
 
\\?\Volume{b8e5dc61-2870-11e5-ad3b-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 223.6 GB) (Disk ID: F60F1EBF)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223.5 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
Any help would be greatly appreciated as it seems such a pity that I went to the expense of a new graphics card for my computer to seemingly take the hump with me lol. Sitting here crossing my thumbs and waiting for a reply. Thank you in advance to anyone who can help me. I understand that all the experts are volunteers and have lives outside of my problems and to be fair that comes first. I can wait patiently
 

  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,623 posts
  • MVP

Search for:

 

msconfig

hit Enter

 

Under the Startup Tab

Make sure everything is checked.

OK.

Reboot.

 

Uninstall:

 

Avira

Avira Antivirus

Avira Phantom VPN
Avira Safe Shopping

Avira Software Updater (HKLM-x32\...\{A7F41426-5F75-4695-BE5D-B011821079A3}) (Version: 2.0.5.48230 - Avira Operations GmbH & Co. KG)

Avira System Speedup

Dropbox

IObit Uninstaller

Microsoft Silverlight

Trusteer Endpoint Protection

Unchecky v1.2

Windscribe

Zemana AntiMalware

 

Reboot

 

Download the attached fixlist.txt to the same location as FRST



Run FRST and press Fix
A fix log will be generated please post that
Reboot if the fix doesn't reboot it for you

Run FRST again as before.  Make sure Addition.txt is checked and hit Scan.  Post both logs.

 

Try MBAM now.

 


 

 

 

 

 


  • 0

#3
grdsproblem

grdsproblem

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Thank you for your quick reply. I have done the msconfig and reboot , then went to uninstall all the programs. Some uninstalled but others came up with an error box containing " An error occured while trying to uninstall (program). It may have already been uninstalled. Would you like to remove from the Programs and Features list?" Each time I have clicked no as I know that Dropbox at least is still installed as it uploads data every time I open the desktop. 

 

The list that came with this error box is 

Avira

Avira AV

Avira Phantom

Avira System Speedup

Dropbox

Iobit Uninstaller

Trusteer

Windscribe

Unchecky

Zemana

 

All others uninstalled as requested.

 

Should I go ahead with the fixlog or try something else?

Thanks for your patience


  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,623 posts
  • MVP

Go ahead with the fix and a new scan.  On our next fix I'll have FRST remove whatever is left.

 

I'm going to be offline for a few hours today.  They are painting the room where my router lives so everything has to be disconnected.  Expect I can stay on until 10:30 EDT or maybe 11.

 

With so many programs claiming to be already uninstalled I'm wondering if the hard drive has lost a sector or two.  When you get a chance:

 


1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, but don't restart yet.

Right click on (My) Computer and select Manage (Continue) Then the Event Viewer. Next select Windows Logs.  Right click on System and Clear Log, Clear. Repeat for Application. Reboot. The disk check will run and will probably take an hour or more to finish.  (Depends on the size of the drive and the speed of the CPU.  I have seen it take 6 hours with a very large drive and a slow CPU)


Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator.  Then type (with an Enter after each line).

sfc /scannow

(SPACE after sfc.  This will check your critical system files. Does this finish without complaint? 

Copy the next two lines:
findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  %UserProfile%\desktop\junk.txt
notepad %UserProfile%\desktop\junk.txt


Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue.  Right click and Paste or Edit then Paste and the copied line should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.  Close notepad.  Close the Command Window.


1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application. (Each time you run VEW it overwrites the log so copy the first one to a Reply or rename it before running it a second time.)
 


  • 0

#5
grdsproblem

grdsproblem

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Fixlog

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by robin (11-07-2018 14:58:16) Run:3
Running from C:\Users\robin\Desktop
Loaded Profiles: robin (Available Profiles: robin)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Policies\Explorer: [DisallowCpl] 1
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\MountPoints2: {2746c5cc-0f46-11e7-884e-90e6ba4f7032} - E:\Setup.exe
SearchScopes: HKU\S-1-5-21-1842024429-2714170209-1629358381-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={D7B0D661-1F0E-4026-8CF9-771B143800A5}&mid=3e24702b1e7047cd90ae41affcab99c1-7c8f98919273630b2f1b9f57a2c9093ee4e299f0&lang=en&ds=AVG&coid=avgtbavg&cmpid=0516avz&pr=fr&d=2016-05-16 12:06:18&v=4.2.9.726&pid=wtu&sg=&sap=dsp&q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2018-01-25] (IObit)
S2 AdvancedSystemCareService11; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S3 IUFileFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IUFileFilter.sys [21928 2017-06-06] (IObit.com)
S3 IURegProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IURegProcessFilter.sys [22416 2018-01-11] (IObit.com)
S3 iobit_monitor_server; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_win7_x64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
CMD: dir /a C:\Windows\system32\unknown
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll -> No File
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll -> No File
Task: {47F5BB32-639E-4832-9EF7-8B862C2B9958} - System32\Tasks\Avira\System Speedup\TestScheduler => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [2018-03-22] (Avira Operations GmbH & Co. KG)
Task: {4CCAFA97-DA72-48A8-944C-7AE5C527BF6F} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2018-06-20] (Avira Operations GmbH & Co. KG)
Task: {665DBBD3-7E44-4A8C-A185-13A34E2CDA66} - System32\Tasks\{282CA983-1786-4B1A-9AAE-2F92F8EBEF32} => C:\Users\robin\Desktop\avira_en_fass0_5b44ff778f8d6__ws.exe [2018-07-10] (Avira Operations GmbH & Co. KG)
Task: {8A17E877-E81D-4CD7-81A5-E0765B35A0B9} - System32\Tasks\GPU Tweak II => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [2017-04-12] (TODO: <Company name>)
Task: {90176E31-415D-4C53-9357-3C67A83685FE} - System32\Tasks\Avira\Safe Shopping\Check => C:\Program Files (x86)\Avira\Safe Shopping\Updater\Updater.exe [2018-06-13] (Avira Operations Gmbh & Co. KG)
Task: {C655F85F-B8E7-4CF8-81B0-D842126E5785} - System32\Tasks\Avira\Safe Shopping\Update => C:\Program Files (x86)\Avira\Safe Shopping\Updater\Updater.exe [2018-06-13] (Avira Operations Gmbh & Co. KG)
Task: {CE048D73-140A-4C72-8179-AF5517937291} - System32\Tasks\ASC11_SkipUac_robin => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {DB737D28-7C34-47F1-9F48-13BE35C2795D} - System32\Tasks\Avira\Safe Shopping\Launch => C:\Program Files (x86)\Avira\Safe Shopping\Updater\Updater.exe [2018-06-13] (Avira Operations Gmbh & Co. KG)
Task: {F85C1A72-2F11-4A5F-8A69-577268816696} - System32\Tasks\AviraSystemSpeedupUpdate => C:\ProgramData\Avira\SystemSpeedup\Update\avira_speedup_setup_update.exe [2018-03-26] (Avira Operations GmbH & Co. KG )
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
 
 
 
 
 
 
 
 
 
 
 
 
 
*****************
 
"HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisallowCpl" => removed successfully
"HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2746c5cc-0f46-11e7-884e-90e6ba4f7032}" => removed successfully
HKLM\Software\Classes\CLSID\{2746c5cc-0f46-11e7-884e-90e6ba4f7032} => not found
"HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => removed successfully
HKLM\Software\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => removed successfully
"HKLM\Software\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => removed successfully
"HKLM\System\CurrentControlSet\Services\AdvancedSystemCareService11" => removed successfully
AdvancedSystemCareService11 => service removed successfully
"HKLM\System\CurrentControlSet\Services\IUFileFilter" => removed successfully
IUFileFilter => service removed successfully
"HKLM\System\CurrentControlSet\Services\IURegProcessFilter" => removed successfully
IURegProcessFilter => service removed successfully
"HKLM\System\CurrentControlSet\Services\iobit_monitor_server" => removed successfully
iobit_monitor_server => service removed successfully
"HKLM\System\CurrentControlSet\Services\Synth3dVsc" => removed successfully
Synth3dVsc => service removed successfully
"HKLM\System\CurrentControlSet\Services\tsusbhub" => removed successfully
tsusbhub => service removed successfully
"HKLM\System\CurrentControlSet\Services\VGPU" => removed successfully
VGPU => service removed successfully
 
========= dir /a C:\Windows\system32\unknown =========
 
 Volume in drive C has no label.
 Volume Serial Number is C61A-7217
 
 Directory of C:\Windows\system32\unknown
 
12/06/2018  18:51    <DIR>          .
12/06/2018  18:51    <DIR>          ..
02/06/2018  04:06           456,800 OpenCL32.dll
02/06/2018  04:06           551,872 OpenCL64.dll
02/06/2018  04:06         1,231,856 VulkanRT-Installer.exe
               3 File(s)      2,240,528 bytes
               2 Dir(s)  97,887,195,136 bytes free
 
========= End of CMD: =========
 
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw" => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Advanced SystemCare" => removed successfully
"HKLM\Software\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D}" => removed successfully
"HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\Advanced SystemCare" => removed successfully
HKLM\Software\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{47F5BB32-639E-4832-9EF7-8B862C2B9958}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47F5BB32-639E-4832-9EF7-8B862C2B9958}" => removed successfully
C:\Windows\System32\Tasks\Avira\System Speedup\TestScheduler => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira\System Speedup\TestScheduler" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4CCAFA97-DA72-48A8-944C-7AE5C527BF6F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CCAFA97-DA72-48A8-944C-7AE5C527BF6F}" => removed successfully
C:\Windows\System32\Tasks\Avira_Antivirus_Systray => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira_Antivirus_Systray" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{665DBBD3-7E44-4A8C-A185-13A34E2CDA66}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{665DBBD3-7E44-4A8C-A185-13A34E2CDA66}" => removed successfully
C:\Windows\System32\Tasks\{282CA983-1786-4B1A-9AAE-2F92F8EBEF32} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{282CA983-1786-4B1A-9AAE-2F92F8EBEF32}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8A17E877-E81D-4CD7-81A5-E0765B35A0B9}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A17E877-E81D-4CD7-81A5-E0765B35A0B9}" => removed successfully
C:\Windows\System32\Tasks\GPU Tweak II => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GPU Tweak II" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{90176E31-415D-4C53-9357-3C67A83685FE}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{90176E31-415D-4C53-9357-3C67A83685FE}" => removed successfully
C:\Windows\System32\Tasks\Avira\Safe Shopping\Check => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira\Safe Shopping\Check" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C655F85F-B8E7-4CF8-81B0-D842126E5785}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C655F85F-B8E7-4CF8-81B0-D842126E5785}" => removed successfully
C:\Windows\System32\Tasks\Avira\Safe Shopping\Update => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira\Safe Shopping\Update" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE048D73-140A-4C72-8179-AF5517937291}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE048D73-140A-4C72-8179-AF5517937291}" => removed successfully
C:\Windows\System32\Tasks\ASC11_SkipUac_robin => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASC11_SkipUac_robin" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DB737D28-7C34-47F1-9F48-13BE35C2795D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB737D28-7C34-47F1-9F48-13BE35C2795D}" => removed successfully
C:\Windows\System32\Tasks\Avira\Safe Shopping\Launch => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira\Safe Shopping\Launch" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F85C1A72-2F11-4A5F-8A69-577268816696}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F85C1A72-2F11-4A5F-8A69-577268816696}" => removed successfully
C:\Windows\System32\Tasks\AviraSystemSpeedupUpdate => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AviraSystemSpeedupUpdate" => removed successfully
C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => moved successfully
C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => moved successfully
 
========= FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" =========
 
 
========= End of CMD: =========
 
 
==== End of Fixlog 14:58:38 ====
 
FRST log
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by robin (administrator) on ROBIN-PC (11-07-2018 15:01:06)
Running from C:\Users\robin\Desktop
Loaded Profiles: robin (Available Profiles: robin)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
HKLM-x32\...\Run: [Avira System Speedup User Starter] => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [64096 2018-03-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2018-05-30] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3752768 2018-06-18] (Dropbox, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [f.lux] => C:\Users\robin\AppData\Local\FluxSoftware\Flux\flux.exe [1682936 2018-01-17] (f.lux Software LLC)
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46139776 2018-03-15] ()
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [Spotify Web Helper] => C:\Users\robin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [782736 2018-05-12] (Spotify Ltd)
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3201312 2018-06-09] (Valve Corporation)
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [456576 2015-06-10] (Sony)
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10024624 2017-11-08] (Piriform Ltd)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
Startup: C:\Users\robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zSpeedup.lnk [2017-10-11]
ShortcutTarget: zSpeedup.lnk -> C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe (Avira Operations GmbH & Co. KG)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{74134C22-B139-4950-A9F4-BEEFD0288E23}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{9C1F6614-1893-45D7-9C93-B71051A292FD}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{E34654FF-2966-4B38-A6DD-8C8A5B581BEF}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.sky.com/
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-07-14] (LastPass)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-04-18] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Arc\plugins\ArcPluginIE.dll [2017-07-28] (Perfect World Entertainment Inc)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-07-14] (LastPass)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-18] (Oracle Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-07-14] (LastPass)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-07-14] (LastPass)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
Toolbar: HKU\S-1-5-21-1842024429-2714170209-1629358381-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
IE Session Restore: HKU\S-1-5-21-1842024429-2714170209-1629358381-1001 -> is enabled.
DPF: HKLM-x32 {0E5F0222-96B9-11D3-8997-00104BD12D94} hxxp://www.pcpitstop.com/nirvana/controls/pcmatic.cab
 
FireFox:
========
FF DefaultProfile: 
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-07-14] (LastPass)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-18] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-07-14] (LastPass)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-06-01] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-06-01] (NVIDIA Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Arc\plugins\npArcPluginFF.dll [2017-07-28] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxps://www.facebook.com/login.php"
CHR NewTab: Default ->  Active:"chrome-extension://ojhmphdkpgbibohbnpbfiefkgieacjmh/app/index.html"
CHR DefaultSearchURL: Default -> hxxps://search.avira.com/#web/result?source=omnibar&q={searchTerms}
CHR DefaultSearchKeyword: Default -> lp
CHR DefaultSuggestURL: Default -> hxxps://search.avira.com/suggestions?q={searchTerms}&li=ff&hl=en
CHR Profile: C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default [2018-07-11]
CHR Extension: (Slides) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Docs) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (IBM Security Rapport) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof [2018-03-14]
CHR Extension: (YouTube) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Adblock Plus) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-05-16]
CHR Extension: (Google Search) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Tampermonkey) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-05-15]
CHR Extension: (Iron Man 3) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebkgohjhkmajdealpbnfimnchjepjmii [2015-07-17]
CHR Extension: (Mahjongg) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegpopcingfghbompjfejakfeaolmbop [2015-07-17]
CHR Extension: (minerBlock) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\emikbbbebcdfohonlaifafnoanocnebl [2018-07-10]
CHR Extension: (Sheets) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Google Docs Offline) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2018-07-10]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-04-02]
CHR Extension: (Lightshot (screenshot tool)) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbniclmhobmnbdlbpiphghaielnnpgdp [2018-01-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Picky Wallpapers) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\odklcfojpedohplkimfdpcamkjnhanaj [2015-08-18]
CHR Extension: (Currently) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhmphdkpgbibohbnpbfiefkgieacjmh [2016-07-17]
CHR Extension: (Weather Underground) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjejbgheonogbpfkkjigbmahaljipoej [2015-07-17]
CHR Extension: (Gmail) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-18]
CHR Extension: (Chrome Media Router) - C:\Users\robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-30]
CHR Profile: C:\Users\robin\AppData\Local\Google\Chrome\User Data\System Profile [2018-06-30]
CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [879128 2018-06-20] (Avira Operations GmbH & Co. KG)
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [224472 2018-06-20] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [224472 2018-06-20] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1164808 2018-06-20] (Avira Operations GmbH & Co. KG)
S3 ArcService; C:\Program Files (x86)\Arc\ArcService.exe [87064 2017-07-28] (Perfect World Entertainment Inc)
S3 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1149712 2016-09-13] (AVG Technologies CZ, s.r.o.)
S2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [452352 2018-05-30] (Avira Operations GmbH & Co. KG)
S2 AviraOptimizerHost; C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe [2940584 2018-03-16] (Avira Operations GmbH & Co. KG)
R2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [346528 2018-05-17] (Avira Operations GmbH & Co. KG)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-05-30] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-05-30] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51024 2018-06-18] (Dropbox, Inc.)
S3 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659456 2017-12-11] (Foxit Software Inc.)
S3 ImDskSvc; C:\Windows\system32\imdsksvc.exe [25720 2017-02-17] (Olof Lagerkvist)
S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [206096 2018-01-25] (IObit)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [3878728 2017-02-25] (Paramount Software UK Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-14] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-14] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2201920 2018-06-12] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3072328 2018-06-12] (Electronic Arts)
S2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [5253624 2018-05-23] (IBM Corp.)
S3 Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [155520 2015-06-10] (Avanquest Software) [File not signed]
S2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [297240 2018-04-09] (Reason Software Company Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [466096 2018-04-24] (Windscribe Limited)
S3 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 
S2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [64504 2017-09-23] (Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [199912 2018-05-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [153552 2018-05-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-09-23] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [78600 2017-09-23] (Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [34128 2017-09-23] (Avira Operations GmbH & Co. KG)
R2 ImDisk; C:\Windows\System32\DRIVERS\imdisk.sys [95376 2017-02-28] (Olof Lagerkvist)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-07-11] (Malwarebytes)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 netr28x; C:\Windows\System32\DRIVERS\netr28x.sys [2473616 2014-12-10] (MediaTek Inc.)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [31168 2018-03-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [59240 2017-12-15] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [68112 2018-06-01] (NVIDIA Corporation)
S3 phantomtap; C:\Windows\System32\DRIVERS\phantomtap.sys [35664 2017-10-25] (The OpenVPN Project)
R1 RapportAegle64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportAegle64.sys [496744 2018-05-23] (IBM Corp.)
R1 RapportCerberus_1919106; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1919106.sys [1645288 2018-06-12] (IBM Corp.)
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [712488 2018-05-23] (IBM Corp.)
R0 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [340904 2018-05-23] (IBM Corp.)
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [605160 2018-05-23] (IBM Corp.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [751976 2018-05-23] (IBM Corp.)
R3 tapwindscribe0901; C:\Windows\System32\DRIVERS\tapwindscribe0901.sys [45560 2018-02-01] (The OpenVPN Project)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2017-10-08] (Zemana Ltd.)
R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-10-08] (Zemana Ltd.)
S3 GLCKIO; \??\C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\690b33e1-0462-4e84-9bea-c7552b45432a.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-07-11 15:01 - 2018-07-11 15:01 - 000022085 _____ C:\Users\robin\Desktop\FRST.txt
2018-07-11 14:58 - 2018-07-11 14:58 - 000012187 _____ C:\Users\robin\Desktop\Fixlog.txt
2018-07-11 13:35 - 2018-07-11 13:35 - 000000000 ____D C:\Windows\system32\appmgmt
2018-07-10 20:03 - 2018-06-13 17:23 - 000140992 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-07-10 20:03 - 2018-06-13 17:18 - 000680960 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-07-10 20:03 - 2018-06-08 14:05 - 002860032 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-07-10 20:03 - 2018-06-08 14:05 - 001602048 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-07-10 20:03 - 2018-06-08 14:05 - 000783872 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-07-10 20:03 - 2018-06-08 14:05 - 000612352 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-07-10 20:03 - 2018-06-08 14:05 - 000470016 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-07-10 20:03 - 2018-06-08 14:05 - 000443392 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-07-10 20:03 - 2018-06-08 14:05 - 000301056 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-07-10 20:03 - 2018-06-08 14:05 - 000246272 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-07-10 19:57 - 2018-07-10 19:57 - 000947200 _____ C:\Users\robin\Desktop\avcertclean_1.2.0.exe
2018-07-10 19:49 - 2018-07-10 19:49 - 005414912 _____ (Avira Operations GmbH & Co. KG) C:\Users\robin\Desktop\avira_en_fass0_5b44ff778f8d6__ws.exe
2018-06-30 17:24 - 2018-06-30 17:25 - 010393048 _____ (COMODO) C:\Users\robin\Desktop\ccav_installer_chid33220011.exe
2018-06-30 07:59 - 2018-07-11 15:01 - 000000000 ____D C:\FRST
2018-06-30 07:58 - 2018-06-30 07:58 - 002412544 _____ (Farbar) C:\Users\robin\Desktop\FRST64.exe
2018-06-30 07:50 - 2018-06-30 07:50 - 002526736 _____ (Trend Micro Inc.) C:\Users\robin\Downloads\HousecallLauncher64.exe
2018-06-30 07:50 - 2018-06-30 07:50 - 000000036 _____ C:\Users\robin\AppData\Local\housecall.guid.cache
2018-06-30 07:26 - 2018-06-30 07:26 - 000002942 _____ C:\Windows\System32\Tasks\{1B7BAF58-7C42-47F2-96B9-BA0CF07AF434}
2018-06-29 13:22 - 2018-07-11 14:50 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-06-29 13:17 - 2018-06-29 13:17 - 005376592 _____ (Avira Operations GmbH & Co. KG) C:\Users\robin\Downloads\avira_en_av_59db815d90804__ws.exe
2018-06-21 14:47 - 2018-06-21 14:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-06-19 22:42 - 2018-06-19 22:42 - 002673793 _____ C:\Users\robin\Downloads\SSE_Airtricity_Domestic_Tariff_Table_effective_from_01_Apr_2018.pdf
2018-06-19 01:47 - 2018-06-19 01:47 - 000000222 _____ C:\Users\robin\Desktop\Neverwinter.url
2018-06-18 11:23 - 2018-06-18 11:23 - 000051024 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2018-06-18 11:23 - 2018-06-18 11:23 - 000050232 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2018-06-18 11:23 - 2018-06-18 11:23 - 000045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2018-06-18 11:23 - 2018-06-18 11:23 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2018-06-13 15:15 - 2018-06-13 15:15 - 000000000 ____D C:\ProgramData\PopCap Games
2018-06-12 18:52 - 2018-06-12 18:52 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-06-12 18:52 - 2018-06-01 09:47 - 000132680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2018-06-12 18:51 - 2018-06-12 18:51 - 000000000 ____D C:\Windows\system32\unknown
2018-06-12 18:51 - 2018-06-12 18:51 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2018-06-12 18:50 - 2018-06-02 04:06 - 040090152 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 032360304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 016999360 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2018-06-12 18:50 - 2018-06-02 04:06 - 001419200 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 001092008 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 000627240 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2018-06-12 18:50 - 2018-06-02 04:06 - 000517544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 040346536 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 035250624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 031276296 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 013727800 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 003964328 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 003497024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 002014144 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6439811.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 001562208 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 001468272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6439811.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 001216448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 001157216 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000420008 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000182600 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000165136 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000159712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2018-06-12 18:50 - 2018-06-02 04:05 - 000142824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2018-06-12 18:50 - 2018-06-02 04:04 - 019081176 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2018-06-12 18:50 - 2018-06-02 04:04 - 017782576 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2018-06-12 18:50 - 2018-06-01 11:27 - 000227928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2018-06-12 18:50 - 2018-06-01 11:27 - 000068112 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2018-06-12 18:50 - 2018-06-01 11:27 - 000047648 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2018-06-12 18:50 - 2018-06-01 11:27 - 000000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2018-06-12 18:50 - 2018-06-01 11:27 - 000000669 _____ C:\Windows\system32\nv-vk64.json
2018-06-12 18:40 - 2018-06-12 18:40 - 000003922 _____ C:\Windows\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2018-06-12 18:40 - 000000000 ____D C:\Users\robin\ansel
2018-06-12 18:40 - 2017-12-15 03:03 - 000059240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2018-06-12 18:34 - 2018-06-25 13:33 - 000000022 _____ C:\Windows\GPU-Z.INI
2018-06-12 18:30 - 2018-06-12 18:30 - 000001067 _____ C:\Users\Public\Desktop\ASUS GPU TweakII.lnk
2018-06-12 18:30 - 2018-06-12 18:30 - 000000000 ____D C:\Windows\Downloaded Installations
2018-06-12 18:30 - 2018-06-12 18:30 - 000000000 ____D C:\Users\robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS
2018-06-12 18:30 - 2018-06-12 18:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2018-06-12 18:30 - 2018-06-12 18:30 - 000000000 ____D C:\Program Files (x86)\ASUS
2018-06-12 18:29 - 2018-06-01 11:27 - 001688848 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2018-06-12 18:29 - 2018-06-01 09:39 - 000634152 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2018-06-12 18:29 - 2018-06-01 09:39 - 000083528 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2018-06-12 18:28 - 2017-05-11 21:43 - 001988032 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438223.dll
2018-06-12 18:28 - 2017-05-11 21:43 - 001589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438223.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 025990104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 023298224 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 020323576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 011272944 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 000904720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2018-06-12 18:27 - 2018-06-02 04:05 - 000505928 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2018-06-12 18:27 - 2018-06-02 04:04 - 015691144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2018-06-12 18:27 - 2018-06-02 04:04 - 015192816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2018-06-12 18:26 - 2018-06-02 04:04 - 004613600 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2018-06-12 18:26 - 2018-06-02 04:04 - 004081440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2018-06-12 13:02 - 2018-06-12 13:05 - 000152184 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-06-12 13:02 - 2018-06-12 13:02 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-06-12 13:02 - 2018-06-12 13:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-06-11 19:15 - 2018-06-11 19:15 - 000001116 _____ C:\Users\Public\Desktop\Avira.lnk
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-07-11 15:01 - 2017-10-08 00:25 - 000113941 _____ C:\Windows\ZAM.krnl.trace
2018-07-11 15:01 - 2017-10-08 00:25 - 000087250 _____ C:\Windows\ZAM_Guard.krnl.trace
2018-07-11 14:58 - 2009-07-14 05:45 - 000017760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-07-11 14:58 - 2009-07-14 05:45 - 000017760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-07-11 14:57 - 2017-05-14 17:31 - 000000000 ____D C:\Users\robin\Desktop\Free tools
2018-07-11 14:54 - 2009-07-14 06:13 - 000781790 _____ C:\Windows\system32\PerfStringBackup.INI
2018-07-11 14:54 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2018-07-11 14:52 - 2015-07-12 09:46 - 000000000 ____D C:\ProgramData\NVIDIA
2018-07-11 14:49 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-07-11 13:36 - 2017-10-05 11:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2018-07-11 13:35 - 2017-10-05 11:34 - 000000000 ____D C:\Program Files (x86)\Avira
2018-07-11 13:28 - 2017-10-11 15:14 - 000000000 ____D C:\Windows\pss
2018-07-11 04:00 - 2015-07-12 09:39 - 000000000 ____D C:\Users\robin
2018-07-11 03:19 - 2015-07-12 09:48 - 000000000 ____D C:\Windows\system32\appraiser
2018-07-11 03:00 - 2015-07-12 09:42 - 134675576 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-07-11 03:00 - 2015-07-12 09:42 - 000000000 ____D C:\Windows\system32\MRT
2018-06-29 13:20 - 2015-07-12 09:46 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-06-29 13:19 - 2018-05-15 16:38 - 000000000 ____D C:\Program Files (x86)\Steam
2018-06-29 13:18 - 2017-05-08 16:11 - 000000000 ____D C:\Users\robin\AppData\Local\CrashDumps
2018-06-29 13:14 - 2016-12-07 20:54 - 000000000 ____D C:\Users\robin\AppData\Roaming\Origin
2018-06-21 14:47 - 2017-05-30 14:16 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-06-19 01:47 - 2018-05-15 16:51 - 000000000 ____D C:\Users\robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-06-15 16:14 - 2017-10-12 03:05 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-06-13 14:27 - 2016-12-07 20:52 - 000000000 ____D C:\ProgramData\Origin
2018-06-12 19:22 - 2016-12-07 21:05 - 000000000 ____D C:\Program Files (x86)\Origin Games
2018-06-12 19:22 - 2009-07-14 06:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2018-06-12 19:04 - 2016-12-07 20:53 - 000000000 ____D C:\Program Files (x86)\Origin
2018-06-12 18:52 - 2015-07-12 09:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-06-12 18:52 - 2015-07-12 09:46 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-06-12 18:52 - 2015-07-12 09:46 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-06-12 18:51 - 2016-11-21 20:11 - 000000000 ____D C:\Users\robin\AppData\Roaming\NVIDIA
2018-06-12 18:40 - 2017-08-27 13:29 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003798 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-06-12 18:40 - 2017-03-22 17:17 - 000001416 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2018-06-12 18:39 - 2017-03-22 17:17 - 000000000 ____D C:\Users\robin\AppData\Local\NVIDIA Corporation
2018-06-12 18:32 - 2018-03-26 17:58 - 000000000 ____D C:\Users\Public\Speedup Sessions
2018-06-12 18:30 - 2015-07-13 11:03 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-06-12 18:22 - 2016-11-09 11:11 - 000000000 ____D C:\ProgramData\ProductData
2018-06-12 18:22 - 2015-11-19 15:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
2018-06-11 19:15 - 2015-07-12 22:34 - 000000000 ____D C:\ProgramData\Package Cache
 
==================== Files in the root of some directories =======
 
2015-07-14 19:22 - 2015-07-14 19:22 - 016581656 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2018-06-30 07:50 - 2018-06-30 07:50 - 000000036 _____ () C:\Users\robin\AppData\Local\housecall.guid.cache
2017-06-01 14:49 - 2017-06-01 14:49 - 000002169 _____ () C:\Users\robin\AppData\Local\recently-used.xbel
2017-03-19 18:13 - 2017-10-04 12:52 - 000007613 _____ () C:\Users\robin\AppData\Local\resmon.resmoncfg
2015-08-03 00:19 - 2015-08-03 00:19 - 000000000 _____ () C:\Users\robin\AppData\Local\{1CDDFEFE-2396-4356-9F17-7D3511F8B3BB}
2015-08-05 23:53 - 2015-08-05 23:53 - 000000000 _____ () C:\Users\robin\AppData\Local\{5C712DF7-A97E-4A15-ABB6-FC693BC721FF}
2015-07-31 15:18 - 2015-07-31 15:18 - 000000000 _____ () C:\Users\robin\AppData\Local\{660DCC4B-0A28-4AE3-902D-BF3558E7BDC0}
2015-08-09 04:48 - 2015-08-09 04:48 - 000000000 _____ () C:\Users\robin\AppData\Local\{A3E00A1E-B47F-4DD3-88D1-6BEF3A159611}
2017-10-11 15:04 - 2017-10-11 15:04 - 000000000 _____ () C:\Users\robin\AppData\Local\{D4A2EB80-4AF0-472D-9C97-C07DFD97709D}
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-07-10 21:30
 
==================== End of FRST.txt ============================
 
Addition log
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by robin (11-07-2018 15:01:40)
Running from C:\Users\robin\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2015-07-12 08:39:05)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1842024429-2714170209-1629358381-500 - Administrator - Disabled)
Guest (S-1-5-21-1842024429-2714170209-1629358381-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1842024429-2714170209-1629358381-1002 - Limited - Enabled)
robin (S-1-5-21-1842024429-2714170209-1629358381-1001 - Administrator - Enabled) => C:\Users\robin
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avira Antivirus (Disabled - Out of date) {B3F630BD-538D-1B4A-14FA-14B63235278F}
AS: Avira Antivirus (Disabled - Out of date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.215 - Adobe Systems Incorporated)
Adobe Flash Player 30 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Amazon Kindle) (Version: 1.21.0.48017 - Amazon)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
ASUS GPU TweakII (HKLM-x32\...\{0075AAC2-EA9F-490E-83F7-5D5F81EB2A43}) (Version: 1.4.5.2 - ASUSTek COMPUTER INC.) Hidden
ASUS GPU TweakII (HKLM-x32\...\InstallShield_{0075AAC2-EA9F-490E-83F7-5D5F81EB2A43}) (Version: 1.4.5.2 - ASUSTek COMPUTER INC.)
AVG Zen (HKLM\...\{6DDF7DAF-58CC-44EC-B172-22CC5886E472}) (Version: 1.111.9 - AVG Technologies) Hidden
Avira (HKLM-x32\...\{606c7b25-e58d-4e72-82dd-4a0e4e163086}) (Version: 1.2.114.16977 - Avira Operations GmbH & Co. KG)
Avira (HKLM-x32\...\{C7FA948A-FC14-4316-92DC-23AF70C55A10}) (Version: 1.2.114.16977 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.36.200 - Avira Operations GmbH & Co. KG)
Avira Phantom VPN (HKLM-x32\...\Avira Phantom VPN) (Version: 2.14.1.26975 - Avira Operations GmbH & Co. KG)
Avira Safe Shopping (HKLM-x32\...\{9158dccb-03a7-493c-b07e-f47b9784425c}) (Version: 1.0.65.2672 - Avira Operations Gmbh & Co. KG) Hidden
Avira System Speedup (HKLM-x32\...\Avira System Speedup_is1) (Version: 4.8.0.7455 - Avira Operations GmbH & Co. KG)
Backup and Sync from Google (HKLM\...\{4B7277C7-9CEE-45FC-B36B-19AD28281B9C}) (Version: 3.40.8921.5350 - Google, Inc.)
BBC iPlayer Downloads (HKLM-x32\...\{148784F3-3B6E-4DFA-B7A1-3400B277DAF3}) (Version: 1.14.2 - BBC)
CCleaner (HKLM\...\CCleaner) (Version: 5.37 - Piriform)
DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 398.11 - NVIDIA Corporation) Hidden
Drakensang Online (HKLM-x32\...\Drakensang Online) (Version:  - )
Dropbox (HKLM-x32\...\Dropbox) (Version: 52.4.58 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.75.1 - Dropbox, Inc.) Hidden
f.lux (HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Flux) (Version:  - f.lux Software LLC)
FastStone Image Viewer 6.2 (HKLM-x32\...\FastStone Image Viewer) (Version: 6.2 - FastStone Soft)
FMW 1 (HKLM\...\{1C3364DF-40B5-4DA4-9810-652A9A792FB1}) (Version: 1.132.1 - AVG Technologies) Hidden
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 9.0.1.1049 - Foxit Software Inc.)
GIMP 2.8.22 (HKLM\...\GIMP-2_is1) (Version: 2.8.22 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 65.0.3325.181 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.115 - Google Inc.) Hidden
GXTool (HKLM-x32\...\93D383D2-DFB3-46F1-8A08-AA6113AB39DE) (Version: 1.0 - Trust International BV)
Icecream Ebook Reader version 5.07 (HKLM-x32\...\{B8C30F0F-1F23-49E1-A3ED-44DE17660EE2}_is1) (Version: 5.07 - Icecream Apps)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 7.4.0.8 - IObit)
Java 8 Update 171 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
LastPass (uninstall only) (HKLM-x32\...\LastPass) (Version:  - LastPass)
Macrium Reflect Free Edition (HKLM\...\{595B8A7B-253D-4A4E-95C2-A823EDDD5496}) (Version: 6.3.1745 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 6.3 - Paramount Software (UK) Ltd.)
Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Mass Effect™ 2 (HKLM-x32\...\{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}) (Version: 1.2.1604.0 - Electronic Arts)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40649 (HKLM-x32\...\{35b83883-40fa-423c-ae73-2aff7e1ea820}) (Version: 12.0.40649.5 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NVIDIA 3D Vision Controller Driver 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 398.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 398.11 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.13.1.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.13.1.30 - NVIDIA Corporation)
NVIDIA Graphics Driver 398.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 398.11 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.37.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.37.4 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 10.5.20.63112 - Electronic Arts, Inc.)
Peggle (HKLM-x32\...\{715AD72D-887A-459E-988B-D4F3E87FA24B}) (Version: 1.04.0.0 - PopCap Games)
PVSonyDll (HKLM\...\{3D3E663D-4E7E-4577-A560-7ECDDD45548A}) (Version: 1.00.0001 - NVIDIA Corporation) Hidden
Rapport (HKLM-x32\...\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}) (Version: 3.5.1919.126 - Trusteer) Hidden
Serif PagePlus X7 (HKLM\...\{CB487BBA-A1AC-4B2B-80AC-DED349C897C5}) (Version: 17.0.3.28 - Serif (Europe) Ltd)
Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.15.9.201506301709 - Sony Mobile Communications Inc.)
Sony PC Companion 2.10.275 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.275 - Sony)
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Spotify (HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\...\Spotify) (Version: 1.0.80.474.gef6b503e - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SysGauge 2.3.18 (HKLM-x32\...\SysGauge) (Version: 2.3.18 - Flexense Computing Systems Ltd.)
Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1919.126 - Trusteer)
Unchecky v1.2 (HKLM-x32\...\Unchecky) (Version: 1.2 - Reason Software Company Inc.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windscribe (HKLM-x32\...\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1) (Version: 1.81 Build 44 - Windscribe Limited)
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.150 - Zemana Ltd.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-03-15] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-03-15] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-03-15] (Google)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-10-08] ()
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} =>  -> No File
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ContextMenuHandlers1: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2017-12-11] (Foxit Software Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-03-15] (Google)
ContextMenuHandlers1: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2018-01-25] (IObit)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers1: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2018-06-20] (Avira Operations GmbH & Co. KG)
ContextMenuHandlers1: [SystemSpeedupFilesMenu] -> {ef263503-8f0e-3e6a-ae2e-fe0b4b441d52} => C:\Windows\system32\mscoree.dll [2010-11-05] (Microsoft Corporation)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-03-15] (Google)
ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2018-01-25] (IObit)
ContextMenuHandlers4: [SystemSpeedupFoldersMenu] -> {3d52b24d-33bb-3895-99ea-a0156f24a3f9} => C:\Windows\system32\mscoree.dll [2010-11-05] (Microsoft Corporation)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-18] (Dropbox, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2018-06-01] (NVIDIA Corporation)
ContextMenuHandlers5: [SystemSpeedupDesktopMenu] -> {cefaf456-bc17-3f4b-b7d9-75070925911b} => C:\Windows\system32\mscoree.dll [2010-11-05] (Microsoft Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-10-08] ()
ContextMenuHandlers6: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2017-12-11] (Foxit Software Inc.)
ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2018-01-25] (IObit)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers6: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2018-06-20] (Avira Operations GmbH & Co. KG)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {12154847-6015-4A4A-A8E0-0BC14A6D9C8A} - System32\Tasks\{E745508C-7C48-4833-8CD1-FBF2DFACAA52} => C:\Program Files (x86)\Arc\ArcLauncher.exe [2017-07-28] (Perfect World Entertainment)
Task: {24021360-F1E2-488E-892E-77085812125D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {365EB785-625F-4428-BFC4-DE277C4A5AAA} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-11-08] (Piriform Ltd)
Task: {37873B39-08B1-4178-AD5D-FFCFEDD2E35A} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-05-30] (Dropbox, Inc.)
Task: {473D73B3-A037-4BC5-A4A9-5E947B386FCD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {721CA277-CA6A-4E2A-BD0D-E4DFB6AC8434} - System32\Tasks\{1B7BAF58-7C42-47F2-96B9-BA0CF07AF434} => C:\Program Files (x86)\Steam\Steam.exe [2018-06-09] (Valve Corporation)
Task: {75C12851-5E7F-4463-8A42-4ABA2FEB053F} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-03-14] (NVIDIA Corporation)
Task: {85487D5A-1950-4F15-86A3-2710A99BC584} - System32\Tasks\Uninstaller_SkipUac_robin => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2018-03-28] (IObit)
Task: {8A0F8D44-B1F7-419C-9684-E6EE85B38C24} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\2 => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-03-28] (Oracle Corporation)
Task: {8A4248A2-611B-4FE1-B1BC-FEB50EC5BF99} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-03-14] (NVIDIA Corporation)
Task: {8B4D7B0C-9E28-4BC2-9CA1-B3E1F5487550} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\1 => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2018-06-18] (Dropbox, Inc.)
Task: {90988451-0E55-4DA2-9E08-06562BB1E225} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\4 => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
Task: {95197C81-C36E-401D-A93F-6A13958404D2} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-03-14] (NVIDIA Corporation)
Task: {98970E1F-AE1B-40B3-BFA0-CEB3796141CF} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-03-14] (NVIDIA Corporation)
Task: {B08301AD-ED1C-4D31-9C6E-5CF2F181B7C2} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-03-14] (NVIDIA Corporation)
Task: {B0B1D339-DA94-4C6D-87EF-981B687C6F3B} - System32\Tasks\Avira\System Speedup\Delayed Startup\All users\3 => C:\Program Files (x86)\Common Files\lpuninstall.exe [2015-07-14] (LastPass)
Task: {C297E826-97BD-4456-8F0D-9D9DB244F7AC} - System32\Tasks\{2E98E6EB-122B-4F06-827D-45859DFE9060} => C:\Program Files (x86)\Arc\ArcLauncher.exe [2017-07-28] (Perfect World Entertainment)
Task: {CB7CF415-1DD5-4C6D-B86F-2992229800AD} - System32\Tasks\{1FC9F61C-5CE7-4A47-9E3B-D00C948504B7} => C:\Program Files (x86)\Arc\ArcLauncher.exe [2017-07-28] (Perfect World Entertainment)
Task: {CDAD47D6-C109-4C20-868B-0D2893FA2FF4} - System32\Tasks\Avira\System Speedup\Delayed Startup\robin\1 => C:\Users\robin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018-05-12] (Spotify Ltd) <==== ATTENTION
Task: {D0869D90-F0D3-4B50-8257-9965FBC3252A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-11-08] (Piriform Ltd)
Task: {D902A691-4E87-4AEB-A7F0-2C762C277CEF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-06-08] (Adobe Systems Incorporated)
Task: {E1F4B9E4-E2CC-4C14-9DC9-91D105FCA9CF} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-03-28] (Oracle Corporation)
Task: {EE60FCF1-E17C-4DEB-BB20-F51093FD4D5B} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-03-14] (NVIDIA Corporation)
Task: {F3831C5D-3D07-470B-8DC2-A5AAA85A509C} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-05-30] (Dropbox, Inc.)
Task: {F43F7407-7AD3-4F5A-A484-EAFE7ABF4B26} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-03-14] (NVIDIA Corporation)
Task: {F9BEE171-2CAF-402F-B52B-08A70124DC96} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-03-14] (NVIDIA Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2018-03-15 11:31 - 2018-03-15 11:31 - 046139776 _____ () C:\Program Files\Google\Drive\googledrivesync.exe
2018-07-11 14:49 - 2018-07-11 14:49 - 000113152 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\_ctypes.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000080896 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\bz2.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 001585152 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\_hashlib.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000128512 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32api.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000137728 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\pywintypes27.dll
2018-07-11 14:49 - 2018-07-11 14:49 - 000548864 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\pythoncom27.dll
2018-07-11 14:49 - 2018-07-11 14:49 - 000689664 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\unicodedata.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000438784 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32com.shell.shell.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 001489408 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\wx._core_.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 001007104 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\wx._gdi_.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 001039872 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\wx._windows_.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 001325056 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\wx._controls_.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000916992 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\wx._misc_.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 001084416 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\pysqlite2._sqlite.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000149504 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32file.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000136192 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32security.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000007680 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\hashobjs_ext.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000020992 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\thumbnails_ext.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000118784 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\usb_ext.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000047616 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\_socket.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 002224128 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\_ssl.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000014848 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\common.time34.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000023040 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32event.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000033280 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\windows.conditional.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000019968 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\windows.winwrap.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000107520 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\windows.volumes.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000223232 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32gui.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000173568 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\_elementtree.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000169472 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\pyexpat.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000048128 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32inet.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000103424 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\wx._html2.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000046080 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\_psutil_windows.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000633240 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\windows._cacheinvalidation.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 005408256 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\cello.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000010752 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\select.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000011776 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32crypt.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000301568 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\PIL._imaging.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000032256 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\_multiprocessing.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000026112 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\_yappi.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000044032 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32process.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000027648 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32pipe.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000029696 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32pdh.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000038400 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\windows.connectivity.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000071168 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\windows.device_monitor.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000020480 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32profile.pyd
2018-07-11 14:49 - 2018-07-11 14:49 - 000026624 _____ () C:\Users\robin\AppData\Local\Temp\_MEI18322\win32ts.pyd
2017-03-22 17:17 - 2018-03-14 14:05 - 001267648 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2018-03-29 14:35 - 2018-03-20 07:00 - 004435288 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libglesv2.dll
2018-03-29 14:35 - 2018-03-20 07:00 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\robin\Documents\Doughnaughty2d.ppp:SummaryInformation [215]
AlternateDataStreams: C:\Users\robin\Documents\Doughnaughty2d.ppp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\robin\Documents\Doughnaughty3d.ppp:SummaryInformation [215]
AlternateDataStreams: C:\Users\robin\Documents\Doughnaughty3d.ppp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 03:34 - 2018-06-30 08:25 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1842024429-2714170209-1629358381-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\robin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: nvsvc => 2
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
11-07-2018 03:00:17 Windows Update
11-07-2018 13:34:26 Removed Avira Safe Shopping
11-07-2018 13:35:25 Removed Avira Software Updater
11-07-2018 13:50:42 Removed Microsoft Silverlight
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
 
System errors:
=============
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7 CPU 920 @ 2.67GHz
Percentage of memory in use: 23%
Total physical RAM: 12279.12 MB
Available physical RAM: 9400.84 MB
Total Virtual: 24556.4 MB
Available Virtual: 21022.54 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:223.47 GB) (Free:91.05 GB) NTFS
 
\\?\Volume{b8e5dc61-2870-11e5-ad3b-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 223.6 GB) (Disk ID: F60F1EBF)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223.5 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
Sending this bit now and am just about to run the error checking tool. Don't worry if you cannot get to this immediately as I have resigned myself to not being able to play for the moment lol. Take a moment and relax when the painting is being done (as long as it is not you doing the painting you can relax :) )

  • 0

#6
grdsproblem

grdsproblem

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

scannow = Windows Resource Protection found corrupt files and successfully repaired them. Details included in CBS.Log windir\Logs\CBS\CBS.log

 the file repair changes will take effect after the next reboot

 

Reply from notepad for next bit

 

2018-07-11 15:46:41, Info                  CSI    00000009 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:41, Info                  CSI    0000000a [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:42, Info                  CSI    0000000c [SR] Verify complete
2018-07-11 15:46:42, Info                  CSI    0000000d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:42, Info                  CSI    0000000e [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:42, Info                  CSI    00000010 [SR] Verify complete
2018-07-11 15:46:43, Info                  CSI    00000011 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:43, Info                  CSI    00000012 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:43, Info                  CSI    00000014 [SR] Verify complete
2018-07-11 15:46:44, Info                  CSI    00000015 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:44, Info                  CSI    00000016 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:44, Info                  CSI    00000018 [SR] Verify complete
2018-07-11 15:46:44, Info                  CSI    00000019 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:44, Info                  CSI    0000001a [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:44, Info                  CSI    0000001c [SR] Verify complete
2018-07-11 15:46:45, Info                  CSI    0000001d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:45, Info                  CSI    0000001e [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:45, Info                  CSI    00000020 [SR] Verify complete
2018-07-11 15:46:46, Info                  CSI    00000021 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:46, Info                  CSI    00000022 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:46, Info                  CSI    00000024 [SR] Verify complete
2018-07-11 15:46:46, Info                  CSI    00000025 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:46, Info                  CSI    00000026 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:47, Info                  CSI    00000028 [SR] Verify complete
2018-07-11 15:46:47, Info                  CSI    00000029 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:47, Info                  CSI    0000002a [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:47, Info                  CSI    0000002c [SR] Verify complete
2018-07-11 15:46:48, Info                  CSI    0000002d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:48, Info                  CSI    0000002e [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:48, Info                  CSI    00000030 [SR] Verify complete
2018-07-11 15:46:48, Info                  CSI    00000031 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:48, Info                  CSI    00000032 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:49, Info                  CSI    00000034 [SR] Verify complete
2018-07-11 15:46:49, Info                  CSI    00000035 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:49, Info                  CSI    00000036 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:49, Info                  CSI    00000038 [SR] Verify complete
2018-07-11 15:46:50, Info                  CSI    00000039 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:50, Info                  CSI    0000003a [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:50, Info                  CSI    0000003c [SR] Verify complete
2018-07-11 15:46:51, Info                  CSI    0000003d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:51, Info                  CSI    0000003e [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:51, Info                  CSI    00000040 [SR] Verify complete
2018-07-11 15:46:51, Info                  CSI    00000041 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:51, Info                  CSI    00000042 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:51, Info                  CSI    00000044 [SR] Verify complete
2018-07-11 15:46:52, Info                  CSI    00000045 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:52, Info                  CSI    00000046 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:52, Info                  CSI    00000048 [SR] Verify complete
2018-07-11 15:46:53, Info                  CSI    00000049 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:53, Info                  CSI    0000004a [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:53, Info                  CSI    0000004c [SR] Verify complete
2018-07-11 15:46:53, Info                  CSI    0000004d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:53, Info                  CSI    0000004e [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:54, Info                  CSI    00000050 [SR] Verify complete
2018-07-11 15:46:54, Info                  CSI    00000051 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:54, Info                  CSI    00000052 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:54, Info                  CSI    00000054 [SR] Verify complete
2018-07-11 15:46:55, Info                  CSI    00000055 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:55, Info                  CSI    00000056 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:55, Info                  CSI    00000058 [SR] Verify complete
2018-07-11 15:46:55, Info                  CSI    00000059 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:55, Info                  CSI    0000005a [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:56, Info                  CSI    0000005c [SR] Verify complete
2018-07-11 15:46:56, Info                  CSI    0000005d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:56, Info                  CSI    0000005e [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:56, Info                  CSI    00000060 [SR] Verify complete
2018-07-11 15:46:57, Info                  CSI    00000061 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:57, Info                  CSI    00000062 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:57, Info                  CSI    00000064 [SR] Verify complete
2018-07-11 15:46:57, Info                  CSI    00000065 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:57, Info                  CSI    00000066 [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:58, Info                  CSI    00000068 [SR] Verify complete
2018-07-11 15:46:59, Info                  CSI    00000069 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:59, Info                  CSI    0000006a [SR] Beginning Verify and Repair transaction
2018-07-11 15:46:59, Info                  CSI    0000006c [SR] Verify complete
2018-07-11 15:46:59, Info                  CSI    0000006d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:46:59, Info                  CSI    0000006e [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:00, Info                  CSI    00000070 [SR] Verify complete
2018-07-11 15:47:00, Info                  CSI    00000071 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:00, Info                  CSI    00000072 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:01, Info                  CSI    00000074 [SR] Verify complete
2018-07-11 15:47:01, Info                  CSI    00000075 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:01, Info                  CSI    00000076 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:01, Info                  CSI    00000078 [SR] Verify complete
2018-07-11 15:47:02, Info                  CSI    00000079 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:02, Info                  CSI    0000007a [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:02, Info                  CSI    0000007c [SR] Verify complete
2018-07-11 15:47:03, Info                  CSI    0000007d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:03, Info                  CSI    0000007e [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:03, Info                  CSI    00000080 [SR] Verify complete
2018-07-11 15:47:03, Info                  CSI    00000081 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:03, Info                  CSI    00000082 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:04, Info                  CSI    00000084 [SR] Verify complete
2018-07-11 15:47:04, Info                  CSI    00000085 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:04, Info                  CSI    00000086 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:04, Info                  CSI    00000088 [SR] Verify complete
2018-07-11 15:47:05, Info                  CSI    00000089 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:05, Info                  CSI    0000008a [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:05, Info                  CSI    0000008c [SR] Verify complete
2018-07-11 15:47:06, Info                  CSI    0000008d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:06, Info                  CSI    0000008e [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:06, Info                  CSI    00000090 [SR] Verify complete
2018-07-11 15:47:06, Info                  CSI    00000091 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:06, Info                  CSI    00000092 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:07, Info                  CSI    00000094 [SR] Verify complete
2018-07-11 15:47:07, Info                  CSI    00000095 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:07, Info                  CSI    00000096 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:08, Info                  CSI    00000098 [SR] Verify complete
2018-07-11 15:47:08, Info                  CSI    00000099 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:08, Info                  CSI    0000009a [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:09, Info                  CSI    0000009c [SR] Verify complete
2018-07-11 15:47:10, Info                  CSI    0000009d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:10, Info                  CSI    0000009e [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:10, Info                  CSI    000000a0 [SR] Verify complete
2018-07-11 15:47:11, Info                  CSI    000000a1 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:11, Info                  CSI    000000a2 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:11, Info                  CSI    000000a4 [SR] Verify complete
2018-07-11 15:47:12, Info                  CSI    000000a5 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:12, Info                  CSI    000000a6 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:14, Info                  CSI    000000a9 [SR] Verify complete
2018-07-11 15:47:15, Info                  CSI    000000aa [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:15, Info                  CSI    000000ab [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:17, Info                  CSI    000000af [SR] Verify complete
2018-07-11 15:47:17, Info                  CSI    000000b0 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:17, Info                  CSI    000000b1 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:19, Info                  CSI    000000b4 [SR] Verify complete
2018-07-11 15:47:19, Info                  CSI    000000b5 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:19, Info                  CSI    000000b6 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:21, Info                  CSI    000000b9 [SR] Verify complete
2018-07-11 15:47:21, Info                  CSI    000000ba [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:21, Info                  CSI    000000bb [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:23, Info                  CSI    000000bd [SR] Verify complete
2018-07-11 15:47:23, Info                  CSI    000000be [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:23, Info                  CSI    000000bf [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:27, Info                  CSI    000000e4 [SR] Verify complete
2018-07-11 15:47:27, Info                  CSI    000000e5 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:27, Info                  CSI    000000e6 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:29, Info                  CSI    000000e8 [SR] Verify complete
2018-07-11 15:47:30, Info                  CSI    000000e9 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:30, Info                  CSI    000000ea [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:31, Info                  CSI    000000ec [SR] Verify complete
2018-07-11 15:47:32, Info                  CSI    000000ed [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:32, Info                  CSI    000000ee [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:33, Info                  CSI    000000f0 [SR] Verify complete
2018-07-11 15:47:34, Info                  CSI    000000f1 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:34, Info                  CSI    000000f2 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:36, Info                  CSI    000000f4 [SR] Verify complete
2018-07-11 15:47:36, Info                  CSI    000000f5 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:36, Info                  CSI    000000f6 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:38, Info                  CSI    000000f8 [SR] Verify complete
2018-07-11 15:47:38, Info                  CSI    000000f9 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:38, Info                  CSI    000000fa [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:41, Info                  CSI    000000fc [SR] Verify complete
2018-07-11 15:47:41, Info                  CSI    000000fd [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:41, Info                  CSI    000000fe [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:46, Info                  CSI    00000121 [SR] Verify complete
2018-07-11 15:47:46, Info                  CSI    00000122 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:46, Info                  CSI    00000123 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:49, Info                  CSI    00000125 [SR] Verify complete
2018-07-11 15:47:49, Info                  CSI    00000126 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:49, Info                  CSI    00000127 [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:55, Info                  CSI    00000129 [SR] Verify complete
2018-07-11 15:47:56, Info                  CSI    0000012a [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:56, Info                  CSI    0000012b [SR] Beginning Verify and Repair transaction
2018-07-11 15:47:58, Info                  CSI    0000012f [SR] Verify complete
2018-07-11 15:47:59, Info                  CSI    00000130 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:47:59, Info                  CSI    00000131 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:00, Info                  CSI    00000133 [SR] Verify complete
2018-07-11 15:48:00, Info                  CSI    00000134 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:00, Info                  CSI    00000135 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:01, Info                  CSI    00000137 [SR] Verify complete
2018-07-11 15:48:01, Info                  CSI    00000138 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:01, Info                  CSI    00000139 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:02, Info                  CSI    0000013b [SR] Verify complete
2018-07-11 15:48:03, Info                  CSI    0000013c [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:03, Info                  CSI    0000013d [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:08, Info                  CSI    00000150 [SR] Verify complete
2018-07-11 15:48:08, Info                  CSI    00000151 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:08, Info                  CSI    00000152 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:09, Info                  CSI    00000154 [SR] Verify complete
2018-07-11 15:48:10, Info                  CSI    00000155 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:10, Info                  CSI    00000156 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:10, Info                  CSI    00000158 [SR] Verify complete
2018-07-11 15:48:11, Info                  CSI    00000159 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:11, Info                  CSI    0000015a [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:12, Info                  CSI    0000015c [SR] Verify complete
2018-07-11 15:48:13, Info                  CSI    0000015d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:13, Info                  CSI    0000015e [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:14, Info                  CSI    00000160 [SR] Verify complete
2018-07-11 15:48:15, Info                  CSI    00000161 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:15, Info                  CSI    00000162 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:19, Info                  CSI    00000166 [SR] Verify complete
2018-07-11 15:48:20, Info                  CSI    00000167 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:20, Info                  CSI    00000168 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:22, Info                  CSI    0000016a [SR] Verify complete
2018-07-11 15:48:22, Info                  CSI    0000016b [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:22, Info                  CSI    0000016c [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:23, Info                  CSI    0000016e [SR] Verify complete
2018-07-11 15:48:23, Info                  CSI    0000016f [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:23, Info                  CSI    00000170 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:23, Info                  CSI    00000172 [SR] Cannot repair member file [l:28{14}]"lsasrv.dll.mui" of Microsoft-Windows-LSA.Resources, Version = 6.1.7601.24059, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2018-07-11 15:48:25, Info                  CSI    00000173 [SR] Repaired file \SystemRoot\WinSxS\Manifests\\[l:28{14}]"lsasrv.dll.mui" by copying from backup
2018-07-11 15:48:25, Info                  CSI    00000175 [SR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\en-US"\[l:28{14}]"lsasrv.dll.mui" from store
2018-07-11 15:48:25, Info                  CSI    00000177 [SR] Verify complete
2018-07-11 15:48:26, Info                  CSI    00000178 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:26, Info                  CSI    00000179 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:27, Info                  CSI    0000017b [SR] Verify complete
2018-07-11 15:48:28, Info                  CSI    0000017c [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:28, Info                  CSI    0000017d [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:29, Info                  CSI    0000017f [SR] Verify complete
2018-07-11 15:48:30, Info                  CSI    00000180 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:30, Info                  CSI    00000181 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:34, Info                  CSI    00000183 [SR] Verify complete
2018-07-11 15:48:34, Info                  CSI    00000184 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:34, Info                  CSI    00000185 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:38, Info                  CSI    0000019d [SR] Verify complete
2018-07-11 15:48:39, Info                  CSI    0000019e [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:39, Info                  CSI    0000019f [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:41, Info                  CSI    000001a1 [SR] Verify complete
2018-07-11 15:48:41, Info                  CSI    000001a2 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:41, Info                  CSI    000001a3 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:50, Info                  CSI    000001a5 [SR] Verify complete
2018-07-11 15:48:51, Info                  CSI    000001a6 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:51, Info                  CSI    000001a7 [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:55, Info                  CSI    000001aa [SR] Verify complete
2018-07-11 15:48:56, Info                  CSI    000001ab [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:56, Info                  CSI    000001ac [SR] Beginning Verify and Repair transaction
2018-07-11 15:48:58, Info                  CSI    000001ae [SR] Verify complete
2018-07-11 15:48:58, Info                  CSI    000001af [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:48:58, Info                  CSI    000001b0 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:00, Info                  CSI    000001b2 [SR] Verify complete
2018-07-11 15:49:01, Info                  CSI    000001b3 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:01, Info                  CSI    000001b4 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:02, Info                  CSI    000001b6 [SR] Verify complete
2018-07-11 15:49:03, Info                  CSI    000001b7 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:03, Info                  CSI    000001b8 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:04, Info                  CSI    000001ba [SR] Verify complete
2018-07-11 15:49:04, Info                  CSI    000001bb [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:04, Info                  CSI    000001bc [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:06, Info                  CSI    000001c0 [SR] Verify complete
2018-07-11 15:49:07, Info                  CSI    000001c1 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:07, Info                  CSI    000001c2 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:08, Info                  CSI    000001c4 [SR] Verify complete
2018-07-11 15:49:09, Info                  CSI    000001c5 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:09, Info                  CSI    000001c6 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:16, Info                  CSI    000001c8 [SR] Verify complete
2018-07-11 15:49:17, Info                  CSI    000001c9 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:17, Info                  CSI    000001ca [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:21, Info                  CSI    000001cd [SR] Verify complete
2018-07-11 15:49:21, Info                  CSI    000001ce [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:21, Info                  CSI    000001cf [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:23, Info                  CSI    000001d2 [SR] Verify complete
2018-07-11 15:49:23, Info                  CSI    000001d3 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:23, Info                  CSI    000001d4 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:25, Info                  CSI    000001d6 [SR] Verify complete
2018-07-11 15:49:26, Info                  CSI    000001d7 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:26, Info                  CSI    000001d8 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:29, Info                  CSI    000001db [SR] Verify complete
2018-07-11 15:49:30, Info                  CSI    000001dc [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:30, Info                  CSI    000001dd [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:32, Info                  CSI    000001df [SR] Verify complete
2018-07-11 15:49:33, Info                  CSI    000001e0 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:33, Info                  CSI    000001e1 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:34, Info                  CSI    000001e3 [SR] Verify complete
2018-07-11 15:49:35, Info                  CSI    000001e4 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:35, Info                  CSI    000001e5 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:37, Info                  CSI    000001e7 [SR] Verify complete
2018-07-11 15:49:37, Info                  CSI    000001e8 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:37, Info                  CSI    000001e9 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:39, Info                  CSI    000001ec [SR] Verify complete
2018-07-11 15:49:39, Info                  CSI    000001ed [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:39, Info                  CSI    000001ee [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:41, Info                  CSI    000001f0 [SR] Verify complete
2018-07-11 15:49:42, Info                  CSI    000001f1 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:42, Info                  CSI    000001f2 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:43, Info                  CSI    000001f5 [SR] Verify complete
2018-07-11 15:49:43, Info                  CSI    000001f6 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:43, Info                  CSI    000001f7 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:46, Info                  CSI    000001fa [SR] Verify complete
2018-07-11 15:49:46, Info                  CSI    000001fb [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:46, Info                  CSI    000001fc [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:48, Info                  CSI    000001fe [SR] Verify complete
2018-07-11 15:49:49, Info                  CSI    000001ff [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:49, Info                  CSI    00000200 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:51, Info                  CSI    00000204 [SR] Verify complete
2018-07-11 15:49:51, Info                  CSI    00000205 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:51, Info                  CSI    00000206 [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:54, Info                  CSI    00000208 [SR] Verify complete
2018-07-11 15:49:54, Info                  CSI    00000209 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:54, Info                  CSI    0000020a [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:57, Info                  CSI    0000020d [SR] Verify complete
2018-07-11 15:49:57, Info                  CSI    0000020e [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:57, Info                  CSI    0000020f [SR] Beginning Verify and Repair transaction
2018-07-11 15:49:59, Info                  CSI    00000211 [SR] Verify complete
2018-07-11 15:49:59, Info                  CSI    00000212 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:49:59, Info                  CSI    00000213 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:00, Info                  CSI    00000215 [SR] Verify complete
2018-07-11 15:50:00, Info                  CSI    00000216 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:00, Info                  CSI    00000217 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:02, Info                  CSI    00000219 [SR] Verify complete
2018-07-11 15:50:02, Info                  CSI    0000021a [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:02, Info                  CSI    0000021b [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:03, Info                  CSI    0000021d [SR] Verify complete
2018-07-11 15:50:04, Info                  CSI    0000021e [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:04, Info                  CSI    0000021f [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:06, Info                  CSI    00000221 [SR] Verify complete
2018-07-11 15:50:06, Info                  CSI    00000222 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:06, Info                  CSI    00000223 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:08, Info                  CSI    00000225 [SR] Verify complete
2018-07-11 15:50:08, Info                  CSI    00000226 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:08, Info                  CSI    00000227 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:09, Info                  CSI    00000229 [SR] Verify complete
2018-07-11 15:50:10, Info                  CSI    0000022a [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:10, Info                  CSI    0000022b [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:13, Info                  CSI    0000022d [SR] Verify complete
2018-07-11 15:50:14, Info                  CSI    0000022e [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:14, Info                  CSI    0000022f [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:19, Info                  CSI    00000231 [SR] Verify complete
2018-07-11 15:50:20, Info                  CSI    00000232 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:20, Info                  CSI    00000233 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:21, Info                  CSI    00000235 [SR] Verify complete
2018-07-11 15:50:21, Info                  CSI    00000236 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:21, Info                  CSI    00000237 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:23, Info                  CSI    00000239 [SR] Verify complete
2018-07-11 15:50:23, Info                  CSI    0000023a [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:23, Info                  CSI    0000023b [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:24, Info                  CSI    0000023d [SR] Verify complete
2018-07-11 15:50:24, Info                  CSI    0000023e [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:24, Info                  CSI    0000023f [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:25, Info                  CSI    00000241 [SR] Verify complete
2018-07-11 15:50:26, Info                  CSI    00000242 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:26, Info                  CSI    00000243 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:27, Info                  CSI    00000245 [SR] Verify complete
2018-07-11 15:50:28, Info                  CSI    00000246 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:28, Info                  CSI    00000247 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:28, Info                  CSI    00000249 [SR] Verify complete
2018-07-11 15:50:29, Info                  CSI    0000024a [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:29, Info                  CSI    0000024b [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:29, Info                  CSI    0000024d [SR] Verify complete
2018-07-11 15:50:30, Info                  CSI    0000024e [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:30, Info                  CSI    0000024f [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:32, Info                  CSI    00000257 [SR] Verify complete
2018-07-11 15:50:32, Info                  CSI    00000258 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:32, Info                  CSI    00000259 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:33, Info                  CSI    0000025b [SR] Verify complete
2018-07-11 15:50:34, Info                  CSI    0000025c [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:34, Info                  CSI    0000025d [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:35, Info                  CSI    0000025f [SR] Verify complete
2018-07-11 15:50:36, Info                  CSI    00000260 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:36, Info                  CSI    00000261 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:36, Info                  CSI    00000263 [SR] Verify complete
2018-07-11 15:50:37, Info                  CSI    00000264 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:37, Info                  CSI    00000265 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:38, Info                  CSI    00000267 [SR] Verify complete
2018-07-11 15:50:39, Info                  CSI    00000268 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:39, Info                  CSI    00000269 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:41, Info                  CSI    0000026b [SR] Verify complete
2018-07-11 15:50:41, Info                  CSI    0000026c [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:41, Info                  CSI    0000026d [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:45, Info                  CSI    00000270 [SR] Verify complete
2018-07-11 15:50:45, Info                  CSI    00000271 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:45, Info                  CSI    00000272 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:46, Info                  CSI    00000274 [SR] Verify complete
2018-07-11 15:50:46, Info                  CSI    00000275 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:46, Info                  CSI    00000276 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:47, Info                  CSI    00000278 [SR] Verify complete
2018-07-11 15:50:48, Info                  CSI    00000279 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:48, Info                  CSI    0000027a [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:49, Info                  CSI    0000027c [SR] Cannot repair member file [l:24{12}]"kernel32.dll" of Microsoft-Windows-Kernel32, Version = 6.1.7601.24059, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2018-07-11 15:50:53, Info                  CSI    00000280 [SR] Repaired file \SystemRoot\WinSxS\Manifests\\[l:24{12}]"kernel32.dll" by copying from backup
2018-07-11 15:50:53, Info                  CSI    00000282 [SR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"kernel32.dll" from store
2018-07-11 15:50:54, Info                  CSI    00000284 [SR] Verify complete
2018-07-11 15:50:55, Info                  CSI    00000285 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:55, Info                  CSI    00000286 [SR] Beginning Verify and Repair transaction
2018-07-11 15:50:57, Info                  CSI    0000028b [SR] Verify complete
2018-07-11 15:50:58, Info                  CSI    0000028c [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:50:58, Info                  CSI    0000028d [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:00, Info                  CSI    0000028f [SR] Verify complete
2018-07-11 15:51:01, Info                  CSI    00000290 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:01, Info                  CSI    00000291 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:03, Info                  CSI    0000029f [SR] Verify complete
2018-07-11 15:51:04, Info                  CSI    000002a0 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:04, Info                  CSI    000002a1 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:06, Info                  CSI    000002a7 [SR] Verify complete
2018-07-11 15:51:07, Info                  CSI    000002a8 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:07, Info                  CSI    000002a9 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:09, Info                  CSI    000002ab [SR] Verify complete
2018-07-11 15:51:09, Info                  CSI    000002ac [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:09, Info                  CSI    000002ad [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:10, Info                  CSI    000002b1 [SR] Verify complete
2018-07-11 15:51:11, Info                  CSI    000002b2 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:11, Info                  CSI    000002b3 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:12, Info                  CSI    000002b5 [SR] Verify complete
2018-07-11 15:51:13, Info                  CSI    000002b6 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:13, Info                  CSI    000002b7 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:15, Info                  CSI    000002dc [SR] Verify complete
2018-07-11 15:51:16, Info                  CSI    000002dd [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:16, Info                  CSI    000002de [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:17, Info                  CSI    000002e0 [SR] Verify complete
2018-07-11 15:51:18, Info                  CSI    000002e1 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:18, Info                  CSI    000002e2 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:19, Info                  CSI    000002e4 [SR] Verify complete
2018-07-11 15:51:20, Info                  CSI    000002e5 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:20, Info                  CSI    000002e6 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:21, Info                  CSI    000002e8 [SR] Verify complete
2018-07-11 15:51:22, Info                  CSI    000002e9 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:22, Info                  CSI    000002ea [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:23, Info                  CSI    000002f8 [SR] Verify complete
2018-07-11 15:51:24, Info                  CSI    000002f9 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:24, Info                  CSI    000002fa [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:26, Info                  CSI    000002fc [SR] Verify complete
2018-07-11 15:51:27, Info                  CSI    000002fd [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:27, Info                  CSI    000002fe [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:30, Info                  CSI    0000030c [SR] Verify complete
2018-07-11 15:51:30, Info                  CSI    0000030d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:30, Info                  CSI    0000030e [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:32, Info                  CSI    00000310 [SR] Verify complete
2018-07-11 15:51:32, Info                  CSI    00000311 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:32, Info                  CSI    00000312 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:33, Info                  CSI    00000314 [SR] Verify complete
2018-07-11 15:51:33, Info                  CSI    00000315 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:33, Info                  CSI    00000316 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:36, Info                  CSI    00000319 [SR] Verify complete
2018-07-11 15:51:36, Info                  CSI    0000031a [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:36, Info                  CSI    0000031b [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:37, Info                  CSI    0000031d [SR] Verify complete
2018-07-11 15:51:37, Info                  CSI    0000031e [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:37, Info                  CSI    0000031f [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:39, Info                  CSI    00000321 [SR] Verify complete
2018-07-11 15:51:39, Info                  CSI    00000322 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:39, Info                  CSI    00000323 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:41, Info                  CSI    00000325 [SR] Verify complete
2018-07-11 15:51:41, Info                  CSI    00000326 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:41, Info                  CSI    00000327 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:43, Info                  CSI    00000329 [SR] Verify complete
2018-07-11 15:51:43, Info                  CSI    0000032a [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:43, Info                  CSI    0000032b [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:48, Info                  CSI    00000345 [SR] Verify complete
2018-07-11 15:51:48, Info                  CSI    00000346 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:48, Info                  CSI    00000347 [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:56, Info                  CSI    00000349 [SR] Verify complete
2018-07-11 15:51:57, Info                  CSI    0000034a [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:57, Info                  CSI    0000034b [SR] Beginning Verify and Repair transaction
2018-07-11 15:51:58, Info                  CSI    0000034d [SR] Verify complete
2018-07-11 15:51:59, Info                  CSI    0000034e [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:51:59, Info                  CSI    0000034f [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:00, Info                  CSI    00000351 [SR] Verify complete
2018-07-11 15:52:00, Info                  CSI    00000352 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:00, Info                  CSI    00000353 [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:01, Info                  CSI    00000357 [SR] Verify complete
2018-07-11 15:52:02, Info                  CSI    00000358 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:02, Info                  CSI    00000359 [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:02, Info                  CSI    0000035b [SR] Verify complete
2018-07-11 15:52:03, Info                  CSI    0000035c [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:03, Info                  CSI    0000035d [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:05, Info                  CSI    0000035f [SR] Verify complete
2018-07-11 15:52:05, Info                  CSI    00000360 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:05, Info                  CSI    00000361 [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:06, Info                  CSI    00000363 [SR] Verify complete
2018-07-11 15:52:07, Info                  CSI    00000364 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:07, Info                  CSI    00000365 [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:08, Info                  CSI    00000368 [SR] Verify complete
2018-07-11 15:52:09, Info                  CSI    00000369 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:09, Info                  CSI    0000036a [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:10, Info                  CSI    0000036c [SR] Verify complete
2018-07-11 15:52:10, Info                  CSI    0000036d [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:10, Info                  CSI    0000036e [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:12, Info                  CSI    00000370 [SR] Verify complete
2018-07-11 15:52:12, Info                  CSI    00000371 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:12, Info                  CSI    00000372 [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:14, Info                  CSI    00000374 [SR] Verify complete
2018-07-11 15:52:14, Info                  CSI    00000375 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:14, Info                  CSI    00000376 [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:16, Info                  CSI    00000379 [SR] Verify complete
2018-07-11 15:52:16, Info                  CSI    0000037a [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:16, Info                  CSI    0000037b [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:18, Info                  CSI    0000037d [SR] Verify complete
2018-07-11 15:52:18, Info                  CSI    0000037e [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:18, Info                  CSI    0000037f [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:19, Info                  CSI    00000381 [SR] Verify complete
2018-07-11 15:52:20, Info                  CSI    00000382 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:20, Info                  CSI    00000383 [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:21, Info                  CSI    00000385 [SR] Verify complete
2018-07-11 15:52:22, Info                  CSI    00000386 [SR] Verifying 100 (0x0000000000000064) components
2018-07-11 15:52:22, Info                  CSI    00000387 [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:24, Info                  CSI    00000389 [SR] Verify complete
2018-07-11 15:52:24, Info                  CSI    0000038a [SR] Verifying 22 (0x0000000000000016) components
2018-07-11 15:52:24, Info                  CSI    0000038b [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:24, Info                  CSI    0000038d [SR] Verify complete
2018-07-11 15:52:24, Info                  CSI    0000038e [SR] Repairing 2 components
2018-07-11 15:52:24, Info                  CSI    0000038f [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:24, Info                  CSI    00000391 [SR] Cannot repair member file [l:28{14}]"lsasrv.dll.mui" of Microsoft-Windows-LSA.Resources, Version = 6.1.7601.24059, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2018-07-11 15:52:24, Info                  CSI    00000393 [SR] Cannot repair member file [l:24{12}]"kernel32.dll" of Microsoft-Windows-Kernel32, Version = 6.1.7601.24059, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2018-07-11 15:52:24, Info                  CSI    00000394 [SR] Repaired file \SystemRoot\WinSxS\Manifests\\[l:24{12}]"kernel32.dll" by copying from backup
2018-07-11 15:52:24, Info                  CSI    00000396 [SR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"kernel32.dll" from store
2018-07-11 15:52:24, Info                  CSI    00000397 [SR] Repaired file \SystemRoot\WinSxS\Manifests\\[l:28{14}]"lsasrv.dll.mui" by copying from backup
2018-07-11 15:52:24, Info                  CSI    00000399 [SR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\en-US"\[l:28{14}]"lsasrv.dll.mui" from store
2018-07-11 15:52:24, Info                  CSI    0000039b [SR] Repair complete
2018-07-11 15:52:24, Info                  CSI    0000039c [SR] Committing transaction
2018-07-11 15:52:24, Info                  CSI    000003a0 [SR] Unable to complete Verify and Repair transaction because some of the files that need to be repaired are in use. A reboot is required to complete this operation.
2018-07-11 15:52:24, Info                  CSI    000003a1 [SR] Repairing 2 components
2018-07-11 15:52:24, Info                  CSI    000003a2 [SR] Beginning Verify and Repair transaction
2018-07-11 15:52:24, Info                  CSI    000003a4 [SR] Cannot repair member file [l:28{14}]"lsasrv.dll.mui" of Microsoft-Windows-LSA.Resources, Version = 6.1.7601.24059, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2018-07-11 15:52:24, Info                  CSI    000003a6 [SR] Cannot repair member file [l:24{12}]"kernel32.dll" of Microsoft-Windows-Kernel32, Version = 6.1.7601.24059, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2018-07-11 15:52:24, Info                  CSI    000003a7 [SR] Repaired file \SystemRoot\WinSxS\Manifests\\[l:24{12}]"kernel32.dll" by copying from backup
2018-07-11 15:52:24, Info                  CSI    000003a9 [SR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"kernel32.dll" from store
2018-07-11 15:52:24, Info                  CSI    000003aa [SR] Repaired file \SystemRoot\WinSxS\Manifests\\[l:28{14}]"lsasrv.dll.mui" by copying from backup
2018-07-11 15:52:24, Info                  CSI    000003ac [SR] Repairing corrupted file [ml:520{260},l:58{29}]"\??\C:\Windows\System32\en-US"\[l:28{14}]"lsasrv.dll.mui" from store
2018-07-11 15:52:25, Info                  CSI    000003ae [SR] Repair complete
 
VEW will not run. It was allowed to be downloaded but will not run

  • 0

#7
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,623 posts
  • MVP

Right click on VEW.exe and select Properties.  Sometimes at the bottom you will see Security and something about Unblocking.  Check Unblock and OK.  Now right click on VEW.exe and run as admin.

 

Does that change anything?

 

Rerun sfc /scannow as before.  Does it find any corruption?

 

Are you able to uninstall any of the programs that wouldn't uninstall before?


  • 0

#8
grdsproblem

grdsproblem

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

I take it I was supposed to reboot after the disc check as it stated it needed to reboot to repair itself. I have done this and now VEW is running

 

Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 12/07/2018 15:20:47
 
Note: All dates below are in the format dd/mm/yyyy
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 12/07/2018 02:00:34
Type: Error Category: 0
Event: 12344 Source: VSS
Volume Shadow Copy Error: An error 0x00000000c000014d was encountered while Registry Writer was preparing the registry for a shadow copy.  Check the Application and System event logs for any related errors. 
 
Operation:
   OnFreeze event
   Freeze Event
 
Context:
   Execution Context: Registry Writer
   Execution Context: Writer
   Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485}
   Writer Name: Registry Writer
   Writer Instance ID: {60c2f170-1a3a-4552-a93e-21708d592a3a}
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 12/07/2018 14:19:00
Type: Warning Category: 2
Event: 4113 Source: Avira Antivirus
AntiVir has detected 'DR/Autoit.lnsqn' in the file C:\Users\robin\Desktop\avcertclean_1.2.0.exe
 
Log: 'Application' Date/Time: 12/07/2018 14:11:15
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.     DETAIL -   0 user registry handles leaked from \Registry\User\S-1-5-21-1842024429-2714170209-1629358381-1001_Classes:
 
 
Log: 'Application' Date/Time: 12/07/2018 14:11:15
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.     DETAIL -   1 user registry handles leaked from \Registry\User\S-1-5-21-1842024429-2714170209-1629358381-1001:
Process 2128 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe) has opened key \REGISTRY\USER\S-1-5-21-1842024429-2714170209-1629358381-1001\Software\NVIDIA Corporation\Global\ShadowPlay
 
 
Log: 'Application' Date/Time: 12/07/2018 02:00:34
Type: Warning Category: 0
Event: 8229 Source: VSS
A VSS writer has rejected an event with error 0x800423f4, The writer experienced a non-transient error.  If the backup process is retried, the error is likely to reoccur. . Changes that the writer made to the writer components while handling the event will not be available to the requester. Check the event log for related events from the application hosting the VSS writer. 
 
Operation:
   Freeze Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485}
   Writer Name: Registry Writer
   Writer Instance ID: {60c2f170-1a3a-4552-a93e-21708d592a3a}
   Command Line: C:\Windows\system32\vssvc.exe
   Process ID: 5208
 
Log: 'Application' Date/Time: 11/07/2018 14:16:05
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.     DETAIL -   0 user registry handles leaked from \Registry\User\S-1-5-21-1842024429-2714170209-1629358381-1001_Classes:
 
 
Log: 'Application' Date/Time: 11/07/2018 14:16:05
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.     DETAIL -   1 user registry handles leaked from \Registry\User\S-1-5-21-1842024429-2714170209-1629358381-1001:
Process 4444 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe) has opened key \REGISTRY\USER\S-1-5-21-1842024429-2714170209-1629358381-1001\Software\NVIDIA Corporation\Global\ShadowPlay
 
Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 12/07/2018 15:28:57
 
Note: All dates below are in the format dd/mm/yyyy
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 12/07/2018 02:01:08
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: 2018-07 Security and Quality Rollup for .NET Framework 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 7 and Server 2008 R2 for x64 (KB4340556).
 
Log: 'System' Date/Time: 12/07/2018 02:01:08
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070bc9: 2018-07 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4338818).
 
Log: 'System' Date/Time: 12/07/2018 02:00:34
Type: Error Category: 0
Event: 6 Source: Microsoft-Windows-Kernel-General
An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): '\??\GLOBALROOT\Device\HarddiskVolumeShadowCopy4\Users\default\ntuser.dat'.
 
Log: 'System' Date/Time: 11/07/2018 17:03:46
Type: Error Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
The server {06622D85-6856-4460-8DE1-A81921B41C4B} did not register with DCOM within the required timeout.
 
Log: 'System' Date/Time: 11/07/2018 14:41:00
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Unchecky service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
 
Log: 'System' Date/Time: 11/07/2018 14:41:00
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (120000 milliseconds) while waiting for the Unchecky service to connect.
 
Log: 'System' Date/Time: 11/07/2018 14:41:00
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (120000 milliseconds) while waiting for the NVIDIA Telemetry Container service to connect.
 
Log: 'System' Date/Time: 11/07/2018 14:40:57
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Dropbox Update Service (dbupdate) service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
 
Log: 'System' Date/Time: 11/07/2018 14:40:57
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (120000 milliseconds) while waiting for the Dropbox Update Service (dbupdate) service to connect.
 
Log: 'System' Date/Time: 11/07/2018 14:40:57
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (120000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.
 
Log: 'System' Date/Time: 11/07/2018 14:40:25
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  {C97FCC79-E628-407D-AE68-A06AD6D8B4D1}  and APPID  {344ED43D-D086-4961-86A6-1106F4ACAD9B}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 11/07/2018 14:38:57
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (120000 milliseconds) while waiting for the Avira Service Host service to connect.
 
Log: 'System' Date/Time: 11/07/2018 14:38:42
Type: Error Category: 0
Event: 7001 Source: Service Control Manager
The Avira Mail Protection service depends on the Avira Real-Time Protection service which failed to start because of the following error:  The service did not respond to the start or control request in a timely fashion.
 
Log: 'System' Date/Time: 11/07/2018 14:38:41
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Origin Web Helper Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
 
Log: 'System' Date/Time: 11/07/2018 14:38:41
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (120000 milliseconds) while waiting for the Origin Web Helper Service service to connect.
 
Log: 'System' Date/Time: 11/07/2018 14:38:26
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (120000 milliseconds) while waiting for the IObit Uninstaller Service service to connect.
 
Log: 'System' Date/Time: 11/07/2018 14:38:11
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Avira Optimizer Host service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
 
Log: 'System' Date/Time: 11/07/2018 14:38:11
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (120000 milliseconds) while waiting for the Avira Optimizer Host service to connect.
 
Log: 'System' Date/Time: 11/07/2018 14:37:56
Type: Error Category: 0
Event: 7001 Source: Service Control Manager
The Avira Web Protection service depends on the Avira Real-Time Protection service which failed to start because of the following error:  The service did not respond to the start or control request in a timely fashion.
 
Log: 'System' Date/Time: 11/07/2018 14:37:56
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Avira Real-Time Protection service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 12/07/2018 14:11:17
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped. 
 
Log: 'System' Date/Time: 12/07/2018 02:00:19
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name isatap.lan timed out after none of the configured DNS servers responded.
 
Log: 'System' Date/Time: 11/07/2018 16:43:51
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name isatap.lan timed out after none of the configured DNS servers responded.
 
Log: 'System' Date/Time: 11/07/2018 14:16:06
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped. 
 
 All other programs were able to have been removed as discussed earlier. As I had used MBAM at an earlier date I could only run a basic scan which has reported that I am all clear. sfc reported no problems YAY! What now, do you think i am clear and have you any idea what was my problem? I'm eternally grateful to you and your wisdom
 
 

  • 0

#9
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,623 posts
  • MVP

Let's see if the errors are gone now:

 

Right click on (My) Computer and select Manage (Continue) Then click on the arrow in front of Event Viewer. Next Click on the arrow in front of Windows Logs Right click on System and Clear Log, Clear. Repeat for Application.

Reboot.
 

Then run VEW again for Application and System as before and post the logs.

 

Let's also check a few more things:

Get Process Explorer

http://live.sysinter...com/procexp.exe
Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.


Copy the next 2 lines:

TASKLIST /SVC  > \junk.txt
notepad \junk.txt

Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Win 8: http://www.eightforu...indows-8-a.html
win 10: http://www.howtogeek...-in-windows-10/

Right click and Paste (or Edit then Paste) and the copied lines should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.


Get the free version of Speccy:

http://www.filehippo...ownload_speccy/ 

(Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  
Download, Save and Install it.  Tell it you do not need CCLEANER.    Run Speccy.  When it finishes (the little icon in the bottom left will stop moving),
File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  
(It will be near the top,  10-20  lines down.) Save the file.  Attach the file to your next post.  Attaching the log is the best option as it is too big for the forum.  Attaching is a multi step process.

First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.
 


  • 0

#10
grdsproblem

grdsproblem

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 12/07/2018 21:16:07
 
Note: All dates below are in the format dd/mm/yyyy
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 12/07/2018 20:12:47
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.     DETAIL -   0 user registry handles leaked from \Registry\User\S-1-5-21-1842024429-2714170209-1629358381-1001_Classes:
 
 
Log: 'Application' Date/Time: 12/07/2018 20:12:47
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.     DETAIL -   3 user registry handles leaked from \Registry\User\S-1-5-21-1842024429-2714170209-1629358381-1001:
Process 4256 (\Device\HarddiskVolume2\Program Files\AVG\Antivirus\AVGSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-1842024429-2714170209-1629358381-1001
Process 9104 (\Device\HarddiskVolume2\Windows\System32\PrintIsolationHost.exe) has opened key \REGISTRY\USER\S-1-5-21-1842024429-2714170209-1629358381-1001
Process 1592 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe) has opened key \REGISTRY\USER\S-1-5-21-1842024429-2714170209-1629358381-1001\Software\NVIDIA Corporation\Global\ShadowPlay
 
Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 12/07/2018 21:17:21
 
Note: All dates below are in the format dd/mm/yyyy
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 12/07/2018 20:15:44
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The AVG Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
 
Log: 'System' Date/Time: 12/07/2018 20:15:44
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (120000 milliseconds) while waiting for the AVG Service service to connect.
 
Log: 'System' Date/Time: 12/07/2018 20:15:08
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  {C97FCC79-E628-407D-AE68-A06AD6D8B4D1}  and APPID  {344ED43D-D086-4961-86A6-1106F4ACAD9B}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 12/07/2018 20:12:49
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped. 
 
Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
chrome.exe 0.06 364,612 K 405,712 K 7192 Google Chrome Google Inc. (Verified) Google Inc
chrome.exe 0.01 153,244 K 207,384 K 6448 Google Chrome Google Inc. (Verified) Google Inc
chrome.exe 138,188 K 148,816 K 5960 Google Chrome Google Inc. (Verified) Google Inc
svchost.exe < 0.01 246,376 K 142,584 K 572 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
chrome.exe 192,600 K 93,848 K 6888 Google Chrome Google Inc. (Verified) Google Inc
chrome.exe 48,844 K 65,744 K 544 Google Chrome Google Inc. (Verified) Google Inc
TrustedInstaller.exe 56,104 K 63,140 K 6236 Windows Modules Installer Microsoft Corporation (Verified) Microsoft Windows
chrome.exe 45,240 K 59,464 K 7280 Google Chrome Google Inc. (Verified) Google Inc
procexp64.exe 2.03 33,368 K 52,536 K 5020 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
chrome.exe 36,496 K 49,540 K 3024 Google Chrome Google Inc. (Verified) Google Inc
googledrivesync.exe 0.03 136,484 K 45,300 K 5416 (Verified) Google Inc
AVGSvc.exe 0.01 108,096 K 44,652 K 1304 AVG Service AVG Technologies CZ, s.r.o. (Verified) AVG Netherlands B.V.
AVGUI.exe 0.14 23,284 K 38,012 K 4212 AVG Antivirus AVG Technologies CZ, s.r.o. (Verified) AVG Netherlands B.V.
chrome.exe 25,080 K 34,864 K 1316 Google Chrome Google Inc. (Verified) Google Inc
explorer.exe 0.04 31,708 K 33,060 K 2948 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
svchost.exe < 0.01 38,136 K 33,016 K 1196 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
dwm.exe 0.21 45,756 K 26,412 K 3156 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
Steam.exe 0.30 42,296 K 24,980 K 3636 Steam Client Bootstrapper Valve Corporation (Verified) Valve
chrome.exe 16,168 K 22,064 K 8040 Google Chrome Google Inc. (Verified) Google Inc
aswidsagenta.exe 0.01 21,372 K 19,680 K 2928 AVG Software Analyzer AVG Technologies CZ, s.r.o. (Verified) AVG Netherlands B.V.
svchost.exe < 0.01 23,568 K 16,524 K 348 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe < 0.01 14,920 K 16,148 K 552 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
nvcontainer.exe < 0.01 25,500 K 14,072 K 5348 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
csrss.exe 0.17 3,440 K 14,048 K 640
NVDisplay.Container.exe < 0.01 27,728 K 13,216 K 1436
svchost.exe 13,556 K 12,992 K 1740 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
mscorsvw.exe 9,664 K 12,644 K 8108 .NET Runtime Optimization Service Microsoft Corporation (Verified) Microsoft Dynamic Code Publisher
svchost.exe 13,248 K 12,148 K 448 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
MBAMService.exe < 0.01 22,660 K 11,708 K 2288 Malwarebytes Service Malwarebytes (Verified) Malwarebytes Corporation
spoolsv.exe < 0.01 12,132 K 11,388 K 1680 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
svchost.exe < 0.01 14,820 K 10,996 K 1412 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
steamwebhelper.exe < 0.01 16,472 K 10,396 K 4420 Steam Client WebHelper Valve Corporation (Verified) Valve
flux.exe 0.01 11,488 K 9,504 K 3876 f.lux f.lux Software LLC (Verified) F.lux Software LLC
mscorsvw.exe 5,320 K 9,344 K 7976 .NET Runtime Optimization Service Microsoft Corporation (Verified) Microsoft Dynamic Code Publisher
jusched.exe 5,400 K 9,220 K 4220 Java Update Scheduler Oracle Corporation (Verified) Oracle America
svchost.exe < 0.01 6,420 K 8,668 K 2228 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
chrome.exe 4,300 K 8,640 K 6268 Google Chrome Google Inc. (Verified) Google Inc
NVIDIA Web Helper.exe 0.01 35,424 K 8,492 K 4328 NVIDIA Web Helper Service Node.js (Verified) NVIDIA Corporation
wmpnetwk.exe < 0.01 9,048 K 8,484 K 4976 Windows Media Player Network Sharing Service Microsoft Corporation (Verified) Microsoft Windows
lsass.exe < 0.01 6,292 K 8,416 K 732 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.02 8,424 K 8,176 K 1904 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
chrome.exe 3,996 K 7,828 K 6528 Google Chrome Google Inc. (Verified) Google Inc
taskhost.exe < 0.01 14,700 K 7,820 K 4032 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
nvcontainer.exe 0.02 12,616 K 7,792 K 3808 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
procexp.exe 3,292 K 7,672 K 6584 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
svchost.exe < 0.01 7,568 K 7,612 K 1000 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
OriginWebHelperService.exe < 0.01 6,948 K 7,448 K 1948 OriginWebHelperService Electronic Arts (Verified) Electronic Arts
mbamtray.exe < 0.01 18,556 K 6,860 K 4052 Malwarebytes Tray Application Malwarebytes (Verified) Malwarebytes Corporation
svchost.exe 7,360 K 6,744 K 1868 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
NvTelemetryContainer.exe < 0.01 8,048 K 6,684 K 1640 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
svchost.exe 2,440 K 6,408 K 992 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
services.exe 6,356 K 6,024 K 688
svchost.exe 4,220 K 5,204 K 1044 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
NVDisplay.Container.exe 6,172 K 5,064 K 936 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
svchost.exe 5,968 K 4,688 K 860 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 4,128 K 4,444 K 4088
steamwebhelper.exe 22,916 K 3,864 K 4788 Steam Client WebHelper Valve Corporation (Verified) Valve
MacriumService.exe 4,528 K 3,052 K 1376 Macrium Reflect Utility Service Paramount Software UK Ltd (Verified) Paramount Software UK Ltd
csrss.exe < 0.01 3,080 K 2,508 K 536
SteamService.exe < 0.01 7,268 K 2,384 K 4440 Steam Client Service Valve Corporation (Verified) Valve
lsm.exe 3,264 K 2,156 K 744
System 0.06 168 K 1,888 K 4
steamwebhelper.exe 14,964 K 1,856 K 4888 Steam Client WebHelper Valve Corporation (Verified) Valve
winlogon.exe 4,348 K 1,636 K 724
SpotifyWebHelper.exe 2,148 K 1,624 K 4084 SpotifyWebHelper Spotify Ltd (Verified) Spotify AB
steamwebhelper.exe 12,648 K 1,568 K 4452 Steam Client WebHelper Valve Corporation (Verified) Valve
conhost.exe 2,288 K 732 K 3612 Console Window Host Microsoft Corporation (Verified) Microsoft Windows
wininit.exe 2,112 K 188 K 632
googledrivesync.exe 3,604 K 164 K 4312 (Verified) Google Inc
smss.exe 776 K 84 K 432
System Idle Process 97.38 0 K 24 K 0
Interrupts 0.39 0 K 0 K n/a Hardware Interrupts and DPCs
 
 
 
Image Name                     PID Services                                    
========================= ======== ============================================
System Idle Process              0 N/A                                         
System                           4 N/A                                         
smss.exe                       432 N/A                                         
csrss.exe                      536 N/A                                         
wininit.exe                    632 N/A                                         
csrss.exe                      640 N/A                                         
services.exe                   688 N/A                                         
winlogon.exe                   724 N/A                                         
lsass.exe                      732 KeyIso, SamSs                               
lsm.exe                        744 N/A                                         
svchost.exe                    860 DcomLaunch, PlugPlay, Power                 
NVDisplay.Container.exe        936 NVDisplay.ContainerLocalSystem              
svchost.exe                   1000 RpcEptMapper, RpcSs                         
svchost.exe                    348 AudioSrv, Dhcp, eventlog,                   
                                   HomeGroupProvider, lmhosts, wscsvc          
svchost.exe                    448 AudioEndpointBuilder, CscService, hidserv,  
                                   HomeGroupListener, IPBusEnum, Netman,       
                                   PcaSvc, TrkWks, UxSms, Wlansvc              
svchost.exe                    552 EventSystem, fdPHost, FontCache, netprofm,  
                                   nsi, WdiServiceHost, WinHttpAutoProxySvc    
svchost.exe                    572 AeLookupSvc, Appinfo, BITS, EapHost,        
                                   IKEEXT, iphlpsvc, LanmanServer, MMCSS,      
                                   ProfSvc, Schedule, SENS, ShellHWDetection,  
                                   Themes, Winmgmt, wuauserv                   
svchost.exe                   1044 gpsvc                                       
svchost.exe                   1196 CryptSvc, Dnscache, LanmanWorkstation,      
                                   NlaSvc                                      
AVGSvc.exe                    1304 AVG Antivirus                               
NVDisplay.Container.exe       1436 N/A                                         
spoolsv.exe                   1680 Spooler                                     
svchost.exe                   1740 BFE, DPS, MpsSvc                            
svchost.exe                   1868 DiagTrack                                   
svchost.exe                   1904 FDResPub, SSDPSRV, wcncsvc                  
OriginWebHelperService.ex     1948 Origin Web Helper Service                   
svchost.exe                   2228 stisvc                                      
MBAMService.exe               2288 MBAMService                                 
aswidsagenta.exe              2928 avgbIDSAgent                                
taskhost.exe                  4032 N/A                                         
mbamtray.exe                  4052 N/A                                         
dwm.exe                       3156 N/A                                         
flux.exe                      3876 N/A                                         
WmiPrvSE.exe                  4088 N/A                                         
SpotifyWebHelper.exe          4084 N/A                                         
Steam.exe                     3636 N/A                                         
AVGUI.exe                     4212 N/A                                         
jusched.exe                   4220 N/A                                         
steamwebhelper.exe            4420 N/A                                         
SteamService.exe              4440 Steam Client Service                        
steamwebhelper.exe            4452 N/A                                         
wmpnetwk.exe                  4976 WMPNetworkSvc                               
svchost.exe                   1412 p2pimsvc, p2psvc, PNRPsvc                   
NVIDIA Web Helper.exe         4328 N/A                                         
steamwebhelper.exe            4788 N/A                                         
steamwebhelper.exe            4888 N/A                                         
conhost.exe                   3612 N/A                                         
nvcontainer.exe               3808 NvContainerLocalSystem                      
nvcontainer.exe               5348 N/A                                         
MacriumService.exe            1376 MacriumService                              
NvTelemetryContainer.exe      1640 NvTelemetryContainer                        
googledrivesync.exe           4312 N/A                                         
googledrivesync.exe           5416 N/A                                         
explorer.exe                  2948 N/A                                         
TrustedInstaller.exe          6236 TrustedInstaller                            
chrome.exe                    6448 N/A                                         
chrome.exe                    6528 N/A                                         
chrome.exe                    6268 N/A                                         
chrome.exe                    6888 N/A                                         
chrome.exe                    5960 N/A                                         
chrome.exe                    3024 N/A                                         
chrome.exe                    1316 N/A                                         
chrome.exe                     544 N/A                                         
chrome.exe                    7192 N/A                                         
chrome.exe                    7280 N/A                                         
mscorsvw.exe                  7976 clr_optimization_v4.0.30319_32              
chrome.exe                    8040 N/A                                         
mscorsvw.exe                  8108 clr_optimization_v4.0.30319_64              
taskeng.exe                   2768 N/A                                         
GoogleUpdate.exe              7544 N/A                                         
audiodg.exe                   2828 N/A                                         
cmd.exe                       6348 N/A                                         
conhost.exe                   6536 N/A                                         
tasklist.exe                  7904 N/A                                         
WmiPrvSE.exe                  6868 N/A                                         
 

Hope this is all i need to be given the all clear. As I said before everything seems ok atm but I value your opinion and hope that you can give me the all clear and a possible idea as to what it was that hit me.

Attached Files


  • 0

#11
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,623 posts
  • MVP

Your OCZ-ARC100 SSD shows a bad block. 

 

Get the maintenance program from OCZ:

 

https://ssd.toshiba-...oad/ssd-utility

 

Have it check for firmware updates and run the tuning program.

 

AVG is not all that healthy.  Perhaps a reinstall might be in order or a switch to the free Avast.

 

https://support.avas...-Free-Antivirus

 

Download the program.  Uninstall AVG, reboot then install the program per the instructions on the page.  Avoid optional software and stick with the free (Basic) version and avoid

Free Trials.

 

 

Other than that it looks pretty good.  No sign of an infection.

 

Time to clean up:
If we used FRST to clean your PC:

right click on FRST.exe or FRST64.exe (whichever you used) and rename it to uninstall.exe.  Then right click on uninstall.exe and Run as Admin.

 
If we installed Speccy it needs to be uninstalled.  Process Explorer, VEW, AdwCleaner, JRT  and their logs and Speccy's log can just be deleted.

Also make sure you have the latest versions of any adobe.com products you use like Shockwave, Flash or Acrobat.  Flash is now the most malware targeted program so it must be kept up to date.  Be careful with Adobe.  They are fond of offering optional downloads like yahoo or Ask toolbars or that worthless McAfee Security Scan.  Go slow and uncheck the optional stuff.

Whether you use adobe reader, acrobat or fox-it to read pdf files you need to disable Javascript in the program.  There is an exploit out there now that can use it to get on your PC.  For Adobe Reader:  Start, All Programs, Adobe Reader, Edit, Preferences, Click on Javascript in the left column and uncheck Enable Acrobat Javascript.  OK Close program.  It's the same for Foxit reader except you uncheck Enable Javascript Actions.


If you use Chrome/Firefox/Edge then get the Ublock Origin extension.  For IE go to adblockplus.org  and get the program.
If Chrome/Firefox is slow loading make sure it only has the current Java add-on.  Then download and run Speedy Fox.
http://www.crystalidea.com/speedyfox. Close Chrome/Firefox/Skpe. Hit Optimize.   You can run it any time that Chrome/Firefox seems slow starting..

If you use Facebook you need FB Purity: http://www.fbpurity.com/
To prevent a relatively new phishing attack:  In Firefox, type:

about:config

in the URL box and hit Enter.  You should get a new page of options (if you get a notice about voiding the warranty just cancel the warning).  In the Search box put in

puny

You should only get 2 options:
"network.IDN_show_punycode"
We want it to say True but by default it is False so double click on it to toggle from False to True.
 "network.standard-url.punycode-host" Leave this one at default of Flase.
Close and restart firefox.

To test it you can go to:

https://www.xn--80ak6aa92e.com/

If the value is false you will see https://www.apple.cominstead of the correct value


If you are a Facebook user get the FB Purity extension for your browser:
http://www.fbpurity.com/
This will stop all of the suggested pages and ads so that Facebook loads much quicker.


Be warned:  If you use Limewire, utorrent or any of the other P2P programs you will probably be coming back to the Malware Removal forum.  If you must use P2P then submit any files you get to http://virustotal.combeforeyou open them.

Due to a recent rise in the number of Crytolocker infections I am now recommending you install:

CryptoPrevent
http://www.majorgeek...ptoprevent.html

The free version. When you install it the default is NONE which is kind of worthless so change it to Standard or default. If you have problems after installing CryptoPrevent you can just uninstall it.

If you have a router, log on to it today and change the default password!  If using a Wireless router you really should be using encryption on the link.  Use the strongest (newest) encryption method that your router and PC wireless adapter support especially if you own a business.  See http://www.king5.com...0637284.htmlandhttp://www.seattlepi...ted-1344185.php for why encryption is important.  If you don't know how, visit the router maker's website.  They all have detailed step by step instructions or a wizard you can download.

Special note on Java.  Old Java versions should be removed after first clearing the Java Cache by following the instructions in:
http://www.java.com/...lugin_cache.xml
Then remove the old versions by going to Control Panel, Programs and Features and Uninstall all Java programs which are not Java Version 7 update 25 or better.  These may call themselves: Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, J2RE, J2SE.  Get the latest version from Java.com.  They will usually attempt to foist some garbage like the Ask toolbar, Yahoo toolbar or McAfee Security Scan on you as part of the download.  Just uncheck the garbage before the download (or install) starts.  If you use a 64-bit browser and want the 64-bit version of Java you need to use it to visit java.com.
Due to multiple security problems with Java we are now recommending that it not be installed unless you absolutely know you need it.  IF that is the case then go to Control Panel, Java, Security and slide it up to the highest level.  OK.


Recommended software: (I'm not saying you should download these just that if you have a need for a new program these are safe and work)  
Compression:  7-zip.  Avoid WinRar and WinZip as the free versions have adware.
Video Player:  VLC  Unlike Windows Medi Player it never seems to need extra files to work.
Photo organizer and editor:  Google's Picasa.  While it has been discontinued by Google you can still get it at:
http://techfilehippo...-free-download/
Office like free program:  Open Office: https://www.openoffice.org/download/
or
LibreOffice: https://www.libreoffice.org/
Free Anti-Virus:  Avast
Free Malware prevention:  MBAM: Free version at https://www.malwareb...m/mwb-download/
Can run with your anti-virus.
Paid Anti-Virus:  Kaspersky or BitDefender
Utilities:
Root Kit Detector:  MBAR: https://www.malwareb...om/antirootkit/
Process Explorer:  Show you what is running on the PC.  Like Task manager but better:  http://live.sysinter...com/procexp.exe
WhoCrashed: Why did your system crash?
http://www.resplendence.com/downloads
Then click on Download free home edition
where it says:
WhoCrashed 5.51
Comprehensible crash dump analysis tool
for Windows 10/8.1/8/7/Vista/XP/2012/2008/2003 (x86 and x64)
System Health:
Speccy:  
http://www.filehippo.com/download_speccy (Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  Decline CCleaner if offered.  Pay attention to SMART info on your hard drives and to temps.  If in doubt about temps try:
SpeedFan:  Try speedfan
http://www.filehippo...nload_speedfan/
Download, save and Install it (Win 7 or Vista right click and Run As Admin.) then run it.
Download Flash and Video.  To save flash video.  Works with Firefox.  https://addons.mozil...lash-and-video/This allows you to start a recording and then switch to a different window and record another video.

With Win 10 only there is a new Game recorder program.  It's supposed to only work for games but it works nicely to record any video you watch.  Hit the Win key + Alt + r to start the recorder.  The first time it asks you if it is looking at a game.  Just tell it yes.  After that it starts recording whenever you bring it up.  Videos are saved to the Captures folder under Videos.  You can only record what you watch so limited to only one video at a time.  Best to go to full screen before starting the recorder.

Avoid:  
Advanced System Care
SuperAntiSpyware
HitmanPro
Spybot S&D
Any P2P software especially if it comes from Conduit.
Registry Cleaners
Driver updating software.
PC fixing or Speed up software.
Running more than one anti-virus.
Seagate hard drives.  If you have one it's going to fail on you so backup your data now!

 


  • 1

#12
grdsproblem

grdsproblem

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Thank you for all your help. I had basically thought about trying to get a fresh install and lose all my programs, but your sound advice saved me.

I only installed AVG as a stopgap as when you told me to uninstall Avira I did not wish to leave myself with no AV. I have Avast on my missus comp but really didn't like the look of it lol. Now I know that looks aren't everything in computer terms as well as real life lol. Ps I never would have thought of just loading basic items before but it really makes a difference. Most times I do go for a custom install and do notice the tickboxes for add-ons but thought that having Unchecky would solve that (obviously not foolproof)

I just love Ublock Origin and fbpurity. So few ads, so much more chance of catching up with what everyone is really doing instead of what stupid quiz or game they are playing.

My internet and router privacy is always important to me so I always change my default password as standard lol. It only causes me problems when I finally forget it but I try to keep everything in a password manager to get around this.

 

I use TamperMonkey to use Java on certain websites. Is it safe to remove all Java from my computer if I use this, and if I do find a problem do I just need to install as required?

 

Thanks for the list of safe programs and unsafe ones. Ps why does HitmanPro get a bad rep?

 

As I have said before, I really appreciate all the help you have given me and I'm really glad that you and others like you have this ability and want to help others like myself

 

Ps For some reason your previous reply did not hit my inbox so that is why it took so long for me to reply


  • 0

#13
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,623 posts
  • MVP

Personally I prefer the free Avast http://www.avast.com...ivirus-downloadto AVG.   (I think I read somewhere that Avast bought up AVG recently so there probably won't be much difference in the future.)  Avast seems to be a bit better plus they have a boot-time scan that it one of the best.  If you feel you need a firewall then the free Online Armor http://www.online-ar...-armor-free.php can be used with Avast.  IF you try Avast:  Some people object to the voice notification of updates.  To turn it off, click on the Avast ball then on Settings.  Then on Sounds and uncheck Automatic Updates OK.  (It will still update it just won't tell you about in a loud voice in the middle of the night.)

They have also started using their info popup to try and get you to upgrade so I go into Settings, Popups and change the first two to 1 second.

The registration is good for 12-14 months then you will need to register again.  They will, of course, try to talk you into buying the product but you can always register again for another year free.  As before look for the Basic or Free option.  (It won't be the default).


To use their boot-time scan:
Click on the Avast ball.  Then click on Protection, then on Antivirus, then on Other Scans then on Boot-time Scan.  Click on Install Special Definitions.  Click on Run on Next PC Reboot.

When you reboot you will see the scan start.  It will tell you where it saves its log.  Usually it's C:\ProgramData\AVAST Software\Avast\report\aswBoot.txt but it might change so verify the location.   This is a hidden location so you will need to tell Windows to let you see it:

http://www.howtogeek...-windows-vista/

Copy and paste the text from the log to a Reply when done.
 

 

You can reinstall Java if you find a site that absolutely requires it but make sure you get it from java.com and not from some link the site gives you. Such sites are becoming very rare these days.

 

why does HitmanPro get a bad rep

 

It sometimes removes malware incorrectly and leaves a system unbootable.  We see a lot of systems like that in our

Computer Won't Boot - Malware Related forum.


  • 0

#14
grdsproblem

grdsproblem

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Avast Boot time scan results
 
07/18/2018 15:05
Scan of C:
 
Scan of *STARTUP
 
File C:\Program Files (x86)\Java\jre1.8.0_171\lib\ext\access-bridge-32.jar|>com\sun\java\accessibility\AccessBridge$134.class Error 42125 {ZIP archive is corrupted.}
Number of searched folders: 40756
Number of tested files: 1143240
Number of infected files: 0

  • 0

#15
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,623 posts
  • MVP

Looks good.  If you still have Java, remove the file:

C:\Program Files (x86)\Java\jre1.8.0_171\lib\ext\access-bridge-32.jar

 

IF there are no other problems I think we can cleanup:

 

Time to clean up:
If we used FRST to clean your PC:

right click on FRST.exe or FRST64.exe (whichever you used) and rename it to uninstall.exe.  Then right click on uninstall.exe and Run as Admin.

 
If we installed Speccy it needs to be uninstalled.  Process Explorer, VEW, AdwCleaner, JRT  and their logs and Speccy's log can just be deleted.

Also make sure you have the latest versions of any adobe.com products you use like Shockwave, Flash or Acrobat.  Flash is now the most malware targeted program so it must be kept up to date.  Be careful with Adobe.  They are fond of offering optional downloads like yahoo or Ask toolbars or that worthless McAfee Security Scan.  Go slow and uncheck the optional stuff.

Whether you use adobe reader, acrobat or fox-it to read pdf files you need to disable Javascript in the program.  There is an exploit out there now that can use it to get on your PC.  For Adobe Reader:  Start, All Programs, Adobe Reader, Edit, Preferences, Click on Javascript in the left column and uncheck Enable Acrobat Javascript.  OK Close program.  It's the same for Foxit reader except you uncheck Enable Javascript Actions.


If you use Chrome/Firefox/Edge then get the Ublock Origin extension.  For IE go to adblockplus.org  and get the program.
If Chrome/Firefox is slow loading make sure it only has the current Java add-on.  Then download and run Speedy Fox.
http://www.crystalidea.com/speedyfox. Close Chrome/Firefox/Skpe. Hit Optimize.   You can run it any time that Chrome/Firefox seems slow starting..

If you use Facebook you need FB Purity: http://www.fbpurity.com/
To prevent a relatively new phishing attack:  In Firefox, type:

about:config

in the URL box and hit Enter.  You should get a new page of options (if you get a notice about voiding the warranty just cancel the warning).  In the Search box put in

puny

You should only get 2 options:
"network.IDN_show_punycode"
We want it to say True but by default it is False so double click on it to toggle from False to True.
 "network.standard-url.punycode-host" Leave this one at default of Flase.
Close and restart firefox.

To test it you can go to:

https://www.xn--80ak6aa92e.com/

If the value is false you will see https://www.apple.cominstead of the correct value


If you are a Facebook user get the FB Purity extension for your browser:
http://www.fbpurity.com/
This will stop all of the suggested pages and ads so that Facebook loads much quicker.


Be warned:  If you use Limewire, utorrent or any of the other P2P programs you will probably be coming back to the Malware Removal forum.  If you must use P2P then submit any files you get to http://virustotal.combeforeyou open them.

Due to a recent rise in the number of Crytolocker infections I am now recommending you install:

CryptoPrevent
http://www.majorgeek...ptoprevent.html

The free version. When you install it the default is NONE which is kind of worthless so change it to Standard or default. If you have problems after installing CryptoPrevent you can just uninstall it.

If you have a router, log on to it today and change the default password!  If using a Wireless router you really should be using encryption on the link.  Use the strongest (newest) encryption method that your router and PC wireless adapter support especially if you own a business.  See http://www.king5.com...0637284.htmlandhttp://www.seattlepi...ted-1344185.php for why encryption is important.  If you don't know how, visit the router maker's website.  They all have detailed step by step instructions or a wizard you can download.

Special note on Java.  Old Java versions should be removed after first clearing the Java Cache by following the instructions in:
http://www.java.com/...lugin_cache.xml
Then remove the old versions by going to Control Panel, Programs and Features and Uninstall all Java programs which are not Java Version 7 update 25 or better.  These may call themselves: Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, J2RE, J2SE.  Get the latest version from Java.com.  They will usually attempt to foist some garbage like the Ask toolbar, Yahoo toolbar or McAfee Security Scan on you as part of the download.  Just uncheck the garbage before the download (or install) starts.  If you use a 64-bit browser and want the 64-bit version of Java you need to use it to visit java.com.
Due to multiple security problems with Java we are now recommending that it not be installed unless you absolutely know you need it.  IF that is the case then go to Control Panel, Java, Security and slide it up to the highest level.  OK.


Recommended software: (I'm not saying you should download these just that if you have a need for a new program these are safe and work)  
Compression:  7-zip.  Avoid WinRar and WinZip as the free versions have adware.
Video Player:  VLC  Unlike Windows Medi Player it never seems to need extra files to work.
Photo organizer and editor:  Google's Picasa.  While it has been discontinued by Google you can still get it at:
http://techfilehippo...-free-download/
Office like free program:  Open Office: https://www.openoffice.org/download/
or
LibreOffice: https://www.libreoffice.org/
Free Anti-Virus:  Avast
Free Malware prevention:  MBAM: Free version at https://www.malwareb...m/mwb-download/
Can run with your anti-virus.
Paid Anti-Virus:  Kaspersky or BitDefender
Utilities:
Root Kit Detector:  MBAR: https://www.malwareb...om/antirootkit/
Process Explorer:  Show you what is running on the PC.  Like Task manager but better:  http://live.sysinter...com/procexp.exe
WhoCrashed: Why did your system crash?
http://www.resplendence.com/downloads
Then click on Download free home edition
where it says:
WhoCrashed 5.51
Comprehensible crash dump analysis tool
for Windows 10/8.1/8/7/Vista/XP/2012/2008/2003 (x86 and x64)
System Health:
Speccy:  
http://www.filehippo.com/download_speccy (Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  Decline CCleaner if offered.  Pay attention to SMART info on your hard drives and to temps.  If in doubt about temps try:
SpeedFan:  Try speedfan
http://www.filehippo...nload_speedfan/
Download, save and Install it (Win 7 or Vista right click and Run As Admin.) then run it.
Download Flash and Video.  To save flash video.  Works with Firefox.  https://addons.mozil...lash-and-video/This allows you to start a recording and then switch to a different window and record another video.

With Win 10 only there is a new Game recorder program.  It's supposed to only work for games but it works nicely to record any video you watch.  Hit the Win key + Alt + r to start the recorder.  The first time it asks you if it is looking at a game.  Just tell it yes.  After that it starts recording whenever you bring it up.  Videos are saved to the Captures folder under Videos.  You can only record what you watch so limited to only one video at a time.  Best to go to full screen before starting the recorder.

Avoid:  
Advanced System Care
SuperAntiSpyware
HitmanPro
Spybot S&D
Any P2P software especially if it comes from Conduit.
Registry Cleaners
Driver updating software.
PC fixing or Speed up software.
Running more than one anti-virus.
Seagate hard drives.  If you have one it's going to fail on you so backup your data now!
 


  • 1






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP