USB Shortcut Malware, Malwarebytes can't detect

I currently have a problem with my computer whenever I try to attach a USB drive into it.

Everytime I plug any USB drive into the computer, a "shortcut" appears instead of the files in it. Fortunately, I was able to recover the files with AutoRunExterminator.


I tried scanning with MalwareBytes, and it couldn't detect the malware. I also tried other solutions on the internet which did not work. I need help, thanks!


Here are the FRST logs:


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23.08.2018
Ran by server (administrator) on SERVER-PC (27-08-2018 09:07:15)
Running from C:\Users\server\Downloads
Loaded Profiles: server (Available Profiles: server)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Popcorn Time) C:\Program Files (x86)\Popcorn Time\Updater.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Bluebeam Software, Inc.) C:\Program Files\Common Files\Bluebeam Software\Bluebeam Revu\Brewery\V45\Printer Support\BBPrint.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Tweaking.com) E:\repair tools\windows_repair\WR_Tray_Icon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\server\Downloads\FRST64(1).exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11905128 2011-06-28] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297272 2017-12-11] (Apple Inc.)
HKLM\...\Run: [BbInstallUser] => C:\Program Files\Bluebeam Software\Bluebeam Revu\Pushbutton PDF\Bluebeam Admin User.exe [48696 2014-02-21] (Bluebeam Software, Inc.)
HKLM\...\Run: [BbPrintMonitor] => C:\Program Files\Common Files\Bluebeam Software\Bluebeam Revu\Brewery\V45\Printer Support\BBPrint.exe [211000 2014-02-21] (Bluebeam Software, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [919008 2012-07-28] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM-x32\...\Run: [AirBackupHelper] => D:\AnyTrans\AnyTrans\AirBackupHelper.exe [2445792 2018-01-03] (iMobie Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1001631739-621710209-3946131499-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2014-09-10] (Google Inc.)
HKU\S-1-5-21-1001631739-621710209-3946131499-1000\...\Run: [AVG-Secure-Search-Update_1114av] => C:\Users\server\AppData\Roaming\Avg_Update_1114av\AVG-Secure-Search-Update_1114av.exe /PROMPT /mid=d12b04026ece47d284dbc593af508105-bcb8af8a3cd61613982ae7bfd0a367c3c44e513e /CMPID=1114av
HKU\S-1-5-21-1001631739-621710209-3946131499-1000\...\Run: [AVG-Secure-Search-Update_1214av] => C:\Users\server\AppData\Roaming\Avg_Update_1214av\AVG-Secure-Search-Update_1214av.exe /PROMPT /mid=d12b04026ece47d284dbc593af508105-bcb8af8a3cd61613982ae7bfd0a367c3c44e513e /CMPID=1214av
HKU\S-1-5-21-1001631739-621710209-3946131499-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-10] (Skype Technologies S.A.)
HKU\S-1-5-21-1001631739-621710209-3946131499-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1001631739-621710209-3946131499-1000\...\MountPoints2: {15259624-7105-11e5-aea0-14dae9b468f6} - G:\bootstrap.exe
HKU\S-1-5-21-1001631739-621710209-3946131499-1000\...\MountPoints2: {15259631-7105-11e5-aea0-14dae9b468f6} - G:\bootstrap.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk [2017-06-29]
ShortcutTarget: AutoCAD Startup Accelerator.lnk -> C:\Program Files (x86)\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc)
Startup: C:\Users\server\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a.lnk [2018-07-09]
ShortcutTarget: a.lnk -> C:\Users\server\AppData\Roaming\eekCe9b6Vx.exe (SunSecurity Soft)
Startup: C:\Users\server\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\j.lnk [2016-10-17]
ShortcutTarget: j.lnk -> C:\Users\server\AppData\Roaming\obdyvnrkjc.exe (No File)
GroupPolicy: Restriction ? <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{C3BB5AD5-6497-4B6B-BAAF-4AE08C361982}: [DhcpNameServer]

Internet Explorer:
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_151\bin\ssv.dll [2017-10-20] (Oracle Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-10-15] (Google Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-20] (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-28] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-10-15] (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-10-15] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-10-15] (Google Inc.)
Toolbar: HKU\S-1-5-21-1001631739-621710209-3946131499-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-10-15] (Google Inc.)

FF DefaultProfile: 2mp3zi6r.default
FF ProfilePath: C:\Users\server\AppData\Roaming\Mozilla\Firefox\Profiles\2mp3zi6r.default [2018-08-27]
FF Homepage: Mozilla\Firefox\Profiles\2mp3zi6r.default -> hxxps://www.google.com.ph/
FF Extension: (Adblock Plus) - C:\Users\server\AppData\Roaming\Mozilla\Firefox\Profiles\2mp3zi6r.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-07-18]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_101.dll [2018-08-22] ()
FF Plugin: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-20] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_101.dll [2018-08-22] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-07-28] (Adobe Systems Inc.)

CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxp://www.google.com.ph/?gfe_rd=cr&ei=vgUQVJGJJ-yV8Qfc24CoCw"
CHR Profile: C:\Users\server\AppData\Local\Google\Chrome\User Data\Default [2018-08-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\server\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (Chrome Media Router) - C:\Users\server\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-08-15]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-11-27] (Apple Inc.)
S3 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [77944 2017-06-29] (Autodesk)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2016-08-26] (Popcorn Time) [File not signed]
S3 uSHAREitSvc; C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe [33224 2017-09-11] (SHAREit Technologies Co.Ltd)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [269408 2018-02-21] (Bluestack System Inc. )
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-08-27] (Malwarebytes)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-08-27 09:06 - 2018-08-27 09:06 - 002413056 _____ (Farbar) C:\Users\server\Downloads\FRST64(1).exe
2018-08-27 09:06 - 2018-08-27 09:06 - 000000000 ____D C:\Users\server\Downloads\FRST-OlderVersion
2018-08-15 08:17 - 2018-08-15 08:44 - 000364544 _____ C:\Users\server\Documents\Database1.accdb
2018-08-15 07:22 - 2018-08-15 08:44 - 000356352 _____ C:\Users\server\Documents\Classic Savory Restaurant 3.accdb
2018-08-15 07:18 - 2018-08-15 08:44 - 000565248 _____ C:\Users\server\Documents\Classic Savory Restaurant 2.accdb
2018-08-15 07:08 - 2018-08-15 08:44 - 000425984 _____ C:\Users\server\Documents\Classic Savory Restaurant.accdb
2018-08-15 07:02 - 2018-08-15 07:07 - 000376832 _____ C:\Users\server\Documents\Classic Savory Restaurant inventory.accdb
2018-08-15 04:25 - 2018-08-15 07:17 - 000339968 _____ C:\Users\server\Documents\Classic Savory Food Ingredients Inventory.accdb
2018-08-15 04:20 - 2018-08-15 06:05 - 000819200 _____ C:\Users\server\Downloads\Inventory Access_Mark Joseph Cruz.accdb
2018-08-13 18:00 - 2018-08-13 18:01 - 000031906 _____ C:\Users\server\Downloads\Addition.txt
2018-08-13 17:58 - 2018-08-27 09:07 - 000012436 _____ C:\Users\server\Downloads\FRST.txt
2018-08-13 17:58 - 2018-08-27 09:07 - 000000000 ____D C:\FRST
2018-08-13 17:58 - 2018-08-27 09:06 - 002413056 _____ (Farbar) C:\Users\server\Downloads\FRST64.exe
2018-08-12 22:26 - 2018-08-27 08:33 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-08-12 22:26 - 2018-08-12 22:26 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-08-12 22:26 - 2018-08-12 22:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-08-12 22:26 - 2018-06-19 14:09 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-08-12 22:17 - 2018-08-12 22:21 - 078989872 _____ (Malwarebytes ) C:\Users\server\Downloads\mb3-setup-consumer-
2018-08-12 22:10 - 2018-08-12 22:10 - 000017028 _____ C:\Users\server\Downloads\autorunexterminator-1.8.zip
2018-08-05 05:06 - 2018-08-05 05:07 - 000888931 _____ C:\Users\server\Downloads\aph-journals (1).xlsx
2018-08-05 05:05 - 2018-08-05 05:06 - 000888931 _____ C:\Users\server\Downloads\aph-journals.xlsx

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-08-27 08:57 - 2016-12-13 08:22 - 000000000 ____D C:\Users\server\AppData\LocalLow\Mozilla
2018-08-27 08:57 - 2009-07-14 13:13 - 000006234 _____ C:\Windows\system32\PerfStringBackup.INI
2018-08-27 08:38 - 2009-07-14 12:45 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-08-27 08:38 - 2009-07-14 12:45 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-08-27 08:36 - 2014-09-10 14:26 - 000000000 ____D C:\Users\server\AppData\Roaming\Skype
2018-08-27 08:32 - 2009-07-14 13:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-08-26 20:34 - 2017-06-25 18:25 - 000000000 ____D C:\Program Files (x86)\Steam
2018-08-24 17:53 - 2017-07-20 17:24 - 000001350 _____ C:\Users\server\Desktop\Roblox Player.lnk
2018-08-24 17:53 - 2017-07-20 17:19 - 000001169 _____ C:\Users\server\Desktop\u wot m8.lnk
2018-08-24 17:53 - 2017-07-20 17:19 - 000000000 ____D C:\Users\server\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2018-08-22 20:03 - 2017-02-27 19:55 - 000000000 ____D C:\Users\server\Desktop\lyka
2018-08-22 17:11 - 2018-03-03 20:53 - 000004324 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-08-22 17:11 - 2014-09-10 14:25 - 000846848 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-08-22 17:11 - 2014-09-10 14:25 - 000175616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-08-22 17:11 - 2014-09-10 14:25 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-08-22 17:11 - 2014-09-10 14:25 - 000000000 ____D C:\Windows\system32\Macromed
2018-08-21 16:38 - 2017-01-01 10:15 - 000000000 ____D C:\Users\server\Desktop\sean
2018-08-21 14:59 - 2014-09-10 13:21 - 000000000 ____D C:\Users\server
2018-08-21 10:25 - 2017-07-29 21:15 - 000000000 ____D C:\Users\server\AppData\Roaming\vlc
2018-08-21 09:36 - 2017-08-20 22:21 - 000000000 ____D C:\Users\server\Desktop\axl
2018-08-21 09:36 - 2017-06-25 20:22 - 000000000 ____D C:\Users\server\Desktop\PDF
2018-08-18 20:26 - 2015-05-25 16:39 - 000000000 ____D C:\Users\server\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2018-08-18 08:29 - 2018-06-23 17:34 - 000000000 ____D C:\Users\server\AppData\Local\osu!
2018-08-16 19:35 - 2017-07-28 14:37 - 000000000 ____D C:\Users\server\Documents\Bandicam
2018-08-15 08:01 - 2017-09-29 06:55 - 000004478 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-08-15 04:25 - 2017-10-27 04:30 - 000299008 _____ C:\Users\server\Documents\Inventory System.accdb
2018-08-12 22:26 - 2016-10-17 15:01 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-08-12 09:24 - 2009-07-14 13:08 - 000032568 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-08-10 18:59 - 2014-09-10 13:57 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-08-10 18:59 - 2014-09-10 13:57 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-08-10 12:55 - 2017-06-25 18:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-08-10 12:55 - 2016-10-17 15:42 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-08-07 08:45 - 2017-07-02 09:12 - 000001511 _____ C:\Users\server\Desktop\SPG URL.txt

==================== Files in the root of some directories =======

2018-07-09 09:17 - 2018-07-09 09:17 - 090293376 __RSH (SunSecurity Soft) C:\Users\server\AppData\Roaming\eekCe9b6Vx.exe
2018-08-12 22:11 - 2018-08-27 09:05 - 000073123 _____ () C:\Users\server\AppData\Roaming\ICARE.LOG
2018-01-19 08:21 - 2018-01-19 08:21 - 000000000 ____H () C:\Users\server\AppData\Local\BITBF1B.tmp
2017-07-24 19:01 - 2017-07-24 19:01 - 000003584 _____ () C:\Users\server\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-01-19 08:21 - 2018-01-19 08:21 - 000000000 _____ () C:\Users\server\AppData\Local\{698E78A7-D9ED-45C7-9358-44A62538F81D}

Some files in TEMP:
2013-08-05 14:15 - 2013-08-05 14:15 - 004292136 _____ (www.Bandisoft.com) C:\Users\server\AppData\Local\Temp\bdfilters.dll
2018-03-03 16:07 - 2018-01-10 07:00 - 000969272 _____ (BlueStack Systems, Inc.) C:\Users\server\AppData\Local\Temp\BlueStacksClientUninstaller.exe
2018-07-09 09:17 - 2010-11-21 11:24 - 000805376 _____ (Microsoft Corporation) C:\Users\server\AppData\Local\Temp\cdo2253208388.dll
2015-09-04 05:26 - 2010-11-21 11:24 - 000805376 _____ (Microsoft Corporation) C:\Users\server\AppData\Local\Temp\cdo3309711686.dll
2016-10-15 19:49 - 2010-11-21 11:24 - 000805376 _____ (Microsoft Corporation) C:\Users\server\AppData\Local\Temp\cdo342282706.dll
2014-03-20 14:44 - 2014-03-20 14:44 - 000026936 _____ (TuneUp Software) C:\Users\server\AppData\Local\Temp\DseShExt-x64.dll
2014-03-20 14:44 - 2014-03-20 14:44 - 000028984 _____ (TuneUp Software) C:\Users\server\AppData\Local\Temp\DseShExt-x86.dll
2018-03-03 16:07 - 2018-01-10 06:59 - 000421400 _____ (CodeTitans) C:\Users\server\AppData\Local\Temp\JSON.dll
2016-10-07 08:33 - 2016-10-07 08:33 - 002458672 _____ (The OpenSSL Project, http://www.openssl.org/)C:\Users\server\AppData\Local\Temp\libeay32.dll
2016-10-07 08:33 - 2016-10-07 08:33 - 000970912 _____ (Microsoft Corporation) C:\Users\server\AppData\Local\Temp\msvcr120.dll
2016-04-28 17:06 - 2016-04-28 17:06 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s1ss.dll
2017-07-16 07:12 - 2017-07-16 07:12 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s2eg.dll
2017-07-16 07:12 - 2017-07-16 07:12 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s2nk.dll
2017-01-01 23:24 - 2017-01-01 23:24 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s2og.dll
2017-01-01 23:23 - 2017-01-01 23:23 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s340.dll
2016-04-28 16:23 - 2016-04-28 16:23 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s36c.dll
2016-04-28 16:38 - 2016-04-28 16:38 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s3mg.dll
2016-04-30 14:33 - 2016-04-30 14:33 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s3ss.dll
2016-04-28 17:05 - 2016-04-28 17:05 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s474.dll
2016-04-28 16:37 - 2016-04-28 16:37 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s48g.dll
2016-04-30 14:34 - 2016-04-30 14:34 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s4d0.dll
2016-04-28 17:05 - 2016-04-28 17:05 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s4l8.dll
2016-04-28 16:21 - 2016-04-28 16:21 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s4ok.dll
2017-11-25 18:50 - 2017-11-25 18:50 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_s4ss.dll
2016-04-28 16:33 - 2016-04-28 16:33 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_sgk.dll
2016-04-28 16:27 - 2016-04-28 16:27 - 000072704 _____ () C:\Users\server\AppData\Local\Temp\rldfw32_slc.dll
2016-06-05 19:41 - 2016-06-05 19:41 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s22k.dll
2016-06-05 19:44 - 2016-06-05 19:44 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s2l4.dll
2017-01-01 23:25 - 2017-01-01 23:25 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s3eg.dll
2016-04-28 16:57 - 2016-04-28 16:57 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s3i4.dll
2016-04-30 14:35 - 2016-04-30 14:35 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s3qo.dll
2017-11-25 18:50 - 2017-11-25 18:50 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4ao.dll
2016-04-28 16:50 - 2016-04-28 16:50 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4do.dll
2016-06-08 13:11 - 2016-06-08 13:11 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4e8.dll
2017-01-02 21:41 - 2017-01-02 21:41 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4eo.dll
2016-04-30 14:44 - 2016-04-30 14:44 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4g0.dll
2016-06-06 17:02 - 2016-06-06 17:02 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4ks.dll
2016-06-05 19:40 - 2016-06-05 19:40 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4lk.dll
2016-04-28 17:02 - 2016-04-28 17:02 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4ms.dll
2016-04-28 16:41 - 2016-04-28 16:41 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4ok.dll
2016-06-05 19:37 - 2016-06-05 19:37 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4q0.dll
2016-04-28 17:05 - 2016-04-28 17:05 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4tc.dll
2016-04-28 17:01 - 2016-04-28 17:01 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_s4uc.dll
2016-04-28 16:39 - 2016-04-28 16:39 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_seg.dll
2016-04-28 16:35 - 2016-04-28 16:35 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_sf0.dll
2016-06-05 19:43 - 2016-06-05 19:43 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_sg4.dll
2016-06-07 15:26 - 2016-06-07 15:26 - 000084992 _____ () C:\Users\server\AppData\Local\Temp\rldfw64_sqg.dll
2014-03-20 14:44 - 2014-03-20 14:44 - 000032568 _____ (TuneUp Software) C:\Users\server\AppData\Local\Temp\SDShelEx-win32.dll
2014-03-20 14:44 - 2014-03-20 14:44 - 000032056 _____ (TuneUp Software) C:\Users\server\AppData\Local\Temp\SDShelEx-x64.dll
2018-07-20 10:43 - 2018-08-12 22:36 - 000192512 _____ () C:\Users\server\AppData\Local\Temp\sfamcc00001.dll
2015-02-11 01:56 - 2015-02-11 01:56 - 000105984 _____ () C:\Users\server\AppData\Local\Temp\sfextra.dll
2016-10-07 08:33 - 2016-10-07 08:33 - 000772672 _____ () C:\Users\server\AppData\Local\Temp\sqlite3.dll
2017-06-26 07:17 - 2017-06-26 07:17 - 014456872 _____ (Microsoft Corporation) C:\Users\server\AppData\Local\Temp\vc_redist.x86.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-08-16 10:30

==================== End of FRST.txt ============================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23.08.2018
Ran by server (27-08-2018 09:08:04)
Running from C:\Users\server\Downloads
Windows 7 Ultimate Service Pack 1 (X64) (2014-09-10 05:21:23)
Boot Mode: Normal

==================== Accounts: =============================

Administrator (S-1-5-21-1001631739-621710209-3946131499-500 - Administrator - Disabled)
Guest (S-1-5-21-1001631739-621710209-3946131499-501 - Limited - Enabled)
server (S-1-5-21-1001631739-621710209-3946131499-1000 - Administrator - Enabled) => C:\Users\server

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 30 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Reader X (10.1.4) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.4 - Adobe Systems Incorporated)
AnyTrans (HKLM-x32\...\AnyTrans) (Version: - iMobie Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{BC7C46A4-D7A7-48EC-A98C-32A7762B5EFA}) (Version: 6.2.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{F0C4B709-8BF4-4A72-B527-12E7BF5482F8}) (Version: 6.2.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BD6778C5-6FA5-492A-ADD6-E706339C2A7B}) (Version: - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: - Apple Inc.)
Assassin's Creed III version 1.06 (HKLM-x32\...\Assassin's Creed III_is1) (Version: 1.06 - Ubisoft)
AutoCAD 2007 - English (HKLM-x32\...\{5783F2D7-5001-0409-0002-0060B0CE6BBA}) (Version: - Autodesk)
Autodesk DWF Viewer (HKLM-x32\...\Autodesk DWF Viewer) (Version: 6.5 - Autodesk, Inc.)
Bandicam (HKLM-x32\...\Bandicam) (Version: - Bandisoft.com)
Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version:  - Bandisoft.com)
BbeXtreme (HKLM-x32\...\{E15A3E1F-9066-4B1E-B85F-BC89443B2905}) (Version: 12.0.0 - Bluebeam Software) Hidden
Bigasoft Total Video Converter (HKLM-x32\...\{A72CE741-1F32-4D79-BFFB-A714375C678D}_is1) (Version:  - Bigasoft Corporation)
Bluebeam Revu x64 12 (HKLM\...\{A8E3F673-82B9-4AF0-97C7-4DEDA7042E5E}) (Version: 12.0.0 - Bluebeam Software) Hidden
Bluebeam Revu x64 12 (HKLM-x32\...\InstallShield_{A8E3F673-82B9-4AF0-97C7-4DEDA7042E5E}) (Version: 12.0.0 - Bluebeam Software)
BlueStacks App Player (HKLM-x32\...\BlueStacks) (Version: - BlueStack Systems, Inc.)
Cuphead (HKLM-x32\...\1963513391_is1) (Version: 20170929 - GOG.com)
Garlium version 156f162984c0ee7717d11f703613776363bec359 (HKLM-x32\...\{39298325-1AE0-4C6C-A61F-31911712601C}_is1) (Version: 156f162984c0ee7717d11f703613776363bec359 - Ske)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 68.0.3440.106 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: - Google Inc.) Hidden
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
iTunes (HKLM\...\{D7D4465C-B3B6-4BC1-B336-2803FB57BFAF}) (Version: - Apple Inc.)
Java 8 Update 151 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
Jobber Computer Plus v3.4 version (HKLM-x32\...\{79541A5E-BFDD-4A44-B41E-A6DFD631A287}_is1) (Version: - Jobber Instruments)
Macromedia Flash Player 8 (HKLM-x32\...\ShockwaveFlash) (Version: 8 - Macromedia)
Malwarebytes version (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mozilla Firefox 61.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 61.0.2 (x64 en-US)) (Version: 61.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: - Mozilla)
OldSchool RuneScape Launcher 1.2.7 (HKLM-x32\...\{FEDDCE73-34B8-4980-90B8-8619A78C902C}) (Version: 1.2.7 - Jagex Ltd)
osu! (HKLM-x32\...\{1c153b98-46f5-4932-996e-1bf5fd031308}) (Version: latest - ppy Pty Ltd)
PDF Settings CS6 (HKLM-x32\...\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.5.2 - pdfforge GmbH)
Popcorn Time (HKLM-x32\...\Popcorn Time_is1) (Version: - Popcorn Time) <==== ATTENTION
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.46.610.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Roblox Player for server (HKU\S-1-5-21-1001631739-621710209-3946131499-1000\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - Roblox Corporation)
R-Studio 8.0 (HKLM-x32\...\R-Studio 8.0NSIS) (Version: 8.0.164761 - R-Tools Technology Inc.)
RuneScape Launcher 2.2.4 (HKLM\...\RuneScape Launcher_is1) (Version: 2.2.4 - Jagex Ltd)
SHAREit (HKLM-x32\...\www.ushareit.com_is1) (Version: - SHAREit Technologies Co.Ltd)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.104 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
Tekla Structures  Multiuser Server (HKLM-x32\...\{93D60FA3-DF71-4ECA-8D0F-06DB0F9BED39}) (Version: 2.3 - Tekla Corporation)
Tekla Structures 17.0 Common Env (Required) (HKLM-x32\...\{972ECF76-B4B7-474F-A93A-64BA0CD1A097}) (Version: - Tekla Corporation)
Tekla Structures 17.0 Software (HKLM-x32\...\{3ABA49B3-7BC9-4722-9F72-F7E95A586C88}) (Version: - Tekla Corporation)
Tekla Structures 17.0 US imperial Env (HKLM-x32\...\{9EC2C546-C604-424C-86F7-60A03976175B}) (Version: - Tekla Corporation)
Tekla Structures 17.0 US metric Env (HKLM-x32\...\{8616A81A-1D90-4125-8B38-E181967B1452}) (Version: - Tekla Corporation)
Tekla Structures 19.0 Default Env (HKLM-x32\...\{3C186B69-5E22-4836-8A24-80E623EF82A2}) (Version: - Tekla Corporation)
Tekla Structures 19.0 US imperial Env (HKLM-x32\...\{FDD23A7D-BD5E-4AB2-A74C-E6261ACB915F}) (Version: - Tekla Corporation)
Tekla Structures 19.0 US metric Env (HKLM-x32\...\{334FC5A2-F606-45F4-A176-E58CBAA6B373}) (Version: - Tekla Corporation)
Tekla Structures 19.0 x64 Software (HKLM\...\{8CDB2D79-6062-441D-A130-971C6EF8110C}) (Version: - Tekla Corporation)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.0.23 - Tweaking.com)
Vegas Pro 13.0 (64-bit) (HKLM\...\{1EEE0BEE-0BC8-11E5-A19E-F04DA23A5C58}) (Version: 13.0.453 - Sony)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
WinZip 15.0 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}) (Version: 15.0.9334 - WinZip Computing, S.L. )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers-x32-x32: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\SysWOW64\AcSignIcon.dll [2016-05-01] (Autodesk)
ContextMenuHandlers1-x32: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files (x86)\Common Files\Autodesk shared\dwf common\DWFShellExtension.dll [2005-11-16] (Autodesk, Inc.)
ContextMenuHandlers1-x32: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation)
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal)
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (Alexander Roshal)
ContextMenuHandlers1-x32-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\WZSHLS64.DLL [2010-11-30] (WinZip Computing, S.L.)
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\WZSHLS64.DLL [2010-11-30] (WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2015-05-26] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\WZSHLS64.DLL [2010-11-30] (WinZip Computing, S.L.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {284853EC-B502-4A58-8A24-8CB42487BBC9} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.)
Task: {334496F2-01C2-46D9-837B-83E1EF898B04} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => E:\repair tools\windows_repair\WR_Tray_Icon.exe [2017-05-03] (Tweaking.com)
Task: {3ACF1114-0E66-432A-80B5-E91B382FF233} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_154_pepper.exe [2018-08-15] (Adobe Systems Incorporated)
Task: {41DFB9E1-38A1-4C1A-BCB0-049AF9CD5781} - System32\Tasks\{A7BF4F8E-C88C-4772-AF08-A8ADE15B70DD} => C:\Windows\system32\pcalua.exe -a "E:\cad 2008\AutoCAD2008\Setup.exe" -d "E:\cad 2008\AutoCAD2008"
Task: {542DE84E-7706-4143-94CC-1C4FDB11EB24} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-15] (Google Inc.)
Task: {B6060A19-F1CF-4C93-939E-1FB51E654567} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-15] (Google Inc.)
Task: {CF4804A3-621F-4D18-8F0B-05000B2A23C0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-08-22] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2017-12-08 01:48 - 2017-12-08 01:48 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2017-12-08 01:48 - 2017-12-08 01:48 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2018-08-12 22:26 - 2018-06-18 13:32 - 002433744 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2014-09-10 14:01 - 2011-05-23 17:16 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2017-12-11 11:05 - 2017-12-11 11:05 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll
2017-12-11 11:05 - 2017-12-11 11:05 - 000088888 _____ () C:\Program Files\iTunes\zlib1.dll
2017-09-26 21:22 - 2017-09-26 21:22 - 001984000 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-1001631739-621710209-3946131499-1000\Software\Classes\.scr: AutoCADScriptFile => "C:\Windows\system32\NOTEPAD.EXE" "%1"

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 10:34 - 2009-06-11 05:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1001631739-621710209-3946131499-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\server\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{1FB585F3-BD5E-417F-B8D3-2242D73039B4}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{7C12DE47-E812-467F-BAE1-35A245A4AF30}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{36C649A6-4D08-4572-9678-7C8C64EA53C4}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [TCP Query User{3149178F-4BC6-4A57-B42C-E60FBE6C9B14}C:\teklastructures\multiuserserver\2.3\xs_server.exe] => (Allow) C:\teklastructures\multiuserserver\2.3\xs_server.exe
FirewallRules: [UDP Query User{919A54AD-05DF-4E41-BA18-D6F99402DC5A}C:\teklastructures\multiuserserver\2.3\xs_server.exe] => (Allow) C:\teklastructures\multiuserserver\2.3\xs_server.exe
FirewallRules: [TCP Query User{48511146-1A09-4D3A-9940-219ACD6DC6C4}D:\warcraft iii\war3.exe] => (Allow) D:\warcraft iii\war3.exe
FirewallRules: [UDP Query User{47ED175E-D03B-4C97-A4E7-171A131957CF}D:\warcraft iii\war3.exe] => (Allow) D:\warcraft iii\war3.exe
FirewallRules: [TCP Query User{C0709F37-E330-4B80-B890-AB146496C6CA}C:\windows\syswow64\ctfmon.exe] => (Block) C:\windows\syswow64\ctfmon.exe
FirewallRules: [UDP Query User{1BB864D6-BB37-4BA1-BCCE-C3F5C64EF195}C:\windows\syswow64\ctfmon.exe] => (Block) C:\windows\syswow64\ctfmon.exe
FirewallRules: [{F664D177-BAE8-49B7-AC37-87705AE7ED5A}] => (Allow) C:\Program Files\StarCraft II\Versions\Base38996\SC2_x64.exe
FirewallRules: [{C95460DB-6020-4131-8A4F-08C94D18CC2A}] => (Allow) C:\Program Files\StarCraft II\Versions\Base38996\SC2_x64.exe
FirewallRules: [{A466F3B9-0BB4-4F30-8175-26798F0C3657}] => (Allow) C:\Program Files\StarCraft II\Versions\Base38996\SC2_x64.exe
FirewallRules: [{08B9EFD1-959C-4F12-865F-A743E26E68D7}] => (Allow) C:\Program Files\StarCraft II\Versions\Base38996\SC2_x64.exe
FirewallRules: [TCP Query User{2212F445-AF1C-49F4-A8F8-C69741CB1B95}C:\program files (x86)\avg\avg2015\avgui.exe] => (Block) C:\program files (x86)\avg\avg2015\avgui.exe
FirewallRules: [UDP Query User{385AA3F2-1C1B-48A6-9F0D-BF7DE8312513}C:\program files (x86)\avg\avg2015\avgui.exe] => (Block) C:\program files (x86)\avg\avg2015\avgui.exe
FirewallRules: [{45D2028A-AC04-41A3-8B64-8A6280206596}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{87FDA899-C016-46A3-9D46-6AA5F46D27FF}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [TCP Query User{178B8693-F814-440D-881B-A476770664D8}C:\program files (x86)\avg\framework\common\avguix.exe] => (Block) C:\program files (x86)\avg\framework\common\avguix.exe
FirewallRules: [UDP Query User{80D31830-B4EC-47CF-BB2F-255EE4ACFB20}C:\program files (x86)\avg\framework\common\avguix.exe] => (Block) C:\program files (x86)\avg\framework\common\avguix.exe
FirewallRules: [TCP Query User{48D374B4-9BD8-425A-AF7F-C17B9F8164E6}C:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe] => (Block) C:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe
FirewallRules: [UDP Query User{64AE4674-D001-4D44-A306-36AE7CCEA302}C:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe] => (Block) C:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe
FirewallRules: [{C1AEBE42-6132-429A-9467-102915918F3D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FE7B47A3-C48A-4ADC-A407-F90E8D9D903A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{01DAA711-D8D5-483B-9D1F-2C501515FB3D}] => (Allow) E:\axl\Plague Inc Evolved Game\Plague Inc Evolved\PlagueIncEvolved.exe
FirewallRules: [{21A5F014-3C56-4BD7-BE9B-AE8B3D2A13FB}] => (Allow) E:\axl\Plague Inc Evolved Game\Plague Inc Evolved\PlagueIncEvolved.exe
FirewallRules: [{4460AD81-6313-4B4B-AEDC-D8F2A8A996E1}] => (Allow) E:\axl\Plague Inc Evolved Game\Plague Inc Evolved\PlagueIncEvolved.exe
FirewallRules: [{88666035-EDC9-4DF9-AB9F-B0F21B2E9CED}] => (Allow) E:\axl\Plague Inc Evolved Game\Plague Inc Evolved\PlagueIncEvolved.exe
FirewallRules: [{5EAAA774-2432-43D3-B57F-7E32240F4B82}] => (Allow) D:\NBA 2K16\NBA2K16.exe
FirewallRules: [{A72C2BCF-4C34-4303-85E5-870D828A35FB}] => (Allow) D:\NBA 2K16\NBA2K16.exe
FirewallRules: [{9EFAC132-31DD-4FEC-9CDF-1EF1EC73C17B}] => (Allow) D:\NBA 2K16\NBA2K16.exe
FirewallRules: [{DFAC0904-3129-49FB-B0DC-2958684077CB}] => (Allow) D:\NBA 2K16\NBA2K16.exe
FirewallRules: [{21E91047-F1C0-4DDD-A950-53DE914A26B8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{F3CA9A76-0212-4821-81A6-9E38BEB6CA33}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{454228E5-F40E-4EBB-A906-4032960C62EA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{62F6927E-A218-4E1B-A497-196BB1F573CD}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{363EB8EF-3682-4F10-A0FB-D31D86C32537}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{33909FE3-D30E-4241-8BBB-366D263079E7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{02F87093-0E73-49DE-BDC2-F1E87ED0AFFE}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{B71AD173-38B0-437E-A066-DF50BEF91B0B}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{B972C34F-04FB-43F5-9865-075FE9B636F9}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{E6D2213F-6CE4-43F3-93CF-08D7177D4410}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{5029FA59-72BD-428F-8888-DB27F405E857}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
FirewallRules: [{7338FA02-06BA-4B0B-BB7E-F08CCBD32B79}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
FirewallRules: [{5D0C671E-1237-4E22-9BB9-BC15E9231B3D}] => (Allow) E:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{D2299E33-7313-4F14-9E4E-DB28F46CA46E}] => (Allow) E:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [TCP Query User{1F92A774-9CDE-464D-8C91-6CC4D3968D7A}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{493BA20C-1642-4706-ADC7-32BBAA584D6A}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{4F5C676D-34D3-40ED-8A90-F9348843E8AD}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
FirewallRules: [{FFE3E534-5AC7-4934-A02B-A49D004BD9CE}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{1E1691E4-9A4F-44FA-9DDF-793245DE05D7}E:\assassin's creed iii\ac3sp.exe] => (Allow) E:\assassin's creed iii\ac3sp.exe
FirewallRules: [UDP Query User{5B4D0589-E06A-460E-AD59-1E6F0D6C5131}E:\assassin's creed iii\ac3sp.exe] => (Allow) E:\assassin's creed iii\ac3sp.exe
FirewallRules: [{7B56B6E4-6834-45DC-9350-FE5DB0234DCA}] => (Block) E:\assassin's creed iii\ac3sp.exe
FirewallRules: [{006DBEA9-6776-4EAA-BF62-871DD3561521}] => (Block) E:\assassin's creed iii\ac3sp.exe
FirewallRules: [{5A518334-92FD-4899-9EE2-AD587D408154}] => (Allow) C:\Program Files (x86)\BlueStacks\HD-Player.exe
FirewallRules: [{10DE8CF5-F0F2-4170-8444-304FB97889CD}] => (Allow) C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe
FirewallRules: [{378E8091-6BAD-41F8-91D9-10C46A8369E6}] => (Allow) C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe
FirewallRules: [{4F964CA8-4DA6-4118-9A36-AAE71275B07E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

25-08-2018 20:32:36 Scheduled Checkpoint

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

==================== Event log errors: =========================

Application errors:
Error: (08/27/2018 09:06:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program FRST64.exe version 2.8.2018.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 10c8

Start Time: 01d43da20d31be3a

Termination Time: 2000

Application Path: C:\Users\server\Downloads\FRST64.exe

Report Id: 5ad5b964-a995-11e8-9ae3-14dae9b468f6

Error: (08/27/2018 08:57:51 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/27/2018 08:57:51 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (08/23/2018 03:43:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7
Exception code: 0xc0000374
Fault offset: 0x000ce753
Faulting process id: 0x66c
Faulting application start time: 0x01d43ab4f0bf0954
Faulting application path: C:\Windows\SysWOW64\rundll32.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: 2f5121e9-a6a8-11e8-a1ce-14dae9b468f6

Error: (08/22/2018 10:52:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7
Exception code: 0xc0000374
Fault offset: 0x000ce753
Faulting process id: 0x908
Faulting application start time: 0x01d439c33178fb60
Faulting application path: C:\Windows\SysWOW64\rundll32.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: 6ff73dd3-a5b6-11e8-bbba-14dae9b468f6

Error: (08/21/2018 08:44:49 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7
Exception code: 0xc0000374
Fault offset: 0x000ce753
Faulting process id: 0xb30
Faulting application start time: 0x01d438e8296dbc62
Faulting application path: C:\Windows\SysWOW64\rundll32.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: 68077618-a4db-11e8-a332-14dae9b468f6

Error: (08/19/2018 04:31:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7
Exception code: 0xc0000374
Fault offset: 0x000ce753
Faulting process id: 0x1398
Faulting application start time: 0x01d4379708e1bc11
Faulting application path: C:\Windows\SysWOW64\rundll32.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: 47bdda5c-a38a-11e8-9b7e-14dae9b468f6

Error: (08/16/2018 10:34:46 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7
Exception code: 0xc0000374
Fault offset: 0x000ce753
Faulting process id: 0xbd0
Faulting application start time: 0x01d43509b1ade7bd
Faulting application path: C:\Windows\SysWOW64\rundll32.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: f059f0f5-a0fc-11e8-a967-14dae9b468f6

System errors:
Error: (08/27/2018 08:56:45 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.

Error: (08/27/2018 08:56:45 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.

Error: (08/27/2018 08:56:44 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.

Error: (08/27/2018 08:56:44 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.

Error: (08/27/2018 08:33:01 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:

Error: (08/26/2018 08:16:12 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:

Error: (08/26/2018 05:32:42 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:

Error: (08/26/2018 06:38:08 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:

==================== Memory info ===========================

Processor: Intel® Core™ i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 58%
Total physical RAM: 4008.3 MB
Available physical RAM: 1668.11 MB
Total Virtual: 8014.79 MB
Available Virtual: 5289.44 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:97.56 GB) (Free:9.35 GB) NTFS
Drive d: () (Fixed) (Total:97.66 GB) (Free:18.59 GB) NTFS
Drive e: () (Fixed) (Total:270.45 GB) (Free:17.82 GB) NTFS

\\?\Volume{46e36f40-38a9-11e4-bc62-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 1B691B68)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=97.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=97.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=270.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================


BTW I will be away for 3 - 4 days because of school activities, so I can't do anything during those times.

  • 0




    Malware Expert

  • Expert
  • 24,713 posts
  • MVP

1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, but don't restart yet.

Right click on (My) Computer and select Manage (Continue) Then the Event Viewer. Next select Windows Logs.  Right click on System and Clear Log, Clear. Repeat for Application. Reboot. The disk check will run and will probably take an hour or more to finish.


Repeat the above for D: and E:  Probably won't need to reboot.

Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator.  Then type (with an Enter after each line).

sfc /scannow

(SPACE after sfc.  This will check your critical system files. Does this finish without complaint?  IF it says it couldn't fix everything then:

Copy the next two lines:
findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  %UserProfile%\desktop\junk.txt
notepad %UserProfile%\desktop\junk.txt

Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue.  Right click and Paste or Edit then Paste and the copied line should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.  Close nOtepad.  Close the Command Window.

1. Please download the Event Viewer Tool by Vino Rosso
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning

Then use the 'Number of events' as follows:

1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.

Please post the Output log in your next reply then repeat but select Application. (Each time you run VEW it overwrites the log so copy the first one to a Reply or rename it before running it a second time.)


Download the attached fixlist.txt to the same location as FRST


Run FRST and press Fix
A fix log will be generated please post that

Reboot if the fix doesn't reboot it for you

Run FRST again as before.  Make sure Addition.txt is checked and hit Scan.  Post both logs.



  • 0

