This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Problems starting computer (Win 7) [Solved]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hioes

 

I suddenly have problems starting my computer up. It goes to Windows startup repair, and then, mostly, it comes through.

The problem semed to come out of the blue, while I was trying to connect to a TV with HDMI..

 

Here are the logfiles:

 

aswMBR

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-08-21 10:30:16
—————————–
10:30:16.681    OS Version: Windows x64 6.1.7601 Service Pack 1
10:30:16.681    Number of processors: 2 586 0x2A07
10:30:16.682    ComputerName: SHEANA-PC  UserName: Sheana
10:30:17.781    Initialize success
10:30:17.934    VM: initialized successfully
10:30:17.935    VM: Intel CPU virtualization not supported
10:39:44.959    AVAST engine defs: 16082100
10:41:41.461    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
10:41:41.461    Disk 0 Vendor: TOSHIBA_MQ01ABF050 AM0P1A Size: 476940MB BusType: 11
10:41:41.571    Disk 0 MBR read successfully
10:41:41.571    Disk 0 MBR scan
10:41:41.581    Disk 0 Windows 7 default MBR code
10:41:41.601    Disk 0 Partition 1 00     07    HPFS/NTFS NTFS       199900 MB offset 206848
10:41:41.631    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 409602048
10:41:41.631    Disk 0 Boot: NTFS     code=1
10:41:41.651    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       276838 MB offset 409806848
10:41:41.731    Disk 0 scanning C:\Windows\system32\drivers
10:41:50.811    Service scanning
10:42:17.381    Modules scanning
10:42:17.401    Disk 0 trace - called modules:
10:42:17.441    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
10:42:17.451    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004ce45d0]
10:42:17.471    3 CLASSPNP.SYS[fffff8800183b43f] -> nt!IofCallDriver -> [0xfffffa8004799520]
10:42:17.481    5 ACPI.sys[fffff88000f1e7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004796060]
10:42:18.261    AVAST engine scan C:\Windows
10:42:20.131    AVAST engine scan C:\Windows\system32
10:44:01.141    File: C:\Windows\system32\winshfhc.dll  **SUSPICIOUS**
10:46:09.621    AVAST engine scan C:\Windows\system32\drivers
10:46:24.303    AVAST engine scan C:\Users\Sheana
10:49:55.751    Disk 0 MBR has been saved successfully to "C:\Users\Sheana\Desktop\MBR.dat"
10:49:55.761    The log file has been saved successfully to "C:\Users\Sheana\Desktop\aswMBR.txt"

 

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-08-2016
Ran by [removed] (administrator) on SHEANA-PC (21-08-2016 10:53:51)
Running from C:\Users\[removed]\Downloads
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.2\ToolbarUpdater.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\SpotifyCrashService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\…\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [186640 2016-07-20] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [6709008 2016-07-28] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2162760 2016-07-21] ()
HKLM-x32\…\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [Spotify Web Helper] => C:\Users\Sheana\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1552496 2016-06-14] (Spotify Ltd)
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [Spotify] => C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe [6916208 2016-06-14] (Spotify Ltd)
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29494400 2016-07-13] (Skype Technologies S.A.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{05F01782-356A-4E6E-A8A7-5D782C0D6C0F}: [DhcpNameServer] [removed] [removed]

Internet Explorer:
==================
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc;=UE07&ocid;=UE07DHP
SearchScopes: HKU\S-1-5-21-3135081951-948255948-2762818755-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={142A452D-A6FB-4046-AEBD-5ADAE7D5FA4C}∣=fe48c534f63a47cc8440c1f60ee37f09-6f57c1b4b7f5c8ca2783c1861d5d09e2fa86a60f⟨=en&ds;=ZEN&coid;=avgtbdisZE&cmpid;=0616tb≺=fr&d;=2016-03-28 11:05:22&v;=4.3.1.831&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-21] (Oracle Corporation)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.3.2.18\AVG Web TuneUp.dll [2016-07-21] (AVG)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-21] (Oracle Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Sheana\AppData\Roaming\Mozilla\Firefox\Profiles\47z2ksus.default
FF Homepage: hxxps://www.google.es/?gfe_rd=cr&ei;=5RCiVvTpI6uH8QeepJbwCA&gws;_rd=ssl
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-26] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-26] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.2\\npsitesafety.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-27] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Sheana\AppData\Roaming\Mozilla\Firefox\Profiles\47z2ksus.default\searchplugins\avg-secure-search.xml [2016-07-22]
FF Extension: AVG Web TuneUp - C:\Users\Sheana\AppData\Roaming\Mozilla\Firefox\Profiles\47z2ksus.default\Extensions\[removed] [2016-07-21]

Chrome:
=======
CHR HomePage: Default -> hxxps://www.google.co.uk/?gws_rd=ssl
CHR StartupUrls: Default -> "hxxps://www.google.co.uk/?gws_rd=ssl"
CHR Profile: C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-22]
CHR Extension: (Google Docs) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-21]
CHR Extension: (Google Drive) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-21]
CHR Extension: (YouTube) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-21]
CHR Extension: (Google Search) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-21]
CHR Extension: (Google Sheets) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-21]
CHR Extension: (Google Docs Offline) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-21]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-21]
CHR Extension: (Gmail) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-21]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [674552 2016-07-28] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5267456 2016-07-28] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1097488 2016-07-20] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [760024 2016-07-28] (AVG Technologies CZ, s.r.o.)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R2 vToolbarUpdater40.3.2; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.2\ToolbarUpdater.exe [1309768 2016-07-21] (AVG Secure Search)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [976456 2016-07-21] ()

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [314112 2016-06-30] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [261376 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [260352 2016-06-01] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [261888 2016-07-19] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
R0 Avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3341904 2012-03-26] (Broadcom Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R3 netr28x; C:\Windows\System32\DRIVERS\netr28x.sys [2473616 2014-12-10] (MediaTek Inc.)
U3 aswMBR; \??\C:\Users\Sheana\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Sheana\AppData\Local\Temp\aswVmm.sys [X]

========================== Drivers MD5 =======================

C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit
C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit
C:\Windows\system32\drivers\afd.sys 9A4A1EEE802BF2F878EE8EAB407B21B7
C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49
C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit
C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048
C:\Windows\system32\drivers\appid.sys 6474F8823C7188D2DA579F01FB6CED6B
C:\Windows\system32\drivers\arc.sys ==> MD5 is legit
C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\asmthub3.sys 8569AF4C73747671194EA9EBB2F2D6CF
C:\Windows\System32\DRIVERS\asmtxhci.sys 073716FBFFAC7057CD5FF00A1B558331
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\avgdiska.sys EBE91430DEC70E1F81D1C48B31160CAE
C:\Windows\System32\DRIVERS\avgidsdrivera.sys F363AE47CE4920A46F09BA858952DCBB
C:\Windows\System32\DRIVERS\avgidsha.sys 6E74613980F4691B95E6A10F71218D0B
C:\Windows\System32\DRIVERS\avgldx64.sys 65E62E92584319747183FA54C08C0330
C:\Windows\System32\DRIVERS\avgloga.sys 301E95F388C93D3C73EE35E3693C6A97
C:\Windows\System32\DRIVERS\avgmfx64.sys A1E22774E01EDB88EC9620EF017B3ABE
C:\Windows\System32\DRIVERS\avgrkx64.sys 2A0D6982D0492BF6266E64F25C23EAE8
C:\Windows\System32\DRIVERS\avguniva.sys 1EEB894456B375A486950D343F6DB81F
C:\Windows\system32\drivers\bxvbda.sys 1FED668A08CD871ED317A0388CDD4537
C:\Windows\system32\drivers\bxdiaga.sys CFE42B9C72CD047E478C3B7F4B1FAFFD
C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
C:\Windows\system32\drivers\Xeno7x64.sys 33B114FC0394358DB521828B6F6ACC54
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit
C:\Windows\system32\drivers\bxfcoe.sys 96858ECF6D017E33A5A1A87E7A1E3206
C:\Windows\system32\drivers\bxois.sys 33B60616D5DE1D7FE8B5939D437BC74F
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit
C:\Windows\System32\CLFS.sys 404B7DF9CA4D1CB675045AF220FF3285
C:\Windows\System32\DRIVERS\CmBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
C:\Windows\System32\Drivers\cng.sys CA3FB5A6B626D8A00A89E049CF95954E
C:\Windows\System32\DRIVERS\compbatt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit
C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit
C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
C:\Windows\System32\drivers\disk.sys 616387BBD83372220B09DE95F4E67BBC
C:\Windows\system32\drivers\drmkaud.sys 26FE888505E5A945B0536AF9A2A27A6F
C:\Windows\System32\drivers\dxgkrnl.sys 3A9D7D464BDB3B70D7ECF689ADABBD4D
C:\Windows\system32\drivers\evbda.sys 8947C98CC212AEEE1FABEC4582F652EE
C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit
C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit
C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit
C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B
C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0
C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A
C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
C:\Windows\System32\drivers\HTTP.sys F61634BEC53F73702A10DE69F6DCAF57
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit
C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366
C:\Windows\System32\DRIVERS\igdkmd64.sys 0089B53F1BEFD34B7D8CA4AB021335FA
C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\IntcDAud.sys AE594CC17C33AC146739494615E14851
C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\qd162x64.sys E45575812630B049CE0F679D87561A4D
C:\Windows\System32\Drivers\qd262x64.sys 2C23820DD9E81199E60F553EB50BC449
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
C:\Windows\system32\drivers\msiscsi.sys 96BB922A0981BC7432C8CF52B5410FE6
C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\ksecdd.sys 0878723427BA190E5ABA5AA0112FA4D4
C:\Windows\System32\Drivers\ksecpkg.sys C08CCCE2BE68D04E6C142614736959DA
C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\L1C62x64.sys A43A9920D2409BB9DA747D2FD20A2E61
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit
C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit
C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
C:\Windows\System32\drivers\mountmgr.sys 67050452C0118BAF2883928E6FCCFE47
C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\mrxdav.sys D7ADC2B83CA0B0381F75A98351F72CEE
C:\Windows\System32\DRIVERS\mrxsmb.sys 035C0A9A63DF3F3A52B90D8F6BF0F166
C:\Windows\System32\DRIVERS\mrxsmb10.sys 8308FC2E9147D7632221E3279BB14660
C:\Windows\System32\DRIVERS\mrxsmb20.sys 1F8DA4ECAEA7E2BCD97E738795817431
C:\Windows\System32\drivers\msahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit
C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
C:\Windows\System32\drivers\ndis.sys F7309F42555F8AAB7144A51A1F2585B0
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netr28x.sys 8B5CCD0323FFD5E6A472A5FF30A14799
C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Ntfs.sys 47B2D0B31BDC3EBE6090228E2BA3764D
C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD
C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
C:\Windows\system32\drivers\parport.sys ==> MD5 is legit
C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C
C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit
C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit
C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
C:\Windows\System32\drivers\peauth.sys ED6E75158D28D33A2E2A020AC5B2B59D
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
C:\Windows\system32\drivers\processr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34
C:\Windows\System32\Drivers\RDPWD.sys FE571E088C2D83619D2D48D4E961BF41
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\serenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\serial.sys ==> MD5 is legit
C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit
C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit
C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit
C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B
C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28
C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3
C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit
C:\Windows\System32\drivers\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E
C:\Windows\System32\DRIVERS\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E
C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8
C:\Windows\System32\DRIVERS\tdx.sys AA77EB517D2F07A947294F260E3ACA83
C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit
C:\Windows\system32\drivers\terminpt.sys EF4469AB69EB15E5D3754E6AEAFBCD3D
C:\Windows\System32\DRIVERS\tssecsrv.sys 19BEDA57F3E0A06B8D5EB6D619BD5624
C:\Windows\System32\drivers\tsusbflt.sys E9981ECE8D894CEF7038FD1D040EB426
C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A
C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31
C:\Windows\system32\drivers\usbehci.sys 18A85013A3E0F7E1755365D287443965
C:\Windows\System32\DRIVERS\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA
C:\Windows\system32\drivers\usbohci.sys 765A92D428A8DB88B960DA5A8D6089DC
C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\usbscan.sys 9661DA76B4531B2DA272ECCE25A8AF24
C:\Windows\System32\DRIVERS\USBSTOR.SYS D029DD09E22EB24318A8FC3D8138BA43
C:\Windows\system32\drivers\usbuhci.sys DD253AFC3BC6CBA412342DE60C3647F3
C:\Windows\System32\Drivers\usbvideo.sys 1F775DA4CF1A3A1834207E975A72E9D7
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit
C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vwifimp.sys ==> MD5 is legit
C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\system32\drivers\wd.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wmiacpi.sys ==> MD5 is legit
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F
C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-21 10:53 - 2016-08-21 10:54 - 00027964 _____ C:\Users\Sheana\Downloads\FRST.txt
2016-08-21 10:52 - 2016-08-21 10:53 - 00000000 ____D C:\FRST
2016-08-21 10:51 - 2016-08-21 10:51 - 02396160 _____ (Farbar) C:\Users\Sheana\Downloads\FRST64.exe
2016-08-21 10:49 - 2016-08-21 10:49 - 00002178 _____ C:\Users\Sheana\Desktop\aswMBR.txt
2016-08-21 10:49 - 2016-08-21 10:49 - 00000512 _____ C:\Users\Sheana\Desktop\MBR.dat
2016-08-21 10:29 - 2016-08-21 10:30 - 05198336 _____ (AVAST Software) C:\Users\Sheana\Downloads\aswMBR.exe
2016-08-14 10:50 - 2016-08-14 11:21 - 00004109 _____ C:\Users\Sheana\Documents\Ben.txt
2016-07-29 12:41 - 2016-07-29 12:41 - 00000000 ____H C:\Users\Sheana\Documents\Default.rdp

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-21 20:22 - 2016-02-26 06:29 - 00000000 ___SD C:\Windows\system32\GWX
2016-08-21 20:22 - 2016-01-23 11:30 - 00000000 ____D C:\Users\Sheana\AppData\Roaming\Spotify
2016-08-21 20:22 - 2016-01-21 12:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2016-08-21 20:22 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2016-08-21 20:22 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-08-21 10:38 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-08-21 10:38 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-08-21 10:26 - 2016-01-21 12:14 - 00000000 ____D C:\ProgramData\MFAData
2016-08-21 10:24 - 2016-01-23 11:59 - 00000000 ____D C:\Users\Sheana\AppData\Roaming\Skype
2016-08-21 10:24 - 2016-01-23 11:34 - 00000000 ____D C:\Users\Sheana\AppData\Local\Spotify
2016-08-21 10:23 - 2016-01-21 20:27 - 00000000 ____D C:\Users\Sheana
2016-08-21 10:23 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-20 18:08 - 2016-06-14 20:38 - 00002930 _____ C:\Users\Sheana\Documents\Navne.txt
2016-08-13 09:27 - 2016-02-21 21:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-08-13 09:27 - 2016-01-23 11:59 - 00000000 ____D C:\ProgramData\Skype
2016-08-06 20:19 - 2016-01-21 20:34 - 00000000 ____D C:\Users\Sheana\AppData\Roaming\vlc
2016-08-04 13:01 - 2016-02-18 21:06 - 00000984 _____ C:\Users\Public\Desktop\AVG.lnk
2016-08-04 13:01 - 2016-01-21 12:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2016-08-02 10:35 - 2009-07-14 07:08 - 00032652 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-08-01 09:59 - 2009-07-14 07:13 - 00785366 _____ C:\Windows\system32\PerfStringBackup.INI
2016-07-26 15:45 - 2016-01-21 12:01 - 00000000 ____D C:\Users\Sheana\AppData\Local\Adobe
2016-07-26 15:44 - 2016-01-22 14:25 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-07-26 15:44 - 2016-01-22 14:25 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-07-26 15:44 - 2016-01-22 14:25 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-07-26 15:44 - 2016-01-22 14:25 - 00000000 ____D C:\Windows\system32\Macromed

Some files in TEMP:
====================
C:\Users\Sheana\AppData\Local\Temp\avguirn_081899836627.exe
C:\Users\Sheana\AppData\Local\Temp\avguirn_081927674860.exe
C:\Users\Sheana\AppData\Local\Temp\avguirn_08302635609.exe
C:\Users\Sheana\AppData\Local\Temp\avguirn_08408051081.exe
C:\Users\Sheana\AppData\Local\Temp\avguirn_08549593070.exe
C:\Users\Sheana\AppData\Local\Temp\avguirn_08600366166.exe
C:\Users\Sheana\AppData\Local\Temp\jre-8u101-windows-au.exe
C:\Users\Sheana\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Sheana\AppData\Local\Temp\jre-8u91-windows-au.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

==================== BCD ================================

Windows Boot Manager
——————–
identifier              {bootmgr}
device                  partition=\Device\HarddiskVolume2
description             Windows Boot Manager
locale                  en-US
inherit                 {globalsettings}
default                 {current}
resumeobject            {3c4e6c9b-c06b-11e5-bcf6-e1aacc0f1a3e}
displayorder            {current}
toolsdisplayorder       {memdiag}
timeout                 30

Windows Boot Loader
——————-
identifier              {current}
device                  partition=C:
path                    \Windows\system32\winload.exe
description             Windows 7
locale                  en-US
inherit                 {bootloadersettings}
recoverysequence        {3c4e6c9d-c06b-11e5-bcf6-e1aacc0f1a3e}
recoveryenabled         Yes
osdevice                partition=C:
systemroot              \Windows
resumeobject            {3c4e6c9b-c06b-11e5-bcf6-e1aacc0f1a3e}
nx                      OptIn

Windows Boot Loader
——————-
identifier              {3c4e6c9d-c06b-11e5-bcf6-e1aacc0f1a3e}
device                  ramdisk=[C:]\Recovery\3c4e6c9d-c06b-11e5-bcf6-e1aacc0f1a3e\Winre.wim,{3c4e6c9e-c06b-11e5-bcf6-e1aacc0f1a3e}
path                    \windows\system32\winload.exe
description             Windows Recovery Environment
inherit                 {bootloadersettings}
osdevice                ramdisk=[C:]\Recovery\3c4e6c9d-c06b-11e5-bcf6-e1aacc0f1a3e\Winre.wim,{3c4e6c9e-c06b-11e5-bcf6-e1aacc0f1a3e}
systemroot              \windows
nx                      OptIn
winpe                   Yes

Resume from Hibernate
———————
identifier              {3c4e6c9b-c06b-11e5-bcf6-e1aacc0f1a3e}
device                  partition=C:
path                    \Windows\system32\winresume.exe
description             Windows Resume Application
locale                  en-US
inherit                 {resumeloadersettings}
filedevice              partition=C:
filepath                \hiberfil.sys
debugoptionenabled      No

Windows Memory Tester
———————
identifier              {memdiag}
device                  partition=\Device\HarddiskVolume2
path                    \boot\memtest.exe
description             Windows Memory Diagnostic
locale                  en-US
inherit                 {globalsettings}
badmemoryaccess         Yes

EMS Settings
————
identifier              {emssettings}
bootems                 Yes

Debugger Settings
—————–
identifier              {dbgsettings}
debugtype               Serial
debugport               1
baudrate                115200

RAM Defects
———–
identifier              {badmemory}

Global Settings
—————
identifier              {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}

Boot Loader Settings
——————–
identifier              {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}

Hypervisor Settings
——————-
identifier              {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200

Resume Loader Settings
———————-
identifier              {resumeloadersettings}
inherit                 {globalsettings}

Device options
————–
identifier              {3c4e6c9e-c06b-11e5-bcf6-e1aacc0f1a3e}
description             Ramdisk Options
ramdisksdidevice        partition=C:
ramdisksdipath          \Recovery\3c4e6c9d-c06b-11e5-bcf6-e1aacc0f1a3e\boot.sdi



LastRegBack: 2016-08-16 19:24

==================== End of FRST.txt ============================

 

 

Addition

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-08-2016
Ran by [removed] (21-08-2016 10:54:35)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2016-01-21 18:27:16)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3135081951-948255948-2762818755-500 - Administrator - Disabled)
Guest (S-1-5-21-3135081951-948255948-2762818755-501 - Limited - Disabled)
Sheana (S-1-5-21-3135081951-948255948-2762818755-1000 - Administrator - Enabled) => C:\Users\Sheana

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.016.20045 - Adobe Systems Incorporated)
Adobe Flash Player 22 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.4.0 - Asmedia Technology)
AVG (HKLM\…\AvgZen) (Version: 1.82.2.30772 - AVG Technologies)
AVG (Version: 16.101.7752 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4568 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4647 - AVG Technologies) Hidden
AVG Protection (HKLM\…\AVG) (Version: 2016.101.7752 - AVG Technologies)
AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.3.2.18 - AVG Technologies)
AVG Zen (Version: 1.82.2 - AVG Technologies) Hidden
doPDF 7.2 printer (HKLM\…\doPDF 7 printer_is1) (Version:  - Softland)
FMW 1 (Version: 1.112.3 - AVG Technologies) Hidden
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Java 8 Update 101 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\…\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Mozilla Firefox 47.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 47.0 (x86 en-US)) (Version: 47.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 47.0.0.5999 - Mozilla)
MuseScore 2 (HKLM-x32\…\{D0969A82-E79E-45D9-95D2-B2824880F780}) (Version: 2.0.2 - Werner Schweer and Others)
Skype™ 7.26 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Spotify) (Version: 1.0.31.56.g526cfefe - Spotify AB)
TeamViewer 10 (HKLM-x32\…\TeamViewer) (Version: 10.0.47484 - TeamViewer)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.1.3 (HKLM-x32\…\VLC media player) (Version: 2.1.3 - VideoLAN)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {4181EF81-3C3E-4CA8-9FB7-C8D9256198B4} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {47E122AA-1B42-42B8-93D3-26BA22BA51E9} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {79C8FF37-5FAF-4CC4-8A1E-F91E61A11022} - System32\Tasks\0116avzUpdateInfo => C:\ProgramData\Avg_Update_0116avz\0116avz_AVG-Secure-Search-Update.exe
Task: {805CC98F-C591-41DF-AB27-6CCDACBEC9BB} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-06-22] (Oracle Corporation)
Task: {8C8BB076-ECA0-451D-BCEC-015BE7A92F8F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated)
Task: {9B52586B-2EEF-4353-BDD7-CD85C7E43D66} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-26] (Adobe Systems Incorporated)
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {B9436422-60AB-418C-8B2C-2F8920B24947} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2016-03-28 11:05 - 2016-07-21 19:59 - 00976456 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2016-01-21 11:58 - 2011-11-04 04:09 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2016-03-28 11:05 - 2016-07-21 19:59 - 02162760 _____ () C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
2016-01-21 12:13 - 2016-04-07 21:36 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2016-06-19 10:14 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3135081951-948255948-2762818755-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Sheana\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{CAE3E590-1A56-4FB5-921F-740876D3993B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{2A4ED2D3-F733-47EF-91EF-00D35884DCF5}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{567D9D82-365D-4390-A528-4945C9D667A1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7DF1F4CA-2470-4A18-A9C4-12F0D63F8594}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{E0CBB21C-F436-4CDE-8C3F-FF83548696B3}C:\users\sheana\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\sheana\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{BBEFA09D-53C3-4D27-8672-520CB59D7C3B}C:\users\sheana\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\sheana\appdata\roaming\spotify\spotify.exe
FirewallRules: [{8ACECEA7-BF18-4F44-96BA-F19E16549D79}] => (Block) C:\users\sheana\appdata\roaming\spotify\spotify.exe
FirewallRules: [{9881CA47-E562-4E64-9872-DD50F23192CF}] => (Block) C:\users\sheana\appdata\roaming\spotify\spotify.exe
FirewallRules: [{887C498C-B225-4568-976E-3A512465E342}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{F43F98A3-2304-439C-A6AE-C1E331E9AC09}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{E7BF31DE-B450-4854-BB62-D31F4CB147AE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{2BEFB6DB-A1B9-4A41-8AB1-CBDD2171E1F8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{44423604-F800-47E8-BB4B-5BEDCFEDED2F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{ECCB7CA6-77DF-48BD-B6A4-ACCC14ED7BEE}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{D3DA3194-BF88-41B9-A28C-98E96D91DC1E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe

==================== Restore Points =========================

01-07-2016 10:29:37 Scheduled Checkpoint
08-07-2016 11:20:27 Scheduled Checkpoint
20-07-2016 14:31:02 Scheduled Checkpoint
27-07-2016 22:57:43 Scheduled Checkpoint
04-08-2016 10:54:22 Scheduled Checkpoint
13-08-2016 10:16:07 Scheduled Checkpoint

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/21/2016 10:24:33 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/21/2016 10:24:09 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Spotify.exe, version: 1.0.31.56, time stamp: 0x574ccd44
Faulting module name: libcef.dll, version: 3.2526.1364.0, time stamp: 0x568efb26
Exception code: 0x80000003
Fault offset: 0x0006a793
Faulting process id: 0x65c
Faulting application start time: 0xSpotify.exe0
Faulting application path: Spotify.exe1
Faulting module path: Spotify.exe2
Report Id: Spotify.exe3

Error: (08/20/2016 11:49:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/20/2016 11:49:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Spotify.exe, version: 1.0.31.56, time stamp: 0x574ccd44
Faulting module name: libcef.dll, version: 3.2526.1364.0, time stamp: 0x568efb26
Exception code: 0x80000003
Fault offset: 0x0006a793
Faulting process id: 0x87c
Faulting application start time: 0xSpotify.exe0
Faulting application path: Spotify.exe1
Faulting module path: Spotify.exe2
Report Id: Spotify.exe3

Error: (08/20/2016 09:58:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/20/2016 09:57:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Spotify.exe, version: 1.0.31.56, time stamp: 0x574ccd44
Faulting module name: libcef.dll, version: 3.2526.1364.0, time stamp: 0x568efb26
Exception code: 0x80000003
Fault offset: 0x0006a793
Faulting process id: 0x9ac
Faulting application start time: 0xSpotify.exe0
Faulting application path: Spotify.exe1
Faulting module path: Spotify.exe2
Report Id: Spotify.exe3

Error: (08/20/2016 08:13:12 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/20/2016 05:45:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/20/2016 09:29:47 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/19/2016 08:45:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (08/21/2016 12:06:12 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (08/20/2016 10:10:43 AM) (Source: Tcpip) (EventID: 4199) (User: )
Description: The system detected an address conflict for IP address 192.168.1.43 with the system
having network hardware address 64-76-BA-94-C1-5C. Network operations on this system may
be disrupted as a result.

Error: (08/12/2016 02:05:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The AVG WatchDog service failed to start due to the following error:
%%1053 = The service did not respond to the start or control request in a timely fashion.

Error: (08/12/2016 02:05:54 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the AVG WatchDog service to connect.

Error: (07/28/2016 11:10:58 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

Error: (07/27/2016 06:38:39 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {CC957078-B838-47C4-A7CF-626E7A82FC58}

Error: (07/20/2016 07:17:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Search service failed to start due to the following error:
%%1053 = The service did not respond to the start or control request in a timely fashion.

Error: (07/20/2016 07:17:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.

Error: (07/20/2016 07:17:23 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (07/16/2016 12:01:59 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The AVGIDSAgent service terminated with service-specific error %%-536753635.


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU B950 @ 2.10GHz
Percentage of memory in use: 47%
Total physical RAM: 4000.13 MB
Available physical RAM: 2089.57 MB
Total Virtual: 7998.43 MB
Available Virtual: 6111.88 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:270.35 GB) (Free:93.01 GB) NTFS
Drive d: (DATA) (Fixed) (Total:195.21 GB) (Free:152.8 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 493C1F0B)
Partition 1: (Not Active) - (Size=195.2 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=270.3 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================ns

 

 

Greetings

Jens
 

:welcome:

 

This well maybe a windows problem and not malware, we can run a few programs to see if it picks anything up and go from there

 

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
     
     
    [external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
      •  
        [external image: MBAM221%201043_zpsdtasp5xe.jpg]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • Hi

           

          Here are the results:

           

          AdwCleaner:

           

          # AdwCleaner v6.000 - Logfile created 23/08/2016 at 14:01:37
          # Updated on 12/08/2016 by ToolsLib
          # Database : 2016-08-22.1 [Server]
          # Operating System : Windows 7 Home Premium Service Pack 1 (X64)
          # Username : Sheana - SHEANA-PC
          # Running from : C:\Users\Sheana\Desktop\AdwCleaner.exe
          # Mode: Clean
          # Support : https://toolslib.net/forum



          ***** [ Services ] *****



          ***** [ Folders ] *****



          ***** [ Files ] *****



          ***** [ DLL ] *****



          ***** [ WMI ] *****



          ***** [ Shortcuts ] *****



          ***** [ Scheduled Tasks ] *****



          ***** [ Registry ] *****

          [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key deleted: HKLM\SOFTWARE\AVG Tuneup
          [-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
          [-] Key deleted: HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
          [-] Key deleted: HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
          [-] Key deleted: HKLM\SOFTWARE\Classes\s


          ***** [ Web browsers ] *****



          *************************

          :: "Tracing" keys deleted
          :: Winsock settings cleared

          *************************

          C:\AdwCleaner\AdwCleaner[C0].txt - [1609 Bytes] - [23/08/2016 14:01:37]
          C:\AdwCleaner\AdwCleaner[S0].txt - [4147 Bytes] - [23/08/2016 13:42:34]
          C:\AdwCleaner\AdwCleaner[S1].txt - [1991 Bytes] - [23/08/2016 14:01:23]

          ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1828 Bytes] ##########

           

           

          JRT:

           

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Malwarebytes
          Version: 8.0.7 (07.03.2016)
          Operating System: Windows 7 Home Premium x64
          Ran by [removed] (Administrator) on Tue 08/23/2016 at 13:51:14.94
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




          File System: 17

          Failed to delete: C:\Users\Sheana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7FH7RVZR (Temporary Internet Files Folder)
          Failed to delete: C:\Users\Sheana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DRGO05DN (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\Sheana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\Sheana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\Sheana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\Sheana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\Sheana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S3KAW3WD (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\Sheana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T8OCEITL (Temporary Internet Files Folder)
          Successfully deleted: C:\Windows\prefetch\TOOLBARUPDATER.EXE-7F54DFF6.pf (File)
          Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
          Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
          Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7FH7RVZR (Temporary Internet Files Folder)
          Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DRGO05DN (Temporary Internet Files Folder)
          Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
          Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
          Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S3KAW3WD (Temporary Internet Files Folder)
          Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T8OCEITL (Temporary Internet Files Folder)

          Deleted the following from C:\Users\Sheana\AppData\Roaming\Mozilla\Firefox\Profiles\47z2ksus.default\prefs.js
          user_pref(browser.urlbar.suggest.searches, true);



          Registry: 3

          Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)
          Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)
          Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)




          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Tue 08/23/2016 at 13:53:23.39
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

           

          Malvarebytes:

           

          Malwarebytes Anti-Malware
          www.malwarebytes.org

          Scan Date: 8/23/2016
          Scan Time: 2:11 PM
          Logfile: Malwarebytes.txt
          Administrator: Yes

          Version: 2.2.1.1043
          Malware Database: v2016.08.23.06
          Rootkit Database: v2016.08.15.01
          License: Trial
          Malware Protection: Enabled
          Malicious Website Protection: Enabled
          Self-protection: Disabled

          OS: Windows 7 Service Pack 1
          CPU: x64
          File System: NTFS
          User: Sheana

          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 299702
          Time Elapsed: 11 min, 21 sec

          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled

          Processes: 0
          (No malicious items detected)

          Modules: 0
          (No malicious items detected)

          Registry Keys: 0
          (No malicious items detected)

          Registry Values: 0
          (No malicious items detected)

          Registry Data: 0
          (No malicious items detected)

          Folders: 0
          (No malicious items detected)

          Files: 1
          PUP.Optional.Proinstall, C:\Users\Sheana\Downloads\SpotifySetup-39223635.exe, , [7d052529e4b6c76fbce57d81bc4410f0],

          Physical Sectors: 0
          (No malicious items detected)


          (end)

           

          Jens

          Not really anything earth shattering was removed. This most likely is a windows problem. Have you tried to do a System Restore ?

           

          1. If your connected to a wireless router unplug the power cord from the back of the router

          2. Click on Start> All Programs> Accessories> System Tools> System Restore.
          3. When it opens click on Next
          4. Checkmark Show More Restore Points
          5. Highlight a date a few days prior to your infection
          6. Click on Next again
          7. Ckick on Finnish
          8. Just set back and let it restore, it will take a few minutes
          9. When the computer boots back up let me know how its behaving

          Yep, it seems to have done the trick, thank you. System restore - I completely forgot! It has helped me out a couple of times before..

           

          Jens

          :thumbup:

           

          Thats great Jens. Lets do this. I am going to post some instructions to remove the tools we used. If this problem shows up again post in our windows forum as there more in tune with windows issues, if you do have to post give them the link to this thread so they can see that its not a malware problem.

           

          https://forums.whatthetech.com/index.php?showforum=119       <—Our windows forum

           

           

           

          Double click on AdwCleaner.exe to run the tool again.
          •  
          • Click on the Uninstall button.
          • Click Yes when asked are you sure you want to uninstall.
          • Both AdwCleaner.exe, its folder and all logs will be removed.
           
           
           
          ==========================================================
           
           
          Please download DelFix and save the file to your Desktop.
           
          [external image: DelFix_zps139e2ea1.jpg]
           
          •  
          • Windows XP Double Click DelFix.exe to run the program. 
          • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
          • Checkmark " Remove Disinfection Tools"
          • Click the Run button
           
           
          This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
           
           
           
           
          So How did I get infected in the first place <– Some reading for you to keep yourself safe online
           
           
          Safe Surfn
          Ken
           

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI