I am trying to help my niece with her laptop. It is not the newest and fastest, it is 7years old, 2Gb ram, 2.3 GHz AMD processer, so it will of course never be ligthning fast, but it is running remarkably slow as it is. It litterally took me more tyhan 2 hours to boot, and write this message.
I can't find anything suspicious in the taskmanager. There don't seem to be any processes that uses unusually big amounts of CPU or memmory, so I Wonder if some kind of malware could be to blame? - I have executed aswMBR and FRST as instructed, and I would be grateful if someone here could take a look at the logs and see if anything looks bad.
Thanks in advance. :-)
Here comes my logs:
aswMBR.log:
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-01-11 18:17:36
—————————–
18:17:36.844 OS Version: Windows x64 6.1.7601 Service Pack 1
18:17:36.844 Number of processors: 1 586 0x603
18:17:36.844 ComputerName: NANNA-PC UserName: kim
18:17:39.621 Initialize success
18:17:39.823 VM: initialized successfully
18:17:39.823 VM: Amd CPU supported
18:22:55.388 AVAST engine defs: 17010903
18:26:04.585 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
18:26:04.585 Disk 0 Vendor: WDC_WD3200BPVT-22ZEST0 01.01A01 Size: 305245MB BusType: 11
18:26:04.741 Disk 0 MBR read successfully
18:26:04.741 Disk 0 MBR scan
18:26:04.913 Disk 0 Windows 7 default MBR code
18:26:04.913 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 14336 MB offset 2048
18:26:04.975 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 29362176
18:26:05.037 Disk 0 Boot: NTFS code=1
18:26:05.069 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 290807 MB offset 29566976
18:26:05.271 Disk 0 scanning C:\Windows\system32\drivers
18:26:18.516 Service scanning
18:26:49.310 Modules scanning
18:26:49.326 Disk 0 trace - called modules:
18:26:49.357 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
18:26:49.357 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8002453410]
18:26:49.373 3 CLASSPNP.SYS[fffff880018cd43f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80023fd060]
18:26:50.901 AVAST engine scan C:\Windows
18:26:53.273 AVAST engine scan C:\Windows\system32
18:30:19.567 AVAST engine scan C:\Windows\system32\drivers
18:30:34.013 AVAST engine scan C:\Users\kim
18:30:56.757 AVAST engine scan C:\ProgramData
18:31:51.343 Disk 0 statistics 3115093/0/0 @ 8,09 MB/s
18:31:51.358 Scan finished successfully
18:32:34.040 Disk 0 MBR has been saved successfully to "C:\Users\kim\Desktop\MBR.dat"
18:32:34.040 The log file has been saved successfully to "C:\Users\kim\Desktop\aswMBR.txt"
=======================================================================================
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-01-2017
Ran by [removed] (administrator) on NANNA-PC (11-01-2017 18:34:40)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Dansk (Danmark)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Acer Group) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_11_5_502_146_ActiveX.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11444840 2010-09-21] (Realtek Semiconductor)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated)
HKLM\…\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [206208 2010-06-09] ()
HKLM\…\Run: [Acer ePower Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe [263936 2010-06-28] (NewTech Infosystems, Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-10-28] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\…\Run: [Camera Assistant Software] => c:\program files (x86)\video web camera\traybar.exe [600688 2010-07-06] (Chicony)
HKLM-x32\…\Run: [Browser companion helper] => c:\program files (x86)\browsercompanion\bchelper.exe [182576 2011-11-29] (Blabbers Communications LTD)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\…\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
Startup: C:\Users\Nanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Screen Clipper and Launcher til OneNote 2007.lnk [2012-02-08]
ShortcutTarget: Screen Clipper and Launcher til OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.127.127.11 [removed] [removed]
Tcpip\..\Interfaces\{7669D56C-823A-4037-AC39-2D33B1373031}: [DhcpNameServer] 10.127.127.11 [removed] [removed]
Tcpip\..\Interfaces\{E78EF6AF-F479-4726-AE4C-B73851565F14}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{EF83CEBC-E005-4A94-B194-B3C18B6EBAAC}: [DhcpNameServer] [removed] [removed]
Internet Explorer:
==================
HKU\S-1-5-21-139978781-2723255831-1225844396-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/da-dk/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid;=InternetTurboYB&co;=DK&userid;=4230dde0-841b-494b-add4-53db15c814be&searchtype;=ds&q;={searchTerms}&installDate;=22/02/2013
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid;=InternetTurboYB&co;=DK&userid;=4230dde0-841b-494b-add4-53db15c814be&searchtype;=ds&q;={searchTerms}&installDate;=22/02/2013
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll => No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-20] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-20] (Oracle Corporation)
BHO: DVDVideoSoft WebPageAdjuster Class -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2013-01-30] (DVDVideoSoft Ltd.)
BHO-x32: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssie.dll => No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-03-13] (Sun Microsystems, Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-03-13] (Sun Microsystems, Inc.)
BHO-x32: DVDVideoSoft WebPageAdjuster Class -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2013-01-30] (DVDVideoSoft Ltd.)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll [2013-01-20] ()
FF Plugin: @java.com/DTPlugin,version=10.11.2 -> C:\Windows\system32\npDeployJava1.dll [2013-01-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.11.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-01-20] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll [2013-01-20] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-04-08] ()
FF Plugin-x32: @java.com/DTPlugin -> C:\Program Files (x86)\Java\jre6\bin\npDeployJava1.dll [2012-03-13] (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2012-03-13] (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-16] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-09-26] (Adobe Systems Inc.)
Chrome:
=======
CHR HKLM-x32\…\Chrome\Extension: [ibgfbdggapddbjjbopabhlhianklajie] - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx [2011-11-29]
CHR HKLM-x32\…\Chrome\Extension: [plmlpkfpkijnlijgalnjaacllnjmoamo] - C:\Users\Nanna\AppData\Local\CRE\plmlpkfpkijnlijgalnjaacllnjmoamo.crx [2012-12-01]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [971160 2016-12-15] (AVG Technologies CZ, s.r.o.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5337600 2016-12-15] (AVG Technologies CZ, s.r.o.)
S2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [725976 2016-12-15] (AVG Technologies CZ, s.r.o.)
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [868896 2010-06-11] (Acer Incorporated)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [255744 2010-06-28] (NewTech Infosystems, Inc.)
R2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [312576 2016-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [254208 2016-09-26] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [299264 2016-07-27] (AVG Technologies CZ, s.r.o.)
R0 avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)
U5 GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [33240 2012-08-21] (GEAR Software Inc.)
R4 AVGIDSFilter; system32\DRIVERS\avgidsfiltera.sys [X]
S3 k57nd60a; system32\DRIVERS\k57nd60a.sys [X]
U3 aswMBR; \??\C:\Users\kim\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\kim\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-11 18:34 - 2017-01-11 18:35 - 00014701 _____ C:\Users\kim\Desktop\FRST.txt
2017-01-11 18:33 - 2017-01-11 18:34 - 00000000 ____D C:\FRST
2017-01-11 18:32 - 2017-01-11 18:32 - 00002132 _____ C:\Users\kim\Desktop\aswMBR.txt
2017-01-11 18:32 - 2017-01-11 18:32 - 00000512 _____ C:\Users\kim\Desktop\MBR.dat
2017-01-11 18:16 - 2017-01-11 18:16 - 02419200 _____ (Farbar) C:\Users\kim\Desktop\FRST64.exe
2017-01-11 18:14 - 2017-01-11 18:14 - 05198336 _____ (AVAST Software) C:\Users\kim\Desktop\aswMBR.exe
2017-01-11 18:09 - 2017-01-11 18:09 - 00000000 ____D C:\Program Files\Common Files\AV
2017-01-11 17:32 - 2017-01-11 17:32 - 00000000 __SHD C:\Users\kim\AppData\LocalLow\EmieUserList
2017-01-11 17:29 - 2017-01-11 17:29 - 00000000 __SHD C:\Users\kim\AppData\Local\EmieUserList
2017-01-11 17:29 - 2017-01-11 17:29 - 00000000 __SHD C:\Users\kim\AppData\Local\EmieSiteList
2017-01-11 17:27 - 2017-01-11 17:32 - 00000000 __SHD C:\Users\kim\AppData\LocalLow\EmieSiteList
2017-01-11 17:13 - 2017-01-11 17:13 - 00000000 ____D C:\Users\kim\AppData\Roaming\AVG2012
2017-01-11 17:13 - 2017-01-11 17:13 - 00000000 ____D C:\Users\kim\AppData\Local\CEF
2017-01-11 17:12 - 2017-01-11 17:12 - 00110376 _____ C:\Users\kim\AppData\Local\GDIPFONTCACHEV1.DAT
2017-01-11 17:12 - 2017-01-11 17:12 - 00000000 ____D C:\Users\kim\AppData\Local\Avg
2017-01-11 17:11 - 2017-01-11 17:11 - 00000984 _____ C:\Users\Public\Desktop\AVG.lnk
2017-01-11 17:11 - 2017-01-11 17:11 - 00000000 ____D C:\Users\kim\AppData\Roaming\Apple Computer
2017-01-11 17:10 - 2017-01-11 17:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2017-01-11 17:01 - 2017-01-11 17:01 - 00001429 _____ C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-01-11 17:01 - 2017-01-11 17:01 - 00000000 ____D C:\Users\kim\AppData\Roaming\Adobe
2017-01-11 16:55 - 2017-01-11 16:55 - 00000000 ____D C:\Users\kim\AppData\Local\VirtualStore
2017-01-11 16:53 - 2017-01-11 17:00 - 00000000 ____D C:\Users\kim
2017-01-11 16:53 - 2017-01-11 16:53 - 00000020 ___SH C:\Users\kim\ntuser.ini
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Skabeloner
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Printere
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Menuen Start
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Lokale indstillinger
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Dokumenter
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Documents\Videoer
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Documents\Musik
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Documents\Billeder
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programmer
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\AppData\Local\Oversigt
2017-01-11 16:53 - 2017-01-11 16:53 - 00000000 _SHDL C:\Users\kim\Andre computere
2017-01-11 16:53 - 2013-01-31 00:57 - 00000000 ____D C:\Users\kim\AppData\Roaming\TuneUp Software
2017-01-11 16:53 - 2012-02-09 13:02 - 00000000 ____D C:\Users\kim\AppData\Local\Microsoft Help
2017-01-11 16:53 - 2009-07-14 08:44 - 00000000 ____D C:\Users\kim\AppData\Roaming\Media Center Programs
2017-01-11 16:46 - 2017-01-11 16:46 - 00003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-01-11 16:37 - 2017-01-11 17:37 - 00000000 ____D C:\ProgramData\Avg
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-11 18:12 - 2012-08-02 11:31 - 00000000 ___HD C:\$AVG
2017-01-11 18:12 - 2012-02-06 11:00 - 00000000 ____D C:\ProgramData\AVG2012
2017-01-11 18:12 - 2012-02-06 10:58 - 00000000 ____D C:\Program Files (x86)\AVG
2017-01-11 18:12 - 2012-02-06 10:42 - 00000000 ____D C:\ProgramData\MFAData
2017-01-11 18:11 - 2014-05-25 14:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-01-11 18:08 - 2013-01-20 14:34 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-01-11 17:50 - 2008-12-31 23:17 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-01-11 16:54 - 2013-01-26 16:56 - 00000354 _____ C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job
2017-01-11 16:38 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-11 16:38 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
Files to move or delete:
====================
C:\Users\Nanna\temp.dat
Some files in TEMP:
====================
C:\Users\Michael\AppData\Local\Temp\1249DF99.dll
C:\Users\Michael\AppData\Local\Temp\3FE192CE.dll
C:\Users\Michael\AppData\Local\Temp\3FE4B813.dll
C:\Users\Michael\AppData\Local\Temp\3FE5CADB.dll
C:\Users\Michael\AppData\Local\Temp\42E29267.dll
C:\Users\Michael\AppData\Local\Temp\42E75679.dll
C:\Users\Michael\AppData\Local\Temp\4EA186D8.dll
C:\Users\Michael\AppData\Local\Temp\4EA4B6AF.dll
C:\Users\Michael\AppData\Local\Temp\7DB3C97C.dll
C:\Users\Michael\AppData\Local\Temp\90CAF1B7.dll
C:\Users\Nanna\AppData\Local\Temp\04F76823.dll
C:\Users\Nanna\AppData\Local\Temp\12ED7C46.dll
C:\Users\Nanna\AppData\Local\Temp\12ED7E1A.dll
C:\Users\Nanna\AppData\Local\Temp\1444B246.dll
C:\Users\Nanna\AppData\Local\Temp\32D4FFBF.dll
C:\Users\Nanna\AppData\Local\Temp\32DFDFA4.dll
C:\Users\Nanna\AppData\Local\Temp\33E8E5A1.dll
C:\Users\Nanna\AppData\Local\Temp\46BAACDD.dll
C:\Users\Nanna\AppData\Local\Temp\47A8F8F3.dll
C:\Users\Nanna\AppData\Local\Temp\47B3617E.dll
C:\Users\Nanna\AppData\Local\Temp\8DE221F7.dll
C:\Users\Nanna\AppData\Local\Temp\8DE7710F.dll
C:\Users\Nanna\AppData\Local\Temp\8DEC051B.dll
C:\Users\Nanna\AppData\Local\Temp\9DD13E8D.dll
C:\Users\Nanna\AppData\Local\Temp\9DD560B6.dll
C:\Users\Nanna\AppData\Local\Temp\9DD77CF2.dll
C:\Users\Nanna\AppData\Local\Temp\9DD7E0D6.dll
C:\Users\Nanna\AppData\Local\Temp\EBEEE7EE.dll
C:\Users\Nanna\AppData\Local\Temp\F3891244.dll
C:\Users\Nanna\AppData\Local\Temp\Installer.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Nanna\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2013-04-30 18:44
==================== End of FRST.txt ============================
Addition.txt:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-01-2017
Ran by [removed] (11-01-2017 18:35:46)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-01-30 19:02:06)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-139978781-2723255831-1225844396-500 - Administrator - Disabled)
Gæst (S-1-5-21-139978781-2723255831-1225844396-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-139978781-2723255831-1225844396-1002 - Limited - Enabled)
kim (S-1-5-21-139978781-2723255831-1225844396-1004 - Administrator - Enabled) => C:\Users\kim
Nanna (S-1-5-21-139978781-2723255831-1225844396-1001 - Administrator - Enabled) => C:\Users\Nanna
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: AVG Anti-Virus Free Edition 2012 (Enabled - Up to date) {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: AVG AntiVirus Free Edition (Disabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: AVG Anti-Virus Free Edition 2012 (Enabled - Up to date) {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Disabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Flash Player 11 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 11.5.502.146 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 11.5.502.146 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.05) - Dansk (HKLM-x32\…\{AC76BA86-7AD7-1030-7B44-AB0000000001}) (Version: 11.0.05 - Adobe Systems Incorporated)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Apple Mobile Device Support (HKLM\…\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Apple-programunderstøttelse (HKLM-x32\…\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
ATI Catalyst Install Manager (HKLM\…\{2023DAEC-90C2-E042-909F-BFAD8AC9B60C}) (Version: 3.0.795.0 - ATI Technologies, Inc.)
AVG (HKLM\…\AvgZen) (Version: 1.113.2.50020 - AVG Technologies)
AVG (Version: 16.141.7996 - AVG Technologies) Hidden
AVG 2012 (Version: 12.0.3222 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4749 - AVG Technologies) Hidden
AVG Protection (HKLM\…\AVG) (Version: 2016.141.7996 - AVG Technologies)
AVG Zen (Version: 1.113.1 - AVG Technologies) Hidden
Backup Manager Basic (x32 Version: 2.0.0.68 - NewTech Infosystems) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon MP490 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) (Version: - )
ccc-core-static (x32 Version: 2010.1028.1114.18274 - Dit firmanavn) Hidden
FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden
Free YouTube Download version 3.2.0.128 (HKLM-x32\…\Free YouTube Download_is1) (Version: 3.2.0.128 - DVDVideoSoft Ltd.)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3003 - Packard Bell)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
iTunes (HKLM\…\{76FF0F03-B707-4332-B5D1-A56C8303514E}) (Version: 11.0.4.4 - Apple Inc.)
Java 7 Update 11 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417011FF}) (Version: 7.0.110 - Oracle)
Java 7 Update 45 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Java(TM) 6 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 4.0.14 - Packard Bell)
Microsoft .NET Framework 4.5.1 (dansk) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1030) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\…\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Klik og kør 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - dansk (HKLM-x32\…\{90140011-0066-0406-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\…\{95140000-00AF-0406-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyTomTom 3.2.0.1055 (HKLM-x32\…\MyTomTom) (Version: 3.2.0.1055 - TomTom)
Nero 9 Essentials (HKLM-x32\…\{a97f0ac6-e34b-400a-8ce4-c4a5ab45344e}) (Version: - Nero AG)
Opdatering til Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\…\{90120000-0016-0406-0000-0000000FF1CE}_ENTERPRISE_{7304A9DD-2F95-4147-8CD4-E135168C61E6}) (Version: - Microsoft)
Opdatering til Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\…\{90120000-0018-0406-0000-0000000FF1CE}_ENTERPRISE_{0C315122-B0FA-428D-A3BB-6F6510F866FF}) (Version: - Microsoft)
Opdatering til Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\…\{90120000-001B-0406-0000-0000000FF1CE}_ENTERPRISE_{EA60117C-C535-4A3F-AED1-C888F5114210}) (Version: - Microsoft)
Overførselsværktøj til Windows Live (HKLM-x32\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Packard Bell MyBackup (HKLM-x32\…\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.68 - NewTech Infosystems)
Packard Bell Power Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.00.3005 - Packard Bell)
Packard Bell Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Packard Bell)
Packard Bell Social Networks (HKLM-x32\…\InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}) (Version: 1.0.1901 - CyberLink Corp.)
Packard Bell Social Networks (x32 Version: 1.0.1901 - CyberLink Corp.) Hidden
Packard Bell Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3001 - Packard Bell)
Realtek HDMI Audio Driver for ATI (HKLM-x32\…\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6034 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6206 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30122 - Realtek Semiconductor Corp.)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 14.0.19.0 - Synaptics Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Video Web Camera (HKLM-x32\…\{12A1B519-5934-4508-ADBD-335347B0DC87}) (Version: 1.7.137.706 - Chicony Electronics Co.,Ltd.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\…\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Visual Studio C++ 10.0 Runtime (HKLM-x32\…\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{02B8DBC1-7312-43AF-8BA7-9F29CDD6B348}) (Version: 14.0.8117.416 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {2920AE8A-E72D-4EBA-9DAD-AE00CD10462A} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {429F750E-E424-45C8-8111-D5FB15349F9D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-20] (Adobe Systems Incorporated)
Task: {9600B749-2A15-48D3-8CFE-840073931790} - System32\Tasks\ROC_JAN2013_TB_rmv => C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe
Task: {CA648314-17B8-4937-A075-A31D6AFC81D0} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job => C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2011-11-01 23:26 - 2011-11-01 23:26 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-11-01 23:26 - 2011-11-01 23:26 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2010-06-28 23:20 - 2010-06-28 23:20 - 00465576 _____ () C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
2010-06-28 23:12 - 2010-06-28 23:12 - 01081600 _____ () C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\ACE.dll
2010-09-16 11:55 - 2009-05-20 07:02 - 00072200 _____ () C:\Program Files (x86)\Launch Manager\CdDirIo.dll
2017-01-11 16:46 - 2017-01-11 16:43 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-139978781-2723255831-1225844396-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\kim\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.127.127.11 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{BCBB3E32-8A4F-4C9D-87AD-85113628492E}] => C:\Program Files (x86)\Adobe\Elements Organizer 8.0\AdobePhotoshopElementsMediaServer.exe
FirewallRules: [{527B415A-27C4-4ADB-B950-CDBE0381B93B}] => C:\Program Files (x86)\Adobe\Elements Organizer 8.0\AdobePhotoshopElementsMediaServer.exe
FirewallRules: [{26C2BCCA-4635-4F92-9D64-50FC3EEAF567}] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{C81A9253-C70B-43EC-8079-F45E33B09434}] => svchost.exe
FirewallRules: [{8149B6A7-322F-4D7E-A04D-7BB5AB381D5B}] => C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{D7832EB0-A552-4AED-956E-C1FBDDEB0AF0}] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{A07AE41F-B8CA-452C-893D-BF343EF0F8ED}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{21940ECF-7B93-4E19-999B-AB5F9684F2AD}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{35041BCB-9238-4632-947C-AB79063999A1}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{12307BD3-B4C1-4372-A808-A5EF13025A9A}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{D28254BF-B9FA-4DD7-AE11-4F5F62C4F8E5}C:\program files (x86)\java\jre6\bin\java.exe] => C:\program files (x86)\java\jre6\bin\java.exe
FirewallRules: [UDP Query User{A11C4438-88A8-4516-9846-811F601BFE0D}C:\program files (x86)\java\jre6\bin\java.exe] => C:\program files (x86)\java\jre6\bin\java.exe
FirewallRules: [{82519764-9E61-4217-A9C1-52A87A1A073B}] => C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{CB885D71-8C2E-40FD-A68A-9A707B772756}] => C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{222521B9-0F4B-4F02-ADFE-91FE875C7850}] => C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{C75E0D39-0CA3-45B8-87A0-65B7EB8A919C}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{299A961A-D598-4808-ADB4-367148342122}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{691331BF-2AA2-4A67-9AA2-71300EA16A46}] => C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{949A55D3-7ABC-445C-A20A-BCDF28BAFAD1}] => C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{D65CE8C4-D29B-4AA5-A214-2ECCDC59A084}] => C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{CFDB7880-5B88-4A8C-B910-29DD3FE13B28}] => C:\Program Files (x86)\AVG\Av\avgemca.exe
==================== Restore Points =========================
31-12-2008 23:31:32 Windows Update
18-01-2014 23:30:44 Windows Update
20-04-2014 19:54:32 Windows Update
20-04-2014 20:22:16 Windows Update
25-05-2014 14:47:38 Windows Update
25-05-2014 16:13:12 Windows Update
06-07-2014 18:23:05 Windows Update
11-01-2017 17:25:02 Installed AVG 2016
11-01-2017 17:40:03 Installed AVG
==================== Faulty Device Manager Devices =============
Name: TSSTcorp CDDVDW TS-L633F ATA Device
Description: cd-rom-drev
Class Guid: {4d36e965-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard cd-rom-drev)
Service: cdrom
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
Name: Ethernet-controller
Description: Ethernet-controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (01/11/2017 06:07:43 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: Sikkerhedskopieringen blev ikke fuldført, da der ikke kunne skrives til sikkerhedskopiplaceringen D:\. Fejlen er: Sikkerhedskopiplaceringen blev ikke fundet, eller den er ikke gyldig. Gennemgå indstillingerne for sikkerhedskopiering, og kontrollér sikkerhedskopiplaceringen. (0x81000006).
Error: (01/11/2017 04:52:58 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Aktiveringskontekstgenereringen mislykkedes for "C:\Windows\Temp\AvgSetup\1b29118f-ce2e-47cf-8e9c-35bbaea1640d\install\fmw\avgrdsttestx.exe".
Afhængig samling AVG.VC140.CRT,processorArchitecture="x86",publicKeyToken="f92d94485545da78",type="win32",version="14.0.23918.0" blev ikke fundet.
Anvend sxstrace.exe til detaljeret diagnose.
Error: (01/11/2017 04:51:12 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Aktiveringskontekstgenereringen mislykkedes for "C:\Windows\Temp\AvgSetup\1b29118f-ce2e-47cf-8e9c-35bbaea1640d\install\fmw\avgrdsttesta.exe".
Afhængig samling AVG.VC140.CRT,processorArchitecture="amd64",publicKeyToken="f92d94485545da78",type="win32",version="14.0.23918.0" blev ikke fundet.
Anvend sxstrace.exe til detaljeret diagnose.
Error: (01/11/2017 04:45:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programmet Explorer.EXE version 6.1.7601.17567 afbrød kommunikationen med Windows og blev afsluttet. Hvis du vil se, om der findes flere oplysninger om problemet, kan du læse om problemets historik via Løsningscenter.
Proces-id: dbc
Starttidspunkt: 01c96ba61d45d445
Afslutningstidspunkt: 18159
Programsti: C:\Windows\Explorer.EXE
Rapport-id: c768a8c0-d814-11e6-ad26-e4f2e8458dfe
Error: (01/01/2009 12:54:22 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Fjernelse af ydelsestællerstrenge for tjenesten WmiApRpl (WmiApRpl) mislykkedes. Det første DWORD i dataafsnittet indeholder fejlkoden.
Error: (01/01/2009 12:54:22 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Ydelsestællerstrengene i registreringsdatabaseværdien for ydelse blev beskadiget under behandling af udvidelsestællerudbyderen Performance. Værdien BaseIndex fra registreringsdatabasen for ydelse er det første DWORD i dataafsnittet, værdien LastCounter er det andet DWORD i dataafsnittet, og værdien LastHelp er det tredje DWORD i dataafsnittet.
Error: (01/01/2009 12:54:21 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Ydelsestællerstrengene i registreringsdatabaseværdien for ydelse blev beskadiget under behandling af udvidelsestællerudbyderen Performance. Værdien BaseIndex fra registreringsdatabasen for ydelse er det første DWORD i dataafsnittet, værdien LastCounter er det andet DWORD i dataafsnittet, og værdien LastHelp er det tredje DWORD i dataafsnittet.
Error: (12/31/2008 11:11:43 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Kun oplysninger.
(Patch task for {90140011-0066-0406-0000-0000000FF1CE}): DownloadLatest Failed: Der er ingen aktiv netværksforbindelse i øjeblikket. BITS (Background Intelligent Transfer Service) prøver igen, når der er tilsluttet et netværkskort.
Error: (12/31/2008 11:06:33 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Fjernelse af ydelsestællerstrenge for tjenesten WmiApRpl (WmiApRpl) mislykkedes. Det første DWORD i dataafsnittet indeholder fejlkoden.
Error: (12/31/2008 11:06:33 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Ydelsestællerstrengene i registreringsdatabaseværdien for ydelse blev beskadiget under behandling af udvidelsestællerudbyderen Performance. Værdien BaseIndex fra registreringsdatabasen for ydelse er det første DWORD i dataafsnittet, værdien LastCounter er det andet DWORD i dataafsnittet, og værdien LastHelp er det tredje DWORD i dataafsnittet.
System errors:
=============
Error: (01/11/2017 06:09:08 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Tjenesten AVGIDSAgent blev afbrudt med den tjenestespecifikke fejl %%-536753635.
Error: (01/11/2017 06:03:29 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten avgwd.
Error: (01/11/2017 05:54:08 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten Browser.
Error: (01/11/2017 05:53:38 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten Browser.
Error: (01/11/2017 05:53:08 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten Browser.
Error: (01/11/2017 05:24:36 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: Fejlen "1053" opstod på DCOM under forsøg på at starte tjenesten VSS med argumenterne "" for at køre serveren:
{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}
Error: (01/11/2017 05:24:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Tjenesten Øjebliksbillede af diskenhed kunne ikke starte pga. følgende fejl:
Tjenesten svarede ikke på en start- eller kontrolanmodning inden for det forventede tidsinterval.
Error: (01/11/2017 05:24:36 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Der opstod timeout (30000 millisekunder), mens systemet ventede på, at der blev oprettet forbindelse til tjenesten Øjebliksbillede af diskenhed.
Error: (01/11/2017 05:00:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Tjenesten AVG Service kunne ikke starte pga. følgende fejl:
Tjenesten svarede ikke på en start- eller kontrolanmodning inden for det forventede tidsinterval.
Error: (01/11/2017 05:00:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Der opstod timeout (30000 millisekunder), mens systemet ventede på, at der blev oprettet forbindelse til tjenesten AVG Service.
==================== Memory info ===========================
Processor: AMD V140 Processor
Percentage of memory in use: 63%
Total physical RAM: 1786.9 MB
Available physical RAM: 650.87 MB
Total Virtual: 4021.8 MB
Available Virtual: 2389.91 MB
==================== Drives ================================
Drive c: (Packard Bell) (Fixed) (Total:283.99 GB) (Free:217.56 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 9DBC78D8)
Partition 1: (Not Active) - (Size=14 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=284 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================