This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow computer [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My wife has a Dell Latitude D630 computer with Win 7 and mostly uses Google Chrome.  Her computer is slow, especially when there are more than 7 or so tabs open.  I think there is malware.  I have run Malwarebytes and 360 Total Security and they show no malware but I am unconvinced.  Can anyone help?

 

Thanks

GB

:welcome:

 

 
[external image: 1QYkxTZ.jpg] Please download aswMBR to your DESKTOP <<<<<
 
  •  
  • Right click the aswMBR icon and select Run as Administrator
  • XP users just Double Click it to run
  • If it says that this computer supports VIRTUALIZATION TECHNOLOGY do you want to use it say Yes
  • Click the Scan button to start scan.
  • Select Quickscan on the dropdown list
  • If you are asked to update the Avast Virus database please allow it to do so.
  • The scan could take 20 minutes or more , please be patient and let it finish
  • It will say Scan Finished when its done.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
 
 
I just want to see the report….Please Do Not Fix Anything
 
 
 
============================================================================
 
 
 
 
Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
 

 

Thank you for helping. Here are the scans.
GB

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-07-10 23:57:20
—————————–
23:57:20.124 OS Version: Windows x64 6.1.7601 Service Pack 1
23:57:20.125 Number of processors: 2 586 0xF0B
23:57:20.180 ComputerName: USER-PC UserName: USER
23:57:34.098 Initialize success
23:57:35.170 VM: initialized successfully
23:57:35.172 VM: Intel CPU BiosDisabled
00:07:22.878 AVAST engine defs: 17030301
01:36:33.623 The log file has been saved successfully to "C:\Users\USER\Desktop\aswMBR.txt"


aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-07-10 23:57:20
—————————–
23:57:20.124 OS Version: Windows x64 6.1.7601 Service Pack 1
23:57:20.125 Number of processors: 2 586 0xF0B
23:57:20.180 ComputerName: USER-PC UserName: USER
23:57:34.098 Initialize success
23:57:35.170 VM: initialized successfully
23:57:35.172 VM: Intel CPU BiosDisabled
00:07:22.878 AVAST engine defs: 17030301
01:36:33.623 The log file has been saved successfully to "C:\Users\USER\Desktop\aswMBR.txt"
01:39:56.004 The log file has been saved successfully to "C:\Users\USER\Desktop\aswMBR.txt"





Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2017
Ran by [removed] (11-07-2017 01:51:27)
Running from C:\Users\[removed]\Downloads
Windows 7 Ultimate Service Pack 1 (X64) (2016-03-11 00:10:30)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1569642822-292156195-3241122032-500 - Administrator - Disabled)
Guest (S-1-5-21-1569642822-292156195-3241122032-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1569642822-292156195-3241122032-1003 - Limited - Enabled)
USER (S-1-5-21-1569642822-292156195-3241122032-1000 - Administrator - Enabled) => C:\Users\USER

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: 360 Total Security (Enabled - Up to date) {0371CA44-3F80-A1D3-BECE-910620B58D50}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: 360 Total Security (Enabled - Up to date) {B8102BA0-19BA-AE5D-847E-AA745B32C7ED}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

360 Total Security (HKLM-x32\…\360TotalSecurity) (Version: 9.0.0.1202 - 360 Security Center)
Acronis True Image 2016 (HKLM-x32\…\{986072E2-9A8A-4BE9-896B-18C3219BCE58}) (Version: 19.0.5518 - Acronis) Hidden
Acronis True Image 2016 (HKLM-x32\…\{986072E2-9A8A-4BE9-896B-18C3219BCE58}Visible) (Version: 19.0.5518 - Acronis)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe Flash Player 26 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Ashampoo Burning Studio 11 v.11.0.2 (HKLM-x32\…\Ashampoo Burning Studio 11_is1) (Version: 11.0.2 - Ashampoo GmbH & Co. KG)
Brother MFL-Pro Suite MFC-J825DW (HKLM-x32\…\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.1.6.0 - Brother Industries, Ltd.)
BS.Player PRO (HKLM-x32\…\BSPlayerp) (Version: 2.69.1078 - AB Team, d.o.o.)
CAM UnZip 5.2.0.0 (HKLM-x32\…\CUZ5_is1) (Version: - CAM Development)
Citrix Online Launcher (HKLM-x32\…\{48947098-A67C-46D4-90C5-9F2F6F0F96FE}) (Version: 1.0.449 - Citrix)
CyberLink PowerDVD 11 (HKLM-x32\…\InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}) (Version: 11.0.1719.51 - CyberLink Corp.)
Driver Support (HKLM-x32\…\DriverSupport) (Version: 10.1.3.34 - PC Drivers HeadQuarters LP) <==== ATTENTION
FreeScreenSharing (HKU\S-1-5-21-1569642822-292156195-3241122032-1000\…\FreeScreenSharing) (Version: 0.58.75.0 - Free Conferencing Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.3 - Google Inc.) Hidden
GoToMeeting 8.7.0.7155 (HKU\S-1-5-21-1569642822-292156195-3241122032-1000\…\GoToMeeting) (Version: 8.7.0.7155 - CitrixOnline)
Intel Security True Key (HKLM\…\TrueKey) (Version: 4.19.108.1 - Intel Security)
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
LG AirDrive (HKLM-x32\…\{101E5DB3-07FA-4E52-8923-05068C94CF43}) (Version: 1.2.60617.11 - LG Electronics)
LG Bridge (HKLM-x32\…\LG Bridge) (Version: 1.2.18 - LG Electronics)
LG Mobile Driver (HKLM-x32\…\{3F490D0E-3131-438C-BCF9-7549CB88DF41}) (Version: 4.1.1 - LG Electronics)
Linksys Connect (HKLM-x32\…\Linksys Connect) (Version: 1.5.15287.0 - Linksys LLC)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\…\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
The Unzip Wizard (HKLM-x32\…\The Unzip Wizard) (Version: - )
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Zoom (HKU\S-1-5-21-1569642822-292156195-3241122032-1000\…\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1569642822-292156195-3241122032-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\USER\AppData\Local\Citrix\GoToMeeting\6749\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2015-07-23] (Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2015-07-23] (Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2015-07-23] (Acronis)
ContextMenuHandlers01: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2017-06-09] ()
ContextMenuHandlers01: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => -> No File
ContextMenuHandlers01: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers03: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers04: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2017-06-09] ()
ContextMenuHandlers04: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2009-09-23] (Intel Corporation)
ContextMenuHandlers05: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers06: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2017-06-09] ()
ContextMenuHandlers06: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => -> No File
ContextMenuHandlers06: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0B7B9022-9008-42C1-BE30-84619AB03DE0} - System32\Tasks\G2MUploadTask-S-1-5-21-1569642822-292156195-3241122032-1000 => C:\Users\USER\AppData\Local\Citrix\GoToMeeting\7155\g2mupload.exe [2017-06-13] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {50D25BB3-976D-4D60-B23A-CD590BE0398F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-24] (Adobe Systems Incorporated)
Task: {536E9D21-486F-457E-84C6-5F5431E9D540} - System32\Tasks\G2MUpdateTask-S-1-5-21-1569642822-292156195-3241122032-1000 => C:\Users\USER\AppData\Local\Citrix\GoToMeeting\7155\g2mupdate.exe [2017-06-13] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {5ACBC616-0A12-410B-AEC4-31898DD4E2D2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-23] (Google Inc.)
Task: {7AE76A1D-59DE-4E19-BA1F-13DE522827DE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {9679BE3B-1702-4A4C-8B47-E180AFF9A66E} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_26_0_0_131_pepper.exe [2017-06-24] (Adobe Systems Incorporated)
Task: {A8F9CDDF-52B1-4D41-814C-21BAB977B674} - System32\Tasks\Driver Support => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2016-08-10] (PC Drivers Headquarters)
Task: {B7EC7288-73CF-4093-970D-F5B32EF9D0EB} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2016-12-15] (McAfee, Inc.)
Task: {D3C015CC-DC08-4290-96DA-98F651E54C1B} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2016-08-10] (PC Drivers Headquarters)
Task: {D708DFAD-0BC4-47DF-B761-E4291E42AF3C} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2016-08-10] (PC Drivers Headquarters)
Task: {E034AA29-BAE4-4718-92D8-32107A76E085} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2016-08-10] (PC Drivers Headquarters)
Task: {EF03D0EA-E8EF-4A0F-A45F-7BA3ACB28357} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-23] (Google Inc.)
Task: {FCB202BD-083B-45F6-99C2-933FA8943C84} - System32\Tasks\{2D2EC208-BE45-4E45-B192-781DF9CA4591} => C:\Program Files (x86)\LG Electronics\LG Bridge\LGBridge.exe [2016-07-21] (LG Electronics)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1569642822-292156195-3241122032-1000.job => C:\Users\USER\AppData\Local\Citrix\GoToMeeting\7155\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1569642822-292156195-3241122032-1000.job => C:\Users\USER\AppData\Local\Citrix\GoToMeeting\7155\g2mupload.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2016-03-10 16:30 - 2011-05-18 19:00 - 00083240 _____ () C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
2016-03-10 16:54 - 2017-06-09 01:00 - 00099240 _____ () C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll
2016-03-10 16:54 - 2017-06-09 01:00 - 00498272 _____ () C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll
2016-10-11 23:29 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2015-08-16 23:44 - 2015-08-16 23:44 - 00036160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll
2015-08-16 23:44 - 2015-08-16 23:44 - 00446272 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll
2015-08-16 23:44 - 2015-08-16 23:44 - 00116032 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\EXPAT.dll
2017-04-20 22:50 - 2017-03-28 18:04 - 02187096 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libglesv2.dll
2017-04-20 22:50 - 2017-03-28 18:04 - 00086360 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1569642822-292156195-3241122032-1000\…\driversupport.com -> hxxp://apps.driversupport.com
IE trusted site: HKU\S-1-5-21-1569642822-292156195-3241122032-1000\…\driversupport.com -> hxxps://apps.driversupport.com

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 18:34 - 2017-05-21 01:21 - 00000838 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 activation.acronis.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1569642822-292156195-3241122032-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\USER\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: Acronis Scheduler2 Service => "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
MSCONFIG\startupreg: AcronisTibMounterMonitor => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: ControlCenter4 => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: FreeScreenSharing => C:\Users\USER\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: RemoteControl11 => "C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe"
MSCONFIG\startupreg: TrueImageMonitor.exe => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{A0027C7A-1E63-444E-9EAD-79441C14E670}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\PowerDVD11.exe
FirewallRules: [{8302C41C-A07B-4DC3-9126-F58EB97D5F36}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe
FirewallRules: [{8FB9F484-95CB-4F34-8C15-9EADBFE59A29}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
FirewallRules: [{A7E582B0-57A2-47D4-B474-76510248E652}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\Movie\MovieModule.exe
FirewallRules: [{EE6C942E-C218-4866-9199-5573BF7C7149}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\Movie\PowerDVD Cinema\PowerDVDCinema11.exe
FirewallRules: [{032826FE-5294-4D2F-8951-42E30D4805E8}] => (Allow) C:\Users\USER\AppData\Local\Temp\chrome.exe
FirewallRules: [{15DE69DA-1D77-443F-BE73-0650689DF99F}] => (Allow) C:\Users\USER\AppData\Local\Temp\chrome.exe
FirewallRules: [{09BDB1A6-8431-4A94-8EB3-D0E760732B96}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{13AC9174-F59F-4ABA-B8B3-6BC6AE7A71C7}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe
FirewallRules: [{4331D2E6-448F-4E9A-A98F-B1975F750C16}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{E2E3669C-53C0-44A0-BA9F-3F8636A60D53}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{1A24B702-8747-45EF-84C7-85625073225C}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{9BE300FC-1325-4BB8-8C3E-B22F92C4673B}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{9F12E978-B2ED-40D8-9CEE-D6C7C4788E7C}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\InstantSetup.exe
FirewallRules: [{28F87125-FEB2-44AF-BC64-62555D52A346}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\InstantSetup.exe
FirewallRules: [{DAA0E368-95E7-4156-ACD3-F84921F762FD}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{25B65283-8BB4-4EC3-BB60-7995C30437E3}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{6C19E9BF-9255-4B9A-9891-D935B7A5B7E4}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{E47C08CD-158C-4B7D-85D8-8AD5C3D706A5}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [TCP Query User{A710672D-1E30-46A8-B6DB-50972914BF30}C:\users\user\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\user\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe
FirewallRules: [UDP Query User{87DC36E8-D25D-4D39-B141-958ACEE4B229}C:\users\user\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\user\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe
FirewallRules: [TCP Query User{2CF87008-053D-4D99-839D-075BF440EFB3}C:\users\user\appdata\local\logmein rescue applet\lmir0002.tmp\lmi_rescue.exe] => (Allow) C:\users\user\appdata\local\logmein rescue applet\lmir0002.tmp\lmi_rescue.exe
FirewallRules: [UDP Query User{85E9F466-B495-4241-8AE7-F1C7C4C8F4E4}C:\users\user\appdata\local\logmein rescue applet\lmir0002.tmp\lmi_rescue.exe] => (Allow) C:\users\user\appdata\local\logmein rescue applet\lmir0002.tmp\lmi_rescue.exe
FirewallRules: [{62026277-0E71-4CD5-B0CC-F8950BDD1B33}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{89ADA82F-3DE2-4247-807D-33539B90C16C}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{055A4135-5F81-4411-BA8E-776E3AABCBA3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{7D3A8F20-6FA9-44F5-9A80-EA13E734F345}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{DF9AC609-3B5A-4DAD-A9F3-E89C295980A0}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe

==================== Restore Points =========================

06-07-2017 16:32:29 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/09/2017 07:48:43 PM) (Source: Acronis Scheduler) (EventID: 1) (User: USER-PC)
Description: Scheduler failed to run task with GUID 'A2BB4F95-348C-4590-958E-DF518374D6D4' because of error 5 (Access is denied.).

Error: (07/09/2017 04:25:44 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/09/2017 04:24:45 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.

Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/09/2017 04:24:45 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.

Context: Windows Application

Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/09/2017 04:24:45 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/09/2017 04:24:45 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
Element not found. (HRESULT : 0x80070490) (0x80070490)

Error: (07/09/2017 04:24:44 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/09/2017 04:24:44 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: The Windows Search Service cannot load the property store information.

Context: Windows Application, SystemIndex Catalog

Details:
The content index database is corrupt. (HRESULT : 0xc0041800) (0xc0041800)

Error: (07/09/2017 04:24:44 AM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.

Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/09/2017 04:24:44 AM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: The search service has detected corrupted data files in the index {id=4700}. The service will attempt to automatically correct this problem by rebuilding the index.

Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)


System errors:
=============
Error: (07/11/2017 12:19:43 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/11/2017 12:18:36 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/10/2017 11:49:00 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/10/2017 11:48:09 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/10/2017 09:59:36 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/09/2017 04:24:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (07/09/2017 04:24:46 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The Windows Search service terminated with service-specific error %%-1073473535.

Error: (07/09/2017 04:24:19 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Service Installer TrueKey service failed to start due to the following error:
The system cannot find the file specified.

Error: (07/07/2017 04:09:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Service Installer TrueKey service failed to start due to the following error:
The system cannot find the file specified.

Error: (07/07/2017 04:09:22 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 4:06:32 PM on ‎7/‎7/‎2017 was unexpected.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU T7500 @ 2.20GHz
Percentage of memory in use: 94%
Total physical RAM: 2037.97 MB
Available physical RAM: 105.13 MB
Total Virtual: 5678.15 MB
Available Virtual: 1736.88 MB

==================== Drives ================================

Drive c: (New Volume) (Fixed) (Total:74.53 GB) (Free:31.75 GB) NTFS ==>[drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 74.5 GB) (Disk ID: A0C27A56)
Partition 1: (Active) - (Size=74.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2017
Ran by [removed] (administrator) on USER-PC (11-07-2017 01:57:17)
Running from C:\Users\[removed]\Downloads
[removed]

Good Morning,

 

I think what I would do first is uninstall Driver Support , if you need updated drivers for a device its always best to go right to the manufacturer in lieu of using a 3rd party program.  Its running as a task using up system resources.  You can uninstall it via Programs and Features in the Control Panel.

 

I am not looking at anything earthshattering on your logs, although I see some things need to be fixed on your FRST log but before we do that lets run these programs and see what they find and remove.  Its always best to download and run the programs from the desktop in lieu of having the program buried in a folder.

 

 

-AdwCleaner-by Xplode

 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
[external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 

 

 

Ken

I deleted the Driver support. What is the differencee between ADWCleaner and malwarebytes? I used malwarebytes before contact what the tech. lping.

Thanks for helping
GB

Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 7 Ultimate x64
Ran by [removed] (Administrator) on Thu 07/13/2017 at 3:05:48.50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 16

Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WL1QEWZ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DCQ8TOC8 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U104L9XB (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WQGPVGFE (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WL1QEWZ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DCQ8TOC8 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U104L9XB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WQGPVGFE (Temporary Internet Files Folder)



Registry: 0

# AdwCleaner v6.047 - Logfile created 13/07/2017 at 02:48:36
# Updated on 19/05/2017 by Malwarebytes
# Database : 2017-07-11.1 [Server]
# Operating System : Windows 7 Ultimate Service Pack 1 (X64)
# Username : USER - USER-PC
# Running from : C:\Users\USER\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****



***** [ Folders ] *****



***** [ Files ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****



***** [ Scheduled Tasks ] *****



***** [ Registry ] *****

[-] Key deleted: HKCU\Software\968b0cd4741bd45d13980d124343ffb7
[-] Key deleted: HKU\S-1-5-21-1569642822-292156195-3241122032-1000\Software\Conduit
[-] Key deleted: HKU\S-1-5-21-1569642822-292156195-3241122032-1000\Software\eSupport.com
[#] Key deleted on reboot: HKCU\Software\Conduit
[#] Key deleted on reboot: HKCU\Software\eSupport.com
[#] Key deleted on reboot: [x64] HKCU\Software\Conduit
[#] Key deleted on reboot: [x64] HKCU\Software\eSupport.com
[-] Key deleted: HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[#] Key deleted on reboot: [x64] HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd

AdwCleaner is a different program that has recently been aqurired by Malwarebyes and scans and removes adware.  Junkware Removal is also owned by Malwarebyes and it found and removed some adware, go ahead and run AdwCleaner

My bad, saw Junkware Removal report and missed AdwCleaner   :smack:

 

You have Malwarebytes installed, open it, check for updates and run the Threat scan, make sure it removes anything it finds, if the scan comes back clean, just let me know then there will be no need to post the log.

 

Go into your Downloads folder and look for FRST64, right click on it and select CUT, come back to you desktop and on a blank space right click and select PASTE, then we will have FRST64 on the desktop where we need it to be

 

Then Right click on FRST64 and select RUN AS ADMINISTRATOR, make sure there is a checkmark in ADDITIONS,  leave everything else as is, then click on SCAN and post both new FRST64 and Additions logs and lets see if there is anything else to remove

Ken,

Mawarebytes found nothing. Here is FRST 64. Thanks for helping.

GB

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2017
Ran by [removed] (15-07-2017 04:37:18)
Running from C:\Users\[removed]\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2016-03-11 00:10:30)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1569642822-292156195-3241122032-500 - Administrator - Disabled)
Guest (S-1-5-21-1569642822-292156195-3241122032-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1569642822-292156195-3241122032-1003 - Limited - Enabled)
USER (S-1-5-21-1569642822-292156195-3241122032-1000 - Administrator - Enabled) => C:\Users\USER

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: 360 Total Security (Enabled - Up to date) {0371CA44-3F80-A1D3-BECE-910620B58D50}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: 360 Total Security (Enabled - Up to date) {B8102BA0-19BA-AE5D-847E-AA745B32C7ED}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

360 Total Security (HKLM-x32\…\360TotalSecurity) (Version: 9.0.0.1202 - 360 Security Center)
Acronis True Image 2016 (HKLM-x32\…\{986072E2-9A8A-4BE9-896B-18C3219BCE58}) (Version: 19.0.5518 - Acronis) Hidden
Acronis True Image 2016 (HKLM-x32\…\{986072E2-9A8A-4BE9-896B-18C3219BCE58}Visible) (Version: 19.0.5518 - Acronis)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20058 - Adobe Systems Incorporated)
Adobe Flash Player 26 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Ashampoo Burning Studio 11 v.11.0.2 (HKLM-x32\…\Ashampoo Burning Studio 11_is1) (Version: 11.0.2 - Ashampoo GmbH & Co. KG)
Brother MFL-Pro Suite MFC-J825DW (HKLM-x32\…\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.1.6.0 - Brother Industries, Ltd.)
BS.Player PRO (HKLM-x32\…\BSPlayerp) (Version: 2.69.1078 - AB Team, d.o.o.)
CAM UnZip 5.2.0.0 (HKLM-x32\…\CUZ5_is1) (Version: - CAM Development)
Citrix Online Launcher (HKLM-x32\…\{48947098-A67C-46D4-90C5-9F2F6F0F96FE}) (Version: 1.0.449 - Citrix)
CyberLink PowerDVD 11 (HKLM-x32\…\InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}) (Version: 11.0.1719.51 - CyberLink Corp.)
FreeScreenSharing (HKU\S-1-5-21-1569642822-292156195-3241122032-1000\…\FreeScreenSharing) (Version: 0.58.75.0 - Free Conferencing Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.3 - Google Inc.) Hidden
GoToMeeting 8.8.0.7297 (HKU\S-1-5-21-1569642822-292156195-3241122032-1000\…\GoToMeeting) (Version: 8.8.0.7297 - LogMeIn, Inc.)
Intel Security True Key (HKLM\…\TrueKey) (Version: 4.19.108.1 - Intel Security)
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
LG AirDrive (HKLM-x32\…\{101E5DB3-07FA-4E52-8923-05068C94CF43}) (Version: 1.2.60617.11 - LG Electronics)
LG Bridge (HKLM-x32\…\LG Bridge) (Version: 1.2.18 - LG Electronics)
LG Mobile Driver (HKLM-x32\…\{3F490D0E-3131-438C-BCF9-7549CB88DF41}) (Version: 4.1.1 - LG Electronics)
Linksys Connect (HKLM-x32\…\Linksys Connect) (Version: 1.5.15287.0 - Linksys LLC)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\…\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
The Unzip Wizard (HKLM-x32\…\The Unzip Wizard) (Version: - )
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Zoom (HKU\S-1-5-21-1569642822-292156195-3241122032-1000\…\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1569642822-292156195-3241122032-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\USER\AppData\Local\Citrix\GoToMeeting\6749\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2015-07-23] (Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2015-07-23] (Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2015-07-23] (Acronis)
ContextMenuHandlers01: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2017-06-09] ()
ContextMenuHandlers01: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => -> No File
ContextMenuHandlers01: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers03: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers04: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2017-06-09] ()
ContextMenuHandlers04: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2009-09-23] (Intel Corporation)
ContextMenuHandlers05: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers06: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2017-06-09] ()
ContextMenuHandlers06: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => -> No File
ContextMenuHandlers06: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0B7B9022-9008-42C1-BE30-84619AB03DE0} - System32\Tasks\G2MUploadTask-S-1-5-21-1569642822-292156195-3241122032-1000 => C:\Users\USER\AppData\Local\GoToMeeting\7297\g2mupload.exe [2017-07-11] (LogMeIn, Inc.)
Task: {50D25BB3-976D-4D60-B23A-CD590BE0398F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-24] (Adobe Systems Incorporated)
Task: {536E9D21-486F-457E-84C6-5F5431E9D540} - System32\Tasks\G2MUpdateTask-S-1-5-21-1569642822-292156195-3241122032-1000 => C:\Users\USER\AppData\Local\GoToMeeting\7297\g2mupdate.exe [2017-07-11] (LogMeIn, Inc.)
Task: {5ACBC616-0A12-410B-AEC4-31898DD4E2D2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-23] (Google Inc.)
Task: {7AE76A1D-59DE-4E19-BA1F-13DE522827DE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {9679BE3B-1702-4A4C-8B47-E180AFF9A66E} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_26_0_0_131_pepper.exe [2017-06-24] (Adobe Systems Incorporated)
Task: {B7EC7288-73CF-4093-970D-F5B32EF9D0EB} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2016-12-15] (McAfee, Inc.)
Task: {EF03D0EA-E8EF-4A0F-A45F-7BA3ACB28357} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-23] (Google Inc.)
Task: {FCB202BD-083B-45F6-99C2-933FA8943C84} - System32\Tasks\{2D2EC208-BE45-4E45-B192-781DF9CA4591} => C:\Program Files (x86)\LG Electronics\LG Bridge\LGBridge.exe [2016-07-21] (LG Electronics)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1569642822-292156195-3241122032-1000.job => C:\Users\USER\AppData\Local\GoToMeeting\7297\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1569642822-292156195-3241122032-1000.job => C:\Users\USER\AppData\Local\GoToMeeting\7297\g2mupload.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2016-03-10 16:54 - 2017-06-09 01:00 - 00785360 _____ () C:\Program Files (x86)\360\Total Security\MenuEx64.dll
2016-03-10 16:30 - 2011-05-18 19:00 - 00083240 _____ () C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
2016-03-10 16:54 - 2017-06-09 01:00 - 00099240 _____ () C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll
2016-03-10 16:54 - 2017-06-09 01:00 - 00498272 _____ () C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll
2016-10-11 23:29 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2017-04-20 22:50 - 2017-03-28 18:04 - 02187096 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libglesv2.dll
2017-04-20 22:50 - 2017-03-28 18:04 - 00086360 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libegl.dll
2015-08-16 23:44 - 2015-08-16 23:44 - 00036160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll
2015-08-16 23:44 - 2015-08-16 23:44 - 00446272 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll
2015-08-16 23:44 - 2015-08-16 23:44 - 00116032 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\EXPAT.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 18:34 - 2017-05-21 01:21 - 00000838 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 activation.acronis.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1569642822-292156195-3241122032-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\USER\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: Acronis Scheduler2 Service => "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
MSCONFIG\startupreg: AcronisTibMounterMonitor => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: ControlCenter4 => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: FreeScreenSharing => C:\Users\USER\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: RemoteControl11 => "C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe"
MSCONFIG\startupreg: TrueImageMonitor.exe => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{A0027C7A-1E63-444E-9EAD-79441C14E670}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\PowerDVD11.exe
FirewallRules: [{8302C41C-A07B-4DC3-9126-F58EB97D5F36}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe
FirewallRules: [{8FB9F484-95CB-4F34-8C15-9EADBFE59A29}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
FirewallRules: [{A7E582B0-57A2-47D4-B474-76510248E652}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\Movie\MovieModule.exe
FirewallRules: [{EE6C942E-C218-4866-9199-5573BF7C7149}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\Movie\PowerDVD Cinema\PowerDVDCinema11.exe
FirewallRules: [{032826FE-5294-4D2F-8951-42E30D4805E8}] => (Allow) C:\Users\USER\AppData\Local\Temp\chrome.exe
FirewallRules: [{15DE69DA-1D77-443F-BE73-0650689DF99F}] => (Allow) C:\Users\USER\AppData\Local\Temp\chrome.exe
FirewallRules: [{09BDB1A6-8431-4A94-8EB3-D0E760732B96}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{13AC9174-F59F-4ABA-B8B3-6BC6AE7A71C7}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe
FirewallRules: [{4331D2E6-448F-4E9A-A98F-B1975F750C16}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{E2E3669C-53C0-44A0-BA9F-3F8636A60D53}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{1A24B702-8747-45EF-84C7-85625073225C}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{9BE300FC-1325-4BB8-8C3E-B22F92C4673B}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{9F12E978-B2ED-40D8-9CEE-D6C7C4788E7C}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\InstantSetup.exe
FirewallRules: [{28F87125-FEB2-44AF-BC64-62555D52A346}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\InstantSetup.exe
FirewallRules: [{DAA0E368-95E7-4156-ACD3-F84921F762FD}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{25B65283-8BB4-4EC3-BB60-7995C30437E3}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{6C19E9BF-9255-4B9A-9891-D935B7A5B7E4}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{E47C08CD-158C-4B7D-85D8-8AD5C3D706A5}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [TCP Query User{A710672D-1E30-46A8-B6DB-50972914BF30}C:\users\user\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\user\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe
FirewallRules: [UDP Query User{87DC36E8-D25D-4D39-B141-958ACEE4B229}C:\users\user\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe] => (Allow) C:\users\user\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe
FirewallRules: [TCP Query User{2CF87008-053D-4D99-839D-075BF440EFB3}C:\users\user\appdata\local\logmein rescue applet\lmir0002.tmp\lmi_rescue.exe] => (Allow) C:\users\user\appdata\local\logmein rescue applet\lmir0002.tmp\lmi_rescue.exe
FirewallRules: [UDP Query User{85E9F466-B495-4241-8AE7-F1C7C4C8F4E4}C:\users\user\appdata\local\logmein rescue applet\lmir0002.tmp\lmi_rescue.exe] => (Allow) C:\users\user\appdata\local\logmein rescue applet\lmir0002.tmp\lmi_rescue.exe
FirewallRules: [{62026277-0E71-4CD5-B0CC-F8950BDD1B33}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{89ADA82F-3DE2-4247-807D-33539B90C16C}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
FirewallRules: [{055A4135-5F81-4411-BA8E-776E3AABCBA3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{96D92463-3A81-43D2-8AF8-29699A87CA91}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{10599774-7D90-4CD0-9D23-A9AAB51BC4D8}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe

==================== Restore Points =========================

12-07-2017 03:01:10 Windows Update
13-07-2017 03:05:54 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/15/2017 03:47:50 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/14/2017 09:51:50 PM) (Source: Acronis Scheduler) (EventID: 1) (User: USER-PC)
Description: Scheduler failed to run task with GUID 'A2BB4F95-348C-4590-958E-DF518374D6D4' because of error 5 (Access is denied.).

Error: (07/14/2017 11:38:34 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/13/2017 02:38:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/13/2017 02:52:53 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/13/2017 02:29:29 AM) (Source: Application) (EventID: 0) (User: )
Description: Event-ID 0

Error: (07/12/2017 03:52:33 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/09/2017 07:48:43 PM) (Source: Acronis Scheduler) (EventID: 1) (User: USER-PC)
Description: Scheduler failed to run task with GUID 'A2BB4F95-348C-4590-958E-DF518374D6D4' because of error 5 (Access is denied.).

Error: (07/09/2017 04:25:44 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/09/2017 04:24:45 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.

Details:
The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801)


System errors:
=============
Error: (07/15/2017 03:46:08 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Service Installer TrueKey service failed to start due to the following error:
The system cannot find the file specified.

Error: (07/14/2017 11:37:06 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Service Installer TrueKey service failed to start due to the following error:
The system cannot find the file specified.

Error: (07/14/2017 11:36:53 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 11:36:17 AM on ‎7/‎14/‎2017 was unexpected.

Error: (07/14/2017 12:49:01 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/14/2017 12:48:29 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/14/2017 12:47:45 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/14/2017 12:47:11 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/14/2017 12:46:10 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/14/2017 12:45:35 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.

Error: (07/14/2017 12:18:26 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the afcdpsrv service.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU T7500 @ 2.20GHz
Percentage of memory in use: 72%
Total physical RAM: 2037.97 MB
Available physical RAM: 555.91 MB
Total Virtual: 4075.94 MB
Available Virtual: 1955.39 MB

==================== Drives ================================

Drive c: (New Volume) (Fixed) (Total:74.53 GB) (Free:31.79 GB) NTFS ==>[drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 74.5 GB) (Disk ID: A0C27A56)
Partition 1: (Active) - (Size=74.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-07-2017
Ran by [removed] (administrator) on USER-PC (15-07-2017 04:35:56)
Running from C:\Users\[removed]\Desktop
[removed]

Not looking to bad, just a few things to fix not malware related

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
GroupPolicy: Restriction <==== ATTENTION
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
ContextMenuHandlers01: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => -> No File
ContextMenuHandlers01: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers03: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers04: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers05: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers06: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => -> No File
ContextMenuHandlers06: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
CMD: ipconfig /flushdns
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
 
 
Let me know if your system is running any better after the fix

Ken,

 

The log is posted below.  I have a couple questions. I guess that fix also erased cookies, etc.  When I reopened the browser, this site was on there.  Was that part of the fix?  http://www.fvddownloader.com/

Also all my browser tabs were closed and had to reopen them.  Is there an easier way to open them like all at once than going to History and open one, go back to history and open another and keep opening each individually than doing it all at once?

 

Thanks

GB

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 15-07-2017
Ran by [removed] (16-07-2017 14:54:00) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
GroupPolicy: Restriction <==== ATTENTION
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
ContextMenuHandlers01: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => -> No File
ContextMenuHandlers01: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers03: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers04: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers05: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers06: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => -> No File
ContextMenuHandlers06: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
CMD: ipconfig /flushdns
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
 
"C:\Windows\system32\GroupPolicy\Machine" folder move:
 
Could not move "C:\Windows\system32\GroupPolicy\Machine" => Scheduled to move on reboot.
 
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => key removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => key removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\VersionsPageShellExt => key removed successfully
HKLM\Software\Classes\CLSID\{9E42900A-85F9-4E67-9778-575FBBA0A81C} => key not found. 
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX => key removed successfully
HKLM\Software\Classes\CLSID\{6C467336-8281-4E60-8204-430CED96822D} => key not found. 
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX => key removed successfully
HKLM\Software\Classes\CLSID\{6C467336-8281-4E60-8204-430CED96822D} => key not found. 
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX => key removed successfully
HKLM\Software\Classes\CLSID\{6C467336-8281-4E60-8204-430CED96822D} => key not found. 
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX => key removed successfully
HKLM\Software\Classes\CLSID\{6C467336-8281-4E60-8204-430CED96822D} => key not found. 
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\VersionsPageShellExt => key removed successfully
HKLM\Software\Classes\CLSID\{9E42900A-85F9-4E67-9778-575FBBA0A81C} => key not found. 
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX => key removed successfully
HKLM\Software\Classes\CLSID\{6C467336-8281-4E60-8204-430CED96822D} => key not found. 
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 15842718 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 524288 B
Edge => 0 B
Chrome => 841574680 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 16802 B
systemprofile32 => 95326734 B
LocalService => 0 B
NetworkService => 39408 B
USER => 10926681 B

Thats not a safe site, not sure why it came back up, run AdwCleaner again and lets see if it finds and removes it.  

 

What browser are you talking about ??

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI