This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Restarted from a Bug Check! BSOD crashes [Solved]

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi my name is Jeff,

 

My machine has been experiencing some unusual symptoms and erratic behavior. At first i noticed a few times my machine would reboot it self usually on idle or just by running a few system programs. The internet was also not working, i was not able to connect to any domain on any websites. How ever, as the problem persists for a few more days, other symptoms starting appearing such as Disappearing desktop icons flashing off and on rapidly. The start button not functioning, Indexing turned off as well as firewalls turned off. The machine also having very slow boot times and CPU using a constant 90%. I also noticed that my windows login-id and password did not work at all when i tried to run a repair recovery console. I noticed another user established on my network that was never there before titled "person 1". The same user was created for my google chrome account because the proxy settings were not functioning correctly as i said before which i believe led to websites not being able to locate their DNS addresses.

 

So naturally i decided to isolate this issue to determine if its  a hardware or software issue. So i booted the machine into safe mode, let it sit idle for a while. Every symptom that i experience well booted in normal mode was not apparent, in addition the machine stayed on over night and never once rebooted. This is when i came to the conclusion that this must be a software related issue or perhaps even a maleware rogue agent or hyjacker.

 

So the first step towards resolving this issue was to due a system restore. I successfully completed this and many of the symptoms that i experienced didn't happen any more and i was able to connect to the internet. How ever the "rebooting and restarting" issue still persists.

 

So with that being said, i'll leave it up to the professionals to figure this one out. In the mean time here is my log.

 

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-09-2017
Ran by [removed] (administrator) on DESKTOP-K72D4JE (09-09-2017 20:49:05)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 10 Pro Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor)
HKLM\…\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM\…\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [239856 2017-09-04] (AVAST Software)
HKLM-x32\…\Run: [Sound Blaster Cinema 2] => C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe [1442304 2014-05-29] (Creative Technology Ltd)
HKLM-x32\…\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [413696 2009-01-05] (Apple Inc.)
HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1279120 2012-09-27] (CANON INC.)
HKLM-x32\…\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452272 2012-08-31] (CANON INC.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-4212484089-3487115953-933115951-1004\…\Run: [Mal Updater 2] => C:\Program Files (x86)\Mal Updater 2\MalUpdater.exe [7100928 2017-06-16] (eden.fm)
HKU\S-1-5-21-4212484089-3487115953-933115951-1004\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3071776 2017-09-06] (Valve Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-10-25]
ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks)
GroupPolicy: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f185da36-ed8e-44d6-a98c-87cebaebd02d}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\S-1-5-21-4212484089-3487115953-933115951-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP
SearchScopes: HKU\S-1-5-21-4212484089-3487115953-933115951-1004 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-09-03] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-09-03] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
 
FireFox:
========
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-09-03] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-02-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-02-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default [2017-09-09]
CHR Extension: (Google Slides) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-09-08]
CHR Extension: (Google Docs) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-09-08]
CHR Extension: (Google Drive) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-25]
CHR Extension: (YouTube) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-25]
CHR Extension: (uBlock Origin) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-09-08]
CHR Extension: (Adobe Acrobat) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-09-08]
CHR Extension: (Avast SafePrice) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-09-08]
CHR Extension: (Google Sheets) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-09-08]
CHR Extension: (Google Docs Offline) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-09-08]
CHR Extension: (Avast Online Security) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-09-08]
CHR Extension: (Search Manager) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [2017-09-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-08]
CHR Extension: (Gmail) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-25]
CHR Extension: (Chrome Media Router) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-08]
CHR HKLM\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4212484089-3487115953-933115951-1004\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7452288 2017-09-04] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [275208 2017-09-04] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [322976 2017-09-04] (AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4424384 2017-08-28] (Microsoft Corporation)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [135488 2017-06-16] (SurfRight B.V.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [402432 2015-07-07] (Rivet Networks) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-11-17] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-18] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-07-10] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [320528 2017-09-04] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [198976 2017-09-04] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [343296 2017-09-04] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [57736 2017-09-04] (AVAST Software s.r.o.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [47016 2017-09-04] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [41832 2017-09-04] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [147784 2017-09-04] (AVAST Software)
R1 aswNetSec; C:\WINDOWS\system32\drivers\aswNetSec.sys [555072 2017-09-04] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [110376 2017-09-04] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [84416 2017-09-04] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1016384 2017-09-04] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [590880 2017-09-04] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [199312 2017-09-04] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [361336 2017-09-04] (AVAST Software)
R1 BfLwf; C:\WINDOWS\system32\DRIVERS\bwcW10x64.sys [114736 2015-07-07] (Rivet Networks, LLC.)
R3 KillerEth; C:\WINDOWS\System32\drivers\e2xw10x64.sys [145920 2017-03-18] (Qualcomm Atheros, Inc.)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [253856 2017-09-09] (Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_f9309145156afb40\nvlddmkm.sys [14456912 2017-05-19] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-11-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [46016 2016-11-17] (NVIDIA Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
S3 ALSysIO; \??\C:\Users\JEFFM~1\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-09-09 20:49 - 2017-09-09 20:49 - 000019588 _____ C:\Users\Jeff M\Desktop\FRST.txt
2017-09-09 20:48 - 2017-09-09 20:49 - 000000000 ____D C:\FRST
2017-09-09 20:48 - 2017-09-09 20:48 - 002396160 _____ (Farbar) C:\Users\Jeff M\Desktop\FRST64.exe
2017-09-09 20:18 - 2017-09-09 20:18 - 000614884 _____ C:\WINDOWS\Minidump\090917-7375-01.dmp
2017-09-09 17:56 - 2017-09-09 17:56 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\4598
2017-09-09 16:20 - 2017-09-09 16:20 - 000646993 _____ C:\Users\Jeff M\Desktop\c1d77b51-2579-4787-b132-2695da92fccb_1.009cbfecfe61be8862a9c75c856c60da (1).jpeg
2017-09-09 16:19 - 2017-09-09 16:19 - 000646993 _____ C:\Users\Jeff M\Desktop\c1d77b51-2579-4787-b132-2695da92fccb_1.009cbfecfe61be8862a9c75c856c60da.jpeg
2017-09-09 16:18 - 2017-09-09 16:18 - 001096086 _____ C:\Users\Jeff M\Desktop\4a60fded-509e-4952-bd92-5b2558b07f15_1.9741e5d681357165c4f5c41b9d9594ce.jpeg
2017-09-09 13:54 - 2017-09-09 13:54 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-09-09 12:54 - 2017-09-04 13:45 - 000401488 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-09-08 21:15 - 2017-09-08 21:15 - 000000989 _____ C:\Users\Jeff M\Desktop\Core Temp.lnk
2017-09-08 21:15 - 2017-09-08 21:15 - 000000165 _____ C:\Users\Jeff M\Desktop\Goodgame Empire.url
2017-09-08 21:15 - 2017-09-08 21:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
2017-09-08 21:15 - 2017-09-08 21:15 - 000000000 ____D C:\Program Files\Core Temp
2017-09-08 20:57 - 2017-09-08 22:04 - 000000000 ___HD C:\$SysReset
2017-09-08 19:21 - 2017-09-08 19:21 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Roaming\AVAST Software
2017-09-08 19:21 - 2017-09-08 19:21 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\CEF
2017-09-08 19:20 - 2017-09-08 19:20 - 000000000 ___RD C:\Users\Jeff.DESKTOP-K72D4JE\OneDrive
2017-09-08 19:20 - 2017-09-08 19:20 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\Comms
2017-09-08 19:19 - 2017-09-08 19:19 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Roaming\Canon
2017-09-08 19:04 - 2017-09-08 19:04 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\DBG
2017-09-08 18:59 - 2017-09-08 19:19 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\Packages
2017-09-08 18:59 - 2017-09-08 18:59 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Roaming\Adobe
2017-09-08 18:59 - 2017-09-08 18:59 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\VirtualStore
2017-09-08 18:59 - 2017-09-08 18:59 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\Publishers
2017-09-08 18:59 - 2017-09-08 18:59 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\Google
2017-09-08 18:58 - 2017-09-08 22:04 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE
2017-09-08 18:58 - 2017-09-08 19:00 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\NVIDIA Corporation
2017-09-08 18:58 - 2017-09-08 18:58 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\NVIDIA
2017-09-08 18:58 - 2017-09-08 18:58 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\ConnectedDevicesPlatform
2017-09-04 19:46 - 2017-09-04 19:46 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-09-03 14:42 - 2017-09-03 15:12 - 000012212 _____ C:\Users\Jeff M\Documents\Book1.xlsx
2017-09-03 09:32 - 2017-09-09 20:18 - 4072317727 _____ C:\WINDOWS\MEMORY.DMP
2017-09-03 09:32 - 2017-09-03 09:32 - 000662332 _____ C:\WINDOWS\Minidump\090317-13296-01.dmp
2017-09-03 02:52 - 2017-09-09 20:18 - 000000000 ____D C:\WINDOWS\Minidump
2017-08-28 12:41 - 2017-08-28 12:41 - 000249326 _____ C:\Users\Jeff M\Desktop\key-visual.jpg-723x1024.jpeg
2017-08-21 15:47 - 2017-08-21 15:47 - 000000000 ____D C:\Users\Jeff M\Documents\Proposal and Contract
2017-08-21 15:44 - 2017-08-21 15:45 - 000000000 ___HD C:\ProgramData\CanonIJMIG
2017-08-21 15:43 - 2017-08-21 15:43 - 000000000 ___HD C:\ProgramData\CanonIJScan
2017-08-21 15:28 - 2017-09-04 15:05 - 000000000 ____D C:\ProgramData\CanonIJPLM
2017-08-21 15:28 - 2017-08-28 15:29 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\canon
2017-08-21 15:28 - 2017-08-21 15:28 - 000000000 ___HD C:\ProgramData\CanonIJQuickMenu
2017-08-21 15:28 - 2017-08-21 15:28 - 000000000 ____D C:\ProgramData\Canon IJ Network Tool
2017-08-21 15:27 - 2012-09-21 09:33 - 000321024 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNC_BLL.dll
2017-08-21 15:27 - 2012-05-25 09:21 - 000103936 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNC_BLU.dll
2017-08-21 15:27 - 2012-05-15 15:58 - 000098048 _____ C:\WINDOWS\SysWOW64\CNC176BD.TBL
2017-08-21 15:27 - 2008-08-25 18:02 - 000015872 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNHMCA.dll
2017-08-21 15:25 - 2017-09-08 22:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX920 series User Registration
2017-08-21 15:25 - 2017-08-21 15:25 - 000000000 ____D C:\Users\Jeff M\AppData\LocalLow\Canon Easy-WebPrint EX2
2017-08-21 15:25 - 2017-08-21 15:25 - 000000000 ____D C:\Users\Jeff M\AppData\LocalLow\Canon Easy-WebPrint EX
2017-08-21 15:24 - 2017-08-21 15:24 - 000002094 _____ C:\Users\Public\Desktop\Canon Quick Menu.lnk
2017-08-21 15:24 - 2017-08-21 15:24 - 000000000 ____D C:\ProgramData\CanonIJWSpt
2017-08-21 15:20 - 2017-09-08 22:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2017-08-21 15:20 - 2017-08-21 15:25 - 000000000 ____D C:\Program Files\Canon
2017-08-21 15:19 - 2017-09-08 22:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX920 series Manual
2017-08-21 15:19 - 2017-08-21 15:19 - 000002431 _____ C:\Users\Public\Desktop\Canon MX920 series On-screen Manual.lnk
2017-08-21 15:19 - 2017-08-21 15:19 - 000000000 ___HD C:\Program Files\CanonBJ
2017-08-21 15:19 - 2017-08-21 15:19 - 000000000 ____D C:\WINDOWS\system32\STRING
2017-08-21 15:19 - 2012-07-31 01:48 - 000359936 _____ (CANON INC.) C:\WINDOWS\system32\CNMN6PPM.DLL
2017-08-21 15:19 - 2012-07-31 01:48 - 000039424 _____ (CANON INC.) C:\WINDOWS\system32\CNMN6UI.DLL
2017-08-21 15:19 - 2012-07-31 01:47 - 000366592 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNMNPPM.DLL
2017-08-21 15:18 - 2017-08-21 15:28 - 000000000 ____D C:\Program Files (x86)\Canon
2017-08-21 09:56 - 2017-08-21 09:56 - 000000000 ____D C:\Users\Jeff M\Desktop\camera pics
2017-08-20 14:39 - 2017-08-20 14:39 - 000000000 ____D C:\Users\Jeff M\Desktop\Walmart pics upload
2017-08-18 00:33 - 2017-08-18 00:33 - 000012872 _____ (SurfRight B.V.) C:\WINDOWS\system32\bootdelete.exe
2017-08-14 13:28 - 2017-08-14 13:28 - 000000000 ____D C:\Users\Jeff M\AppData\Local\DBG
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-09-09 20:24 - 2017-08-09 21:06 - 001130182 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-09-09 20:18 - 2017-08-09 21:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-09-09 20:18 - 2017-08-09 20:57 - 000000000 ____D C:\Users\Jeff M
2017-09-09 20:18 - 2017-08-09 20:56 - 000000000 ____D C:\ProgramData\NVIDIA
2017-09-09 20:18 - 2017-06-16 13:18 - 000000000 ____D C:\Program Files (x86)\Steam
2017-09-09 20:18 - 2017-03-24 21:27 - 000253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-09-09 20:18 - 2016-12-08 15:46 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Mal Updater
2017-09-09 20:05 - 2017-08-09 20:56 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-09-09 19:13 - 2017-08-09 21:01 - 000004168 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{F33DBF81-DB59-40F2-81B3-09A0751603E4}
2017-09-09 12:59 - 2017-03-18 14:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-09-09 12:59 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-09-09 12:55 - 2017-03-24 21:56 - 000001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Internet Security.lnk
2017-09-09 12:55 - 2017-03-24 21:56 - 000001967 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk
2017-09-09 12:54 - 2017-08-09 21:01 - 000004268 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-09-09 12:54 - 2017-08-09 21:01 - 000004022 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1490417705
2017-09-09 12:54 - 2017-03-24 21:55 - 000001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-09-09 12:46 - 2017-03-18 04:40 - 001835008 _____ C:\WINDOWS\system32\config\BBI
2017-09-08 22:04 - 2017-08-09 20:57 - 000000000 ____D C:\Users\defaultuser0.DESKTOP-K72D4JE
2017-09-08 22:04 - 2017-06-16 13:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-09-08 22:04 - 2017-06-16 11:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2017-09-08 22:04 - 2017-06-16 03:15 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-09-08 22:04 - 2017-04-22 00:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Shrink
2017-09-08 22:04 - 2017-04-02 19:09 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2017-09-08 22:04 - 2017-04-02 19:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VSO
2017-09-08 22:04 - 2017-03-24 21:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-09-08 22:04 - 2017-03-19 03:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2017-09-08 22:04 - 2017-03-19 02:49 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Sony
2017-09-08 22:04 - 2017-03-19 02:28 - 000000000 ____D C:\Users\Jeff M\Documents\Sony Vegas Pro 13.0 Build 453 (x64) + Patch DI
2017-09-08 22:04 - 2017-03-18 14:01 - 000000000 ____D C:\WINDOWS\INF
2017-09-08 22:04 - 2017-01-22 17:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2017-09-08 22:04 - 2017-01-22 17:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\honestech VHS to DVD 5.0 Deluxe
2017-09-08 22:04 - 2017-01-01 22:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 9
2017-09-08 22:04 - 2017-01-01 22:20 - 000000000 ____D C:\Users\Jeff M\Documents\DVDFab Platinum v9.1.2.2 + Crack [ChattChitto RG]
2017-09-08 22:04 - 2016-12-08 15:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mal Updater 2
2017-09-08 22:04 - 2016-12-08 15:44 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Taiga
2017-09-08 22:04 - 2016-12-08 15:44 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Taiga
2017-09-08 22:04 - 2016-12-08 15:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KCP
2017-09-08 22:04 - 2016-12-08 15:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-09-08 22:04 - 2016-12-08 03:44 - 000000000 ____D C:\Users\Jeff M\Desktop\mpv-x86_64-20161120
2017-09-08 22:04 - 2016-12-08 03:44 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-09-08 22:04 - 2016-12-08 03:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-09-08 22:04 - 2016-11-15 10:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2017-09-08 22:04 - 2016-10-25 23:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2017-09-08 22:04 - 2016-10-25 23:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2017-09-08 22:04 - 2016-10-25 23:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Killer Networking
2017-09-08 22:04 - 2016-10-25 23:23 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-09-08 22:04 - 2016-10-25 23:23 - 000000000 ____D C:\Users\Jeff M\AppData\Local\VirtualStore
2017-09-08 22:03 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\registration
2017-09-08 22:01 - 2017-06-16 02:38 - 000000000 ____D C:\Users\Jeff M\AppData\Local\Steam
2017-09-08 22:01 - 2017-04-21 01:33 - 000000000 ____D C:\Users\Jeff M\Documents\VSO ConvertXtoDVD v7.0.0.30 Beta + Patch
2017-09-08 22:01 - 2017-04-02 19:10 - 000000000 ____D C:\Users\Jeff M\AppData\Local\chromium
2017-09-08 22:01 - 2017-03-19 03:11 - 000000000 ____D C:\Users\Jeff M\AppData\Local\Sony
2017-09-08 22:01 - 2017-01-01 22:22 - 000000000 ____D C:\Users\Jeff M\Documents\DVDFab9
2017-09-08 22:01 - 2016-12-18 20:25 - 000000000 ____D C:\Users\Jeff M\Desktop\Back-up USB Drive
2017-09-08 22:01 - 2016-12-08 15:36 - 000000000 ____D C:\Users\Jeff M\AppData\Local\NVIDIA Corporation
2017-09-08 22:01 - 2016-10-25 23:46 - 000000000 ____D C:\Users\Jeff M\AppData\Local\Google
2017-09-08 22:01 - 2016-10-25 23:42 - 000000000 ____D C:\Users\Jeff M\AppData\Local\NVIDIA
2017-09-08 22:01 - 2016-10-25 23:23 - 000000000 ____D C:\Users\Jeff M\AppData\Local\TileDataLayer
2017-09-08 21:28 - 2017-06-16 10:53 - 000000000 ____D C:\WINDOWS\pss
2017-09-08 21:20 - 2017-06-16 10:57 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-09-08 21:14 - 2017-01-01 21:31 - 000000000 ____D C:\Users\Jeff M\AppData\Local\ElevatedDiagnostics
2017-09-08 19:45 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-09-04 13:45 - 2017-03-24 21:55 - 000555072 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetSec.sys
2017-09-04 13:45 - 2017-03-24 21:54 - 000041832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 001016384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000590880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000361336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000343296 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000320528 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000199312 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000198976 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000147784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000110376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000084416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000057736 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000047016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-09-03 12:42 - 2017-01-22 05:03 - 000017884 ____H C:\Users\Jeff M\Desktop\~WRL2757.tmp
2017-09-03 09:48 - 2016-11-15 10:48 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2017-09-03 09:33 - 2017-03-18 04:40 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2017-09-03 09:33 - 2016-10-26 02:49 - 000544424 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-09-03 05:33 - 2017-03-18 14:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-09-03 02:52 - 2016-10-25 23:18 - 000314231 ____N C:\WINDOWS\Minidump\090317-14203-01.dmp
2017-08-31 11:39 - 2017-08-09 21:01 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4212484089-3487115953-933115951-1004
2017-08-31 11:39 - 2016-10-25 23:24 - 000002366 _____ C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-08-31 11:39 - 2016-10-25 23:24 - 000000000 ___RD C:\Users\Jeff M\OneDrive
2017-08-29 13:47 - 2017-01-12 15:15 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-08-28 12:47 - 2016-10-25 23:46 - 000002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-28 12:47 - 2016-10-25 23:46 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-21 15:27 - 2017-03-18 14:03 - 000000000 __RSD C:\WINDOWS\Media
2017-08-21 09:55 - 2016-12-30 16:07 - 000000000 ____D C:\Users\Jeff M\Desktop\100PHOTO
2017-08-18 00:33 - 2017-06-16 11:54 - 000000000 ____D C:\ProgramData\HitmanPro
2017-08-17 00:21 - 2017-08-09 20:56 - 000380296 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-08-17 00:21 - 2016-10-25 23:23 - 000000000 ____D C:\Users\Jeff M\AppData\Local\ConnectedDevicesPlatform
2017-08-12 21:09 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\rescache
2017-08-10 20:07 - 2016-10-25 23:23 - 000000000 ____D C:\Users\Jeff M\AppData\Local\Packages
2017-08-10 11:47 - 2017-03-18 13:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-08-10 07:47 - 2017-08-09 21:01 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-08-10 03:41 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\appcompat
 
==================== Files in the root of some directories =======
 
2017-04-02 19:03 - 2017-04-21 01:35 - 000099384 _____ () C:\Users\Jeff M\AppData\Roaming\inst.exe
2017-04-02 19:03 - 2017-04-21 01:35 - 000007859 _____ () C:\Users\Jeff M\AppData\Roaming\pcouffin.cat
2017-04-02 19:03 - 2017-04-21 01:35 - 000001167 _____ () C:\Users\Jeff M\AppData\Roaming\pcouffin.inf
2017-04-02 19:03 - 2017-04-21 01:35 - 000000055 _____ () C:\Users\Jeff M\AppData\Roaming\pcouffin.log
2017-04-02 19:03 - 2017-04-21 01:35 - 000082816 _____ (VSO Software) C:\Users\Jeff M\AppData\Roaming\pcouffin.sys
 
Some files in TEMP:
====================
2017-08-21 15:18 - 2012-09-27 03:15 - 000865424 _____ (CANON INC.) C:\Users\Jeff M\AppData\Local\Temp\MSETUP4.EXE
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-08-31 22:59
 
==================== End of FRST.txt ============================

Attachments:

I did find items that need to be removed but, I don't know if it will have any influence on some of this your explaining.

*********************

Start Farbar Recovery Scan Tool (Please double-click on FRST/FRST64) with Administrator privileges
or Right click on the FRST icon and select Run as administrator
Highlight the below information then hit the Ctrl + C keys at the same time
or
Right click/highlight on the text below and select Copy.
beginning with Start:: and finishing with End::


Start::
CloseProcesses:
CreateRestorePoint:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
GroupPolicy: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKU\S-1-5-21-4212484089-3487115953-933115951-1004 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Google\Chrome\Extension\nahhmpbckpgdidfnmfkfgiflpjijilce
CHR HKLM\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4212484089-3487115953-933115951-1004\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
S3 ALSysIO; \??\C:\Users\JEFFM~1\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
2017-08-21 15:18 - 2012-09-27 03:15 - 000865424 _____ (CANON INC.) C:\Users\Jeff M\AppData\Local\Temp\MSETUP4.EXE
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Emptytemp:
End::


Press the Fix button.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


~~~~~~~~~~~~~~~

Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Here
  • After the installation IS complete let it update if it asks.
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
    If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
    Upon completion of the scan (or after the reboot), click the Reports tab.
    Double-click the Scan Log.
    At the bottom click Export and choose Text file.

    Save the file to your desktop and include its content in your next reply.

    You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here

    ~~~~~~~~~~~~~~~

    [external image: h3qKPnn.png]Malwarebytes AdwCleaner
  • Please download Malwarebytes AdwCleaner and save the file to your Desktop
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S0].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C0].txt) will open. Copy the contents of the log and paste in your next reply.
    – File, folder and registry backups are made for items removed using this programme. Should a legitimate file, folder or registry item be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[S0].txt.
please post
Fixlog.txt
MBAM log
AdwCleanertxt

Ok so with the first step you indicate to just copy the text, but aren't i supposed to create a text file and title it with an extension and then paste the contents into notepad.  

Ok so with the first step you indicate to just copy the text, but aren't i supposed to create a text file and title it with an extension and then paste the contents into notepad.


You can still do that but, the creator/developer of the tool made fixes to allow victims to use this method too.
At times it's easier this way due to code.

if you want to do it the other way:

Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text below.



Start:
CloseProcesses:
CreateRestorePoint:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
GroupPolicy: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKU\S-1-5-21-4212484089-3487115953-933115951-1004 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Google\Chrome\Extension\nahhmpbckpgdidfnmfkfgiflpjijilce
CHR HKLM\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4212484089-3487115953-933115951-1004\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
S3 ALSysIO; \??\C:\Users\JEFFM~1\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
2017-08-21 15:18 - 2012-09-27 03:15 - 000865424 _____ (CANON INC.) C:\Users\Jeff M\AppData\Local\Temp\MSETUP4.EXE
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Emptytemp:
End:

Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

[external image: 15wKX7o.jpg]

Well here is this log but i can't seem to run malewarebytes in safe mode. It says "Missing dll file" I am sure its because i am in safe mode so i tried to reboot my computer in normal mode, but i seem to be locked in safe mode. I used the MS config command to try and it doesn't seem to be working

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 12-09-2017
Ran by [removed] (13-09-2017 02:14:12) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Safe Mode (with Networking)
==============================================
 
fixlist content:
*****************
 
CloseProcesses:
CreateRestorePoint:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
GroupPolicy: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKU\S-1-5-21-4212484089-3487115953-933115951-1004 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Google\Chrome\Extension\nahhmpbckpgdidfnmfkfgiflpjijilce
CHR HKLM\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4212484089-3487115953-933115951-1004\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
S3 ALSysIO; \??\C:\Users\JEFFM~1\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
2017-08-21 15:18 - 2012-09-27 03:15 - 000865424 _____ (CANON INC.) C:\Users\Jeff M\AppData\Local\Temp\MSETUP4.EXE
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Emptytemp:
 
*****************
 
Processes closed successfully.
Error: Restore point can only be created in normal mode.
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Google => key removed successfully
HKU\S-1-5-21-4212484089-3487115953-933115951-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSuggestURL => removed successfully
HKLM\SOFTWARE\WOW6432Node\Google\Chrome\Extension\nahhmpbckpgdidfnmfkfgiflpjijilce => key not found. 
HKLM\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce => key removed successfully
HKU\S-1-5-21-4212484089-3487115953-933115951-1004\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce => key removed successfully
HKLM\System\CurrentControlSet\Services\ALSysIO => key removed successfully
ALSysIO => service removed successfully
C:\Users\Jeff M\AppData\Local\Temp\MSETUP4.EXE => moved successfully
C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => moved successfully
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 6053888 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 334604352 B
Java, Flash, Steam htmlcache => 6894302 B
Windows/system/drivers => 8301423 B
Edge => 4893576 B
Chrome => 812299405 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 16376 B
NetworkService => 959788 B
defaultuser0.DESKTOP-K72D4JE => 0 B
Jeff M => 79008218 B
 
RecycleBin => 37472 B
EmptyTemp: => 1.2 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 02:14:54 ====

In addition, it seems its not saving any of my settings and it says my google chrome settings are corrupted. You know i had an issue some what similar like this before years ago and it turned out it was pretty nasty virus of some sort. I am not sure if that is the case currently, but i do know some viruses do intentionally lock you into safe mode. Well this is a real nuisance. Whats even worse is the fact is i don't no longer have a windows 10 OS disk cause the one i did have turned out to be a counterfeit from a company illegally distributing the same serial numbers.

 

So i have to get my self another windows 10 disk. But if all else fails ill have to use a free download so i can initiate the proper tools if need be. Anyways any suggestions on how to get me out of safe mode so i can run my virus scan programs?

Well i manage to get the scan, here ya go: Also ADW cleaner found nothing so i don't think its necessary to post the log for that one.

 

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 9/13/17
Scan Time: 2:40 AM
Log File: 8c5e322c-9867-11e7-a38f-4ccc6a67517a.json
Administrator: Yes
 
-Software Information-
Version: 3.2.2.2018
Components Version: 1.0.186
Update Package Version: 1.0.2792
License: Trial
 
-System Information-
OS: Windows 10 (Build 15063.540)
CPU: x64
File System: NTFS
User: DESKTOP-K72D4JE\Jeff M
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 497320
Threats Detected: 1
Threats Quarantined: 1
Time Elapsed: 0 min, 39 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 1
PUP.Optional.GoodGame, C:\USERS\JEFF M\DESKTOP\GOODGAME EMPIRE.URL, Quarantined, [14817], [261883],1.0.2792
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)
Not really pointing to malware.

For safe mode try following the below
https://www.pcworld.com/article/3085034/windows/how-to-get-out-of-windows-safe-mode.html

Looking back over logs to see if something stood out among the listed errors
Cloud Files Mini Filter Driver. I have no idea if this would have any influence here
https://www.tenforums.com/general-support/90593-why-no-cldflt-service.html

~~

Please Download Tweaking.com - Windows Repair from Here
OR
Windows Repair (all in one) from here.
  • Install and then run the program
  • Execute the instructions on Step 1 Important
  • Click Next on Step 2 Optional, do the Pre Scan skip Step 3 and 4 Optional for now.
  • On Step 5 Backup System Restore Do a Registry backup. When you have completed this click Next
  • Click Repairs - Open Repairs in the bottom right corner
  • Uncheck the All repair button then select just the item(s) listed below

    01 - Repair Registry Permissions
    03 - Reset Service permissions
    04 - Register System Files
    05 - Repair WMI
    06 - Repair Windows Firewall
    07 - Repair Internet Explorer
    10 - Remove Policies Set By Infections
    17 - Repair Windows Updates
    19 - Repair Volume Shadow Copy Service
    21 - Repair MSI (Windows Installer)
    26 - Restore Important Windows Services
    27 - Set Windows Service to Default Startup
  • Click the Start button and let the process run to completion. Copy any error messages into Notepad, Save it on your Desktop. ( Reboot if asked to do so)
  • Please copy and paste the Contents of this file on your next reply.
Restart the computer normally.

I am currently running the repairs for this but just to give you a heads up. Some of the instructions that you list for these steps, tweaking software, malewarebytes and the farbar recovery scan tool are not up to date. Especially the tweaking program which had numbers that did not coincide with the exact numbers listed. I did how ever follow the wordings and text of each instruction to make sure i utilized the right function. But this is something you will have to go back and look at, not only for my benefit but for others as well. It can be a little confusing if someone is trying to follow exact instructions to a tea.

 

In any case, i hope i did everything correctly here.

 

Here is the log:

 

 

Log:
Tweaking.com - Windows Repair 2018 (v4.0.5)
────────────────────────────────────────────────────────────────────────────────
 
System Variables
────────────────────────────────────────────────────────────────────────────────
OS: Windows 10 Pro
OS Architecture: 64-bit
OS Version: 10.0.15063.540
OS Service Pack: 
Computer Name: DESKTOP-K72D4JE
Windows Drive: C:\
Windows Path: C:\WINDOWS
Program Files: C:\Program Files
Program Files (x86): C:\Program Files (x86)
Current Profile: C:\Users\Jeff M
Current Profile SID: S-1-5-21-4212484089-3487115953-933115951-1004
Current Profile Classes: S-1-5-21-4212484089-3487115953-933115951-1004_Classes
Profiles Location: C:\Users
Profiles Location 2: C:\WINDOWS\ServiceProfiles
Local Settings AppData: C:\Users\Jeff M\AppData\Local
────────────────────────────────────────────────────────────────────────────────
 
System Information
────────────────────────────────────────────────────────────────────────────────
System Up Time: 01 Day 16:01:49
 
Process Count: 51
Commit Total: 1.80 GB
Commit Limit: 31.95 GB
Commit Peak: 2.15 GB
Handle Count: 20015
Kernel Total: 441.44 MB
Kernel Paged: 347.16 MB
Kernel Non Paged: 94.27 MB
System Cache: 4.53 GB
Thread Count: 610
────────────────────────────────────────────────────────────────────────────────
 
Memory Before Cleaning with CleanMem
────────────────────────────────────────────────────────────────────────────────
Memory Total: 15.95 GB
Memory Used: 2.07 GB(12.986%)
Memory Avail.: 13.88 GB
────────────────────────────────────────────────────────────────────────────────
 
Cleaning Memory Before Starting Repairs…
 
Memory After Cleaning with CleanMem
────────────────────────────────────────────────────────────────────────────────
Memory Total: 15.95 GB
Memory Used: 1.66 GB(10.4183%)
Memory Avail.: 14.29 GB
────────────────────────────────────────────────────────────────────────────────
 
Starting Repairs…
   Started at (9/14/2017 6:27:53 PM)
 
Setting Any Missing 'InstallDate' From Uninstall Sections Before Running Repair…
Total Missing 'InstallDate' Fixed: 74
 
01 - Reset Registry Permissions
   Restore Windows 7/8/10 Default Registry Permissions
   Start (9/14/2017 6:27:54 PM)
 
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\hku.7z
Done,  0.24 seconds.
 
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\hklm.7z
Done,  3.24 seconds.
 
   Running Repair Under System Account
   Done (9/14/2017 6:29:04 PM)
 
03 - Reset Service Permissions
   Start (9/14/2017 6:29:04 PM)
 
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (9/14/2017 6:29:17 PM)
 
04 - Register System Files
   Start (9/14/2017 6:29:17 PM)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (9/14/2017 6:29:51 PM)
 
05 - Repair WMI
   Start (9/14/2017 6:29:51 PM)
 
   Starting Security Center So We Can Export The Security Info.
 
   Exporting Antivirus Info…
   Avast Antivirus Exported.
   Windows Defender Exported.
 
   Exporting AntiSpyware Info…
   Windows Defender Exported.
   Avast Antivirus Exported.
 
   Exporting 3rd Party Firewall Info…
   Avast Antivirus Exported.
 
   Running Repair Under Current User Account
   Done (9/14/2017 6:30:53 PM)
 
06 - Repair Windows Firewall
   Start (9/14/2017 6:30:53 PM)
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z
Done,  0.14 seconds.
 
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (9/14/2017 6:31:24 PM)
 
07 - Repair Internet Explorer
   Start (9/14/2017 6:31:24 PM)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (9/14/2017 6:31:36 PM)
 
10 - Remove Policies Set By Infections
   Start (9/14/2017 6:31:37 PM)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (9/14/2017 6:31:39 PM)
 
17 - Repair CD/DVD Missing/Not Working
   Start (9/14/2017 6:31:39 PM)
   iTunes or GEARAspiWDM.sys not found, not applying UpperFilters iTunes Reg Key
   Done (9/14/2017 6:31:39 PM)
 
18 - Repair Volume Shadow Copy Service
   Start (9/14/2017 6:31:39 PM)
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z
Done,  0.14 seconds.
 
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (9/14/2017 6:32:17 PM)
 
20 - Repair MSI (Windows Installer)
   Start (9/14/2017 6:32:17 PM)
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z
Done,  0.16 seconds.
 
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (9/14/2017 6:32:27 PM)
 
25 - Restore Important Windows Services
   Start (9/14/2017 6:32:27 PM)
 
Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z
Done,  0.16 seconds.
 
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (9/14/2017 6:32:33 PM)
 
26 - Set Windows Services To Default Startup
   Start (9/14/2017 6:32:33 PM)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (9/14/2017 6:32:38 PM)
 
Cleaning up empty logs…
 
All Selected Repairs Done.
   Done at (9/14/2017 6:32:38 PM)
   Total Repair Time: 00:04:46
 
 
…YOU MUST RESTART YOUR SYSTEM…
Thanks for the heads up on the tool.
Developers tweak their tools and no notifications go out on that.

I'm thinking logs are only created if error messages were found. I'll have to ask around about that tho.

By default Windows Repair All-In-One will create a "Logs" folder in its folder on the Desktop.



Go to Step 3, then click Check in the See If Check Disk Is Needed.

- If Windows Repair stated that errors are found, click Open Check Disk At Next Boot. Choose (/R) Fixes errors on the disk also locate bad sectors and recovers readable information, then click Add To Next Boot. Reboot the computer to let Windows check the disk.
[external image: Ymy7crZ.png]

- Go to Step 4, then click Do It.
[external image: zDtdN75.png]

- Go to Step 5. Under System Restore click Create.
[external image: f7lEe1N.png]

There were no errors in the hard disk drive. The system checker also didn't find any integrity violations. How ever here is a log that did find some errors in the system during the Pre-scan. Also i am able to reboot back into "normal start-up" mode again. How ever fire walls all are turned off so i turned them back on. What sort of errors was i experiencing and how did this happen in the first place?

 

 

┌────────────────────────────────────────────────────────────────────────────────┐
│ Tweaking.com - Windows Repair 2018 (v4.0.5) - Pre-Scan
│ Computer: DESKTOP-K72D4JE (Windows 10 Pro 10.0.15063.540 ) (64-bit)
│ [Started Scan - 9/14/2017 6:23:28 PM]
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ Scanning Windows Packages Files.
│ Started at (9/14/2017 6:23:28 PM)
│ 
│ These Files Are Possibly Corrupt (Bad Digital Signature): (Total: 1)
C:\WINDOWS\servicing\Packages\Microsoft-Windows-TestRoot-and-FlightSigning-Package~31bf3856ad364e35~amd64~~10.0.15063.0.mum
│ 
1 Combined Problems were found with the packages files, these files need to be replaced (These mainly only effect installing Windows Updates.)
│ The SFC (System File Checker) doesn't scan and replace some of these files, so you may need to replace them manually.
│ 
│ THESE FILES DO NOT KEEP THE REPAIRS FROM WORKING; YOU MAY STILL RUN THE REPAIRS IN THE PROGRAM.
│ 
│ Files Checked & Verified: 5,374
│ 
│ Done Scanning Windows Packages Files.(9/14/2017 6:23:53 PM)
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ Scanning Reparse Points.
│ Started at (9/14/2017 6:23:53 PM)
│ 
│ Missing Default Reparse Point: (Original Path: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5) (Target Path: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE)
│ A Default Reparse Point is missing and this can cause problems on the system.
│ 
│ Missing Default Reparse Point: (Original Path: C:\Users\defaultuser0\AppData\Local\Microsoft\Windows\INetCache\Content.IE5) (Target Path: C:\Users\defaultuser0\AppData\Local\Microsoft\Windows\INetCache\IE)
│ A Default Reparse Point is missing and this can cause problems on the system.
│ 
│ Missing Default Reparse Point: (Original Path: C:\Users\defaultuser0.DESKTOP-K72D4JE\AppData\Local\Microsoft\Windows\INetCache\Content.IE5) (Target Path: C:\Users\defaultuser0.DESKTOP-K72D4JE\AppData\Local\Microsoft\Windows\INetCache\IE)
│ A Default Reparse Point is missing and this can cause problems on the system.
│ 
│ Missing Default Reparse Point: (Original Path: C:\Users\defaultuser0.DESKTOP-LRKV6L0\AppData\Local\Microsoft\Windows\INetCache\Content.IE5) (Target Path: C:\Users\defaultuser0.DESKTOP-LRKV6L0\AppData\Local\Microsoft\Windows\INetCache\IE)
│ A Default Reparse Point is missing and this can cause problems on the system.
│ 
│ Missing Default Reparse Point: (Original Path: C:\Users\Jeff\AppData\Local\Microsoft\Windows\INetCache\Content.IE5) (Target Path: C:\Users\Jeff\AppData\Local\Microsoft\Windows\INetCache\IE)
│ A Default Reparse Point is missing and this can cause problems on the system.
│ 
│ Problems were found with the Reparse Points.
│ You can use the Repair Reparse Points Tool at the bottom of this Window to try and fix these problems.
│ 
│ Files & Folders Searched: 232,958
│ Reparse Points Found: 192
│ 
│ Done Scanning Reparse Points.(9/14/2017 6:24:02 PM)
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ Checking Environment Variables.
│ Started at (9/14/2017 6:24:02 PM)
│ 
│ No problems were found with the Environment Variables.
│ 
│ Done Checking Environment Variables. (9/14/2017 6:24:02 PM)
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ [Finished Scan - 9/14/2017 6:24:02 PM]
│ 
│ [x] Scan Complete - Problems Found!
│ [x] 
│ [x] You can use the Repair Reparse Points or Repair Environment Variables tools at the bottom of this Window if needed.
│ [x] 
│ [x] While problems have been found, you can still run the repairs in the program.
│ [x] But for the best results it is recommended to fix the problems reported in this scan if possible.
└────────────────────────────────────────────────────────────────────────────────┘

 

What sort of errors was i experiencing and how did this happen in the first place?

 

Thats the million dollar question, and I'll have to guess.

First thought is a bad update from Microsoft then again which one?, very hard to say since it seems something is reported monthly as in going wrong with their rollup updates now.

 

for an example, scroll down to post #3

https://forums.whatthetech.com/index.php?showtopic=131265

 

Also, somehow system settings changed,  and from what, why, how?

it's a mystery.

 

People have encountered these types of mishaps who allowed Microsoft to update the computers operating system to Windows 10.

 

We can run an online scan if you wish,

Yeah go for it, just make sure there is no other errors. So far its looking pretty good. The machine has been on for 24 hrs at least with out rebooting.

yeah, good news

Emsisoft Emergency Kit

Please download Emsisoft Emergency Kit and save it to your desktop. Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop. Leave all settings as they are and click the Extract button at the bottom. A folder named EEK will be created in the root of the drive (usually c:\).
  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.
  • When update is complete, click Malware Scan. When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes. Emsisoft Emergency Kit will start scanning.
  • When the scan is completed click Quarantine selected objects. Note, this option is only available if malicious objects were detected during the scan.
  • When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI