This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help please <3 [Closed]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey there, my computer seems to turn off randomly alot and its getting really annoying … I think i might be infected.   Any help would be great, here's the logs:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2018-09-17 01:43:53
—————————–
01:43:53.855    OS Version: Windows x64 6.1.7601 Service Pack 1
01:43:53.855    Number of processors: 2 586 0x170A
01:43:53.855    ComputerName: COMPUTER-PC  UserName: tvcomp
01:43:57.443    Initialize success
01:43:57.474    VM: initialized successfully
01:43:57.474    VM: Intel CPU supported
01:44:04.831    VM: supported disk I/O ataport.SYS
01:45:19.566    The log file has been saved successfully to "C:\Users\tvcomp\Desktop\aswMBR.txt"

 

 

Addition Log :

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15.09.2018
Ran by [removed] (17-09-2018 01:49:10)
Running from C:\Users\[removed]\Downloads
Windows 7 Enterprise Service Pack 1 (X64) (2016-09-01 22:31:03)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-946118099-592492296-2719631590-500 - Administrator - Disabled)
Guest (S-1-5-21-946118099-592492296-2719631590-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-946118099-592492296-2719631590-1002 - Limited - Enabled)
tvcomp (S-1-5-21-946118099-592492296-2719631590-1001 - Administrator - Enabled) => C:\Users\tvcomp
UpdatusUser (S-1-5-21-946118099-592492296-2719631590-1003 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 31 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 31.0.0.108 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\…\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
ASIO4ALL (HKLM-x32\…\ASIO4ALL) (Version: 2.10 - Michael Tippach)
AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.3.8.566 - AVG Technologies)
Avid Mbox 2 USB Drivers (x64) (HKLM\…\{F9242D4E-09E7-45C7-A53A-83375D0FAD42}) (Version: 9.0.2 - Avid Technology, Inc.)
BitTorrent (HKU\S-1-5-21-946118099-592492296-2719631590-1001\…\BitTorrent) (Version: 7.10.4.44521 - BitTorrent Inc.)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
D-Link DWA-171 Wireless AC Dual Band Adapter (HKLM-x32\…\{5F1C0C6E-0E47-4D60-8971-6EF9FC439B8B}) (Version: 1 - D-Link)
FL Studio 10 (HKLM-x32\…\FL Studio 10) (Version:  - Image-Line)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 68.0.3440.106 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
IL Download Manager (HKLM-x32\…\IL Download Manager) (Version:  - Image-Line)
Interlok driver setup x64 (HKLM\…\{25613C10-27D2-410B-942B-D922D5C3A7BE}) (Version: 5.9.0 - PACE Anti-Piracy, Inc.)
iTunes (HKLM\…\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Kodi (HKU\S-1-5-21-946118099-592492296-2719631590-1001\…\Kodi) (Version:  - XBMC-Foundation)
Microsoft .NET Framework 4.7.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\…\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Mozilla Firefox 62.0 (x64 en-US) (HKLM\…\Mozilla Firefox 62.0 (x64 en-US)) (Version: 62.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 54.0 - Mozilla)
NVIDIA Graphics Driver 309.08 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 309.08 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
OpenOffice 4.1.3 (HKLM-x32\…\{EEA30AEB-8BA7-465B-85D4-098BB99733E7}) (Version: 4.13.9783 - Apache Software Foundation)
REAPER (HKLM-x32\…\REAPER) (Version:  - )
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Web Companion (HKLM-x32\…\{b93562a7-7f1a-45d5-b36f-8748ca3bb5f4}) (Version: 4.3.1908.3686 - Lavasoft)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2015-01-30] (NVIDIA Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {3B15DE8D-5840-4FE4-A409-A61C694354B1} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_Plugin.exe [2018-09-11] (Adobe Systems Incorporated)
Task: {41ACF1C5-4F16-4435-B660-1E10DB759E13} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-04] (Google Inc.)
Task: {4BB233E1-5947-4A7B-A594-A6396B76E626} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-04] (Google Inc.)
Task: {86134DD4-0FE6-424B-9BE6-6970A6C2BB23} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {95C875E8-2CC6-4F8A-9DA1-15BB9F151BD2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-09-11] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\tvcomp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Image-Line website.lnk -> hxxp://www.image-line.com
Shortcut: C:\Users\tvcomp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Advanced\Diagnostic.lnk -> hxxp://www.image-line.com/diagnosti
Shortcut: C:\Users\tvcomp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Additional\Download Deckadance.lnk -> hxxp://www.deckadance.com
Shortcut: C:\Users\tvcomp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Additional\SynthMaker website.lnk -> hxxp://www.synthmaker.co.uk

==================== Loaded Modules (Whitelisted) ==============

2016-12-04 18:17 - 2017-10-25 08:12 - 000981576 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2016-09-01 18:27 - 2015-01-30 17:57 - 000086160 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-10-05 19:17 - 2016-10-05 19:17 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 19:17 - 2016-10-05 19:17 - 001353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2017-07-24 01:48 - 2018-08-01 16:26 - 000025888 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
2017-07-24 01:48 - 2018-08-01 16:26 - 000017696 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.Service.Logger.dll
2017-07-24 01:48 - 2018-08-01 16:26 - 000037664 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WcfService.dll
2016-12-04 18:17 - 2017-10-25 08:12 - 002187336 _____ () C:\Program Files (x86)\AVG Web TuneUp\vprot.exe

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\…\localhost -> localhost
IE trusted site: HKU\.DEFAULT\…\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-946118099-592492296-2719631590-1001\…\localhost -> localhost
IE trusted site: HKU\S-1-5-21-946118099-592492296-2719631590-1001\…\webcompanion.com -> hxxp://webcompanion.com

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2009-06-10 14:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-946118099-592492296-2719631590-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
DNS Servers: 192.168.1.254 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{4F6DC029-2779-49CE-9CFC-5ADA1D2B6774}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{AFAAA402-2C7A-4AA3-87B1-06E11E3C552F}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{1A02B37B-063C-4A40-B3B9-B3411714480D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{585ABB6B-B2B5-4879-8B24-9550B479B075}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{03070A3D-C34F-4CE7-B78D-E8959CF8575C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6BD7F0D2-B049-4DEE-B3DF-41B9595BAFF0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{03FF4B13-A040-4CB7-AC05-89F78CD946BE}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{D2565F67-4353-44D2-801A-9109FDD3E178}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5F65247A-7E38-484E-A868-6647CD6B3B6F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A199A145-60BA-4BAB-8C3B-1D5FC20BEF5C}] => (Allow) C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{A07CCA04-E674-4F77-A271-CBAC0777E65D}] => (Allow) C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{18115EE6-BAC0-4BE7-86F4-136E5DD4CC8E}] => (Allow) C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{4F2612F1-25E2-4E8F-BB75-9328A2281990}] => (Allow) C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{7AC024C4-876C-4B01-AB64-FC8E4C5DC287}] => (Allow) C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{6283B815-40A4-4C27-B682-7EE7F8146338}] => (Allow) C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [TCP Query User{179D60F6-B9C7-4AB1-8356-B69B8CE29E89}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{066CC8FF-DF1B-4F42-BCB2-3FE225A5520E}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{663DAE58-B601-4F24-9F3C-63FCCE551C54}] => (Allow) C:\Program Files (x86)\PremierOpinion\pmropn.exe
FirewallRules: [{E58B518E-14E1-474E-AB69-8681EAFDE3F6}] => (Allow) C:\Program Files (x86)\PremierOpinion\pmropn.exe
FirewallRules: [TCP Query User{1E845FA0-3CBF-4665-A509-A9E7A5F275E2}C:\program files (x86)\kodi\kodi.exe] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{6C8BCCA4-F762-4C96-A633-62B7FC848F3B}C:\program files (x86)\kodi\kodi.exe] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{3B4B3F3C-EEE0-4F18-A423-FDF799B32D54}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{497180CE-5D5D-49FF-BEBF-0F009B8C1199}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{91CC0E86-F69F-4F69-9878-F884AE35CC74}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe

==================== Restore Points =========================

13-09-2018 03:00:21 Windows Update
14-09-2018 03:00:16 Windows Update
15-09-2018 14:45:11 Windows Update
16-09-2018 03:00:17 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/16/2018 12:40:33 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/16/2018 11:15:28 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/15/2018 11:33:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: wmpnetwk.exe, version: 12.0.7601.17514, time stamp: 0x4ce7ae7f
Faulting module name: ntdll.dll, version: 6.1.7601.23807, time stamp: 0x5915fdce
Exception code: 0xc0000005
Fault offset: 0x000000000004f2a2
Faulting process id: 0xc58
Faulting application start time: 0x01d44d872f261e50
Faulting application path: C:\Program Files\Windows Media Player\wmpnetwk.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 73b061c0-b97a-11e8-a2e0-4487fc46d0cb

Error: (09/15/2018 05:37:53 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/15/2018 04:43:10 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/15/2018 03:33:33 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/13/2018 08:13:46 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/13/2018 07:33:43 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).


System errors:
=============
Error: (09/17/2018 01:46:42 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.66.
The computer with the IP address 192.168.1.65 did not allow the name to be claimed by
this computer.

Error: (09/17/2018 01:41:31 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.66.
The computer with the IP address 192.168.1.65 did not allow the name to be claimed by
this computer.

Error: (09/17/2018 01:36:21 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.66.
The computer with the IP address 192.168.1.65 did not allow the name to be claimed by
this computer.

Error: (09/17/2018 01:35:28 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (09/17/2018 01:35:27 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 1:23:53 AM on ‎9/‎17/‎2018 was unexpected.

Error: (09/17/2018 01:20:39 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.66.
The computer with the IP address 192.168.1.65 did not allow the name to be claimed by
this computer.

Error: (09/17/2018 01:20:05 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (09/17/2018 01:20:04 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 1:11:34 AM on ‎9/‎17/‎2018 was unexpected.


Windows Defender:
===================================
Date: 2018-08-26 19:31:24.243
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070003
Error description:The system cannot find the path specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

Date: 2018-08-26 19:26:22.064
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070003
Error description:The system cannot find the path specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

Date: 2018-08-26 19:09:31.500
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070003
Error description:The system cannot find the path specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

Date: 2018-08-26 16:16:24.289
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

Date: 2018-08-20 14:16:36.013
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

CodeIntegrity:
===================================

Date: 2018-07-20 19:55:24.467
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:24.358
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:24.062
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:23.937
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:16.948
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:16.839
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:16.714
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:16.589
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU E5400 @ 2.70GHz
Percentage of memory in use: 89%
Total physical RAM: 2815.23 MB
Available physical RAM: 288.75 MB
Total Virtual: 5628.65 MB
Available Virtual: 2868.48 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:398.33 GB) NTFS

\\?\Volume{bf5b49e5-708f-11e6-9b15-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 29C30B47)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

 

 

FRST LOG :

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15.09.2018
Ran by [removed] (administrator) on COMPUTER-PC (17-09-2018 01:47:39)
Running from C:\Users\[removed]\Downloads
[removed] Platform: Windows 7 Enterprise Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(BitTorrent Inc.) C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe
() C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(BitTorrent Inc.) C:\Users\tvcomp\AppData\Roaming\BitTorrent\updates\7.10.4_44521\bittorrentie.exe
(BitTorrent Inc.) C:\Users\tvcomp\AppData\Roaming\BitTorrent\updates\7.10.4_44521\bittorrentie.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(AVAST Software) C:\Users\tvcomp\Downloads\aswMBR.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2187336 2017-10-25] ()
HKU\S-1-5-21-946118099-592492296-2719631590-1001\…\Run: [BitTorrent] => C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe [2157760 2018-09-05] (BitTorrent Inc.)
HKU\S-1-5-21-946118099-592492296-2719631590-1001\…\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [7368480 2018-08-01] (Lavasoft)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 [removed]
Tcpip\..\Interfaces\{9D5A6C74-68EE-4341-A9F2-A168805F96B2}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{E7E875DE-2586-4C43-8C9A-FBD45765E8C4}: [DhcpNameServer] 192.168.1.254 [removed]

Internet Explorer:
==================
HKU\S-1-5-21-946118099-592492296-2719631590-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag;=D072417-A21ABFDD9D88F4162B1F&form;=CONMHP&conlogo;=CT3332016
HKU\S-1-5-21-946118099-592492296-2719631590-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-ca/?ocid=iehp
SearchScopes: HKU\S-1-5-21-946118099-592492296-2719631590-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={AEB854C9-5743-4A68-912B-57294787C037}∣=32ddd540ec9a47cfa61395cebaa23938-249425336082f47712e6c524b939a69b8ccd31a9⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0717tb≺=fr&d;=2016-12-05 01:17:01&v;=4.3.8.510&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-946118099-592492296-2719631590-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag;=D072417-A21ABFDD9D88F4162B1F&form;=CONBDF&conlogo;=CT3332016&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-946118099-592492296-2719631590-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={AEB854C9-5743-4A68-912B-57294787C037}∣=32ddd540ec9a47cfa61395cebaa23938-249425336082f47712e6c524b939a69b8ccd31a9⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0717tb≺=fr&d;=2016-12-05 01:17:01&v;=4.3.8.510&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.3.8.566\AVG Web TuneUp.dll [2017-10-25] (AVG)

FireFox:
========
FF DefaultProfile: gpo7ho2p.default
FF ProfilePath: C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Profiles\gpo7ho2p.default [2018-09-17]
FF Extension: (AVG Web TuneUp) - C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Profiles\gpo7ho2p.default\Extensions\[removed] [2017-10-25] [Legacy]
FF Extension: (Adblock Plus) - C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Profiles\gpo7ho2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-08-31]
FF Extension: (Firefox Monitor) - C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Profiles\gpo7ho2p.default\features\{043c6dda-4a9a-4c35-a438-b576d3a9b487}\[removed] [2018-09-10]
FF SearchPlugin: C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Profiles\gpo7ho2p.default\searchplugins\bing-lavasoft-ff59.xml [2018-08-02]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_108.dll [2018-09-11] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_108.dll [2018-09-11] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.8\\npsitesafety.dll [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)

Chrome:
=======
CHR HomePage: Default -> mysearch.avg.com
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR DefaultSearchURL: Default -> hxxps://mysearch.avg.com/search?rvt=1&sap;=dsp&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> hxxps://mysearch.avg.com
CHR DefaultSuggestURL: Default -> hxxps://toolbar.avg.com/acp?q={searchTerms}&o;=1
CHR Profile: C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default [2018-06-27]
CHR Extension: (Slides) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-07]
CHR Extension: (Docs) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-07]
CHR Extension: (Google Drive) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-04]
CHR Extension: (YouTube) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-04]
CHR Extension: (Adblock Plus) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-05-17]
CHR Extension: (AVG Secure Search) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2017-09-02]
CHR Extension: (Sheets) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-07]
CHR Extension: (Google Docs Offline) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-09]
CHR Extension: (Gmail) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-04]
CHR Extension: (Chrome Media Router) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-12]
CHR HKLM\…\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-946118099-592492296-2719631590-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [chfdnecihphmhljaaejmgoiahnihplgn] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [25888 2018-08-01] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [981576 2017-10-25] ()

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 DGUSBAP; C:\Windows\System32\DRIVERS\dgmbx2.sys [194864 2011-02-13] (Avid Technology, Inc.)
R3 MBX2DFU; C:\Windows\System32\DRIVERS\dgmbx2fu.sys [32944 2011-02-13] (Avid Technology, Inc.)
R3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [5088000 2016-09-06] (Realtek Semiconductor Corporation )
U3 swmidi; no ImagePath
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 aswMBR; \??\C:\Users\tvcomp\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\tvcomp\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-17 01:47 - 2018-09-17 01:48 - 000011126 _____ C:\Users\tvcomp\Downloads\FRST.txt
2018-09-17 01:46 - 2018-09-17 01:47 - 000000000 ____D C:\FRST
2018-09-17 01:46 - 2018-09-17 01:46 - 002413568 _____ (Farbar) C:\Users\tvcomp\Downloads\FRST64.exe
2018-09-17 01:45 - 2018-09-17 01:45 - 000000577 _____ C:\Users\tvcomp\Desktop\aswMBR.txt
2018-09-17 01:43 - 2018-09-17 01:43 - 005198336 _____ (AVAST Software) C:\Users\tvcomp\Downloads\aswMBR.exe
2018-09-17 01:11 - 2018-09-17 01:11 - 000282552 _____ C:\Windows\Minidump\091718-24039-01.dmp
2018-09-17 01:09 - 2018-09-17 01:09 - 000262144 _____ C:\Windows\Minidump\091718-22885-01.dmp
2018-09-09 19:51 - 2018-09-09 19:51 - 000281832 _____ C:\Windows\Minidump\090918-21340-01.dmp
2018-09-09 19:15 - 2018-09-09 19:16 - 000262144 _____ C:\Windows\Minidump\090918-19671-01.dmp
2018-09-09 19:07 - 2018-09-09 19:07 - 000266288 _____ C:\Windows\Minidump\090918-20248-01.dmp
2018-09-09 19:00 - 2018-09-09 19:00 - 000266288 _____ C:\Windows\Minidump\090918-20186-01.dmp
2018-09-09 18:39 - 2018-09-09 18:39 - 000266288 _____ C:\Windows\Minidump\090918-20841-01.dmp
2018-09-09 18:24 - 2018-09-09 18:24 - 000266288 _____ C:\Windows\Minidump\090918-20966-01.dmp
2018-09-08 21:26 - 2018-09-08 21:26 - 000282856 _____ C:\Windows\Minidump\090818-19422-01.dmp
2018-09-08 13:58 - 2018-09-08 13:59 - 000266288 _____ C:\Windows\Minidump\090818-19578-01.dmp
2018-09-08 13:03 - 2018-09-08 13:03 - 000282936 _____ C:\Windows\Minidump\090818-20155-01.dmp
2018-09-08 03:17 - 2018-09-08 03:17 - 000280808 _____ C:\Windows\Minidump\090818-20264-01.dmp
2018-09-08 03:16 - 2018-09-08 03:16 - 000281912 _____ C:\Windows\Minidump\090818-21918-01.dmp
2018-09-08 03:09 - 2018-09-08 03:09 - 000281752 _____ C:\Windows\Minidump\090818-22713-01.dmp
2018-09-08 03:01 - 2018-09-08 03:01 - 000262144 _____ C:\Windows\Minidump\090818-29889-01.dmp
2018-09-08 02:57 - 2018-09-08 02:57 - 000266288 _____ C:\Windows\Minidump\090818-18829-01.dmp
2018-09-08 02:52 - 2018-09-08 02:52 - 000266288 _____ C:\Windows\Minidump\090818-19671-01.dmp
2018-09-08 02:49 - 2018-09-08 02:49 - 000282792 _____ C:\Windows\Minidump\090818-23150-01.dmp
2018-09-08 02:47 - 2018-09-08 02:47 - 000285560 _____ C:\Windows\Minidump\090818-22838-01.dmp
2018-09-08 02:19 - 2018-09-08 02:19 - 000262144 _____ C:\Windows\Minidump\090818-18236-01.dmp
2018-09-07 07:08 - 2018-09-07 07:08 - 000266288 _____ C:\Windows\Minidump\090718-19827-01.dmp
2018-09-06 15:17 - 2018-09-06 15:17 - 000323880 _____ C:\Windows\Minidump\090618-19312-01.dmp
2018-09-06 15:08 - 2018-09-06 15:08 - 000283096 _____ C:\Windows\Minidump\090618-23774-01.dmp
2018-09-06 15:06 - 2018-09-06 15:06 - 000266288 _____ C:\Windows\Minidump\090618-20919-01.dmp
2018-09-06 06:29 - 2018-09-06 06:29 - 000266288 _____ C:\Windows\Minidump\090618-23665-01.dmp
2018-09-06 05:02 - 2018-09-06 05:02 - 000266288 _____ C:\Windows\Minidump\090618-20997-01.dmp
2018-09-05 19:41 - 2018-09-05 19:41 - 000281912 _____ C:\Windows\Minidump\090518-23088-01.dmp
2018-09-05 19:39 - 2018-09-05 19:39 - 000266288 _____ C:\Windows\Minidump\090518-18922-01.dmp
2018-09-05 17:48 - 2018-09-05 17:48 - 000266288 _____ C:\Windows\Minidump\090518-31871-01.dmp
2018-09-05 17:37 - 2018-09-05 17:37 - 000280808 _____ C:\Windows\Minidump\090518-30856-01.dmp
2018-09-05 17:35 - 2018-09-05 17:35 - 000266288 _____ C:\Windows\Minidump\090518-32526-01.dmp
2018-09-05 16:48 - 2018-09-05 16:48 - 000326256 _____ C:\Windows\Minidump\090518-32807-01.dmp
2018-09-05 16:39 - 2018-09-05 16:39 - 000262144 _____ C:\Windows\Minidump\090518-19890-01.dmp
2018-09-05 15:05 - 2018-09-05 15:05 - 000000000 ____D C:\Users\tvcomp\Downloads\Eminem - Kamikaze (2018) Mp3 (320kbps) [Hunter]
2018-09-05 03:37 - 2018-09-05 03:37 - 000283344 _____ C:\Windows\Minidump\090518-19328-01.dmp
2018-09-05 03:19 - 2018-09-05 03:19 - 000266288 _____ C:\Windows\Minidump\090518-19765-01.dmp
2018-09-05 03:04 - 2018-09-05 03:04 - 000283096 _____ C:\Windows\Minidump\090518-18829-01.dmp
2018-09-05 02:43 - 2018-09-05 02:43 - 000266288 _____ C:\Windows\Minidump\090518-18376-01.dmp
2018-09-05 02:34 - 2018-09-05 02:34 - 000284864 _____ C:\Windows\Minidump\090518-19234-01.dmp
2018-09-04 20:24 - 2018-09-04 20:24 - 000282144 _____ C:\Windows\Minidump\090418-19718-01.dmp
2018-09-04 14:58 - 2018-09-04 14:58 - 000262144 _____ C:\Windows\Minidump\090418-30513-01.dmp
2018-09-04 14:50 - 2018-09-04 14:51 - 000262144 _____ C:\Windows\Minidump\090418-31839-01.dmp
2018-09-04 14:47 - 2018-09-04 14:47 - 000282968 _____ C:\Windows\Minidump\090418-21309-01.dmp
2018-09-04 14:45 - 2018-09-04 14:45 - 000282472 _____ C:\Windows\Minidump\090418-22807-01.dmp
2018-09-04 14:43 - 2018-09-04 14:44 - 000323568 _____ C:\Windows\Minidump\090418-24320-01.dmp
2018-09-04 12:02 - 2018-09-04 12:02 - 000282872 _____ C:\Windows\Minidump\090418-22058-01.dmp
2018-09-04 11:01 - 2018-09-04 11:01 - 000266288 _____ C:\Windows\Minidump\090418-19968-01.dmp
2018-09-04 10:53 - 2018-09-04 10:53 - 000262144 _____ C:\Windows\Minidump\090418-22074-01.dmp
2018-09-04 10:50 - 2018-09-04 10:50 - 000266288 _____ C:\Windows\Minidump\090418-20233-01.dmp
2018-09-04 10:39 - 2018-09-04 10:39 - 000282872 _____ C:\Windows\Minidump\090418-25381-01.dmp
2018-09-04 10:37 - 2018-09-04 10:37 - 000262144 _____ C:\Windows\Minidump\090418-24039-01.dmp
2018-08-27 16:23 - 2018-08-27 16:23 - 000000000 ____D C:\Users\tvcomp\Downloads\Murs - Captain California (2017) [Mp3~320kbps]
2018-08-27 14:55 - 2018-08-27 14:55 - 000000000 ____D C:\Users\tvcomp\Downloads\Murs - A Strange Journey Into the Unimaginable (2018) Mp3 (320kbps) [Hunter]
2018-08-27 14:53 - 2018-08-27 14:53 - 000000000 ____D C:\Users\tvcomp\Downloads\MAC MILLER - Swimming (2018) Mp3 (320kbps) [Hunter]
2018-08-27 14:52 - 2018-08-27 14:52 - 000000000 ____D C:\Users\tvcomp\Downloads\Florence and The Machine - High As Hope (2018) [320]
2018-08-27 14:43 - 2018-08-27 14:46 - 000000000 ____D C:\Users\tvcomp\Downloads\Reflective (Part 1)
2018-08-27 14:42 - 2018-08-27 14:42 - 000000000 ____D C:\Users\tvcomp\Downloads\Bryson Tiller - TRAPSOUL [2015] [MP3-320Kbps] [CBR] [sn3h1t87] [GloDLS]
2018-08-27 14:38 - 2018-08-27 14:38 - 000000000 ____D C:\Users\tvcomp\Downloads\Nas - NASIR (2018) Mp3 (320kbps) [Hunter]
2018-08-27 14:27 - 2018-08-27 14:31 - 000000000 ____D C:\Users\tvcomp\Desktop\photos from old phone
2018-08-27 14:23 - 2018-08-27 17:24 - 332410373 _____ C:\Users\tvcomp\Downloads\MusicPack_29569.rar
2018-08-27 14:12 - 2018-08-27 14:12 - 000000000 ____D C:\Users\tvcomp\Downloads\Ariana Grande - Sweetener (Super Deluxe Version) (2018)

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-17 01:47 - 2017-07-08 03:16 - 000000000 ____D C:\Users\tvcomp\AppData\Roaming\BitTorrent
2018-09-17 01:38 - 2017-06-19 15:35 - 000000000 ____D C:\Users\tvcomp\AppData\LocalLow\Mozilla
2018-09-17 01:37 - 2016-09-01 18:28 - 000000000 ____D C:\Users\UpdatusUser
2018-09-17 01:35 - 2018-08-02 03:20 - 000000000 ____D C:\Users\tvcomp\AppData\LocalLow\BitTorrent
2018-09-17 01:35 - 2009-07-13 22:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-09-17 01:11 - 2018-01-17 03:52 - 408292175 _____ C:\Windows\MEMORY.DMP
2018-09-17 01:11 - 2018-01-17 03:52 - 000000000 ____D C:\Windows\Minidump
2018-09-16 04:38 - 2009-07-13 21:45 - 000015488 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-09-16 04:38 - 2009-07-13 21:45 - 000015488 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-09-12 03:26 - 2016-09-01 16:54 - 000000000 ____D C:\Windows\system32\MRT
2018-09-12 03:15 - 2016-09-01 16:54 - 139184408 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-09-12 03:06 - 2017-07-17 22:50 - 000808400 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-09-12 03:06 - 2009-07-13 22:13 - 000808400 _____ C:\Windows\system32\PerfStringBackup.INI
2018-09-12 03:06 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\inf
2018-09-11 20:54 - 2018-05-19 22:46 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-09-11 20:54 - 2018-05-19 22:46 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-09-11 20:54 - 2018-05-19 22:46 - 000004470 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-09-11 20:54 - 2018-05-19 22:46 - 000004324 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-09-11 20:54 - 2018-05-19 22:46 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-09-11 20:54 - 2018-05-19 22:46 - 000000000 ____D C:\Windows\system32\Macromed
2018-09-09 21:37 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\registration
2018-09-09 20:38 - 2016-09-01 15:31 - 000000000 ____D C:\Users\tvcomp
2018-09-05 16:24 - 2017-06-19 15:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-09-05 16:24 - 2016-12-04 18:17 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-09-03 01:40 - 2017-06-19 15:52 - 000000000 ____D C:\Users\tvcomp\AppData\Roaming\REAPER
2018-09-03 01:18 - 2009-07-13 22:08 - 000032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-09-02 09:47 - 2017-06-19 16:42 - 000000000 ____D C:\Users\tvcomp\Documents\REAPER Media
2018-08-29 13:00 - 2018-08-09 22:02 - 000000000 ____D C:\Users\tvcomp\Downloads\Liquid Stranger- The Arcane Terrain
2018-08-27 20:27 - 2017-11-20 22:02 - 000000000 ____D C:\Users\tvcomp\AppData\Roaming\Kodi

Some files in TEMP:
====================
2017-11-26 21:32 - 2017-11-26 21:32 - 000937664 _____ (adaware) C:\Users\tvcomp\AppData\Local\Temp\WCU008.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-09-16 00:01

==================== End of FRST.txt =========================


 

Hello montab and welcome to WTT.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

P2P - I see you have P2P software, (BitTorrent ), installed on your machine. Although BitTorrent itself is a legitimate program, it is usually seen here in conjunction with other programs used for P2P file-sharing.

We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection.

If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

If you still think about using it, please see the link below for information about CryptoLocker Ransomware, a type of Ransomware which can be delivered via P2P file transfers.

CryptoLocker Ransomware.

The newest variation of Ransomware can make it impossible to recover the files that it encrypts. In other words, you will probably lose most, if not all of your files, including pictures. In addition, it has recently been reported that P2P downloads may be tracked, resulting in your IP address being monitored by copyright authorities.

I would strongly recommend that you uninstall BitTorrent now.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Note: Please complete these tasks in the order given in the instructions.

===================================================

Uninstall a programme

Please uninstall this programme:

Web Companion

  • click Start, Control Panel, Programs and Features
  • click on Web Companion and then on Uninstall

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Run Malwarebytes Anti-Malware

Please download and run the installer for Malwarebytes 3.0.

  • follow the prompts to install the program, (Malwarebytes 3.0 will automatically upgrade Malwarebytes Anti-Malware 2.x to Malwarebytes 3.0)
  • at the end, be sure a checkmark is placed next to the following
    • Launch Malwarebytes Anti-Malware
    • a 14 day trial of the Premium features is pre-selected: deselect this if you don’t want it, (it won’t diminish the scanning and removal capabilities of the program).
  • click Finish.
  • on the Dashboard, click Update Now
  • after the update completes, click the Scan Now' button.
  • if an update is available, clicking the Update Now button will update it
  • a Threat Scan will begin.
  • when the scan is complete, if malware has been detected, click Apply Actions to allow MBAM to clean what was found
  • when the prompt to restart the computer appears, click Yes.
  • after the restart once you are back at your desktop, open MBAM once more
  • click on the ‘History’ tab, the ‘Application Logs’
  • double-click on the scan log which shows the date and time of the scan just performed.
  • click Copy to Clipboard
  • please paste the contents of the clipboard into your reply.

Logs to include with the next post:

AdwCleaner log
Mbam.txt


Thanks

Satchfan

 

alright,  here are the two logs

 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 9/18/18
Scan Time: 3:47 AM
Log File: 45dbef50-bb30-11e8-8850-4487fc46d0cb.json

-Software Information-
Version: 3.5.1.2522
Components Version: 1.0.441
Update Package Version: 1.0.6887
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: COMPUTER-PC\tvcomp

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 285417
Threats Detected: 8
Threats Quarantined: 8
Time Elapsed: 9 min, 18 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 3
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\NLADLJMABBOANHIHFKJACNNKGJHNOKHJ, Quarantined, [277], [550469],1.0.6887
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\nladljmabboanhihfkjacnnkgjhnokhj, Quarantined, [277], [550469],1.0.6887
PUP.Optional.MediaPlayAir, HKU\S-1-5-21-946118099-592492296-2719631590-1001\SOFTWARE\UNDEFINED, Quarantined, [1135], [334354],1.0.6887

Registry Value: 1
PUP.Optional.MediaPlayAir, HKU\S-1-5-21-946118099-592492296-2719631590-1001\SOFTWARE\UNDEFINED|FLASHPLAYERPRO.EXE, Quarantined, [1135], [334354],1.0.6887

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 1
PUP.Optional.PCAP, C:\PROGRAM FILES (X86)\INSTALLER_P.C.A.P, Quarantined, [3026], [383709],1.0.6887

File: 3
PUP.Optional.DefaultSearch, C:\USERS\TVCOMP\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [277], [550469],1.0.6887
PUP.Optional.BundleInstaller, C:\USERS\TVCOMP\DOWNLOADS\FLASHPLAYERPRO_2761331769.EXE, Quarantined, [413], [419899],1.0.6887
PUP.Optional.MediaPlayAir, C:\USERS\TVCOMP\DOWNLOADS\FLASHPLAYERPRO.EXE, Quarantined, [1135], [428122],1.0.6887

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

 

 

 

# ——————————-
# Malwarebytes AdwCleaner 7.2.3.1
# ——————————-
# Build:    09-03-2018
# Database: 2018-09-17.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start:    09-18-2018
# Duration: 00:00:10
# OS:       Windows 7 Enterprise
# Cleaned:  42
# Failed:   0


***** [ Services ] *****

Deleted       WtuSystemSupport

***** [ Folders ] *****

Deleted       C:\Users\tvcomp\AppData\Local\Temp\PremierOpinion
Deleted       C:\Users\tvcomp\AppData\Roaming\InstantSupport
Deleted       C:\ProgramData\avg web tuneup
Deleted       C:\Program Files (x86)\avg web tuneup
Deleted       C:\Users\tvcomp\AppData\Local\avg web tuneup
Deleted       C:\Program Files\Common Files\AVG Secure Search
Deleted       C:\Program Files (x86)\Common Files\AVG Secure Search

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKCU\Software\csastats
Deleted       HKCU\Software\InSTab
Deleted       HKCU\Software\InstantSupport
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion
Deleted       HKCU\Software\ACPTab
Deleted       HKLM\Software\Wow6432Node\AVG Tuneup
Deleted       HKLM\Software\Wow6432Node\Google\Chrome\NativeMessagingHosts\avgsh
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
Deleted       HKLM\Software\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Deleted       HKLM\Software\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Deleted       HKLM\Software\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Deleted       HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{E58B518E-14E1-474E-AB69-8681EAFDE3F6}
Deleted       HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{663DAE58-B601-4F24-9F3C-63FCCE551C54}
Deleted       HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\glassinbox.com
Deleted       HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Deleted       HKCU\Software\Microsoft\Internet Explorer\Main|Start Page
Deleted       HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Deleted       HKLM\Software\Wow6432Node\PCAcceleratePro
Deleted       HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|PCAcceleratePro.exe
Deleted       HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION|PCAcceleratePro.exe
Deleted       HKCU\Software\PRODUCTSETUP
Deleted       HKCU\Software\Lavasoft\Web Companion
Deleted       HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted       HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted       HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com

***** [ Chromium (and derivatives) ] *****

Deleted       AVG Web TuneUp

***** [ Chromium URLs ] *****

Deleted       Ask
Deleted       AOL

***** [ Firefox (and derivatives) ] *****

Deleted       AVG Web TuneUp

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [4958 octets] - [18/09/2018 03:41:08]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
 

Please run FRST again and make sure there is a checkmark next to ‘Addition.txt’ before you hit Scan.

Logs to include with next post:

New Frst.txt
New Addition.txt


Thanks

Satchfan

okay, here ya go:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15.09.2018
Ran by [removed] (administrator) on COMPUTER-PC (18-09-2018 15:05:42)
Running from C:\Users\[removed]\Downloads
[removed] Platform: Windows 7 Enterprise Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM-x32\…\Run: [vProt] => "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 [removed]
Tcpip\..\Interfaces\{9D5A6C74-68EE-4341-A9F2-A168805F96B2}: [DhcpNameServer] 192.168.137.1
Tcpip\..\Interfaces\{E7E875DE-2586-4C43-8C9A-FBD45765E8C4}: [DhcpNameServer] 192.168.1.254 [removed]

Internet Explorer:
==================
HKU\S-1-5-21-946118099-592492296-2719631590-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-ca/?ocid=iehp
SearchScopes: HKU\S-1-5-21-946118099-592492296-2719631590-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL =
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.3.8.566\AVG Web TuneUp.dll => No File

FireFox:
========
FF DefaultProfile: gpo7ho2p.default
FF ProfilePath: C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Profiles\gpo7ho2p.default [2018-09-18]
FF Extension: (Adblock Plus) - C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Profiles\gpo7ho2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-08-31]
FF Extension: (Firefox Monitor) - C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Profiles\gpo7ho2p.default\features\{043c6dda-4a9a-4c35-a438-b576d3a9b487}\[removed] [2018-09-10]
FF SearchPlugin: C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Profiles\gpo7ho2p.default\searchplugins\bing-lavasoft-ff59.xml [2018-08-02]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_108.dll [2018-09-11] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_108.dll [2018-09-11] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.8\\npsitesafety.dll [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR Profile: C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default [2018-06-27]
CHR Extension: (Slides) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-07]
CHR Extension: (Docs) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-07]
CHR Extension: (Google Drive) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-04]
CHR Extension: (YouTube) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-04]
CHR Extension: (Adblock Plus) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-05-17]
CHR Extension: (AVG Web TuneUp) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2017-09-02]
CHR Extension: (Sheets) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-07]
CHR Extension: (Google Docs Offline) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-09]
CHR Extension: (Gmail) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-04]
CHR Extension: (Chrome Media Router) - C:\Users\tvcomp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-12]
CHR HKU\S-1-5-21-946118099-592492296-2719631590-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [chfdnecihphmhljaaejmgoiahnihplgn] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 DGUSBAP; C:\Windows\System32\DRIVERS\dgmbx2.sys [194864 2011-02-13] (Avid Technology, Inc.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [152688 2018-07-12] (Malwarebytes)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193256 2018-09-18] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [117472 2018-09-18] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [52328 2018-09-18] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [259360 2018-09-18] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [98616 2018-09-18] (Malwarebytes)
R3 MBX2DFU; C:\Windows\System32\DRIVERS\dgmbx2fu.sys [32944 2011-02-13] (Avid Technology, Inc.)
R3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [5088000 2016-09-06] (Realtek Semiconductor Corporation )
U3 swmidi; no ImagePath
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-18 03:46 - 2018-09-18 13:49 - 000098616 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-09-18 03:46 - 2018-09-18 03:46 - 000259360 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-09-18 03:46 - 2018-09-18 03:46 - 000193256 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-09-18 03:46 - 2018-09-18 03:46 - 000117472 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-09-18 03:46 - 2018-09-18 03:46 - 000052328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-09-18 03:46 - 2018-09-18 03:46 - 000000000 ____D C:\Users\tvcomp\AppData\Local\mbam
2018-09-18 03:45 - 2018-09-18 03:45 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-09-18 03:45 - 2018-09-18 03:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-09-18 03:45 - 2018-09-18 03:45 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-09-18 03:45 - 2018-09-18 03:45 - 000000000 ____D C:\Program Files\Malwarebytes
2018-09-18 03:45 - 2018-07-12 08:42 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-09-18 03:44 - 2018-09-18 03:44 - 081615816 _____ (Malwarebytes ) C:\Users\tvcomp\Downloads\mb3-setup-consumer-3.5.1.2522-1.0.441-1.0.6871.exe
2018-09-18 03:40 - 2018-09-18 03:41 - 000000000 ____D C:\AdwCleaner
2018-09-18 03:39 - 2018-09-18 03:39 - 007571152 _____ (Malwarebytes) C:\Users\tvcomp\Downloads\adwcleaner_7.2.3.1.exe
2018-09-17 16:17 - 2018-09-17 16:17 - 001790024 _____ (Malwarebytes) C:\Users\tvcomp\Downloads\JRT(1).exe
2018-09-17 16:17 - 2018-09-17 16:17 - 000000000 _____ C:\Users\tvcomp\Downloads\JRT.exe
2018-09-17 01:49 - 2018-09-17 01:49 - 000024541 _____ C:\Users\tvcomp\Downloads\Addition.txt
2018-09-17 01:47 - 2018-09-18 15:07 - 000008931 _____ C:\Users\tvcomp\Downloads\FRST.txt
2018-09-17 01:46 - 2018-09-18 15:05 - 000000000 ____D C:\FRST
2018-09-17 01:46 - 2018-09-17 01:46 - 002413568 _____ (Farbar) C:\Users\tvcomp\Downloads\FRST64.exe
2018-09-17 01:45 - 2018-09-17 01:45 - 000000577 _____ C:\Users\tvcomp\Desktop\aswMBR.txt
2018-09-17 01:43 - 2018-09-17 01:43 - 005198336 _____ (AVAST Software) C:\Users\tvcomp\Downloads\aswMBR.exe
2018-09-17 01:11 - 2018-09-17 01:11 - 000282552 _____ C:\Windows\Minidump\091718-24039-01.dmp
2018-09-17 01:09 - 2018-09-17 01:09 - 000262144 _____ C:\Windows\Minidump\091718-22885-01.dmp
2018-09-09 19:51 - 2018-09-09 19:51 - 000281832 _____ C:\Windows\Minidump\090918-21340-01.dmp
2018-09-09 19:15 - 2018-09-09 19:16 - 000262144 _____ C:\Windows\Minidump\090918-19671-01.dmp
2018-09-09 19:07 - 2018-09-09 19:07 - 000266288 _____ C:\Windows\Minidump\090918-20248-01.dmp
2018-09-09 19:00 - 2018-09-09 19:00 - 000266288 _____ C:\Windows\Minidump\090918-20186-01.dmp
2018-09-09 18:39 - 2018-09-09 18:39 - 000266288 _____ C:\Windows\Minidump\090918-20841-01.dmp
2018-09-09 18:24 - 2018-09-09 18:24 - 000266288 _____ C:\Windows\Minidump\090918-20966-01.dmp
2018-09-08 21:26 - 2018-09-08 21:26 - 000282856 _____ C:\Windows\Minidump\090818-19422-01.dmp
2018-09-08 13:58 - 2018-09-08 13:59 - 000266288 _____ C:\Windows\Minidump\090818-19578-01.dmp
2018-09-08 13:03 - 2018-09-08 13:03 - 000282936 _____ C:\Windows\Minidump\090818-20155-01.dmp
2018-09-08 03:17 - 2018-09-08 03:17 - 000280808 _____ C:\Windows\Minidump\090818-20264-01.dmp
2018-09-08 03:16 - 2018-09-08 03:16 - 000281912 _____ C:\Windows\Minidump\090818-21918-01.dmp
2018-09-08 03:09 - 2018-09-08 03:09 - 000281752 _____ C:\Windows\Minidump\090818-22713-01.dmp
2018-09-08 03:01 - 2018-09-08 03:01 - 000262144 _____ C:\Windows\Minidump\090818-29889-01.dmp
2018-09-08 02:57 - 2018-09-08 02:57 - 000266288 _____ C:\Windows\Minidump\090818-18829-01.dmp
2018-09-08 02:52 - 2018-09-08 02:52 - 000266288 _____ C:\Windows\Minidump\090818-19671-01.dmp
2018-09-08 02:49 - 2018-09-08 02:49 - 000282792 _____ C:\Windows\Minidump\090818-23150-01.dmp
2018-09-08 02:47 - 2018-09-08 02:47 - 000285560 _____ C:\Windows\Minidump\090818-22838-01.dmp
2018-09-08 02:19 - 2018-09-08 02:19 - 000262144 _____ C:\Windows\Minidump\090818-18236-01.dmp
2018-09-07 07:08 - 2018-09-07 07:08 - 000266288 _____ C:\Windows\Minidump\090718-19827-01.dmp
2018-09-06 15:17 - 2018-09-06 15:17 - 000323880 _____ C:\Windows\Minidump\090618-19312-01.dmp
2018-09-06 15:08 - 2018-09-06 15:08 - 000283096 _____ C:\Windows\Minidump\090618-23774-01.dmp
2018-09-06 15:06 - 2018-09-06 15:06 - 000266288 _____ C:\Windows\Minidump\090618-20919-01.dmp
2018-09-06 06:29 - 2018-09-06 06:29 - 000266288 _____ C:\Windows\Minidump\090618-23665-01.dmp
2018-09-06 05:02 - 2018-09-06 05:02 - 000266288 _____ C:\Windows\Minidump\090618-20997-01.dmp
2018-09-05 19:41 - 2018-09-05 19:41 - 000281912 _____ C:\Windows\Minidump\090518-23088-01.dmp
2018-09-05 19:39 - 2018-09-05 19:39 - 000266288 _____ C:\Windows\Minidump\090518-18922-01.dmp
2018-09-05 17:48 - 2018-09-05 17:48 - 000266288 _____ C:\Windows\Minidump\090518-31871-01.dmp
2018-09-05 17:37 - 2018-09-05 17:37 - 000280808 _____ C:\Windows\Minidump\090518-30856-01.dmp
2018-09-05 17:35 - 2018-09-05 17:35 - 000266288 _____ C:\Windows\Minidump\090518-32526-01.dmp
2018-09-05 16:48 - 2018-09-05 16:48 - 000326256 _____ C:\Windows\Minidump\090518-32807-01.dmp
2018-09-05 16:39 - 2018-09-05 16:39 - 000262144 _____ C:\Windows\Minidump\090518-19890-01.dmp
2018-09-05 15:05 - 2018-09-05 15:05 - 000000000 ____D C:\Users\tvcomp\Downloads\Eminem - Kamikaze (2018) Mp3 (320kbps) [Hunter]
2018-09-05 03:37 - 2018-09-05 03:37 - 000283344 _____ C:\Windows\Minidump\090518-19328-01.dmp
2018-09-05 03:19 - 2018-09-05 03:19 - 000266288 _____ C:\Windows\Minidump\090518-19765-01.dmp
2018-09-05 03:04 - 2018-09-05 03:04 - 000283096 _____ C:\Windows\Minidump\090518-18829-01.dmp
2018-09-05 02:43 - 2018-09-05 02:43 - 000266288 _____ C:\Windows\Minidump\090518-18376-01.dmp
2018-09-05 02:34 - 2018-09-05 02:34 - 000284864 _____ C:\Windows\Minidump\090518-19234-01.dmp
2018-09-04 20:24 - 2018-09-04 20:24 - 000282144 _____ C:\Windows\Minidump\090418-19718-01.dmp
2018-09-04 14:58 - 2018-09-04 14:58 - 000262144 _____ C:\Windows\Minidump\090418-30513-01.dmp
2018-09-04 14:50 - 2018-09-04 14:51 - 000262144 _____ C:\Windows\Minidump\090418-31839-01.dmp
2018-09-04 14:47 - 2018-09-04 14:47 - 000282968 _____ C:\Windows\Minidump\090418-21309-01.dmp
2018-09-04 14:45 - 2018-09-04 14:45 - 000282472 _____ C:\Windows\Minidump\090418-22807-01.dmp
2018-09-04 14:43 - 2018-09-04 14:44 - 000323568 _____ C:\Windows\Minidump\090418-24320-01.dmp
2018-09-04 12:02 - 2018-09-04 12:02 - 000282872 _____ C:\Windows\Minidump\090418-22058-01.dmp
2018-09-04 11:01 - 2018-09-04 11:01 - 000266288 _____ C:\Windows\Minidump\090418-19968-01.dmp
2018-09-04 10:53 - 2018-09-04 10:53 - 000262144 _____ C:\Windows\Minidump\090418-22074-01.dmp
2018-09-04 10:50 - 2018-09-04 10:50 - 000266288 _____ C:\Windows\Minidump\090418-20233-01.dmp
2018-09-04 10:39 - 2018-09-04 10:39 - 000282872 _____ C:\Windows\Minidump\090418-25381-01.dmp
2018-09-04 10:37 - 2018-09-04 10:37 - 000262144 _____ C:\Windows\Minidump\090418-24039-01.dmp
2018-08-27 16:23 - 2018-08-27 16:23 - 000000000 ____D C:\Users\tvcomp\Downloads\Murs - Captain California (2017) [Mp3~320kbps]
2018-08-27 14:55 - 2018-08-27 14:55 - 000000000 ____D C:\Users\tvcomp\Downloads\Murs - A Strange Journey Into the Unimaginable (2018) Mp3 (320kbps) [Hunter]
2018-08-27 14:53 - 2018-08-27 14:53 - 000000000 ____D C:\Users\tvcomp\Downloads\MAC MILLER - Swimming (2018) Mp3 (320kbps) [Hunter]
2018-08-27 14:52 - 2018-08-27 14:52 - 000000000 ____D C:\Users\tvcomp\Downloads\Florence and The Machine - High As Hope (2018) [320]
2018-08-27 14:43 - 2018-08-27 14:46 - 000000000 ____D C:\Users\tvcomp\Downloads\Reflective (Part 1)
2018-08-27 14:42 - 2018-08-27 14:42 - 000000000 ____D C:\Users\tvcomp\Downloads\Bryson Tiller - TRAPSOUL [2015] [MP3-320Kbps] [CBR] [sn3h1t87] [GloDLS]
2018-08-27 14:38 - 2018-08-27 14:38 - 000000000 ____D C:\Users\tvcomp\Downloads\Nas - NASIR (2018) Mp3 (320kbps) [Hunter]
2018-08-27 14:27 - 2018-08-27 14:31 - 000000000 ____D C:\Users\tvcomp\Desktop\photos from old phone
2018-08-27 14:23 - 2018-08-27 17:24 - 332410373 _____ C:\Users\tvcomp\Downloads\MusicPack_29569.rar
2018-08-27 14:12 - 2018-08-27 14:12 - 000000000 ____D C:\Users\tvcomp\Downloads\Ariana Grande - Sweetener (Super Deluxe Version) (2018)

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-18 04:04 - 2009-07-13 21:45 - 000015488 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-09-18 04:04 - 2009-07-13 21:45 - 000015488 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-09-18 03:45 - 2016-09-01 18:28 - 000000000 ____D C:\Users\UpdatusUser
2018-09-18 03:43 - 2017-06-19 15:35 - 000000000 ____D C:\Users\tvcomp\AppData\LocalLow\Mozilla
2018-09-18 03:43 - 2009-07-13 22:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-09-17 16:15 - 2017-07-08 03:16 - 000000000 ____D C:\Users\tvcomp\AppData\Roaming\BitTorrent
2018-09-17 01:11 - 2018-01-17 03:52 - 408292175 _____ C:\Windows\MEMORY.DMP
2018-09-17 01:11 - 2018-01-17 03:52 - 000000000 ____D C:\Windows\Minidump
2018-09-12 03:26 - 2016-09-01 16:54 - 000000000 ____D C:\Windows\system32\MRT
2018-09-12 03:15 - 2016-09-01 16:54 - 139184408 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-09-12 03:06 - 2017-07-17 22:50 - 000808400 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-09-12 03:06 - 2009-07-13 22:13 - 000808400 _____ C:\Windows\system32\PerfStringBackup.INI
2018-09-12 03:06 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\inf
2018-09-11 20:54 - 2018-05-19 22:46 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-09-11 20:54 - 2018-05-19 22:46 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-09-11 20:54 - 2018-05-19 22:46 - 000004470 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-09-11 20:54 - 2018-05-19 22:46 - 000004324 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-09-11 20:54 - 2018-05-19 22:46 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-09-11 20:54 - 2018-05-19 22:46 - 000000000 ____D C:\Windows\system32\Macromed
2018-09-09 21:37 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\registration
2018-09-09 20:38 - 2016-09-01 15:31 - 000000000 ____D C:\Users\tvcomp
2018-09-05 16:24 - 2017-06-19 15:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-09-05 16:24 - 2016-12-04 18:17 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-09-03 01:40 - 2017-06-19 15:52 - 000000000 ____D C:\Users\tvcomp\AppData\Roaming\REAPER
2018-09-03 01:18 - 2009-07-13 22:08 - 000032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-09-02 09:47 - 2017-06-19 16:42 - 000000000 ____D C:\Users\tvcomp\Documents\REAPER Media
2018-08-29 13:00 - 2018-08-09 22:02 - 000000000 ____D C:\Users\tvcomp\Downloads\Liquid Stranger- The Arcane Terrain
2018-08-27 20:27 - 2017-11-20 22:02 - 000000000 ____D C:\Users\tvcomp\AppData\Roaming\Kodi

Some files in TEMP:
====================
2017-11-26 21:32 - 2017-11-26 21:32 - 000937664 _____ (adaware) C:\Users\tvcomp\AppData\Local\Temp\WCU008.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-09-17 04:59

==================== End of FRST.txt ============================

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15.09.2018
Ran by [removed] (18-09-2018 15:08:15)
Running from C:\Users\[removed]\Downloads
Windows 7 Enterprise Service Pack 1 (X64) (2016-09-01 22:31:03)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-946118099-592492296-2719631590-500 - Administrator - Disabled)
Guest (S-1-5-21-946118099-592492296-2719631590-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-946118099-592492296-2719631590-1002 - Limited - Enabled)
tvcomp (S-1-5-21-946118099-592492296-2719631590-1001 - Administrator - Enabled) => C:\Users\tvcomp
UpdatusUser (S-1-5-21-946118099-592492296-2719631590-1003 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 31 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 31.0.0.108 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\…\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
ASIO4ALL (HKLM-x32\…\ASIO4ALL) (Version: 2.10 - Michael Tippach)
AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.3.8.566 - AVG Technologies)
Avid Mbox 2 USB Drivers (x64) (HKLM\…\{F9242D4E-09E7-45C7-A53A-83375D0FAD42}) (Version: 9.0.2 - Avid Technology, Inc.)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
D-Link DWA-171 Wireless AC Dual Band Adapter (HKLM-x32\…\{5F1C0C6E-0E47-4D60-8971-6EF9FC439B8B}) (Version: 1 - D-Link)
FL Studio 10 (HKLM-x32\…\FL Studio 10) (Version:  - Image-Line)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 68.0.3440.106 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
IL Download Manager (HKLM-x32\…\IL Download Manager) (Version:  - Image-Line)
Interlok driver setup x64 (HKLM\…\{25613C10-27D2-410B-942B-D922D5C3A7BE}) (Version: 5.9.0 - PACE Anti-Piracy, Inc.)
iTunes (HKLM\…\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Kodi (HKU\S-1-5-21-946118099-592492296-2719631590-1001\…\Kodi) (Version:  - XBMC-Foundation)
Malwarebytes version 3.5.1.2522 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Microsoft .NET Framework 4.7.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\…\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Mozilla Firefox 62.0 (x64 en-US) (HKLM\…\Mozilla Firefox 62.0 (x64 en-US)) (Version: 62.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 54.0 - Mozilla)
NVIDIA Graphics Driver 309.08 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 309.08 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
OpenOffice 4.1.3 (HKLM-x32\…\{EEA30AEB-8BA7-465B-85D4-098BB99733E7}) (Version: 4.13.9783 - Apache Software Foundation)
REAPER (HKLM-x32\…\REAPER) (Version:  - )
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2015-01-30] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {3B15DE8D-5840-4FE4-A409-A61C694354B1} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_Plugin.exe [2018-09-11] (Adobe Systems Incorporated)
Task: {41ACF1C5-4F16-4435-B660-1E10DB759E13} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-04] (Google Inc.)
Task: {4BB233E1-5947-4A7B-A594-A6396B76E626} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-04] (Google Inc.)
Task: {86134DD4-0FE6-424B-9BE6-6970A6C2BB23} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {95C875E8-2CC6-4F8A-9DA1-15BB9F151BD2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-09-11] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\tvcomp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Image-Line website.lnk -> hxxp://www.image-line.com
Shortcut: C:\Users\tvcomp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Advanced\Diagnostic.lnk -> hxxp://www.image-line.com/diagnosti
Shortcut: C:\Users\tvcomp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Additional\Download Deckadance.lnk -> hxxp://www.deckadance.com
Shortcut: C:\Users\tvcomp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Additional\SynthMaker website.lnk -> hxxp://www.synthmaker.co.uk

==================== Loaded Modules (Whitelisted) ==============

2016-09-01 18:27 - 2015-01-30 17:57 - 000086160 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-10-05 19:17 - 2016-10-05 19:17 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 19:17 - 2016-10-05 19:17 - 001353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2018-09-18 03:45 - 2018-07-24 12:32 - 002681424 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-09-18 03:45 - 2018-08-06 14:20 - 002769768 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2018-09-11 20:54 - 2018-09-11 20:54 - 026864128 _____ () C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_108.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\…\localhost -> localhost
IE trusted site: HKU\S-1-5-21-946118099-592492296-2719631590-1001\…\localhost -> localhost

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2009-06-10 14:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-946118099-592492296-2719631590-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\tvcomp\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
DNS Servers: 192.168.1.254 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{4F6DC029-2779-49CE-9CFC-5ADA1D2B6774}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{AFAAA402-2C7A-4AA3-87B1-06E11E3C552F}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{1A02B37B-063C-4A40-B3B9-B3411714480D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{585ABB6B-B2B5-4879-8B24-9550B479B075}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{03070A3D-C34F-4CE7-B78D-E8959CF8575C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6BD7F0D2-B049-4DEE-B3DF-41B9595BAFF0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{03FF4B13-A040-4CB7-AC05-89F78CD946BE}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{D2565F67-4353-44D2-801A-9109FDD3E178}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5F65247A-7E38-484E-A868-6647CD6B3B6F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4F2612F1-25E2-4E8F-BB75-9328A2281990}] => (Allow) C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{7AC024C4-876C-4B01-AB64-FC8E4C5DC287}] => (Allow) C:\Users\tvcomp\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [TCP Query User{179D60F6-B9C7-4AB1-8356-B69B8CE29E89}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{066CC8FF-DF1B-4F42-BCB2-3FE225A5520E}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [TCP Query User{1E845FA0-3CBF-4665-A509-A9E7A5F275E2}C:\program files (x86)\kodi\kodi.exe] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{6C8BCCA4-F762-4C96-A633-62B7FC848F3B}C:\program files (x86)\kodi\kodi.exe] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{3B4B3F3C-EEE0-4F18-A423-FDF799B32D54}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{497180CE-5D5D-49FF-BEBF-0F009B8C1199}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{91CC0E86-F69F-4F69-9878-F884AE35CC74}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe

==================== Restore Points =========================

14-09-2018 03:00:16 Windows Update
15-09-2018 14:45:11 Windows Update
16-09-2018 03:00:17 Windows Update
17-09-2018 02:00:14 Windows Update
17-09-2018 03:00:27 Windows Update
18-09-2018 03:00:20 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/17/2018 07:58:49 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/17/2018 06:38:43 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/17/2018 01:53:00 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/16/2018 12:40:33 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/16/2018 11:15:28 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/15/2018 11:33:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: wmpnetwk.exe, version: 12.0.7601.17514, time stamp: 0x4ce7ae7f
Faulting module name: ntdll.dll, version: 6.1.7601.23807, time stamp: 0x5915fdce
Exception code: 0xc0000005
Fault offset: 0x000000000004f2a2
Faulting process id: 0xc58
Faulting application start time: 0x01d44d872f261e50
Faulting application path: C:\Program Files\Windows Media Player\wmpnetwk.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 73b061c0-b97a-11e8-a2e0-4487fc46d0cb

Error: (09/15/2018 05:37:53 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).

Error: (09/15/2018 04:43:10 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).


System errors:
=============
Error: (09/18/2018 03:43:31 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (09/18/2018 03:42:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Apple Mobile Device Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (09/18/2018 03:42:49 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Apple Mobile Device Service service to connect.

Error: (09/18/2018 03:41:47 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The WtuSystemSupport service terminated unexpectedly.  It has done this 1 time(s).

Error: (09/18/2018 03:41:47 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Apple Mobile Device Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (09/18/2018 03:41:46 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Display Driver Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (09/18/2018 03:41:46 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Bonjour Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (09/18/2018 03:41:45 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The iPod Service service terminated unexpectedly.  It has done this 1 time(s).


Windows Defender:
===================================
Date: 2018-08-26 19:31:24.243
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070003
Error description:The system cannot find the path specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

Date: 2018-08-26 19:26:22.064
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070003
Error description:The system cannot find the path specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

Date: 2018-08-26 19:09:31.500
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070003
Error description:The system cannot find the path specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

Date: 2018-08-26 16:16:24.289
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

Date: 2018-08-20 14:16:36.013
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

CodeIntegrity:
===================================

Date: 2018-07-20 19:55:24.467
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:24.358
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:24.062
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:23.937
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:16.948
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:16.839
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:16.714
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-07-20 19:55:16.589
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\videoprt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU E5400 @ 2.70GHz
Percentage of memory in use: 83%
Total physical RAM: 2815.23 MB
Available physical RAM: 457.77 MB
Total Virtual: 5628.65 MB
Available Virtual: 1996.39 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:395.53 GB) NTFS

\\?\Volume{bf5b49e5-708f-11e6-9b15-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 29C30B47)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Uninstall a programme

Please uninstall this programme:

AVG Web TuneUp

  • click Start, Control Panel, Programs and Features
  • click on Web Companion and then on Uninstall

===================================================

You need to move Farbar Recovery Scan Tool to your desktop otherwise fixes will not work.

  • go to your Downloads folder and locate FRST64
  • right click and select Cut
  • go to an empty spot on your desktop, right click and select Paste

Farbar Recovery Scan Tool should now be on your desktop.

================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CloseProcesses:
SearchScopes: HKU\S-1-5-21-946118099-592492296-2719631590-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL =
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.3.8.566\AVG Web TuneUp.dll => No File
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.8\\npsitesafety.dll [No File]
CHR HKU\S-1-5-21-946118099-592492296-2719631590-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [chfdnecihphmhljaaejmgoiahnihplgn] - hxxps://clients2.google.com/service/update2/crx
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2018-09-17 01:11 - 2018-09-17 01:11 - 000282552 _____ C:\Windows\Minidump\091718-24039-01.dmp
2018-09-17 01:09 - 2018-09-17 01:09 - 000262144 _____ C:\Windows\Minidump\091718-22885-01.dmp
2018-09-09 19:51 - 2018-09-09 19:51 - 000281832 _____ C:\Windows\Minidump\090918-21340-01.dmp
2018-09-09 19:15 - 2018-09-09 19:16 - 000262144 _____ C:\Windows\Minidump\090918-19671-01.dmp
2018-09-09 19:07 - 2018-09-09 19:07 - 000266288 _____ C:\Windows\Minidump\090918-20248-01.dmp
2018-09-09 19:00 - 2018-09-09 19:00 - 000266288 _____ C:\Windows\Minidump\090918-20186-01.dmp
2018-09-09 18:39 - 2018-09-09 18:39 - 000266288 _____ C:\Windows\Minidump\090918-20841-01.dmp
2018-09-09 18:24 - 2018-09-09 18:24 - 000266288 _____ C:\Windows\Minidump\090918-20966-01.dmp
2018-09-08 21:26 - 2018-09-08 21:26 - 000282856 _____ C:\Windows\Minidump\090818-19422-01.dmp
2018-09-08 13:58 - 2018-09-08 13:59 - 000266288 _____ C:\Windows\Minidump\090818-19578-01.dmp
2018-09-08 13:03 - 2018-09-08 13:03 - 000282936 _____ C:\Windows\Minidump\090818-20155-01.dmp
2018-09-08 03:17 - 2018-09-08 03:17 - 000280808 _____ C:\Windows\Minidump\090818-20264-01.dmp
2018-09-08 03:16 - 2018-09-08 03:16 - 000281912 _____ C:\Windows\Minidump\090818-21918-01.dmp
2018-09-08 03:09 - 2018-09-08 03:09 - 000281752 _____ C:\Windows\Minidump\090818-22713-01.dmp
2018-09-08 03:01 - 2018-09-08 03:01 - 000262144 _____ C:\Windows\Minidump\090818-29889-01.dmp
2018-09-08 02:57 - 2018-09-08 02:57 - 000266288 _____ C:\Windows\Minidump\090818-18829-01.dmp
2018-09-08 02:52 - 2018-09-08 02:52 - 000266288 _____ C:\Windows\Minidump\090818-19671-01.dmp
2018-09-08 02:49 - 2018-09-08 02:49 - 000282792 _____ C:\Windows\Minidump\090818-23150-01.dmp
2018-09-08 02:47 - 2018-09-08 02:47 - 000285560 _____ C:\Windows\Minidump\090818-22838-01.dmp
2018-09-08 02:19 - 2018-09-08 02:19 - 000262144 _____ C:\Windows\Minidump\090818-18236-01.dmp
2018-09-07 07:08 - 2018-09-07 07:08 - 000266288 _____ C:\Windows\Minidump\090718-19827-01.dmp
2018-09-06 15:17 - 2018-09-06 15:17 - 000323880 _____ C:\Windows\Minidump\090618-19312-01.dmp
2018-09-06 15:08 - 2018-09-06 15:08 - 000283096 _____ C:\Windows\Minidump\090618-23774-01.dmp
2018-09-06 15:06 - 2018-09-06 15:06 - 000266288 _____ C:\Windows\Minidump\090618-20919-01.dmp
2018-09-06 06:29 - 2018-09-06 06:29 - 000266288 _____ C:\Windows\Minidump\090618-23665-01.dmp
2018-09-06 05:02 - 2018-09-06 05:02 - 000266288 _____ C:\Windows\Minidump\090618-20997-01.dmp
2018-09-05 19:41 - 2018-09-05 19:41 - 000281912 _____ C:\Windows\Minidump\090518-23088-01.dmp
2018-09-05 19:39 - 2018-09-05 19:39 - 000266288 _____ C:\Windows\Minidump\090518-18922-01.dmp
2018-09-05 17:48 - 2018-09-05 17:48 - 000266288 _____ C:\Windows\Minidump\090518-31871-01.dmp
2018-09-05 17:37 - 2018-09-05 17:37 - 000280808 _____ C:\Windows\Minidump\090518-30856-01.dmp
2018-09-05 17:35 - 2018-09-05 17:35 - 000266288 _____ C:\Windows\Minidump\090518-32526-01.dmp
2018-09-05 16:48 - 2018-09-05 16:48 - 000326256 _____ C:\Windows\Minidump\090518-32807-01.dmp
2018-09-05 16:39 - 2018-09-05 16:39 - 000262144 _____ C:\Windows\Minidump\090518-19890-01.dmp
2018-09-05 03:37 - 2018-09-05 03:37 - 000283344 _____ C:\Windows\Minidump\090518-19328-01.dmp
2018-09-05 03:19 - 2018-09-05 03:19 - 000266288 _____ C:\Windows\Minidump\090518-19765-01.dmp
2018-09-05 03:04 - 2018-09-05 03:04 - 000283096 _____ C:\Windows\Minidump\090518-18829-01.dmp
2018-09-05 02:43 - 2018-09-05 02:43 - 000266288 _____ C:\Windows\Minidump\090518-18376-01.dmp
2018-09-05 02:34 - 2018-09-05 02:34 - 000284864 _____ C:\Windows\Minidump\090518-19234-01.dmp
2018-09-04 20:24 - 2018-09-04 20:24 - 000282144 _____ C:\Windows\Minidump\090418-19718-01.dmp
2018-09-04 14:58 - 2018-09-04 14:58 - 000262144 _____ C:\Windows\Minidump\090418-30513-01.dmp
2018-09-04 14:50 - 2018-09-04 14:51 - 000262144 _____ C:\Windows\Minidump\090418-31839-01.dmp
2018-09-04 14:47 - 2018-09-04 14:47 - 000282968 _____ C:\Windows\Minidump\090418-21309-01.dmp
2018-09-04 14:45 - 2018-09-04 14:45 - 000282472 _____ C:\Windows\Minidump\090418-22807-01.dmp
2018-09-04 14:43 - 2018-09-04 14:44 - 000323568 _____ C:\Windows\Minidump\090418-24320-01.dmp
2018-09-04 12:02 - 2018-09-04 12:02 - 000282872 _____ C:\Windows\Minidump\090418-22058-01.dmp
2018-09-04 11:01 - 2018-09-04 11:01 - 000266288 _____ C:\Windows\Minidump\090418-19968-01.dmp
2018-09-04 10:53 - 2018-09-04 10:53 - 000262144 _____ C:\Windows\Minidump\090418-22074-01.dmp
2018-09-04 10:50 - 2018-09-04 10:50 - 000266288 _____ C:\Windows\Minidump\090418-20233-01.dmp
2018-09-04 10:39 - 2018-09-04 10:39 - 000282872 _____ C:\Windows\Minidump\090418-25381-01.dmp
2018-09-04 10:37 - 2018-09-04 10:37 - 000262144 _____ C:\Windows\Minidump\090418-24039-01.dmp
2018-09-17 16:15 - 2017-07-08 03:16 - 000000000 ____D C:\Users\tvcomp\AppData\Roaming\BitTorrent
C:\Users\tvcomp\AppData\Local\Temp\WCU008.exe
C:\Users\tvcomp\AppData\Roaming\BitTorrent
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

Thanks

 

Note: I will not be able to reply tomorrow as I have a 500 mile around-trip drive to attend a funeral, leaving at 8am, (GMT), and returning about 10pm.

 

Satchfan

Hi montab

It has been several days since I replied to your request for help with your computer problems.

Please let me know if you are having problems and still need help.

Thanks

Note: I have to go away again tomorrow and won't be back until Sunday lunchtime, (GMT). While I'm away I won't have access to a computer.

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI