
Regular 100% disk usage, blocking my day to day PC access
#1
Posted 14 March 2019 - 08:32 AM
Register to Remove
#2
Posted 14 March 2019 - 08:55 AM
#3
Posted 15 March 2019 - 04:25 AM
The device, \Device\Harddisk0\DR0, has a bad block.
I think you should
https://support.micr...orrupted-system
please scroll down to Windows 8 /8.1
- Mozimax likes this
MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??
#4
Posted 15 March 2019 - 07:33 AM
Here are the results and thanks for your fast and useful help.
>>>>>>>>>>>>>>>>>><<<<<<<<<<<<<<<<<<<
Microsoft Windows [Version 6.3.9600]
© 2013 Microsoft Corporation. All rights reserved.
C:\Windows\system32>DISM.exe /Online /Cleanup-image /Restorehealth
Deployment Image Servicing and Management tool
Version: 6.3.9600.17031
Image Version: 6.3.9600.17031
[==========================100.0%==========================]
Error: 0x800f0906
The source files could not be downloaded.
Use the "source" option to specify the location of the files that are required to restore the feature. For more information on specifying a source location, see
http://go.microsoft..../?LinkId=243077.
The DISM log file can be found at C:\Windows\Logs\DISM\dism.log
>>>>>>>>>>>>>>>>>><<<<<<<<<<<<<<<<<<
There is a YouTube vlog for this repair @
If not, please advise. Thanks
#5
Posted 15 March 2019 - 12:02 PM
Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)
highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Highlight the entire content of the quote box below and select Copy.
Start::
CloseProcesses:
CreateRestorePoint:
URLSearchHook: [S-1-5-21-1975610405-2585747867-3397885706-1003] ATTENTION => Default URLSearchHook is missing
BHO-x32: No Name -> {451C804F-C205-4F03-B48E-537EC94937BF} -> No File
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
FF HKLM-x32\...\Firefox\Extensions: [WSVCU@Wondershare.com] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com => not found
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [No File]
S3 mfesapsn; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [X]
U3 aswMBR; \??\C:\Users\Moz\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\Moz\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {C458F123-BD5B-46D1-A7F7-D28C7E6AB2AA} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe (AVAST Software s.r.o. -> AVAST Software)
AlternateDataStreams: C:\Windows\notepad.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentExtensions.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AuthHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\basesrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\calc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cfgbkend.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CNHI10A.DLL:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\CNHL5100.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CNHMCA6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CNHMCAN.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\COLORCNV.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\comctl32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CPFilters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dbgeng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dhcpsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eapp3hst.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eappgnui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eapphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EncDec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fhcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FWPUCLNT.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InkEd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ksproxy.ax:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LockScreenContentServer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfc42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfc42u.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfvdsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MFWMAAEC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MP3DMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MP43DECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MP4SDECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MPG4DECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mtxoci.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\notepad.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcuda.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvd3dumx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispco6435435.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispgenco6435435.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvEncodeAPI64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvFBC64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvIFR64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvinitx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvoglv64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvwgf2umx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PCPKsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\photowiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pku2u.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RESAMPLEDMO.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\schtasks.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sdbinst.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sechost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingSync.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SRH.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StorageContextHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\storewuauth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SysFxUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsAdminFlows.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsAdminFlowUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsDatabase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\themecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tracerpt.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TsWpfWrp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usercpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UtcResources.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VIDRESZR.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VSSVC.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wdfcoinstaller01007.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Input.Inking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WindowsAnytimeUpgradeui.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winshfhc.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\WinSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMADMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMADMOE.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMALFXGFXDSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMASF.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMPhoto.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMSPDMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMSPDMOE.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVDECOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVENCOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVSDECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVSENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVXENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkfoldersControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WsmAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WsmAuto.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AGaugeM.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AniGIF.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atlthunk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\calc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cfgbkend.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CNHMCA.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\COLORCNV.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CPFilters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d2d1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_43.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\davclnt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dbgeng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dbghelp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dhcpsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dsparse.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eapp3hst.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappgnui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eapphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\EncDec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\FWPUCLNT.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GeofenceMonitorService.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\hgcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InkEd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\IPHLPAPI.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ksproxy.ax:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfc42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfc42u.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfvdsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MFWMAAEC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MP3DMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MP43DECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MP4SDECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MPG4DECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msorcl32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mtxoci.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\netcfgx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\notepad.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcuda.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvd3dum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvEncodeAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvFBC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvIFR.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvinit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvoglv32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvwgf2um.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PCPKsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Percent.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PhotoMetadataHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\photowiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\pku2u.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\qedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RESAMPLEDMO.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rgb9rast.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rsaenh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\schtasks.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sdbinst.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sechost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingMonitor.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\shacct.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SHCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SRH.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\stobject.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\StorageContextHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Strip.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\taskeng.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\themecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tracerpt.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TsWpfWrp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\usercpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\VIDRESZR.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Immersive.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\winshfhc.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\WinSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMADMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMADMOE.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMASF.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOE.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVDECOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVENCOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVSDECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVSENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVXENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wpdshext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wscapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WSCM64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WsmAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WsmAuto.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\WSShared.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ahcache.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\bthhfenum.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\bthport.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dumpsd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ew_jubusenum.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hidbth.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\IPMIDrv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\nvlddmkm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rasl2tp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rfcomm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rmcast.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rndismpx.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\sdbus.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tap0901.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tpm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tunnel.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\udfs.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usb8023.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usb8023x.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbehci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\USBHUB3.SYS:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbohci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbscan.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\USBSTOR.SYS:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbuhci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\volmgr.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\volsnap.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vpci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\winusb.sys:$CmdTcID [64]
AlternateDataStreams: C:\ProgramData\cisF14A.exe:$CmdTcID [64]
C:\Windows\Temp\*.*
Emptytemp:
End::
Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.
Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

- Download AdwCleaner and move it to your Desktop
- Right-click on AdwCleaner.exe and select
Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
- Accept the EULA (I accept), then click on Scan
- Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button. This will kill all the active processes
- Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
- After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply

- Download the right version of RogueKiller for your Windows version (32 or 64-bit)
- Once done, move the executable file to your Desktop, right-click on it and select
Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
- Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
- Wait for the scan to complete
- On completion, the results will be displayed
- Check every single entry (threat found), and click on the Remove Selected button
- On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
- This will open the report in Notepad. Copy/paste its content in your next reply
- Mozimax likes this
MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??
#6
Posted 16 March 2019 - 08:28 AM
Fix result of Farbar Recovery Scan Tool (x64) Version: 13.03.2019 01
Ran by Moz (16-03-2019 15:36:33) Run:2
Running from E:\Downloads\FRST-OlderVersion
Loaded Profiles: Moz (Available Profiles: Moz & Acronis Agent User)
Boot Mode: Normal
==============================================
fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
URLSearchHook: [S-1-5-21-1975610405-2585747867-3397885706-1003] ATTENTION => Default URLSearchHook is missing
BHO-x32: No Name -> {451C804F-C205-4F03-B48E-537EC94937BF} -> No File
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
FF HKLM-x32\...\Firefox\Extensions: [WSVCU@Wondershare.com] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com => not found
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [No File]
S3 mfesapsn; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [X]
U3 aswMBR; \??\C:\Users\Moz\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\Moz\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {C458F123-BD5B-46D1-A7F7-D28C7E6AB2AA} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe (AVAST Software s.r.o. -> AVAST Software)
AlternateDataStreams: C:\Windows\notepad.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AppXDeploymentExtensions.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\AuthHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\basesrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\calc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\cfgbkend.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CNHI10A.DLL:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\CNHL5100.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CNHMCA6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CNHMCAN.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\COLORCNV.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\comctl32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\CPFilters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\d3dx9_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dbgeng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dhcpsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eapp3hst.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eappgnui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\eapphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\EncDec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\fhcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\FWPUCLNT.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\InkEd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ksproxy.ax:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\LockScreenContentServer.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfc42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfc42u.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mfvdsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MFWMAAEC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MP3DMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MP43DECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MP4SDECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\MPG4DECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mtxoci.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\notepad.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcuda.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvd3dumx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispco6435435.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvdispgenco6435435.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvEncodeAPI64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvFBC64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvIFR64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvinitx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvoglv64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\nvwgf2umx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\PCPKsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\photowiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\pku2u.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\RESAMPLEDMO.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\schtasks.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sdbinst.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\sechost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingsHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SettingSync.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SRH.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\StorageContextHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\storewuauth.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SysFxUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsAdminFlows.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsAdminFlowUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\SystemSettingsDatabase.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\themecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\tracerpt.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\TsWpfWrp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\usercpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\UtcResources.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VIDRESZR.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\VSSVC.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wdfcoinstaller01007.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Windows.UI.Input.Inking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WindowsAnytimeUpgradeui.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\winshfhc.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\WinSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMADMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMADMOE.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMALFXGFXDSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMASF.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMPhoto.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMSPDMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMSPDMOE.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVDECOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVENCOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVSDECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVSENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WMVXENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WorkfoldersControl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WsmAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\WsmAuto.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\XAPOFX1_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\XAudio2_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AGaugeM.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\AniGIF.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atlthunk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\calc.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\cfgbkend.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CNHMCA.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\COLORCNV.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\CPFilters.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d2d1.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_43.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\davclnt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dbgeng.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dbghelp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\devenum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dhcpsapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\dsparse.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eapp3hst.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eappgnui.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\eapphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\EncDec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\FWPUCLNT.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GeofenceMonitorService.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\hgcpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\InkEd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\IPHLPAPI.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ksproxy.ax:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfc42.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfc42u.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfds.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mfvdsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MFWMAAEC.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MP3DMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MP43DECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MP4SDECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MPG4DECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\MrmCoreR.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\msorcl32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mtxoci.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\netcfgx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\notepad.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvcuda.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvd3dum.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvEncodeAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvFBC.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvIFR.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvinit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvoglv32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\nvwgf2um.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PCPKsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Percent.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\PhotoMetadataHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\photowiz.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\pku2u.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\qedit.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\RESAMPLEDMO.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rgb9rast.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\rsaenh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\schtasks.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sdbinst.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\sechost.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingMonitor.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\shacct.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SHCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\SRH.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\stobject.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\StorageContextHandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Strip.ocx:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\taskeng.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\themecpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\tracerpt.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\TsWpfWrp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\UIAutomationCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\usercpl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\VIDRESZR.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Immersive.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\winshfhc.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\WinSync.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMADMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMADMOE.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMASF.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMSPDMOE.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVDECOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVENCOD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVSDECD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVSENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WMVXENCD.DLL:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wpdshext.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wscapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WSCM64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WsmAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\WsmAuto.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\WSShared.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_5.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_7.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ahcache.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\bthhfenum.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\bthport.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\dumpsd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ew_jubusenum.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\hidbth.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\IPMIDrv.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\nvlddmkm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rasl2tp.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rfcomm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rmcast.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\rndismpx.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\sdbus.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tap0901.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tpm.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tunnel.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\udfs.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usb8023.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usb8023x.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbehci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\USBHUB3.SYS:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbohci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbscan.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\USBSTOR.SYS:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\usbuhci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\volmgr.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\volsnap.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\vpci.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\winusb.sys:$CmdTcID [64]
AlternateDataStreams: C:\ProgramData\cisF14A.exe:$CmdTcID [64]
C:\Windows\Temp\*.*
Emptytemp:
*****************
Processes closed successfully.
Restore point was successfully created.
Could not restore Default URLSearchHook.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{451C804F-C205-4F03-B48E-537EC94937BF} => not found
HKLM\Software\Wow6432Node\Classes\CLSID\{451C804F-C205-4F03-B48E-537EC94937BF} => not found
HKLM\Software\Classes\PROTOCOLS\Handler\WSWSVCUchrome => not found
"HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\WSVCU@Wondershare.com" => not found
HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0 => not found
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0 => not found
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0 => not found
mfesapsn => service not found.
aswMBR => service not found.
aswVmm => service not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => not found
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C458F123-BD5B-46D1-A7F7-D28C7E6AB2AA}" => not found
"C:\Windows\System32\Tasks\Avast Software\Overseer" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => not found
"C:\Windows\notepad.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\AppXDeploymentExtensions.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\AuthHost.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\basesrv.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\calc.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\cfgbkend.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\clfsw32.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\CNHI10A.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\CNHL5100.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\CNHMCA6.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\CNHMCAN.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\COLORCNV.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\comctl32.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\CPFilters.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\d3dx9_32.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\dbgeng.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\dhcpsapi.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\eapp3hst.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\eappgnui.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\eapphost.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\EncDec.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\fhcpl.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\FWPUCLNT.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\InkEd.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\ksproxy.ax" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\LockScreenContentServer.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mfc42.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mfc42u.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mfds.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mfnetcore.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mfnetsrc.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mfvdsp.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\MFWMAAEC.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\MP3DMOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\MP43DECD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\MP4SDECD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\MPG4DECD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\mtxoci.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\notepad.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\ntvdm64.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvcuda.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvcuvid.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvd3dumx.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvdispco6435435.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvdispgenco6435435.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvEncodeAPI64.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\NvFBC64.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\NvIFR64.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\NvIFROpenGL.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvinitx.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvoglv64.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvopencl.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\nvwgf2umx.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\PCPKsp.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\photowiz.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\pku2u.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\RESAMPLEDMO.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\schtasks.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\sdbinst.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\sechost.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\services.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\SettingsHandlers.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\SettingSync.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\SettingSyncHost.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\SRH.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\StorageContextHandler.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\storewuauth.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\SysFxUI.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\SystemSettingsAdminFlows.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\SystemSettingsAdminFlowUI.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\SystemSettingsDatabase.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\tdh.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\themecpl.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\tracerpt.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\TsWpfWrp.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\usercpl.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\UtcResources.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\VIDRESZR.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\VSSVC.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\wdfcoinstaller01007.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Windows.UI.Input.Inking.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WindowsAnytimeUpgradeui.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WinSetupUI.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\winshfhc.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WinSync.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMADMOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMADMOE.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMALFXGFXDSP.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMASF.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMPhoto.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMSPDMOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMSPDMOE.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMVDECOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMVENCOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMVSDECD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMVSENCD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WMVXENCD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WorkfoldersControl.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\wpdshext.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WsmAgent.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\WsmAuto.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\XAPOFX1_5.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\XAudio2_7.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\AGaugeM.ocx" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\AniGIF.ocx" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\atlthunk.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\calc.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\cfgbkend.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\clfsw32.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\CNHMCA.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\COLORCNV.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\comctl32.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\CPFilters.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\d2d1.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\D3DCompiler_43.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\d3dx10_42.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\d3dx9_32.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\davclnt.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\dbgeng.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\dbghelp.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\devenum.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\dhcpsapi.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\dsparse.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\eapp3hst.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\eappcfg.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\eappgnui.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\eapphost.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\EncDec.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\FWPUCLNT.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\GeofenceMonitorService.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\hgcpl.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\InkEd.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\IPHLPAPI.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\ksproxy.ax" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mfc42.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mfc42u.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mfds.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mfnetcore.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mfnetsrc.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mfps.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mfvdsp.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\MFWMAAEC.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\MP3DMOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\MP43DECD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\MP4SDECD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\MPG4DECD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\MrmCoreR.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\msorcl32.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\mtxoci.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\netcfgx.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\notepad.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvapi.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvcompiler.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvcuda.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvcuvid.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvd3dum.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvEncodeAPI.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\NvFBC.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\NvIFR.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\NvIFROpenGL.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvinit.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvoglv32.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvopencl.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\nvwgf2um.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\PCPKsp.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\Percent.ocx" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\PhotoMetadataHandler.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\photowiz.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\pku2u.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\qedit.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\RESAMPLEDMO.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\rgb9rast.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\rsaenh.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\schtasks.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\sdbinst.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\sechost.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\SettingMonitor.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\SettingSync.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\SettingSyncCore.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\SettingSyncHost.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\shacct.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\SHCore.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\SRH.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\stobject.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\StorageContextHandler.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\Strip.ocx" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\taskeng.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\tdh.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\themecpl.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\tracerpt.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\TsWpfWrp.exe" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\UIAutomationCore.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\usercpl.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\VIDRESZR.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\Windows.UI.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\Windows.UI.Immersive.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\winshfhc.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WinSync.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMADMOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMADMOE.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMASF.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMPhoto.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMSPDMOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMSPDMOE.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMVDECOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMVENCOD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMVSDECD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMVSENCD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WMVXENCD.DLL" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\wpdshext.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\wscapi.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WSCM64.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WsmAgent.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WsmAuto.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\WSShared.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\wups.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\XAPOFX1_5.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\SysWOW64\XAudio2_7.dll" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\ahcache.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\bthhfenum.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\bthport.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\dumpsd.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\ew_jubusenum.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\hidbth.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\IPMIDrv.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\nvlddmkm.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\rasl2tp.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\rfcomm.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\rmcast.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\rndismpx.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\sdbus.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\tap0901.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\tpm.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\tunnel.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\udfs.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\usb8023.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\usb8023x.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\usbd.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\usbehci.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\USBHUB3.SYS" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\usbohci.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\usbscan.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\USBSTOR.SYS" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\usbuhci.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\volmgr.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\volsnap.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\vpci.sys" => ":$CmdTcID" ADS not found.
"C:\Windows\system32\Drivers\winusb.sys" => ":$CmdTcID" ADS not found.
"C:\ProgramData\cisF14A.exe" => ":$CmdTcID" ADS not found.
=========== "C:\Windows\Temp\*.*" ==========
C:\Windows\Temp\adobegc.log => moved successfully
========= End -> "C:\Windows\Temp\*.*" ========
=========== EmptyTemp: ==========
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9644785 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 5686 B
Edge => 0 B
Chrome => 64109373 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 1654 B
NetworkService => 0 B
Moz => 10057311 B
Acronis Agent User => 678 B
RecycleBin => 0 B
EmptyTemp: => 79.9 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 15:38:44 ====
>>>>>>>>>>>>>>>><<<<<<<<<<<<<<<<
# -------------------------------
# Malwarebytes AdwCleaner 7.2.7.0
# -------------------------------
# Build: 01-30-2019
# Database: 2019-03-11.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-16-2019
# Duration: 00:00:05
# OS: Windows 8.1 Single Language
# Cleaned: 12
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
No malicious folders cleaned.
***** [ Files ] *****
Deleted C:\END
Deleted C:\Users\Acronis Agent User\Desktop\eBay.lnk
Deleted C:\Users\Acronis Agent User\Favorites\eBay.lnk
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
Deleted HKLM\Software\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\geekbuddyrsp
***** [ Chromium (and derivatives) ] *****
Deleted Microformats
Deleted Alexa Traffic Rank
Deleted FromDocToPDF
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [2160 octets] - [16/03/2019 14:12:01]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
>>>>>>>>>>>>>>>>>>>>>><<<<<<<<<<<<<<<<<<<<<
# -------------------------------
# Malwarebytes AdwCleaner 7.2.7.0
# -------------------------------
# Build: 01-30-2019
# Database: 2019-03-11.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 03-16-2019
# Duration: 00:00:15
# OS: Windows 8.1 Single Language
# Scanned: 31892
# Detected: 12
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
PUP.Optional.Legacy C:\END
PUP.Optional.Legacy C:\Users\Acronis Agent User\Desktop\eBay.lnk
PUP.Optional.Legacy C:\Users\Acronis Agent User\Favorites\eBay.lnk
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
PUP.Optional.Legacy HKLM\Software\Wow6432Node\Classes\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}
PUP.Optional.Legacy HKLM\Software\Wow6432Node\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
PUP.Optional.Legacy HKLM\Software\Wow6432Node\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}
PUP.Optional.Legacy HKLM\Software\Wow6432Node\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
PUP.Optional.Legacy HKLM\Software\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
PUP.Optional.Legacy HKLM\System\CurrentControlSet\Services\EventLog\Application\geekbuddyrsp
***** [ Chromium (and derivatives) ] *****
PUP.Optional.Legacy Microformats
PUP.Optional.Legacy Alexa Traffic Rank
PUP.Optional.MindSpark FromDocToPDF
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
>>>>>>>>>>>>>>>>>>>><<<<<<<<<<<<<<<<<<<<<
#7
Posted 16 March 2019 - 12:03 PM
Hi Juliet,
I ran Rogue Killer but all hell broke loose - as it has for the past 14 hours. I can't get to work anymore, it keeps insisting on installing the program and won't fix anything. First time I ran it, it ran beautifully and then blocked when I tried to download the fixes. I switched off the PC manually then nothing worked until now to give you this message. I'm still being blocked 100% disk usage.
Can you help with the data you have? As you can understand, none of my critical work is being done at all. My clients have no clue where I am.
Thanks,
Cari
#8
Posted 16 March 2019 - 01:12 PM
Let's see if you can temporarily disable to run the tools
https://support.kaspersky.com/us/12161
If that doesn't work let's try booting into safe mode to run the tool from there
https://support.micr...ne-click-series
- Mozimax likes this
MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??
#9
Posted 18 March 2019 - 05:02 AM
OK Juliet,
It liked that. Has been keeping it's cool, but it can never pass my cool
What's next?
Cari
#10
Posted 18 March 2019 - 06:31 AM
Also, if you disabled your antivirus, make sure to turn it back on after using the tools.
- Mozimax likes this
MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??
Register to Remove
#11
Posted 18 March 2019 - 11:12 AM
As I said before, Rogue Killer insisted on installing the program after the log was lost.
Now it won't run a fix, because I think it remembers having done it already. I have tried three times and then I uninstalled it.
Yes, Kaspersky is now running, thanks.
#12
Posted 18 March 2019 - 06:15 PM
Let's check for remnants
Please download the Malwarebytes Anti-Malware setup file to your Desktop.
OR from this location Here
- Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
- Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
- After the installation IS complete let it update if it asks.
- Under SETTINGS.....APPLICATIONS leave everything at default
- Under SETTINGS.....PROTECTION make sure AUTOMATIC QUARANTINE is on.
- Then go to the Dashboard and click on SCAN NOW
- If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
Upon completion of the scan (or after the reboot), click the Reports tab.
Double-click the Scan Log.
At the bottom click Export and choose Text file.
Save the file to your desktop and include its content in your next reply.
You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here - Then click on POST
- Exit Malwarebytes

Follow the instructions below to run a scan using the Emsisoft Emergency Kit.
- Download the Emsisoft Emergency Kit and execute it. From there, click on the Install button to extract the program in the EEK folder;
- Once the extraction is complete, the EEK folder will open. Right-click on
start emergency kit scanner.exe and select
Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
- EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
- After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
- Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
- If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
- After the restart, open EEK again (in the C:\EEK folder);
- This time, click on Logs;
- From there, go under the Quarantine Log tab, and click on the Export button;
- Save the log on your desktop, then open it, and copy/paste its content in your next reply;
Also, tell me how the computer is now.
- Mozimax likes this
MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??
#13
Posted 19 March 2019 - 06:36 AM
In Malwarebytes, ‘Auto Quarantine’ only comes with premium.
>>>>>>>>>>>>>>>>>>>>>>><<<<<<<<<<<<<<<<<<<<<<
Emsisoft Anti-Malware - Version 2019.2
Last update: 3/19/2019 1:47:07 PM
Initiated by: RedEnjin\Moz
Computer name: REDENJIN
OS version: Windows 8.1x64
Scan settings:
Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files
Detect PUPs: On
Scan archives: Off
Scan mail archives: Off
ADS Scan: On
File extension filter: Off
Direct disk access: Off
Scan start: 3/19/2019 2:05:35 PM
Scanned 76284
Found 0
Scan end: 3/19/2019 2:08:34 PM
Scan time: 0:02:59
#14
Posted 19 March 2019 - 03:12 PM
MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??
#15
Posted 20 March 2019 - 03:25 AM
As long as Kaspersky is off, all goes well, but every time I switch it on, the 100% disk returns. So if I can run without internet security. All goes well, I suppose, unless I get infected. If you are signing off, I must thank you very much for the most fantastic job. I have struggled with this 100% disk story for four months, with it getting progressively worse until now. My faith took quite a knock in that time, while I choked every day on stolen time.
Also tagged with one or more of these keywords: 100% disk use, pc access blocked, PC takeover, Cannot bypass, Task manager useless to stop, No fixes found, Dont know the problem, Malware
3 user(s) are reading this topic
0 members, 3 guests, 0 anonymous users