Numerous Problems On Older Computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by SusieQueue, Nov 6, 2025.

  1. SusieQueue

    SusieQueue Private E-2

    When starting the computer sometimes Malwarebytes doesn't load and antivirus features are occasionally disabled. There are consistent internes disconnections and frequent trouble with VPN software. Some icons are not displayed and Windows Defender seems to end scans prematurely. I am not sure if it's a malware problem but could use your help, please.
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to the Major Geeks Malware Forum.

    Please allow me some time to review what you have posted.
     
  3. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    Do you recognize this program?

    Although you can have both Malwarebytes and Avast on a computer at the same time, you need to disable one of the programs' real-time protection. If not, conflicts will degrade your computer performance.

    Windows Defender is disabled and might have difficulty running because of the other antivirus programs.

    You have 2 VPNs, Nord and Malwarebytes. Your log shows Nord is running but Malwarebytes is not. This combination could be the source of the VPN issue.

    What is your preference for your primary antivirus and VPN programs?
     
  4. SusieQueue

    SusieQueue Private E-2

    Yes, that program is a game that was installed. I actually installed Avast because of the trouble I was having with Windows Defender, but would prefer to just use Windows Defender. I only subscribe to NordVPN, not the Malwarebytes one. I apologize for not replying sooner; I was expecting to be notified by email when you replied, but wasn't.
     
  5. Oh My!

    Oh My! Malware Expert Staff Member

    Let's double check your alerts.

    While logged into Major Geelks copy and paste https://forums.majorgeeks.com/account/alert-preferences into the address bar. Verify next to Receive an alert when someone... there is a check mark next to Replies to a watched thread. If it is checked see if the email alert was moved to the Spam folder.

    The first thing I would like to do is clear out Avast. I would also like to remove CCleaner. Please do this.

    ===================================================

    Uninstalling Programs Using Revo Uninstaller Free Portable

    --------------------

    • Download Revo Uninstaller Free Portable and save it to your Desktop
    • Right click on the folder and select Extract All..., then click Extract
    • Double click on the RevoUninstaller-Portable folder
    • Right click on RevoUPort and select Run as administrator
    • Click OK on the License Agreement
    • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
    Code:
    Avast Free Antivirus
    CCleaner
    CCleaner 7
    
    • If the program's uninstaller appears work through the steps to remove the program(s)
    • Be sure the Advanced option is selected then click Scan
    • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
    • Once done click Finish
    • Reboot your computer
    ===================================================

    Farbar Recovery Scan Tool SearchAll

    --------------------
    • Launch FRST
    • Copy and paste the following in the Search: box
    Code:
    SearchAll: Avast;Avira;"Gen Digital Inc.";CCleaner
    
    • Click the Search Files button
    • When completed click OK and a Search.txt document will open on your desktop
    • Attach the report to your reply. Let me know if the file is too large.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Programs removed?
    • Attached file
     
  6. SusieQueue

    SusieQueue Private E-2

    Okay, I removed CCleaner, CCleaner 7, and Avast, as per your instructions.
     

    Attached Files:

  7. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool - Run Fix Using Attached File

    --------------------
    • Download the attached file and save it in the same location as FRST.exe (example, Desktop, USB device) <<< Important
    • Right click on FRST and select Run as administrator
    • Click Fix and once completed your computer will reboot
    • The tool will create a log on the desktop called Fixlog.txt
    • Copy and paste the contents of the report in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     

    Attached Files:

  8. SusieQueue

    SusieQueue Private E-2

    Fix result of Farbar Recovery Scan Tool (x64) Version: 10-11-2025
    Ran by miste (11-11-2025 04:50:47) Run:1
    Running from C:\Users\miste\OneDrive\Desktop
    Loaded Profiles: miste
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    C:\Windows\Prefetch\AVASTNM.EXE-DDE86B71.pf
    C:\Windows\Prefetch\AVASTUI.EXE-56B29A08.pf
    C:\Windows\Prefetch\AVASTUI.EXE-56B29A09.pf
    C:\Windows\Prefetch\CCLEANER.EXE-1209881F.pf
    C:\Windows\Prefetch\CCLEANER64.EXE-779BD542.pf
    C:\Windows\Prefetch\CCLEANERPERFORMANCEOPTIMIZERS-06B93656.pf
    C:\Windows\Prefetch\CCLEANER_SERVICE.EXE-D7E7DBF7.pf
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\avast! Antivirus
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\CCleaner 7
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_CCleaner_CCleaner64_exe
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\avast! Antivirus
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\CCleaner 7
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_CCleaner_CCleaner64_exe
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|AvastUI.exe
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings|TargetingAttributes
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings|TargetingAttributesVerified
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\AvastAdSDK
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|avast! Antivirus
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{6D809377-6AF0-444B-8957-A3773F02200E}\Common Files\Avast Software\Icarus\avast-av\icarus_ui.exe
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\Avast Software\Avast\AvastUI.exe
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\02B0C1DA7CED6E134B2971E6E9B947D9\SourceList|LastUsedSource
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\02B0C1DA7CED6E134B2971E6E9B947D9\SourceList\Net|1
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\02B0C1DA7CED6E134B2971E6E9B947D9\InstallProperties|InstallSource
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD1C0B20-DEC7-31E6-B492-176E9E9B749D}|InstallSource
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\cdrom.inf_amd64_970e40f68a7583a1|OemPath
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\heci.inf_amd64_61ea518ffd0290a4|OemPath
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\lxptusb.inf_amd64_0e8d55b1f6f01e37|OemPath
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\lynxpointsystem.inf_amd64_ca9e125b91ae1a98|OemPath
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3962057343-3219533117-270726214-1002|\Device\HarddiskVolume2\Program Files\Piriform\CCleaner 7\CCleaner.exe
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3962057343-3219533117-270726214-1002|\Device\HarddiskVolume2\Program Files\CCleaner\CCleanerBugReport.exe
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCleanerPerformanceOptimizerService|ImagePath
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCleanerPerformanceOptimizerService|DisplayName
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCleanerPerformanceOptimizerService|Description
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{6D809377-6AF0-444B-8957-A3773F02200E}\CCleaner\CCleaner64.exe
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{6D809377-6AF0-444B-8957-A3773F02200E}\CCleaner\temp_ccupdate\ccupdate700_free.exe
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|CCleaner 7
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView|{6D809377-6AF0-444B-8957-A3773F02200E}\CCleaner\CCleaner64.exe
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView|{6D809377-6AF0-444B-8957-A3773F02200E}\CCleaner\temp_ccupdate\ccupdate700_free.exe
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|CCleaner Smart Cleaning
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\CCleaner\CCleanerReactivator.exe
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\CCleaner\CCleaner64.exe
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avast Software
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\AvastAdSDK
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~avast! antivirus
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$avast antivirus
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~avast! antivirus
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$avast antivirus
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\CCleaner64.exe
    DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCleanerPerformanceOptimizerService
    DeleteKey: HKEY_USERS\.DEFAULT\Software\Piriform\CCleaner7
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~ccleaner 7
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~httpwww.ccleaner.comccleaner
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}ccleanerccleaner64.exe
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$ccleaner
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$ccleaner 7
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~ccleaner 7
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~httpwww.ccleaner.comccleaner
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}ccleanerccleaner64.exe
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$ccleaner
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$ccleaner 7
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth

    *****************

    "C:\Windows\Prefetch\AVASTNM.EXE-DDE86B71.pf" => not found
    C:\Windows\Prefetch\AVASTUI.EXE-56B29A08.pf => moved successfully
    "C:\Windows\Prefetch\AVASTUI.EXE-56B29A09.pf" => not found
    C:\Windows\Prefetch\CCLEANER.EXE-1209881F.pf => moved successfully
    C:\Windows\Prefetch\CCLEANER64.EXE-779BD542.pf => moved successfully
    "C:\Windows\Prefetch\CCLEANERPERFORMANCEOPTIMIZERS-06B93656.pf" => not found
    "C:\Windows\Prefetch\CCLEANER_SERVICE.EXE-D7E7DBF7.pf" => not found
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\avast! Antivirus => moved successfully
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\CCleaner 7 => moved successfully
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_CCleaner_CCleaner64_exe => moved successfully
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\avast! Antivirus => moved successfully
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\CCleaner 7 => moved successfully
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_CCleaner_CCleaner64_exe => moved successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\AvastUI.exe" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings\\TargetingAttributes" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings\\TargetingAttributesVerified" => removed successfully
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\AvastAdSDK => Error = 6
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\avast! Antivirus" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\{6D809377-6AF0-444B-8957-A3773F02200E}\Common Files\Avast Software\Icarus\avast-av\icarus_ui.exe" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files\Avast Software\Avast\AvastUI.exe" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\02B0C1DA7CED6E134B2971E6E9B947D9\SourceList\\LastUsedSource" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\02B0C1DA7CED6E134B2971E6E9B947D9\SourceList\Net\\1" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\02B0C1DA7CED6E134B2971E6E9B947D9\InstallProperties\\InstallSource" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD1C0B20-DEC7-31E6-B492-176E9E9B749D}\\InstallSource" => removed successfully
    HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\cdrom.inf_amd64_970e40f68a7583a1 => Access Denied
    HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\heci.inf_amd64_61ea518ffd0290a4 => Access Denied
    HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\lxptusb.inf_amd64_0e8d55b1f6f01e37 => Access Denied
    HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\lynxpointsystem.inf_amd64_ca9e125b91ae1a98 => Access Denied
    "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3962057343-3219533117-270726214-1002\\\Device\HarddiskVolume2\Program Files\Piriform\CCleaner 7\CCleaner.exe" => removed successfully
    "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3962057343-3219533117-270726214-1002\\\Device\HarddiskVolume2\Program Files\CCleaner\CCleanerBugReport.exe" => removed successfully
    "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCleanerPerformanceOptimizerService\\ImagePath" => removed successfully
    "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCleanerPerformanceOptimizerService\\DisplayName" => removed successfully
    "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCleanerPerformanceOptimizerService\\Description" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\{6D809377-6AF0-444B-8957-A3773F02200E}\CCleaner\CCleaner64.exe" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\{6D809377-6AF0-444B-8957-A3773F02200E}\CCleaner\temp_ccupdate\ccupdate700_free.exe" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\CCleaner 7" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView\\{6D809377-6AF0-444B-8957-A3773F02200E}\CCleaner\CCleaner64.exe" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView\\{6D809377-6AF0-444B-8957-A3773F02200E}\CCleaner\temp_ccupdate\ccupdate700_free.exe" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\CCleaner Smart Cleaning" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files\CCleaner\CCleanerReactivator.exe" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files\CCleaner\CCleaner64.exe" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files\Piriform\CCleaner 7\CCleaner.exe" => removed successfully
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage => removed successfully
    RegLink Found. Source: "" => Target: "HKLM\SOFTWARE\Avast Software"
    "HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avast Software" => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\AvastAdSDK => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~avast! antivirus => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$avast antivirus => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~avast! antivirus => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$avast antivirus => removed successfully
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\CCleaner64.exe => removed successfully
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCleanerPerformanceOptimizerService => removed successfully
    HKEY_USERS\.DEFAULT\Software\Piriform\CCleaner7 => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~ccleaner 7 => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~httpwww.ccleaner.comccleaner => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}ccleanerccleaner64.exe => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$ccleaner => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$ccleaner 7 => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~ccleaner 7 => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~httpwww.ccleaner.comccleaner => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}ccleanerccleaner64.exe => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$ccleaner => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$ccleaner 7 => removed successfully

    ========= sfc /scannow =========


    Fixing is terminated due to reaching maximum fixing time of 60 minutes. <==== ATTENTION
     
  9. Oh My!

    Oh My! Malware Expert Staff Member

    The program got hung up when trying to run some commands. Let's try that part again.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool - Run Fix Using Attached File

    --------------------
    • Download the attached file and save it in the same location as FRST.exe (example, Desktop, USB device) <<< Important
    • Right click on FRST and select Run as administrator
    • Click Fix and once completed your computer will reboot
    • The tool will create a log on the desktop called Fixlog.txt
    • Copy and paste the contents of the report in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     

    Attached Files:

  10. SusieQueue

    SusieQueue Private E-2

    Fix result of Farbar Recovery Scan Tool (x64) Version: 10-11-2025
    Ran by miste (12-11-2025 06:16:34) Run:2
    Running from C:\Users\miste\OneDrive\Desktop
    Loaded Profiles: miste
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth

    *****************


    ========= sfc /scannow =========



    Beginning system scan. This process will take some time.



    Beginning verification phase of system scan.


    Verification 0% complete.
    Verification 1% complete.
    Verification 1% complete.
    Verification 2% complete.
    Verification 2% complete.
    Verification 3% complete.
    Verification 4% complete.
    Verification 4% complete.
    Verification 5% complete.
    Verification 5% complete.
    Verification 6% complete.
    Verification 6% complete.
    Verification 7% complete.
    Verification 8% complete.
    Verification 8% complete.
    Verification 9% complete.
    Verification 9% complete.
    Verification 10% complete.
    Verification 11% complete.
    Verification 11% complete.
    Verification 12% complete.
    Verification 12% complete.
    Verification 13% complete.
    Verification 13% complete.
    Verification 14% complete.
    Verification 15% complete.
    Verification 15% complete.
    Verification 16% complete.
    Verification 16% complete.
    Verification 17% complete.
    Verification 18% complete.
    Verification 18% complete.
    Verification 19% complete.
    Verification 19% complete.
    Verification 20% complete.
    Verification 20% complete.
    Verification 21% complete.
    Verification 22% complete.
    Verification 22% complete.
    Verification 23% complete.
    Verification 23% complete.
    Verification 24% complete.
    Verification 25% complete.
    Verification 25% complete.
    Verification 26% complete.
    Verification 26% complete.
    Verification 27% complete.
    Verification 27% complete.
    Verification 28% complete.
    Verification 29% complete.
    Verification 29% complete.
    Verification 30% complete.
    Verification 30% complete.
    Verification 31% complete.
    Verification 32% complete.
    Verification 32% complete.
    Verification 33% complete.
    Verification 33% complete.
    Verification 34% complete.
    Verification 34% complete.
    Verification 35% complete.
    Verification 36% complete.
    Verification 36% complete.
    Verification 37% complete.
    Verification 37% complete.
    Verification 38% complete.
    Verification 39% complete.
    Verification 39% complete.
    Verification 40% complete.
    Verification 40% complete.
    Verification 41% complete.
    Verification 41% complete.
    Verification 42% complete.
    Verification 43% complete.
    Verification 43% complete.
    Verification 44% complete.
    Verification 44% complete.
    Verification 45% complete.
    Verification 45% complete.
    Verification 46% complete.
    Verification 47% complete.
    Verification 47% complete.
    Verification 48% complete.
    Verification 48% complete.
    Verification 49% complete.
    Verification 50% complete.
    Verification 50% complete.
    Verification 51% complete.
    Verification 51% complete.
    Verification 52% complete.
    Verification 52% complete.
    Verification 53% complete.
    Verification 54% complete.
    Verification 54% complete.
    Verification 55% complete.
    Verification 55% complete.
    Verification 56% complete.
    Verification 57% complete.
    Verification 57% complete.
    Verification 58% complete.
    Verification 58% complete.
    Verification 59% complete.
    Verification 59% complete.
    Verification 60% complete.
    Verification 61% complete.
    Verification 61% complete.
    Verification 62% complete.
    Verification 62% complete.
    Verification 63% complete.
    Verification 64% complete.
    Verification 64% complete.
    Verification 65% complete.
    Verification 65% complete.
    Verification 66% complete.
    Verification 66% complete.
    Verification 67% complete.
    Verification 68% complete.
    Verification 68% complete.
    Verification 69% complete.
    Verification 69% complete.
    Verification 70% complete.
    Verification 71% complete.
    Verification 71% complete.
    Verification 72% complete.
    Verification 72% complete.
    Verification 73% complete.
    Verification 73% complete.
    Verification 74% complete.
    Verification 75% complete.
    Verification 75% complete.
    Verification 76% complete.
    Verification 76% complete.
    Verification 77% complete.
    Verification 78% complete.
    Verification 78% complete.
    Verification 79% complete.
    Verification 79% complete.
    Verification 80% complete.
    Verification 80% complete.
    Verification 81% complete.
    Verification 82% complete.
    Verification 82% complete.
    Verification 83% complete.
    Verification 83% complete.
    Verification 84% complete.
    Verification 85% complete.
    Verification 85% complete.
    Verification 86% complete.
    Verification 86% complete.
    Verification 87% complete.
    Verification 87% complete.
    Verification 88% complete.
    Verification 89% complete.
    Verification 89% complete.
    Verification 90% complete.
    Verification 90% complete.
    Verification 91% complete.
    Verification 91% complete.
    Verification 92% complete.
    Verification 93% complete.
    Verification 93% complete.
    Verification 94% complete.
    Verification 94% complete.
    Verification 95% complete.
    Verification 96% complete.
    Verification 96% complete.
    Verification 97% complete.
    Verification 97% complete.
    Verification 98% complete.
    Verification 98% complete.
    Verification 99% complete.
    Verification 100% complete.


    Windows Resource Protection did not find any integrity violations.



    ========= End of CMD: =========


    ========= DISM /Online /Cleanup-Image /CheckHealth =========


    Deployment Image Servicing and Management tool
    Version: 10.0.19041.3636

    Image Version: 10.0.19045.6456

    No component store corruption detected.
    The operation completed successfully.


    ========= End of CMD: =========


    ==== End of Fixlog 06:44:03 ====
     
  11. Oh My!

    Oh My! Malware Expert Staff Member

    That looks good. Can you provide an update regarding the performance of the computer? What symptoms are gone/remain?
     
  12. SusieQueue

    SusieQueue Private E-2

    A couple of days ago, NordVPN was still disconnecting intermittently while browsing, but that may have stopped since then. I would probably need to use it over a longer period to be sure. I haven't had any real problems with staying connected to the Internet for some time, though. Thanks a lot for your help.
     
  13. SusieQueue

    SusieQueue Private E-2

    One thing I just noticed is that icons for things like Windows Security and some programs are still displaying as generic ones when searching from the taskbar. I can live with it, but don't know if that's cause for any concern.
     
  14. Oh My!

    Oh My! Malware Expert Staff Member

    If Nord hiccups again we should think about uninstalling and reinstalling the program.

    Let's run this and see if the icon issue is resolved.

    ===================================================

    Rebuilding Icon Cache

    --------------------

    • Download Icon_Cache.zip and save it to your Desktop
    • Unzip the folder onto your Desktop
    • Right click on the Icon_Cache.bat icon and select Run as administrator
    • Follow the prompts and once the process is complete your computer will reboot
    • Check your computer performance
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Results?
     
  15. SusieQueue

    SusieQueue Private E-2

    Unfortunately, the icons still aren't displaying correctly after doing that. It's only with certain ones (like Windows Security and Voice Recorder), and it only seems to be when searching from the taskbar.
     
  16. Oh My!

    Oh My! Malware Expert Staff Member

    Can you take a screen shot and attach it to your reply?
     
  17. SusieQueue

    SusieQueue Private E-2

    The missing icons in the screenshot are for Windows Security and Microsoft Store.
     

    Attached Files:

  18. Oh My!

    Oh My! Malware Expert Staff Member

    When did you first notice the icon issue?
     
  19. SusieQueue

    SusieQueue Private E-2

    I have noticed it for a long time-months to a year.
     
  20. Oh My!

    Oh My! Malware Expert Staff Member

    I would like to make sure the IconCache.db file was rebuilt since that is the most common reason for corrupted icon issues.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    File: C:\Users\miste\AppData\Local\IconCache.db
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     
  21. SusieQueue

    SusieQueue Private E-2

    Fix result of Farbar Recovery Scan Tool (x64) Version: 10-11-2025
    Ran by miste (13-11-2025 11:32:45) Run:3
    Running from C:\Users\miste\OneDrive\Desktop
    Loaded Profiles: miste
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    File: C:\Users\miste\AppData\Local\IconCache.db
    End::
    *****************


    ========================= File: C:\Users\miste\AppData\Local\IconCache.db ========================

    C:\Users\miste\AppData\Local\IconCache.db
    File not signed
    MD5: 465399B8FF7D735D9CE5CFEF57584202
    Creation and modification date: 2022-08-16 21:00 - 2025-11-12 14:01
    Size: 000057795
    Attributes: ---AH
    Company Name:
    Internal Name:
    Original Name:
    Product:
    Description:
    File Version:
    Product Version:
    Copyright:
    Virusscan: https://virusscan.jotti.org/filescanjob/oz5jffsn7c

    ====== End of File: ======


    ==== End of Fixlog 11:32:47 ====
     
  22. SusieQueue

    SusieQueue Private E-2

    It seems to have fixed the issue. Thanks!
     
  23. Oh My!

    Oh My! Malware Expert Staff Member

    Great.

    Are you experiencing any issues?
     
  24. SusieQueue

    SusieQueue Private E-2

    No, thanks for your help! It is really appreciated.
     
  25. SusieQueue

    SusieQueue Private E-2

    Sorry to bother you again, but I am still having trouble connecting and staying connected to Nord VPN. I just started having trouble again after my last post.
     
  26. SusieQueue

    SusieQueue Private E-2

    After terminating the processes in task manager and reopening, it started working again. I'm not sure if there's still something wrong with it.
     
  27. Oh My!

    Oh My! Malware Expert Staff Member

    I think we should uninstall and reinstall NordVPN as a first troubleshooting step.

    Please do this.

    ===================================================

    Uninstalling Programs Using Revo Uninstaller

    --------------------

    I recommend uninstalling the below listed program(s) from your computer.

    • Right click on Revo Uninstaller and select Run as administrator
    • From the list of programs highlight the listed program(s), or anything similar, then select Uninstall
    Code:
    NordUpdater
    NordVPN
    
    • If the program's uninstaller appears work through the steps to remove the program(s)
    • Be sure the Advanced option is selected then click Scan
    • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
    • Once done click Finish
    • Reboot your computer
    ===================================================

    Farbar Recovery Scan Tool SearchAll

    --------------------
    • Right click on FRST64 and select Run as administrator
    • Copy/paste the following in the Search: box
    Code:
    SearchAll: NordVPN;NordSec
    
    • Click Search Files
    • When completed click OK and a Search.txt document will open on your desktop
    • Attach the report to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Programs uninstalled?
    • Attached Search report
     
  28. SusieQueue

    SusieQueue Private E-2

    I uninstalled the associated programs.
     

    Attached Files:

  29. Oh My!

    Oh My! Malware Expert Staff Member

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    C:\Windows\Prefetch\NORDSEC-THREATPROTECTION-SERV-AAA96FA6.pf
    C:\Windows\Prefetch\NORDVPN-SERVICE.EXE-D99C30BA.pf
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\NordVPN
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_NordVPN_Diagnostics_NordSecurity_NordVpn_DiagnosticsTool_Application_exe
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-128-active.png
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-16-active.png
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-32-active.png
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-48-active.png
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-48-inactive.png
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\NordVPN
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_NordVPN_Diagnostics_NordSecurity_NordVpn_DiagnosticsTool_Application_exe
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-128-active.png
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-16-active.png
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-32-active.png
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-active.png
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-new-notification.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-128-active.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-16-active.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-32-active.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-active.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-new-notification.png
    2025-05-19 06:01 - 2025-11-06 08:40 _____ C:\Users\shini\AppData\Local\NordVPN
    2025-05-19 06:01 - 2025-11-06 08:38 _____ C:\Users\shini\AppData\Local\ToastNotificationManagerCompat\Apps\NordVPN
    2025-09-08 14:47 - 2025-09-08 14:47 ____C C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_nordvpn-service._c59366a629b65bb83adcc7f31a349ab077c42_79e6433e_ca227593-a488-4371-af92-4bd38042a6dd
    2025-10-15 03:57 - 2025-10-15 03:57 ____C C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_NordVPN.exe_9bf8cbf724f6f787c5679fd6c39a881f8875247_893440e4_35fc307d-9fef-4a89-b3ff-d7ded99e666a
    2025-11-08 07:24 - 2025-11-08 07:24 ____C C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_NordVPN.exe_886121ab70db363f94fa2dd212bda51d9efda_893440e4_10cc9111-9b31-4e02-b6c2-dd53d13a3a36
    2025-10-15 03:57 - 2025-10-15 03:57 ____C C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_NordVPN.exe_886121ab70db363f94fa2dd212bda51d9efda_893440e4_59ca45d0-00e2-4ce0-b7cf-a08b83a11294
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{4BBC7459-1B6A-4534-AE55-2CE1CCAC98B8}|ProfileName
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{4BBC7459-1B6A-4534-AE55-2CE1CCAC98B8}|Description
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{61B4286E-B35C-4EED-BEEC-A9F640346AA3}|ProfileName
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{61B4286E-B35C-4EED-BEEC-A9F640346AA3}|Description
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0A8D73C0C1E272F28839EF0D0F08714A1A53D3182A2489F4F23227CC940F0E4C0|Description
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0A8D73C0C1E272F28839EF0D0F08714A1A53D3182A2489F4F23227CC940F0E4C0|FirstNetwork
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0C08DEE8B47EADAF806A0BB5CB14A0379EC47FFAAF7017CBBCF1D4CA065FA4367|Description
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0C08DEE8B47EADAF806A0BB5CB14A0379EC47FFAAF7017CBBCF1D4CA065FA4367|FirstNetwork
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3962057343-3219533117-270726214-1003|\Device\HarddiskVolume2\Program Files\NordVPN\NordVPN.exe
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts|nordvpn_nordvpn
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|NordVPN
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\nordvpn-service.exe
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\NordVPN.exe
    DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\NordVPN
    DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\NordVPN Service
    DeleteKey: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\NordVPN
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~nordvpn
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~nordvpn
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings\NordVPN
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\NordVPN
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Classes\AppUserModelId\NordVPN
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\nordsec-threatprotection-service.exe
    DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\nordsec-threatprotection-service
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     
  30. SusieQueue

    SusieQueue Private E-2

    Fix result of Farbar Recovery Scan Tool (x64) Version: 14-11-2025
    Ran by miste (16-11-2025 04:46:22) Run:4
    Running from C:\Users\miste\OneDrive\Desktop
    Loaded Profiles: miste
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    CreateRestorePoint:
    CloseProcesses:
    C:\Windows\Prefetch\NORDSEC-THREATPROTECTION-SERV-AAA96FA6.pf
    C:\Windows\Prefetch\NORDVPN-SERVICE.EXE-D99C30BA.pf
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\NordVPN
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_NordVPN_Diagnostics_NordSecurity_NordVpn_DiagnosticsTool_Application_exe
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-128-active.png
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-16-active.png
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-32-active.png
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-48-active.png
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-48-inactive.png
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\NordVPN
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_NordVPN_Diagnostics_NordSecurity_NordVpn_DiagnosticsTool_Application_exe
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-128-active.png
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-16-active.png
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-32-active.png
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-active.png
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-new-notification.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-128-active.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-16-active.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-32-active.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-active.png
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-new-notification.png
    2025-05-19 06:01 - 2025-11-06 08:40 _____ C:\Users\shini\AppData\Local\NordVPN
    2025-05-19 06:01 - 2025-11-06 08:38 _____ C:\Users\shini\AppData\Local\ToastNotificationManagerCompat\Apps\NordVPN
    2025-09-08 14:47 - 2025-09-08 14:47 ____C C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_nordvpn-service._c59366a629b65bb83adcc7f31a349ab077c42_79e6433e_ca227593-a488-4371-af92-4bd38042a6dd
    2025-10-15 03:57 - 2025-10-15 03:57 ____C C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_NordVPN.exe_9bf8cbf724f6f787c5679fd6c39a881f8875247_893440e4_35fc307d-9fef-4a89-b3ff-d7ded99e666a
    2025-11-08 07:24 - 2025-11-08 07:24 ____C C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_NordVPN.exe_886121ab70db363f94fa2dd212bda51d9efda_893440e4_10cc9111-9b31-4e02-b6c2-dd53d13a3a36
    2025-10-15 03:57 - 2025-10-15 03:57 ____C C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_NordVPN.exe_886121ab70db363f94fa2dd212bda51d9efda_893440e4_59ca45d0-00e2-4ce0-b7cf-a08b83a11294
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{4BBC7459-1B6A-4534-AE55-2CE1CCAC98B8}|ProfileName
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{4BBC7459-1B6A-4534-AE55-2CE1CCAC98B8}|Description
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{61B4286E-B35C-4EED-BEEC-A9F640346AA3}|ProfileName
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{61B4286E-B35C-4EED-BEEC-A9F640346AA3}|Description
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0A8D73C0C1E272F28839EF0D0F08714A1A53D3182A2489F4F23227CC940F0E4C0|Description
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0A8D73C0C1E272F28839EF0D0F08714A1A53D3182A2489F4F23227CC940F0E4C0|FirstNetwork
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0C08DEE8B47EADAF806A0BB5CB14A0379EC47FFAAF7017CBBCF1D4CA065FA4367|Description
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0C08DEE8B47EADAF806A0BB5CB14A0379EC47FFAAF7017CBBCF1D4CA065FA4367|FirstNetwork
    DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3962057343-3219533117-270726214-1003|\Device\HarddiskVolume2\Program Files\NordVPN\NordVPN.exe
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts|nordvpn_nordvpn
    DeleteValue: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|NordVPN
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\nordvpn-service.exe
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\NordVPN.exe
    DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\NordVPN
    DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\NordVPN Service
    DeleteKey: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\NordVPN
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~nordvpn
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~nordvpn
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings\NordVPN
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\NordVPN
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Classes\AppUserModelId\NordVPN
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\nordsec-threatprotection-service.exe
    DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\nordsec-threatprotection-service
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe
    DeleteKey: HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe
    End::
    *****************

    Restore point was successfully created.
    Processes closed successfully.
    "C:\Windows\Prefetch\NORDSEC-THREATPROTECTION-SERV-AAA96FA6.pf" => not found
    "C:\Windows\Prefetch\NORDVPN-SERVICE.EXE-D99C30BA.pf" => not found
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\NordVPN => moved successfully
    C:\Users\shini\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_NordVPN_Diagnostics_NordSecurity_NordVpn_DiagnosticsTool_Application_exe => moved successfully
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-128-active.png => moved successfully
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-16-active.png => moved successfully
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-32-active.png => moved successfully
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-48-active.png => moved successfully
    C:\Users\shini\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\4.15.1_0\icons\nordvpn-48-inactive.png => moved successfully
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\NordVPN => moved successfully
    C:\Users\miste\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_NordVPN_Diagnostics_NordSecurity_NordVpn_DiagnosticsTool_Application_exe => moved successfully
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-128-active.png => moved successfully
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-16-active.png => moved successfully
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-32-active.png => moved successfully
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-active.png => moved successfully
    C:\Users\miste\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-new-notification.png => moved successfully
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-128-active.png => moved successfully
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-16-active.png => moved successfully
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-32-active.png => moved successfully
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-active.png => moved successfully
    C:\Users\miste\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoaledfpmneenckfbpdfhkmimnjocfa\5.1.1_0\icons\nordvpn-48-new-notification.png => moved successfully

    "C:\Users\shini\AppData\Local\NordVPN" Folder move:

    C:\Users\shini\AppData\Local\NordVPN => moved successfully

    "C:\Users\shini\AppData\Local\ToastNotificationManagerCompat\Apps\NordVPN" Folder move:

    C:\Users\shini\AppData\Local\ToastNotificationManagerCompat\Apps\NordVPN => moved successfully

    "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_nordvpn-service._c59366a629b65bb83adcc7f31a349ab077c42_79e6433e_ca227593-a488-4371-af92-4bd38042a6dd" Folder move:

    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_nordvpn-service._c59366a629b65bb83adcc7f31a349ab077c42_79e6433e_ca227593-a488-4371-af92-4bd38042a6dd => moved successfully

    "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_NordVPN.exe_9bf8cbf724f6f787c5679fd6c39a881f8875247_893440e4_35fc307d-9fef-4a89-b3ff-d7ded99e666a" Folder move:

    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_NordVPN.exe_9bf8cbf724f6f787c5679fd6c39a881f8875247_893440e4_35fc307d-9fef-4a89-b3ff-d7ded99e666a => moved successfully

    "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_NordVPN.exe_886121ab70db363f94fa2dd212bda51d9efda_893440e4_10cc9111-9b31-4e02-b6c2-dd53d13a3a36" Folder move:

    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_NordVPN.exe_886121ab70db363f94fa2dd212bda51d9efda_893440e4_10cc9111-9b31-4e02-b6c2-dd53d13a3a36 => moved successfully

    "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_NordVPN.exe_886121ab70db363f94fa2dd212bda51d9efda_893440e4_59ca45d0-00e2-4ce0-b7cf-a08b83a11294" Folder move:

    C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_NordVPN.exe_886121ab70db363f94fa2dd212bda51d9efda_893440e4_59ca45d0-00e2-4ce0-b7cf-a08b83a11294 => moved successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{4BBC7459-1B6A-4534-AE55-2CE1CCAC98B8}\\ProfileName" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{4BBC7459-1B6A-4534-AE55-2CE1CCAC98B8}\\Description" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{61B4286E-B35C-4EED-BEEC-A9F640346AA3}\\ProfileName" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{61B4286E-B35C-4EED-BEEC-A9F640346AA3}\\Description" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0A8D73C0C1E272F28839EF0D0F08714A1A53D3182A2489F4F23227CC940F0E4C0\\Description" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0A8D73C0C1E272F28839EF0D0F08714A1A53D3182A2489F4F23227CC940F0E4C0\\FirstNetwork" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0C08DEE8B47EADAF806A0BB5CB14A0379EC47FFAAF7017CBBCF1D4CA065FA4367\\Description" => removed successfully
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged\010103000F0000F0000200000F0000F0C08DEE8B47EADAF806A0BB5CB14A0379EC47FFAAF7017CBBCF1D4CA065FA4367\\FirstNetwork" => removed successfully
    "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3962057343-3219533117-270726214-1003\\\Device\HarddiskVolume2\Program Files\NordVPN\NordVPN.exe" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\\nordvpn_nordvpn" => removed successfully
    "HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\NordVPN" => removed successfully
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\nordvpn-service.exe => removed successfully
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\NordVPN.exe => removed successfully
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\NordVPN => removed successfully
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\NordVPN Service => removed successfully
    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\NordVPN => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~nordvpn => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~nordvpn => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings\NordVPN => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\NordVPN => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Classes\AppUserModelId\NordVPN => removed successfully
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\nordsec-threatprotection-service.exe => removed successfully
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\nordsec-threatprotection-service => removed successfully
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe => not found
    HKEY_USERS\S-1-5-21-3962057343-3219533117-270726214-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{8dac8e4b-428a-4d6e-aa7e-d572e5fa62d3}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{6d809377-6af0-444b-8957-a3773f02200e}nordvpndiagnosticsnordsecurity.nordvpn.diagnosticstool.application.exe => not found


    The system needed a reboot.

    ==== End of Fixlog 04:47:51 ====
     
  31. Oh My!

    Oh My! Malware Expert Staff Member

    How is the system running now?
     
  32. SusieQueue

    SusieQueue Private E-2

    It's running fine now. Thanks again.
     
  33. Oh My!

    Oh My! Malware Expert Staff Member

    Very good.

    If you would like to reinstall NordVPN feel free to do so then let me know if the issue is resolved.
     
  34. SusieQueue

    SusieQueue Private E-2

    Nord seems to be working fine but the icons are missing again.
     
  35. Oh My!

    Oh My! Malware Expert Staff Member

    Which ones and is it back to a generic icon?
     
  36. SusieQueue

    SusieQueue Private E-2

    They all look like they did before
     
  37. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    Let's run the below.

    ===================================================

    Rebuilding Windows Indexing

    --------------------

    Note: This process may take a long time to complete. Do not interrupt the process.
    • Click Start, type Indexing then select Indexing Options
    • Click Advanced
    • Click Rebuild, then OK
    • When completed you will see Indexing complete
    • Reboot your computer then check your icons
    ===================================================

    Things I would like to see in your next reply.
    • Results?
     
  38. SusieQueue

    SusieQueue Private E-2

    The icons are still not showing but for the most part the computer is usable now. Thanks for all your help.
     
  39. Oh My!

    Oh My! Malware Expert Staff Member

    OK, if you prefer to leave things as is that is fine. This is a known issue that is not always easy to identify and fix. There are multiple causes.
     
  40. SusieQueue

    SusieQueue Private E-2

    If I leave the computer unattended sometimes when I go back 20 or so notifications show that Nord VPN has reconnected every few minutes. Sorry to keep bothering you but VPN is worthless if I can't stay connected to it.
     
  41. Oh My!

    Oh My! Malware Expert Staff Member

    A few options.

    If you no longer want NordVPN we can uninstall it again.

    You can attempt to troubleshoot the issue by following the steps here. This page also has a Live Chat option. If you want Live Chat Support or help via email you should complete the steps here before contacting them.

    As a 3rd option you and I can troubleshoot but it will be less efficient than contacting the experts at NordVPN.

    Let me know your thoughts.
     
  42. SusieQueue

    SusieQueue Private E-2

    Thanks for all your help. I will definitely look into that.
     
  43. Oh My!

    Oh My! Malware Expert Staff Member

    Very good.

    If you otherwise like NordVPN I think it would be worth the aggravation to give them a shot at resolving it.

    FWIW I have experienced the same type of issue with my VPN from a different company....

    Gary
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds