Bsods And Slow Starts

Discussion in 'Malware Help (A Specialist Will Reply)' started by pjubber, Jul 28, 2023.

  1. pjubber

    pjubber Private E-2

    My issue began a few days ago with a Critical Process Died. During several soft and HARD restarts, I got a few freeze-ups and BSOD's. After running the scans, the laptop actually worked for a few hours today before crashing again. Even as I was creating this thread, my laptop had to restart: Critical Process Died
    I hope I can finish the post this time. My title should have included "forced restarts" I think. I appreciate any help you can give. (I know the PC is quite old, but it is what I have.)
     

    Attached Files:

  2. pjubber

    pjubber Private E-2

    I forgot to attach the Mbam report.
     

    Attached Files:

  3. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to the MajorGeeks Malware Forum.

    Though this may not be a malware issue we can take a look at things. While I review what you have posted please do this.

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download Farbar Recover Scan Tool for 64 bit systems and save it to your Desktop. <<< Important
    • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
    • 2 Notepad documents should now be open on your desktop.
    • Please copy and paste the contents of each report in separate reply windows
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:

    • FRST.txt
    • Addition.txt
     
  4. pjubber

    pjubber Private E-2

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-07-2023
    Ran by peggy (administrator) on LAPTOP-LR (HP HP Laptop 15-bs1xx) (29-07-2023 07:45:17)
    Running from C:\Users\peggy\Desktop\FRST64.exe
    Loaded Profiles: peggy
    Platform: Microsoft Windows 10 Home Version 22H2 19045.3208 (X64) Language: English (United States)
    Default browser: "C:\Program Files (x86)\Pale Moon\palemoon.exe" -osint -url "%1"
    Boot Mode: Normal

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe
    (C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\igfxCUIService.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\igfxEM.exe
    (Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
    (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
    (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2302.13003.0_x64__8wekyb3d8bbwe\MicrosoftSecurityApp\MicrosoftSecurityApp.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe
    (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
    (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe
    (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\DiagsCap.exe
    (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\NetworkCap.exe
    (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe
    (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
    (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
    (services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (services.exe ->) (Intel Corporation -> IntelĀ® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
    (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\igfxCUIService.exe
    (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\IntelCpHDCPSvc.exe
    (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki135422.inf_amd64_819df826076efbf4\IntelCpHeciSvc.exe
    (services.exe ->) (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
    (services.exe ->) (Intuit, Inc. -> Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
    (services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MsMpEng.exe
    (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\NisSrv.exe
    (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    (services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3205_none_7e1f4da67c811930\TiWorker.exe
    (SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
    (SystemSettingsAdminFlows.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Users\peggy\AppData\Local\Temp\0FF71E7C-93E3-45E3-97F2-F1DD700F190E\DismHost.exe

    ==================== Registry (Whitelisted) ===================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11235928 2020-04-24] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
    HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
    HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [703312 2017-07-21] (HP Inc. -> HP Inc.)
    HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
    HKU\S-1-5-21-1466392891-3797003834-4236733652-1001\...\Run: [QuickenScheduledUpdates] => C:\Program Files (x86)\Quicken\bagent.exe [96304 2023-07-20] (Quicken Inc. -> Quicken Inc.)
    HKU\S-1-5-21-1466392891-3797003834-4236733652-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [40496032 2023-06-07] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
    Startup: C:\Users\peggy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2022-06-17]
    ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
    HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
    HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION

    ==================== Scheduled Tasks (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {F18EC808-EA09-4973-958A-9E80ED598675} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-06-07] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
    Task: {04548A7B-1BC4-407F-87B5-44C6AE54929B} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-06-07] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "d2e0459e-2064-4521-b241-3d7a044b8a6a" --version "6.13.10517" --silent
    Task: {679D4468-6296-46E1-8FB0-265722C9D81B} - System32\Tasks\CCleanerSkipUAC - peggy => C:\Program Files\CCleaner\CCleaner64.exe [40496032 2023-06-07] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
    Task: {0BB54293-B32C-4293-929A-64D2A249BBA3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe /send (No File)
    Task: {D4F3419D-B4D8-485F-B7D9-32B4511ECB23} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe /f (No File)
    Task: {E21F2427-6618-4FAF-B921-63C572F6C935} - System32\Tasks\HPEA3JOBS => C:\Program -> Files\HP\HP ePrint\hpeprint.exe /CheckJobs
    Task: {15FEA0C2-89D9-4C0C-8542-88FFC9696BDB} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe [818008 2021-09-15] (Intel Corporation -> Intel(R) Corporation)
    Task: {35476A25-FFBB-43EA-A8A3-B8BA338A5E71} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26616832 2023-07-15] (Microsoft Corporation -> Microsoft Corporation)
    Task: {08EC34C7-48A7-4676-8C45-C547DFAE4DA2} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26616832 2023-07-15] (Microsoft Corporation -> Microsoft Corporation)
    Task: {DD0321FB-60DB-4D81-A52E-61D98643ABA7} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [124296 2023-07-15] (Microsoft Corporation -> Microsoft Corporation)
    Task: {4210FE72-9420-4C18-B5FF-89EC1C642E8F} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [124296 2023-07-15] (Microsoft Corporation -> Microsoft Corporation)
    Task: {99B11296-A133-40F3-94B9-EA9DDE898311} - System32\Tasks\Microsoft\Windows\WaaSMedic\MaintenanceWork => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}
    Task: {A765F42E-05DA-4270-A1EF-B74A0ED16DC2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MpCmdRun.exe [1649976 2023-07-22] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {2A0872D5-DC50-4363-B776-F7E43C8250D5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MpCmdRun.exe [1649976 2023-07-22] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {F56A675C-B2BC-4BF5-A587-E5B1918CBE82} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MpCmdRun.exe [1649976 2023-07-22] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {78238D55-5E64-4B00-9CAE-0338978B0685} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MpCmdRun.exe [1649976 2023-07-22] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {3E3010CA-CCD5-4191-9468-2437DF429F8F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [724384 2023-07-16] (Mozilla Corporation -> Mozilla Foundation)
    Task: {EEFBDEBF-FB99-4A67-86E5-ABD80C6B7E11} - System32\Tasks\Opera scheduled Autoupdate 1647718698 => C:\Users\peggy\AppData\Local\Programs\Opera\launcher.exe [2708376 2023-06-07] (Opera Norway AS -> Opera Software)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
    Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{37c27e24-0e12-4ee2-9fae-59a3a27850ca}: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{6ead0b60-1746-4561-a3d4-9703f68a0b37}: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{8bbdde21-65e7-49f9-bc66-32c8eb30038a}: [DhcpNameServer] 71.10.216.2 71.10.216.1

    Edge:
    =======
    DownloadDir: C:\Users\peggy\Downloads
    Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
    Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
    Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
    Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
    Edge DefaultProfile: Default
    Edge Profile: C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Default [2023-07-28]
    Edge HomePage: Default -> hxxps://cprportal.lls.org/#/login
    Edge StartupUrls: Default -> "hxxps://www.biblegateway.com/reading-plans/beginning/next?version=KJV&interface=print"
    Edge DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
    Edge DefaultSearchKeyword: Default -> duckduckgo.com
    Edge DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab
    Edge DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
    Edge Extension: (Adblock Plus - free ad blocker) - C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2023-07-25]
    Edge Extension: (Edge relevant text changes) - C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-07-25]
    Edge Profile: C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Guest Profile [2023-07-28]
    Edge Profile: C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2023-07-28]
    Edge Extension: (Goodnight Glow) - C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\enfdmlidcoffeadcfoncdbihnbidbbfn [2022-02-03]

    FireFox:
    ========
    FF DefaultProfile: ynbql7q7.default-1689550989702
    FF DefaultProfile: pjzxghku.default
    FF ProfilePath: C:\Users\peggy\AppData\Roaming\Mozilla\Firefox\Profiles\ynbql7q7.default-1689550989702 [2023-07-28]
    FF Homepage: Mozilla\Firefox\Profiles\ynbql7q7.default-1689550989702 -> hxxps://www.biblegateway.com/reading-plans/beginning/next?version=KJV&interface=print
    FF Extension: (AdBlocker Ultimate) - C:\Users\peggy\AppData\Roaming\Mozilla\Firefox\Profiles\ynbql7q7.default-1689550989702\Extensions\adblockultimate@adblockultimate.net.xpi [2023-07-25]
    FF ProfilePath: C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default [2023-07-29]
    FF Homepage: Moonchild Productions\Pale Moon\Profiles\pjzxghku.default -> hxxps://www.biblegateway.com/reading-plans/beginning/next?version=KJV&interface=print
    FF Extension: (Adblock Latitude) - C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default\Extensions\adblocklatitude@addons.palemoon.org.xpi [2022-05-11] [Legacy] [not signed]
    FF SearchPlugin: C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default\searchplugins\conservapedia-en.xml [2023-07-29]
    FF SearchPlugin: C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default\searchplugins\startpage---english.xml [2023-07-29]
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-06-30] (Microsoft Corporation -> Microsoft Corporation)

    Chrome:
    =======
    CHR Profile: C:\Users\peggy\AppData\Local\Google\Chrome\User Data\Default [2023-07-28]
    CHR StartupUrls: Default -> "hxxps://www.google.com/"
    CHR Extension: (Slides) - C:\Users\peggy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-03-09]

    Opera:
    =======
    OPR Profile: C:\Users\peggy\AppData\Roaming\Opera Software\Opera Stable [2023-07-28]
    OPR StartupUrls: Opera Stable -> "hxxps://www.foxnews.com/politics"
    OPR DefaultSearchURL: Opera Stable -> hxxps://duckduckgo.com/?q={searchTerms}&t={opera:vpnClient}
    OPR DefaultSearchKeyword: Opera Stable -> d
    OPR Extension: (Rich Hints Agent) - C:\Users\peggy\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2023-04-16]
    OPR Extension: (Opera Wallet) - C:\Users\peggy\AppData\Roaming\Opera Software\Opera Stable\Extensions\gojhcdgcpbpfigcaejpfhfegekdgiblk [2023-04-16]
    OPR Extension: (Amazon Assistant Promotion) - C:\Users\peggy\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2022-03-19]
    OPR Extension: (Opera AI Prompts) - C:\Users\peggy\AppData\Roaming\Opera Software\Opera Stable\Extensions\mljbnbeedpkgakdchcmfapkjhfcogaoc [2023-04-16]

    ==================== Services (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11851240 2023-07-15] (Microsoft Corporation -> Microsoft Corporation)
    R2 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [733200 2021-04-19] (HP Inc. -> HP Inc.)
    R2 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [731152 2021-04-19] (HP Inc. -> HP Inc.)
    R2 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [731152 2021-04-19] (HP Inc. -> HP Inc.)
    R2 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [732176 2021-04-19] (HP Inc. -> HP Inc.)
    R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9267376 2023-07-26] (Malwarebytes Inc. -> Malwarebytes)
    R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\NisSrv.exe [3244928 2023-07-22] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.9-0\MsMpEng.exe [133576 2023-07-22] (Microsoft Windows Publisher -> Microsoft Corporation)
    S2 HP Comm Recover; "C:\Program Files\HPCommRecovery\HPCommRecovery.exe" [X]
    S2 HPJumpStartBridge; "c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe" [X]
    S2 HPSupportSolutionsFrameworkService; "C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe" [X]

    ===================== Drivers (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77288 2017-10-17] (McAfee, Inc. -> McAfee LLC)
    R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223176 2023-07-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
    S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-07-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
    R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-07-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
    S3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [492520 2017-10-17] (McAfee, Inc. -> McAfee LLC)
    S3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [115176 2017-10-17] (McAfee, Inc. -> McAfee LLC)
    R3 MpKsl5968f6cc; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4AF1B57-9338-4886-B759-CC1AC4940961}\MpKslDrv.sys [221480 2023-07-28] (Microsoft Windows -> Microsoft Corporation)
    R2 NPF; C:\WINDOWS\system32\drivers\npf.sys [35344 2021-11-25] (CACE Technologies, Inc. -> CACE Technologies, Inc.)
    S3 usbser; C:\Windows\SysWOW64\drivers\usbser.sys [26112 2013-07-04] (Microsoft Corporation) [File not signed]
    S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49600 2023-07-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
    R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [498944 2023-07-22] (Microsoft Windows -> Microsoft Corporation)
    R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99608 2023-07-22] (Microsoft Windows -> Microsoft Corporation)
    R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [40104 2022-06-17] (HP Inc. -> HP)
    S3 MpKsl01daf1ea; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    S3 MpKsl5e1ba4d3; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    S3 MpKsl6cca9f70; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    S3 MpKslf8151fa8; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) (Whitelisted) =========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2023-07-29 07:45 - 2023-07-29 07:47 - 000022135 _____ C:\Users\peggy\Desktop\FRST.txt
    2023-07-29 07:42 - 2023-07-29 07:46 - 000000000 ____D C:\FRST
    2023-07-29 07:37 - 2023-07-29 07:37 - 002384384 _____ (Farbar) C:\Users\peggy\Desktop\FRST64.exe
    2023-07-28 20:02 - 2023-07-28 20:02 - 000001227 _____ C:\Users\peggy\Desktop\mbam.txt
    2023-07-28 19:17 - 2023-07-28 19:17 - 000004040 _____ C:\WINDOWS\system32\Tasks\PostponeDeviceSetupToast_S-1-5-21-1466392891-3797003834-4236733652-1001_1
    2023-07-28 19:14 - 2023-07-28 19:14 - 000003840 _____ C:\WINDOWS\system32\Tasks\Intel PTT EK Recertification
    2023-07-28 15:39 - 2023-07-28 15:39 - 000001337 _____ C:\Users\peggy\AppData\Roaming\Microsoft\Windows\Start Menu\Williams-2023-Autism and Renal Sulfate Transport.pdf - Shortcut.lnk
    2023-07-26 22:23 - 2023-07-26 22:24 - 000033431 _____ C:\MGlogs.zip
    2023-07-26 22:23 - 2023-07-26 22:24 - 000000000 ____D C:\MGtools
    2023-07-26 21:57 - 2023-07-26 21:57 - 000000000 ___HD C:\$SysReset
    2023-07-26 21:45 - 2023-07-26 22:10 - 000000000 ____D C:\ProgramData\HitmanPro
    2023-07-26 21:44 - 2023-07-26 21:44 - 000004908 _____ C:\Users\peggy\Desktop\RKlog.txt
    2023-07-26 19:35 - 2023-07-26 21:41 - 000000000 ____D C:\ProgramData\RogueKiller
    2023-07-26 19:08 - 2023-07-29 07:36 - 000000000 ____D C:\Users\peggy\AppData\Local\Malwarebytes
    2023-07-26 19:08 - 2023-07-26 19:15 - 000002040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
    2023-07-26 19:08 - 2023-07-26 19:15 - 000002028 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2023-07-26 19:07 - 2023-07-26 19:07 - 000000000 ____D C:\ProgramData\Malwarebytes
    2023-07-26 19:01 - 2023-07-26 19:03 - 296437336 _____ (Malwarebytes) C:\Users\peggy\Desktop\mb.exe
    2023-07-26 18:42 - 2023-07-26 21:45 - 014248944 _____ (SurfRight B.V.) C:\Users\peggy\Desktop\HitmanPro_x64.exe
    2023-07-26 18:40 - 2023-07-26 18:40 - 035220912 _____ C:\Users\peggy\Desktop\RogueKiller_portable64.exe
    2023-07-26 18:38 - 2023-07-26 18:41 - 296437336 _____ (Malwarebytes) C:\Users\peggy\Downloads\mb.exe
    2023-07-26 18:28 - 2023-07-26 18:33 - 000000000 ____D C:\AdwCleaner
    2023-07-26 18:27 - 2023-07-26 18:27 - 008791352 _____ (Malwarebytes) C:\Users\peggy\Desktop\AdwCleaner.exe
    2023-07-22 07:31 - 2023-07-22 07:31 - 001558509 _____ C:\Users\peggy\Desktop\Williams-2023-Autism and Renal Sulfate Transport.pdf
    2023-07-16 21:35 - 2023-07-16 21:35 - 000547517 _____ C:\Users\peggy\Downloads\CoPay_Claims_FAQs_3.18.21.pdf
    2023-07-16 19:54 - 2023-07-27 18:43 - 000000000 ____D C:\Program Files\Mozilla Firefox
    2023-07-15 09:51 - 2023-07-15 09:51 - 000201049 _____ C:\Users\peggy\Downloads\X4Orx9kU.pdf
    2023-07-15 09:15 - 2023-07-15 09:15 - 000201264 _____ C:\Users\peggy\Downloads\YAXVi_CG.pdf
    2023-07-13 10:39 - 2023-07-13 10:39 - 000000000 ___HD C:\$WinREAgent
    2023-07-10 21:36 - 2023-07-10 21:36 - 000032427 _____ C:\Users\peggy\Desktop\Q VALIDATION DATA_LOG.TXT
    2023-07-08 22:54 - 2023-07-08 22:54 - 000610214 _____ C:\Users\peggy\Downloads\9780802490957-TOC-CH1,2.pdf
    2023-07-02 22:36 - 2023-07-02 22:59 - 000000000 ____D C:\Users\peggy\Documents\state farm
    2023-07-01 21:26 - 2023-07-01 21:26 - 000000099 _____ C:\Users\peggy\Desktop\evening and morning.txt
    2023-07-01 14:46 - 2023-07-01 14:46 - 001722901 _____ C:\Users\peggy\Downloads\bookmarks.html
    2023-06-30 14:57 - 2023-07-28 20:14 - 000000000 ___HD C:\Users\peggy\Downloads\.opera
    2023-06-30 14:57 - 2023-07-28 20:14 - 000000000 ___HD C:\Users\peggy\.opera

    ==================== One month (modified) ==================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2023-07-29 07:36 - 2018-05-18 19:20 - 000000000 ____D C:\Users\peggy\Documents\Outlook Files
    2023-07-29 07:35 - 2023-02-12 09:12 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2023-07-28 21:32 - 2023-06-26 19:00 - 000000000 ____D C:\WINDOWS\Minidump
    2023-07-28 21:32 - 2022-03-19 14:57 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
    2023-07-28 21:32 - 2018-07-03 22:02 - 000000000 ____D C:\Users\peggy\AppData\Local\CrashDumps
    2023-07-28 21:23 - 2018-05-16 08:16 - 000000000 ____D C:\Program Files\CCleaner
    2023-07-28 21:18 - 2018-05-15 15:19 - 000000000 ____D C:\Users\peggy\AppData\Local\ClassicShell
    2023-07-28 20:01 - 2023-01-21 09:18 - 000000000 ____D C:\Users\peggy\AppData\LocalLow\IGDump
    2023-07-28 19:23 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2023-07-28 19:16 - 2018-05-15 14:24 - 000000000 __SHD C:\Users\peggy\IntelGraphicsProfiles
    2023-07-28 19:13 - 2023-02-12 09:52 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2023-07-28 19:13 - 2021-06-12 00:17 - 000008192 ___SH C:\DumpStack.log.tmp
    2023-07-28 19:13 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
    2023-07-28 18:52 - 2020-06-17 00:13 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
    2023-07-28 18:52 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
    2023-07-28 18:52 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
    2023-07-28 08:36 - 2020-01-28 15:10 - 000918960 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2023-07-27 21:17 - 2018-05-23 20:15 - 000000000 ____D C:\ProgramData\TEMP
    2023-07-27 21:17 - 2018-05-23 20:15 - 000000000 ____D C:\Program Files (x86)\SpywareBlaster
    2023-07-26 19:08 - 2019-12-07 05:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
    2023-07-26 19:07 - 2023-01-11 12:55 - 000000000 ____D C:\Program Files\Malwarebytes
    2023-07-26 18:55 - 2017-11-10 16:54 - 000000000 ____D C:\ProgramData\HP
    2023-07-26 18:34 - 2018-05-15 14:29 - 000000000 ____D C:\Users\peggy\AppData\Roaming\Hewlett-Packard
    2023-07-26 18:34 - 2017-11-10 16:54 - 000000000 ____D C:\ProgramData\Hewlett-Packard
    2023-07-26 18:34 - 2017-11-10 16:54 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
    2023-07-26 18:34 - 2017-10-31 19:51 - 000000000 ___HD C:\hp
    2023-07-26 18:33 - 2017-11-10 16:53 - 000000000 ____D C:\Program Files (x86)\HP
    2023-07-26 10:36 - 2023-02-12 09:21 - 000000000 ____D C:\Users\peggy
    2023-07-26 06:44 - 2019-12-07 05:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI
    2023-07-24 18:48 - 2018-11-27 21:46 - 000000000 ____D C:\Users\peggy\AppData\Local\D3DSCache
    2023-07-22 07:11 - 2018-05-23 10:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
    2023-07-18 19:57 - 2022-03-20 23:13 - 000000000 ____D C:\Program Files (x86)\Pale Moon
    2023-07-18 13:52 - 2020-02-25 00:17 - 000000000 ____D C:\Users\peggy\Documents\OSCAR_Data
    2023-07-16 22:20 - 2020-04-11 14:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2023-07-16 20:29 - 2020-04-11 14:55 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
    2023-07-16 19:41 - 2020-04-11 14:56 - 000000000 ____D C:\Users\peggy\AppData\LocalLow\Mozilla
    2023-07-15 18:18 - 2021-11-05 15:46 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
    2023-07-15 08:02 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
    2023-07-14 21:54 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
    2023-07-14 20:25 - 2018-05-15 15:13 - 000000000 ____D C:\WINDOWS\system32\MRT
    2023-07-14 20:20 - 2018-05-15 15:12 - 173351160 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2023-07-14 09:06 - 2023-02-12 09:38 - 000935026 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2023-07-14 09:06 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
    2023-07-14 09:01 - 2023-02-12 09:12 - 000449240 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2023-07-14 08:56 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
    2023-07-14 08:56 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
    2023-07-14 08:56 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\setup
    2023-07-14 08:56 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
    2023-07-14 08:56 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
    2023-07-14 08:55 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2023-07-14 08:55 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
    2023-07-13 15:23 - 2023-02-12 09:17 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2023-07-10 21:35 - 2018-05-15 20:34 - 000000000 ____D C:\Users\peggy\Documents\Quicken
    2023-07-08 17:16 - 2018-05-20 13:29 - 000000000 ____D C:\Users\peggy\Documents\obit
    2023-07-07 08:45 - 2023-02-12 09:52 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
    2023-07-07 08:45 - 2023-02-12 09:52 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
    2023-07-05 20:20 - 2018-05-15 14:24 - 000000000 ____D C:\Users\peggy\AppData\Local\ConnectedDevicesPlatform
    2023-07-02 23:14 - 2019-04-11 12:34 - 000000000 ____D C:\Users\peggy\Documents\thyroid
    2023-07-02 23:13 - 2018-10-25 19:36 - 000000000 ____D C:\Users\peggy\Documents\LLS and PAN
    2023-07-02 23:12 - 2021-06-28 18:17 - 000000000 ____D C:\Users\peggy\Documents\a Medical -cl
    2023-07-02 23:11 - 2021-10-08 16:07 - 000000000 ____D C:\Users\peggy\Documents\budget
    2023-07-02 23:08 - 2019-05-03 20:38 - 000000000 ____D C:\Users\peggy\Documents\misc med
    2023-07-02 23:08 - 2019-01-12 16:18 - 000000000 ___RD C:\Users\peggy\Documents\Scanned Documents
    2023-07-02 23:06 - 2022-08-08 09:39 - 000000000 ____D C:\Users\peggy\Documents\garden and home
    2023-07-02 22:57 - 2019-09-07 20:40 - 000000000 ____D C:\Users\peggy\Documents\Government
    2023-07-02 22:56 - 2021-06-04 16:24 - 000000000 ____D C:\Users\peggy\Documents\a Medical p
    2023-07-02 22:48 - 2022-02-14 19:19 - 000000000 ____D C:\Users\peggy\Documents\fam and friends
    2023-07-02 22:48 - 2021-10-16 22:28 - 000000000 ____D C:\Users\peggy\Documents\Covid
    2023-07-02 22:47 - 2018-11-18 20:32 - 000000000 ____D C:\Users\peggy\Documents\Bible
    2023-07-02 22:02 - 2018-05-15 14:24 - 000000000 ____D C:\Users\peggy\AppData\Local\Packages
    2023-07-02 21:51 - 2018-05-16 14:17 - 000000000 ____D C:\Users\peggy\AppData\Roaming\Microsoft\Word
    2023-07-01 21:31 - 2018-05-17 20:23 - 000000000 ____D C:\Users\peggy\AppData\Roaming\Microsoft\Signatures
    2023-06-30 13:36 - 2023-02-12 09:21 - 000000000 ____D C:\Users\away
    2023-06-30 13:36 - 2021-04-28 14:54 - 000000000 ____D C:\Program Files (x86)\Quicken
    2023-06-30 13:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
    2023-06-30 13:36 - 2018-06-11 12:35 - 000000000 ____D C:\Users\peggy\Documents\computer
    2023-06-30 13:36 - 2018-05-23 20:15 - 000000000 ____D C:\ProgramData\Licenses
    2023-06-30 13:36 - 2018-03-08 03:40 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
    2023-06-30 13:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\registration
    2023-06-30 13:20 - 2018-08-31 21:17 - 000000000 ____D C:\Users\peggy\Documents\tax misc
    2023-06-30 13:20 - 2018-06-04 16:13 - 000000000 ____D C:\Users\peggy\Documents\aero

    ==================== Files in the root of some directories ========

    2019-06-06 12:39 - 2019-06-06 12:53 - 000038416 _____ () C:\Users\peggy\AppData\Roaming\Comma Separated Values.ADR
    2019-06-06 12:44 - 2019-06-06 12:44 - 000012948 _____ () C:\Users\peggy\AppData\Roaming\Comma Separated Values.CAL
    2019-07-08 20:28 - 2019-10-28 18:34 - 000009306 _____ () C:\Users\peggy\AppData\Roaming\Comma Separated Values.EML
    2018-05-22 06:36 - 2023-01-03 22:53 - 000007653 _____ () C:\Users\peggy\AppData\Local\Resmon.ResmonCfg

    ==================== SigCheck ============================

    (There is no automatic fix for files that do not pass verification.)

    ==================== End of FRST.txt ========================
     
  5. pjubber

    pjubber Private E-2

    Addition text uploaded because file exceeded 40,000 characters. Thank you.
     

    Attached Files:

  6. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for your patience.

    As I suspected, your issue is not malware related.

    Let's start with this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------

    • Right click on the FRST icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    Zip: C:\WINDOWS\MEMORY.DMP
    C:\WINDOWS\System32\drivers\cfwids.sys
    C:\WINDOWS\System32\drivers\mfeaack.sys
    C:\WINDOWS\System32\drivers\mfeplk.sys
    Task: {0BB54293-B32C-4293-929A-64D2A249BBA3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe /send (No File)
    Task: {D4F3419D-B4D8-485F-B7D9-32B4511ECB23} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe /f (No File)
    Task: {3E3010CA-CCD5-4191-9468-2437DF429F8F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [724384 2023-07-16] (Mozilla Corporation -> Mozilla Foundation)
    Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
    Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
    Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
    Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
    C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\enfdmlidcoffeadcfoncdbihnbidbbfn
    FF SearchPlugin: C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default\searchplugins\conservapedia-en.xml [2023-07-29]
    FF SearchPlugin: C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default\searchplugins\startpage---english.xml [2023-07-29]
    S2 HP Comm Recover; "C:\Program Files\HPCommRecovery\HPCommRecovery.exe" [X]
    S2 HPJumpStartBridge; "c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe" [X]
    S2 HPSupportSolutionsFrameworkService; "C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe" [X]
    S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77288 2017-10-17] (McAfee, Inc. -> McAfee LLC)
    S3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [492520 2017-10-17] (McAfee, Inc. -> McAfee LLC)
    S3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [115176 2017-10-17] (McAfee, Inc. -> McAfee LLC)
    S3 MpKsl01daf1ea; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    S3 MpKsl5e1ba4d3; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    S3 MpKsl6cca9f70; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    S3 MpKslf8151fa8; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
    AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
    ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
    AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [274]
    FirewallRules: [{513BB25F-8FE4-4071-99C4-9423043D6204}] => (Allow) C:\Program Files\OSCAR\OSCAR.exe => No File
    FirewallRules: [{F956BF42-C3DA-4E2E-A6BB-2A5AC0D4DBBF}] => (Allow) C:\Program Files\OSCAR\OSCAR.exe => No File
    FirewallRules: [{39BD176A-45E7-4ADD-8C98-F6C27163D9C5}] => (Allow) C:\Program Files\OSCAR\OSCAR.exe => No File
    FirewallRules: [{91797645-1DCA-45BC-9F58-7C269363BD76}] => (Allow) C:\Program Files\OSCAR\OSCAR.exe => No File
    FirewallRules: [{E94CC475-9F13-4E42-9E92-1F797726E0F4}] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [{8731FFDF-DB8D-43E6-8BA6-460DDDC38932}] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [TCP Query User{FA22C86E-52E2-4915-869D-1E528C58B1C7}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [UDP Query User{C40CAD8C-994F-41D3-99EB-D6FE3BDC4084}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [{1EFDD09B-55A7-48B0-AF5A-AEC5773A0E34}] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [{49890B5D-7CA9-4576-8310-6D5696BAE647}] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    cmd: netsh winsock reset catalog
    cmd: netsh int ip reset resetlog.txt
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state ON
    cmd: bitsadmin /reset /allusers
    cmd: ipconfig /flushdns
    Removeproxy:
    hosts:
    cmd: chkdsk
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    End::
    
    • Click Fix and wait patiently for the process to complete
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • The tool will create a zipped folder on your Desktop with today's date, example: 06.20.2023_13.24.50.zip. Please upload the folder GoFile, WeTransfer, or the file hosting site of your choice. Post the download link in your reply
    • Note: This step resets your Firewall settings and you may be asked later to grant permission for legitimate programs to pass through the Firewall. If you recognize the program agree to the request.
    • Note: The Emptytemp: command will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
    ===================================================

    Rebuilding Windows Indexing

    --------------------

    Note: This process may take a long time to complete.

    • Click Start, then Control Panel (icons view)
    • Click Indexing Options
    • Click Advanced
    • Click Rebuild, then OK
    • When completed you will see Indexing complete
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • Download link
    • Index rebuilt successfully?
     
  7. pjubber

    pjubber Private E-2

    I don't have the 'zip' file on my desktop that you mentioned. The Indexing says it completed, but it sure was fast. (145,118 items indexed)
    Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2023
    Ran by peggy (29-07-2023 19:11:21) Run:1
    Running from C:\Users\peggy\Desktop
    Loaded Profiles: peggy
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************

    Code:

    Start::
    CreateRestorePoint:
    CloseProcesses:
    Zip: C:\WINDOWS\MEMORY.DMP
    C:\WINDOWS\System32\drivers\cfwids.sys
    C:\WINDOWS\System32\drivers\mfeaack.sys
    C:\WINDOWS\System32\drivers\mfeplk.sys
    Task: {0BB54293-B32C-4293-929A-64D2A249BBA3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe /send (No File)
    Task: {D4F3419D-B4D8-485F-B7D9-32B4511ECB23} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe /f (No File)
    Task: {3E3010CA-CCD5-4191-9468-2437DF429F8F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [724384 2023-07-16] (Mozilla Corporation -> Mozilla Foundation)
    Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
    Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
    Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
    Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
    C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\enfdmlidcoffeadcfoncdbihnbidbbfn
    FF SearchPlugin: C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default\searchplugins\conservapedia-en.xml [2023-07-29]
    FF SearchPlugin: C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default\searchplugins\startpage---english.xml [2023-07-29]
    S2 HP Comm Recover; "C:\Program Files\HPCommRecovery\HPCommRecovery.exe" [X]
    S2 HPJumpStartBridge; "c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe" [X]
    S2 HPSupportSolutionsFrameworkService; "C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe" [X]
    S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77288 2017-10-17] (McAfee, Inc. -> McAfee LLC)
    S3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [492520 2017-10-17] (McAfee, Inc. -> McAfee LLC)
    S3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [115176 2017-10-17] (McAfee, Inc. -> McAfee LLC)
    S3 MpKsl01daf1ea; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    S3 MpKsl5e1ba4d3; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    S3 MpKsl6cca9f70; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    S3 MpKslf8151fa8; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{20000F88-9098-44F1-89EC-63B264673ECB}\MpKslDrv.sys [X]
    AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
    AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
    ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
    AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [274]
    FirewallRules: [{513BB25F-8FE4-4071-99C4-9423043D6204}] => (Allow) C:\Program Files\OSCAR\OSCAR.exe => No File
    FirewallRules: [{F956BF42-C3DA-4E2E-A6BB-2A5AC0D4DBBF}] => (Allow) C:\Program Files\OSCAR\OSCAR.exe => No File
    FirewallRules: [{39BD176A-45E7-4ADD-8C98-F6C27163D9C5}] => (Allow) C:\Program Files\OSCAR\OSCAR.exe => No File
    FirewallRules: [{91797645-1DCA-45BC-9F58-7C269363BD76}] => (Allow) C:\Program Files\OSCAR\OSCAR.exe => No File
    FirewallRules: [{E94CC475-9F13-4E42-9E92-1F797726E0F4}] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [{8731FFDF-DB8D-43E6-8BA6-460DDDC38932}] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [TCP Query User{FA22C86E-52E2-4915-869D-1E528C58B1C7}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [UDP Query User{C40CAD8C-994F-41D3-99EB-D6FE3BDC4084}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [{1EFDD09B-55A7-48B0-AF5A-AEC5773A0E34}] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    FirewallRules: [{49890B5D-7CA9-4576-8310-6D5696BAE647}] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe => No File
    cmd: netsh winsock reset catalog
    cmd: netsh int ip reset resetlog.txt
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state ON
    cmd: bitsadmin /reset /allusers
    cmd: ipconfig /flushdns
    Removeproxy:
    hosts:
    cmd: chkdsk
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    End::


    *****************

    Restore point was successfully created.
    Processes closed successfully.
    ================== Zip: ===================
    "C:\WINDOWS\MEMORY.DMP" => not found
    =========== Zip: End ===========
    C:\WINDOWS\System32\drivers\cfwids.sys => moved successfully
    C:\WINDOWS\System32\drivers\mfeaack.sys => moved successfully
    C:\WINDOWS\System32\drivers\mfeplk.sys => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0BB54293-B32C-4293-929A-64D2A249BBA3}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BB54293-B32C-4293-929A-64D2A249BBA3}" => removed successfully
    C:\WINDOWS\System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D4F3419D-B4D8-485F-B7D9-32B4511ECB23}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4F3419D-B4D8-485F-B7D9-32B4511ECB23}" => removed successfully
    C:\WINDOWS\System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E3010CA-CCD5-4191-9468-2437DF429F8F}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E3010CA-CCD5-4191-9468-2437DF429F8F}" => removed successfully
    C:\WINDOWS\System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB" => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully

    "C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\enfdmlidcoffeadcfoncdbihnbidbbfn" folder move:

    C:\Users\peggy\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\enfdmlidcoffeadcfoncdbihnbidbbfn => moved successfully
    C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default\searchplugins\conservapedia-en.xml => moved successfully
    C:\Users\peggy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\pjzxghku.default\searchplugins\startpage---english.xml => moved successfully
    HKLM\System\CurrentControlSet\Services\HP Comm Recover => removed successfully
    HP Comm Recover => service removed successfully
    HKLM\System\CurrentControlSet\Services\HPJumpStartBridge => removed successfully
    HPJumpStartBridge => service removed successfully
    HKLM\System\CurrentControlSet\Services\HPSupportSolutionsFrameworkService => removed successfully
    HPSupportSolutionsFrameworkService => service removed successfully
    HKLM\System\CurrentControlSet\Services\cfwids => removed successfully
    cfwids => service removed successfully
    HKLM\System\CurrentControlSet\Services\mfeaack => removed successfully
    mfeaack => service removed successfully
    HKLM\System\CurrentControlSet\Services\mfeplk => removed successfully
    mfeplk => service removed successfully
    HKLM\System\CurrentControlSet\Services\MpKsl01daf1ea => removed successfully
    MpKsl01daf1ea => service removed successfully
    HKLM\System\CurrentControlSet\Services\MpKsl5e1ba4d3 => removed successfully
    MpKsl5e1ba4d3 => service removed successfully
    HKLM\System\CurrentControlSet\Services\MpKsl6cca9f70 => removed successfully
    MpKsl6cca9f70 => service removed successfully
    HKLM\System\CurrentControlSet\Services\MpKslf8151fa8 => removed successfully
    MpKslf8151fa8 => service removed successfully
    "AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}" => removed successfully
    "AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}" => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
    HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
    C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{513BB25F-8FE4-4071-99C4-9423043D6204}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F956BF42-C3DA-4E2E-A6BB-2A5AC0D4DBBF}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{39BD176A-45E7-4ADD-8C98-F6C27163D9C5}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{91797645-1DCA-45BC-9F58-7C269363BD76}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E94CC475-9F13-4E42-9E92-1F797726E0F4}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8731FFDF-DB8D-43E6-8BA6-460DDDC38932}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FA22C86E-52E2-4915-869D-1E528C58B1C7}C:\program files (x86)\netgear genie\bin\netgeargenie.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C40CAD8C-994F-41D3-99EB-D6FE3BDC4084}C:\program files (x86)\netgear genie\bin\netgeargenie.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1EFDD09B-55A7-48B0-AF5A-AEC5773A0E34}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{49890B5D-7CA9-4576-8310-6D5696BAE647}" => removed successfully

    ========= netsh winsock reset catalog =========


    Sucessfully reset the Winsock Catalog.
    You must restart the computer in order to complete the reset.



    ========= End of CMD: =========


    ========= netsh int ip reset resetlog.txt =========

    Resetting Compartment Forwarding, OK!
    Resetting Compartment, OK!
    Resetting Control Protocol, OK!
    Resetting Echo Sequence Request, OK!
    Resetting Global, OK!
    Resetting Interface, OK!
    Resetting Anycast Address, OK!
    Resetting Multicast Address, OK!
    Resetting Unicast Address, OK!
    Resetting Neighbor, OK!
    Resetting Path, OK!
    Resetting Potential, OK!
    Resetting Prefix Policy, OK!
    Resetting Proxy Neighbor, OK!
    Resetting Route, OK!
    Resetting Site Prefix, OK!
    Resetting Subinterface, OK!
    Resetting Wakeup Pattern, OK!
    Resetting Resolve Neighbor, OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , failed.
    Access is denied.

    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Restart the computer to complete this action.



    ========= End of CMD: =========


    ========= netsh advfirewall reset =========

    Ok.



    ========= End of CMD: =========


    ========= netsh advfirewall set allprofiles state ON =========

    Ok.



    ========= End of CMD: =========


    ========= bitsadmin /reset /allusers =========


    BITSADMIN version 3.0
    BITS administration utility.
    (C) Copyright Microsoft Corp.

    0 out of 0 jobs canceled.


    ========= End of CMD: =========


    ========= ipconfig /flushdns =========


    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.


    ========= End of CMD: =========


    ========= RemoveProxy: =========

    HKU\S-1-5-21-1466392891-3797003834-4236733652-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-21-1466392891-3797003834-4236733652-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-21-1466392891-3797003834-4236733652-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


    ========= End of RemoveProxy: =========

    C:\Windows\System32\Drivers\etc\hosts => moved successfully
    Hosts restored successfully.

    ========= chkdsk =========

    The type of the file system is NTFS.
    Volume label is Windows.

    WARNING! /F parameter not specified.
    Running CHKDSK in read-only mode.

    Stage 1: Examining basic file system structure ...
    Progress: 0 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:47:55
    Progress: 108 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:47:55 .
    Progress: 661 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:48:36 ..
    Progress: 1537 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:37:48 ...
    Progress: 2561 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:32:32
    Progress: 3585 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:30:08 .
    Progress: 4353 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:29:24 ..
    Progress: 5121 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:30:07 ...
    Progress: 6145 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:29:24
    Progress: 7169 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:28:37 .
    Progress: 7937 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:27:46 ..
    Progress: 9152 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:28:12 ...
    Progress: 9874 of 996608 done; Stage: 0%; Total: 0%; ETA: 0:27:12
    Progress: 11009 of 996608 done; Stage: 1%; Total: 0%; ETA: 0:27:18 .
    Progress: 12033 of 996608 done; Stage: 1%; Total: 0%; ETA: 0:27:00 ..
    Progress: 13313 of 996608 done; Stage: 1%; Total: 0%; ETA: 0:26:13 ...
    Progress: 14337 of 996608 done; Stage: 1%; Total: 0%; ETA: 0:26:01
    Progress: 15617 of 996608 done; Stage: 1%; Total: 0%; ETA: 0:25:27 .
    Progress: 17153 of 996608 done; Stage: 1%; Total: 0%; ETA: 0:24:37 ..
    Progress: 18177 of 996608 done; Stage: 1%; Total: 0%; ETA: 0:24:31 ...
    Progress: 19457 of 996608 done; Stage: 1%; Total: 0%; ETA: 0:24:07
    Progress: 20737 of 996608 done; Stage: 2%; Total: 0%; ETA: 0:23:47 .
    Progress: 21761 of 996608 done; Stage: 2%; Total: 0%; ETA: 0:23:48 ..
    Progress: 22785 of 996608 done; Stage: 2%; Total: 0%; ETA: 0:23:47 ...
    Progress: 23818 of 996608 done; Stage: 2%; Total: 0%; ETA: 0:23:31
    Progress: 24833 of 996608 done; Stage: 2%; Total: 0%; ETA: 0:23:33 .
    Progress: 26113 of 996608 done; Stage: 2%; Total: 0%; ETA: 0:23:30 ..
    Progress: 27137 of 996608 done; Stage: 2%; Total: 0%; ETA: 0:23:19 ...
    Progress: 27896 of 996608 done; Stage: 2%; Total: 0%; ETA: 0:23:33
    Progress: 28417 of 996608 done; Stage: 2%; Total: 0%; ETA: 0:23:53 .
    Progress: 29953 of 996608 done; Stage: 3%; Total: 1%; ETA: 0:23:37 ..
    Progress: 30977 of 996608 done; Stage: 3%; Total: 1%; ETA: 0:23:36 ...
    Progress: 31745 of 996608 done; Stage: 3%; Total: 1%; ETA: 0:23:46
    Progress: 33025 of 996608 done; Stage: 3%; Total: 1%; ETA: 0:23:34 .
    Progress: 33692 of 996608 done; Stage: 3%; Total: 1%; ETA: 0:23:46 ..
    Progress: 34687 of 996608 done; Stage: 3%; Total: 1%; ETA: 0:23:44 ...
    Progress: 36097 of 996608 done; Stage: 3%; Total: 1%; ETA: 0:23:27
    Progress: 37377 of 996608 done; Stage: 3%; Total: 1%; ETA: 0:23:17 .
    Progress: 38913 of 996608 done; Stage: 3%; Total: 1%; ETA: 0:22:59 ..
    Progress: 40193 of 996608 done; Stage: 4%; Total: 1%; ETA: 0:22:49 ...
    Progress: 41985 of 996608 done; Stage: 4%; Total: 1%; ETA: 0:22:25
    Progress: 43265 of 996608 done; Stage: 4%; Total: 1%; ETA: 0:22:14 .
    Progress: 44545 of 996608 done; Stage: 4%; Total: 1%; ETA: 0:22:08 ..
    Progress: 46081 of 996608 done; Stage: 4%; Total: 1%; ETA: 0:21:55 ...
    Progress: 47873 of 996608 done; Stage: 4%; Total: 1%; ETA: 0:21:36
    Progress: 50177 of 996608 done; Stage: 5%; Total: 1%; ETA: 0:21:04 .
    Progress: 52063 of 996608 done; Stage: 5%; Total: 1%; ETA: 0:20:47 ..
    Progress: 53761 of 996608 done; Stage: 5%; Total: 1%; ETA: 0:20:29 ...
    Progress: 54785 of 996608 done; Stage: 5%; Total: 1%; ETA: 0:20:32
    Progress: 55809 of 996608 done; Stage: 5%; Total: 1%; ETA: 0:20:34 .
    Progress: 57089 of 996608 done; Stage: 5%; Total: 1%; ETA: 0:20:32 ..
    Progress: 58369 of 996608 done; Stage: 5%; Total: 2%; ETA: 0:20:29 ...
    Progress: 60004 of 996608 done; Stage: 6%; Total: 2%; ETA: 0:20:23
    Progress: 61185 of 996608 done; Stage: 6%; Total: 2%; ETA: 0:20:16 .
    Progress: 62209 of 996608 done; Stage: 6%; Total: 2%; ETA: 0:20:17 ..
    Progress: 65025 of 996608 done; Stage: 6%; Total: 2%; ETA: 0:19:45 ...
    Progress: 66561 of 996608 done; Stage: 6%; Total: 2%; ETA: 0:19:39
    Progress: 67964 of 996608 done; Stage: 6%; Total: 2%; ETA: 0:19:39 .
    Progress: 69633 of 996608 done; Stage: 6%; Total: 2%; ETA: 0:19:27 ..
    Progress: 71169 of 996608 done; Stage: 7%; Total: 2%; ETA: 0:19:21 ...
    Progress: 71937 of 996608 done; Stage: 7%; Total: 2%; ETA: 0:19:28
    Progress: 73217 of 996608 done; Stage: 7%; Total: 2%; ETA: 0:19:26 .
    Progress: 74241 of 996608 done; Stage: 7%; Total: 2%; ETA: 0:19:29 ..
    Progress: 75009 of 996608 done; Stage: 7%; Total: 2%; ETA: 0:19:36 ...
    Progress: 75521 of 996608 done; Stage: 7%; Total: 2%; ETA: 0:19:41
    Progress: 76801 of 996608 done; Stage: 7%; Total: 2%; ETA: 0:19:44 .
    Progress: 78081 of 996608 done; Stage: 7%; Total: 2%; ETA: 0:19:42 ..
    Progress: 79105 of 996608 done; Stage: 7%; Total: 2%; ETA: 0:19:44 ...
    Progress: 80897 of 996608 done; Stage: 8%; Total: 2%; ETA: 0:19:34
    Progress: 82227 of 996608 done; Stage: 8%; Total: 2%; ETA: 0:19:34 .
    Progress: 83713 of 996608 done; Stage: 8%; Total: 2%; ETA: 0:19:27 ..
    Progress: 85249 of 996608 done; Stage: 8%; Total: 2%; ETA: 0:19:21 ...
    Progress: 86529 of 996608 done; Stage: 8%; Total: 2%; ETA: 0:19:21
    Progress: 87809 of 996608 done; Stage: 8%; Total: 3%; ETA: 0:19:18 .
    Progress: 88575 of 996608 done; Stage: 8%; Total: 3%; ETA: 0:19:24 ..
    Progress: 90881 of 996608 done; Stage: 9%; Total: 3%; ETA: 0:19:11 ...
    Progress: 92929 of 996608 done; Stage: 9%; Total: 3%; ETA: 0:18:59
    Progress: 93322 of 996608 done; Stage: 9%; Total: 3%; ETA: 0:18:58 .
    Progress: 94137 of 996608 done; Stage: 9%; Total: 3%; ETA: 0:19:12 ..
    Progress: 95233 of 996608 done; Stage: 9%; Total: 3%; ETA: 0:19:12 ...
    Progress: 97279 of 996608 done; Stage: 9%; Total: 3%; ETA: 0:19:03
    Progress: 99073 of 996608 done; Stage: 9%; Total: 3%; ETA: 0:18:54 .
    Progress: 100865 of 996608 done; Stage: 10%; Total: 3%; ETA: 0:18:44 ..
    Progress: 103169 of 996608 done; Stage: 10%; Total: 3%; ETA: 0:18:33 ...
    Progress: 104449 of 996608 done; Stage: 10%; Total: 3%; ETA: 0:18:32
    Progress: 106753 of 996608 done; Stage: 10%; Total: 3%; ETA: 0:18:21 .
    Progress: 108033 of 996608 done; Stage: 10%; Total: 3%; ETA: 0:18:19 ..
    Progress: 110849 of 996608 done; Stage: 11%; Total: 3%; ETA: 0:18:04 ...
    Progress: 112444 of 996608 done; Stage: 11%; Total: 3%; ETA: 0:18:00
    Progress: 113197 of 996608 done; Stage: 11%; Total: 3%; ETA: 0:18:03 .
    Progress: 114433 of 996608 done; Stage: 11%; Total: 3%; ETA: 0:18:04 ..
    Progress: 117030 of 996608 done; Stage: 11%; Total: 4%; ETA: 0:17:52 ...
    Progress: 118785 of 996608 done; Stage: 11%; Total: 4%; ETA: 0:17:47
    Progress: 120065 of 996608 done; Stage: 12%; Total: 4%; ETA: 0:17:47 .
    Progress: 121857 of 996608 done; Stage: 12%; Total: 4%; ETA: 0:17:42 ..
    Progress: 123649 of 996608 done; Stage: 12%; Total: 4%; ETA: 0:17:37 ...
    Progress: 125185 of 996608 done; Stage: 12%; Total: 4%; ETA: 0:17:34
    Progress: 128001 of 996608 done; Stage: 12%; Total: 4%; ETA: 0:17:20 .
    Progress: 130049 of 996608 done; Stage: 13%; Total: 4%; ETA: 0:17:15 ..
    Progress: 132458 of 996608 done; Stage: 13%; Total: 4%; ETA: 0:17:05 ...
    Progress: 137348 of 996608 done; Stage: 13%; Total: 4%; ETA: 0:16:36
    Progress: 139777 of 996608 done; Stage: 14%; Total: 4%; ETA: 0:16:27 .
    Progress: 141825 of 996608 done; Stage: 14%; Total: 4%; ETA: 0:16:22 ..
    Progress: 144129 of 996608 done; Stage: 14%; Total: 4%; ETA: 0:16:17 ...
    Progress: 147969 of 996608 done; Stage: 14%; Total: 5%; ETA: 0:15:58
    Progress: 150501 of 996608 done; Stage: 15%; Total: 5%; ETA: 0:15:52 .
    Progress: 153089 of 996608 done; Stage: 15%; Total: 5%; ETA: 0:15:44 ..
    Progress: 155137 of 996608 done; Stage: 15%; Total: 5%; ETA: 0:15:39 ...
    Progress: 158274 of 996608 done; Stage: 15%; Total: 5%; ETA: 0:15:28
    Progress: 161281 of 996608 done; Stage: 16%; Total: 5%; ETA: 0:15:18 .
    Progress: 165889 of 996608 done; Stage: 16%; Total: 5%; ETA: 0:15:00 ..
    Progress: 169729 of 996608 done; Stage: 17%; Total: 5%; ETA: 0:14:46 ...
    Progress: 171530 of 996608 done; Stage: 17%; Total: 5%; ETA: 0:14:43
    Progress: 172212 of 996608 done; Stage: 17%; Total: 5%; ETA: 0:14:44 .
    Progress: 173707 of 996608 done; Stage: 17%; Total: 6%; ETA: 0:14:43 ..
    Progress: 175172 of 996608 done; Stage: 17%; Total: 6%; ETA: 0:14:41 ...
    Progress: 178177 of 996608 done; Stage: 17%; Total: 6%; ETA: 0:14:32
    Progress: 180481 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:28 .
    Progress: 182529 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:25 ..
    Progress: 183553 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:25 ...
    Progress: 185332 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:25
    Progress: 188161 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:16 .
    Progress: 188313 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:20 ..
    Progress: 188417 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:25 ...
    Progress: 188556 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:32
    Progress: 188673 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:36 .
    Progress: 188776 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:41 ..
    Progress: 188873 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:46 ...
    Progress: 188962 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:52
    Progress: 189110 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:14:57 .
    Progress: 189334 of 996608 done; Stage: 18%; Total: 6%; ETA: 0:15:00 ..
    Progress: 189688 of 996608 done; Stage: 19%; Total: 6%; ETA: 0:15:04 ...
    Progress: 194561 of 996608 done; Stage: 19%; Total: 6%; ETA: 0:14:44
    Progress: 195841 of 996608 done; Stage: 19%; Total: 6%; ETA: 0:14:46 .
    Progress: 196865 of 996608 done; Stage: 19%; Total: 7%; ETA: 0:14:48 ..
    Progress: 198145 of 996608 done; Stage: 19%; Total: 7%; ETA: 0:14:48 ...
    Progress: 199937 of 996608 done; Stage: 20%; Total: 7%; ETA: 0:14:46
    Progress: 200716 of 996608 done; Stage: 20%; Total: 7%; ETA: 0:14:46 .
    Progress: 201556 of 996608 done; Stage: 20%; Total: 7%; ETA: 0:14:49 ..
    Progress: 202613 of 996608 done; Stage: 20%; Total: 7%; ETA: 0:14:49 ...
    Progress: 203063 of 996608 done; Stage: 20%; Total: 7%; ETA: 0:14:52
    Progress: 204021 of 996608 done; Stage: 20%; Total: 7%; ETA: 0:14:54 .
    Progress: 206803 of 996608 done; Stage: 20%; Total: 7%; ETA: 0:14:46 ..
    Progress: 208447 of 996608 done; Stage: 20%; Total: 7%; ETA: 0:14:43 ...
    Progress: 209656 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:14:41
    Progress: 210090 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:14:44 .
    Progress: 210383 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:14:49 ..
    Progress: 210548 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:14:54 ...
    Progress: 210745 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:14:59
    Progress: 211120 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:02 .
    Progress: 212037 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:04 ..
    Progress: 212526 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:07 ...
    Progress: 212830 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:10
    Progress: 213452 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:13 .
    Progress: 213477 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:18 ..
    Progress: 214047 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:21 ...
    Progress: 215115 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:21
    Progress: 216149 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:21 .
    Progress: 216612 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:23 ..
    Progress: 216789 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:26 ...
    Progress: 216970 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:29
    Progress: 217479 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:32 .
    Progress: 218476 of 996608 done; Stage: 21%; Total: 7%; ETA: 0:15:32 ..
    Progress: 219400 of 996608 done; Stage: 22%; Total: 8%; ETA: 0:15:31 ...
    Progress: 219950 of 996608 done; Stage: 22%; Total: 8%; ETA: 0:15:35
    Progress: 221073 of 996608 done; Stage: 22%; Total: 8%; ETA: 0:15:32 .
    Progress: 224280 of 996608 done; Stage: 22%; Total: 8%; ETA: 0:15:23 ..
    Progress: 226365 of 996608 done; Stage: 22%; Total: 8%; ETA: 0:15:18 ...
    Progress: 228536 of 996608 done; Stage: 22%; Total: 8%; ETA: 0:15:12
    Progress: 233729 of 996608 done; Stage: 23%; Total: 8%; ETA: 0:14:56 .
    Progress: 240129 of 996608 done; Stage: 24%; Total: 8%; ETA: 0:14:36 ..
    Progress: 251137 of 996608 done; Stage: 25%; Total: 9%; ETA: 0:14:03 ...
    Progress: 258817 of 996608 done; Stage: 25%; Total: 9%; ETA: 0:13:42
    Progress: 262657 of 996608 done; Stage: 26%; Total: 9%; ETA: 0:13:34 .
    Progress: 267777 of 996608 done; Stage: 26%; Total: 9%; ETA: 0:13:23 ..
    Progress: 271361 of 996608 done; Stage: 27%; Total: 9%; ETA: 0:13:16 ...
    Progress: 273409 of 996608 done; Stage: 27%; Total: 9%; ETA: 0:13:15
    Progress: 277366 of 996608 done; Stage: 27%; Total: 10%; ETA: 0:13:08 .
    Progress: 281158 of 996608 done; Stage: 28%; Total: 10%; ETA: 0:13:00 ..
    Progress: 282180 of 996608 done; Stage: 28%; Total: 10%; ETA: 0:13:00 ...
    Progress: 284381 of 996608 done; Stage: 28%; Total: 10%; ETA: 0:12:57
    Progress: 287848 of 996608 done; Stage: 28%; Total: 10%; ETA: 0:12:52 .
    Progress: 291585 of 996608 done; Stage: 29%; Total: 10%; ETA: 0:12:46 ..
    Progress: 294299 of 996608 done; Stage: 29%; Total: 10%; ETA: 0:12:41 ...
    Progress: 296908 of 996608 done; Stage: 29%; Total: 10%; ETA: 0:12:39
    Progress: 298241 of 996608 done; Stage: 29%; Total: 10%; ETA: 0:12:38 .
    Progress: 301825 of 996608 done; Stage: 30%; Total: 10%; ETA: 0:12:31 ..
    Progress: 303361 of 996608 done; Stage: 30%; Total: 11%; ETA: 0:12:31 ...
    Progress: 306308 of 996608 done; Stage: 30%; Total: 11%; ETA: 0:12:27
    Progress: 312577 of 996608 done; Stage: 31%; Total: 11%; ETA: 0:12:15 .
    Progress: 316901 of 996608 done; Stage: 31%; Total: 11%; ETA: 0:12:09 ..
    Progress: 325685 of 996608 done; Stage: 32%; Total: 11%; ETA: 0:11:51 ...
    Progress: 338177 of 996608 done; Stage: 33%; Total: 12%; ETA: 0:11:26
    Progress: 342349 of 996608 done; Stage: 34%; Total: 12%; ETA: 0:11:21 .
    Progress: 346625 of 996608 done; Stage: 34%; Total: 12%; ETA: 0:11:15 ..
    Progress: 349592 of 996608 done; Stage: 35%; Total: 12%; ETA: 0:11:10 ...
    Progress: 366714 of 996608 done; Stage: 36%; Total: 13%; ETA: 0:10:41
    Progress: 381697 of 996608 done; Stage: 38%; Total: 13%; ETA: 0:10:15 .
    Progress: 390401 of 996608 done; Stage: 39%; Total: 14%; ETA: 0:10:03 ..
    Progress: 403457 of 996608 done; Stage: 40%; Total: 14%; ETA: 0:09:45 ...
    Progress: 406673 of 996608 done; Stage: 40%; Total: 14%; ETA: 0:09:43
    Progress: 411905 of 996608 done; Stage: 41%; Total: 14%; ETA: 0:09:37 .
    Progress: 420353 of 996608 done; Stage: 42%; Total: 15%; ETA: 0:09:27 ..
    Progress: 430337 of 996608 done; Stage: 43%; Total: 15%; ETA: 0:09:16 ...
    Progress: 438017 of 996608 done; Stage: 43%; Total: 15%; ETA: 0:09:08
    Progress: 444673 of 996608 done; Stage: 44%; Total: 15%; ETA: 0:09:00 .
    Progress: 450049 of 996608 done; Stage: 45%; Total: 16%; ETA: 0:08:56 ..
    Progress: 453633 of 996608 done; Stage: 45%; Total: 16%; ETA: 0:08:54 ...
    Progress: 456449 of 996608 done; Stage: 45%; Total: 16%; ETA: 0:08:52
    Progress: 459009 of 996608 done; Stage: 46%; Total: 16%; ETA: 0:08:52 .
    Progress: 465149 of 996608 done; Stage: 46%; Total: 16%; ETA: 0:08:47 ..
    Progress: 478721 of 996608 done; Stage: 48%; Total: 17%; ETA: 0:08:31 ...
    Progress: 481327 of 996608 done; Stage: 48%; Total: 17%; ETA: 0:08:30
    Progress: 483639 of 996608 done; Stage: 48%; Total: 17%; ETA: 0:08:28 .
    Progress: 485152 of 996608 done; Stage: 48%; Total: 17%; ETA: 0:08:27 ..
    Progress: 486657 of 996608 done; Stage: 48%; Total: 17%; ETA: 0:08:27 ...
    Progress: 489217 of 996608 done; Stage: 49%; Total: 17%; ETA: 0:08:27
    Progress: 492801 of 996608 done; Stage: 49%; Total: 17%; ETA: 0:08:25 .
    Progress: 494849 of 996608 done; Stage: 49%; Total: 17%; ETA: 0:08:25 ..
    Progress: 497665 of 996608 done; Stage: 49%; Total: 17%; ETA: 0:08:24 ...
    Progress: 502529 of 996608 done; Stage: 50%; Total: 17%; ETA: 0:08:20
    Progress: 509137 of 996608 done; Stage: 51%; Total: 18%; ETA: 0:08:15 .
    Progress: 517889 of 996608 done; Stage: 51%; Total: 18%; ETA: 0:08:07 ..
    Progress: 520961 of 996608 done; Stage: 52%; Total: 18%; ETA: 0:08:06 ...
    Progress: 536577 of 996608 done; Stage: 53%; Total: 19%; ETA: 0:07:51
    Progress: 546561 of 996608 done; Stage: 54%; Total: 19%; ETA: 0:07:43 .
    Progress: 548194 of 996608 done; Stage: 55%; Total: 19%; ETA: 0:07:43 ..
    Progress: 549633 of 996608 done; Stage: 55%; Total: 19%; ETA: 0:07:43 ...
    Progress: 554241 of 996608 done; Stage: 55%; Total: 19%; ETA: 0:07:42
    Progress: 564247 of 996608 done; Stage: 56%; Total: 20%; ETA: 0:07:34 .
    Progress: 593009 of 996608 done; Stage: 59%; Total: 21%; ETA: 0:07:10 ..
    Progress: 621194 of 996608 done; Stage: 62%; Total: 22%; ETA: 0:06:47 ...
    Progress: 630529 of 996608 done; Stage: 63%; Total: 22%; ETA: 0:06:41
    Progress: 632085 of 996608 done; Stage: 63%; Total: 22%; ETA: 0:06:41 .
    Progress: 634625 of 996608 done; Stage: 63%; Total: 22%; ETA: 0:06:41 ..
    Progress: 636417 of 996608 done; Stage: 63%; Total: 22%; ETA: 0:06:41 ...
    Progress: 650241 of 996608 done; Stage: 65%; Total: 23%; ETA: 0:06:33
    Progress: 671489 of 996608 done; Stage: 67%; Total: 23%; ETA: 0:06:19 .
    Progress: 700929 of 996608 done; Stage: 70%; Total: 24%; ETA: 0:05:59 ..
    Progress: 734977 of 996608 done; Stage: 73%; Total: 25%; ETA: 0:05:40 ...
    Progress: 777932 of 996608 done; Stage: 78%; Total: 27%; ETA: 0:05:16
    Progress: 781313 of 996608 done; Stage: 78%; Total: 27%; ETA: 0:05:16 .
    Progress: 782593 of 996608 done; Stage: 78%; Total: 27%; ETA: 0:05:16 ..
    Progress: 787835 of 996608 done; Stage: 79%; Total: 27%; ETA: 0:05:15 ...
    Progress: 813689 of 996608 done; Stage: 81%; Total: 28%; ETA: 0:05:03
    Progress: 826881 of 996608 done; Stage: 82%; Total: 29%; ETA: 0:04:57 .
    Progress: 835585 of 996608 done; Stage: 83%; Total: 29%; ETA: 0:04:54 ..
    Progress: 836353 of 996608 done; Stage: 83%; Total: 29%; ETA: 0:04:54 ...
    Progress: 838574 of 996608 done; Stage: 84%; Total: 29%; ETA: 0:04:54
    Progress: 839681 of 996608 done; Stage: 84%; Total: 29%; ETA: 0:04:54 .
    Progress: 874241 of 996608 done; Stage: 87%; Total: 30%; ETA: 0:04:39 ..
    Progress: 916737 of 996608 done; Stage: 91%; Total: 32%; ETA: 0:04:23 ...
    Progress: 932865 of 996608 done; Stage: 93%; Total: 32%; ETA: 0:04:17
    Progress: 934809 of 996608 done; Stage: 93%; Total: 32%; ETA: 0:04:17 .
    Progress: 936193 of 996608 done; Stage: 93%; Total: 33%; ETA: 0:04:17 ..
    Progress: 937985 of 996608 done; Stage: 94%; Total: 33%; ETA: 0:04:17 ...
    Progress: 949249 of 996608 done; Stage: 95%; Total: 33%; ETA: 0:04:14
    Progress: 979713 of 996608 done; Stage: 98%; Total: 34%; ETA: 0:04:04 .
    Progress: 996608 of 996608 done; Stage: 100%; Total: 35%; ETA: 0:03:58 ..


    996608 file records processed.
     
  8. pjubber

    pjubber Private E-2

    File verification completed.
    Phase duration (File record verification): 2.12 minutes.
    Progress: 12745 of 12745 done; Stage: 100%; Total: 26%; ETA: 0:05:52 ...


    12745 large file records processed.

    Phase duration (Orphan file record recovery): 0.00 milliseconds.
    Progress: 0 of 0 done; Stage: 99%; Total: 26%; ETA: 0:05:52


    0 bad file records processed.

    Phase duration (Bad file record checking): 0.19 milliseconds.

    Stage 2: Examining file name linkage ...
    Progress: 1274 of 1283638 done; Stage: 0%; Total: 26%; ETA: 0:05:51 .
    Progress: 8110 of 1283638 done; Stage: 0%; Total: 26%; ETA: 0:05:50 ..
    Progress: 12590 of 1283638 done; Stage: 0%; Total: 27%; ETA: 0:05:50 ...
    Progress: 15022 of 1283638 done; Stage: 1%; Total: 27%; ETA: 0:05:50
    Progress: 17198 of 1283638 done; Stage: 1%; Total: 27%; ETA: 0:05:50 .
    Progress: 19630 of 1283638 done; Stage: 1%; Total: 27%; ETA: 0:05:50 ..
    Progress: 21294 of 1283638 done; Stage: 1%; Total: 27%; ETA: 0:05:50 ...
    Progress: 53450 of 1283638 done; Stage: 4%; Total: 28%; ETA: 0:05:37
    Progress: 137164 of 1283638 done; Stage: 10%; Total: 30%; ETA: 0:05:05 .
    Progress: 212334 of 1283638 done; Stage: 16%; Total: 32%; ETA: 0:04:38 ..
    Progress: 292200 of 1283638 done; Stage: 22%; Total: 34%; ETA: 0:04:14 ...
    Progress: 375495 of 1283638 done; Stage: 29%; Total: 36%; ETA: 0:03:51
    Progress: 449776 of 1283638 done; Stage: 35%; Total: 38%; ETA: 0:03:34 .
    Progress: 534751 of 1283638 done; Stage: 41%; Total: 40%; ETA: 0:03:16 ..
    Progress: 621577 of 1283638 done; Stage: 48%; Total: 43%; ETA: 0:02:59 ...
    Progress: 808161 of 1283638 done; Stage: 62%; Total: 48%; ETA: 0:02:28
    Progress: 3462 of 73652 done; Stage: 4%; Total: 53%; ETA: 0:02:01 .
    Progress: 73652 of 73652 done; Stage: 100%; Total: 55%; ETA: 0:01:50 ..


    73652 reparse records processed.

    Progress: 996659 of 1283638 done; Stage: 77%; Total: 55%; ETA: 0:01:50 ...
    Progress: 996789 of 1283638 done; Stage: 77%; Total: 55%; ETA: 0:01:50
    Progress: 996995 of 1283638 done; Stage: 77%; Total: 55%; ETA: 0:01:50 .
    Progress: 997243 of 1283638 done; Stage: 77%; Total: 55%; ETA: 0:01:50 ..
    Progress: 997783 of 1283638 done; Stage: 77%; Total: 55%; ETA: 0:01:50 ...
    Progress: 997925 of 1283638 done; Stage: 77%; Total: 55%; ETA: 0:01:50
    Progress: 998028 of 1283638 done; Stage: 77%; Total: 55%; ETA: 0:01:50 .
    Progress: 998200 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50 ..
    Progress: 998305 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50 ...
    Progress: 998400 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50
    Progress: 998518 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50 .
    Progress: 998789 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50 ..
    Progress: 999084 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50 ...
    Progress: 999277 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50
    Progress: 999421 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50 .
    Progress: 999582 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50 ..
    Progress: 999865 of 1283638 done; Stage: 77%; Total: 56%; ETA: 0:01:50 ...
    Progress: 1000052 of 1283638 done; Stage: 77%; Total: 57%; ETA: 0:01:50
    Progress: 1000270 of 1283638 done; Stage: 77%; Total: 57%; ETA: 0:01:50 .
    Progress: 1000401 of 1283638 done; Stage: 77%; Total: 57%; ETA: 0:01:50 ..
    Progress: 1000621 of 1283638 done; Stage: 77%; Total: 57%; ETA: 0:01:50 ...
    Progress: 1000802 of 1283638 done; Stage: 77%; Total: 57%; ETA: 0:01:50
    Progress: 1000935 of 1283638 done; Stage: 77%; Total: 57%; ETA: 0:01:50 .
    Progress: 1001032 of 1283638 done; Stage: 77%; Total: 57%; ETA: 0:01:50 ..
    Progress: 1001230 of 1283638 done; Stage: 77%; Total: 57%; ETA: 0:01:50 ...
    Progress: 1001390 of 1283638 done; Stage: 78%; Total: 57%; ETA: 0:01:50
    Progress: 1001581 of 1283638 done; Stage: 78%; Total: 57%; ETA: 0:01:50 .
    Progress: 1001724 of 1283638 done; Stage: 78%; Total: 57%; ETA: 0:01:50 ..
    Progress: 1001915 of 1283638 done; Stage: 78%; Total: 57%; ETA: 0:01:50 ...
    Progress: 1002041 of 1283638 done; Stage: 78%; Total: 57%; ETA: 0:01:50
    Progress: 1002191 of 1283638 done; Stage: 78%; Total: 57%; ETA: 0:01:50 .
    Progress: 1002408 of 1283638 done; Stage: 78%; Total: 57%; ETA: 0:01:50 ..
    Progress: 1002589 of 1283638 done; Stage: 78%; Total: 58%; ETA: 0:01:50 ...
    Progress: 1002792 of 1283638 done; Stage: 78%; Total: 58%; ETA: 0:01:50
    Progress: 1002973 of 1283638 done; Stage: 78%; Total: 58%; ETA: 0:01:50 .
    Progress: 1003148 of 1283638 done; Stage: 78%; Total: 58%; ETA: 0:01:50 ..
    Progress: 1003470 of 1283638 done; Stage: 78%; Total: 58%; ETA: 0:01:50 ...
    Progress: 1003846 of 1283638 done; Stage: 78%; Total: 58%; ETA: 0:01:50
    Progress: 1003901 of 1283638 done; Stage: 78%; Total: 58%; ETA: 0:01:50 .
    Progress: 1004027 of 1283638 done; Stage: 78%; Total: 58%; ETA: 0:01:50 ..
    Progress: 1004161 of 1283638 done; Stage: 78%; Total: 61%; ETA: 0:01:49 ...
    Progress: 1004299 of 1283638 done; Stage: 78%; Total: 61%; ETA: 0:01:39
    Progress: 1004572 of 1283638 done; Stage: 78%; Total: 61%; ETA: 0:01:39 .
    Progress: 1004624 of 1283638 done; Stage: 78%; Total: 64%; ETA: 0:01:38 ..
    Progress: 1004667 of 1283638 done; Stage: 78%; Total: 64%; ETA: 0:01:27 ...
    Progress: 1004871 of 1283638 done; Stage: 78%; Total: 64%; ETA: 0:01:27
    Progress: 1005052 of 1283638 done; Stage: 78%; Total: 64%; ETA: 0:01:27 .
    Progress: 1005322 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:27 ..
    Progress: 1005487 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:27 ...
    Progress: 1005790 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:27
    Progress: 1005929 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:27 .
    Progress: 1006064 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:27 ..
    Progress: 1006227 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:28 ...
    Progress: 1006427 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:28
    Progress: 1006928 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:28 .
    Progress: 1007834 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:27 ..
    Progress: 1007969 of 1283638 done; Stage: 78%; Total: 65%; ETA: 0:01:27 ...
    Progress: 1008058 of 1283638 done; Stage: 78%; Total: 66%; ETA: 0:01:26
    Progress: 1008763 of 1283638 done; Stage: 78%; Total: 66%; ETA: 0:01:26 .
    Progress: 1008965 of 1283638 done; Stage: 78%; Total: 66%; ETA: 0:01:26 ..
    Progress: 1009218 of 1283638 done; Stage: 78%; Total: 66%; ETA: 0:01:26 ...
    Progress: 1009424 of 1283638 done; Stage: 78%; Total: 66%; ETA: 0:01:26
    Progress: 1009672 of 1283638 done; Stage: 78%; Total: 66%; ETA: 0:01:26 .
    Progress: 1009981 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:26 ..
    Progress: 1009995 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:24 ...
    Progress: 1010611 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23
    Progress: 1010862 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23 .
    Progress: 1011209 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23 ..
    Progress: 1011583 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23 ...
    Progress: 1011803 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23
    Progress: 1012061 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23 .
    Progress: 1012360 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23 ..
    Progress: 1012594 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23 ...
    Progress: 1012876 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23
    Progress: 1013257 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23 .
    Progress: 1013631 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23 ..
    Progress: 1013891 of 1283638 done; Stage: 78%; Total: 67%; ETA: 0:01:23 ...
    Progress: 1014232 of 1283638 done; Stage: 79%; Total: 67%; ETA: 0:01:23
    Progress: 1014898 of 1283638 done; Stage: 79%; Total: 67%; ETA: 0:01:23 .
    Progress: 1015154 of 1283638 done; Stage: 79%; Total: 67%; ETA: 0:01:23 ..
    Progress: 1015564 of 1283638 done; Stage: 79%; Total: 67%; ETA: 0:01:23 ...
    Progress: 1015938 of 1283638 done; Stage: 79%; Total: 67%; ETA: 0:01:23
    Progress: 1016507 of 1283638 done; Stage: 79%; Total: 67%; ETA: 0:01:24 .
    Progress: 1016987 of 1283638 done; Stage: 79%; Total: 67%; ETA: 0:01:24 ..
    Progress: 1017413 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 ...
    Progress: 1017633 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24
    Progress: 1018134 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 .
    Progress: 1018459 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 ..
    Progress: 1018889 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 ...
    Progress: 1019132 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24
    Progress: 1019342 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 .
    Progress: 1019827 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 ..
    Progress: 1020284 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 ...
    Progress: 1020689 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24
    Progress: 1021142 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 .
    Progress: 1021726 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 ..
    Progress: 1022276 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 ...
    Progress: 1022884 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24
    Progress: 1023568 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 .
    Progress: 1024084 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 ..
    Progress: 1024603 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 ...
    Progress: 1025132 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24
    Progress: 1025816 of 1283638 done; Stage: 79%; Total: 68%; ETA: 0:01:24 .
    Progress: 1025960 of 1283638 done; Stage: 79%; Total: 70%; ETA: 0:01:24 ..
    Progress: 1025990 of 1283638 done; Stage: 79%; Total: 70%; ETA: 0:01:21 ...
    Progress: 1026184 of 1283638 done; Stage: 79%; Total: 70%; ETA: 0:01:19
    Progress: 1026669 of 1283638 done; Stage: 79%; Total: 71%; ETA: 0:01:18 .
    Progress: 1027526 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:18 ..
    Progress: 1028162 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:18 ...
    Progress: 1029184 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:18
    Progress: 1029854 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:18 .
    Progress: 1030317 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:18 ..
    Progress: 1031058 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:18 ...
    Progress: 1031870 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:18
    Progress: 1032521 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:16 .
    Progress: 1033121 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:16 ..
    Progress: 1033524 of 1283638 done; Stage: 80%; Total: 71%; ETA: 0:01:16 ...
    Progress: 1033822 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16
    Progress: 1034054 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16 .
    Progress: 1034307 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16 ..
    Progress: 1034456 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16 ...
    Progress: 1034555 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16
    Progress: 1034743 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16 .
    Progress: 1034966 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16 ..
    Progress: 1035211 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16 ...
    Progress: 1035694 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16
    Progress: 1036029 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16 .
    Progress: 1036148 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16 ..
    Progress: 1036339 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16 ...
    Progress: 1036430 of 1283638 done; Stage: 80%; Total: 72%; ETA: 0:01:16
    Progress: 1036470 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:16 .
    Progress: 1036521 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 ..
    Progress: 1036595 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 ...
    Progress: 1036693 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15
    Progress: 1036838 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 .
    Progress: 1036935 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 ..
    Progress: 1037131 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 ...
    Progress: 1037500 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15
    Progress: 1037735 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 .
    Progress: 1037982 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 ..
    Progress: 1038137 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 ...
    Progress: 1038389 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15
    Progress: 1038629 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 .
    Progress: 1038876 of 1283638 done; Stage: 80%; Total: 73%; ETA: 0:01:15 ..
    Progress: 1039426 of 1283638 done; Stage: 80%; Total: 74%; ETA: 0:01:15 ...
    Progress: 1039937 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:15
    Progress: 1040366 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:15 .
    Progress: 1041389 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:15 ..
    Progress: 1042238 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:15 ...
    Progress: 1042463 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:15
    Progress: 1042806 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:13 .
    Progress: 1043098 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:13 ..
    Progress: 1043702 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:13 ...
    Progress: 1043986 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:13
    Progress: 1044976 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:13 .
    Progress: 1045387 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:13 ..
    Progress: 1046179 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:13 ...
    Progress: 1046885 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:13
    Progress: 1048415 of 1283638 done; Stage: 81%; Total: 74%; ETA: 0:01:13 .
    Progress: 1052124 of 1283638 done; Stage: 81%; Total: 75%; ETA: 0:01:13 ..
    Progress: 1054316 of 1283638 done; Stage: 82%; Total: 75%; ETA: 0:01:13 ...
    Progress: 1056120 of 1283638 done; Stage: 82%; Total: 75%; ETA: 0:01:13
    Progress: 1057809 of 1283638 done; Stage: 82%; Total: 75%; ETA: 0:01:13 .
    Progress: 1059021 of 1283638 done; Stage: 82%; Total: 75%; ETA: 0:01:13 ..
    Progress: 1059341 of 1283638 done; Stage: 82%; Total: 75%; ETA: 0:01:13 ...
    Progress: 1062201 of 1283638 done; Stage: 82%; Total: 75%; ETA: 0:01:11
    Progress: 1067705 of 1283638 done; Stage: 83%; Total: 75%; ETA: 0:01:11 .
    Progress: 1070129 of 1283638 done; Stage: 83%; Total: 75%; ETA: 0:01:11 ..
    Progress: 1070701 of 1283638 done; Stage: 83%; Total: 75%; ETA: 0:01:11 ...
    Progress: 1071589 of 1283638 done; Stage: 83%; Total: 75%; ETA: 0:01:11
    Progress: 1074009 of 1283638 done; Stage: 83%; Total: 75%; ETA: 0:01:11 .
    Progress: 1079868 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ..
    Progress: 1082452 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ...
    Progress: 1082624 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10
    Progress: 1082814 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 .
    Progress: 1082946 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ..
    Progress: 1083157 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ...
    Progress: 1083541 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10
    Progress: 1083940 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 .
    Progress: 1084029 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ..
    Progress: 1084233 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ...
    Progress: 1084326 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10
    Progress: 1084421 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 .
    Progress: 1084526 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ..
    Progress: 1084717 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ...
    Progress: 1084809 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10
    Progress: 1084918 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 .
    Progress: 1085015 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ..
    Progress: 1085109 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ...
    Progress: 1085178 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10
    Progress: 1085270 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 .
    Progress: 1085352 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ..
    Progress: 1085403 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ...
    Progress: 1085593 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10
    Progress: 1085699 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 .
    Progress: 1086032 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ..
    Progress: 1086185 of 1283638 done; Stage: 84%; Total: 76%; ETA: 0:01:10 ...
    Progress: 1086462 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10
    Progress: 1086717 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 .
    Progress: 1086796 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 ..
    Progress: 1087132 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 ...
    Progress: 1087728 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10
    Progress: 1087785 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 .
    Progress: 1088124 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 ..
    Progress: 1088223 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 ...
    Progress: 1088402 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10
    Progress: 1088667 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 .
    Progress: 1088754 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 ..
    Progress: 1088864 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 ...
    Progress: 1089062 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10
    Progress: 1089314 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 .
    Progress: 1089563 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 ..
    Progress: 1089888 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 ...
    Progress: 1090142 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10
    Progress: 1090532 of 1283638 done; Stage: 84%; Total: 77%; ETA: 0:01:10 .
    Progress: 1091115 of 1283638 done; Stage: 85%; Total: 77%; ETA: 0:01:10 ..
    Progress: 1091462 of 1283638 done; Stage: 85%; Total: 77%; ETA: 0:01:10 ...
    Progress: 1091568 of 1283638 done; Stage: 85%; Total: 77%; ETA: 0:01:10
    Progress: 1091755 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:10 .
    Progress: 1092081 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:10 ..
    Progress: 1092432 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:10 ...
    Progress: 1092722 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:10
    Progress: 1092950 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:10 .
    Progress: 1093453 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:10 ..
    Progress: 1093909 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:10 ...
    Progress: 1094241 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:10
    Progress: 1094742 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:10 .
    Progress: 1094982 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:08 ..
    Progress: 1095072 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:08 ...
    Progress: 1095239 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:08
    Progress: 1095634 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:08 .
    Progress: 1096505 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:08 ..
    Progress: 1097249 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:08 ...
    Progress: 1098300 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:08
    Progress: 1099286 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:08 .
    Progress: 1100611 of 1283638 done; Stage: 85%; Total: 78%; ETA: 0:01:08 ..
    Progress: 1104623 of 1283638 done; Stage: 86%; Total: 79%; ETA: 0:01:08 ...
    Progress: 1108091 of 1283638 done; Stage: 86%; Total: 79%; ETA: 0:01:08
    Progress: 1111078 of 1283638 done; Stage: 86%; Total: 79%; ETA: 0:01:08 .
    Progress: 1114401 of 1283638 done; Stage: 86%; Total: 79%; ETA: 0:01:08 ..
    Progress: 1119861 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ...
    Progress: 1120817 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07
    Progress: 1120841 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 .
    Progress: 1120947 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ..
    Progress: 1121084 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ...
    Progress: 1121160 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07
    Progress: 1121220 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 .
    Progress: 1121277 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ..
    Progress: 1121366 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ...
    Progress: 1121517 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07
    Progress: 1121654 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 .
    Progress: 1121888 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ..
    Progress: 1122317 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ...
    Progress: 1122654 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07
    Progress: 1123102 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 .
    Progress: 1123536 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ..
    Progress: 1123994 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ...
    Progress: 1124953 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07
    Progress: 1125611 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 .
    Progress: 1126117 of 1283638 done; Stage: 87%; Total: 79%; ETA: 0:01:07 ..
    Progress: 1129069 of 1283638 done; Stage: 87%; Total: 80%; ETA: 0:01:07 ...
    Progress: 1131734 of 1283638 done; Stage: 88%; Total: 80%; ETA: 0:01:07
    Progress: 1137541 of 1283638 done; Stage: 88%; Total: 80%; ETA: 0:01:07 .
    Progress: 1137721 of 1283638 done; Stage: 88%; Total: 80%; ETA: 0:01:07 ..
    Progress: 1137974 of 1283638 done; Stage: 88%; Total: 80%; ETA: 0:01:07 ...
    Progress: 1138436 of 1283638 done; Stage: 88%; Total: 80%; ETA: 0:01:07
    Progress: 1139158 of 1283638 done; Stage: 88%; Total: 80%; ETA: 0:01:05 .
    Progress: 1140021 of 1283638 done; Stage: 88%; Total: 80%; ETA: 0:01:05 ..
    Progress: 1283638 of 1283638 done; Stage: 100%; Total: 79%; ETA: 0:01:08 ...


    1283638 index entries processed.

    Index verification completed.
    Phase duration (Index verification): 2.41 minutes.
    Progress: 1 of 0 done; Stage: 99%; Total: 79%; ETA: 0:01:08
    Progress: 0 of 0 done; Stage: 99%; Total: 79%; ETA: 0:01:09 .


    0 unindexed files scanned.

    Phase duration (Orphan reconnection): 7.14 seconds.
    Progress: 0 of 0 done; Stage: 99%; Total: 79%; ETA: 0:01:09 ..


    0 unindexed files recovered to lost and found.

    Phase duration (Orphan recovery to lost and found): 0.04 milliseconds.
    Progress: 73652 of 73652 done; Stage: 100%; Total: 79%; ETA: 0:01:09 ...


    73652 reparse records processed.

    Phase duration (Reparse point and Object ID verification): 196.97 milliseconds.

    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.
    Phase duration (Security descriptor verification): 287.12 milliseconds.
    Progress: 17 of 17 done; Stage: 100%; Total: 99%; ETA: 0:00:00


    143516 data files processed.

    Phase duration (Data attribute verification): 0.10 milliseconds.
    CHKDSK is verifying Usn Journal...
    Progress: 0 of 4844 done; Stage: 0%; Total: 99%; ETA: 0:00:00 .
    Progress: 375 of 4844 done; Stage: 7%; Total: 99%; ETA: 0:00:00 ..
    Progress: 4844 of 4844 done; Stage: 100%; Total: 98%; ETA: 0:00:03 ...


    39687672 USN bytes processed.

    Usn Journal verification completed.
    Phase duration (USN journal verification): 490.15 milliseconds.
    The Volume Bitmap is incorrect.
    Windows has checked the file system and found problems.
    Please run chkdsk /scan to find the problems and queue them for repair.

    1935390719 KB total disk space.
    201304464 KB in 542500 files.
    312168 KB in 143517 indexes.
    0 KB in bad sectors.
    1167507 KB in use by the system.
    65536 KB occupied by the log file.
    1732606580 KB available on disk.

    4096 bytes in each allocation unit.
    483847679 total allocation units on disk.
    433151645 allocation units available on disk.
    Total duration: 4.67 minutes (280247 ms).


    ========= End of CMD: =========


    ========= sfc /scannow =========



    Beginning system scan. This process will take some time.



    Beginning verification phase of system scan.


    Verification 0% complete.
    Verification 1% complete.
    Verification 1% complete.
    Verification 2% complete.
    Verification 3% complete.
    Verification 3% complete.
    Verification 4% complete.
    Verification 5% complete.
    Verification 5% complete.
    Verification 6% complete.
    Verification 6% complete.
    Verification 7% complete.
    Verification 8% complete.
    Verification 8% complete.
    Verification 9% complete.
    Verification 10% complete.
    Verification 10% complete.
    Verification 11% complete.
    Verification 11% complete.
    Verification 12% complete.
    Verification 13% complete.
    Verification 13% complete.
    Verification 14% complete.
    Verification 15% complete.
    Verification 15% complete.
    Verification 16% complete.
    Verification 17% complete.
    Verification 17% complete.
    Verification 18% complete.
    Verification 18% complete.
    Verification 19% complete.
    Verification 20% complete.
    Verification 20% complete.
    Verification 21% complete.
    Verification 22% complete.
    Verification 22% complete.
    Verification 23% complete.
    Verification 23% complete.
    Verification 24% complete.
    Verification 25% complete.
    Verification 25% complete.
    Verification 26% complete.
    Verification 27% complete.
    Verification 27% complete.
    Verification 28% complete.
    Verification 28% complete.
    Verification 29% complete.
    Verification 30% complete.
    Verification 30% complete.
    Verification 31% complete.
    Verification 32% complete.
    Verification 32% complete.
    Verification 33% complete.
    Verification 34% complete.
    Verification 34% complete.
    Verification 35% complete.
    Verification 35% complete.
    Verification 36% complete.
    Verification 37% complete.
    Verification 37% complete.
    Verification 38% complete.
    Verification 39% complete.
    Verification 39% complete.
    Verification 40% complete.
    Verification 40% complete.
    Verification 41% complete.
    Verification 42% complete.
    Verification 42% complete.
    Verification 43% complete.
    Verification 44% complete.
    Verification 44% complete.
    Verification 45% complete.
    Verification 45% complete.
    Verification 46% complete.
    Verification 47% complete.
    Verification 47% complete.
    Verification 48% complete.
    Verification 49% complete.
    Verification 49% complete.
    Verification 50% complete.
    Verification 51% complete.
    Verification 51% complete.
    Verification 52% complete.
    Verification 52% complete.
    Verification 53% complete.
    Verification 54% complete.
    Verification 54% complete.
    Verification 55% complete.
    Verification 56% complete.
    Verification 56% complete.
    Verification 57% complete.
    Verification 57% complete.
    Verification 58% complete.
    Verification 59% complete.
    Verification 59% complete.
    Verification 60% complete.
    Verification 61% complete.
    Verification 61% complete.
    Verification 62% complete.
    Verification 63% complete.
    Verification 63% complete.
    Verification 64% complete.
    Verification 64% complete.
    Verification 65% complete.
    Verification 66% complete.
    Verification 66% complete.
    Verification 67% complete.
    Verification 68% complete.
    Verification 68% complete.
    Verification 69% complete.
    Verification 69% complete.
    Verification 70% complete.
    Verification 71% complete.
    Verification 71% complete.
    Verification 72% complete.
    Verification 73% complete.
    Verification 73% complete.
    Verification 74% complete.
    Verification 74% complete.
    Verification 75% complete.
    Verification 76% complete.
    Verification 76% complete.
    Verification 77% complete.
    Verification 78% complete.
    Verification 78% complete.
    Verification 79% complete.
    Verification 80% complete.
    Verification 80% complete.
    Verification 81% complete.
    Verification 81% complete.
    Verification 82% complete.
    Verification 83% complete.
    Verification 83% complete.
    Verification 84% complete.
    Verification 85% complete.
    Verification 85% complete.
    Verification 86% complete.
    Verification 86% complete.
    Verification 87% complete.
    Verification 88% complete.
    Verification 88% complete.
    Verification 89% complete.
    Verification 90% complete.
    Verification 90% complete.
    Verification 91% complete.
    Verification 91% complete.
    Verification 92% complete.
    Verification 93% complete.
    Verification 93% complete.
    Verification 94% complete.
    Verification 95% complete.
    Verification 95% complete.
    Verification 96% complete.
    Verification 97% complete.
    Verification 97% complete.
    Verification 98% complete.
    Verification 98% complete.
    Verification 99% complete.
    Verification 100% complete.


    Windows Resource Protection did not find any integrity violations.



    ========= End of CMD: =========


    ========= DISM /Online /Cleanup-Image /CheckHealth =========


    Deployment Image Servicing and Management tool
    Version: 10.0.19041.844

    Image Version: 10.0.19045.3208

    No component store corruption detected.
    The operation completed successfully.


    ========= End of CMD: =========


    =========== EmptyTemp: ==========

    FlushDNS => completed
    BITS transfer queue => 2097152 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 7434863 B
    Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
    Windows/system/drivers => 5379504 B
    Edge => 0 B
    Chrome => 139264 B
    Firefox => 20534321 B
    Opera => 10632560 B

    Temp, IE cache, history, cookies, recent:
    Default => 6656 B
    ProgramData => 6656 B
    Public => 6656 B
    systemprofile => 6656 B
    systemprofile32 => 6656 B
    LocalService => 6656 B
    NetworkService => 13404936 B
    peggy => 149197208 B
    away => 149226748 B

    RecycleBin => 0 B
    EmptyTemp: => 341.5 MB temporary data Removed.

    ================================


    The system needed a reboot.

    ==== End of Fixlog 19:40:14 ====
     
  9. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the information.

    We need to be cautious moving forward. If you do not have a backup of your data files (photos, music, documents, etc) I would advise you save your data onto an external drive before completing the below.

    I would like to run a hard drive test to determine the health of the drive. Following that we need to take a look at file system errors being reported in the Fixlog report.

    Please do this.

    ===================================================

    SeaTools Disk Checking

    --------------
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Seatools test results
     
  10. pjubber

    pjubber Private E-2

    Short Self Test Passed
     
  11. Oh My!

    Oh My! Malware Expert Staff Member

    Excellent.

    Please do this now.

    ===================================================

    BlueScreenView

    ----------

    • Download BlueScreenView and save it to your desktop
    • Right click on BlueScreenView.exe then select Run as administrator
    • Select Yes, Next, then Next again
    • Click Install
    • Click Finish and the program should automatically run
    • When the scanning is complete, select Edit and Select All
    • Then click File and Save Selected Items
    • Save the report as BSOD.txt
    • Copy and paste the report information in your reply
    ===================================================

    Running chkdsk /r

    --------------------

    • Click Start, type cmd, then select Run as administrator
    • Type chkdsk /r and press Enter
    • When asked to schedule the disk check for next reboot, press Y
    • Restart your computer and allow the process to run unhindered
    ===================================================

    ListChkdskResult by SleepyDude

    --------------------

    • Download ListChkdskResult and save it to your Desktop
    • Right click on the file and select Run as administrator
    • Copy and paste the contents of the ListChkdskResult.txt report in your reply
    ===================================================

    Farbar Recovery Scan Tool Search

    --------------------
    • Launch FRST
    • Type the following in the Search: box
    Code:
    *.dmp
    • Click Search Files button
    • When completed click OK and a Search.txt document will open on your desktop
    • Copy and paste the contents of that document your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • BSOD.txt
    • ListChkdskResult.txt
    • Search.txt
     
  12. pjubber

    pjubber Private E-2

    Thank you for your help. The Blue Screen View didn't seem to run... nothing to copy and paste. Here is the Chkdsk list and then I will post the Search.txt. BTW, my laptop has run fine all day. :) Thanks again.

    ListChkdskResult by SleepyDude v0.1.7 Beta | 21-09-2013

    ------< Log generate on 7/30/2023 6:19:57 PM >------
    Category: 0
    Computer Name: Laptop-lr
    Event Code: 1001
    Record Number: 33276
    Source Name: Microsoft-Windows-Wininit
    Time Written: 07-30-2023 @ 20:57:47
    Event Type: Information
    User:
    Message:

    Checking file system on C:
    The type of the file system is NTFS.
    Volume label is Windows.

    A disk check has been scheduled.
    Windows will now check the disk.

    Stage 1: Examining basic file system structure ...
    996608 file records processed.


    File verification completed.
    Phase duration (File record verification): 1.22 minutes.
    12742 large file records processed.


    Phase duration (Orphan file record recovery): 0.00 milliseconds.
    0 bad file records processed.


    Phase duration (Bad file record checking): 0.96 milliseconds.

    Stage 2: Examining file name linkage ...
    73502 reparse records processed.


    1283598 index entries processed.


    Index verification completed.
    Phase duration (Index verification): 5.28 minutes.
    0 unindexed files scanned.


    Phase duration (Orphan reconnection): 4.94 seconds.
    0 unindexed files recovered to lost and found.


    Phase duration (Orphan recovery to lost and found): 8.00 seconds.
    73502 reparse records processed.


    Phase duration (Reparse point and Object ID verification): 148.71 milliseconds.

    Stage 3: Examining security descriptors ...
    Cleaning up 101 unused index entries from index $SII of file 0x9.
    Cleaning up 101 unused index entries from index $SDH of file 0x9.
    Cleaning up 101 unused security descriptors.
    Security descriptor verification completed.
    Phase duration (Security descriptor verification): 930.32 milliseconds.
    143496 data files processed.


    Phase duration (Data attribute verification): 1.08 milliseconds.
    CHKDSK is verifying Usn Journal...
    37864744 USN bytes processed.


    Usn Journal verification completed.
    Phase duration (USN journal verification): 665.52 milliseconds.

    Stage 4: Looking for bad clusters in user file data ...
    996592 files processed.


    File data verification completed.
    Phase duration (User file recovery): 1.42 hours.

    Stage 5: Looking for bad, free clusters ...
    433065951 free clusters processed.


    Free space verification is complete.
    Phase duration (Free space recovery): 0.00 milliseconds.
    CHKDSK discovered free space marked as allocated in the volume bitmap.

    Windows has made corrections to the file system.
    No further action is required.

    1935390719 KB total disk space.
    201649340 KB in 541743 files.
    311808 KB in 143497 indexes.
    0 KB in bad sectors.
    1165767 KB in use by the system.
    65536 KB occupied by the log file.
    1732263804 KB available on disk.

    4096 bytes in each allocation unit.
    483847679 total allocation units on disk.
    433065951 allocation units available on disk.
    Total duration: 1.53 hours (5542224 ms).

    Internal Info:
    00 35 0f 00 c4 74 0a 00 55 9f 12 00 00 00 00 00 .5...t..U.......
    8b 0d 00 00 93 11 01 00 00 00 00 00 00 00 00 00 ................

    -----------------------------------------------------------------------
    Category: 0
    Computer Name: Laptop-lr
    Event Code: 26212
    Record Number: 33113
    Source Name: Chkdsk
    Time Written: 07-29-2023 @ 23:18:54
    Event Type: Information
    User:
    Message: Chkdsk was executed in read-only mode on a volume snapshot.

    Checking file system on C:
    The type of the file system is NTFS.
    Volume label is Windows.

    WARNING! /F parameter not specified.
    Running CHKDSK in read-only mode.

    Stage 1: Examining basic file system structure ...
    996608 file records processed.

    File verification completed.
    Phase duration (File record verification): 2.12 minutes.
    12745 large file records processed.

    Phase duration (Orphan file record recovery): 0.00 milliseconds.
    0 bad file records processed.

    Phase duration (Bad file record checking): 0.19 milliseconds.

    Stage 2: Examining file name linkage ...
    73652 reparse records processed.

    1283638 index entries processed.

    Index verification completed.
    Phase duration (Index verification): 2.41 minutes.
    0 unindexed files scanned.

    Phase duration (Orphan reconnection): 7.14 seconds.
    0 unindexed files recovered to lost and found.

    Phase duration (Orphan recovery to lost and found): 0.04 milliseconds.
    73652 reparse records processed.

    Phase duration (Reparse point and Object ID verification): 196.97 milliseconds.

    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.
    Phase duration (Security descriptor verification): 287.12 milliseconds.
    143516 data files processed.

    Phase duration (Data attribute verification): 0.10 milliseconds.
    CHKDSK is verifying Usn Journal...
    39687672 USN bytes processed.

    Usn Journal verification completed.
    Phase duration (USN journal verification): 490.15 milliseconds.
    The Volume Bitmap is incorrect.
    Windows has checked the file system and found problems.
    Please run chkdsk /scan to find the problems and queue them for repair.

    1935390719 KB total disk space.
    201304464 KB in 542500 files.
    312168 KB in 143517 indexes.
    0 KB in bad sectors.
    1167507 KB in use by the system.
    65536 KB occupied by the log file.
    1732606580 KB available on disk.

    4096 bytes in each allocation unit.
    483847679 total allocation units on disk.
    433151645 allocation units available on disk.
    Total duration: 4.67 minutes (280247 ms).

    -----------------------------------------------------------------------
     
  13. pjubber

    pjubber Private E-2

    Farbar Recovery Scan Tool (x64) Version: 27-07-2023
    Ran by peggy (30-07-2023 18:23:13)
    Running from C:\Users\peggy\Desktop
    Boot Mode: Normal

    ================== Search Files: "*.dmp" =============

    C:\Windows\System32\config\systemprofile\AppData\Local\CrashDumps\ZeroConfigService.exe.4572.dmp
    [2023-07-27 07:42][2023-07-27 07:42] 001859767 _____ () D4567FD812AEF19A0C4B83ED3EF54357 [File not signed]

    C:\Windows\ServiceProfiles\LocalService\AppData\Local\CrashDumps\WUDFHost.exe.1136.dmp
    [2020-12-14 17:24][2020-12-14 17:24] 001375231 _____ () 1A2F9BAB3DBAC8CA35E0375E3F5B8E3D [File not signed]

    C:\Users\peggy\AppData\LocalLow\webviewdata\2\EBWebView\Crashpad\reports\7aa4f8ed-727c-4862-9aed-37b705c22a3f.dmp
    [2023-01-20 22:29][2023-01-20 22:30] 003213547 _____ () 73F2FD8FFA7CC292942E6C21C23CABB6 [File not signed]

    C:\Users\peggy\AppData\LocalLow\webviewdata\2\EBWebView\Crashpad\reports\98096c0a-b6c9-47d0-8d84-6dfc7426f866.dmp
    [2023-01-20 22:29][2023-01-20 22:30] 003217245 _____ () 9D5701136DAA316A3B89435B064B8BE2 [File not signed]

    C:\Users\peggy\AppData\LocalLow\webviewdata\2\EBWebView\Crashpad\reports\b2654961-0b10-416e-be76-ac9e80a08680.dmp
    [2023-01-20 22:30][2023-01-20 22:30] 003216905 _____ () 54663DBE096BDB382DFF48594A105C57 [File not signed]

    C:\Users\peggy\AppData\LocalLow\webviewdata\2\EBWebView\Crashpad\reports\e75ec20c-fe3e-44eb-9b74-e4f963f47cb1.dmp
    [2023-01-20 22:31][2023-01-20 22:31] 003214944 _____ () 8057E8DD62207C0BC68E12E63B7D89BF [File not signed]

    C:\Users\peggy\AppData\Local\CrashDumps\Malwarebytes\mbam.exe(1).15012.dmp
    [2023-01-11 18:03][2023-01-11 18:03] 390130613 _____ () F6B22CA6BA9E02154AB9A0DF0048BF0B [File not signed]

    C:\Users\peggy\AppData\Local\CrashDumps\Malwarebytes\mbamtray.exe.9208.dmp
    [2023-07-28 19:37][2023-07-28 19:37] 207534211 _____ () B4D02428BBCB4ECA3008052EC9054E48 [File not signed]

    C:\Users\away\AppData\Local\CrashDumps\qw.exe.12836.dmp
    [2019-02-19 16:10][2019-02-19 16:10] 018027483 _____ () FFBA52DCB4AA922D2811C00826951B46 [File not signed]

    C:\Users\away\AppData\Local\CrashDumps\SystemSettings.exe.13112.dmp
    [2019-02-19 00:59][2019-02-19 00:59] 004344237 _____ () 901CAF78F1F666BBBBCB0794A04F36A8 [File not signed]

    C:\ProgramData\Microsoft\WDF\DriverManager_824.dmp
    [2023-07-14 08:58][2023-07-14 08:59] 000220584 _____ () 56FBF6974FAAFC5DB8408F14549CB52B [File not signed]


    ====== End of Search ======
     
  14. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the reports and updates.

    This is the result we wanted. The file system was corrected.

    Even though your system crashed and the crash report indicated information could be obtained from a memory dump file, no reports have been generated. That is why you didn't get any results after running BlueScreenView.

    These types of situations can be difficult to diagnose. Part of the approach is to reset areas of the computer commonly known to become corrupted for one reason or another. Often times an underlying issue is resolved without us knowing exactly what the cause was.

    Let's monitor things for a day and see how we do. Touch base tomorrow, or sooner if an issue arises.
     
  15. pjubber

    pjubber Private E-2

    Sounds good. Thanks again. (I appreciate your signature.)
     
  16. Oh My!

    Oh My! Malware Expert Staff Member

    Truth be told, a major reason why I do this is to have the opportunity to display that passage to tell others of my thankfulness that Christ has saved me. Your comment is a great encouragement to me.
     
    pjubber likes this.
  17. pjubber

    pjubber Private E-2

    Still going well - no crashes. Thanks
     
  18. Oh My!

    Oh My! Malware Expert Staff Member

    Very good.

    We will wrap this up but if it starts up again let me know.

    Here is our final step and some additional information to consider.

    ===================================================

    KpRm by Kernel-panik

    --------------
    • Download KpRm and save it to your Desktop (see here if you must use Chrome)
    • Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
    • Right click on the icon and select Run as administrator
    • Click Yes on the Disclaimer
    • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
    • Click Run
    • Click OK on All operations are completed
    • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
    • You are free to remove any other tools/reports still remaining
    ===================================================

    All Clean!

    --------------

    Your computer is now clean. Please consider this going forward.

    ===================================================

    Please take the time to read below on how to secure the machine and take the necessary steps to keep it clean.
    Thank you for placing your trust in MajorGeeks. It was a pleasure serving you.
     
  19. pjubber

    pjubber Private E-2

    Done. Thanks. God Bless.
     
  20. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you, my friend. You are always welcome here.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds