Clean Install High Cpu And 100% Disc Use

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nomogoog, Nov 3, 2023.

  1. nomogoog

    nomogoog Private E-2

    I recently did a clean install of win10 and after I noticed unusually slow startup and/or any app i start uses a lot of disc and cpu so i did some googling and realized i installed windows with legacy bios and couldn't access winre troubleshooting or uefi options and i assumed that was the culprit so I converted it from legacy to uefi and did all the scndsk and chkdsk and repair windows troubleshooters and advanced repairing tools but after the bios conversion it got worse and now startup and apps use 100% disc and 35-100% cpu and frequently freezes and stalls. Ive tried searching fixes for ever and nothing helps like updating drivers to manufacturer drivers and bios firmware update and chipset driver updates, i tried shutting down a lot of processes i thought were unneeded a few registry tweaks but nothing helped so i
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to the Major Geeks Malware Forum.

    This doesn't sound like a malware issue but let's see what we find. While I review what you have posted please do this.

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download Farbar Recover Scan Tool for 64 bit systems and save (or copy and paste) the file onto your Desktop
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
    • 2 Notepad documents should now be open on your desktop.
    • Please attempt to copy and paste each report in a separate reply. If unable to do so, attach both reports.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
    • FRST.txt
    • Addition.txt
     
  3. nomogoog

    nomogoog Private E-2

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-10-2023
    Ran by ross1 (administrator) on DESKTOP-JBUIU2S (TOSHIBA Satellite C55-A) (03-11-2023 10:00:56)
    Running from C:\Users\ross1\Desktop\FRST64.exe
    Loaded Profiles: ross1
    Platform: Microsoft Windows 10 Home Version 22H2 19045.3570 (X64) Language: English (United States)
    Default browser: FF
    Boot Mode: Normal

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (C:\Program Files\RogueKiller\RogueKillerSvc.exe ->) (ADLICE -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
    (Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\DSDFunctionKeyCtlService.exe
    (services.exe ->) (ADLICE -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe
    (services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\vds.exe
    (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe
    (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

    ==================== Registry (Whitelisted) ===================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKU\S-1-5-21-2167588370-2769944560-668675099-1001\...\Run: [MicrosoftEdgeAutoLaunch_D9C3DAB0B411DEA3A5BCC19B78C7E1D8] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4187176 2023-10-27] (Microsoft Corporation -> Microsoft Corporation)

    ==================== Scheduled Tasks (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {83C38708-AE11-469B-AD16-B9B78068A08E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-25] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {4B7E638C-745A-4789-8D00-3CB923EADFF0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-25] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {E5A02DF5-9477-4375-BBBA-06EB34E3743F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-25] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {89DCE63A-645E-4053-8516-16CBB84CE9F2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-25] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {7963221D-17D5-420A-A08D-94403E4D339A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [723872 2023-10-19] (Mozilla Corporation -> Mozilla Foundation)
    Task: {9F5E56DF-D501-47DB-8B3B-4DBB42DCDDC8} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16161536 2015-07-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{220237df-3b2e-494d-abab-ff401186a256}: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{bbfed8b7-31bd-4b7e-bcc2-f6b1f86d0097}: [DhcpNameServer] 10.0.0.1

    Edge:
    =======
    Edge Profile: C:\Users\ross1\AppData\Local\Microsoft\Edge\User Data\Default [2023-11-03]
    Edge Extension: (Google Docs Offline) - C:\Users\ross1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-11-03]
    Edge Extension: (Edge relevant text changes) - C:\Users\ross1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-10-25]

    FireFox:
    ========
    FF DefaultProfile: 49v210kz.default
    FF ProfilePath: C:\Users\ross1\AppData\Roaming\Mozilla\Firefox\Profiles\49v210kz.default [2023-10-25]
    FF ProfilePath: C:\Users\ross1\AppData\Roaming\Mozilla\Firefox\Profiles\ujs1bnwh.default-esr-1699011186369 [2023-11-03]
    FF Homepage: Mozilla\Firefox\Profiles\ujs1bnwh.default-esr-1699011186369 -> hxxps://www.google.com/
    FF Plugin: @videolan.org/vlc,version=3.0.19 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-07] (VideoLAN -> VideoLAN)

    ==================== Services (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 DSDFunctionKeyCtlService; C:\WINDOWS\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\DSDFunctionKeyCtlService.exe [718168 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
    S2 DSDTabletControlService; C:\WINDOWS\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\DSDTabSysSvc.exe [330136 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
    S2 DSDWirelessLEDCtlService; C:\WINDOWS\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\RMService.exe [480144 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
    S2 dynabookSettingService; C:\WINDOWS\System32\DriverStore\FileRepository\dsrvctldrv.inf_amd64_5df7e0d31a7e7230\dynabookSystemService.exe [24153096 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
    S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9343840 2023-11-03] (Malwarebytes Inc. -> Malwarebytes)
    R2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [16033712 2023-10-19] (ADLICE -> )
    R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\NisSrv.exe [3116904 2023-10-25] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.23090.2008-0\MsMpEng.exe [133584 2023-10-25] (Microsoft Windows Publisher -> Microsoft Corporation)

    ===================== Drivers (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
    S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
    R3 dhotkey; C:\WINDOWS\System32\drivers\dhotkey.sys [52736 2023-03-22] (Dynabook Inc. -> Dynabook Inc.)
    R1 dsrvctldrv; C:\WINDOWS\System32\drivers\dsrvctldrv.sys [30232 2023-07-13] (Dynabook Inc. -> Dynabook Inc.)
    R0 DVALZ_O; C:\WINDOWS\System32\drivers\DVALZ_O.SYS [47464 2022-07-18] (Dynabook Inc. -> Dynabook Inc.)
    S3 iscFlash; C:\Users\ross1\AppData\Local\Temp\7zS3F2.tmp\iscflashx64.sys [60680 2013-02-24] (Insyde Software Corp. -> Insyde Software) <==== ATTENTION
    S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-11-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
    S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-11-03] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
    S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [27744 2021-03-09] (Daniel Terhell -> Resplendence Software Projects Sp.)
    U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [53696 2023-11-03] (ADLICE (Julien Ascoet) -> )
    S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55856 2023-10-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
    R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [572712 2023-10-25] (Microsoft Windows -> Microsoft Corporation)
    R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105872 2023-10-25] (Microsoft Windows -> Microsoft Corporation)
    S3 IntelCseWNP; \??\C:\Windows\system32\drivers\wnpdriver.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) (Whitelisted) =========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2023-11-03 10:00 - 2023-11-03 10:02 - 000009039 _____ C:\Users\ross1\Desktop\FRST.txt
    2023-11-03 10:00 - 2023-11-03 10:01 - 000000000 ____D C:\FRST
    2023-11-03 09:59 - 2023-11-03 09:59 - 002383872 _____ (Farbar) C:\Users\ross1\Desktop\FRST64.exe
    2023-11-03 09:09 - 2023-11-03 09:09 - 000000000 ____D C:\Program Files\Reference Assemblies
    2023-11-03 09:09 - 2023-11-03 09:09 - 000000000 ____D C:\Program Files\MSBuild
    2023-11-03 09:09 - 2023-11-03 09:09 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
    2023-11-03 09:09 - 2023-11-03 09:09 - 000000000 ____D C:\Program Files (x86)\MSBuild
    2023-11-03 08:47 - 2023-11-03 09:09 - 000000000 ____D C:\MGtools
    2023-11-03 08:37 - 2023-11-03 08:46 - 000000000 ____D C:\ProgramData\HitmanPro
    2023-11-03 08:20 - 2023-11-03 08:20 - 000053696 _____ C:\WINDOWS\system32\Drivers\truesight.sys
    2023-11-03 08:19 - 2023-11-03 08:34 - 000000000 ____D C:\ProgramData\RogueKiller
    2023-11-03 08:19 - 2023-11-03 08:19 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
    2023-11-03 08:19 - 2023-11-03 08:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
    2023-11-03 08:19 - 2023-11-03 08:19 - 000000000 ____D C:\Program Files\RogueKiller
    2023-11-03 07:32 - 2023-11-03 07:38 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
    2023-11-03 07:32 - 2023-11-03 07:33 - 000000000 ____D C:\Program Files\Mozilla Firefox
    2023-11-03 07:32 - 2023-11-03 07:32 - 000002038 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk
    2023-11-03 07:32 - 2023-11-03 07:32 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
    2023-11-03 07:32 - 2023-11-03 07:32 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2023-11-03 05:07 - 2023-11-03 05:07 - 000003192 _____ C:\WINDOWS\system32\Tasks\RTKCPL
    2023-11-03 05:07 - 2023-11-03 05:07 - 000000000 ____H C:\ProgramData\DP45977C.lfl
    2023-11-03 05:07 - 2023-11-03 05:07 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2023-11-03 05:07 - 2023-11-03 05:07 - 000000000 ____D C:\Program Files\Realtek
    2023-11-03 05:06 - 2015-07-23 13:25 - 005289952 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 003271912 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 003232448 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 002965632 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001965816 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001780624 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001591064 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001508936 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001382240 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001334384 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxSpeechAPO64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001331336 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001211840 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO5064.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001164336 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO4064.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 001122648 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\slcnt64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000998032 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO2064.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000965032 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000961024 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000923752 _____ (Sony Corporation) C:\WINDOWS\system32\MISS_APO.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000888480 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tossaeapo64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000873472 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000749776 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000743968 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000727440 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000708320 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000678192 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000677680 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000645464 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000618192 _____ (Knowles Acoustics ) C:\WINDOWS\system32\KAAPORT64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000596120 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosasfapo64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000574248 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000532384 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000514528 _____ (DTS) C:\WINDOWS\system32\DTSU2PLFX64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000504312 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000500560 _____ (DTS) C:\WINDOWS\system32\DTSU2PGFX64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000447728 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000445408 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000441272 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000428232 _____ (DTS) C:\WINDOWS\system32\DTSU2PREC64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000387320 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000330568 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000327464 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000272720 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000253904 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000253872 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000252880 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000231920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000221976 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000214840 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000209544 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000195192 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000172584 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\toseaeapo64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000166208 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000158704 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000151792 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000134208 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000118600 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000110992 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000090920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000088352 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000088328 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000084624 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000083632 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
    2023-11-03 05:06 - 2015-07-23 13:25 - 000075544 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 007172920 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 007096192 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 004598528 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
    2023-11-03 05:06 - 2015-07-23 13:22 - 002927872 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 002711296 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
    2023-11-03 05:06 - 2015-07-23 13:22 - 002110600 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 002050184 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 001758976 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 000259288 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 000122328 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 000118600 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 000105312 _____ C:\WINDOWS\system32\audioLibVc.dll
    2023-11-03 05:06 - 2015-07-23 13:22 - 000023704 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
    2023-11-03 04:14 - 2023-11-03 04:14 - 000000000 ___HD C:\$SysReset
    2023-11-03 03:12 - 2023-11-03 03:12 - 000000112 ___SH C:\bootTel.dat
    2023-11-03 03:12 - 2023-11-03 03:12 - 000000000 __SHD C:\found.000
    2023-11-03 02:41 - 2023-11-03 02:41 - 000000000 ____D C:\Users\ross1\AppData\Local\Microsoft_Corporation
    2023-11-03 02:20 - 2023-11-03 08:04 - 000000000 ____D C:\Users\ross1\AppData\Local\Malwarebytes
    2023-11-03 02:20 - 2023-11-03 02:20 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
    2023-11-03 02:20 - 2023-11-03 02:20 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2023-11-03 02:20 - 2023-11-03 02:20 - 000000000 ____D C:\Users\ross1\AppData\Local\mbam
    2023-11-03 02:19 - 2023-11-03 02:19 - 000000000 ____D C:\ProgramData\Malwarebytes
    2023-11-03 02:19 - 2023-11-03 02:19 - 000000000 ____D C:\Program Files\Malwarebytes
    2023-11-03 02:13 - 2023-11-03 02:13 - 001993530 _____ C:\MGtools.exe
    2023-11-03 02:09 - 2023-11-03 02:09 - 014287912 _____ (Sophos B.V.) C:\Users\ross1\Desktop\HitmanPro_x64.exe
    2023-11-03 01:57 - 2023-11-03 02:01 - 000000000 ____D C:\AdwCleaner
    2023-11-03 01:56 - 2023-11-03 01:56 - 008791352 _____ (Malwarebytes) C:\Users\ross1\Desktop\AdwCleaner.exe
    2023-11-02 23:25 - 2023-11-03 08:09 - 000000000 _____ C:\Recovery.txt
    2023-11-02 23:11 - 2021-03-09 15:07 - 000027744 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL64.sys
    2023-11-02 22:59 - 2023-11-02 22:59 - 000000207 _____ C:\WINDOWS\tweaking.com-regbackup-DESKTOP-JBUIU2S-Windows-10-Home-(64-bit).dat
    2023-11-02 22:59 - 2023-11-02 22:59 - 000000000 ____D C:\RegBackup
    2023-11-02 21:51 - 2023-11-02 21:51 - 000000000 ____D C:\Users\ross1\AppData\LocalLow\Intel
    2023-11-02 20:19 - 2023-11-02 20:23 - 000391080 _____ C:\WINDOWS\Tweaking.com - Windows Repair Setup Log.txt
    2023-11-02 19:37 - 2023-11-02 23:16 - 000001118 _____ C:\Users\ross1\Documents\ReAgent.xml
    2023-11-02 18:09 - 2023-11-02 18:29 - 000000000 ____D C:\ESD
    2023-11-02 18:04 - 2023-11-02 18:04 - 000000000 ___HD C:\$Windows.~WS
    2023-11-02 18:04 - 2023-11-02 18:04 - 000000000 ____D C:\$WINDOWS.~BT
    2023-11-02 17:53 - 2023-11-02 20:29 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
    2023-11-02 17:28 - 2023-11-02 17:28 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2023-11-02 14:54 - 2023-11-02 14:54 - 000055335 _____ C:\Users\ross1\Documents\satellite_C55-A5311.pdf
    2023-10-26 00:30 - 2023-11-03 02:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Toshiba
    2023-10-26 00:29 - 2023-10-26 00:29 - 000000000 ____D C:\Users\ross1\AppData\Roaming\WinBatch
    2023-10-26 00:29 - 2023-10-26 00:29 - 000000000 ____D C:\ProgramData\TOSHIBA
    2023-10-26 00:28 - 2023-10-26 00:28 - 000000000 ____D C:\Users\ross1\Intel
    2023-10-26 00:28 - 2023-10-26 00:28 - 000000000 ____D C:\ProgramData\Intel Package Cache {1CEAC85D-2590-4760-800F-8DE5E91F3700}
    2023-10-26 00:27 - 2023-10-26 00:27 - 000000000 ____D C:\Users\ross1\AppData\Roaming\WinRAR
    2023-10-26 00:27 - 2023-10-26 00:27 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    2023-10-26 00:27 - 2023-10-26 00:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    2023-10-26 00:27 - 2023-10-26 00:27 - 000000000 ____D C:\Program Files\WinRAR
    2023-10-25 23:42 - 2023-10-26 00:26 - 000000000 ____D C:\ProgramData\WinZip
    2023-10-25 23:41 - 2023-10-25 23:41 - 000000000 ____D C:\ProgramData\UniqueId
    2023-10-25 23:14 - 2023-10-25 23:14 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Microsoft\HTML Help
    2023-10-25 22:59 - 2023-10-25 22:59 - 000000375 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
    2023-10-25 21:31 - 2023-10-25 21:31 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Microsoft\IME
    2023-10-25 19:09 - 2023-10-25 19:09 - 000016059 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
    2023-10-25 18:39 - 2023-10-25 18:39 - 000000000 ___HD C:\$WinREAgent
    2023-10-25 18:34 - 2023-10-25 18:34 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
    2023-10-25 18:33 - 2023-10-25 18:33 - 000000000 ____D C:\ProgramData\PLUG
    2023-10-25 18:29 - 2023-10-25 18:29 - 000000000 ____D C:\Program Files\RUXIM
    2023-10-25 18:26 - 2023-10-25 18:29 - 000000000 ____D C:\WINDOWS\system32\MRT
    2023-10-25 18:08 - 2023-11-02 18:29 - 000000000 ____D C:\WINDOWS\Panther
    2023-10-25 18:06 - 2023-11-03 01:54 - 000000000 ____D C:\Users\ross1\AppData\Local\ElevatedDiagnostics
    2023-10-25 17:33 - 2023-11-03 05:14 - 000795738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2023-10-25 17:29 - 2023-10-25 17:29 - 000000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
    2023-10-25 17:27 - 2023-10-25 17:27 - 000000000 _SHDL C:\Documents and Settings
    2023-10-25 17:25 - 2023-11-02 21:16 - 000514222 _____ C:\WINDOWS\ntbtlog.txt
    2023-10-25 17:22 - 2023-11-02 14:50 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
    2023-10-25 17:21 - 2023-11-02 14:44 - 000003534 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
    2023-10-25 17:21 - 2023-11-02 14:44 - 000003410 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
    2023-10-25 17:19 - 2023-11-03 05:09 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2023-10-25 17:19 - 2023-10-25 16:51 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
    2023-10-25 17:18 - 2023-11-03 05:09 - 000008192 ___SH C:\DumpStack.log.tmp
    2023-10-25 17:18 - 2023-11-03 03:17 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2023-10-25 17:18 - 2023-10-25 19:40 - 000259496 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2023-10-25 17:18 - 2023-10-25 17:18 - 000000000 ____D C:\WINDOWS\ServiceProfiles
    2023-10-25 16:58 - 2023-11-02 23:52 - 000000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
    2023-10-25 16:34 - 2023-11-03 05:10 - 000000000 __SHD C:\Users\ross1\IntelGraphicsProfiles
    2023-10-25 16:32 - 2023-11-02 21:51 - 000000000 ____D C:\ProgramData\Intel
    2023-10-25 16:32 - 2023-10-25 19:01 - 000000000 ____D C:\ProgramData\Package Cache
    2023-10-25 16:22 - 2023-11-03 02:57 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Microsoft\MMC
    2023-10-25 15:34 - 2023-10-25 16:44 - 000000000 ____D C:\Users\ross1\AppData\Roaming\qBittorrent
    2023-10-25 15:34 - 2023-10-25 15:34 - 000000000 ____D C:\Users\ross1\AppData\Local\qBittorrent
    2023-10-25 15:34 - 2023-10-25 15:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
    2023-10-25 15:34 - 2023-10-25 15:34 - 000000000 ____D C:\Program Files\qBittorrent
    2023-10-25 15:32 - 2023-11-03 09:55 - 000000000 ____D C:\Users\ross1\AppData\Roaming\vlc
    2023-10-25 15:31 - 2023-10-25 15:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
    2023-10-25 15:31 - 2023-10-25 15:31 - 000000000 ____D C:\Program Files\VideoLAN
    2023-10-25 15:08 - 2023-11-03 07:42 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
    2023-10-25 15:08 - 2023-10-25 15:08 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Mozilla
    2023-10-25 15:08 - 2023-10-25 15:08 - 000000000 ____D C:\Users\ross1\AppData\Local\Mozilla
    2023-10-25 15:07 - 2023-11-03 05:16 - 000000000 ____D C:\Users\ross1\AppData\Local\D3DSCache
    2023-10-25 15:05 - 2023-10-25 15:05 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Microsoft\Spelling
    2023-10-25 14:56 - 2023-10-25 16:02 - 000000000 ____D C:\Users\ross1\AppData\Local\PlaceholderTileLogoFolder
    2023-10-25 14:54 - 2023-10-25 14:54 - 000000000 ____D C:\Users\ross1\AppData\Local\Comms
    2023-10-25 14:47 - 2023-10-25 14:47 - 000000000 ___RD C:\Users\ross1\OneDrive
    2023-10-25 14:45 - 2023-10-25 14:45 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
    2023-10-25 14:43 - 2023-11-03 09:04 - 000000000 ____D C:\Users\ross1\AppData\Local\VirtualStore
    2023-10-25 14:43 - 2023-11-03 03:55 - 000000000 ____D C:\ProgramData\Packages
    2023-10-25 14:43 - 2023-11-03 03:50 - 000000000 ____D C:\Users\ross1\AppData\Local\Packages
    2023-10-25 14:43 - 2023-10-25 16:58 - 000000000 ____D C:\Users\ross1\AppData\Local\ConnectedDevicesPlatform
    2023-10-25 14:43 - 2023-10-25 14:45 - 000000000 __RHD C:\Users\Public\AccountPictures
    2023-10-25 14:43 - 2023-10-25 14:43 - 000000000 ___SD C:\Users\ross1\AppData\Roaming\Microsoft\Crypto
    2023-10-25 14:43 - 2023-10-25 14:43 - 000000000 ___RD C:\Users\ross1\3D Objects
    2023-10-25 14:43 - 2023-10-25 14:43 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Microsoft\Vault
    2023-10-25 14:43 - 2023-10-25 14:43 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Microsoft\Network
    2023-10-25 14:43 - 2023-10-25 14:43 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Adobe
    2023-10-25 14:43 - 2023-10-25 14:43 - 000000000 ____D C:\Users\ross1\AppData\Local\Publishers
    2023-10-25 14:40 - 2023-11-02 23:45 - 000000000 ____D C:\Program Files (x86)\Intel
    2023-10-25 14:40 - 2023-11-02 21:51 - 000000000 ____D C:\Program Files\Intel
    2023-10-25 14:40 - 2023-10-25 14:40 - 000000000 ____D C:\Intel
    2023-10-25 14:39 - 2023-10-25 14:39 - 000000000 ___SD C:\Users\ross1\AppData\Roaming\Microsoft\SystemCertificates
    2023-10-25 14:39 - 2023-10-25 14:39 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
    2023-10-25 14:39 - 2023-10-25 14:39 - 000000000 ____D C:\Program Files\Synaptics
    2023-10-25 14:38 - 2023-11-03 01:20 - 000000000 ____D C:\Users\ross1
    2023-10-25 14:38 - 2023-11-02 19:14 - 000000000 ___SD C:\Users\ross1\AppData\Roaming\Microsoft\Protect
    2023-10-25 14:38 - 2023-10-25 16:13 - 000000000 ____D C:\Users\ross1\AppData\Roaming\Microsoft\Windows
    2023-10-25 14:38 - 2023-10-25 14:38 - 000000020 ___SH C:\Users\ross1\ntuser.ini
    2023-10-25 14:38 - 2023-10-25 14:38 - 000000000 ___SD C:\Users\ross1\AppData\Roaming\Microsoft\Credentials

    ==================== One month (modified) ==================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2023-11-03 09:43 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
    2023-11-03 09:11 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
    2023-11-03 05:11 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2023-11-03 05:09 - 2019-12-07 05:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
    2023-11-03 03:55 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
    2023-11-03 03:55 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
    2023-11-03 02:20 - 2019-12-07 05:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
    2023-11-03 01:49 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\NDF
    2023-11-02 23:18 - 2019-12-07 05:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2023-11-02 21:23 - 2023-05-05 08:27 - 000000000 ____D C:\WINDOWS\SystemTemp
    2023-11-02 13:48 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\appcompat
    2023-10-25 19:46 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\setup
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
    2023-10-25 19:37 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
    2023-10-25 19:36 - 2019-12-07 05:52 - 000000000 ____D C:\Program Files\Windows Photo Viewer
    2023-10-25 19:36 - 2019-12-07 05:52 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\system32\F12
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Dism
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Com
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ShellComponents
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\Provisioning
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\IME
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Windows Defender
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Common Files\System
    2023-10-25 19:36 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
    2023-10-25 19:36 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\servicing
    2023-10-25 19:27 - 2019-12-07 05:52 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
    2023-10-25 19:27 - 2019-12-07 05:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
    2023-10-25 19:27 - 2019-12-07 05:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
    2023-10-25 17:33 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2023-10-25 17:30 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\spool
    2023-10-25 17:29 - 2019-12-07 05:50 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
    2023-10-25 17:20 - 2019-12-07 05:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
    2023-10-25 15:00 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
    2023-10-25 14:34 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\USOPrivate

    ==================== SigCheck ============================

    (There is no automatic fix for files that do not pass verification.)

    ==================== End of FRST.txt ========================
     
  4. nomogoog

    nomogoog Private E-2

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-10-2023
    Ran by ross1 (03-11-2023 10:06:37)
    Running from C:\Users\ross1\Desktop
    Microsoft Windows 10 Home Version 22H2 19045.3570 (X64) (2023-10-25 21:28:19)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================


    (If an entry is included in the fixlist, it will be removed.)

    Administrator (S-1-5-21-2167588370-2769944560-668675099-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-2167588370-2769944560-668675099-503 - Limited - Disabled)
    Guest (S-1-5-21-2167588370-2769944560-668675099-501 - Limited - Disabled)
    ross1 (S-1-5-21-2167588370-2769944560-668675099-1001 - Administrator - Enabled) => C:\Users\ross1
    WDAGUtilityAccount (S-1-5-21-2167588370-2769944560-668675099-504 - Limited - Disabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Malwarebytes (Disabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543}
    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Intel(R) Graphics Driver Software (HKLM-x32\...\{e7e9dac9-c330-48d8-9e17-d21a19dc942c}) (Version: 3.11.1.0 - Intel) Hidden
    Intel(R) ME UninstallLegacy (HKLM\...\{FD37351B-3074-4652-8188-1B3FB784EC4E}) (Version: 1.0.1.0 - Intel Corporation) Hidden
    Malwarebytes version 4.6.6.294 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.6.294 - Malwarebytes)
    Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 118.0.2088.76 - Microsoft Corporation)
    Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 118.0.2088.76 - Microsoft Corporation)
    Microsoft Update Health Tools (HKLM\...\{2953E19B-9F91-4A49-A23B-7E25970A1951}) (Version: 3.73.0.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.32.31332 (HKLM-x32\...\{3746f21b-c990-4045-bb33-1cf98cff7a68}) (Version: 14.32.31332.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.32.31332 (HKLM-x32\...\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}) (Version: 14.32.31332.0 - Microsoft Corporation)
    Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332 (HKLM\...\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 (HKLM\...\{3407B900-37F5-4CC2-B612-5CD5D580A163}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2022 X86 Additional Runtime - 14.32.31332 (HKLM-x32\...\{8972AC25-452E-4FFE-945A-EB9E28C20322}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.32.31332 (HKLM-x32\...\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
    Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 119.0 (x64 en-US)) (Version: 119.0 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 119.0 - Mozilla)
    qBittorrent (HKLM-x32\...\qBittorrent) (Version: 4.6.0 - The qBittorrent project)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7564 - Realtek Semiconductor Corp.)
    RogueKiller version 15.12.2.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 15.12.2.0 - Adlice Software)
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.4.3.38 - Synaptics Incorporated)
    Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{7B63012A-4AC6-40C6-B6AF-B24A84359DD5}) (Version: 8.93.0.0 - Microsoft Corporation)
    VLC media player (HKLM\...\VLC media player) (Version: 3.0.19 - VideoLAN)
    WinRAR 6.24 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.24.0 - win.rar GmbH)

    ==================== Custom CLSID (Whitelisted): ==============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-2167588370-2769944560-668675099-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX 2020 -> Intel Corporation)
    ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
    ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-11-03] (Malwarebytes Inc. -> Malwarebytes)
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
    ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2020-08-31] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-11-03] (Malwarebytes Inc. -> Malwarebytes)
    ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)

    ==================== Codecs (Whitelisted) ====================

    ==================== Shortcuts & WMI ========================

    ==================== Loaded Modules (Whitelisted) =============

    ==================== Alternate Data Streams (Whitelisted) ========

    ==================== Safe Mode (Whitelisted) ==================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dps => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lfsvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semgrsvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\shellhwdetection => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TokenBroker => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dps => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lfsvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semgrsvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\shellhwdetection => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TokenBroker => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"

    ==================== Association (Whitelisted) =================

    ==================== Internet Explorer (Whitelisted) ==========


    ==================== Hosts content: =========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2019-12-07 05:14 - 2019-12-07 05:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

    2023-10-25 22:59 - 2023-10-25 22:59 - 000000375 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

    ==================== Other Areas ===========================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-2167588370-2769944560-668675099-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (If an entry is included in the fixlist, it will be removed.)

    HKU\S-1-5-21-2167588370-2769944560-668675099-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_D9C3DAB0B411DEA3A5BCC19B78C7E1D8"

    ==================== FirewallRules (Whitelisted) ================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{5D1B0CC5-FB23-4145-9293-B35B76BE2336}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
    FirewallRules: [{5A5A953D-26DE-424F-949D-0A0FF5E63AA7}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
    FirewallRules: [{455EFD61-4586-43DB-957A-201A2C2A2BAD}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
    FirewallRules: [{230A8489-3261-4116-A769-ACE0869F0D82}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\118.0.2088.76\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)

    ==================== Restore Points =========================


    ==================== Faulty Device Manager Devices ============

    Name:
    Description:
    Class Guid:
    Manufacturer:
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


    ==================== Event log errors: ========================

    Application errors:
    ==================
    Error: (11/03/2023 09:41:12 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on System Reserved (E:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)

    Error: (11/03/2023 09:06:21 AM) (Source: System Restore) (EventID: 8193) (User: )
    Description: Failed to create restore point (Process = C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3562_none_7e0523f67c93b82a\TiWorker.exe -Embedding; Description = Windows Modules Installer; Error = 0x80070422).

    Error: (11/03/2023 09:03:52 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on System Reserved (E:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)

    Error: (11/03/2023 04:02:27 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on System Reserved (E:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)

    Error: (11/03/2023 03:56:34 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on System Reserved (E:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)

    Error: (11/03/2023 02:01:02 AM) (Source: System Restore) (EventID: 8193) (User: )
    Description: Failed to create restore point (Process = C:\Users\ross1\Desktop\AdwCleaner.exe ; Description = AdwCleaner_BeforeCleaning_03/11/2023_02:01:01; Error = 0x80070422).

    Error: (11/02/2023 07:48:14 PM) (Source: System Restore) (EventID: 8193) (User: )
    Description: Failed to create restore point (Process = C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3562_none_7e0523f67c93b82a\TiWorker.exe -Embedding; Description = Windows Modules Installer; Error = 0x80070422).

    Error: (11/02/2023 07:41:42 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: DESKTOP-JBUIU2S)
    Description: Application or service 'TOSHIBA Function Key Main Module' could not be shut down.


    System errors:
    =============
    Error: (11/03/2023 07:53:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The SynTPEnh Caller Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (11/03/2023 07:53:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The dynabookSettingService service terminated unexpectedly. It has done this 1 time(s).

    Error: (11/03/2023 07:53:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The DSDWirelessLEDCtlService service terminated unexpectedly. It has done this 1 time(s).

    Error: (11/03/2023 07:53:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The dynabook Function Key control service service terminated unexpectedly. It has done this 1 time(s).

    Error: (11/03/2023 07:53:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Intel(R) HD Graphics Control Panel Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (11/03/2023 03:17:06 AM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 2:39:20 AM on ‎11/‎3/‎2023 was unexpected.

    Error: (11/03/2023 03:06:37 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
    Description: A corruption was discovered in the file system structure on volume C:.

    A corruption was found in a file system index structure. The file reference number is 0x1000000005344. The name of the file is "\Windows\WinSxS\Temp\InFlight". The corrupted index attribute is ":$I30:$INDEX_ALLOCATION".

    Error: (11/03/2023 03:06:29 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
    Description: A corruption was discovered in the file system structure on volume C:.

    The exact nature of the corruption is unknown. The file system structures need to be scanned online.


    Windows Defender:
    ================
    Date: 2023-11-03 09:55:18
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2023-11-03 09:41:14
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2023-11-03 09:03:57
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2023-11-03 04:02:32
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2023-11-03 03:57:03
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan
    Event[0]:

    Date: 2023-11-02 20:39:49
    Description:
    Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.399.1747.0
    Update Source: Microsoft Update Server
    Security intelligence Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.23090.2007
    Error code: 0x8007043c
    Error description: This service cannot be started in Safe Mode

    Date: 2023-11-02 20:29:39
    Description:
    Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
    Feature: On Access
    Error Code: 0x8007043c
    Error description: This service cannot be started in Safe Mode
    Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

    Date: 2023-11-02 17:53:18
    Description:
    Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
    Feature: On Access
    Error Code: 0x8007043c
    Error description: This service cannot be started in Safe Mode
    Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

    ==================== Memory info ===========================

    BIOS: Insyde Corp. 1.40 04/28/2014
    Motherboard: TOSHIBA Portable PC
    Processor: Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz
    Percentage of memory in use: 19%
    Total physical RAM: 16263.27 MB
    Available physical RAM: 13088.55 MB
    Total Virtual: 18695.27 MB
    Available Virtual: 15402.46 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:697.98 GB) (Free:651.29 GB) (Model: TOSHIBA MQ01ABD075) NTFS
    Drive d: (Repair disc Windows Recovery Env) (CDROM) (Total:0.74 GB) (Free:0 GB) UDF
    Drive e: (System Reserved) (Fixed) (Total:0.05 GB) (Free:0.04 GB) (Model: TOSHIBA MQ01ABD075) NTFS

    \\?\Volume{43b8adfd-79f7-11ee-993d-bdef00c65423}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
    \\?\Volume{43b8adfc-79f7-11ee-993d-bdef00c65423}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

    ==================== MBR & Partition Table ====================

    ==========================================================
    Disk: 0 (Size: 698.6 GB) (Disk ID: 4850BAC1)

    Partition: GPT.

    ==================== End of Addition.txt =======================
     
  5. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and thank you for your patience.

    I suspect this is a hardware/corruption related issue.

    Please do these things.

    ===================================================

    Crystal Disk Info

    --------------

    • Download Crystal Disk Info and save it to your Desktop
    • Right click on the icon and select Run as administrator
    • Select I accept the agreement and click Next 4 times
    • Click Install
    • Click Finish to launch the program
    • On the CrystalDiskInfo screen click File, then Save (text)
    • Save the file onto your Desktop using the default file name
    • Copy and paste the information in your reply
    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    SystemRestore: On
    CreateRestorePoint:
    CloseProcesses:
    S3 IntelCseWNP; \??\C:\Windows\system32\drivers\wnpdriver.sys [X] 
    ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File 
    ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File 
    ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File 
    ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File 
    ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File 
    ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File 
    ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File 
    ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File 
    ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File 
    ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File 
    ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File 
    ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File 
    ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File 
    ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File 
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File 
    S3 iscFlash; C:\Users\ross1\AppData\Local\Temp\7zS3F2.tmp\iscflashx64.sys [60680 2013-02-24] (Insyde Software Corp. -> Insyde Software) <==== ATTENTION 
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) 
    S3 iscFlash; C:\Users\ross1\AppData\Local\Temp\7zS3F2.tmp\iscflashx64.sys [60680 2013-02-24] (Insyde Software Corp. -> Insyde Software) <==== ATTENTION 
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    cmd: chkdsk
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Running Chkdsk /r From Command Prompt

    --------------------

    • Click Start, type cmd, then select Run as administrator
    • Copy and paste the following after the command prompt and press Enter
    cmd /c echo y|chkdsk /r c: /r | shutdown /r /t 05
    • Please allow the system to reboot on its own and run the program. This may take a bit of time
    • When completed your system will automatically reboot
    ===================================================

    ListChkdskResult by SleepyDude

    --------------------

    • Download ListChkdskResult and save it to your Desktop
    • Right click on the file and select Run as administrator
    • Copy and paste the contents of the ListChkdskResult.txt report in your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • CrystalDiskInfo information
    • Fixlog
    • ListChkdskResult.txt
     
  6. nomogoog

    nomogoog Private E-2

    ----------------------------------------------------------------------------
    CrystalDiskInfo 9.1.1 (C) 2008-2023 hiyohiyo
    Crystal Dew World: https://crystalmark.info/
    ----------------------------------------------------------------------------

    OS : Windows 10 [10.0 Build 19045] (x64)
    Date : 2023/11/04 16:25:38

    -- Controller Map ----------------------------------------------------------
    + Standard SATA AHCI Controller [ATA]
    - TOSHIBA MQ01ABD075
    - MATSHITA DVD-RAM UJ8C2
    - Microsoft Storage Spaces Controller [SCSI]

    -- Disk List ---------------------------------------------------------------
    (01) TOSHIBA MQ01ABD075 : 750.1 GB [0/0/0, pd1]

    ----------------------------------------------------------------------------
    (01) TOSHIBA MQ01ABD075
    ----------------------------------------------------------------------------
    Model : TOSHIBA MQ01ABD075
    Firmware : AX0A4M
    Serial Number : 63O2SAHNS
    Disk Size : 750.1 GB (8.4/137.4/750.1/750.1)
    Buffer Size : 8192 KB
    Queue Depth : 32
    # of Sectors : 1465149168
    Rotation Rate : 5400 RPM
    Interface : Serial ATA
    Major Version : ATA8-ACS
    Minor Version : ----
    Transfer Mode : SATA/300 | SATA/300
    Power On Hours : 50677 hours
    Power On Count : 6051 count
    Temperature : 36 C (96 F)
    Health Status : Good
    Features : S.M.A.R.T., APM, NCQ, GPL
    APM Level : 0080h [ON]
    AAM Level : ----
    Drive Letter : C: E:

    -- S.M.A.R.T. --------------------------------------------------------------
    ID Cur Wor Thr RawValues(6) Attribute Name
    01 100 100 _50 000000000000 Read Error Rate
    02 100 100 _50 000000000000 Throughput Performance
    03 100 100 __1 00000000069E Spin-Up Time
    04 100 100 __0 00000000180A Start/Stop Count
    05 100 100 _50 000000000000 Reallocated Sectors Count
    07 100 100 _50 000000000000 Seek Error Rate
    08 100 100 _50 000000000000 Seek Time Performance
    09 __1 __1 __0 00000000C5F5 Power-On Hours
    0A 222 100 _30 000000000000 Spin Retry Count
    0C 100 100 __0 0000000017A3 Power Cycle Count
    BF 100 100 __0 0000000001CE G-Sense Error Rate
    C0 100 100 __0 00000000008D Power-off Retract Count
    C1 _18 _18 __0 0000000C87D3 Load/Unload Cycle Count
    C2 100 100 __0 003F00050024 Temperature
    C4 100 100 __0 000000000000 Reallocation Event Count
    C5 100 100 __0 000000000000 Current Pending Sector Count
    C6 100 100 __0 000000000000 Uncorrectable Sector Count
    C7 200 200 __0 000000000001 UltraDMA CRC Error Count
    DC 100 100 __0 000000000000 Disk Shift
    DE __1 __1 __0 00000000A374 Loaded Hours
    DF 100 100 __0 000000000000 Load/Unload Retry Count
    E0 100 100 __0 000000000000 Load Friction
    E2 100 100 __0 0000000000AF Load 'In'-time
    F0 100 100 __1 000000000000 Head Flying Hours

    -- IDENTIFY_DEVICE ---------------------------------------------------------
    0 1 2 3 4 5 6 7 8 9
    000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
    010: 2020 2020 2020 2020 2020 2036 334F 3253 4148 4E53
    020: 0000 4000 0000 4158 3041 344D 2020 544F 5348 4942
    030: 4120 4D51 3031 4142 4430 3735 2020 2020 2020 2020
    040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
    050: 4000 0200 0000 0007 3FFF 0010 003F FC10 00FB 0110
    060: FFFF 0FFF 0007 0407 0003 0078 0078 0078 0078 0000
    070: 0000 0000 0000 0000 0000 001F 0F06 0004 004C 0040
    080: 01F8 0000 746B 7D09 6163 7469 BC09 6163 003F 0058
    090: 0058 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
    100: 66F0 5754 0000 0000 0000 0000 4000 0000 5000 0394
    110: D568 64F8 0000 0000 0000 0000 0000 0000 0000 401C
    120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
    130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
    140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
    150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
    160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
    170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
    180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
    190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
    200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 0000
    210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
    220: 0000 0000 101F 0000 0000 0000 0000 0000 0000 0000
    230: 0000 0000 0000 0000 0001 0080 0000 0000 0000 0000
    240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
    250: 0000 0000 0000 0000 0000 4CA5

    -- SMART_READ_DATA ---------------------------------------------------------
    +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
    000: 10 00 01 0B 00 64 64 00 00 00 00 00 00 00 02 05
    010: 00 64 64 00 00 00 00 00 00 00 03 27 00 64 64 9E
    020: 06 00 00 00 00 00 04 32 00 64 64 0A 18 00 00 00
    030: 00 00 05 33 00 64 64 00 00 00 00 00 00 00 07 0B
    040: 00 64 64 00 00 00 00 00 00 00 08 05 00 64 64 00
    050: 00 00 00 00 00 00 09 32 00 01 01 F5 C5 00 00 00
    060: 00 00 0A 33 00 DE 64 00 00 00 00 00 00 00 0C 32
    070: 00 64 64 A3 17 00 00 00 00 00 BF 32 00 64 64 CE
    080: 01 00 00 00 00 00 C0 32 00 64 64 8D 00 00 00 00
    090: 00 00 C1 32 00 12 12 D3 87 0C 00 00 00 00 C2 22
    0A0: 00 64 64 24 00 05 00 3F 00 00 C4 32 00 64 64 00
    0B0: 00 00 00 00 00 00 C5 32 00 64 64 00 00 00 00 00
    0C0: 00 00 C6 30 00 64 64 00 00 00 00 00 00 00 C7 32
    0D0: 00 C8 C8 01 00 00 00 00 00 00 DC 02 00 64 64 00
    0E0: 00 00 00 00 00 00 DE 32 00 01 01 74 A3 00 00 00
    0F0: 00 00 DF 32 00 64 64 00 00 00 00 00 00 00 E0 22
    100: 00 64 64 00 00 00 00 00 00 00 E2 26 00 64 64 AF
    110: 00 00 00 00 00 00 F0 01 00 64 64 00 00 00 00 00
    120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    160: 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 5B
    170: 03 00 01 00 02 BD 00 00 00 00 00 00 00 00 00 00
    180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4D

    -- SMART_READ_THRESHOLD ----------------------------------------------------
    +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
    000: 10 00 01 32 00 00 00 00 00 00 00 00 00 00 02 32
    010: 00 00 00 00 00 00 00 00 00 00 03 01 00 00 00 00
    020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00
    030: 00 00 05 32 00 00 00 00 00 00 00 00 00 00 07 32
    040: 00 00 00 00 00 00 00 00 00 00 08 32 00 00 00 00
    050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00
    060: 00 00 0A 1E 00 00 00 00 00 00 00 00 00 00 0C 00
    070: 00 00 00 00 00 00 00 00 00 00 BF 00 00 00 00 00
    080: 00 00 00 00 00 00 C0 00 00 00 00 00 00 00 00 00
    090: 00 00 C1 00 00 00 00 00 00 00 00 00 00 00 C2 00
    0A0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00
    0B0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00
    0C0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00
    0D0: 00 00 00 00 00 00 00 00 00 00 DC 00 00 00 00 00
    0E0: 00 00 00 00 00 00 DE 00 00 00 00 00 00 00 00 00
    0F0: 00 00 DF 00 00 00 00 00 00 00 00 00 00 00 E0 00
    100: 00 00 00 00 00 00 00 00 00 00 E2 00 00 00 00 00
    110: 00 00 00 00 00 00 F0 01 00 00 00 00 00 00 00 00
    120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 36
     
  7. nomogoog

    nomogoog Private E-2

    I am not sure but I do not think chkdsk ran after initial restart because it restarted straight to login screen, and I'm just remembering that the last time I tried to run chkdsk it said it couldn't run because the files were missing but this was before I repaired windows.
    Fix result of Farbar Recovery Scan Tool (x64) Version: 03-10-2023
    Ran by ross1 (04-11-2023 16:27:57) Run:1
    Running from C:\Users\ross1\Desktop
    Loaded Profiles: ross1
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    SystemRestore: On
    CreateRestorePoint:
    CloseProcesses:
    S3 IntelCseWNP; \??\C:\Windows\system32\drivers\wnpdriver.sys [X]
    ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
    ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
    ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
    S3 iscFlash; C:\Users\ross1\AppData\Local\Temp\7zS3F2.tmp\iscflashx64.sys [60680 2013-02-24] (Insyde Software Corp. -> Insyde Software) <==== ATTENTION
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    S3 iscFlash; C:\Users\ross1\AppData\Local\Temp\7zS3F2.tmp\iscflashx64.sys [60680 2013-02-24] (Insyde Software Corp. -> Insyde Software) <==== ATTENTION
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    cmd: chkdsk
    End::
    *****************

    SystemRestore: On => completed
    Restore point was successfully created.
    Processes closed successfully.
    HKLM\System\CurrentControlSet\Services\IntelCseWNP => removed successfully
    IntelCseWNP => service removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
    HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
    HKLM\System\CurrentControlSet\Services\iscFlash => removed successfully
    iscFlash => service removed successfully
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) => Error: No automatic fix found for this entry.
    iscFlash => service not found.

    ========= sfc /scannow =========



    Beginning system scan. This process will take some time.



    Beginning verification phase of system scan.


    Verification 0% complete.
    Verification 1% complete.
    Verification 1% complete.
    Verification 2% complete.
    Verification 3% complete.
    Verification 3% complete.
    Verification 4% complete.
    Verification 4% complete.
    Verification 5% complete.
    Verification 6% complete.
    Verification 6% complete.
    Verification 7% complete.
    Verification 8% complete.
    Verification 8% complete.
    Verification 9% complete.
    Verification 9% complete.
    Verification 10% complete.
    Verification 11% complete.
    Verification 11% complete.
    Verification 12% complete.
    Verification 13% complete.
    Verification 13% complete.
    Verification 14% complete.
    Verification 14% complete.
    Verification 15% complete.
    Verification 16% complete.
    Verification 16% complete.
    Verification 17% complete.
    Verification 18% complete.
    Verification 18% complete.
    Verification 19% complete.
    Verification 19% complete.
    Verification 20% complete.
    Verification 21% complete.
    Verification 21% complete.
    Verification 22% complete.
    Verification 23% complete.
    Verification 23% complete.
    Verification 24% complete.
    Verification 24% complete.
    Verification 25% complete.
    Verification 26% complete.
    Verification 26% complete.
    Verification 27% complete.
    Verification 28% complete.
    Verification 28% complete.
    Verification 29% complete.
    Verification 29% complete.
    Verification 30% complete.
    Verification 31% complete.
    Verification 31% complete.
    Verification 32% complete.
    Verification 33% complete.
    Verification 33% complete.
    Verification 34% complete.
    Verification 34% complete.
    Verification 35% complete.
    Verification 36% complete.
    Verification 36% complete.
    Verification 37% complete.
    Verification 38% complete.
    Verification 38% complete.
    Verification 39% complete.
    Verification 39% complete.
    Verification 40% complete.
    Verification 41% complete.
    Verification 41% complete.
    Verification 42% complete.
    Verification 43% complete.
    Verification 43% complete.
    Verification 44% complete.
    Verification 44% complete.
    Verification 45% complete.
    Verification 46% complete.
    Verification 46% complete.
    Verification 47% complete.
    Verification 48% complete.
    Verification 48% complete.
    Verification 49% complete.
    Verification 49% complete.
    Verification 50% complete.
    Verification 51% complete.
    Verification 51% complete.
    Verification 52% complete.
    Verification 53% complete.
    Verification 53% complete.
    Verification 54% complete.
    Verification 54% complete.
    Verification 55% complete.
    Verification 56% complete.
    Verification 56% complete.
    Verification 57% complete.
    Verification 58% complete.
    Verification 58% complete.
    Verification 59% complete.
    Verification 59% complete.
    Verification 60% complete.
    Verification 61% complete.
    Verification 61% complete.
    Verification 62% complete.
    Verification 63% complete.
    Verification 63% complete.
    Verification 64% complete.
    Verification 64% complete.
    Verification 65% complete.
    Verification 66% complete.
    Verification 66% complete.
    Verification 67% complete.
    Verification 68% complete.
    Verification 68% complete.
    Verification 69% complete.
    Verification 69% complete.
    Verification 70% complete.
    Verification 71% complete.
    Verification 71% complete.
    Verification 72% complete.
    Verification 72% complete.
    Verification 73% complete.
    Verification 74% complete.
    Verification 74% complete.
    Verification 75% complete.
    Verification 76% complete.
    Verification 76% complete.
    Verification 77% complete.
    Verification 77% complete.
    Verification 78% complete.
    Verification 79% complete.
    Verification 79% complete.
    Verification 80% complete.
    Verification 81% complete.
    Verification 81% complete.
    Verification 82% complete.
    Verification 82% complete.
    Verification 83% complete.
    Verification 84% complete.
    Verification 84% complete.
    Verification 85% complete.
    Verification 86% complete.
    Verification 86% complete.
    Verification 87% complete.
    Verification 87% complete.
    Verification 88% complete.
    Verification 89% complete.
    Verification 89% complete.
    Verification 90% complete.
    Verification 91% complete.
    Verification 91% complete.
    Verification 92% complete.
    Verification 92% complete.
    Verification 93% complete.
    Verification 94% complete.
    Verification 94% complete.
    Verification 95% complete.
    Verification 96% complete.
    Verification 96% complete.
    Verification 97% complete.
    Verification 97% complete.
    Verification 98% complete.
    Verification 99% complete.
    Verification 99% complete.
    Verification 100% complete.


    Windows Resource Protection found corrupt files and successfully repaired them.

    For online repairs, details are included in the CBS log file located at

    windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline

    repairs, details are included in the log file provided by the /OFFLOGFILE flag.



    ========= End of CMD: =========


    ========= DISM /Online /Cleanup-Image /CheckHealth =========


    Deployment Image Servicing and Management tool
    Version: 10.0.19041.3570

    Image Version: 10.0.19045.3570

    No component store corruption detected.
    The operation completed successfully.


    ========= End of CMD: =========


    ========= chkdsk =========

    The type of the file system is NTFS.

    WARNING! /F parameter not specified.
    Running CHKDSK in read-only mode.

    Stage 1: Examining basic file system structure ...
    Progress: 0 of 327424 done; Stage: 0%; Total: 0%; ETA: 0:15:46
    Progress: 5288 of 327424 done; Stage: 1%; Total: 0%; ETA: 0:15:42 .
    Progress: 11265 of 327424 done; Stage: 3%; Total: 1%; ETA: 0:15:35 ..
    Progress: 20544 of 327424 done; Stage: 6%; Total: 2%; ETA: 0:00:51 ...
    Progress: 28765 of 327424 done; Stage: 8%; Total: 3%; ETA: 0:00:48
    Progress: 29153 of 327424 done; Stage: 8%; Total: 3%; ETA: 0:00:58 .
    Progress: 37134 of 327424 done; Stage: 11%; Total: 4%; ETA: 0:00:57 ..
    Progress: 39007 of 327424 done; Stage: 11%; Total: 4%; ETA: 0:01:02 ...
    Progress: 39092 of 327424 done; Stage: 11%; Total: 4%; ETA: 0:01:12
    Progress: 44406 of 327424 done; Stage: 13%; Total: 5%; ETA: 0:01:13 .
    Progress: 53186 of 327424 done; Stage: 16%; Total: 6%; ETA: 0:01:08 ..
    Progress: 57343 of 327424 done; Stage: 17%; Total: 6%; ETA: 0:01:08 ...
    Progress: 73993 of 327424 done; Stage: 22%; Total: 8%; ETA: 0:01:00
    Progress: 96513 of 327424 done; Stage: 29%; Total: 11%; ETA: 0:00:51 .
    Progress: 112195 of 327424 done; Stage: 34%; Total: 12%; ETA: 0:00:46 ..
    Progress: 127438 of 327424 done; Stage: 38%; Total: 14%; ETA: 0:00:43 ...
    Progress: 154220 of 327424 done; Stage: 47%; Total: 17%; ETA: 0:00:38
    Progress: 181505 of 327424 done; Stage: 55%; Total: 19%; ETA: 0:00:33 .
    Progress: 208129 of 327424 done; Stage: 63%; Total: 22%; ETA: 0:00:30 ..
    Progress: 233729 of 327424 done; Stage: 71%; Total: 25%; ETA: 0:00:27 ...
    Progress: 260097 of 327424 done; Stage: 79%; Total: 28%; ETA: 0:00:25
    Progress: 281601 of 327424 done; Stage: 86%; Total: 30%; ETA: 0:00:23 .
    Progress: 301021 of 327424 done; Stage: 91%; Total: 32%; ETA: 0:00:22 ..
    Progress: 317308 of 327424 done; Stage: 96%; Total: 34%; ETA: 0:00:22 ...
    Progress: 327424 of 327424 done; Stage: 100%; Total: 35%; ETA: 0:00:20


    327424 file records processed.

    File verification completed.
    Phase duration (File record verification): 11.08 seconds.
    Progress: 10298 of 10298 done; Stage: 100%; Total: 24%; ETA: 0:00:33 .


    10298 large file records processed.

    Phase duration (Orphan file record recovery): 0.00 milliseconds.
    Progress: 0 of 0 done; Stage: 99%; Total: 24%; ETA: 0:00:33 ..


    0 bad file records processed.

    Phase duration (Bad file record checking): 0.08 milliseconds.

    Stage 2: Examining file name linkage ...
    Progress: 21970 of 514010 done; Stage: 4%; Total: 26%; ETA: 0:00:33 ...
    Progress: 64002 of 514010 done; Stage: 12%; Total: 29%; ETA: 0:00:30
    Progress: 111846 of 514010 done; Stage: 21%; Total: 32%; ETA: 0:00:27 .
    Progress: 155611 of 514010 done; Stage: 30%; Total: 35%; ETA: 0:00:23 ..
    Progress: 208218 of 514010 done; Stage: 40%; Total: 39%; ETA: 0:00:22 ...
    Progress: 249550 of 514010 done; Stage: 48%; Total: 42%; ETA: 0:00:20
    Progress: 297613 of 514010 done; Stage: 57%; Total: 46%; ETA: 0:00:17 .
    Progress: 146 of 146 done; Stage: 100%; Total: 48%; ETA: 0:00:17 ..


    146 reparse records processed.

    Progress: 327572 of 514010 done; Stage: 63%; Total: 48%; ETA: 0:00:17 ...
    Progress: 328624 of 514010 done; Stage: 63%; Total: 48%; ETA: 0:00:17
    Progress: 329103 of 514010 done; Stage: 64%; Total: 49%; ETA: 0:00:17 .
    Progress: 330190 of 514010 done; Stage: 64%; Total: 49%; ETA: 0:00:17 ..
    Progress: 330909 of 514010 done; Stage: 64%; Total: 50%; ETA: 0:00:17 ...
    Progress: 331198 of 514010 done; Stage: 64%; Total: 50%; ETA: 0:00:17
    Progress: 331642 of 514010 done; Stage: 64%; Total: 50%; ETA: 0:00:17 .
    Progress: 332088 of 514010 done; Stage: 64%; Total: 51%; ETA: 0:00:17 ..
    Progress: 332114 of 514010 done; Stage: 64%; Total: 53%; ETA: 0:00:17 ...
    Progress: 332535 of 514010 done; Stage: 64%; Total: 53%; ETA: 0:00:17
    Progress: 332874 of 514010 done; Stage: 64%; Total: 53%; ETA: 0:00:17 .
    Progress: 333130 of 514010 done; Stage: 64%; Total: 53%; ETA: 0:00:17 ..
    Progress: 333535 of 514010 done; Stage: 64%; Total: 53%; ETA: 0:00:17 ...
    Progress: 333828 of 514010 done; Stage: 64%; Total: 53%; ETA: 0:00:17
    Progress: 334001 of 514010 done; Stage: 64%; Total: 53%; ETA: 0:00:17 .
    Progress: 334236 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:19 ..
    Progress: 334450 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:19 ...
    Progress: 334812 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:19
    Progress: 335032 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:19 .
    Progress: 335368 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:19 ..
    Progress: 335633 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:20 ...
    Progress: 335899 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:20
    Progress: 336136 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:20 .
    Progress: 336332 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:20 ..
    Progress: 336606 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:22 ...
    Progress: 337097 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:22
    Progress: 337469 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:22 .
    Progress: 337706 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:22 ..
    Progress: 338021 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:24 ...
    Progress: 338220 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:24
    Progress: 338700 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:24 .
    Progress: 338908 of 514010 done; Stage: 65%; Total: 54%; ETA: 0:00:24 ..
    Progress: 339212 of 514010 done; Stage: 65%; Total: 55%; ETA: 0:00:24 ...
    Progress: 339578 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:25
    Progress: 339804 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:25 .
    Progress: 340028 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:25 ..
    Progress: 340375 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:25 ...
    Progress: 340539 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:25
    Progress: 340789 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:27 .
    Progress: 341109 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:27 ..
    Progress: 341369 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:27 ...
    Progress: 341655 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:27
    Progress: 342057 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:27 .
    Progress: 342400 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:28 ..
    Progress: 342557 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:28 ...
    Progress: 342727 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:28
    Progress: 342925 of 514010 done; Stage: 66%; Total: 55%; ETA: 0:00:28 .
    Progress: 343114 of 514010 done; Stage: 66%; Total: 56%; ETA: 0:00:28 ..
    Progress: 343325 of 514010 done; Stage: 66%; Total: 56%; ETA: 0:00:30 ...
    Progress: 343600 of 514010 done; Stage: 66%; Total: 56%; ETA: 0:00:30
    Progress: 343905 of 514010 done; Stage: 66%; Total: 56%; ETA: 0:00:30 .
    Progress: 344214 of 514010 done; Stage: 66%; Total: 56%; ETA: 0:00:30 ..
    Progress: 344665 of 514010 done; Stage: 67%; Total: 56%; ETA: 0:00:30 ...
    Progress: 344935 of 514010 done; Stage: 67%; Total: 56%; ETA: 0:00:32
    Progress: 345188 of 514010 done; Stage: 67%; Total: 56%; ETA: 0:00:32 .
    Progress: 345433 of 514010 done; Stage: 67%; Total: 56%; ETA: 0:00:32 ..
    Progress: 345791 of 514010 done; Stage: 67%; Total: 56%; ETA: 0:00:32 ...
    Progress: 346166 of 514010 done; Stage: 67%; Total: 56%; ETA: 0:00:32
    Progress: 346583 of 514010 done; Stage: 67%; Total: 56%; ETA: 0:00:32 .
    Progress: 347035 of 514010 done; Stage: 67%; Total: 56%; ETA: 0:00:33 ..
    Progress: 347786 of 514010 done; Stage: 67%; Total: 57%; ETA: 0:00:33 ...
    Progress: 347969 of 514010 done; Stage: 67%; Total: 57%; ETA: 0:00:33
    Progress: 347971 of 514010 done; Stage: 67%; Total: 61%; ETA: 0:00:33 .
    Progress: 348431 of 514010 done; Stage: 67%; Total: 61%; ETA: 0:00:30 ..
    Progress: 348643 of 514010 done; Stage: 67%; Total: 61%; ETA: 0:00:30 ...
    Progress: 349000 of 514010 done; Stage: 67%; Total: 61%; ETA: 0:00:30
    Progress: 349305 of 514010 done; Stage: 67%; Total: 61%; ETA: 0:00:30 .
    Progress: 349660 of 514010 done; Stage: 68%; Total: 61%; ETA: 0:00:30 ..
    Progress: 350034 of 514010 done; Stage: 68%; Total: 61%; ETA: 0:00:30 ...
    Progress: 350594 of 514010 done; Stage: 68%; Total: 61%; ETA: 0:00:30
    Progress: 350988 of 514010 done; Stage: 68%; Total: 61%; ETA: 0:00:30 .
    Progress: 351314 of 514010 done; Stage: 68%; Total: 61%; ETA: 0:00:30 ..
    Progress: 351647 of 514010 done; Stage: 68%; Total: 61%; ETA: 0:00:30 ...
    Progress: 351853 of 514010 done; Stage: 68%; Total: 62%; ETA: 0:00:30
    Progress: 352217 of 514010 done; Stage: 68%; Total: 62%; ETA: 0:00:32 .
    Progress: 352504 of 514010 done; Stage: 68%; Total: 62%; ETA: 0:00:32 ..
    Progress: 352775 of 514010 done; Stage: 68%; Total: 62%; ETA: 0:00:32 ...
    Progress: 353109 of 514010 done; Stage: 68%; Total: 62%; ETA: 0:00:32
    Progress: 353416 of 514010 done; Stage: 68%; Total: 62%; ETA: 0:00:32 .
    Progress: 353804 of 514010 done; Stage: 68%; Total: 62%; ETA: 0:00:32 ..
    Progress: 354023 of 514010 done; Stage: 68%; Total: 62%; ETA: 0:00:32 ...
    Progress: 354448 of 514010 done; Stage: 68%; Total: 62%; ETA: 0:00:33
    Progress: 355061 of 514010 done; Stage: 69%; Total: 62%; ETA: 0:00:33 .
    Progress: 355147 of 514010 done; Stage: 69%; Total: 63%; ETA: 0:00:33 ..
    Progress: 355459 of 514010 done; Stage: 69%; Total: 63%; ETA: 0:00:33 ...
    Progress: 355697 of 514010 done; Stage: 69%; Total: 63%; ETA: 0:00:33
    Progress: 356199 of 514010 done; Stage: 69%; Total: 63%; ETA: 0:00:33 .
    Progress: 356489 of 514010 done; Stage: 69%; Total: 63%; ETA: 0:00:33 ..
    Progress: 356808 of 514010 done; Stage: 69%; Total: 64%; ETA: 0:00:33 ...
    Progress: 357677 of 514010 done; Stage: 69%; Total: 64%; ETA: 0:00:33
    Progress: 357913 of 514010 done; Stage: 69%; Total: 64%; ETA: 0:00:33 .
    Progress: 358062 of 514010 done; Stage: 69%; Total: 64%; ETA: 0:00:33 ..
    Progress: 358302 of 514010 done; Stage: 69%; Total: 64%; ETA: 0:00:33 ...
    Progress: 358545 of 514010 done; Stage: 69%; Total: 64%; ETA: 0:00:33
    Progress: 358825 of 514010 done; Stage: 69%; Total: 64%; ETA: 0:00:33 .
    Progress: 359465 of 514010 done; Stage: 69%; Total: 64%; ETA: 0:00:33 ..
    Progress: 359714 of 514010 done; Stage: 69%; Total: 64%; ETA: 0:00:33 ...
    Progress: 359717 of 514010 done; Stage: 69%; Total: 73%; ETA: 0:00:33
    Progress: 359719 of 514010 done; Stage: 69%; Total: 73%; ETA: 0:00:32 .
    Progress: 360502 of 514010 done; Stage: 70%; Total: 73%; ETA: 0:00:25 ..
    Progress: 360605 of 514010 done; Stage: 70%; Total: 73%; ETA: 0:00:25 ...
    Progress: 360702 of 514010 done; Stage: 70%; Total: 73%; ETA: 0:00:25
    Progress: 361143 of 514010 done; Stage: 70%; Total: 73%; ETA: 0:00:25 .
    Progress: 361974 of 514010 done; Stage: 70%; Total: 72%; ETA: 0:00:25 ..
    Progress: 362915 of 514010 done; Stage: 70%; Total: 73%; ETA: 0:00:25 ...
    Progress: 364869 of 514010 done; Stage: 70%; Total: 73%; ETA: 0:00:25
    Progress: 364870 of 514010 done; Stage: 70%; Total: 73%; ETA: 0:00:25 .
    Progress: 365890 of 514010 done; Stage: 71%; Total: 73%; ETA: 0:00:25 ..
    Progress: 369427 of 514010 done; Stage: 71%; Total: 73%; ETA: 0:00:25 ...
    Progress: 374620 of 514010 done; Stage: 72%; Total: 74%; ETA: 0:00:25
    Progress: 383837 of 514010 done; Stage: 74%; Total: 75%; ETA: 0:00:23 .
    Progress: 389724 of 514010 done; Stage: 75%; Total: 75%; ETA: 0:00:23 ..
    Progress: 395706 of 514010 done; Stage: 76%; Total: 76%; ETA: 0:00:23 ...
    Progress: 403421 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:22
    Progress: 403790 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:22 .
    Progress: 403859 of 514010 done; Stage: 78%; Total: 77%; ETA: 0:00:22 ..
    Progress: 403970 of 514010 done; Stage: 78%; Total: 77%; ETA: 0:00:22 ...
    Progress: 404097 of 514010 done; Stage: 78%; Total: 77%; ETA: 0:00:22
    Progress: 404247 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:22 .
    Progress: 404362 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:24 ..
    Progress: 404492 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:24 ...
    Progress: 404607 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:24
    Progress: 404687 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:24 .
    Progress: 404840 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:24 ..
    Progress: 405143 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:24 ...
    Progress: 405428 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:24
    Progress: 405834 of 514010 done; Stage: 78%; Total: 76%; ETA: 0:00:24 .
    Progress: 406139 of 514010 done; Stage: 79%; Total: 76%; ETA: 0:00:24 ..
    Progress: 406685 of 514010 done; Stage: 79%; Total: 76%; ETA: 0:00:24 ...
    Progress: 407302 of 514010 done; Stage: 79%; Total: 76%; ETA: 0:00:24
    Progress: 408199 of 514010 done; Stage: 79%; Total: 77%; ETA: 0:00:24 .
    Progress: 408679 of 514010 done; Stage: 79%; Total: 77%; ETA: 0:00:24 ..
    Progress: 409099 of 514010 done; Stage: 79%; Total: 77%; ETA: 0:00:24 ...
    Progress: 409446 of 514010 done; Stage: 79%; Total: 77%; ETA: 0:00:24
    Progress: 409707 of 514010 done; Stage: 79%; Total: 77%; ETA: 0:00:24 .
    Progress: 410491 of 514010 done; Stage: 79%; Total: 77%; ETA: 0:00:24 ..
    Progress: 411006 of 514010 done; Stage: 79%; Total: 77%; ETA: 0:00:24 ...
    Progress: 411356 of 514010 done; Stage: 80%; Total: 77%; ETA: 0:00:24
    Progress: 411644 of 514010 done; Stage: 80%; Total: 77%; ETA: 0:00:24 .
    Progress: 411955 of 514010 done; Stage: 80%; Total: 77%; ETA: 0:00:24 ..
    Progress: 412513 of 514010 done; Stage: 80%; Total: 77%; ETA: 0:00:24 ...
    Progress: 413091 of 514010 done; Stage: 80%; Total: 77%; ETA: 0:00:24
    Progress: 413519 of 514010 done; Stage: 80%; Total: 78%; ETA: 0:00:24 .
    Progress: 414048 of 514010 done; Stage: 80%; Total: 78%; ETA: 0:00:24 ..
    Progress: 414544 of 514010 done; Stage: 80%; Total: 78%; ETA: 0:00:24 ...
    Progress: 415005 of 514010 done; Stage: 80%; Total: 77%; ETA: 0:00:25
    Progress: 415391 of 514010 done; Stage: 80%; Total: 77%; ETA: 0:00:25 .
    Progress: 415945 of 514010 done; Stage: 80%; Total: 77%; ETA: 0:00:25 ..
    Progress: 416251 of 514010 done; Stage: 80%; Total: 77%; ETA: 0:00:25 ...
    Progress: 416537 of 514010 done; Stage: 81%; Total: 77%; ETA: 0:00:25
    Progress: 416889 of 514010 done; Stage: 81%; Total: 77%; ETA: 0:00:25 .
    Progress: 417132 of 514010 done; Stage: 81%; Total: 77%; ETA: 0:00:25 ..
    Progress: 417487 of 514010 done; Stage: 81%; Total: 77%; ETA: 0:00:25 ...
    Progress: 417759 of 514010 done; Stage: 81%; Total: 77%; ETA: 0:00:25
    Progress: 418025 of 514010 done; Stage: 81%; Total: 77%; ETA: 0:00:25 .
    Progress: 418394 of 514010 done; Stage: 81%; Total: 77%; ETA: 0:00:25 ..
    Progress: 418732 of 514010 done; Stage: 81%; Total: 77%; ETA: 0:00:25 ...
    Progress: 418865 of 514010 done; Stage: 81%; Total: 77%; ETA: 0:00:25
    Progress: 419199 of 514010 done; Stage: 81%; Total: 78%; ETA: 0:00:25 .
    Progress: 420157 of 514010 done; Stage: 81%; Total: 78%; ETA: 0:00:25 ..
    Progress: 420363 of 514010 done; Stage: 81%; Total: 78%; ETA: 0:00:25 ...
    Progress: 420646 of 514010 done; Stage: 81%; Total: 78%; ETA: 0:00:25
    Progress: 420715 of 514010 done; Stage: 81%; Total: 78%; ETA: 0:00:25 .
    Progress: 514010 of 514010 done; Stage: 100%; Total: 78%; ETA: 0:00:25 ..


    514010 index entries processed.

    Index verification completed.
    Phase duration (Index verification): 1.45 minutes.
    Progress: 1 of 0 done; Stage: 99%; Total: 78%; ETA: 0:00:25 ...
    Progress: 0 of 0 done; Stage: 99%; Total: 78%; ETA: 0:00:25


    0 unindexed files scanned.

    Phase duration (Orphan reconnection): 1.91 seconds.
    Progress: 0 of 0 done; Stage: 99%; Total: 78%; ETA: 0:00:25 .


    0 unindexed files recovered to lost and found.

    Phase duration (Orphan recovery to lost and found): 0.09 milliseconds.
    Progress: 146 of 146 done; Stage: 100%; Total: 78%; ETA: 0:00:25 ..


    146 reparse records processed.

    Phase duration (Reparse point and Object ID verification): 2.98 milliseconds.

    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.
    Phase duration (Security descriptor verification): 96.94 milliseconds.
    Progress: 11 of 11 done; Stage: 100%; Total: 99%; ETA: 0:00:00 ...


    93294 data files processed.

    Phase duration (Data attribute verification): 0.11 milliseconds.
    CHKDSK is verifying Usn Journal...
    Progress: 0 of 4493 done; Stage: 0%; Total: 99%; ETA: 0:00:00
    Progress: 3281 of 4493 done; Stage: 73%; Total: 97%; ETA: 0:00:03 .
    Progress: 4493 of 4493 done; Stage: 100%; Total: 98%; ETA: 0:00:03 ..


    36811200 USN bytes processed.

    Usn Journal verification completed.
    Phase duration (USN journal verification): 486.00 milliseconds.

    Windows has scanned the file system and found no problems.
    No further action is required.

    731881714 KB total disk space.
    71892356 KB in 223704 files.
    154672 KB in 93295 indexes.
    0 KB in bad sectors.
    455626 KB in use by the system.
    65536 KB occupied by the log file.
    659379060 KB available on disk.

    4096 bytes in each allocation unit.
    182970428 total allocation units on disk.
    164844765 allocation units available on disk.
    Total duration: 1.68 minutes (100977 ms).


    ========= End of CMD: =========



    The system needed a reboot.

    ==== End of Fixlog 16:36:20 ====
     
  8. nomogoog

    nomogoog Private E-2

    ListChkdskResult by SleepyDude v0.1.7 Beta | 21-09-2013

    ------< Log generate on 11/4/2023 4:48:35 PM >------
    Category: 0
    Computer Name: DESKTOP-JBUIU2S
    Event Code: 26212
    Record Number: 2602
    Source Name: Chkdsk
    Time Written: 11-04-2023 @ 20:36:19
    Event Type: Information
    User:
    Message: Chkdsk was executed in read-only mode on a volume snapshot.

    Checking file system on C:
    The type of the file system is NTFS.

    WARNING! /F parameter not specified.
    Running CHKDSK in read-only mode.

    Stage 1: Examining basic file system structure ...
    327424 file records processed.

    File verification completed.
    Phase duration (File record verification): 11.08 seconds.
    10298 large file records processed.

    Phase duration (Orphan file record recovery): 0.00 milliseconds.
    0 bad file records processed.

    Phase duration (Bad file record checking): 0.08 milliseconds.

    Stage 2: Examining file name linkage ...
    146 reparse records processed.

    514010 index entries processed.

    Index verification completed.
    Phase duration (Index verification): 1.45 minutes.
    0 unindexed files scanned.

    Phase duration (Orphan reconnection): 1.91 seconds.
    0 unindexed files recovered to lost and found.

    Phase duration (Orphan recovery to lost and found): 0.09 milliseconds.
    146 reparse records processed.

    Phase duration (Reparse point and Object ID verification): 2.98 milliseconds.

    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.
    Phase duration (Security descriptor verification): 96.94 milliseconds.
    93294 data files processed.

    Phase duration (Data attribute verification): 0.11 milliseconds.
    CHKDSK is verifying Usn Journal...
    36811200 USN bytes processed.

    Usn Journal verification completed.
    Phase duration (USN journal verification): 486.00 milliseconds.

    Windows has scanned the file system and found no problems.
    No further action is required.

    731881714 KB total disk space.
    71892356 KB in 223704 files.
    154672 KB in 93295 indexes.
    0 KB in bad sectors.
    455626 KB in use by the system.
    65536 KB occupied by the log file.
    659379060 KB available on disk.

    4096 bytes in each allocation unit.
    182970428 total allocation units on disk.
    164844765 allocation units available on disk.
    Total duration: 1.68 minutes (100977 ms).

    -----------------------------------------------------------------------
    Category: 0
    Computer Name: DESKTOP-JBUIU2S
    Event Code: 1001
    Record Number: 2383
    Source Name: Microsoft-Windows-Wininit
    Time Written: 11-03-2023 @ 09:00:15
    Event Type: Information
    User:
    Message:

    Checking file system on C:
    The type of the file system is NTFS.


    A disk check has been scheduled.
    Windows will now check the disk.

    Stage 1: Examining basic file system structure ...
    322560 file records processed.


    File verification completed.
    Phase duration (File record verification): 8.82 seconds.
    9822 large file records processed.


    Phase duration (Orphan file record recovery): 0.00 milliseconds.
    0 bad file records processed.


    Phase duration (Bad file record checking): 2.92 milliseconds.

    Stage 2: Examining file name linkage ...
    134 reparse records processed.


    506364 index entries processed.


    Index verification completed.
    Phase duration (Index verification): 1.69 minutes.
    0 unindexed files scanned.


    Phase duration (Orphan reconnection): 1.41 seconds.
    0 unindexed files recovered to lost and found.


    Phase duration (Orphan recovery to lost and found): 273.69 milliseconds.
    134 reparse records processed.


    Phase duration (Reparse point and Object ID verification): 8.66 milliseconds.

    Stage 3: Examining security descriptors ...
    Cleaning up 130 unused index entries from index $SII of file 0x9.
    Cleaning up 130 unused index entries from index $SDH of file 0x9.
    Cleaning up 130 unused security descriptors.
    Security descriptor verification completed.
    Phase duration (Security descriptor verification): 244.25 milliseconds.
    91903 data files processed.


    Phase duration (Data attribute verification): 3.08 milliseconds.
    CHKDSK is verifying Usn Journal...
    9253216 USN bytes processed.


    Usn Journal verification completed.
    Phase duration (USN journal verification): 289.00 milliseconds.

    Windows has scanned the file system and found no problems.
    No further action is required.

    731881714 KB total disk space.
    38114260 KB in 211093 files.
    148488 KB in 91904 indexes.
    0 KB in bad sectors.
    423842 KB in use by the system.
    65536 KB occupied by the log file.
    693195124 KB available on disk.

    4096 bytes in each allocation unit.
    182970428 total allocation units on disk.
    173298781 allocation units available on disk.
    Total duration: 1.89 minutes (113831 ms).

    Internal Info:
    00 ec 04 00 a1 9f 04 00 c9 68 08 00 00 00 00 00 .........h......
    4a 00 00 00 3c 00 00 00 00 00 00 00 00 00 00 00 J...<...........

    -----------------------------------------------------------------------
    Category: 0
    Computer Name: DESKTOP-JBUIU2S
    Event Code: 26212
    Record Number: 2360
    Source Name: Chkdsk
    Time Written: 11-03-2023 @ 08:54:33
    Event Type: Information
    User:
    Message: Chkdsk was executed in read-only mode on a volume snapshot.

    Checking file system on C:
    The type of the file system is NTFS.

    WARNING! /F parameter not specified.
    Running CHKDSK in read-only mode.

    Stage 1: Examining basic file system structure ...
    322560 file records processed.

    File verification completed.
    Phase duration (File record verification): 9.33 seconds.
    9822 large file records processed.

    Phase duration (Orphan file record recovery): 0.00 milliseconds.
    0 bad file records processed.

    Phase duration (Bad file record checking): 0.33 milliseconds.

    Stage 2: Examining file name linkage ...
    134 reparse records processed.

    506366 index entries processed.

    Index verification completed.
    Phase duration (Index verification): 1.35 minutes.
    0 unindexed files scanned.

    Phase duration (Orphan reconnection): 1.30 seconds.
    0 unindexed files recovered to lost and found.

    Phase duration (Orphan recovery to lost and found): 0.33 milliseconds.
    134 reparse records processed.

    Phase duration (Reparse point and Object ID verification): 6.17 milliseconds.

    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.
    Phase duration (Security descriptor verification): 187.75 milliseconds.
    91904 data files processed.

    Phase duration (Data attribute verification): 1.09 milliseconds.
    CHKDSK is verifying Usn Journal...
    9180296 USN bytes processed.

    Usn Journal verification completed.
    Phase duration (USN journal verification): 284.86 milliseconds.

    Windows has scanned the file system and found no problems.
    No further action is required.

    731881714 KB total disk space.
    38630900 KB in 211164 files.
    148512 KB in 91905 indexes.
    0 KB in bad sectors.
    423398 KB in use by the system.
    65536 KB occupied by the log file.
    692678904 KB available on disk.

    4096 bytes in each allocation unit.
    182970428 total allocation units on disk.
    173169726 allocation units available on disk.
    Total duration: 1.54 minutes (92683 ms).

    -----------------------------------------------------------------------
    Category: 0
    Computer Name: DESKTOP-JBUIU2S
    Event Code: 26228
    Record Number: 2208
    Source Name: Chkdsk
    Time Written: 11-03-2023 @ 07:06:37
    Event Type: Information
    User:
    Message: Chkdsk was executed in verify mode on a volume snapshot.

    Checking file system on \Device\HarddiskVolume2

    Examining 3 corruption records ...

    Record 1 of 3: Corrupt File "\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc\{EA16329E-1A23-4E62-B13E-2AEAF2119675}\Protectors\1\6.dat <0x1,0x4c870>" ... no corruption found.

    Record 2 of 3: Corrupt File "\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal <0x4,0x1e4b8>" ... no corruption found.

    Record 3 of 3: Bad subtree in index "$I30" of directory "\Windows\WinSxS\Temp\InFlight <0x1,0x5344>" ... corruption found.

    3 corruption records processed in 0.4 seconds.

    Windows has examined the list of previously identified potential issues and found problems.
    Please run chkdsk /scan to fully analyze the problems and queue them for repair.

    -----------------------------------------------------------------------
     
  9. Oh My!

    Oh My! Malware Expert Staff Member

    I think we got the available information.

    Please do this.

    ===================================================

    Windows Update with CBS Folder

    --------------------

    • Click Start, type Check for updates and hit Enter
    • Attempt to install all availabe updates, continually checking for updates until no more are available
    • If updating is successful let me know
    • If updating fails provide the KB number and Error Code information in your reply
    • Hit the Windows Key + E at the same time
    • Navigate to C:\Windows\Logs
    • Right click on the CBS folder, select Send to, the click Compressed (zipped) folder
    • Click Yes to placing the folder on your Desktop
    • Upload the file to GoFile or the file hosting site of your choice and post the download link in your reply.
    ===================================================

    Things I would like to see in your next reply.
    • Windows Update successful?
    • Link to download
     
  10. nomogoog

    nomogoog Private E-2

    Windows updated 3 drivers but stalled out twice maxing out ram and disc while trying to install windows cumulative preview for windows 10. The 1st time it stalled at 100% installed and the second at 20% installed which is when I paused it so I could use the firefox app to post here. it did not log an error
    https://gofile.io/d/AcCf6u
     
  11. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    Windows Update issues can be quite complex and as you can see by the size of the folder there is a lot to review. Please be patient while I sort through the reports.
     
  12. the mekanic

    the mekanic Major Mekanical Geek

  13. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    Since I believe this is a hardware issue I will step aside and allow the mekanic to guide you from this point on.
     
  14. nomogoog

    nomogoog Private E-2

    -- General Information --

    Application Information
    -------------------------
    Installed Version . . . . . . . . . . . . . . . : Hard Disk Sentinel 6.10
    Registered To . . . . . . . . . . . . . . . . . : Unregistered version, please register.
    Current Date And Time . . . . . . . . . . . . . : 11/6/2023 3:56:43 AM
    Health Calculation Method . . . . . . . . . . . : Analyse data field (default)

    Computer Information
    ----------------------
    Computer Name . . . . . . . . . . . . . . . . . : HELLFIRE
    User Name . . . . . . . . . . . . . . . . . . . : ross1
    Computer Type . . . . . . . . . . . . . . . . . : Mobile
    IP Address . . . . . . . . . . . . . . . . . . . : 192.168.1.21
    MAC Address . . . . . . . . . . . . . . . . . . : 00-8C-FA-6A-50-61
    System Uptime . . . . . . . . . . . . . . . . . : 0 days, 5 hours, 40 minutes, 24 seconds
    System Idle Time . . . . . . . . . . . . . . . . : 0 days, 0 hours, 0 minutes, 0 seconds
    System Up Since . . . . . . . . . . . . . . . . : 11/5/2023 10:16:19 PM
    CPU Usage . . . . . . . . . . . . . . . . . . . : CPU #1: 0 %, CPU #2: 0 %, CPU #3: 3 %, CPU #4: 3 %
    Virtual Memory . . . . . . . . . . . . . . . . . : 18695 MB, Used: 4275 MB (23 %)

    System Information
    --------------------
    Windows Version . . . . . . . . . . . . . . . . : Windows 10 Home 22H2
    CPU Type & Speed #1 . . . . . . . . . . . . . . : Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz, 2494 MHz
    CPU Type & Speed #2 . . . . . . . . . . . . . . : Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz, 2494 MHz
    CPU Type & Speed #3 . . . . . . . . . . . . . . : Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz, 2494 MHz
    CPU Type & Speed #4 . . . . . . . . . . . . . . : Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz, 2494 MHz
    BIOS Manufacturer . . . . . . . . . . . . . . . : TOSINV - 1 1.40 INSYDE Corp. - 10000001
    Physical Memory Size . . . . . . . . . . . . . . : 16263 MB, Used: 4015 MB (25 %)
    Display Adapter . . . . . . . . . . . . . . . . : Intel(R) HD Graphics 4000
    Display Resolution . . . . . . . . . . . . . . . : 1920 x 1080 (32 bit)
    Printer #1 . . . . . . . . . . . . . . . . . . . : Fax
    Printer #2 . . . . . . . . . . . . . . . . . . . : Microsoft Print to PDF
    Printer #3 . . . . . . . . . . . . . . . . . . . : Microsoft XPS Document Writer
    Network Controller #1 . . . . . . . . . . . . . : Realtek RTL8188EE Wireless LAN 802.11n PCI-E NIC
    Network Controller #2 . . . . . . . . . . . . . : Qualcomm Atheros AR8162/8166/8168 PCI-E Fast Ethernet Controller (NDIS 6.30)
    Optical Drive . . . . . . . . . . . . . . . . . : D: MATSHITA DVD-RAM UJ8C2 / 1.00 (CD)

    PCI Device Information
    ------------------------
    PCI Bus 0; Device 2; Function 0 . . . . . . . . : Intel(R) HD Graphics 4000
    PCI Bus 0; Device 20; Function 0 . . . . . . . . : %1 USB %2 eXtensible Host Controller - %3 (Microsoft);(Intel(R),3.0,1.0)
    PCI Bus 0; Device 22; Function 0 . . . . . . . . : Intel(R) Management Engine Interface
    PCI Bus 0; Device 26; Function 0 . . . . . . . . : Intel(R) 7 Series/C216 Chipset Family USB Enhanced Host Controller - 1E2D
    PCI Bus 0; Device 27; Function 0 . . . . . . . . : High Definition Audio Controller
    PCI Bus 0; Device 28; Function 0 . . . . . . . . : Intel(R) 7 Series/C216 Chipset Family PCI Express Root Port 1 - 1E10
    PCI Bus 0; Device 28; Function 1 . . . . . . . . : Intel(R) 7 Series/C216 Chipset Family PCI Express Root Port 2 - 1E12
    PCI Bus 0; Device 29; Function 0 . . . . . . . . : Intel(R) 7 Series/C216 Chipset Family USB Enhanced Host Controller - 1E26
    PCI Bus 0; Device 31; Function 2 . . . . . . . . : Standard SATA AHCI Controller
    PCI Bus 1; Device 0; Function 0 . . . . . . . . : Qualcomm Atheros AR8162/8166/8168 PCI-E Fast Ethernet Controller (NDIS 6.30)
    PCI Bus 2; Device 0; Function 0 . . . . . . . . : Realtek RTL8188EE Wireless LAN 802.11n PCI-E NIC



    -- Physical Disk Information - Disk: #0: TOSHIBA MQ01ABD075 --

    Hard Disk Summary
    -------------------
    Hard Disk Number . . . . . . . . . . . . . . . . : 0
    Interface . . . . . . . . . . . . . . . . . . . : S-ATA II
    Disk Controller . . . . . . . . . . . . . . . . : Standard SATA AHCI Controller (AHCI) [VEN: 8086, DEV: 1E03] Version: 10.0.19041.3570, 6-21-2006
    Disk Location . . . . . . . . . . . . . . . . . : Bus Number 0, Target Id 0, LUN 0
    Hard Disk Model ID . . . . . . . . . . . . . . . : TOSHIBA MQ01ABD075
    Firmware Revision . . . . . . . . . . . . . . . : AX0A4M
    Hard Disk Serial Number . . . . . . . . . . . . : 63O2SAHNS
    Total Size . . . . . . . . . . . . . . . . . . . : 715402 MB
    Power State . . . . . . . . . . . . . . . . . . : Active
    Device Type . . . . . . . . . . . . . . . . . . : Fixed Disk
    Logical Drive(s) . . . . . . . . . . . . . . . . : C: [] E: [System Reserved]
    Current Temperature . . . . . . . . . . . . . . : 38 °C
    Power On Time . . . . . . . . . . . . . . . . . : 2112 days, 22 hours
    Estimated Remaining Lifetime . . . . . . . . . . : more than 100 days
    Health . . . . . . . . . . . . . . . . . . . . . : #################### 100 % (Excellent)
    Performance . . . . . . . . . . . . . . . . . . : #################### 100 % (Excellent)

    The hard disk status is PERFECT. Problematic or weak sectors were not found and there are no spin up or data transfer errors.
    The disk drive reached the end of the designed lifetime. Chance of sudden, unforeseen failure is higher.
    In a critical system, it is recommended to consider replacement.
    No actions needed.

    ATA Information
    -----------------
    Hard Disk Cylinders . . . . . . . . . . . . . . : 1453521
    Hard Disk Heads . . . . . . . . . . . . . . . . : 16
    Hard Disk Sectors . . . . . . . . . . . . . . . : 63
    ATA Revision . . . . . . . . . . . . . . . . . . : ATA8-ACS
    Transport Version . . . . . . . . . . . . . . . : SATA Rev 2.6
    Total Sectors . . . . . . . . . . . . . . . . . : 1465149168
    Bytes Per Sector . . . . . . . . . . . . . . . . : 512
    Buffer Size . . . . . . . . . . . . . . . . . . : 8192 KB
    Multiple Sectors . . . . . . . . . . . . . . . . : 16
    Error Correction Bytes . . . . . . . . . . . . . : 0
    Unformatted Capacity . . . . . . . . . . . . . . : 715405 MB
    Maximum PIO Mode . . . . . . . . . . . . . . . . : 4
    Maximum Multiword DMA Mode . . . . . . . . . . . : 2
    Highest Possible Transfer Rate . . . . . . . . . : S-ATA II Signaling Speed (3 Gps)
    Negotiated Transfer Rate . . . . . . . . . . . . : S-ATA II Signaling Speed (3 Gps)
    Minimum Multiword DMA Transfer Time . . . . . . : 120 ns
    Recommended Multiword DMA Transfer Time . . . . : 120 ns
    Minimum PIO Transfer Time Without IORDY . . . . : 120 ns
    Minimum PIO Transfer Time With IORDY . . . . . . : 120 ns
    ATA Control Byte . . . . . . . . . . . . . . . . : Valid
    ATA Checksum Value . . . . . . . . . . . . . . . : Valid

    Acoustic Management Configuration
    -----------------------------------
    Acoustic Management . . . . . . . . . . . . . . : Not supported
    Acoustic Management . . . . . . . . . . . . . . : Disabled
    Current Acoustic Level . . . . . . . . . . . . . : Default (00h)
    Recommended Acoustic Level . . . . . . . . . . . : Default (00h)

    ATA Features
    --------------
    Read Ahead Buffer . . . . . . . . . . . . . . . : Supported, Enabled
    DMA . . . . . . . . . . . . . . . . . . . . . . : Supported
    Ultra DMA . . . . . . . . . . . . . . . . . . . : Supported
    S.M.A.R.T. . . . . . . . . . . . . . . . . . . . : Supported
    Power Management . . . . . . . . . . . . . . . . : Supported
    Write Cache . . . . . . . . . . . . . . . . . . : Supported
    Host Protected Area . . . . . . . . . . . . . . : Supported
    HPA Security Extensions . . . . . . . . . . . . : Supported
    Advanced Power Management . . . . . . . . . . . : Supported, Enabled
    Advanced Power Management Level . . . . . . . . : Minimum power consumption without standby (128)
    Extended Power Management . . . . . . . . . . . : Not supported
    Power Up In Standby . . . . . . . . . . . . . . : Not supported
    48-Bit LBA Addressing . . . . . . . . . . . . . : Supported
    Device Configuration Overlay . . . . . . . . . . : Supported
    IORDY Support . . . . . . . . . . . . . . . . . : Supported
    Read/Write DMA Queue . . . . . . . . . . . . . . : Not supported
    NOP Command . . . . . . . . . . . . . . . . . . : Supported
    Trusted Computing . . . . . . . . . . . . . . . : Not supported
    64-Bit World Wide ID . . . . . . . . . . . . . . : 50000394D56864F8
    Streaming . . . . . . . . . . . . . . . . . . . : Not supported
    Media Card Pass Through . . . . . . . . . . . . : Not supported
    General Purpose Logging . . . . . . . . . . . . : Supported
    Error Logging . . . . . . . . . . . . . . . . . : Supported
    CFA Feature Set . . . . . . . . . . . . . . . . : Not supported
    CFast Device . . . . . . . . . . . . . . . . . . : Not supported
    Long Physical Sectors (1) . . . . . . . . . . . : Not supported
    Long Logical Sectors . . . . . . . . . . . . . . : Not supported
    Write-Read-Verify . . . . . . . . . . . . . . . : Not supported
    NV Cache Feature . . . . . . . . . . . . . . . . : Not supported
    NV Cache Power Mode . . . . . . . . . . . . . . : Not supported
    NV Cache Size . . . . . . . . . . . . . . . . . : Not supported
    Free-fall Control . . . . . . . . . . . . . . . : Not supported
    Free-fall Control Sensitivity . . . . . . . . . : Not supported
    Service Interrupt . . . . . . . . . . . . . . . : Not supported
    IDLE IMMEDIATE Command With UNLOAD Feature . . . : Supported
    Zoned Capabilities . . . . . . . . . . . . . . . : Not supported
    SCT Command Transport . . . . . . . . . . . . . : Supported
    SCT Error Recovery Control . . . . . . . . . . . : Supported
    Nominal Media Rotation Rate . . . . . . . . . . : 5400 RPM
    Nominal Form Factor . . . . . . . . . . . . . . : 2.5 inch

    SSD Features
    --------------
    Data Set Management . . . . . . . . . . . . . . : Not supported
    TRIM Command . . . . . . . . . . . . . . . . . . : Not supported
    Deterministic Read After TRIM . . . . . . . . . : Not supported
    Read Zeroes After TRIM . . . . . . . . . . . . . : Not supported

    S.M.A.R.T. Details
    --------------------
    Off-line Data Collection Status . . . . . . . . : Never Started
    Self Test Execution Status . . . . . . . . . . . : Successfully Completed
    Total Time To Complete Off-line Data Collection : 120 seconds
    Execute Off-line Immediate . . . . . . . . . . . : Supported
    Abort/restart Off-line By Host . . . . . . . . . : Not supported
    Off-line Read Scanning . . . . . . . . . . . . . : Supported
    Short Self-test . . . . . . . . . . . . . . . . : Supported
    Extended Self-test . . . . . . . . . . . . . . . : Supported
    Conveyance Self-test . . . . . . . . . . . . . . : Not supported
    Selective Self-Test . . . . . . . . . . . . . . : Supported
    Save Data Before/After Power Saving Mode . . . . : Supported
    Enable/Disable Attribute Autosave . . . . . . . : Supported
    Error Logging Capability . . . . . . . . . . . . : Supported
    Short Self-test Estimated Time . . . . . . . . . : 2 minutes
    Extended Self-test Estimated Time . . . . . . . : 189 minutes
    Last Short Self-test Result . . . . . . . . . . : Never Started
    Last Short Self-test Date . . . . . . . . . . . : Never Started
    Last Extended Self-test Result . . . . . . . . . : Never Started
    Last Extended Self-test Date . . . . . . . . . . : Never Started

    Security Mode
    ---------------
    Security Mode . . . . . . . . . . . . . . . . . : Supported
    Security Erase . . . . . . . . . . . . . . . . . : Supported
    Security Erase Time . . . . . . . . . . . . . . : 176 minutes
    Security Enhanced Erase Feature . . . . . . . . : Supported
    Security Enhanced Erase Time . . . . . . . . . . : 176 minutes
    Security Enabled . . . . . . . . . . . . . . . . : No
    Security Locked . . . . . . . . . . . . . . . . : No
    Security Frozen . . . . . . . . . . . . . . . . : Yes
    Security Counter Expired . . . . . . . . . . . . : No
    Security Level . . . . . . . . . . . . . . . . . : High
    Device Encrypts All User Data . . . . . . . . . : No
    Sanitize . . . . . . . . . . . . . . . . . . . . : Not supported
    Overwrite . . . . . . . . . . . . . . . . . . . : Not supported
    Crypto Scramble . . . . . . . . . . . . . . . . : Not supported
    Block Erase . . . . . . . . . . . . . . . . . . : Not supported
    Sanitize Antifreeze Lock . . . . . . . . . . . . : Not supported
    ACS-3 Commands Allowed By Sanitize . . . . . . . : No

    Serial ATA Features
    ---------------------
    S-ATA Compliance . . . . . . . . . . . . . . . . : Yes
    S-ATA I Signaling Speed (1.5 Gps) . . . . . . . : Supported
    S-ATA II Signaling Speed (3 Gps) . . . . . . . . : Supported
    S-ATA Gen3 Signaling Speed (6 Gps) . . . . . . . : Not supported
    Receipt Of Power Management Requests From Host . : Supported
    PHY Event Counters . . . . . . . . . . . . . . . : Supported
    Non-Zero Buffer Offsets In DMA Setup FIS . . . . : Not supported
    DMA Setup Auto-Activate Optimization . . . . . . : Supported, Disabled
    Device Initiating Interface Power Management . . : Supported, Disabled
    In-Order Data Delivery . . . . . . . . . . . . . : Not supported
    Asynchronous Notification . . . . . . . . . . . : Not supported
    Software Settings Preservation . . . . . . . . . : Supported, Enabled
    Native Command Queuing (NCQ) . . . . . . . . . . : Supported
    Queue Length . . . . . . . . . . . . . . . . . . : 32
    NCQ Streaming . . . . . . . . . . . . . . . . . : Not supported
    NCQ Autosense . . . . . . . . . . . . . . . . . : Not supported
    Automatic Partial To Slumber Translations . . . : Not supported
    Rebuild Assist . . . . . . . . . . . . . . . . . : Not supported
    Hybrid Information . . . . . . . . . . . . . . . : Not supported
    Device Sleep (DevSleep) . . . . . . . . . . . . : Not supported
    DevSleep To ReducedPwrState . . . . . . . . . . : Not supported

    Disk Information
    ------------------
    Disk Family . . . . . . . . . . . . . . . . . . : MQ-01ABD075
    Form Factor . . . . . . . . . . . . . . . . . . : 2.5"
    Capacity . . . . . . . . . . . . . . . . . . . . : 750 GB (750 x 1,000,000,000 bytes)
    Number Of Disks . . . . . . . . . . . . . . . . : 2
    Number Of Heads . . . . . . . . . . . . . . . . : 4
    Rotational Speed . . . . . . . . . . . . . . . . : 5400 RPM
    Rotation Time . . . . . . . . . . . . . . . . . : 11.11 ms
    Average Rotational Latency . . . . . . . . . . . : 5.56 ms
    Disk Interface . . . . . . . . . . . . . . . . . : Serial-ATA/300
    Buffer-Host Max. Rate . . . . . . . . . . . . . : 300 MB/seconds
    Buffer Size . . . . . . . . . . . . . . . . . . : 8192 KB
    Drive Ready Time (Typical) . . . . . . . . . . . : ? seconds
    Average Seek Time . . . . . . . . . . . . . . . : 12.0 ms
    Track To Track Seek Time . . . . . . . . . . . . : 2.0 ms
    Full Stroke Seek Time . . . . . . . . . . . . . : ? ms
    Width . . . . . . . . . . . . . . . . . . . . . : 69.9 mm (2.8 inch)
    Depth . . . . . . . . . . . . . . . . . . . . . : 100.0 mm (3.9 inch)
    Height . . . . . . . . . . . . . . . . . . . . . : 9.5 mm (0.4 inch)
    Weight . . . . . . . . . . . . . . . . . . . . . : 112 grams (0.2 pounds)
    Required Power For Spinup . . . . . . . . . . . : 940 mA
    Power Required (Seek) . . . . . . . . . . . . . : 2.7 W
    Power Required (Idle) . . . . . . . . . . . . . : 1.0 W
    Power Required (Standby) . . . . . . . . . . . . : 0.3 W
    Manufacturer . . . . . . . . . . . . . . . . . . : Toshiba Corp., Storage Device Division
    Manufacturer Website . . . . . . . . . . . . . . : https://toshiba.semicon-storage.com/eu/product/storage-products.html

    S.M.A.R.T.
    ------------
    No. Attribute Thre.. Value Worst Data Status Flags
    1 Raw Read Error Rate 50 100 100 000000000000 OK Error-Rate, Statistical, Critical
    2 Throughput Performance 50 100 100 000000000000 OK Performance, Critical
    3 Spin Up Time 1 100 100 0000000006B3 OK Self Preserving, Performance, Statistical, Critical
    4 Start/Stop Count 0 100 100 00000000180F OK (Always passing) Self Preserving, Event Count, Statistical
    5 Reallocated Sectors Co.. 50 100 100 000000000000 OK Self Preserving, Event Count, Statistical, Critical
    7 Seek Error Rate 50 100 100 000000000000 OK Error-Rate, Statistical, Critical
    8 Seek Time Performance 50 100 100 000000000000 OK Performance, Critical
    9 Power On Time Count 0 1 1 00000000C616 OK (Always passing) Self Preserving, Event Count, Statistical
    10 Spin Retry Count 30 223 100 000000000000 OK Self Preserving, Event Count, Statistical, Critical
    12 Drive Power Cycle Count 0 100 100 0000000017A8 OK (Always passing) Self Preserving, Event Count, Statistical
    191 G-Sense Error Rate 0 100 100 0000000001CE OK (Always passing) Self Preserving, Event Count, Statistical
    192 Power off Retract Cycl.. 0 100 100 00000000008D OK (Always passing) Self Preserving, Event Count, Statistical
    193 Load/Unload Cycle Count 0 18 18 0000000C8949 OK (Always passing) Self Preserving, Event Count, Statistical
    194 Disk Temperature 0 100 100 003F00050026 OK (Always passing) Self Preserving, Statistical
    196 Reallocation Event Count 0 100 100 000000000000 OK (Always passing) Self Preserving, Event Count, Statistical
    197 Current Pending Sector.. 0 100 100 000000000000 OK (Always passing) Self Preserving, Event Count, Statistical
    198 Off-Line Uncorrectable.. 0 100 100 000000000000 OK (Always passing) Self Preserving, Event Count
    199 Ultra ATA CRC Error Co.. 0 200 200 000000000001 OK (Always passing) Self Preserving, Event Count, Statistical
    220 Disk Shift 0 100 100 000000000000 OK (Always passing) Statistical
    222 Loaded Hours 0 1 1 00000000A394 OK (Always passing) Self Preserving, Event Count, Statistical
    223 Load/Unload Retry Count 0 100 100 000000000000 OK (Always passing) Self Preserving, Event Count, Statistical
    224 Load Friction 0 100 100 000000000000 OK (Always passing) Self Preserving, Statistical
    226 Load-in Time 0 100 100 000000000105 OK (Always passing) Self Preserving, Performance, Statistical
    240 Head Flying Hours 1 100 100 000000000000 OK Critical

    Transfer Rate Information
    ---------------------------
    Total Data Read . . . . . . . . . . . . . . . . : 17 MB, 17 MB since installation (11/6/2023)
    Total Data Write . . . . . . . . . . . . . . . . : 59 MB, 59 MB since installation
    Average Reads Per Day . . . . . . . . . . . . . : 17.00 MB
    Average Writes Per Day . . . . . . . . . . . . . : 59.00 MB
    Current Transfer Rate . . . . . . . . . . . . . : 860 KB/s
    Maximum Transfer Rate . . . . . . . . . . . . . : 3986 KB/s
    Current Read Rate . . . . . . . . . . . . . . . : 771 KB/s
    Current Write Rate . . . . . . . . . . . . . . . : 89 KB/s
    Current Disk Activity . . . . . . . . . . . . . : 23 %



    -- Partition Information --

    Logical Drive Total Space Free Space Free Space Used Space
    C: (Disk: #0) 698.0 GB 628.0 GB 90 % ##------------------
    E: System Reserved (Disk: #0) 0.0 GB 0.0 GB 76 % ####----------------



    -- System Management Information --


    Motherboard Information
    -------------------------
    Manufacturer . . . . . . . . : TOSHIBA
    Product . . . . . . . . . . : Portable PC MP
    Serial Number . . . . . . . : 1
    BIOS . . . . . . . . . . . . : Insyde Corp. ver. 1.40 [04/28/2014]
    Memory Module 1 . . . . . . : 8192 MB [1600 MHz] BANK 0
    Memory Module 2 . . . . . . : 8192 MB [1600 MHz] BANK 2

    System Information
    --------------------
    Manufacturer . . . . . . . . : TOSHIBA
    Product . . . . . . . . . . : Satellite C55-A PSCF6U-010056
    Serial Number . . . . . . . : 8D067498Q
    UUID . . . . . . . . . . . . : 4F39E8D0-FEE4-11E2-8C9C-008CFA6A5061
    Chassis . . . . . . . . . . : OEM Chassis Manufacturer ver. OEM Chassis Version
    Chassis Serial Number . . . : OEM Chassis Serial Number
    Chassis Asset Tag . . . . . : No Asset Tag
     
  15. the mekanic

    the mekanic Major Mekanical Geek

    Well, your system seems to have aged well. Though you have a quad core processor, W10 is a lot for it. The HDD is seemingly in surprisingly good shape for it's age. Just to rule out RAM as a factor, let's get a MemTest done to make sure Windows isn't being corrupted by bad bits. Any red on this scan is bad.

    https://www.majorgeeks.com/files/details/memtest.html
     
  16. nomogoog

    nomogoog Private E-2

    Every time I hit start testing I get the could not allocate error window. I have 4 cores so I started 4 separate copies but they all give me the error window and do not seem to be running. Task mgr shows the apps open but using no cpu or disk and 1.3 mb of ram
     
  17. nomogoog

    nomogoog Private E-2

    I have 16gb of ram so I put 4gb in each instance and its running now
     
  18. nomogoog

    nomogoog Private E-2

  19. the mekanic

    the mekanic Major Mekanical Geek

  20. nomogoog

    nomogoog Private E-2

    it says its too long to post so im just attaching it hope thats ok
     

    Attached Files:

  21. the mekanic

    the mekanic Major Mekanical Geek

    Pardon the absence, was out of town. Don't see any errors in the log. I'm starting to think that Ivy Bridge just may be too old to run W10 without bogging down anymore. It's the oldest platform supported.
     
  22. nomogoog

    nomogoog Private E-2

    I have actually had windows 10 on this device for a long time and I only recently started having issues which is why I did the fresh install. Is there a way to roll back the windows 10 updates to see if that fixes the problem? Or do you think I'd be better off just installing an older windows like 7?
     
  23. the mekanic

    the mekanic Major Mekanical Geek

  24. the mekanic

    the mekanic Major Mekanical Geek

    BTW, this did make me read it a few times to make sure I wasn't hallucinating. And I put on my glasses. And double checked my glass to make sure what was in it.:)

    Power on time: 2112 days, 22 hours (just shy of six years of uptime)

    The hard disk status is PERFECT. Problematic or weak sectors were not found and there are no spin up or data transfer errors.
    The disk drive reached the end of the designed lifetime. Chance of sudden, unforeseen failure is higher.
    In a critical system, it is recommended to consider replacement.
    No actions needed.
     
  25. nomogoog

    nomogoog Private E-2

    ok ill try that. what is it im missing that made you double check that?
     
  26. nomogoog

    nomogoog Private E-2

    that links download button just takes me to a page with all the free tools they offer but none are called tdsskiller or have rootkit in the description
     
  27. nomogoog

    nomogoog Private E-2

    i found it
     
  28. the mekanic

    the mekanic Major Mekanical Geek

    Sometimes it's best to rule out the oddest things. I found a salvage Dell XPS years ago someone tossed. Turned out to be a rootikit mucking up Windows, not the hardware. Still have it...
     
  29. nomogoog

    nomogoog Private E-2

    no threats found
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds