Pc Very Slow To Load Windows, And To Start Any Programs

Discussion in 'Malware Help (A Specialist Will Reply)' started by MoPman, May 27, 2023.

  1. MoPman

    MoPman Private E-2

    Hi!
    I bought a basic desktop pc (Asus I5-7400, 3ghz, 8gb ram, 64bit Windows 10 Home) from Costco for the guestroom in my house. It is very seldom used, but I've noticed over the past year or so that it is extremely slow in loading in Windows upon startup, as well as opening Chrome or File Explorer, etc. Sometimes it will take several minutes. I bought a lifetime version of SUPERAntiSpyware over a decade ago and it routinely runs scans without finding anything.

    Yesterday I went through your "Do This First" and followed all your instructions. Until I reached MGtools. When I click your link, Chrome begins opening a window for it and then it immediately closes. This happens in less than one second, so there's no opportunity to see anything. There are no warnings, etc, from Chrome or an AV, etc. It simply won't open a window to the MGtools page or download the tool (whatever is supposed to happen). I followed your directions about disabling the Chrome security, but the same problem remains.

    I am attaching all the other logs in the initial cleanup procedure.

    Thanks in advance!
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to the MajorGeeks Malware Forum.

    While I review what you have posted please do this.

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download Farbar Recover Scan Tool for 64 bit systems and save it to your Desktop. <<< Important
    • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
    • 2 Notepad documents should now be open on your desktop.
    • Please copy and paste the contents of each report in separate reply windows
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:

    • FRST.txt
    • Addition.txt
     
  3. MoPman

    MoPman Private E-2

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-05-2023
    Ran by Peter (administrator) on PETERTV (ASUSTeK COMPUTER INC. K31CD-K) (28-05-2023 04:23:40)
    Running from C:\Users\Peter\Desktop\FRST64.exe
    Loaded Profiles: Peter
    Platform: Microsoft Windows 10 Home Version 22H2 19045.2965 (X64) Language: English (United States)
    Default browser: Chrome
    Boot Mode: Normal

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (C:\Program Files\RogueKiller\RogueKillerSvc.exe ->) (ADLICE -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
    (C:\Windows\runSW.exe ->) (Realtek Semiconductor Corp. -> Realtek) C:\Windows\SwUSB.exe
    (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <35>
    (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
    (explorer.exe ->) (RealDefense, LLC -> SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
    (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.242\GoogleCrashHandler.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.242\GoogleCrashHandler64.exe
    (NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
    (services.exe ->) (ADLICE -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe
    (services.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
    (services.exe ->) (GZ Systems Limited -> ) C:\Program Files (x86)\PureVPN\PureVPNService.exe
    (services.exe ->) (ICEpower a/s -> ICEpower A/S) C:\Windows\System32\ICEsoundService64.exe
    (services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\MsMpEng.exe
    (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\NisSrv.exe
    (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
    (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
    (services.exe ->) (Realtek Semiconductor Corp -> ) C:\Windows\runSW.exe
    (services.exe ->) (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (svchost.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

    ==================== Registry (Whitelisted) ===================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9270560 2019-03-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
    HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [11327200 2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    HKLM-x32\...\Run: [HiCOS Token Utility] => C:\Program Files (x86)\Chunghwa Telecom\HiCOS PKI Smart Card\TokenUtility.exe [534248 2019-10-21] (CHUNGHWA TELECOM CO., LTD. -> Chunghwa Telecom Corp., Ltd.)
    HKLM-x32\...\Run: [跨平台網頁元件] => C:\Program Files (x86)\HiPKILocalSignServer\ChkSrv.exe [886920 2021-04-16] (CHUNGHWA TELECOM CO., LTD. -> )
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\Run: [World of Tanks] => C:\Games\World_of_Tanks\WargamingGameUpdater.exe [3139936 2018-06-25] (Wargaming.net Limited -> Wargaming.net)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [11190504 2023-05-26] (RealDefense, LLC -> SUPERAntiSpyware)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [33102224 2020-11-06] (Epic Games Inc. -> Epic Games, Inc.)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\Run: [MicrosoftEdgeAutoLaunch_70ABF69C36125B78732041588D6A0A36] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4152208 2023-05-25] (Microsoft Corporation -> Microsoft Corporation)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Application Restart #3] => C:\Program Files (x86)\ASUS\Giftbox\Asusgiftbox.exe [1049608 2017-07-03] (ASUSTek Computer Inc. -> ASUSTek Computer Inc)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Application Restart #2] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --enable-audio-service-sandbox --restore-last-session -- hxxps://www.bing.com/search?q=troublesho (the data entry has 99 more characters). [3172120 2023-05-16] (Google LLC -> Google LLC)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Uninstall 22.225.1026.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\22.225.1026.0001" (No File)
    HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\113.0.5672.127\Installer\chrmstp.exe [2023-05-26] (Google LLC -> Google LLC)

    ==================== Scheduled Tasks (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {163073C6-5C42-41D9-A45E-1DD182CBA21C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {173B0CE2-1E30-4279-882A-23D23FC9456B} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
    Task: {19A7DB37-5A15-4AB6-8E73-9B8A097C0D68} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-12-16] (Google Inc -> Google Inc.)
    Task: {1C81349C-0BE4-4832-9096-9A8EB5BC74B6} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339120 2021-06-15] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {2F194BC5-76B5-4FB7-9167-8FD54FFB14ED} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\MpCmdRun.exe [1650024 2023-05-26] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {3DFB4C8B-5739-4FDA-B829-392CB215AA26} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [143160 2019-03-12] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
    Task: {4E3501EF-FDD1-4422-A505-DB5F7B054EF2} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {4F3733AC-A040-4800-A4BB-000536D5ECF7} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {55354FB1-3785-4816-B77E-45F28B03D8A2} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [1579296 2016-11-10] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) [File not signed]
    Task: {57B51384-17F6-4480-A075-DAF67AC9944B} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2022-01-25] (Dropbox, Inc -> Dropbox, Inc.)
    Task: {5F017807-6757-46F4-BE9F-C54D2137B936} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
    Task: {61B8C187-1F4D-4145-AE70-2BF1BC5A7F9D} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {6CDFB7F6-E5AE-4912-9326-335B510A45ED} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\MpCmdRun.exe [1650024 2023-05-26] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {75D7A453-E742-48C9-B926-F6706AA94A0E} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {7CF99150-2C36-47F1-9105-BFBB1F0636DE} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {862CB16D-9624-4E3C-899D-C98440F5110F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\MpCmdRun.exe [1650024 2023-05-26] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {9A655614-7400-4B64-9CC8-CF07CF1A5102} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-12-16] (Google Inc -> Google Inc.)
    Task: {AA50674E-5D13-44C7-88E4-AC8DFA0AF18F} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2022-01-25] (Dropbox, Inc -> Dropbox, Inc.)
    Task: {CE9FD8FF-BC77-4838-B8A1-FC3F7C23B472} - System32\Tasks\ASUSTek Computer Inc\ASUS GIFTBOX => C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe [1049608 2017-07-03] (ASUSTek Computer Inc. -> ASUSTek Computer Inc)
    Task: {D1C43A07-0865-4706-ACB0-EFD881E574E1} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [909112 2016-07-27] (Intel(R) Trusted Connect Service -> Intel(R) Corporation)
    Task: {DA19BD1B-5D9F-4784-A286-A488ED6A3342} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\MpCmdRun.exe [1650024 2023-05-26] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {F31097D0-8594-4A6C-8939-3992CF85819D} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-09] (NVIDIA Corporation -> NVIDIA Corporation)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.50.1
    Tcpip\..\Interfaces\{c2b50fd1-5a4a-4f69-b655-2db91b3bc970}: [DhcpNameServer] 192.168.50.1
    Tcpip\..\Interfaces\{ca264b1f-871e-4128-9c2e-5804af8216c6}: [DhcpNameServer] 192.168.50.1

    Edge:
    =======
    Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
    Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
    Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
    Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
    Edge Profile: C:\Users\Peter\AppData\Local\Microsoft\Edge\User Data\Default [2023-05-28]
    Edge Extension: (Edge relevant text changes) - C:\Users\Peter\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-05-26]

    FireFox:
    ========
    FF ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\PJoT0IxB.default [2018-01-15]
    FF Extension: (Avira Browser Safety) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\PJoT0IxB.default\Extensions\abs@avira.com [2018-01-15] [hxxps://download.avira.com/package/absnooffers/firefox/update_webext_no_offers.rdf]
    FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-01-10] (VideoLAN -> VideoLAN)
    FF Plugin-x32: www.chttl.com.tw/HttpComponent -> C:\Program Files (x86)\HiPKILocalSignServer\npHttpComponent.dll [2020-07-29] (CHUNGHWA TELECOM CO., LTD. -> CHTTL)

    Chrome:
    =======
    CHR DefaultProfile: Default
    CHR Profile: C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default [2023-05-28]
    CHR Notifications: Default -> hxxps://shop.gopro.com; hxxps://www.youtube.com
    CHR NewTab: Default -> Not-active:"chrome-extension://laookkfknpbbblfpciffpaejjkokdgca/dashboard.html"
    CHR Extension: (Avira Browser Safety) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2023-05-26]
    CHR Extension: (Google Docs Offline) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-05-27]
    CHR Extension: (Avira SafeSearch Plus) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2020-09-23]
    CHR Extension: (Momentum) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\laookkfknpbbblfpciffpaejjkokdgca [2023-05-26]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-13]
    CHR Profile: C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-05-15]
    CHR Profile: C:\Users\Peter\AppData\Local\Google\Chrome\User Data\System Profile [2019-05-15]
    CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
    CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
    CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp]
    CHR HKLM-x32\...\Chrome\Extension: [bfidboloedlamgdmenmlbipfnccokknp]
    CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
    CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
    CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp]

    ==================== Services (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
    S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2022-01-25] (Dropbox, Inc -> Dropbox, Inc.)
    S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2022-01-25] (Dropbox, Inc -> Dropbox, Inc.)
    R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [46824 2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    S3 DevActSvc; C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe [326032 2018-06-05] (ASUSTeK Computer Inc. -> )
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9255384 2023-05-27] (Malwarebytes Inc. -> Malwarebytes)
    R2 PureVPNService; C:\Program Files (x86)\PureVPN\PureVPNService.exe [197896 2019-12-19] (GZ Systems Limited -> )
    R2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [15413680 2023-05-24] (ADLICE -> )
    R2 RunSwUSB; C:\Windows\runSW.exe [44760 2014-12-12] (Realtek Semiconductor Corp -> )
    R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\NisSrv.exe [3216064 2023-05-26] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\MsMpEng.exe [133544 2023-05-26] (Microsoft Windows Publisher -> Microsoft Corporation)

    ===================== Drivers (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
    S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
    S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
    R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2023-05-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
    R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223176 2023-05-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
    S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-05-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
    R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [199640 2023-05-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
    R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77752 2023-05-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
    R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-05-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
    R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [181984 2023-05-27] (Malwarebytes Inc. -> Malwarebytes)
    R3 MpKslf51250ce; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C42F7E82-70FE-4682-B46F-71FFD2E9768E}\MpKslDrv.sys [212264 2023-05-27] (Microsoft Windows -> Microsoft Corporation)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-23] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
    S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
    R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39040 2019-12-13] (GZ Systems Limited -> The OpenVPN Project)
    U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [41920 2023-05-27] (ADLICE (Julien ASCOET) -> )
    S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49616 2023-05-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
    R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [498944 2023-05-26] (Microsoft Windows -> Microsoft Corporation)
    R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99608 2023-05-26] (Microsoft Windows -> Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) (Whitelisted) =========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2023-05-28 04:23 - 2023-05-28 04:26 - 000022035 _____ C:\Users\Peter\Desktop\FRST.txt
    2023-05-28 04:22 - 2023-05-28 04:25 - 000000000 ____D C:\FRST
    2023-05-28 04:01 - 2021-05-15 15:19 - 000078192 _____ C:\WINDOWS\system32\FvSDK_x64.dll
    2023-05-28 04:01 - 2021-05-15 15:19 - 000067952 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
    2023-05-28 04:00 - 2023-05-28 04:22 - 002382848 _____ (Farbar) C:\Users\Peter\Desktop\FRST64.exe
    2023-05-28 03:58 - 2021-06-04 20:22 - 000168304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
    2023-05-28 03:58 - 2021-06-04 20:22 - 000144240 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
    2023-05-28 03:57 - 2021-06-03 21:56 - 000043408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\NvModuleTracker.sys
    2023-05-27 15:45 - 2023-05-27 15:45 - 000181984 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
    2023-05-27 15:44 - 2023-05-27 15:50 - 002370468 _____ C:\WINDOWS\Minidump\052723-33640-01.dmp
    2023-05-27 15:43 - 2023-05-27 15:45 - 000041920 _____ C:\WINDOWS\system32\Drivers\truesight.sys
    2023-05-27 13:53 - 2023-05-27 13:54 - 000000000 ____D C:\ProgramData\HitmanPro
    2023-05-27 13:51 - 2023-05-27 13:51 - 000006496 _____ C:\Users\Peter\Desktop\RK.txt
    2023-05-27 13:19 - 2023-05-27 13:50 - 000000000 ____D C:\ProgramData\RogueKiller
    2023-05-27 13:19 - 2023-05-27 13:19 - 000000901 _____ C:\Users\Public\Desktop\RogueKiller.lnk
    2023-05-27 13:19 - 2023-05-27 13:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
    2023-05-27 13:19 - 2023-05-27 13:19 - 000000000 ____D C:\Program Files\RogueKiller
    2023-05-27 13:15 - 2023-05-27 13:15 - 000001226 _____ C:\Users\Peter\Desktop\mbscan.txt
    2023-05-27 04:08 - 2023-05-27 04:08 - 000000000 ____D C:\Users\Peter\AppData\Local\mbam
    2023-05-27 03:50 - 2023-05-27 15:49 - 000000000 ____D C:\Users\Peter\AppData\Local\Malwarebytes
    2023-05-27 03:50 - 2023-05-27 03:50 - 000002035 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
    2023-05-27 03:50 - 2023-05-27 03:50 - 000002023 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2023-05-27 03:47 - 2023-05-27 03:47 - 000000000 ____D C:\ProgramData\Malwarebytes
    2023-05-27 03:47 - 2023-05-27 03:47 - 000000000 ____D C:\Program Files\Malwarebytes
    2023-05-27 03:39 - 2023-05-27 13:53 - 014248944 _____ (SurfRight B.V.) C:\Users\Peter\Desktop\HitmanPro_x64.exe
    2023-05-27 03:39 - 2023-05-27 13:17 - 047322760 _____ (Adlice Software ) C:\Users\Peter\Desktop\setup.exe
    2023-05-27 03:36 - 2023-05-27 03:37 - 328608056 _____ (Malwarebytes) C:\Users\Peter\Desktop\mb.exe
    2023-05-27 03:31 - 2023-05-27 03:31 - 000002823 _____ C:\Users\Peter\Desktop\AdwCleaner[S00].txt
    2023-05-27 03:24 - 2023-05-27 03:29 - 000000000 ____D C:\AdwCleaner
    2023-05-27 03:16 - 2023-05-27 03:16 - 008791352 _____ (Malwarebytes) C:\Users\Peter\Desktop\AdwCleaner.exe
    2023-05-27 01:35 - 2023-05-27 01:35 - 000000000 ___HD C:\$WinREAgent
    2023-05-26 22:25 - 2023-05-26 22:25 - 001369128 _____ (Google LLC) C:\Users\Peter\Downloads\ChromeSetup.exe
    2023-05-26 21:51 - 2023-05-26 21:51 - 000000000 ____H C:\Users\Peter\Documents\Default.rdp
    2023-05-26 21:33 - 2023-05-26 21:37 - 002799180 _____ C:\WINDOWS\Minidump\052623-43625-01.dmp
    2023-05-26 20:53 - 2023-05-26 20:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
    2023-05-26 20:33 - 2023-05-26 20:33 - 000002255 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
    2023-05-26 20:33 - 2023-05-26 20:33 - 000002243 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
    2023-05-26 20:32 - 2023-05-26 20:32 - 000000000 ____D C:\Program Files\Google
    2023-05-18 11:03 - 2023-05-18 11:03 - 000046824 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe

    ==================== One month (modified) ==================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2023-05-28 04:21 - 2017-08-08 06:05 - 000000000 ____D C:\ProgramData\NVIDIA
    2023-05-28 04:20 - 2020-11-04 04:30 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2023-05-28 04:06 - 2019-12-07 17:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2023-05-28 04:02 - 2020-11-04 19:46 - 000439444 _____ C:\WINDOWS\system32\prfh0404.dat
    2023-05-28 04:02 - 2020-11-04 19:46 - 000133276 _____ C:\WINDOWS\system32\prfc0404.dat
    2023-05-28 04:02 - 2020-11-04 04:51 - 001404164 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2023-05-28 04:02 - 2020-06-19 02:19 - 000001445 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
    2023-05-28 04:02 - 2019-12-07 17:13 - 000000000 ____D C:\WINDOWS\INF
    2023-05-28 04:02 - 2017-08-08 06:05 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
    2023-05-28 04:01 - 2020-11-04 05:06 - 000003976 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 04:01 - 2020-11-04 05:06 - 000003940 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 04:01 - 2017-08-08 06:05 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
    2023-05-28 04:01 - 2017-08-08 06:04 - 000000000 ____D C:\Program Files\NVIDIA Corporation
    2023-05-28 03:58 - 2020-11-04 05:06 - 000004308 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 03:58 - 2020-11-04 05:06 - 000004106 _____ C:\WINDOWS\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 03:58 - 2020-11-04 05:06 - 000003894 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 03:58 - 2020-11-04 05:06 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 03:58 - 2020-11-04 05:06 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 03:58 - 2020-11-04 05:06 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 03:58 - 2020-11-04 05:06 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 03:58 - 2020-11-04 05:06 - 000003654 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2023-05-28 03:57 - 2017-12-16 15:58 - 000000000 ____D C:\Program Files (x86)\Google
    2023-05-27 20:54 - 2022-01-28 08:17 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3094068508-250876253-3180504964-1001
    2023-05-27 20:54 - 2021-05-07 06:50 - 000002381 _____ C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2023-05-27 20:54 - 2020-11-04 05:06 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3094068508-250876253-3180504964-1001
    2023-05-27 20:31 - 2019-03-24 17:55 - 000000000 ____D C:\Users\Peter\AppData\Roaming\vlc
    2023-05-27 15:51 - 2021-09-23 19:26 - 000000000 ____D C:\WINDOWS\Minidump
    2023-05-27 15:44 - 2021-09-23 19:26 - 740886031 _____ C:\WINDOWS\MEMORY.DMP
    2023-05-27 15:44 - 2020-11-04 05:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2023-05-27 15:44 - 2020-11-04 04:30 - 000008192 ___SH C:\DumpStack.log.tmp
    2023-05-27 15:41 - 2019-12-07 17:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
    2023-05-27 14:33 - 2019-12-07 17:14 - 000000000 ___HD C:\Program Files\WindowsApps
    2023-05-27 14:33 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\AppReadiness
    2023-05-27 14:28 - 2020-11-04 04:30 - 000515584 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2023-05-27 14:24 - 2020-11-04 19:46 - 000000000 ____D C:\WINDOWS\SysWOW64\zh-HANT
    2023-05-27 14:24 - 2020-11-04 19:46 - 000000000 ____D C:\WINDOWS\system32\zh-HANT
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\SystemResources
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\system32\setup
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\system32\oobe
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\system32\Dism
    2023-05-27 14:24 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
    2023-05-27 14:23 - 2019-12-07 17:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2023-05-27 14:23 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
    2023-05-27 14:23 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
    2023-05-27 14:23 - 2019-12-07 17:14 - 000000000 ____D C:\WINDOWS\bcastdvr
    2023-05-27 13:18 - 2020-06-13 21:42 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
    2023-05-27 03:49 - 2019-12-07 17:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
    2023-05-27 03:47 - 2019-12-07 17:03 - 000000000 ____D C:\WINDOWS\CbsTemp
    2023-05-27 03:12 - 2020-11-04 04:35 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2023-05-26 23:42 - 2017-12-19 07:58 - 000000000 ____D C:\Users\Peter\AppData\Local\Packages
    2023-05-26 23:01 - 2020-09-30 07:04 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
    2023-05-26 22:40 - 2017-12-17 05:34 - 000000000 ____D C:\WINDOWS\system32\MRT
    2023-05-26 22:35 - 2017-12-17 05:34 - 159583304 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2023-05-26 22:28 - 2017-12-16 15:58 - 000002375 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2023-05-26 22:28 - 2017-12-16 15:58 - 000002334 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2023-05-26 22:18 - 2020-11-04 04:39 - 000000000 ____D C:\Users\Peter
    2023-05-26 22:03 - 2017-12-17 05:46 - 000000000 ____D C:\Users\Peter\AppData\Roaming\Microsoft\MMC
    2023-05-26 21:47 - 2018-09-11 20:09 - 000000000 ____D C:\Users\Peter\AppData\Local\D3DSCache
    2023-05-26 21:46 - 2018-03-28 03:54 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
    2023-05-26 21:41 - 2017-12-17 03:34 - 000000000 ____D C:\Users\Peter\AppData\Local\NVIDIA Corporation
    2023-05-26 21:33 - 2018-09-09 05:32 - 000000922 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
    2023-05-26 21:33 - 2018-09-09 05:32 - 000000918 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
    2023-05-26 21:33 - 2018-01-15 02:34 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
    2023-05-26 21:01 - 2018-09-09 05:32 - 000000000 ____D C:\Program Files (x86)\Dropbox
    2023-05-26 20:52 - 2020-11-04 05:06 - 000003714 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
    2023-05-26 20:52 - 2020-11-04 05:06 - 000003590 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
    2023-05-26 20:16 - 2018-07-11 15:16 - 000000000 ____D C:\ProgramData\Packages
    2023-05-26 20:15 - 2020-11-04 05:06 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
    2023-05-26 20:15 - 2020-11-04 05:06 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
    2023-05-26 20:09 - 2020-11-04 05:06 - 000003982 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineUA
    2023-05-26 20:09 - 2020-11-04 05:06 - 000003750 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineCore

    ==================== Files in the root of some directories ========

    2020-10-17 11:44 - 2020-10-17 11:44 - 000007607 _____ () C:\Users\Peter\AppData\Local\Resmon.ResmonCfg

    ==================== SigCheck ============================

    (There is no automatic fix for files that do not pass verification.)

    ==================== End of FRST.txt ========================
     
  4. MoPman

    MoPman Private E-2

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-05-2023
    Ran by Peter (28-05-2023 04:29:26)
    Running from C:\Users\Peter\Desktop
    Microsoft Windows 10 Home Version 22H2 19045.2965 (X64) (2020-11-03 21:07:44)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================


    (If an entry is included in the fixlist, it will be removed.)

    Administrator (S-1-5-21-3094068508-250876253-3180504964-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-3094068508-250876253-3180504964-503 - Limited - Disabled)
    Guest (S-1-5-21-3094068508-250876253-3180504964-501 - Limited - Disabled)
    Peter (S-1-5-21-3094068508-250876253-3180504964-1001 - Administrator - Enabled) => C:\Users\Peter
    WDAGUtilityAccount (S-1-5-21-3094068508-250876253-3180504964-504 - Limited - Disabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
    ASUS Device Activation (HKLM-x32\...\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}) (Version: 1.0.4.0 - ASUSTeK COMPUTER INC.)
    ASUS GIFTBOX (HKLM-x32\...\ASUS GIFTBOX) (Version: 7.5.24 - ASUSTek Computer Inc)
    ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.6.8 - ASUSTeK COMPUTER INC.)
    ASUS USB-AC68 WLAN Card Driver (HKLM-x32\...\{56A6C59A-E783-41CB-A5F9-9240CA3C6B87}) (Version: 2.1.4.8 - ASUS)
    AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.3.28 - ICEpower a/s)
    calibre (HKLM-x32\...\{DD87CCE3-2BE7-49EA-8261-BF997D3B7768}) (Version: 3.41.3 - Kovid Goyal)
    Device Setup (HKLM-x32\...\{8D6B05E0-F457-408C-9D13-549334D8FAE1}) (Version: 2.2.7 - ASUSTek COMPUTER INC.)
    Dropbox (HKLM-x32\...\Dropbox) (Version: 174.4.5852 - Dropbox, Inc.)
    Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.761.1 - Dropbox, Inc.) Hidden
    Epic Games Launcher (HKLM-x32\...\{1D4EB18B-0FEE-444E-B4D1-6F2CFBC363E6}) (Version: 1.1.267.0 - Epic Games, Inc.)
    Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 113.0.5672.127 - Google LLC)
    Google Earth Pro (HKLM\...\{F27DBA46-80E1-4858-9285-19198FFFBF3D}) (Version: 7.3.6.9345 - Google)
    HiCOS PKI Smart Card (HKLM\...\{C9BD427F-EF5C-4361-BEA1-202104203086}) (Version: 3.0.8.63420 - Chunghwa Telecom) Hidden
    HiCOS PKI Smart Card (HKLM-x32\...\{81a40430-7664-4614-a14e-d66755d37e3e}) (Version: 3.0.3.63420 - Chunghwa Telecom)
    Intel(R) Chipset Device Software (HKLM\...\{81520FC5-3518-40E9-9803-70CE8A801D07}) (Version: 10.1.1.38 - Intel Corporation) Hidden
    Intel(R) Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden
    Intel(R) Management Engine Components (HKLM\...\{177F3AF8-1D9D-4C47-AB82-69571F4630DE}) (Version: 1.0.0.0 - Intel Corporation) Hidden
    Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1035 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM\...\{DEDA24FF-BA95-42E7-B914-639D32515511}) (Version: 11.6.0.1035 - Intel Corporation) Hidden
    Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.5.0.1051 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM\...\{649A7D62-D903-4F30-B7C3-F0D15E4CAD67}) (Version: 15.5.0.1051 - Intel Corporation) Hidden
    Intel(R) Serial IO (HKLM\...\{6F97B5F8-7B9A-454E-8096-CF7B51A84731}) (Version: 30.100.1713.2 - Intel Corporation) Hidden
    Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1713.2 - Intel Corporation)
    Intel® Trusted Connect Service Client (HKLM\...\{75FE588B-F158-4BB3-A283-A8D18E522A52}) (Version: 1.43.301.1 - Intel Corporation) Hidden
    Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
    Lightworks (HKLM-x32\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 14.0.0.0 - EditShare)
    Malwarebytes version 4.5.29.268 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.29.268 - Malwarebytes)
    Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 113.0.1774.57 - Microsoft Corporation)
    Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 113.0.1774.50 - Microsoft Corporation)
    Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
    Microsoft OneDrive (HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\OneDriveSetup.exe) (Version: 23.096.0507.0001 - Microsoft Corporation)
    Microsoft Update Health Tools (HKLM\...\{BB052C53-34CB-42DE-AF41-66FDFCEEC868}) (Version: 3.72.0.0 - Microsoft Corporation)
    Microsoft VC++ redistributables repacked. (HKLM\...\{F72EB01C-8051-488C-AB30-848E38D3598B}) (Version: 12.0.0.0 - Intel Corporation) Hidden
    Microsoft VC++ redistributables repacked. (HKLM-x32\...\{F29F6D90-52BF-4644-9F61-82EFF42A9268}) (Version: 12.0.0.0 - Intel Corporation) Hidden
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\...\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation)
    Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020 (HKLM-x32\...\{5c045b7f-e561-4794-91f8-c6cda0893107}) (Version: 14.13.26020.0 - Microsoft Corporation)
    Microsoft Visual C++ 2017 x64 Additional Runtime - 14.13.26020 (HKLM\...\{C5ECDB9A-D9B0-3107-BA85-1269998A5B3E}) (Version: 14.13.26020 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.13.26020 (HKLM\...\{221D6DB4-46E2-333C-B09B-5F49351D0980}) (Version: 14.13.26020 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2017 x86 Additional Runtime - 14.13.26020 (HKLM-x32\...\{895D5198-C5DB-375E-86AB-133F4DAA9FE2}) (Version: 14.13.26020 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.13.26020 (HKLM-x32\...\{8F271F6C-6E7B-3D0A-951B-6E7B694D78BD}) (Version: 14.13.26020 - Microsoft Corporation) Hidden
    Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.5.3 - Notepad++ Team)
    NVIDIA FrameView SDK 1.1.4923.29968894 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.1.4923.29968894 - NVIDIA Corporation)
    NVIDIA GeForce Experience 3.23.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.23.0.74 - NVIDIA Corporation)
    NVIDIA Graphics Driver 446.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 446.14 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.38.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.26 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
    Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0439-1000-0000000FF1CE}) (Version: 16.0.7571.2122 - Microsoft Corporation) Hidden
    OpenOffice 4.1.4 (HKLM-x32\...\{BDB210E1-06C5-451F-BDAC-C18DDC7C2F14}) (Version: 4.14.9788 - Apache Software Foundation)
    PureVPN (HKLM-x32\...\{599fa1b8-2fbf-4b24-98d9-89e209b15012}) (Version: 7.1.1.0 - ) Hidden
    PureVPN (HKLM-x32\...\PureVPN) (Version: 7.1.1.0 - PureVPN)
    qBittorrent 4.1.5 (HKLM-x32\...\qBittorrent) (Version: 4.1.5 - The qBittorrent project)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.16.323.2017 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8656 - Realtek Semiconductor Corp.)
    RogueKiller version 15.10.0.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 15.10.0.0 - Adlice Software)
    Spotify (HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\Spotify) (Version: 1.1.15.448.g00fba0e3 - Spotify AB)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1254 - SUPERAntiSpyware.com)
    Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{C22F49B1-0F67-47DC-A490-E8B4B6558EA9}) (Version: 8.91.0.0 - Microsoft Corporation)
    UpdateAssistant (HKLM\...\{F49D6A65-1AB6-4728-9FDA-DB5BAB631CF6}) (Version: 1.23.0.0 - Microsoft Corporation) Hidden
    VLC media player (HKLM\...\VLC media player) (Version: 3.0.6 - VideoLAN)
    Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation)
    WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.2.9.0 - ASUSTeK COMPUTER INC.)
    WinRAR 5.70 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.70.0 - win.rar GmbH)
    World of Tanks (HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812na}_is1) (Version: - Wargaming.net)
    跨平台網頁元件 版本 1.3.4.103339 (HKLM-x32\...\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1) (Version: 1.3.4.103339 - Chunghwa Telecom Co., Ltd.)

    Packages:
    =========
    ASUS ZenLink -> C:\Program Files\WindowsApps\B9ECED6F.ZenSync_1.0.7.0_x86__qmba6cd70vzyy [2023-05-26] (ASUSTeK COMPUTER INC.) [MS Ad]
    Bubble Witch 3 Saga -> C:\Program Files\WindowsApps\king.com.BubbleWitch3Saga_7.33.22.0_x64__kgqvnymyfvs32 [2023-05-26] (king.com)
    Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.243.300.0_x64__kgqvnymyfvs32 [2023-05-26] (king.com)
    March of Empires: War of Lords -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_7.4.0.0_x86__h6adky7gbf63m [2023-05-26] (Gameloft SE)
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2020-11-04] (Microsoft Corporation) [MS Ad]
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-14] (Microsoft Corporation) [MS Ad]
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-14] (Microsoft Corporation) [MS Ad]
    Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.19.8301.0_x64__8wekyb3d8bbwe [2023-05-27] (Microsoft Studios)
    MyASUS-Service Center -> C:\Program Files\WindowsApps\B9ECED6F.MyASUS_3.3.11.0_x86__qmba6cd70vzyy [2018-04-27] (ASUSTeK COMPUTER INC.) [Startup Task]
    Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-21] (Netflix, Inc.)
    Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.16.3140.0_x64__8wekyb3d8bbwe [2023-05-26] (Microsoft Studios) [MS Ad]
    WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.851.1712.0_x64__8wekyb3d8bbwe [2023-05-26] (Microsoft Corporation)
    WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.851.1712.0_x86__8wekyb3d8bbwe [2023-05-26] (Microsoft Corporation)

    ==================== Custom CLSID (Whitelisted): ==============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-3094068508-250876253-3180504964-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\Peter\Dropbox [2018-09-09 05:38]
    ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) [File not signed]
    ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2017-12-06] (Notepad++ -> )
    ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-25] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-25] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) [File not signed]
    ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.61.0.dll [2023-05-18] (Dropbox, Inc -> Dropbox, Inc.)
    ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-05-16] (NVIDIA Corporation -> NVIDIA Corporation)
    ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) [File not signed]
    ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-25] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-25] (win.rar GmbH -> Alexander Roshal)

    ==================== Codecs (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Drivers32: [VIDC.LWLR] => C:\Windows\SysWOW64\RGBACodec.dll [37488 2017-04-04] (EditShare EMEA (X-Edit Limited) -> )

    ==================== Shortcuts & WMI ========================

    ==================== Loaded Modules (Whitelisted) =============

    2017-12-16 17:42 - 2016-10-04 22:51 - 000076800 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll

    ==================== Alternate Data Streams (Whitelisted) ========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\Users\Peter\Desktop\FRST64.exe:MBAM.Zone.Identifier [240]
    AlternateDataStreams: C:\Users\Peter\Desktop\HitmanPro_x64.exe:MBAM.Zone.Identifier [164]
    AlternateDataStreams: C:\Users\Peter\Desktop\setup.exe:MBAM.Zone.Identifier [151]

    ==================== Safe Mode (Whitelisted) ==================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

    ==================== Association (Whitelisted) =================

    ==================== Internet Explorer (Whitelisted) ==========

    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus17win10.msn.com/?pc=ASTE
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus17win10.msn.com/?pc=ASTE
    SearchScopes: HKU\S-1-5-21-3094068508-250876253-3180504964-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-3094068508-250876253-3180504964-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

    ==================== Hosts content: =========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2017-03-19 05:03 - 2017-03-19 05:01 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

    ==================== Other Areas ===========================

    (Currently there is no automatic fix for this section.)

    HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\Calibre2\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Peter\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img13.jpg
    DNS Servers: 192.168.50.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (If an entry is included in the fixlist, it will be removed.)

    HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
    HKLM\...\StartupApproved\Run32: => "Dropbox"
    HKLM\...\StartupApproved\Run32: => "跨平台網頁元件"
    HKLM\...\StartupApproved\Run32: => "HiCOS Token Utility"
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\StartupApproved\Run: => "World of Tanks"
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\StartupApproved\Run: => "EpicGamesLauncher"

    ==================== FirewallRules (Whitelisted) ================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [TCP Query User{FE57EB9B-DF99-404C-AA87-25ECDF2A2756}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [UDP Query User{CEBA16A7-9900-4EA1-AC86-3E658F9F4771}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [TCP Query User{B49033A3-D1DB-4B33-B9EE-268469FDCF7D}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [UDP Query User{77126203-3044-4DBC-A89D-124CC218F39E}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [TCP Query User{37F202AF-E28C-4620-8FE1-5F783000109D}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
    FirewallRules: [UDP Query User{AEAA595F-4019-46C1-A693-E91B37108495}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
    FirewallRules: [{E8F32BC9-CE31-4E9E-980A-4B1072E75D26}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
    FirewallRules: [{BD24D8E0-1FD4-4C56-8936-F48CC9C4155D}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
    FirewallRules: [{AEA83A51-C9BC-4514-8A39-0A7D6C7192D4}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\113.0.1774.50\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
    FirewallRules: [{7E1A17C8-5F18-46F0-A56A-B366EC5FF15A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
    FirewallRules: [{6AE01AF1-4408-4C66-B67C-C36C78B3E577}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.98.3206.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{3A805E92-AB9E-4483-A350-8A9995C5D47B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.98.3206.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{130A1910-59B9-4558-8556-F97BA3A234F2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.98.3206.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{B4D30D40-20C2-4D0D-BA40-9A66DBB5EE7D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.98.3206.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{2308643E-2DA7-4320-A639-56EEBCBA8C4D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{DA223C53-A3BC-4ABA-9B1F-5F8217E11AF7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{A32C78E3-B66B-4AC6-A529-6D41D488CD57}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{D0F392BB-CD6B-4AEF-8D5F-E3876BE6A7A1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{7A1CFBC3-E639-461F-A9B6-E7CE76976526}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{2EB542C1-5D6B-460A-823B-9BC709301DA2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)

    ==================== Restore Points =========================

    26-05-2023 21:46:31 Windows Modules Installer

    ==================== Faulty Device Manager Devices ============


    ==================== Event log errors: ========================

    Application errors:
    ==================
    Error: (05/27/2023 05:49:51 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on DATA1 (F:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)

    Error: (05/27/2023 05:49:36 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on OS (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)

    Error: (05/27/2023 04:59:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program SystemSettings.exe version 10.0.19041.2075 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: 41c8

    Start Time: 01d99014b63e9530

    Termination Time: 4294967295

    Application Path: C:\Windows\ImmersiveControlPanel\SystemSettings.exe

    Report Id: d78cb520-3628-4fe3-a83d-6aa78e4ab918

    Faulting package full name: windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy

    Faulting package-relative application ID: microsoft.windows.immersivecontrolpanel

    Hang type: Cross-thread

    Error: (05/27/2023 02:52:49 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program SystemSettings.exe version 10.0.19041.2075 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: 240

    Start Time: 01d98feb9647fc4a

    Termination Time: 4294967295

    Application Path: C:\Windows\ImmersiveControlPanel\SystemSettings.exe

    Report Id: 05232200-863a-440b-96b0-a2d7dd6aa983

    Faulting package full name: windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy

    Faulting package-relative application ID: microsoft.windows.immersivecontrolpanel

    Hang type: Quiesce

    Error: (05/26/2023 10:45:35 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on DATA1 (F:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)

    Error: (05/26/2023 10:29:57 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on DATA1 (F:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)

    Error: (05/26/2023 10:29:45 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on DATA1 (F:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)

    Error: (05/26/2023 10:29:27 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
    Description: The storage optimizer couldn't complete retrim on DATA1 (F:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)


    System errors:
    =============
    Error: (05/27/2023 03:50:21 PM) (Source: BugCheck) (EventID: 1001) (User: )
    Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x00000133 (0x0000000000000000, 0x0000000000000501, 0x0000000000000500, 0xfffff803514fb320). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: bccb0350-9eb0-48d8-a130-30375dd65207.

    Error: (05/27/2023 03:44:59 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The WMPNetworkSvc service depends on the WSearch service which failed to start because of the following error:
    The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

    Error: (05/27/2023 03:44:28 PM) (Source: volmgr) (EventID: 161) (User: )
    Description: Dump file creation failed due to error during dump creation.

    Error: (05/27/2023 02:27:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The WMPNetworkSvc service depends on the WSearch service which failed to start because of the following error:
    The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

    Error: (05/26/2023 11:17:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The WMPNetworkSvc service depends on the WSearch service which failed to start because of the following error:
    The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

    Error: (05/26/2023 11:16:15 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: DCOM got error "1053" attempting to start the service wuauserv with arguments "Unavailable" in order to run the server:
    {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error: (05/26/2023 11:16:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Windows Update service failed to start due to the following error:
    The service did not respond to the start or control request in a timely fashion.

    Error: (05/26/2023 10:20:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The WMPNetworkSvc service depends on the WSearch service which failed to start because of the following error:
    The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


    Windows Defender:
    ================
    Date: 2023-05-26 22:49:38
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2022-11-16 17:37:01
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2021-10-15 18:28:26
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2021-09-23 22:51:56
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2021-08-16 14:27:28
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan
    Event[0]:

    Date: 2023-05-26 20:49:37
    Description:
    Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.381.814.0
    Update Source: Microsoft Malware Protection Center
    Security intelligence Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.19900.2
    Error code: 0x80070020
    Error description: The process cannot access the file because it is being used by another process.

    Date: 2023-05-26 20:49:37
    Description:
    Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.381.814.0
    Update Source: Microsoft Malware Protection Center
    Security intelligence Type: AntiSpyware
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.19900.2
    Error code: 0x80070020
    Error description: The process cannot access the file because it is being used by another process.

    Date: 2023-05-26 20:49:37
    Description:
    Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.381.814.0
    Update Source: Microsoft Malware Protection Center
    Security intelligence Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.19900.2
    Error code: 0x80070020
    Error description: The process cannot access the file because it is being used by another process.

    Date: 2023-05-26 20:44:42
    Description:
    Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.381.814.0
    Update Source: Microsoft Update Server
    Security intelligence Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.19900.2
    Error code: 0x80070102
    Error description: The wait operation timed out.

    Date: 2023-05-26 20:44:42
    Description:
    Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.381.814.0
    Update Source: Microsoft Update Server
    Security intelligence Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.19900.2
    Error code: 0x80070102
    Error description: The wait operation timed out.

    CodeIntegrity:
    ===============
    Date: 2023-05-28 04:30:20
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.


    ==================== Memory info ===========================

    BIOS: American Megatrends Inc. 0604 04/06/2017
    Motherboard: ASUSTeK COMPUTER INC. K31CD-K
    Processor: Intel(R) Core(TM) i5-7400 CPU @ 3.00GHz
    Percentage of memory in use: 56%
    Total physical RAM: 8145.21 MB
    Available physical RAM: 3540.03 MB
    Total Virtual: 9617.21 MB
    Available Virtual: 3192.99 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:930.46 GB) (Free:678.01 GB) (Model: TOSHIBA DT01ACA100) NTFS
    Drive f: (DATA1) (Fixed) (Total:931.51 GB) (Free:0.08 GB) (Model: ST31000528AS) NTFS

    \\?\Volume{8a266d6b-a599-4d3b-a841-6525f97f5cdc}\ () (Fixed) (Total:0.78 GB) (Free:0.35 GB) NTFS
    \\?\Volume{b098e2b0-05ee-4495-86c3-e81eb88f14be}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

    ==================== MBR & Partition Table ====================

    ==========================================================
    Disk: 0 (Size: 931.5 GB) (Disk ID: 6C5D8EC1)

    Partition: GPT.

    ==========================================================
    Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: B089C940)
    Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt =======================
     
  5. MoPman

    MoPman Private E-2

    Hi!
    First, thank you for your rapid reply.

    I thought I would add the following information as I'm not sure whether it could be helpful or not:
    -Upon completing installation, Farbar said that it failed to update.
    -During the various scans, the program seemed to freeze (blabla "is not responding") five times for approximately 20 seconds each time.

    Thank you!
     
  6. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks for the feedback on FRST. The Failed to update has been reported.

    There is no evidence of malware on the system but let's see what we can do. Please start with this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File) 
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) 
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Uninstall 22.225.1026.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\22.225.1026.0001" (No File) 
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File) 
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) 
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Uninstall 22.225.1026.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\22.225.1026.0001" (No File) 
    Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found] 
    Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found] 
    Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found] 
    Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found] 
    CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
    CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
    CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp]
    CHR HKLM-x32\...\Chrome\Extension: [bfidboloedlamgdmenmlbipfnccokknp]
    CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
    CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
    CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp]
    Zip: C:\Windows\Minidump
    cmd: chkdsk
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp: 
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • The tool will create a zipped folder in the same location from where FRST was run with today's date, example: 06.11.2016_13.24.50.zip. Please attach the file to your reply
    • Note: The Emptytemp: command will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
    • Fixlog
     
  7. MoPman

    MoPman Private E-2

    Fix result of Farbar Recovery Scan Tool (x64) Version: 27-05-2023
    Ran by Peter (28-05-2023 11:35:27) Run:1
    Running from C:\Users\Peter\Desktop
    Loaded Profiles: Peter
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    CreateRestorePoint:
    CloseProcesses:
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Uninstall 22.225.1026.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\22.225.1026.0001" (No File)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
    HKU\S-1-5-21-3094068508-250876253-3180504964-1001\...\RunOnce: [Uninstall 22.225.1026.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Peter\AppData\Local\Microsoft\OneDrive\22.225.1026.0001" (No File)
    Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
    Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
    Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
    Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
    CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
    CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
    CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp]
    CHR HKLM-x32\...\Chrome\Extension: [bfidboloedlamgdmenmlbipfnccokknp]
    CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
    CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
    CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp]
    Zip: C:\Windows\Minidump
    cmd: chkdsk
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    End::
    *****************

    Restore point was successfully created.
    Processes closed successfully.
    "HKU\S-1-5-21-3094068508-250876253-3180504964-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Update Binary" => not found
    "HKU\S-1-5-21-3094068508-250876253-3180504964-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Standalone Update Binary" => not found
    "HKU\S-1-5-21-3094068508-250876253-3180504964-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall 22.225.1026.0001" => not found
    "HKU\S-1-5-21-3094068508-250876253-3180504964-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Update Binary" => not found
    "HKU\S-1-5-21-3094068508-250876253-3180504964-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Standalone Update Binary" => not found
    "HKU\S-1-5-21-3094068508-250876253-3180504964-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall 22.225.1026.0001" => not found
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\caljgklbbfbcjjanaijlacgncafpegll => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bfidboloedlamgdmenmlbipfnccokknp => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\caljgklbbfbcjjanaijlacgncafpegll => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp => removed successfully
    ================== Zip: ===================
    C:\Windows\Minidump -> copied successfully to C:\Users\Peter\Desktop\28.05.2023_11.36.33.zip
    =========== Zip: End ===========

    ========= chkdsk =========

    The type of the file system is NTFS.
    Volume label is OS.

    WARNING! /F parameter not specified.
    Running CHKDSK in read-only mode.

    Stage 1: Examining basic file system structure ...
    Progress: 0 of 857600 done; Stage: 0%; Total: 0%; ETA: 0:41:14
    Progress: 1861 of 857600 done; Stage: 0%; Total: 0%; ETA: 0:41:13 .
    Progress: 5121 of 857600 done; Stage: 0%; Total: 0%; ETA: 0:41:10 ..
    Progress: 8169 of 857600 done; Stage: 0%; Total: 0%; ETA: 0:06:02 ...
    Progress: 8932 of 857600 done; Stage: 1%; Total: 0%; ETA: 0:07:47
    Progress: 9096 of 857600 done; Stage: 1%; Total: 0%; ETA: 0:09:09 .
    Progress: 9640 of 857600 done; Stage: 1%; Total: 0%; ETA: 0:10:41 ..
    Progress: 10623 of 857600 done; Stage: 1%; Total: 0%; ETA: 0:11:18 ...
    Progress: 13569 of 857600 done; Stage: 1%; Total: 0%; ETA: 0:10:27
    Progress: 18081 of 857600 done; Stage: 2%; Total: 0%; ETA: 0:09:04 .
    Progress: 18689 of 857600 done; Stage: 2%; Total: 0%; ETA: 0:09:45 ..
    Progress: 28781 of 857600 done; Stage: 3%; Total: 1%; ETA: 0:07:11 ...
    Progress: 32217 of 857600 done; Stage: 3%; Total: 1%; ETA: 0:07:00
    Progress: 33296 of 857600 done; Stage: 3%; Total: 1%; ETA: 0:07:15 .
    Progress: 36958 of 857600 done; Stage: 4%; Total: 1%; ETA: 0:07:03 ..
    Progress: 39467 of 857600 done; Stage: 4%; Total: 1%; ETA: 0:07:05 ...
    Progress: 41636 of 857600 done; Stage: 4%; Total: 1%; ETA: 0:07:08
    Progress: 42479 of 857600 done; Stage: 4%; Total: 1%; ETA: 0:07:20 .
    Progress: 42996 of 857600 done; Stage: 5%; Total: 1%; ETA: 0:07:41 ..
    Progress: 44083 of 857600 done; Stage: 5%; Total: 1%; ETA: 0:07:51 ...
    Progress: 46128 of 857600 done; Stage: 5%; Total: 2%; ETA: 0:07:52
    Progress: 48122 of 857600 done; Stage: 5%; Total: 2%; ETA: 0:07:53 .
    Progress: 49578 of 857600 done; Stage: 5%; Total: 2%; ETA: 0:07:59 ..
    Progress: 50876 of 857600 done; Stage: 5%; Total: 2%; ETA: 0:08:06 ...
    Progress: 50967 of 857600 done; Stage: 5%; Total: 2%; ETA: 0:08:16
    Progress: 54017 of 857600 done; Stage: 6%; Total: 2%; ETA: 0:08:12 .
    Progress: 56672 of 857600 done; Stage: 6%; Total: 2%; ETA: 0:08:09 ..
    Progress: 58369 of 857600 done; Stage: 6%; Total: 2%; ETA: 0:08:12 ...
    Progress: 60898 of 857600 done; Stage: 7%; Total: 2%; ETA: 0:08:09
    Progress: 61439 of 857600 done; Stage: 7%; Total: 2%; ETA: 0:08:18 .
    Progress: 61670 of 857600 done; Stage: 7%; Total: 2%; ETA: 0:08:30 ..
    Progress: 62280 of 857600 done; Stage: 7%; Total: 2%; ETA: 0:08:46 ...
    Progress: 64879 of 857600 done; Stage: 7%; Total: 2%; ETA: 0:08:41
    Progress: 66888 of 857600 done; Stage: 7%; Total: 3%; ETA: 0:08:40 .
    Progress: 67745 of 857600 done; Stage: 7%; Total: 3%; ETA: 0:08:49 ..
    Progress: 70078 of 857600 done; Stage: 8%; Total: 3%; ETA: 0:08:46 ...
    Progress: 72961 of 857600 done; Stage: 8%; Total: 3%; ETA: 0:08:38
    Progress: 80037 of 857600 done; Stage: 9%; Total: 3%; ETA: 0:08:09 .
    Progress: 95320 of 857600 done; Stage: 11%; Total: 4%; ETA: 0:07:05 ..
    Progress: 106241 of 857600 done; Stage: 12%; Total: 4%; ETA: 0:06:35 ...
    Progress: 108841 of 857600 done; Stage: 12%; Total: 4%; ETA: 0:06:35
    Progress: 113242 of 857600 done; Stage: 13%; Total: 4%; ETA: 0:06:28 .
    Progress: 118245 of 857600 done; Stage: 13%; Total: 5%; ETA: 0:06:20 ..
    Progress: 122122 of 857600 done; Stage: 14%; Total: 5%; ETA: 0:06:15 ...
    Progress: 125358 of 857600 done; Stage: 14%; Total: 5%; ETA: 0:06:14
    Progress: 130055 of 857600 done; Stage: 15%; Total: 5%; ETA: 0:06:07 .
    Progress: 137073 of 857600 done; Stage: 15%; Total: 6%; ETA: 0:05:58 ..
    Progress: 144671 of 857600 done; Stage: 16%; Total: 6%; ETA: 0:05:44 ...
    Progress: 147050 of 857600 done; Stage: 17%; Total: 6%; ETA: 0:05:47
    Progress: 153286 of 857600 done; Stage: 17%; Total: 6%; ETA: 0:05:39 .
    Progress: 155100 of 857600 done; Stage: 18%; Total: 6%; ETA: 0:05:40 ..
    Progress: 160683 of 857600 done; Stage: 18%; Total: 7%; ETA: 0:05:34 ...
    Progress: 165633 of 857600 done; Stage: 19%; Total: 7%; ETA: 0:05:31
    Progress: 176086 of 857600 done; Stage: 20%; Total: 7%; ETA: 0:05:16 .
    Progress: 181135 of 857600 done; Stage: 21%; Total: 7%; ETA: 0:05:13 ..
    Progress: 186398 of 857600 done; Stage: 21%; Total: 8%; ETA: 0:05:08 ...
    Progress: 187198 of 857600 done; Stage: 21%; Total: 8%; ETA: 0:05:12
    Progress: 196325 of 857600 done; Stage: 22%; Total: 8%; ETA: 0:05:03 .
    Progress: 201848 of 857600 done; Stage: 23%; Total: 8%; ETA: 0:05:00 ..
    Progress: 215713 of 857600 done; Stage: 25%; Total: 9%; ETA: 0:04:44 ...
    Progress: 219180 of 857600 done; Stage: 25%; Total: 9%; ETA: 0:04:44
    Progress: 223004 of 857600 done; Stage: 26%; Total: 9%; ETA: 0:04:43 .
    Progress: 232869 of 857600 done; Stage: 27%; Total: 10%; ETA: 0:04:35 ..
    Progress: 234832 of 857600 done; Stage: 27%; Total: 10%; ETA: 0:04:35 ...
    Progress: 239534 of 857600 done; Stage: 27%; Total: 10%; ETA: 0:04:33
    Progress: 246840 of 857600 done; Stage: 28%; Total: 10%; ETA: 0:04:30 .
    Progress: 256350 of 857600 done; Stage: 29%; Total: 11%; ETA: 0:04:22 ..
    Progress: 265217 of 857600 done; Stage: 30%; Total: 11%; ETA: 0:04:17 ...
    Progress: 270577 of 857600 done; Stage: 31%; Total: 11%; ETA: 0:04:15
    Progress: 277761 of 857600 done; Stage: 32%; Total: 12%; ETA: 0:04:11 .
    Progress: 288054 of 857600 done; Stage: 33%; Total: 12%; ETA: 0:04:06 ..
    Progress: 291396 of 857600 done; Stage: 33%; Total: 12%; ETA: 0:04:04 ...
    Progress: 296645 of 857600 done; Stage: 34%; Total: 12%; ETA: 0:04:04
    Progress: 299030 of 857600 done; Stage: 34%; Total: 12%; ETA: 0:04:04 .
    Progress: 303449 of 857600 done; Stage: 35%; Total: 13%; ETA: 0:04:04 ..
    Progress: 304426 of 857600 done; Stage: 35%; Total: 13%; ETA: 0:04:06 ...
    Progress: 307225 of 857600 done; Stage: 35%; Total: 13%; ETA: 0:04:06
    Progress: 311591 of 857600 done; Stage: 36%; Total: 13%; ETA: 0:04:06 .
    Progress: 315988 of 857600 done; Stage: 36%; Total: 13%; ETA: 0:04:03 ..
    Progress: 316323 of 857600 done; Stage: 36%; Total: 13%; ETA: 0:04:06 ...
    Progress: 316331 of 857600 done; Stage: 36%; Total: 13%; ETA: 0:04:07
    Progress: 316426 of 857600 done; Stage: 36%; Total: 13%; ETA: 0:04:11 .
    Progress: 317350 of 857600 done; Stage: 37%; Total: 13%; ETA: 0:04:14 ..
    Progress: 317606 of 857600 done; Stage: 37%; Total: 13%; ETA: 0:04:17 ...
    Progress: 318858 of 857600 done; Stage: 37%; Total: 13%; ETA: 0:04:19
    Progress: 321281 of 857600 done; Stage: 37%; Total: 13%; ETA: 0:04:19 .
    Progress: 322049 of 857600 done; Stage: 37%; Total: 14%; ETA: 0:04:22 ..
    Progress: 324353 of 857600 done; Stage: 37%; Total: 14%; ETA: 0:04:22 ...
    Progress: 327606 of 857600 done; Stage: 38%; Total: 14%; ETA: 0:04:23
    Progress: 331931 of 857600 done; Stage: 38%; Total: 14%; ETA: 0:04:23 .
    Progress: 335873 of 857600 done; Stage: 39%; Total: 14%; ETA: 0:04:22 ..
    Progress: 340993 of 857600 done; Stage: 39%; Total: 14%; ETA: 0:04:20 ...
    Progress: 350878 of 857600 done; Stage: 40%; Total: 15%; ETA: 0:04:14
    Progress: 371395 of 857600 done; Stage: 43%; Total: 16%; ETA: 0:04:03 .
    Progress: 373227 of 857600 done; Stage: 43%; Total: 16%; ETA: 0:04:03 ..
    Progress: 373403 of 857600 done; Stage: 43%; Total: 16%; ETA: 0:04:03 ...
    Progress: 373466 of 857600 done; Stage: 43%; Total: 16%; ETA: 0:04:05
    Progress: 378540 of 857600 done; Stage: 44%; Total: 16%; ETA: 0:04:06 .
    Progress: 395521 of 857600 done; Stage: 46%; Total: 17%; ETA: 0:03:56 ..
    Progress: 405473 of 857600 done; Stage: 47%; Total: 17%; ETA: 0:03:51 ...
    Progress: 411393 of 857600 done; Stage: 47%; Total: 17%; ETA: 0:03:48
    Progress: 420551 of 857600 done; Stage: 49%; Total: 18%; ETA: 0:03:42 .
    Progress: 425000 of 857600 done; Stage: 49%; Total: 18%; ETA: 0:03:40 ..
    Progress: 429424 of 857600 done; Stage: 50%; Total: 19%; ETA: 0:03:39 ...
    Progress: 444573 of 857600 done; Stage: 51%; Total: 19%; ETA: 0:03:31
    Progress: 464129 of 857600 done; Stage: 54%; Total: 20%; ETA: 0:03:23 .
    Progress: 466024 of 857600 done; Stage: 54%; Total: 20%; ETA: 0:03:23 ..
    Progress: 487937 of 857600 done; Stage: 56%; Total: 21%; ETA: 0:03:15 ...
    Progress: 515091 of 857600 done; Stage: 60%; Total: 22%; ETA: 0:03:02
    Progress: 518353 of 857600 done; Stage: 60%; Total: 22%; ETA: 0:03:02 .
    Progress: 525952 of 857600 done; Stage: 61%; Total: 23%; ETA: 0:03:00 ..
    Progress: 529451 of 857600 done; Stage: 61%; Total: 23%; ETA: 0:03:00 ...
    Progress: 530363 of 857600 done; Stage: 61%; Total: 23%; ETA: 0:03:00
    Progress: 532383 of 857600 done; Stage: 62%; Total: 23%; ETA: 0:03:00 .
    Progress: 533045 of 857600 done; Stage: 62%; Total: 23%; ETA: 0:03:02 ..
    Progress: 537095 of 857600 done; Stage: 62%; Total: 23%; ETA: 0:03:02 ...
    Progress: 541441 of 857600 done; Stage: 63%; Total: 24%; ETA: 0:03:02
    Progress: 542577 of 857600 done; Stage: 63%; Total: 24%; ETA: 0:03:02 .
    Progress: 543079 of 857600 done; Stage: 63%; Total: 24%; ETA: 0:03:04 ..
    Progress: 543559 of 857600 done; Stage: 63%; Total: 24%; ETA: 0:03:04 ...
    Progress: 544229 of 857600 done; Stage: 63%; Total: 24%; ETA: 0:03:05
    Progress: 544815 of 857600 done; Stage: 63%; Total: 24%; ETA: 0:03:07 .
    Progress: 547939 of 857600 done; Stage: 63%; Total: 24%; ETA: 0:03:07 ..
    Progress: 559689 of 857600 done; Stage: 65%; Total: 25%; ETA: 0:03:03 ...
    Progress: 567790 of 857600 done; Stage: 66%; Total: 25%; ETA: 0:03:02
    Progress: 590909 of 857600 done; Stage: 68%; Total: 26%; ETA: 0:02:54 .
    Progress: 600990 of 857600 done; Stage: 70%; Total: 26%; ETA: 0:02:51 ..
    Progress: 602835 of 857600 done; Stage: 70%; Total: 26%; ETA: 0:02:51 ...
    Progress: 604415 of 857600 done; Stage: 70%; Total: 26%; ETA: 0:02:52
    Progress: 607651 of 857600 done; Stage: 70%; Total: 27%; ETA: 0:02:52 .
    Progress: 611664 of 857600 done; Stage: 71%; Total: 27%; ETA: 0:02:52 ..
    Progress: 613633 of 857600 done; Stage: 71%; Total: 27%; ETA: 0:02:52 ...
    Progress: 615853 of 857600 done; Stage: 71%; Total: 27%; ETA: 0:02:52
    Progress: 618569 of 857600 done; Stage: 72%; Total: 27%; ETA: 0:02:52 .
    Progress: 620801 of 857600 done; Stage: 72%; Total: 27%; ETA: 0:02:54 ..
    Progress: 624071 of 857600 done; Stage: 72%; Total: 27%; ETA: 0:02:56 ...
    Progress: 628143 of 857600 done; Stage: 73%; Total: 27%; ETA: 0:02:56
    Progress: 629923 of 857600 done; Stage: 73%; Total: 27%; ETA: 0:02:56 .
    Progress: 631933 of 857600 done; Stage: 73%; Total: 27%; ETA: 0:02:56 ..
    Progress: 638721 of 857600 done; Stage: 74%; Total: 28%; ETA: 0:02:55 ...
    Progress: 652609 of 857600 done; Stage: 76%; Total: 28%; ETA: 0:02:51
    Progress: 657409 of 857600 done; Stage: 76%; Total: 28%; ETA: 0:02:52 .
    Progress: 683521 of 857600 done; Stage: 79%; Total: 29%; ETA: 0:02:46 ..
    Progress: 722833 of 857600 done; Stage: 84%; Total: 31%; ETA: 0:02:36 ...
    Progress: 746190 of 857600 done; Stage: 87%; Total: 32%; ETA: 0:02:31
    Progress: 768001 of 857600 done; Stage: 89%; Total: 33%; ETA: 0:02:27 .
    Progress: 784956 of 857600 done; Stage: 91%; Total: 33%; ETA: 0:02:22 ..
    Progress: 800777 of 857600 done; Stage: 93%; Total: 34%; ETA: 0:02:19 ...
    Progress: 851055 of 857600 done; Stage: 99%; Total: 36%; ETA: 0:02:09
    Progress: 857600 of 857600 done; Stage: 100%; Total: 36%; ETA: 0:02:09 .


    857600 file records processed.

    File verification completed.
     
  8. MoPman

    MoPman Private E-2

    Phase duration (File record verification): 1.21 minutes.
    Progress: 36436 of 36436 done; Stage: 100%; Total: 24%; ETA: 0:03:45 ..


    36436 large file records processed.

    Phase duration (Orphan file record recovery): 0.00 milliseconds.
    Progress: 0 of 0 done; Stage: 99%; Total: 24%; ETA: 0:03:45 ...


    0 bad file records processed.

    Phase duration (Bad file record checking): 0.06 milliseconds.

    Stage 2: Examining file name linkage ...
    Progress: 54998 of 1212470 done; Stage: 4%; Total: 26%; ETA: 0:03:31
    Progress: 134377 of 1212470 done; Stage: 11%; Total: 28%; ETA: 0:03:11 .
    Progress: 222639 of 1212470 done; Stage: 18%; Total: 30%; ETA: 0:02:52 ..
    Progress: 308248 of 1212470 done; Stage: 25%; Total: 32%; ETA: 0:02:36 ...
    Progress: 382798 of 1212470 done; Stage: 31%; Total: 34%; ETA: 0:02:23
    Progress: 475980 of 1212470 done; Stage: 39%; Total: 37%; ETA: 0:02:09 .
    Progress: 587108 of 1212470 done; Stage: 48%; Total: 40%; ETA: 0:01:55 ..
    Progress: 668551 of 1212470 done; Stage: 55%; Total: 42%; ETA: 0:01:45 ...
    Progress: 748728 of 1212470 done; Stage: 61%; Total: 44%; ETA: 0:01:37
    Progress: 1742 of 117330 done; Stage: 1%; Total: 48%; ETA: 0:01:26 .
    Progress: 117330 of 117330 done; Stage: 100%; Total: 52%; ETA: 0:01:13 ..


    117330 reparse records processed.

    Progress: 857663 of 1212470 done; Stage: 70%; Total: 52%; ETA: 0:01:13 ...
    Progress: 857835 of 1212470 done; Stage: 70%; Total: 52%; ETA: 0:01:13
    Progress: 857983 of 1212470 done; Stage: 70%; Total: 52%; ETA: 0:01:13 .
    Progress: 858228 of 1212470 done; Stage: 70%; Total: 52%; ETA: 0:01:13 ..
    Progress: 858442 of 1212470 done; Stage: 70%; Total: 52%; ETA: 0:01:13 ...
    Progress: 858620 of 1212470 done; Stage: 70%; Total: 52%; ETA: 0:01:13
    Progress: 858791 of 1212470 done; Stage: 70%; Total: 52%; ETA: 0:01:13 .
    Progress: 858997 of 1212470 done; Stage: 70%; Total: 52%; ETA: 0:01:13 ..
    Progress: 859100 of 1212470 done; Stage: 70%; Total: 53%; ETA: 0:01:13 ...
    Progress: 859177 of 1212470 done; Stage: 70%; Total: 53%; ETA: 0:01:13
    Progress: 859315 of 1212470 done; Stage: 70%; Total: 53%; ETA: 0:01:13 .
    Progress: 859618 of 1212470 done; Stage: 70%; Total: 54%; ETA: 0:01:13 ..
    Progress: 859766 of 1212470 done; Stage: 70%; Total: 54%; ETA: 0:01:13 ...
    Progress: 859921 of 1212470 done; Stage: 70%; Total: 54%; ETA: 0:01:13
    Progress: 860092 of 1212470 done; Stage: 70%; Total: 54%; ETA: 0:01:13 .
    Progress: 860212 of 1212470 done; Stage: 70%; Total: 54%; ETA: 0:01:13 ..
    Progress: 860343 of 1212470 done; Stage: 70%; Total: 54%; ETA: 0:01:13 ...
    Progress: 860406 of 1212470 done; Stage: 70%; Total: 54%; ETA: 0:01:13
    Progress: 860485 of 1212470 done; Stage: 70%; Total: 54%; ETA: 0:01:13 .
    Progress: 860640 of 1212470 done; Stage: 70%; Total: 54%; ETA: 0:01:13 ..
    Progress: 860723 of 1212470 done; Stage: 70%; Total: 55%; ETA: 0:01:13 ...
    Progress: 860987 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13
    Progress: 861086 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13 .
    Progress: 861223 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13 ..
    Progress: 861362 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13 ...
    Progress: 861532 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13
    Progress: 861763 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13 .
    Progress: 861985 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13 ..
    Progress: 862251 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13 ...
    Progress: 862445 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13
    Progress: 862581 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:13 .
    Progress: 862696 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:15 ..
    Progress: 862953 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:15 ...
    Progress: 863201 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:15
    Progress: 863321 of 1212470 done; Stage: 71%; Total: 55%; ETA: 0:01:15 .
    Progress: 863490 of 1212470 done; Stage: 71%; Total: 56%; ETA: 0:01:15 ..
    Progress: 863492 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:14 ...
    Progress: 863612 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08
    Progress: 863691 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08 .
    Progress: 863828 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08 ..
    Progress: 864011 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08 ...
    Progress: 864295 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08
    Progress: 864505 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08 .
    Progress: 864737 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08 ..
    Progress: 865009 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08 ...
    Progress: 865281 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08
    Progress: 865551 of 1212470 done; Stage: 71%; Total: 59%; ETA: 0:01:08 .
    Progress: 865889 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08 ..
    Progress: 866157 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08 ...
    Progress: 866303 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08
    Progress: 866546 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08 .
    Progress: 866629 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08 ..
    Progress: 866839 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08 ...
    Progress: 867126 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08
    Progress: 867365 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08 .
    Progress: 867580 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08 ..
    Progress: 867780 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08 ...
    Progress: 867859 of 1212470 done; Stage: 71%; Total: 60%; ETA: 0:01:08
    Progress: 867926 of 1212470 done; Stage: 71%; Total: 61%; ETA: 0:01:08 .
    Progress: 867992 of 1212470 done; Stage: 71%; Total: 61%; ETA: 0:01:08 ..
    Progress: 868143 of 1212470 done; Stage: 71%; Total: 61%; ETA: 0:01:08 ...
    Progress: 868276 of 1212470 done; Stage: 71%; Total: 61%; ETA: 0:01:08
    Progress: 868517 of 1212470 done; Stage: 71%; Total: 61%; ETA: 0:01:08 .
    Progress: 868869 of 1212470 done; Stage: 71%; Total: 61%; ETA: 0:01:08 ..
    Progress: 869043 of 1212470 done; Stage: 71%; Total: 61%; ETA: 0:01:08 ...
    Progress: 869277 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08
    Progress: 869453 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08 .
    Progress: 869775 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08 ..
    Progress: 870142 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08 ...
    Progress: 870741 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08
    Progress: 871059 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08 .
    Progress: 871257 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08 ..
    Progress: 871514 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08 ...
    Progress: 871879 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08
    Progress: 872167 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08 .
    Progress: 872530 of 1212470 done; Stage: 71%; Total: 62%; ETA: 0:01:08 ..
    Progress: 872883 of 1212470 done; Stage: 71%; Total: 63%; ETA: 0:01:08 ...
    Progress: 873097 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:08
    Progress: 873298 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:08 .
    Progress: 873655 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:08 ..
    Progress: 874077 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 ...
    Progress: 874959 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10
    Progress: 875510 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 .
    Progress: 875732 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 ..
    Progress: 876499 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 ...
    Progress: 877557 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10
    Progress: 878098 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 .
    Progress: 878823 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 ..
    Progress: 879328 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 ...
    Progress: 880051 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10
    Progress: 880224 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 .
    Progress: 880752 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 ..
    Progress: 881324 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:10 ...
    Progress: 881764 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:12
    Progress: 882185 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:12 .
    Progress: 882491 of 1212470 done; Stage: 72%; Total: 63%; ETA: 0:01:12 ..
    Progress: 883237 of 1212470 done; Stage: 72%; Total: 64%; ETA: 0:01:12 ...
    Progress: 883729 of 1212470 done; Stage: 72%; Total: 64%; ETA: 0:01:12
    Progress: 884195 of 1212470 done; Stage: 72%; Total: 64%; ETA: 0:01:12 .
    Progress: 884767 of 1212470 done; Stage: 72%; Total: 64%; ETA: 0:01:12 ..
    Progress: 885901 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12 ...
    Progress: 886753 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12
    Progress: 887078 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12 .
    Progress: 887444 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12 ..
    Progress: 888306 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12 ...
    Progress: 889599 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12
    Progress: 891010 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12 .
    Progress: 891803 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12 ..
    Progress: 892817 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12 ...
    Progress: 894463 of 1212470 done; Stage: 73%; Total: 64%; ETA: 0:01:12
    Progress: 896044 of 1212470 done; Stage: 73%; Total: 65%; ETA: 0:01:12 .
    Progress: 898134 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12 ..
    Progress: 899045 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12 ...
    Progress: 899657 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12
    Progress: 900371 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12 .
    Progress: 900997 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12 ..
    Progress: 902152 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12 ...
    Progress: 902613 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12
    Progress: 904949 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12 .
    Progress: 906049 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12 ..
    Progress: 906617 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12 ...
    Progress: 907377 of 1212470 done; Stage: 74%; Total: 65%; ETA: 0:01:12
    Progress: 907422 of 1212470 done; Stage: 74%; Total: 66%; ETA: 0:01:11 .
    Progress: 908119 of 1212470 done; Stage: 74%; Total: 66%; ETA: 0:01:11 ..
    Progress: 908397 of 1212470 done; Stage: 74%; Total: 66%; ETA: 0:01:11 ...
    Progress: 908778 of 1212470 done; Stage: 74%; Total: 66%; ETA: 0:01:11
    Progress: 908978 of 1212470 done; Stage: 74%; Total: 66%; ETA: 0:01:11 .
    Progress: 909391 of 1212470 done; Stage: 75%; Total: 68%; ETA: 0:01:11 ..
    Progress: 909975 of 1212470 done; Stage: 75%; Total: 68%; ETA: 0:01:08 ...
    Progress: 910522 of 1212470 done; Stage: 75%; Total: 68%; ETA: 0:01:08
    Progress: 911056 of 1212470 done; Stage: 75%; Total: 68%; ETA: 0:01:08 .
    Progress: 911863 of 1212470 done; Stage: 75%; Total: 68%; ETA: 0:01:08 ..
    Progress: 913231 of 1212470 done; Stage: 75%; Total: 68%; ETA: 0:01:08 ...
    Progress: 914731 of 1212470 done; Stage: 75%; Total: 68%; ETA: 0:01:08
    Progress: 914786 of 1212470 done; Stage: 75%; Total: 69%; ETA: 0:01:07 .
    Progress: 915983 of 1212470 done; Stage: 75%; Total: 69%; ETA: 0:01:07 ..
    Progress: 917029 of 1212470 done; Stage: 75%; Total: 69%; ETA: 0:01:07 ...
    Progress: 918125 of 1212470 done; Stage: 75%; Total: 69%; ETA: 0:01:07
    Progress: 919150 of 1212470 done; Stage: 75%; Total: 69%; ETA: 0:01:07 .
    Progress: 920018 of 1212470 done; Stage: 75%; Total: 69%; ETA: 0:01:07 ..
    Progress: 920721 of 1212470 done; Stage: 75%; Total: 72%; ETA: 0:01:06 ...
    Progress: 920918 of 1212470 done; Stage: 75%; Total: 73%; ETA: 0:00:57
    Progress: 921122 of 1212470 done; Stage: 75%; Total: 74%; ETA: 0:00:56 .
    Progress: 921392 of 1212470 done; Stage: 75%; Total: 74%; ETA: 0:00:52 ..
    Progress: 921935 of 1212470 done; Stage: 76%; Total: 74%; ETA: 0:00:52 ...
    Progress: 923633 of 1212470 done; Stage: 76%; Total: 74%; ETA: 0:00:52
    Progress: 925068 of 1212470 done; Stage: 76%; Total: 75%; ETA: 0:00:52 .
    Progress: 925675 of 1212470 done; Stage: 76%; Total: 75%; ETA: 0:00:52 ..
    Progress: 926555 of 1212470 done; Stage: 76%; Total: 75%; ETA: 0:00:52 ...
    Progress: 927606 of 1212470 done; Stage: 76%; Total: 75%; ETA: 0:00:52
    Progress: 927724 of 1212470 done; Stage: 76%; Total: 75%; ETA: 0:00:52 .
    Progress: 928577 of 1212470 done; Stage: 76%; Total: 75%; ETA: 0:00:52 ..
    Progress: 932262 of 1212470 done; Stage: 76%; Total: 75%; ETA: 0:00:52 ...
    Progress: 936237 of 1212470 done; Stage: 77%; Total: 75%; ETA: 0:00:52
    Progress: 937336 of 1212470 done; Stage: 77%; Total: 75%; ETA: 0:00:52 .
    Progress: 938060 of 1212470 done; Stage: 77%; Total: 75%; ETA: 0:00:52 ..
    Progress: 938880 of 1212470 done; Stage: 77%; Total: 75%; ETA: 0:00:52 ...
    Progress: 939371 of 1212470 done; Stage: 77%; Total: 75%; ETA: 0:00:52
    Progress: 939660 of 1212470 done; Stage: 77%; Total: 75%; ETA: 0:00:52 .
    Progress: 940194 of 1212470 done; Stage: 77%; Total: 75%; ETA: 0:00:52 ..
    Progress: 941355 of 1212470 done; Stage: 77%; Total: 75%; ETA: 0:00:52 ...
    Progress: 941485 of 1212470 done; Stage: 77%; Total: 75%; ETA: 0:00:52
    Progress: 941553 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 .
    Progress: 941632 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 ..
    Progress: 941729 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 ...
    Progress: 941925 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52
    Progress: 942339 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 .
    Progress: 942572 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 ..
    Progress: 942967 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 ...
    Progress: 943263 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52
    Progress: 943667 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 .
    Progress: 944019 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 ..
    Progress: 944336 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 ...
    Progress: 944644 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52
    Progress: 944830 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 .
    Progress: 945032 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 ..
    Progress: 945280 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52 ...
    Progress: 945482 of 1212470 done; Stage: 77%; Total: 76%; ETA: 0:00:52
    Progress: 945783 of 1212470 done; Stage: 78%; Total: 76%; ETA: 0:00:52 .
    Progress: 946079 of 1212470 done; Stage: 78%; Total: 76%; ETA: 0:00:52 ..
    Progress: 946546 of 1212470 done; Stage: 78%; Total: 76%; ETA: 0:00:52 ...
    Progress: 946833 of 1212470 done; Stage: 78%; Total: 76%; ETA: 0:00:52
    Progress: 947253 of 1212470 done; Stage: 78%; Total: 76%; ETA: 0:00:52 .
    Progress: 947850 of 1212470 done; Stage: 78%; Total: 76%; ETA: 0:00:52 ..
    Progress: 948397 of 1212470 done; Stage: 78%; Total: 76%; ETA: 0:00:52 ...
    Progress: 948884 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52
    Progress: 949239 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 .
    Progress: 949810 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 ..
    Progress: 950863 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 ...
    Progress: 951984 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52
    Progress: 952552 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 .
    Progress: 952922 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 ..
    Progress: 953080 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 ...
    Progress: 953295 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52
    Progress: 953788 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 .
    Progress: 954456 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 ..
    Progress: 955110 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 ...
    Progress: 955706 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52
    Progress: 956114 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 .
    Progress: 956885 of 1212470 done; Stage: 78%; Total: 77%; ETA: 0:00:52 ..
    Progress: 957869 of 1212470 done; Stage: 79%; Total: 77%; ETA: 0:00:52 ...
    Progress: 959290 of 1212470 done; Stage: 79%; Total: 78%; ETA: 0:00:52
    Progress: 960725 of 1212470 done; Stage: 79%; Total: 78%; ETA: 0:00:52 .
    Progress: 961288 of 1212470 done; Stage: 79%; Total: 78%; ETA: 0:00:52 ..
    Progress: 961825 of 1212470 done; Stage: 79%; Total: 78%; ETA: 0:00:52 ...
    Progress: 962602 of 1212470 done; Stage: 79%; Total: 78%; ETA: 0:00:52
    Progress: 963601 of 1212470 done; Stage: 79%; Total: 78%; ETA: 0:00:52 .
    Progress: 963914 of 1212470 done; Stage: 79%; Total: 78%; ETA: 0:00:52 ..
    Progress: 964237 of 1212470 done; Stage: 79%; Total: 78%; ETA: 0:00:52 ...
    Progress: 965691 of 1212470 done; Stage: 79%; Total: 77%; ETA: 0:00:54
    Progress: 966041 of 1212470 done; Stage: 79%; Total: 77%; ETA: 0:00:54 .
    Progress: 967022 of 1212470 done; Stage: 79%; Total: 77%; ETA: 0:00:54 ..
    Progress: 967793 of 1212470 done; Stage: 79%; Total: 77%; ETA: 0:00:54 ...
    Progress: 969191 of 1212470 done; Stage: 79%; Total: 77%; ETA: 0:00:54
    Progress: 973740 of 1212470 done; Stage: 80%; Total: 77%; ETA: 0:00:54 .
    Progress: 975000 of 1212470 done; Stage: 80%; Total: 77%; ETA: 0:00:54 ..
    Progress: 975939 of 1212470 done; Stage: 80%; Total: 78%; ETA: 0:00:54 ...
    Progress: 976826 of 1212470 done; Stage: 80%; Total: 78%; ETA: 0:00:54
    Progress: 977719 of 1212470 done; Stage: 80%; Total: 78%; ETA: 0:00:54 .
    Progress: 979254 of 1212470 done; Stage: 80%; Total: 78%; ETA: 0:00:54 ..
    Progress: 980203 of 1212470 done; Stage: 80%; Total: 78%; ETA: 0:00:54 ...
    Progress: 981436 of 1212470 done; Stage: 80%; Total: 78%; ETA: 0:00:54
    Progress: 981987 of 1212470 done; Stage: 80%; Total: 78%; ETA: 0:00:54 .
    Progress: 982189 of 1212470 done; Stage: 81%; Total: 79%; ETA: 0:00:52 ..
    Progress: 984155 of 1212470 done; Stage: 81%; Total: 79%; ETA: 0:00:52 ...
    Progress: 984871 of 1212470 done; Stage: 81%; Total: 79%; ETA: 0:00:52
    Progress: 986779 of 1212470 done; Stage: 81%; Total: 79%; ETA: 0:00:51 .
    Progress: 987516 of 1212470 done; Stage: 81%; Total: 79%; ETA: 0:00:51 ..
    Progress: 988316 of 1212470 done; Stage: 81%; Total: 79%; ETA: 0:00:51 ...
    Progress: 988795 of 1212470 done; Stage: 81%; Total: 79%; ETA: 0:00:51
    Progress: 989280 of 1212470 done; Stage: 81%; Total: 78%; ETA: 0:00:54 .
    Progress: 992277 of 1212470 done; Stage: 81%; Total: 78%; ETA: 0:00:54 ..
    Progress: 993954 of 1212470 done; Stage: 81%; Total: 78%; ETA: 0:00:54 ...
    Progress: 996182 of 1212470 done; Stage: 82%; Total: 78%; ETA: 0:00:54
    Progress: 1000943 of 1212470 done; Stage: 82%; Total: 79%; ETA: 0:00:54 .
    Progress: 1001165 of 1212470 done; Stage: 82%; Total: 79%; ETA: 0:00:54 ..
    Progress: 1001860 of 1212470 done; Stage: 82%; Total: 79%; ETA: 0:00:52 ...
    Progress: 1002560 of 1212470 done; Stage: 82%; Total: 79%; ETA: 0:00:52
    Progress: 1004428 of 1212470 done; Stage: 82%; Total: 79%; ETA: 0:00:52 .
    Progress: 1007136 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52 ..
    Progress: 1009407 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52 ...
    Progress: 1009692 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52
    Progress: 1010085 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52 .
    Progress: 1011052 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52 ..
    Progress: 1012048 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52 ...
    Progress: 1012895 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52
    Progress: 1014010 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52 .
    Progress: 1015674 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52 ..
    Progress: 1016766 of 1212470 done; Stage: 83%; Total: 79%; ETA: 0:00:52 ...
    Progress: 1017507 of 1212470 done; Stage: 83%; Total: 80%; ETA: 0:00:52
    Progress: 1018563 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:52 .
    Progress: 1019718 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:52 ..
    Progress: 1020768 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:52 ...
    Progress: 1022112 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:52
    Progress: 1023266 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:52 .
    Progress: 1024329 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:51 ..
    Progress: 1025297 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:51 ...
    Progress: 1025542 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:51
    Progress: 1025828 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:51 .
    Progress: 1026511 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:51 ..
    Progress: 1027152 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:51 ...
    Progress: 1028024 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:51
    Progress: 1028881 of 1212470 done; Stage: 84%; Total: 80%; ETA: 0:00:51 .
    Progress: 1029993 of 1212470 done; Stage: 84%; Total: 81%; ETA: 0:00:51 ..
    Progress: 1030907 of 1212470 done; Stage: 85%; Total: 81%; ETA: 0:00:51 ...
    Progress: 1031506 of 1212470 done; Stage: 85%; Total: 81%; ETA: 0:00:49
    Progress: 1032226 of 1212470 done; Stage: 85%; Total: 81%; ETA: 0:00:49 .
    Progress: 1032951 of 1212470 done; Stage: 85%; Total: 81%; ETA: 0:00:49 ..
    Progress: 1033599 of 1212470 done; Stage: 85%; Total: 81%; ETA: 0:00:49 ...
    Progress: 1212470 of 1212470 done; Stage: 100%; Total: 82%; ETA: 0:00:49


    1212470 index entries processed.

    Index verification completed.
    Phase duration (Index verification): 2.40 minutes.
    Progress: 1 of 0 done; Stage: 99%; Total: 82%; ETA: 0:00:49 .
    Progress: 0 of 0 done; Stage: 99%; Total: 82%; ETA: 0:00:49 ..


    0 unindexed files scanned.

    Phase duration (Orphan reconnection): 5.00 seconds.
    Progress: 0 of 0 done; Stage: 99%; Total: 82%; ETA: 0:00:49 ...


    0 unindexed files recovered to lost and found.

    Phase duration (Orphan recovery to lost and found): 0.03 milliseconds.
    Progress: 117330 of 117330 done; Stage: 100%; Total: 82%; ETA: 0:00:49


    117330 reparse records processed.

    Phase duration (Reparse point and Object ID verification): 265.57 milliseconds.

    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.
    Phase duration (Security descriptor verification): 210.83 milliseconds.
    Progress: 21 of 21 done; Stage: 100%; Total: 99%; ETA: 0:00:00 .


    177436 data files processed.

    Phase duration (Data attribute verification): 0.04 milliseconds.
    CHKDSK is verifying Usn Journal...
    Progress: 0 of 4370 done; Stage: 0%; Total: 99%; ETA: 0:00:00 ..
    Progress: 1396 of 4370 done; Stage: 31%; Total: 99%; ETA: 0:00:00 ...
    Progress: 4352 of 4370 done; Stage: 99%; Total: 97%; ETA: 0:00:06
    Progress: 4370 of 4370 done; Stage: 100%; Total: 97%; ETA: 0:00:06 .


    35805464 USN bytes processed.

    Usn Journal verification completed.
    Phase duration (USN journal verification): 647.64 milliseconds.

    Windows has scanned the file system and found no problems.
    No further action is required.

    975659007 KB total disk space.
    267350380 KB in 523440 files.
    389032 KB in 177437 indexes.
    0 KB in bad sectors.
    1020895 KB in use by the system.
    65536 KB occupied by the log file.
    706898700 KB available on disk.

    4096 bytes in each allocation unit.
    243914751 total allocation units on disk.
    176724675 allocation units available on disk.
    Total duration: 3.72 minutes (223230 ms).


    ========= End of CMD: =========


    ========= sfc /scannow =========



    Beginning system scan. This process will take some time.



    Beginning verification phase of system scan.


    Verification 0% complete.
    Verification 1% complete.
    Verification 1% complete.
    Verification 2% complete.
    Verification 2% complete.
    Verification 3% complete.
    Verification 3% complete.
    Verification 4% complete.
    Verification 4% complete.
    Verification 5% complete.
    Verification 5% complete.
    Verification 6% complete.
    Verification 6% complete.
    Verification 7% complete.
    Verification 8% complete.
    Verification 8% complete.
    Verification 9% complete.
    Verification 9% complete.
    Verification 10% complete.
    Verification 10% complete.
    Verification 11% complete.
    Verification 11% complete.
    Verification 12% complete.
    Verification 12% complete.
    Verification 13% complete.
    Verification 13% complete.
    Verification 14% complete.
    Verification 14% complete.
    Verification 15% complete.
    Verification 16% complete.
    Verification 16% complete.
    Verification 17% complete.
    Verification 17% complete.
    Verification 18% complete.
    Verification 18% complete.
    Verification 19% complete.
    Verification 19% complete.
    Verification 20% complete.
    Verification 20% complete.
    Verification 21% complete.
    Verification 21% complete.
    Verification 22% complete.
    Verification 22% complete.
    Verification 23% complete.
    Verification 24% complete.
    Verification 24% complete.
    Verification 25% complete.
    Verification 25% complete.
    Verification 26% complete.
    Verification 26% complete.
    Verification 27% complete.
    Verification 27% complete.
    Verification 28% complete.
    Verification 28% complete.
    Verification 29% complete.
    Verification 29% complete.
    Verification 30% complete.
    Verification 31% complete.
    Verification 31% complete.
    Verification 32% complete.
    Verification 32% complete.
    Verification 33% complete.
    Verification 33% complete.
    Verification 34% complete.
    Verification 34% complete.
    Verification 35% complete.
    Verification 35% complete.
    Verification 36% complete.
    Verification 36% complete.
    Verification 37% complete.
    Verification 37% complete.
    Verification 38% complete.
    Verification 39% complete.
    Verification 39% complete.
    Verification 40% complete.
    Verification 40% complete.
    Verification 41% complete.
    Verification 41% complete.
    Verification 42% complete.
    Verification 42% complete.
    Verification 43% complete.
    Verification 43% complete.
    Verification 44% complete.
    Verification 44% complete.
    Verification 45% complete.
    Verification 45% complete.
    Verification 46% complete.
    Verification 47% complete.
    Verification 47% complete.
    Verification 48% complete.
    Verification 48% complete.
    Verification 49% complete.
    Verification 49% complete.
    Verification 50% complete.
    Verification 50% complete.
    Verification 51% complete.
    Verification 51% complete.
    Verification 52% complete.
    Verification 52% complete.
    Verification 53% complete.
    Verification 53% complete.
    Verification 54% complete.
    Verification 55% complete.
    Verification 55% complete.
    Verification 56% complete.
    Verification 56% complete.
    Verification 57% complete.
    Verification 57% complete.
    Verification 58% complete.
    Verification 58% complete.
    Verification 59% complete.
    Verification 59% complete.
    Verification 60% complete.
    Verification 60% complete.
    Verification 61% complete.
    Verification 62% complete.
    Verification 62% complete.
    Verification 63% complete.
    Verification 63% complete.
    Verification 64% complete.
    Verification 64% complete.
    Verification 65% complete.
    Verification 65% complete.
    Verification 66% complete.
    Verification 66% complete.
    Verification 67% complete.
    Verification 67% complete.
    Verification 68% complete.
    Verification 68% complete.
    Verification 69% complete.
    Verification 70% complete.
    Verification 70% complete.
    Verification 71% complete.
    Verification 71% complete.
    Verification 72% complete.
    Verification 72% complete.
    Verification 73% complete.
    Verification 73% complete.
    Verification 74% complete.
    Verification 74% complete.
    Verification 75% complete.
    Verification 75% complete.
    Verification 76% complete.
    Verification 76% complete.
    Verification 77% complete.
    Verification 78% complete.
    Verification 78% complete.
    Verification 79% complete.
    Verification 79% complete.
    Verification 80% complete.
    Verification 80% complete.
    Verification 81% complete.
    Verification 81% complete.
    Verification 82% complete.
    Verification 82% complete.
    Verification 83% complete.
    Verification 83% complete.
    Verification 84% complete.
    Verification 84% complete.
    Verification 85% complete.
    Verification 86% complete.
    Verification 86% complete.
    Verification 87% complete.
    Verification 87% complete.
    Verification 88% complete.
    Verification 88% complete.
    Verification 89% complete.
    Verification 89% complete.
    Verification 90% complete.
    Verification 90% complete.
    Verification 91% complete.
    Verification 91% complete.
    Verification 92% complete.
    Verification 93% complete.
    Verification 93% complete.
    Verification 94% complete.
    Verification 94% complete.
    Verification 95% complete.
    Verification 95% complete.
    Verification 96% complete.
    Verification 96% complete.
    Verification 97% complete.
    Verification 97% complete.
    Verification 98% complete.
    Verification 98% complete.
    Verification 99% complete.
    Verification 99% complete.
    Verification 100% complete.


    Windows Resource Protection found corrupt files and successfully repaired them.

    For online repairs, details are included in the CBS log file located at

    windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline

    repairs, details are included in the log file provided by the /OFFLOGFILE flag.



    ========= End of CMD: =========


    ========= DISM /Online /Cleanup-Image /CheckHealth =========


    Deployment Image Servicing and Management tool
    Version: 10.0.19041.844

    Image Version: 10.0.19045.2965

    No component store corruption detected.
    The operation completed successfully.


    ========= End of CMD: =========


    =========== EmptyTemp: ==========

    FlushDNS => completed
    BITS transfer queue => 1572864 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 23373877 B
    Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
    Windows/system/drivers => 507448001 B
    Edge => 44239003 B
    Chrome => 974585483 B
    Firefox => 0 B
    Opera => 0 B

    Temp, IE cache, history, cookies, recent:
    Default => 0 B
    ProgramData => 0 B
    Public => 0 B
    systemprofile => 688516197 B
    systemprofile32 => 688516197 B
    LocalService => 688523623 B
    NetworkService => 1447194483 B
    Peter => 1793364842 B

    RecycleBin => 0 B
    EmptyTemp: => 6.4 GB temporary data Removed.

    ================================


    The system needed a reboot.

    ==== End of Fixlog 12:16:17 ====
     
  9. MoPman

    MoPman Private E-2

    Hi!

    Sorry that the fixlog copy/paste is truncated. I had to post it as two replies because a message popped up saying there was a 40,000 character limit to each post. The second post picks up exactly where the first leaves off.

    Just an FYI, Farbar seemed to freeze (not responding) several times during the clean-up of temporary files, sometimes for several minutes.

    Thank you for your help in this!
     

    Attached Files:

  10. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the detailed replies, they are helpful. And I also appreciate you going through the extra effort to break up the reports into separate posts as having the reports pasted rather than attached helps me in reviewing everything.

    It is not uncommon for FRST to grind through the Fixlist when there are quite a number of temporary files to remove (EmptyTemp: => 6.4 GB temporary data Removed).

    Some system files were repaired during the last step but I suspect that is not the cause for your issue.

    Before doing anything else can you tell me whether or not your system is performing differently?
     
  11. MoPman

    MoPman Private E-2

    Yes! Thank you!

    It's not perfect, but there is a marked improvement in loading times and general performance.

    I understand that the system is 5-6 years old and what that means overall, and especially with software updates continuing to push the envelope. But the system has also seen very light use, and looks pristine inside and out. I think all of these procedures have removed most of the "muck" that regular use and diligent upkeep would have avoided.

    That said, from pc startup to windows fully loading used to be an easy 5-8 minute process, but now is about 2 minutes...with an occasional hiccup, ie "something went wrong / system needs to restart." Similarly, once windows has loaded, double-clicking and starting a program has gone from total freezes or extremely long waits (as much as 5-10 minutes was typical) to loading what I've tried thus far (Chrome for the most part) with delays of less than 1 minute. I call that a great success.

    I suspect that further maintenance will have diminishing returns, unless there are some other simple things you might suggest I try. If I were to make a wild guess, I'd suspect that the rather weak graphics card that came with the system might be the culprit (Geforce GT720).

    What are your thoughts on buying Malwarebytes after this free trial ends? The professional version of SUPERAntiSpyware has certainly paid off over the past decade, imho. I'm not sure about RogueKiller, though, as it has already annoyed me with incessant popups and startling beeps asking me to upgrade.

    Thank you so much for your kind and professional assistance!
     
  12. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    You are quite welcome but I could do nothing without your assistance.

    There are some additional things we can look at and troubleshooting steps we can take. This may be a multi-step process since there are a variety of possible reasons for the slow performance. If you are up for it I certainly am as well. If not, no problem at all.

    First, there are 2 errors/crashes relate to your Realtek Ethernet Controller. I would like to uninstall/reinstall the software.

    I would like to see is if the boot time is shortened if you boot into Safe Mode, hopefully with Networking. It is very common for a delay in initially launching a browser but "delay" is a relative term. Try launching a program you know should launch fairly quickly in addition to testing the Internet/browser.

    ===================================================

    Reinstalling Network Adapter

    ----------

    • Press Windows Key + R at the same time
    • Type devmgmt.msc and press Enter
    • Expand the Network Adapter section by clicking + sign
    • Right click on Realtek Ethernet Controller Driver and select Uninstall, then OK
    • Click Action, then Scan for hardware changes
    • Allow the drivers to be reinstalled
    • Connect to your Network Adapter and re-enter any required information
    • Check your internet access
    ===================================================

    BootSafe by d7xTech

    --------------------

    • Download d7xTech BootSafe and save it to your Desktop
    • Unzip the folder onto your Desktop
    • In the BootSafe folder right click on BootSafe.exe and select Run as administrator
    • Select Safe Mode with Networking then click Restart Windows
    • Click Yes to restart
    • Upon restart select Yes to configure the next Windows restart into Normal Mode restart
    • Attempt to log into your Network, if you are able, and test the Internet performance along with another program
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
    • Realtek uninstall and reinstall?
    • Boot time
    • Results of testing Internet/browser and launching of program
     
  13. MoPman

    MoPman Private E-2

    Hello again!

    Uninstalling/reinstalling the Realtek Ethernet Control Driver didn't seem to have any effect. Upon clicking "Action" and then "Scan for Hardware Changes," it immediately re-added the Realtek Driver without any noticeable drivers being installed. I checked internet speeds using Ookla Speedtest both before and after doing this, and there was no real difference in speed.

    I followed your instructions exactly using BootSafe. The boot time coming back in Safe Mode with Networking was slightly slower, but less than a minute's difference. Once I was back in windows, there was no networking available. After a fresh restart in Normal Mode, both the boot time and networking appeared to be back to normal. As well, the delay in launching Chrome and other programs was about the same.

    I did three internet speedtests prior to doing all of this, and three again after completing the steps you gave me. The average download speed prior was 193 Mbps, and upload 155 Mbps. The average speeds after the steps were 197 Mbps and 171 Mbps, respectively.

    I should mention this...the room where this computer is located is at the very back of the house where there are no available ethernet ports. For this reason, I purchased an ASUS USB-AC68 USB 3.0 Wireless Adapter so that the computer would have internet access over wifi. The computer didn't come with any wifi hardware itself, so this little wifi antenna with unfolding arms is plugged into a USB 3.0 port on the back of the computer and it sits on top of the pc tower. My wired modem and routers have a maximum rated speeds of 500 and 200 Mbps, respectively.

    Could it be this peripheral that is causing the crashes or other problems? It came with a setup cd with its own set of drivers, and I don't recall having any issues in the initial installation. I also see it right above the Realtek Driver in the Network Adapter section.

    Sorry for any misunderstanding or hassle.
     
  14. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    The reinstallation of the Realtek drivers was intended to stop potention crashes. Yes, uninstall the USB drivers and reinstall.

    When you say booting into Normal Boot was back to "normal" does that mean it is still abnormally slow? If so, please complete the below.

    ===================================================

    Disabling Fast Startup

    --------------------
    • Click Start, type Power Options, then hit Enter
    • Click Choose what the power buttons do
    • Click Change settings that are currently unavailable
    • Uncheck Turn on fast startup (recommended)
    • Click Save changes
    • Close all windows and completely shut down your computer
    • Restart your computer and monitor the startup behavior
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
    • USB drivers reinstalled?
    • Boot time any faster?
     
  15. MoPman

    MoPman Private E-2

    Okay, I uninstalled the USB drivers and reinstalled, and everything seems to be working the same. I checked the ASUS website and they said that I had the most current drivers.

    "When you say booting into Normal Boot was back to "normal" does that mean it is still abnormally slow?"

    I should have been more clear. I meant back to the new "normal" in the sense that it's about five times faster than before we began these cleaning procedures. Sorry about the confusion.

    I went ahead and tried the Disabling Fast Startup option. Here's a breakdown of what it now (post-cleaning) does:

    From hitting the power button, I get the standard beep...followed by a black screen with the "ASUS - In Search of Incredible" title in the middle. This lasts about 25-30 seconds.
    This is usually followed by a blue screen (not BSOD) that states, "Please wait..." and this lasts about 10-15 seconds. Sometimes, though, that message will change to, "Something went wrong - System restarting," though it's been happening fewer times as we've proceeded.
    The I get the Windows wallpaper for my account login screen. After entering my password, I see the windows desktop almost immediately. But if I try to run or launch anything right away, it does nothing.
    I have to wait for the task tray items to all load before trying to do anything else in Windows.
    Here's what loads in the task tray in order with a rough estimate of how long each takes from the moment I see the desktop:

    1. Safely remove hardware and eject media (almost immediately)
    2. Automatically connects to my desired wifi network (within about 15 seconds)
    3. Nvidia control panel icon appears right after that
    4. Windows security and RogueKiller icons then appear almost simultaneously on the heels of Nvidia
    5. The SUPERAntiSpyware icon appears after about 25-30 seconds
    6. And finally, the Malwarebytes icon appears after a whopping 80 seconds

    That's all of them, and it is at that point that I can try to launch programs, typically Chrome or File explorer. They both still have a bit of a delay, though, once the task tray items are fully loaded. Chrome will make the entire screen turn white for about 15 seconds before loading my homepage. File Explorer will only show the circular "working" icon that moves with mouse for about 8 seconds before opening. After these delays, things seem to much more smoothly...but not quickly by any means. (still, I am quite pleased with the speed improvements you've helped me with. Everything would take much, much longer previously...or not work at all)

    As should be abundantly clear by now, I know very little about computers...lol

    But I was wondering, if because of location I'm only going to be using wifi to connect this pc to the internet, would it be ok to keep the Realtek PCIe Controller disabled? Wouldn't that avoid the crashes you mentioned earlier? AFAIK, ethernet and wlan can operate independently of each other.

    And just to recap, yes, the USB drivers have been reinstalled and seem to be working properly. And yes, the boot times (from both shutdown and restart) are significantly better than they were when I started this thread.

    Thanks again for all of your patience and kind assistance!
     
  16. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    For someone who claims to not know much about computer you are quite articulate in your descriptions.

    Regarding the Realtek PCIe Controller there were only 2 instances where this crashed the computer (detailed in the Minidump reports). Often times uninstall/reinstall resolves any corruption or conflict issues that may have caused it. For now I would just leave it as is unless you start to experience more BSOD events. If that happens Realtek may be causing it but that is not a guarantee. It would require further investigation.

    As you mentioned, this is a basic computer now about 6 years old. Though there is only so much we can expect out of it, it would be nice to try to get the most we can. There are 2 issues I am focusing on. One is the boot time and the other is the Something went wrong... error you have received.

    Please do these things. As it pertains to Autoruns I would recommend being aggressive in unchecking items at the start to see if there is noticeable improvement. Settings are easily adjustable after that by re-checking items and testing the effect on boot up time.

    ===================================================

    Disabling Autoruns Entries

    --------------------

    Autoruns Explained

    Many programs, when installed, create registry or file entries that instruct a program to launch at system startup whether or not that program is essential or advantageous to run in the background. By disabling the autorun feature we do not delete or otherwise prohibit the program from running, it is just that it does not automatically start regardless of whether or not you are going to use it. Think of it like a car. Sometime today you might want to use the car to go to the store. The car can be in one of two conditions before you decide. You can leave the car running all day long even though you may or may not use it (enabling autorun) or you can start the car when you are ready (disabling autorun then launching a program when needed). Either way the car will work for you it is just a matter of how ready it will be if/when it is time. Just as gas is wasted by leaving the car running, your computer resources are "wasted" because programs are running in the background that you may not be using.
    • Please download AutoRuns and save it to your desktop
    • Right click the autoruns.exe and select Run as administrator
    • After the program loads click File, Save..., and save the file on your Desktop using the default file name
    • Uncheck any items you do not need to launch at startup
    • If you are unsure about an entry you can Google it or check the startup in the BleepingComputer Startup List. You can also ask me about it
    • Reboot your computer and check the performance
    ===================================================

    FullEventLogView by Nirsoft

    --------------------

    • Download FullEventLogView by Nirsoft and save it to your Desktop
    • Right click on the folder, select Extract All... and extract the folder onto your Desktop
    • Open the fulleventlogview-x64 folder, right click on FullEventLogView (Application), then select Run as administrator
    • Monitor the lower left hand corner of the screen until the Loading... no longer appears and an item(s) total is listed
    • Click Edit, then Select All
    • Click File, then Save Selected Items
    • Save the file onto your Desktop as NirsoftEV.txt
    • Please zip and attach the file to your reply
    ===================================================

    System Summary Information

    --------------------

    • Press the Windows Key + R at the same time
    • Type msinfo32 and press Enter
    • Left click on System Summary
    • Click File, Save, and name the file Summary and save it to your Desktop
    • Please zip and attach the file to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
    • Autoruns results
    • Attached zip files
     
    TimW likes this.
  17. MoPman

    MoPman Private E-2

    Good Morning!

    I've tried and tried to download AutoRuns, but nothing happens. It is very similar to what occurred when I tried to download MGtools in the initial cleaning procedure.

    I'm attaching the FullEventLogView zip as directed, as well as the System Summary Information.

    Thanks again!

    Edit: The zip file for NirsoftEV.txt was too large to attach (6.7mb), so I've attached it as a .Rar file type instead (1.7mb). I hope that's ok.
     

    Attached Files:

  18. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    Are you using Chrome to download Autoruns? If so, please try using Microsoft Edge or another browser. Let me know what happens.
     
  19. MoPman

    MoPman Private E-2

    Hello again!

    Sorry for the delay.

    I was using Chrome to try to download it. I tried and Edge and had the same issue, but at least it had a popup saying it was blocking the download because it could potentially be malicious software. Realizing what was causing the problem, I remembered how to disable the same type of security feature on Chrome. I did so and was able to download and install Autoruns.

    I've run it as instructed and am attaching the file. I don't recognize the file type, as well as it said the file was too large to attach here...so I attached it as a zip file.

    I also went through and deselected all the autoruns on startup that I felt fairly sure I didn't need, or that I thought could be loaded when and if I should choose to run that particular program.

    Then I restarted the computer and watched for any changes. Everything appeared to be the same...except all items in the task tray were loaded about 30 seconds faster than previously.

    If you'd be so kind as to take a look at the results of the Autoruns results, I'd greatly appreciate and will feel reassured. LOL

    Thank you so much!
     

    Attached Files:

  20. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for your detective work. I was trying to test to see if Avira Extensions were blocking the programs but it appears it may be a different setting(s). I was attempting to pinpoint the issue but your workaround is good for now.

    Security programs provide roadblocks to prevent malicious software from being downloaded. Sometimes there are known, specific files that are in the database to identify and stop threats. The programs are also designed to look for malicious type characteristics or intrusive abilities and when they are spotted they throw up a generic red flag. The problem is they sometimes can't distinguish between good or bad intrusiveness. Programs like FRST64.exe and Autoruns are usually Whitelisted but in your case they are not. We may want to follow-up on that at some point.

    We are going to scale back on the autostart entries to see if it makes a difference. If it does then we will troubleshoot which one(s) is causing the problem.

    In the Autoruns screen select the Logon tab
    Deselect the below, restart your system and see if there is a difference.

    SuperAntiSpyware
    World of Tanks
    Application Restart #3 ASUS GIFTBOX
    Google Chrome Google Chrome Installer
    Microsoft Edge Microsoft Edge Installer
    Dropbox
    n/a Microsoft .NET IE SECURITY REGISTRATION

    Reboot and check the computer performance.
     
  21. MoPman

    MoPman Private E-2

    Hello again!

    I am so, so sorry for not replying sooner. All of this maintenance and realizing how old the system was put me in mind to just buy a new system. So I went out and bought a new laptop to use as a backup. After playing around with the new toy, and getting everything set up the way I like it...I realized that I'd forgotten to reply to your latest helpful advice.

    I did as you mentioned above, and have tried several reboots. The reboot/restart is about the same (improved) speed, but Windows and especially Chrome are loading faster. Windows task tray is fully loaded (minus SuperAntiSpyware) within a minute, and the white screen before Chrome loads the initial page takes just a few seconds. Thank you so much!

    I really, really appreciate your help, time, and especially your patience in assisting me with all of this.

    I'm attaching the most recent Autoruns log.
     

    Attached Files:

  22. Oh My!

    Oh My! Malware Expert Staff Member

    You are quite welcome and no problem on the delay.

    If you are satisfied with the performance of the old computer we might do well to leave things as they are.

    Are there any remaining questions or concerns you might have before I post some tool/log clean up instructions and other information for you to consider going forward?
     
  23. MoPman

    MoPman Private E-2

    Hi!

    No, I think I'm all good on my end.

    Thanks again for all you've done!
     
  24. Oh My!

    Oh My! Malware Expert Staff Member

    You are quite welcome.

    Here is our final step and some additional information to consider.

    ===================================================

    KpRm by Kernel-panik

    --------------
    • Download KpRm and save it to your Desktop (see here if you must use Chrome)
    • Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
    • Right click on the icon and select Run as administrator
    • Click Yes on the Disclaimer
    • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
    • Click Run
    • Click OK on All operations are completed
    • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
    • You are free to remove any other tools/reports still remaining
    ===================================================

    All Clean!

    --------------

    Your computer is now clean. Please consider this going forward.

    ===================================================

    Please take the time to read below on how to secure the machine and take the necessary steps to keep it clean.

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds