Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

It's been too long - general cleanup and service [Solved]


  • This topic is locked This topic is locked

#1
daveBB

daveBB

    Member

  • Member
  • PipPip
  • 63 posts

Hi All,

Several years ago you lot helped me out very kindly and so I wandered back here again.

Fortunately not in desperate need of help but I want to 'service' my laptop after having used it thouroughly for several years.

I use AVG anti-virus (free) and it gives me pop ups quite frequently about being traced and stuff like that. I believe that to be at least partially true but also a way of trying to sell me a payed version.

 

So I am not in a hurry but would love some help cleaning unneeded stuff out.

Also some advice on the best Anti-Virus software would be apreciated but only necessary in the end of the journey I just started.

 

Many thanks in advance

 

Dave

 

 

FRST - Log:

 

Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 19-06-2023
Gestart door info (Beheerder) op LAPTOP-QBAAO188 (ASUSTeK COMPUTER INC. VivoBook_ASUSLaptop X430FA_S430FA) (19-06-2023 16:31:01)
Gestart vanaf C:\Users\info\Desktop\FRST-OlderVersion\FRST64.exe
Geladen Profielen: info
Platform: Microsoft Windows 11 Home Versie 22H2 22621.1848 (X64) Taal: Nederlands (Nederland)
Standaardbrowser: Chrome
Boot Modus: Normal
 
==================== Processen (gefilterd) =================
 
(Als een item is opgenomen in de fixlist, zal het proces worden gesloten. Het bestand zal niet worden verplaatst.)
 
(ASUSTek Computer Inc. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\ATKOSD2.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe <4>
(C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe ->) (ASUSTek Computer Inc. -> ASUSTeK COMPUTER INC.) C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBox.Agent.exe
(C:\Program Files\AVG\Antivirus\AVGSvc.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe
(C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.16327.20248.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.EXE ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.16327.20248.0_x86__8wekyb3d8bbwe\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\ai.exe
(C:\Program Files\WindowsApps\MicrosoftTeams_23119.303.2080.2726_x64__8wekyb3d8bbwe\msteams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\114.0.1823.51\msedgewebview2.exe <12>
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSoftwareManager\AsusSoftwareManager.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSoftwareManager\AsusSoftwareManagerAgent.exe
(DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsLdrSrv64.exe ->) (ASUSTek Computer Inc. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsMonStartupTask64.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxEM.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <17>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.16327.20248.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.EXE
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.272\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.272\GoogleCrashHandler64.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\info\AppData\Local\Microsoft\OneDrive\23.114.0530.0001\Microsoft.SharePoint.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSLinkRemote\AsusLinkRemote.exe
(services.exe ->) (ASUSTek Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\AsusAppService\AsusAppService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSLinkNear\AsusLinkNear.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\AsusOptimization\AsusOptimization.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSoftwareManager\AsusSoftwareManager.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSwitch\AsusSwitch.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSystemAnalysis\AsusSystemAnalysis.exe
(services.exe ->) (ASUSTek Computer Inc. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsHidSrv64.exe
(services.exe ->) (ASUSTek Computer Inc. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsLdrSrv64.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\avgToolsSvc.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ELANFPService.exe
(services.exe ->) (ICEpower a/s -> ICEpower A/S) C:\Windows\System32\DriverStore\FileRepository\icesoundapo64.inf_amd64_db704b106aae3892\ICEsoundService64.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\jhi_service.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_54b736e5be5b50b2\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e9b40d45ab4dc6b8\IntelCpHDCPSvc.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e9b40d45ab4dc6b8\IntelCpHeciSvc.exe
(services.exe ->) (Intel® Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_a2fcfdfc3497e17c\RstMwService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSystemDiagnosis\AsusSystemDiagnosis.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Intel) C:\Windows\System32\cAVS\Intel® Audio Service\IntelAudioService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(sihost.exe ->) (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTek Computer Inc.) C:\Program Files\WindowsApps\B9ECED6F.ASUSKeyboardHotkeys_1.0.12.0_x86__qmba6cd70vzyy\ATK Package\HControl.exe
(sihost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2322.2.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\SpotifyWidgetProvider.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.16327.20248.0_x86__8wekyb3d8bbwe\Office16\SDXHelperBgt.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.3261.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.3261.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftTeams_23119.303.2080.2726_x64__8wekyb3d8bbwe\msteamsupdate.exe <2>
(svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.11600.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
 
==================== Register (gefilterd) ===================
 
(Als een item is opgenomen in de fixlist, zal het registeritem worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)
 
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [256952 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Zwift] => C:\Program Files (x86)\Zwift\ZwiftLauncher.exe [18038304 2023-03-16] (Zwift, Inc. -> Zwift, Inc)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [278440 2019-12-05] (Canon Inc. -> CANON INC.)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restrictie <==== AANDACHT
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restrictie <==== AANDACHT
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\Run: [Zoom] => [X]
HKLM\...\Windows x64\Print Processors\Canon TS3400 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDGF.DLL [525824 2021-09-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS3400 series: C:\WINDOWS\system32\CNMLMGF.DLL [962560 2021-09-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\114.0.5735.134\Installer\chrmstp.exe [2023-06-16] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] -> 
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restrictie <==== AANDACHT
HKLM\SOFTWARE\Policies\Google: Restrictie <==== AANDACHT
 
==================== Geplande Taken (gefilterd) =================
 
(Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)
 
Task: {00744A9E-E92C-47F4-8259-D94A8B3D6084} - System32\Tasks\MyASUS Update Messenger => C:\Users\info\AppData\Local\MyASUS Update Messenger\UpdateMessenger.exe [13859888 2021-02-22] (SweetLabs Inc. -> SweetLabs, Inc)
Task: {10BF01BC-42BA-401E-AC23-45DE3FE39E61} - System32\Tasks\RtkAudUService64_BG => C:\Windows\system32\RtkAudUService64.exe [874184 2020-12-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {1A75CD0A-6F99-4012-8144-016738526CF6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-07] (Google Inc -> Google LLC)
Task: {22D0360A-F612-456A-852D-853E1D46E5A0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-07] (Google Inc -> Google LLC)
Task: {267A5359-8F4F-4207-8392-DAC5D6A5A71B} - System32\Tasks\ASUS Hello => C:\Program Files (x86)\ASUS\ASUS Hello\ASUSHelloBG.exe [609592 2018-07-11] (ASUSTek Computer Inc. -> )
Task: {3C2D0044-0DF3-4B8F-9CD7-C428A88A6B4F} - System32\Tasks\ASUS Update Checker 2.0 => C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSoftwareManager\AsusUpdateChecker.exe [797832 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
Task: {6A981D5A-530A-4167-86F7-883253442715} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe  Display (Geen bestand)
Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe  RebootDialog (Geen bestand)
Task: {73C8F0B6-F299-4271-82F2-2770A9FB54B6} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2172344 2023-04-13] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {771370F6-1948-4F56-88E1-B595220D33F7} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [4922296 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Task: {A5BB7AA7-376B-446B-8329-8F4EE11C02C5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564152 2023-04-03] (Adobe Inc. -> Adobe Inc.)
Task: {B255D67A-16DB-470B-A090-877FEF048EF5} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery Reboot (Geen bestand)
Task: {C1EF45A1-44D2-48F3-862D-DCB5FA3AA96A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe  Display (Geen bestand)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (Geen bestand)
Task: {DD42B29C-7F91-4510-9DA7-1A63F55A159D} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC Reboot (Geen bestand)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (Geen bestand)
Task: {F677D99A-6D44-43AD-9E94-28D5FB5337F7} - System32\Tasks\AsusSystemAnalysis_754F3273-0563-4F20-B12F-826510B07474 => C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSystemAnalysis\AsusSystemAnalysis.exe [3697760 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
Task: {FBE9C792-71B0-4E4F-AD1C-90853357C53D} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\WINDOWS\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsHotkeyExec64.exe [176064 2019-03-04] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
 
(Als een item is opgenomen in de fixlist, wordt de taak (job) bestand verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.)
 
 
==================== Internet (gefilterd) ====================
 
(Als een item is opgenomen in de fixlist en een registeritem is, wordt het verwijderd of hersteld naar de standaard.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{35fe1c02-7b75-4a5a-9d5d-ca0f7b63d258}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{ae8c850e-d435-4025-b5d4-a77d43bf0440}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{e74f76e7-cafb-4d86-8bd0-43fc384d236e}: [DhcpNameServer] 40.53.1.12
 
Edge: 
=======
DownloadDir: C:\Users\info\Downloads
Edge Extension: (Geen Naam) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [niet gevonden]
Edge Extension: (Geen Naam) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [niet gevonden]
Edge Extension: (Geen Naam) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [niet gevonden]
Edge Extension: (Geen Naam) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [niet gevonden]
Edge Profile: C:\Users\info\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-09]
Edge DownloadDir: Default -> C:\Users\info\Downloads
 
FireFox:
========
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-05-04] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\info\AppData\Local\Google\Chrome\User Data\Guest Profile [2023-04-17]
CHR Profile: C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1 [2023-06-19]
CHR Notifications: Profile 1 -> hxxps://calendar.google.com; hxxps://www.letour.fr; hxxps://yaktribe.games; hxxps://zwiftinsider.com
CHR Extension: (Honey: automatische bonnen en beloningen) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2023-06-16]
CHR Extension: (Adblock Plus - gratis adblocker) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2023-06-17]
CHR Extension: (Elevate for Strava) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhiaggccakkgdfcadnklkbljcgicpckn [2022-05-26]
CHR Extension: (Offline Documenten) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-05-18]
CHR Extension: (AVG SafePrice | prijsvergelijking, aanbiedingen, waardebonnen) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2023-04-22]
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-04-13]
CHR Profile: C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 2 [2023-04-17]
CHR Extension: (Offline Documenten) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-04-16]
CHR Extension: (AVG SafePrice | prijsvergelijking, aanbiedingen, waardebonnen) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2023-04-16]
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-04-16]
CHR Profile: C:\Users\info\AppData\Local\Google\Chrome\User Data\System Profile [2023-04-17]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]
 
==================== Services (gefilterd) ===================
 
(Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.)
R2 AsHidService; C:\WINDOWS\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsHidSrv64.exe [173504 2019-03-04] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
R2 ASLDRService; C:\WINDOWS\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsLdrSrv64.exe [227776 2019-03-04] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
R2 AsusAppService; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\AsusAppService\AsusAppService.exe [1159304 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSLinkNear; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSLinkNear\AsusLinkNear.exe [1335392 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
R2 ASUSLinkRemote; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSLinkRemote\AsusLinkRemote.exe [764552 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​)
R2 ASUSLiveUpdateAgent; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSoftwareManager\AsusSoftwareManager.exe [1091720 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSOptimization; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\AsusOptimization\AsusOptimization.exe [197328 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSSwitch; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSwitch\AsusSwitch.exe [635488 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSSystemAnalysis; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSystemAnalysis\AsusSystemAnalysis.exe [3697760 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSSystemDiagnosis; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSystemDiagnosis\AsusSystemDiagnosis.exe [526256 2023-03-26] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek COMPUTER INC.)
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [619448 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AVG Tools; C:\Program Files\AVG\Antivirus\avgToolsSvc.exe [620472 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [8851384 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AvgWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [109480 2021-05-31] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 GiftBox.Service; C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe [299320 2019-04-09] (ASUSTek Computer Inc. -> ASUSTeK Computer Inc.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [445432 2021-04-19] (Canon Inc. -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [2909208 2022-05-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [128376 2022-05-07] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (gefilterd) ===================
 
(Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)
 
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R3 AsusPTPDrv; C:\WINDOWS\System32\DriverStore\FileRepository\asusptpfilter.inf_amd64_314b5cb6bf57f471\AsusPTPFilter.sys [116712 2021-12-02] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
R3 AsusSAIO; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSystemAnalysis\AsusSAIO.sys [46736 2023-03-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R1 ATKWMIACPIIO; C:\WINDOWS\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\atkwmiacpi64.sys [36368 2019-03-04] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
R0 avgArDisk; C:\WINDOWS\System32\drivers\avgArDisk.sys [31408 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [236440 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [392360 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [297872 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [96464 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [25064 2022-10-14] (Microsoft Windows Early Launch Anti-malware Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [39640 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [271544 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [556104 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [105240 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [80408 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [943448 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [703792 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [212672 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [319552 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [106496 2022-05-07] (Microsoft Corporation) [Bestand niet getekend]
S3 CMUSBDAC; C:\WINDOWS\system32\DRIVERS\CMUSBDAC.sys [3819744 2018-07-24] (WDKTestCert cm359,131641702659254692 -> C-MEDIA)
R3 libusb0; C:\WINDOWS\system32\DRIVERS\libusb0.sys [44480 2019-10-10] (Akeo Consulting -> hxxp://libusb-win32.sourceforge.net)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [48536 2022-05-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [438544 2022-05-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [90384 2022-05-07] (Microsoft Windows -> Microsoft Corporation)
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
 
==================== NetSvcs (gefilterd) ===================
 
(Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)
 
 
==================== Een maand (aangemaakt) (gefilterd) =========
 
(Als een item is opgenomen in de fixlist, wordt de map of het bestand verplaatst.)
 
2023-06-19 16:25 - 2023-06-19 16:31 - 000000000 ____D C:\Users\info\Desktop\FRST-OlderVersion
2023-06-19 16:25 - 2023-06-19 16:31 - 000000000 ____D C:\FRST
2023-06-16 07:11 - 2023-06-16 07:11 - 000804920 _____ C:\WINDOWS\system32\perfh013.dat
2023-06-16 07:11 - 2023-06-16 07:11 - 000160452 _____ C:\WINDOWS\system32\perfc013.dat
2023-06-14 08:43 - 2023-06-14 08:43 - 000000000 ___HD C:\$WinREAgent
2023-06-08 22:43 - 2023-06-08 22:43 - 000313272 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2023-06-05 14:09 - 2023-06-05 14:09 - 000545088 _____ C:\Users\info\Downloads\114342778.pdf
2023-05-26 20:40 - 2023-05-26 20:40 - 000446420 _____ C:\Users\info\Downloads\Polisvoorwaarden Ruime Keuze.pdf
2023-05-26 20:38 - 2023-05-26 20:38 - 000411873 _____ C:\Users\info\Downloads\Polisvoorwaarden Aanvullende Verzekeringen Optimaal.pdf
2023-05-24 09:25 - 2023-05-24 09:25 - 000423307 _____ C:\Users\info\Downloads\FA008237.pdf
 
==================== Een maand (gewijzigd) ==================
 
(Als een item is opgenomen in de fixlist, wordt de map of het bestand verplaatst.)
 
2023-06-19 16:16 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-06-19 16:10 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-06-19 16:10 - 2019-08-07 14:12 - 000000000 ____D C:\Program Files (x86)\Google
2023-06-19 15:34 - 2022-09-28 13:30 - 000003750 _____ C:\WINDOWS\system32\Tasks\AsusSystemAnalysis_754F3273-0563-4F20-B12F-826510B07474
2023-06-19 15:32 - 2022-09-28 13:25 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-06-19 07:18 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-06-18 07:37 - 2022-09-28 13:30 - 000003658 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-06-18 07:37 - 2022-09-28 13:30 - 000003504 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-06-18 07:37 - 2022-09-28 13:30 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2023-06-18 07:37 - 2022-09-28 13:30 - 000003434 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-06-18 07:37 - 2022-09-28 13:30 - 000003280 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2023-06-18 07:37 - 2022-09-28 13:30 - 000003250 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update
2023-06-18 07:37 - 2022-09-28 13:30 - 000003114 _____ C:\WINDOWS\system32\Tasks\ASUS Update Checker 2.0
2023-06-18 07:37 - 2022-09-28 13:30 - 000003062 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2140152316-3761713159-350972558-1001
2023-06-18 07:37 - 2022-09-28 13:30 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2140152316-3761713159-350972558-1001
2023-06-18 07:37 - 2022-09-28 13:30 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2023-06-17 06:28 - 2022-05-07 07:24 - 000000000 ___HD C:\Program Files\WindowsApps
2023-06-17 06:28 - 2021-04-16 23:50 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-06-16 17:51 - 2021-01-15 12:03 - 000000000 ____D C:\Users\info\AppData\Local\D3DSCache
2023-06-16 17:43 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2023-06-16 07:11 - 2022-09-28 13:29 - 001803066 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-06-16 07:11 - 2022-05-07 07:22 - 000000000 ____D C:\WINDOWS\INF
2023-06-16 07:06 - 2019-08-07 12:27 - 000000000 __SHD C:\Users\info\IntelGraphicsProfiles
2023-06-16 07:05 - 2022-09-28 13:30 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-06-16 07:05 - 2022-09-28 13:25 - 000302192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-06-16 07:05 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ServiceState
2023-06-16 07:05 - 2022-05-07 07:17 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2023-06-16 07:05 - 2020-09-30 21:59 - 000012288 ___SH C:\DumpStack.log.tmp
2023-06-16 07:05 - 2019-08-11 12:46 - 000000000 ____D C:\ProgramData\AVG
2023-06-16 07:05 - 2018-12-21 07:26 - 000000000 ___HD C:\Intel
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\WUModels
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\UUS
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemResources
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Dism
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ShellExperiences
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-06-16 07:04 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\servicing
2023-06-16 04:50 - 2019-08-07 14:14 - 000002323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-06-15 14:20 - 2020-09-30 22:00 - 000002380 _____ C:\Users\info\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-06-14 08:49 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-06-14 08:46 - 2022-09-28 13:26 - 003211776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2023-06-14 08:30 - 2021-02-09 20:30 - 000000000 ____D C:\Users\info\AppData\Local\MyASUS Update Messenger
2023-06-14 08:07 - 2019-08-11 12:21 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-06-14 08:05 - 2019-08-11 12:21 - 170078616 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-06-14 04:51 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2023-06-09 17:38 - 2021-06-30 15:38 - 000000000 ____D C:\ProgramData\CanonIJPLM
2023-06-08 22:43 - 2022-05-07 07:24 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-06-08 22:43 - 2020-10-23 15:05 - 000271544 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2023-06-08 22:43 - 2020-06-16 16:46 - 000556104 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgNetHub.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000943448 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000703792 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000392360 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdriver.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000319552 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000297872 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsh.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000236440 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000105240 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000096464 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniv.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000080408 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000039640 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgKbd.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000031408 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArDisk.sys
2023-06-08 17:45 - 2019-08-07 12:27 - 000000000 ____D C:\Users\info\AppData\Local\Packages
2023-06-01 19:22 - 2021-06-08 23:14 - 000000000 ____D C:\Users\info\Documents\Documenten
2023-05-26 22:40 - 2021-04-12 20:55 - 000000000 ____D C:\Program Files (x86)\Steam
 
==================== SigCheck ============================
 
(Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.)
 
==================== Einde van FRST.txt ========================
 
 
 
 
ADDITION - Log:
 
 
Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie: 19-06-2023
Gestart door info (19-06-2023 16:31:59)
Gestart vanaf C:\Users\info\Desktop\FRST-OlderVersion
Microsoft Windows 11 Home Versie 22H2 22621.1848 (X64) (2022-09-28 11:30:43)
Boot Modus: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(Als een item is opgenomen in de fixlist, zal het worden verwijderd.)
 
Administrator (S-1-5-21-2140152316-3761713159-350972558-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2140152316-3761713159-350972558-503 - Limited - Disabled)
Gast (S-1-5-21-2140152316-3761713159-350972558-501 - Limited - Disabled)
info (S-1-5-21-2140152316-3761713159-350972558-1001 - Administrator - Enabled) => C:\Users\info
WDAGUtilityAccount (S-1-5-21-2140152316-3761713159-350972558-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(Als een item is opgenomen in de fixlist, zal het worden verwijderd.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F4A6BD41-306E-5B9F-464B-23E1AE81F649}
 
==================== Geïnstalleerde programma's ======================
 
(Alleen de adware-programma's met 'verborgen' vlag kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeïnstalleerd worden.)
 
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1043-1033-7760-BC15014EA700}) (Version: 23.001.20174 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601047}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
ASUS GiftBox Service (HKLM-x32\...\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B}) (Version: 3.2.5.0 - ASUSTeK COMPUTER INC.)
ASUS Hello (HKLM-x32\...\{D8CE1923-92A9-4036-817E-9E0D8AA2169B}) (Version: 1.1.10.0 - ASUSTeK COMPUTER INC.)
AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.8.4 - ICEpower a/s)
AVG AntiVirus Free (HKLM\...\AVG Antivirus) (Version: 23.5.3286 - AVG Technologies)
Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.15.2 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.61.1.10 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.6.0.2 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.4.0 - Canon Inc.)
Canon TS3400 series Driver (HKLM\...\{1199FAD5-9546-44F3-81CF-FFDB8040B7BF}_Canon_TS3400_series) (Version: 1.02 - Canon Inc.)
Elevate 7.0.0-beta.5 (HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\6548da05-a4bc-57ed-8c01-06101fc8d1df) (Version: 7.0.0-beta.5 - Thomas Champagne)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 114.0.5735.134 - Google LLC)
Intel® Serial IO (HKLM\...\{72759DFB-9080-46A5-ACCF-5BA26A6FF3FD}) (Version: 30.100.1727.1 - Intel Corporation) Hidden
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1727.1 - Intel Corporation)
Intel® Optane™ Pinning Explorer Extensions (HKLM\...\{88667F43-B63E-4046-AF02-35E5412B8FAF}) (Version: 16.5.1.1030 - Intel Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 114.0.1823.51 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 114.0.1823.51 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\OneDriveSetup.exe) (Version: 23.114.0530.0001 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\Teams) (Version: 1.4.00.8872 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{43D501A5-E5E3-46EC-8F33-9E15D2A2CBD5}) (Version: 5.70.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.31.31103 (HKLM-x32\...\{2aaf1df0-eb13-4099-9992-962bb4e596d1}) (Version: 14.31.31103.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29334 (HKLM-x32\...\{14C49FC8-3E9B-4F29-8526-26629B5CF30B}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29334 (HKLM-x32\...\{0D01A812-82A1-481F-8546-8E28E976F8DF}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.31.31103 (HKLM\...\{A977984B-9244-49E3-BD24-43F0A8009667}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.31.31103 (HKLM\...\{A181A302-3F6D-4BAD-97A8-A426A6499D78}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Paradox Launcher v2 (HKLM\...\{986898D9-7C26-4E7F-814C-9B5472FA3209}) (Version: 2.0.0.0 - Paradox Interactive)
Printerregistratie (HKLM-x32\...\Canon EISRegistration) (Version: 1.9.0 - Canon Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{3BAE4496-6F6C-4330-A8AA-B93D3D346FA5}) (Version: 2.53.0.0 - Microsoft Corporation)
Windows Pc-statuscontrole (HKLM\...\{D1F16371-7951-41EB-A367-507D779F1E64}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Windows-stuurprogrammapakket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Zwift Activity Monitor 1.2.5 (HKLM-x32\...\Zwift Activity Monitor) (Version: 1.2.5 - Kevin Ruff p/b EnJoy Fitness)
Zwift version 1.1.6 (HKLM-x32\...\{E4DA422A-82AB-44A4-B3A5-0AF60F47B7AB}_is1) (Version: 1.1.6 - Zwift, LLC)
 
Packages:
=========
ASUS GIFTBOX -> C:\Program Files\WindowsApps\B9ECED6F.ASUSGIFTBOX_3.2.4.0_x64__qmba6cd70vzyy [2022-09-29] (ASUSTeK COMPUTER INC.)
ASUS Keyboard Hotkeys -> C:\Program Files\WindowsApps\B9ECED6F.ASUSKeyboardHotkeys_1.0.12.0_x86__qmba6cd70vzyy [2019-09-18] (ASUSTeK COMPUTER INC.) [Startup Task]
Audiotonic Pro -> C:\Program Files\WindowsApps\BluskySoftwareInc.AudiotonicPro_2.0.4.0_x86__61yk12x6sxn40 [2021-09-10] (Blusky Software Inc.)
AudioWizard -> C:\Program Files\WindowsApps\ICEpower.AudioWizard_1.5.28.0_x64__dxp88312j1fgj [2023-06-12] (ICEpower)
eManual -> C:\Program Files\WindowsApps\B9ECED6F.eManual_2.0.3.0_x86__qmba6cd70vzyy [2018-12-21] (ASUSTeK COMPUTER INC.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_146.2.1055.0_x64__v10z8vjag6ke6 [2023-06-14] (HP Inc.)
Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2021-04-01] (INTEL CORP)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa [2023-06-10] (Apple Inc.) [Startup Task]
LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_2.1.7098.0_neutral__w1wdnht996qgy [2023-05-23] (LinkedIn)
Media-engine-invoegtoepassing voor Foto's -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-24] (Microsoft Corporation)
Microsoft Access -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Access_16051.16327.20248.0_x86__8wekyb3d8bbwe [2023-05-12] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-11-01] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-11-01] (Microsoft Corporation) [MS Ad]
Microsoft Excel -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Excel_16051.16327.20248.0_x86__8wekyb3d8bbwe [2023-05-12] (Microsoft Corporation)
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.39.0_x64__8wekyb3d8bbwe [2023-01-03] (Microsoft Corp.)
Microsoft Office Desktop Apps -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.16327.20248.0_x86__8wekyb3d8bbwe [2023-05-12] (Microsoft Corporation)
Microsoft Outlook -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.16327.20248.0_x86__8wekyb3d8bbwe [2023-05-12] (Microsoft Corporation)
Microsoft PowerPoint -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.PowerPoint_16051.16327.20248.0_x86__8wekyb3d8bbwe [2023-05-12] (Microsoft Corporation)
Microsoft Publisher -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Publisher_16051.16327.20248.0_x86__8wekyb3d8bbwe [2023-05-12] (Microsoft Corporation)
Microsoft Word -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.16327.20248.0_x86__8wekyb3d8bbwe [2023-05-12] (Microsoft Corporation)
ms-resource:AppDisplayName -> C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy [2023-06-14] (ASUSTeK COMPUTER INC.)
ms-resource:PkgDisplayName -> C:\Program Files\WindowsApps\64404Softuna.TotalDiskCleaner_2.1.10.0_x64__r1b4jsc7ddp3p [2023-05-18] (Total PC Cleaner)
ms-resource:System_Item_Title_IntelGraphicsControlPanel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.4979.0_x64__8j3eq9eme6ctt [2023-05-26] (INTEL CORP) [Startup Task]
MuseScore 3 -> C:\Program Files\WindowsApps\64051MuseScoreBVBA.MuseScoreNotationSoftware_3.3.4.0_x64__pz631wrhsw9tj [2020-01-22] (MuseScore BVBA)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-16] (Netflix, Inc.)
Reader Notification Client -> C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2019-11-16] (Adobe Systems Incorporated)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.2.172.0_x64__dt26b99r8h8gj [2019-08-12] (Realtek Semiconductor Corp)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0 [2023-06-10] (Spotify AB) [Startup Task]
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2322.2.0_x64__cv1g1gvanyjgm [2023-06-16] (WhatsApp Inc.) [Startup Task]
WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.851.1712.0_x64__8wekyb3d8bbwe [2023-06-08] (Microsoft Corporation)
WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.851.1712.0_x86__8wekyb3d8bbwe [2023-06-08] (Microsoft Corporation)
 
==================== Aangepaste CLSID (gefilterd): ==============
 
(Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)
 
CustomCLSID: HKU\S-1-5-21-2140152316-3761713159-350972558-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\info\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20339.4\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2140152316-3761713159-350972558-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\info\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20091.2\x64\Microsoft.Teams.AddinLoader.dll => Geen bestand
CustomCLSID: HKU\S-1-5-21-2140152316-3761713159-350972558-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> C:\Users\info\AppData\Local\Microsoft\Teams\current\Teams.exe (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [  OptaneIconOverlay] -> {A3AF6F6C-8BED-3D93-8B5D-33427B5D38E9} => C:\Program Files\Intel\OptaneShellExtensions\OptaneShellExt.dll [2018-06-13] () [Bestand niet getekend] [Bestand is in gebruik]
ShellIconOverlayIdentifiers: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ShellIconOverlayIdentifiers-x32: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers3: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers3: [OptaneContextMenu] -> {AD7EBB13-617D-3270-8FA8-46583499C4FB} => C:\Program Files\Intel\OptaneShellExtensions\OptaneShellExt.dll [2018-06-13] () [Bestand niet getekend] [Bestand is in gebruik]
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
 
==================== Codecs (gefilterd) ====================
 
==================== Snelkoppelingen & WMI ========================
 
(De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.)
 
ShortcutWithArgument: C:\Users\info\Desktop\tanja\Persoon 1 - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\info\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
 
==================== Geladen Modules (gefilterd) =============
 
2022-07-30 14:54 - 2019-12-05 16:17 - 000104448 _____ (CANON INC.) [Bestand niet getekend] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_IMG.dll
2022-07-30 14:54 - 2019-12-05 16:17 - 000009216 _____ (CANON INC.) [Bestand niet getekend] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_NLD.DLL
2018-06-13 06:01 - 2018-06-13 06:01 - 000125952 _____ (Intel Corporation) [Bestand niet getekend] C:\Program Files\Intel\OptaneShellExtensions\iaStorAfsServiceApi.dll
 
==================== Alternate Data Streams (gefilterd) ========
 
==================== Veilige Modus (gefilterd) ==================
 
(Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. De waarde van "AlternateShell" wordt hersteld.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\avgSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avgSP.sys => ""="Driver"
 
==================== Bestandskoppeling (gefilterd) =================
 
==================== Internet Explorer (gefilterd) ==========
 
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus17win10.msn.com/?pc=ASTE
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus17win10.msn.com/?pc=ASTE
SearchScopes: HKU\S-1-5-21-2140152316-3761713159-350972558-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2140152316-3761713159-350972558-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
 
==================== Hosts inhoud: =========================
 
(Indien nodig kan Hosts:-opdracht worden opgenomen in de fixlist om Hosts te resetten.)
 
2018-04-12 01:38 - 2018-04-12 01:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
2021-02-07 00:32 - 2021-02-07 00:37 - 000000444 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
==================== Andere gebieden ===========================
 
(Momenteel is er geen automatische fix voor dit onderdeel.)
 
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\info\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\MER02948.JPG
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is ingeschakeld.
 
==================== MSCONFIG/TASK MANAGER Uitgeschakelde items ==
 
(Als een item is opgenomen in de fixlist, zal het worden verwijderd.)
 
HKLM\...\StartupApproved\Run: => "Focusrite Notifier"
HKLM\...\StartupApproved\Run32: => "Zwift"
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams"
 
==================== Firewall regels (gefilterd) ================
 
(Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)
 
FirewallRules: [{896FB7AB-F868-445B-8E70-047C3B351511}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{3E5A8DF4-ADA6-4195-9AF2-400C686151F1}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{544138B3-5472-404B-8866-B2ACDECDFB87}] => (Allow) C:\Users\info\Downloads\win-ts3400-1_3-n_mcd\win\MSetup64.exe => Geen bestand
FirewallRules: [{B19D1D19-2AF5-46CE-9650-675C49D45F4B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ticket to Ride\Ticket to Ride.exe (Days of Wonder, Inc.) [Bestand niet getekend]
FirewallRules: [{D2E10484-C3F2-4B94-ADFA-CBEABDD252D0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ticket to Ride\Ticket to Ride.exe (Days of Wonder, Inc.) [Bestand niet getekend]
FirewallRules: [{057C2CC6-259D-4D9A-81C5-E84DFC61737E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Carcassonne The Official Board Game\Carcassonne.exe () [Bestand niet getekend]
FirewallRules: [{9140BF03-E70F-4335-86C1-8F3D9458F96E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Carcassonne The Official Board Game\Carcassonne.exe () [Bestand niet getekend]
FirewallRules: [UDP Query User{355494F5-6EB0-4674-B0BE-26B76845D098}C:\program files (x86)\zwift\zwiftapp.exe] => (Allow) C:\program files (x86)\zwift\zwiftapp.exe (Zwift, Inc. -> )
FirewallRules: [TCP Query User{B7A35808-C55B-4559-9525-401AA0D8757D}C:\program files (x86)\zwift\zwiftapp.exe] => (Allow) C:\program files (x86)\zwift\zwiftapp.exe (Zwift, Inc. -> )
FirewallRules: [UDP Query User{0BFFD11C-097D-45BE-B309-032B8699DA93}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => Geen bestand
FirewallRules: [TCP Query User{39DA58D4-D436-4B6C-A4B1-099C7F7C9450}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => Geen bestand
FirewallRules: [UDP Query User{97A73D71-B224-44B7-B341-9C2A89E2143D}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => Geen bestand
FirewallRules: [TCP Query User{316FC8A6-2536-4032-BCD9-04544B5BA476}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => Geen bestand
FirewallRules: [{8572A005-A524-4BA0-B168-CC33AED09624}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Scythe Digital Edition\Scythe.exe () [Bestand niet getekend]
FirewallRules: [{7FE449E0-815D-4E85-AB20-6F4324D2A5E2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Scythe Digital Edition\Scythe.exe () [Bestand niet getekend]
FirewallRules: [UDP Query User{693EFBB5-FACE-441F-B77A-8A0CB015DEAB}C:\users\info\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\info\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{6BA16B67-C888-49E3-9E5D-F53B909A0A64}C:\users\info\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\info\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1850A575-8881-433A-B13B-823F459EE9D1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Wingspan\Wingspan.exe (Unity Technologies ApS) [Bestand niet getekend]
FirewallRules: [{1166B07A-301B-4591-B707-1701110FEA2E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Wingspan\Wingspan.exe (Unity Technologies ApS) [Bestand niet getekend]
FirewallRules: [{A2B03916-42B4-475A-875C-37075807E0CF}] => (Allow) C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe => Geen bestand
FirewallRules: [{F84E06AD-DF39-4246-B897-AEFFA775CB19}] => (Allow) C:\Users\info\AppData\Roaming\Zoom\bin\airhost.exe => Geen bestand
FirewallRules: [{76A471F4-8A4D-4441-91C4-69C7A1AC0FF9}] => (Allow) C:\Users\info\AppData\Roaming\Zoom\bin\Zoom.exe => Geen bestand
FirewallRules: [UDP Query User{4FD0DDE7-71AC-467D-8013-C027C8DB1EF7}C:\users\info\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\info\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{3CCBFA1B-F909-43B5-A74B-303876364292}C:\users\info\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\info\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9E660CB0-1F71-4E89-93C8-9813722C710E}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => Geen bestand
FirewallRules: [{C8F02751-0B29-4254-942D-A2FAC1997446}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => Geen bestand
FirewallRules: [TCP Query User{3F04446E-F962-47AB-9C6C-F2F05E162491}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => Geen bestand
FirewallRules: [UDP Query User{D7A57D79-EA19-4369-B805-4305DD44F7DF}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => Geen bestand
FirewallRules: [{66E45CC8-6D69-4B65-B269-AAFF7B717E88}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{23CB10F3-4C1D-437F-BF8C-4478229F6CAF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D9F26FFC-7A26-4DB7-8919-723F1180F43C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1ADEEF01-A616-4651-85AF-924BA15D728D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{65A24EE6-36B9-4241-992E-E3AC920513C7}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => Geen bestand
FirewallRules: [UDP Query User{ED247984-0BA4-485F-B684-ADD75B9D7C96}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => Geen bestand
FirewallRules: [{E9A26FA7-FA22-4B00-A436-7EE59DBEC211}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{D32E50BC-D28B-447A-9923-EB9046795962}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{D6F0D809-38F0-4BE8-9251-C944DF978506}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{B8BFC2A3-1F96-4A73-9340-160BD70ACD7E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{5FA50336-0910-4BC1-A4C3-68229F564BA5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{E35E223D-54A4-4302-8C53-A73304FD53A4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [TCP Query User{11FA1CAA-D45F-4EEE-862B-6D8486EAD29B}C:\program files (x86)\zwift\zwiftapp.exe] => (Allow) C:\program files (x86)\zwift\zwiftapp.exe (Zwift, Inc. -> )
FirewallRules: [UDP Query User{A8AB8CBF-BCA2-43FD-B306-BBDBB6CB459B}C:\program files (x86)\zwift\zwiftapp.exe] => (Allow) C:\program files (x86)\zwift\zwiftapp.exe (Zwift, Inc. -> )
FirewallRules: [{5D5B44B6-EED9-4FE8-A410-BE37F6C3257D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blood Bowl 3\BB3.exe (Epic Games, Inc.) [Bestand niet getekend]
FirewallRules: [{6E76A8AC-6449-4828-AF91-EAFD15C6A3B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blood Bowl 3\BB3.exe (Epic Games, Inc.) [Bestand niet getekend]
FirewallRules: [{83A7964A-F697-4A27-B48C-3057E4F38429}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.16327.20248.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{064DDDD9-640C-4D91-88F8-1299BD6DA804}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{B056385D-A065-480E-A3EB-481D7D351F89}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{0F7E2278-F57C-4007-ABB8-B734AF21602E}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{6C555034-6DA4-4699-B190-1CDF328BA59F}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{154D2EC3-110F-4556-A49E-CE4CCDF2AF9A}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{B48A9AC2-AA62-4301-AC57-DC28E0F05D9B}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{0CBCC94E-8CA8-4909-A49C-FD59846BFC2B}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{D5B59D6A-80BC-4334-80F7-2564AB0C3E22}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{794E2B95-8F0E-453E-8AF0-D5480CC3669C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{3D99CCE6-0440-41A8-99C8-B2A0745E3225}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D935ECC5-34CB-4DFD-A1E2-3D36FD05A531}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{217C54E0-0576-4C52-99DB-3595A7F28202}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{C5217C0D-843D-452F-9A2F-DB8F50BFF71B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{81745C31-8513-4DF2-9931-5C2174FD6B90}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{EF7F4881-458A-40E6-851C-106C74859879}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{318E3D05-3EDD-4EFC-AD7C-2126DD8E2C26}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{24D13F9E-D7DB-48C3-A8F5-867A6E45544D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2B99CDBA-2D48-4475-855D-F310255DCBBC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.213.661.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B20B521D-280E-4D8D-96C6-C922503BF079}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23119.303.2080.2726_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{296AA4D7-97EE-4B4C-B246-936792C7F14C}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23119.303.2080.2726_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9FECAD59-570B-4E08-87B7-33C74D4399FD}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTeK COMPUTER INC.)
FirewallRules: [{6ADE9A78-19F6-473D-88E0-7C8218CD54DB}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTeK COMPUTER INC.)
FirewallRules: [{60EDD709-1DC5-461A-9BB6-98680D4F7873}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTeK COMPUTER INC.)
FirewallRules: [{48F37BE0-DFEC-4805-AD6D-2C7A2281A8FD}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTeK COMPUTER INC.)
FirewallRules: [{E9FA5F41-FD07-40BB-BF7E-DBB539FE063E}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\114.0.1823.51\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B92338DE-456D-40F0-99B8-B4B9CAABB520}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{85F7E465-FD5C-45D2-8951-669753D9E310}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSLinkNear\AsusLinkNear.exe (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
FirewallRules: [{E215ED14-0665-4D49-8A6B-70E35C5EF1B3}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSwitch\AsusSwitchNet.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
FirewallRules: [{95E82C03-E310-4F23-8AF9-A1BA1E49A2B6}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSSwitch\AsusSwitchNetMDNS.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
FirewallRules: [{41F2201B-9D38-4A1C-AE55-EEBDF4BF209F}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSLinkRemote\AsusLinkRemoteAgent.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​)
FirewallRules: [{3CDA5DEC-C87C-4A6C-9528-CA8686DAAD98}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fb020b09d857a47b\ASUSLinkRemote\AsusLinkRemoteAgent.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​)
FirewallRules: [{E4FFA6A4-0702-4416-A86C-66703346A396}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23119.304.2165.4533_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{888A8AA1-674A-47B1-A7FA-7A8875BC0552}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23119.304.2165.4533_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
 
==================== Herstelpunten =========================
 
14-06-2023 08:43:18 Installatieprogramma voor Windows-modules
14-06-2023 08:44:14 Installatieprogramma voor Windows-modules
 
==================== Defecte Apparaatbeheer Apparaten ============
 
 
==================== Eventlog fouten: ========================
 
Applicatiefouten:
==================
Error: (06/19/2023 04:31:14 PM) (Source: VSS) (EventID: 12298) (User: )
Description: Fout in de Volume Shadow Copy-service: de I/O-schrijfbewerkingen kunnen niet worden vastgelegd tijdens het maken van de schaduwkopie op volume \\?\Volume{584bea99-6542-4539-9603-0e057ba53116}\.
De volume-index in de set met schaduwkopieën is 0. Foutdetails: Openen [0x00000000, De bewerking is voltooid.
], Leegmaken[0x00000000, De bewerking is voltooid.
], Vrijgeven[0x80042314, Er heeft een time-out bij de provider van schaduwkopieën plaats gevonden bij het opslaan van schrijfbewerkingen op het volume waarvan een schaduwkopie wordt gemaakt. Dit komt waarschijnlijk door overmatige activiteit op het volume, veroorzaakt door een toepassing of systeemservice. Probeer het opnieuw zodra de activiteit op het volume is verminderd.
], Uitvoeren[0x00000000, De bewerking is voltooid.
].
 
 
Bewerking:
   Asynchrone bewerking uitvoeren
 
Context:
   Huidige status: DoSnapshotSet
 
Error: (05/19/2023 09:39:21 PM) (Source: Microsoft-Windows-AppModel-State) (EventID: 12) (User: LAPTOP-QBAAO188)
Description: Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy-2147023878
 
Error: (05/18/2023 05:20:13 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine CoCreateInstance.  hr = 0x8007045b, Systeem wordt afgesloten.
.
 
Error: (05/18/2023 05:20:13 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informatie voor de Volume Shadow Copy-service: de COM-server met CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} en de naam CEventSystem kan niet worden gestart. [0x8007045b, Systeem wordt afgesloten.
]
 
Error: (05/18/2023 05:20:13 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine CoCreateInstance.  hr = 0x8007045b, Systeem wordt afgesloten.
.
 
Error: (05/18/2023 05:20:13 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informatie voor de Volume Shadow Copy-service: de COM-server met CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} en de naam CEventSystem kan niet worden gestart. [0x8007045b, Systeem wordt afgesloten.
]
 
Error: (05/16/2023 07:07:02 PM) (Source: Microsoft-Windows-AppModel-State) (EventID: 12) (User: LAPTOP-QBAAO188)
Description: Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy-2147023878
 
Error: (05/14/2023 01:23:07 AM) (Source: Application Error) (EventID: 1000) (User: LAPTOP-QBAAO188)
Description: Naam van toepassing met fout: msteamsupdate.exe, versie: 23091.406.2009.3890, tijdstempel: 0x643593c8
Naam van module met fout: msteamsupdate.exe, versie: 23091.406.2009.3890, tijdstempel: 0x643593c8
Uitzonderingscode: 0xc0000005
Foutmarge: 0x000000000011afbb
Id van proces met fout: 0x0x1d20
Starttijd van toepassing met fout: 0x0x1d985f077322f01
Pad naar toepassing met fout: C:\Program Files\WindowsApps\MicrosoftTeams_23091.406.2009.3890_x64__8wekyb3d8bbwe\msteamsupdate.exe
Pad naar module met fout: C:\Program Files\WindowsApps\MicrosoftTeams_23091.406.2009.3890_x64__8wekyb3d8bbwe\msteamsupdate.exe
Rapport-id: 955801af-f46e-4064-86b3-88a5657fa5cd
Volledige pakketnaam met fout: MicrosoftTeams_23091.406.2009.3890_x64__8wekyb3d8bbwe
Relatieve toepassings-id van pakket met fout: msteamsupdate
 
 
Systeemfouten:
=============
Error: (06/15/2023 07:27:47 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop.
 
Error: (06/15/2023 07:11:31 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop.
 
Error: (06/14/2023 08:26:03 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: 9N7R5S6B0ZZH-B9ECED6F.ASUSPCAssistant.
 
Error: (06/14/2023 08:24:17 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop.
 
Error: (06/13/2023 07:10:16 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-QBAAO188)
Description: De server {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.
 
Error: (06/12/2023 06:51:49 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-QBAAO188)
Description: De server {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.
 
Error: (06/12/2023 06:49:13 AM) (Source: IntcOED) (EventID: 45) (User: )
Description: Event-ID 45
 
Error: (06/11/2023 08:15:54 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop.
 
 
CodeIntegrity:
===============
Date: 2023-06-19 14:47:16
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Windows signing level requirements. 
 
 
==================== Geheugen info =========================== 
 
BIOS: American Megatrends Inc. X430FA.308 05/28/2019
Moederbord: ASUSTeK COMPUTER INC. X430FA
Processor: Intel® Core™ i5-8265U CPU @ 1.60GHz
Percentage geheugen in gebruik: 78%
Totaal fysiek RAM-geheugen: 8043.61 MB
Beschikbaar fysiek RAM-geheugen: 1750.73 MB
Totaal Virtueel geheugen: 9579.61 MB
Beschikbaar Virtueel geheugen: 2596.71 MB
 
==================== Schijven ================================
 
Drive c: (OS) (Fixed) (Total:237.42 GB) (Free:59.8 GB) (Model: INTEL SSDSCKKW256G8) NTFS
 
\\?\Volume{54e95cf9-9493-4202-8beb-a6fc7d552267}\ (RECOVERY) (Fixed) (Total:0.78 GB) (Free:0.16 GB) NTFS
\\?\Volume{f0180894-28fc-4771-89f4-efa7f35c2201}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
 
==================== MBR & Partitietabel ====================
 
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 9929D3AC)
 
Partition: GPT.
 
==================== Einde van Addition.txt =======================
 

  • 0

Advertisements


#2
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,422 posts
Hi, Dave. Welcome back.  :)

I tried to go through your logs, but the language made it a bit difficult for me. To translate FRST logs in English, please right click on FRST64.exe and rename to FRST64English.exe

After that, run the tool once more and attach the 2 fresh logs.
  • 0

#3
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,422 posts

Do you still need our assistance, Dave? 


  • 0

#4
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,422 posts
Due to lack of feedback, this topic has been closed.
 
If you need this topic reopened, please contact a staff member, or send me a personal message (hoover with the mouse on my profile name and choose Send message).

  • 0

#5
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,422 posts

Topic re-opens after User's (Dave88) request.


  • 0

#6
daveBB

daveBB

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

Just did this, edited the first post accordingly

 

thanks

Hi, Dave. Welcome back.  :)

I tried to go through your logs, but the language made it a bit difficult for me. To translate FRST logs in English, please right click on FRST64.exe and rename to FRST64English.exe

After that, run the tool once more and attach the 2 fresh logs.


  • 0

#7
daveBB

daveBB

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

grr .. can't find how to do that, have been away from fora for too long aparently.

 

FRST:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-06-2023
Ran by info (administrator) on LAPTOP-QBAAO188 (ASUSTeK COMPUTER INC. VivoBook_ASUSLaptop X430FA_S430FA) (28-06-2023 18:48:46)
Running from C:\Users\info\Desktop\FRST-OlderVersion\FRST64english.exe
Loaded Profiles: info
Platform: Microsoft Windows 11 Home Version 22H2 22621.1848 (X64) Language: Nederlands (Nederland)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(ASUSTek Computer Inc. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\ATKOSD2.exe
(C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe ->) (ASUSTek Computer Inc. -> ASUSTeK COMPUTER INC.) C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBox.Agent.exe
(C:\Program Files (x86)\Microsoft\EdgeWebView\Application\114.0.1823.58\msedgewebview2.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe <4>
(C:\Program Files\AVG\Antivirus\AVGSvc.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe
(C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.16501.20210.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.EXE ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.16501.20210.0_x86__8wekyb3d8bbwe\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\ai.exe <2>
(C:\Program Files\WindowsApps\MicrosoftTeams_23119.304.2165.4533_x64__8wekyb3d8bbwe\msteams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\114.0.1823.58\msedgewebview2.exe <12>
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSoftwareManager\AsusSoftwareManager.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSoftwareManager\AsusSoftwareManagerAgent.exe
(DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsLdrSrv64.exe ->) (ASUSTek Computer Inc. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsMonStartupTask64.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxEM.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <21>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.16501.20210.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.16501.20210.0_x86__8wekyb3d8bbwe\Office16\WINWORD.EXE
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.272\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.272\GoogleCrashHandler64.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSLinkRemote\AsusLinkRemote.exe
(services.exe ->) (ASUSTek Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\AsusAppService\AsusAppService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSLinkNear\AsusLinkNear.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\AsusOptimization\AsusOptimization.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSoftwareManager\AsusSoftwareManager.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSwitch\AsusSwitch.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSystemAnalysis\AsusSystemAnalysis.exe
(services.exe ->) (ASUSTek Computer Inc. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsHidSrv64.exe
(services.exe ->) (ASUSTek Computer Inc. -> ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsLdrSrv64.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\avgToolsSvc.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ELANFPService.exe
(services.exe ->) (ICEpower a/s -> ICEpower A/S) C:\Windows\System32\DriverStore\FileRepository\icesoundapo64.inf_amd64_db704b106aae3892\ICEsoundService64.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\jhi_service.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_54b736e5be5b50b2\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e9b40d45ab4dc6b8\IntelCpHDCPSvc.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_e9b40d45ab4dc6b8\IntelCpHeciSvc.exe
(services.exe ->) (Intel® Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_a2fcfdfc3497e17c\RstMwService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSystemDiagnosis\AsusSystemDiagnosis.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Intel) C:\Windows\System32\cAVS\Intel® Audio Service\IntelAudioService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(sihost.exe ->) (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTek Computer Inc.) C:\Program Files\WindowsApps\B9ECED6F.ASUSKeyboardHotkeys_1.0.12.0_x86__qmba6cd70vzyy\ATK Package\HControl.exe
(sihost.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2323.2.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\SpotifyWidgetProvider.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.16501.20210.0_x86__8wekyb3d8bbwe\Office16\SDXHelperBgt.exe
(svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.13900.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [256952 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Zwift] => C:\Program Files (x86)\Zwift\ZwiftLauncher.exe [18038304 2023-03-16] (Zwift, Inc. -> Zwift, Inc)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [278440 2019-12-05] (Canon Inc. -> CANON INC.)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\Run: [Zoom] => [X]
HKLM\...\Windows x64\Print Processors\Canon TS3400 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDGF.DLL [525824 2021-09-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS3400 series: C:\WINDOWS\system32\CNMLMGF.DLL [962560 2021-09-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\114.0.5735.198\Installer\chrmstp.exe [2023-06-27] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] -> 
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {00744A9E-E92C-47F4-8259-D94A8B3D6084} - System32\Tasks\MyASUS Update Messenger => C:\Users\info\AppData\Local\MyASUS Update Messenger\UpdateMessenger.exe [13859888 2021-02-22] (SweetLabs Inc. -> SweetLabs, Inc)
Task: {0491F4E0-867F-4923-9EA4-48EE9A0B00F1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564152 2023-04-03] (Adobe Inc. -> Adobe Inc.)
Task: {10BF01BC-42BA-401E-AC23-45DE3FE39E61} - System32\Tasks\RtkAudUService64_BG => C:\Windows\system32\RtkAudUService64.exe [874184 2020-12-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {1A75CD0A-6F99-4012-8144-016738526CF6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-07] (Google Inc -> Google LLC)
Task: {22D0360A-F612-456A-852D-853E1D46E5A0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-07] (Google Inc -> Google LLC)
Task: {267A5359-8F4F-4207-8392-DAC5D6A5A71B} - System32\Tasks\ASUS Hello => C:\Program Files (x86)\ASUS\ASUS Hello\ASUSHelloBG.exe [609592 2018-07-11] (ASUSTek Computer Inc. -> )
Task: {6312717F-E59E-4D54-B496-CE8175085E23} - System32\Tasks\ASUS Update Checker 2.0 => C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSoftwareManager\AsusUpdateChecker.exe [797832 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
Task: {6A981D5A-530A-4167-86F7-883253442715} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe  Display (No File)
Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe  RebootDialog (No File)
Task: {73C8F0B6-F299-4271-82F2-2770A9FB54B6} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2172344 2023-04-13] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {771370F6-1948-4F56-88E1-B595220D33F7} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [4922296 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Task: {B255D67A-16DB-470B-A090-877FEF048EF5} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery Reboot (No File)
Task: {C1EF45A1-44D2-48F3-862D-DCB5FA3AA96A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe  Display (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File)
Task: {DD42B29C-7F91-4510-9DA7-1A63F55A159D} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC Reboot (No File)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
Task: {F677D99A-6D44-43AD-9E94-28D5FB5337F7} - System32\Tasks\AsusSystemAnalysis_754F3273-0563-4F20-B12F-826510B07474 => C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSystemAnalysis\AsusSystemAnalysis.exe [3860576 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
Task: {FBE9C792-71B0-4E4F-AD1C-90853357C53D} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\WINDOWS\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsHotkeyExec64.exe [176064 2019-03-04] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{35fe1c02-7b75-4a5a-9d5d-ca0f7b63d258}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{ae8c850e-d435-4025-b5d4-a77d43bf0440}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{e74f76e7-cafb-4d86-8bd0-43fc384d236e}: [DhcpNameServer] 40.53.1.12
 
Edge: 
=======
DownloadDir: C:\Users\info\Downloads
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\info\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-09]
Edge DownloadDir: Default -> C:\Users\info\Downloads
 
FireFox:
========
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-06-14] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\info\AppData\Local\Google\Chrome\User Data\Guest Profile [2023-04-17]
CHR Profile: C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1 [2023-06-28]
CHR Notifications: Profile 1 -> hxxps://calendar.google.com; hxxps://www.letour.fr; hxxps://yaktribe.games; hxxps://zwiftinsider.com
CHR Extension: (Honey: automatische bonnen en beloningen) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2023-06-21]
CHR Extension: (Adblock Plus - gratis adblocker) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2023-06-17]
CHR Extension: (Elevate for Strava) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhiaggccakkgdfcadnklkbljcgicpckn [2022-05-26]
CHR Extension: (Offline Documenten) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-05-18]
CHR Extension: (AVG SafePrice | prijsvergelijking, aanbiedingen, waardebonnen) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2023-04-22]
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-04-13]
CHR Profile: C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 2 [2023-04-17]
CHR Extension: (Offline Documenten) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-04-16]
CHR Extension: (AVG SafePrice | prijsvergelijking, aanbiedingen, waardebonnen) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2023-04-16]
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\info\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-04-16]
CHR Profile: C:\Users\info\AppData\Local\Google\Chrome\User Data\System Profile [2023-04-17]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.)
R2 AsHidService; C:\WINDOWS\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsHidSrv64.exe [173504 2019-03-04] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
R2 ASLDRService; C:\WINDOWS\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\AsLdrSrv64.exe [227776 2019-03-04] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
R2 AsusAppService; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\AsusAppService\AsusAppService.exe [1174672 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSLinkNear; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSLinkNear\AsusLinkNear.exe [1637472 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
R2 ASUSLinkRemote; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSLinkRemote\AsusLinkRemote.exe [783968 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​)
R2 ASUSLiveUpdateAgent; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSoftwareManager\AsusSoftwareManager.exe [1125520 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSOptimization; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\AsusOptimization\AsusOptimization.exe [206472 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSSwitch; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSwitch\AsusSwitch.exe [641168 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSSystemAnalysis; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSystemAnalysis\AsusSystemAnalysis.exe [3860576 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSSystemDiagnosis; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSystemDiagnosis\AsusSystemDiagnosis.exe [526256 2023-05-17] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek COMPUTER INC.)
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [619448 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AVG Tools; C:\Program Files\AVG\Antivirus\avgToolsSvc.exe [620472 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [8851384 2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AvgWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [109480 2021-05-31] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 GiftBox.Service; C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe [299320 2019-04-09] (ASUSTek Computer Inc. -> ASUSTeK Computer Inc.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [445432 2021-04-19] (Canon Inc. -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [2909208 2022-05-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [128376 2022-05-07] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R3 AsusPTPDrv; C:\WINDOWS\System32\DriverStore\FileRepository\asusptpfilter.inf_amd64_314b5cb6bf57f471\AsusPTPFilter.sys [116712 2021-12-02] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
R3 AsusSAIO; C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSystemAnalysis\AsusSAIO.sys [46736 2023-05-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R1 ATKWMIACPIIO; C:\WINDOWS\System32\DriverStore\FileRepository\atkwmiacpiio.inf_amd64_30ffacb41f78f352\atkwmiacpi64.sys [36368 2019-03-04] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
R0 avgArDisk; C:\WINDOWS\System32\drivers\avgArDisk.sys [31408 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [236440 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [392360 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [297872 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [96464 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [25064 2022-10-14] (Microsoft Windows Early Launch Anti-malware Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [39640 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [271544 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [556104 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [105240 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [80408 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [943448 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [703792 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [212672 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [319552 2023-06-08] (Microsoft Windows Hardware Compatibility Publisher -> AVG Technologies CZ, s.r.o.)
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [106496 2022-05-07] (Microsoft Corporation) [File not signed]
S3 CMUSBDAC; C:\WINDOWS\system32\DRIVERS\CMUSBDAC.sys [3819744 2018-07-24] (WDKTestCert cm359,131641702659254692 -> C-MEDIA)
R3 libusb0; C:\WINDOWS\system32\DRIVERS\libusb0.sys [44480 2019-10-10] (Akeo Consulting -> hxxp://libusb-win32.sourceforge.net)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [48536 2022-05-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [438544 2022-05-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [90384 2022-05-07] (Microsoft Windows -> Microsoft Corporation)
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2023-06-27 20:02 - 2023-06-27 20:02 - 000737096 _____ C:\Users\info\Desktop\20230626 email1.pdf
2023-06-27 20:01 - 2023-06-27 20:02 - 000842946 _____ C:\Users\info\Desktop\20230626 email2.pdf
2023-06-27 20:01 - 2023-06-27 20:01 - 000737099 _____ C:\Users\info\Desktop\2.pdf
2023-06-19 16:55 - 2023-06-19 16:55 - 000041467 _____ C:\Users\info\Downloads\pensioenoverzicht-geen-bsn (2).pdf
2023-06-19 16:52 - 2023-06-19 16:52 - 000042043 _____ C:\Users\info\Downloads\pensioenoverzicht-geen-bsn (1).pdf
2023-06-19 16:25 - 2023-06-28 18:49 - 000000000 ____D C:\FRST
2023-06-19 16:25 - 2023-06-28 18:48 - 000000000 ____D C:\Users\info\Desktop\FRST-OlderVersion
2023-06-16 07:11 - 2023-06-16 07:11 - 000804920 _____ C:\WINDOWS\system32\perfh013.dat
2023-06-16 07:11 - 2023-06-16 07:11 - 000160452 _____ C:\WINDOWS\system32\perfc013.dat
2023-06-14 08:43 - 2023-06-14 08:43 - 000000000 ___HD C:\$WinREAgent
2023-06-08 22:43 - 2023-06-08 22:43 - 000313272 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2023-06-05 14:09 - 2023-06-05 14:09 - 000545088 _____ C:\Users\info\Downloads\114342778.pdf
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2023-06-28 18:44 - 2022-09-28 13:30 - 000003750 _____ C:\WINDOWS\system32\Tasks\AsusSystemAnalysis_754F3273-0563-4F20-B12F-826510B07474
2023-06-28 18:37 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-06-28 18:37 - 2019-08-07 14:12 - 000000000 ____D C:\Program Files (x86)\Google
2023-06-28 17:00 - 2022-09-28 13:25 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-06-28 17:00 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-06-28 14:34 - 2019-08-07 12:27 - 000000000 __SHD C:\Users\info\IntelGraphicsProfiles
2023-06-28 06:42 - 2022-09-28 13:30 - 000003658 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-06-28 06:42 - 2022-09-28 13:30 - 000003504 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-06-28 06:42 - 2022-09-28 13:30 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2023-06-28 06:42 - 2022-09-28 13:30 - 000003434 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-06-28 06:42 - 2022-09-28 13:30 - 000003280 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2023-06-28 06:42 - 2022-09-28 13:30 - 000003250 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update
2023-06-28 06:42 - 2022-09-28 13:30 - 000003114 _____ C:\WINDOWS\system32\Tasks\ASUS Update Checker 2.0
2023-06-28 06:42 - 2022-09-28 13:30 - 000003062 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2140152316-3761713159-350972558-1001
2023-06-28 06:42 - 2022-09-28 13:30 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2140152316-3761713159-350972558-1001
2023-06-28 06:42 - 2022-09-28 13:30 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2023-06-28 06:20 - 2022-05-07 07:24 - 000000000 ___HD C:\Program Files\WindowsApps
2023-06-28 06:20 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-06-27 22:01 - 2022-10-12 20:02 - 000002075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2023-06-27 22:01 - 2022-10-12 20:02 - 000002063 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2023-06-27 06:54 - 2021-01-15 12:03 - 000000000 ____D C:\Users\info\AppData\Local\D3DSCache
2023-06-27 06:32 - 2019-08-07 14:14 - 000002323 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-06-26 22:19 - 2020-09-30 22:00 - 000002380 _____ C:\Users\info\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-06-26 02:49 - 2019-08-12 18:50 - 000000000 ____D C:\Users\info\AppData\Local\CrashDumps
2023-06-25 07:44 - 2022-05-07 07:22 - 000000000 ____D C:\WINDOWS\INF
2023-06-24 07:37 - 2019-08-12 18:48 - 000000000 ____D C:\ProgramData\Packages
2023-06-24 06:23 - 2021-04-16 23:50 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-06-21 07:37 - 2021-06-30 15:38 - 000000000 ____D C:\ProgramData\CanonIJPLM
2023-06-16 17:43 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2023-06-16 07:11 - 2022-09-28 13:29 - 001803066 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-06-16 07:05 - 2022-09-28 13:30 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-06-16 07:05 - 2022-09-28 13:25 - 000302192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-06-16 07:05 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ServiceState
2023-06-16 07:05 - 2022-05-07 07:17 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2023-06-16 07:05 - 2020-09-30 21:59 - 000012288 ___SH C:\DumpStack.log.tmp
2023-06-16 07:05 - 2019-08-11 12:46 - 000000000 ____D C:\ProgramData\AVG
2023-06-16 07:05 - 2018-12-21 07:26 - 000000000 ___HD C:\Intel
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\WUModels
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\UUS
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemResources
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Dism
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ShellExperiences
2023-06-16 07:04 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-06-16 07:04 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\servicing
2023-06-14 08:49 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-06-14 08:46 - 2022-09-28 13:26 - 003211776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2023-06-14 08:30 - 2021-02-09 20:30 - 000000000 ____D C:\Users\info\AppData\Local\MyASUS Update Messenger
2023-06-14 08:07 - 2019-08-11 12:21 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-06-14 08:05 - 2019-08-11 12:21 - 170078616 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-06-14 04:51 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2023-06-08 22:43 - 2022-05-07 07:24 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-06-08 22:43 - 2020-10-23 15:05 - 000271544 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2023-06-08 22:43 - 2020-06-16 16:46 - 000556104 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgNetHub.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000943448 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000703792 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000392360 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdriver.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000319552 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000297872 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsh.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000236440 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000105240 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000096464 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniv.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000080408 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000039640 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgKbd.sys
2023-06-08 22:43 - 2019-08-11 12:48 - 000031408 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArDisk.sys
2023-06-08 17:45 - 2019-08-07 12:27 - 000000000 ____D C:\Users\info\AppData\Local\Packages
2023-06-01 19:22 - 2021-06-08 23:14 - 000000000 ____D C:\Users\info\Documents\Documenten
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
 
 
 
ADDITION:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-06-2023
Ran by info (28-06-2023 18:49:53)
Running from C:\Users\info\Desktop\FRST-OlderVersion
Microsoft Windows 11 Home Version 22H2 22621.1848 (X64) (2022-09-28 11:30:43)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-2140152316-3761713159-350972558-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2140152316-3761713159-350972558-503 - Limited - Disabled)
Gast (S-1-5-21-2140152316-3761713159-350972558-501 - Limited - Disabled)
info (S-1-5-21-2140152316-3761713159-350972558-1001 - Administrator - Enabled) => C:\Users\info
WDAGUtilityAccount (S-1-5-21-2140152316-3761713159-350972558-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F4A6BD41-306E-5B9F-464B-23E1AE81F649}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1043-1033-7760-BC15014EA700}) (Version: 23.003.20215 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601047}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
ASUS GiftBox Service (HKLM-x32\...\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B}) (Version: 3.2.5.0 - ASUSTeK COMPUTER INC.)
ASUS Hello (HKLM-x32\...\{D8CE1923-92A9-4036-817E-9E0D8AA2169B}) (Version: 1.1.10.0 - ASUSTeK COMPUTER INC.)
AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.8.4 - ICEpower a/s)
AVG AntiVirus Free (HKLM\...\AVG Antivirus) (Version: 23.5.3286 - AVG Technologies)
Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.15.2 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.61.1.10 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.6.0.2 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.4.0 - Canon Inc.)
Canon TS3400 series Driver (HKLM\...\{1199FAD5-9546-44F3-81CF-FFDB8040B7BF}_Canon_TS3400_series) (Version: 1.02 - Canon Inc.)
Elevate 7.0.0-beta.5 (HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\6548da05-a4bc-57ed-8c01-06101fc8d1df) (Version: 7.0.0-beta.5 - Thomas Champagne)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 114.0.5735.198 - Google LLC)
Intel® Serial IO (HKLM\...\{72759DFB-9080-46A5-ACCF-5BA26A6FF3FD}) (Version: 30.100.1727.1 - Intel Corporation) Hidden
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1727.1 - Intel Corporation)
Intel® Optane™ Pinning Explorer Extensions (HKLM\...\{88667F43-B63E-4046-AF02-35E5412B8FAF}) (Version: 16.5.1.1030 - Intel Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 114.0.1823.58 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 114.0.1823.58 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\OneDriveSetup.exe) (Version: 23.122.0611.0001 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\Teams) (Version: 1.4.00.8872 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{43D501A5-E5E3-46EC-8F33-9E15D2A2CBD5}) (Version: 5.70.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.31.31103 (HKLM-x32\...\{2aaf1df0-eb13-4099-9992-962bb4e596d1}) (Version: 14.31.31103.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29334 (HKLM-x32\...\{14C49FC8-3E9B-4F29-8526-26629B5CF30B}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29334 (HKLM-x32\...\{0D01A812-82A1-481F-8546-8E28E976F8DF}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.31.31103 (HKLM\...\{A977984B-9244-49E3-BD24-43F0A8009667}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.31.31103 (HKLM\...\{A181A302-3F6D-4BAD-97A8-A426A6499D78}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Paradox Launcher v2 (HKLM\...\{986898D9-7C26-4E7F-814C-9B5472FA3209}) (Version: 2.0.0.0 - Paradox Interactive)
Printerregistratie (HKLM-x32\...\Canon EISRegistration) (Version: 1.9.0 - Canon Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{3BAE4496-6F6C-4330-A8AA-B93D3D346FA5}) (Version: 2.53.0.0 - Microsoft Corporation)
Windows Pc-statuscontrole (HKLM\...\{D1F16371-7951-41EB-A367-507D779F1E64}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Windows-stuurprogrammapakket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Zwift Activity Monitor 1.2.5 (HKLM-x32\...\Zwift Activity Monitor) (Version: 1.2.5 - Kevin Ruff p/b EnJoy Fitness)
Zwift version 1.1.6 (HKLM-x32\...\{E4DA422A-82AB-44A4-B3A5-0AF60F47B7AB}_is1) (Version: 1.1.6 - Zwift, LLC)
 
Packages:
=========
ASUS GIFTBOX -> C:\Program Files\WindowsApps\B9ECED6F.ASUSGIFTBOX_3.2.4.0_x64__qmba6cd70vzyy [2022-09-29] (ASUSTeK COMPUTER INC.)
ASUS Keyboard Hotkeys -> C:\Program Files\WindowsApps\B9ECED6F.ASUSKeyboardHotkeys_1.0.12.0_x86__qmba6cd70vzyy [2019-09-18] (ASUSTeK COMPUTER INC.) [Startup Task]
Audiotonic Pro -> C:\Program Files\WindowsApps\BluskySoftwareInc.AudiotonicPro_2.0.4.0_x86__61yk12x6sxn40 [2021-09-10] (Blusky Software Inc.)
AudioWizard -> C:\Program Files\WindowsApps\ICEpower.AudioWizard_1.5.28.0_x64__dxp88312j1fgj [2023-06-12] (ICEpower)
eManual -> C:\Program Files\WindowsApps\B9ECED6F.eManual_2.0.3.0_x86__qmba6cd70vzyy [2018-12-21] (ASUSTeK COMPUTER INC.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_146.3.1087.0_x64__v10z8vjag6ke6 [2023-06-21] (HP Inc.)
Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2021-04-01] (INTEL CORP)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa [2023-06-10] (Apple Inc.) [Startup Task]
LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_3.0.4.0_x64__w1wdnht996qgy [2023-06-24] (LinkedIn)
Media-engine-invoegtoepassing voor Foto's -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-24] (Microsoft Corporation)
Microsoft Access -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Access_16051.16501.20210.0_x86__8wekyb3d8bbwe [2023-06-26] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-11-01] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-11-01] (Microsoft Corporation) [MS Ad]
Microsoft Excel -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Excel_16051.16501.20210.0_x86__8wekyb3d8bbwe [2023-06-26] (Microsoft Corporation)
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.39.0_x64__8wekyb3d8bbwe [2023-01-03] (Microsoft Corp.)
Microsoft Office Desktop Apps -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.16501.20210.0_x86__8wekyb3d8bbwe [2023-06-26] (Microsoft Corporation)
Microsoft Outlook -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.16501.20210.0_x86__8wekyb3d8bbwe [2023-06-26] (Microsoft Corporation)
Microsoft PowerPoint -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.PowerPoint_16051.16501.20210.0_x86__8wekyb3d8bbwe [2023-06-26] (Microsoft Corporation)
Microsoft Publisher -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Publisher_16051.16501.20210.0_x86__8wekyb3d8bbwe [2023-06-26] (Microsoft Corporation)
Microsoft Word -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.16501.20210.0_x86__8wekyb3d8bbwe [2023-06-26] (Microsoft Corporation)
ms-resource:AppDisplayName -> C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy [2023-06-14] (ASUSTeK COMPUTER INC.)
ms-resource:PkgDisplayName -> C:\Program Files\WindowsApps\64404Softuna.TotalDiskCleaner_2.1.10.0_x64__r1b4jsc7ddp3p [2023-06-20] (Total PC Cleaner)
ms-resource:System_Item_Title_IntelGraphicsControlPanel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.4979.0_x64__8j3eq9eme6ctt [2023-06-27] (INTEL CORP) [Startup Task]
MuseScore 3 -> C:\Program Files\WindowsApps\64051MuseScoreBVBA.MuseScoreNotationSoftware_3.3.4.0_x64__pz631wrhsw9tj [2020-01-22] (MuseScore BVBA)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-16] (Netflix, Inc.)
Reader Notification Client -> C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2019-11-16] (Adobe Systems Incorporated)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.2.172.0_x64__dt26b99r8h8gj [2019-08-12] (Realtek Semiconductor Corp)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0 [2023-06-26] (Spotify AB) [Startup Task]
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2323.2.0_x64__cv1g1gvanyjgm [2023-06-26] (WhatsApp Inc.) [Startup Task]
WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.882.2207.0_x64__8wekyb3d8bbwe [2023-06-27] (Microsoft Corporation)
WindowsAppRuntime.1.3 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.3_3000.882.2207.0_x86__8wekyb3d8bbwe [2023-06-27] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2140152316-3761713159-350972558-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\info\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20339.4\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2140152316-3761713159-350972558-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\info\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20091.2\x64\Microsoft.Teams.AddinLoader.dll => No File
CustomCLSID: HKU\S-1-5-21-2140152316-3761713159-350972558-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> C:\Users\info\AppData\Local\Microsoft\Teams\current\Teams.exe (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [  OptaneIconOverlay] -> {A3AF6F6C-8BED-3D93-8B5D-33427B5D38E9} => C:\Program Files\Intel\OptaneShellExtensions\OptaneShellExt.dll [2018-06-13] () [File not signed] [File is in use]
ShellIconOverlayIdentifiers: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ShellIconOverlayIdentifiers-x32: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers3: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers3: [OptaneContextMenu] -> {AD7EBB13-617D-3270-8FA8-46583499C4FB} => C:\Program Files\Intel\OptaneShellExtensions\OptaneShellExt.dll [2018-06-13] () [File not signed] [File is in use]
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2023-06-08] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\info\Desktop\tanja\Persoon 1 - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\info\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
 
==================== Loaded Modules (Whitelisted) =============
 
2022-07-30 14:54 - 2019-12-05 16:17 - 000104448 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_IMG.dll
2022-07-30 14:54 - 2019-12-05 16:17 - 000009216 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_NLD.DLL
2018-06-13 06:01 - 2018-06-13 06:01 - 000125952 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\OptaneShellExtensions\iaStorAfsServiceApi.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\avgSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avgSP.sys => ""="Driver"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus17win10.msn.com/?pc=ASTE
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus17win10.msn.com/?pc=ASTE
SearchScopes: HKU\S-1-5-21-2140152316-3761713159-350972558-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2140152316-3761713159-350972558-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2018-04-12 01:38 - 2018-04-12 01:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
2021-02-07 00:32 - 2021-02-07 00:37 - 000000444 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\info\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\MER02948.JPG
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
HKLM\...\StartupApproved\Run: => "Focusrite Notifier"
HKLM\...\StartupApproved\Run32: => "Zwift"
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{896FB7AB-F868-445B-8E70-047C3B351511}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{3E5A8DF4-ADA6-4195-9AF2-400C686151F1}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{544138B3-5472-404B-8866-B2ACDECDFB87}] => (Allow) C:\Users\info\Downloads\win-ts3400-1_3-n_mcd\win\MSetup64.exe => No File
FirewallRules: [{B19D1D19-2AF5-46CE-9650-675C49D45F4B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ticket to Ride\Ticket to Ride.exe (Days of Wonder, Inc.) [File not signed]
FirewallRules: [{D2E10484-C3F2-4B94-ADFA-CBEABDD252D0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ticket to Ride\Ticket to Ride.exe (Days of Wonder, Inc.) [File not signed]
FirewallRules: [{057C2CC6-259D-4D9A-81C5-E84DFC61737E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Carcassonne The Official Board Game\Carcassonne.exe () [File not signed]
FirewallRules: [{9140BF03-E70F-4335-86C1-8F3D9458F96E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Carcassonne The Official Board Game\Carcassonne.exe () [File not signed]
FirewallRules: [UDP Query User{355494F5-6EB0-4674-B0BE-26B76845D098}C:\program files (x86)\zwift\zwiftapp.exe] => (Allow) C:\program files (x86)\zwift\zwiftapp.exe (Zwift, Inc. -> )
FirewallRules: [TCP Query User{B7A35808-C55B-4559-9525-401AA0D8757D}C:\program files (x86)\zwift\zwiftapp.exe] => (Allow) C:\program files (x86)\zwift\zwiftapp.exe (Zwift, Inc. -> )
FirewallRules: [UDP Query User{0BFFD11C-097D-45BE-B309-032B8699DA93}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File
FirewallRules: [TCP Query User{39DA58D4-D436-4B6C-A4B1-099C7F7C9450}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File
FirewallRules: [UDP Query User{97A73D71-B224-44B7-B341-9C2A89E2143D}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File
FirewallRules: [TCP Query User{316FC8A6-2536-4032-BCD9-04544B5BA476}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File
FirewallRules: [{8572A005-A524-4BA0-B168-CC33AED09624}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Scythe Digital Edition\Scythe.exe () [File not signed]
FirewallRules: [{7FE449E0-815D-4E85-AB20-6F4324D2A5E2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Scythe Digital Edition\Scythe.exe () [File not signed]
FirewallRules: [UDP Query User{693EFBB5-FACE-441F-B77A-8A0CB015DEAB}C:\users\info\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\info\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{6BA16B67-C888-49E3-9E5D-F53B909A0A64}C:\users\info\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\info\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1850A575-8881-433A-B13B-823F459EE9D1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Wingspan\Wingspan.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [{1166B07A-301B-4591-B707-1701110FEA2E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Wingspan\Wingspan.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [{A2B03916-42B4-475A-875C-37075807E0CF}] => (Allow) C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe => No File
FirewallRules: [{F84E06AD-DF39-4246-B897-AEFFA775CB19}] => (Allow) C:\Users\info\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{76A471F4-8A4D-4441-91C4-69C7A1AC0FF9}] => (Allow) C:\Users\info\AppData\Roaming\Zoom\bin\Zoom.exe => No File
FirewallRules: [UDP Query User{4FD0DDE7-71AC-467D-8013-C027C8DB1EF7}C:\users\info\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\info\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{3CCBFA1B-F909-43B5-A74B-303876364292}C:\users\info\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\info\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9E660CB0-1F71-4E89-93C8-9813722C710E}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{C8F02751-0B29-4254-942D-A2FAC1997446}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [TCP Query User{3F04446E-F962-47AB-9C6C-F2F05E162491}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [UDP Query User{D7A57D79-EA19-4369-B805-4305DD44F7DF}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [{66E45CC8-6D69-4B65-B269-AAFF7B717E88}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{23CB10F3-4C1D-437F-BF8C-4478229F6CAF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D9F26FFC-7A26-4DB7-8919-723F1180F43C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1ADEEF01-A616-4651-85AF-924BA15D728D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{65A24EE6-36B9-4241-992E-E3AC920513C7}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [UDP Query User{ED247984-0BA4-485F-B684-ADD75B9D7C96}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [{E9A26FA7-FA22-4B00-A436-7EE59DBEC211}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{D32E50BC-D28B-447A-9923-EB9046795962}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{D6F0D809-38F0-4BE8-9251-C944DF978506}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{B8BFC2A3-1F96-4A73-9340-160BD70ACD7E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{5FA50336-0910-4BC1-A4C3-68229F564BA5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{E35E223D-54A4-4302-8C53-A73304FD53A4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [TCP Query User{11FA1CAA-D45F-4EEE-862B-6D8486EAD29B}C:\program files (x86)\zwift\zwiftapp.exe] => (Allow) C:\program files (x86)\zwift\zwiftapp.exe (Zwift, Inc. -> )
FirewallRules: [UDP Query User{A8AB8CBF-BCA2-43FD-B306-BBDBB6CB459B}C:\program files (x86)\zwift\zwiftapp.exe] => (Allow) C:\program files (x86)\zwift\zwiftapp.exe (Zwift, Inc. -> )
FirewallRules: [{5D5B44B6-EED9-4FE8-A410-BE37F6C3257D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blood Bowl 3\BB3.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{6E76A8AC-6449-4828-AF91-EAFD15C6A3B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blood Bowl 3\BB3.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{064DDDD9-640C-4D91-88F8-1299BD6DA804}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{B056385D-A065-480E-A3EB-481D7D351F89}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{0F7E2278-F57C-4007-ABB8-B734AF21602E}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{6C555034-6DA4-4699-B190-1CDF328BA59F}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{154D2EC3-110F-4556-A49E-CE4CCDF2AF9A}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{B48A9AC2-AA62-4301-AC57-DC28E0F05D9B}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{0CBCC94E-8CA8-4909-A49C-FD59846BFC2B}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{D5B59D6A-80BC-4334-80F7-2564AB0C3E22}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12129.4.57066.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{9FECAD59-570B-4E08-87B7-33C74D4399FD}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTeK COMPUTER INC.)
FirewallRules: [{6ADE9A78-19F6-473D-88E0-7C8218CD54DB}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTeK COMPUTER INC.)
FirewallRules: [{60EDD709-1DC5-461A-9BB6-98680D4F7873}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTeK COMPUTER INC.)
FirewallRules: [{48F37BE0-DFEC-4805-AD6D-2C7A2281A8FD}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.20.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTeK COMPUTER INC.)
FirewallRules: [{824740D6-FC9F-41A5-AF71-464D06F0B418}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{E62BA368-2D55-4EBE-B16D-F904C8AFA45B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{FABC4701-DD29-4F21-945E-91BDF9D5B9D6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{8AF28E44-8BAB-478D-9B0A-9043CB029876}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2E322E3C-5A21-409F-AD77-AC87E9021E77}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B48B7E43-952F-46EE-9840-46C0100E6DF2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{3FCC5914-9F5B-4756-A468-80AF88204551}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{7EB3904F-BB21-49C5-BEFE-E750AFAFF1C7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2BFCD96D-D10E-4263-885F-C56717CA6B41}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{6B3F178B-F7BB-4E72-A7D5-091CABC32725}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{8A9D42F8-DCD7-44B0-9D4A-EE5CAF729995}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\114.0.1823.58\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F9755E66-1277-4034-91C7-BA4CC61BBF5F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.16501.20210.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6918DCD1-C8B7-4401-AD9C-8852F3BFBCB9}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSLinkRemote\AsusLinkRemoteAgent.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​)
FirewallRules: [{3AB21348-589C-493E-87DE-83688B462655}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSLinkRemote\AsusLinkRemoteAgent.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.​)
FirewallRules: [{A535B0D5-FD9C-4D4B-AD78-FC077DE9FC47}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSLinkNear\AsusLinkNear.exe (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
FirewallRules: [{8D2B958D-086B-4E22-B49C-8169A0D83800}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSwitch\AsusSwitchNet.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
FirewallRules: [{12FB1093-1913-42AB-A074-CA3381CFE90B}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci.inf_amd64_fc4a043093a77fa3\ASUSSwitch\AsusSwitchNetMDNS.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
FirewallRules: [{DF4B0383-CBA5-4BF1-B0F6-03292F669246}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{26C216A5-7A95-4C03-A668-EA7D99121388}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23119.304.2165.4533_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FAC23CFA-5E02-4724-9A82-9CAFAAE29C14}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23119.304.2165.4533_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
 
==================== Restore Points =========================
 
21-06-2023 14:17:32 Gepland controlepunt
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (06/26/2023 02:50:34 AM) (Source: Application Hang) (EventID: 1002) (User: NT AUTHORITY)
Description: Programma WidgetService.exe versie 0.0.0.0 communiceert niet meer met Windows en is gesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, controleert u de probleemgeschiedenis in het configuratiescherm van Beveiliging en onderhoud.
 
Error: (06/26/2023 02:49:39 AM) (Source: Application Error) (EventID: 1000) (User: LAPTOP-QBAAO188)
Description: Naam van toepassing met fout: OUTLOOK.exe, versie: 16.0.16327.20248, tijdstempel: 0x644cd312
Naam van module met fout: WWLIB.DLL, versie: 16.0.16327.20248, tijdstempel: 0x644cd366
Uitzonderingscode: 0xc0000005
Foutmarge: 0x004636e7
Id van proces met fout: 0x0x4ca0
Starttijd van toepassing met fout: 0x0x1d9a7abd5c97258
Pad naar toepassing met fout: C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.16327.20248.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe
Pad naar module met fout: C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.16327.20248.0_x86__8wekyb3d8bbwe\Office16\WWLIB.DLL
Rapport-id: f385adaa-29d1-459d-9267-33dc7de27e38
Volledige pakketnaam met fout: Microsoft.Office.Desktop_16051.16327.20248.0_x86__8wekyb3d8bbwe
Relatieve toepassings-id van pakket met fout: Outlook
 
Error: (06/19/2023 04:31:14 PM) (Source: VSS) (EventID: 12298) (User: )
Description: Fout in de Volume Shadow Copy-service: de I/O-schrijfbewerkingen kunnen niet worden vastgelegd tijdens het maken van de schaduwkopie op volume \\?\Volume{584bea99-6542-4539-9603-0e057ba53116}\.
De volume-index in de set met schaduwkopieën is 0. Foutdetails: Openen [0x00000000, De bewerking is voltooid.
], Leegmaken[0x00000000, De bewerking is voltooid.
], Vrijgeven[0x80042314, Er heeft een time-out bij de provider van schaduwkopieën plaats gevonden bij het opslaan van schrijfbewerkingen op het volume waarvan een schaduwkopie wordt gemaakt. Dit komt waarschijnlijk door overmatige activiteit op het volume, veroorzaakt door een toepassing of systeemservice. Probeer het opnieuw zodra de activiteit op het volume is verminderd.
], Uitvoeren[0x00000000, De bewerking is voltooid.
].
 
 
Bewerking:
   Asynchrone bewerking uitvoeren
 
Context:
   Huidige status: DoSnapshotSet
 
Error: (05/19/2023 09:39:21 PM) (Source: Microsoft-Windows-AppModel-State) (EventID: 12) (User: LAPTOP-QBAAO188)
Description: Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy-2147023878
 
Error: (05/18/2023 05:20:13 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine CoCreateInstance.  hr = 0x8007045b, Systeem wordt afgesloten.
.
 
Error: (05/18/2023 05:20:13 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informatie voor de Volume Shadow Copy-service: de COM-server met CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} en de naam CEventSystem kan niet worden gestart. [0x8007045b, Systeem wordt afgesloten.
]
 
Error: (05/18/2023 05:20:13 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine CoCreateInstance.  hr = 0x8007045b, Systeem wordt afgesloten.
.
 
Error: (05/18/2023 05:20:13 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informatie voor de Volume Shadow Copy-service: de COM-server met CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} en de naam CEventSystem kan niet worden gestart. [0x8007045b, Systeem wordt afgesloten.
]
 
 
System errors:
=============
Error: (06/28/2023 02:37:58 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-QBAAO188)
Description: De server {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.
 
Error: (06/28/2023 06:22:45 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-QBAAO188)
Description: De server {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} heeft zich niet binnen de vereiste termijn bij DCOM geregistreerd.
 
Error: (06/25/2023 07:46:30 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: 9MSSGKG348SP-MicrosoftWindows.Client.WebExperience.
 
Error: (06/25/2023 07:46:27 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: ApplicationSet-CFQ7TTC0K56C-Microsoft.Office.Desktop.
 
Error: (06/25/2023 07:46:23 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop.
 
Error: (06/25/2023 07:46:22 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: 9NCBCSZSJRSB-SpotifyAB.SpotifyMusic.
 
Error: (06/24/2023 07:38:00 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: 9MSSGKG348SP-MicrosoftWindows.Client.WebExperience.
 
Error: (06/24/2023 07:38:00 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80073d02: ApplicationSet-CFQ7TTC0K56C-Microsoft.Office.Desktop.
 
 
CodeIntegrity:
===============
Date: 2023-06-28 15:06:07
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Windows signing level requirements. 
 
Date: 2023-06-28 14:35:52
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Windows signing level requirements. 
 
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. X430FA.308 05/28/2019
Motherboard: ASUSTeK COMPUTER INC. X430FA
Processor: Intel® Core™ i5-8265U CPU @ 1.60GHz
Percentage of memory in use: 82%
Total physical RAM: 8043.61 MB
Available physical RAM: 1388 MB
Total Virtual: 9579.61 MB
Available Virtual: 1787.46 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:237.42 GB) (Free:58.44 GB) (Model: INTEL SSDSCKKW256G8) NTFS
 
\\?\Volume{54e95cf9-9493-4202-8beb-a6fc7d552267}\ (RECOVERY) (Fixed) (Total:0.78 GB) (Free:0.16 GB) NTFS
\\?\Volume{f0180894-28fc-4771-89f4-efa7f35c2201}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 9929D3AC)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

  • 0

#8
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,422 posts

Hi, Dave.
 
Better to post a new post instead of editing a previous one. So... all is good now. Thanks for running FRST again.
 
Although I usually leave the specific subject at the end, I'll reply now for the following:
 

Also some advice on the best Anti-Virus software would be apreciated but only necessary in the end of the journey I just started.

 
Things changed since Windows 10 was introduced. The integrated security platform, with the Windows Defender antivirus, is good enough to protect the ordinary user. Many of the experts recommend it rather than any other antivirus, especially the free versions, which actually became very annoying by pushing the users to buy the paid versions. Personally, I have Windows Defender as my primary antivirus solution, together with Malwarebytes Premium. Although I am very happy with it, I'll not push a user to do the same if they want to use any other security platform. But considering the RAM in use in your case (above 80%), I would consider uninstalling AVG to release resources. Your computer, your choice, of course. But think about it and let me know.
 
Before I give my instructions:

Please, adhere to the guidelines below, and then carefully follow, with the same order, all the instructions after:

1. Always ask before acting. Do not continue if you are not sure, or if something unexpected happens!

2. Do not run any tools unless instructed to do so. Also, do not uninstall or install any software during the procedure, unless I ask you to do so.

3. Cracked or pirated programs are not only illegal, but also can make your computer a malware target. Having such programs installed, is the easiest way to get infected. Thus, no need to clean the computer, since, soon or later, it will get infected again. If you have such programs, please uninstall them now, before we start the cleaning procedure.

4. If your computer seems to start working normally, don't abandon the topic. Even if your system is behaving normally, there may still be some malware remnants left over. Additionally, malware can re-infect the computer if some remnants are left. Therefore, please complete all requested steps to make sure any malware is successfully eradicated from your PC.

5. You have to reply to my posts within 3 days. If you need some additional time, just let me know. Otherwise, I will leave the topic due to lack of feedback. If you are able, I would request you to check this thread at least once per day so that we can resolve your issues effectively and efficiently.

6. Logs from malware diagnostic or removal programs can take some time to get analyzed. Also, have in mind that all the experts here are volunteers and may not be available to assist when you post. Please, be patient, while I analyze your logs.
 
 
================================
 
1. Notifications in Chrome
 
Did you intentionally set these notifications from these sites in Chrome?
 

hxxps://calendar.google.com; 
hxxps://www.letour.fr; 
hxxps://yaktribe.games; 
hxxps://zwiftinsider.com 

 
 
2. FRST fix

Please do the following to run a FRST fix.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start::
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\Run: [Zoom] => [X]
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {00744A9E-E92C-47F4-8259-D94A8B3D6084} - System32\Tasks\MyASUS Update Messenger => C:\Users\info\AppData\Local\MyASUS Update Messenger\UpdateMessenger.exe [13859888 2021-02-22] (SweetLabs Inc. -> SweetLabs, Inc)
Task: {6A981D5A-530A-4167-86F7-883253442715} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe  Display (No File)
Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe  RebootDialog (No File)
Task: {B255D67A-16DB-470B-A090-877FEF048EF5} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery Reboot (No File)
Task: {C1EF45A1-44D2-48F3-862D-DCB5FA3AA96A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe  Display (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File)
Task: {DD42B29C-7F91-4510-9DA7-1A63F55A159D} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC Reboot (No File)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
2023-06-28 06:42 - 2022-09-28 13:30 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
SearchScopes: HKU\S-1-5-21-2140152316-3761713159-350972558-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2140152316-3761713159-350972558-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
FirewallRules: [{544138B3-5472-404B-8866-B2ACDECDFB87}] => (Allow) C:\Users\info\Downloads\win-ts3400-1_3-n_mcd\win\MSetup64.exe => No File
FirewallRules: [UDP Query User{0BFFD11C-097D-45BE-B309-032B8699DA93}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File
FirewallRules: [TCP Query User{39DA58D4-D436-4B6C-A4B1-099C7F7C9450}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File
FirewallRules: [UDP Query User{97A73D71-B224-44B7-B341-9C2A89E2143D}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File
FirewallRules: [TCP Query User{316FC8A6-2536-4032-BCD9-04544B5BA476}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File
FirewallRules: [{A2B03916-42B4-475A-875C-37075807E0CF}] => (Allow) C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe => No File
FirewallRules: [{F84E06AD-DF39-4246-B897-AEFFA775CB19}] => (Allow) C:\Users\info\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{76A471F4-8A4D-4441-91C4-69C7A1AC0FF9}] => (Allow) C:\Users\info\AppData\Roaming\Zoom\bin\Zoom.exe => No File
FirewallRules: [{9E660CB0-1F71-4E89-93C8-9813722C710E}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{C8F02751-0B29-4254-942D-A2FAC1997446}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [TCP Query User{3F04446E-F962-47AB-9C6C-F2F05E162491}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [UDP Query User{D7A57D79-EA19-4369-B805-4305DD44F7DF}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [TCP Query User{65A24EE6-36B9-4241-992E-E3AC920513C7}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [UDP Query User{ED247984-0BA4-485F-B684-ADD75B9D7C96}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
EmptyTemp:
End::
  • Right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Post the log in your next reply.

 

 

3. Run AdwCleaner (scan only)

Download AdwCleaner and save it to your desktop.

  • Double click AdwCleaner.exe to run it.
  • Click Scan Now.
    • When the scan has finished, a Scan Results window will open.
    • Click Cancel (at this point do not attempt to Quarantine anything that is found)
  • Now click the Log Files tab.
    • Double click on the latest scan log (Scan logs have a [S0*] suffix, where * is replaced by a number. The latest scan will have the largest number)
    • A Notepad file will open containing the results of the scan.
    • Please post the contents of the file in your next reply.

 

 

4. Run Malwarebytes (scan only)

  • Download Malwarebytes and save it to your Desktop.
  • Once downloaded, close all programs and Windows on your computer.
  • Double-click on the icon on your desktop named MBSetup.exe. This will start the installation of MBAM onto your computer.
  • Follow the instructions to install the program.
  • When finished, double click the program's icon created on your Desktop.
  • Click the little gear on the top right (Settings) and when it opens, click the Security tab and make sure about the following:
    Under the title Scan Options, all the options are checked.
    Under the title Windows Security Center (Premium only) the option is NOT checked.
    Under the title Potentially unwanted items all options are set to Always.
  • Click on the little gear to return to the main menu and select Scan. The program will start scanning your computer. This may take about 10 minutes, but in some cases it may be take longer.
  • When finished, you will see the Threat Scan Summary window open.
  • If threats are not found, click View Report and proceed to the two last steps below.

    If threats are found, make sure that all threats are not selected, close the program and proceed to the next steps below.
    • Open Malwarebytes again, click on the Scanner, and then on the Reports tab.
    • Find the report with the most recent date and double click on it.
    • Click on Export and then Copy to Clipboard.
    • Paste its content here, in your next reply.

 

 

In your next reply please post:

  1. A reply about AVG 
  2. A reply about the Chrome notifications
  3. The AdwCleaner[S0*].txt
  4. The Malwarebytes report

  • 0

#9
daveBB

daveBB

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

1) on the notifications: not that I know of but apart from the more or less obvious calendar the other sites are sites I more or less frequently visit, depending on the time of the year


  • 0

#10
daveBB

daveBB

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts
Fix result of Farbar Recovery Scan Tool (x64) Version: 28-06-2023
Ran by info (29-06-2023 19:53:17) Run:1
Running from C:\Users\info\Desktop\FRST-OlderVersion
Loaded Profiles: info
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\...\Run: [Zoom] => [X]
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {00744A9E-E92C-47F4-8259-D94A8B3D6084} - System32\Tasks\MyASUS Update Messenger => C:\Users\info\AppData\Local\MyASUS Update Messenger\UpdateMessenger.exe [13859888 2021-02-22] (SweetLabs Inc. -> SweetLabs, Inc)
Task: {6A981D5A-530A-4167-86F7-883253442715} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe  Display (No File)
Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe  RebootDialog (No File)
Task: {B255D67A-16DB-470B-A090-877FEF048EF5} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery Reboot (No File)
Task: {C1EF45A1-44D2-48F3-862D-DCB5FA3AA96A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe  Display (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File)
Task: {DD42B29C-7F91-4510-9DA7-1A63F55A159D} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC Reboot (No File)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
2023-06-28 06:42 - 2022-09-28 13:30 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
SearchScopes: HKU\S-1-5-21-2140152316-3761713159-350972558-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2140152316-3761713159-350972558-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
FirewallRules: [{544138B3-5472-404B-8866-B2ACDECDFB87}] => (Allow) C:\Users\info\Downloads\win-ts3400-1_3-n_mcd\win\MSetup64.exe => No File
FirewallRules: [UDP Query User{0BFFD11C-097D-45BE-B309-032B8699DA93}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File
FirewallRules: [TCP Query User{39DA58D4-D436-4B6C-A4B1-099C7F7C9450}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe => No File
FirewallRules: [UDP Query User{97A73D71-B224-44B7-B341-9C2A89E2143D}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File
FirewallRules: [TCP Query User{316FC8A6-2536-4032-BCD9-04544B5BA476}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe => No File
FirewallRules: [{A2B03916-42B4-475A-875C-37075807E0CF}] => (Allow) C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe => No File
FirewallRules: [{F84E06AD-DF39-4246-B897-AEFFA775CB19}] => (Allow) C:\Users\info\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{76A471F4-8A4D-4441-91C4-69C7A1AC0FF9}] => (Allow) C:\Users\info\AppData\Roaming\Zoom\bin\Zoom.exe => No File
FirewallRules: [{9E660CB0-1F71-4E89-93C8-9813722C710E}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{C8F02751-0B29-4254-942D-A2FAC1997446}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [TCP Query User{3F04446E-F962-47AB-9C6C-F2F05E162491}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [UDP Query User{D7A57D79-EA19-4369-B805-4305DD44F7DF}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [TCP Query User{65A24EE6-36B9-4241-992E-E3AC920513C7}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
FirewallRules: [UDP Query User{ED247984-0BA4-485F-B684-ADD75B9D7C96}C:\program files (x86)\jamulus\jamulus.exe] => (Allow) C:\program files (x86)\jamulus\jamulus.exe => No File
EmptyTemp:
End::
*****************
 
Restore point was successfully created.
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully
"HKU\S-1-5-21-2140152316-3761713159-350972558-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Zoom" => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{00744A9E-E92C-47F4-8259-D94A8B3D6084}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00744A9E-E92C-47F4-8259-D94A8B3D6084}" => removed successfully
C:\WINDOWS\System32\Tasks\MyASUS Update Messenger => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MyASUS Update Messenger" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A981D5A-530A-4167-86F7-883253442715}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A981D5A-530A-4167-86F7-883253442715}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B255D67A-16DB-470B-A090-877FEF048EF5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B255D67A-16DB-470B-A090-877FEF048EF5}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C1EF45A1-44D2-48F3-862D-DCB5FA3AA96A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C1EF45A1-44D2-48F3-862D-DCB5FA3AA96A}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DD42B29C-7F91-4510-9DA7-1A63F55A159D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD42B29C-7F91-4510-9DA7-1A63F55A159D}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully
HKLM\System\CurrentControlSet\Services\WinSetupMon => removed successfully
WinSetupMon => service removed successfully
C:\WINDOWS\system32\Tasks\AVAST Software => moved successfully
"HKU\S-1-5-21-2140152316-3761713159-350972558-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-2140152316-3761713159-350972558-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{544138B3-5472-404B-8866-B2ACDECDFB87}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{0BFFD11C-097D-45BE-B309-032B8699DA93}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{39DA58D4-D436-4B6C-A4B1-099C7F7C9450}C:\program files (x86)\steam\steamapps\common\blood bowl 2\bloodbowl2_dx_32.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{97A73D71-B224-44B7-B341-9C2A89E2143D}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{316FC8A6-2536-4032-BCD9-04544B5BA476}C:\program files (x86)\steam\steamapps\common\blood bowl 2\benchmarkdx11.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A2B03916-42B4-475A-875C-37075807E0CF}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F84E06AD-DF39-4246-B897-AEFFA775CB19}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{76A471F4-8A4D-4441-91C4-69C7A1AC0FF9}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9E660CB0-1F71-4E89-93C8-9813722C710E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C8F02751-0B29-4254-942D-A2FAC1997446}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{3F04446E-F962-47AB-9C6C-F2F05E162491}C:\program files (x86)\jamulus\jamulus.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D7A57D79-EA19-4369-B805-4305DD44F7DF}C:\program files (x86)\jamulus\jamulus.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{65A24EE6-36B9-4241-992E-E3AC920513C7}C:\program files (x86)\jamulus\jamulus.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{ED247984-0BA4-485F-B684-ADD75B9D7C96}C:\program files (x86)\jamulus\jamulus.exe" => removed successfully
 
=========== EmptyTemp: ==========
 
FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 112746390 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 675452714 B
Windows/system/drivers => 5029436 B
Edge => 2858421 B
Chrome => 1535450876 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 6656 B
ProgramData => 6656 B
Public => 6656 B
systemprofile => 6656 B
systemprofile32 => 6656 B
LocalService => 218296 B
NetworkService => 224952 B
info => 262788249 B
 
RecycleBin => 2383360 B
EmptyTemp: => 2.4 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 20:01:12 ====

  • 0

Advertisements


#11
daveBB

daveBB

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts
Excuse for the double (quadruple?) posts, I read through the entire post you made but oversaw the bit about 'one post' that was implied.
Both Malwarebytes - logs follow here (second one edited in):
 
 
 
# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build:    08-30-2022
# Database: 2022-10-10.1 (Cloud)
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    06-29-2023
# Duration: 00:00:05
# OS:       Windows 11 (Build 22621.1848)
# Scanned:  32096
# Detected: 8
 
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
No malicious folders found.
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries found.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs found.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries found.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs found.
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries found.
 
***** [ Preinstalled Software ] *****
 
Preinstalled.ASUSGiftBox   Folder   C:\Program Files (x86)\ASUS\ASUS GIFTBOX SERVICE 
Preinstalled.ASUSGiftBox   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B} 
Preinstalled.ASUSHello   Folder   C:\Program Files (x86)\ASUS\ASUS HELLO 
Preinstalled.ASUSHello   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{267A5359-8F4F-4207-8392-DAC5D6A5A71B}  
Preinstalled.ASUSHello   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Hello 
Preinstalled.ASUSHello   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{D8CE1923-92A9-4036-817E-9E0D8AA2169B} 
Preinstalled.ASUSHello   Task   C:\Windows\System32\Tasks\ASUS HELLO 
Preinstalled.HPTouchSmart   File   C:\Users\info\Desktop\Netflix.lnk 
 
 
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
 
 
 
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 6/29/23
Scan Time: 10:55 PM
Log File: 41a50c06-16bf-11ee-8b49-dcf505202552.json
 
-Software Information-
Version: 4.5.32.271
Components Version: 1.0.2051
Update Package Version: 1.0.71715
License: Trial
 
-System Information-
OS: Windows 11 (Build 22621.1848)
CPU: x64
File System: NTFS
User: LAPTOP-QBAAO188\info
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 241883
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 2 min, 4 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)

Edited by daveBB, 29 June 2023 - 03:02 PM.

  • 0

#12
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,422 posts

Dave,
 
The good thing is that no bad items detected. The only detected items by AdwCleaner have to do with software that was apparently installed when the device was new, which you may or may not use. Personally, I do not keep anything I don't use/need. But it's your computer, so your decision.

So, if you would like to remove the preinstalled software, please do the following:

  • Double click AdwCleaner.exe on your Desktop, to run it as you did before.
  • Click Scan Now.
  • When the scan has finished a Scan Results window will open.
  • Please check all the boxes and then click Quarantine.
  • Click Next.
    • If any pre-installed software was found on your machine, a prompt window will open. Click OK to close it.
    • Check any pre-installed software items you want to remove.
    • Click Quarantine.
  • A prompt to save your work will appear.
    • Click Continue when you're ready to proceed.
  • A prompt to restart your computer will appear.
    • Click Restart Now.
  • Once your computer has restarted:
    • If it doesn't open automatically, please start AdwCleaner.
    • Click the Log Files tab.
    • Double click on the latest Clean log (Clean logs have a [C0*] suffix, where * is replaced by a number, the latest scan will have the largest number)
    • A Notepad file will open containing the results of the removal.
    • Please post the contents of the file in your next reply.

 

Next step:
 
 
1. FRST fix

Please do the following to run a FRST fix.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start::
CMD: DISM /Online /Cleanup-Image /RestoreHealth
CMD: SFC /scannow
End::
  • Right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Post the log in your next reply.

 

 

2. Fresh FRST logs

  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produce two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach these two logs in your next reply.

 

 

In your next reply please post:

  • What did you decide to do with the preinstalled software. If you removed it, please post the AdwCleaner[C0*].txt
  • The fixlog.txt
  • The 2 fresh FRST logs, Addition and FRST
  • Feedback: how is the computer running? Any remaining issues/questions/concerns? 

  • 0

#13
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,422 posts

Hi, Dave. Still with me? 


  • 0

#14
daveBB

daveBB

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

yes, coming in now


  • 0

#15
daveBB

daveBB

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts
# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build:    08-30-2022
# Database: 2022-10-10.1 (Cloud)
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    07-03-2023
# Duration: 00:00:01
# OS:       Windows 11 (Build 22621.1848)
# Cleaned:  8
# Awaiting reboot:1
# Failed:   0
 
 
***** [ Services ] *****
 
No malicious services cleaned.
 
***** [ Folders ] *****
 
No malicious folders cleaned.
 
***** [ Files ] *****
 
No malicious files cleaned.
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks cleaned.
 
***** [ Registry ] *****
 
No malicious registry entries cleaned.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries cleaned.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs cleaned.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries cleaned.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs cleaned.
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries cleaned.
 
***** [ Preinstalled Software ] *****
 
Deleted       Preinstalled.ASUSGiftBox   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B}
Deleted       Preinstalled.ASUSHello   Folder   C:\Program Files (x86)\ASUS\ASUS HELLO
Deleted       Preinstalled.ASUSHello   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{267A5359-8F4F-4207-8392-DAC5D6A5A71B} 
Deleted       Preinstalled.ASUSHello   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Hello
Deleted       Preinstalled.ASUSHello   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{D8CE1923-92A9-4036-817E-9E0D8AA2169B}
Deleted       Preinstalled.ASUSHello   Task   C:\Windows\System32\Tasks\ASUS HELLO
Deleted       Preinstalled.HPTouchSmart   File   C:\Users\info\Desktop\Netflix.lnk
Needs Reboot  Preinstalled.ASUSGiftBox   Folder   C:\Program Files (x86)\ASUS\ASUS GIFTBOX SERVICE
 
 
*************************
 
[+] Delete Tracing Keys
[+] Reset Winsock
 
*************************
 
***** Reboot Required to Complete *****
 
 
***** [ Folders ] *****
 
Cleaning failed   C:\Program Files (x86)\ASUS\ASUS GIFTBOX SERVICE
 
*************************
 
AdwCleaner[S00].txt - [2263 octets] - [29/06/2023 22:36:49]
AdwCleaner[S01].txt - [2324 octets] - [03/07/2023 14:08:10]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########
 
 
 
 
 
 
 
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 28-06-2023
Ran by info (03-07-2023 14:13:22) Run:2
Running from C:\Users\info\Desktop\FRST-OlderVersion
Loaded Profiles: info
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CMD: DISM /Online /Cleanup-Image /RestoreHealth
CMD: SFC /scannow
End::
*****************
 
 
========= DISM /Online /Cleanup-Image /RestoreHealth =========
 
 
Deployment Image Servicing and Management tool
Version: 10.0.22621.1
 
Image Version: 10.0.22621.1848
 
 
[==                         3.8%                           ] 
 
[==                         4.3%                           ] 
 
[==                         4.8%                           ] 
 
[===                        5.5%                           ] 
 
[===                        6.5%                           ] 
 
[===                        6.7%                           ] 
 
[====                       7.5%                           ] 
 
[====                       8.5%                           ] 
 
[=====                      9.4%                           ] 
 
[======                     10.4%                          ] 
 
[======                     11.3%                          ] 
 
[=======                    12.3%                          ] 
 
[=======                    13.2%                          ] 
 
[========                   14.2%                          ] 
 
[========                   15.2%                          ] 
 
[=========                  15.9%                          ] 
 
[=========                  16.7%                          ] 
 
[=========                  17.1%                          ] 
 
[==========                 17.5%                          ] 
 
[==========                 18.0%                          ] 
 
[==========                 18.3%                          ] 
 
[==========                 18.4%                          ] 
 
[==========                 18.6%                          ] 
 
[===========                19.2%                          ] 
 
[===========                19.8%                          ] 
 
[============               20.8%                          ] 
 
[============               21.8%                          ] 
 
[=============              22.8%                          ] 
 
[=============              23.5%                          ] 
 
[==============             24.5%                          ] 
 
[==============             25.4%                          ] 
 
[===============            26.4%                          ] 
 
[===============            27.2%                          ] 
 
[================           28.2%                          ] 
 
[================           29.1%                          ] 
 
[=================          29.6%                          ] 
 
[=================          30.6%                          ] 
 
[==================         31.2%                          ] 
 
[==================         31.5%                          ] 
 
[==================         31.8%                          ] 
 
[==================         32.1%                          ] 
 
[==================         32.5%                          ] 
 
[===================        32.8%                          ] 
 
[===================        32.9%                          ] 
 
[===================        33.1%                          ] 
 
[===================        33.4%                          ] 
 
[===================        33.7%                          ] 
 
[===================        34.0%                          ] 
 
[====================       34.9%                          ] 
 
[====================       34.9%                          ] 
 
[====================       35.8%                          ] 
 
[====================       35.8%                          ] 
 
[=====================      36.8%                          ] 
 
[=====================      37.7%                          ] 
 
[======================     38.3%                          ] 
 
[======================     38.7%                          ] 
 
[======================     39.4%                          ] 
 
[=======================    39.8%                          ] 
 
[=======================    40.8%                          ] 
 
[========================   41.7%                          ] 
 
[========================   42.7%                          ] 
 
[=========================  43.7%                          ] 
 
[=========================  44.7%                          ] 
 
[========================== 45.7%                          ] 
 
[===========================46.6%                          ] 
 
[===========================47.6%                          ] 
 
[===========================48.6%                          ] 
 
[===========================49.6%                          ] 
 
[===========================50.6%                          ] 
 
[===========================51.5%                          ] 
 
[===========================52.2%                          ] 
 
[===========================52.2%                          ] 
 
[===========================52.2%                          ] 
 
[===========================52.3%                          ] 
 
[===========================52.4%                          ] 
 
[===========================52.5%                          ] 
 
[===========================52.5%                          ] 
 
[===========================52.6%                          ] 
 
[===========================52.7%                          ] 
 
[===========================52.7%                          ] 
 
[===========================52.8%                          ] 
 
[===========================52.8%                          ] 
 
[===========================52.9%                          ] 
 
[===========================52.9%                          ] 
 
[===========================53.0%                          ] 
 
[===========================53.0%                          ] 
 
[===========================53.1%                          ] 
 
[===========================53.1%                          ] 
 
[===========================53.2%                          ] 
 
[===========================53.3%                          ] 
 
[===========================53.3%                          ] 
 
[===========================53.3%                          ] 
 
[===========================53.4%                          ] 
 
[===========================53.4%                          ] 
 
[===========================53.4%                          ] 
 
[===========================53.5%                          ] 
 
[===========================53.6%                          ] 
 
[===========================53.7%                          ] 
 
[===========================53.9%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.1%                          ] 
 
[===========================54.2%                          ] 
 
[===========================54.2%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.4%                          ] 
 
[===========================54.5%                          ] 
 
[===========================54.5%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.7%                          ] 
 
[===========================54.8%                          ] 
 
[===========================54.8%                          ] 
 
[===========================54.9%                          ] 
 
[===========================54.9%                          ] 
 
[===========================55.0%                          ] 
 
[===========================55.0%                          ] 
 
[===========================55.1%                          ] 
 
[===========================55.2%                          ] 
 
[===========================55.3%                          ] 
 
[===========================55.5%                          ] 
 
[===========================55.5%                          ] 
 
[===========================55.6%                          ] 
 
[===========================55.7%                          ] 
 
[===========================55.8%                          ] 
 
[===========================55.8%                          ] 
 
[===========================56.0%                          ] 
 
[===========================56.0%                          ] 
 
[===========================56.1%                          ] 
 
[===========================56.3%                          ] 
 
[===========================56.5%                          ] 
 
[===========================57.5%=                         ] 
 
[===========================58.5%=                         ] 
 
[===========================59.0%==                        ] 
 
[===========================59.0%==                        ] 
 
[===========================59.8%==                        ] 
 
[===========================62.3%====                      ] 
 
[===========================77.4%============              ] 
 
[===========================84.9%=================         ] 
 
[==========================100.0%==========================] 
The restore operation completed successfully.
The operation completed successfully.
 
 
========= End of CMD: =========
 
 
========= SFC /scannow =========
 
 
Beginning system scan.  This process will take some time.
 
Beginning verification phase of system scan.
 
Verification 0% complete.
Verification 1% complete.
Verification 1% complete.
Verification 2% complete.
Verification 2% complete.
Verification 3% complete.
Verification 3% complete.
Verification 4% complete.
Verification 4% complete.
Verification 5% complete.
Verification 6% complete.
Verification 6% complete.
Verification 7% complete.
Verification 7% complete.
Verification 8% complete.
Verification 8% complete.
Verification 9% complete.
Verification 9% complete.
Verification 10% complete.
Verification 11% complete.
Verification 11% complete.
Verification 12% complete.
Verification 12% complete.
Verification 13% complete.
Verification 13% complete.
Verification 14% complete.
Verification 14% complete.
Verification 15% complete.
Verification 16% complete.
Verification 16% complete.
Verification 17% complete.
Verification 17% complete.
Verification 18% complete.
Verification 18% complete.
Verification 19% complete.
Verification 19% complete.
Verification 20% complete.
Verification 20% complete.
Verification 21% complete.
Verification 22% complete.
Verification 22% complete.
Verification 23% complete.
Verification 23% complete.
Verification 24% complete.
Verification 24% complete.
Verification 25% complete.
Verification 25% complete.
Verification 26% complete.
Verification 27% complete.
Verification 27% complete.
Verification 28% complete.
Verification 28% complete.
Verification 29% complete.
Verification 29% complete.
Verification 30% complete.
Verification 30% complete.
Verification 31% complete.
Verification 32% complete.
Verification 32% complete.
Verification 33% complete.
Verification 33% complete.
Verification 34% complete.
Verification 34% complete.
Verification 35% complete.
Verification 35% complete.
Verification 36% complete.
Verification 36% complete.
Verification 37% complete.
Verification 38% complete.
Verification 38% complete.
Verification 39% complete.
Verification 39% complete.
Verification 40% complete.
Verification 40% complete.
Verification 41% complete.
Verification 41% complete.
Verification 42% complete.
Verification 43% complete.
Verification 43% complete.
Verification 44% complete.
Verification 44% complete.
Verification 45% complete.
Verification 45% complete.
Verification 46% complete.
Verification 46% complete.
Verification 47% complete.
Verification 48% complete.
Verification 48% complete.
Verification 49% complete.
Verification 49% complete.
Verification 50% complete.
Verification 50% complete.
Verification 51% complete.
Verification 51% complete.
Verification 52% complete.
Verification 53% complete.
Verification 53% complete.
Verification 54% complete.
Verification 54% complete.
Verification 55% complete.
Verification 55% complete.
Verification 56% complete.
Verification 56% complete.
Verification 57% complete.
Verification 57% complete.
Verification 58% complete.
Verification 59% complete.
Verification 59% complete.
Verification 60% complete.
Verification 60% complete.
Verification 61% complete.
Verification 61% complete.
Verification 62% complete.
Verification 62% complete.
Verification 63% complete.
Verification 64% complete.
Verification 64% complete.
Verification 65% complete.
Verification 65% complete.
Verification 66% complete.
Verification 66% complete.
Verification 67% complete.
Verification 67% complete.
Verification 68% complete.
Verification 69% complete.
Verification 69% complete.
Verification 70% complete.
Verification 70% complete.
Verification 71% complete.
Verification 71% complete.
Verification 72% complete.
Verification 72% complete.
Verification 73% complete.
Verification 73% complete.
Verification 74% complete.
Verification 75% complete.
Verification 75% complete.
Verification 76% complete.
Verification 76% complete.
Verification 77% complete.
Verification 77% complete.
Verification 78% complete.
Verification 78% complete.
Verification 79% complete.
Verification 80% complete.
Verification 80% complete.
Verification 81% complete.
Verification 81% complete.
Verification 82% complete.
Verification 82% complete.
Verification 83% complete.
Verification 83% complete.
Verification 84% complete.
Verification 85% complete.
Verification 85% complete.
Verification 86% complete.
Verification 86% complete.
Verification 87% complete.
Verification 87% complete.
Verification 88% complete.
Verification 88% complete.
Verification 89% complete.
Verification 90% complete.
Verification 90% complete.
Verification 91% complete.
Verification 91% complete.
Verification 92% complete.
Verification 92% complete.
Verification 93% complete.
Verification 93% complete.
Verification 94% complete.
Verification 94% complete.
Verification 95% complete.
Verification 96% complete.
Verification 96% complete.
Verification 97% complete.
Verification 97% complete.
Verification 98% complete.
Verification 98% complete.
Verification 99% complete.
Verification 99% complete.
Verification 100% complete.
 
Windows Resource Protection found corrupt files and successfully repaired them.
For online repairs, details are included in the CBS log file located at
windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline
repairs, details are included in the log file provided by the /OFFLOGFILE flag.
 
 
========= End of CMD: =========
 
 
==== End of Fixlog 14:33:05 ====

  • 0






Similar Topics

2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP