SFC/Scannow & Dism.../RestoreHealth Failure

Hey, Just to let you know, as of tomorrow morning, I'm going wild camping, therefore I won't have access to my laptop until Wednesday.
Hiya, I managed to do what you requested...

==================================================
Dump File : 022621-39015-01.dmp
Crash Time : 26/02/2021 00:28:41
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 00000000`00041793
Parameter 2 : fffff6bf`ff51c000
Parameter 3 : 00000000`00000001
Parameter 4 : 00000000`00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\022621-39015-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 26/02/2021 00:30:11
==================================================

==================================================
Dump File : 022621-39781-01.dmp
Crash Time : 26/02/2021 00:21:17
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 00000000`00041201
Parameter 2 : fffff6bf`fc17d368
Parameter 3 : 00730025`00003131
Parameter 4 : ffffe000`4b213500
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\022621-39781-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 26/02/2021 00:22:50
==================================================

==================================================
Dump File : 022621-59750-01.dmp
Crash Time : 26/02/2021 00:03:57
Bug Check String : KERNEL_DATA_INPAGE_ERROR
Bug Check Code : 0x0000007a
Parameter 1 : 00000000`00000004
Parameter 2 : 00000000`00000000
Parameter 3 : ffffe001`28fe5c40
Parameter 4 : ffffc001`9e80712e
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\022621-59750-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 26/02/2021 00:06:03
==================================================

==================================================
Dump File : 022121-41500-01.dmp
Crash Time : 21/02/2021 09:55:17
Bug Check String : KERNEL_DATA_INPAGE_ERROR
Bug Check Code : 0x0000007a
Parameter 1 : 00000000`00000004
Parameter 2 : 00000000`00000000
Parameter 3 : ffffe001`05c957e0
Parameter 4 : 00007ff5`f43df320
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\022121-41500-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 21/02/2021 09:57:04
==================================================

==================================================
Dump File : 021621-45015-01.dmp
Crash Time : 16/02/2021 19:25:31
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : fffff580`10004064
Parameter 2 : 00000000`00000000
Parameter 3 : fffff800`85038c14
Parameter 4 : 00000000`00000008
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\021621-45015-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 16/02/2021 19:26:48
==================================================

==================================================
Dump File : 021621-37656-01.dmp
Crash Time : 16/02/2021 19:08:38
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 00000000`00041201
Parameter 2 : fffff680`59edf040
Parameter 3 : 51313c86`222a4f3b
Parameter 4 : ffffe000`5a72cbf0
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\021621-37656-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 16/02/2021 19:09:55
==================================================

==================================================
Dump File : 021621-37812-01.dmp
Crash Time : 16/02/2021 19:00:49
Bug Check String : NTFS_FILE_SYSTEM
Bug Check Code : 0x00000024
Parameter 1 : 000000b5`00190645
Parameter 2 : ffffd000`709cc928
Parameter 3 : ffffd000`709cc140
Parameter 4 : fffff803`349081ef
Caused By Driver : PCIIDEX.SYS
Caused By Address : PCIIDEX.SYS+14b94ef
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\021621-37812-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,344
Dump File Time : 16/02/2021 19:02:01
==================================================

==================================================
Dump File : 021621-46406-01.dmp
Crash Time : 16/02/2021 16:46:43
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : fffff69c`39481e80
Parameter 2 : 00000000`00000000
Parameter 3 : fffff802`60cd91f3
Parameter 4 : 00000000`00000002
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\021621-46406-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 16/02/2021 16:48:01
==================================================

==================================================
Dump File : 021621-42000-01.dmp
Crash Time : 16/02/2021 16:41:55
Bug Check String : KERNEL_DATA_INPAGE_ERROR
Bug Check Code : 0x0000007a
Parameter 1 : 00000000`00000004
Parameter 2 : 00000000`00000000
Parameter 3 : ffffe000`c6d28010
Parameter 4 : 0000002a`6fbe2de0
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\021621-42000-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 16/02/2021 16:43:43
==================================================

==================================================
Dump File : 021621-43968-01.dmp
Crash Time : 16/02/2021 01:06:12
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 00000000`00041201
Parameter 2 : fffff680`378a8000
Parameter 3 : 175e3900`3a027317
Parameter 4 : ffffe000`0f0912b0
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\021621-43968-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 16/02/2021 01:08:12
==================================================

==================================================
Dump File : 021621-44796-01.dmp
Crash Time : 16/02/2021 00:49:35
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 00000000`00041287
Parameter 2 : 00000000`00000040
Parameter 3 : 00000000`00000000
Parameter 4 : 00000000`00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\021621-44796-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 16/02/2021 00:51:27
==================================================

==================================================
Dump File : 021321-51406-01.dmp
Crash Time : 13/02/2021 02:48:53
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : fffff6c0`d615e698
Parameter 2 : 00000000`00000000
Parameter 3 : fffff803`9be6d1f3
Parameter 4 : 00000000`00000002
Caused By Driver : hal.dll
Caused By Address : hal.dll+6164
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\021321-51406-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 13/02/2021 02:50:49
==================================================

==================================================
Dump File : 020821-47187-01.dmp
Crash Time : 08/02/2021 08:44:10
Bug Check String : CRITICAL_PROCESS_DIED
Bug Check Code : 0x000000ef
Parameter 1 : ffffe000`f23d88c0
Parameter 2 : 00000000`00000000
Parameter 3 : 00000000`00000000
Parameter 4 : 00000000`00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\020821-47187-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 08/02/2021 08:45:56
==================================================

==================================================
Dump File : 020821-45875-01.dmp
Crash Time : 08/02/2021 08:37:45
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : fffff6bb`4b6b3568
Parameter 2 : 00000000`00000000
Parameter 3 : fffff802`6da811f3
Parameter 4 : 00000000`00000002
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\020821-45875-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,344
Dump File Time : 08/02/2021 08:39:25
==================================================

==================================================
Dump File : 020821-36906-01.dmp
Crash Time : 08/02/2021 07:16:41
Bug Check String : SYSTEM_SERVICE_EXCEPTION
Bug Check Code : 0x0000003b
Parameter 1 : 00000000`c0000005
Parameter 2 : fffff800`25c9c1ef
Parameter 3 : ffffd001`bde454b0
Parameter 4 : 00000000`00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\020821-36906-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 08/02/2021 07:17:45
==================================================

==================================================
Dump File : 020821-33203-01.dmp
Crash Time : 08/02/2021 07:13:19
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 00000000`00041201
Parameter 2 : fffff680`20756000
Parameter 3 : 2cc188b2`9d0af309
Parameter 4 : ffffe000`20690830
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\020821-33203-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 08/02/2021 07:14:42
==================================================

==================================================
Dump File : 020821-33281-01.dmp
Crash Time : 08/02/2021 07:07:05
Bug Check String : KERNEL_DATA_INPAGE_ERROR
Bug Check Code : 0x0000007a
Parameter 1 : 00000000`00000004
Parameter 2 : 00000000`00000000
Parameter 3 : ffffe001`f43ca360
Parameter 4 : 00000000`74faa3d0
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\020821-33281-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,344
Dump File Time : 08/02/2021 07:08:18
==================================================

==================================================
Dump File : 012921-47890-01.dmp
Crash Time : 29/01/2021 16:14:34
Bug Check String : KERNEL_DATA_INPAGE_ERROR
Bug Check Code : 0x0000007a
Parameter 1 : 00000000`00000004
Parameter 2 : 00000000`00000000
Parameter 3 : ffffe001`adf4d010
Parameter 4 : 00000000`0b6e700f
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+1404c0
File Description :
Product Name :
Company :
File Version :
Processor : x64
Crash Address : ntoskrnl.exe+1404c0
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\WINDOWS\Minidump\012921-47890-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 9600
Dump File Size : 288,032
Dump File Time : 29/01/2021 16:16:49
==================================================
 
Hi, Rowls1967 ..! Unfortunately there is a hardware problem ..! We will comment on this at a later stage ..!

No working antivirus program is visible in your Security Center ..! For this reason, I will propose to remove AVG AntiVirus as follows:


AVG Remover Tool
  • Please download AVG Remover Tool and save it to your Desktop
  • Right click the icon and select Run as administrator
  • Click Continue on the AVG Remover section
  • If presented with screen saying Run anyway click that button
  • Follow the on screen instructions


Fresh FRST logs
  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach the content of these two logs in your next reply.


In your next reply, please post:

  1. The fresh FRST logs, FRST.txt and Addition.txt
 
Hi, Rowls1967 ..! Unfortunately there is a hardware problem ..! We will comment on this at a later stage ..!

No working antivirus program is visible in your Security Center ..! For this reason, I will propose to remove AVG AntiVirus as follows:


AVG Remover Tool
  • Please download AVG Remover Tool and save it to your Desktop
  • Right click the icon and select Run as administrator
  • Click Continue on the AVG Remover section
  • If presented with screen saying Run anyway click that button
  • Follow the on screen instructions


Fresh FRST logs
  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach the content of these two logs in your next reply.


In your next reply, please post:

  1. The fresh FRST logs, FRST.txt and Addition.txt
Hi Icotonev, here are the reports. I hope that you're having a good day.

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-03-2021
Ran by Richard (14-03-2021 11:11:50)
Running from C:\Users\Richard\Downloads
Windows 8.1 (Update) (X64) (2017-04-22 20:18:23)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3411107159-1070077873-1841525149-500 - Administrator - Disabled)
Guest (S-1-5-21-3411107159-1070077873-1841525149-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3411107159-1070077873-1841525149-1003 - Limited - Enabled)
Richard (S-1-5-21-3411107159-1070077873-1841525149-1001 - Administrator - Enabled) => C:\Users\Richard

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)


==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

aioprnt (HKLM\...\{0645A454-AD44-4F0D-99CF-6B762735AD1F}) (Version: 5.3.1.0 - Eastman Kodak Company) Hidden
aioscnnr (HKLM-x32\...\{376348C2-E372-48BC-A138-E896757BD86A}) (Version: 5.8.10.0 - Your Company Name) Hidden
aioscnnr (HKLM-x32\...\{EF53BFAB-4C10-40DB-A82D-9B07111715C6}) (Version: 7.6.13.10 - Your Company Name) Hidden
AVG AntiVirus FREE (HKLM-x32\...\AVG Antivirus) (Version: 21.1.3164 - AVG Technologies)
AVG Driver Updater (HKLM-x32\...\{BAAB946F-7E00-41F4-BEC7-B8CCF758E012}) (Version: 2.3.0 - AVG Netherlands B.V) Hidden
BrLauncher (HKLM-x32\...\{42D26B47-887C-45FC-BCAE-0BE485C5C0BB}) (Version: 2.0.11.0 - Brother Industries Ltd.) Hidden
BrLogRx (HKLM-x32\...\{190861E7-09C5-42D8-BB4B-0AFB234BCFC1}) (Version: 1.0.3.1 - Brother Industries Ltd.) Hidden
Brother iPrint&Scan (HKLM-x32\...\{0F3243B3-FEA6-44DA-A6A6-4CA42F6A20DF}) (Version: 6.1.3.4 - Brother Industries, Ltd.) Hidden
Brother iPrint&Scan (HKLM-x32\...\{f3688e1e-b3e5-403f-9750-b51816920212}) (Version: 6.1.3.4 - Brother Industries, Ltd.)
Brother PCFax Driver (HKLM-x32\...\{56BA05BD-7A67-4EF8-85A7-8C6528AEE2AC}) (Version: 1.4.0.0 - Brother Industries Ltd.) Hidden
Brother PowerENGAGE (HKLM-x32\...\{05421625-9BA9-482B-ACF2-794221A06F4E}) (Version: 1.0.23 - Aviata, Inc.)
Brother Printer Driver (HKLM-x32\...\{272543B6-B337-4C8F-B9F1-19E884C2C7AC}) (Version: 1.4.0.0 - Brother Industries Ltd.) Hidden
Brother Scanner Driver (HKLM-x32\...\{1162495D-7CE7-4EF9-A0F8-151196F3A660}) (Version: 1.0.17.1 - Brother Industries Ltd.) Hidden
BrSupportTools (HKLM-x32\...\{32F47565-84B1-42CC-B09A-4CDDD9A32F94}) (Version: 1.0.20.0 - Brother Industries Ltd.) Hidden
center (HKLM-x32\...\{56BA241F-580C-43D2-8403-947241AAE633}) (Version: 7.8.0.0 - Eastman Kodak Company) Hidden
ControlCenter4 CSDK (HKLM-x32\...\{FD8A9511-BFC9-43B5-BB75-9CEC0EA03CF0}) (Version: 4.6.1.1 - Brother Industries, Ltd.) Hidden
essentials (HKLM-x32\...\{BE94C681-68E2-4561-8ABC-8D2E799168B4}) (Version: 7.8.0.0 - Eastman Kodak Company) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 89.0.4389.82 - Google LLC)
Google Earth (HKLM-x32\...\{F6430171-B86B-4639-839E-374913E7911D}) (Version: 7.1.8.3036 - Google)
Herramientas de corrección de Microsoft Office 2016: español (HKLM\...\{90160000-001F-0C0A-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
HowToGuide (HKLM-x32\...\{36580EEB-4EDF-4880-BBD4-097E2C645ECD}) (Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
HttpToUsbBridge (HKLM-x32\...\{7BC71E16-6656-4F86-A274-4DF34437975E}) (Version: 1.2.25.1 - Brother Industries Ltd.)
iCare Data Recovery Free (HKLM-x32\...\{43D63B27-661F-428E-97B7-70D0604D28E8}_is1) (Version: 8.0.3 - iCareAll Inc.)
Kodak AIO Printer (HKLM\...\{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}) (Version: 7.8.1.0 - Eastman Kodak Company) Hidden
KODAK AiO Software (HKLM-x32\...\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 7.9.1.1 - Eastman Kodak Company)
Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4048 (HKLM\...\{91415F19-4C22-3609-A105-92ED3522D83C}) (Version: 9.0.30729.4048 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048 (HKLM-x32\...\{5B1F2843-B379-3FF2-B0D3-64DD143ED53A}) (Version: 9.0.30729.4048 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (HKLM-x32\...\{49697869-be8e-427d-81a0-c334d1d14950}) (Version: 14.21.27702.2 - Microsoft Corporation)
NetworkRepairTool (HKLM-x32\...\{86E68F57-FAFE-4052-BDD4-3B90C38236AE}) (Version: 1.2.16.0 - Brother Industries, Ltd.) Hidden
NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version: - )
ocr (HKLM-x32\...\{BFBCF96F-7361-486A-965C-54B17AC35421}) (Version: 6.2.3.50 - Eastman Kodak Company) Hidden
Outils de vérification linguistique 2016 de Microsoft Office - Français (HKLM\...\{90160000-001F-040C-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 14.00.0002 - Nuance Communications, Inc.)
PC-FAXReceive (HKLM-x32\...\{65EA2C86-30CD-444C-ADAB-8762BE4E2E8C}) (Version: 1.8.003.0 - Brother Insutries Ltd.) Hidden
PCFaxTx (HKLM-x32\...\{03BF5A21-6363-410C-B3BE-0946B0012704}) (Version: 3.7.3.1 - Brother Industries Ltd.) Hidden
PowerENGAGE (HKLM-x32\...\{BFE5C68B-E6D4-4421-9ACF-2B8C4BC2D2A1}) (Version: 3.2.13 - Aviata, Inc.) Hidden
PreReq (HKLM-x32\...\{DA5BDB2A-12F0-4343-8351-21AAEB293990}) (Version: 6.2.4.0 - Eastman Kodak Company) Hidden
Private Internet Access (HKLM\...\{33023371-7761-4F81-BBB1-0E0D0D175ACF}) (Version: 2.4.0+05574 - Private Internet Access, Inc.)
Private Internet Access WinTUN Driver (HKLM\...\{0419A0C0-4CC8-459E-9BAE-F3BF5D2E2CCB}) (Version: 1.0 - Private Internet Access, Inc.) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.27055 - Realtek Semiconduct Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8581 - Realtek Semiconductor Corp.)
RemoteSetup (HKLM-x32\...\{FAB8A30A-B074-48F9-9D73-5E9A757403F8}) (Version: 3.10.2.0 - Brother Industries Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.)
ScannerUtilityInstaller (HKLM-x32\...\{5B645FE2-19E9-4B15-B5B2-3D8766F6FA27}) (Version: 1.0.0.0 - Brother) Hidden
SoftwareUpdateNotification (HKLM-x32\...\{F58E9F54-C092-42C5-B4C3-C4B7C337750B}) (Version: 1.0.7.0 - Brother Insutries Ltd.) Hidden
StatusMonitor (HKLM-x32\...\{40578A7A-6E36-457F-A4F0-45BC37EB61FD}) (Version: 1.20.1.0 - Brother Insutries Ltd.) Hidden
Telegram Desktop version 2.5.1 (HKU\S-1-5-21-3411107159-1070077873-1841525149-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 2.5.1 - Telegram FZ-LLC)
Update for Skype for Business 2016 (KB3115087) 64-Bit Edition (HKLM\...\{90160000-0011-0000-1000-0000000FF1CE}_Office16.PROPLUS_{C48D0508-2A21-42EA-8BC9-D387768F54F4}) (Version: - Microsoft)
Update for Skype for Business 2016 (KB3115087) 64-Bit Edition (HKLM\...\{90160000-00C1-0000-1000-0000000FF1CE}_Office16.PROPLUS_{C48D0508-2A21-42EA-8BC9-D387768F54F4}) (Version: - Microsoft)
Update for Skype for Business 2016 (KB3115087) 64-Bit Edition (HKLM\...\{90160000-012B-0409-1000-0000000FF1CE}_Office16.PROPLUS_{C48D0508-2A21-42EA-8BC9-D387768F54F4}) (Version: - Microsoft)
UsbRepairTool (HKLM-x32\...\{F8762A81-32B5-4144-9F3C-9274F515A651}) (Version: 1.4.0.0 - Brother Industries, Ltd.) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.12 - VideoLAN)
WhatsApp (HKU\S-1-5-21-3411107159-1070077873-1841525149-1001\...\WhatsApp) (Version: 2.2106.16 - WhatsApp)

Packages:
=========
Games -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe [2014-11-21] (Microsoft Corporation) [MS Ad]
MSN Food & Drink -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2017-04-23] (Microsoft Corporation) [MS Ad]
MSN Health & Fitness -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2017-04-23] (Microsoft Corporation) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.4.344_x64__8wekyb3d8bbwe [2017-04-23] (Microsoft Corporation) [MS Ad]
MSN News -> C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.4.344_x64__8wekyb3d8bbwe [2017-04-23] (Microsoft Corporation) [MS Ad]
MSN Sport -> C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.345_x64__8wekyb3d8bbwe [2017-04-23] (Microsoft Corporation) [MS Ad]
MSN Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2017-04-23] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.4.350_x64__8wekyb3d8bbwe [2017-04-23] (Microsoft Corporation) [MS Ad]
Music -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_2.6.672.0_x64__8wekyb3d8bbwe [2017-04-23] (Microsoft Corporation) [MS Ad]
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c [2017-04-23] (Skype) [MS Ad]
Video -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_2.6.446.0_x64__8wekyb3d8bbwe [2017-04-23] (Microsoft Corporation) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3411107159-1070077873-1841525149-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation)
ShellIconOverlayIdentifiers: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ShellIconOverlayIdentifiers-x32: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2019-07-30] (IObit Information Technology -> IObit)
ContextMenuHandlers3: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2019-07-30] (IObit Information Technology -> IObit)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-10-10] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\WINDOWS\system32\igfxOSP.dll [2016-10-10] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2019-07-30] (IObit Information Technology -> IObit)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\avgSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avgSP.sys => ""="Driver"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\S-1-5-21-3411107159-1070077873-1841525149-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2019-06-20] (IObit Information Technology -> IObit)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-05-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-05-20] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-05-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-05-20] (Microsoft Corporation -> Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 13:25 - 2019-01-08 02:47 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3411107159-1070077873-1841525149-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Richard\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AdvancedSystemCareService13 => 2
MSCONFIG\Services: AeLookupSvc => 3
MSCONFIG\Services: ALG => 3
MSCONFIG\Services: AppIDSvc => 3
MSCONFIG\Services: AppReadiness => 3
MSCONFIG\Services: AudioEndpointBuilder => 2
MSCONFIG\Services: Audiosrv => 2
MSCONFIG\Services: AVG Tools => 2
MSCONFIG\Services: AxInstSV => 3
MSCONFIG\Services: BDESVC => 3
MSCONFIG\Services: BitDefenderCOM => 2
MSCONFIG\Services: BITS => 2
MSCONFIG\Services: Browser => 3
MSCONFIG\Services: BrYNSvc => 3
MSCONFIG\Services: BthHFSrv => 3
MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: COMSysApp => 3
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: CryptSvc => 2
MSCONFIG\Services: defragsvc => 3
MSCONFIG\Services: DeviceAssociationService => 2
MSCONFIG\Services: DeviceInstall => 3
MSCONFIG\Services: Dhcp => 2
MSCONFIG\Services: DiagTrack => 2
MSCONFIG\Services: Dnscache => 2
MSCONFIG\Services: dot3svc => 3
MSCONFIG\Services: DPS => 2
MSCONFIG\Services: DsmSvc => 3
MSCONFIG\Services: Eaphost => 3
MSCONFIG\Services: EFS => 3
MSCONFIG\Services: EventLog => 2
MSCONFIG\Services: EventSystem => 2
MSCONFIG\Services: Fax => 3
MSCONFIG\Services: fdPHost => 3
MSCONFIG\Services: FDResPub => 3
MSCONFIG\Services: fhsvc => 3
MSCONFIG\Services: FontCache => 2
MSCONFIG\Services: FontCache3.0.0.0 => 3
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: hidserv => 3
MSCONFIG\Services: hkmsvc => 3
MSCONFIG\Services: HomeGroupListener => 3
MSCONFIG\Services: HomeGroupProvider => 3
MSCONFIG\Services: IEEtwCollectorService => 3
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: IKEEXT => 2
MSCONFIG\Services: IObitUnSvr => 2
MSCONFIG\Services: iphlpsvc => 2
MSCONFIG\Services: KeyIso => 3
MSCONFIG\Services: Kodak AiO Network Discovery Service => 2
MSCONFIG\Services: Kodak AiO Status Monitor Service => 2
MSCONFIG\Services: KtmRm => 3
MSCONFIG\Services: LanmanServer => 2
MSCONFIG\Services: LanmanWorkstation => 2
MSCONFIG\Services: lfsvc => 3
MSCONFIG\Services: lltdsvc => 3
MSCONFIG\Services: lmhosts => 2
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: MMCSS => 2
MSCONFIG\Services: MpsSvc => 2
MSCONFIG\Services: MSDTC => 3
MSCONFIG\Services: NcaSvc => 3
MSCONFIG\Services: NcbService => 3
MSCONFIG\Services: NcdAutoSetup => 3
MSCONFIG\Services: Netlogon => 3
MSCONFIG\Services: Netman => 3
MSCONFIG\Services: netprofm => 3
MSCONFIG\Services: NlaSvc => 2
MSCONFIG\Services: nsi => 2
MSCONFIG\Services: ose64 => 3
MSCONFIG\Services: p2pimsvc => 3
MSCONFIG\Services: p2psvc => 3
MSCONFIG\Services: PcaSvc => 2
MSCONFIG\Services: PerfHost => 3
MSCONFIG\Services: pla => 3
MSCONFIG\Services: PlugPlay => 3
MSCONFIG\Services: PNRPAutoReg => 3
MSCONFIG\Services: PNRPsvc => 3
MSCONFIG\Services: PolicyAgent => 3
MSCONFIG\Services: Power => 2
MSCONFIG\Services: PrintNotify => 3
MSCONFIG\Services: PrivateInternetAccessService => 2
MSCONFIG\Services: PrivateInternetAccessWireguard => 3
MSCONFIG\Services: QWAVE => 3
MSCONFIG\Services: RasAuto => 3
MSCONFIG\Services: RasMan => 3
MSCONFIG\Services: RpcLocator => 3
MSCONFIG\Services: SamSs => 2
MSCONFIG\Services: ScDeviceEnum => 3
MSCONFIG\Services: SCPolicySvc => 3
MSCONFIG\Services: seclogon => 3
MSCONFIG\Services: SENS => 2
MSCONFIG\Services: SensrSvc => 3
MSCONFIG\Services: SessionEnv => 3
MSCONFIG\Services: SharedAccess => 3
MSCONFIG\Services: ShellHWDetection => 2
MSCONFIG\Services: smphost => 3
MSCONFIG\Services: Spooler => 2
MSCONFIG\Services: SSDPSRV => 3
MSCONFIG\Services: SstpSvc => 3
MSCONFIG\Services: ss_conn_launcher_service => 3
MSCONFIG\Services: stisvc => 2
MSCONFIG\Services: StorSvc => 3
MSCONFIG\Services: svsvc => 3
MSCONFIG\Services: swprv => 3
MSCONFIG\Services: SysMain => 2
MSCONFIG\Services: TabletInputService => 3
MSCONFIG\Services: TapiSrv => 3
MSCONFIG\Services: TermService => 3
MSCONFIG\Services: Themes => 2
MSCONFIG\Services: THREADORDER => 3
MSCONFIG\Services: TrustedInstaller => 3
MSCONFIG\Services: UI0Detect => 3
MSCONFIG\Services: UmRdpService => 3
MSCONFIG\Services: upnphost => 3
MSCONFIG\Services: USBAppControl => 2
MSCONFIG\Services: VaultSvc => 3
MSCONFIG\Services: vds => 3
MSCONFIG\Services: vmicguestinterface => 3
MSCONFIG\Services: vmicheartbeat => 3
MSCONFIG\Services: vmickvpexchange => 3
MSCONFIG\Services: vmicrdv => 3
MSCONFIG\Services: vmicshutdown => 3
MSCONFIG\Services: vmictimesync => 3
MSCONFIG\Services: vmicvss => 3
MSCONFIG\Services: VSS => 2
MSCONFIG\Services: W32Time => 3
MSCONFIG\Services: wbengine => 3
MSCONFIG\Services: WbioSrvc => 3
MSCONFIG\Services: Wcmsvc => 2
MSCONFIG\Services: wcncsvc => 3
MSCONFIG\Services: WcsPlugInService => 3
MSCONFIG\Services: WdiServiceHost => 3
MSCONFIG\Services: WdiSystemHost => 3
MSCONFIG\Services: WebClient => 3
MSCONFIG\Services: Wecsvc => 3
MSCONFIG\Services: WEPHOSTSVC => 3
MSCONFIG\Services: wercplsupport => 3
MSCONFIG\Services: WerSvc => 3
MSCONFIG\Services: WiaRpc => 3
MSCONFIG\Services: WinHttpAutoProxySvc => 3
MSCONFIG\Services: Winmgmt => 2
MSCONFIG\Services: WinRM => 3
MSCONFIG\Services: WlanSvc => 2
MSCONFIG\Services: wlidsvc => 3
MSCONFIG\Services: wmiApSrv => 3
MSCONFIG\Services: WMPNetworkSvc => 3
MSCONFIG\Services: WorkflowAppControl => 2
MSCONFIG\Services: workfolderssvc => 3
MSCONFIG\Services: WPCSvc => 3
MSCONFIG\Services: WPDBusEnum => 3
MSCONFIG\Services: wscsvc => 2
MSCONFIG\Services: WSearch => 2
MSCONFIG\Services: wuauserv => 3
MSCONFIG\Services: wudfsvc => 3
MSCONFIG\Services: WwanSvc => 3
HKLM\...\StartupApproved\Run: => "EKIJ5000StatusMonitor"
HKLM\...\StartupApproved\Run: => "TuneupUI.exe"
HKLM\...\StartupApproved\Run32: => "EKStatusMonitor"
HKLM\...\StartupApproved\Run32: => "DSATray"
HKLM\...\StartupApproved\Run32: => "ControlCenter4"
HKLM\...\StartupApproved\Run32: => "ISUSPM"
HKLM\...\StartupApproved\Run32: => "PaperPort PTD"
HKLM\...\StartupApproved\Run32: => "EKIJ5000StatusMonitor"
HKU\S-1-5-21-3411107159-1070077873-1841525149-1001\...\StartupApproved\Run: => "AVGBrowserAutoLaunch_8A93C1D26E6679F3B6F436A3F299CCC8"
HKU\S-1-5-21-3411107159-1070077873-1841525149-1001\...\StartupApproved\Run: => "Advanced SystemCare"
HKU\S-1-5-21-3411107159-1070077873-1841525149-1001\...\StartupApproved\Run: => "Adobe Reader Synchronizer"
HKU\S-1-5-21-3411107159-1070077873-1841525149-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_94A469CBA2277F7295F560B121FA07B1"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{DD1A15A1-B23B-496D-828C-29E7D4558070}] => (Allow) LPort=1688
FirewallRules: [{DEEE57D2-A2EA-4964-8E2E-252BDCAEE3C3}] => (Block) LPort=445
FirewallRules: [{76EE6F2B-E7C7-44AE-89E1-5788E5E6B14C}] => (Block) LPort=445
FirewallRules: [{FF3805C2-55BF-42C0-8654-306F8337774F}] => (Allow) LPort=1688
FirewallRules: [{D1B01DC0-E1C9-4B59-A24A-1E4895016F3A}] => (Allow) LPort=9322
FirewallRules: [{4264BA44-9581-4C56-9A04-6E4EF7CE720E}] => (Allow) LPort=5353
FirewallRules: [{1B6EED72-800D-4471-952E-E61E663FC658}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{0737E079-EE02-474E-9FB2-45A5DC809EF1}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{B974E3FC-650A-47DB-9BBC-0530E3261882}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{C31B4A1F-ACBC-4C7B-BFC7-FCCC2EEC030C}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{06476668-F55E-4D2A-861D-549D086C6935}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{00339ADE-2FA0-47E3-B417-FE2BD710DABB}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{074A51E3-D035-45D4-A084-B7F16EA2C6DB}] => (Allow) LPort=54925
FirewallRules: [{81CF8617-2F01-4071-BE89-58D3140A67DF}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe (Brother Industries, Ltd.) [File not signed]
FirewallRules: [{993AF3CF-D964-4CE6-B0EF-F8F447FE9384}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe (Brother Industries, Ltd.) [File not signed]
FirewallRules: [TCP Query User{3CFA0FAC-534E-4A74-BC1A-7C84054B7452}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{4A854861-308D-4F13-94B2-A69479B22ED6}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{E63762B9-801F-482E-A2A9-7C85474D7DB4}] => (Allow) LPort=54950
FirewallRules: [{762BEB76-C88E-407A-BCF1-1B5521E3551D}] => (Allow) LPort=54955
FirewallRules: [{CE6BDCC0-122A-49D2-97EA-F74997C4759D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

Could not list restore points
Check "winmgmt" service or repair WMI.


==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (03/14/2021 10:53:22 AM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.

Error: (03/14/2021 10:52:02 AM) (Source: WorkflowAppControl) (EventID: 32767) (User: )
Description: Wait Workflow Commands request from device.

Error: (03/14/2021 10:52:02 AM) (Source: WorkflowAppControl) (EventID: 32767) (User: )
Description: Start Broadcast Receiver Server...

Error: (03/14/2021 10:52:02 AM) (Source: WorkflowAppControl) (EventID: 32767) (User: )
Description: Start Server...

Error: (03/14/2021 10:52:02 AM) (Source: WorkflowAppControl) (EventID: 32767) (User: )
Description: Start Server...

Error: (03/14/2021 10:52:02 AM) (Source: WorkflowAppControl) (EventID: 32767) (User: )
Description: Host.AddressList[1]: 192.168.1.6

Error: (03/14/2021 10:52:02 AM) (Source: WorkflowAppControl) (EventID: 32767) (User: )
Description: Host.AddressList[0]: fe80::1dab:377f:dad:847%3

Error: (03/14/2021 10:52:02 AM) (Source: WorkflowAppControl) (EventID: 32767) (User: )
Description: Host.AddressList.Length: 2


System errors:
=============
Error: (03/14/2021 10:53:22 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Work Folders service hung on starting.

Error: (03/14/2021 10:51:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Defender Service service failed to start due to the following error:
Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Error: (03/14/2021 10:51:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Defender Network Inspection Service service failed to start due to the following error:
Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Error: (03/14/2021 10:44:54 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Work Folders service hung on starting.

Error: (03/14/2021 10:43:26 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Defender Service service failed to start due to the following error:
Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Error: (03/14/2021 10:43:26 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Defender Network Inspection Service service failed to start due to the following error:
Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Error: (03/14/2021 10:39:41 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Superfetch service terminated with the following error:
The service has not been started.

Error: (03/13/2021 02:39:13 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Work Folders service hung on starting.


Windows Defender:
================
Date: 2017-06-11 14:44:05.806
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2017-06-11 14:32:39.187
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2017-06-11 13:50:33.124
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2017-06-07 02:23:33.175
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2017-05-26 14:46:41.511
Description:
Windows Defender scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2017-06-12 07:15:04.980
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.245.730.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.13804.0
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install.

Date: 2017-06-12 07:15:04.979
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.245.730.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.13804.0
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install.

Date: 2017-06-12 07:15:04.529
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source: User
Signature Type:
Update Type:
Current Engine Version:
Previous Engine Version:
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install.

Date: 2017-06-12 07:15:04.528
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source: User
Signature Type:
Update Type:
Current Engine Version:
Previous Engine Version:
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install.

Date: 2017-06-12 07:14:55.167
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.245.730.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.13804.0
Error code: 0x80240016
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

==================== Memory info ===========================

BIOS: American Megatrends Inc. X550CA.212 08/13/2013
Motherboard: ASUSTeK COMPUTER INC. X550CA
Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz
Percentage of memory in use: 37%
Total physical RAM: 6029.74 MB
Available physical RAM: 3745.83 MB
Total Virtual: 12173.74 MB
Available Virtual: 9626.2 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:371.38 GB) (Free:290.52 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (DATA) (Fixed) (Total:537.8 GB) (Free:536.69 GB) NTFS

\\?\Volume{b81970ed-33f5-4c1e-868a-a9f407dc4092}\ (Recovery) (Fixed) (Total:0.88 GB) (Free:0.77 GB) NTFS
\\?\Volume{2789036b-ad4f-4416-9f8e-e20a9348f31d}\ () (Fixed) (Total:0.44 GB) (Free:0.15 GB) NTFS
\\?\Volume{21b11954-97a1-4a1d-ba35-26ec54f79eda}\ (Restore) (Fixed) (Total:20.01 GB) (Free:7.74 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: FAF3F0E5)

Partition: GPT.

==================== End of Addition.txt =======================



Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-03-2021
Ran by Richard (administrator) on RICHARD (ASUSTeK COMPUTER INC. X550CA) (14-03-2021 11:09:05)
Running from C:\Users\Richard\Downloads
Loaded Profiles: Richard
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\avgToolsSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe <3>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <16>
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft) [File not signed] C:\Program Files (x86)\Brother\iPrint&Scan\USBAppControl.exe
(Microsoft) [File not signed] C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [164608 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-3411107159-1070077873-1841525149-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKLM\...\Windows x64\Print Processors\KODAK EASYSHARE All-in-One Printer: C:\Windows\System32\spool\prtprocs\x64\EKIJ5000PPR.dll [261632 2012-10-08] (Microsoft Windows Hardware Compatibility Publisher -> Eastman Kodak Company)
HKLM\...\Print\Monitors\KODAK EASYSHARE All-in-One Printer: C:\WINDOWS\system32\EKIJ5000MON.dll [805376 2012-10-08] (Microsoft Windows Hardware Compatibility Publisher -> Eastman Kodak Company)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\89.0.4389.82\Installer\chrmstp.exe [2021-03-10] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {3C893D5A-8C9A-4B15-8D4D-2BD4B1C8B9D8} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {47DF9810-F6A2-4B0C-98E4-B70A28CABDF8} - System32\Tasks\{65C3D43E-E5A3-481D-9352-126F2DD99808} => C:\WINDOWS\system32\pcalua.exe -a C:\ProgramData\Kodak\Installer\Setup.exe -c /Web /x "{E0F274B7-592B-4669-8FB8-8D9825A09858}" CompanyName="Eastman Kodak Company" /code "2057"
Task: {5E415433-D5BC-414B-8985-44515AAE6A19} - System32\Tasks\Uninstaller_SkipUac_Richard => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [5900560 2019-09-10] (IObit Information Technology -> IObit)
Task: {644370C0-0F78-4799-A741-525E9EFC74C6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-23] (Google Inc -> Google Inc.)
Task: {73DF959D-C868-4F23-A973-6E80B6A277E2} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [4730624 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Task: {77D7B2E9-D157-4B75-849F-912D477BF1DD} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506384 2019-07-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {8D939978-1C04-4261-9087-B58A7E403F0B} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506384 2019-07-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {B5DFDE52-BF65-47ED-A482-EC4E67E51CF6} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506384 2019-07-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {C1D26FC8-180C-4AE7-9F10-9D30933380A0} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-09] (Adobe Inc. -> Adobe)
Task: {DB5AFBF8-22CC-445E-B842-BB00C6859B44} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1822976 2021-02-23] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {FB4B7999-9C47-4041-973F-5BC9E1CD750E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-23] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\AVG Driver Updater Scan.job => C:\Program Files (x86)\AVG Driver Updater\AVG Driver Updater.exe
Task: C:\WINDOWS\Tasks\AVG Driver Updater Startup.job => C:\Program Files (x86)\AVG Driver Updater\AVG Driver Updater.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{79D1DE68-56FB-4F72-B5E0-FB918DAD2B4C}: [DhcpNameServer] 10.0.0.243
Tcpip\..\Interfaces\{CA17CCC0-C1E3-4678-A9C4-A38235A3F540}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{D33B41AE-F5DB-42CB-8859-CC313193AC99}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\Richard\AppData\Local\Google\Chrome\User Data\Default [2021-03-14]
CHR DownloadDir: C:\Users\Richard\Downloads
CHR Notifications: Default -> hxxps://pirateproxy.cc; hxxps://thepiratebay.org; hxxps://www.electriciansforums.net; hxxps://www.facebook.com; hxxps://www.junglescout.com; hxxps://www.wakeupuk.net; hxxps://www.wish.com
CHR HomePage: Default -> hxxp://mysearch.avg.com?cid={013DF0A8-A4BC-4DD5-B565-06D763B93533}&mid=8743dd459dca47d29dc96da73dc8933a-3c5e627b1624c73ab826fb50cd5d9c87c5579247&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-03-16 09:28:15&v=17.3.1.91&pid=safeguard&sg=&sap=hp
CHR StartupUrls: Default -> "hxxps://www.google.co.uk/"
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab
CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
CHR Extension: (Slides) - C:\Users\Richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
CHR Extension: (DuckDuckGo) - C:\Users\Richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2021-03-14]
CHR Extension: (YouTube) - C:\Users\Richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-23]
CHR Extension: (Sheets) - C:\Users\Richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2021-03-14]
CHR Extension: (Chrome Media Router) - C:\Users\Richard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-03-14]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-09] (Adobe Inc. -> Adobe)
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [622184 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 AVG Tools; C:\Program Files\AVG\Antivirus\avgToolsSvc.exe [353024 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [8091704 2021-03-03] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S4 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [298496 2017-03-22] (Brother Industries, Ltd.) [File not signed]
S3 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [156944 2019-08-23] (IObit Information Technology -> IObit)
S4 PrivateInternetAccessService; C:\Program Files\Private Internet Access\pia-service.exe [1900032 2020-09-04] () [File not signed]
S4 PrivateInternetAccessWireguard; C:\Program Files\Private Internet Access\pia-wgservice.exe [4433920 2020-09-04] () [File not signed]
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182328 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 USBAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\USBAppControl.exe [12288 2020-12-18] (Microsoft) [File not signed]
S2 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
R2 WorkflowAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl.exe [20480 2020-12-18] (Microsoft) [File not signed]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 athr; C:\WINDOWS\system32\DRIVERS\athwbx.sys [4318648 2020-01-04] (Qualcomm Atheros -> Qualcomm Atheros Communications, Inc.)
R3 ATP; C:\WINDOWS\System32\drivers\AsusTP.sys [73512 2015-11-01] (ASUSTeK Computer Inc. -> ASUS Corporation)
R0 avgArDisk; C:\WINDOWS\System32\drivers\avgArDisk.sys [35792 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [208176 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [357400 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [249368 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [98840 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [41424 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [175368 2021-02-23] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [521472 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [107920 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [83496 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [850248 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [465800 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [215464 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [327104 2021-02-18] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-10-30] (Martin Malik - REALiX -> REALiX(tm))
S3 IUFileFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IUFileFilter.sys [25992 2019-07-30] (IObit CO., LTD -> IObit)
S3 IUProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IUProcessFilter.sys [19280 2019-07-30] (IObit CO., LTD -> IObit)
S3 IURegistryFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IURegistryFilter.sys [31648 2019-07-30] (IObit CO., LTD -> IObit)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [14992 2012-08-02] (ASUSTeK Computer Inc. -> )
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166760 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43368 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 tap-pia-0901; C:\WINDOWS\system32\DRIVERS\tap-pia-0901.sys [30720 2020-01-16] (Private Internet Access (London Trust Media Incorporated) -> The OpenVPN Project)
S3 tap0901; C:\WINDOWS\system32\DRIVERS\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
S3 cpuz145; \??\C:\WINDOWS\temp\cpuz145\cpuz145_x64.sys [X]
S3 SWDUMon; \SystemRoot\system32\DRIVERS\SWDUMon.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-03-14 11:07 - 2021-03-14 11:07 - 002300928 _____ (Farbar) C:\Users\Richard\Downloads\FRST64 (2).exe
2021-03-14 10:55 - 2021-03-14 10:55 - 000000000 ____D C:\Users\Richard\AppData\Roaming\AVG
2021-03-13 14:13 - 2021-03-13 14:13 - 007986864 _____ ( ) C:\Users\Richard\Downloads\AVG_Remover (1).exe
2021-03-09 19:02 - 2021-02-13 02:47 - 000088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2021-03-09 19:02 - 2021-02-13 02:26 - 002132992 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-03-09 19:02 - 2021-02-13 02:24 - 000073728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2021-03-09 19:02 - 2021-02-13 02:12 - 002058752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-03-08 11:09 - 2021-03-08 11:09 - 000033842 _____ C:\Users\Richard\Documents\BDSO.txt
2021-03-08 11:07 - 2021-03-08 11:07 - 000141864 _____ C:\Users\Richard\Downloads\bluescreenview_setup (1).exe
2021-03-07 20:23 - 2021-03-07 20:23 - 000000000 ____D C:\Users\Richard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2021-03-07 20:23 - 2021-03-07 20:23 - 000000000 ____D C:\Program Files (x86)\NirSoft
2021-03-07 20:22 - 2021-03-07 20:22 - 000141480 _____ C:\Users\Richard\Downloads\bluescreenview_setup.exe
2021-03-07 18:57 - 2021-03-07 18:57 - 001503928 _____ (Adobe) C:\Users\Richard\Downloads\uninstall_flash_player.exe
2021-03-07 17:30 - 2021-03-07 17:31 - 000003060 _____ C:\Users\Richard\Downloads\FSS.txt
2021-03-07 17:29 - 2021-03-07 17:29 - 000909824 _____ (Farbar) C:\Users\Richard\Downloads\FSS.exe
2021-03-07 17:23 - 2021-03-07 17:24 - 008463216 _____ (Malwarebytes) C:\Users\Richard\Downloads\AdwCleaner.exe
2021-03-07 15:19 - 2021-03-07 20:12 - 000016228 _____ C:\Users\Richard\Downloads\Fixlog.txt
2021-03-04 01:55 - 2021-03-04 01:55 - 000675494 _____ C:\Users\Richard\Downloads\PhoneCallWithRyan_20210303-192955_01133209634.amr
2021-02-28 10:31 - 2021-02-28 10:31 - 000357446 _____ C:\Users\Richard\Downloads\PhoneCallWithKev_20210226-171938_01133209634.amr
2021-02-28 10:29 - 2021-02-28 10:29 - 001481574 _____ C:\Users\Richard\Downloads\PhoneCallWithAlicia_20210226-164643_03300081555.amr
2021-02-27 08:13 - 2021-02-27 08:13 - 000175952 _____ (Sysnative) C:\Users\Richard\Downloads\SysnativeBSODCollectionApp (1).exe
2021-02-27 08:01 - 2021-03-14 11:07 - 000000000 ____D C:\Users\Richard\Downloads\FRST-OlderVersion
2021-02-26 06:50 - 2021-03-07 17:39 - 000033799 _____ C:\Users\Richard\Downloads\Addition.txt
2021-02-26 06:41 - 2021-03-14 11:09 - 000015490 _____ C:\Users\Richard\Downloads\FRST.txt
2021-02-26 06:40 - 2021-03-14 11:09 - 000000000 ____D C:\FRST
2021-02-26 06:37 - 2021-02-26 06:37 - 002781052 _____ C:\Users\Richard\Downloads\Speccy x64 portable.zip
2021-02-26 06:07 - 2021-02-27 08:16 - 000000000 ____D C:\Users\Richard\Documents\SysnativeFileCollectionApp
2021-02-26 06:07 - 2021-02-26 06:07 - 000175952 _____ (Sysnative) C:\Users\Richard\Downloads\SysnativeBSODCollectionApp.exe
2021-02-26 05:22 - 2021-02-26 05:22 - 000000017 _____ C:\Users\Richard\AppData\Local\resmon.resmoncfg
2021-02-26 00:30 - 2021-02-26 00:30 - 000288032 _____ C:\WINDOWS\Minidump\022621-39015-01.dmp
2021-02-26 00:22 - 2021-02-26 00:22 - 000288032 _____ C:\WINDOWS\Minidump\022621-39781-01.dmp
2021-02-26 00:05 - 2021-02-26 00:06 - 000288032 _____ C:\WINDOWS\Minidump\022621-59750-01.dmp
2021-02-25 23:54 - 2021-02-25 23:54 - 098435072 _____ C:\WINDOWS\system32\config\SOFTWARE.iobit
2021-02-25 23:54 - 2021-02-25 23:54 - 006205440 _____ C:\WINDOWS\system32\config\DRIVERS.iobit
2021-02-25 23:54 - 2021-02-25 23:54 - 000425984 _____ C:\WINDOWS\system32\config\DEFAULT.iobit
2021-02-25 23:54 - 2021-02-25 23:54 - 000028672 _____ C:\WINDOWS\system32\config\SAM.iobit
2021-02-25 23:54 - 2021-02-25 23:54 - 000024576 _____ C:\WINDOWS\system32\config\SECURITY.iobit
2021-02-23 23:13 - 2021-02-23 23:13 - 000175368 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2021-02-23 01:53 - 2021-02-23 01:53 - 000319254 _____ C:\Users\Richard\Downloads\Untitled_Message (3).zip
2021-02-23 01:53 - 2021-02-23 01:53 - 000000000 ____D C:\Users\Richard\Downloads\Untitled_Message (3)
2021-02-23 01:44 - 2021-02-23 01:45 - 004162925 _____ C:\Users\Richard\Downloads\Untitled_Message (2).zip
2021-02-23 01:38 - 2021-02-23 01:38 - 004162925 _____ C:\Users\Richard\Downloads\Untitled_Message.zip
2021-02-23 01:38 - 2021-02-23 01:38 - 004162925 _____ C:\Users\Richard\Downloads\Untitled_Message (1).zip
2021-02-21 09:56 - 2021-02-21 09:57 - 000288032 _____ C:\WINDOWS\Minidump\022121-41500-01.dmp
2021-02-21 08:41 - 2021-02-21 08:42 - 015970496 _____ (IObit ) C:\Users\Richard\Downloads\smart-defrag-setup.exe
2021-02-20 03:36 - 2021-02-20 03:36 - 000095903 _____ C:\Users\Richard\Downloads\Tracked_Returns_label_DA088912438GB.pdf
2021-02-18 22:28 - 2021-02-26 00:10 - 000000000 ____D C:\WINDOWS\softwaredistribution.bak1
2021-02-18 19:36 - 2021-03-07 18:26 - 000004162 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update
2021-02-18 19:36 - 2021-02-18 19:36 - 000465800 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000850248 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000521472 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgNetHub.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000357400 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdriver.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000340224 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2021-02-18 19:35 - 2021-02-18 19:35 - 000327104 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000249368 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsh.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000215464 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000208176 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000107920 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000098840 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniv.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000083496 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000041424 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgKbd.sys
2021-02-18 19:35 - 2021-02-18 19:35 - 000035792 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArDisk.sys
2021-02-17 08:04 - 2021-02-17 09:13 - 025559040 _____ C:\Users\Richard\Downloads\Win8.1_English_x64.iso
2021-02-16 22:09 - 2021-02-16 22:09 - 000000000 ____D C:\WINDOWS\system32\%LOCALAPPDATA%
2021-02-16 19:26 - 2021-02-16 19:26 - 000288032 _____ C:\WINDOWS\Minidump\021621-45015-01.dmp
2021-02-16 19:09 - 2021-02-16 19:09 - 000288032 _____ C:\WINDOWS\Minidump\021621-37656-01.dmp
2021-02-16 19:01 - 2021-02-16 19:02 - 000288344 _____ C:\WINDOWS\Minidump\021621-37812-01.dmp
2021-02-16 16:47 - 2021-02-16 16:48 - 000288032 _____ C:\WINDOWS\Minidump\021621-46406-01.dmp
2021-02-16 16:43 - 2021-02-16 16:43 - 000288032 _____ C:\WINDOWS\Minidump\021621-42000-01.dmp
2021-02-16 01:07 - 2021-02-16 01:08 - 000288032 _____ C:\WINDOWS\Minidump\021621-43968-01.dmp
2021-02-16 00:51 - 2021-02-16 00:51 - 000288032 _____ C:\WINDOWS\Minidump\021621-44796-01.dmp
2021-02-14 11:18 - 2021-02-14 11:18 - 001578036 _____ C:\Users\Richard\Desktop\Vaccine_n.mp4
2021-02-13 15:18 - 2021-02-13 15:18 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-02-13 02:50 - 2021-02-13 02:50 - 000288032 _____ C:\WINDOWS\Minidump\021321-51406-01.dmp

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-03-14 11:08 - 2020-08-02 10:48 - 000000000 ____D C:\ProgramData\AVG
2021-03-14 10:54 - 2017-04-22 20:26 - 000000000 ___RD C:\Users\Richard\OneDrive
2021-03-14 10:54 - 2016-08-21 16:09 - 000000000 ____D C:\AVG_Remover
2021-03-14 10:48 - 2013-08-22 14:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-03-14 10:48 - 2013-08-22 13:25 - 000524288 ___SH C:\WINDOWS\system32\config\BBI
2021-03-14 10:45 - 2017-06-12 06:11 - 000000000 ____D C:\Users\Richard\AppData\Local\Avg
2021-03-14 08:38 - 2017-04-23 09:15 - 000003930 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{98C8926F-187D-4723-A2B6-6CFA634D385A}
2021-03-13 14:48 - 2017-04-22 20:25 - 000003600 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3411107159-1070077873-1841525149-1001
2021-03-13 14:29 - 2020-06-10 19:42 - 000472680 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-03-13 14:29 - 2013-08-22 13:36 - 000000000 ____D C:\WINDOWS\Inf
2021-03-13 14:21 - 2013-08-22 15:36 - 000000000 ___RD C:\WINDOWS\ToastData
2021-03-13 14:21 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-03-13 14:21 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\system32\setup
2021-03-12 21:01 - 2018-12-16 08:46 - 000000000 ____D C:\Users\Richard\AppData\Roaming\WhatsApp
2021-03-11 19:15 - 2013-08-22 15:20 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-03-11 19:10 - 2017-04-23 14:55 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-03-11 19:05 - 2017-04-23 14:55 - 131005360 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-03-10 23:51 - 2017-04-23 09:21 - 000002246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-03-10 19:36 - 2021-01-24 13:26 - 000196608 ___SH C:\Users\Richard\Downloads\Thumbs.db
2021-03-09 23:38 - 2019-09-21 11:46 - 000000000 ____D C:\Users\Richard\AppData\Local\WhatsApp
2021-03-07 18:59 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2021-03-07 18:59 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\system32\Macromed
2021-03-07 18:58 - 2017-09-05 05:45 - 000000000 ____D C:\Users\Default\AppData\Roaming\Adobe
2021-03-07 18:58 - 2017-04-22 20:19 - 000000000 ____D C:\Users\Richard\AppData\Roaming\Adobe
2021-03-07 18:21 - 2017-04-22 20:14 - 000000000 ____D C:\Users\Richard
2021-03-07 18:18 - 2017-04-27 12:34 - 000000000 ____D C:\ProgramData\IObit
2021-03-07 18:18 - 2017-04-27 12:34 - 000000000 ____D C:\Program Files (x86)\IObit
2021-03-07 17:25 - 2016-11-19 14:09 - 000000000 ____D C:\AdwCleaner
2021-03-07 16:47 - 2017-04-23 09:31 - 000998912 ___SH C:\Users\Richard\Desktop\Thumbs.db
2021-03-07 15:23 - 2019-09-29 22:09 - 000000000 ____D C:\Users\Richard\AppData\LocalLow\Temp
2021-03-07 15:21 - 2019-11-02 13:51 - 000002862 _____ C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_Richard
2021-03-07 15:21 - 2018-07-21 08:46 - 000004324 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2021-03-07 15:21 - 2018-07-21 08:36 - 000003282 _____ C:\WINDOWS\system32\Tasks\{65C3D43E-E5A3-481D-9352-126F2DD99808}
2021-03-07 15:21 - 2017-04-23 16:02 - 000003180 _____ C:\WINDOWS\system32\Tasks\RtHDVBg_ListenToDevice
2021-03-07 15:21 - 2017-04-23 16:02 - 000003168 _____ C:\WINDOWS\system32\Tasks\RTKCPL
2021-03-07 15:21 - 2017-04-23 16:02 - 000003152 _____ C:\WINDOWS\system32\Tasks\RtHDVBg
2021-03-07 15:21 - 2017-04-23 09:20 - 000003332 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-03-07 15:21 - 2017-04-23 09:20 - 000003204 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-03-06 17:20 - 2019-01-30 22:08 - 000000000 ____D C:\Users\Richard\Documents\DadsWill
2021-03-03 13:20 - 2019-12-06 13:55 - 000000000 ____D C:\Users\Richard\AppData\Roaming\vlc
2021-02-27 08:01 - 2018-07-22 15:55 - 000000000 ____D C:\Users\Richard\AppData\Local\CrashDumps
2021-02-26 21:44 - 2017-04-27 12:38 - 000000000 ____D C:\Users\Richard\AppData\LocalLow\IObit
2021-02-26 21:44 - 2017-04-27 12:34 - 000000000 ____D C:\Users\Richard\AppData\Roaming\IObit
2021-02-26 00:30 - 2018-04-08 18:49 - 000000000 ____D C:\WINDOWS\Minidump
2021-02-23 23:12 - 2017-04-27 12:38 - 000000000 ____D C:\ProgramData\ProductData
2021-02-21 08:45 - 2020-04-08 09:06 - 000000000 ____D C:\Users\Richard\AppData\Roaming\Telegram Desktop
2021-02-20 03:51 - 2017-04-22 20:18 - 000000000 ____D C:\Users\Richard\AppData\Local\Packages
2021-02-18 22:29 - 2017-04-23 10:12 - 000000000 ____D C:\Users\Richard\AppData\Local\ElevatedDiagnostics
2021-02-17 11:26 - 2018-07-06 10:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
2021-02-17 11:26 - 2018-07-06 09:56 - 000000000 ____D C:\Program Files (x86)\Brother
2021-02-17 11:26 - 2018-04-14 08:39 - 000000000 ____D C:\ProgramData\Package Cache
2021-02-17 06:00 - 2021-02-06 16:55 - 000000000 _____ C:\Recovery.txt
2021-02-16 19:26 - 2017-10-30 18:01 - 000000000 ____D C:\ProgramData\Kodak
2021-02-16 16:35 - 2017-04-23 03:59 - 000000000 ____D C:\WINDOWS\softwaredistribution.bak
2021-02-16 16:08 - 2021-02-09 07:53 - 011636936 _____ C:\Users\Richard\Downloads\MB-SupportTool.exe
2021-02-16 00:37 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-02-16 00:37 - 2013-08-22 15:36 - 000000000 ____D C:\Program Files\Common Files\System

==================== Files in the root of some directories ========

2017-11-19 15:31 - 2017-11-22 05:54 - 000000115 _____ () C:\Users\Richard\AppData\Roaming\LogFile.txt
2017-10-30 18:13 - 2017-10-30 18:13 - 000003178 _____ () C:\Users\Richard\AppData\Local\installer.log
2017-10-30 18:13 - 2017-10-30 18:13 - 000000236 _____ () C:\Users\Richard\AppData\Local\LaunchHomeCenter.log
2021-02-26 05:22 - 2021-02-26 05:22 - 000000017 _____ () C:\Users\Richard\AppData\Local\resmon.resmoncfg
2019-12-10 05:00 - 2019-12-10 05:00 - 000000000 _____ () C:\Users\Richard\AppData\Local\{735F5212-8A05-435A-8589-15A45D7DCAF5}

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)


LastRegBack: 2020-12-03 01:33
==================== End of FRST.txt ========================
 
.... I hope that you're having a good day.

Hi, Rowls1967 ..! The day is really wonderful when spent with the family ..! I just got home from a walk in the park with my wife ..! It was a great day ..!



Download Windows Repair (All-in-One) Portable

  • Boot into Safe Mode
  • Navigate to the tweaking.com_windows_repair_aio folder and Unzip the folder on the Desktop.
  • Double click the Tweaking.com - Windows Repair folders (twice)
  • Right click on the Repair_Windows.exe icon and select Run as administrator
  • Click I agree
  • Click Jump To Repairs

WindowsRepair.png


  • click the box All Repairs to uncheck all the box's
  • check onlythe following box's:
  • 05 - Repair WMI
  • 10 - Remove Policies Set By Infections
  • 25 - Restore Important Windows Services
  • 26 - Set Windows Services to Default Startup
  • check the box Restart/Shutdown System When Finished > Restart System
  • click the Start Repairs button
  • Your computer will reboot upon completion
  • Double click the Logs folder on the Desktop.
  • Double click the file folder created on today's date
  • Double click on _Windows_Repair_Log
  • Copy and paste the contents of the report in your reply
  • Check your computer performance
 
Hi, Rowls1967 ..! The day is really wonderful when spent with the family ..! I just got home from a walk in the park with my wife ..! It was a great day ..!



Download Windows Repair (All-in-One) Portable

  • Boot into Safe Mode
  • Navigate to the tweaking.com_windows_repair_aio folder and Unzip the folder on the Desktop.
  • Double click the Tweaking.com - Windows Repair folders (twice)
  • Right click on the Repair_Windows.exe icon and select Run as administrator
  • Click I agree
  • Click Jump To Repairs

WindowsRepair.png


  • click the box All Repairs to uncheck all the box's
  • check onlythe following box's:
  • 05 - Repair WMI

  • 10 - Remove Policies Set By Infections

  • 25 - Restore Important Windows Services

  • 26 - Set Windows Services to Default Startup

  • check the box Restart/Shutdown System When Finished > Restart System
  • click the Start Repairs button
  • Your computer will reboot upon completion
  • Double click the Logs folder on the Desktop.
  • Double click the file folder created on today's date
  • Double click on _Windows_Repair_Log
  • Copy and paste the contents of the report in your reply
  • Check your computer performance
Yes, people shouldn't under estimate the power of spending quality time with loved ones, plus the importance of getting out into the open air, especially in these current times.
Myself, I shall be going into the woods with my Husky and a couple of buddies tomorrow, to do some wild camping, practicing my bushcraft skills whilst out there, plus eating some steaks and stuff - love the outdoors!

Just to let you know that I'm still getting notifications from AVG...

Tweaking.com - Windows Repair 2021 (v4.11.1)
--------------------------------------------------------------------------------

System Variables
--------------------------------------------------------------------------------
Running In Windows Safe Mode: True
OS: Windows 8.1
OS Architecture: 64-bit
OS Version: 6.3.9600.19968
OS Service Pack:
Computer Name: RICHARD
Windows Drive: C:\
Windows Path: C:\WINDOWS
Program Files: C:\Program Files
Program Files (x86): C:\Program Files (x86)
Current Profile: C:\Users\Richard
Current Profile SID: S-1-5-21-3411107159-1070077873-1841525149-1001
Current Profile Classes: S-1-5-21-3411107159-1070077873-1841525149-1001_Classes
Profiles Location: C:\Users
Profiles Location 2: C:\WINDOWS\ServiceProfiles
Local Settings AppData: C:\Users\Richard\AppData\Local
--------------------------------------------------------------------------------

System Information
--------------------------------------------------------------------------------
System Up Time: 0 Days 00:09:34

Process Count: 20
Commit Total: 797.89 MB
Commit Limit: 11.89 GB
Commit Peak: 1.15 GB
Handle Count: 5445
Kernel Total: 420.66 MB
Kernel Paged: 329.91 MB
Kernel Non Paged: 90.75 MB
System Cache: 862.72 MB
Thread Count: 233
--------------------------------------------------------------------------------

Memory Before Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 5.89 GB
Memory Used: 875.13 MB(14.5135%)
Memory Avail.: 5.03 GB
--------------------------------------------------------------------------------

Cleaning Memory Before Starting Repairs...

Memory After Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 5.89 GB
Memory Used: 752.20 MB(12.4748%)
Memory Avail.: 5.15 GB
--------------------------------------------------------------------------------

Starting Repairs...
Started at (15/03/2021 08:17:14)

<TextBlock>05 - Repair WMI</TextBlock>
Start (15/03/2021 08:17:15)

Starting Security Center So We Can Export The Security Info.

Exporting Antivirus Info...
No Antivirus Products Reported.

Exporting AntiSpyware Info...
No AntiSpyware Products Reported.

Exporting 3rd Party Firewall Info...
No Firewall Products Reported.

Running Repair Under Current User Account
Done (15/03/2021 08:26:51)

<TextBlock>10 - Remove Policies Set By Infections</TextBlock>
Start (15/03/2021 08:26:51)
Running Repair Under Current User Account
Running Repair Under System Account
Done (15/03/2021 08:26:54)

<TextBlock>25 - Restore Important Windows Services</TextBlock>
Start (15/03/2021 08:26:54)

Decompressing & Updating Windows Permission File C:\Users\Richard\Desktop\tweaking.com_windows_repair_aio (1)\Tweaking.com - Windows Repair\files\permissions\8.1\services.7z
Done, 0.19 seconds.

Running Repair Under Current User Account
Running Repair Under System Account
Done (15/03/2021 08:27:04)

<TextBlock>26 - Set Windows Services To Default Startup</TextBlock>
Start (15/03/2021 08:27:04)
Running Repair Under Current User Account
Running Repair Under System Account
Done (15/03/2021 08:27:08)

Cleaning up empty logs...

All Selected Repairs Done.
Done at (15/03/2021 08:27:08)
Total Repair Time: 00:09:56


...YOU MUST RESTART YOUR SYSTEM...
 
Bug Check String : KERNEL_DATA_INPAGE_ERROR
Bug Check Code : 0x0000007a

Bugcheck 0x7a = indicates that the requested page of kernel data from the page file (from your hard drive) could not be read into memory. So, either the RAM that is trying to accept the kernel data from the page file is bad or the hard drive is failing/bad as the kernel data that was written to it is now corrupted for some unknown reason.

Test RAM and Hard Drive -

Run Sea Tools for DOS - LONG Test - (15) Hard Drive (HDD) Diagnostics (Sea Tools for DOS) & SSD Test | Sysnative Forums

Test RAM - (15) Test RAM with memtest.org MemTest86+ | Sysnative Forums

Regards. . .

jcgriff2
 
Bugcheck 0x7a = indicates that the requested page of kernel data from the page file (from your hard drive) could not be read into memory. So, either the RAM that is trying to accept the kernel data from the page file is bad or the hard drive is failing/bad as the kernel data that was written to it is now corrupted for some unknown reason.

Test RAM and Hard Drive -

Run Sea Tools for DOS - LONG Test - (15) Hard Drive (HDD) Diagnostics (Sea Tools for DOS) & SSD Test | Sysnative Forums

Test RAM - (15) Test RAM with memtest.org MemTest86+ | Sysnative Forums

Regards. . .

jcgriff2
Sorry, but i don't have a scooby about what you're talking about, plus the instructions are not clear...you are talking to a newb, so please explain as such...
 
Sorry, but i don't have a scooby about what you're talking about, plus the instructions are not clear...you are talking to a newb, so please explain as such...
From the link, I can't see a "Sea tools for DOS" download...I also do not know what an ISO file is, or how to "burn" to a CD-R. The second link just blows me away...
 

Attachments

  • Screenshot (12).png
    Screenshot (12).png
    99.7 KB · Views: 6
  • Screenshot (13).png
    Screenshot (13).png
    121.3 KB · Views: 7
  • Screenshot (14).png
    Screenshot (14).png
    81.8 KB · Views: 7
Hi, Rowls1967 ..! I apologize a lot for the late response, but this week I was very busy with my work ..! And some family problems are on my mind..! Give an excuse ..! :(
I see that the topic has a development on your hardware problem ..!

I confirm from you that active infections are not visible in your system..!

The following will remove the tools we used as well as reset system restore points:

KpRm

Download KpRm by kernel-panik and save it to your desktop.
  • Right-click kprm_(version).exe and select Run as Administrator.
  • When the tool opens, ensure all boxes are checked, and select Run.
  • Once complete, click OK.
  • A log will open in Notepad titled kprm-(date).txt.
  • Please copy and paste its contents in your next reply.



Please continue with jcgriff2's hardware troubleshooting instructions..! Nice work..! :-)
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top