Solved Help with Laptop

Fix result of Farbar Recovery Scan Tool (x64) Version:03-06-2015
Ran by Akshay at 2015-06-07 14:30:48 Run:2
Running from C:\Users\Akshay\Desktop
Loaded Profiles: Akshay (Available Profiles: Akshay)
Boot Mode: Normal
==============================================

fixlist content:
*****************
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2090909380-4087199382-2303749201-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
FF Plugin-x32: @qq.com/npqscall -> C:\Program Files (x86)\Common Files\Tencent\NPQSCALL\npqscall.dll No File
U3 catchme; \??\C:\ComboFix\catchme.sys [X]
2015-06-05 13:25 - 2015-06-06 01:41 - 00000000 ____D C:\Users\Akshay\AppData\Roaming\jensgqtf
2015-06-05 02:19 - 2015-06-06 01:38 - 00000000 ____D C:\Users\Akshay\AppData\Roaming\xvolvopm
2015-06-04 20:54 - 2015-06-06 01:38 - 00000000 ____D C:\Users\Akshay\AppData\Roaming\adwpqscu
2015-06-05 22:24 - 2015-06-06 20:26 - 0007616 _____ () C:\Users\Akshay\AppData\Local\Resmon.ResmonCfg
2015-06-05 18:52 - 2015-06-06 01:39 - 0000112 _____ () C:\ProgramData\hf6Arut.dat

*****************

"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-2090909380-4087199382-2303749201-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@qq.com/npqscall" => key removed successfully
catchme => Service removed successfully
C:\Users\Akshay\AppData\Roaming\jensgqtf => moved successfully.
C:\Users\Akshay\AppData\Roaming\xvolvopm => moved successfully.
C:\Users\Akshay\AppData\Roaming\adwpqscu => moved successfully.
C:\Users\Akshay\AppData\Local\Resmon.ResmonCfg => moved successfully.
C:\ProgramData\hf6Arut.dat => moved successfully.

==== End of Fixlog 14:30:48 ====
 
Last scans...

redtarget.gif
Download Security Check from here or here and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


redtarget.gif
Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

redtarget.gif
Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.

redtarget.gif
Download Sophos Free Virus Removal Tool and save it to your desktop.
  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program
 
Results of screen317's Security Check version 1.003
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Windows Firewall Disabled!
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 8 Update 45
Java SE Development Kit 8 Update 45
Adobe Flash Player 17.0.0.188
Adobe Reader 10.1.13 Adobe Reader out of Date!
Mozilla Firefox 35.0.1 Firefox out of Date!
Google Chrome (43.0.2357.65)
Google Chrome (43.0.2357.81)
````````Process Check: objlist.exe by Laurent````````
AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 2%
````````````````````End of Log``````````````````````
 
Farbar Service Scanner Version: 17-01-2015
Ran by Akshay (administrator) on 07-06-2015 at 17:27:43
Running from "C:\Users\Akshay\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Policy:
========================


Action Center:
============

Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============
Checking FirewallRules of SharedAccess: ATTENTION!=====> Unable to open "SharedAccess\Defaults\FirewallPolicy\FirewallRules" registry key. The key does not exist.


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****
 
I ran Temp File cleaner and it did what you said, and close all programs but it pretty much restarted within a second of shutting down programs so I'm not sure if that's what it was supposed to do but I did it. About to run Sophos now.
 
This one took a really long time but it's finally done! Sophos:



2015-06-07 22:58:33.447 Sophos Virus Removal Tool version 2.5.4
2015-06-07 22:58:33.447 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

2015-06-07 22:58:33.447 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2015-06-07 22:58:33.447 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x300 PT=0x1 WOW64
2015-06-07 22:58:33.447 Checking for updates...
2015-06-07 22:58:36.495 Update progress: proxy server not available
2015-06-07 22:59:05.045 Option all = no
2015-06-07 22:59:05.045 Option recurse = yes
2015-06-07 22:59:05.046 Option archive = no
2015-06-07 22:59:05.046 Option service = yes
2015-06-07 22:59:05.046 Option confirm = yes
2015-06-07 22:59:05.046 Option sxl = yes
2015-06-07 22:59:05.047 Option max-data-age = 35
2015-06-07 22:59:05.047 Option EnableSafeClean = yes
2015-06-07 22:59:07.418 Option vdl-logging = yes
2015-06-07 22:59:07.423 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-06-07 22:59:07.423 Machine ID: bb6f1a52592c40d28d2ba44f3e3c4256
2015-06-07 22:59:07.430 Component SVRTcli.exe version 2.5.4
2015-06-07 22:59:07.430 Component control.dll version 2.5.4
2015-06-07 22:59:07.431 Component SVRTservice.exe version 2.5.4
2015-06-07 22:59:07.431 Component engine\osdp.dll version 1.44.1.2200
2015-06-07 22:59:07.431 Component engine\veex.dll version 3.60.0.2200
2015-06-07 22:59:07.432 Component engine\savi.dll version 8.1.7.2200
2015-06-07 22:59:07.433 Component rkdisk.dll version 1.5.30.0
2015-06-07 22:59:07.433 Version info: Product version 2.5.4
2015-06-07 22:59:07.433 Version info: Detection engine 3.60.0
2015-06-07 22:59:07.433 Version info: Detection data 5.15
2015-06-07 22:59:07.433 Version info: Build date 5/26/2015
2015-06-07 22:59:07.433 Version info: Data files added 240
2015-06-07 22:59:07.433 Version info: Last successful update (not yet updated)
2015-06-07 22:59:23.337 Downloading updates...
2015-06-07 22:59:23.341 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
2015-06-07 22:59:23.341 Update progress: [I49502] Found supplement SAVIW32 LATEST
2015-06-07 22:59:23.341 Update progress: [I49502] Found supplement IDE516 LATEST
2015-06-07 22:59:23.341 Update progress: [I49502] Found supplement IDE517 LATEST
2015-06-07 22:59:23.341 Update progress: [I49502] Found supplement IDE518 LATEST
2015-06-07 22:59:23.342 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
2015-06-07 22:59:23.342 Update progress: [I19463] Syncing product SAVIW32 55
2015-06-07 22:59:31.919 Update progress: [I19463] Syncing product IDE516 178
2015-06-07 22:59:35.114 Installing updates...
2015-06-07 22:59:36.315 Error level 1
2015-06-07 22:59:37.281 Update progress: [I19463] Syncing product IDE517 66
2015-06-07 22:59:37.281 Update progress: [I19463] Syncing product IDE518 1
2015-06-07 22:59:51.848 Update successful
2015-06-07 23:00:10.264 Option all = no
2015-06-07 23:00:10.264 Option recurse = yes
2015-06-07 23:00:10.264 Option archive = no
2015-06-07 23:00:10.264 Option service = yes
2015-06-07 23:00:10.264 Option confirm = yes
2015-06-07 23:00:10.264 Option sxl = yes
2015-06-07 23:00:10.265 Option max-data-age = 35
2015-06-07 23:00:10.265 Option EnableSafeClean = yes
2015-06-07 23:00:10.586 Option vdl-logging = yes
2015-06-07 23:00:10.590 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-06-07 23:00:10.590 Machine ID: bb6f1a52592c40d28d2ba44f3e3c4256
2015-06-07 23:00:10.591 Component SVRTcli.exe version 2.5.4
2015-06-07 23:00:10.592 Component control.dll version 2.5.4
2015-06-07 23:00:10.592 Component SVRTservice.exe version 2.5.4
2015-06-07 23:00:10.592 Component engine\osdp.dll version 1.44.1.2200
2015-06-07 23:00:10.592 Component engine\veex.dll version 3.60.0.2200
2015-06-07 23:00:10.592 Component engine\savi.dll version 8.1.7.2200
2015-06-07 23:00:10.593 Component rkdisk.dll version 1.5.30.0
2015-06-07 23:00:10.593 Version info: Product version 2.5.4
2015-06-07 23:00:10.593 Version info: Detection engine 3.60.0
2015-06-07 23:00:10.593 Version info: Detection data 5.15G
2015-06-07 23:00:10.593 Version info: Build date 5/26/2015
2015-06-07 23:00:10.593 Version info: Data files added 240
2015-06-07 23:00:10.593 Version info: Last successful update 6/7/2015 6:59:51 PM

2015-06-08 00:41:10.319 Could not open C:\hiberfil.sys
2015-06-08 00:42:05.992 Could not open C:\pagefile.sys
2015-06-08 01:01:44.707 >>> Virus 'Mal/VMProtBad-A' found in file C:\Program Files (x86)\Sleeping Dogs\buddha.dll
2015-06-08 01:01:44.707 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2090909380-4087199382-2303749201-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-06-08 01:01:44.707 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-2090909380-4087199382-2303749201-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-06-08 01:01:44.707 >>> Virus 'Mal/VMProtBad-A' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-06-08 01:17:49.982 Could not open C:\System Volume Information\{0fb08868-0c12-11e5-98ab-685d43f2a0f7}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-06-08 01:17:49.982 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-06-08 01:17:49.982 Could not open C:\System Volume Information\{9a7c2c3f-0992-11e5-bf00-685d43f2a0f7}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-06-08 01:17:49.982 Could not open C:\System Volume Information\{9a7c2cbb-0992-11e5-bf00-685d43f2a0f7}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-06-08 01:19:23.611 Could not open C:\Users\Akshay\AppData\Local\Google\Chrome\User Data\Default\Current Session
2015-06-08 01:19:23.611 Could not open C:\Users\Akshay\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
2015-06-08 01:19:23.691 Could not check C:\Users\Akshay\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOCK (virus scan failed)
2015-06-08 01:19:23.715 Could not check C:\Users\Akshay\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK (virus scan failed)
2015-06-08 01:19:32.768 Could not check C:\Users\Akshay\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\LOCK (virus scan failed)
2015-06-08 01:19:32.936 Could not check C:\Users\Akshay\AppData\Local\Google\Chrome\User Data\Default\GCM Store\LOCK (virus scan failed)
2015-06-08 01:19:33.526 Could not check C:\Users\Akshay\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pafkbggdmjlpgkdkcbjmhmfcdpncadgh\LOCK (virus scan failed)
2015-06-08 01:19:35.739 Could not check C:\Users\Akshay\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOCK (virus scan failed)
2015-06-08 01:41:48.707 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\steam_api_ext.dll
2015-06-08 01:41:48.707 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\steam_api_ext.dll
2015-06-08 01:41:48.707 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\steam_api_ext.dll
2015-06-08 01:41:48.707 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\steam_api_ext.dll
2015-06-08 01:41:48.708 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\steam_api_ext.dll
2015-06-08 01:41:48.708 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2090909380-4087199382-2303749201-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-06-08 01:41:48.708 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2090909380-4087199382-2303749201-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-06-08 01:41:48.708 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-06-08 01:42:22.910 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\uplay_r1.dll
2015-06-08 01:42:22.910 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\uplay_r1.dll
2015-06-08 01:42:22.910 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\uplay_r1.dll
2015-06-08 01:42:22.910 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\uplay_r1.dll
2015-06-08 01:42:22.910 >>> Virus 'Mal/Generic-S' found in file C:\Users\Akshay\Desktop\Games\Game ISOs\ac4\Assassin's Creed IV Black Flag Gold Edition-SKIDROWCRACK\uplay_r1.dll
2015-06-08 01:42:22.911 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2090909380-4087199382-2303749201-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-06-08 01:42:22.911 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2090909380-4087199382-2303749201-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-06-08 01:42:22.911 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-06-08 01:56:09.225 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
2015-06-08 01:56:09.226 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
2015-06-08 01:56:25.245 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2015-06-08 01:56:25.247 Could not open C:\Windows\System32\config\RegBack\SAM
2015-06-08 01:56:25.248 Could not open C:\Windows\System32\config\RegBack\SECURITY
2015-06-08 01:56:25.250 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2015-06-08 01:56:25.251 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2015-06-08 02:18:26.639 The following items will be cleaned up:
2015-06-08 02:18:26.640 Mal/VMProtBad-A
2015-06-08 02:18:26.640 Mal/Generic-S
 
redtarget.gif
Update Firefox to the current version.

redtarget.gif
Update Adobe Reader

You can download it from https://www.techspot.com/downloads/2083-adobe-reader-dc.html
After installing the latest Adobe Reader, uninstall all previous versions (if present).
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

redtarget.gif
We have couple of registry issues.
Following steps involve registry editing. Please create new restore point before proceeding!!!
How to: http://www.smartestcomputing.us.com/topic/63983-how-to-create-new-restore-point-all-windows/

Download win-7-8-action-center-notification-icon-missing.reg from here: http://www.bleepstatic.com/fhost/uploads/1/win-7-8-action-center-notification-icon-missing.reg
Double-click on downloaded file and confirm the prompt.

Download SharedAccess.reg
Double-click on downloaded file and confirm the prompt.

Restart computer.
Post new FSS log.
 
Farbar Service Scanner Version: 17-01-2015
Ran by Akshay (administrator) on 08-06-2015 at 03:34:03
Running from "C:\Users\Akshay\Downloads"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============

Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****
 
One issue has been fixed by the other not.

Re-run this part from safe mode.
How to start Windows in Safe Mode

Following steps involve registry editing. Please create new restore point before proceeding!!!
How to: http://www.smartestcomputing.us.com/topic/63983-how-to-create-new-restore-point-all-windows/

Download win-7-8-action-center-notification-icon-missing.reg from here: http://www.bleepstatic.com/fhost/uploads/1/win-7-8-action-center-notification-icon-missing.reg
Double-click on downloaded file and confirm the prompt.

Restart computer.
Post new FSS log.
 
Farbar Service Scanner Version: 17-01-2015
Ran by Akshay (administrator) on 08-06-2015 at 21:49:37
Running from "C:\Users\Akshay\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============

Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****
 
Hmmm...still didn't work.

Download Windows Repair (All in One) from this site

Install the program then run it.

NOTE 1. In Windows Vista, 7 and 8 right click on the program, click "Run As Administrator".
NOTE 2. Disable your antivirus program before running Windows Repair.


Go to Step 3 and click on Check button next to 1. See If Check Disk Is Needed.
If the tool that the Check Disk is needed click on Do It button next to 2. Check Disk.
In that case make sure you restart computer.

p22012121.gif



Once the above is done go to Step 4 and allow it to run System File Check by clicking on Do It button:

p22012122.gif



Go to Step 5 and under "System Restore" click on Create button:

p22012123.gif



Go to Repairs tab and click Open Repairs button.

p22012124.gif


In next window....
Leave all checkmarks as they're.
Click on Start Repairs button.

p22012126.gif


Post Windows Repair log which is located in the following folder:
64-bit systems - C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Logs
32-bit systems - C:\Program Files\Tweaking.com\Windows Repair (All in One)\Logs

Post fresh FSS log as well.
 
Tweaking.com - Windows Repair v3.2.1
--------------------------------------------------------------------------------

System Variables
--------------------------------------------------------------------------------
OS: Windows 7 Home Premium
OS Architecture: 64-bit
OS Version: 6.1.7601
OS Service Pack: Service Pack 1
Computer Name: AKSHAY-PC
Windows Drive: C:\
Windows Path: C:\Windows
Program Files: C:\Program Files
Program Files (x86): C:\Program Files (x86)
Current Profile: C:\Users\Akshay
Current Profile SID: S-1-5-21-2090909380-4087199382-2303749201-1000
Current Profile Classes: S-1-5-21-2090909380-4087199382-2303749201-1000_Classes
Profiles Location: C:\Users
Profiles Location 2: C:\Windows\ServiceProfiles
Local Settings AppData: C:\Users\Akshay\AppData\Local
--------------------------------------------------------------------------------

System Information
--------------------------------------------------------------------------------
System Up Time: 0 Days 00:06:18

Process Count: 93
Commit Total: 2.99 GB
Commit Limit: 15.75 GB
Commit Peak: 3.10 GB
Handle Count: 29355
Kernel Total: 457.94 MB
Kernel Paged: 323.66 MB
Kernel Non Paged: 134.28 MB
System Cache: 2.11 GB
Thread Count: 1256
--------------------------------------------------------------------------------

Memory Before Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 7.88 GB
Memory Used: 2.68 GB(33.965%)
Memory Avail.: 5.20 GB
--------------------------------------------------------------------------------

Cleaning Memory Before Starting Repairs...

Memory After Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 7.88 GB
Memory Used: 2.34 GB(29.7536%)
Memory Avail.: 5.53 GB
--------------------------------------------------------------------------------

Starting Repairs...
Started at (6/10/2015 1:42:17 AM)

Setting Any Missing 'InstallDate' From Uninstall Sections Before Running Repair...
Total Missing 'InstallDate' Fixed: 214

01 - Reset Registry Permissions 01/03
HKEY_CURRENT_USER & Sub Keys
Start (6/10/2015 1:42:30 AM)

Running Repair Under Current User Account
Done (6/10/2015 1:42:52 AM)

01 - Reset Registry Permissions 02/03
HKEY_LOCAL_MACHINE & Sub Keys
Start (6/10/2015 1:42:52 AM)


Decompressing & Updating Windows Permission File services.txt
Done, 0.17 seconds.

Running Repair Under System Account
Done (6/10/2015 1:46:28 AM)

01 - Reset Registry Permissions 03/03
HKEY_CLASSES_ROOT & Sub Keys
Start (6/10/2015 1:46:28 AM)

Running Repair Under System Account
Done (6/10/2015 1:47:39 AM)

03 - Reset Service Permissions
Start (6/10/2015 1:47:39 AM)

Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:03:42 AM)

04 - Register System Files
Start (6/10/2015 2:03:42 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:04:42 AM)

05 - Repair WMI
Start (6/10/2015 2:04:42 AM)

Starting Security Center So We Can Export The Security Info.

Exporting Antivirus Info...
avast! Antivirus Exported.

Exporting AntiSpyware Info...
Windows Defender Exported.
avast! Antivirus Exported.

Exporting 3rd Party Firewall Info...
No Firewall Products Reported.

Running Repair Under Current User Account
Done (6/10/2015 2:10:05 AM)

06 - Repair Windows Firewall
Start (6/10/2015 2:10:05 AM)
Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done, 0.13 seconds.

Running Repair Under System Account
Done (6/10/2015 2:10:53 AM)

07 - Repair Internet Explorer
Start (6/10/2015 2:10:53 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:11:19 AM)

08 - Repair MDAC/MS Jet
Start (6/10/2015 2:11:19 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:11:33 AM)

09 - Repair Hosts File
Start (6/10/2015 2:11:33 AM)
Running Repair Under System Account
Done (6/10/2015 2:11:41 AM)

10 - Remove Policies Set By Infections
Start (6/10/2015 2:11:41 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:11:56 AM)

12 - Repair Icons
Start (6/10/2015 2:11:56 AM)
Running Repair Under Current User Account
Done (6/10/2015 2:12:00 AM)

13 - Repair Network
Start (6/10/2015 2:12:00 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:12:21 AM)

15 - Repair Proxy Settings
Start (6/10/2015 2:12:21 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:12:28 AM)

17 - Repair Windows Updates
Start (6/10/2015 2:12:28 AM)
Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done, 0.13 seconds.

Running Repair Under System Account
Setting Windows Updates Files That Are In Use To Be Removed At Next Boot.
Done (6/10/2015 2:13:15 AM)

18 - Repair CD/DVD Missing/Not Working
Start (6/10/2015 2:13:15 AM)
iTunes not found, not applying UpperFilters iTunes Reg Key
Done (6/10/2015 2:13:15 AM)

19 - Repair Volume Shadow Copy Service
Start (6/10/2015 2:13:15 AM)
Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done, 0.13 seconds.

Running Repair Under System Account
Done (6/10/2015 2:13:52 AM)

21 - Repair MSI (Windows Installer)
Start (6/10/2015 2:13:52 AM)
Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done, 0.13 seconds.

Running Repair Under System Account
Done (6/10/2015 2:14:18 AM)

23.01 - Repair bat Association
Start (6/10/2015 2:14:18 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:14:25 AM)

23.02 - Repair cmd Association
Start (6/10/2015 2:14:25 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:14:32 AM)

23.03 - Repair com Association
Start (6/10/2015 2:14:32 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:14:38 AM)

23.04 - Repair Directory Association
Start (6/10/2015 2:14:38 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:14:45 AM)

23.05 - Repair Drive Association
Start (6/10/2015 2:14:45 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:14:51 AM)

23.06 - Repair exe Association
Start (6/10/2015 2:14:51 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:14:58 AM)

23.07 - Repair Folder Association
Start (6/10/2015 2:14:58 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:15:04 AM)

23.08 - Repair inf Association
Start (6/10/2015 2:15:04 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:15:11 AM)

23.09 - Repair lnk (Shortcuts) Association
Start (6/10/2015 2:15:11 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:15:17 AM)

23.10 - Repair msc Association
Start (6/10/2015 2:15:17 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:15:24 AM)

23.11 - Repair reg Association
Start (6/10/2015 2:15:24 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:15:31 AM)

23.12 - Repair scr Association
Start (6/10/2015 2:15:31 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:15:38 AM)

24 - Repair Windows Safe Mode
Start (6/10/2015 2:15:38 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:15:44 AM)

25 - Repair Print Spooler
Start (6/10/2015 2:15:44 AM)
Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done, 0.13 seconds.

Running Repair Under System Account
Done (6/10/2015 2:16:13 AM)

26 - Restore Important Windows Services
Start (6/10/2015 2:16:13 AM)
Running Repair Under Current User Account

Decompressing & Updating Windows Permission File services.txt
Done, 0.13 seconds.

Running Repair Under System Account
Done (6/10/2015 2:16:34 AM)

27 - Set Windows Services To Default Startup
Start (6/10/2015 2:16:34 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:16:51 AM)

Skipping Repair.
Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
Current version: 6.1

Skipping Repair.
Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
Current version: 6.1

Skipping Repair.
Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
Current version: 6.1

31 - Repair Windows 'New' Submenu
Start (6/10/2015 2:16:51 AM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/10/2015 2:16:57 AM)

33 - Repair Performance Counters
Start (6/10/2015 2:16:57 AM)
Running Repair Under Current User Account
Done (6/10/2015 2:17:07 AM)

Cleaning up empty logs...

All Selected Repairs Done.
Done at (6/10/2015 2:17:07 AM)
Total Repair Time: 00:34:54


...YOU MUST RESTART YOUR SYSTEM...
 
Farbar Service Scanner Version: 17-01-2015
Ran by Akshay (administrator) on 10-06-2015 at 09:40:08
Running from "C:\Users\Akshay\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============

Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****
 
Not sure what's going on here...

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

64-bit users go HERE
  • Double-click SystemLook.exe to run it.
  • Vista users:: Right click on SystemLook.exe, click Run As Administrator
  • Copy the content of the following box and paste it into the main textfield:
Code:
:reg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
 
SystemLook 30.07.11 by jpshortstuff
Log created at 12:12 on 11/06/2015 by Akshay
Administrator - Elevation successful

========== reg ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{003e0278-eca8-4bb8-a256-3689ca1c2600}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{3BF043EF-A974-49B3-8322-B853CF1E5EC5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{566296fe-e0e8-475f-ba9c-a31ad31620b1}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{5FF49FE8-B332-4CB9-B102-FB6951629E55}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{68ddbb56-9d1d-4fd9-89c5-c0da2a625392}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{7007ACCF-3202-11D1-AAD2-00805FC1270E}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{7849596a-48ea-486e-8937-a2a3009f31a9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{900c0763-5cad-4a34-bc1f-40cd513679d5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{A1607060-5D4C-467a-B711-2B59A6F25957}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{AAA288BA-9A4C-45B0-95D7-94D524869DB5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{C2796011-81BA-4148-8FCA-C6643245113F}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{DA67B8AD-E81B-4c70-9B91-B417B5E33527}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{EF4D1E1A-1C87-4AA8-8934-E68E4367468D}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{F08C5AC2-E722-4116-ADB7-CE41B527994B}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{F20487CC-FC04-4B1E-863F-D9801796130B}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{fbeb8a05-beee-4442-804e-409d6c4515e9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{ff363bfe-4941-4179-a81c-f3f1ca72d820}]


-= EOF =-
 
Download PsExec.exe to your desktop (IMPORTANT!)
Go Start and in "Start search" type in:
cmd
Hold CTRL and SHIFT keys, press Enter.
Command prompt window will open.
Copy and paste following command:

"%userprofile%\desktop\psexec" -I -d -s c:\windows\regedit.exe

Press Enter.
Registry Editor will open.
Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects
Right-Click ShellServiceObjects and select Permissions...
Click Advanced.
Under Owner tab select the entry starting with you user name, example: Farbar(Farbar-PC\Farbar)
Put a check mark next to Replace owner on subcontainers and objects and click Apply and OK.
Under Security type while Everyone is selected put a check mark in the box under Allow next to Full Control.
Click Apply and OK.

Re-run registry fix.

Please go back to the the ShellServiceObjects key again while Everyone is selected remove check mark in the box under Allow next to Full Control and close the registry.
Restart computer.
Post new FSS log.
 
Last edited:
I don't see a root anywhere in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects
There is a permissions option in the edit thing though. should I click on the shell serviceObjects folder and then click permissions?
 
When I got to the everyone/allow check box, they were colored out but it already was on allow so I can'e deselct the allow part
 
Farbar Service Scanner Version: 17-01-2015
Ran by Akshay (administrator) on 13-06-2015 at 20:42:48
Running from "C:\Users\Akshay\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============

Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****
 
Back