MeinAutoIstKaput
Posts: 7 +0
I suspect my pc may be infected. I ran tdsskiller and when it reached "Device0" it caused the computer to restart. I then tried running the program again, with the same results. I then checked out this forum and have pasted the directories below as instructed and am now awaiting further assistance.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-07-2021
Ran by javau (administrator) on DESKTOP-VE26JV6 (07-07-2021 10:10:04)
Running from C:\Users\javau\OneDrive\Desktop
Loaded Profiles: javau
Platform: Windows 10 Home Version 21H1 19043.1052 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0368925.inf_amd64_05ef22929fd9ebfc\B368707\atieclxx.exe
(Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0368925.inf_amd64_05ef22929fd9ebfc\B368707\atiesrxx.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe
(ASRock Incorporation -> ASRock Incorporation) C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\AsrSvc.exe
(ASRock Incorporation -> ASRock Incorporation) C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\ATuning.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\SyncUp\Server\SyncUp Server.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <43>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee Security Scan\3.11.2254\SSScheduler.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\FileCoAuth.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2106.14307.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [881440 2019-06-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [7580488 2021-05-24] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1794888 2015-06-29] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.2.9.564\ASUSWSLoader.exe [63968 2016-06-21] (ASUS Cloud Corporation -> ASUS Cloud Corporation)
HKLM-x32\...\Run: [OnScreen Control] => C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreenStartUpApp.exe [1820568 2020-10-19] (LG Electronics Inc. -> LG Electronics Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe [1976184 2021-06-26] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4109032 2021-06-08] (Valve -> Valve Corporation)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [AMDDVR] => C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe [2524632 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [ASRock A-Tuning] => [X]
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [BsgLauncher] => T:\Program Files\Battlestate\BsgLauncher\BsgLauncher.exe [1122512 2021-06-17] (BATTLESTATE GAMES LIMITED -> Battlestate Games)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5549280 2021-05-28] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2147264 2021-07-01] (Wargaming.net Limited -> Wargaming.net)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssText3d.scr [224768 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.124\Installer\chrmstp.exe [2021-06-24] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2021-06-30]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.2254\SSScheduler.exe (McAfee, LLC -> McAfee, LLC)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08D75B76-7957-44E5-8CA3-1DA453C40D56} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [5938888 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {21E8BA00-AD0B-4A75-935A-29EBBE600959} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {28E8DE9D-4599-4B1A-BE48-9F758363658A} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [5938888 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {33172F9A-EEA4-40DC-B783-91493A8B15E5} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [1578784 2016-07-07] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) [File not signed]
Task: {3D43F398-505A-4806-BD44-21AEACB5177F} - System32\Tasks\Driver Easy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [3817392 2020-06-18] (Easeware Technology Limited -> Easeware)
Task: {3E1B86AA-CAED-4AEF-9CD6-C49F6DF4B43F} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [2822520 2021-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {40545C02-5D55-4A62-A4F6-134A487B365A} - System32\Tasks\ATuning => C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\ATuning.exe [9712088 2020-11-10] (ASRock Incorporation -> ASRock Incorporation)
Task: {4E7EFD74-3D23-41B8-9601-192F343DC2A3} - System32\Tasks\AMD.PROCC CleanupTemporaryInternetFiles => C:\Program Files (x86)\AMD PRO Control Center\AMD.PROCC.CleanupSchedulerTool.exe [15464 2015-03-20] (Advanced Micro Devices, Inc. -> AMD) [File not signed]
Task: {62F032BC-8855-4046-B9D4-F663B6C2DA5C} - System32\Tasks\ASUS\ASUS Manager BackgroundWindow => C:\Program Files (x86)\ASUS\ASUS Manager\BackgroundWindow.exe [21784 2016-03-24] (ASUSTeK Computer Inc. -> )
Task: {652BA8CE-4678-46F3-BB08-A700B4C3624B} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [43520 2021-06-17] (Advanced Micro Devices, Inc.) [File not signed]
Task: {74C3086F-25AE-4497-86E4-D88DD96E03A5} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [5938888 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {7A4CB82E-EBFC-4776-8E8A-4515F4A9B97A} - System32\Tasks\ASUS\ASUS Updater => C:\Program Files (x86)\ASUS\ASUS Manager\Application Update\ASUSFourceUpdater.exe [940496 2016-07-15] (ASUSTeK Computer Inc. -> )
Task: {82740ED4-9641-4FA3-AB86-048E2CB6CF57} - System32\Tasks\CorelUpdateHelperTask-FA701FD46DEE5BD579DFADDAEEB217B7 => c:\Program Files (x86)\Corel\CUH\v2\CUH.exe
Task: {8AD7FEA3-81CE-4B45-8DC5-F2389D0EDD98} - System32\Tasks\ASUS\ASUS Update Checker => C:\Program Files (x86)\ASUS\ASUS Manager\Application Update\ASUSUpdateChecker.exe [922576 2016-07-15] (ASUSTeK Computer Inc. -> )
Task: {98AA6CF0-4172-48B2-BBFE-6FF2A985CEC8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-26] (Adobe Inc. -> Adobe Inc.)
Task: {993A37B3-01F9-4BB2-BC1C-D68F028B43B8} - System32\Tasks\ASUS\ASUS Manager HotKey Service => C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe [225592 2016-03-24] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {AEEE1EA9-C467-4921-A6E9-E09A4549DD47} - System32\Tasks\AMD.PROCC SleepHibernate Computer => C:\Program Files (x86)\AMD PRO Control Center\AMD.PROCC.Notifier.exe [35432 2015-03-20] (Advanced Micro Devices, Inc. -> AMD) [File not signed]
Task: {C383F64F-0048-4657-B415-2841483C9CD8} - System32\Tasks\AMD.PROCC WakeUp Computer => C:\Program Files (x86)\AMD PRO Control Center\AMD.PROCC.Notifier.exe [35432 2015-03-20] (Advanced Micro Devices, Inc. -> AMD) [File not signed]
Task: {C72EC81B-BE97-4A55-9455-930D1D35CAF4} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe [382168 2020-05-21] (Advanced Micro Devices INC. -> )
Task: {D36CC70A-A288-4280-9F5D-EDF94D666537} - System32\Tasks\ASUS\SyncUp => C:\Program Files (x86)\ASUS\ASUS Manager\SyncUp\Server\SyncUp Server.exe [3494200 2015-04-01] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {DD3FEA5B-2D0B-4BF1-9850-F65C5AF6FDF1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-25] (Google Inc -> Google LLC)
Task: {DFCFA362-B87D-44BA-B5CD-9C7A26520BB2} - System32\Tasks\AMD.PROCC CleanupCookies => C:\Program Files (x86)\AMD PRO Control Center\AMD.PROCC.CleanupSchedulerTool.exe [15464 2015-03-20] (Advanced Micro Devices, Inc. -> AMD) [File not signed]
Task: {EE59E04B-C17C-4E7B-9D37-96BC34BA7D0C} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [269272 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {F24D8FE8-E872-4219-8DC9-A5F418729EF8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-25] (Google Inc -> Google LLC)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{584842d4-e75c-45ee-ab0a-bf62afbcb7f9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{585f592d-776d-4dad-884c-a7dbfb45f42c}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{bd960918-39e4-4af6-bc57-d3df8698c303}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\javau\AppData\Local\Microsoft\Edge\User Data\Default [2021-07-07]
Will post the remainder of this log, and the next log separately.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-07-2021
Ran by javau (administrator) on DESKTOP-VE26JV6 (07-07-2021 10:10:04)
Running from C:\Users\javau\OneDrive\Desktop
Loaded Profiles: javau
Platform: Windows 10 Home Version 21H1 19043.1052 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0368925.inf_amd64_05ef22929fd9ebfc\B368707\atieclxx.exe
(Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0368925.inf_amd64_05ef22929fd9ebfc\B368707\atiesrxx.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe
(ASRock Incorporation -> ASRock Incorporation) C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\AsrSvc.exe
(ASRock Incorporation -> ASRock Incorporation) C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\ATuning.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\SyncUp\Server\SyncUp Server.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <43>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee Security Scan\3.11.2254\SSScheduler.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\FileCoAuth.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2106.14307.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [881440 2019-06-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [7580488 2021-05-24] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1794888 2015-06-29] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.2.9.564\ASUSWSLoader.exe [63968 2016-06-21] (ASUS Cloud Corporation -> ASUS Cloud Corporation)
HKLM-x32\...\Run: [OnScreen Control] => C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreenStartUpApp.exe [1820568 2020-10-19] (LG Electronics Inc. -> LG Electronics Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe [1976184 2021-06-26] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4109032 2021-06-08] (Valve -> Valve Corporation)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [AMDDVR] => C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe [2524632 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [ASRock A-Tuning] => [X]
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [BsgLauncher] => T:\Program Files\Battlestate\BsgLauncher\BsgLauncher.exe [1122512 2021-06-17] (BATTLESTATE GAMES LIMITED -> Battlestate Games)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5549280 2021-05-28] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2147264 2021-07-01] (Wargaming.net Limited -> Wargaming.net)
HKU\S-1-5-21-1516065185-2354279922-2247536414-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssText3d.scr [224768 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.124\Installer\chrmstp.exe [2021-06-24] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2021-06-30]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.2254\SSScheduler.exe (McAfee, LLC -> McAfee, LLC)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08D75B76-7957-44E5-8CA3-1DA453C40D56} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [5938888 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {21E8BA00-AD0B-4A75-935A-29EBBE600959} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [63448 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {28E8DE9D-4599-4B1A-BE48-9F758363658A} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [5938888 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {33172F9A-EEA4-40DC-B783-91493A8B15E5} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [1578784 2016-07-07] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) [File not signed]
Task: {3D43F398-505A-4806-BD44-21AEACB5177F} - System32\Tasks\Driver Easy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [3817392 2020-06-18] (Easeware Technology Limited -> Easeware)
Task: {3E1B86AA-CAED-4AEF-9CD6-C49F6DF4B43F} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [2822520 2021-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {40545C02-5D55-4A62-A4F6-134A487B365A} - System32\Tasks\ATuning => C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\ATuning.exe [9712088 2020-11-10] (ASRock Incorporation -> ASRock Incorporation)
Task: {4E7EFD74-3D23-41B8-9601-192F343DC2A3} - System32\Tasks\AMD.PROCC CleanupTemporaryInternetFiles => C:\Program Files (x86)\AMD PRO Control Center\AMD.PROCC.CleanupSchedulerTool.exe [15464 2015-03-20] (Advanced Micro Devices, Inc. -> AMD) [File not signed]
Task: {62F032BC-8855-4046-B9D4-F663B6C2DA5C} - System32\Tasks\ASUS\ASUS Manager BackgroundWindow => C:\Program Files (x86)\ASUS\ASUS Manager\BackgroundWindow.exe [21784 2016-03-24] (ASUSTeK Computer Inc. -> )
Task: {652BA8CE-4678-46F3-BB08-A700B4C3624B} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [43520 2021-06-17] (Advanced Micro Devices, Inc.) [File not signed]
Task: {74C3086F-25AE-4497-86E4-D88DD96E03A5} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [5938888 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {7A4CB82E-EBFC-4776-8E8A-4515F4A9B97A} - System32\Tasks\ASUS\ASUS Updater => C:\Program Files (x86)\ASUS\ASUS Manager\Application Update\ASUSFourceUpdater.exe [940496 2016-07-15] (ASUSTeK Computer Inc. -> )
Task: {82740ED4-9641-4FA3-AB86-048E2CB6CF57} - System32\Tasks\CorelUpdateHelperTask-FA701FD46DEE5BD579DFADDAEEB217B7 => c:\Program Files (x86)\Corel\CUH\v2\CUH.exe
Task: {8AD7FEA3-81CE-4B45-8DC5-F2389D0EDD98} - System32\Tasks\ASUS\ASUS Update Checker => C:\Program Files (x86)\ASUS\ASUS Manager\Application Update\ASUSUpdateChecker.exe [922576 2016-07-15] (ASUSTeK Computer Inc. -> )
Task: {98AA6CF0-4172-48B2-BBFE-6FF2A985CEC8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-26] (Adobe Inc. -> Adobe Inc.)
Task: {993A37B3-01F9-4BB2-BC1C-D68F028B43B8} - System32\Tasks\ASUS\ASUS Manager HotKey Service => C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe [225592 2016-03-24] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {AEEE1EA9-C467-4921-A6E9-E09A4549DD47} - System32\Tasks\AMD.PROCC SleepHibernate Computer => C:\Program Files (x86)\AMD PRO Control Center\AMD.PROCC.Notifier.exe [35432 2015-03-20] (Advanced Micro Devices, Inc. -> AMD) [File not signed]
Task: {C383F64F-0048-4657-B415-2841483C9CD8} - System32\Tasks\AMD.PROCC WakeUp Computer => C:\Program Files (x86)\AMD PRO Control Center\AMD.PROCC.Notifier.exe [35432 2015-03-20] (Advanced Micro Devices, Inc. -> AMD) [File not signed]
Task: {C72EC81B-BE97-4A55-9455-930D1D35CAF4} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe [382168 2020-05-21] (Advanced Micro Devices INC. -> )
Task: {D36CC70A-A288-4280-9F5D-EDF94D666537} - System32\Tasks\ASUS\SyncUp => C:\Program Files (x86)\ASUS\ASUS Manager\SyncUp\Server\SyncUp Server.exe [3494200 2015-04-01] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {DD3FEA5B-2D0B-4BF1-9850-F65C5AF6FDF1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-25] (Google Inc -> Google LLC)
Task: {DFCFA362-B87D-44BA-B5CD-9C7A26520BB2} - System32\Tasks\AMD.PROCC CleanupCookies => C:\Program Files (x86)\AMD PRO Control Center\AMD.PROCC.CleanupSchedulerTool.exe [15464 2015-03-20] (Advanced Micro Devices, Inc. -> AMD) [File not signed]
Task: {EE59E04B-C17C-4E7B-9D37-96BC34BA7D0C} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [269272 2021-06-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {F24D8FE8-E872-4219-8DC9-A5F418729EF8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-25] (Google Inc -> Google LLC)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{584842d4-e75c-45ee-ab0a-bf62afbcb7f9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{585f592d-776d-4dad-884c-a7dbfb45f42c}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{bd960918-39e4-4af6-bc57-d3df8698c303}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\javau\AppData\Local\Microsoft\Edge\User Data\Default [2021-07-07]
Will post the remainder of this log, and the next log separately.