Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Problems with soundcard, control panel and apps. Found Misleading.FakeAV?  (Read 11484 times)

0 Members and 1 Guest are viewing this topic.

PeterClausen

    Topic Starter


    Greenhorn

    • Experience: Familiar
    • OS: Windows 8
    Hello Malware Fighters!
    I am total newbie to this forum, so i hope you will forgive me, if i make some stupid questions ;)

    My brothers pc is having a bit of trouble. It is a Dell Inspiron 17 with Windows 8 64-bit. The soundcard won't work, the controlpanel frezzers, apps will not start and so on. The internet works fine with Chrome, but Explorer will not start. Advance Systemcare 7 found Misleading.FakeAV?, and i tried to delete it. It did not work. Can you please help me?

    If you have questions please write :D

    It will be amazing if you can help me!

    Hope the logs is okay.

    Logs:

    Malware Bytes:

    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org

    Database version: v2014.02.24.08

    Windows 8 x64 NTFS
    Internet Explorer 10.0.9200.16750
    Niels Clausen :: NIELS [administrator]

    24-02-2014 21:07:11
    MBAM-log-2014-02-24 (21-12-20).txt

    Skanningstype: Hurtig skanning
    Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
    Skanningsmuligheder som er deaktiverede: P2P
    Objekter skannet: 216015
    Tid gået: 4 minut(ter), 7 sekund(er)

    Hukommelses Processorer Inficeret: 1
    C:\Windows\KMService.exe (RiskWare.Tool.CK) -> 1976 -> Ingen handling valgt.

    Hukommelses Moduler Inficeret: 0
    (Ingen skadelige objekter blev fundet)

    Registreringsdatabasenøgler Inficeret: 0
    (Ingen skadelige objekter blev fundet)

    Registreringsdatabaseværdier Inficeret: 0
    (Ingen skadelige objekter blev fundet)

    Registreringsdatabasedata Objekter Inficeret: 0
    (Ingen skadelige objekter blev fundet)

    Inficerede Mapper: 0
    (Ingen skadelige objekter blev fundet)

    Inficerede Filer: 1
    C:\Windows\KMService.exe (RiskWare.Tool.CK) -> Ingen handling valgt.

    (færdig)

    Adwcleaner:

    # AdwCleaner v3.019 - Report created 24/02/2014 at 20:58:45
    # Updated 17/02/2014 by Xplode
    # Operating System : Windows 8  (64 bits)
    # Username : Niels Clausen - NIELS
    # Running from : C:\Users\Niels Clausen\Downloads\adwcleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Deleted : C:\Program Files (x86)\Vuze

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
    Key Deleted : HKCU\Software\Conduit

    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16537


    -\\ Google Chrome v33.0.1750.117

    [ File : C:\Users\Niels Clausen\AppData\Local\Google\Chrome\User Data\Default\preferences ]


    *************************

    AdwCleaner[R0].txt - [1126 octets] - [24/02/2014 20:54:18]
    AdwCleaner[S0].txt - [1015 octets] - [24/02/2014 20:58:45]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1075 octets] ##########

    Security Check: 

    Results of screen317's Security Check version 0.99.79 
       x64 (UAC is enabled) 
     Internet Explorer 10 Out of date!
    ``````````````Antivirus/Firewall Check:``````````````[/u]
     Windows Firewall Enabled! 
     Windows Firewall Disabled! 
     WMI entry may not exist for antivirus; attempting automatic update.
    `````````Anti-malware/Other Utilities Check:`````````[/u]
     Malwarebytes Anti-Malware version 1.75.0.1300 
     Java 7 Update 45 
     Java version out of Date!
     Google Chrome 32.0.1700.102 
     Google Chrome 33.0.1750.117 
    ````````Process Check: objlist.exe by Laurent````````[/u] 
    `````````````````System Health check`````````````````[/u]
     Total Fragmentation on Drive C:  %
    ````````````````````End of Log``````````````````````[/u]
     

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    *************************************************************************
    You will need to run MBAM again. Make sure all the infections have a checkmark and select "Remove Selected." 
    Why have you not upgraded your Internet Explorer? Is this a legal Windows OS?


    Looking over your log it seems you don't have any antivirus software.

    Before we continue download and install a free antivirus.

    Remember to only install one antivirus!
     
    1) Avast! Home Edition
    2) AVG Free Edition
    3) Avira AntiVir Personal
    4) MicroSoft Security Essentials   All versions and all languages.
    5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
    6) PC Tools AntiVirus Free Edition

    It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.
    *************************************************
    Please download Junkware Removal Tool to your desktop.

    Warning! Once the scan is complete JRT will shut down your browser with NO warning.

    Shut down your protection software now to avoid potential conflicts.

    •Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    •Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

    •The tool will open and start scanning your system.

    •Please be patient as this can take a while to complete depending on your system's specifications.

    •On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

    •Copy and Paste the JRT.txt log into your next message.
    Windows 8 and Windows 10 dual boot with two SSD's

    PeterClausen

      Topic Starter


      Greenhorn

      • Experience: Familiar
      • OS: Windows 8
      Hi Dave.
      The windows OS is legal and came with the laptop from Dell. I have run MBAM again and delete the file.  The laptop have Avast, so it is a bit weird the logs do not show it. I have uninstalled it, i installed AVG instead. It is my brothers pc, and I think he has been lazy with the updates. Windows update and windows store will not work and probably many others app. So I cannot update…  I have installed Junkware Removal Tool, but it freezes. Then I push a button and it starts, but it stops again pretty quickly when checking processes. I have tried to turn off the AV, but it does not help. Thanks again for your time! :D
      Here are some updated logs, if you can use it :)
      AdwCleaner:

      # AdwCleaner v3.019 - Report created 25/02/2014 at 14:47:01
      # Updated 17/02/2014 by Xplode
      # Operating System : Windows 8  (64 bits)
      # Username : Niels Clausen - NIELS
      # Running from : C:\Users\Niels Clausen\Downloads\adwcleaner (1).exe
      # Option : Clean

      ***** [ Services ] *****


      ***** [ Files / Folders ] *****


      ***** [ Shortcuts ] *****


      ***** [ Registry ] *****


      ***** [ Browsers ] *****

      -\\ Internet Explorer v10.0.9200.16537


      -\\ Google Chrome v33.0.1750.117

      [ File : C:\Users\Niels Clausen\AppData\Local\Google\Chrome\User Data\Default\preferences ]


      *************************

      AdwCleaner[R0].txt - [1126 octets] - [24/02/2014 20:54:18]
      AdwCleaner[R1].txt - [881 octets] - [25/02/2014 14:45:02]
      AdwCleaner[S0].txt - [1159 octets] - [24/02/2014 20:58:45]
      AdwCleaner[S1].txt - [803 octets] - [25/02/2014 14:47:01]

      ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [862 octets] ##########

      mbam:
      Malwarebytes Anti-Malware 1.75.0.1300
      www.malwarebytes.org

      Database version: v2014.02.24.08

      Windows 8 x64 NTFS
      Internet Explorer 10.0.9200.16750
      Niels Clausen :: NIELS [administrator]

      25-02-2014 14:54:37
      mbam-log-2014-02-25 (14-54-37).txt

      Skanningstype: Hurtig skanning
      Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
      Skanningsmuligheder som er deaktiverede: P2P
      Objekter skannet: 215820
      Tid gået: 4 minut(ter), 8 sekund(er)

      Hukommelses Processorer Inficeret: 0
      (Ingen skadelige objekter blev fundet)

      Hukommelses Moduler Inficeret: 0
      (Ingen skadelige objekter blev fundet)

      Registreringsdatabasenøgler Inficeret: 0
      (Ingen skadelige objekter blev fundet)

      Registreringsdatabaseværdier Inficeret: 0
      (Ingen skadelige objekter blev fundet)

      Registreringsdatabasedata Objekter Inficeret: 0
      (Ingen skadelige objekter blev fundet)

      Inficerede Mapper: 0
      (Ingen skadelige objekter blev fundet)

      Inficerede Filer: 0
      (Ingen skadelige objekter blev fundet)

      (færdig)

      Results of screen317's Security Check version 0.99.79 
         x64 (UAC is enabled) 
       Internet Explorer 10 Out of date!
      ``````````````Antivirus/Firewall Check:``````````````[/u]
       Windows Security Center service is not running! This report may not be accurate!
       Windows Firewall Enabled! 
       Windows Firewall Disabled! 
       WMI entry may not exist for antivirus; attempting automatic update.
      `````````Anti-malware/Other Utilities Check:`````````[/u]
       Malwarebytes Anti-Malware version 1.75.0.1300 
       Java 7 Update 45 
       Java version out of Date!
       Google Chrome 32.0.1700.102 
       Google Chrome 33.0.1750.117 
      ````````Process Check: objlist.exe by Laurent````````[/u] 
      `````````````````System Health check`````````````````[/u]
       Total Fragmentation on Drive C:  %
      ````````````````````End of Log``````````````````````[/u]

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Quote
      Windows update and windows store will not work and probably many others app.
      What happens when you try to get your updates manually?

      Please download and run MS Fix-it from here. Click on "Visit our solution center" and click on the Windows tab. This tool may also repair the sound and IE problems.

      Quote
      The laptop have Avast, so it is a bit weird the logs do not show it.
      I'm sorry. You have Windows 7 in your profile while in reality, the computer has Windows 8 which mislead me. Windows 8 comes with it's own Av; Windows Defender. If your brother is laxical about updates, Windows Defender will look after the updates. If you're going to stick with AVG, you will need to disable Windows Defender.

      Update Your Java (JRE)

      Old versions of Java have vulnerabilities that malware can use to infect your system.


      First Verify your Java Version

      If there are any other version(s) installed then update now.

      Get the new version (if needed)

      If your version is out of date install the newest version of the Sun Java Runtime Environment.

      Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

      Be sure to close ALL open web browsers before starting the installation.

      Remove any old versions

      1. Download JavaRa and unzip the file to your Desktop.
      2. Open JavaRA.exe and choose Remove Older Versions
      3. Once complete exit JavaRA.

      Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
      Windows 8 and Windows 10 dual boot with two SSD's

      PeterClausen

        Topic Starter


        Greenhorn

        • Experience: Familiar
        • OS: Windows 8
        I can not update it manually. When i go to options and find windows update it is just a blank page (See attachments). MS_fix do not support windows 8 i think (See attachments). When i try via the desktop to search after updates, it says it need to restart the computer, because windows update is not started. But a restart does not help.   
        When i try to start windows defender, there comes an error message, that says it will not start.

        I have tried to use the  WindowsUpdateDiagnostic tool fund on the solutioncenter, it did not work.

        Also i have  327 background processes when i see my tasklist, can that be normal? The majority is "Windows Problem Reporting".

        I have tried to use the  WindowsUpdateDiagnostic tool fund on the solutioncenter, it did not work.

        To the good news. Java is now updated and all older versions should be gone.

        Thanks again! :)


        [recovering disk space, attachment deleted by admin]

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Quote
        Also i have  327 background processes when i see my tasklist, can that be normal? The majority is "Windows Problem Reporting".
        That's because something is not working correctly on your computer.

        Please download Farbar Service Scanner and run it on the computer with the issue.
        • Press "Scan".
        • It will create a log (FSS.txt) in the same directory the tool is run.
        • Please copy and paste the log to your reply.
        Windows 8 and Windows 10 dual boot with two SSD's

        PeterClausen

          Topic Starter


          Greenhorn

          • Experience: Familiar
          • OS: Windows 8

          Here is the log :D

          Farbar Service Scanner Version: 25-02-2014
          Ran by Niels Clausen (administrator) on 26-02-2014 at 21:54:48
          Running from "C:\Users\Niels Clausen\Downloads"
          Windows 8  (X64)
          Boot Mode: Normal
          ****************************************************************

          Internet Services:
          ============

          Connection Status:
          ==============
          Localhost is accessible.
          LAN connected.
          Google IP is accessible.
          Google.com is accessible.
          Yahoo.com is accessible.


          Windows Firewall:
          =============

          Firewall Disabled Policy:
          ==================
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
          "EnableFirewall"=DWORD:0


          System Restore:
          ============

          System Restore Disabled Policy:
          ========================


          Action Center:
          ============


          Windows Update:
          ============
          wuauserv Service is not running. Checking service configuration:
          The start type of wuauserv service is OK.
          The ImagePath of wuauserv service is OK.
          The ServiceDll of wuauserv: "C:\Windows\system32\wuaueng.dll".

          BITS Service is not running. Checking service configuration:
          The start type of BITS service is OK.
          The ImagePath of BITS service is OK.
          The ServiceDll of BITS service is OK.


          Windows Autoupdate Disabled Policy:
          ============================


          Windows Defender:
          ==============
          WinDefend Service is not running. Checking service configuration:
          The start type of WinDefend service is set to Demand. The default start type is Auto.
          The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"".


          Windows Defender Disabled Policy:
          ==========================
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
          "DisableAntiSpyware"=DWORD:1


          Other Services:
          ==============


          File Check:
          ========
          C:\Windows\System32\nsisvc.dll => MD5 is legit
          C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
          C:\Windows\System32\dhcpcore.dll => MD5 is legit
          C:\Windows\System32\drivers\afd.sys
          [2013-12-19 12:36] - [2013-09-04 04:11] - 0576512 ____A (Microsoft Corporation) 7C0E0EDF18D6CC565D7BFBB451709FA5

          C:\Windows\System32\drivers\tdx.sys => MD5 is legit
          C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
          C:\Windows\System32\dnsrslvr.dll => MD5 is legit
          C:\Windows\System32\mpssvc.dll
          [2014-01-15 07:52] - [2013-10-31 06:56] - 0915968 ____A (Microsoft Corporation) 9DE3341BD4E14BC5FADFCAD3019F2D0D

          C:\Windows\System32\bfe.dll
          [2013-12-19 12:42] - [2013-10-10 10:20] - 0723968 ____A (Microsoft Corporation) 53AA55632B94622F2DC3695E86EF9363

          C:\Windows\System32\drivers\mpsdrv.sys
          [2014-01-15 07:52] - [2013-10-31 04:42] - 0074752 ____A (Microsoft Corporation) 4CCBBD4944777CA100B9A6C2F149A46F

          C:\Windows\System32\SDRSVC.dll => MD5 is legit
          C:\Windows\System32\vssvc.exe => MD5 is legit
          C:\Windows\System32\wscsvc.dll => MD5 is legit
          C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
          C:\Windows\System32\wuaueng.dll
          [2013-12-19 12:37] - [2013-10-08 23:27] - 3279872 ____A (Microsoft Corporation) 311E5E1976E0BD9110A88B93158055D5

          C:\Windows\System32\qmgr.dll => MD5 is legit
          C:\Windows\System32\es.dll => MD5 is legit
          C:\Windows\System32\cryptsvc.dll => MD5 is legit
          C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
          C:\Program Files\Windows Defender\MsMpEng.exe => MD5 is legit
          C:\Windows\System32\ipnathlp.dll => MD5 is legit
          C:\Windows\System32\iphlpsvc.dll => MD5 is legit
          C:\Windows\System32\svchost.exe => MD5 is legit
          C:\Windows\System32\rpcss.dll => MD5 is legit


          **** End of log ****

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Malwarebytes' Anti-Rootkit

          Please download Malwarebytes' Anti-Rootkit and save it to your desktop.
          • Be sure to print out and follow the instructions provided on that same page for performing a scan.
          • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
          • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
          • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
          • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
          • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
          • Copy and paste the contents of these two log files in your next reply.
          Windows 8 and Windows 10 dual boot with two SSD's

          PeterClausen

            Topic Starter


            Greenhorn

            • Experience: Familiar
            • OS: Windows 8
            Hi Dave.

            MBAR did not find any threats. I tried the fixdamage tool. It said it fix a file and rebooted, but i can not see any change.


            Systemlog:
            Malwarebytes Anti-Rootkit BETA 1.07.0.1009

            (c) Malwarebytes Corporation 2011-2012

            OS version: 6.2.9200 Windows 8 x64

            Account is Administrative

            Internet Explorer version: 10.0.9200.16750

            File system is: NTFS
            Disk drives: C:\ DRIVE_FIXED, X:\ DRIVE_FIXED, Y:\ DRIVE_FIXED
            CPU speed: 2.295000 GHz
            Memory total: 6317625344, free: 2503000064

            Downloaded database version: v2014.02.27.04
            Downloaded database version: v2014.02.20.01
            =======================================
            Initializing...
            ------------ Kernel report ------------
                 02/27/2014 15:16:28
            ------------ Loaded modules -----------
            \SystemRoot\system32\ntoskrnl.exe
            \SystemRoot\system32\hal.dll
            \SystemRoot\system32\kd.dll
            \SystemRoot\system32\mcupdate_GenuineIntel.dll
            \SystemRoot\System32\drivers\CLFS.SYS
            \SystemRoot\System32\drivers\tm.sys
            \SystemRoot\system32\PSHED.dll
            \SystemRoot\system32\BOOTVID.dll
            \SystemRoot\system32\CI.dll
            \SystemRoot\System32\drivers\msrpc.sys
            \SystemRoot\system32\drivers\Wdf01000.sys
            \SystemRoot\system32\drivers\WDFLDR.SYS
            \SystemRoot\System32\Drivers\acpiex.sys
            \SystemRoot\System32\Drivers\WppRecorder.sys
            \SystemRoot\System32\drivers\ACPI.sys
            \SystemRoot\System32\drivers\WMILIB.SYS
            \SystemRoot\System32\drivers\msisadrv.sys
            \SystemRoot\System32\drivers\pci.sys
            \SystemRoot\System32\Drivers\cng.sys
            \SystemRoot\system32\drivers\tpm.sys
            \SystemRoot\System32\drivers\vdrvroot.sys
            \SystemRoot\system32\drivers\pdc.sys
            \SystemRoot\System32\drivers\partmgr.sys
            \SystemRoot\System32\drivers\spaceport.sys
            \SystemRoot\System32\drivers\volmgr.sys
            \SystemRoot\System32\drivers\volmgrx.sys
            \SystemRoot\System32\drivers\mountmgr.sys
            \SystemRoot\System32\drivers\iaStorA.sys
            \SystemRoot\System32\drivers\storport.sys
            \SystemRoot\System32\drivers\EhStorClass.sys
            \SystemRoot\system32\drivers\fltmgr.sys
            \SystemRoot\System32\drivers\fileinfo.sys
            \SystemRoot\System32\Drivers\Ntfs.sys
            \SystemRoot\System32\Drivers\ksecdd.sys
            \SystemRoot\System32\drivers\pcw.sys
            \SystemRoot\System32\Drivers\Fs_Rec.sys
            \SystemRoot\system32\drivers\ndis.sys
            \SystemRoot\system32\drivers\NETIO.SYS
            \SystemRoot\System32\Drivers\ksecpkg.sys
            \SystemRoot\System32\drivers\tcpip.sys
            \SystemRoot\System32\drivers\fwpkclnt.sys
            \SystemRoot\system32\DRIVERS\wfplwfs.sys
            \SystemRoot\system32\DRIVERS\avgloga.sys
            \SystemRoot\system32\DRIVERS\avgmfx64.sys
            \SystemRoot\System32\DRIVERS\fvevol.sys
            \SystemRoot\system32\DRIVERS\avgidsha.sys
            \SystemRoot\System32\drivers\volsnap.sys
            \SystemRoot\System32\drivers\rdyboost.sys
            \SystemRoot\System32\Drivers\mup.sys
            \SystemRoot\System32\drivers\disk.sys
            \SystemRoot\System32\drivers\CLASSPNP.SYS
            \SystemRoot\system32\DRIVERS\avgrkx64.sys
            \SystemRoot\System32\Drivers\crashdmp.sys
            \SystemRoot\System32\drivers\cdrom.sys
            \SystemRoot\System32\Drivers\Null.SYS
            \SystemRoot\System32\Drivers\Beep.SYS
            \SystemRoot\System32\drivers\BasicRender.sys
            \SystemRoot\System32\drivers\dxgkrnl.sys
            \SystemRoot\System32\drivers\watchdog.sys
            \SystemRoot\System32\drivers\dxgmms1.sys
            \SystemRoot\System32\drivers\BasicDisplay.sys
            \SystemRoot\System32\Drivers\Npfs.SYS
            \SystemRoot\System32\Drivers\Msfs.SYS
            \SystemRoot\system32\DRIVERS\avgwfpa.sys
            \SystemRoot\system32\DRIVERS\tdx.sys
            \SystemRoot\system32\DRIVERS\TDI.SYS
            \SystemRoot\System32\DRIVERS\netbt.sys
            \SystemRoot\system32\drivers\afd.sys
            \SystemRoot\system32\DRIVERS\pacer.sys
            \SystemRoot\system32\DRIVERS\vwififlt.sys
            \SystemRoot\system32\DRIVERS\netbios.sys
            \SystemRoot\system32\DRIVERS\avgldx64.sys
            \SystemRoot\system32\DRIVERS\rdbss.sys
            \SystemRoot\system32\DRIVERS\wanarp.sys
            \SystemRoot\system32\drivers\nsiproxy.sys
            \SystemRoot\System32\drivers\npsvctrig.sys
            \SystemRoot\System32\drivers\mssmbios.sys
            \SystemRoot\System32\drivers\discache.sys
            \SystemRoot\System32\Drivers\dfsc.sys
            \SystemRoot\system32\DRIVERS\CLVirtualDrive.sys
            \SystemRoot\system32\DRIVERS\avgidsdrivera.sys
            \SystemRoot\system32\DRIVERS\avgdiska.sys
            \SystemRoot\system32\DRIVERS\ndistapi.sys
            \SystemRoot\system32\DRIVERS\ndiswan.sys
            \SystemRoot\system32\DRIVERS\rassstp.sys
            \SystemRoot\system32\DRIVERS\AgileVpn.sys
            \SystemRoot\system32\DRIVERS\tunnel.sys
            \SystemRoot\System32\drivers\CompositeBus.sys
            \SystemRoot\system32\DRIVERS\kdnic.sys
            \SystemRoot\System32\drivers\umbus.sys
            \SystemRoot\system32\DRIVERS\igdkmd64.sys
            \SystemRoot\System32\drivers\HDAudBus.sys
            \SystemRoot\System32\drivers\USBXHCI.SYS
            \SystemRoot\System32\drivers\ucx01000.sys
            \SystemRoot\System32\drivers\TeeDriverx64.sys
            \SystemRoot\system32\DRIVERS\Rt630x64.sys
            \SystemRoot\system32\DRIVERS\athw8x.sys
            \SystemRoot\System32\drivers\vwifibus.sys
            \SystemRoot\System32\drivers\usbehci.sys
            \SystemRoot\System32\drivers\USBPORT.SYS
            \SystemRoot\System32\drivers\i8042prt.sys
            \SystemRoot\System32\drivers\SynTP.sys
            \SystemRoot\System32\drivers\USBD.SYS
            \SystemRoot\System32\drivers\kbdclass.sys
            \SystemRoot\System32\drivers\mouclass.sys
            \SystemRoot\System32\drivers\CmBatt.sys
            \SystemRoot\System32\drivers\BATTC.SYS
            \SystemRoot\System32\drivers\Smb_driver_Intel.sys
            \SystemRoot\System32\drivers\DellRbtn.sys
            \SystemRoot\System32\drivers\mshidkmdf.sys
            \SystemRoot\System32\drivers\HIDCLASS.SYS
            \SystemRoot\System32\drivers\HIDPARSE.SYS
            \SystemRoot\System32\drivers\wmiacpi.sys
            \SystemRoot\System32\drivers\intelppm.sys
            \SystemRoot\system32\DRIVERS\serscan.sys
            \SystemRoot\system32\drivers\ksthunk.sys
            \SystemRoot\system32\drivers\ks.sys
            \SystemRoot\system32\DRIVERS\raspptp.sys
            \SystemRoot\system32\DRIVERS\rasl2tp.sys
            \SystemRoot\system32\DRIVERS\raspppoe.sys
            \SystemRoot\System32\drivers\swenum.sys
            \SystemRoot\System32\drivers\btath_bus.sys
            \SystemRoot\System32\drivers\rdpbus.sys
            \SystemRoot\System32\Drivers\NDProxy.SYS
            \SystemRoot\System32\drivers\usbhub.sys
            \SystemRoot\system32\DRIVERS\portcls.sys
            \SystemRoot\system32\DRIVERS\drmk.sys
            \SystemRoot\System32\drivers\UsbHub3.sys
            \SystemRoot\system32\drivers\RTKVHD64.sys
            \SystemRoot\System32\drivers\usbccgp.sys
            \SystemRoot\System32\drivers\hidusb.sys
            \SystemRoot\System32\drivers\kbdhid.sys
            \SystemRoot\System32\drivers\mouhid.sys
            \SystemRoot\system32\DRIVERS\btfilter.sys
            \SystemRoot\System32\Drivers\BTHUSB.sys
            \SystemRoot\System32\Drivers\bthport.sys
            \SystemRoot\System32\Drivers\RtsUVStor.sys
            \SystemRoot\System32\Drivers\usbvideo.sys
            \SystemRoot\system32\DRIVERS\BthLEEnum.sys
            \SystemRoot\system32\DRIVERS\rfcomm.sys
            \SystemRoot\system32\DRIVERS\BthEnum.sys
            \SystemRoot\system32\DRIVERS\bthpan.sys
            \SystemRoot\System32\drivers\btath_rcp.sys
            \SystemRoot\system32\drivers\btath_avdt.sys
            \SystemRoot\system32\drivers\btath_a2dp.sys
            \SystemRoot\System32\drivers\btath_hcrp.sys
            \SystemRoot\system32\DRIVERS\btath_flt.sys
            \SystemRoot\system32\DRIVERS\btath_lwflt.sys
            \SystemRoot\System32\Drivers\fastfat.SYS
            \SystemRoot\System32\Drivers\dump_diskdump.sys
            \SystemRoot\System32\Drivers\dump_iaStorA.sys
            \SystemRoot\System32\Drivers\dump_dumpfve.sys
            \SystemRoot\System32\win32k.sys
            \SystemRoot\System32\TSDDD.dll
            \SystemRoot\System32\cdd.dll
            \SystemRoot\System32\ATMFD.DLL
            \SystemRoot\system32\drivers\luafv.sys
            \SystemRoot\system32\DRIVERS\lltdio.sys
            \SystemRoot\system32\DRIVERS\nwifi.sys
            \SystemRoot\system32\DRIVERS\ndisuio.sys
            \SystemRoot\system32\DRIVERS\rspndr.sys
            \SystemRoot\system32\drivers\HTTP.sys
            \SystemRoot\system32\DRIVERS\vwifimp.sys
            \SystemRoot\system32\DRIVERS\bowser.sys
            \SystemRoot\System32\drivers\mpsdrv.sys
            \SystemRoot\system32\DRIVERS\mrxsmb.sys
            \SystemRoot\system32\DRIVERS\mrxsmb10.sys
            \SystemRoot\system32\DRIVERS\mrxsmb20.sys
            \SystemRoot\system32\drivers\Ndu.sys
            \SystemRoot\system32\drivers\peauth.sys
            \SystemRoot\System32\Drivers\secdrv.SYS
            \SystemRoot\System32\DRIVERS\srvnet.sys
            \SystemRoot\System32\drivers\tcpipreg.sys
            \SystemRoot\System32\DRIVERS\srv2.sys
            \SystemRoot\System32\DRIVERS\srv.sys
            \SystemRoot\system32\DRIVERS\cdfs.sys
            \SystemRoot\System32\drivers\condrv.sys
            \SystemRoot\system32\DRIVERS\asyncmac.sys
            \SystemRoot\system32\DRIVERS\monitor.sys
            \??\C:\Windows\system32\drivers\mbamchameleon.sys
            \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
            ----------- End -----------
            Done!
            <<<1>>>
            Upper Device Name: \Device\Harddisk0\DR0
            Upper Device Object: 0xfffffa80080d7060
            Upper Device Driver Name: \Driver\disk\
            Lower Device Name: \Device\00000039\
            Lower Device Object: 0xfffffa80066d6060
            Lower Device Driver Name: \Driver\iaStorA\
            <<<2>>>
            Physical Sector Size: 512
            Drive: 0, DevicePointer: 0xfffffa80080d7060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
            --------- Disk Stack ------
            DevicePointer: 0xfffffa80080d82b0, DeviceName: Unknown, DriverName: \Driver\partmgr\
            DevicePointer: 0xfffffa80080d7060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
            DevicePointer: 0xfffffa8005b63cc0, DeviceName: Unknown, DriverName: \Driver\ACPI\
            DevicePointer: 0xfffffa80066d6060, DeviceName: \Device\00000039\, DriverName: \Driver\iaStorA\
            ------------ End ----------
            Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
            Upper DeviceData: 0x0, 0x0, 0x0
            Lower DeviceData: 0x0, 0x0, 0x0
            <<<3>>>
            Volume: C:
            File system type: NTFS
            SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
            <<<2>>>
            <<<3>>>
            Volume: C:
            File system type: NTFS
            SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
            Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
            <<<2>>>
            <<<3>>>
            Volume: C:
            File system type: NTFS
            SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
            Read File: File "C:\Windows\System32\Drivers\vwifibus.sys" is compressed (flags = 1)
            Read File: File "C:\WINDOWS\SYSTEM32\drivers\vwifibus.sys" is compressed (flags = 1)
            Done!
            Drive 0
            Scanning MBR on drive 0...
            Inspecting partition table:
            This drive is a GPT Drive.
            MBR Signature: 55AA
            Disk Signature: 44D1A162

            GPT Protective MBR Partition information:

                Partition 0 type is EFI-GPT (0xee)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 1  Numsec = 4294967295

                Partition 1 type is Empty (0x0)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 0  Numsec = 0

                Partition 2 type is Empty (0x0)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 0  Numsec = 0

                Partition 3 type is Empty (0x0)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 0  Numsec = 0

            GPT Partition information:

                GPT Header Signature 4546492050415254
                GPT Header Revision 65536 Size 92 CRC 2505083374
                GPT Header CurrentLba = 1 BackupLba 1465149167
                GPT Header FirstUsableLba 34  LastUsableLba 1465149134
                GPT Header Guid 24c4ead8-fe42-4297-9aee-402535de7797
                GPT Header Contains 128 partition entries starting at LBA 2
                GPT Header Partition entry size = 128

                Backup GPT header Signature 4546492050415254
                Backup GPT header Revision 65536 Size 92 CRC 2505083374
                Backup GPT header CurrentLba = 1465149167 BackupLba 1
                Backup GPT header FirstUsableLba 34  LastUsableLba 1465149134
                Backup GPT header Guid 24c4ead8-fe42-4297-9aee-402535de7797
                Backup GPT header Contains 128 partition entries starting at LBA 1465149135
                Backup GPT header Partition entry size = 128

                Partition 0 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
                Partition ID 9bb5d2e-481c-4fc3-afe8-c052e0733d7e
                FirstLBA 2048  Last LBA 1026047
                Attributes 0
                Partition Name                 EFI system partition

                GPT Partition 0 is bootable
                Partition 1 Type 796badd3-6bbf-4d9f-b631-466eb71a4965
                Partition ID ad681f2d-41c6-48e7-b1ea-43906a705949
                FirstLBA 1026048  Last LBA 1107967
                Attributes 1
                Partition Name                 Basic data partition

                Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
                Partition ID 6488712e-b6a9-4d06-9ccd-fd586489b015
                FirstLBA 1107968  Last LBA 1370111
                Attributes 0
                Partition Name         Microsoft reserved partition

                Partition 3 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
                Partition ID 29a4d99c-bf4d-4d2a-a150-6e948fb753b4
                FirstLBA 1370112  Last LBA 2373631
                Attributes 1
                Partition Name                 Basic data partition

                Partition 4 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
                Partition ID 8a4a6132-ccd5-48b0-978a-61df32d2aac4
                FirstLBA 2373632  Last LBA 1440112639
                Attributes 0
                Partition Name                 Basic data partition

                Partition 5 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
                Partition ID 50899bd-6151-43c6-99b4-678e4e963219
                FirstLBA 1440112640  Last LBA 1465147119
                Attributes 1
                Partition Name         Microsoft recovery partition

            Disk Size: 750156374016 bytes
            Sector size: 512 bytes

            Done!
            Read File:  File "c:\programdata\avg2014\chjw\40c4fb5ec4fb549e.dat:8a5e4f29-a7ed-411c-b562-b34257f0c02c" is sparse (flags = 32768)
            Scan finished
            =======================================
            <<<1>>>
            Upper Device Name: \Device\Harddisk0\DR0
            Upper Device Object: 0xfffffa80080d7060
            Upper Device Driver Name: \Driver\disk\
            Lower Device Name: \Device\00000039\
            Lower Device Object: 0xfffffa80066d6060
            Lower Device Driver Name: \Driver\iaStorA\
            <<<2>>>
            <<<3>>>
            Volume: C:
            File system type: NTFS
            SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
            <<<2>>>
            <<<3>>>
            Volume: C:
            File system type: NTFS
            SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
            Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
            <<<2>>>
            <<<3>>>
            Volume: C:
            File system type: NTFS
            SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
            Read File: File "C:\Windows\System32\Drivers\vwifibus.sys" is compressed (flags = 1)
            Read File: File "C:\WINDOWS\SYSTEM32\drivers\vwifibus.sys" is compressed (flags = 1)
            Done!
            Drive 0
            Scanning MBR on drive 0...
            Inspecting partition table:
            This drive is a GPT Drive.
            MBR Signature: 55AA
            Disk Signature: 44D1A162

            GPT Protective MBR Partition information:

                Partition 0 type is EFI-GPT (0xee)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 1  Numsec = 4294967295

                Partition 1 type is Empty (0x0)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 0  Numsec = 0

                Partition 2 type is Empty (0x0)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 0  Numsec = 0

                Partition 3 type is Empty (0x0)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 0  Numsec = 0

            GPT Partition information:

                GPT Header Signature 4546492050415254
                GPT Header Revision 65536 Size 92 CRC 2505083374
                GPT Header CurrentLba = 1 BackupLba 1465149167
                GPT Header FirstUsableLba 34  LastUsableLba 1465149134
                GPT Header Guid 24c4ead8-fe42-4297-9aee-402535de7797
                GPT Header Contains 128 partition entries starting at LBA 2
                GPT Header Partition entry size = 128

                Backup GPT header Signature 4546492050415254
                Backup GPT header Revision 65536 Size 92 CRC 2505083374
                Backup GPT header CurrentLba = 1465149167 BackupLba 1
                Backup GPT header FirstUsableLba 34  LastUsableLba 1465149134
                Backup GPT header Guid 24c4ead8-fe42-4297-9aee-402535de7797
                Backup GPT header Contains 128 partition entries starting at LBA 1465149135
                Backup GPT header Partition entry size = 128

                Partition 0 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
                Partition ID 9bb5d2e-481c-4fc3-afe8-c052e0733d7e
                FirstLBA 2048  Last LBA 1026047
                Attributes 0
                Partition Name                 EFI system partition

                GPT Partition 0 is bootable
                Partition 1 Type 796badd3-6bbf-4d9f-b631-466eb71a4965
                Partition ID ad681f2d-41c6-48e7-b1ea-43906a705949
                FirstLBA 1026048  Last LBA 1107967
                Attributes 1
                Partition Name                 Basic data partition

                Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
                Partition ID 6488712e-b6a9-4d06-9ccd-fd586489b015
                FirstLBA 1107968  Last LBA 1370111
                Attributes 0
                Partition Name         Microsoft reserved partition

                Partition 3 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
                Partition ID 29a4d99c-bf4d-4d2a-a150-6e948fb753b4
                FirstLBA 1370112  Last LBA 2373631
                Attributes 1
                Partition Name                 Basic data partition

                Partition 4 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
                Partition ID 8a4a6132-ccd5-48b0-978a-61df32d2aac4
                FirstLBA 2373632  Last LBA 1440112639
                Attributes 0
                Partition Name                 Basic data partition

                Partition 5 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
                Partition ID 50899bd-6151-43c6-99b4-678e4e963219
                FirstLBA 1440112640  Last LBA 1465147119
                Attributes 1
                Partition Name         Microsoft recovery partition

            Disk Size: 750156374016 bytes
            Sector size: 512 bytes

            Done!
            Read File:  File "c:\programdata\avg2014\chjw\40c4fb5ec4fb549e.dat:8a5e4f29-a7ed-411c-b562-b34257f0c02c" is sparse (flags = 32768)
            Read File: File "C:\Windows\System32\config\systemprofile\AppData\Local\Avg2014\log\avgcore.log.1" is compressed (flags = 1)
            Scan finished
            =======================================


            Removal queue found; removal started
            Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
            Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
            Removal finished
            ---------------------------------------
            Malwarebytes Anti-Rootkit BETA 1.07.0.1009

            (c) Malwarebytes Corporation 2011-2012

            OS version: 6.2.9200 Windows 8 x64

            Account is Administrative

            Internet Explorer version: 10.0.9200.16750

            File system is: NTFS
            Disk drives: C:\ DRIVE_FIXED
            CPU speed: 2.295000 GHz
            Memory total: 6317625344, free: 4622536704

            Downloaded database version: v2014.02.27.05
            =======================================
            ------------ Kernel report ------------
                 02/27/2014 16:15:06
            ------------ Loaded modules -----------
            \SystemRoot\system32\ntoskrnl.exe
            \SystemRoot\system32\hal.dll
            \SystemRoot\system32\kd.dll
            \SystemRoot\system32\mcupdate_GenuineIntel.dll
            \SystemRoot\System32\drivers\CLFS.SYS
            \SystemRoot\System32\drivers\tm.sys
            \SystemRoot\system32\PSHED.dll
            \SystemRoot\system32\BOOTVID.dll
            \SystemRoot\system32\CI.dll
            \SystemRoot\System32\drivers\msrpc.sys
            \SystemRoot\system32\drivers\Wdf01000.sys
            \SystemRoot\system32\drivers\WDFLDR.SYS
            \SystemRoot\System32\Drivers\acpiex.sys
            \SystemRoot\System32\Drivers\WppRecorder.sys
            \SystemRoot\System32\drivers\ACPI.sys
            \SystemRoot\System32\drivers\WMILIB.SYS
            \SystemRoot\System32\drivers\msisadrv.sys
            \SystemRoot\System32\drivers\pci.sys
            \SystemRoot\System32\Drivers\cng.sys
            \SystemRoot\system32\drivers\tpm.sys
            \SystemRoot\System32\drivers\vdrvroot.sys
            \SystemRoot\system32\drivers\pdc.sys
            \SystemRoot\System32\drivers\partmgr.sys
            \SystemRoot\System32\drivers\spaceport.sys
            \SystemRoot\System32\drivers\volmgr.sys
            \SystemRoot\System32\drivers\volmgrx.sys
            \SystemRoot\System32\drivers\mountmgr.sys
            \SystemRoot\System32\drivers\iaStorA.sys
            \SystemRoot\System32\drivers\storport.sys
            \SystemRoot\System32\drivers\EhStorClass.sys
            \SystemRoot\system32\drivers\fltmgr.sys
            \SystemRoot\System32\drivers\fileinfo.sys
            \SystemRoot\System32\Drivers\Ntfs.sys
            \SystemRoot\System32\Drivers\ksecdd.sys
            \SystemRoot\System32\drivers\pcw.sys
            \SystemRoot\System32\Drivers\Fs_Rec.sys
            \SystemRoot\system32\drivers\ndis.sys
            \SystemRoot\system32\drivers\NETIO.SYS
            \SystemRoot\System32\Drivers\ksecpkg.sys
            \SystemRoot\System32\drivers\tcpip.sys
            \SystemRoot\System32\drivers\fwpkclnt.sys
            \SystemRoot\system32\DRIVERS\wfplwfs.sys
            \SystemRoot\system32\DRIVERS\avgloga.sys
            \SystemRoot\system32\DRIVERS\avgmfx64.sys
            \SystemRoot\System32\DRIVERS\fvevol.sys
            \SystemRoot\system32\DRIVERS\avgidsha.sys
            \SystemRoot\System32\drivers\volsnap.sys
            \SystemRoot\System32\drivers\rdyboost.sys
            \SystemRoot\System32\Drivers\mup.sys
            \SystemRoot\System32\drivers\disk.sys
            \SystemRoot\System32\drivers\CLASSPNP.SYS
            \SystemRoot\system32\DRIVERS\avgrkx64.sys
            \SystemRoot\System32\Drivers\crashdmp.sys
            \SystemRoot\System32\drivers\cdrom.sys
            \SystemRoot\System32\Drivers\Null.SYS
            \SystemRoot\System32\Drivers\Beep.SYS
            \SystemRoot\System32\drivers\BasicRender.sys
            \SystemRoot\System32\drivers\dxgkrnl.sys
            \SystemRoot\System32\drivers\watchdog.sys
            \SystemRoot\System32\drivers\dxgmms1.sys
            \SystemRoot\System32\drivers\BasicDisplay.sys
            \SystemRoot\System32\Drivers\Npfs.SYS
            \SystemRoot\System32\Drivers\Msfs.SYS
            \SystemRoot\system32\DRIVERS\avgwfpa.sys
            \SystemRoot\system32\DRIVERS\tdx.sys
            \SystemRoot\system32\DRIVERS\TDI.SYS
            \SystemRoot\System32\DRIVERS\netbt.sys
            \SystemRoot\system32\drivers\afd.sys
            \SystemRoot\system32\DRIVERS\pacer.sys
            \SystemRoot\system32\DRIVERS\vwififlt.sys
            \SystemRoot\system32\DRIVERS\netbios.sys
            \SystemRoot\system32\DRIVERS\avgldx64.sys
            \SystemRoot\system32\DRIVERS\rdbss.sys
            \SystemRoot\system32\DRIVERS\wanarp.sys
            \SystemRoot\system32\drivers\nsiproxy.sys
            \SystemRoot\System32\drivers\npsvctrig.sys
            \SystemRoot\System32\drivers\mssmbios.sys
            \SystemRoot\System32\drivers\discache.sys
            \SystemRoot\System32\Drivers\dfsc.sys
            \SystemRoot\system32\DRIVERS\CLVirtualDrive.sys
            \SystemRoot\system32\DRIVERS\avgidsdrivera.sys
            \SystemRoot\system32\DRIVERS\avgdiska.sys
            \SystemRoot\system32\DRIVERS\ndistapi.sys
            \SystemRoot\system32\DRIVERS\ndiswan.sys
            \SystemRoot\system32\DRIVERS\rassstp.sys
            \SystemRoot\system32\DRIVERS\AgileVpn.sys
            \SystemRoot\system32\DRIVERS\tunnel.sys
            \SystemRoot\System32\drivers\CompositeBus.sys
            \SystemRoot\system32\DRIVERS\kdnic.sys
            \SystemRoot\System32\drivers\umbus.sys
            \SystemRoot\system32\DRIVERS\igdkmd64.sys
            \SystemRoot\System32\drivers\HDAudBus.sys
            \SystemRoot\System32\drivers\USBXHCI.SYS
            \SystemRoot\System32\drivers\ucx01000.sys
            \SystemRoot\System32\drivers\TeeDriverx64.sys
            \SystemRoot\system32\DRIVERS\Rt630x64.sys
            \SystemRoot\system32\DRIVERS\athw8x.sys
            \SystemRoot\System32\drivers\vwifibus.sys
            \SystemRoot\System32\drivers\usbehci.sys
            \SystemRoot\System32\drivers\USBPORT.SYS
            \SystemRoot\System32\drivers\i8042prt.sys
            \SystemRoot\System32\drivers\SynTP.sys
            \SystemRoot\System32\drivers\USBD.SYS
            \SystemRoot\System32\drivers\kbdclass.sys
            \SystemRoot\System32\drivers\mouclass.sys
            \SystemRoot\System32\drivers\CmBatt.sys
            \SystemRoot\System32\drivers\BATTC.SYS
            \SystemRoot\System32\drivers\Smb_driver_Intel.sys
            \SystemRoot\System32\drivers\DellRbtn.sys
            \SystemRoot\System32\drivers\mshidkmdf.sys
            \SystemRoot\System32\drivers\HIDCLASS.SYS
            \SystemRoot\System32\drivers\HIDPARSE.SYS
            \SystemRoot\System32\drivers\wmiacpi.sys
            \SystemRoot\System32\drivers\intelppm.sys
            \SystemRoot\system32\DRIVERS\serscan.sys
            \SystemRoot\system32\drivers\ksthunk.sys
            \SystemRoot\system32\drivers\ks.sys
            \SystemRoot\system32\DRIVERS\raspptp.sys
            \SystemRoot\system32\DRIVERS\rasl2tp.sys
            \SystemRoot\system32\DRIVERS\raspppoe.sys
            \SystemRoot\System32\drivers\swenum.sys
            \SystemRoot\System32\drivers\btath_bus.sys
            \SystemRoot\System32\drivers\rdpbus.sys
            \SystemRoot\System32\Drivers\NDProxy.SYS
            \SystemRoot\System32\drivers\usbhub.sys
            \SystemRoot\system32\DRIVERS\portcls.sys
            \SystemRoot\system32\DRIVERS\drmk.sys
            \SystemRoot\System32\drivers\UsbHub3.sys
            \SystemRoot\system32\drivers\RTKVHD64.sys
            \SystemRoot\System32\drivers\usbccgp.sys
            \SystemRoot\System32\drivers\hidusb.sys
            \SystemRoot\System32\drivers\kbdhid.sys
            \SystemRoot\System32\drivers\mouhid.sys
            \SystemRoot\system32\DRIVERS\btfilter.sys
            \SystemRoot\System32\Drivers\BTHUSB.sys
            \SystemRoot\System32\Drivers\bthport.sys
            \SystemRoot\System32\Drivers\RtsUVStor.sys
            \SystemRoot\System32\Drivers\usbvideo.sys
            \SystemRoot\system32\DRIVERS\BthLEEnum.sys
            \SystemRoot\system32\DRIVERS\rfcomm.sys
            \SystemRoot\system32\DRIVERS\BthEnum.sys
            \SystemRoot\system32\DRIVERS\bthpan.sys
            \SystemRoot\System32\drivers\btath_rcp.sys
            \SystemRoot\system32\drivers\btath_avdt.sys
            \SystemRoot\system32\drivers\btath_a2dp.sys
            \SystemRoot\System32\drivers\btath_hcrp.sys
            \SystemRoot\system32\DRIVERS\btath_flt.sys
            \SystemRoot\system32\DRIVERS\btath_lwflt.sys
            \SystemRoot\System32\Drivers\fastfat.SYS
            \SystemRoot\System32\Drivers\dump_diskdump.sys
            \SystemRoot\System32\Drivers\dump_iaStorA.sys
            \SystemRoot\System32\Drivers\dump_dumpfve.sys
            \SystemRoot\System32\win32k.sys
            \SystemRoot\system32\DRIVERS\monitor.sys
            \SystemRoot\System32\TSDDD.dll
            \SystemRoot\System32\cdd.dll
            \SystemRoot\System32\ATMFD.DLL
            \SystemRoot\system32\drivers\luafv.sys
            \SystemRoot\system32\DRIVERS\lltdio.sys
            \SystemRoot\system32\DRIVERS\nwifi.sys
            \SystemRoot\system32\DRIVERS\ndisuio.sys
            \SystemRoot\system32\DRIVERS\rspndr.sys
            \SystemRoot\system32\drivers\HTTP.sys
            \SystemRoot\system32\DRIVERS\vwifimp.sys
            \SystemRoot\system32\DRIVERS\bowser.sys
            \SystemRoot\System32\drivers\mpsdrv.sys
            \SystemRoot\system32\DRIVERS\mrxsmb.sys
            \SystemRoot\system32\DRIVERS\mrxsmb10.sys
            \SystemRoot\system32\DRIVERS\mrxsmb20.sys
            \SystemRoot\system32\drivers\Ndu.sys
            \SystemRoot\system32\drivers\peauth.sys
            \SystemRoot\System32\Drivers\secdrv.SYS
            \SystemRoot\System32\DRIVERS\srvnet.sys
            \SystemRoot\System32\drivers\tcpipreg.sys
            \SystemRoot\System32\DRIVERS\srv2.sys
            \SystemRoot\System32\DRIVERS\srv.sys
            \SystemRoot\System32\drivers\condrv.sys
            \SystemRoot\System32\drivers\WSDPrint.sys
            \SystemRoot\system32\DRIVERS\asyncmac.sys
            \SystemRoot\system32\DRIVERS\cdfs.sys
            \??\C:\Windows\system32\drivers\mbamchameleon.sys
            \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
            ----------- End -----------
            Done!
            <<<1>>>
            Upper Device Name: \Device\Harddisk0\DR0
            Upper Device Object: 0xfffffa8008172060
            Upper Device Driver Name: \Driver\disk\
            Lower Device Name: \Device\00000039\
            Lower Device Object: 0xfffffa8005b637f0
            Lower Device Driver Name: \Driver\iaStorA\
            <<<2>>>
            Physical Sector Size: 512
            Drive: 0, DevicePointer: 0xfffffa8008172060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
            --------- Disk Stack ------
            DevicePointer: 0xfffffa8008172b10, DeviceName: Unknown, DriverName: \Driver\partmgr\
            DevicePointer: 0xfffffa8008172060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
            DevicePointer: 0xfffffa8005b67b20, DeviceName: Unknown, DriverName: \Driver\ACPI\
            DevicePointer: 0xfffffa8005b637f0, DeviceName: \Device\00000039\, DriverName: \Driver\iaStorA\
            ------------ End ----------
            Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
            Upper DeviceData: 0x0, 0x0, 0x0
            Lower DeviceData: 0x0, 0x0, 0x0
            <<<3>>>
            Volume: C:
            File system type: NTFS
            SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
            <<<2>>>
            <<<3>>>
            Volume: C:
            File system type: NTFS
            SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
            Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
            <<<2>>>
            <<<3>>>
            Volume: C:
            File system type: NTFS
            SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
            Read File: File "C:\Windows\System32\Drivers\vwifibus.sys" is compressed (flags = 1)
            Read File: File "C:\WINDOWS\SYSTEM32\drivers\vwifibus.sys" is compressed (flags = 1)
            Done!
            Drive 0
            Scanning MBR on drive 0...
            Inspecting partition table:
            This drive is a GPT Drive.
            MBR Signature: 55AA
            Disk Signature: 44D1A162

            GPT Protective MBR Partition information:

                Partition 0 type is EFI-GPT (0xee)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 1  Numsec = 4294967295

                Partition 1 type is Empty (0x0)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 0  Numsec = 0

                Partition 2 type is Empty (0x0)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 0  Numsec = 0

                Partition 3 type is Empty (0x0)
                Partition is NOT ACTIVE.
                Partition starts at LBA: 0  Numsec = 0

            GPT Partition information:

                GPT Header Signature 4546492050415254
                GPT Header Revision 65536 Size 92 CRC 2505083374
                GPT Header CurrentLba = 1 BackupLba 1465149167
                GPT Header FirstUsableLba 34  LastUsableLba 1465149134
                GPT Header Guid 24c4ead8-fe42-4297-9aee-402535de7797
                GPT Header Contains 128 partition entries starting at LBA 2
                GPT Header Partition entry size = 128

                Backup GPT header Signature 4546492050415254
                Backup GPT header Revision 65536 Size 92 CRC 2505083374
                Backup GPT header CurrentLba = 1465149167 BackupLba 1
                Backup GPT header FirstUsableLba 34  LastUsableLba 1465149134
                Backup GPT header Guid 24c4ead8-fe42-4297-9aee-402535de7797
                Backup GPT header Contains 128 partition entries starting at LBA 1465149135
                Backup GPT header Partition entry size = 128

                Partition 0 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
                Partition ID 9bb5d2e-481c-4fc3-afe8-c052e0733d7e
                FirstLBA 2048  Last LBA 1026047
                Attributes 0
                Partition Name                 EFI system partition

                GPT Partition 0 is bootable
                Partition 1 Type 796badd3-6bbf-4d9f-b631-466eb71a4965
                Partition ID ad681f2d-41c6-48e7-b1ea-43906a705949
                FirstLBA 1026048  Last LBA 1107967
                Attributes 1
                Partition Name                 Basic data partition

                Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
                Partition ID 6488712e-b6a9-4d06-9ccd-fd586489b015
                FirstLBA 1107968  Last LBA 1370111
                Attributes 0
                Partition Name         Microsoft reserved partition

                Partition 3 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
                Partition ID 29a4d99c-bf4d-4d2a-a150-6e948fb753b4
                FirstLBA 1370112  Last LBA 2373631
                Attributes 1
                Partition Name                 Basic data partition

                Partition 4 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
                Partition ID 8a4a6132-ccd5-48b0-978a-61df32d2aac4
                FirstLBA 2373632  Last LBA 1440112639
                Attributes 0
                Partition Name                 Basic data partition

                Partition 5 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
                Partition ID 50899bd-6151-43c6-99b4-678e4e963219
                FirstLBA 1440112640  Last LBA 1465147119
                Attributes 1
                Partition Name         Microsoft recovery partition

            Disk Size: 750156374016 bytes
            Sector size: 512 bytes

            Done!
            Read File:  File "c:\programdata\avg2014\chjw\40c4fb5ec4fb549e.dat:8a5e4f29-a7ed-411c-b562-b34257f0c02c" is sparse (flags = 32768)
            Scan finished
            =======================================


            Removal queue found; removal started
            Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
            Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
            Removal finished


            mbar-log-YYYY-MM-DD

            Database version: v2014.02.27.05

            Windows 8 x64 NTFS
            Internet Explorer 10.0.9200.16750
            Niels Clausen :: NIELS [administrator]

            27-02-2014 16:15:09
            mbar-log-2014-02-27 (16-15-09).txt

            Scan type: Quick scan
            Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
            Scan options disabled:
            Objects scanned: 244525
            Time elapsed: 20 minute(s), 42 second(s)

            Memory Processes Detected: 0
            (No malicious items detected)

            Memory Modules Detected: 0
            (No malicious items detected)

            Registry Keys Detected: 0
            (No malicious items detected)

            Registry Values Detected: 0
            (No malicious items detected)

            Registry Data Items Detected: 0
            (No malicious items detected)

            Folders Detected: 0
            (No malicious items detected)

            Files Detected: 0
            (No malicious items detected)

            Physical Sectors Detected: 0
            (No malicious items detected)

            (end)

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            This is the instruction for running SFC on Windows 7 but it should be the same for Win8

            To Run the SFC /SCANNOW Command in Windows 7
            1. Open an elevated command prompt.

            2. To Scan and Repair System Files
            NOTE: Scans the integrity of all protected system files and repairs the system files if needed.
            A) In the elevated command prompt, type sfc /scannow and press Enter. (see screenshot below)
            NOTE: This may take some time to finish.



            B) Go to step 4.

            3. To Only Verify if the System Files are Corrupted
            NOTE: Scans and only verifies the integrity of all proteced system files only.
            A) In the elevated command prompt, type sfc /verifyonly and press Enter.

            4. When the scan is complete, hopefully you will see all is ok like the screenshot below.
            NOTE: If not, then you can attempt to run a System Restore using a restore point dated before the bad file occured to fix it. You may need to repeat doing a System Restore until you find a older restore point that may work.



            5. When done, close the elevated command prompt.
            Windows 8 and Windows 10 dual boot with two SSD's

            PeterClausen

              Topic Starter


              Greenhorn

              • Experience: Familiar
              • OS: Windows 8
              Re: Problems with soundcard, control panel and apps. Found Misleading.FakeAV?
              « Reply #10 on: February 27, 2014, 11:37:57 AM »
              Hi Dave

              I can not get the scan started. See attachments. I hope i am doing it right ;)

              [recovering disk space, attachment deleted by admin]

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: Problems with soundcard, control panel and apps. Found Misleading.FakeAV?
              « Reply #11 on: February 27, 2014, 04:02:32 PM »
              Hi Dave

              I can not get the scan started. See attachments. I hope i am doing it right ;)
              So, nothing happens when you press Enter?
              Windows 8 and Windows 10 dual boot with two SSD's

              PeterClausen

                Topic Starter


                Greenhorn

                • Experience: Familiar
                • OS: Windows 8
                Re: Problems with soundcard, control panel and apps. Found Misleading.FakeAV?
                « Reply #12 on: February 28, 2014, 03:43:21 AM »
                Hi Dave :)

                I got the scan to work, but it could only fix some of the corrupts files. Then i started a system restore, but i get a errormessage?

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: Problems with soundcard, control panel and apps. Found Misleading.FakeAV?
                « Reply #13 on: February 28, 2014, 07:10:25 AM »
                What is the error message. Do you have the Recovery Console on your computer? It's usually on a separate partition of your harddrive usually named D. Do you have your OS disk?
                Windows 8 and Windows 10 dual boot with two SSD's

                PeterClausen

                  Topic Starter


                  Greenhorn

                  • Experience: Familiar
                  • OS: Windows 8
                  Re: Problems with soundcard, control panel and apps. Found Misleading.FakeAV?
                  « Reply #14 on: February 28, 2014, 12:42:49 PM »
                  Hi Dave.

                  I have attached the errormessage, translatned it says that a error was found, i do not know what it is called in english, but maybe it is Volume Shadow Copy Service?  I do not have any CD's and i do not think there is a separate partition of my harddrive. But it seems like i have two restore points on the computer?

                  [recovering disk space, attachment deleted by admin]