Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

I may have gotten some crappy malware on my PC.


  • Please log in to reply
15 replies to this topic

#1 CaptainBlud

CaptainBlud

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 07 April 2024 - 08:29 PM

Idrk bleep about malware, but when lots of CMDs can open absolutely randomly at any given time, and when my hard drive space shrinks almost immediately after I delete things or even make a factory reset, it seems like I do actually have something like that. My cooler makes a bleep mix of chopper and chainsaw sounds, as loud as a Falcon Heavy failing to take off the ground to any significant altitude as they usually do, like most of the time my PC is on.
Both AVG's and Malwarebytes' free no subscription versions can't find bleep.
Yes, I've even done factory resets. Doesn't really help.
I just want somebody to guide me through the woods of FRST, since I don't really want to make an effort to figure it out on myself.



BC AdBot (Login to Remove)

 


#2 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,348 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 08 April 2024 - 01:20 AM

Hi CaptainBlud,
My name is Dennis and I will assist you with your computer problems.
Please read through these guidelines before we start.

  • Back up any important data, as a precaution before starting this process.
  • If you are unsure about anything then please ask. This makes the task much easier in the long run.
  • Do not run any other tools or make changes to your system during the removal process.
  • Please do not start a new topic and keep all replies in this thread.
  • Follow the instructions in the sequence advised.
  • Copy and paste the logs into the reply. I will advise if anything needs to be added as an attachment.
  • Here at Bleeping Computer we are mostly volunteers, so please be patient with us. I’ll try to respond within 24 hours. You will be advised if it is expected to be longer than 48 hours.
  • Please let me know if you are going to be delayed in responding. If you do not reply after 5 days, I’ll assume you do not want to continue and will close the topic.
  • Sometimes things might seem to be resolved, but there may still need to be more checks necessary, so please wait until I give the all clear.Firstly I'd like you to follow the steps outlined here: Preparation Guide

Section 6 covers how to download and run the Farbar Recovery Scan Tool (FRST).
Note: If you receive a warning about the download, it is a false positive and you can safely ignore it.
Please copy and paste both FRST logs into your reply. If you get an error message advising that the content is too long, you should post 2 separate replies.

Dennis



#3 CaptainBlud

CaptainBlud
  • Topic Starter

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 08 April 2024 - 10:01 PM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06.04.2024 01
Ran by david (administrator) on DESKTOP-OADEFFT (FUJITSU LIFEBOOK E734) (09-04-2024 05:55:59)
Running from C:\Users\david\Downloads\FRST64.exe
Loaded Profiles: david
Platform: Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Discord Inc. -> Discord Inc.) C:\Users\david\AppData\Local\Discord\app-1.0.9039\Discord.exe <6>
(explorer.exe ->) (Elan Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <18>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(explorer.exe ->) (Spotify AB -> Spotify Ltd) C:\Users\david\AppData\Roaming\Spotify\Spotify.exe <6>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.363\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.363\GoogleCrashHandler64.exe
(Intel® pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wimserv.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Intel® Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\david\AppData\Local\Microsoft\OneDrive\24.055.0317.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [FUJ02E3_BatteryChargingControlUpdate] => C:\Program Files (x86)\Fujitsu\FUJ02E3_BatteryChargingControlUpdate\CheckBatteryFW.exe [447808 2021-08-20] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU LIMITED)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2906608 2015-09-23] (Elan Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [FUJ02B1_Apps] => C:\Program Files (x86)\Fujitsu\FUJ02B1\CheckBatteryPack.exe [376128 2018-09-06] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16696840 2016-10-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1467400 2016-10-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS_SWVOL] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1467400 2016-10-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [FUJ02B1_Apps] => C:\Program Files (x86)\Fujitsu\FUJ02B1\CheckBatteryPack.exe [376128 2018-09-06] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
HKLM-x32\...\Run: [FUJ02E3_BatteryChargingControlUpdate] => C:\Program Files (x86)\Fujitsu\FUJ02E3_BatteryChargingControlUpdate\CheckBatteryFW.exe [447808 2021-08-20] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU LIMITED)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [Discord] => C:\Users\david\AppData\Local\Discord\Update.exe [1525024 2024-01-09] (Discord Inc. -> GitHub)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4384104 2024-03-06] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [Spotify] => C:\Users\david\AppData\Roaming\Spotify\Spotify.exe [33526600 2024-03-25] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45285792 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [MicrosoftEdgeAutoLaunch_30FCCE2722F4190AAE310221237BB02B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4063784 2024-04-04] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\david\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\david\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" [67157520 2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\RunOnce: [Uninstall 24.050.0310.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\david\AppData\Local\Microsoft\OneDrive\24.050.0310.0001" [0 2024-04-09] () <==== ATTENTION [zero byte File/Folder]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\123.0.6312.106\Installer\chrmstp.exe [2024-04-08] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {760F5BDD-F686-46A7-9282-30BBBB73E45E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {F1798882-027A-41E7-A133-05510E2F3783} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "e5347dbd-9e84-4a70-811b-ad1d555c6009" --version "6.22.10977" --silent
Task: {28BA7143-EF6C-4CA8-A7F6-DEA68DA0D6DC} - System32\Tasks\CCleanerSkipUAC - david => C:\Program Files\CCleaner\CCleaner.exe [39024544 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {BD8F8ADD-4F19-4C1B-A01F-33D89BD497A3} - System32\Tasks\GoogleUpdateTaskMachineCore{B18D7657-2F7F-498F-BC25-D473D4C5522C} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162080 2024-01-16] (Google LLC -> Google LLC)
Task: {D0BE20CC-D308-4069-B40A-9344A49C44F0} - System32\Tasks\GoogleUpdateTaskMachineUA{E11CFAF6-CB2C-428C-A1B5-B4B6EE3A58E8} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162080 2024-01-16] (Google LLC -> Google LLC)
Task: {8FA93DA7-FB8D-4BE7-9CEE-F5B566A1A97D} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [255056 2024-01-19] (Microsoft Corporation -> Microsoft)
Task: {CF926037-4077-4859-BD1E-9F74D961CCD1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1E20BE71-32C3-4EC9-807C-1E402F786889} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A112DC4F-53E6-4B7F-9D11-A8786FF2AA63} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {51E58255-EA4A-44E1-83AD-E74A6C9EE5BE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{930713eb-41ce-4d9f-ae20-b0cdcb7b71ae}: [DhcpNameServer] 192.168.1.1
 
Edge: 
=======
Edge Profile: C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default [2024-04-09]
Edge Extension: (RoPro - Enhance Your Roblox Experience) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\adbacgifemdbhdkfppmeilbgppmhaobf [2024-03-13]
Edge Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-29]
Edge Extension: (BTRoblox - Making Roblox Better) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hbkpclpemjeibhioopcebchdmohaieln [2024-03-23]
Edge Extension: (Touch VPN - Secure and unlimited VPN proxy) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ighhnpmaabelnfcbbkijikgghajbiaml [2024-02-01]
Edge Extension: (Edge relevant text changes) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-27]
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Default [2024-04-09]
CHR Extension: (RoPro - Enhance Your Roblox Experience) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\adbacgifemdbhdkfppmeilbgppmhaobf [2024-03-13]
CHR Extension: (Just Black) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\aghfnjkcakhmadgdomlmlhhaocbkloab [2024-01-26]
CHR Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-21]
CHR Extension: (Beyond 20) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnblbpbepfbfmoobegdogkglpbhcjofh [2024-02-24]
CHR Extension: (BTRoblox - Making Roblox Better) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbkpclpemjeibhioopcebchdmohaieln [2024-03-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-01-16]
CHR Extension: (hyde — hide the YouTube video player controls) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmkpddhfbiojipiehnejbjkgdgdpkdpb [2024-04-08]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-03-28]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-04-08]
CHR Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-04-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-01-19]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 2 [2024-03-28]
CHR Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-01-26]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 3 [2024-03-28]
CHR Extension: (Just Black) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aghfnjkcakhmadgdomlmlhhaocbkloab [2024-01-26]
CHR Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-01-26]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\System Profile [2024-01-19]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1081248 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [935344 2023-10-13] (EasyAntiCheat Oy -> Epic Games, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9423680 2024-03-30] (Malwarebytes Inc. -> Malwarebytes)
S3 VSInstallerElevationService; C:\Program Files (x86)\Microsoft Visual Studio\Installer\VSInstallerElevationService.exe [41520 2024-01-19] (Microsoft Corporation -> Microsoft)
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [142304 2022-06-01] (Microsoft Corporation -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe [3191272 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe [133688 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-12-23] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-12-23] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 ETDHIDUSB; C:\WINDOWS\System32\drivers\ETDHIDUSB.sys [233440 2015-09-23] (Elan Microelectronics Corporation -> ELAN Microelectronic Corp.)
R2 FBIOSDRV; C:\WINDOWS\System32\Drivers\FBIOSDRV.sys [48928 2016-01-28] (FUJITSU LIMITED -> FUJITSU LIMITED)
R3 FUJ02B1; C:\WINDOWS\System32\drivers\FUJ02B1.sys [68536 2018-09-06] (FUJITSU LIMITED -> FUJITSU LIMITED)
R3 fuj02e3; C:\WINDOWS\System32\drivers\fuj02e3.sys [182216 2021-08-20] (FUJITSU LIMITED -> FUJITSU LIMITED)
S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpioe.sys [31232 2014-06-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
S3 iaioi2c; C:\WINDOWS\System32\drivers\iaioi2ce.sys [69632 2014-06-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223296 2024-03-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2024-02-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-02-08] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 parsecudeaudio; C:\WINDOWS\System32\drivers\parsecudeaudio.sys [163856 2023-05-24] (Microsoft Windows Hardware Compatibility Publisher -> Parsec)
S3 parsecvusba; C:\WINDOWS\System32\drivers\parsecvusba.sys [262712 2023-05-24] (Microsoft Windows Hardware Compatibility Publisher -> Parsec)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [76832 2022-09-30] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated)
R0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20928 2024-03-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [603416 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\System32\drivers\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105752 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-04-09 05:55 - 2024-04-09 05:55 - 000000000 ___DC C:\Users\david\Downloads\FRST-OlderVersion
2024-04-09 05:42 - 2024-04-09 05:42 - 000000000 __HDC C:\OneDriveTemp
2024-04-08 04:40 - 2024-04-08 04:40 - 000000000 ___DC C:\Users\david\AppData\Roaming\Blender Foundation
2024-04-08 04:40 - 2024-04-08 04:40 - 000000000 ___DC C:\Users\david\AppData\Local\Blender Foundation
2024-04-08 04:40 - 2024-04-08 04:40 - 000000000 ___DC C:\Users\david\.thumbnails
2024-04-08 04:35 - 2024-04-08 04:35 - 000001314 ____C C:\Users\david\OneDrive\Desktop\Blender 4.1.lnk
2024-04-08 04:35 - 2024-04-08 04:35 - 000000000 ___DC C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\blender
2024-04-08 04:34 - 2024-04-08 04:34 - 000000000 ___DC C:\Program Files\Blender Foundation
2024-04-08 04:05 - 2024-04-08 04:10 - 343068672 ____C C:\Users\david\Downloads\blender-4.1.0-windows-x64.msi
2024-04-01 15:34 - 2024-04-01 15:35 - 000000000 __HDC C:\$WinREAgent
2024-03-19 09:00 - 2024-03-19 09:00 - 000137032 ____C (Zoom Video Communications, Inc.) C:\Users\david\Downloads\Zoom_cm_fo42lnktZ9vvrZo4_mOhRUBioIkX300FYal3iu4wJejON5PLhBzRoc@eBHqRsU8EY6fDT0q_k72deb81ba874761f_.exe
2024-03-19 08:41 - 2024-03-19 08:41 - 000000000 ___DC C:\ProgramData\Piriform
2024-03-19 08:41 - 2024-03-19 08:41 - 000000000 ___DC C:\ProgramData\Norton
2024-03-12 22:21 - 2024-03-12 22:21 - 000019530 ____C C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-03-12 22:21 - 2024-03-12 22:21 - 000019530 ____C C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-04-09 05:56 - 2024-01-19 12:37 - 000019758 ____C C:\Users\david\Downloads\FRST.txt
2024-04-09 05:56 - 2024-01-19 12:37 - 000000000 ___DC C:\FRST
2024-04-09 05:55 - 2024-01-19 12:35 - 002393600 ____C (Farbar) C:\Users\david\Downloads\FRST64.exe
2024-04-09 05:50 - 2024-01-21 11:17 - 000000000 ___DC C:\Program Files (x86)\Steam
2024-04-09 05:50 - 2024-01-15 18:50 - 000000000 ___DC C:\ProgramData\regid.1991-06.com.microsoft
2024-04-09 05:47 - 2024-01-16 08:49 - 000000000 ___DC C:\Program Files (x86)\Google
2024-04-09 05:47 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\SystemTemp
2024-04-09 05:42 - 2024-01-15 19:32 - 000000000 __RDC C:\Users\david\OneDrive
2024-04-09 05:41 - 2024-01-26 19:03 - 000000000 ___DC C:\Users\david\AppData\Local\Spotify
2024-04-09 05:41 - 2024-01-17 08:52 - 000003592 ____C C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1346671777-2945835254-3822528861-1001
2024-04-09 05:41 - 2024-01-15 19:32 - 000003380 ____C C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1346671777-2945835254-3822528861-1001
2024-04-09 05:41 - 2024-01-15 19:29 - 000002383 ____C C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-04-09 05:34 - 2024-02-08 02:30 - 000000000 ___DC C:\Users\david\AppData\Local\Malwarebytes
2024-04-09 05:34 - 2024-01-27 18:34 - 000000000 ___DC C:\Program Files\CCleaner
2024-04-09 05:34 - 2024-01-26 19:02 - 000000000 ___DC C:\Users\david\AppData\Roaming\Spotify
2024-04-09 05:34 - 2024-01-16 09:04 - 000002237 ____C C:\Users\david\OneDrive\Desktop\Discord.lnk
2024-04-09 05:34 - 2024-01-16 09:04 - 000000000 ___DC C:\Users\david\AppData\Roaming\discord
2024-04-09 05:34 - 2024-01-16 09:03 - 000000000 ___DC C:\Users\david\AppData\Local\Discord
2024-04-09 05:33 - 2024-01-16 05:04 - 000000180 ____C C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2024-04-09 05:33 - 2024-01-15 19:30 - 000000000 _SHDC C:\Users\david\IntelGraphicsProfiles
2024-04-08 08:16 - 2024-01-16 05:03 - 000000000 ___DC C:\WINDOWS\system32\SleepStudy
2024-04-08 08:16 - 2024-01-15 18:50 - 000000000 __HDC C:\Program Files\WindowsApps
2024-04-08 08:16 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\AppReadiness
2024-04-08 07:14 - 2024-01-16 10:16 - 000000000 ___DC C:\Users\david\AppData\Roaming\Telegram Desktop
2024-04-08 04:40 - 2024-01-15 19:29 - 000000000 ___DC C:\Users\david
2024-04-08 04:14 - 2024-01-16 05:04 - 000002438 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-04-08 04:08 - 2024-01-16 08:50 - 000002247 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-04-08 04:08 - 2024-01-16 05:04 - 000003536 ____C C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-04-08 04:08 - 2024-01-16 05:04 - 000003412 ____C C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-04-08 04:02 - 2024-01-19 11:42 - 000000000 ___DC C:\Program Files\Unity Hub
2024-04-08 03:45 - 2024-01-27 18:34 - 000004210 ____C C:\WINDOWS\system32\Tasks\CCleaner Update
2024-04-08 03:45 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\LiveKernelReports
2024-03-29 21:00 - 2024-01-16 05:12 - 001767980 ____C C:\WINDOWS\system32\PerfStringBackup.INI
2024-03-29 21:00 - 2024-01-15 18:52 - 000785394 ____C C:\WINDOWS\system32\perfh015.dat
2024-03-29 21:00 - 2024-01-15 18:52 - 000152280 ____C C:\WINDOWS\system32\perfc015.dat
2024-03-29 21:00 - 2024-01-15 18:48 - 000000000 ___DC C:\WINDOWS\INF
2024-03-29 20:52 - 2024-01-16 05:04 - 000000006 ___HC C:\WINDOWS\Tasks\SA.DAT
2024-03-29 20:52 - 2024-01-16 05:03 - 000008192 ___SH C:\DumpStack.log.tmp
2024-03-29 20:52 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\ServiceState
2024-03-29 20:52 - 2024-01-15 18:44 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-03-29 15:56 - 2024-01-24 13:12 - 000001401 ____C C:\Users\david\OneDrive\Desktop\Roblox Player.lnk
2024-03-29 15:56 - 2024-01-24 13:12 - 000001229 ____C C:\Users\david\OneDrive\Desktop\Roblox Studio.lnk
2024-03-29 15:56 - 2024-01-24 13:12 - 000000000 ___DC C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2024-03-29 14:42 - 2024-01-15 19:30 - 000000000 ___DC C:\Users\david\AppData\Local\Packages
2024-03-28 12:07 - 2024-02-11 07:49 - 000000000 ___DC C:\Users\david\AppData\Local\CrashDumps
2024-03-26 11:50 - 2024-01-16 08:53 - 000000000 ___DC C:\Users\david\AppData\Roaming\Zoom
2024-03-21 14:15 - 2024-01-27 18:34 - 000000666 ____C C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-03-21 14:14 - 2024-01-15 18:45 - 000000000 ___DC C:\WINDOWS\CbsTemp
2024-03-19 08:40 - 2024-01-27 18:34 - 000003382 ____C C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-03-15 21:28 - 2024-01-19 11:21 - 000000000 ___DC C:\Program Files\RUXIM
2024-03-14 14:32 - 2024-01-15 19:31 - 000000000 ___DC C:\ProgramData\Packages
2024-03-14 14:31 - 2024-01-15 19:32 - 000000000 ___DC C:\Users\david\AppData\Local\PlaceholderTileLogoFolder
2024-03-13 18:28 - 2024-01-16 05:03 - 000272072 ____C C:\WINDOWS\system32\FNTCACHE.DAT
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 __RDC C:\WINDOWS\ImmersiveControlPanel
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\SysWOW64\Dism
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\SystemResources
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\system32\oobe
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\system32\Dism
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\ShellExperiences
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\bcastdvr
2024-03-13 18:28 - 2024-01-15 18:44 - 000000000 ___DC C:\WINDOWS\servicing
2024-03-13 17:12 - 2024-01-16 05:04 - 000000000 ___DC C:\WINDOWS\system32\Drivers\wd
2024-03-12 22:21 - 2024-01-16 05:04 - 003017216 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-03-12 22:11 - 2024-01-19 11:21 - 000000000 ___DC C:\WINDOWS\system32\MRT
2024-03-12 22:09 - 2024-01-19 11:21 - 190470136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06.04.2024 01
Ran by david (09-04-2024 05:58:06)
Running from C:\Users\david\Downloads
Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) (2024-01-16 02:08:05)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-1346671777-2945835254-3822528861-500 - Administrator - Disabled)
david (S-1-5-21-1346671777-2945835254-3822528861-1001 - Administrator - Enabled) => C:\Users\david
DefaultAccount (S-1-5-21-1346671777-2945835254-3822528861-503 - Limited - Disabled)
Guest (S-1-5-21-1346671777-2945835254-3822528861-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1346671777-2945835254-3822528861-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
blender (HKLM\...\{1589EDDA-7F97-49A7-A931-5646B819BC9E}) (Version: 4.1.0 - Blender Foundation)
CCleaner (HKLM\...\CCleaner) (Version: 6.22 - Piriform)
ClickOnce Bootstrapper Package for Microsoft .NET Framework (HKLM-x32\...\{22E13608-4DB0-4977-A267-3AAFA09CD54A}) (Version: 4.8.09037 - Microsoft Corporation) Hidden
DiagnosticsHub_CollectionService (HKLM\...\{FECAFEB5-8D0E-4AE4-8FA0-745BAA835C35}) (Version: 17.3.32601 - Microsoft Corporation) Hidden
Discord (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Discord) (Version: 1.0.9030 - Discord Inc.)
ELAN Touchpad 12.8.3.13_X64 (HKLM\...\Elantech) (Version: 12.8.3.13 - ELAN Microelectronic Corp.)
Entity Framework 6.2.0 Tools  for Visual Studio 2022 (HKLM-x32\...\{3EDA2628-CE9D-4024-B0FC-669A477C3728}) (Version: 6.2.0.0 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 123.0.6312.106 - Google LLC)
Goose Goose Duck version 3.04.02 (HKLM-x32\...\{934B69A4-1E69-4309-9624-828F7982050D}_is1) (Version: 3.04.02 - Gaggle Studios Inc)
icecap_collection_neutral (HKLM-x32\...\{9DB8E966-047B-4FF5-B982-6FF32AD9EF02}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
icecap_collection_x64 (HKLM\...\{CFD78991-1C3B-4C91-9119-67A3C55D1F78}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
icecap_collectionresources (HKLM-x32\...\{62D8E076-72EB-44EB-99A6-6D7C22E6AAB8}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
icecap_collectionresourcesx64 (HKLM-x32\...\{6CE350F6-4B97-45A1-9B32-3B7925F2F25B}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
IntelliTraceProfilerProxy (HKLM\...\{F8B9E8C8-61E8-4E9E-879D-F3F498AD0230}) (Version: 15.0.21225.01 - Microsoft Corporation) Hidden
IntelliTraceProfilerProxy (HKLM-x32\...\{C8891AD2-C223-45CD-A9BE-617A68923B61}) (Version: 15.0.21225.01 - Microsoft Corporation) Hidden
Malwarebytes version 4.6.10.316 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.10.316 - Malwarebytes)
Microsoft .NET 8.0 Templates 8.0.101 (x64) (HKLM\...\{327FE233-6B6A-4AB4-89E1-746BC6FF8670}) (Version: 32.6.64801 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 8.0.1 (x64) (HKLM\...\{8F4A7EF6-D703-49BA-8CBF-25EACA80ACFE}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 8.0.1 (x64_arm64) (HKLM\...\{254DCD95-B644-4CA9-BC9D-6C8284624DC0}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 8.0.1 (x64_x86) (HKLM\...\{6764BE50-AB13-4D6B-8893-F2FD8E801539}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.1 Doc Redirected Targeting Pack (ENU) (HKLM-x32\...\{8F5A2690-2EBD-4017-B995-C522C9204312}) (Version: 4.7.02558 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.1 Targeting Pack (HKLM-x32\...\{5686C5E9-A3B3-451E-A2EA-4C246CDE5CC9}) (Version: 4.7.02558 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 Targeting Pack (ENU) (HKLM-x32\...\{B517DBD3-B542-4FC8-9957-FFB2C3E65D1D}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 Targeting Pack (HKLM-x32\...\{1784A8CD-F7FE-47E2-A87D-1F31E7242D0D}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.8 SDK (HKLM-x32\...\{949C0535-171C-480F-9CF4-D25C9E60FE88}) (Version: 4.8.03928 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.8 Targeting Pack (ENU) (HKLM-x32\...\{A4EA9EE5-7CFF-4C5F-B159-B9B4E5D2BDE2}) (Version: 4.8.03761 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.8 Targeting Pack (HKLM-x32\...\{BAAF5851-0759-422D-A1E9-90061B597188}) (Version: 4.8.03761 - Microsoft Corporation) Hidden
Microsoft .NET Framework Cumulative Intellisense Pack for Visual Studio (ENU) (HKLM-x32\...\{1A9C3A1A-566B-4CFA-8B27-71FC623963BE}) (Version: 4.8.09037 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.1 (x64) (HKLM\...\{CF9AD294-8156-4084-A5CC-839970BA09FE}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.1 (x86) (HKLM-x32\...\{41A5E673-39F9-4990-86C4-06132C5D4C90}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.1 (x64) (HKLM\...\{9B3DED90-F398-457A-9F6C-855A543FEC5C}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.1 (x86) (HKLM-x32\...\{69E249E3-4273-41A7-8955-510331DF4F32}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.1 (x64) (HKLM\...\{16FC6669-9194-4096-8BDA-68907224C20B}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.1 (x86) (HKLM-x32\...\{517088ED-4FE7-4A92-B833-6A72240B8933}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET SDK 8.0.101 (x64) from Visual Studio (HKLM\...\{24E9FB48-4983-4C9C-93D2-27307AE92B5E}) (Version: 8.1.123.58017 - Microsoft Corporation)
Microsoft .NET Standard Targeting Pack - 2.1.0 (x64) (HKLM\...\{A7036CFB-B403-4598-85FF-D397ABB88173}) (Version: 24.0.28113 - Microsoft Corporation) Hidden
Microsoft .NET Targeting Pack - 8.0.1 (x64) (HKLM\...\{227585DF-8EC9-4666-8A50-775D33FAE2D6}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Targeting Pack - 8.0.1 (x86) (HKLM-x32\...\{C0BC54F5-E755-4079-9A19-B015822DF58C}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Toolset 8.0.101 (x64) (HKLM\...\{9B8818C6-A34F-470C-B0FD-1765BB96A98A}) (Version: 32.6.64801 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.1 Shared Framework (x64) (HKLM\...\{093059CD-C51E-3BF3-95DA-E8269426A7F4}) (Version: 8.0.1.23580 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.1 Shared Framework (x86) (HKLM-x32\...\{8976E660-0FC8-3D45-95B9-72FEB340FD01}) (Version: 8.0.1.23580 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.1 Targeting Pack (x64) (HKLM\...\{031E4A07-D777-3102-B9ED-DD2A670186D9}) (Version: 8.0.1.23580 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.1 Targeting Pack (x86) (HKLM-x32\...\{D97FBF4B-A709-3D68-BC9E-7231ADAE1187}) (Version: 8.0.1.23580 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 123.0.2420.81 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 123.0.2420.81 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\OneDriveSetup.exe) (Version: 24.055.0317.0002 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2019 (HKLM\...\{5BC7E9EB-13E8-45DB-8A60-F2481FEB4595}) (Version: 15.0.2000.5 - Microsoft Corporation)
Microsoft TestPlatform SDK Local Feed (HKLM-x32\...\{839C2D45-DDF6-432C-A6A2-C6AF2EF281BF}) (Version: 17.0.0.5175695 - Microsoft) Hidden
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.38.33130 (HKLM-x32\...\{1de5e707-82da-4db6-b810-5d140cc4cbb3}) (Version: 14.38.33130.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.38.33130 (HKLM-x32\...\{2cfeba4a-21f8-4ea7-9927-c5a5c6f13cc9}) (Version: 14.38.33130.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.38.33130 (HKLM\...\{C31777DB-51C1-4B19-9F80-38EF5C1D7C89}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.38.33130 (HKLM\...\{1CA7421F-A225-4A9C-B320-A36981A2B789}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33130 (HKLM-x32\...\{5CA9AE7B-2EFC-4F02-81CD-32ABE173C755}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33130 (HKLM-x32\...\{DF1B52DF-C88E-4DDF-956B-6E7A03327F46}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 3.8.2122.37638 - Microsoft Corporation)
Microsoft Visual Studio Setup Configuration (HKLM-x32\...\{C777E5A3-D26A-4F0D-84AC-79ECE7560EA5}) (Version: 3.8.2091.34612 - Microsoft Corporation) Hidden
Microsoft Visual Studio Setup WMI Provider (HKLM-x32\...\{9E0059DE-74E7-49A5-8F2A-C17B5BE58B4C}) (Version: 3.8.2091.34612 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.1 (x64) (HKLM\...\{A46C65AB-B1B1-427F-87D5-1B8F22ACEC50}) (Version: 64.4.5797 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.1 (x86) (HKLM-x32\...\{B6D7ADDD-3020-47A1-BF6B-200097111909}) (Version: 64.4.5797 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Targeting Pack - 8.0.1 (x64) (HKLM\...\{3277237E-8466-4FCE-B5F4-A82B152DA1F9}) (Version: 64.4.5797 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Targeting Pack - 8.0.1 (x86) (HKLM-x32\...\{80F66075-4AFD-4CC9-8F71-0A39B29F95DB}) (Version: 64.4.5797 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Android.Manifest-8.0.100 (x64) (HKLM\...\{B5A57BF9-FC7A-4FA6-BAEB-46E173986DF3}) (Version: 34.0.43 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.iOS.Manifest-8.0.100 (x64) (HKLM\...\{1949FBD5-3860-4274-AA04-00E0E33C9B11}) (Version: 17.2.8004 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.MacCatalyst.Manifest-8.0.100 (x64) (HKLM\...\{BF0BA430-95E3-4AD1-917A-93C02E2FD1ED}) (Version: 17.2.8004 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.macOS.Manifest-8.0.100 (x64) (HKLM\...\{D7827DB4-FB1C-4A45-9E0B-AC57ECC286E6}) (Version: 14.2.8004 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Maui.Manifest-8.0.100 (x64) (HKLM\...\{116EF6D0-AE8E-4E6D-B0D8-EFF145CD45DA}) (Version: 8.0.3 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.tvOS.Manifest-8.0.100 (x64) (HKLM\...\{2D16D57A-929A-42CE-B95A-53889E755F27}) (Version: 17.2.8004 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.Current.Manifest (x64) (HKLM\...\{6B392BFB-F933-478E-8117-047A5316147D}) (Version: 64.4.5649 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net6.Manifest (x64) (HKLM\...\{401CE2E2-3487-4F90-8441-58453E64AF77}) (Version: 64.4.5649 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net7.Manifest (x64) (HKLM\...\{B7026CB6-B219-4E2D-A5F8-5B83A6BA92BC}) (Version: 64.4.5649 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.Current.Manifest (x64) (HKLM\...\{862DF818-B4D9-402D-90BF-D4498ABB7A82}) (Version: 64.4.5765 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net6.Manifest (x64) (HKLM\...\{C072E2E0-93BB-450C-8D4E-D6406DB06DA7}) (Version: 64.4.5765 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net7.Manifest (x64) (HKLM\...\{D2E7F6D7-51C8-4C42-8FE0-F2BE9BA64459}) (Version: 64.4.5765 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7931 - Realtek Semiconductor Corp.)
RimWorld - Biotech (HKLM-x32\...\1865538500_is1) (Version: 1.4.3901 rev218 - GOG.com)
RimWorld - Ideology (HKLM-x32\...\1827857764_is1) (Version: 1.4.3901 rev218 - GOG.com)
RimWorld - Royalty (HKLM-x32\...\1233017772_is1) (Version: 1.4.3901 rev218 - GOG.com)
RimWorld (HKLM-x32\...\1094900565_is1) (Version: 1.4.3901 rev218 - GOG.com)
Roblox Player for david (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\roblox-player) (Version:  - Roblox Corporation)
Spotify (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Spotify) (Version: 1.2.33.1042.g26c92729 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.13.20 - Synaptics Incorporated)
Telegram Desktop (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.15.2 - Telegram FZ-LLC)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{B9A7A138-BFD5-4C73-A269-F78CCA28150E}) (Version: 8.94.0.0 - Microsoft Corporation)
vcpp_crt.redist.clickonce (HKLM-x32\...\{4BD69DE8-B66B-4BD4-A502-4E50AB081145}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Visual Studio Community 2022 (HKLM-x32\...\a45067d3) (Version: 17.8.5 - Microsoft Corporation)
VS Immersive Activate Helper (HKLM-x32\...\{FFFF1EAF-0FE4-4E67-82C2-CA5DB41BB093}) (Version: 17.0.125.0 - Microsoft Corporation) Hidden
VS JIT Debugger (HKLM\...\{C17B72FB-7790-44C0-B897-9BEE0BAD5BA0}) (Version: 17.0.125.0 - Microsoft Corporation) Hidden
VS Script Debugging Common (HKLM\...\{D56DC014-C4C1-4330-B32B-D9785DAE7BCB}) (Version: 17.0.125.0 - Microsoft Corporation) Hidden
vs_BlendMsi (HKLM-x32\...\{F52924D9-B226-488E-96AB-FA5A56722091}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsi (HKLM-x32\...\{4961B6E1-A98B-43A9-BFC0-F2E741B6F998}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsires (HKLM-x32\...\{8B0218E5-A9A0-4C9D-A0F4-442117192AE5}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_clickoncesigntoolmsi (HKLM-x32\...\{72BD9E2C-6B91-40B9-8FCF-FEDAFDD67C18}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_communitymsires (HKLM-x32\...\{3B1E620A-2D84-442A-9E91-3D5B6D4ECAAD}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_communitysharedmsi (HKLM-x32\...\{95F790F1-F8CC-445E-BBCB-C5446EF10C0C}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_communityx64msi (HKLM\...\{9DAFCFF7-0036-4739-A685-5DDF62466E05}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_CoreEditorFonts (HKLM-x32\...\{1851460E-0E63-4117-B5BA-25A2F045801B}) (Version: 17.7.40001 - Microsoft Corporation)
vs_devenvsharedmsi (HKLM-x32\...\{CBF6EE7C-AF9F-4B46-9097-60065588AC55}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_devenx64vmsi (HKLM\...\{3E31A14F-E205-4F3F-9E20-3BAEB97957D1}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_filehandler_amd64 (HKLM-x32\...\{F3214775-93E6-4462-AAAD-5ACFB687CED2}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_filehandler_x86 (HKLM-x32\...\{A749897F-8AD4-4006-B622-7A8CA09FEB2C}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_FileTracker_Singleton (HKLM-x32\...\{87A00560-EABF-4423-A876-F564B14F2499}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_githubprotocolhandlermsi (HKLM-x32\...\{4BD007CE-3471-40DA-9479-506CB09B8FBD}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_minshellinteropsharedmsi (HKLM-x32\...\{E5AF49C9-6FC6-404A-8562-16BDD6CFA531}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_minshellinteropx64msi (HKLM\...\{5F7E78E9-97B3-4CC2-AF61-4E13FFD183B9}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_minshellmsires (HKLM-x32\...\{3A6E1E89-2ED2-4F08-896B-F6F8999AD0F5}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_minshellsharedmsi (HKLM-x32\...\{E3FA95C9-9130-4173-AA94-60A8312A3CFC}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_minshellx64msi (HKLM\...\{C8E7596B-BE87-4C7B-B9A0-EA9BF41090D0}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_SQLClickOnceBootstrappermsi (HKLM-x32\...\{ED1CA098-DB2C-42FF-A9A5-BE564482AC95}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_tipsmsi (HKLM-x32\...\{424D8C15-669A-49BC-9DD4-99322263E41C}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_vswebprotocolselectormsi (HKLM-x32\...\{AFF58319-E812-40D5-8C65-5A311B541716}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
WinRAR 6.24 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.24.0 - win.rar GmbH)
Zoom (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\ZoomUMX) (Version: 5.17.2 (29988) - Zoom Video Communications, Inc.)
 
Packages:
=========
 
ibis Paint -> C:\Program Files\WindowsApps\ibisinc.ibisPaint_12.0.4.0_x64__sxbx2qs82h9wr [2024-04-08] (ibis inc.)
Microsoft Copilot -> C:\Program Files\WindowsApps\Microsoft.Windows.Ai.Copilot.Provider_1.0.3.0_neutral__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)
Roblox -> C:\Program Files\WindowsApps\ROBLOXCORPORATION.ROBLOX_2.618.546.0_x64__55nm5eh3cm0pr [2024-03-30] (Roblox Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-02-08] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-10-20] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-02-08] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2ce.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2024-01-15 18:50 - 2024-01-15 18:48 - 000000824 ____C C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{6CCADE46-6685-4EDF-A529-1E4A2904973A}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{461DD8CC-C32E-4712-B984-F09264F3FF11}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{19D4D2A2-D824-4429-8064-D5CFDE85374E}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{E163F5E2-B4A0-4B0B-A21B-57216ABCA55F}] => (Allow) C:\Program Files\Unity Hub\Unity Hub.exe => No File
FirewallRules: [{BBB93C97-6535-4469-AA72-E2635CD5EEF9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{8FFA2879-1451-4E3F-AE68-15EE686E8DEC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{DFF564AF-B976-444C-B4FF-1CCAA0F9FE18}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{7CFBD9D8-7EEE-4291-940F-1BBDDA0A6BA7}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{C81058DC-6FB6-4BBD-8024-3DDC59C7BC31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Pirate Plague of the Dead\ThePirate2.exe () [File not signed]
FirewallRules: [{8FB6435F-9943-4009-B366-C0FF42FDFCB1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Pirate Plague of the Dead\ThePirate2.exe () [File not signed]
FirewallRules: [TCP Query User{25B413D0-2794-4125-B178-24F5B73EDA95}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{121C4610-59C9-4E64-BA1B-4A4B01D6FC79}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{8D22F4CB-1410-4230-B194-64B65F45FEBD}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{33466B66-5B49-4929-9199-156E011D2AE1}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{778043E1-6AD6-43A3-B8C9-44A27E10AF52}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{7354C07B-7ACA-4407-8720-5546E49B37F0}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\123.0.2420.81\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C4B49B6A-FDDA-4507-AC98-69733CDE8CDC}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BB9C3A03-6BB6-4AFF-A727-151C19DDAA18}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AEB8ED22-21BF-45D4-8822-FC4469DA3CFA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1A5D85F7-622B-4906-9FA8-668CA71F3512}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled (Total:56.95 GB) (Free:8.03 GB) (14%)
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (03/27/2024 08:41:10 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SearchApp.exe version 10.0.19041.4170 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 25b0
 
Start Time: 01da8020d2588ad8
 
Termination Time: 4294967295
 
Application Path: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
 
Report Id: 17126cdb-8461-4cd1-8446-4a7bd05907e0
 
Faulting package full name: Microsoft.Windows.Search_1.14.13.19041_neutral_neutral_cw5n1h2txyewy
 
Faulting package-relative application ID: ShellFeedsUI
 
Hang type: Quiesce
 
Error: (03/27/2024 07:29:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_cbdhsvc, version: 10.0.19041.3636, time stamp: 0x122dc5a3
Faulting module name: combase.dll, version: 10.0.19041.4123, time stamp: 0x81a292dc
Exception code: 0xc0000005
Fault offset: 0x00000000000339b5
Faulting process id: 0x504
Faulting application start time: 0x01da80201d7382af
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\WINDOWS\System32\combase.dll
Report Id: e88d5c26-7f7e-4635-a6e2-dfd9a95bb5c4
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (03/23/2024 08:02:34 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program RobloxPlayerBeta.exe version 0.617.344.10272 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 2df4
 
Start Time: 01da7cc3af46928c
 
Termination Time: 19
 
Application Path: C:\Users\david\AppData\Local\Roblox\Versions\version-2e85a7f050554e83\RobloxPlayerBeta.exe
 
Report Id: a99efce2-4a1b-43df-a2a0-d1b63466d803
 
Faulting package full name: 
 
Faulting package-relative application ID: 
 
Hang type: Unknown
 
Error: (03/23/2024 04:44:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program RobloxPlayerBeta.exe version 0.617.344.10272 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 34d4
 
Start Time: 01da7cbda74ac20c
 
Termination Time: 12
 
Application Path: C:\Users\david\AppData\Local\Roblox\Versions\version-2e85a7f050554e83\RobloxPlayerBeta.exe
 
Report Id: ce1bb6b5-b65e-424a-ba6b-284ab75952a9
 
Faulting package full name: 
 
Faulting package-relative application ID: 
 
Hang type: Unknown
 
Error: (03/22/2024 12:24:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: malwarebytes_assistant.exe, version: 4.0.0.1747, time stamp: 0x65cbc6c8
Faulting module name: ucrtbase.dll, version: 10.0.19041.3636, time stamp: 0x81cf5d89
Exception code: 0xc0000409
Fault offset: 0x000000000007286e
Faulting process id: 0x383c
Faulting application start time: 0x01da7c3aaf3f9279
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe
Faulting module path: C:\WINDOWS\System32\ucrtbase.dll
Report Id: 98427aa5-33b9-4c5c-a244-691ec9ea84c5
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (03/21/2024 11:11:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: TextInputHost.exe, version: 123.26505.0.0, time stamp: 0x650e209e
Faulting module name: KERNELBASE.dll, version: 10.0.19041.3996, time stamp: 0xb756c9ff
Exception code: 0xc000027b
Fault offset: 0x000000000012d952
Faulting process id: 0x3a7c
Faulting application start time: 0x01da79bfeb3a4a77
Faulting application path: C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: 539ff861-0089-4592-b12e-c8bb45df5e7e
Faulting package full name: MicrosoftWindows.Client.CBS_1000.19054.1000.0_x64__cw5n1h2txyewy
Faulting package-relative application ID: InputApp
 
Error: (03/21/2024 10:46:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_cbdhsvc, version: 10.0.19041.3636, time stamp: 0x122dc5a3
Faulting module name: cbdhsvc.dll, version: 10.0.19041.3996, time stamp: 0xa3dae9cc
Exception code: 0xc0000005
Fault offset: 0x000000000005138d
Faulting process id: 0x1490
Faulting application start time: 0x01da79bfe4a8df6c
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: c:\windows\system32\cbdhsvc.dll
Report Id: 4ac02289-5e93-4dbd-819f-2fc5ae24cb74
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (03/19/2024 08:41:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 10.0.19041.4170, time stamp: 0x36e20eb9
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x725881f0
Faulting process id: 0x10dc
Faulting application start time: 0x01da79c00420c1d5
Faulting application path: C:\WINDOWS\SysWOW64\explorer.exe
Faulting module path: unknown
Report Id: 96415d19-00ce-418f-973f-b0252ee1f526
Faulting package full name: 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (04/01/2024 03:35:29 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200b: 2024-01 Security Update for Windows 10 Version 22H2 for x64-based Systems (KB5034441).
 
Error: (03/29/2024 08:52:26 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-OADEFFT)
Description: The server Microsoft.Windows.ContentDeliveryManager_10.0.19041.3636_neutral_neutral_cw5n1h2txyewy!App.AppXwdz8g2fxr36xz0tdtagygnvemf85s7gg.mca did not register with DCOM within the required timeout.
 
Error: (03/29/2024 08:52:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-OADEFFT)
Description: The server Microsoft.MicrosoftOfficeHub_18.2311.1071.0_x64__8wekyb3d8bbwe!Microsoft.MicrosoftOfficeHub.AppXvhez9tbpytkh6zv5q0bx5fj12yay14wg.mca did not register with DCOM within the required timeout.
 
Error: (03/29/2024 08:52:25 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-OADEFFT)
Description: DCOM got error "1053" attempting to start the service BcastDVRUserService_4fd29 with arguments "Unavailable" in order to run the server:
Windows.Media.Capture.Internal.AppCaptureShell
 
Error: (03/29/2024 08:52:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The GameDVR and Broadcast User Service_4fd29 service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (03/29/2024 08:52:25 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the GameDVR and Broadcast User Service_4fd29 service to connect.
 
Error: (03/29/2024 08:35:17 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-OADEFFT)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.
 
Error: (03/29/2024 03:56:55 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-OADEFFT)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.
 
 
Windows Defender:
================
Date: 2024-04-01 19:02:19
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2024-04-01 15:44:56
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2024-03-29 19:34:55
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2024-03-29 19:23:52
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2024-03-28 18:04:54
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]:
 
Date: 2024-01-20 15:55:47
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.2416.0
Previous security intelligence Version: 1.403.2375.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
 
Date: 2024-01-20 15:55:47
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.2416.0
Previous security intelligence Version: 1.403.2375.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
 
Date: 2024-01-16 04:22:56
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 0.0.0.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 0.0.0.0
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
Date: 2024-01-16 04:22:56
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 0.0.0.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version: 
Previous Engine Version: 0.0.0.0
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
Date: 2024-01-16 04:22:56
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 0.0.0.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 0.0.0.0
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
CodeIntegrity:
===============
Date: 2024-02-08 01:32:07
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Microsoft signing level requirements.
 
Date: 2024-02-08 01:32:07
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Windows signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: FUJITSU // Phoenix Technologies Ltd. Version 1.14 01/13/2015
Motherboard: FUJITSU FJNB270
Processor: Intel® Core™ i5-4200M CPU @ 2.50GHz
Percentage of memory in use: 73%
Total physical RAM: 8089.84 MB
Available physical RAM: 2180 MB
Total Virtual: 10649.84 MB
Available Virtual: 3710.21 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:56.95 GB) (Free:8.03 GB) (Model: TOSHIBA-TR150) NTFS
 
\\?\Volume{4b4035a3-2ecd-41a1-89af-809bd0d015be}\ (Відновити) (Fixed) (Total:0.52 GB) (Free:0.5 GB) NTFS
\\?\Volume{2f0c7daf-358d-4e24-867e-5235c9664dc3}\ () (Fixed) (Total:0.67 GB) (Free:0.08 GB) NTFS
\\?\Volume{11965be1-6d9e-4fb9-8343-8292078295e4}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 111.8 GB) (Disk ID: 6E505E75)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

Edited by CaptainBlud, 08 April 2024 - 10:02 PM.


#4 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,348 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 09 April 2024 - 05:47 AM

I am pleased to advise that there are no obvious signs of malware present, although there are 2 folders I'd like to check.
Let's do some cleanup and maintenance next, by running the following FRST script.
As a part of this I have included the The Emptytemp: command.
Note: This will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
Important: This script was written specifically for you, for use only on this machine. Running this on another machine may cause damage to your operating system

  • Right click on the FRST icon and select Run as administrator.
  • Highlight all of the information in the text box below then hit the Ctrl + C keys together to copy the text.
  • It is not necessary to paste the information anywhere as FRST will do this for you.
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
Folder: C:\ProgramData\Piriform
Folder: C:\ProgramData\Norton
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\david\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
FirewallRules: [{461DD8CC-C32E-4712-B984-F09264F3FF11}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{19D4D2A2-D824-4429-8064-D5CFDE85374E}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{E163F5E2-B4A0-4B0B-A21B-57216ABCA55F}] => (Allow) C:\Program Files\Unity Hub\Unity Hub.exe => No File
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /RestoreHealth
cmd: chkdsk
Emptytemp:
End::
  • Click on the Fix button just once and wait.
  • If the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When it's finished FRST will generate a log in the location you ran the tool from. (Fixlog.txt).

Please copy the contents from this text file and paste into your next reply.
-----------------------------------------------------------------------
Then please do this.
Crystal Disk Info

  • Download Crystal Disk Info and save it to your Desktop.
  • Right click on the icon and select Run as administrator.
  • Accept the agreement and click Next four times.
  • Click Install.
  • Click Finish to launch the program.
  • On the CrystalDiskInfo screen click File, then Save (text)
  • Save the file onto your Desktop using the default file name.
  • Copy and paste the information into your next reply.

Also advise how your computer is running now.



#5 CaptainBlud

CaptainBlud
  • Topic Starter

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 10 April 2024 - 01:14 AM

Additionally to the info you asked me to provide, I think I should inform you on this too. Upon launching CrystalDiskInfo, I discovered that the total amount of SSD (actually I just discovered that I have an SSD and not an HDD, funnily enough) space it shows is actually very different from what file explorer and the system settings do. File explorer and the settings show that Local Disk C (the only one) has 56.9 GB of total storage space, while CrystalDiskInfo shows 120 GB. I am ashamed to confess, but I don't know bleep about how storage space is partitioned in Windows (10). Ashamed because it surely does indicate an absolute lack of knowledge about how the device I use for the most part of my daily routine works, and that's just bad consumer behavior, though kind of normalized in modern consumer culture for some reason. I'm a little bit concerned about this, but honestly clueless what it can possibly indicate. As I said, bad consumer behavior.

But back to the main thing. Here's what you asked for:
 

----------------------------------------------------------------------------
CrystalDiskInfo 9.2.3 © 2008-2024 hiyohiyo
                                Crystal Dew World: https://crystalmark.info/
----------------------------------------------------------------------------
 
    OS : Windows 10  22H2 [10.0 Build 19045] (x64)
  Date : 2024/04/10 8:39:44
 
-- Controller Map ----------------------------------------------------------
 + Standard SATA AHCI Controller [ATA]
   - TOSHIBA-TR150
 - Microsoft Storage Spaces Controller [SCSI]
 
-- Disk List ---------------------------------------------------------------
 (01) TOSHIBA-TR150 : 120.0 GB [0/0/0, pd1] - to
 
----------------------------------------------------------------------------
 (01) TOSHIBA-TR150
----------------------------------------------------------------------------
           Model : TOSHIBA-TR150
        Firmware : SAFZ12.3
   Serial Number : 46RB511JK8VU
       Disk Size : 120.0 GB (8.4/120.0/120.0/120.0)
     Buffer Size : Unknown
     Queue Depth : 32
    # of Sectors : 234441648
   Rotation Rate : ---- (SSD)
       Interface : Serial ATA
   Major Version : ACS-2
   Minor Version : ----
   Transfer Mode : SATA/600 | SATA/600
  Power On Hours : 13947 hours
  Power On Count : 4920 count
     Host Writes : 16034 GB
     Temperature : 33 C (91 F)
   Health Status : Good (89 %)
        Features : S.M.A.R.T., APM, NCQ, TRIM, DevSleep, GPL
       APM Level : 00FEh [ON]
       AAM Level : ----
    Drive Letter : C:
 
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
09 100 100 __0 00000000367B Power-On Hours
0C 100 100 __0 000000001338 Power Cycle Count
A7 100 100 __0 000000000000 SSD Protect Mode
A8 100 100 __0 000000000000 SATA PHY Error Count
A9 100 100 _10 000000000000 Total Bad Block Count
AD 189 189 __0 000000000000 Erase Count
C0 100 100 __0 0000000001C0 Unexpected Power Loss Count
C2 _67 _52 _20 003000090021 Temperature
F1 100 100 __0 00000007D454 Total Host Writes
 
-- IDENTIFY_DEVICE ---------------------------------------------------------
        0    1    2    3    4    5    6    7    8    9
000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 3436 5242 3531 314A 4B38 5655 2020 2020 2020 2020
020: 0000 0000 0000 5341 465A 3132 2E33 544F 5348 4942
030: 412D 5452 3135 3020 2020 2020 2020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0000 0000 0007 3FFF 0010 003F FC10 00FB 0110
060: 4BB0 0DF9 0000 0007 0003 0078 0078 0078 0078 4F20
070: 0000 0000 0000 0000 0000 001F E70E 0086 014C 0040
080: 03F8 0000 746B 7509 4163 7469 B409 4163 407F 0001
090: 0001 00FE FFFE 0000 0000 0000 0000 0000 0000 0000
100: 4BB0 0DF9 0000 0000 0000 0008 4000 0000 5E83 A972
110: 0046 0FAF 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0001
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 0000 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 0001 0000 0000
220: 0000 0000 107F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 FFFF 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 60A5
 
-- SMART_READ_DATA ---------------------------------------------------------
     +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 09 12 00 64 64 7B 36 00 00 00 00 00 0C 12
010: 00 64 64 38 13 00 00 00 00 00 A7 22 00 64 64 00
020: 00 00 00 00 00 00 A8 12 00 64 64 00 00 00 00 00
030: 00 00 A9 03 00 64 64 00 00 00 00 00 00 00 AD 12
040: 00 BD BD 00 00 00 00 00 00 00 C0 12 00 64 64 C0
050: 01 00 00 00 00 00 C2 23 00 43 34 21 00 09 00 30
060: 00 00 F1 32 00 64 64 54 D4 07 00 00 00 00 00 00
070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
090: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 1E 00 00 79
170: 03 00 01 00 01 02 03 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 9F
 
-- SMART_READ_THRESHOLD ----------------------------------------------------
     +0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 09 00 00 64 64 00 00 00 00 00 00 00 0C 00
010: 00 64 64 00 00 00 00 00 00 00 A7 00 00 64 64 00
020: 00 00 00 00 00 00 A8 00 00 64 64 00 00 00 00 00
030: 00 00 A9 0A 00 64 64 00 00 00 00 00 00 00 AD 00
040: 00 64 64 00 00 00 00 00 00 00 C0 00 00 64 64 00
050: 00 00 00 00 00 00 C2 14 00 64 64 00 00 00 00 00
060: 00 00 F1 00 00 64 64 00 00 00 00 00 00 00 00 00
070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
090: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 9D


#6 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,348 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 10 April 2024 - 06:59 AM

Please post the contents of the Fixlog.txt that was created after you ran the fix.
Regarding the drive space query, right-click This PC on your Desktop and then click Manage.
In the Computer Management window, click Disk Management.
A list of available drives and partitions will be shown.
Please advise the results.



#7 CaptainBlud

CaptainBlud
  • Topic Starter

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 11 April 2024 - 08:20 PM

Here.

Fix result of Farbar Recovery Scan Tool (x64) Version: 06.04.2024
Ran by david (10-04-2024 07:54:01) Run:1
Running from C:\Users\david\Downloads
Loaded Profiles: david
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
Folder: C:\ProgramData\Piriform
Folder: C:\ProgramData\Norton
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\david\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
FirewallRules: [{461DD8CC-C32E-4712-B984-F09264F3FF11}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{19D4D2A2-D824-4429-8064-D5CFDE85374E}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{E163F5E2-B4A0-4B0B-A21B-57216ABCA55F}] => (Allow) C:\Program Files\Unity Hub\Unity Hub.exe => No File
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /RestoreHealth
cmd: chkdsk
Emptytemp:
End::
*****************
 
SystemRestore: On => Error -> 9%
CreateRestorePoint: Error(1=9%) -> Failed to create a restore point.
Processes closed successfully.
 
========================= Folder: C:\ProgramData\Piriform ========================
 
2024-03-19 08:41 - 2024-03-19 08:41 - 000000000 ___DC [00000000000000000000000000000000] C:\ProgramData\Piriform\CCleaner
2024-03-19 08:41 - 2024-03-28 12:06 - 000090112 ___AC [A55E648A59C212F8B1552CA93B3F10D0] () C:\ProgramData\Piriform\CCleaner\CCleanerProgramDeactivator.db
2024-03-19 08:41 - 2024-03-28 12:06 - 000155648 ___AC [F91EF6AA8E01461AE9328C70CA1D2EB9] () C:\ProgramData\Piriform\CCleaner\CCleanerProgramDeactivatorCache.db
2024-03-19 08:41 - 2024-03-19 08:41 - 000000000 ___DC [00000000000000000000000000000000] C:\ProgramData\Piriform\CCleaner\burger_client
2024-03-19 08:41 - 2024-03-19 08:41 - 000000000 ___DC [00000000000000000000000000000000] C:\ProgramData\Piriform\CCleaner\burger_client\825E3DD4-926B-4EB9-A66E-9F88AAD28A0F
2024-03-19 08:41 - 2024-03-19 08:42 - 000000000 ___DC [00000000000000000000000000000000] C:\ProgramData\Piriform\CCleaner\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417
2024-03-19 08:41 - 2024-03-19 08:41 - 000000110 ___AC [F8D1C068561DEB36DB3CF635BFD0C903] () C:\ProgramData\Piriform\CCleaner\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\44ED97C8-2D40-4A50-913D-673F6858B9AF
 
====== End of Folder: ======
 
 
========================= Folder: C:\ProgramData\Norton ========================
 
2024-03-19 08:41 - 2024-03-19 08:41 - 000000000 ___DC [00000000000000000000000000000000] C:\ProgramData\Norton\{086A63F0-6B13-4F29-9695-134E7A01E963}
2024-03-19 08:41 - 2024-03-19 08:41 - 000000075 ___AC [57E814ABE4DC9EADD773AEA8CC10E713] () C:\ProgramData\Norton\{086A63F0-6B13-4F29-9695-134E7A01E963}\LC.INI
 
====== End of Folder: ======
 
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Update Binary" => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{461DD8CC-C32E-4712-B984-F09264F3FF11}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{19D4D2A2-D824-4429-8064-D5CFDE85374E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E163F5E2-B4A0-4B0B-A21B-57216ABCA55F}" => removed successfully
 
========= sfc /scannow =========
 
 
 
Windows Resource Protection could not start the repair service.
 
 
 
========= End of CMD: =========
 
 
========= DISM /Online /Cleanup-Image /RestoreHealth =========
 
 
Deployment Image Servicing and Management tool
Version: 10.0.19041.3636
 
Image Version: 10.0.19045.4170
 
 
[==                         3.8%                           ] 
 
[==                         4.8%                           ] 
 
[===                        5.7%                           ] 
 
[===                        6.2%                           ] 
 
[====                       7.2%                           ] 
 
[====                       7.4%                           ] 
 
[====                       8.2%                           ] 
 
[=====                      9.0%                           ] 
 
[=====                      9.7%                           ] 
 
[=====                      10.2%                          ] 
 
[======                     11.0%                          ] 
 
[======                     11.8%                          ] 
 
[=======                    12.4%                          ] 
 
[=======                    13.4%                          ] 
 
[========                   14.0%                          ] 
 
[========                   14.7%                          ] 
 
[========                   15.2%                          ] 
 
[========                   15.3%                          ] 
 
[========                   15.3%                          ] 
 
[========                   15.4%                          ] 
 
[========                   15.5%                          ] 
 
[=========                  15.9%                          ] 
 
[=========                  16.9%                          ] 
 
[==========                 17.9%                          ] 
 
[==========                 18.9%                          ] 
 
[===========                19.4%                          ] 
 
[===========                20.1%                          ] 
 
[============               20.8%                          ] 
 
[============               21.3%                          ] 
 
[============               21.8%                          ] 
 
[============               22.0%                          ] 
 
[============               22.3%                          ] 
 
[=============              22.6%                          ] 
 
[=============              22.8%                          ] 
 
[=============              22.9%                          ] 
 
[=============              22.9%                          ] 
 
[=============              23.3%                          ] 
 
[==============             24.3%                          ] 
 
[==============             25.3%                          ] 
 
[===============            26.0%                          ] 
 
[===============            27.0%                          ] 
 
[===============            27.4%                          ] 
 
[================           28.4%                          ] 
 
[=================          29.4%                          ] 
 
[=================          29.7%                          ] 
 
[=================          30.2%                          ] 
 
[=================          30.9%                          ] 
 
[==================         31.8%                          ] 
 
[==================         31.9%                          ] 
 
[===================        32.9%                          ] 
 
[===================        33.6%                          ] 
 
[===================        33.7%                          ] 
 
[===================        34.0%                          ] 
 
[===================        34.0%                          ] 
 
[===================        34.3%                          ] 
 
[===================        34.4%                          ] 
 
[====================       34.8%                          ] 
 
[====================       35.0%                          ] 
 
[====================       35.3%                          ] 
 
[====================       35.5%                          ] 
 
[====================       35.7%                          ] 
 
[====================       35.9%                          ] 
 
[=====================      36.2%                          ] 
 
[=====================      36.4%                          ] 
 
[=====================      36.8%                          ] 
 
[=====================      36.9%                          ] 
 
[=====================      37.1%                          ] 
 
[=====================      37.3%                          ] 
 
[=====================      37.4%                          ] 
 
[=====================      37.4%                          ] 
 
[=====================      37.7%                          ] 
 
[=====================      37.7%                          ] 
 
[=====================      37.7%                          ] 
 
[=====================      37.8%                          ] 
 
[=====================      37.9%                          ] 
 
[======================     38.1%                          ] 
 
[======================     38.2%                          ] 
 
[======================     38.3%                          ] 
 
[======================     38.6%                          ] 
 
[======================     38.9%                          ] 
 
[======================     39.4%                          ] 
 
[=======================    40.0%                          ] 
 
[=======================    41.0%                          ] 
 
[========================   42.0%                          ] 
 
[========================   42.2%                          ] 
 
[=========================  43.2%                          ] 
 
[=========================  44.2%                          ] 
 
[========================== 45.1%                          ] 
 
[========================== 46.0%                          ] 
 
[===========================46.9%                          ] 
 
[===========================47.9%                          ] 
 
[===========================48.9%                          ] 
 
[===========================49.9%                          ] 
 
[===========================50.9%                          ] 
 
[===========================51.7%                          ] 
 
[===========================51.9%                          ] 
 
[===========================52.5%                          ] 
 
[===========================52.5%                          ] 
 
[===========================52.6%                          ] 
 
[===========================52.6%                          ] 
 
[===========================52.7%                          ] 
 
[===========================52.7%                          ] 
 
[===========================53.0%                          ] 
 
[===========================53.0%                          ] 
 
[===========================53.1%                          ] 
 
[===========================53.1%                          ] 
 
[===========================53.1%                          ] 
 
[===========================53.2%                          ] 
 
[===========================53.2%                          ] 
 
[===========================53.3%                          ] 
 
[===========================53.4%                          ] 
 
[===========================53.4%                          ] 
 
[===========================53.4%                          ] 
 
[===========================53.5%                          ] 
 
[===========================53.5%                          ] 
 
[===========================53.6%                          ] 
 
[===========================53.7%                          ] 
 
[===========================53.7%                          ] 
 
[===========================53.7%                          ] 
 
[===========================53.7%                          ] 
 
[===========================53.9%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.2%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.4%                          ] 
 
[===========================54.4%                          ] 
 
[===========================54.5%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.7%                          ] 
 
[===========================54.8%                          ] 
 
[===========================54.8%                          ] 
 
[===========================54.9%                          ] 
 
[===========================54.9%                          ] 
 
[===========================54.9%                          ] 
 
[===========================54.9%                          ] 
 
[===========================55.0%                          ] 
 
[===========================55.0%                          ] 
 
[===========================55.2%                          ] 
 
[===========================55.2%                          ] 
 
[===========================55.2%                          ] 
 
[===========================55.3%                          ] 
 
[===========================55.4%                          ] 
 
[===========================55.5%                          ] 
 
[===========================55.8%                          ] 
 
[===========================55.8%                          ] 
 
[===========================55.9%                          ] 
 
[===========================55.9%                          ] 
 
[===========================56.0%                          ] 
 
[===========================56.2%                          ] 
 
[===========================56.2%                          ] 
 
[===========================56.2%                          ] 
 
[===========================56.3%                          ] 
 
[===========================56.3%                          ] 
 
[===========================56.6%                          ] 
 
[===========================56.8%                          ] 
 
[===========================57.7%=                         ] 
 
[===========================58.7%==                        ] 
 
[===========================59.7%==                        ] 
 
[===========================60.1%==                        ] 
 
[===========================62.3%====                      ] 
 
[===========================84.9%=================         ] 
 
[===========================85.7%=================         ] 
 
[===========================86.6%==================        ] 
 
[===========================87.3%==================        ] 
 
[===========================89.0%===================       ] 
 
[===========================90.6%====================      ] 
 
[===========================92.5%=====================     ] 
 
[==========================100.0%==========================] 
The restore operation completed successfully.
The operation completed successfully.
 
 
========= End of CMD: =========
 
 
========= chkdsk =========
 
The type of the file system is NTFS.
 
WARNING!  /F parameter not specified.
Running CHKDSK in read-only mode.
 
Stage 1: Examining basic file system structure ...
Progress: 0 of 974080 done; Stage:  0%; Total:  0%; ETA:   0:46:50    
Progress: 3223 of 974080 done; Stage:  0%; Total:  0%; ETA:   0:46:47 .  
Progress: 14306 of 974080 done; Stage:  1%; Total:  0%; ETA:   0:46:35 .. 
Progress: 30209 of 974080 done; Stage:  3%; Total:  1%; ETA:   0:01:40 ...
Progress: 53761 of 974080 done; Stage:  5%; Total:  2%; ETA:   0:01:19    
Progress: 59923 of 974080 done; Stage:  6%; Total:  2%; ETA:   0:01:28 .  
Progress: 67324 of 974080 done; Stage:  6%; Total:  2%; ETA:   0:01:32 .. 
Progress: 72449 of 974080 done; Stage:  7%; Total:  3%; ETA:   0:01:39 ...
Progress: 81091 of 974080 done; Stage:  8%; Total:  3%; ETA:   0:01:40    
Progress: 92434 of 974080 done; Stage:  9%; Total:  4%; ETA:   0:01:36 .  
Progress: 101093 of 974080 done; Stage: 10%; Total:  4%; ETA:   0:01:34 .. 
Progress: 111175 of 974080 done; Stage: 11%; Total:  5%; ETA:   0:01:32 ...
Progress: 119106 of 974080 done; Stage: 12%; Total:  5%; ETA:   0:01:31    
Progress: 134410 of 974080 done; Stage: 13%; Total:  6%; ETA:   0:01:26 .  
Progress: 166207 of 974080 done; Stage: 17%; Total:  7%; ETA:   0:01:18 .. 
Progress: 177153 of 974080 done; Stage: 18%; Total:  8%; ETA:   0:01:16 ...
Progress: 204033 of 974080 done; Stage: 20%; Total:  9%; ETA:   0:01:13    
Progress: 218214 of 974080 done; Stage: 22%; Total: 10%; ETA:   0:01:12 .  
Progress: 244225 of 974080 done; Stage: 25%; Total: 11%; ETA:   0:01:10 .. 
Progress: 273151 of 974080 done; Stage: 28%; Total: 12%; ETA:   0:01:07 ...
Progress: 300539 of 974080 done; Stage: 30%; Total: 13%; ETA:   0:01:05    
Progress: 330744 of 974080 done; Stage: 33%; Total: 14%; ETA:   0:01:02 .  
Progress: 371201 of 974080 done; Stage: 38%; Total: 15%; ETA:   0:00:57 .. 
Progress: 411565 of 974080 done; Stage: 42%; Total: 17%; ETA:   0:00:54 ...
Progress: 444417 of 974080 done; Stage: 45%; Total: 18%; ETA:   0:00:52    
Progress: 472876 of 974080 done; Stage: 48%; Total: 19%; ETA:   0:00:51 .  
Progress: 497387 of 974080 done; Stage: 51%; Total: 20%; ETA:   0:00:51 .. 
Progress: 524803 of 974080 done; Stage: 53%; Total: 21%; ETA:   0:00:49 ...
Progress: 551425 of 974080 done; Stage: 56%; Total: 22%; ETA:   0:00:49    
Progress: 578561 of 974080 done; Stage: 59%; Total: 23%; ETA:   0:00:47 .  
Progress: 617217 of 974080 done; Stage: 63%; Total: 24%; ETA:   0:00:46 .. 
Progress: 642639 of 974080 done; Stage: 65%; Total: 25%; ETA:   0:00:44 ...
Progress: 656583 of 974080 done; Stage: 67%; Total: 26%; ETA:   0:00:44    
Progress: 662588 of 974080 done; Stage: 68%; Total: 26%; ETA:   0:00:44 .  
Progress: 667124 of 974080 done; Stage: 68%; Total: 26%; ETA:   0:00:44 .. 
Progress: 676353 of 974080 done; Stage: 69%; Total: 27%; ETA:   0:00:44 ...
Progress: 725505 of 974080 done; Stage: 74%; Total: 28%; ETA:   0:00:44    
Progress: 772236 of 974080 done; Stage: 79%; Total: 30%; ETA:   0:00:43 .  
Progress: 813973 of 974080 done; Stage: 83%; Total: 31%; ETA:   0:00:41 .. 
Progress: 849862 of 974080 done; Stage: 87%; Total: 32%; ETA:   0:00:39 ...
Progress: 879361 of 974080 done; Stage: 90%; Total: 33%; ETA:   0:00:39    
Progress: 908965 of 974080 done; Stage: 93%; Total: 34%; ETA:   0:00:38 .  
Progress: 943473 of 974080 done; Stage: 96%; Total: 35%; ETA:   0:00:38 .. 
Progress: 956929 of 974080 done; Stage: 98%; Total: 36%; ETA:   0:00:36 ...
Progress: 963841 of 974080 done; Stage: 98%; Total: 36%; ETA:   0:00:36    
Progress: 974080 of 974080 done; Stage: 100%; Total: 36%; ETA:   0:00:38 .  
                                                                                       
                                                                                       
  974080 file records processed.                                                        
 
File verification completed.
 Phase duration (File record verification): 21.92 seconds.
Progress: 45793 of 45793 done; Stage: 100%; Total: 26%; ETA:   0:01:00 .. 
                                                                                       
                                                                                       
  45793 large file records processed.                                   
 
 Phase duration (Orphan file record recovery): 0.00 milliseconds.
Progress: 0 of 0 done; Stage: 99%; Total: 26%; ETA:   0:01:00 ...
                                                                                       
                                                                                       
  0 bad file records processed.                                     
 
 Phase duration (Bad file record checking): 0.06 milliseconds.
 
Stage 2: Examining file name linkage ...
Progress: 11217 of 1414532 done; Stage:  0%; Total: 26%; ETA:   0:01:00    
Progress: 61246 of 1414532 done; Stage:  4%; Total: 28%; ETA:   0:00:59 .  
Progress: 115238 of 1414532 done; Stage:  8%; Total: 29%; ETA:   0:00:55 .. 
Progress: 178941 of 1414532 done; Stage: 12%; Total: 31%; ETA:   0:00:52 ...
Progress: 228695 of 1414532 done; Stage: 16%; Total: 32%; ETA:   0:00:51    
Progress: 281676 of 1414532 done; Stage: 19%; Total: 34%; ETA:   0:00:49 .  
Progress: 333017 of 1414532 done; Stage: 23%; Total: 35%; ETA:   0:00:47 .. 
Progress: 442316 of 1414532 done; Stage: 31%; Total: 38%; ETA:   0:00:43 ...
Progress: 504546 of 1414532 done; Stage: 35%; Total: 39%; ETA:   0:00:41    
Progress: 545263 of 1414532 done; Stage: 38%; Total: 40%; ETA:   0:00:39 .  
Progress: 621812 of 1414532 done; Stage: 43%; Total: 42%; ETA:   0:00:38 .. 
Progress: 677897 of 1414532 done; Stage: 47%; Total: 44%; ETA:   0:00:36 ...
Progress: 745376 of 1414532 done; Stage: 52%; Total: 45%; ETA:   0:00:35    
Progress: 810847 of 1414532 done; Stage: 57%; Total: 47%; ETA:   0:00:33 .  
Progress: 861447 of 1414532 done; Stage: 60%; Total: 48%; ETA:   0:00:31 .. 
Progress: 895649 of 1414532 done; Stage: 63%; Total: 49%; ETA:   0:00:31 ...
Progress: 948823 of 1414532 done; Stage: 67%; Total: 50%; ETA:   0:00:30    
Progress: 54692 of 98365 done; Stage: 55%; Total: 53%; ETA:   0:00:27 .  
Progress: 98365 of 98365 done; Stage: 100%; Total: 54%; ETA:   0:00:27 .. 
                                                                                       
                                                                                       
  98365 reparse records processed.                                      
 
Progress: 974576 of 1414532 done; Stage: 68%; Total: 55%; ETA:   0:00:25 ...
Progress: 974676 of 1414532 done; Stage: 68%; Total: 58%; ETA:   0:00:25    
Progress: 977029 of 1414532 done; Stage: 69%; Total: 58%; ETA:   0:00:23 .  
Progress: 978739 of 1414532 done; Stage: 69%; Total: 58%; ETA:   0:00:23 .. 
Progress: 980136 of 1414532 done; Stage: 69%; Total: 59%; ETA:   0:00:23 ...
Progress: 980284 of 1414532 done; Stage: 69%; Total: 62%; ETA:   0:00:23    
Progress: 982612 of 1414532 done; Stage: 69%; Total: 62%; ETA:   0:00:20 .  
Progress: 983210 of 1414532 done; Stage: 69%; Total: 62%; ETA:   0:00:20 .. 
Progress: 985181 of 1414532 done; Stage: 69%; Total: 63%; ETA:   0:00:20 ...
Progress: 986287 of 1414532 done; Stage: 69%; Total: 63%; ETA:   0:00:20    
Progress: 986493 of 1414532 done; Stage: 69%; Total: 66%; ETA:   0:00:20 .  
Progress: 988339 of 1414532 done; Stage: 69%; Total: 66%; ETA:   0:00:19 .. 
Progress: 990345 of 1414532 done; Stage: 70%; Total: 67%; ETA:   0:00:19 ...
Progress: 997371 of 1414532 done; Stage: 70%; Total: 67%; ETA:   0:00:19    
Progress: 1020725 of 1414532 done; Stage: 72%; Total: 68%; ETA:   0:00:19 .  
Progress: 1022964 of 1414532 done; Stage: 72%; Total: 68%; ETA:   0:00:19 .. 
Progress: 1027157 of 1414532 done; Stage: 72%; Total: 69%; ETA:   0:00:19 ...
Progress: 1033824 of 1414532 done; Stage: 73%; Total: 69%; ETA:   0:00:19    
Progress: 1034115 of 1414532 done; Stage: 73%; Total: 69%; ETA:   0:00:19 .  
Progress: 1034562 of 1414532 done; Stage: 73%; Total: 69%; ETA:   0:00:19 .. 
Progress: 1043289 of 1414532 done; Stage: 73%; Total: 70%; ETA:   0:00:19 ...
Progress: 1053200 of 1414532 done; Stage: 74%; Total: 73%; ETA:   0:00:18    
Progress: 1055464 of 1414532 done; Stage: 74%; Total: 74%; ETA:   0:00:15 .  
Progress: 1065520 of 1414532 done; Stage: 75%; Total: 74%; ETA:   0:00:15 .. 
Progress: 1079839 of 1414532 done; Stage: 76%; Total: 75%; ETA:   0:00:15 ...
Progress: 1090880 of 1414532 done; Stage: 77%; Total: 75%; ETA:   0:00:15    
Progress: 1098267 of 1414532 done; Stage: 77%; Total: 75%; ETA:   0:00:15 .  
Progress: 1102341 of 1414532 done; Stage: 77%; Total: 75%; ETA:   0:00:15 .. 
Progress: 1105844 of 1414532 done; Stage: 78%; Total: 75%; ETA:   0:00:15 ...
Progress: 1107945 of 1414532 done; Stage: 78%; Total: 76%; ETA:   0:00:15    
Progress: 1112724 of 1414532 done; Stage: 78%; Total: 76%; ETA:   0:00:15 .  
Progress: 1117313 of 1414532 done; Stage: 78%; Total: 75%; ETA:   0:00:15 .. 
Progress: 1125192 of 1414532 done; Stage: 79%; Total: 76%; ETA:   0:00:15 ...
Progress: 1133094 of 1414532 done; Stage: 80%; Total: 76%; ETA:   0:00:15    
Progress: 1140905 of 1414532 done; Stage: 80%; Total: 76%; ETA:   0:00:15 .  
Progress: 1142068 of 1414532 done; Stage: 80%; Total: 77%; ETA:   0:00:15 .. 
Progress: 1142882 of 1414532 done; Stage: 80%; Total: 77%; ETA:   0:00:15 ...
Progress: 1145235 of 1414532 done; Stage: 80%; Total: 77%; ETA:   0:00:15    
Progress: 1146415 of 1414532 done; Stage: 81%; Total: 77%; ETA:   0:00:15 .  
Progress: 1159037 of 1414532 done; Stage: 81%; Total: 78%; ETA:   0:00:15 .. 
Progress: 1173756 of 1414532 done; Stage: 82%; Total: 77%; ETA:   0:00:15 ...
Progress: 1180615 of 1414532 done; Stage: 83%; Total: 77%; ETA:   0:00:15    
Progress: 1192697 of 1414532 done; Stage: 84%; Total: 78%; ETA:   0:00:15 .  
Progress: 1414532 of 1414532 done; Stage: 100%; Total: 79%; ETA:   0:00:15 .. 
                                                                                       
                                                                                       
  1414532 index entries processed.                                                       
 
Index verification completed.
 Phase duration (Index verification): 32.18 seconds.
Progress: 1 of 0 done; Stage: 99%; Total: 79%; ETA:   0:00:16 ...
Progress: 0 of 0 done; Stage: 99%; Total: 79%; ETA:   0:00:16    
                                                                                       
                                                                                       
  0 unindexed files scanned.                                        
 
 Phase duration (Orphan reconnection): 15.89 seconds.
Progress: 0 of 0 done; Stage: 99%; Total: 79%; ETA:   0:00:16 .  
                                                                                       
                                                                                       
  0 unindexed files recovered to lost and found.                    
 
 Phase duration (Orphan recovery to lost and found): 0.03 milliseconds.
Progress: 98365 of 98365 done; Stage: 100%; Total: 79%; ETA:   0:00:16 .. 
                                                                                       
                                                                                       
  98365 reparse records processed.                                      
 
 Phase duration (Reparse point and Object ID verification): 432.04 milliseconds.
 
Stage 3: Examining security descriptors ...
Security descriptor verification completed.
 Phase duration (Security descriptor verification): 814.00 milliseconds.
Progress: 26 of 26 done; Stage: 100%; Total: 99%; ETA:   0:00:00 ...
                                                                                       
                                                                                       
  220227 data files processed.                                           
 
 Phase duration (Data attribute verification): 0.07 milliseconds.
CHKDSK is verifying Usn Journal...
Progress: 0 of 4628 done; Stage:  0%; Total: 99%; ETA:   0:00:00    
Progress: 3477 of 4628 done; Stage: 75%; Total: 96%; ETA:   0:00:01 .  
Progress: 4628 of 4628 done; Stage: 100%; Total: 97%; ETA:   0:00:01 .. 
                                                                                       
                                                                                       
  37913888 USN bytes processed.                                                           
 
Usn Journal verification completed.
 Phase duration (USN journal verification): 433.05 milliseconds.
 
Windows has scanned the file system and found no problems.
No further action is required.
 
  59713670 KB total disk space.
  45909028 KB in 597959 files.
    349880 KB in 220228 indexes.
         0 KB in bad sectors.
   1128214 KB in use by the system.
     65536 KB occupied by the log file.
  12326548 KB available on disk.
 
      4096 bytes in each allocation unit.
  14928417 total allocation units on disk.
   3081637 allocation units available on disk.
Total duration: 1.19 minutes (71722 ms).
 
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
FlushDNS => completed
BITS transfer queue => 1572864 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 26450121 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 447114285 B
Windows/system/drivers => 8251892 B
Edge => 0 B
Chrome => 359125339 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 5850 B
david => 73442175 B
 
RecycleBin => 113636 B
EmptyTemp: => 873.6 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 08:04:10 ====


#8 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,348 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 12 April 2024 - 06:26 AM

Unfortunately the System File Checker did not run.
Let's try again as follows.

  • Click on the Start button.
  • In the search box at the bottom, type cmd.
  • Command Prompt should appear at the top of the menu.
  • Right-click on this and select Run As Administrator.
  • Type sfc /scannow. (Make sure there is a space between sfc and /scannow)
  • The scan will start. The time taken varies so please be patient and wait until completed.
  • Please report the results from the SFC scan in your next post.

-------------------------------------------------------------------------------------
Then please run a full scan with ESET Online Scanner, as an extra check.

  • Download ESET Online Scanner from here and save it to your Desktop.
  • Right click the esetonlinescanner.exe file you downloaded and select Run as administrator.
  • Select your desired language from the drop-down menu and click Get started.
  • Click Yes if a User Account window appears.
  • In the Terms of use screen, click Accept if you agree to the Terms of use.
  • Click Get started in the welcome screen.
  • Select your preference for the Customer Experience Improvement Program and the Detection feedback system.Click Continue.
  • Click Computer scan, in the Welcome back screen.
  • Choose Full scan on the next screen.
  • Select Enable ESET to detect and quarantine potentially unwanted applications.Then click Start scan
  • Please note that this process can take several hours to complete.
  • At the end of the scan, the Found and resolved detections screen may be displayed. You can click View detailed results to view specific information. Click Continue.
  • On the following screen click Save scan log and save it to your Desktop as ESETScan.txt. Click Continue.
  • ESET Online Scanner will now ask if you wish to turn on the Periodic Scan feature.I suggest that you do not do this for now Click Continue
  • You are offered a 30 day trial of ESET Internet Security on the next screen. Click Continue
  • On the next screen, you can leave feedback about the program if you wish.
  • There is an option to delete the application's data on closing, but we can but we can do this later.
  • If you left feedback, click Submit and Close. If not, click Close.
  • Copy and paste the contents of the ESETScan.txt file in your next reply.

 



#9 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,348 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 15 April 2024 - 05:16 AM

Please advise if you still need help?
It has been 3 days since my last post.
If you have not replied within the next 48 hours, I will assume that you no longer need help and this topic will be closed.



#10 CaptainBlud

CaptainBlud
  • Topic Starter

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 17 April 2024 - 01:11 AM

The first one here.
Microsoft Windows [Version 10.0.19045.4291]
© Microsoft Corporation. All rights reserved.
 
C:\WINDOWS\system32>sfc /scannow
 
Beginning system scan.  This process will take some time.
 
Beginning verification phase of system scan.
Verification 100% complete.
 
Windows Resource Protection did not find any integrity violations.
 
C:\WINDOWS\system32>

The second one probably in the few hours you said it might take to complete.


#11 CaptainBlud

CaptainBlud
  • Topic Starter

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 17 April 2024 - 02:46 AM

Alright, soooo...
ESET does this and then crashes.

Attached Files


Edited by CaptainBlud, 17 April 2024 - 02:46 AM.


#12 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,348 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 17 April 2024 - 07:46 AM

This happens sometimes with ESET. Removing the tool and starting again has worked in the past, but let's try an alternative scanner instead.
Emsisoft Emergency Kit.

  • Download and save the installation file from here:
  • Emsisoft
  • Double-click on the Emsisoft Emergency Kit setup file to start the installation process and then click on the Install button.
  • You may be presented with a User Account Control warning, asking you if you want to run this file. Click Yes to continue.
  • The downloaded package unpacks to “C:\EEK” by default and this folder now opens on your screen.
  • To start Emsisoft, double-click on the Start Emergency Kit Scanner icon in this folder.
  • You may get another User Account Control warning. Click Yes to continue.
  • Accept the Licence Agreement.
  • When you launch the program for the first time, Emsisoft Emergency Kit will automatically download updates. The Scan tab changes from orange to green when the update process is completed.
  • Leave the settings unchanged, which include detection of Potentially Unwanted Programs.
  • Now click on Malware Scan in the Scan button.
  • When the Emsisoft scan has finished, you will see a screen reporting details of any malicious files found on your computer.(Close the pop up inviting installation of Emsisoft protection)
  • Click Quarantine selected objects. (Note, this option is only shown if malicious objects were detected during the scan)
  • You may be asked to restart your computer.
  • When the threats have been quarantined, click the View Report button in the lower-right corner and the scan log will open in Notepad. The logs can also be accessed in the left hand menu bar.
  • Please save this log on your desktop and post the contents into your next reply.
  • When you close Emsisoft Emergency Kit it asks if you wish to sign up for a newsletter. This is optional, and does not affect the malware removal process.

 



#13 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,348 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 21 April 2024 - 10:13 AM

Did you manage to run a scan with Emsisoft?



#14 CaptainBlud

CaptainBlud
  • Topic Starter

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 22 April 2024 - 01:46 PM

The Emisoft download link you put there doesn't work. I waited for a few days thinking it'll get fixed, but apparently it hasn't gotten yet. Clicking "click here" doesn't help. Though, I found a solution. Copying the address of "click here" and then pasting it into a new tab's URL search bar helps. Now lemme do the scan rq.


Edited by CaptainBlud, 22 April 2024 - 02:05 PM.


#15 CaptainBlud

CaptainBlud
  • Topic Starter

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 22 April 2024 - 02:05 PM

Here ya go.
Emsisoft Emergency Kit 2024.4.0.12347 stable [en-us]

OS: Windows 10 (Version 10.0, Build 19045, 64-bit Edition)
 
Forensics log
 
Date Component Action Details
4/22/2024 10:03:13 PM Scanner Scan finished Scanned 78549 objects and found nothing.
4/22/2024 9:52:15 PM User DESKTOP-OADEFFT\david Scan started Malware Scan
4/22/2024 9:51:57 PM User Update Downloaded and installed 95 files (36179 kb) (23 sec.).
4/22/2024 9:51:32 PM User DESKTOP-OADEFFT\david Setting modified "Detect PUPs" has been changed to "Enabled".
Thank you for helping, I guess. Now I have even less idea about what the hell happened to my pc.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users