Jump to content

All Activity

This stream auto-updates     

  1. Past hour
  2. @amartilianom, the log files are located here: C:\Users\[user_name]\AppData\Local\Temp\Malwarebytes Excel Addin adregistrator.log is the log file generated during installation. adxloader.log is the log file generated when the Addin is being loaded in Excel You can send to me via private message, and we will look for errors. If think you have already done this, in Excel Menu --> File --> Options screen below, make sure that the Excel Addin is not in the Inactive or Disable lists. Lastly, I have message you with my contact info to help.
  3. Firefox

    Account settings - User Access

    Hello and Welcome! The only way to remove the forgotten password is to uninstall the software and then re-install it. Please do the following and it should correct the issue: Run the Malwarebytes Support Tool Accept the EULA and click Advanced Options on the main page (not Get Started) Click the Clean button, and allow it to restart your system and then reinstall Malwarebytes, either by allowing the tool to do so when it offers to on restart, or by downloading and installing the latest version from here Please let us know how it goes and if the issue persists or if any additional issues occur. Thanks
  4. Think I messed up and clicked the Start Repair. Looked like it uninstalled the program and then it was gone. I downloaded it again and installed it. It is running and running, says it is updating the software and doesn't seem to want to finish. I'm guessing whatever logs were there are gone, so I can't do the "grab" even if I do it after the install and update finished, right? Thanks.
  5. Valentin77

    KMS-r@1nhook removal

    Thank you so much!!! It seems the problem is gone ! Here is the fixlog.txt: Fix result of Farbar Recovery Scan Tool (x64) Version: 13.02.2019 Ran by Valentin (15-02-2019 20:12:24) Run:1 Running from E:\Programs\Farbar Loaded Profiles: Valentin (Available Profiles: Valentin) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: EmptyTemp: CloseProcesses: CHR NewTab: Default -> Active:"chrome-extension://ggonkegnkiclajiocblalpkfajkbkelp/newtab.html", Not-active:"chrome-extension://jpfpebmajhhopeonhlcgidhclcccjcik/newtab.html" CHR Extension: (Speed Dial) - C:\Users\valyo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggonkegnkiclajiocblalpkfajkbkelp [2017-09-12] CHR Extension: (Speed Dial 2 New tab) - C:\Users\valyo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik [2018-03-27] CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{123C44B9-728B-404C-9275-A9AAFF4A2A70}\localserver32 -> "E:\Programs\Orcad\tools\bin\Capture.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{15B7EDEC-C27A-4830-869D-7AABCC104E51}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{160497BE-0194-4784-84A6-96FBD633F876}\localserver32 -> "E:\Programs\Orcad\tools\bin\modeled.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{189387F1-D978-4524-BF3C-694E8E07EFFF}\InprocServer32 -> E:\Programs\Orcad\tools\bin\ortruereuse64.ocx => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{1DFD9959-3EE6-45E0-9D43-824EBD4CD389}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspice.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{21976533-5648-4E42-B84F-C169898F1ECB}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{27508707-B27E-42D2-BE29-1AF8AEA93A0E}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPIC64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{2B1066C6-1A94-4E0B-BABF-D85DD868B7D5}\localserver32 -> E:\Programs\Orcad\tools\bin\stmed.exe => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{31BDEAF6-95DE-4175-9119-92D525A3B600}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiica64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{33365B87-BA80-4476-AC3F-C126F30656C3}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{348E9523-9774-41DF-A24B-EF4C0A8BCB3F}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orApConCtl64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{358849F0-B260-49CC-8BCE-8FD7FE2A23F8}\localserver32 -> "E:\Programs\Orcad\tools\bin\simmgr.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{3899FD4D-D0C0-11D1-BBA2-0000C0708DD0}\localserver32 -> "E:\Programs\Orcad\tools\bin\modeled.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{3DAD4F8B-49BA-4D7C-B348-CBA6A03E22D9}\localserver32 -> "E:\Programs\Orcad\tools\bin\simmgr.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{53D45603-B24B-4F0B-8DD7-DA3C1125445F}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{5C192887-CF9F-4E9D-833D-4D5A6366CA4D}\localserver32 -> "E:\Programs\Orcad\tools\bin\modeled.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{5EBE72AF-6082-481F-9C6B-9E5F994D8C23}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspice.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{60FD2BEA-A369-42DC-985C-BDBE8617C0D8}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{6353D943-5A1D-4495-B23F-49097930CBE8}\localserver32 -> E:\Programs\Orcad\tools\bin\stmed.exe => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{66985293-D546-11D1-B884-0000C080A60E}\localserver32 -> "E:\Programs\Orcad\tools\bin\modeled.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{673C46C9-D4C6-414F-94B5-D2439DE33E36}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiica64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{684C263C-4A60-4FE0-9A89-D2FCDFA28D82}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspice.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{69F086C1-793F-4B2A-AE35-9668CA58929F}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspice.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{6B41BE7A-E146-480C-9D2B-519E1A0A6CE6}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpxllite64.ocx => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{79AE55D2-F2B3-41A6-94D8-E936999AAEC8}\localserver32 -> "E:\Programs\Orcad\tools\bin\SimSrvr.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{80EC1B8D-6958-41C3-8F57-03962BBF01FC}\localserver32 -> "E:\Programs\Orcad\tools\bin\modeled.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{83637867-7260-4F1E-B2F8-FB4D8E6F5546}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpxllite64.ocx => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{918E2AD0-E4CE-4C8F-A1D3-DE73B3592C48}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{9BCA2D46-3639-466C-828D-662B9C254E93}\localserver32 -> "E:\Programs\Orcad\tools\bin\PspiceExplorerSrvr.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{9D272CB5-46DE-4E10-99A3-C8A6BD3A0748}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orlayoutreuse64.ocx => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{A3822123-1F17-435C-BE1B-13CC7D64A1F4}\localserver32 -> "E:\Programs\Orcad\tools\bin\Capture.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{A50B40B5-3AD6-45E9-AE0F-8411180FF935}\localserver32 -> "E:\Programs\Orcad\tools\bin\mrksrvr.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{A5BC9D30-4956-44FC-8837-66692742AD07}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPIC64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{A8FC1C08-D635-4C63-AEAA-10C9BC2CE570}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orApConCtl64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{AFC0797D-1E57-4EA0-A0DD-A71297A4ACD8}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPIC64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{AFC4FCF3-0EEE-4448-AE23-0680A88A22AA}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspice.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{B246A908-770E-4B98-99EA-EC23648F2532}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{BBB19602-BF51-11D1-BB9B-0000C0708DD0}\localserver32 -> "E:\Programs\Orcad\tools\bin\modeled.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{BC52C06A-D1F8-4039-8C44-F78A70B5EA3C}\localserver32 -> "E:\Programs\Orcad\tools\bin\Capture.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{C04B6E75-FF75-4C5F-9560-89352E9BAA0B}\localserver32 -> "E:\Programs\Orcad\tools\bin\Capture.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{C262C294-C3F0-48FD-A178-BA3396528151}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpicis64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{C76160CB-15E7-4299-A018-5CE6E15A7D2A}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspice.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{CADC842C-7C64-40B4-9F9A-7C82A0FC1DB7}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{CBEF1209-5E8B-47A4-862A-E716EBCA78DA}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{CD2425E4-8141-11D0-8CE4-444553540000}\InprocServer32 -> E:\Programs\Orcad\tools\bin\Capture.exe => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{D23CAAEF-6DA2-4797-83D8-021970040DDE}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPspice64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{D70EB2BC-F3DC-4362-89A1-8C1C2BE75459}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspice.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{D7C7376A-B776-4266-8108-86A983B62A57}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspiceaa.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{DB2D5854-0B7A-468D-8E7F-1F328DD4D4A9}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpicis64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{DF76FC8B-0E2E-4B81-8417-E46B4B084927}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpxllite64.ocx => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> E:\Programs\Autocad\AutoCAD 2018\en-US\acadficn.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{E5D385DC-2563-45E3-BF55-CB94821EAA0B}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiica64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{E6C99519-1BEA-4F29-B199-F85A462DFF82}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpicis64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{EA0541F9-E147-4F3A-B637-D787673F1699}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpicis64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{EB0DEA2E-EF40-44CD-A2B0-2B66C03C3762}\localserver32 -> "E:\Programs\Orcad\tools\bin\Capture.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{EB78627A-B70D-41F3-B44E-C1415BF04121}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspiceaa.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{EC0D4058-AAED-4535-8BE6-564062563D5F}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpicis64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F152E572-47A0-46F9-BE18-E2E83FAE95A2}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspiceaa.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F2930AA9-1354-4497-A6F5-45C8D3FA73D6}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPIC64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F38847C9-55DC-4B52-AB3B-B919CE49C7DF}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orgenlibcom64.dll => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F614E8A5-E663-4F4D-8ACE-A909A5EA6AED}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orlayoutreuse64.ocx => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F8518828-EC72-4B05-A8C9-040CB8390727}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpxllite64.ocx => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F9CE1B02-BDC1-11D1-BB99-0000C0708DD0}\localserver32 -> "E:\Programs\Orcad\tools\bin\modeled.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F9FACC57-5B03-4063-AC9F-DEC6FAB02DDC}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspice.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{FD4187F1-FE95-435F-8174-3FC392E5BEC5}\localserver32 -> "E:\Programs\Orcad\tools\bin\pspice.exe" => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{FD829158-7ADE-44B4-91F9-28CF7FD51E4C}\InprocServer32 -> E:\Programs\Orcad\tools\bin\ortruereuse64.ocx => No File CustomCLSID: HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{FEB15EE1-0DD2-4B20-BB58-698FAB59913C}\InprocServer32 -> E:\Programs\Orcad\tools\bin\orpiPIC64.dll => No File ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File Task: {064743F1-68CD-421E-8738-A84C4D731730} - System32\Tasks\R@1n-KMS\Office16ProjectPro => wmic path SoftwareLicensingProduct where (ID="4f414197-0fc2-4c01-b68a-86cbb9ac254c") call Activate Task: {86C5222D-53A1-4825-9967-C9B2485D2065} - System32\Tasks\R@1n-KMS\Office16VisioPro => wmic path SoftwareLicensingProduct where (ID="6bf301c1-b94a-43e9-ba31-d494598c47fb") call Activate Task: {B0A57812-8967-4E1B-9504-7DD035E631D8} - System32\Tasks\R@1n-KMS\Office16ProPlus => wmic path SoftwareLicensingProduct where (ID="d450596f-894d-49e0-966a-fd39ed4c4c64") call Activate Task: {F6FD4CC3-37B8-4776-89CF-DE85C3F00CC9} - System32\Tasks\R@1n-KMS\Windows64Professional => wmic path SoftwareLicensingProduct where (ID="2de67392-b7a7-462a-b1ca-108dd189f588") call Activate AlternateDataStreams: C:\Users\Public\AppData:CSM [468] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [468] MSCONFIG\Services: KMS-R@1n => 2 C:\Windows\KMS-R@1nHook.exe C:\WINDOWS\System32\Tasks\R@1n-KMS Reboot: ***************** Restore point was successfully created. Processes closed successfully. "Chrome NewTab" => removed successfully CHR Extension: (Speed Dial) - C:\Users\valyo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggonkegnkiclajiocblalpkfajkbkelp [2017-09-12] => Error: No automatic fix found for this entry. CHR Extension: (Speed Dial 2 New tab) - C:\Users\valyo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik [2018-03-27] => Error: No automatic fix found for this entry. HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{123C44B9-728B-404C-9275-A9AAFF4A2A70} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{15B7EDEC-C27A-4830-869D-7AABCC104E51} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{160497BE-0194-4784-84A6-96FBD633F876} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{189387F1-D978-4524-BF3C-694E8E07EFFF} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{1DFD9959-3EE6-45E0-9D43-824EBD4CD389} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{21976533-5648-4E42-B84F-C169898F1ECB} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{27508707-B27E-42D2-BE29-1AF8AEA93A0E} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{2B1066C6-1A94-4E0B-BABF-D85DD868B7D5} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{31BDEAF6-95DE-4175-9119-92D525A3B600} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{33365B87-BA80-4476-AC3F-C126F30656C3} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{348E9523-9774-41DF-A24B-EF4C0A8BCB3F} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{358849F0-B260-49CC-8BCE-8FD7FE2A23F8} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{3899FD4D-D0C0-11D1-BBA2-0000C0708DD0} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{3DAD4F8B-49BA-4D7C-B348-CBA6A03E22D9} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{53D45603-B24B-4F0B-8DD7-DA3C1125445F} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{5C192887-CF9F-4E9D-833D-4D5A6366CA4D} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{5EBE72AF-6082-481F-9C6B-9E5F994D8C23} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{60FD2BEA-A369-42DC-985C-BDBE8617C0D8} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{6353D943-5A1D-4495-B23F-49097930CBE8} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{66985293-D546-11D1-B884-0000C080A60E} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{673C46C9-D4C6-414F-94B5-D2439DE33E36} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{684C263C-4A60-4FE0-9A89-D2FCDFA28D82} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{69F086C1-793F-4B2A-AE35-9668CA58929F} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{6B41BE7A-E146-480C-9D2B-519E1A0A6CE6} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{79AE55D2-F2B3-41A6-94D8-E936999AAEC8} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{80EC1B8D-6958-41C3-8F57-03962BBF01FC} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{83637867-7260-4F1E-B2F8-FB4D8E6F5546} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{918E2AD0-E4CE-4C8F-A1D3-DE73B3592C48} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{9BCA2D46-3639-466C-828D-662B9C254E93} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{9D272CB5-46DE-4E10-99A3-C8A6BD3A0748} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{A3822123-1F17-435C-BE1B-13CC7D64A1F4} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{A50B40B5-3AD6-45E9-AE0F-8411180FF935} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{A5BC9D30-4956-44FC-8837-66692742AD07} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{A8FC1C08-D635-4C63-AEAA-10C9BC2CE570} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{AFC0797D-1E57-4EA0-A0DD-A71297A4ACD8} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{AFC4FCF3-0EEE-4448-AE23-0680A88A22AA} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{B246A908-770E-4B98-99EA-EC23648F2532} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{BBB19602-BF51-11D1-BB9B-0000C0708DD0} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{BC52C06A-D1F8-4039-8C44-F78A70B5EA3C} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{C04B6E75-FF75-4C5F-9560-89352E9BAA0B} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{C262C294-C3F0-48FD-A178-BA3396528151} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{C76160CB-15E7-4299-A018-5CE6E15A7D2A} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{CADC842C-7C64-40B4-9F9A-7C82A0FC1DB7} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{CBEF1209-5E8B-47A4-862A-E716EBCA78DA} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{CD2425E4-8141-11D0-8CE4-444553540000} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{D23CAAEF-6DA2-4797-83D8-021970040DDE} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{D70EB2BC-F3DC-4362-89A1-8C1C2BE75459} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{D7C7376A-B776-4266-8108-86A983B62A57} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{DB2D5854-0B7A-468D-8E7F-1F328DD4D4A9} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{DF76FC8B-0E2E-4B81-8417-E46B4B084927} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{E5D385DC-2563-45E3-BF55-CB94821EAA0B} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{E6C99519-1BEA-4F29-B199-F85A462DFF82} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{EA0541F9-E147-4F3A-B637-D787673F1699} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{EB0DEA2E-EF40-44CD-A2B0-2B66C03C3762} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{EB78627A-B70D-41F3-B44E-C1415BF04121} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{EC0D4058-AAED-4535-8BE6-564062563D5F} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F152E572-47A0-46F9-BE18-E2E83FAE95A2} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F2930AA9-1354-4497-A6F5-45C8D3FA73D6} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F38847C9-55DC-4B52-AB3B-B919CE49C7DF} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F614E8A5-E663-4F4D-8ACE-A909A5EA6AED} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F8518828-EC72-4B05-A8C9-040CB8390727} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F9CE1B02-BDC1-11D1-BB99-0000C0708DD0} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{F9FACC57-5B03-4063-AC9F-DEC6FAB02DDC} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{FD4187F1-FE95-435F-8174-3FC392E5BEC5} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{FD829158-7ADE-44B4-91F9-28CF7FD51E4C} => removed successfully HKU\S-1-5-21-2645659846-2928543511-1746150927-1001_Classes\CLSID\{FEB15EE1-0DD2-4B20-BB58-698FAB59913C} => removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully HKLM\Software\Classes\CLSID\{B298D29A-A6ED-11DE-BA8C-A68E55D89593} => not found HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully "HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully HKLM\Software\Classes\CLSID\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => not found HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} => not found "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{064743F1-68CD-421E-8738-A84C4D731730}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{064743F1-68CD-421E-8738-A84C4D731730}" => removed successfully C:\WINDOWS\System32\Tasks\R@1n-KMS\Office16ProjectPro => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\R@1n-KMS\Office16ProjectPro" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{86C5222D-53A1-4825-9967-C9B2485D2065}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{86C5222D-53A1-4825-9967-C9B2485D2065}" => removed successfully C:\WINDOWS\System32\Tasks\R@1n-KMS\Office16VisioPro => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\R@1n-KMS\Office16VisioPro" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B0A57812-8967-4E1B-9504-7DD035E631D8}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B0A57812-8967-4E1B-9504-7DD035E631D8}" => removed successfully C:\WINDOWS\System32\Tasks\R@1n-KMS\Office16ProPlus => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\R@1n-KMS\Office16ProPlus" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F6FD4CC3-37B8-4776-89CF-DE85C3F00CC9}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6FD4CC3-37B8-4776-89CF-DE85C3F00CC9}" => removed successfully C:\WINDOWS\System32\Tasks\R@1n-KMS\Windows64Professional => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\R@1n-KMS\Windows64Professional" => removed successfully C:\Users\Public\AppData => ":CSM" ADS removed successfully C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\KMS-R@1n => removed successfully HKLM\System\CurrentControlSet\Services\KMS-R@1n => not found C:\Windows\KMS-R@1nHook.exe => moved successfully C:\WINDOWS\System32\Tasks\R@1n-KMS => moved successfully =========== EmptyTemp: ========== BITS transfer queue => 10772480 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 27583716 B Java, Flash, Steam htmlcache => 408548384 B Windows/system/drivers => 10678927 B Edge => 1148069 B Chrome => 422769716 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 4590 B LocalService => 0 B NetworkService => 982 B NetworkService => 0 B valyo => 39009168 B RecycleBin => 0 B EmptyTemp: => 877.9 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 20:14:01 ==== Fixlog.txt
  6. Hello @nickajack910 and To commence an accurate analysis, please go to the Malwarebytes Bot automated reply post above and open the upper "Reveal hidden contents" section just beneath technical issues. Please study and then perform all the steps. Note: Do not select the Start Repair button. Then, attach the resulting archive/zip file mbst-grab-results.zip to your next topic reply. Thank you.
  7. djacobson

    Need to rename endpoints

    Do you guys use AD or workgroups? We just mirror the names to which your computers are already set, to change them they must be changed in the computer's properties pane or AD entry. Assuming you do not have a set naming convention in place, if you change the names in your AD to have a reliable convention, or set computer names for workgroup machines, those names will be reflected in MB's client view. Here is an article by Microsoft about the characters allowed and some best practices - https://support.microsoft.com/en-us/help/909264/naming-conventions-in-active-directory-for-computers-domains-sites-and A popular format goes like this: Location-Department-Computer type (D desktop, L laptop, T tablet). User (if assigned)-tag or serial. For example, HQ-HR-D-UserName-ABC123.
  8. Considering downloading the Blue Stacks Apps Player from www.bluestacks.com to use for security camera viewer (HIK vision's iVMS 4500). Virus Total listed the site as safe 0/66, the community has a +34 score - 84 thumbs up and 33 thumbs down. Appreciate any help I can get.
  9. Fred_L

    Xdebug blocked on first try

    Hi, the problem only occurs when "Web protection" is enabled.
  10. Today
  11. Interesting, thanks for the info! That's not what I would have expected.
  12. Gary230

    Gukacado

    threat scan.txt
  13. I recently set up a password under Account Settings/Application Tab/User Access/Set Password. When I went back in to check on some exclusions, I was unable to open the quarantine link as my password was not recognized. How do I reset the password or turn off the protection for user access? I think some web addresses were blocked and now I cannot access internet on my desktop pc. Thanks
  14. MAXBAR1

    Malwarebytes for Mac 3.7 beta

    Thanks, @treed I did the test and I can say that everything works correctly. I created a new user who became an administrator and I made the old user standard so I do not have to move data. In the new user, total access to the disk has been automatically reported.
  15. Thanks for that info. I guess it's a bit of a relief. I'll reconfig my Airport when I get a chance and see what happens. thanks again
  16. Only Malwarebytes sir. I run a Fortigate 30E and could never see any traffic getting blocked from that PC. It made perfect sense once you had me uninstall the internet lock app.
  17. Smalltalker

    settings and scan report don't match

    Aha. Cool I did not realize that the setting for rootkits doesn't apply to scheduled scans. I will try that and report again if I encounter an issue. Thanks for the quick response.
  18. Porthos

    settings and scan report don't match

    You need to set up rootkit scanning in each scheduled scan.
  19. Hello, Welcome to Malwarebytes. I'm nasdaq and will be helping you. If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed. === Remove these programs in bold via the Control Panel > Programs > Programs and Features. Pokki (HKU\S-1-5-21-1220125042-4281096239-2101652433-1000\...\SweetLabs_AP) (Version: 0.269.7.802 - Pokki) Pokki Download Helper (HKU\S-1-5-21-1220125042-4281096239-2101652433-1000\...\PokkiDownloadHelper) (Version: 1.3.1.282 - Pokki) === Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from. The location is listed in the 3rd line of the FRST.txt log you have submitted. Run FRST and click Fix only once and wait. The tool will create a log (Fixlog.txt) please post it to your reply. === Reset Chrome... Open Google Chrome, click on menu icon or the 3 vertical dots located right side top of the google chrome. Click "Settings" then "Show advanced settings" at the bottom of the screen. Click "Reset and clean up" > "Restore settings to their original defaults" Restart Chrome. <<<>>> Please post the Fixlog.txt and let me know what problem persists. fixlist.txt
  20. David H. Lipman

    Can MP3 files contain a virus?

    You are late. This thread is almost 2.5 yrs old. If you have questions, please start a new thread and fully describe the problem or situation.
  21. Many Thanks, LT: I set the delay to the default per your suggestion. Tme will tell if it works. If the issue reappears I'll update this thread, try a longer delay, see what happens, etc.
  22. Hello, I'm trying to have the add-in incorporated in Excel but I don't get the menu to be shown despite the tool is correctly installed. I've tried installing it as a administrator and the result is the same, I've also checked if the ribbon is deactivated from the Excel options but it doesn't even appear there. Any idea what may be happening? My Office version is the one attached. Thanks in advance
  23. Can't get rid of gukacado I ran malwarebytes and adwcleaner Fabar Recovery gave me the follow Addition.txt FRST.txt
  24. CHMOD_777

    Need to rename endpoints

    Hello OB1knobie, Exile360 is correct in that it is currently not possible to rename individual endpoints. I have submitted a feature request on your behalf regarding this. In the effort of making your deployment easier to manage, you can create various groups with separate polices and sort your endpoints into these groups. If you do have any additional questions or concerns, please feel free to reach out and open a support ticket with us at https://support.malwarebytes.com/community/contactsupport/pages/business-support Warm Regards,
  25. nithin604

    Can MP3 files contain a virus?

    Hi, I'm not late,I hope. There is an infection called Brisv, or Trojan Brisv where the infection modifies the meta data of the mp3 file.
  26. Malwarebytes

    settings and scan report don't match

    ***This is an automated reply*** Hi, Thanks for posting in the Malwarebytes 3 Help forum. If you are having technical issues with our Windows product, please do the following: If you are having licensing issues, please do the following: Thanks in advance for your patience. -The Malwarebytes Forum Team
  27. I have the latest version of Malwarebytes. It has been telling me everything is great for a long time. Scans run daily and report nothing. I started having some display issues which I thought was a driver. But it got me to run ESET online scanner which found a bunch of infections. Malwarebytes scan still says everything is ok in the scan. Scan options are set to scan for everything including rootkits. But when I look at the detailed scan report, it says that Filesystem and Rootkits options are disabled. When you look at the settings, all options are enabled. How worried should I be about my confidence in Malwarebytes? Scan report is attached. Also, I just realized that a custom scan was running on the schedule. Could something have modified the scan settings on that? Just deleted it and set up a scheduled threat scan again. I haven't seen any display issues since I ran ESET. Ran the scan again after deleting custom scan and report still shows rootkit scan is disabled even though the setting shows it is enabled. What do I do now? malwareBytesScanReport02142019.txt malwareBytesScanReport02152019.txt malwareBytesScanReport02152019-stdscan.txt
  1. Load more activity
×

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.