Jump to content

Jc191

Members
  • Posts

    9
  • Joined

  • Last visited

Reputation

0 Neutral
  1. hi seems okay, did you find anything bad?
  2. Fix result of Farbar Recovery Scan Tool (x64) Version: 24.10.2018 Ran by chris (07-11-2018 12:54:23) Run:2 Running from C:\Users\chris\OneDrive\Desktop Loaded Profiles: chris (Available Profiles: chris) Boot Mode: Normal ============================================== fixlist content: ***************** Start CreateRestorePoint: CloseProcesses: Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0 Tcpip\..\Interfaces\{bbe1f4b9-bbf5-4386-a3e8-5109600fd0b2}: [DhcpNameServer] 192.168.1.1 0.0.0.0 U4 npcap_wifi; no ImagePath ContextMenuHandlers1: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => C:\Windows\SysWOW64\WSCM64.dll -> No File Task: {BB20CDC3-D9AB-4A3F-B717-204F9525467D} - \DRScanner Startup -> No File <==== ATTENTION CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R RemoveProxy: EmptyTemp: Hosts: CMD: ipconfig /flushDNS end ***************** Restore point was successfully created. Processes closed successfully. "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer" => removed successfully "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{bbe1f4b9-bbf5-4386-a3e8-5109600fd0b2}\\DhcpNameServer" => removed successfully npcap_wifi => service not found. HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WondershareVideoConverterFileOpreation => not found HKLM\Software\Classes\CLSID\{FEB746CA-95C2-485F-B386-C30D4E56D22E} => not found "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB20CDC3-D9AB-4A3F-B717-204F9525467D}" => not found "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DRScanner Startup" => not found ========= "%WINDIR%\SYSTEM32\lodctr.exe" /R ========= Info: Successfully rebuilt performance counter setting from system backup store ========= End of CMD: ========= ========= "%WINDIR%\SysWOW64\lodctr.exe" /R ========= Info: Successfully rebuilt performance counter setting from system backup store ========= End of CMD: ========= ========= RemoveProxy: ========= "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-3746604060-3463744706-3131182942-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-3746604060-3463744706-3131182942-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully ========= End of RemoveProxy: ========= C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. ========= ipconfig /flushDNS ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 9199616 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9452112 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => -292784 B Edge => 3584 B Chrome => 42156244 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B LocalService => 0 B NetworkService => 0 B NetworkService => 0 B chris => 41359 B RecycleBin => 0 B EmptyTemp: => 57.8 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 12:56:02 ====
  3. when i tried to run it i got this
  4. Zemana AntiMalware 2.74.2.150 (Installed) ------------------------------------------------------- Scan Result : Completed Scan Date : 2018/11/5 Operating System : Windows 10 64-bit Processor : 4X Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz BIOS Mode : Legacy CUID : 12DABAD059EE256DDDD406 Scan Type : System Scan Duration : 3m 20s Scanned Objects : 40681 Detected Objects : 0 Excluded Objects : 0 Read Level : SCSI Auto Upload : Enabled Detect All Extensions : Disabled Scan Documents : Disabled Domain Info : WORKGROUP,0,2 Detected Objects ------------------------------------------------------- No threats detected
  5. Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24.10.2018 Ran by chris (31-10-2018 19:12:26) Running from C:\Users\chris\Downloads Windows 10 Pro Version 1803 17134.345 (X64) (2018-05-15 06:52:09) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3746604060-3463744706-3131182942-500 - Administrator - Disabled) chris (S-1-5-21-3746604060-3463744706-3131182942-1001 - Administrator - Enabled) => C:\Users\chris DefaultAccount (S-1-5-21-3746604060-3463744706-3131182942-503 - Limited - Disabled) Guest (S-1-5-21-3746604060-3463744706-3131182942-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-3746604060-3463744706-3131182942-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Bitdefender Antivirus (Enabled - Up to date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Bitdefender Antispyware (Enabled - Up to date) {B5763A99-8435-6D40-83EB-2CA97758A9A5} FW: Bitdefender Firewall (Enabled) {362C5A58-E860-6396-9204-BEEEF20CA463} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 23.0.8.115 - Bitdefender) Bitdefender Device Management (HKLM\...\Bitdefender Device Management) (Version: 23.0.10.34 - Bitdefender) Bitdefender Total Security (HKLM\...\Bitdefender) (Version: 23.0.10.34 - Bitdefender) Bitdefender VPN (HKLM\...\Bitdefender VPN) (Version: 23.0.8.605 - Bitdefender) CCleaner (HKLM\...\CCleaner) (Version: 5.47 - Piriform) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 70.0.3538.77 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden Malwarebytes version 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes) Microsoft OneDrive (HKU\S-1-5-21-3746604060-3463744706-3131182942-1001\...\OneDriveSetup.exe) (Version: 18.172.0826.0010 - Microsoft Corporation) PokerStars.uk (HKLM-x32\...\PokerStars.uk) (Version: - PokerStars.uk) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.3 - VideoLAN) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers1: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => C:\Windows\SysWOW64\WSCM64.dll -> No File ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {1B4FDA26-CA3C-4979-BFF4-F3640CC07777} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [2018-10-21] (Bitdefender) Task: {28944444-2936-4BBA-A3F5-CBEC705081A1} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-07-31] (Bitdefender) Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] () Task: {7BA093CE-D5A2-48E6-9FC9-6078F18E93E8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-12-18] (Google Inc.) Task: {8E502639-FCD6-416F-9AB2-230E67B018AA} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-09-19] (Piriform Ltd) Task: {BB20CDC3-D9AB-4A3F-B717-204F9525467D} - \DRScanner Startup -> No File <==== ATTENTION Task: {E5592126-B3B4-4A22-AECB-22B48C6258FB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-09-19] (Piriform Ltd) Task: {FD647621-DCFC-457A-8ED8-0F47CFC8C49E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-12-18] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Take on the 2017 Champion.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=dcoeconcacbhobljolikkacpalpocmll ==================== Loaded Modules (Whitelisted) ============== 2018-10-05 22:40 - 2018-10-05 22:40 - 000994752 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_002\ashttpbr.mdl 2018-10-05 22:40 - 2018-10-05 22:40 - 000544880 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_002\ashttpdsp.mdl 2018-10-05 22:40 - 2018-10-05 22:40 - 003240080 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_002\ashttpph.mdl 2018-10-05 22:40 - 2018-10-05 22:40 - 001530368 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_002\ashttprbl.mdl 2018-10-06 10:49 - 2018-10-27 04:49 - 002695360 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2018-04-11 23:34 - 2018-04-11 23:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll 2018-04-11 23:34 - 2018-04-11 23:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll 2018-04-11 23:34 - 2018-04-11 23:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll 2018-10-13 12:21 - 2018-09-20 03:38 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-07-03 17:44 - 2018-07-04 17:28 - 001922224 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.1000_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll 2018-10-04 20:15 - 2018-10-04 20:18 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\ImagePipelineNative.dll 2018-10-23 17:47 - 2018-10-23 17:50 - 000060416 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\ChakraBridge.dll 2018-10-23 17:47 - 2018-10-23 17:50 - 000019456 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeProxiesAndStubs.dll 2018-10-23 17:47 - 2018-10-23 17:50 - 010978304 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\LibWrapper.dll 2018-10-23 17:47 - 2018-10-23 17:50 - 002810368 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\skypert.dll 2018-10-23 17:47 - 2018-10-23 17:50 - 000685056 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2018-10-19 15:30 - 2018-10-16 00:01 - 005020504 _____ () C:\Program Files (x86)\Google\Chrome\Application\70.0.3538.67\libglesv2.dll 2018-10-19 15:30 - 2018-10-16 00:01 - 000116056 _____ () C:\Program Files (x86)\Google\Chrome\Application\70.0.3538.67\libegl.dll 2018-10-23 17:47 - 2018-10-23 17:50 - 000183808 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe 2018-09-27 00:15 - 2018-09-27 00:18 - 000479232 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2018-09-27 00:15 - 2018-09-27 00:18 - 069128192 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2018-09-27 00:15 - 2018-09-27 00:18 - 000010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll 2017-12-18 17:48 - 2017-12-18 17:59 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll 2018-05-10 16:09 - 2018-05-10 16:11 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\ImagePipelineNative.dll 2018-08-31 22:11 - 2018-08-31 22:15 - 003699200 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll 2018-08-31 22:11 - 2018-08-31 22:15 - 000035328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll 2018-08-20 22:48 - 2018-08-20 22:51 - 002480640 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\opencv_imgproc320.dll 2018-08-20 22:48 - 2018-08-20 22:51 - 002280960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\opencv_core320.dll 2018-03-30 08:45 - 2018-03-30 08:48 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll 2018-09-27 00:15 - 2018-09-27 00:18 - 014171648 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll 2018-08-31 22:11 - 2018-08-31 22:15 - 003544576 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\MediaEngine.dll 2018-09-27 00:15 - 2018-09-27 00:18 - 002866176 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll 2018-08-31 22:11 - 2018-08-31 22:15 - 000973312 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll 2018-07-27 03:08 - 2018-07-27 03:10 - 004584960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-09-27 00:15 - 2018-09-27 00:18 - 000145920 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\SKU.dll 2018-10-06 22:50 - 2018-10-06 22:50 - 000194048 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11809.1001.8.0_x64__8wekyb3d8bbwe\WinStore.Preview.dll 2018-08-01 10:02 - 2018-08-01 10:03 - 002447072 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11809.1001.8.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-10-06 22:50 - 2018-10-06 22:50 - 001689088 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11809.1001.8.0_x64__8wekyb3d8bbwe\Microsoft.Membership.MeControl.dll 2018-07-21 19:25 - 2018-06-15 17:30 - 001308672 _____ () c:\windows\system32\FaceProcessor.dll 2018-07-21 19:24 - 2018-06-15 17:55 - 000542888 _____ () c:\windows\system32\FaceProcessorCore.dll 2018-04-11 23:34 - 2018-04-11 23:34 - 001348664 _____ () c:\windows\system32\FaceTrackerInternal.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2017-09-29 13:46 - 2018-10-31 18:34 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3746604060-3463744706-3131182942-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img13.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{BF179218-7BE3-4BC6-B190-765A42B70053}] => (Allow) C:\Program Files\Bitdefender Home Scanner\hvasrv.exe FirewallRules: [{6485F539-AEF7-444A-B259-A764ED8D1542}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{9543C16B-3FC2-4126-85E5-4686F3F7B15A}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{8D9C484A-277C-42DD-92B2-01773BFE38FD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.92.390.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{28D41E00-4204-4F03-88FA-AD752073C3FE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.92.390.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{E8DBEE86-46CD-4A06-A9E2-5B467995A65B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.92.390.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{8113CCF8-526E-45CF-9073-325B410C84D0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.92.390.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{42EC5DB8-6964-4366-A76B-F04A385478C2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.92.390.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{8DF122DA-ADAF-402A-BDC5-E5D44CF7BBFE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.92.390.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{93E2D78D-CC2F-4199-9972-EE35DB7C809D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.92.390.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{1D4273E3-59C0-4897-B3A6-12A4316AD5AA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.92.390.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{FBDE21AB-4A78-4EE9-845D-1282F9705BD4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 13-10-2018 12:20:20 Windows Update 21-10-2018 02:23:40 Scheduled Checkpoint 30-10-2018 18:43:31 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: PCI Serial Port Description: PCI Serial Port Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (10/22/2018 06:06:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.17134.1, time stamp: 0xcb43d9c5 Faulting module name: combase.dll, version: 10.0.17134.112, time stamp: 0xfad18dc5 Exception code: 0xc0000005 Fault offset: 0x000000000003afdf Faulting process ID: 0x2bdc Faulting application start time: 0x01d46a31f71e8fed Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe Faulting module path: C:\WINDOWS\System32\combase.dll Report ID: d0a68418-d7cd-4c61-98e1-70c37c21b0e1 Faulting package full name: Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: App System errors: ============= Error: (10/30/2018 06:32:17 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the CDPSvc service. Error: (10/24/2018 12:45:56 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID Windows.SecurityCenter.WscBrokerManager and APPID Unavailable to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (10/24/2018 12:45:32 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-NRT0SVH) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user DESKTOP-NRT0SVH\chris SID (S-1-5-21-3746604060-3463744706-3131182942-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (10/24/2018 12:44:00 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 23:04:22 on ‎23/‎10/‎2018 was unexpected. Error: (10/22/2018 02:06:21 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID Windows.SecurityCenter.WscBrokerManager and APPID Unavailable to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (10/22/2018 02:05:49 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-NRT0SVH) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user DESKTOP-NRT0SVH\chris SID (S-1-5-21-3746604060-3463744706-3131182942-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (10/22/2018 02:03:14 PM) (Source: DCOM) (EventID: 10001) (User: DESKTOP-NRT0SVH) Description: Unable to start a DCOM Server: microsoft.windowscommunicationsapps_16005.10827.20186.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca as Unavailable/Unavailable. The error: "0" Happened while starting this command: "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.10827.20186.0_x64__8wekyb3d8bbwe\HxTsr.exe" -ServerName:Hx.IPC.Server Error: (10/22/2018 02:03:14 PM) (Source: DCOM) (EventID: 10001) (User: DESKTOP-NRT0SVH) Description: Unable to start a DCOM Server: microsoft.windowscommunicationsapps_16005.10827.20186.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca as Unavailable/Unavailable. The error: "298" Happened while starting this command: "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.10827.20186.0_x64__8wekyb3d8bbwe\HxTsr.exe" -ServerName:Hx.IPC.Server CodeIntegrity: =================================== Date: 2018-10-24 13:46:33.756 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-10-22 15:06:46.476 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-10-22 15:04:28.762 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender Security\vsservp.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-10-16 18:39:52.318 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-10-16 18:39:52.308 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-10-16 15:51:48.945 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-10-16 15:51:48.940 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-10-14 13:07:45.613 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz Percentage of memory in use: 50% Total physical RAM: 8027.61 MB Available physical RAM: 3970.02 MB Total Virtual: 9307.61 MB Available Virtual: 4513.66 MB ==================== Drives ================================ Drive ? () (Fixed) (Total:929.73 GB) (Free:894.73 GB) NTFS \\?\Volume{95574d95-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.49 GB) (Free:0.18 GB) NTFS \\?\Volume{95574d95-0000-0000-0000-e08de8000000}\ () (Fixed) (Total:0.46 GB) (Free:0.08 GB) NTFS \\?\Volume{95574d95-0000-0000-0000-40abe8000000}\ () (Fixed) (Total:0.84 GB) (Free:0.34 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 95574D95) Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=929.7 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=469 MB) - (Type=27) Partition 4: (Not Active) - (Size=857 MB) - (Type=27) ==================== End of Addition.txt ============================
  6. HI Malware premium didnt pick this up but adware cleaner did, I click delete and restarts and it keeps coming back # ------------------------------- # Malwarebytes AdwCleaner 7.2.4.0 # ------------------------------- # Build: 09-25-2018 # Database: 2018-10-23.1 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Scan # ------------------------------- # Start: 10-30-2018 # Duration: 00:00:13 # OS: Windows 10 Pro # Scanned: 32011 # Detected: 1 ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** No malicious registry entries found. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries found. ***** [ Chromium URLs ] ***** PUP.Optional.Legacy Ask Jeeves ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries found. ***** [ Firefox URLs ] ***** No malicious Firefox URLs found. AdwCleaner[S00].txt - [1250 octets] - [10/05/2018 23:26:15] AdwCleaner[C00].txt - [1355 octets] - [10/05/2018 23:28:00] AdwCleaner[S01].txt - [1250 octets] - [22/05/2018 17:22:48] AdwCleaner[C01].txt - [1355 octets] - [22/05/2018 17:23:20] AdwCleaner[S02].txt - [1250 octets] - [22/05/2018 17:31:16] AdwCleaner[S03].txt - [1250 octets] - [24/05/2018 07:30:37] AdwCleaner[S04].txt - [1250 octets] - [29/05/2018 21:44:08] AdwCleaner[S05].txt - [1250 octets] - [30/05/2018 16:57:17] AdwCleaner[S06].txt - [1241 octets] - [30/05/2018 23:11:37] AdwCleaner[S07].txt - [1790 octets] - [16/06/2018 14:31:34] AdwCleaner[S08].txt - [1860 octets] - [28/06/2018 01:26:01] AdwCleaner[S09].txt - [1921 octets] - [01/08/2018 13:23:19] AdwCleaner[C09].txt - [2087 octets] - [01/08/2018 13:24:36] AdwCleaner[S10].txt - [2039 octets] - [23/09/2018 15:12:59] AdwCleaner[C10].txt - [2205 octets] - [23/09/2018 15:13:10] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S11].txt ##########
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.