baconjr612
-
Posts
14 -
Joined
-
Last visited
Content Type
Events
Profiles
Forums
Posts posted by baconjr612
-
-
On 2/17/2024 at 10:46 PM, AdvancedSetup said:
Thank you. The log ran well. It also found and corrected some other Windows issues
Windows Resource Protection found corrupt files and successfully repaired them.
The following folder does not look to be valid and I'd recommend removing it and it's contents.
C:\ProgramData\photowiz
There was a bogus fake file stored there running on the system
I would also recommend you consider changing your Web Browser. The Opera browser used to be a good alternative browser but today it does not care about your privacy. I'd suggest either Firefox or Brave
Please run the following scanner. Note the canned message may not be 100% accurate but should be close enough for you to figure out and complete the scan and post back the log.
Sophos Scan & Clean
Download Sophos Free Virus Removal Tool and save it to your desktop.
- If your security alerts to this scan either accept the alert or turn off your security to allow Sophos to run and complete.....
- Please close all other open applications and Do Not use your PC whilst the scan is in progress... This scan is very thorough so it may take several hours to complete, please be patient...
Double click the icon and select Run
Click Next
Select I accept the terms in this license agreement, then click Next twice
Click Install
Click Finish to launch the program
- Once the virus database has been updated click Start Scanning
If any threats are found click Details, then View log file... (bottom left hand corner)
Attach the results in your next reply
- Close the Notepad document, close the Threat Details screen, then click Start cleanup
Click Exit to close the program
If no threats were found please confirm that result...
- The Virus Removal Tool scans the following areas of your computer:
- Memory, including system memory on 32-bit (x86) versions of Windows
- The Windows registry
- All local hard drives, fixed and removable
- Mapped network drives are not scanned.
Note: If threats are found in the computer memory, the scan stops. This is because further scanning could enable the threat to spread. You will be asked to click Start Cleanup to remove the threats before continuing the scan.
Saved logs are found under this sub-folder: C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs
Please attach that log on your next reply
Thank you
looks like nothing was found and alright thanks for the tips SophosScanAndClean_20240219_0843.log
-
36 minutes ago, AdvancedSetup said:
Please run the following fix
NOTE: Please read all of the information below before running this fix.
- NOTICE: This script was written specifically for this user, for use on this particular machine.
- Running this on another machine may cause damage to your operating system that cannot be undone.
Once the fix has been completed, please attach the file FIXLOG.TXT to your next reply
Farbar program: FRSTEnglish.exe
Save the attached file: FIXLIST.TXT to this folder C:\Users\bacon\Downloads\
NOTE. It's important that both files, FRSTEnglish.exe, and fixlist.txt are in the same location or the fix will not work.
Please make sure you disable any real-time antivirus or security software before running this script. Once completed, make sure you re-enable it.
Run the Farbar program with Admin rights and press the Fix button just once and wait.
The fix may possibly take up to 60 minutes to complete
If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart.
The tool will make a log named Fixlog.txt in the same folder you ran the Farbar program from. Please attach that log on your next reply.- NOTE: This fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files. It will also run a disk check on the restart to ensure disk integrity.
-
NOTE: As part of this fix all temporary files will be removed. If you have any open web pages that have not been bookmarked please make sure you bookmark them now as all open applications may be automatically closed.
Also, make sure you know the passwords for all websites as cookies may possibly be removed in some cases, but not all cases. - NOTE: As part of this fix, it will also reset the network to default settings including the firewall. If you have custom firewall rules you need to save please export or save them first before running this fix.
The following directories are emptied:
- Windows Temp
- Users Temp folders
- Edge, IE, FF, Chrome, and Opera caches, HTML5 storages, Cookies and History
- Recently opened files cache
- Discord cache
- Java cache
- Steam HTML cache
- Explorer thumbnail and icon cache
- BITS transfer queue (qmgr*.dat files)
- Recycle Bin
Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns please ask before running this fix.
The system will be rebooted after the fix has run.
fixlist.txt 55.63 kB · 1 download
Thanks
Fixlog.txt here you go
-
On 2/16/2024 at 11:33 AM, AdvancedSetup said:
I need the FIXLOG.TXT file please.
Then run Farbar scanner again with Admin rights and get me 2 new fresh logs from a new scan.
FRST.TXT
ADDITION.TXT
Thanks @baconjr612I think that is where the confusion is coming. I do not have a fixlog.txt file..
-
8 hours ago, AdvancedSetup said:
The Farbar (FRST) program is located here in your downloads folder: C:\Users\bacon\Downloads\FRSTEnglish.exe
Please follow the process below to perform a fix in Safe Mode
Start in Safe mode:
- Press the Windows icon on the keyboard together with the letter I, to get into the Settings.
- Choose Update and Security.
- From the menu at the left, choose Recovery.
- Under the title Advanced startup at the right, choose Restart now.
- From the window that will appear choose Troubleshoot and then Advanced options.
- Choose Startup Settings and then Restart.
- Press number 5, for choosing Safe mode with networking.
- You will know that you are in Safe mode, if the background is black and Safe mode is written at the four corners of the screen.
After that:
Please do the following to run a FRST fix.
NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system- Select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start:: HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction GroupPolicy: Restriction End::- Right-click on FRSTEnglish in your Downloads folder, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
- Press the Fix button once and wait.
- FRST will process fixlist.txt
- When finished, it will produce a log fixlog.txt in your Downloads folder or where you have the Farbar program located.
- Attach that log in your next reply.
Thank youSo when I restarted in safe mode with option 5 , network connectivity was still disabled
-
1 hour ago, AdvancedSetup said:
Windows Autoupdate Disabled Policy:
============================
ATTENTION!=====> policy restriction on WindowsUpdate: HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdateHKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
Please remove the restriction from the Registry and restart the computer.
Then check for Windows Updates
How do i do that? this is the only thing that I see under that folder
-
8 minutes ago, AdvancedSetup said:
Thank you for the logs, but you need to run them with Admin rights.
Ran by Oscar (Welltree) (ATTENTION: The user is not administrator
Please run them again but this time use an account that has Administrator rights
-
7 minutes ago, AdvancedSetup said:
Thank you for the mbst-grab-results.zip file but I'd like to have you run the following exactly as shown and post those logs back, please.
Scan with FSS Farbar Service Scanner
Scan with Farbar Recovery Scan Tool
Thank you
here you go
-
7 hours ago, AdvancedSetup said:
I will try again to attach.. mbst-grab-results.zip
-
22 hours ago, AdvancedSetup said:
Please get us some logs from the mbst-grab-results.ziplaptop. You can use a USB thumb drive to save and copy the logs to post back from another computer if needed.
Scan with FSS Farbar Service Scanner
https://forums.malwarebytes.com/topic/306736-scan-with-fss-farbar-service-scanner/Scan with Farbar Recovery Scan Tool
https://forums.malwarebytes.com/topic/306601-scan-with-farbar-recovery-scan-tool/Here you go , got everything to work.
-
2 minutes ago, AdvancedSetup said:
I am still not able to access from the laptop
-
8 hours ago, AdvancedSetup said:
Thank you for the follow up @baconjr612
I have removed the block from our Clean Talk spam protection. You should be able to post your logs now.
Cheers
Aweosome though i still seem to have an issue accessing the website on my laptop. it’s still giving me that firewall alert . Is there an
-
19 hours ago, AdvancedSetup said:
Hello so , it seems like for whatever reason yesterday i was trying to reply with that log and it kept giving me a ‘this message may create spam’ now it seems like im giving a SpamFireWall is activated . so it blacklisted me??
the only reason i am able to reply here is i disconnected from my home wifi on my phone
-
Having continuous pop-up on Malwarebytes- Scan shows nothing.
in Resolved Malware Removal Logs
Posted
here you go SecurityCheck.txt