Jump to content

baconjr612

Members
  • Posts

    14
  • Joined

  • Last visited

Posts posted by baconjr612

  1. On 2/17/2024 at 10:46 PM, AdvancedSetup said:

    Thank you. The log ran well. It also found and corrected some other Windows issues

    Windows Resource Protection found corrupt files and successfully repaired them.

     

    The following folder does not look to be valid and I'd recommend removing it and it's contents.

    C:\ProgramData\photowiz

    There was a bogus fake file stored there running on the system

     

    I would also recommend you consider changing your Web Browser. The Opera browser used to be a good alternative browser but today it does not care about your privacy. I'd suggest either Firefox or Brave

     

    Please run the following scanner. Note the canned message may not be 100% accurate but should be close enough for you to figure out and complete the scan and post back the log.

     

    Sophos Scan & Clean

    Download Sophos Free Virus Removal Tool and save it to your desktop.

    • If your security alerts to this scan either accept the alert or turn off your security to allow Sophos to run and complete.....
    • Please close all other open applications and Do Not use your PC whilst the scan is in progress... This scan is very thorough so it may take several hours to complete, please be patient...

    Double click the icon and select Run

    Click Next

    Select I accept the terms in this license agreement, then click Next twice

    Click Install

    Click Finish to launch the program

    • Once the virus database has been updated click Start Scanning

    If any threats are found click Details, then View log file... (bottom left hand corner)

     

    Attach the results in your next reply

    • Close the Notepad document, close the Threat Details screen, then click Start cleanup

    Click Exit to close the program

     

    If no threats were found please confirm that result...

    • The Virus Removal Tool scans the following areas of your computer:
    • Memory, including system memory on 32-bit (x86) versions of Windows
    • The Windows registry
    • All local hard drives, fixed and removable
    • Mapped network drives are not scanned.

    Note: If threats are found in the computer memory, the scan stops. This is because further scanning could enable the threat to spread. You will be asked to click Start Cleanup to remove the threats before continuing the scan.

     

    Saved logs are found under this sub-folder: C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs 

    Please attach that log on your next reply

    Thank you

     

    looks like nothing was found and alright thanks for the tips SophosScanAndClean_20240219_0843.log

  2. 36 minutes ago, AdvancedSetup said:

    Please run the following fix

     

    NOTE: Please read all of the information below before running this fix.

    • NOTICE: This script was written specifically for this user, for use on this particular machine.
    • Running this on another machine may cause damage to your operating system that cannot be undone.

    Once the fix has been completed, please attach the file FIXLOG.TXT to your next reply

    Farbar program:   FRSTEnglish.exe

    Save the attached file:  FIXLIST.TXT to this folder C:\Users\bacon\Downloads\

    NOTE. It's important that both files, FRSTEnglish.exe, and fixlist.txt are in the same location or the fix will not work.

    Please make sure you disable any real-time antivirus or security software before running this script. Once completed, make sure you re-enable it.

     

     

    Run the Farbar program with Admin rights and press the Fix button just once and wait.

    The fix may possibly take up to 60 minutes to complete

    If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart.
    The tool will make a log named Fixlog.txt in the same folder you ran the Farbar program from. Please attach that log on your next reply.

     

    1. NOTE:  This fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files. It will also run a disk check on the restart to ensure disk integrity.
    2. NOTE: As part of this fix all temporary files will be removed. If you have any open web pages that have not been bookmarked please make sure you bookmark them now as all open applications may be automatically closed.
                  Also, make sure you know the passwords for all websites as cookies may possibly be removed in some cases, but not all cases.
    3. NOTE: As part of this fix, it will also reset the network to default settings including the firewall. If you have custom firewall rules you need to save please export or save them first before running this fix.

    The following directories are emptied:

    • Windows Temp
    • Users Temp folders
    • Edge, IE, FF, Chrome, and Opera caches, HTML5 storages, Cookies and History
    • Recently opened files cache
    • Discord cache
    • Java cache
    • Steam HTML cache
    • Explorer thumbnail and icon cache
    • BITS transfer queue (qmgr*.dat files)
    • Recycle Bin

    Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns please ask before running this fix.

    The system will be rebooted after the fix has run.

    fixlist.txt 55.63 kB · 1 download

    Thanks

     

    Fixlog.txt here you go

  3. 8 hours ago, AdvancedSetup said:

    The Farbar (FRST) program is located here in your downloads folder:  C:\Users\bacon\Downloads\FRSTEnglish.exe

    Please follow the process below to perform a fix in Safe Mode

     

    Start in Safe mode:

    • Press the Windows icon on the keyboard together with the letter I, to get into the Settings.
    • Choose Update and Security.
    • From the menu at the left, choose Recovery.
    • Under the title Advanced startup at the right, choose Restart now.
    • From the window that will appear choose Troubleshoot and then Advanced options.
    • Choose Startup Settings and then Restart.
    • Press number 5, for choosing Safe mode with networking.
    • You will know that you are in Safe mode, if the background is black and Safe mode is written at the four corners of the screen.


    After that:

    Please do the following to run a FRST fix.

    NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

    • Select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.

     

    Start::
    HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction
    HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction
    HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction
    HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction
    GroupPolicy: Restriction
    End::

     

    • Right-click on FRSTEnglish in your Downloads folder, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
    • Press the Fix button once and wait.
    • FRST will process fixlist.txt
    • When finished, it will produce a log fixlog.txt in your Downloads folder or where you have the Farbar program located.
    • Attach that log in your next reply.
     
    Thank you
     
     

    So when I restarted in safe mode with option 5 , network connectivity was still disabled 

    mbst-grab-results.zip

  4. 1 hour ago, AdvancedSetup said:

    Windows Autoupdate Disabled Policy:
    ============================
    ATTENTION!=====> policy restriction on WindowsUpdate: HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate

     

    HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION

     

    Please remove the restriction from the Registry and restart the computer.

    Then check for Windows Updates

     

    How do i do that? this is the only thing that I see under that folderwr.PNG.9a6efd3af62f0e56fbaa0aef81ef1516.PNG

  5. 22 hours ago, AdvancedSetup said:

    Please get us some logs from the mbst-grab-results.ziplaptop. You can use a USB thumb drive to save and copy the logs to post back from another computer if needed.

    Scan with FSS Farbar Service Scanner
    https://forums.malwarebytes.com/topic/306736-scan-with-fss-farbar-service-scanner/

    Scan with Farbar Recovery Scan Tool
    https://forums.malwarebytes.com/topic/306601-scan-with-farbar-recovery-scan-tool/

     

    Here you go , got everything to work. 

  6. 19 hours ago, AdvancedSetup said:

    Good day, @baconjr612

    Please post back the requested log and we'll be happy to assist you.

    Thanks

     

    Hello so , it seems like for whatever reason yesterday i was trying to reply with that log and it kept giving me a ‘this message may create spam’ now it seems like im giving a SpamFireWall is activated . so it blacklisted me??

     

    the only reason i am able to reply here is i disconnected from my home wifi on my phone 

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.