Jump to content
Jared_jaz

Keep loosing admin on Windows after multiple re-installs

Recommended Posts

Hello, I have had my whole network ripped apart, pretty much lost access to most of my files on every computer. i have been deleting partitions and reinstalling windows and it seems to be coming back. its been a 10 day battle so far, please help.

 

 

@AppHelpToast

@AudioToastIcon

@BackgroundAccessToastIcon

@bitlockertoastimage

@edptoastimage

@EnrollmentToastIcon

@language_notification_icon

@optionalfeatures

@VpnToastIcon

@WiFiNotificationIcon

@WindowsHelloFaceToastIcon

@windows-hello-V4.1

@WindowsUpdateToastIcon.contrast-black

@WindowsUpdateToastIcon.contrast-white

@WindowsUpdateToastIcon

@WirelessDisplayToast

@WwanNotificationIcon

@WwanSimLockIcon

 

 

 

 

Share this post


Link to post
Share on other sites
Just now, Jared_jaz said:

Hello, I have had my whole network ripped apart, pretty much lost access to most of my files on every computer. i have been deleting partitions and reinstalling windows and it seems to be coming back. its been a 10 day battle so far, please help.

 

 

@AppHelpToast

@AudioToastIcon

@BackgroundAccessToastIcon

@bitlockertoastimage

@edptoastimage

@EnrollmentToastIcon

@language_notification_icon

@optionalfeatures

@VpnToastIcon

@WiFiNotificationIcon

@WindowsHelloFaceToastIcon

@windows-hello-V4.1

@WindowsUpdateToastIcon.contrast-black

@WindowsUpdateToastIcon.contrast-white

@WindowsUpdateToastIcon

@WirelessDisplayToast

@WwanNotificationIcon

@WwanSimLockIcon

 

 

 

 

Sorry forgot to mention, these files are all  in my System32 folder, all are PNG file except @windows-hello-V4.1 is a GIF file

Share this post


Link to post
Share on other sites

Hi,

 

I did a FarBar Scan.. any advice? 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-03-2020
Ran by Jazza (administrator) on DESKTOP-QQKD9QT (Alienware Alienware 17 R4) (22-03-2020 15:44:59)
Running from C:\Users\Jazza\Desktop
Loaded Profiles: Jazza (Available Profiles: Jazza)
Platform: Windows 10 Home Version 1809 17763.107 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(A-Volute -> ) C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterSvc32.exe
(A-Volute -> ) C:\Program Files\Alienware\AWSoundCenter\UserInterface\x64\AWSoundCenterSvc64.exe
(A-Volute -> Alienware) C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterUILauncher.exe
(Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\DellDataVault\nvapiw.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(INTEL CORP) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.2727.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe
(INTEL CORP) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.2727.0_x64__8j3eq9eme6ctt\IGCC.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_f3a64c75ee4defb7\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_f3a64c75ee4defb7\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_38bfcb542ef4272e\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_38bfcb542ef4272e\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_a9a8972288e9f3b5\RstMwService.exe
(McAfee, Inc. -> McAfee LLC.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc. -> McAfee, LLC) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc. -> McAfee, LLC) C:\Windows\System32\mfevtps.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(McAfee, LLC -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(McAfee, LLC -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(McAfee, LLC. -> McAfee, LLC) C:\Program Files\Common Files\McAfee\VSCore_20_1\mcapexe.exe
(McAfee, LLC. -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\CSP\3.4.105.0\McCSPServiceHost.exe
(McAfee, LLC. -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHOST.exe
(McAfee, LLC. -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\ModuleCore\ProtectedModuleHost.exe
(McAfee, LLC. -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe
(McAfee, LLC. -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(McAfee, LLC. -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\Platform\MSM\McSmtFwk.exe
(McAfee, LLC. -> McAfee, LLC.) C:\Program Files\McAfee\MfeAV\MfeAVSvc.exe
(McAfee, LLC. -> McAfee, LLC.) C:\Program Files\McAfee\MQS\QcShm.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.19081.28230.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7106.1402\DSAPI.exe
(Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe
(Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9286352 2019-11-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515200 2019-11-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AWSoundCenterUILauncher] => C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterUILauncher.exe [1367416 2019-10-15] (A-Volute -> Alienware)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321112 2019-07-29] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.149\Installer\chrmstp.exe [2020-03-22] (Google LLC -> Google LLC)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {1395A34A-F4FB-4D2F-B398-02D88CE20809} - System32\Tasks\McAfee\McAfee DAT Built in test => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.0.9.577\mcdatrep.exe [1826656 2020-03-22] (McAfee, Inc. -> McAfee, LLC.)
Task: {260B5BD5-A276-4D95-9CE7-B5C7CE8BB83F} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4552120 2020-01-06] (McAfee, LLC -> McAfee, LLC.)
Task: {38410EBA-FECC-4FD8-822C-9B9581A5245D} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1072312 2020-02-04] (McAfee, LLC. -> McAfee, LLC.)
Task: {3B1CC168-8BCA-4E48-82DC-230ACF3F3EA9} - System32\Tasks\Microsoft\Windows\RetailDemo\CleanupOfflineContent => {61f77d5e-afe9-400b-a5e6-e9e80fc8e601} C:\Windows\System32\RDXTaskFactory.dll [411136 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
Task: {854F1E20-664A-47F4-A3F0-52286088BDC1} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1553880 2020-03-12] (Dell Inc. -> Dell Inc.)
Task: {9336695F-562C-4F19-8099-8AC957E59750} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-22] (Google LLC -> Google LLC)
Task: {971FA75D-C919-44CD-A84E-DB6433EE3CA3} - System32\Tasks\AWSoundCenterSvc64Run => C:\Program Files\Alienware\AWSoundCenter\UserInterface\x64\AWSoundCenterSvc64.exe [513912 2019-10-15] (A-Volute -> )
"C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" was unlocked. <==== ATTENTION
Task: {9D037929-1AB0-4422-AC6F-578F170748CB} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1072312 2020-02-04] (McAfee, LLC. -> McAfee, LLC.)
Task: {C5EBCD19-0DEB-4A4A-9F3B-1F7C5E298CE9} - System32\Tasks\AWSoundCenterSvc32Run => C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterSvc32.exe [2375544 2019-10-15] (A-Volute -> )
Task: {D1650345-3877-41B2-9D88-024F05F3F69A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-22] (Google LLC -> Google LLC)
Task: {D7D482A6-8EFE-40C0-A24A-1F63B7203821} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\DADUpdater.exe [4144776 2020-01-26] (McAfee, Inc. -> McAfee, LLC.)
Task: {D84C9D9C-FAC7-4A5A-8C04-F70A822A1F8C} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\IntelPTTEKRecertification.exe [916840 2019-06-07] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {DBCA4691-8531-4370-A453-48538E94B7D6} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [761424 2020-02-05] (McAfee, LLC. -> McAfee, LLC.)
Task: {F0A8C575-17CD-4BE5-A242-1BD8AA138639} - System32\Tasks\AWSoundCenterUILauncherRun => C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterUILauncher.exe [1367416 2019-10-15] (A-Volute -> Alienware)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{75983cd5-dd42-405f-9f39-f7efd152a328}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{d6017546-fee2-4dc9-9ab4-ca407d65f30f}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2020-03-22] (McAfee, LLC -> McAfee, LLC)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-03-22] (McAfee, LLC -> McAfee, LLC)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll [2020-02-05] (McAfee, LLC. -> McAfee, LLC.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2020-02-05] (McAfee, LLC. -> McAfee, LLC.)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2020-03-22] [UpdateUrl:hxxps://www.siteadvisor.com/waffinstall/update.json]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\McAfee\MSC\npMcSnFFPl64.dll [2020-02-05] (McAfee, LLC. -> )
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll [2020-02-05] (McAfee, LLC. -> )

Chrome: 
=======
CHR Profile: C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default [2020-03-22]
CHR HomePage: Default -> hxxp://google.com/
CHR Session Restore: Default -> is enabled.
CHR Extension: (Slides) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-03-21]
CHR Extension: (Docs) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-03-21]
CHR Extension: (Google Drive) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-03-21]
CHR Extension: (YouTube) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-03-21]
CHR Extension: (Sheets) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-03-21]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-03-21]
CHR Extension: (Google Docs Offline) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-21]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-03-21]
CHR Extension: (Gmail) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-03-21]
CHR Extension: (Chrome Media Router) - C:\Users\Jazza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-03-22]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\Windows\System32\drivers\AdminService.exe [424288 2018-05-22] (Qualcomm Atheros -> Windows (R) Win 7 DDK provider)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [244280 2020-01-14] (Dell Technologies Inc. -> Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3339824 2020-01-14] (Dell Technologies Inc. -> Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [271416 2020-01-14] (Dell Technologies Inc. -> Dell Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7106.1402\DSAPI.exe [965104 2020-03-22] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [36032 2020-02-12] (Dell Inc -> )
R2 esifsvc; C:\Windows\System32\Intel\DPTF\esif_uf.exe [1705488 2018-08-30] (Intel Corporation -> Intel Corporation)
S4 HfcDisableService; C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_a9a8972288e9f3b5\HfcDisableService.exe [1712128 2019-07-29] (Intel(R) Rapid Storage Technology -> Intel Corporation)
S3 iaStorAfsService; C:\Windows\System32\iaStorAfsService.exe [2844672 2019-07-29] (Intel(R) Rapid Storage Technology -> Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\SocketHeciServer.exe [870248 2019-06-07] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\TPMProvisioningService.exe [790376 2019-06-07] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [538088 2019-08-05] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [907224 2020-03-22] (McAfee, LLC -> McAfee, LLC)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_20_1\McApExe.exe [758864 2020-02-05] (McAfee, LLC. -> McAfee, LLC)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\3.4.105.0\\McCSPServiceHost.exe [2687856 2020-01-26] (McAfee, LLC. -> McAfee, LLC.)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [639048 2020-01-08] (McAfee, Inc. -> McAfee, LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [639048 2020-01-08] (McAfee, Inc. -> McAfee, LLC)
R3 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [639048 2020-01-08] (McAfee, Inc. -> McAfee, LLC)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1737992 2020-02-06] (McAfee, LLC -> McAfee, LLC.)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [1373912 2020-02-04] (McAfee, LLC. -> McAfee, LLC.)
R2 QcomWlanSrv; C:\Windows\System32\drivers\QcomWlanSrvx64.exe [191256 2019-01-28] (Qualcomm Atheros -> Qualcomm Technologies Inc.)
R2 RstMwService; C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_a9a8972288e9f3b5\RstMwService.exe [1970896 2019-07-29] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [276376 2019-11-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [38360 2020-03-12] (Dell Inc. -> Dell Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [257064 2018-06-27] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3830488 2018-09-15] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [110944 2018-09-15] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [75896 2020-01-15] (McAfee, Inc. -> McAfee, LLC)
R3 DDDriver; C:\Windows\System32\drivers\dddriver64Dcsa.sys [35704 2019-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
R3 dptf_acpi; C:\Windows\System32\drivers\dptf_acpi.sys [74584 2018-08-30] (Intel Corporation -> Intel Corporation)
R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [69984 2018-08-30] (Intel Corporation -> Intel Corporation)
R0 EMSC; C:\Windows\System32\drivers\EMSC.SYS [35216 2016-08-18] (Compal electronic ,inc -> )
R3 esif_lf; C:\Windows\System32\drivers\esif_lf.sys [383328 2018-08-30] (Intel Corporation -> Intel Corporation)
R3 HidEventFilter; C:\Windows\System32\drivers\HidEventFilter.sys [54800 2016-08-12] (Intel(R) Software -> Intel Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [217912 2019-06-04] (McAfee, LLC -> McAfee, Inc.)
R0 iaStorAC; C:\Windows\System32\drivers\iaStorAC.sys [1096192 2019-07-29] (Intel(R) Rapid Storage Technology -> Intel Corporation)
S3 iaStorAfs; C:\Windows\System32\drivers\iaStorAfs.sys [74752 2019-07-29] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R3 KillerEth; C:\Windows\System32\drivers\e2xw10x64.sys [145920 2018-09-15] (Microsoft Windows -> Qualcomm Atheros, Inc.)
R3 MEIx64; C:\Windows\System32\DriverStore\FileRepository\heci.inf_amd64_85021432489d6a1c\x64\TeeDriverW8x64.sys [266128 2019-08-05] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [527272 2020-01-15] (McAfee, Inc. -> McAfee, LLC)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [380840 2020-01-15] (McAfee, Inc. -> McAfee, LLC)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [85920 2020-01-15] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee, LLC)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [521128 2020-01-15] (McAfee, Inc. -> McAfee, LLC)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [997800 2020-01-15] (McAfee, Inc. -> McAfee, LLC)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [594360 2019-12-23] (McAfee, Inc. -> McAfee LLC.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [107960 2019-12-23] (McAfee, Inc. -> McAfee LLC.)
R3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [116856 2020-01-15] (McAfee, Inc. -> McAfee, LLC)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [252328 2020-01-15] (McAfee, Inc. -> McAfee, LLC)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvdmegpu.inf_amd64_b7816616157a066e\nvlddmkm.sys [21788872 2019-08-22] (NVIDIA Corporation -> NVIDIA Corporation)
R3 Qcamain10x64; C:\Windows\System32\drivers\Qcamain10x64.sys [2369816 2019-01-28] (Qualcomm Atheros -> Qualcomm Atheros, Inc.)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3224552 2017-05-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [45096 2018-06-27] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46584 2018-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [340008 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [61992 2018-09-15] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Three months (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-03-22 15:44 - 2020-03-22 15:45 - 000027207 _____ C:\Users\Jazza\Desktop\FRST.txt
2020-03-22 15:16 - 2020-03-22 15:16 - 030035968 _____ C:\Users\Jazza\Downloads\netgear-r7000p-webflash.bin
2020-03-22 13:31 - 2020-03-22 15:16 - 002279936 _____ (Farbar) C:\Users\Jazza\Downloads\FRST64.exe
2020-03-22 13:31 - 2020-03-22 13:31 - 008199856 _____ (Malwarebytes) C:\Users\Jazza\Downloads\adwcleaner_8.0.3.exe
2020-03-22 13:30 - 2020-03-22 15:45 - 000000000 ____D C:\FRST
2020-03-22 13:29 - 2020-03-22 13:29 - 002279936 _____ (Farbar) C:\Users\Jazza\Desktop\FRST64.exe
2020-03-22 13:22 - 2020-03-22 13:22 - 000255928 _____ (Malwarebytes) C:\Windows\system32\Drivers\233555FE.sys
2020-03-22 13:22 - 2020-03-22 13:22 - 000192952 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2020-03-22 13:21 - 2020-03-22 13:22 - 014161479 _____ C:\Users\Jazza\Downloads\mbar-1.10.3.1001-nr.exe
2020-03-22 12:38 - 2020-03-22 12:38 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-03-22 12:37 - 2020-03-22 13:26 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2020-03-22 12:36 - 2020-03-22 13:26 - 000000000 ____D C:\Users\Jazza\Desktop\mbar
2020-03-22 04:20 - 2020-03-22 04:20 - 000006407 _____ C:\Users\Jazza\Downloads\jazfam_openvpn.zip
2020-03-22 02:45 - 2020-03-22 13:19 - 000000000 ____D C:\Users\Jazza\Downloads\ReadySHAREVault-install-v2.0.10.100
2020-03-22 02:15 - 2020-03-22 02:15 - 000003794 _____ C:\Windows\system32\Tasks\Intel PTT EK Recertification
2020-03-22 02:14 - 2020-03-22 02:14 - 000000000 __SHD C:\IntelOptaneData
2020-03-22 02:14 - 2020-03-22 02:14 - 000000000 ____D C:\Windows\system32\Tasks\Intel
2020-03-22 02:13 - 2020-03-22 02:13 - 000000000 ____D C:\Program Files\Common Files\Intel Corporation
2020-03-22 02:12 - 2020-03-22 02:12 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2020-03-22 02:12 - 2020-03-22 02:12 - 000000000 ____D C:\Users\Jazza\AppData\Roaming\Intel Corporation
2020-03-22 02:12 - 2020-03-22 02:12 - 000000000 ____D C:\Program Files\Common Files\Intel
2020-03-22 02:11 - 2020-03-22 02:13 - 000000000 ____D C:\Program Files (x86)\Intel
2020-03-22 02:11 - 2020-03-22 02:11 - 000000000 ____D C:\Program Files\Killer Networking
2020-03-22 02:10 - 2020-03-22 02:13 - 000000000 ____D C:\Program Files\Intel
2020-03-22 02:08 - 2020-03-22 02:08 - 000000000 ____D C:\Users\Jazza\AppData\Local\Dell Inc
2020-03-22 02:04 - 2020-03-22 02:04 - 000000000 ____D C:\Program Files\Synaptics
2020-03-22 02:04 - 2018-06-27 16:06 - 000804392 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll
2020-03-22 02:04 - 2018-06-27 16:06 - 000428072 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCom.dll
2020-03-22 02:04 - 2018-06-27 16:06 - 000297000 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo46-4.dll
2020-03-22 02:04 - 2018-06-27 16:06 - 000278568 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll
2020-03-22 02:04 - 2018-06-27 16:05 - 000674344 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys
2020-03-22 02:04 - 2018-06-27 16:05 - 000070184 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynPTPHID_Aux.sys
2020-03-22 02:04 - 2018-06-27 16:05 - 000057384 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynRMIHID_Aux.sys
2020-03-22 02:04 - 2018-06-27 16:05 - 000045096 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel_Aux.sys
2020-03-22 02:04 - 2018-06-27 16:05 - 000045096 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel.sys
2020-03-22 02:04 - 2018-06-27 16:05 - 000044072 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_AMDASF_Aux.sys
2020-03-22 02:04 - 2014-01-30 18:17 - 001795952 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2020-03-22 02:02 - 2020-03-22 02:02 - 064581456 _____ (Dell Inc.) C:\Users\Jazza\Downloads\Dell-Touchpad-Driver_9NNK9_WIN_19.2.17.70_A11.EXE
2020-03-22 02:00 - 2020-03-22 02:07 - 000000000 ____D C:\ProgramData\PCDr
2020-03-22 02:00 - 2020-03-22 02:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2020-03-22 01:59 - 2020-03-22 01:59 - 000003916 _____ C:\Windows\system32\Tasks\Dell SupportAssistAgent AutoUpdate
2020-03-22 01:58 - 2020-03-22 02:00 - 000000000 ____D C:\Program Files\Dell
2020-03-22 01:58 - 2020-03-22 01:59 - 000000000 ____D C:\ProgramData\SupportAssist
2020-03-22 01:58 - 2020-03-22 01:58 - 000000000 ____D C:\ProgramData\Dell Inc
2020-03-22 01:58 - 2020-03-22 01:58 - 000000000 ____D C:\Program Files (x86)\Dell
2020-03-22 01:55 - 2020-03-22 01:55 - 000002377 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-03-22 01:55 - 2020-03-22 01:55 - 000002336 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-03-22 01:55 - 2020-03-22 01:55 - 000002336 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-03-22 01:54 - 2020-03-22 02:00 - 000003420 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-22 01:54 - 2020-03-22 02:00 - 000003296 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-22 01:54 - 2020-03-22 01:54 - 001288408 _____ (Google LLC) C:\Users\Jazza\Downloads\ChromeSetup.exe
2020-03-22 01:52 - 2020-03-22 01:52 - 000000000 ____D C:\Users\Jazza\AppData\Roaming\Synaptics
2020-03-22 01:44 - 2020-03-22 01:44 - 000000000 ____D C:\Windows\system32\Tasks\S-1-5-21-1911456875-2270903825-3414958252-1001
2020-03-22 01:22 - 2020-03-22 01:22 - 000000000 ____D C:\Program Files\UNP
2020-03-22 01:21 - 2020-03-21 06:25 - 000000000 ____D C:\Windows\Panther
2020-03-22 01:19 - 2020-03-22 01:19 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2020-03-22 01:19 - 2019-07-12 18:52 - 005435192 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2020-03-22 01:19 - 2019-07-12 18:52 - 002637352 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2020-03-22 01:19 - 2019-07-12 18:52 - 001767464 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2020-03-22 01:19 - 2019-07-12 18:52 - 000650608 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2020-03-22 01:19 - 2019-07-12 18:52 - 000450872 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2020-03-22 01:19 - 2019-07-12 18:52 - 000124784 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2020-03-22 01:19 - 2019-07-12 18:52 - 000083440 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2020-03-22 01:19 - 2019-07-05 04:58 - 008632992 _____ C:\Windows\system32\nvcoproc.bin
2020-03-22 01:19 - 2019-03-08 20:30 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2020-03-22 01:18 - 2020-03-22 01:18 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2020-03-22 01:15 - 2020-03-22 02:13 - 000000000 ____D C:\ProgramData\Package Cache
2020-03-22 01:15 - 2020-03-22 01:15 - 000000000 ____D C:\Users\Jazza\AppData\Local\D3DSCache
2020-03-22 01:15 - 2020-03-22 01:15 - 000000000 ____D C:\Program Files\Alienware
2020-03-22 01:12 - 2020-03-22 13:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2020-03-22 01:12 - 2020-03-22 01:12 - 000013850 _____ C:\Windows\system32\Drivers\rtkhdasetting.zip
2020-03-22 01:12 - 2020-03-22 01:12 - 000003254 _____ C:\Windows\system32\Tasks\AWSoundCenterUILauncherRun
2020-03-22 01:12 - 2020-03-22 01:12 - 000003242 _____ C:\Windows\system32\Tasks\AWSoundCenterSvc64Run
2020-03-22 01:12 - 2020-03-22 01:12 - 000003234 _____ C:\Windows\system32\Tasks\AWSoundCenterSvc32Run
2020-03-22 01:12 - 2020-03-22 01:12 - 000002059 _____ C:\Users\Public\Desktop\McAfee® Total Protection.lnk
2020-03-22 01:12 - 2020-03-22 01:12 - 000002059 _____ C:\ProgramData\Desktop\McAfee® Total Protection.lnk
2020-03-22 01:12 - 2020-03-22 01:12 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2020-03-22 01:12 - 2020-03-22 01:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alienware
2020-03-22 01:12 - 2020-03-22 01:12 - 000000000 ____D C:\Program Files (x86)\Realtek
2020-03-22 01:11 - 2019-06-04 04:13 - 000217912 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2020-03-22 01:09 - 2020-03-22 01:09 - 000003332 _____ C:\Windows\system32\Tasks\McAfeeLogon
2020-03-22 01:08 - 2020-03-22 14:35 - 000000000 ____D C:\Windows\system32\Tasks\McAfee
2020-03-22 01:07 - 2020-03-22 01:07 - 000003706 _____ C:\Windows\system32\Tasks\McAfee Remediation (Prepare)
2020-03-22 01:07 - 2020-03-22 01:07 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2020-03-22 01:07 - 2020-03-22 01:07 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2020-03-22 01:07 - 2020-03-22 01:07 - 000000000 ____D C:\Program Files\Common Files\AV
2020-03-22 01:06 - 2020-03-22 13:19 - 000000000 ____D C:\Intel
2020-03-22 01:06 - 2020-03-22 01:06 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2020-03-22 01:06 - 2020-01-08 23:03 - 000554288 _____ (McAfee, LLC) C:\Windows\system32\mfevtps.exe
2020-03-22 01:05 - 2020-03-22 01:05 - 042627888 _____ (McAfee, LLC.) C:\Users\Jazza\Downloads\McAfee_Installer_serial_YVmu3WD0ijnDeVBIhQKFrw2_key_affid_1274_akey.exe
2020-03-22 01:03 - 2020-03-22 01:03 - 000000000 ____D C:\Windows\system32\Intel
2020-03-22 00:47 - 2020-03-22 00:47 - 000000000 _____ C:\Users\Jazza\Desktop\New Text Document.txt
2020-03-21 21:59 - 2020-03-21 21:59 - 000000000 ____D C:\Program Files\AMD
2020-03-21 21:52 - 2020-03-21 21:52 - 000000000 ____D C:\Windows\nvmup
2020-03-21 21:51 - 2020-03-21 21:51 - 000000000 ____D C:\Dell
2020-03-21 21:50 - 2020-03-22 01:58 - 000000000 ____D C:\ProgramData\Dell
2020-03-21 21:24 - 2020-03-22 02:15 - 000000000 ____D C:\ProgramData\Intel
2020-03-21 21:22 - 2020-03-21 21:22 - 000000000 ____D C:\Program Files (x86)\Google
2020-03-21 21:21 - 2020-03-21 21:24 - 000000000 ____D C:\Users\Jazza\AppData\Local\Google
2020-03-21 21:04 - 2020-03-22 01:11 - 000000000 ____D C:\Program Files\McAfee
2020-03-21 21:04 - 2020-03-22 01:11 - 000000000 ____D C:\Program Files (x86)\McAfee
2020-03-21 21:04 - 2020-03-21 21:04 - 000000000 ____D C:\Program Files\McAfee.com
2020-03-21 21:03 - 2020-03-22 01:36 - 000000000 ____D C:\ProgramData\McAfee
2020-03-21 21:03 - 2020-03-22 01:11 - 000000000 ____D C:\Program Files\Common Files\McAfee
2020-03-21 21:03 - 2020-03-21 21:03 - 000000000 ____D C:\Users\Jazza\AppData\Local\DBG
2020-03-21 21:03 - 2020-03-21 21:03 - 000000000 ____D C:\Users\Jazza\AppData\Local\CEF
2020-03-21 20:55 - 2020-03-22 13:19 - 000000000 __SHD C:\Users\Jazza\IntelGraphicsProfiles
2020-03-21 20:55 - 2020-03-21 20:56 - 000000000 ____D C:\Users\Jazza\AppData\Local\Intel
2020-03-21 20:51 - 2020-03-22 13:19 - 000000000 ____D C:\ProgramData\NVIDIA
2020-03-21 20:50 - 2020-03-22 01:19 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2020-03-21 20:50 - 2020-03-21 20:51 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2020-03-21 20:42 - 2020-03-22 01:12 - 000000000 ____D C:\ProgramData\RTKAMPINFO
2020-03-21 20:37 - 2020-03-22 01:03 - 000000000 ____D C:\Program Files\Realtek
2020-03-21 06:52 - 2020-03-22 14:52 - 000000000 ____D C:\Users\Jazza\AppData\Local\PlaceholderTileLogoFolder
2020-03-21 06:47 - 2020-03-21 20:58 - 000000000 ____D C:\ProgramData\Packages
2020-03-21 06:41 - 2020-03-21 06:41 - 000000000 ___HD C:\Users\Jazza\MicrosoftEdgeBackups
2020-03-21 06:35 - 2020-03-21 06:35 - 000000000 ____D C:\Users\Jazza\AppData\Local\Comms
2020-03-21 06:33 - 2020-03-22 13:26 - 000797804 _____ C:\Windows\system32\PerfStringBackup.INI
2020-03-21 06:33 - 2020-03-21 06:33 - 000000000 ___RD C:\Users\Jazza\OneDrive
2020-03-21 06:32 - 2020-03-21 06:32 - 000001446 _____ C:\Users\Jazza\Desktop\Microsoft Edge.lnk
2020-03-21 06:32 - 2020-03-21 06:32 - 000000000 ____D C:\Users\Jazza\AppData\Local\MicrosoftEdge
2020-03-21 06:32 - 2020-03-21 06:32 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-03-21 06:31 - 2020-03-22 13:19 - 000000000 ____D C:\Users\Jazza\AppData\Local\ConnectedDevicesPlatform
2020-03-21 06:31 - 2020-03-22 13:19 - 000000000 ____D C:\Users\Jazza
2020-03-21 06:31 - 2020-03-22 02:22 - 000000000 ____D C:\Users\Jazza\AppData\Local\Packages
2020-03-21 06:31 - 2020-03-21 20:58 - 000000000 ____D C:\Users\Jazza\AppData\Local\Publishers
2020-03-21 06:31 - 2020-03-21 06:31 - 000000020 ___SH C:\Users\Jazza\ntuser.ini
2020-03-21 06:31 - 2020-03-21 06:31 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-03-21 06:31 - 2020-03-21 06:31 - 000000000 ___RD C:\Users\Jazza\3D Objects
2020-03-21 06:31 - 2020-03-21 06:31 - 000000000 ____D C:\Users\Jazza\AppData\Roaming\Adobe
2020-03-21 06:31 - 2020-03-21 06:31 - 000000000 ____D C:\Users\Jazza\AppData\Local\VirtualStore
2020-03-21 06:31 - 2020-03-21 06:31 - 000000000 ____D C:\ProgramData\USOShared
2020-03-21 06:31 - 2018-09-15 18:28 - 002864640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2020-03-21 06:27 - 2020-03-21 06:27 - 000000000 _SHDL C:\Documents and Settings
2020-03-21 06:24 - 2020-03-22 14:43 - 000000000 ____D C:\Windows\system32\SleepStudy
2020-03-21 06:24 - 2020-03-22 13:19 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-03-21 06:24 - 2020-03-22 01:01 - 000257824 _____ C:\Windows\system32\FNTCACHE.DAT
2020-03-21 06:24 - 2020-03-21 06:24 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2020-03-21 06:24 - 2020-03-21 06:24 - 000000000 ____D C:\Windows\system32\Drivers\wd
2020-03-21 06:24 - 2020-03-21 06:24 - 000000000 ____D C:\Windows\ServiceProfiles
2020-01-15 19:13 - 2020-01-15 19:13 - 000997800 _____ (McAfee, LLC) C:\Windows\system32\Drivers\mfehidk.sys
2020-01-15 19:13 - 2020-01-15 19:13 - 000527272 _____ (McAfee, LLC) C:\Windows\system32\Drivers\mfeaack.sys
2020-01-15 19:13 - 2020-01-15 19:13 - 000521128 _____ (McAfee, LLC) C:\Windows\system32\Drivers\mfefirek.sys
2020-01-15 19:13 - 2020-01-15 19:13 - 000380840 _____ (McAfee, LLC) C:\Windows\system32\Drivers\mfeavfk.sys
2020-01-15 19:13 - 2020-01-15 19:13 - 000252328 _____ (McAfee, LLC) C:\Windows\system32\Drivers\mfewfpk.sys
2020-01-15 19:13 - 2020-01-15 19:13 - 000116856 _____ (McAfee, LLC) C:\Windows\system32\Drivers\mfeplk.sys
2020-01-15 19:13 - 2020-01-15 19:13 - 000085920 _____ (McAfee, LLC) C:\Windows\system32\Drivers\mfeelamk.sys
2020-01-15 19:13 - 2020-01-15 19:13 - 000075896 _____ (McAfee, LLC) C:\Windows\system32\Drivers\cfwids.sys
2019-12-23 01:37 - 2019-12-23 01:37 - 000594360 _____ (McAfee LLC.) C:\Windows\system32\Drivers\mfencbdc.sys
2019-12-23 01:37 - 2019-12-23 01:37 - 000107960 _____ (McAfee LLC.) C:\Windows\system32\Drivers\mfencrk.sys
2019-12-23 01:37 - 2019-12-23 01:37 - 000030136 _____ (McAfee LLC.) C:\Windows\system32\Drivers\mfeclnrk.sys

==================== Three months (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-03-22 15:45 - 2018-09-15 18:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-03-22 13:35 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\AppReadiness
2020-03-22 13:26 - 2018-09-15 18:31 - 000000000 ____D C:\Windows\INF
2020-03-22 13:21 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\registration
2020-03-22 13:19 - 2018-09-15 18:33 - 000000000 ___SD C:\Windows\system32\UNP
2020-03-22 13:19 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2020-03-22 13:18 - 2018-09-15 18:33 - 000000000 ___HD C:\Program Files\WindowsApps
2020-03-22 13:18 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\appcompat
2020-03-22 02:41 - 2018-09-15 20:10 - 000000000 ____D C:\Windows\OCR
2020-03-22 02:41 - 2018-09-15 18:23 - 000000000 ____D C:\Windows\CbsTemp
2020-03-22 02:29 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\system32\NDF
2020-03-22 02:15 - 2018-09-15 17:09 - 000000000 ____D C:\Windows\servicing
2020-03-22 02:13 - 2018-09-15 17:09 - 000524288 _____ C:\Windows\system32\config\BBI
2020-03-22 01:30 - 2018-09-15 17:09 - 000000000 ____D C:\Windows\system32\Sysprep
2020-03-22 01:21 - 2018-09-15 18:31 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2020-03-22 01:19 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\Help
2020-03-22 01:17 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2020-03-22 01:17 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2020-03-22 01:06 - 2018-09-15 18:33 - 000000000 ___HD C:\Windows\ELAMBKUP
2020-03-21 21:07 - 2018-09-15 17:09 - 000032768 _____ C:\Windows\system32\config\ELAM
2020-03-21 06:31 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\system32\spool
2020-03-21 06:31 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\system32\FxsTmp
2020-03-21 06:31 - 2018-09-15 18:33 - 000000000 ____D C:\ProgramData\USOPrivate
2020-03-21 06:24 - 2018-09-15 18:33 - 000000000 ___RD C:\Windows\PrintDialog
2020-03-21 06:24 - 2018-09-15 18:33 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-03-21 06:24 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\ServiceState

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Share this post


Link to post
Share on other sites

Please run the following steps and post back the logs as an attachment when ready.

STEP 01

  • If you're already running Malwarebytes then open Malwarebytes and check for updates. Then click on the Scan tab and select Threat Scan and click on Start Scan button.
  • If you don't have Malwarebytes installed yet please download it from here and install it.
  • Once installed then open Malwarebytes and select Scan and let it run.
  • Once the scan is completed click on the View Report button, then the Export button and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.
  • If Malwarebytes won't run then please skip to the next step and let me know in your next reply.

STEP 02

Please download AdwCleaner by Malwarebytes and save the file to your Desktop.

  • Right-click on the program and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Accept the Terms of use.
  • Wait until the database is updated.
  • Click Scan Now.
  • When finished, please click Clean & Repair.
  • Your PC should reboot now if any items were found.
  • After reboot, a log file will be opened. Attach or Copy its content into your next reply.

 

RESTART THE COMPUTER Before running Step 3

STEP 03
Please download the Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit

  • Double-click to run it. When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it also makes another log (Addition.txt). If you've, run the tool before you need to place a checkmark here.
  • Please attach the Additions.txt log to your reply as well.

 

Thanks

Share this post


Link to post
Share on other sites

I don't expect anything to be found, but let's go ahead and run this rootkit scanner. Please isolate this computer for others as best as possible. 

 

Please download the following scanner from Kaspersky and save it to your computer: TDSSkiller

Then watch the following video on how to use the tool and make sure to temporarily disable your security applications before running TDSSkiller.

PC Winvids - How to run Kaspersky TDSSKiller

If any infection is found please make sure to choose SKIP and post back the log in case of a False Positive detection.

Once the tool has completed scanning make sure to re-enable your other security applications.

Thank you

 

 

 

Share this post


Link to post
Share on other sites

Please review the following website and read it before continuing and then do a Hard Reset back to Factory Defaults for your router.
This information is only for resetting the router DO NOT erase, install, or update the firmware, just reset your router to factory defaults.


https://wiki.dd-wrt.com/wiki/index.php/Reset_And_Reboot

https://wiki.dd-wrt.com/wiki/index.php/Hard_reset_or_30/30/30

 

Share this post


Link to post
Share on other sites

All 3 logs show not detection

Detected object count: 0
Actual detected object count: 0

 

Please go ahead and reset the router.

What is the Manufacturer name, model number, and version if listed of the router?

 

Share this post


Link to post
Share on other sites

Technicolor TG789vac V2
 

that’s the make and model. Sorry didn’t get a firmware version.

 

so i did the 30/30/30 reset and I’m getting all green lights but no Internet connectivity. I’m on the phone to the ISP now. This is the 4th time on the phone to the ISP and I have flashed and re-configured around 8 times 

Share this post


Link to post
Share on other sites

As long as the router was factory reset then it should be safe. Ensure you've set a strong admin level password on the unit that only you know.

INFORMATION ONLY


Technicolor Setup and User Guide TG789vac v2
https://www.resqnet.co.uk/wp-content/uploads/2016/02/TG789vac-v2-Set-up-and-user-guide.pdf

Technicolor TG789vac Login Instructions
https://setuprouter.com/router/technicolor/tg789vac/login.htm


What is DD-WRT
https://forum.dd-wrt.com/wiki/index.php/What_is_DD-WRT%3F

DD-WRT Firmware FAQ
https://wiki.dd-wrt.com/wiki/index.php/Index:FAQ

FlashRouters
https://blog.flashrouters.com/2020/02/07/flashrouters-2020-reboot/

Router FAQs
https://support.flashrouters.com/faqs/router-faqs/

Reading and Research information ONLY! Any type of modifications done are at your own risk
Hacking Technicolor Gateways
https://hack-technicolor.readthedocs.io/en/stable/

 

Let me get a fresh set of FRST logs please.

 

 

Share this post


Link to post
Share on other sites

This doesn’t look right to me, I haven’t set up any sort of network or anything

image.png

Share this post


Link to post
Share on other sites

Not sure what the image is you're showing me.

Looking at the Dell Support site it looks like your network drivers may not be up to date?
https://www.dell.com/support/home/us/en/04/product-support/product/alienware-17-laptop/drivers

 

image.png

 

 

Have you also installed the  latest Chipset drivers as well?

image.png

 

Some of the hard drives also have firmware updates if you've not installed or updated

image.png

 

 

 

Share this post


Link to post
Share on other sites

As long as the network ingress into the home is secure (why a factory reset to the router) we can rule out external access from that level.

Now, only need to look at other potential exploits or ingress from individual machine access to the outside world.

The log shows that Windows was installed a few days ago:  Windows 10 Home Version 1809 17763.107 (X64) (2020-03-24 08:29:45)

It needs to be updated to the latest version of Windows

image.png

 

How to get the Windows 10 November 2019 Update
https://blogs.windows.com/windowsexperience/2019/11/12/how-to-get-the-windows-10-november-2019-update/

 

 

 

Share this post


Link to post
Share on other sites

To my understanding NETbios is not needed for win 10 however it is installed by defult? is this correct. I have not set any of this up. Can you please look at the network set up and advise me what it is saying? To me it looks like I'm part of that homegroup. I’m not familiar with UPnP service WFAWLANConfig(1) and I'm not sure why it has FileServer marked as Yes. 

I found more evidence towards my computer being part of a windows server looking in regedit. A whole series of services were calling port numbers that shouldn't be there or they shouldn't be calling for a port. There's also heaps of users that only appear under security and an extra user in my group. The Desktop.ini file I pulled from a HDD that it took out of my pc last week after I had lost complete permissions on everything. I have had all my computer had their BIOS edited with windows powershell and the only way I can even boot is  in legacy boot too be able to start a install. all of my EFI boot options are gone and I only have network boot ipv4 or the ipv6 version. AllJoyn and mDNS services have been used to uses I-phones and my Samsung to remotely turn on various laptops. I have had aptiode installed on my smart TV which I never did, its logged into an account that I cant access and I cant remove the software. My sony Bluetooth/wifi speaker now acts as a router with options via mobile to configure IP and DNS addresses. 

I think the NTD has been compromised as to my understanding they only use MAC address, NBN have told me I can touch the NTD and everytime I reconfigure my router the calls start pouring in. I have went through 3 different routers and I always loose access the same day. every time I have configured them on an offline computer changing all passwords and account profiles. I have even had the ISP change my public facing IP and NBN co change the NTD for me about 9 days ago now. originally it was done via VOIP calls which I have now got VOIP disabled, my firewalls always end up with the users added as an exception to be able to bypass the rules.

I am at a complete loss at what to do next, I purchased the premium protect 3 computers with Malwarebytes a few days ago. I am going to subscribe to a VPN service and get a VPN enabled router but I don't want to add that stuff until my network is no longer compromised. The majority of my computers are sitting with no boot (deleted partitions).

image.png.b6d57af774ed3833075082a6ec65e51f.png

91393921_2562197434100108_9012911604194344960_n.thumb.jpg.4dc79825615d366168e76a703a39aa65.jpg91320752_276529763336298_4510182536629977088_n.thumb.jpg.d8fd2d3d8267db9b2b56f2fefacdfa2a.jpg91288165_509402019749222_9125389406037868544_n.thumb.jpg.32123f7a4e0ebe0664e2adab7fd1fa10.jpg91247412_562360571072271_2189325949542072320_n.thumb.jpg.e487df6930e425ac1233a714976d0621.jpg91216651_235235804532343_5217730410976378880_n.thumb.jpg.25a6ddaca579b17fa18dbf3f3ec805a1.jpg91025249_199530514679239_8170974469444075520_n.thumb.jpg.44be5cb0ad9ef85e69931f4d6eeae8a7.jpg91013198_2643020095983170_5962771451441315840_n.thumb.jpg.7a8421984652ab9ce1170727be8642f5.jpg90979990_205018267505722_936997048912183296_n.thumb.jpg.7e98a38d5bb4aa620d71995ec07ffd8b.jpg90969844_612177356003661_1737280401119903744_n.thumb.jpg.49e5ff10609d09ce47fd5e5b6fbbc07a.jpg90964838_513101036018481_1188414010534395904_n.thumb.jpg.ec2d5d2288cd7b6a328733338df6f8ec.jpg

image.png

Share this post


Link to post
Share on other sites

I think you're in some type of unexplained panic mode over nothing. All the screenshots above are normal.

https://ss64.com/nt/syntax-security_groups.html

 

https://support.microsoft.com/en-us/help/243330/well-known-security-identifiers-in-windows-operating-systems

 

From a command prompt type the following and see what it tells you.

WHOAMI   /ALL

 

Share this post


Link to post
Share on other sites

Privilege Name                            Description                                                        State
========================================= ================================================================== ========
SeIncreaseQuotaPrivilege                  Adjust memory quotas for a process                                 Disabled
SeSecurityPrivilege                       Manage auditing and security log                                   Disabled
SeTakeOwnershipPrivilege                  Take ownership of files or other objects                           Disabled
SeLoadDriverPrivilege                     Load and unload device drivers                                     Disabled
SeSystemProfilePrivilege                  Profile system performance                                         Disabled
SeSystemtimePrivilege                     Change the system time                                             Disabled
SeProfileSingleProcessPrivilege           Profile single process                                             Disabled
SeIncreaseBasePriorityPrivilege           Increase scheduling priority                                       Disabled
SeCreatePagefilePrivilege                 Create a pagefile                                                  Disabled
SeBackupPrivilege                         Back up files and directories                                      Disabled
SeRestorePrivilege                        Restore files and directories                                      Disabled
SeShutdownPrivilege                       Shut down the system                                               Disabled
SeDebugPrivilege                          Debug programs                                                     Disabled
SeSystemEnvironmentPrivilege              Modify firmware environment values                                 Disabled
SeChangeNotifyPrivilege                   Bypass traverse checking                                           Enabled
SeRemoteShutdownPrivilege                 Force shutdown from a remote system                                Disabled
SeUndockPrivilege                         Remove computer from docking station                               Disabled
SeManageVolumePrivilege                   Perform volume maintenance tasks                                   Disabled
SeImpersonatePrivilege                    Impersonate a client after authentication                          Enabled
SeCreateGlobalPrivilege                   Create global objects                                              Enabled
SeIncreaseWorkingSetPrivilege             Increase a process working set                                     Disabled
SeTimeZonePrivilege                       Change the time zone                                               Disabled
SeCreateSymbolicLinkPrivilege             Create symbolic links                                              Disabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Disabled

Share this post


Link to post
Share on other sites

That's good to hear, I have only just reinstalled windows a few hours ago and it seems to progress over time.

I am however unsure where to go from here moving forwards, I have been constantly trying to regain full control and the router settings keep getting changed. I also need to learn how to get the bios back in order via powershell as now when I do restore to default it puts it back to how they have set it.

Share this post


Link to post
Share on other sites

There should have been more to that entry but that's the main idea. Those are normal valid accounts.

When you say "I have been constantly trying to regain full control"  - Full control of what?

"the router settings keep getting changed"   - How do you know they're getting changed?

"how to get the bios back in order via powershell"   - I really don't know what you mean by that. There is no BIOS/UEFI that is managed or controlled by PowerShell

"when I do restore to default it puts it back to how they have set it"  - When you put back what?

 

Share this post


Link to post
Share on other sites

default.txtthis is a log from when it all first started. this was from the mac that I'm am assuming originally got infected. its a late 2013 27inch macOS, its been disconnect and off from power with a deleted partition for around 3 weeks

Share this post


Link to post
Share on other sites

I'm sorry but I'm not going to go through a 10K line log file from 7 years ago. No one I'm aware of does that type of forensic work for free.

I want to help you but so far you've provided nothing to indicate there is actually anything wrong. Please try to answer the questions I've asked above so I can better understand your concerns

Thanks

 

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.