Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Fake virus popups and running extremely slowly


  • Please log in to reply
9 replies to this topic

#1 adaniel

adaniel

  •  Avatar image
  • Members
  • 214 posts
  • ONLINE
  •  
  • Local time:10:02 AM

Posted Yesterday, 12:28 AM

I am trying to cleanup an HP ProBook for a friend.  It runs extremely slowly, taking up to 40 minutes to boot up.  I ran a MalwareBytes scan which ran for 10 hours on a 500 GB disk and did no good.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-10-2025
Ran by gsegebade (administrator) on SEGEBADE-01 (Hewlett-Packard HP ProBook 6570b) (15-10-2025 23:26:19)
Running from C:\Users\gsegebade\Downloads\FRST64.exe
Loaded Profiles: gsegebade
Platform: Microsoft Windows 10 Pro Version 22H2 19045.6332 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe ->) (Adobe Systems, Incorporated -> ) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\FullTrustNotifier.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(C:\Program Files\RUXIM\PLUGScheduler.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\RUXIM\RUXIMICS.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <12>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\GoogleUpdater\142.0.7416.0\updater.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(services.exe ->) (GlavSoft LLC. -> GlavSoft LLC.) C:\Program Files\TightVNC\tvnserver.exe
(services.exe ->) (Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(services.exe ->) (Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(services.exe ->) (Hewlett-Packard Company -> Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(services.exe ->) (Intel Corporation) [File not signed] [File is in use] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Intel® Upgrade Service -> Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(services.exe ->) (RealNetworks, Inc. -> RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
(services.exe ->) (RealNetworks, Inc. -> RealNetworks, Inc.) C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(services.exe ->) (Validity Sensors, Inc -> Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(services.exe ->) (Validity Sensors, Inc.) [File not signed] C:\Windows\System32\valWBFPolicyService.exe
(svchost.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\gsegebade\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\RUXIM\PLUGScheduler.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (RealNetworks, Inc. -> ) C:\Program Files (x86)\Real\RealPlayer\downloader2.exe <4>
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [tvncontrol] => C:\Program Files\TightVNC\tvnserver.exe [2179056 2013-07-19] (GlavSoft LLC. -> GlavSoft LLC.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-19] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [3158704 2021-08-20] (Corel Corporation -> Corel Corporation)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [334240 2012-08-28] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [277504 2012-08-28] (Intel Corporation) [File not signed]
HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [348736 2023-12-13] (RealNetworks, Inc. -> RealNetworks, Inc.)
HKLM-x32\...\Run: [RealPlayer] => c:\program files (x86)\real\realplayer\RPDS\Bin\rpsystray.exe [5942360 2023-12-13] (RealNetworks, Inc. -> RealNetworks, Inc.)
HKLM-x32\...\Run: [RealDownloader] => c:\program files (x86)\real\realplayer\downloader2.exe [1244224 2023-12-13] (RealNetworks, Inc. -> )
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2619967780-3706259895-3790722038-1001\...\Run: [MicrosoftEdgeAutoLaunch_2BBA73BF061ED00FD3C930720F27DAC8] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4265000 2025-10-09] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\141.0.7390.77\Installer\chrmstp.exe [2025-10-13] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\WIDCOMM\Bluetooth Software\BtwCP.dll [2012-09-04] (Broadcom Corporation -> Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2014-08-10]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2022-06-06]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (Corel Corporation -> WinZip Computing)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {04121FF1-519F-41B5-9086-CB08CCEAEB44} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {29817316-6EED-4776-9481-98BEC6DF328D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {322E5C15-9BEE-46C0-A1F7-D3B00BBC2F16} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {45905824-29C3-4D6B-AC4B-650612DCA01A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {61809F96-8261-4DC1-A055-E3BC2B0DC19C} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {6EC1A5FA-2592-43E9-B043-17FBD61947FD} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {6F6410F5-F0C4-495C-9673-1CEE391102BE} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {7C6F5CB8-DB8C-4E10-ACBF-F9283B0F01CA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B3BDCB84-A553-40F5-8BAB-94EAC862E720} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {BADBDD3D-8D7D-47CF-A0C7-58C88FC3DFEE} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {CBD402D7-A169-4365-B415-977BB64BF3C0} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {D613EB01-2625-4FD7-979D-2AA9D00B0238} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {EA3528D4-B37F-40FD-98AE-E80B1D68CB20} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {FC4C1DF5-39BA-4A3E-9346-B46ED71EFC34} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {76D3F4E5-280D-403D-A463-242CB69BA072} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1581568 2025-08-24] (Adobe Inc. -> Adobe Inc.)
Task: {06ACB895-08FC-44D1-A41F-E552F9329ED5} - System32\Tasks\AdwCleaner_onReboot => C:\Users\gsegebade\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\adwcleaner_8.0.2 (1).exe  /r (No File)
Task: {0FA15B94-7F2D-4F35-9104-A2DDCAA4AB08} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem142.0.7416.0{CE16D7E0-539F-4092-9FD8-27AE5B74BE90} => C:\Program Files (x86)\Google\GoogleUpdater\142.0.7416.0\updater.exe [6863512 2025-09-15] (Google LLC -> Google LLC)
Task: {20AAE1BC-E10C-440E-893B-602FA554D895} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {8B937291-233E-4E4D-B4A9-82D58C8EE5F9} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA}
Task: {4F12818E-179B-46F9-AF53-2245F5E1A4F7} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {D1538B6E-7B8B-4294-9270-7919670CF2CE} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {B4978C0E-CC38-468D-99B0-2DB81422639D} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {4697E406-581F-4420-827A-B4BF719DCC9C} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE}
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe  join (No File)
Task: {4826EE36-BCE5-43A3-9D76-538D24B1AAB1} - System32\Tasks\Mozilla\Firefox Background Update E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\firefox.exe [693376 2025-10-04] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla\updates\E7CF176E110C211B\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla\updates\E7CF176E110C211B\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {EFADA024-EFA1-4B7D-897F-F5F618DA3551} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [34944 2025-10-04] (Mozilla Corporation -> Mozilla Foundation)
Task: {064D3346-5432-429C-8018-639EC954C77C} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2619967780-3706259895-3790722038-1001 => C:\Users\gsegebade\AppData\Local\Microsoft\OneDrive\25.179.0914.0003\OneDriveLauncher.exe [725864 2025-10-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {B4DDBE3C-0DBC-4D31-8745-FD53444926CB} - System32\Tasks\Opera scheduled assistant Autoupdate 1636817284 => C:\Users\gsegebade\AppData\Local\Programs\Opera\launcher.exe  -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\gsegebade\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {AB3285F2-ECE6-43C9-AF8D-45C405C505B7} - System32\Tasks\Opera scheduled Autoupdate 1636817210 => C:\Users\gsegebade\AppData\Local\Programs\Opera\launcher.exe  --scheduledautoupdate $(Arg0) (No File)
Task: {7E38D1CD-630E-4AEA-820A-C6D0AF07748D} - System32\Tasks\Paragon Archive name arc_060814134545869 => C:\Program Files\Paragon Software\Backup and Recovery 2014 Free\program\scripts.exe [861448 2014-05-09] (Paragon Software GmbH -> Paragon Software Group) -> C:\Program Files\Paragon Software\Backup and Recovery 2014 Free\program\\--rebootonconfirm -Wno --graph --multiple "C:/Program Files/Paragon Software/Backup and Recovery 2014 Free/scripts/scr_060814134727604.psl"
Task: {1BFCA1D6-F88C-454E-91B3-E442B9C94CB0} - System32\Tasks\RealDownloader Update Check => c:\program files (x86)\Real\realplayer\downloader2.exe [1244224 2023-12-13] (RealNetworks, Inc. -> )
Task: {C7FE6B82-12A6-4FDD-8C2D-9D03B9818303} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2619967780-3706259895-3790722038-1001 => C:\program files (x86)\Real\realplayer\RealUpgrade.exe [131648 2023-12-13] (RealNetworks, Inc. -> RealNetworks, Inc.)
Task: {75B604FB-9236-4D21-8C84-13DD6DF71E07} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2619967780-3706259895-3790722038-1001 => C:\program files (x86)\Real\realplayer\RealUpgrade.exe [131648 2023-12-13] (RealNetworks, Inc. -> RealNetworks, Inc.)
Task: {D284A81D-FCB7-4EED-B231-514614B615E4} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3965536 2017-08-19] (Synaptics Incorporated -> Synaptics Incorporated)
Task: {A4CDD482-A8A1-459B-824D-6AB837A26F23} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files\WinZip\WZUpdateNotifier.exe [3158704 2021-08-20] (Corel Corporation -> Corel Corporation)
Task: {BB764A5C-2394-422B-B813-AE633DB35461} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files\WinZip\WZUpdateNotifier.exe [3158704 2021-08-20] (Corel Corporation -> Corel Corporation)
Task: {62A030CA-CE1E-46D0-8A48-1A71F9EA5DB1} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files\WinZip\WZUpdateNotifier.exe [3158704 2021-08-20] (Corel Corporation -> Corel Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Paragon Archive name arc_060814134545869.job => C:\Program Files\Paragon Software\Backup and Recovery 2014 Free\program\scripts.exe--rebootonconfirm -Wno --graph --multiple C:/Program Files/Paragon Software/Backup and Recovery 2014 Free/scripts/scr_060814134727604.psl
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{6faccdad-de8c-440f-a300-0a6ae41a179e}: [DhcpNameServer] 209.18.47.61 209.18.47.63
Tcpip\..\Interfaces\{6faccdad-de8c-440f-a300-0a6ae41a179e}: [DhcpDomain] triad.rr.com
Tcpip\..\Interfaces\{be9694ed-c460-4d73-8864-63ea36a3349e}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{be9694ed-c460-4d73-8864-63ea36a3349e}: [DhcpDomain] attlocal.net
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
 
Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\gsegebade\AppData\Local\Microsoft\Edge\User Data\Default [2025-10-16]
Edge DownloadDir: Default -> C:\Users\gsegebade\Downloads
Edge Notifications: Default -> hxxps://74ng76qecrpaf3.webmotion.co.in; hxxps://amgreatness.com; hxxps://cvggq81029pc73dalvu0.visolabala.co.in; hxxps://d10e1r8ko90s73e7e9l0.gms-adguard.co.in; hxxps://d2u8n8ghubcc7389bv70.webmotion.co.in; hxxps://radio.foxnews.com; hxxps://www.accuweather.com; hxxps://www.bandsintown.com; hxxps://www.cbssports.com; hxxps://www.facebook.com; hxxps://www.iheart.com; hxxps://www.usatoday.com
Edge Extension: (Google Docs Offline) - C:\Users\gsegebade\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-09-28]
Edge Extension: (Edge relevant text changes) - C:\Users\gsegebade\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-09]
 
FireFox:
========
FF DefaultProfile: sp682dyk.default-1540171918119
FF ProfilePath: C:\Users\gsegebade\AppData\Roaming\Mozilla\Firefox\Profiles\sp682dyk.default-1540171918119 [2025-10-15]
FF Homepage: Mozilla\Firefox\Profiles\sp682dyk.default-1540171918119 -> hxxps://www.malwarebytes.org/restorebrowser/?lic=free&product=MBAM-Cparam1=y6bdVFVIsvuYsgEClQfz8FBvKkXdqONxqOqRNOxENVYj5gI%2BADbKO0zfqZKIog4BEsEaAEGyI1Zx2VIqFa71jY%2F1OfgnGeIMtzeMFqMqY342sANNXvguPtyuy4%2Bv4cfXhyAddLRAqDRYO8GYgTEuXizDaoEo%2FC%2BFiIoo0vF3DAOUYQ0HpLr6L8TxgR7OknZaXd0HyKeJxwxpxaN0fQ3inemPQjM96aGMPuV0PmazG82veyekNVmmrUNn7h8cxSnrgE%2BNx1seOecxd5HXzKmmWSgL4yGjNlZHuC%2Fye73zGAc%3D
FF SearchPlugin: C:\Users\gsegebade\AppData\Roaming\Mozilla\Firefox\Profiles\sp682dyk.default-1540171918119\searchplugins\Yahoo powered search.xml [2020-02-24]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @real.com/nppl3260;version=22.0.5.310 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2023-12-13] (RealNetworks, Inc. -> RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=22.0.5.310 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2023-12-13] (RealNetworks, Inc. -> RealPlayer)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2025-09-29] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\gsegebade\AppData\Local\Google\Chrome\User Data\Default [2025-10-16]
CHR Notifications: Default -> hxxps://odesclub.com; hxxps://www.cbssports.com; hxxps://www.dodgersnation.com; hxxps://www.facebook.com; hxxps://www.newsbreak.com; hxxps://www.pinterest.co.uk; hxxps://www.pinterest.ie
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\gsegebade\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-10-14]
CHR Extension: (Google Docs Offline) - C:\Users\gsegebade\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-10-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\gsegebade\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKU\S-1-5-21-2619967780-3706259895-3790722038-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
 
Opera: 
=======
OPR Profile: C:\Users\gsegebade\AppData\Roaming\Opera Software\Opera Stable [2022-01-10]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\gsegebade\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-12-16]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\gsegebade\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-11-14]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174584 2025-08-24] (Adobe Inc. -> Adobe Inc.)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [523680 2012-08-28] (Hewlett-Packard Company -> Hewlett-Packard Company)
R2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-08-28] (Intel Corporation) [File not signed] [File is in use] <==== ATTENTION
R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8965728 2024-09-06] (Malwarebytes Inc. -> Malwarebytes)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe [2009656 2025-09-22] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 RealPlayerUpdateSvc; C:\program files (x86)\real\UpdateService\RealPlayerUpdateSvc.exe [40544 2023-11-22] (RealNetworks, Inc. -> RealNetworks, Inc.)
R2 RealTimes Desktop Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [992856 2023-12-13] (RealNetworks, Inc. -> RealNetworks, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-08-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [323072 2012-08-19] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
R2 tvnserver; C:\Program Files\TightVNC\tvnserver.exe [2179056 2013-07-19] (GlavSoft LLC. -> GlavSoft LLC.)
R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [35328 2013-10-11] (Validity Sensors, Inc.) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\NisSrv.exe [4414464 2025-09-22] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe [282480 2025-09-22] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ahcix64s; C:\WINDOWS\System32\drivers\ahcix64s.sys [298304 2012-10-08] (Promise Technology, Inc. -> Advanced Micro Devices, Inc)
S3 BioNTDrv; C:\Program Files\Paragon Software\Backup and Recovery 2014 Free\program\BioNTDrv.SYS [18696 2014-05-09] (Paragon Software GmbH -> Paragon Software Group)
S3 BrSerIb; C:\WINDOWS\system32\DRIVERS\BrSerIb.sys [284160 2012-03-27] (Microsoft Windows Hardware Compatibility Publisher -> Brother Industries Ltd.)
S3 BrUsbSIb; C:\WINDOWS\system32\DRIVERS\BrUsbSIb.sys [15360 2011-07-19] (Microsoft Windows Hardware Compatibility Publisher -> Brother Industries Ltd.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2023-12-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [42040 2025-10-14] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 johci; C:\WINDOWS\System32\drivers\johci.sys [26208 2012-07-16] (JMicron Technology Corp. -> JMicron Technology Corp.)
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333216 2025-09-22] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [231504 2025-02-03] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-12-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [201280 2025-10-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [78928 2025-10-15] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239568 2024-09-06] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [189776 2025-10-15] (Malwarebytes Inc. -> Malwarebytes)
R3 SNP2UVCW10; C:\WINDOWS\system32\DRIVERS\snp2uvcW10.sys [2530920 2015-12-21] (Sonix Technology CO., LTD -> Sonix Tech. Co., Ltd.)
R3 STHDA; C:\WINDOWS\system32\DRIVERS\stwrt64.sys [542208 2012-08-19] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
R1 UimBus; C:\WINDOWS\System32\drivers\UimBus.sys [102664 2014-05-09] (Paragon Software GmbH -> )
R1 Uim_DEVIM; C:\WINDOWS\System32\drivers\uim_devim.sys [25992 2014-05-09] (Paragon Software GmbH -> )
R1 Uim_IM; C:\WINDOWS\System32\drivers\uim_im.sys [700296 2014-05-09] (Paragon Software GmbH -> )
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [20880 2025-09-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [627104 2025-09-22] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102816 2025-09-22] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [34944 2018-05-11] (HP Inc. -> HP)
S3 hsstap; \SystemRoot\System32\drivers\hsstap.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2025-10-15 23:26 - 2025-10-15 23:37 - 000028531 _____ C:\Users\gsegebade\Downloads\FRST.txt
2025-10-15 23:22 - 2025-10-15 23:32 - 000000000 ____D C:\FRST
2025-10-15 23:21 - 2025-10-15 23:21 - 002442752 _____ (Farbar) C:\Users\gsegebade\Downloads\FRST64 (1).exe
2025-10-15 23:20 - 2025-10-15 23:21 - 002442752 _____ (Farbar) C:\Users\gsegebade\Downloads\FRST64.exe
2025-10-15 17:13 - 2025-10-15 17:13 - 000189776 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2025-10-14 01:19 - 2025-10-15 08:00 - 000000000 ____D C:\ProgramData\HitmanPro
2025-10-14 01:16 - 2025-10-14 01:17 - 014292512 _____ (Sophos B.V.) C:\Users\gsegebade\Downloads\HitmanPro_x64.exe
2025-10-06 04:15 - 2025-10-06 04:15 - 000000000 ____D C:\Users\gsegebade\AppData\LocalLow\Temp
2025-10-02 12:57 - 2025-10-06 03:08 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2025-09-22 12:13 - 2025-09-22 12:13 - 000017698 _____ C:\Users\gsegebade\Downloads\registrants2025 - 2025-09-22T121259.954.csv
2025-09-22 12:02 - 2025-10-15 13:02 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2025-09-16 09:21 - 2025-10-15 09:09 - 000003590 _____ C:\WINDOWS\system32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2619967780-3706259895-3790722038-1001
2025-09-16 09:21 - 2025-10-15 09:09 - 000003530 _____ C:\WINDOWS\system32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2619967780-3706259895-3790722038-1001
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2025-10-15 22:56 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-10-15 22:49 - 2020-08-19 16:51 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-10-15 17:17 - 2023-10-17 13:04 - 000000000 ____D C:\ProgramData\WZUpdateNotifier.exe
2025-10-15 17:16 - 2023-12-18 13:16 - 000000000 ____D C:\Users\gsegebade\AppData\Local\Malwarebytes
2025-10-15 09:02 - 2014-08-04 12:35 - 000000000 __SHD C:\Users\gsegebade\IntelGraphicsProfiles
2025-10-15 08:07 - 2021-12-16 02:00 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-10-15 08:07 - 2020-08-19 17:24 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-10-15 08:07 - 2020-08-19 16:51 - 000008192 ___SH C:\DumpStack.log.tmp
2025-10-15 08:07 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2025-10-15 08:06 - 2019-12-07 05:03 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2025-10-15 08:00 - 2014-08-04 14:37 - 000000000 ____D C:\Users\gsegebade\AppData\Roaming\Microsoft\MMC
2025-10-14 21:46 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-10-14 21:46 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-10-14 20:48 - 2020-08-19 17:24 - 000004168 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{013DED0C-3E36-441D-A943-4427A0485CA4}
2025-10-13 21:38 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-10-13 21:22 - 2025-02-08 00:19 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2619967780-3706259895-3790722038-1001
2025-10-13 21:22 - 2021-12-11 18:03 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2619967780-3706259895-3790722038-1001
2025-10-13 21:22 - 2020-08-19 17:24 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2619967780-3706259895-3790722038-1001
2025-10-13 21:22 - 2020-08-19 16:54 - 000002436 _____ C:\Users\gsegebade\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-10-13 21:17 - 2018-01-24 12:08 - 000000000 ____D C:\Users\gsegebade\AppData\Local\Packages
2025-10-13 20:48 - 2021-12-16 01:47 - 000000000 ____D C:\Users\gsegebade\AppData\Local\CrashDumps
2025-10-13 19:06 - 2018-03-22 21:55 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-10-13 19:06 - 2018-03-22 21:55 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-10-13 10:03 - 2020-08-19 17:24 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-10-13 10:03 - 2020-08-19 17:24 - 000003410 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-10-09 09:28 - 2022-02-08 23:02 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-10-07 17:40 - 2014-08-10 16:22 - 000000000 ____D C:\Users\gsegebade\AppData\Roaming\Microsoft\Word
2025-10-07 14:17 - 2014-08-10 16:23 - 000000000 ____D C:\Users\gsegebade\AppData\Roaming\Microsoft\Proof
2025-10-06 04:15 - 2014-08-07 01:07 - 000000000 ____D C:\Users\gsegebade\AppData\LocalLow\Adobe
2025-10-06 03:08 - 2014-08-04 22:47 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-10-04 11:14 - 2017-02-02 22:36 - 000001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-10-03 11:09 - 2014-08-04 22:47 - 000002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2025-10-01 14:32 - 2022-10-11 15:01 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2025-09-23 12:05 - 2020-08-19 17:10 - 000842418 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-09-23 12:05 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2025-09-23 11:57 - 2020-08-19 16:54 - 000000000 ____D C:\Users\gsegebade
2025-09-21 23:53 - 2018-02-13 18:40 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-10-2025
Ran by gsegebade (15-10-2025 23:48:53)
Running from C:\Users\gsegebade\Downloads
Microsoft Windows 10 Pro Version 22H2 19045.6332 (X64) (2020-08-19 21:26:26)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-2619967780-3706259895-3790722038-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2619967780-3706259895-3790722038-503 - Limited - Disabled)
gsegebade (S-1-5-21-2619967780-3706259895-3790722038-1001 - Administrator - Enabled) => C:\Users\gsegebade
Guest (S-1-5-21-2619967780-3706259895-3790722038-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2619967780-3706259895-3790722038-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 25.001.20756 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601120}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\{F24F876B-7D71-4BD6-88E9-614D3BB84231}) (Version: 1.7.31.0 - Alcor Micro Corp.) Hidden
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\SZCCID) (Version: 1.7.31.0 - Alcor Micro Corp.)
Apple Application Support (32-bit) (HKLM-x32\...\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1189.1 - AVAST Software) Hidden
AVG Update Helper (HKLM-x32\...\{EDB7AEE7-E932-4836-AE50-D3B0B7766CB5}) (Version: 1.8.1188.1 - AVG Technologies) Hidden
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version:  - Broadcom Corporation)
Broadcom Bluetooth Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.2100 - Broadcom Corporation)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 141.0.7390.77 - Google LLC)
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Hard Disk Scrubber 3.4 (Remove Only) (HKLM-x32\...\{DE47ADD1-B82B-4B52-AF29-76AE7EF4E19D}_is1) (Version:  - Summit Computer Networks, Inc.)
HP 3D DriveGuard (HKLM\...\{C35A147C-5037-443A-9BF8-A5E7C2154CE4}) (Version: 5.1.7.1 - Hewlett-Packard Company)
HP HD Webcam Driver (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1111.0_WHQL - Sonix)
HP Hotkey Support (HKLM-x32\...\{C97CC14E-4789-4FC5-BC75-79191F7CE009}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.6.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.6.1002 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{977D1ABF-4089-4CA7-BA33-CC75808B7ACE}) (Version: 1.24.738.1 - Intel Corporation) Hidden
JMicron 1394 Filter Driver (HKLM-x32\...\{13C96625-28E4-4c58-ADE0-CDAFC64752EB}) (Version: 1.00.25.03 - JMicron Technology Corp.)
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.76.1 - JMicron Technology Corp.)
LG AirDrive (HKLM-x32\...\{8137B0B3-043B-415D-9095-172CA399D785}) (Version: 3.1.1 - LG Electronics)
LG Bridge (HKLM-x32\...\LG Bridge) (Version: 1.2.46 - LG Electronics)
LG Mobile Drivers (HKLM-x32\...\{C3C008A7-D4A5-4E19-B0D6-72043D6EFE34}) (Version: 4.2.0 - LG Electronics)
Malwarebytes version 4.6.17.334 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.17.334 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 141.0.3537.71 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 141.0.3537.71 - Microsoft Corporation) Hidden
Microsoft Office 2000 SR-1 Professional (HKLM-x32\...\{00010409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.3821 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2619967780-3706259895-3790722038-1001\...\OneDriveSetup.exe) (Version: 25.179.0914.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 143.0.4 (x64 en-US)) (Version: 143.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 143.0.4.287 - Mozilla)
Mozilla Thunderbird ESR (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 140.3.1 ESR (x86 en-US)) (Version: 140.3.1 - Mozilla)
Paragon Backup and Recovery™ 2014 Free (HKLM\...\{C268B5E1-A5DA-11DF-A289-005056C00008}) (Version: 90.00.0003 - Paragon Software)
RealNetworks - Microsoft Visual C++ 2008 Runtime (HKLM-x32\...\{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}) (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM-x32\...\{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}) (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\...\RealPlayer 22.0) (Version: 22.0.5 - RealNetworks)
Roadkil's Unstoppable Copier Version 5.2 (HKLM-x32\...\{A306FD29-7D3A-4287-91AC-9A0180931395}_is1) (Version:  - Roadkil.Net)
SSOption (HKLM-x32\...\Obvious Gokyhe) (Version: 2.6.4.8 - Obvious Gokyhe) <==== ATTENTION
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.19.63 - Synaptics Incorporated)
TightVNC (HKLM\...\{D2372F87-7DA2-47F7-A102-AF2181B8EAA2}) (Version: 2.7.10.0 - GlavSoft LLC.)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
UpdateService (HKLM-x32\...\{E3AE96D6-E196-45B4-AF62-2B41998B9E37}) (Version: 1.0.0 - RealNetworks, Inc.) Hidden
Validity Fingerprint Sensor Driver (HKLM\...\{AA51ED2E-DCE7-415F-9C32-CB9B561D216D}) (Version: 4.4.228.0 - Validity Sensors, Inc.)
vc2012_redist (HKLM-x32\...\{9402AEF2-5981-4097-8BE2-6501DAC4DBFD}) (Version: 1.0.0.0 - Realnetworks) Hidden
vs2015_redist x86 (HKLM-x32\...\{BD46163A-0331-4A61-B65A-7B66D7C93F8E}) (Version: 1.0.0.0 - Realnetworks) Hidden
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
WinZip 26.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C2413B}) (Version: 26.0.14610 - Corel Corporation)
Zoom (HKU\S-1-5-21-2619967780-3706259895-3790722038-1001\...\ZoomUMX) (Version: 5.0 - Zoom Video Communications, Inc.)
 
Packages:
=========
Adobe Acrobat Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC [2025-10-01] ()
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-08] (Autodesk Inc.)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.303.100.0_x64__kgqvnymyfvs32 [2025-10-01] (king.com)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa [2025-09-17] (Apple Inc.) [Startup Task]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
MSN Food & Drink -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-20] (Microsoft Corporation) [MS Ad]
MSN Health & Fitness -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-20] (Microsoft Corporation) [MS Ad]
MSN Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-20] (Microsoft Corporation) [MS Ad]
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-01-12] (Microsoft Corporation)
Spotify - Music and Podcasts -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0 [2025-10-08] (Spotify AB) [Startup Task]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2021-06-11] (Twitter Inc.)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2619967780-3706259895-3790722038-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> C:\Users\gsegebade\AppData\Local\Microsoft\OneDrive\25.179.0914.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2619967780-3706259895-3790722038-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel® pGFX -> Intel Corporation)
CustomCLSID: HKU\S-1-5-21-2619967780-3706259895-3790722038-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> C:\Users\gsegebade\AppData\Local\Microsoft\OneDrive\25.179.0914.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Acrobat Elements\ContextMenuShim64.dll [2025-09-08] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2021-08-20] (Corel Corporation -> WinZip Computing)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-12-18] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => c:\program files (x86)\real\realplayer\RPDS\Bin64\rpcontextmenu.dll [2023-12-13] (RealNetworks, Inc. -> RealNetworks, Inc.)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2021-08-20] (Corel Corporation -> WinZip Computing)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-04] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-12-18] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2021-08-20] (Corel Corporation -> WinZip Computing)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\gsegebade\Desktop\Connect To Allen.lnk -> C:\Users\gsegebade\Documents\vnc.bat ()
 
==================== Loaded Modules (Whitelisted) =============
 
2025-04-24 18:09 - 2025-04-24 18:09 - 000016384 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\ca77ca24950058a8201fc3115a88bb89\PSIClient.ni.dll
2025-04-24 18:09 - 2025-04-24 18:09 - 000019968 _____ (Intel Corp.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\IAStorCommon\67c6a76790f7edb26f333824dea1b8c9\IAStorCommon.ni.dll
2014-08-04 15:45 - 2012-08-27 21:04 - 000269312 ____R (Intel Corporation) [File not signed] [File is in use] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\PsiData.dll
2014-08-04 15:45 - 2012-08-27 21:04 - 000498176 ____R (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\ISDI2.dll
2025-04-24 18:08 - 2025-04-24 18:08 - 000075264 _____ (Intel Corporation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\IAStorDataMgr\ee17ceaad1b57c8d43501d8d0857083a\IAStorDataMgr.ni.dll
2025-09-10 18:16 - 2025-09-10 18:16 - 000380416 _____ (Intel Corporation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\IAStorUtil\84d3fe19e088e9895849eb80ffe36901\IAStorUtil.ni.dll
2025-09-10 18:17 - 2025-09-10 18:17 - 001113088 _____ (Intel Corporation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\IAStorViewModel\a901677bc26c2fb524ad6a9b25265ac6\IAStorViewModel.ni.dll
2025-04-24 18:08 - 2025-04-24 18:08 - 003864576 _____ (Intel Corporation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSI\72a8048242adf94de5108c3496e9be31\PSI.ni.dll
2025-04-24 18:09 - 2025-04-24 18:09 - 000643072 _____ (Intel Corporation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PsiData\936e0d3e337c72d1b2c0feecd75cad76\PsiData.ni.dll
2025-04-24 18:09 - 2025-04-24 18:09 - 000027136 _____ (Microsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\IAStorDataMcfeeca6f#\cf503d636939b578d0940e76c4c9fd39\IAStorDataMgrSvcInterfaces.ni.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\gsegebade\Downloads\FRST64.exe:MBAM.Zone.Identifier [225]
AlternateDataStreams: C:\Users\gsegebade\Downloads\HitmanPro_x64.exe:MBAM.Zone.Identifier [138]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) =============
 
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> c:\program files (x86)\real\realplayer\BrowserRecordPlugin\IE\rndlbrowserrecordplugin64.dll [2023-12-13] (RealNetworks, Inc. -> RealPlayer)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> c:\program files (x86)\real\realplayer\BrowserRecordPlugin\IE\rndlbrowserrecordplugin.dll [2023-12-13] (RealNetworks, Inc. -> RealPlayer)
Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\system\ole db\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation) [File not signed]
Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\system\ole db\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\system\ole db\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\system\ole db\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation) [File not signed]
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\system\ole db\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\system\ole db\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\system\ole db\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation) [File not signed]
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 09:25 - 2020-03-02 11:54 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Network ===========================
 
(Currently there is no automatic fix for this section.)
 
DNS Servers: 192.168.1.254
Windows Firewall is enabled.
 
Network Binding:
=============
Wi-Fi: Broadcom BCM943228HM4L 802.11a/b/g/n 2x2 WiFi Adapter -> bcmwl63a.sys
Ethernet: Intel® 82579V Gigabit Network Connection -> e1c64x64.sys
Bluetooth Network Connection: Bluetooth Device (Personal Area Network) -> bthpan.sys
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Program Files\Broadcom\Broadcom 802.11\Driver;;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\WIDCOMM\Bluetooth Software\;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-2619967780-3706259895-3790722038-1001\Control Panel\Desktop\\Wallpaper -> 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
 
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
HKLM\...\StartupApproved\StartupFolder: => "Microsoft Office.lnk"
HKLM\...\StartupApproved\StartupFolder: => "WinZip Preloader.lnk"
HKLM\...\StartupApproved\Run: => "tvncontrol"
HKLM\...\StartupApproved\Run: => "SysTrayApp"
HKLM\...\StartupApproved\Run: => "WinZip UN"
HKLM\...\StartupApproved\Run32: => "RealDownloader"
HKLM\...\StartupApproved\Run32: => "TkBellExe"
HKLM\...\StartupApproved\Run32: => "RealPlayer"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{DCE6836F-C7D7-4326-887A-16AE2D5D41AC}] => (Allow) C:\Users\gsegebade\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{486D5730-C96B-4AFB-9914-D954B7317DA2}] => (Allow) C:\Users\gsegebade\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{A91AA6BD-ED83-4481-A5CC-EFF3302A3626}] => (Allow) C:\Program Files\TightVNC\tvnserver.exe (GlavSoft LLC. -> GlavSoft LLC.)
FirewallRules: [{59200D1C-C095-479C-9562-43365539658B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D9FB159E-7557-4800-B3F9-5EADA857A916}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{E343F183-0D8C-4DCE-A53A-3C8763555B7B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{279853DD-B167-44B7-9994-1D1F8F682F74}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{939CC2DB-329F-4E05-850E-EC8EF11AD994}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{41348423-F7FB-4AF4-99C5-D69BC2A2907E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C30E7774-CA37-4121-9F28-4F1EFF5B9F25}] => (Allow) C:\Users\gsegebade\AppData\Local\Programs\Opera\82.0.4227.33\opera.exe => No File
FirewallRules: [{3B06537B-C647-4A6E-8695-7B5DC92CE617}] => (Allow) C:\Users\gsegebade\AppData\Local\Programs\Opera\82.0.4227.43\opera.exe => No File
FirewallRules: [{BF44EC83-55A7-4619-B786-32F746D20E63}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe (RealNetworks, Inc. -> RealNetworks, Inc.)
FirewallRules: [{E7F760EA-4653-456C-9618-F77BEB5C9973}] => (Allow) c:\program files (x86)\real\realplayer\RealPlay.exe (RealNetworks, Inc. -> RealNetworks, Inc.)
FirewallRules: [{B683B982-8263-4464-9813-96E510A91310}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{4D34E5E1-6F52-46D7-91B2-0B4B45165A42}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{77F19E06-8812-4D69-A7A6-084E40E76D45}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{002B3B77-D1EC-44B6-99CF-F2712FDF8CEA}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{AB0CC5AC-E8CA-46AF-8F70-CFE97076E344}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{94DBA4B6-13FA-4708-8AD9-975A2FF037C0}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{A5A59620-91EE-40EE-A75E-BB0C47C87921}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{9818B118-092D-4DBE-926C-E881B3EBB570}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{26AFCD19-28D5-43EE-8E49-93E3C71FDC7C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{868AA002-BF2E-4EF2-A225-0856BA60A1FB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{34EDA9DF-027D-4F34-BFFC-E8A17AF8A669}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{A24FBD2C-4D92-4591-832D-F94FBEFA84CD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{3B8291F2-4F68-408A-AC6A-A3DFED30EC6C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{33DEE07F-41D4-46B9-AAF8-75DD0F9CCC11}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{E9198576-35A7-4138-BA5E-87EF3920C40E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B42DF357-8D33-429A-8620-136F94C4FAC0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{0242E8D9-1369-432E-8D60-5DD4FC64FBE5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{66A4B127-430E-43D9-8FC0-11B69EFC8FF2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{ACEB5017-04CF-4E73-B25C-17801CBA842A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1166FEFB-527A-4D1C-B419-BBDB768C296C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{7D5F6E8A-4733-4139-B888-CF44848857FB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.274.477.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{F87F057F-A02C-4EED-B709-BF9BEBF1544E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
 
==================== Faulty Device Manager Devices ============
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (10/15/2025 09:58:20 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on System Reserved because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (10/15/2025 08:05:57 AM) (Source: Microsoft-Windows-Perflib) (EventID: 1000) (User: NT AUTHORITY)
Description: Access to performance data was denied to user "SYSTEM" (value from GetUserName() for the running thread) as attempted from module "c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe" (value from GetModuleFileName() for the binary that issued the query).
 
Error: (10/15/2025 08:04:35 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress..
 
Error: (10/15/2025 08:04:33 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]
 
Error: (10/15/2025 07:58:36 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW.  hr = 0x80070006, The handle is invalid..
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (10/15/2025 07:23:13 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW.  hr = 0x80070006, The handle is invalid..
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (10/15/2025 07:14:59 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied..This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {6caab251-0c85-41f9-acfa-3c1ef8b8a75c}
 
Error: (10/15/2025 02:02:06 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on System Reserved because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
 
System errors:
=============
Error: (10/15/2025 10:34:01 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: A fatal error occurred while creating a TLS client credential. The internal error state is 10013.
 
Error: (10/15/2025 08:04:59 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the FontCache3.0.0.0 service.
 
Error: (10/15/2025 08:04:19 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Windows Update service did not shut down properly after receiving a preshutdown control.
 
Error: (10/15/2025 08:04:03 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Malwarebytes Service service did not shut down properly after receiving a preshutdown control.
 
Error: (10/14/2025 07:19:02 AM) (Source: DCOM) (EventID: 10010) (User: SEGEBADE-01)
Description: The server Microsoft.AAD.BrokerPlugin_1000.19041.4239.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider did not register with DCOM within the required timeout.
 
Error: (10/14/2025 03:10:17 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SensrSvc service.
 
Error: (10/13/2025 10:19:31 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240017: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.439.140.0) - Current Channel (Broad).
 
Error: (10/13/2025 08:43:26 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200b: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.439.140.0) - Current Channel (Broad).
 
 
Windows Defender:
================
Date: 2025-10-09 00:46:02
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
 
Date: 2025-10-08 00:07:55
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
 
Date: 2025-10-07 00:33:13
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
 
Date: 2025-10-06 00:05:45
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
 
Date: 2025-10-05 00:11:10
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
Event[0]:
 
Date: 2025-10-13 20:42:56
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.439.140.0
Previous security intelligence Version: 1.439.45.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.25090.3001
Previous Engine Version: 1.1.25090.3001
Error code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
 
Date: 2025-10-13 20:42:55
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.439.140.0
Previous security intelligence Version: 1.439.45.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.25090.3001
Previous Engine Version: 1.1.25090.3001
Error code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
 
Date: 2025-10-13 10:23:48
Description: 
Microsoft Defender Antivirus service seemed to be hung during shutdown.
Timout (seconds):  120
Component:  CleanupAutoPurge
Self-terminated:  0
 
Date: 2025-10-13 10:10:02
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.439.45.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.25090.3001
Error code: 0x80070020
Error description: The process cannot access the file because it is being used by another process. 
 
Date: 2025-10-13 10:10:02
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.439.45.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.25090.3001
Error code: 0x80070020
Error description: The process cannot access the file because it is being used by another process. 
 
CodeIntegrity:
===============
Date: 2025-10-15 23:20:15
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.
 
Date: 2025-10-15 23:19:34
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: Hewlett-Packard 68ICE Ver. F.42 05/20/2013
Motherboard: Hewlett-Packard 17AB
Processor: Intel® Core™ i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 77%
Total physical RAM: 3975.48 MB
Available physical RAM: 894.56 MB
Total Virtual: 8071.48 MB
Available Virtual: 3231.26 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:464.48 GB) (Free:148.1 GB) (Model: HGST HTS725050A7E630) NTFS
 
\\?\Volume{639678f4-1bff-11e4-be66-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.34 GB) (Free:0.06 GB) NTFS
\\?\Volume{97dbc17c-0000-0000-0000-003574000000}\ () (Fixed) (Total:0 GB) (Free:0 GB) 
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 97DBC17C)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=464.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=955 MB) - (Type=27)
 
==================== End of Addition.txt =======================

 



BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 61,282 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted Yesterday, 08:27 AM

Greetings and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, please keep in mind most of us at BleepingComputer volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
  • It is important to not run any tools or take any steps other than those I will provide for you.
  • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
  • Please copy and paste all logs into your post unless otherwise requested.
  • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
  • If you do not reply to your topic after 5 days I will assume it has been abandoned and I will close it.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

Please allow me some time to review what you have posted.

Lord, to whom shall we go? You have the words of eternal life and we have believed and have come to know that you are the Holy One of God.
John 6:68-69


#3 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 61,282 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted Yesterday, 09:20 AM

Greetings.

The system is about 13 years old so there is only so much we can expect from it. There are some issues we can address but we can only get so far when it comes to performance.

Let's start with this.
 

==================== Memory info ===========================

BIOS: Hewlett-Packard 68ICE Ver. F.42 05/20/2013
Motherboard: Hewlett-Packard 17AB
Processor: Intel® Core i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 77%
Total physical RAM: 3975.48 MB
Available physical RAM: 894.56 MB
Total Virtual: 8071.48 MB
Available Virtual: 3231.26 MB

This is very little available RAM to efficiently run the operating system

===================================================

GSmartControl for Windows - Portable

-------------------
  • Download GSmartControl for Windows - Portable and save it to your desktop
  • Right click on gsmartcontrol.zip icon and select Extract All... then Extract
  • Double click on the gsmartcontrol folder
  • Right click on gsmartcontrol (not .manifest) and select Run as administrator
  • Allow the program to search for and list your hard drive(s)
  • Double click your drive C: drive
  • Go to the Self-tests tab
  • Make sure that the Test Type is set to Short Self-test
  • Click the Execute button
  • After the test completes, click the View Output button and copy and paste the contents in your reply
===================================================

Uninstalling Programs Using Revo Uninstaller Free Portable

--------------------
  • Download Revo Uninstaller Free Portable and save it to your Desktop
  • Right click on the folder and select Extract All..., then click Extract
  • Double click on the RevoUninstaller-Portable folder
  • Right click on RevoUPort and select Run as administrator
  • Click OK on the License Agreement
  • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
SSOption
  • If the program's uninstaller appears work through the steps to remove the program(s)
  • Be sure the Advanced option is selected then click Scan
  • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
  • Once done click Finish
  • Reboot your computer
===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
CreateRestorePoint:
CloseProcesses:
Edge Notifications: Default -> hxxps://74ng76qecrpaf3.webmotion.co.in; hxxps://amgreatness.com; hxxps://cvggq81029pc73dalvu0.visolabala.co.in; hxxps://d10e1r8ko90s73e7e9l0.gms-adguard.co.in; hxxps://d2u8n8ghubcc7389bv70.webmotion.co.in; hxxps://radio.foxnews.com; hxxps://www.accuweather.com; hxxps://www.bandsintown.com; hxxps://www.cbssports.com; hxxps://www.facebook.com; hxxps://www.iheart.com; hxxps://www.usatoday.com
CHR Notifications: Default -> hxxps://odesclub.com; hxxps://www.cbssports.com; hxxps://www.dodgersnation.com; hxxps://www.facebook.com; hxxps://www.newsbreak.com; hxxps://www.pinterest.co.uk; hxxps://www.pinterest.ie
2025-10-06 04:15 - 2025-10-06 04:15 - 000000000 ____D C:\Users\gsegebade\AppData\LocalLow\Temp
SearchScopes: HKLM-x32 -> DefaultScope value is missing
S3 hsstap; \SystemRoot\System32\drivers\hsstap.sys [X] 
Task: {04121FF1-519F-41B5-9086-CB08CCEAEB44} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION 
Task: {29817316-6EED-4776-9481-98BEC6DF328D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION 
Task: {322E5C15-9BEE-46C0-A1F7-D3B00BBC2F16} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION 
Task: {45905824-29C3-4D6B-AC4B-650612DCA01A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION 
Task: {61809F96-8261-4DC1-A055-E3BC2B0DC19C} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION 
Task: {6EC1A5FA-2592-43E9-B043-17FBD61947FD} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION 
Task: {6F6410F5-F0C4-495C-9673-1CEE391102BE} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION 
Task: {7C6F5CB8-DB8C-4E10-ACBF-F9283B0F01CA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION 
Task: {B3BDCB84-A553-40F5-8BAB-94EAC862E720} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION 
Task: {BADBDD3D-8D7D-47CF-A0C7-58C88FC3DFEE} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION 
Task: {CBD402D7-A169-4365-B415-977BB64BF3C0} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION 
Task: {D613EB01-2625-4FD7-979D-2AA9D00B0238} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION 
Task: {EA3528D4-B37F-40FD-98AE-E80B1D68CB20} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION 
Task: {FC4C1DF5-39BA-4A3E-9346-B46ED71EFC34} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION 
Task: {06ACB895-08FC-44D1-A41F-E552F9329ED5} - System32\Tasks\AdwCleaner_onReboot => C:\Users\gsegebade\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\adwcleaner_8.0.2 (1).exe  /r (No File) 
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe  join (No File) 
Task: {AB3285F2-ECE6-43C9-AF8D-45C405C505B7} - System32\Tasks\Opera scheduled Autoupdate 1636817210 => C:\Users\gsegebade\AppData\Local\Programs\Opera\launcher.exe  --scheduledautoupdate $(Arg0) (No File) 
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File) 
FirewallRules: [{DCE6836F-C7D7-4326-887A-16AE2D5D41AC}] => (Allow) C:\Users\gsegebade\AppData\Roaming\Zoom\bin\airhost.exe => No File 
FirewallRules: [{C30E7774-CA37-4121-9F28-4F1EFF5B9F25}] => (Allow) C:\Users\gsegebade\AppData\Local\Programs\Opera\82.0.4227.33\opera.exe => No File 
FirewallRules: [{3B06537B-C647-4A6E-8695-7B5DC92CE617}] => (Allow) C:\Users\gsegebade\AppData\Local\Programs\Opera\82.0.4227.43\opera.exe => No File 
cmd: netsh winsock reset catalog
cmd: netsh int ip reset resetlog.txt
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: bitsadmin /reset /allusers
cmd: ipconfig /flushdns
Removeproxy:
hosts:
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /CheckHealth
Emptytemp:
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • GSmart report
  • Program removed?
  • Fixlog
  • Pop up gone?

Lord, to whom shall we go? You have the words of eternal life and we have believed and have come to know that you are the Holy One of God.
John 6:68-69


#4 adaniel

adaniel
  • Topic Starter

  •  Avatar image
  • Members
  • 214 posts
  • ONLINE
  •  
  • Local time:10:02 AM

Posted Yesterday, 10:36 AM

Thank you very much for your help and your quick response.

I have a similar HP laptop of similar vintage that I use daily. While is isn't super fast by current standards, it has none if the issues this one does, booting up or response time.

I am running the requested apps and will post results; but, for example, the GSmartControl scan, with ETA of 2 min had to be restarted once and took about 50 minutes.

#5 adaniel

adaniel
  • Topic Starter

  •  Avatar image
  • Members
  • 214 posts
  • ONLINE
  •  
  • Local time:10:02 AM

Posted Yesterday, 10:47 AM

Other requested output will be sent as apps complete. 
 
 
smartctl 6.6 2017-11-05 r4594 [x86_64-w64-mingw32-w10-b19045] (sf-6.6-1)
Copyright © 2002-17, Bruce Allen, Christian Franke, www.smartmontools.org
 
=== START OF INFORMATION SECTION ===
Model Family:     Hitachi/HGST Travelstar Z7K500
Device Model:     HGST HTS725050A7E630
Serial Number:    TF0501WJ22WEZZ
LU WWN Device Id: 5 000cca 7c5dd7ecc
Firmware Version: GH2OA440
User Capacity:    500,107,862,016 bytes [500 GB]
Sector Sizes:     512 bytes logical, 4096 bytes physical
Rotation Rate:    7200 rpm
Form Factor:      2.5 inches
Device is:        In smartctl database [for details use: -P show]
ATA Version is:   ACS-2, ATA8-ACS T13/1699-D revision 6
SATA Version is:  SATA 3.0, 3.0 Gb/s (current: 3.0 Gb/s)
Local Time is:    Thu Oct 16 11:32:55 2025 EDT
SMART support is: Available - device has SMART capability.
SMART support is: Enabled
AAM feature is:   Unavailable
APM level is:     128 (minimum power consumption without standby)
Rd look-ahead is: Enabled
Write cache is:   Enabled
DSN feature is:   Unavailable
ATA Security is:  Disabled, frozen [SEC2]
 
=== START OF READ SMART DATA SECTION ===
SMART overall-health self-assessment test result: PASSED
 
General SMART Values:
Offline data collection status:  (0x00) Offline data collection activity
was never started.
Auto Offline Data Collection: Disabled.
Self-test execution status:      (   0) The previous self-test routine completed
without error or no self-test has ever 
been run.
Total time to complete Offline 
data collection: (   45) seconds.
Offline data collection
capabilities: (0x51) SMART execute Offline immediate.
No Auto Offline data collection support.
Suspend Offline collection upon new
command.
No Offline surface scan supported.
Self-test supported.
No Conveyance Self-test supported.
Selective Self-test supported.
SMART capabilities:            (0x0003) Saves SMART data before entering
power-saving mode.
Supports SMART auto save timer.
Error logging capability:        (0x01) Error logging supported.
General Purpose Logging supported.
Short self-test routine 
recommended polling time: (   2) minutes.
Extended self-test routine
recommended polling time: (  88) minutes.
SCT capabilities:        (0x003d) SCT Status supported.
SCT Error Recovery Control supported.
SCT Feature Control supported.
SCT Data Table supported.
 
SMART Attributes Data Structure revision number: 16
Vendor Specific SMART Attributes with Thresholds:
ID# ATTRIBUTE_NAME          FLAGS    VALUE WORST THRESH FAIL RAW_VALUE
  1 Raw_Read_Error_Rate     POSR-K   100   092   062    -    0
  2 Throughput_Performance  P-S--K   100   100   040    -    0
  3 Spin_Up_Time            PO---K   222   100   033    -    1
  4 Start_Stop_Count        -O--CK   096   096   000    -    6771
  5 Reallocated_Sector_Ct   PO--CK   100   100   005    -    112 (0 14)
  7 Seek_Error_Rate         POSR-K   100   098   067    -    0
  8 Seek_Time_Performance   P-S--K   100   100   040    -    0
  9 Power_On_Hours          -O--CK   004   004   000    -    42428
 10 Spin_Retry_Count        PO--CK   100   100   060    -    0
 12 Power_Cycle_Count       -O--CK   096   096   000    -    6753
183 Runtime_Bad_Block       -O--CK   100   100   000    -    0
184 End-to-End_Error        PO--CK   100   100   097    -    0
187 Reported_Uncorrect      -O--CK   100   099   000    -    130717360979969
188 Command_Timeout         -O--CK   100   100   000    -    4295032838
190 Airflow_Temperature_Cel -O---K   051   047   045    -    49 (Min/Max 20/53)
191 G-Sense_Error_Rate      -O--CK   094   094   000    -    1773
192 Power-Off_Retract_Count -O--CK   100   100   000    -    4849738
193 Load_Cycle_Count        -O--CK   001   001   000    -    1124666
196 Reallocated_Event_Count -O--CK   100   100   000    -    14
197 Current_Pending_Sector  -O--CK   100   100   000    -    0
198 Offline_Uncorrectable   ----CK   100   100   000    -    0
199 UDMA_CRC_Error_Count    -OS-CK   100   100   000    -    6
223 Load_Retry_Count        -O-R-K   100   100   000    -    0
                            ||||||_ K auto-keep
                            |||||__ C event count
                            ||||___ R error rate
                            |||____ S speed/performance
                            ||_____ O updated online
                            |______ P prefailure warning
 
General Purpose Log Directory Version 1
SMART           Log Directory Version 1 [multi-sector log support]
Address    Access  R/W   Size  Description
0x00       GPL,SL  R/O      1  Log Directory
0x01           SL  R/O      1  Summary SMART error log
0x02           SL  R/O      1  Comprehensive SMART error log
0x03       GPL     R/O      1  Ext. Comprehensive SMART error log
0x06           SL  R/O      1  SMART self-test log
0x07       GPL     R/O      1  Extended self-test log
0x09           SL  R/W      1  Selective self-test log
0x10       GPL     R/O      1  NCQ Command Error log
0x11       GPL     R/O      1  SATA Phy Event Counters log
0x80-0x9f  GPL,SL  R/W     16  Host vendor specific log
0xe0       GPL,SL  R/W      1  SCT Command/Status
0xe1       GPL,SL  R/W      1  SCT Data Transfer
 
SMART Extended Comprehensive Error Log Version: 1 (1 sectors)
Device Error Count: 7 (device log contains only the most recent 4 errors)
CR     = Command Register
FEATR  = Features Register
COUNT  = Count (was: Sector Count) Register
LBA_48 = Upper bytes of LBA High/Mid/Low Registers ]  ATA-8
LH     = LBA High (was: Cylinder High) Register    ]   LBA
LM     = LBA Mid (was: Cylinder Low) Register      ] Register
LL     = LBA Low (was: Sector Number) Register     ]
DV     = Device (was: Device/Head) Register
DC     = Device Control Register
ER     = Error register
ST     = Status register
Powered_Up_Time is measured from power on, and printed as
DDd+hh:mm:SS.sss where DD=days, hh=hours, mm=minutes,
SS=sec, and sss=millisec. It "wraps" after 49.710 days.
 
Error 7 [2] occurred at disk power-on lifetime: 37992 hours (1583 days + 0 hours)
  When the command that caused the error occurred, the device was active or idle.
 
  After command completion occurred, registers were:
  ER -- ST COUNT  LBA_48  LH LM LL DV DC
  -- -- -- == -- == == == -- -- -- -- --
  84 -- 41 00 01 00 00 18 8e b0 1f 08 00  Error: ICRC, ABRT at LBA = 0x188eb01f = 412004383
 
  Commands leading to the command that caused the error were:
  CR FEATR COUNT  LBA_48  LH LM LL DV DC  Powered_Up_Time  Command/Feature_Name
  -- == -- == -- == == == -- -- -- -- --  ---------------  --------------------
  60 00 40 00 18 00 00 17 c7 e0 88 40 00     02:48:35.779  READ FPDMA QUEUED
  60 00 40 00 30 00 00 05 12 a3 d0 40 00     02:48:35.777  READ FPDMA QUEUED
  60 00 40 00 18 00 00 17 c7 df 70 40 00     02:48:35.772  READ FPDMA QUEUED
  60 00 10 00 10 00 00 19 cd 9b 22 40 00     02:48:35.752  READ FPDMA QUEUED
  60 00 08 00 28 00 00 18 8b 32 48 40 00     02:48:35.730  READ FPDMA QUEUED
 
Error 6 [1] occurred at disk power-on lifetime: 37991 hours (1582 days + 23 hours)
  When the command that caused the error occurred, the device was active or idle.
 
  After command completion occurred, registers were:
  ER -- ST COUNT  LBA_48  LH LM LL DV DC
  -- -- -- == -- == == == -- -- -- -- --
  84 -- 41 00 11 00 00 00 4e 35 ef 00 00  Error: ICRC, ABRT at LBA = 0x004e35ef = 5125615
 
  Commands leading to the command that caused the error were:
  CR FEATR COUNT  LBA_48  LH LM LL DV DC  Powered_Up_Time  Command/Feature_Name
  -- == -- == -- == == == -- -- -- -- --  ---------------  --------------------
  61 00 08 00 30 00 00 00 66 84 90 40 00     01:38:06.984  WRITE FPDMA QUEUED
  60 00 38 00 10 00 00 18 ac 8c c8 40 00     01:38:06.983  READ FPDMA QUEUED
  61 00 08 00 30 00 00 16 00 f2 58 40 00     01:38:06.980  WRITE FPDMA QUEUED
  60 00 38 00 08 00 00 18 ac 8f 70 40 00     01:38:06.970  READ FPDMA QUEUED
  60 00 10 00 00 00 00 19 2b 15 20 40 00     01:38:06.969  READ FPDMA QUEUED
 
Error 5 [0] occurred at disk power-on lifetime: 36826 hours (1534 days + 10 hours)
  When the command that caused the error occurred, the device was active or idle.
 
  After command completion occurred, registers were:
  ER -- ST COUNT  LBA_48  LH LM LL DV DC
  -- -- -- == -- == == == -- -- -- -- --
  84 -- 41 00 01 00 00 16 6f 5d 3f 06 00  Error: ICRC, ABRT at LBA = 0x166f5d3f = 376397119
 
  Commands leading to the command that caused the error were:
  CR FEATR COUNT  LBA_48  LH LM LL DV DC  Powered_Up_Time  Command/Feature_Name
  -- == -- == -- == == == -- -- -- -- --  ---------------  --------------------
  60 00 08 00 00 00 00 16 6f 5d 38 40 00     00:02:51.782  READ FPDMA QUEUED
  60 00 08 00 00 00 00 16 6f 5a 08 40 00     00:02:51.782  READ FPDMA QUEUED
  60 00 08 00 00 00 00 16 6f 59 b0 40 00     00:02:51.781  READ FPDMA QUEUED
  60 00 08 00 00 00 00 16 6f 58 b0 40 00     00:02:51.774  READ FPDMA QUEUED
  60 00 08 00 00 00 00 16 6f 52 10 40 00     00:02:51.771  READ FPDMA QUEUED
 
Error 4 [3] occurred at disk power-on lifetime: 36826 hours (1534 days + 10 hours)
  When the command that caused the error occurred, the device was active or idle.
 
  After command completion occurred, registers were:
  ER -- ST COUNT  LBA_48  LH LM LL DV DC
  -- -- -- == -- == == == -- -- -- -- --
  84 -- 41 00 c1 00 00 00 18 c0 3f 00 00  Error: ICRC, ABRT at LBA = 0x0018c03f = 1622079
 
  Commands leading to the command that caused the error were:
  CR FEATR COUNT  LBA_48  LH LM LL DV DC  Powered_Up_Time  Command/Feature_Name
  -- == -- == -- == == == -- -- -- -- --  ---------------  --------------------
  60 01 00 00 78 00 00 00 18 cd 00 40 00     00:02:48.881  READ FPDMA QUEUED
  60 01 00 00 70 00 00 00 18 cc 00 40 00     00:02:48.881  READ FPDMA QUEUED
  60 01 00 00 68 00 00 00 18 cb 00 40 00     00:02:48.881  READ FPDMA QUEUED
  60 01 00 00 60 00 00 00 18 ca 00 40 00     00:02:48.881  READ FPDMA QUEUED
  60 01 00 00 58 00 00 00 18 c9 00 40 00     00:02:48.881  READ FPDMA QUEUED
 
SMART Extended Self-test Log Version: 1 (1 sectors)
Num  Test_Description    Status                  Remaining  LifeTime(hours)  LBA_of_first_error
# 1  Short offline       Completed without error       00%     42428         -
# 2  Short offline       Completed without error       00%     42427         -
# 3  Extended offline    Completed without error       00%         1         -
 
SMART Selective self-test log data structure revision number 1
 SPAN  MIN_LBA  MAX_LBA  CURRENT_TEST_STATUS
    1        0        0  Not_testing
    2        0        0  Not_testing
    3        0        0  Not_testing
    4        0        0  Not_testing
    5        0        0  Not_testing
Selective self-test flags (0x0):
  After scanning selected spans, do NOT read-scan remainder of disk.
If Selective self-test is pending on power-up, resume after 0 minute delay.
 
SCT Status Version:                  3
SCT Version (vendor specific):       256 (0x0100)
SCT Support Level:                   1
Device State:                        Active (0)
Current Temperature:                    49 Celsius
Power Cycle Min/Max Temperature:     20/53 Celsius
Lifetime    Min/Max Temperature:     10/53 Celsius
Lifetime    Average Temperature:        33 Celsius
Under/Over Temperature Limit Count:   0/0
 
SCT Temperature History Version:     2
Temperature Sampling Period:         1 minute
Temperature Logging Interval:        1 minute
Min/Max recommended Temperature:      0/60 Celsius
Min/Max Temperature Limit:           -40/65 Celsius
Temperature History Size (Index):    128 (54)
 
Index    Estimated Time   Temperature Celsius
  55    2025-10-16 09:25    46  ***************************
  56    2025-10-16 09:26    47  ****************************
  57    2025-10-16 09:27    46  ***************************
 ...    ..( 49 skipped).    ..  ***************************
 107    2025-10-16 10:17    46  ***************************
 108    2025-10-16 10:18    47  ****************************
 ...    ..( 19 skipped).    ..  ****************************
   0    2025-10-16 10:38    47  ****************************
   1    2025-10-16 10:39    48  *****************************
 ...    ..( 10 skipped).    ..  *****************************
  12    2025-10-16 10:50    48  *****************************
  13    2025-10-16 10:51    47  ****************************
  14    2025-10-16 10:52    47  ****************************
  15    2025-10-16 10:53    46  ***************************
  16    2025-10-16 10:54    46  ***************************
  17    2025-10-16 10:55    46  ***************************
  18    2025-10-16 10:56    45  **************************
  19    2025-10-16 10:57    45  **************************
  20    2025-10-16 10:58    45  **************************
  21    2025-10-16 10:59    44  *************************
 ...    ..(  5 skipped).    ..  *************************
  27    2025-10-16 11:05    44  *************************
  28    2025-10-16 11:06    43  ************************
  29    2025-10-16 11:07    44  *************************
 ...    ..(  2 skipped).    ..  *************************
  32    2025-10-16 11:10    44  *************************
  33    2025-10-16 11:11    45  **************************
  34    2025-10-16 11:12    45  **************************
  35    2025-10-16 11:13    45  **************************
  36    2025-10-16 11:14    46  ***************************
 ...    ..(  2 skipped).    ..  ***************************
  39    2025-10-16 11:17    46  ***************************
  40    2025-10-16 11:18    47  ****************************
  41    2025-10-16 11:19    47  ****************************
  42    2025-10-16 11:20    47  ****************************
  43    2025-10-16 11:21    48  *****************************
 ...    ..(  5 skipped).    ..  *****************************
  49    2025-10-16 11:27    48  *****************************
  50    2025-10-16 11:28    49  ******************************
 ...    ..(  3 skipped).    ..  ******************************
  54    2025-10-16 11:32    49  ******************************
 
SCT Error Recovery Control:
           Read:     85 (8.5 seconds)
          Write:     85 (8.5 seconds)
 
Device Statistics (GP/SMART Log 0x04) not supported
 
SATA Phy Event Counters (GP Log 0x11)
ID      Size     Value  Description
0x0001  2            0  Command failed due to ICRC error
0x0002  2            0  R_ERR response for data FIS
0x0003  2            0  R_ERR response for device-to-host data FIS
0x0004  2            0  R_ERR response for host-to-device data FIS
0x0005  2            0  R_ERR response for non-data FIS
0x0006  2            0  R_ERR response for device-to-host non-data FIS
0x0007  2            0  R_ERR response for host-to-device non-data FIS
0x0009  2        65535+ Transition from drive PhyRdy to drive PhyNRdy
0x000a  2            4  Device-to-host register FISes sent due to a COMRESET
0x000b  2            0  CRC errors within host-to-device FIS
0x000d  2            0  Non-CRC errors within host-to-device FIS


#6 adaniel

adaniel
  • Topic Starter

  •  Avatar image
  • Members
  • 214 posts
  • ONLINE
  •  
  • Local time:10:02 AM

Posted Yesterday, 11:39 AM

Revo Uninstaller run

SSOption Uninstalled

 

Advanced scan run, no leftover items found.  

 

System rebooted. Boot was much quicker.  No popups so far.

 

Starting FRST64



#7 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 61,282 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted Yesterday, 04:21 PM

Please be sure to copy and paste the Fixlog.txt report that is created after running the FRST64 in your reply.


Lord, to whom shall we go? You have the words of eternal life and we have believed and have come to know that you are the Holy One of God.
John 6:68-69


#8 adaniel

adaniel
  • Topic Starter

  •  Avatar image
  • Members
  • 214 posts
  • ONLINE
  •  
  • Local time:10:02 AM

Posted Yesterday, 08:13 PM

Thank you for your assistance so far.  As you can see, scan took about 7.5 hrs
 
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 11-10-2025
Ran by gsegebade (16-10-2025 12:42:10) Run:1
Running from C:\Users\gsegebade\Downloads
Loaded Profiles: gsegebade
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CreateRestorePoint:
CloseProcesses:
Edge Notifications: Default -> hxxps://74ng76qecrpaf3.webmotion.co.in; hxxps://amgreatness.com; hxxps://cvggq81029pc73dalvu0.visolabala.co.in; hxxps://d10e1r8ko90s73e7e9l0.gms-adguard.co.in; hxxps://d2u8n8ghubcc7389bv70.webmotion.co.in; hxxps://radio.foxnews.com; hxxps://www.accuweather.com; hxxps://www.bandsintown.com; hxxps://www.cbssports.com; hxxps://www.facebook.com; hxxps://www.iheart.com; hxxps://www.usatoday.com
CHR Notifications: Default -> hxxps://odesclub.com; hxxps://www.cbssports.com; hxxps://www.dodgersnation.com; hxxps://www.facebook.com; hxxps://www.newsbreak.com; hxxps://www.pinterest.co.uk; hxxps://www.pinterest.ie
2025-10-06 04:15 - 2025-10-06 04:15 - 000000000 ____D C:\Users\gsegebade\AppData\LocalLow\Temp
SearchScopes: HKLM-x32 -> DefaultScope value is missing
S3 hsstap; \SystemRoot\System32\drivers\hsstap.sys [X] 
Task: {04121FF1-519F-41B5-9086-CB08CCEAEB44} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION 
Task: {29817316-6EED-4776-9481-98BEC6DF328D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION 
Task: {322E5C15-9BEE-46C0-A1F7-D3B00BBC2F16} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION 
Task: {45905824-29C3-4D6B-AC4B-650612DCA01A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION 
Task: {61809F96-8261-4DC1-A055-E3BC2B0DC19C} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION 
Task: {6EC1A5FA-2592-43E9-B043-17FBD61947FD} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION 
Task: {6F6410F5-F0C4-495C-9673-1CEE391102BE} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION 
Task: {7C6F5CB8-DB8C-4E10-ACBF-F9283B0F01CA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION 
Task: {B3BDCB84-A553-40F5-8BAB-94EAC862E720} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION 
Task: {BADBDD3D-8D7D-47CF-A0C7-58C88FC3DFEE} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION 
Task: {CBD402D7-A169-4365-B415-977BB64BF3C0} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION 
Task: {D613EB01-2625-4FD7-979D-2AA9D00B0238} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION 
Task: {EA3528D4-B37F-40FD-98AE-E80B1D68CB20} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION 
Task: {FC4C1DF5-39BA-4A3E-9346-B46ED71EFC34} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION 
Task: {06ACB895-08FC-44D1-A41F-E552F9329ED5} - System32\Tasks\AdwCleaner_onReboot => C:\Users\gsegebade\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\adwcleaner_8.0.2 (1).exe  /r (No File) 
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe  join (No File) 
Task: {AB3285F2-ECE6-43C9-AF8D-45C405C505B7} - System32\Tasks\Opera scheduled Autoupdate 1636817210 => C:\Users\gsegebade\AppData\Local\Programs\Opera\launcher.exe  --scheduledautoupdate $(Arg0) (No File) 
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File) 
FirewallRules: [{DCE6836F-C7D7-4326-887A-16AE2D5D41AC}] => (Allow) C:\Users\gsegebade\AppData\Roaming\Zoom\bin\airhost.exe => No File 
FirewallRules: [{C30E7774-CA37-4121-9F28-4F1EFF5B9F25}] => (Allow) C:\Users\gsegebade\AppData\Local\Programs\Opera\82.0.4227.33\opera.exe => No File 
FirewallRules: [{3B06537B-C647-4A6E-8695-7B5DC92CE617}] => (Allow) C:\Users\gsegebade\AppData\Local\Programs\Opera\82.0.4227.43\opera.exe => No File 
cmd: netsh winsock reset catalog
cmd: netsh int ip reset resetlog.txt
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: bitsadmin /reset /allusers
cmd: ipconfig /flushdns
Removeproxy:
hosts:
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /CheckHealth
Emptytemp:
End::
*****************
 
Restore point was successfully created.
Processes closed successfully.
"Edge Notifications" => removed successfully
"Chrome Notifications" => removed successfully
 
"C:\Users\gsegebade\AppData\LocalLow\Temp" Folder move:
 
C:\Users\gsegebade\AppData\LocalLow\Temp => moved successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully
HKLM\System\CurrentControlSet\Services\hsstap => removed successfully
hsstap => service removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{04121FF1-519F-41B5-9086-CB08CCEAEB44}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{04121FF1-519F-41B5-9086-CB08CCEAEB44}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{29817316-6EED-4776-9481-98BEC6DF328D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{29817316-6EED-4776-9481-98BEC6DF328D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{322E5C15-9BEE-46C0-A1F7-D3B00BBC2F16}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{322E5C15-9BEE-46C0-A1F7-D3B00BBC2F16}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{45905824-29C3-4D6B-AC4B-650612DCA01A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{45905824-29C3-4D6B-AC4B-650612DCA01A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{61809F96-8261-4DC1-A055-E3BC2B0DC19C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{61809F96-8261-4DC1-A055-E3BC2B0DC19C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6EC1A5FA-2592-43E9-B043-17FBD61947FD}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EC1A5FA-2592-43E9-B043-17FBD61947FD}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F6410F5-F0C4-495C-9673-1CEE391102BE}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F6410F5-F0C4-495C-9673-1CEE391102BE}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7C6F5CB8-DB8C-4E10-ACBF-F9283B0F01CA}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C6F5CB8-DB8C-4E10-ACBF-F9283B0F01CA}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B3BDCB84-A553-40F5-8BAB-94EAC862E720}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B3BDCB84-A553-40F5-8BAB-94EAC862E720}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BADBDD3D-8D7D-47CF-A0C7-58C88FC3DFEE}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BADBDD3D-8D7D-47CF-A0C7-58C88FC3DFEE}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CBD402D7-A169-4365-B415-977BB64BF3C0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CBD402D7-A169-4365-B415-977BB64BF3C0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D613EB01-2625-4FD7-979D-2AA9D00B0238}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D613EB01-2625-4FD7-979D-2AA9D00B0238}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA3528D4-B37F-40FD-98AE-E80B1D68CB20}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA3528D4-B37F-40FD-98AE-E80B1D68CB20}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FC4C1DF5-39BA-4A3E-9346-B46ED71EFC34}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC4C1DF5-39BA-4A3E-9346-B46ED71EFC34}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{06ACB895-08FC-44D1-A41F-E552F9329ED5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06ACB895-08FC-44D1-A41F-E552F9329ED5}" => removed successfully
C:\WINDOWS\System32\Tasks\AdwCleaner_onReboot => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdwCleaner_onReboot" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{352E6CA0-7314-4DF4-89C4-682368D80D57}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{352E6CA0-7314-4DF4-89C4-682368D80D57}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AB3285F2-ECE6-43C9-AF8D-45C405C505B7}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB3285F2-ECE6-43C9-AF8D-45C405C505B7}" => removed successfully
C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1636817210 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 1636817210" => removed successfully
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File) => Error: No automatic fix found for this entry.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DCE6836F-C7D7-4326-887A-16AE2D5D41AC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C30E7774-CA37-4121-9F28-4F1EFF5B9F25}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3B06537B-C647-4A6E-8695-7B5DC92CE617}" => removed successfully
 
========= netsh winsock reset catalog =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
 
========= End of CMD: =========
 
 
========= netsh int ip reset resetlog.txt =========
 
Resetting Compartment Forwarding, OK!
Resetting Compartment, OK!
Resetting Control Protocol, OK!
Resetting Echo Sequence Request, OK!
Resetting Global, OK!
Resetting Interface, OK!
Resetting Anycast Address, OK!
Resetting Multicast Address, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting Potential, OK!
Resetting Prefix Policy, OK!
Resetting Proxy Neighbor, OK!
Resetting Route, OK!
Resetting Site Prefix, OK!
Resetting Subinterface, OK!
Resetting Wakeup Pattern, OK!
Resetting Resolve Neighbor, OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , failed.
Access is denied.
 
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.
 
 
 
========= End of CMD: =========
 
 
========= reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
C:\Firewall.reg => moved successfully
 
========= netsh advfirewall reset =========
 
Ok.
 
 
 
========= End of CMD: =========
 
 
========= netsh advfirewall set allprofiles state ON =========
 
Ok.
 
 
 
========= End of CMD: =========
 
 
========= bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0
BITS administration utility.
© Copyright Microsoft Corp.
 
{76DE45FC-5195-4640-95E9-9D5CB753AEAA} canceled.
{7696965D-0613-44E9-90B4-B1E8F33C2940} canceled.
2 out of 2 jobs canceled.
 
 
========= End of CMD: =========
 
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
 
========= End of CMD: =========
 
 
========= RemoveProxy: =========
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-2619967780-3706259895-3790722038-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-2619967780-3706259895-3790722038-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
 
 
========= End of RemoveProxy: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
========= sfc /scannow =========
 
 
 
Beginning system scan.  This process will take some time.
 
 
 
 
There is a system repair pending which requires reboot to complete.  Restart 
 
Windows and run sfc again.
 
 
 
========= End of CMD: =========
 
 
========= DISM /Online /Cleanup-Image /CheckHealth =========
 
 
Deployment Image Servicing and Management tool
Version: 10.0.19041.3636
 
Image Version: 10.0.19045.6332
 
No component store corruption detected.
The operation completed successfully.
 
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 588791864 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 1409408 B
Windows/system/drivers => 320866343 B
Edge => 0 B
Chrome => 303244140 B
Firefox => 756590281 B
Opera => 16520115 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 148381424 B
systemprofile32 => 148381780 B
LocalService => 157709090 B
NetworkService => 251851206 B
gsegebade => 228837690271 B
 
RecycleBin => 332777709 B
EmptyTemp: => 215.9 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 20:05:33 ====


#9 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 61,282 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted Today, 07:43 AM

Thank you for your effort.
 

Beginning system scan. This process will take some time.
There is a system repair pending which requires reboot to complete. Restart
Windows and run sfc again.

Please run the below to see if the previous reboot resolved the pending repair.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
CloseProcesses:
cmd: sfc /scannow
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Fixlog

Lord, to whom shall we go? You have the words of eternal life and we have believed and have come to know that you are the Holy One of God.
John 6:68-69


#10 adaniel

adaniel
  • Topic Starter

  •  Avatar image
  • Members
  • 214 posts
  • ONLINE
  •  
  • Local time:10:02 AM

Posted Today, 08:56 AM

Thank you for your help.  Scan completed.  Reboot took about two minutes, so much faster.  No popups.


 

Fix result of Farbar Recovery Scan Tool (x64) Version: 11-10-2025
Ran by gsegebade (17-10-2025 08:53:54) Run:2
Running from C:\Users\gsegebade\Downloads
Loaded Profiles: gsegebade
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CloseProcesses:
cmd: sfc /scannow
End::
*****************
 
Processes closed successfully.
 
========= sfc /scannow =========
 
 
 
Beginning system scan.  This process will take some time.
 
 
 
Beginning verification phase of system scan.
 
 
Verification 0% complete.
Verification 1% complete.
Verification 1% complete.
Verification 2% complete.
Verification 2% complete.
Verification 3% complete.
Verification 3% complete.
Verification 4% complete.
Verification 5% complete.
Verification 5% complete.
Verification 6% complete.
Verification 6% complete.
Verification 7% complete.
Verification 7% complete.
Verification 8% complete.
Verification 9% complete.
Verification 9% complete.
Verification 10% complete.
Verification 10% complete.
Verification 11% complete.
Verification 11% complete.
Verification 12% complete.
Verification 13% complete.
Verification 13% complete.
Verification 14% complete.
Verification 14% complete.
Verification 15% complete.
Verification 15% complete.
Verification 16% complete.
Verification 17% complete.
Verification 17% complete.
Verification 18% complete.
Verification 18% complete.
Verification 19% complete.
Verification 19% complete.
Verification 20% complete.
Verification 21% complete.
Verification 21% complete.
Verification 22% complete.
Verification 22% complete.
Verification 23% complete.
Verification 23% complete.
Verification 24% complete.
Verification 24% complete.
Verification 25% complete.
Verification 26% complete.
Verification 26% complete.
Verification 27% complete.
Verification 27% complete.
Verification 28% complete.
Verification 28% complete.
Verification 29% complete.
Verification 30% complete.
Verification 30% complete.
Verification 31% complete.
Verification 31% complete.
Verification 32% complete.
Verification 32% complete.
Verification 33% complete.
Verification 34% complete.
Verification 34% complete.
Verification 35% complete.
Verification 35% complete.
Verification 36% complete.
Verification 36% complete.
Verification 37% complete.
Verification 38% complete.
Verification 38% complete.
Verification 39% complete.
Verification 39% complete.
Verification 40% complete.
Verification 40% complete.
Verification 41% complete.
Verification 42% complete.
Verification 42% complete.
Verification 43% complete.
Verification 43% complete.
Verification 44% complete.
Verification 44% complete.
Verification 45% complete.
Verification 46% complete.
Verification 46% complete.
Verification 47% complete.
Verification 47% complete.
Verification 48% complete.
Verification 48% complete.
Verification 49% complete.
Verification 49% complete.
Verification 50% complete.
Verification 51% complete.
Verification 51% complete.
Verification 52% complete.
Verification 52% complete.
Verification 53% complete.
Verification 53% complete.
Verification 54% complete.
Verification 55% complete.
Verification 55% complete.
Verification 56% complete.
Verification 56% complete.
Verification 57% complete.
Verification 57% complete.
Verification 58% complete.
Verification 59% complete.
Verification 59% complete.
Verification 60% complete.
Verification 60% complete.
Verification 61% complete.
Verification 61% complete.
Verification 62% complete.
Verification 63% complete.
Verification 63% complete.
Verification 64% complete.
Verification 64% complete.
Verification 65% complete.
Verification 65% complete.
Verification 66% complete.
Verification 67% complete.
Verification 67% complete.
Verification 68% complete.
Verification 68% complete.
Verification 69% complete.
Verification 69% complete.
Verification 70% complete.
Verification 71% complete.
Verification 71% complete.
Verification 72% complete.
Verification 72% complete.
Verification 73% complete.
Verification 73% complete.
Verification 74% complete.
Verification 74% complete.
Verification 75% complete.
Verification 76% complete.
Verification 76% complete.
Verification 77% complete.
Verification 77% complete.
Verification 78% complete.
Verification 78% complete.
Verification 79% complete.
Verification 80% complete.
Verification 80% complete.
Verification 81% complete.
Verification 81% complete.
Verification 82% complete.
Verification 82% complete.
Verification 83% complete.
Verification 84% complete.
Verification 84% complete.
Verification 85% complete.
Verification 85% complete.
Verification 86% complete.
Verification 86% complete.
Verification 87% complete.
Verification 88% complete.
Verification 88% complete.
Verification 89% complete.
Verification 89% complete.
Verification 90% complete.
Verification 90% complete.
Verification 91% complete.
Verification 92% complete.
Verification 92% complete.
Verification 93% complete.
Verification 93% complete.
Verification 94% complete.
Verification 94% complete.
Verification 95% complete.
Verification 95% complete.
Verification 96% complete.
Verification 97% complete.
Verification 97% complete.
Verification 98% complete.
Verification 98% complete.
Verification 99% complete.
Verification 99% complete.
Verification 100% complete.
 
 
Windows Resource Protection did not find any integrity violations.
 
 
 
========= End of CMD: =========
 
 
 
The system needed a reboot.
 
==== End of Fixlog 09:25:21 ====





7 user(s) are reading this topic

2 members, 5 guests, 0 anonymous users


    Oh My!, adaniel