Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93098 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Posible rootkit and who knows what else. [Solved]

win10 rootkit crypto help cryptominer

  • This topic is locked This topic is locked
37 replies to this topic

#16 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 13 May 2020 - 08:29 AM

Internet still feels funny
Most of the times it fix itself after I reboot

What exactly is wrong with the Internet?

 

Is it the same with all browsers or just one?


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

    Advertisements

Register to Remove


#17 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 13 May 2020 - 11:25 AM

A lot of stuff.-

There are huge speed and signal drops every now and then.

 

For example sometimes downloading stuff from google drive can range from 5mbps to 100kbps constant with no inbetween. So downloading a 5gb file can take to a whole day or just 5 minutes.

I ran a command for checking packet losses in my connection sometime ago and from 20 packets sent, between 5-8 were lost; sometimes this doesn't happen at all or there are 1 or 2 at most and it's very irregular.

Sometimes I can go 2 or 3 days with no problems at all and sometimes for weeks.

Speedtest are mostly consistent because how am I going to run one when there are signal drops haha

 

It is the same with every browser and even when using ethernet cable. I'm practically at 1 meter from my router anyway so there's no real obstacle in between.

There are several connections on my router (phones and a couple of other computers) but it is only this one that works so inconsistently.

I managed to take 2 screenshot of status when signal goes off completely.

2020-05-13-12-48-05-Estado-de-Wi-Fi.png2020-05-13-12-48-24-Estado-de-Wi-Fi.png

As you can see in both of them signal went fully down with 144kbps speed and then it fixed itself like 10 seconds later with a full signal and average speed.

I ran Xirrus once and from what I can remember signal strength goes down to almost -90 dBm but it's around -40 and -55 in general.

I also remember being the only one on channel 1, the only with that frequency on my area, and that's where my wifi knowledge ends tbh



#18 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 13 May 2020 - 01:42 PM

Do you use Jackett or was this one that was put on the computer by your friend?


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#19 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 13 May 2020 - 02:54 PM

I never used so I didn't know what it was. I uninstalled and rebooted but problem persist.

 

Btw, I looked up the network adapter (Broadcom BCM43142) and it looks like it is a generalized problem with windows 10. It is also deprecated both by win10 and HP so there are no real updates to the drivers and installing them from the broadcom site is a gamble as some people say it works but most say it doesn't

I guess i'll have to invest into an adapter or something



#20 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 13 May 2020 - 03:12 PM

Did you uninstall Jackett using Revo Uninstaller, (RU)?

 

I still don't see that the Broadcom driver is the problem.

 

Can you use RU again and uninstall everything that you don't use/need as there are some pretty demanding programmes on your computer.Also, I'd like to check for any leftovers because I'm not sure that all the Jackett files will be gone unless you uninstalled in safe mode. There are also a few other entries that I missed with the last fix.

 

When you've uninstalled all you want to, please run FRST again with a checmark next to Addition.txt.

 

Satchfan


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#21 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 13 May 2020 - 04:18 PM

Hello again.

Yeah I said the stuff about the driver only because the most common solution (even from the official support forums) is "update your drivers" but in this case is not possible haha

I uninstalled everything I don't use and some more.

Can't post FRST.txt because it is too long again, here's on a pastebin: https://pastebin.com/9eCxv3ig

 

Here's Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-05-2020 01
Ran by noise (13-05-2020 17:56:35)
Running from C:\Users\noise\Desktop
Windows 10 Home Single Language Version 1909 18363.836 (X64) (2020-04-29 13:49:57)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

57AECC5B0E0845CFB4AF (S-1-5-21-1886559292-1678889598-4243398580-1009 - Limited - Enabled)
7FD2B45C44BD4925B5EB (S-1-5-21-1886559292-1678889598-4243398580-1005 - Limited - Enabled)
82C6BAB72B714A64A242 (S-1-5-21-1886559292-1678889598-4243398580-1003 - Limited - Enabled)
Administrador (S-1-5-21-1886559292-1678889598-4243398580-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1886559292-1678889598-4243398580-1002 - Limited - Enabled)
DefaultAccount (S-1-5-21-1886559292-1678889598-4243398580-503 - Limited - Disabled)
Invitado (S-1-5-21-1886559292-1678889598-4243398580-501 - Limited - Disabled)
noise (S-1-5-21-1886559292-1678889598-4243398580-1001 - Administrator - Enabled) => C:\Users\noise
WDAGUtilityAccount (S-1-5-21-1886559292-1678889598-4243398580-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 18.05 (x64) (HKLM\...\7-Zip) (Version: 18.05 - Igor Pavlov)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.303 - Adobe)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Asistente para actualización a Windows 10 (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22899 - Microsoft Corporation)
Blender (HKLM\...\{EDFAE2A8-E73B-4CD1-9648-46A7E4434BDA}) (Version: 2.82.1 - Blender Foundation)
Branding64 (HKLM\...\{EE2AFCE4-0238-4DE0-A140-1647021627C1}) (Version: 1.00.0001 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.49 - Piriform)
Cheat Engine 6.8.1 (HKLM-x32\...\Cheat Engine 6.8.1_is1) (Version:  - Cheat Engine)
Discord (HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\Discord) (Version: 0.0.306 - Discord Inc.)
Epic Games Launcher (HKLM-x32\...\{C69A2919-0662-4390-9418-67C931B44C18}) (Version: 1.1.236.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 9.3.0.10826 - Foxit Software Inc.)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Greenshot 1.2.10.6 (HKLM\...\Greenshot_is1) (Version: 1.2.10.6 - Greenshot)
Hextech Repair Tool (HKLM-x32\...\{7F9A97E6-E666-11E5-B582-B88687E82322}) (Version:  - )
HP Support Solutions Framework (HKLM-x32\...\{EA6A1ABF-8D4C-432A-AF6C-84738319C2D7}) (Version: 12.15.14.3 - HP Inc.)
HxD Hex Editor 2.3 (HKLM\...\HxD_is1) (Version: 2.3 - Maël Hörz)
IL Shared Libraries (HKLM-x32\...\IL Shared Libraries) (Version:  - Image-Line)
Java 8 Update 251 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180251F0}) (Version: 8.0.2510.8 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKLM-x32\...\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc)
LibreOffice 6.1.3.2 (HKLM\...\{70F02214-8FF6-48DF-AF3E-7D1A5F7A6BAC}) (Version: 6.1.3.2 - The Document Foundation)
Microsoft SQL Server Compact 4.0 x64 ENU (HKLM\...\{8424B163-D1E0-48B7-88A2-C7A61767B3D7}) (Version: 4.0.8482.1 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\...\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Minion (HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\{Minion}}_is1) (Version: 3.0 - Good Game Mods LLC)
ModDrop Client (HKLM-x32\...\{96A8DB5D-3BA9-4AE0-8285-965E1A288023}) (Version: 1.3.1524 - Olympus Games) Hidden
ModDrop Client (HKLM-x32\...\ModDrop Client 1.3.1524) (Version: 1.3.1524 - Olympus Games)
Mozilla Firefox 76.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 76.0.1 (x64 en-US)) (Version: 76.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 63.0.3 - Mozilla)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.7.1 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{1C4551A6-4743-4093-91E4-1477CD655043}) (Version: 9.09.0203 - NVIDIA Corporation)
OEM Application Profile (HKLM-x32\...\{B4B7FD8F-06FC-E277-4F29-8F75F8281D8F}) (Version: 1.00.0000 - Nombre de su organización) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 1.7.18958 - Kakao Corp.)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Rayman Legends (HKLM-x32\...\Uplay Install 410) (Version:  - Ubisoft)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8395 - Realtek Semiconductor Corp.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.3.31.31 - Synaptics Incorporated)
The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 2.6.3.0 - Zenimax Online Studios)
UE4 Prerequisites (x64) (HKLM-x32\...\{4e242cc8-5e3c-4b08-9d55-dbc62ddd1208}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{3BAE4496-6F6C-4330-A8AA-B93D3D346FA5}) (Version: 2.53.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{F339C545-24DC-4870-AA32-6EB6B0500B95}) (Version: 1.24.0.0 - Microsoft Corporation) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 98.0 - Ubisoft)
WinDirStat 1.1.2 (HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\WinDirStat) (Version:  - )
WinRAR 5.90 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.90.0 - win.rar GmbH)
XnView 2.47 (HKLM-x32\...\XnView_is1) (Version: 2.47 - Gougelet Pierre-e)

Packages:
=========
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2020-04-29] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x86__8wekyb3d8bbwe [2018-11-18] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.96.725.0_x64__mcm4njqhnhss8 [2020-04-10] (Netflix, Inc.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1886559292-1678889598-4243398580-1001_Classes\CLSID\{C591CFEA-E432-495d-A0BE-58E4CCD87B17}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2019-06-16] (Notepad++ -> )
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-11-17 23:30 - 2018-11-17 23:17 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

2019-06-18 19:59 - 2019-06-18 19:59 - 000000375 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> %INTEL_DEV_REDIST%redist\ia32\compiler;%INTEL_DEV_REDIST%redist\intel64\compiler;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\noise\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 1.1.1.1 - 1.0.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: AUEPLauncher => 2
MSCONFIG\Services: SynTPEnhService => 2
MSCONFIG\Services: tbaseprovisioning => 2
HKLM\...\StartupApproved\Run: => "DigidesignMMERefresh"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "CyberGhost"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{05F46053-1BB9-4E3C-8D5B-C6C601F05CA3}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{2FB59D60-746B-4EB1-8BBB-558ECFE0B953}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{850C0B6B-5D01-41EC-BB63-2D8927C5AC0D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{DDC6162C-0D06-4B60-84ED-C5184606206F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{465FA925-BF6B-46CB-B644-999AC23CBE7D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DFO\NeopleLauncher.exe (NEOPLE INC. -> Neople)
FirewallRules: [{64B7BACF-61EE-4A98-827A-262C2A03588B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DFO\NeopleLauncher.exe (NEOPLE INC. -> Neople)
FirewallRules: [TCP Query User{ED621430-E962-4142-ACD8-D22E6AF5A11B}C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe] => (Allow) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
FirewallRules: [UDP Query User{B5A80A84-E93E-4D17-A818-0370EB45D1B9}C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe] => (Allow) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
FirewallRules: [{395BB7DF-20B8-4763-A34D-2707A13EE4EC}] => (Block) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
FirewallRules: [{3B20ECA2-015C-41C8-A9CB-03984175A804}] => (Block) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File

==================== Restore Points =========================

12-05-2020 20:34:11 Punto de control programado

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (05/13/2020 05:40:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: AUDIODG.EXE, versión: 10.0.18362.836, marca de tiempo: 0x3b8d781d
Nombre del módulo con errores: unknown, versión: 0.0.0.0, marca de tiempo: 0x00000000
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x0000000000000000
Identificador del proceso con errores: 0xa98
Hora de inicio de la aplicación con errores: 0x01d6296f2d00ad06
Ruta de acceso de la aplicación con errores: C:\WINDOWS\system32\AUDIODG.EXE
Ruta de acceso del módulo con errores: unknown
Identificador del informe: 80549409-922b-4b16-b180-8457b0fc6696
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:

Error: (05/13/2020 04:45:24 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (9592,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (05/13/2020 04:26:49 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (9672,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (05/13/2020 04:07:06 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (8428,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (05/13/2020 03:55:32 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2604,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (05/13/2020 03:48:26 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al llamar a la rutina CoCreateInstance. HR = 0x8007045b, Se está cerrando el sistema.
.

Error: (05/13/2020 03:48:26 PM) (Source: VSS) (EventID: 13) (User: )
Description: Información del Servicio de instantáneas de volumen: el servidor COM con CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} y el nombre CEventSystem no puede iniciarse. [0x8007045b, Se está cerrando el sistema.
]

Error: (05/13/2020 01:13:21 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1588,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.


System errors:
=============
Error: (05/13/2020 03:49:09 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: El controlador de dispositivo para el Módulo de plataforma segura (TPM) encontró en el hardware de TPM un error irrecuperable que impide que se usen los servicios de TPM (como el cifrado de datos). Para obtener más ayuda, póngase en contacto con el fabricante del equipo.

Error: (05/13/2020 05:09:42 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Error de instalación: error de Windows al instalar la siguiente actualización, error 0x8024001e: Actualización de inteligencia de seguridad para Microsoft Defender Antivirus - KB2267602 (Versión 1.315.554.0).

Error: (05/13/2020 04:50:27 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio ModDrop Client terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 60000 milisegundos: Reiniciar el servicio.

Error: (05/13/2020 04:48:31 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: El servicio Agente de supervisión en tiempo de ejecución de Protección del sistema no respondió después de iniciar.

Error: (05/13/2020 04:43:28 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: El servicio Administrador de mapas descargados no respondió después de iniciar.

Error: (05/13/2020 04:41:16 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: El servicio Servicio de plataforma de dispositivos conectados no respondió después de iniciar.

Error: (05/13/2020 04:35:34 AM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)
Description: El controlador de dispositivo para el Módulo de plataforma segura (TPM) encontró en el hardware de TPM un error irrecuperable que impide que se usen los servicios de TPM (como el cifrado de datos). Para obtener más ayuda, póngase en contacto con el fabricante del equipo.

Error: (05/12/2020 11:04:43 PM) (Source: Microsoft-Windows-BitLocker-Driver) (EventID: 24620) (User: DESKTOP-PA5UUBL)
Description: Comprobar volumen cifrado: no se puede leer la información de volumen en D:.


Windows Defender:
===================================
Date: 2020-05-13 13:05:52.575
Description:
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {85032B53-8757-4294-ACBC-0F6CAAD3678B}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-05-10 23:26:28.725
Description:
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {E7E351C9-3258-4596-8BD8-9773C5CFABFA}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-05-10 23:23:26.785
Description:
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {15B559F9-0486-4F00-91CB-11E63886A60B}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-05-10 23:22:55.876
Description:
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {44EB7A83-6FF6-4952-9CCD-7DDB0F3C6BF9}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-05-10 23:19:49.884
Description:
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {A880F98A-AA76-4B35-981E-8ED8997042FA}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-05-13 12:25:02.016
Description:
Antivirus de Windows Defender encontró un error al intentar cargar la inteligencia de seguridad e intentará revertir a una versión que sepa que es correcta.
Inteligencia de seguridad intentada: Actual
Código de error: 0x80070002
Descripción del error: El sistema no puede encontrar el archivo especificado.
Versión de inteligencia de seguridad: 0.0.0.0;0.0.0.0
Versión del motor: 0.0.0.0

Date: 2020-05-02 19:16:27.860
Description:
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad:
Versión anterior de inteligencia de seguridad: 1.313.2802.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión actual del motor:
Versión anterior del motor: 1.1.16900.4
Código de error: 0x8050a003
Descripción del error: Este paquete no contiene archivos de definición actualizados para este programa. Para obtener más información, consulte Ayuda y soporte técnico.

Date: 2020-05-02 19:16:27.858
Description:
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad:
Versión anterior de inteligencia de seguridad: 1.313.2802.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de inteligencia de seguridad: AntiSpyware
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión actual del motor:
Versión anterior del motor: 1.1.16900.4
Código de error: 0x8050a003
Descripción del error: Este paquete no contiene archivos de definición actualizados para este programa. Para obtener más información, consulte Ayuda y soporte técnico.

Date: 2020-05-02 19:16:27.858
Description:
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad:
Versión anterior de inteligencia de seguridad: 1.313.2802.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión actual del motor:
Versión anterior del motor: 1.1.16900.4
Código de error: 0x8050a003
Descripción del error: Este paquete no contiene archivos de definición actualizados para este programa. Para obtener más información, consulte Ayuda y soporte técnico.

Date: 2020-04-30 22:29:18.945
Description:
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad:
Versión anterior de inteligencia de seguridad: 1.313.2582.0
Origen de actualización: Servidor de Microsoft Update
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión actual del motor:
Versión anterior del motor: 1.1.16900.4
Código de error: 0x80070102
Descripción del error: Tiempo de espera de la operación de espera agotado.

CodeIntegrity:
===================================

Date: 2020-05-11 18:49:33.963
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2020-05-11 00:42:54.430
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2020-05-11 00:42:54.367
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2020-05-10 23:49:42.144
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2020-05-10 23:49:41.875
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2020-05-10 23:47:47.072
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.2004.6-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2020-05-10 23:47:46.883
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.2004.6-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2020-05-10 23:47:46.812
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.2004.6-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

==================== Memory info ===========================

BIOS: Insyde F.1F 12/01/2015
Motherboard: HP 80CC
Processor: AMD A8-7410 APU with AMD Radeon R5 Graphics
Percentage of memory in use: 44%
Total physical RAM: 7113.01 MB
Available physical RAM: 3972.01 MB
Total Virtual: 15113.01 MB
Available Virtual: 11892.5 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:464.32 GB) (Free:218.19 GB) NTFS

\\?\Volume{40d65e13-9ff3-4fb1-b356-3c10208a8557}\ (Recuperación) (Fixed) (Total:0.49 GB) (Free:0.47 GB) NTFS
\\?\Volume{7083d3c3-f4c0-4aa4-a1a8-a8a4b3010d35}\ () (Fixed) (Total:0.84 GB) (Free:0.27 GB) NTFS
\\?\Volume{ab17253a-2b65-476e-bda0-3d30a8c0f683}\ () (Fixed) (Total:0.09 GB) (Free:0.01 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================



#22 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 13 May 2020 - 04:36 PM

Thanks.

 

It's a long log and I want to be thorough so I won't reply until tomorrow as it's 11:35pm here in the UK.


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#23 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 13 May 2020 - 04:38 PM

Hey, don't worry. I'm using your time so answer whenever.

Many thanks



#24 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 13 May 2020 - 04:48 PM

Thans


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#25 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 14 May 2020 - 12:17 PM

I think your problem is related to Windows Defender updates.

Let’s see what happens after running this.

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CloseProcesses:
Task: {79483315-4C82-430A-825F-4F9AB6E55001} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\noise\Desktop\esetonlinescanner.exe [14566496 2020-05-12] (ESET, spol. s r.o. -> ESET spol. s r.o.)
Task: {AEC452CE-2FAF-4148-9D5B-780DD8C15F66} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\noise\Desktop\esetonlinescanner.exe [14566496 2020-05-12] (ESET, spol. s r.o. -> ESET spol. s r.o.)
FF HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\noise\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\noise\AppData\Roaming\IDM\idmmzcc5 [2019-10-03] [Legacy] [not signed]
FF HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
R1 MpKslf9148da9; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5A94E882-B730-4A2B-BF4B-E44EA77711C1}\MpKslf9148da9.sys [43232 2020-05-13] (Microsoft Windows -> Microsoft Corporation)
2020-05-12 23:48 - 2020-05-12 23:48 - 000000222 _____ C:\Users\noise\Desktop\Dungeon Fighter Online.url
2020-05-12 20:10 - 2020-05-12 20:10 - 000003800 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2020-05-12 20:10 - 2020-05-12 20:10 - 000003358 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2020-05-12 20:10 - 2020-05-12 20:10 - 000000262 _____ C:\Users\noise\Desktop\eset.txt
2020-05-12 15:25 - 2020-05-12 20:13 - 000000626 _____ C:\Users\noise\Desktop\ESET Online Scanner.lnk
2020-05-12 15:25 - 2020-05-12 15:25 - 000000743 _____ C:\Users\noise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2020-05-12 15:25 - 2020-05-12 15:25 - 000000000 ____D C:\Users\noise\AppData\Local\ESET
2020-05-12 15:24 - 2020-05-12 15:24 - 014566496 _____ (ESET spol. s r.o.) C:\Users\noise\Desktop\esetonlinescanner.exe
2020-05-09 22:05 - 2020-05-09 22:05 - 000003944 _____ C:\Users\noise\Desktop\ckfiles.txt
2020-05-09 20:24 - 2020-05-09 20:24 - 000468480 _____ () C:\Users\noise\Desktop\CKScanner.exe
2020-05-01 20:32 - 2018-12-20 07:05 - 000229296 _____ (Tonec Inc.) C:\WINDOWS\system32\Drivers\idmwfp.sys
2020-04-16 12:31 - 2020-05-08 18:06 - 000505103 ____N C:\WINDOWS\Minidump\050820-51531-01.dmp
2020-04-16 12:31 - 2020-05-08 07:11 - 000774269 ____N C:\WINDOWS\Minidump\050820-76578-01.dmp
2020-04-14 22:16 - 2020-05-07 22:26 - 000000000 ____D C:\Users\noise\AppData\Local\AMSDK
2020-04-14 22:12 - 2020-04-14 22:12 - 000000000 ____D C:\Users\noise\AppData\Local\PrivacyGuardian
2020-05-13 17:50 - 2018-03-15 20:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoulseekQt
2020-05-13 17:41 - 2019-01-22 18:20 - 001024830 _____ C:\WINDOWS\SysWOW64\rootpa.e2e
2020-05-12 17:08 - 2020-01-25 19:29 - 000000000 ____D C:\WINDOWS\usgwmt
2020-05-11 19:01 - 2020-04-03 02:25 - 000000000 ____D C:\ProgramData\Avast Software
2020-05-09 20:27 - 2019-10-03 22:08 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2020-05-09 20:18 - 2019-04-25 01:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX
2020-05-09 20:18 - 2019-04-14 20:33 - 000000000 ____D C:\Users\noise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sugar Bytes
2020-05-08 06:27 - 2019-10-03 22:09 - 000000000 ____D C:\Users\noise\AppData\Roaming\DMCache
2020-05-08 06:27 - 2019-10-03 22:08 - 000000000 ____D C:\Users\noise\AppData\Roaming\IDM
2020-04-29 08:58 - 2019-10-03 22:08 - 000000000 ____D C:\Users\noise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2020-04-29 03:32 - 2019-10-03 22:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: AUEPLauncher => 2
MSCONFIG\Services: SynTPEnhService => 2
MSCONFIG\Services: tbaseprovisioning => 2
HKLM\...\StartupApproved\Run: => "DigidesignMMERefresh"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "CyberGhost"
FirewallRules: [TCP Query User{ED621430-E962-4142-ACD8-D22E6AF5A11B}C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe] => (Allow) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
FirewallRules: [UDP Query User{B5A80A84-E93E-4D17-A818-0370EB45D1B9}C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe] => (Allow) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
FirewallRules: [{395BB7DF-20B8-4763-A34D-2707A13EE4EC}] => (Block) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
FirewallRules: [{3B20ECA2-015C-41C8-A9CB-03984175A804}] => (Block) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
C:\Users\noise\Desktop\esetonlinescanner.exe
C:\Users\noise\AppData\Roaming\IDM
C:\Program Files (x86)\Internet Download Manager
Cmd: Net Stop bits
Cmd: Net Stop wuauserv
Cmd: Net Stop appidsvc
Cmd: Net Stop cryptsvc
Cmd: Ren %systemroot%\SoftwareDistribution SoftwareDistribution.bak
Cmd: Ren %systemroot%\system32\catroot2 catroot2.bak
Cmd: Net Start bits
Cmd: Net Start wuauserv
Cmd: Net Start appidsvc
Cmd: Net Start cryptsvc
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

Thanks

Satchfan

 


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

    Advertisements

Register to Remove


#26 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 14 May 2020 - 01:54 PM

Hello again.

Here's fixlog

Fix result of Farbar Recovery Scan Tool (x64) Version: 13-05-2020 01
Ran by noise (14-05-2020 15:36:42) Run:3
Running from C:\Users\noise\Desktop
Loaded Profiles: noise
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
Task: {79483315-4C82-430A-825F-4F9AB6E55001} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\noise\Desktop\esetonlinescanner.exe [14566496 2020-05-12] (ESET, spol. s r.o. -> ESET spol. s r.o.)
Task: {AEC452CE-2FAF-4148-9D5B-780DD8C15F66} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\noise\Desktop\esetonlinescanner.exe [14566496 2020-05-12] (ESET, spol. s r.o. -> ESET spol. s r.o.)
FF HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\noise\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\noise\AppData\Roaming\IDM\idmmzcc5 [2019-10-03] [Legacy] [not signed]
FF HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
R1 MpKslf9148da9; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5A94E882-B730-4A2B-BF4B-E44EA77711C1}\MpKslf9148da9.sys [43232 2020-05-13] (Microsoft Windows -> Microsoft Corporation)
2020-05-12 23:48 - 2020-05-12 23:48 - 000000222 _____ C:\Users\noise\Desktop\Dungeon Fighter Online.url
2020-05-12 20:10 - 2020-05-12 20:10 - 000003800 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2020-05-12 20:10 - 2020-05-12 20:10 - 000003358 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2020-05-12 20:10 - 2020-05-12 20:10 - 000000262 _____ C:\Users\noise\Desktop\eset.txt
2020-05-12 15:25 - 2020-05-12 20:13 - 000000626 _____ C:\Users\noise\Desktop\ESET Online Scanner.lnk
2020-05-12 15:25 - 2020-05-12 15:25 - 000000743 _____ C:\Users\noise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2020-05-12 15:25 - 2020-05-12 15:25 - 000000000 ____D C:\Users\noise\AppData\Local\ESET
2020-05-12 15:24 - 2020-05-12 15:24 - 014566496 _____ (ESET spol. s r.o.) C:\Users\noise\Desktop\esetonlinescanner.exe
2020-05-09 22:05 - 2020-05-09 22:05 - 000003944 _____ C:\Users\noise\Desktop\ckfiles.txt
2020-05-09 20:24 - 2020-05-09 20:24 - 000468480 _____ () C:\Users\noise\Desktop\CKScanner.exe
2020-05-01 20:32 - 2018-12-20 07:05 - 000229296 _____ (Tonec Inc.) C:\WINDOWS\system32\Drivers\idmwfp.sys
2020-04-16 12:31 - 2020-05-08 18:06 - 000505103 ____N C:\WINDOWS\Minidump\050820-51531-01.dmp
2020-04-16 12:31 - 2020-05-08 07:11 - 000774269 ____N C:\WINDOWS\Minidump\050820-76578-01.dmp
2020-04-14 22:16 - 2020-05-07 22:26 - 000000000 ____D C:\Users\noise\AppData\Local\AMSDK
2020-04-14 22:12 - 2020-04-14 22:12 - 000000000 ____D C:\Users\noise\AppData\Local\PrivacyGuardian
2020-05-13 17:50 - 2018-03-15 20:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoulseekQt
2020-05-13 17:41 - 2019-01-22 18:20 - 001024830 _____ C:\WINDOWS\SysWOW64\rootpa.e2e
2020-05-12 17:08 - 2020-01-25 19:29 - 000000000 ____D C:\WINDOWS\usgwmt
2020-05-11 19:01 - 2020-04-03 02:25 - 000000000 ____D C:\ProgramData\Avast Software
2020-05-09 20:27 - 2019-10-03 22:08 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2020-05-09 20:18 - 2019-04-25 01:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX
2020-05-09 20:18 - 2019-04-14 20:33 - 000000000 ____D C:\Users\noise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sugar Bytes
2020-05-08 06:27 - 2019-10-03 22:09 - 000000000 ____D C:\Users\noise\AppData\Roaming\DMCache
2020-05-08 06:27 - 2019-10-03 22:08 - 000000000 ____D C:\Users\noise\AppData\Roaming\IDM
2020-04-29 08:58 - 2019-10-03 22:08 - 000000000 ____D C:\Users\noise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2020-04-29 03:32 - 2019-10-03 22:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: AUEPLauncher => 2
MSCONFIG\Services: SynTPEnhService => 2
MSCONFIG\Services: tbaseprovisioning => 2
HKLM\...\StartupApproved\Run: => "DigidesignMMERefresh"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\...\StartupApproved\Run: => "CyberGhost"
FirewallRules: [TCP Query User{ED621430-E962-4142-ACD8-D22E6AF5A11B}C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe] => (Allow) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
FirewallRules: [UDP Query User{B5A80A84-E93E-4D17-A818-0370EB45D1B9}C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe] => (Allow) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
FirewallRules: [{395BB7DF-20B8-4763-A34D-2707A13EE4EC}] => (Block) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
FirewallRules: [{3B20ECA2-015C-41C8-A9CB-03984175A804}] => (Block) C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe => No File
C:\Users\noise\Desktop\esetonlinescanner.exe
C:\Users\noise\AppData\Roaming\IDM
C:\Program Files (x86)\Internet Download Manager
Cmd: Net Stop bits
Cmd: Net Stop wuauserv
Cmd: Net Stop appidsvc
Cmd: Net Stop cryptsvc
Cmd: Ren %systemroot%\SoftwareDistribution SoftwareDistribution.bak
Cmd: Ren %systemroot%\system32\catroot2 catroot2.bak
Cmd: Net Start bits
Cmd: Net Start wuauserv
Cmd: Net Start appidsvc
Cmd: Net Start cryptsvc
EmptyTemp:
*****************

Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{79483315-4C82-430A-825F-4F9AB6E55001}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79483315-4C82-430A-825F-4F9AB6E55001}" => removed successfully
C:\WINDOWS\System32\Tasks\EOSv3 Scheduler onLogOn => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EOSv3 Scheduler onLogOn" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AEC452CE-2FAF-4148-9D5B-780DD8C15F66}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEC452CE-2FAF-4148-9D5B-780DD8C15F66}" => removed successfully
C:\WINDOWS\System32\Tasks\EOSv3 Scheduler onTime => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EOSv3 Scheduler onTime" => removed successfully
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\Software\Mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com" => removed successfully
C:\Users\noise\AppData\Roaming\IDM\idmmzcc5 => moved successfully
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\Software\Mozilla\SeaMonkey\Extensions\\mozilla_cc2@internetdownloadmanager.com" => removed successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => removed successfully
MpKslf9148da9 => service not found.
C:\Users\noise\Desktop\Dungeon Fighter Online.url => moved successfully
"C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn" => not found
"C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime" => not found
C:\Users\noise\Desktop\eset.txt => moved successfully
C:\Users\noise\Desktop\ESET Online Scanner.lnk => moved successfully
C:\Users\noise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk => moved successfully
C:\Users\noise\AppData\Local\ESET => moved successfully
C:\Users\noise\Desktop\esetonlinescanner.exe => moved successfully
C:\Users\noise\Desktop\ckfiles.txt => moved successfully
C:\Users\noise\Desktop\CKScanner.exe => moved successfully
C:\WINDOWS\system32\Drivers\idmwfp.sys => moved successfully
C:\WINDOWS\Minidump\050820-51531-01.dmp => moved successfully
C:\WINDOWS\Minidump\050820-76578-01.dmp => moved successfully
C:\Users\noise\AppData\Local\AMSDK => moved successfully
C:\Users\noise\AppData\Local\PrivacyGuardian => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoulseekQt => moved successfully
C:\WINDOWS\SysWOW64\rootpa.e2e => moved successfully
C:\WINDOWS\usgwmt => moved successfully
C:\ProgramData\Avast Software => moved successfully
C:\Program Files (x86)\Internet Download Manager => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX => moved successfully
C:\Users\noise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sugar Bytes => moved successfully
C:\Users\noise\AppData\Roaming\DMCache => moved successfully
C:\Users\noise\AppData\Roaming\IDM => moved successfully
C:\Users\noise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AMD External Events Utility => removed successfully
HKLM\System\CurrentControlSet\Services\AMD External Events Utility => removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AUEPLauncher => removed successfully
HKLM\System\CurrentControlSet\Services\AUEPLauncher => removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SynTPEnhService => removed successfully
HKLM\System\CurrentControlSet\Services\SynTPEnhService => removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\tbaseprovisioning => removed successfully
HKLM\System\CurrentControlSet\Services\tbaseprovisioning => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\DigidesignMMERefresh" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\DigidesignMMERefresh" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\SunJavaUpdateSched" => removed successfully
"HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\APSDaemon" => removed successfully
"HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\APSDaemon" => not found
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\Discord" => removed successfully
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Discord" => removed successfully
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\Steam" => removed successfully
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Steam" => removed successfully
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\EpicGamesLauncher" => removed successfully
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\EpicGamesLauncher" => removed successfully
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\CyberGhost" => removed successfully
"HKU\S-1-5-21-1886559292-1678889598-4243398580-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\CyberGhost" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{ED621430-E962-4142-ACD8-D22E6AF5A11B}C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{B5A80A84-E93E-4D17-A818-0370EB45D1B9}C:\users\noise\appdata\local\inssider\app-5.3.3\inssider.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{395BB7DF-20B8-4763-A34D-2707A13EE4EC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3B20ECA2-015C-41C8-A9CB-03984175A804}" => removed successfully
"C:\Users\noise\Desktop\esetonlinescanner.exe" => not found
"C:\Users\noise\AppData\Roaming\IDM" => not found
"C:\Program Files (x86)\Internet Download Manager" => not found

========= Net Stop bits =========

El servicio de Servicio de transferencia inteligente en segundo plano (BITS) no se ha iniciado.

Puede obtener m s ayuda con el comando NET HELPMSG 3521.


========= End of CMD: =========


========= Net Stop wuauserv =========

El servicio de Windows Update no se ha iniciado.

Puede obtener m s ayuda con el comando NET HELPMSG 3521.


========= End of CMD: =========


========= Net Stop appidsvc =========

El servicio de Identidad de aplicaci¢n no se ha iniciado.

Puede obtener m s ayuda con el comando NET HELPMSG 3521.


========= End of CMD: =========


========= Net Stop cryptsvc =========

El servicio de Servicios de cifrado est  deteni‚ndose..
El servicio de Servicios de cifrado se detuvo correctamente.


========= End of CMD: =========


========= Ren %systemroot%\SoftwareDistribution SoftwareDistribution.bak =========


========= End of CMD: =========


========= Ren %systemroot%\system32\catroot2 catroot2.bak =========


========= End of CMD: =========


========= Net Start bits =========

El servicio de Servicio de transferencia inteligente en segundo plano (BITS) est  inici ndose.
El servicio de Servicio de transferencia inteligente en segundo plano (BITS) se ha iniciado correctamente.


========= End of CMD: =========


========= Net Start wuauserv =========

El servicio de Windows Update est  inici ndose.
El servicio de Windows Update se ha iniciado correctamente.


========= End of CMD: =========


========= Net Start appidsvc =========

El servicio de Identidad de aplicaci¢n est  inici ndose.
El servicio de Identidad de aplicaci¢n se ha iniciado correctamente.


========= End of CMD: =========


========= Net Start cryptsvc =========

El servicio solicitado ya ha sido iniciado.

Puede obtener m s ayuda con el comando NET HELPMSG 2182.


========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12717025 B
Java, Flash, Steam htmlcache => 24575636 B
Windows/system/drivers => 97766 B
Edge => 0 B
Chrome => 0 B
Firefox => 578315151 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 15538 B
noise => 25277803 B

RecycleBin => 41501774 B
EmptyTemp: => 660.9 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 15:38:19 ====



#27 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 14 May 2020 - 04:27 PM

Excellent.

 

What was happening was that Windows was trying to install updates but the necessary services were not running: they are now.

 

Please install Windows updates:

  • type Windows Update in the search box on your taskbar
  • select Check for Updates
  • when it has finished searching, click Install now.

When the updates have finished being installed your computer should be running better. Please let me know.

 

Satchfan


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#28 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 14 May 2020 - 04:44 PM

I did that, but there's nothing new (Up-to-date).

In general it is running faster and starting faster.

 

I'm still with network problems thou :( I still believe it's a hardware problem.

Last night I tested the ethernet cable again and speed is just awful. It should say 1Gbps in status but it almost half of that (cable is Ok, tested it with 2 other computers, they all work fine) and it drops the connection every now and then.



#29 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 14 May 2020 - 04:58 PM

You may have to go to our Networking forum but let’s have a look here first.

Run Farbar Service Scanner

Please download Farbar Service Scanner and run it on the computer with the issue.

Make sure the following options are checked:


Internet Services
System Restore
Security Center/Action Center
Windows Update
Windows Defender
Other Services

  • press Scan
  • it will create a log (FSS.txt) in the same directory the tool is run
  • please copy and paste the log to your reply.

Late here again so I’ll be in touch tomorrow.

Satchfan

 


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#30 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 14 May 2020 - 06:35 PM

I'll check the other forum when we check here.

Here's the log

Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
The ImagePath of wuauserv: "%systemroot%\system32\svchost.exe -k netsvcs -p".
The ServiceDll of wuauserv service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****

 

Many thanks for your work


Related Topics




Also tagged with one or more of these keywords: win10, rootkit, crypto, help, cryptominer

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users