Password reset and notification emails are now sending correctly.
If you recently requested a password reset, please check your inbox (and spam folder just in case).
You can now reset your password and log in as normal.
Welcome back to PCHF, and thank you for your patience during our migration process!
โ The PCHF Team
Welcome to PC Help Forum!
Youโre viewing our community as a guest.
That means you can browse posts, but canโt yet reply or start new topics.
Join us today โ it's completely free!
As a member, you'll be able to:
โ Get personalized tech support from trusted volunteers
๐ฆ Work one-on-one with our Malware Removal Specialists
My computer keeps permanently freezing when playing games, at seemingly random times, and I have to manually power off the PC. Itโs been happening since a few weeks, and I still havenโt figured it out why.
Things I tried already:
[ul]
[li]Updating drivers (cpu, bios, gpu, sound, lan)[/li][li]Checking temperatures (all fine)[/li][li]Checking event viewer (found nothing before the time of freeze)[/li][/ul]
Do you have any idea on how to fix it? Thanks for the help in advance.
[ul]
[li]Download Security Check to your desktop.[/li][li]Right click it run as administrator.[/li][li]When the program completes, the tool will automatically open a log file.[/li][li]Please post that log here in your next post.[/li][/ul]
Step 2:
Adware Cleaner Scan.
Please download AdwCleaner by Xplode onto your desktop.
[ul]
[li]Close all open programs and internet browsers.[/li][li]Right Click on adwcleaner.exe and run as admin to run the tool.[/li][li]Click on Scan button.[/li][li]When the scan has finished click on Clean button.[/li][li]Your computer will be rebooted automatically. A text file will open after the restart.[/li][li]Please post the contents of that logfile with your next reply.[/li][li]You can find the logfile at C:\AdwCleaner[S1].txt as well.[/li][/ul]
Step 3:
HijackThis.
1- Please click HERE to download HijackThis.
2- Run the program.
3- Click on the Main Menu button if not already there.
4- Select Do a system scan and save a logfile.
5- Copy paste the log here.
Step 4:
Please download MINITOOLBOX and run it.
Checkmark following boxes:
Flush DNS
Reset FF proxy Settings
Reset Ie Proxy Settings
Report IE Proxy Settings
Report FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size
List Devices (problems only)
Okay, I was thinking about it and looked a bit further, it might actually not be a scam site, you just make it really look like one (with typical redflags)
I apologize for my last comment, I canโt edit it, you can remove it. Iโll post the logs later.
By the way, my antivirus recognized your version of Security Check as a trojan, I had no trouble when I downloaded another version.
my antivirus recognized your version of Security Check as a trojan,
I assure you that it is not a virus. Please just disable your antivirus to run it. You can look through my post, I am not here to add malware to peoples machines I remove it.
Iโm using Hungarian language on Windows, I hope thatโs not a problem. If it is, tell me, and Iโll set it to English and run these again.
SysCheck:
SecurityCheck by glax24 & Severnyj v.1.4.0.53 [27.10.17]
WebSite: www.safezone.cc
DateLog: 16.06.2019 16:11:49
Path starting: C:\Users\User\AppData\Local\Temp\SecurityCheck\Sec urityCheck.exe
Log directory: C:\SecurityCheck
IsAdmin: True
User: User
VersionXML: 6.56is-15.06.2019
Windows 10(6.3.17134) (x64) Professional Release: 1803 Lang: 040E
Installation date OS: 26.05.2018 05:21:13
LicenseStatus: Windows(R), Professional edition Volume activation will expire : 23342 minutes
LicenseStatus: Office 16, Office16ProPlusVL_KMS_Client edition Volume activation will expire : 23342 minutes
Boot Mode: Normal
Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.EXE
SystemDrive: C: FS: [NTFS] Capacity: [111.3 Gb] Used: [102.5 Gb] Free: [8.8 Gb]
------------------------------- [ Windows ] -------------------------------
Internet Explorer 11.829.17134.0
User Account Control enabled
The elevation prompt for administrators disabled ^It is recommended to enable (default): Win+R typing UserAccountControlSettings and Enter[1]
Biztonsรกgi kรถzpont (wscsvc) - The service is running
Tรกvoli beรกllรญtรกsjegyzรฉk (RemoteRegistry) - The service has stopped
SSDP keresล (SSDPSRV) - The service is running
Tรกvoli asztali szolgรกltatรกsok (TermService) - The service has stopped
Rendszerfelรผgyeleti webszolgรกltatรกsok (WinRM) - The service has stopped
------------------------------ [ MS Office ] ------------------------------
Microsoft Office 2016 x86 v.16.0.4266.1001
---------------------------- [ Antivirus_WMI ] ----------------------------
Windows Defender (enabled and up to date)
--------------------------- [ FirewallWindows ] ---------------------------
Windows Defender tลฑzfal (mpssvc) - The service is running
--------------------------- [ AntiSpyware_WMI ] ---------------------------
Windows Defender (enabled and up to date)
---------------------- [ AntiVirusFirewallInstall ] -----------------------
Bitdefender Agent v.1.0.1
--------------------------- [ OtherUtilities ] ----------------------------
Git version 2.16.2 v.2.16.2 Warning! Download Update
NVIDIA GeForce Experience 3.19.0.94 v.3.19.0.94
TeamViewer 13 v.13.2.26558 Warning! Download Update
VLC media player v.3.0.1 Warning! Download Update
TeamViewer 13 (TeamViewer) - The service is running
-------------------------------- [ Arch ] ---------------------------------
7-Zip 18.00 beta (x64) v.18.00 beta Warning! This software is no longer supported. Uninstall old version, download and install new one.
WinRAR 5.70 (64-bit) v.5.70.0 Warning! Download Update
7-Zip 18.01 (x64 edition) v.18.01.00.0 Warning! Download Update
Uninstall old version and install new one.
--------------------------------- [ IM ] ----------------------------------
Discord v.0.0.305
--------------------------------- [ P2P ] ---------------------------------
ยตTorrent v.3.5.5.45271 Warning! P2P-client.
-------------------------------- [ Java ] ---------------------------------
Javaโข SE Development Kit 11.0.1 (64-bit) v.11.0.1.0
Java 8 Update 161 v.8.0.1610.12 Warning! Download Update
Uninstall old version and install new one (jre-8u211-windows-i586.exe).
Java 7 Update 21 v.7.0.210 Warning! This software is no longer supported. Please uninstall it and use Java SE 8 (jre-8u211-windows-i586.exe).
--------------------------- [ AdobeProduction ] ---------------------------
Adobe Acrobat Reader DC - Hungarian v.19.010.20098 Warning! Download Update ^Please run Acrobat Reader DC and go Help - Check for updatesโฆ[2]
------------------------------- [ Browser ] -------------------------------
Google Chrome v.74.0.3729.169 Warning! Download Update
------------------ [ AntivirusFirewallProcessServices ] -------------------
ProductAgentService (ProductAgentService) - The service is running
C:\Program Files\Bitdefender Agent\ProductAgentService.exe v.23.0.8.130
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1905.4-0\MsMpEng.exe v.4.18.1905.4
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1905.4-0\NisSrv.exe v.4.18.1905.4
C:\Program Files\Windows Defender\MSASCuiL.exe v.4.13.17134.1
Windows Defender vรญruskeresล szolgรกltatรกs (WinDefend) - The service is running
A Windows Defender vรญruskeresล hรกlรณzatvizsgรกlรณ szolgรกltatรกsa (WdNisSvc) - The service is running
----------------------------- [ End of Log ] ------------------------------
MINITB:
MiniToolBox by Farbar Version: 17-06-2016
Ran by User (administrator) on 16-06-2019 at 16:22:26
Running from โC:\Users\User\Downloadsโ
Microsoft Windows 10 Pro (X64)
Model: To Be Filled By O.E.M. Manufacturer: To Be Filled By O.E.M.
Boot Mode: Normal
========================= Flush DNS: ===================================
Pinging google.com [172.217.20.14] with 32 bytes of data:
Reply from 172.217.20.14: bytes=32 time=12ms TTL=55
Reply from 172.217.20.14: bytes=32 time=13ms TTL=55
Ping statistics for 172.217.20.14:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 12ms, Maximum = 13ms, Average = 12ms
Server: hu-bud02a-dns03.chello.hu
Address: 213.46.246.53
Pinging yahoo.com [72.30.35.10] with 32 bytes of data:
Reply from 72.30.35.10: bytes=32 time=129ms TTL=50
Reply from 72.30.35.10: bytes=32 time=127ms TTL=50
Ping statistics for 72.30.35.10:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 127ms, Maximum = 129ms, Average = 128ms
Error: (06/16/2019 04:20:12 PM) (Source: Application Error) (User: )
Description: A hibรกt okozรณ alkalmazรกs neve: AI Suite II.exe, verziรณ: 2.0.0.0, idลbรฉlyeg: 0x00000000
A hibรกt okozรณ modul neve: KERNELBASE.dll, verziรณ: 10.0.17134.799, idลbรฉlyeg: 0x0117c7be
Kivรฉtelkรณd: 0x0eedfade
Hiba pozรญciรณja: 0x00112c92
A hibรกt okozรณ folyamat azonosรญtรณja: 0x2c8c
A hibรกt okozรณ alkalmazรกs indรญtรกsรกnak idลpontja: 0xAI Suite II.exe0
A hibรกt okozรณ alkalmazรกs elรฉrรฉsi รบtja: AI Suite II.exe1
A hibรกt okozรณ modul elรฉrรฉsi รบtja: AI Suite II.exe2
Jelentรฉs azonosรญtรณja: AI Suite II.exe3
A hibรกt okozรณ csomag teljes neve: AI Suite II.exe4
A hibรกt okozรณ csomag relatรญv alkalmazรกsazonosรญtรณja: AI Suite II.exe5
Error: (06/16/2019 04:19:42 PM) (Source: Application Error) (User: )
Description: A hibรกt okozรณ alkalmazรกs neve: TurboVHelp.exe, verziรณ: 1.0.1.36, idลbรฉlyeg: 0x00000000
A hibรกt okozรณ modul neve: KERNELBASE.dll, verziรณ: 10.0.17134.799, idลbรฉlyeg: 0x0117c7be
Kivรฉtelkรณd: 0x0eedfade
Hiba pozรญciรณja: 0x00112c92
A hibรกt okozรณ folyamat azonosรญtรณja: 0x2448
A hibรกt okozรณ alkalmazรกs indรญtรกsรกnak idลpontja: 0xTurboVHelp.exe0
A hibรกt okozรณ alkalmazรกs elรฉrรฉsi รบtja: TurboVHelp.exe1
A hibรกt okozรณ modul elรฉrรฉsi รบtja: TurboVHelp.exe2
Jelentรฉs azonosรญtรณja: TurboVHelp.exe3
A hibรกt okozรณ csomag teljes neve: TurboVHelp.exe4
A hibรกt okozรณ csomag relatรญv alkalmazรกsazonosรญtรณja: TurboVHelp.exe5
Error: (06/16/2019 03:47:46 PM) (Source: Application Error) (User: )
Description: A hibรกt okozรณ alkalmazรกs neve: AI Suite II.exe, verziรณ: 2.0.0.0, idลbรฉlyeg: 0x00000000
A hibรกt okozรณ modul neve: KERNELBASE.dll, verziรณ: 10.0.17134.799, idลbรฉlyeg: 0x0117c7be
Kivรฉtelkรณd: 0x0eedfade
Hiba pozรญciรณja: 0x00112c92
A hibรกt okozรณ folyamat azonosรญtรณja: 0x26c8
A hibรกt okozรณ alkalmazรกs indรญtรกsรกnak idลpontja: 0xAI Suite II.exe0
A hibรกt okozรณ alkalmazรกs elรฉrรฉsi รบtja: AI Suite II.exe1
A hibรกt okozรณ modul elรฉrรฉsi รบtja: AI Suite II.exe2
Jelentรฉs azonosรญtรณja: AI Suite II.exe3
A hibรกt okozรณ csomag teljes neve: AI Suite II.exe4
A hibรกt okozรณ csomag relatรญv alkalmazรกsazonosรญtรณja: AI Suite II.exe5
Error: (06/16/2019 03:47:16 PM) (Source: Application Error) (User: )
Description: A hibรกt okozรณ alkalmazรกs neve: TurboVHelp.exe, verziรณ: 1.0.1.36, idลbรฉlyeg: 0x00000000
A hibรกt okozรณ modul neve: KERNELBASE.dll, verziรณ: 10.0.17134.799, idลbรฉlyeg: 0x0117c7be
Kivรฉtelkรณd: 0x0eedfade
Hiba pozรญciรณja: 0x00112c92
A hibรกt okozรณ folyamat azonosรญtรณja: 0x1fb8
A hibรกt okozรณ alkalmazรกs indรญtรกsรกnak idลpontja: 0xTurboVHelp.exe0
A hibรกt okozรณ alkalmazรกs elรฉrรฉsi รบtja: TurboVHelp.exe1
A hibรกt okozรณ modul elรฉrรฉsi รบtja: TurboVHelp.exe2
Jelentรฉs azonosรญtรณja: TurboVHelp.exe3
A hibรกt okozรณ csomag teljes neve: TurboVHelp.exe4
A hibรกt okozรณ csomag relatรญv alkalmazรกsazonosรญtรณja: TurboVHelp.exe5
Error: (06/16/2019 03:40:14 PM) (Source: Software Protection Platform Service) (User: )
Description: A licencaktivรกlรกs (slui.exe) a kรถvetkezล hibakรณddal leรกllt:
hr=0x8007139F
Parancssori argumentumok:
RuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=Net workAvailable
[HEADING=1]System errors:[/HEADING]
Error: (06/16/2019 04:21:34 PM) (Source: Service Control Manager) (User: )
Description: A szolgรกltatรกs (ASUS Com Service) a kรถvetkezล hiba kรถvetkeztรฉben leรกllt:
%%1053 = A szolgรกltatรกs nem vรกlaszolt megfelelล idลben az indรญtรกsi vagy vezรฉrlรฉsi kรฉrรฉsre.
Error: (06/16/2019 04:21:34 PM) (Source: Service Control Manager) (User: )
Description: Letelt egy idลkorlรกt (30000 ms) a(z) ASUS Com Service szolgรกltatรกs kapcsolรณdรกsรกra valรณ vรกrakozรกs kรถzben.
Error: (06/16/2019 04:20:12 PM) (Source: Service Control Manager) (User: )
Description: A szolgรกltatรกs (ASUS Com Service) a kรถvetkezล hiba kรถvetkeztรฉben leรกllt:
%%1053 = A szolgรกltatรกs nem vรกlaszolt megfelelล idลben az indรญtรกsi vagy vezรฉrlรฉsi kรฉrรฉsre.
Error: (06/16/2019 04:20:12 PM) (Source: Service Control Manager) (User: )
Description: Letelt egy idลkorlรกt (30000 ms) a(z) ASUS Com Service szolgรกltatรกs kapcsolรณdรกsรกra valรณ vรกrakozรกs kรถzben.
Error: (06/16/2019 04:19:42 PM) (Source: Service Control Manager) (User: )
Description: A szolgรกltatรกs (ASUS Com Service) a kรถvetkezล hiba kรถvetkeztรฉben leรกllt:
%%1053 = A szolgรกltatรกs nem vรกlaszolt megfelelล idลben az indรญtรกsi vagy vezรฉrlรฉsi kรฉrรฉsre.
Error: (06/16/2019 04:19:42 PM) (Source: Service Control Manager) (User: )
Description: Letelt egy idลkorlรกt (30000 ms) a(z) ASUS Com Service szolgรกltatรกs kapcsolรณdรกsรกra valรณ vรกrakozรกs kรถzben.
Error: (06/16/2019 04:20:12 PM) (Source: Application Error)(User: )
Description: AI Suite II.exe2.0.0.000000000KERNELBASE.dll10.0.17134.7990 117c7be0eedfade00112c922c8c01d5244e7c5b2128C:\Prog ram Files (x86)\ASUS\AI Suite II\AI Suite II.exeC:\WINDOWS\System32\KERNELBASE.dll66d9a8a8-3728-4a4a-b222-3eb0a9eb15f8
Error: (06/16/2019 03:47:46 PM) (Source: Application Error)(User: )
Description: AI Suite II.exe2.0.0.000000000KERNELBASE.dll10.0.17134.7990 117c7be0eedfade00112c9226c801d52449f365a502C:\Prog ram Files (x86)\ASUS\AI Suite II\AI Suite II.exeC:\WINDOWS\System32\KERNELBASE.dllb369fd46-0800-4e70-862a-bd6c490ae697
Error: (06/16/2019 03:40:14 PM) (Source: Software Protection Platform Service)(User: )
Description: hr=0x8007139FRuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=Net workAvailable
[HEADING=1]CodeIntegrity Errors:[/HEADING]
Date: 2018-08-14 16:19:20.546
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Date: 2018-08-14 16:19:20.541
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Date: 2018-08-14 16:19:20.536
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Date: 2018-08-14 16:19:20.531
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Date: 2018-08-14 16:19:19.848
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Date: 2018-08-14 16:19:19.833
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Date: 2018-08-14 16:19:19.827
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Date: 2018-08-14 16:19:17.819
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Date: 2018-08-14 16:19:17.814
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Date: 2018-08-14 16:19:17.809
Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Overwolf\0.117.1.43\OWExpl orer.dll that did not meet the Microsoft signing level requirements.
Percentage of memory in use: 36%
Total physical RAM: 8123.74 MB
Available physical RAM: 5128.09 MB
Total Virtual: 13243.74 MB
Available Virtual: 8776.07 MB
Just run Adware cleaner and Hijack this. My laptop is about to die, I have my friend bringing me my power cord soon. You could look over this guide which should basically tune up your machine cause I wont be online till my cord gets here.
I see a few things that need to be taken care of, but my laptop is dead and the power cord wonโt be here for a couple hours. Not much I can do from my phone. Iโd suggest just going through the internet guide I posted until I get my power cord and prepare you a proper reply. But judging by what I see I am fairly certain I can help your issue.
Clean up temp files and reduce startup load with CCleaner.
Note: This tool will clean your browsing history as well.
[ul]
[li]Download CCleaner from here.[/li][li]After install Click Options.[/li][li]Go to monitoring.[/li][li]Uncheck All Monitoring items.[/li][li]Go to advanced โ Click close program after cleaning.[/li][li]Go to settings โ click run ccleaner when the computer starts.[/li][li]Now that you have ccleaner installed and set-up:[/li][li]Open the program.[/li][li]Go to Tools[/li][li]Go to Startup[/li][li]Now double click each item. To Disable.[/li][li]Leave only your antivirus enabled.[/li][li]Then disable All items in your scheduled task as well.[/li][li]Unless they are related to windows defender.Or your antivirus.[/li][li]Reboot the machine.[/li][/ul]
The site is in French so the download button is the same as the picture below..
~ ZHPDiag v2019.6.15.85 By Nicolas Coolman (2019/06/15)
~ Run by User (Administrator) (2019/06/17 00:19:42)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: ZHP
~ Certificate ZHPDiag: Legal
~ State version: Version OK
~ Mode: Scan
~ Report: C:\Users\User\Desktop\ZHPDiag.txt
~ Report: C:\Users\User\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 17134) =>.Microsoft Corporation
โ\ Internet Browsers (3) - 0s
~ GCIE: Google Chrome v74.0.3729.169
~ MSIE: Microsoft Edge v40
~ MSIE: Internet Explorer v11.829.17134.0
โ\ Windows Product Information (3) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Gรฉnรฉration : OK
Windows Automatic Updates : OK
โ\ System protection software (2) - 1s
Windows Defender W10 (Activate) (Protection)
Bitdefender Agent v1.0.1 (Protection)
โ\ Informations on the system (6) - 0s
~ Operating System: AMD64 Family 23 Model 1 Stepping 1, AuthenticAMD
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 8318.708 MB (61% free) : OK =>.RAM Value
System Restore: Activรฉ (Enable)
System drive C: has 6 GB (5%) free of 113 GB : ATTENTION =>Warning Disk Space
โ\ Connection to the system mode (3) - 0s
~ Computer Name: DESKTOP-NQ7JARN
~ User Name: User
~ Logged in as Administrator
โ\ Enumeration of the disk units (5) - 0s
~ Drive C: has 6 GB free of 113 GB (System)
~ Drive D: has 0 GB free of 0 GB
~ Drive F: has 107 GB free of 653 GB
~ Drive G: has 285 GB free of 299 GB
~ Drive K: has 7 GB free of 7 GB
โ\ State of the Windows Security Center (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
Download Adware removal tool to your desktop, right click the icon and select Run as Administrator.
[MEDIA=imgur]LOr0Gd7[/MEDIA]
Hit Ok.
[MEDIA=imgur]sYFsqHx[/MEDIA]
Hit next make sure to leave all items checked, for removal.
[MEDIA=imgur]8NcZjGc[/MEDIA]
The Program will close all open programs to complete the removal, so save any work and hit OK. Then hit OK after the removal process is complete, thenOK again to finish up. Post log generated by tool.
[COLOR=rgb(184, 49, 47)]Hijack This Fix.
Start HijackThis , Right Click Run as Admin.
Close all other open programs prior to running this tool!!
Click System Scan Only.
Then check mark the items listed below.
O1 - Hosts: 0.0.0.0 91.206.200.221
O1 - Hosts: 0.0.0.0 bidtraffic.ru
O1 - Hosts: 0.0.0.0 bir3yka.narod2.ru
O1 - Hosts: 0.0.0.0 enet.vn.ua
O1 - Hosts: 0.0.0.0 rax.ru
O1 - Hosts: 0.0.0.0 yandex.ru
O1 - Hosts: 0.0.0.0 ukraine.com.ua
O4 - HKCU..\Run: [CCleaner Smart Cleaning] = C:\Program Files\CCleaner\CCleaner64.exe /MONITOR
O4 - HKCU..\Run: [DAEMON Tools Lite Automount] = C:\Program Files\DAEMON Tools Lite\DTAgent.exe -autorun (file missing)
O4 - HKCU..\Run: [uTorrent] = C:\Users\User\AppData\Roaming\uTorrent\uTorrent.ex e /MINIMIZED
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] = C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.e xe
O4 - HKU\S-1-5-19..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade
O4 - HKU\S-1-5-20..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade
O4-32 - HKLM..\Run: [LogMeIn Hamachi Ui] = C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start
O4-32 - HKLM..\Run: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
O5 - HKCU\Control Panel\donโt load: [RTSnMg64.cpl] (file missing)
O9-32 - Button: HKLM..{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}: OneNote โ c&satolt feljegyzรฉsek - (no file)
O9-32 - Tools menu item: HKLM..{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}: OneNote โ c&satolt feljegyzรฉsek - (no file)
O21 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive1: (no name) - {BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
O21 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive2: (no name) - {5AB7172C-9C11-405C-8DD5-AF20F3606282} - (no file)
O21 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive3: (no name) - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} - (no file)
O21 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive4: (no name) - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
O21 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive5: (no name) - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
O21 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive6: (no name) - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} - (no file)
O21 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive7: (no name) - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} - (no file)
O21 - HKLM..\ShellIconOverlayIdentifiers\00asw: (no name) - {472083B0-C522-11CF-8763-00608CC02F24} - (no file)
O21-32 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive1: (no name) - {BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
O21-32 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive2: (no name) - {5AB7172C-9C11-405C-8DD5-AF20F3606282} - (no file)
O21-32 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive3: (no name) - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} - (no file)
O21-32 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive4: (no name) - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
O21-32 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive5: (no name) - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
O21-32 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive6: (no name) - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} - (no file)
O21-32 - HKLM..\ShellIconOverlayIdentifiers\ OneDrive7: (no name) - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} - (no file)
O23 - Service S2: ICEsound Service - (ICEsoundService) - C:\WINDOWS\system32\ICEsoundService64.exe (file missing)
O23 - Service S2: Origin Web Helper Service - C:\Program Files (x86)\Origin\OriginWebHelperService.exe (file missing)
O23 - Service S3: Origin Client Service - C:\Program Files (x86)\Origin\OriginClientService.exe (file missing)
Now click on fix checked.
After the fix is complete, then reboot your machine.
Temp File Cleaner.
[ul]
[li] Note: This program may very well reboot your machine. Save any work prior to running.[/li][li]Clean up your temp files with TFC.exe[/li][li]Save it to your desktop.[/li][li]Right click run as admin.[/li][/ul][/COLOR][/COLOR]
1 Drive c: () (Fixed) (Total:111.25 GB) (Free:8.97 GB) NTFS
You only have eight percent free space.
Iโd suggest you free up some space.
In order for windows to function correctly it needs 15 percent free space.
Here is a guide I wrote for another site, it explains very much so how to clean up a HDD.
You have any idea what this file is?
C:\Users\User\AppData\Local\7.b - A jฤหtฤยฉk DEMฤโ
Click on Download Windows 10 Disable Most Of Ads It should give you a zip file, which you will need to right click on and Extract All, Extract then right click on the .reg and MERGE. Then reboot.
ZHP Diag Fix.
ZHP Fix
[MEDIA=imgur]4bd9Ugb[/MEDIA]
[ul]
[li]Disable your antivirus prior to this fix![/li][li]Download ZHP-Fix from here.[/li][li]UnZip it to your desktop โ Tool Here if neededโฆ 7-Zip[/li][li]Install it.[/li][li]Click Suivant 5 Times.[/li][li]Then Installer.[/li][li]Then Terminer.[/li][li]Then right clcick the ZHP Fix icon Run as admin.[/li][li]Copy the entire content of the code box below, the next step will grab it from your clipboard.[/li][li]Then click on import.[/li][li]Then click GO.[/li][li]If you see any Prompts like the one below, select Oui. = Yes in French.[/li][li]https://pchelpforum.net/attachments/upload_2017-5-24_21-17-40-png.2248/[/li]
[li]Allow completion.[/li][li]A log file will appear on your desktop.[/li][li]Post it here in your next reply.[/li][/ul]
I freed up some space.
Yes, I do, itโs a small game, nothing special.
Also, I posted on another forum as well, and the problem seems to be either PSU or heat related, do I really have to keep downloading these programs? I donโt think itโs software related.
When you have completed the above steps, reboot your machine and get me an autoruns log, we will then disable some things from loading when windows loads, that will free up some ram for you.
Download Autoruns and Autorunsc Unzip it to your desktop and then double click autoruns.exe
After the scan is finished then click on File>>>>>>>>>>>Save
The default name will be autoruns.arn make sure to save it as Autoruns.txt under the file type option.
in other words make sure it is a .txt file instead of .arn Attach the text in your next reply.
We process personal data about users of our site, through the use of cookies and other technologies, to deliver our services, personalize advertising, and to analyze site activity. We may share certain information about our users with our advertising and analytics partners. For additional details, refer to our Privacy Policy.
By clicking "I AGREE" below, you agree to our Privacy Policy and our personal data processing and cookie practices as described therein. You also acknowledge that this forum may be hosted outside your country and you consent to the collection, storage, and processing of your data in the country where this forum is hosted.
Comment