My Windows 10 system seems infested with something odd

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #46
    Ok, a log should appear on your desktop when its done.

    Even after that a X-Speed scan from quick diag would be nice, but if it wont run then no big deal.

    Comment

    • Rusty_Rusty
      PCHF Member
      • Jul 2019
      • 64

      #47
      Thanks for the heads-up Malnutrition. I think ZHP was finished writing log 18 minutes ago, when the file was created/mod’d, as it is NOT increasing in size, so here it is attached

      Comment

      • Rusty_Rusty
        PCHF Member
        • Jul 2019
        • 64

        #48
        Yeah that ZHP software deked me out! Apparently it was waiting for me to X-close its “browser” window ad; for when I closed that, then it announced “reporting finished”. He-he - nasty!

        Comment

        • Rusty_Rusty
          PCHF Member
          • Jul 2019
          • 64

          #49
          BTW I am getting the forum’s push notifications successfully.

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7041

            #50
            Nice, this information will take some time to go over. So it will be possibly a few hours before I reply. I need to go over this carefully so i do not miss anything.

            Comment

            • Rusty_Rusty
              PCHF Member
              • Jul 2019
              • 64

              #51
              Great - many thanks!

              Comment

              • Malnutrition
                PCHF Moderator
                • Jul 2016
                • 7041

                #52
                No problem.

                While I look over things, run this for me please.

                ZHP Scan.

                Please download Zhp Cleaner to your desktop. Right Click the icon and select run as administrator.
                1. Once you have started the program, you will need to click the scanner button.

                [IMG alt="EgsT69u" width="602px" height="129px"]https://windowsinstructed.com/wp-content/uploads/2015/06/EgsT69u.png[/IMG]

                The program will close all open browsers!
                3. Once the scan is completed, the you will want to click the Repair button.

                [URL unfurl="true"]http://windowsinstructed.com/wp-content/uploads/2015/06/6QJjV50.png[/URL]

                At the end of the process you may be asked to reboot your machine. After you reboot a report will open on your desktop.

                Copy and paste the report here in your next reply.

                Comment

                • Rusty_Rusty
                  PCHF Member
                  • Jul 2019
                  • 64

                  #53
                  'on it

                  Comment

                  • Rusty_Rusty
                    PCHF Member
                    • Jul 2019
                    • 64

                    #54
                    Ok, ZHP cleaner left two text files on desktop (likely some redundancy), both are attached.

                    And I’ll take this opportunity to remind you that if you tell a forum user to download special software that Defender might object to (for its intent to poke and prod much) that it might become necessary to go to the downloaded file’s Properties box and tick the “Unblock” box in order for the download to be launch-able.

                    Comment

                    • Malnutrition
                      PCHF Moderator
                      • Jul 2016
                      • 7041

                      #55
                      ZHP Diag Fix.

                      ZHP Fix

                      [MEDIA=imgur]4bd9Ugb[/MEDIA]

                      [ul]
                      [li]Disable your antivirus prior to this fix![/li][li]Download ZHP-Fix from here.[/li][li]UnZip it to your desktop – Tool Here if needed… 7-Zip[/li][li]Install it.[/li][li]Click Suivant 5 Times.[/li][li]Then Installer.[/li][li]Then Terminer.[/li][li]Then right clcick the ZHP Fix icon Run as admin.[/li][li]Copy the entire content of the code box below, the next step will grab it from your clipboard.[/li][li]Then click on import.[/li][li]Then click GO.[/li][li]If you see any Prompts like the one below, select Oui. = Yes in French.[/li][li]https://pchelpforum.net/attachments/upload_2017-5-24_21-17-40-png.2248/[/li]

                      [li]Allow completion.[/li][li]A log file will appear on your desktop.[/li][li]Post it here in your next reply.[/li][/ul]
                      Code:
                      Script Zhpfix
                      SysRestore
                      EmptyFlash
                      ProxyFix
                      EmptyCLSID
                      O42 - Logiciel: Facebook Gameroom 1.21.6663.39782 - (.Facebook.) [HKLM] -- {68176DF0-3139-406A-955D-E90916FB9EE8}  =>.Facebook
                      O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {D168AAD0-6686-47C1-B599-CDD4888B9D1A}  =>.Apple Inc.
                      C:\Program Files\Bonjour
                      C:\Program Files\HTC
                      C:\Windows\System32\drivers\ANDROIDUSB.sys
                      C:\Program Files\Common Files\AVG
                      C:\WINDOWS\System32\Tasks\AVG
                      C:\Users\talk2\AppData\Local\Facebook
                      O42 - Logiciel: HP Customer Participation Program 13.0 - (.HP.) [HKLM] -- HPExtendedCapabilities  =>.Hewlett Packard®
                      O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {7059BDA7-E1DB-442C-B7A1-6144596720A4}  =>.Hewlett-Packard
                      O42 - Logiciel: MarketResearch - (.Hewlett-Packard.) [HKLM] -- {175F0111-2968-4935-8F70-33108C6A4DE3}  =>.Hewlett-Packard (Hidden)
                      HKLM\SOFTWARE\AVG  =>.AVG Software
                      HKLM\SOFTWARE\Yahoo  =>.Yahoo! Inc.
                      HKCU\SOFTWARE\AvastAdSDK  =>.Avast Software s.r.o
                      HKCU\SOFTWARE\AVG  =>.AVG Software
                      HKCU\SOFTWARE\Browser Cleanup  =>.Avast Software s.r.o
                      HKCU\SOFTWARE\Chromium  =>.Chromium
                      HKCU\SOFTWARE\Yahoo  =>.Yahoo! Inc.
                      HKCU\SOFTWARE\AppDataLow\Software\Yahoo  =>.Yahoo! Inc.
                      HKU\S-1-5-21-632060980-672400531-471590194-1001\SOFTWARE\AvastAdSDK  =>.Avast Software s.r.o
                      HKU\S-1-5-21-632060980-672400531-471590194-1001\SOFTWARE\AVG  =>.AVG Software
                      HKU\S-1-5-21-632060980-672400531-471590194-1001\SOFTWARE\Browser Cleanup  =>.Avast Software s.r.o
                      HKU\S-1-5-21-632060980-672400531-471590194-1001\SOFTWARE\Chromium  =>.Chromium
                      HKU\S-1-5-21-632060980-672400531-471590194-1001\SOFTWARE\Facebook  =>.Facebook
                      HKU\S-1-5-21-632060980-672400531-471590194-1001\SOFTWARE\Yahoo  =>.Yahoo! Inc.
                      C:\Program Files\Yahoo! 
                      C:\ProgramData\AVG
                      C:\ProgramData\HTC
                      C:\Program Files\Common Files\AVG
                      C:\Users\talk2\AppData\Roaming\Yahoo!
                      C:\Users\talk2\AppData\Local\Avg
                      C:\Users\talk2\AppData\Local\Facebook
                      C:\Program Files\AVG
                      O87 - FAEL: "{F6951D83-0BFC-4510-9BC9-B63157F67166}" [In-None-P17-TRUE] .(...) -- C:\Program Files\AVG\Antivirus\AvEmUpdate.exe (.not file.)  =>.SUP.Orphan
                      O87 - FAEL: "{A00CA56F-ECFE-4828-8F59-24DC2A1FA5B4}" [In-None-P6-TRUE] .(...) -- C:\Program Files\AVG\Antivirus\AvEmUpdate.exe (.not file.)  =>.SUP.Orphan
                      O90 - PUC: "1110F57186925394F8073301C8A6D43E" [HKLM] . (.MarketResearch.)  =>.Market Research
                      O90 - PUC: "7ADB9507BD1EC2447B1A16449576024A" [HKLM] . (.HP Update.)  =>.Hewlett-Packard
                      O90 - PUC: "34180280D77760A4BB4517FBA01DBB07" [HKU] . (.IPTInstaller.)  =>.HTC Corporation
                      [MD5.96E897368CFF41E126E72FD5555D12D8] [WIS][2014/01/10 04:46:22] (.HTC.) -- C:\WINDOWS\Installer\28dc091d.msi   [614400]  =>.HTC
                      [MD5.85614BB500BFDA8DEC8381386F6192EA] [WIS][2018/03/31 01:10:43] (.Facebook - Facebook Gameroom 1.21.6663.39782.) -- C:\WINDOWS\Installer\62bf8a5.msi  [52593664]  =>.Facebook
                      C:\Users\talk2\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d10lpsik1i8c69.cloudfront.net_0.localstorage  =>.SUP.CloudfrontNet
                      C:\Users\talk2\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d10lpsik1i8c69.cloudfront.net_0.localstorage-journal  =>.SUP.CloudfrontNet
                      C:\Users\talk2\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d3jdlwnuo8nsnr.cloudfront.net_0.localstorage  =>.SUP.CloudfrontNet
                      C:\Users\talk2\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d3jdlwnuo8nsnr.cloudfront.net_0.localstorage-journal  =>.SUP.CloudfrontNet
                      C:\Users\talk2\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_d2m2wsoho8qq12.cloudfront.net_0.localstorage  =>.SUP.CloudfrontNet
                      C:\Users\talk2\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_d2m2wsoho8qq12.cloudfront.net_0.localstorage-journal  =>.SUP.CloudfrontNet
                      C:\Users\talk2\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_surveymyopinion.researchnow.com_0.localstorage  =>Adware.SearchNow
                      C:\Users\talk2\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_surveymyopinion.researchnow.com_0.localstorage-journal  =>Adware.SearchNow

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #56
                        Security Check Scan.

                        [ul]
                        [li]Download Security Check to your desktop.[/li][li]Right click it run as administrator.[/li][li]When the program completes, the tool will automatically open a log file.[/li][li]Please post that log here in your next post.[/li][/ul]
                        HijackThis.

                        1- Please click HERE to download HijackThis.
                        2- Run the program.
                        3- Click on the Main Menu button if not already there.
                        4- Select Do a system scan and save a logfile.
                        5- Copy paste the log here.

                        Comment

                        • Rusty_Rusty
                          PCHF Member
                          • Jul 2019
                          • 64

                          #57
                          Regarding ZHPFix, it chose to uninstall a few things. Here is the report attached.

                          Comment

                          • Rusty_Rusty
                            PCHF Member
                            • Jul 2019
                            • 64

                            #58
                            Regarding SecurityCheck, the log is attached

                            SecurityCheck by glax24 & Severnyj v.1.4.0.53 [27.10.17]
                            WebSite: www.safezone.cc
                            DateLog: 13.07.2019 06:23:44
                            Path starting: C:\Users\talk2\AppData\Local\Temp\SecurityCheck\Se curityCheck.exe
                            Log directory: C:\SecurityCheck
                            IsAdmin: True
                            User: ken&vicki
                            VersionXML: 6.63is-06.07.2019


                            Windows 10(6.3.17763) (x86) Core Release: 1809 Lang: English(0409)
                            Installation date OS: 20.01.2019 08:42:23
                            LicenseStatus: Windows(R), Core edition The machine is permanently activated.
                            LicenseStatus: Office 16, Office16O365HomePremR_Grace edition Windows is in Notification mode
                            Boot Mode: Normal
                            Default Browser: C:\Program Files\Google\Chrome\Application\chrome.exe
                            SystemDrive: C: FS: [NTFS] Capacity: [1861.5 Gb] Used: [56.2 Gb] Free: [1805.3 Gb]
                            ------------------------------- [ Windows ] -------------------------------
                            Internet Explorer 11.615.17763.0
                            User Account Control enabled (Level 3)
                            Security Center (wscsvc) - The service is running
                            Remote Registry (RemoteRegistry) - The service has stopped
                            SSDP Discovery (SSDPSRV) - The service is running
                            Remote Desktop Services (TermService) - The service has stopped
                            Windows Remote Management (WS-Management) (WinRM) - The service has stopped
                            Account guest is enabled. Not require a password.
                            ---------------------------- [ Antivirus_WMI ] ----------------------------
                            Windows Defender (disabled)
                            --------------------------- [ FirewallWindows ] ---------------------------
                            Windows Defender Firewall (mpssvc) - The service is running
                            --------------------------- [ AntiSpyware_WMI ] ---------------------------
                            Windows Defender (disabled)
                            --------------------------- [ OtherUtilities ] ----------------------------
                            FileZilla Client 3.42.1 v.3.42.1 Warning! Download Update
                            Microsoft Office 365 - en-us v.16.0.11727.20230
                            VLC media player v.3.0.7.1
                            OpenOffice 4.1.6 v.4.16.9790
                            Microsoft Silverlight v.5.1.50918.0
                            -------------------------------- [ Arch ] ---------------------------------
                            7-Zip 18.06 v.18.06 Warning! Download Update
                            Uninstall old version and install new one.
                            --------------------------------- [ P2P ] ---------------------------------
                            Shareaza 2.7.9.0 v.2.7.9.0 Warning! P2P-client.
                            -------------------------------- [ Java ] ---------------------------------
                            Java 8 Update 211 v.8.0.2110.12
                            Java SE Development Kit 8 Update 201 v.8.0.2010.9 Warning! Download Update
                            Uninstall old version and install new one (jdk-8u211-windows-i586.exe).
                            --------------------------- [ AppleProduction ] ---------------------------
                            iTunes v.12.6.1.25 Warning! Download Update
                            ^Please use Apple Software Update tool.[1]
                            --------------------------- [ AdobeProduction ] ---------------------------
                            Adobe Flash Player 32 PPAPI v.32.0.0.223
                            Adobe Acrobat Reader DC v.19.012.20035
                            ------------------------------- [ Browser ] -------------------------------
                            Google Chrome v.75.0.3770.100
                            Mozilla Firefox 60.0.2 (x86 en-US) v.60.0.2 Warning! Download Update
                            ----------------------------- [ EmailClient ] -----------------------------
                            Mozilla Thunderbird 60.8.0 (x86 en-US) v.60.8.0 [+]
                            ------------------ [ AntivirusFirewallProcessServices ] -------------------
                            C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\MsMpEng.exe v.4.18.1906.3
                            Windows Defender Antivirus Service (WinDefend) - The service is running
                            Windows Defender Antivirus Network Inspection Service (WdNisSvc) - The service has stopped
                            Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - The service has stopped
                            ----------------------------- [ End of Log ] ------------------------------

                            1. /b ↩︎

                            Comment

                            • Rusty_Rusty
                              PCHF Member
                              • Jul 2019
                              • 64

                              #59
                              Last but not least here is the HijackThis log attached. But I have more to say. I rebooted and the problem persists but it is still rather minor. I cannot utilize Cortana regardless of how I elect it to appear on the Taskbar. And it won’t launch when clicked on in the Start menu pane to which it is pinned (system came that way). I don’t know any other way to use/launch it since I don’t find in within C: Program Files. Maybe it is in there within “Windows Apps” which is a folder to which I haven’t even read permission, the owner being “Trusted Installer”. I believe there is a method/protocol for me to take over ownership of that folder and get inside it but I am not sure the exact procedure and have no current interest. I rarely utilize Cortana as I know how to search my files and on the Internet, but on a rare occasion it has proven helpful. And in the Start menu the 5 buttons on the left beside my Programs list don’t work, as I stated previously.

                              Comment

                              • Malnutrition
                                PCHF Moderator
                                • Jul 2016
                                • 7041

                                #60
                                Hijack This Fix.

                                Start HijackThis , Right Click Run as Admin.
                                Close all other open programs prior to running this tool!!
                                Click System Scan Only.
                                Then check mark the items listed below.

                                O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Qshelf.lnk → C:\Program Files\Bookshelf 98\qshelf98.exe
                                O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk → C:\Program Files\Quicken\bagent.exe
                                O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Quicken Startup.lnk → C:\Program Files\Quicken\QWDLLS.EXE
                                O4 - HKCU..\StartupApproved\Run: [OneDrive] = C:\Users\talk2\AppData\Local\Microsoft\OneDrive\On eDrive.exe /background (2017/07/11)
                                O4 - HKLM..\Run: [HP Software Update] = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                4 - HKLM..\Run: [SunJavaUpdateSched] = C:\Program Files\Common Files\Java\Java Update\jusched.exe
                                O4 - HKLM..\StartupApproved\Run: [AdobeCS6ServiceManager] = C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.ex e -launchedbylogin (2018/04/08)
                                O4 - HKLM..\StartupApproved\Run: [AdobeGCInvoker-1.0] = C:\Program Files\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe (2018/04/03)
                                O4 - HKLM..\StartupApproved\Run: [SwitchBoard] = C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (2019/07/12)
                                O4 - HKLM..\StartupApproved\Run: [iTunesHelper] = C:\Program Files\iTunes\iTunesHelper.exe (2017/07/11)
                                O4 - HKLM..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Billminder.lnk → C:\Program Files\Quicken\billmind.exe -startup (2017/07/11)
                                O4 - HKLM..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk → C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (2017/07/11)
                                O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] = C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (Microsoft)
                                O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] = C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (Microsoft)
                                O23 - Service R2: Internet Pass-Through Service - (PassThru Service) - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
                                O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpda teService.exe

                                Now click on fix checked.
                                After the fix is complete, then reboot your machine.

                                Temp File Cleaner.


                                [ul]
                                [li] Note: This program may very well reboot your machine. Save any work prior to running.[/li][li]Clean up your temp files with TFC.exe[/li][li]Save it to your desktop.[/li][li]Right click run as admin.[/li][/ul]

                                Comment

                                Working...