Password reset and notification emails are now sending correctly.
If you recently requested a password reset, please check your inbox (and spam folder just in case).
You can now reset your password and log in as normal.
Welcome back to PCHF, and thank you for your patience during our migration process!
— The PCHF Team
Welcome to PC Help Forum!
You’re viewing our community as a guest.
That means you can browse posts, but can’t yet reply or start new topics.
Join us today — it's completely free!
As a member, you'll be able to:
✅ Get personalized tech support from trusted volunteers
🦠 Work one-on-one with our Malware Removal Specialists
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-04-2023
Ran by Tammie (administrator) on DESKTOP-GRCHUA0 (HP HP Pavilion x360 Convertible 15-cr0xxx) (08-04-2023 19:21:36)
Running from C:\Users\Tammie\OneDrive\Desktop
Loaded Profiles: Tammie
Platform: Microsoft Windows 11 Home Version 22H2 22621.1413 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
[HEADING=1]Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-04-2023
Ran by Tammie (08-04-2023 19:24:05)
Running from C:\Users\Tammie\OneDrive\Desktop
Microsoft Windows 11 Home Version 22H2 22621.1413 (X64) (2023-04-05 15:56:12)
Boot Mode: Normal[/HEADING]
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee VirusScan (Enabled - Up to date) {FE987762-0FB6-6BB6-1BF1-73F8ED8566FA}
FW: McAfee Firewall (Enabled) {C6A3F647-45D9-6AEE-30AE-DACD13562181}
==================== Event log errors: ========================
[HEADING=1]Application errors:[/HEADING]
Error: (04/07/2023 11:47:41 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.22621.1344_no ne_e953938a42d5ff76\TiWorker.exe -Embedding; Description = Windows Modules Installer; Error = 0x80042319).
Error: (04/07/2023 11:47:41 PM) (Source: SPP) (EventID: 16387) (User: )
Description: Writer MSSearch Service Writer experienced some error during snapshot creation.
More info: .
Error: (04/06/2023 07:30:19 PM) (Source: HP Comm Recovery) (EventID: 0) (User: )
Description: Failed in handling the PowerEvent. The error that occurred was: System.IO.IOException: The process cannot access the file ‘C:\Windows\Temp\signtool.exe’ because it is being used by another process.
at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath)
at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)
at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy)
at System.IO.FileStream..ctor(String path, FileMode mode)
at _HPCommRecovery.Tools.Signtool.ExtractSignTool()
at _HPCommRecovery.Tools.Signtool.Verify(String arg)
at _HPCommRecovery.HPAHAgent.CallAgent()
at _HPCommRecovery.AppSession..ctor(DateTime Current, String LogPath)
at _HPCommRecovery.HPAHLogger.NewSession()
at _HPCommRecovery…
Error: (04/06/2023 07:30:17 PM) (Source: HP Comm Recovery) (EventID: 0) (User: )
Description: Failed in handling the PowerEvent. The error that occurred was: System.IO.IOException: The process cannot access the file ‘C:\Windows\Temp\signtool.exe’ because it is being used by another process.
at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath)
at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)
at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy)
at System.IO.FileStream..ctor(String path, FileMode mode)
at _HPCommRecovery.Tools.Signtool.ExtractSignTool()
at _HPCommRecovery.Tools.Signtool.Verify(String arg)
at _HPCommRecovery.HPAHAgent.CallAgent()
at _HPCommRecovery.AppSession..ctor(DateTime Current, String LogPath)
at _HPCommRecovery.HPAHLogger.NewSession()
at _HPCommRecovery…
Error: (04/06/2023 12:03:18 AM) (Source: HP Comm Recovery) (EventID: 0) (User: )
Description: Failed in handling the PowerEvent. The error that occurred was: System.IO.IOException: The process cannot access the file ‘C:\Windows\Temp\signtool.exe’ because it is being used by another process.
at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath)
at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)
at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy)
at System.IO.FileStream..ctor(String path, FileMode mode)
at _HPCommRecovery.Tools.Signtool.ExtractSignTool()
at _HPCommRecovery.Tools.Signtool.Verify(String arg)
at _HPCommRecovery.HPAHAgent.CallAgent()
at _HPCommRecovery.AppSession..ctor(DateTime Current, String LogPath)
at _HPCommRecovery.HPAHLogger.NewSession()
at _HPCommRecovery…
Error: (04/04/2023 02:20:02 PM) (Source: MSDTC Client 2) (EventID: 4104) (User: )
Description: Failed trying to get the state of the cluster node: .The error code returned: 0x8007085A
Error: (04/04/2023 02:18:01 PM) (Source: MSDTC Client 2) (EventID: 4104) (User: )
Description: Failed trying to get the state of the cluster node: .The error code returned: 0x8007085A
[HEADING=1]System errors:[/HEADING]
Error: (04/08/2023 07:07:49 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GRCHUA0)
Description: The server {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} did not register with DCOM within the required timeout.
Error: (04/08/2023 05:33:37 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9MV0B5HZVK9Z-Microsoft.GamingApp.
Error: (04/08/2023 12:18:08 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (04/06/2023 07:55:44 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (04/06/2023 06:00:27 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (04/06/2023 11:41:02 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GRCHUA0)
Description: The server microsoft.windowscommunicationsapps_16005.14326.21 374.0_x64__8wekyb3d8bbwe!microsoft.windowslive.cal endar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout.
Error: (04/05/2023 12:00:49 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (04/05/2023 11:20:42 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GRCHUA0)
Description: The server {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} did not register with DCOM within the required timeout.
[HEADING=1]CodeIntegrity:[/HEADING]
Date: 2023-04-08 19:05:53
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\CastSrv. exe) attempted to load \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: Insyde F.23 04/29/2019
Motherboard: HP 8488
Processor: Intel(R) Core™ i5-8250U CPU @ 1.60GHz
Percentage of memory in use: 69%
Total physical RAM: 8026.16 MB
Available physical RAM: 2411.21 MB
Total Virtual: 9562.16 MB
Available Virtual: 2872.93 MB
[ul]
[li]Download AdwCleaner and save it to your Desktop[/li][li]Right-click on AdwCleaner.exeand select, Run as Administrator[/li][li]Accept the EULA (I accept), then click on Scan Now[/li][li]Let the scan complete[/li][li]Once the scan completes, make sure that every item listed in the different tabs is checked and click on the Quarantine and delete.[/li][li]Once the cleaning process is complete, AdwCleaner will ask you to restart your computer[/li][li]Close all other open windows and allow it to restart[/li][li]After the restart, Notepad will open with the AdwCleaner cleaning log[/li][li]Please Attach the contents of that log into your next reply to me[/li][/ul]
Download Malwarebytes v.4 . Install and run.
[ul]
[li]Once the MBAM dashboard opens, click on Settings (gear icon).[/li][li]Click on Security tab and make sure that all four Scan options are enabled.[/li][li]Close Settings and click on the Scan button on the dashboard.[/li][li]Once the scan is completed make sure you have it quarantine any detections it finds.[/li][li]If no detections were found click on the Save results drop-down, then the Export to TXT button and save the file as a Text file to your desktop.[/li][li]If there were detections then once the quarantine has completed click on the View report button, then click the Export drop-down, then the Export to TXT button, and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.[/li][li]If the computer restarted to quarantine you can access the logs from the Detection History, then the History tab. Highlight the most recent scan and double-click to open it. Then click the Export drop-down, then the Export to TXT button, and save the file as a Text file to your desktop or other location you can find and include that log on your next reply.[/li][/ul]
There will be a new zip file created on your desktop, please attach it.
Seems to be no malware that I am seeing, this fix will remove some rubbish, and send a couple files to virus total for checking.
Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.
I’m confused - what is the zip file that should be attached to my desktop? There is none - what is it supposed to be? I’m holding off on copying the code for now.
With the command below. Via FRST, this will move a zipped copy of this folder to your desktop. I find it highly strange that there is a zip file in your drivers folder, that is part of the malware removal process, is to spot the anomalies
Strange - my message from yesterday didn’t post. Anyway, I’m still confused - can you simplify? I’m not sure what you’re saying about the command in the FRST fix. Do you want me to move the zip file from Zip: C:\WINDOWS\system32\Drivers\rtkhdasetting.zip to my desktop? And then run the exe file?
C:\Windows\Temp.ses => moved successfully
C:\Windows\Temp\39CDDD4.tmp => moved successfully
C:\Windows\Temp\Application_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Application_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\AppxErrorReport_12BAA6D7-67D7-0001-7717-DD12D767D901.txt => moved successfully
C:\Windows\Temp\AppxErrorReport_12BAA6D7-67D7-0005-176B-C112D767D901.txt => moved successfully
C:\Windows\Temp\chrome_installer.log => moved successfully
C:\Windows\Temp\CSPInstall.log => moved successfully
C:\Windows\Temp\CSPUninstall.log => moved successfully
C:\Windows\Temp\dba00e65-7c7c-47f8-b93c-f9bc11b0a2ba.tmp => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230404-1417.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230405-1056.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230405-1101.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230405-1102.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230405-1102a.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230405-1152.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230405-1155.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230405-1204.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230405-1206.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230405-1336.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-1140.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-1146.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-1159.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-1551.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-1556.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-1807.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-1828.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-2011.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-2019.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230406-2021.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230407-1207.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230407-1213.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230407-1213a.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230407-1214.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230407-1217.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230407-2347.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230407-2347a.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230408-1210.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230408-1216.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230408-1216a.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230408-1216b.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230408-1744.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230408-1910.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230408-1949.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230410-0925.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230410-0930.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230410-0936.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230410-0937.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230410-1012.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230410-1254.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230410-1346.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1118.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1124.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1124a.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1129.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1217.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1258.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1303.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1409.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1441.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1540.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1601.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1633.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1639.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-1717.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-2008.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-2011.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-2016.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-2036.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-2056.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230411-2140.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-0713.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-0718.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-1815.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-1821.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-1838.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-2052.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-2055.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-2103.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-2109.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-2120.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230412-2136.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-0007.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-0211.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-0354.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-0357.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-0400.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-0400a.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-0404.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-2021.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-2025.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-2025a.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-2032.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-2033.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-2036.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-2105.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230413-2205.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230414-2149.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230415-0751.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230415-0751a.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230415-0751b.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230415-0755.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230415-0756.log => moved successfully
C:\Windows\Temp\DESKTOP-GRCHUA0-20230415-0756a.log => moved successfully
Could not move “C:\Windows\Temp\DESKTOP-GRCHUA0-20230415-0801.log” => Scheduled to move on reboot.
C:\Windows\Temp\FusionRestarter-expand.log => moved successfully
Could not move “C:\Windows\Temp\FXSAPIDebugLogFile.txt” => Scheduled to move on reboot.
Could not move “C:\Windows\Temp\FXSTIFFDebugLogFile.txt” => Scheduled to move on reboot.
C:\Windows\Temp\mbamiservice.log => moved successfully
C:\Windows\Temp\mb_errors999.log => moved successfully
C:\Windows\Temp\Microsoft-Windows-AppReadiness_Admin_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-AppReadiness_Admin_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-AppReadiness_Operational_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-AppReadiness_Operational_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-AppXDeploymentServer_Operational_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-AppXDeploymentServer_Operational_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-AppXPackaging_Operational_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-AppXPackaging_Operational_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-SettingSync_Debug_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-SettingSync_Debug_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-SettingSync_Operational_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-SettingSync_Operational_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-StateRepository_Operational_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-StateRepository_Operational_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-Store_Operational_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-Store_Operational_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-WindowsUpdateClient_Operational_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\Microsoft-Windows-WindowsUpdateClient_Operational_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\msedge_installer.log => moved successfully
C:\Windows\Temp\nsa2EE8.tmp => moved successfully
C:\Windows\Temp\nsa2EE8.tmp.exe => moved successfully
C:\Windows\Temp\nsa469C.tmp => moved successfully
C:\Windows\Temp\nsa469C.tmp.exe => moved successfully
C:\Windows\Temp\nsb340D.tmp => moved successfully
C:\Windows\Temp\nsb340D.tmp.exe => moved successfully
C:\Windows\Temp\nsb3429.tmp => moved successfully
C:\Windows\Temp\nsb3429.tmp.exe => moved successfully
C:\Windows\Temp\nsd68B5.tmp => moved successfully
C:\Windows\Temp\nsd68B5.tmp.exe => moved successfully
C:\Windows\Temp\nsdB48F.tmp.exe => moved successfully
C:\Windows\Temp\nsdD1A5.tmp => moved successfully
C:\Windows\Temp\nsdD1A5.tmp.exe => moved successfully
C:\Windows\Temp\nse2B1A.tmp.exe => moved successfully
C:\Windows\Temp\nsf1EB.tmp => moved successfully
C:\Windows\Temp\nsf1EB.tmp.exe => moved successfully
C:\Windows\Temp\nsg198E.tmp.exe => moved successfully
C:\Windows\Temp\nsgB2D2.tmp => moved successfully
C:\Windows\Temp\nsgB2D2.tmp.exe => moved successfully
C:\Windows\Temp\nsi63FA.tmp => moved successfully
C:\Windows\Temp\nsi63FA.tmp.exe => moved successfully
C:\Windows\Temp\nsiF44E.tmp.exe => moved successfully
C:\Windows\Temp\nsjB54D.tmp => moved successfully
C:\Windows\Temp\nsjB54D.tmp.exe => moved successfully
C:\Windows\Temp\nsjBA41.tmp => moved successfully
C:\Windows\Temp\nsjBA41.tmp.exe => moved successfully
C:\Windows\Temp\nskDD7E.tmp => moved successfully
C:\Windows\Temp\nskDD7E.tmp.exe => moved successfully
C:\Windows\Temp\nslE49B.tmp => moved successfully
C:\Windows\Temp\nslE49B.tmp.exe => moved successfully
C:\Windows\Temp\nsn922B.tmp.exe => moved successfully
C:\Windows\Temp\nso3BDC.tmp => moved successfully
C:\Windows\Temp\nso3BDC.tmp.exe => moved successfully
C:\Windows\Temp\nsp960F.tmp => moved successfully
C:\Windows\Temp\nsp960F.tmp.exe => moved successfully
C:\Windows\Temp\nsq88EA.tmp => moved successfully
C:\Windows\Temp\nsq88EA.tmp.exe => moved successfully
C:\Windows\Temp\nsq96C6.tmp => moved successfully
C:\Windows\Temp\nsq96C6.tmp.exe => moved successfully
C:\Windows\Temp\nsr8CFD.tmp.exe => moved successfully
C:\Windows\Temp\nsrCF.tmp => moved successfully
C:\Windows\Temp\nsrCF.tmp.exe => moved successfully
C:\Windows\Temp\nss2420.tmp => moved successfully
C:\Windows\Temp\nss2420.tmp.exe => moved successfully
C:\Windows\Temp\nss3AF6.tmp => moved successfully
C:\Windows\Temp\nss3AF6.tmp.exe => moved successfully
C:\Windows\Temp\nst2177.tmp.exe => moved successfully
C:\Windows\Temp\nsu5156.tmp.exe => moved successfully
C:\Windows\Temp\nsuF91A.tmp => moved successfully
C:\Windows\Temp\nsuF91A.tmp.exe => moved successfully
C:\Windows\Temp\nsv2805.tmp => moved successfully
C:\Windows\Temp\nsv2805.tmp.exe => moved successfully
C:\Windows\Temp\nsvF059.tmp => moved successfully
C:\Windows\Temp\nsvF059.tmp.exe => moved successfully
C:\Windows\Temp\nsw1CDC.tmp => moved successfully
C:\Windows\Temp\nsw1CDC.tmp.exe => moved successfully
C:\Windows\Temp\nsw8C7E.tmp.exe => moved successfully
C:\Windows\Temp\nswB1D0.tmp => moved successfully
C:\Windows\Temp\nswB1D0.tmp.exe => moved successfully
C:\Windows\Temp\nsx7C09.tmp.exe => moved successfully
C:\Windows\Temp\nsxC05D.tmp => moved successfully
C:\Windows\Temp\nsxC05D.tmp.exe => moved successfully
C:\Windows\Temp\nsy61C6.tmp => moved successfully
C:\Windows\Temp\nsy61C6.tmp.exe => moved successfully
C:\Windows\Temp\nsy7744.tmp.exe => moved successfully
C:\Windows\Temp\nsyF2D6.tmp.exe => moved successfully
C:\Windows\Temp\nsz47FD.tmp => moved successfully
C:\Windows\Temp\nsz47FD.tmp.exe => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver( 202304071216567194).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver( 2023041009300714CC).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver( 20230415075536183FC).log => moved successfully
Could not move “C:\Windows\Temp\officeclicktorun.exe_streamserver (20230415080128142EC).log” => Scheduled to move on reboot.
C:\Windows\Temp\perfboost.exe_c2rdll(2023040712170 63844).log => moved successfully
C:\Windows\Temp\perfboost.exe_c2rdll(2023041320322 413710).log => moved successfully
C:\Windows\Temp\perfboost.exe_c2rdll(2023041507555 417A98).log => moved successfully
C:\Windows\Temp\System_12BAA6D7-67D7-0001-7717-DD12D767D901.evtx => moved successfully
C:\Windows\Temp\System_12BAA6D7-67D7-0005-176B-C112D767D901.evtx => moved successfully
C:\Windows\Temp\TS_A2B8.tmp => moved successfully
C:\Windows\Temp\TS_A2D8.tmp => moved successfully
C:\Windows\Temp\wbxtra_04102023_093006.wbt => moved successfully
C:\Windows\Temp\wbxtra_04112023_201141.wbt => moved successfully
C:\Windows\Temp\wbxtra_04132023_035420.wbt => moved successfully
C:\Windows\Temp\wct10C.tmp => moved successfully
C:\Windows\Temp\wct1D10.tmp => moved successfully
C:\Windows\Temp\wct25CC.tmp => moved successfully
C:\Windows\Temp\wct26A7.tmp => moved successfully
C:\Windows\Temp\wct43BD.tmp => moved successfully
C:\Windows\Temp\wct48F5.tmp => moved successfully
C:\Windows\Temp\wct4B32.tmp => moved successfully
C:\Windows\Temp\wct4B38.tmp => moved successfully
C:\Windows\Temp\wct4EB4.tmp => moved successfully
C:\Windows\Temp\wct4EFB.tmp => moved successfully
C:\Windows\Temp\wct543D.tmp => moved successfully
C:\Windows\Temp\wct7053.tmp => moved successfully
C:\Windows\Temp\wct78DD.tmp => moved successfully
C:\Windows\Temp\wct7F4.tmp => moved successfully
C:\Windows\Temp\wct8293.tmp => moved successfully
C:\Windows\Temp\wct893F.tmp => moved successfully
C:\Windows\Temp\wct94AB.tmp => moved successfully
C:\Windows\Temp\wctB02B.tmp => moved successfully
C:\Windows\Temp\wctC490.tmp => moved successfully
C:\Windows\Temp\wctD144.tmp => moved successfully
C:\Windows\Temp\wctD8F.tmp => moved successfully
C:\Windows\Temp\wctD998.tmp => moved successfully
C:\Windows\Temp\wctE031.tmp => moved successfully
========= End → “C:\Windows\Temp*.*” ========
=========== “C:\WINDOWS\system32*.tmp” ==========
not found
========= End → “C:\WINDOWS\system32*.tmp” ========
=========== “C:\WINDOWS\syswow64*.tmp” ==========
not found
========= End → “C:\WINDOWS\syswow64*.tmp” ========
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9511392 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 411688 B
Edge => 5886831 B
Chrome => 24572510 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 681648 B
NetworkService => 681648 B
Tammie => 12223907 B
RecycleBin => 0 B
EmptyTemp: => 52.7 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 15-04-2023 08:08:51)
C:\Windows\Temp\DESKTOP-GRCHUA0-20230415-0801.log => Is moved successfully
C:\Windows\Temp\FXSAPIDebugLogFile.txt => Could not move
C:\Windows\Temp\FXSTIFFDebugLogFile.txt => Could not move
C:\Windows\Temp\officeclicktorun.exe_streamserver( 20230415080128142EC).log => Is moved successfully
Select „Ok“ in the Run box.
If the „Windows protected your PC“ window opens, select „More info“. A new windows will open, select „Run anyway“.
An EULA window from KVRT will open, tick all confirmation boxes then select “Accept”.
A window from KVRT will open, select “Change Parameters”.
In the new window ensure the following boxes are ticked:
[ul]
[li]System memory[/li][li]Startup objects[/li][li]Boot sectors[/li][li]System drive[/li][/ul]
Then select “OK” and „Start scan“.
When completed: If entries are found, there will be options to choose. If “Cure” is offered, leave as it is. For any other options change to “Delete”, then select “Continue”.
Usually, your system needs a reboot to finish the removal process.
Logfiles can be found on your systemdrive (usually C: ), similar like this:
C:\KVRT2020_Data\Reports\report__.klr
Right click direct onto those reports, select > open with > Notepad.
Save the files and attach them with your next reply.[/COLOR]
I did not get a prompt to reboot. There were three items found that I deleted. Attached is the notepad file, although it seems gibberish. I’ll reboot and see if it changes.
That is definitely gibberish. Which indicates The tool was ran without the instructions provided to not encrypt. Because of this, there will be no log of what was detected. Not the end of the world…
Can you remember what items were detected? Also, are there anymore issues to speak of?
Let’s take a look at things with one last tool.
ZHP Diag Scanner.
Download ZHP Suite to your desktop.
Right Click Run as admin.
Hit the scanner button.
Once it is complete a file name ZHPdiag.txt will be on your desktop.
Attach it.
We process personal data about users of our site, through the use of cookies and other technologies, to deliver our services, personalize advertising, and to analyze site activity. We may share certain information about our users with our advertising and analytics partners. For additional details, refer to our Privacy Policy.
By clicking "I AGREE" below, you agree to our Privacy Policy and our personal data processing and cookie practices as described therein. You also acknowledge that this forum may be hosted outside your country and you consent to the collection, storage, and processing of your data in the country where this forum is hosted.
Comment