Copy the content of the code box below.
Do not copy the word code!!!
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.
Download and unzip farbar service scanner to your desktop, right click and run as admin…check all boxes and hit scan.
Post the log created.
Do not copy the word code!!!
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.
Code:
Start::
CreateRestorePoint:
CloseProcesses:
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
CHR Extension: (Social Blade) - C:\Users\eiko-\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfidkbgamfhdgmedldkagjopnbobdmdn [2022-09-04] [UpdateUrl:hxxps://addon.socialblade.com/updates.json] <==== ATTENTION
C:\Users\eiko-\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfidkbgamfhdgmedldkagjopnbobdmdn
2024-03-04 09:34 - 2024-03-04 09:34 - 000758086 _____ C:\WINDOWS\system32\perfh007.dat
2024-03-04 09:34 - 2024-03-04 09:34 - 000156254 _____ C:\WINDOWS\system32\perfc007.dat
AlternateDataStreams: C:\Windows:CM_2a732c3f1e3eb40b63fe062d0180f157c71684af0a0442ab953224075801bb78 [74]
AlternateDataStreams: C:\Windows:CM_bf41c588bad5a092a453669c0d3c66d1ec2c072fbf5c15cc6acda24c9e4d0955 [74]
HKU\S-1-5-21-1421055718-2087356316-1872245878-1001\Software\Classes\regfile: <==== ATTENTION
FirewallRules: [{B2A138D0-F9E4-4698-9DD1-1EB7C7AD2D8A}] => (Allow) D:\Programme\Overwolf\0.242.0.11\OverwolfBrowser.exe => No File
FirewallRules: [{415602F8-E1B7-4ABF-9E7D-6815C6D59696}] => (Allow) D:\Programme\Overwolf\0.242.0.11\OverwolfBrowser.exe => No File
FirewallRules: [{45244B3F-8373-4486-A556-B3E76E3EECE6}] => (Block) D:\Programme\Overwolf\0.242.0.11\OverwolfBrowser.exe => No File
FirewallRules: [{DA1A8918-44D1-4DA1-A159-037A7957C8FC}] => (Block) D:\Programme\Overwolf\0.242.0.11\OverwolfBrowser.exe => No File
FirewallRules: [{58963355-4A3E-44B9-9C42-5E84E86DFC04}] => (Allow) LPort=26820
FirewallRules: [{5D09B55C-3DD2-4CFA-906F-0AA480ADEC0C}] => (Allow) LPort=26822
C:\Users\eiko-\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfidkbgamfhdgmedldkagjopnbobdmdn
C:\Program Files\Avast Software
C:\Program Files (x86)\Avira
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
C:\ProgramData\Avira
C:\Users\eiko-\AppData\Local\Avira
DeleteKey: HKLM\SOFTWARE\1D0EC6DE-4A80-4CC3-A335-E6E41C951198
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Avast Software
DeleteKey: HKCU\SOFTWARE\Avast Software
DeleteKey: HKU\S-1-5-21-1421055718-2087356316-1872245878-1001\SOFTWARE\Avast Software
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Avira =>.Avira
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Lavasoft
DeleteKey: HKCU\SOFTWARE\Lavasoft
DeleteKey: HKU\S-1-5-21-1421055718-2087356316-1872245878-1001\SOFTWARE\Lavasoft
DeleteKey: HKCU\SOFTWARE\Avast Software
DeleteKey: HKCU\SOFTWARE\Avira
File: C:\ProgramData\cm-lock
File: C:\WINDOWS\System32\drivers\RoutePolicy.sys
Startbatch:
RD /S /Q "%windir%\System32\GroupPolicyUsers"
RD /S /Q "%windir%\System32\GroupPolicy"
gpupdate /force
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies" /f
reg delete "HKCU\Software\Policies" /f
reg delete "HKLM\Software\Microsoft\Policies" /f
reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies" /f
reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WindowsStore\WindowsUpdate" /f
reg delete "HKLM\Software\Policies" /f
reg delete "HKLM\Software\WOW6432Node\Microsoft\Policies" /f
reg delete "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies" /f
reg delete "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\WindowsStore\WindowsUpdate" /f
REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v SupportUwpStartupTasks /t REG_DWORD /d 1 /f
REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableFullTrustStartupTasks /t REG_DWORD /d 2 /f
REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableUwpStartupTasks /t REG_DWORD /d 2 /f
REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v SupportFullTrustStartupTasks /t REG_DWORD /d 1 /f
endbatch:
emptytemp:
Reboot:
End::
Download and unzip farbar service scanner to your desktop, right click and run as admin…check all boxes and hit scan.
Post the log created.
Comment