• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Solved URGENT: PC still not working optimal

Status
Not open for further replies.
Hi,

The pc of my dad was infected, i've runned several scans with Malwarebytes, roquekiller, ESet online scanner and removed several virusses. Either i get still some messages from Microsoft defender that processes has been blocked. I've createad a FRST logs and i see some error messages, but he need his PC back asap. Can someone help me pls?
 

Attachments

  • Addition.txt
    40.6 KB · Views: 0
  • FRST.txt
    38.7 KB · Views: 0
Uninstall with Geek Uninstaller.

Malwarebytes version 5.0.17.99
RogueKiller version 15.15.2.0
SUPERAntiSpyware

All are running on the machine and provide no real protection unless they are the paid version. You could keep if they are pro versions.

Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.


Code:
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
RemoveProxy:
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restrictie <==== AANDACHT
GroupPolicy: Restrictie ? <==== AANDACHT
Policies: C:\ProgramData\NTUSER.pol: Restrictie <==== AANDACHT
S3 cpuz152; \??\C:\Windows\temp\cpuz152\cpuz152_x64.sys [X] <==== AANDACHT
2024-03-01 00:26 - 2019-12-07 16:12 - 000799568 _____ C:\Windows\system32\perfh013.dat
2024-03-01 00:26 - 2019-12-07 16:12 - 000158280 _____ C:\Windows\system32\perfc013.dat
Shortcut: C:\Users\Robbie\Desktop\(64х)Euro Truck Simulator 2.lnk -> C:\Games\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software) <==== Cyrillic
ShortcutWithArgument: C:\Users\Robbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-apps\YouTube.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml
C:\Windows\system32\drivers\etc\hosts
Hosts:
FirewallRules: [{30AA67DA-C613-4A65-A39E-51956A8C1FBD}] => (Block) C:\Program Files\Image-Line\FL Studio 20\FL64.exe (Image Line -> Image-Line) [Bestand niet getekend]
FirewallRules: [{4987147D-E3E5-444D-B108-50C6A42E553A}] => (Block) C:\Program Files\Image-Line\FL Studio 20\FL64.exe (Image Line -> Image-Line) [Bestand niet getekend]
FirewallRules: [{95C5DF3B-EAF2-4F96-AC1B-3C4A942A3DDF}] => (Block) C:\Program Files\Image-Line\FL Studio 20\FL64.exe (Image Line -> Image-Line) [Bestand niet getekend]
FirewallRules: [{9A315141-DCB7-4CEB-854D-8230112F7D52}] => (Block) C:\Program Files\Image-Line\FL Studio 20\FL64.exe (Image Line -> Image-Line) [Bestand niet getekend]
cmd: net stop bits
Move: C:\ProgramData\Microsoft\Network\Downloader\qmgr*.db C:\ProgramData\Microsoft\Network\Downloader\qmgr*.db.old
cmd: net start bits
CMD: del /f /s /q %windir%\prefetch\*.*
CMD: del /s /q C:\Windows\SoftwareDistribution\download\*.*
CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
CMD: ipconfig /flushdns
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
emptytemp:
Reboot:
End::





Download ZHP Suite to your desktop.
Unzip it there.
Right Click Run as admin.
Hit the scanner button.
Once it is complete a file name ZHPdiag.txt will be on your desktop.
Attach it.
 

Attachments

  • ZHPSuite.zip
    2.9 MB · Views: 5
Sorry for the late reply, have been very busy.



But in the end, the pc crashed so, i've reinstalled Windows again and everything and its works fine now. I will open a new topic for my own pc for a check
:)




Thanks for the fast reply! Really appreciate the help
 
Status
Not open for further replies.