1
General Software News, Updates & Discussions / Re: Microsoft Optional Cumulative Update For WIndows 10 Versions 2004 and 20H2
« on: February 26, 2021, 05:10:01 PM »
Think about it...!!!

It's in Bulgarian ..but of course ..!

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Start::
CreateRestorePoint:
CloseProcesses:
C:\Users\Gordon & Nancy\AppData\Local\Temp\Rar$EXa3416.38939\Malwarebytes.Premium.4.1.2.73.msstdfmt\LicenseMalwareBytes.exe.log
C:\Users\Gordon & Nancy\AppData\Local\Temp\mwb9BE9.tmp\Malwarebytes EULA.rtf
C:\Users\Gordon & Nancy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_Malwarebytes_Privacy_UI_MBPrivacy_exe
C:\Users\Gordon & Nancy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_HitmanPro_Alert_hmpalert_exe
C:\Users\Gordon & Nancy\AppData\Local\glasswire
C:\Users\Gordon & Nancy\AppData\Local\Temp\Rar$EXa3416.38939\Malwarebytes.Premium.4.1.2.73.msstdfmt
C:\Users\Gordon & Nancy\AppData\Local\Temp\Rar$DRa4488.8800\Malwarebytes.Premium.4.1.2.73.msstdfmt
C:\Users\Gordon & Nancy\AppData\Local\Temp\Rar$DRa4488.7946\Malwarebytes.Premium.4.1.2.73.msstdfmt
StartRegedit:
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\SYSTEM\GlassWire]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gwdrv]
"DisplayName"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gwdrv]
"Description"="GlassWire Driver"
[-HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppBadgeUpdated]
"{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\GlassWire\GlassWire.exe"="514"
[-HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched]
"{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\GlassWire\GlassWire.exe"="13"
[-HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView]
"{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\GlassWire\GlassWire.exe"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FAC02B7-77D6-418B-AC11-962C65CDE8DD}]
""=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\HitmanPro.Alert Shell Extension]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\hitmanpro37]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\hitmanpro37.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\HitmanPro.Alert]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\HitmanPro.Alert]
"EventMessageFile"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\HitmanPro.Alert]
"CategoryMessageFile"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hmpalert]
"DisplayName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{23007AD3-69FE-687C-2629-D584AFFAF72B}]
"DISPLAYNAME"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{23007AD3-69FE-687C-2629-D584AFFAF72B}]
"PRODUCTEXE"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{23007AD3-69FE-687C-2629-D584AFFAF72B}]
"REPORTINGEXE"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]
"Malwarebytes Windows Firewall Control"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{36B3D25E-9F02-4C24-9E19-958500BDF3FC}]
"ProfileName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{36B3D25E-9F02-4C24-9E19-958500BDF3FC}]
"Description"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Malwarebytes]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\WinsockUpgrade\WinSock2\Parameters\AppId_Catalog\0462E881]
"AppFullPath"=-
[-HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Malwarebytes Support Tool]
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppBadgeUpdated]
"Malwarebytes.Antimalware"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched]
"Malwarebytes.Antimalware"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched]
"{6D809377-6AF0-444B-8957-A3773F02200E}\Malwarebytes\Anti-Malware\mbuns.exe"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts]
"C:\Users\Gordon & Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts]
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData]
"Malwarebytes.Antimalware"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\UFH\SHC]
"15"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\UFH\SHC]
"16"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows\CurrentVersion\UFH\SHC]
"19"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe"=-
[HKEY_USERS\S-1-5-21-3675653720-2737141039-3862127861-1002\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"C:\Program Files\Malwarebytes\Anti-Malware\mbuns.exe"=-
EndRegedit:
EmptyTemp:
End::
SearchAll: GlassWire;HitmanPro;MalwareBytes
They have been removed awhile ago not using them
Windows Defender:
===================================
Date: 2020-10-29 14:42:40.562
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\AppData\Local\Temp\Rar$DRa4488.8800\Malwarebytes.Premium.4.1.2.73.msstdfmt\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4
Date: 2020-10-29 14:39:27.851
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\AppData\Local\Temp\Rar$EXa3416.38939\Malwarebytes.Premium.4.1.2.73.msstdfmt\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Program Files\WinRAR\WinRAR.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4
Date: 2020-10-29 14:38:32.632
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\Desktop\Junk\lis\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4
Date: 2020-10-29 14:37:51.586
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\Desktop\Junk\lis\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4
Date: 2020-10-29 14:37:44.324
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\Desktop\Junk\lis\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4
R1 gwdrv; C:\WINDOWS\system32\DRIVERS\gwdrv.sys [33152 2015-05-29] (GlassWire -> SecureMix LLC)
R1 hmpalert; C:\WINDOWS\system32\drivers\hmpalert.sys [445400 2020-07-05] (SurfRight B.V. -> SurfRight B.V.)
he ImagePath of wuauserv: "%systemroot%\system32\svchost.exe -k netsvcs -p".