Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - hayc59

Pages: [1] 2 3 ... 59
1
Meet & Greet! / Happy Thanksgiving to all
« on: November 26, 2020, 03:56:32 PM »
God Bless you and yours

2
Meet & Greet! / Re: Happy Birthday, Aaron!
« on: November 24, 2020, 05:19:25 PM »
Happy Birthday A!!

3
God Bless All Of Them!!

4
Analysis and Malware Removal / Re: Re-Check Please
« on: November 05, 2020, 05:31:17 PM »
I thank you all, think I am safe and dont need more security program
and windows defender is good to go...I am down with that

8 pages trying to help me is so very humbling and i think enough is enough!
you are all so special I cant thank you enough

Believe me I wish I could afford a new or used newer laptop!!


and in closing this is my...what does it all mean moment

from theses two program spywareblaster and aimp
I get updates just fine through the about check for updates and come just fine
windows defender updates just fine i think...

5
Analysis and Malware Removal / Re: Re-Check Please
« on: November 05, 2020, 05:09:34 PM »
Yes..Its stated LOWfiltering

6
Analysis and Malware Removal / Re: Re-Check Please
« on: November 05, 2020, 04:22:19 PM »
None of it worked..I am at the end on this
thank you for your help

7
Analysis and Malware Removal / Re: Re-Check Please
« on: November 04, 2020, 11:36:58 PM »
Corrine...same error network
Winchester....No


after the reboot for Corrine I unplugged the usb wifi thing and I get no service at all
I plug it in I have real tight wifi speed can browse anywhere!

The wifi card in the 9/10 laptop is gunny sack and the light on the key board is a burnt orange color, when it was good it was a bright white light
so would a new wifi card work??

THANK YOU ALL FOR SPENDING SO MUCH TIME ON ME!! MEANS ALOT

8
Analysis and Malware Removal / Re: Re-Check Please
« on: November 04, 2020, 05:33:40 PM »
NO activation  :(
oh well you and everyone else has helped so much and as long as I have windows defender running I am cool
for some damn reason this usb wifi is blocking stuff?

9
Analysis and Malware Removal / Re: Re-Check Please
« on: November 04, 2020, 05:31:49 PM »
Fix result of Farbar Recovery Scan Tool (x64) Version: 02-11-2020
Ran by Gordon & Nancy (04-11-2020 11:17:32) Run:1
Running from C:\Users\Gordon & Nancy\Desktop
Loaded Profiles: Gordon & Nancy
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
R1 hmpalert; C:\WINDOWS\system32\drivers\hmpalert.sys [445400 2020-07-05] (SurfRight B.V. -> SurfRight B.V.)
C:\WINDOWS\system32\drivers\hmpalert.sys
C:\ProgramData\oianbuax.xrl
C:\ProgramData\nwckvbae.sbg
C:\ProgramData\rtmeslt
C:\Users\Gordon & Nancy\AppData\Roaming\1816CA7466166.ind
C:\Users\Gordon & Nancy\AppData\Roaming\boo_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
EmptyTemp:

*****************

Restore point was successfully created.
Processes closed successfully.
hmpalert => Unable to stop service.
HKLM\System\CurrentControlSet\Services\hmpalert => removed successfully
hmpalert => service removed successfully
C:\WINDOWS\system32\drivers\hmpalert.sys => moved successfully
C:\ProgramData\oianbuax.xrl => moved successfully
C:\ProgramData\nwckvbae.sbg => moved successfully
C:\ProgramData\rtmeslt => moved successfully
C:\Users\Gordon & Nancy\AppData\Roaming\1816CA7466166.ind => moved successfully
C:\Users\Gordon & Nancy\AppData\Roaming\boo_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8435990 B
Java, Flash, Steam htmlcache => 1352 B
Windows/system/drivers => 1593943 B
Edge => 0 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 20588 B
Gordon & Nancy => 169395471 B

RecycleBin => 0 B
EmptyTemp: => 178.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 11:18:45 ====

10
Analysis and Malware Removal / Re: Re-Check Please
« on: November 04, 2020, 05:14:57 PM »
here go the fix..thank you
MBAM found nothing

11
Analysis and Malware Removal / Re: Re-Check Please
« on: November 04, 2020, 04:47:13 PM »
ok thank you

12
Analysis and Malware Removal / Re: Re-Check Please
« on: November 03, 2020, 09:45:17 PM »
no have not...so no trojan and should i remove the free version of Malwarebytes? thank you Corrine
installed to check that trojan...thought it was still active

13
Analysis and Malware Removal / Re: Re-Check Please
« on: November 03, 2020, 08:38:39 PM »
Ran a full scan with Malwarebytes---nothing
Full scan with windows defender...found that and removed it I hope

14
Analysis and Malware Removal / Re: Re-Check Please
« on: November 03, 2020, 07:25:01 PM »
Trojan:Win32/Ymacco.AB2D.
what is this?

15
Analysis and Malware Removal / Re: Re-Check Please
« on: November 03, 2020, 07:17:28 PM »
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2020
Ran by Gordon & Nancy (03-11-2020 12:45:15)
Running from C:\Users\Gordon & Nancy\Desktop
Windows 10 Home Version 1909 18363.1139 (X64) (2020-01-16 09:33:20)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3675653720-2737141039-3862127861-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3675653720-2737141039-3862127861-503 - Limited - Disabled)
Gordon & Nancy (S-1-5-21-3675653720-2737141039-3862127861-1002 - Administrator - Enabled) => C:\Users\Gordon & Nancy
Guest (S-1-5-21-3675653720-2737141039-3862127861-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3675653720-2737141039-3862127861-1003 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-3675653720-2737141039-3862127861-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ACDSeePro (HKLM-x32\...\ACDSeePro) (Version: 9.3.0.545 - ACD Systems International Inc.)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.445 - Adobe)
AIMP (HKLM-x32\...\AIMP) (Version: v4.70.2233, 08.10.2020 - AIMP DevTeam)
AMD Catalyst Install Manager (HKLM\...\{CF780466-D74B-C6E7-7E61-0C4DCA614455}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.)
BurnAware Professional 13.8 (HKLM-x32\...\BurnAware Professional_is1) (Version:  - Burnaware)
FastStone Capture 9.4 (HKLM-x32\...\FastStone Capture) (Version: 9.4 - FastStone Soft)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6345.0 - IDT)
Malwarebytes version 4.2.2.95 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.2.2.95 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 80.0.361.69 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27033 (HKLM-x32\...\{624ba875-fdfc-4efa-9c66-b170dfebc3ec}) (Version: 14.16.27033.0 - Microsoft Corporation)
Mp3tag v3.03 (HKLM-x32\...\Mp3tag) (Version: 3.03 - Florian Heidenreich)
MPC-HC 1.9.8 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.9.8 - MPC-HC Team)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NETGEAR A6100 Genie (HKLM-x32\...\{15D27BA3-6CCD-4848-8925-07EF083492AD}) (Version: 1.0.0.36 - NETGEAR)
NETGEAR A6100 Genie (HKLM-x32\...\InstallShield_{15D27BA3-6CCD-4848-8925-07EF083492AD}) (Version: 1.0.0.36 - NETGEAR)
Open-Shell (HKLM\...\{F4B6EE58-F183-4B0D-930B-4480673C0F5B}) (Version: 4.4.160 - The Open-Shell Team)
Pale Moon 28.15.0 (x64 en-US) (HKLM\...\Pale Moon 28.15.0 (x64 en-US)) (Version: 28.15.0 - Moonchild Productions)
PDF Shaper Professional 10.4 (HKLM-x32\...\PDF Shaper Professional_is1) (Version:  - Burnaware)
PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Ralink RT5390 802.11b/g/n WiFi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}) (Version: 3.02.02.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.46.610.2011 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.84 - Realtek Semiconductor Corp.)
SereneScreen Marine Aquarium 3 (HKLM-x32\...\SereneScreen Marine Aquarium 3_is1) (Version: 3.3 - Prolific Publishing, Inc.)
SpywareBlaster 6.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 6.0.0 - BrightFort LLC)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.19.1 - Synaptics Incorporated)
WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2020-10-08] (IP Izmaylov Artem Andreevich -> AIMP DevTeam)
ContextMenuHandlers1: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2020-10-02] (Florian Heidenreich) [File not signed]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-06-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-06-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2020-10-02] (Florian Heidenreich) [File not signed]
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-11-03] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers3: [sx_ISO] -> {10E19A29-0E8D-49B7-9587-1760938EE690} => C:\Program Files (x86)\BurnAware Professional\bashell64.dll [2018-05-17] (Burnaware -> Burnaware)
ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2020-10-08] (IP Izmaylov Artem Andreevich -> AIMP DevTeam)
ContextMenuHandlers4: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2020-10-02] (Florian Heidenreich) [File not signed]
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2015-08-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-11-03] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\system32\StartMenuHelper64.dll [2020-09-26] (Open-Shell) [File not signed]
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-06-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-06-25] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [msacm.voxacm160] => C:\WINDOWS\system32\vct3216.acm [82944 2003-05-21] (Voxware, Inc.) [File not signed]
HKLM\...\Drivers32: [msacm.scg726] => C:\WINDOWS\system32\scg726.acm [13239 2000-03-14] (SHARP Corporation) [File not signed]
HKLM\...\Drivers32: [msacm.alf2cd] => C:\WINDOWS\system32\alf2cd.acm [38912 2003-05-21] (NCT Company) [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\WINDOWS\system32\AC3ACM.acm [81920 2004-02-04] (fccHandler) [File not signed]
HKLM\...\Drivers32: [msacm.lame] => C:\WINDOWS\system32\lame.ax [245760 2005-08-01] () [File not signed]
HKLM\...\Drivers32: [vidc.dvsd] => C:\WINDOWS\system32\mcdvd_32.dll [261632 2003-05-21] (MainConcept) [File not signed]
HKLM\...\Drivers32: [vidc.mpg4] => C:\WINDOWS\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.mp42] => C:\WINDOWS\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.mp43] => C:\WINDOWS\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.xvid] => C:\WINDOWS\system32\xvidvfw.dll [139264 2004-07-03] () [File not signed]
HKLM\...\Drivers32: [vidc.DIVX] => C:\WINDOWS\system32\DivX.dll [638976 2003-05-22] (DivXNetworks, Inc.) [File not signed]
HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP62] => C:\WINDOWS\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.LAGS] => C:\WINDOWS\system32\lagarith.dll [216064 2011-12-07] () [File not signed]
HKLM\...\Drivers32: [VIDC.LWLR] => RGBACodec.dll

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2012-11-06 08:47 - 2012-11-06 08:47 - 000114688 _____ () [File not signed] C:\Program Files (x86)\NETGEAR\A6100\EnumDevLib.dll
2018-03-07 09:56 - 2018-03-07 09:56 - 000094208 _____ () [File not signed] C:\Program Files (x86)\NETGEAR\A6100\Realtek.dll
2011-09-15 14:15 - 2011-09-15 14:15 - 000073728 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2020-10-02 08:34 - 2020-10-02 08:34 - 000398336 _____ (Florian Heidenreich) [File not signed] C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll
2020-09-26 12:47 - 2020-09-26 12:47 - 002659328 _____ (Open-Shell) [File not signed] C:\Program Files\Open-Shell\StartMenuDLL.dll
2020-09-26 12:48 - 2020-09-26 12:48 - 000562688 _____ (Open-Shell) [File not signed] C:\WINDOWS\system32\StartMenuHelper64.dll
2013-07-03 17:05 - 2013-07-03 17:05 - 000524288 _____ (Realtek Semiconductor Corp.) [File not signed] C:\Program Files (x86)\NETGEAR\A6100\RtlLib.dll
2012-09-13 08:25 - 2012-09-13 08:25 - 000200704 _____ (Realtek) [File not signed] C:\Program Files (x86)\NETGEAR\A6100\IpLib.dll
2013-07-04 09:35 - 2013-07-04 09:35 - 000290816 _____ (Realtek) [File not signed] C:\Program Files (x86)\NETGEAR\A6100\RtlIhvOid.dll
2009-07-23 16:32 - 2009-07-23 16:32 - 001122304 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\NETGEAR\A6100\LIBEAY32.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [274]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
Handler-x32: http - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: http - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\1001movie.com -> 1001movie.com

There are 6091 more sites.


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 18:34 - 2020-10-20 10:48 - 000000839 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\AMD APP\bin\x86_64;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Gordon\Spooky.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: MpsSvc => 2
MSCONFIG\startupreg: Adobe ARM =>
MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run: => "SysTrayApp"
HKLM\...\StartupApproved\Run: => "SynTPEnh"
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3675653720-2737141039-3862127861-1002\...\StartupApproved\Run: => "GUDelayStartup"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{974DD6C0-9EC9-4986-8C15-2622510CBC20}] => (Allow) LPort=443
FirewallRules: [{9FE7C7AF-F035-4E1A-BDDA-B82FB92A2024}] => (Allow) C:\Program Files\Pale Moon\palemoon.exe (Moonchild Productions) [File not signed]
FirewallRules: [{7CC64642-456C-4B4E-93A6-7B7A55632DDC}] => (Allow) C:\Program Files\Pale Moon\palemoon.exe (Moonchild Productions) [File not signed]

==================== Restore Points =========================

03-11-2020 09:05:15 KpRm

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (11/03/2020 12:40:39 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2652,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (11/03/2020 09:37:10 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5428,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (11/03/2020 09:10:14 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1516,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (11/03/2020 09:05:34 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (11/03/2020 08:09:27 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (6024,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (11/03/2020 08:02:06 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2212,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (11/02/2020 07:36:56 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress.
.

Error: (11/02/2020 07:36:56 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]


System errors:
=============
Error: (11/03/2020 12:31:34 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (11/03/2020 12:31:31 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\WINDOWS\system32\Rtlihvs.dll
Error Code: 126

Error: (11/03/2020 12:31:30 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (11/03/2020 12:30:59 PM) (Source: Microsoft-Windows-HAL) (EventID: 13) (User: NT AUTHORITY)
Description: The system watchdog timer was triggered.

Error: (11/03/2020 09:05:16 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (11/03/2020 07:56:26 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (11/03/2020 07:56:23 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\WINDOWS\system32\Rtlihvs.dll
Error Code: 126

Error: (11/03/2020 07:56:22 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.


Windows Defender:
===================================
Date: 2020-10-29 14:42:40.562
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\AppData\Local\Temp\Rar$DRa4488.8800\Malwarebytes.Premium.4.1.2.73.msstdfmt\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4

Date: 2020-10-29 14:39:27.851
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\AppData\Local\Temp\Rar$EXa3416.38939\Malwarebytes.Premium.4.1.2.73.msstdfmt\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Program Files\WinRAR\WinRAR.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4

Date: 2020-10-29 14:38:32.632
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\Desktop\Junk\lis\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4

Date: 2020-10-29 14:37:51.586
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\Desktop\Junk\lis\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4

Date: 2020-10-29 14:37:44.324
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Ymacco.AB2D&threatid=2147758023&enterprise=0
Name: Trojan:Win32/Ymacco.AB2D
ID: 2147758023
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Gordon & Nancy\Desktop\Junk\lis\LicenseMalwareBytes.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.325.1644.0, AS: 1.325.1644.0, NIS: 1.325.1644.0
Engine Version: AM: 1.1.17500.4, NIS: 1.1.17500.4

Date: 2020-11-01 12:38:03.189
Description:
Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2020-11-01 10:45:51.481
Description:
Windows Defender Antivirus has encountered an error trying to load security intelligence and will attempt reverting back to a known-good version.
Security intelligence Attempted: Current
Error Code: 0x80070003
Error description: The system cannot find the path specified.
Security intelligence version: 0.0.0.0;0.0.0.0
Engine version: 0.0.0.0

Date: 2020-11-01 10:45:51.442
Description:
Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2020-11-01 10:32:09.272
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.327.99.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.17600.5
Error code: 0x8007043c
Error description: This service cannot be started in Safe Mode

Date: 2020-11-01 10:21:09.356
Description:
Windows Defender Antivirus has encountered an error trying to load security intelligence and will attempt reverting back to a known-good version.
Security intelligence Attempted: Current
Error Code: 0x80070003
Error description: The system cannot find the path specified.
Security intelligence version: 0.0.0.0;0.0.0.0
Engine version: 0.0.0.0

CodeIntegrity:
===================================

Date: 2020-11-03 12:34:27.388
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-11-03 12:34:27.359
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-10-29 15:16:23.901
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-10-29 15:16:23.872
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-10-22 15:38:10.985
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-10-22 15:38:10.948
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-06-17 15:15:15.432
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-06-17 15:15:15.375
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

BIOS: Hewlett-Packard F.44 11/14/2011
Motherboard: Hewlett-Packard 169B
Processor: AMD A6-3420M APU with Radeon(tm) HD Graphics
Percentage of memory in use: 55%
Total physical RAM: 3562.9 MB
Available physical RAM: 1573.68 MB
Total Virtual: 7146.9 MB
Available Virtual: 5239.42 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:464.89 GB) (Free:428.59 GB) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{d03c1558-672b-11e6-971c-806e6f6e6963}\ (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.15 GB) NTFS
\\?\Volume{b0b9757b-0000-0000-0000-304574000000}\ () (Fixed) (Total:0.68 GB) (Free:0.08 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: B0B9757B)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=464.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=694 MB) - (Type=27)

==================== End of Addition.txt =======================

Pages: [1] 2 3 ... 59