Microsoft Version 11 Home

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Somemelvin1, Jul 5, 2025 at 3:50 PM.

  1. Somemelvin1

    Somemelvin1 Private First Class

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings.

    Yes, however if you are requesting assistance please just start with the below. Provide an explanation of what issue(s) you are having.

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download FRST64 and save the file on your Desktop
    • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • When completed, FRST.txt and Addition.txt reports will be saved on the Desktop
    • Please attach the reports to your reply
    ===================================================

    Things I would like to see in your next reply.
    • Attached reports
     
  3. Somemelvin1

    Somemelvin1 Private First Class

    As requested, I ran FRST64 and have attached both FRST.txt and Addition.txt for your review.

    Reason for submission:
    A pop-up window appeared instructing me to call Microsoft immediately and warned not to shut down the computer. The system became completely unresponsive—I couldn’t close the message or access any other screen.
    I performed a Ctrl + Alt + Delete and forcefully shut down the system.

    Goal:
    I’d like to confirm whether there is any hidden malware or virus that needs to be removed.

    Thanks in advance for your help!
     

    Attached Files:

  4. Oh My!

    Oh My! Malware Expert Staff Member

    You are quite welcome.

    You handled the shutdown perfectly. I see no evidence of any remnants on your system.

    Things look pretty good but I would like to take a closer look at one file and address some potential non-malware related system issues.

    Let's start with this.

    If you are not using Wild Tangent Games I would recommend uninstalling it using the instructions below. It is currently running on your computer. It comes pre-installed on some computer and most people either do not know it is on their system or don't use it.

    ===================================================

    Uninstalling Programs Using Revo Uninstaller Free Portable

    --------------------

    • Download Revo Uninstaller Free Portable and save it to your Desktop
    • Right click on the folder and select Extract All..., then click Extract
    • Double click on the RevoUninstaller-Portable folder
    • Right click on RevoUPort and select Run as administrator
    • Click OK on the License Agreement
    • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
    Code:
    WildTangent Games
    
    • If the program's uninstaller appears work through the steps to remove the program(s)
    • Be sure the Advanced option is selected then click Scan
    • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
    • Once done click Finish
    • Reboot your computer
    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    cmd: type "C:\logUploaderSettings.ini"
    Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe  (No File) 
    Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File) 
    Task: {F8CC09A9-4234-4274-82ED-5F5D67429A43} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe  LogonUpdateResults (No File) 
    Task: {49992CA2-46E9-468F-837D-5027C54B06E9} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe  Display (No File) 
    Task: {DE3DAD7E-A42A-4CBF-A972-3184776C2475} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC ReadyToReboot (No File) 
    Task: {A19151B1-31F6-4AF6-8E58-98E2D4E7C867} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery ReadyToReboot (No File) 
    Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File) 
    FirewallRules: [UDP Query User{2DD37227-D879-4AE8-95CA-59F59CDB8D3E}C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe => No File 
    FirewallRules: [TCP Query User{8CE62142-C428-4813-8D5B-AD765D500EA9}C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe => No File 
    FirewallRules: [{7F2E9E35-560C-40C9-86F2-8610DC19940C}] => (Allow) C:\Users\dlinc\Desktop\Taxes 2021\Turbo Tax Files 2021\32bit\CefSharp.BrowserSubprocess.exe => No File 
    FF HKLM-x32\...\Firefox\Extensions: [datavault@ascendo.inc] - C:\Program Files (x86)\DataVault\firefox => not found 
    CHR HKLM-x32\...\Chrome\Extension: [idbmmgcdhhiblollphopejjpnkpdgbii] - C:\Program Files (x86)\DataVault\extension.crx <not found> 
    CHR HKLM-x32\...\Chrome\Extension: [nllkablinafpjaedccdhmidmmhmafmlg] - C:\Program Files (x86)\DataVault\extension.crx <not found> 
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Wild Tangent uninstalled?
    • Fixlog
     
  5. Somemelvin1

    Somemelvin1 Private First Class

    Thank you for the assistance with the potential non-malware related system issues.
    I deinstalled wild tangent games with Revo Uninstaller.
    Here is the fixlog.txt data after I ran FRST64.

    Fixlog.txt...
    Fix result of Farbar Recovery Scan Tool (x64) Version: 07-07-2025
    Ran by dlinc (07-07-2025 13:32:01) Run:1
    Running from C:\Users\dlinc\Desktop
    Loaded Profiles: dlinc
    Boot Mode: Normal
    ==============================================
    fixlist content:
    *****************
    Start::
    CreateRestorePoint:
    CloseProcesses:
    cmd: type "C:\logUploaderSettings.ini"
    Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
    Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
    Task: {F8CC09A9-4234-4274-82ED-5F5D67429A43} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe LogonUpdateResults (No File)
    Task: {49992CA2-46E9-468F-837D-5027C54B06E9} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe Display (No File)
    Task: {DE3DAD7E-A42A-4CBF-A972-3184776C2475} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC ReadyToReboot (No File)
    Task: {A19151B1-31F6-4AF6-8E58-98E2D4E7C867} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery ReadyToReboot (No File)
    Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
    FirewallRules: [UDP Query User{2DD37227-D879-4AE8-95CA-59F59CDB8D3E}C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe => No File
    FirewallRules: [TCP Query User{8CE62142-C428-4813-8D5B-AD765D500EA9}C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe => No File
    FirewallRules: [{7F2E9E35-560C-40C9-86F2-8610DC19940C}] => (Allow) C:\Users\dlinc\Desktop\Taxes 2021\Turbo Tax Files 2021\32bit\CefSharp.BrowserSubprocess.exe => No File
    FF HKLM-x32\...\Firefox\Extensions: [datavault@ascendo.inc] - C:\Program Files (x86)\DataVault\firefox => not found
    CHR HKLM-x32\...\Chrome\Extension: [idbmmgcdhhiblollphopejjpnkpdgbii] - C:\Program Files (x86)\DataVault\extension.crx <not found>
    CHR HKLM-x32\...\Chrome\Extension: [nllkablinafpjaedccdhmidmmhmafmlg] - C:\Program Files (x86)\DataVault\extension.crx <not found>
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    End::
    *****************
    Restore point was successfully created.
    Processes closed successfully.
    ========= type "C:\logUploaderSettings.ini" =========
    p a r t n e r S c a n T i m e = 0
    c l o u d F i l e s A c t i v e L o g =
    ========= End of CMD: =========
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F8CC09A9-4234-4274-82ED-5F5D67429A43}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8CC09A9-4234-4274-82ED-5F5D67429A43}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{49992CA2-46E9-468F-837D-5027C54B06E9}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{49992CA2-46E9-468F-837D-5027C54B06E9}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE3DAD7E-A42A-4CBF-A972-3184776C2475}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE3DAD7E-A42A-4CBF-A972-3184776C2475}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A19151B1-31F6-4AF6-8E58-98E2D4E7C867}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A19151B1-31F6-4AF6-8E58-98E2D4E7C867}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2DD37227-D879-4AE8-95CA-59F59CDB8D3E}C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8CE62142-C428-4813-8D5B-AD765D500EA9}C:\users\dlinc\appdata\local\microsoft\teams\current\teams.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7F2E9E35-560C-40C9-86F2-8610DC19940C}" => removed successfully
    "HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\datavault@ascendo.inc" => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\idbmmgcdhhiblollphopejjpnkpdgbii => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nllkablinafpjaedccdhmidmmhmafmlg => removed successfully
    ========= sfc /scannow =========
    Beginning system scan. This process will take some time.
    Beginning verification phase of system scan.
    Verification 0% complete.
    Verification 1% complete.
    Verification 1% complete.
    Verification 2% complete.
    Verification 3% complete.
    Verification 3% complete.
    Verification 4% complete.
    Verification 4% complete.
    Verification 5% complete.
    Verification 6% complete.
    Verification 6% complete.
    Verification 7% complete.
    Verification 8% complete.
    Verification 8% complete.
    Verification 9% complete.
    Verification 9% complete.
    Verification 10% complete.
    Verification 11% complete.
    Verification 11% complete.
    Verification 12% complete.
    Verification 13% complete.
    Verification 13% complete.
    Verification 14% complete.
    Verification 14% complete.
    Verification 15% complete.
    Verification 16% complete.
    Verification 16% complete.
    Verification 17% complete.
    Verification 18% complete.
    Verification 18% complete.
    Verification 19% complete.
    Verification 19% complete.
    Verification 20% complete.
    Verification 21% complete.
    Verification 21% complete.
    Verification 22% complete.
    Verification 23% complete.
    Verification 23% complete.
    Verification 24% complete.
    Verification 24% complete.
    Verification 25% complete.
    Verification 26% complete.
    Verification 26% complete.
    Verification 27% complete.
    Verification 28% complete.
    Verification 28% complete.
    Verification 29% complete.
    Verification 29% complete.
    Verification 30% complete.
    Verification 31% complete.
    Verification 31% complete.
    Verification 32% complete.
    Verification 33% complete.
    Verification 33% complete.
    Verification 34% complete.
    Verification 34% complete.
    Verification 35% complete.
    Verification 36% complete.
    Verification 36% complete.
    Verification 37% complete.
    Verification 38% complete.
    Verification 38% complete.
    Verification 39% complete.
    Verification 39% complete.
    Verification 40% complete.
    Verification 41% complete.
    Verification 41% complete.
    Verification 42% complete.
    Verification 42% complete.
    Verification 43% complete.
    Verification 44% complete.
    Verification 44% complete.
    Verification 45% complete.
    Verification 46% complete.
    Verification 46% complete.
    Verification 47% complete.
    Verification 47% complete.
    Verification 48% complete.
    Verification 49% complete.
    Verification 49% complete.
    Verification 50% complete.
    Verification 51% complete.
    Verification 51% complete.
    Verification 52% complete.
    Verification 52% complete.
    Verification 53% complete.
    Verification 54% complete.
    Verification 54% complete.
    Verification 55% complete.
    Verification 56% complete.
    Verification 56% complete.
    Verification 57% complete.
    Verification 57% complete.
    Verification 58% complete.
    Verification 59% complete.
    Verification 59% complete.
    Verification 60% complete.
    Verification 61% complete.
    Verification 61% complete.
    Verification 62% complete.
    Verification 62% complete.
    Verification 63% complete.
    Verification 64% complete.
    Verification 64% complete.
    Verification 65% complete.
    Verification 66% complete.
    Verification 66% complete.
    Verification 67% complete.
    Verification 67% complete.
    Verification 68% complete.
    Verification 69% complete.
    Verification 69% complete.
    Verification 70% complete.
    Verification 71% complete.
    Verification 71% complete.
    Verification 72% complete.
    Verification 72% complete.
    Verification 73% complete.
    Verification 74% complete.
    Verification 74% complete.
    Verification 75% complete.
    Verification 76% complete.
    Verification 76% complete.
    Verification 77% complete.
    Verification 77% complete.
    Verification 78% complete.
    Verification 79% complete.
    Verification 79% complete.
    Verification 80% complete.
    Verification 80% complete.
    Verification 81% complete.
    Verification 82% complete.
    Verification 82% complete.
    Verification 83% complete.
    Verification 84% complete.
    Verification 84% complete.
    Verification 85% complete.
    Verification 85% complete.
    Verification 86% complete.
    Verification 87% complete.
    Verification 87% complete.
    Verification 88% complete.
    Verification 89% complete.
    Verification 89% complete.
    Verification 90% complete.
    Verification 90% complete.
    Verification 91% complete.
    Verification 92% complete.
    Verification 92% complete.
    Verification 93% complete.
    Verification 94% complete.
    Verification 94% complete.
    Verification 95% complete.
    Verification 95% complete.
    Verification 96% complete.
    Verification 97% complete.
    Verification 97% complete.
    Verification 98% complete.
    Verification 99% complete.
    Verification 99% complete.
    Verification 100% complete.
    Windows Resource Protection found corrupt files and successfully repaired them.
    For online repairs, details are included in the CBS log file located at
    windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline
    repairs, details are included in the log file provided by the /OFFLOGFILE flag.
    ========= End of CMD: =========
    ========= DISM /Online /Cleanup-Image /CheckHealth =========
    Deployment Image Servicing and Management tool
    Version: 10.0.26100.1150
    Image Version: 10.0.26100.4349
    The component store is repairable.
    The operation completed successfully.
    ========= End of CMD: =========
    The system needed a reboot.
    ==== End of Fixlog 13:35:01 ====
     
  6. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the reports.
    One of the system issues was repaired now let's try to fix the second issue.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     
  7. Somemelvin1

    Somemelvin1 Private First Class

    It appears there was a glitch while running FRST64—it ran for over 15 minutes without completing, so I had to manually end the task.
    Here is the Fixlog.txt for your review:

    Fix result of Farbar Recovery Scan Tool (x64) Version: 07-07-2025
    Ran by dlinc (07-07-2025 21:35:04) Run:2
    Running from C:\Users\dlinc\Desktop
    Loaded Profiles: dlinc
    Boot Mode: Normal
    ==============================================
    fixlist content:
    *****************
    Start::
    CreateRestorePoint:
    CloseProcesses:
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    End::
    *****************
    Restore point was successfully created.
    Processes closed successfully.
    ========= DISM /Online /Cleanup-Image /RestoreHealth =========

    (In addition, there was another file created: bdaziufsncz.txt)

    Would you recommend that I run FRST64 again?
     
  8. Oh My!

    Oh My! Malware Expert Staff Member

    That randomly named file is a FRST temporary file that is supposed to be automatically deleted upon successful completion. Try running the Fixlist instructions again and if it fails to complete zip and attach the C:\Windows\Logs\DISM folder to your reply. Let it run for awhile longer.
     
  9. Somemelvin1

    Somemelvin1 Private First Class

    This time I let it run for 50 minutes without completing, so I manually ended the task.
    I have attached the DISM folder per your instructions.
    Thank you.
     

    Attached Files:

  10. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    I need some additional information. Please zip the C:\Windows\Logs\CBS folder and upload the file to GoFile or the file hosting site of your choice. Post the download link in your reply.
     
  11. Somemelvin1

    Somemelvin1 Private First Class

  12. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    Can you do the same for the C:\Windows\inf\setupapi.offline.log file please?
     
  13. Somemelvin1

    Somemelvin1 Private First Class


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds