1. vampirate

    vampirate Private E-2

    1. A few Command Prompts have a tendency of popping up and closing, usually after a few minutes of using the desktop, it's semi frequent (meaning sometimes the prompts show up near the beginning of using the desktop, sometimes there's no command prompts at all), not sure if it's anything to do with Steam or the browser. I use Firefox.

    2. When using youtube, i've noticed that when clicking play some black text briefly shows up in the video before it starts to play

    3. I've noticed lately my browser has gotten sluggish, but not sure if this is anything.


    For the command prompts that show up for an instant, i've ran the free malware bytes on safe mode and it picked up nothing

    I'm not sure if any of these 3 issues actually mean anything, but i've decided to rely on a professional more than a scanner atm

    The files are in the attachment
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and :welcome: to Major Geeks Malware Forum.

    My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

    ===================================================

    Ground Rules:
    • First, please keep in mind most of us at Major Geeks volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
    • It is important to not run any tools or take any steps other than those I will provide for you.
    • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
    • Please take special note in my instructions whether to copy and paste, attach, or upload reports or files requested in my instructions
    • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
    ===================================================

    Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

    The Addition.txt report is incomplete. Please run another FRST scan and attach that report to your reply.
     
  3. vampirate

    vampirate Private E-2

    Hopefully this one is good
     

    Attached Files:

  4. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks for the report, this one was complete.

    Let's start with this.

    ===================================================

    Uninstalling Programs Using Revo Uninstaller Free Portable

    --------------------

    • Download Revo Uninstaller Free Portable and save it to your Desktop
    • Right click on the folder and select Extract All..., then click Extract
    • Double click on the RevoUninstaller-Portable folder
    • Right click on RevoUPort and select Run as administrator
    • Click OK on the License Agreement
    • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
    Code:
    App Explorer
    Adobe Shockwave Player 12.3
    
    • If the program's uninstaller appears work through the steps to remove the program(s)
    • Be sure the Advanced option is selected then click Scan
    • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
    • Once done click Finish
    • Reboot your computer
    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1234204.dll [2018-06-06] (Adobe Systems, Inc.) [File not signed]
    GroupPolicy: Restriction ? <==== ATTENTION
    Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
    HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
    HKU\S-1-5-21-1548894264-819181210-1643564009-1004\Software\Classes\exefile:  <==== ATTENTION
    AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [113]
    Task: {0DE8B5C5-D933-4CB9-98FA-D5C31ED9F685} - System32\Tasks\AcerCMUpdateTask2.5.22250 => C:\Program Files (x86)\Acer\Amundsen\2.5.22250\awc.exe [96904 2022-09-25] (Acer Incorporated -> )
    Task: {07E94F36-7571-4BBB-81C8-06869D1CCEF3} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
    Task: {B8076462-66D6-41D5-B4D7-6E60841A0E1B} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe  -sr (No File)
    Task: {DA466977-043C-44A2-BDC3-EB23AF71D0FE} - System32\Tasks\CCleaner Update => D:\Various Programs\CCleaner\CCUpdate.exe  (No File)
    Task: {C1172F43-7126-4DC5-A601-48994E510A6C} - System32\Tasks\CCleanerSkipUAC - Jesse => "D:\Various Programs\CCleaner\CCleaner.exe"  $(Arg0) (No File)
    Task: {5DA5EB4F-6F8A-45AB-B3F7-E3035B2A2C40} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => %SystemRoot%\system32\clipesu.exe  (No File)
    Task: {6CAA0058-2521-4F39-9C16-09F6A85D84D8} - System32\Tasks\Microsoft\Windows\Clip\ClipESUConsumer => %SystemRoot%\system32\ClipESUConsumer.exe  -evaluateEligibility (No File)
    Task: {518AF501-674B-4095-97EB-F03D798C0524} - System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessPreOrder => %SystemRoot%\system32\ClipESUConsumer.exe  -postProcessPreOrder (No File)
    Task: {A3F74F1A-D08D-4202-8FCD-7EFF379B82B2} - System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessRefund => %SystemRoot%\system32\ClipESUConsumer.exe  -processRefund (No File)
    Task: {E88D9B2C-DDEA-47B2-9582-085153004DB5} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe  (No File)
    Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File)
    Task: {4DC0E083-16FB-4735-B610-A39AB5F3C97D} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe  LogonUpdateResults (No File)
    Task: {FB1544C1-FB2E-4870-B6B6-8F20B40138C0} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe  Display (No File)
    Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe  Reboot (No File)
    Task: {E67F75A9-1405-41C5-B572-D2E4AB3F7DE5} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC RebootDialog (No File)
    Task: {7E4ADFE9-4C6C-4AF0-B9EA-FAA31AE86B39} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery RebootDialog (No File)
    Task: {BBFC2016-970B-41DE-BA6C-25B569993AD1} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe  Display (No File)
    Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
    Task: {CA753B15-CE73-4790-AA30-8E0A4A2BD548} - System32\Tasks\Mozilla\Firefox Default Browser Agent 3EEC2BB1E75616D8 => D:\Various Programs\Fire Fox\default-browser-agent.exe  do-task "3EEC2BB1E75616D8" (No File) <==== ATTENTION
    Task: {39C0F019-A1CB-4409-AF68-0AD12A9FC98E} - System32\Tasks\Oem\AcerJumpstartTask => "C:\Program Files (x86)\Acer\Acer Jumpstart\hermes.exe"  /default (No File)
    Task: {339DE183-0AE1-4E66-89A6-ECD3EDF313AD} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1548894264-819181210-1643564009-1001 => C:\Users\Jesse\AppData\Local\Microsoft\OneDrive\25.206.1021.0003\OneDriveLauncher.exe  /startInstances (No File)
    Task: {A85B5056-9BAD-4B17-865C-9EB097C02DCF} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1548894264-819181210-1643564009-1003 => C:\Users\New Guest\AppData\Local\Microsoft\OneDrive\25.216.1104.0002\OneDriveLauncher.exe  /startInstances (No File)
    HKU\S-1-5-21-1548894264-819181210-1643564009-1004\...\Run: [MicrosoftEdgeAutoLaunch_CB597B479230DDCF7F69B4ACCD0FB52F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5018440 2026-08-09] (Microsoft Corporation -> Microsoft Corporation)
    HKU\S-1-5-21-1548894264-819181210-1643564009-1005\...\Run: [MicrosoftEdgeAutoLaunch_8D6AADF2653E934432CCA87C0AED8CC3] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5018440 2026-08-09] (Microsoft Corporation -> Microsoft Corporation)
    S3 LVRS64; \SystemRoot\system32\DRIVERS\lvrs64.sys (No File)
    S3 LVUVC64; \SystemRoot\system32\DRIVERS\lvuvc64.sys (No File)
    S3 MpKsl93e081d8; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{26D56574-3298-4820-B054-859ADD67510E}\MpKslDrv.sys (No File)
    S4 NvModuleTracker; \SystemRoot\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys (No File)
    ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} =>  -> No File
    ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} =>  -> No File
    ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} =>  -> No File
    HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
    cmd: netsh winsock reset catalog
    cmd: netsh int ip reset resetlog.txt
    Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
    C:\Firewall.reg
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state ON
    cmd: bitsadmin /reset /allusers
    cmd: ipconfig /flushdns
    Removeproxy:
    hosts:
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • Note: This step resets your Firewall settings and you may be asked later to grant permission for legitimate programs to pass through the Firewall. If you recognize the program agree to the request.
    • WARNING Regarding the Emptytemp: command, please see here before running the Fixlist. If you have concerns stop and let me know.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Programs removed?
    • Fixlog
    • Update on computer behavior
     
  5. vampirate

    vampirate Private E-2

    Thing was, before I made the post I ran CC cleaner to clean up the temporary internet files and whatnot, but it was slow after that. Before even before I ran all this things have gotten smoother so i've no idea what caused the slowdown. I do have my computer on wireless so maybe that's contributing.

    Regardless if it was the fix or something else, things are noticiably smoother right now.

    When using Revo I couldn't find App Explorer, but found Adobe Shockwave Player 12.3 got rid of it as instructed.

    Fix result of Farbar Recovery Scan Tool (x64) Version: 15-08-2026
    Ran by mych4 (15-08-2026 15:19:29) Run:1
    Running from C:\Users\mych4\OneDrive\Desktop
    Loaded Profiles: mych4 & WsiAccount
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    CreateRestorePoint:
    CloseProcesses:
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1234204.dll [2018-06-06] (Adobe Systems, Inc.) [File not signed]
    GroupPolicy: Restriction ? <==== ATTENTION
    Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
    HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
    HKU\S-1-5-21-1548894264-819181210-1643564009-1004\Software\Classes\exefile: <==== ATTENTION
    AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [113]
    Task: {0DE8B5C5-D933-4CB9-98FA-D5C31ED9F685} - System32\Tasks\AcerCMUpdateTask2.5.22250 => C:\Program Files (x86)\Acer\Amundsen\2.5.22250\awc.exe [96904 2022-09-25] (Acer Incorporated -> )
    Task: {07E94F36-7571-4BBB-81C8-06869D1CCEF3} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
    Task: {B8076462-66D6-41D5-B4D7-6E60841A0E1B} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe -sr (No File)
    Task: {DA466977-043C-44A2-BDC3-EB23AF71D0FE} - System32\Tasks\CCleaner Update => D:\Various Programs\CCleaner\CCUpdate.exe (No File)
    Task: {C1172F43-7126-4DC5-A601-48994E510A6C} - System32\Tasks\CCleanerSkipUAC - Jesse => "D:\Various Programs\CCleaner\CCleaner.exe" $(Arg0) (No File)
    Task: {5DA5EB4F-6F8A-45AB-B3F7-E3035B2A2C40} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => %SystemRoot%\system32\clipesu.exe (No File)
    Task: {6CAA0058-2521-4F39-9C16-09F6A85D84D8} - System32\Tasks\Microsoft\Windows\Clip\ClipESUConsumer => %SystemRoot%\system32\ClipESUConsumer.exe -evaluateEligibility (No File)
    Task: {518AF501-674B-4095-97EB-F03D798C0524} - System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessPreOrder => %SystemRoot%\system32\ClipESUConsumer.exe -postProcessPreOrder (No File)
    Task: {A3F74F1A-D08D-4202-8FCD-7EFF379B82B2} - System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessRefund => %SystemRoot%\system32\ClipESUConsumer.exe -processRefund (No File)
    Task: {E88D9B2C-DDEA-47B2-9582-085153004DB5} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
    Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
    Task: {4DC0E083-16FB-4735-B610-A39AB5F3C97D} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe LogonUpdateResults (No File)
    Task: {FB1544C1-FB2E-4870-B6B6-8F20B40138C0} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe Display (No File)
    Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe Reboot (No File)
    Task: {E67F75A9-1405-41C5-B572-D2E4AB3F7DE5} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
    Task: {7E4ADFE9-4C6C-4AF0-B9EA-FAA31AE86B39} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
    Task: {BBFC2016-970B-41DE-BA6C-25B569993AD1} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe Display (No File)
    Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
    Task: {CA753B15-CE73-4790-AA30-8E0A4A2BD548} - System32\Tasks\Mozilla\Firefox Default Browser Agent 3EEC2BB1E75616D8 => D:\Various Programs\Fire Fox\default-browser-agent.exe do-task "3EEC2BB1E75616D8" (No File) <==== ATTENTION
    Task: {39C0F019-A1CB-4409-AF68-0AD12A9FC98E} - System32\Tasks\Oem\AcerJumpstartTask => "C:\Program Files (x86)\Acer\Acer Jumpstart\hermes.exe" /default (No File)
    Task: {339DE183-0AE1-4E66-89A6-ECD3EDF313AD} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1548894264-819181210-1643564009-1001 => C:\Users\Jesse\AppData\Local\Microsoft\OneDrive\25.206.1021.0003\OneDriveLauncher.exe /startInstances (No File)
    Task: {A85B5056-9BAD-4B17-865C-9EB097C02DCF} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1548894264-819181210-1643564009-1003 => C:\Users\New Guest\AppData\Local\Microsoft\OneDrive\25.216.1104.0002\OneDriveLauncher.exe /startInstances (No File)
    HKU\S-1-5-21-1548894264-819181210-1643564009-1004\...\Run: [MicrosoftEdgeAutoLaunch_CB597B479230DDCF7F69B4ACCD0FB52F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5018440 2026-08-09] (Microsoft Corporation -> Microsoft Corporation)
    HKU\S-1-5-21-1548894264-819181210-1643564009-1005\...\Run: [MicrosoftEdgeAutoLaunch_8D6AADF2653E934432CCA87C0AED8CC3] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5018440 2026-08-09] (Microsoft Corporation -> Microsoft Corporation)
    S3 LVRS64; \SystemRoot\system32\DRIVERS\lvrs64.sys (No File)
    S3 LVUVC64; \SystemRoot\system32\DRIVERS\lvuvc64.sys (No File)
    S3 MpKsl93e081d8; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{26D56574-3298-4820-B054-859ADD67510E}\MpKslDrv.sys (No File)
    S4 NvModuleTracker; \SystemRoot\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys (No File)
    ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => -> No File
    ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
    ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
    HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
    cmd: netsh winsock reset catalog
    cmd: netsh int ip reset resetlog.txt
    Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
    C:\Firewall.reg
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state ON
    cmd: bitsadmin /reset /allusers
    cmd: ipconfig /flushdns
    Removeproxy:
    hosts:
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    End::
    *****************

    Restore point was successfully created.
    Processes closed successfully.
    HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer => not found

    "C:\WINDOWS\system32\GroupPolicy\Machine" Folder move:

    C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol => moved successfully
    C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully

    C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
    C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
    C:\ProgramData\NTUSER.pol => moved successfully
    HKLM\SOFTWARE\Policies\Google => removed successfully
    HKLM\SOFTWARE\Policies\Microsoft\Edge => removed successfully
    HKU\S-1-5-21-1548894264-819181210-1643564009-1004\Software\Classes\exefile => removed successfully
    C:\ProgramData\Temp => ":5C321E34" ADS removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0DE8B5C5-D933-4CB9-98FA-D5C31ED9F685}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DE8B5C5-D933-4CB9-98FA-D5C31ED9F685}" => removed successfully
    C:\WINDOWS\System32\Tasks\AcerCMUpdateTask2.5.22250 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AcerCMUpdateTask2.5.22250" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{07E94F36-7571-4BBB-81C8-06869D1CCEF3}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{07E94F36-7571-4BBB-81C8-06869D1CCEF3}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B8076462-66D6-41D5-B4D7-6E60841A0E1B}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B8076462-66D6-41D5-B4D7-6E60841A0E1B}" => removed successfully
    C:\WINDOWS\System32\Tasks\BlueStacksHelper => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BlueStacksHelper" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{DA466977-043C-44A2-BDC3-EB23AF71D0FE}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA466977-043C-44A2-BDC3-EB23AF71D0FE}" => removed successfully
    C:\WINDOWS\System32\Tasks\CCleaner Update => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleaner Update" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C1172F43-7126-4DC5-A601-48994E510A6C}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C1172F43-7126-4DC5-A601-48994E510A6C}" => removed successfully
    C:\WINDOWS\System32\Tasks\CCleanerSkipUAC - Jesse => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC - Jesse" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5DA5EB4F-6F8A-45AB-B3F7-E3035B2A2C40}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5DA5EB4F-6F8A-45AB-B3F7-E3035B2A2C40}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Clip\ClipESU => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Clip\ClipESU" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6CAA0058-2521-4F39-9C16-09F6A85D84D8}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6CAA0058-2521-4F39-9C16-09F6A85D84D8}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Clip\ClipESUConsumer => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Clip\ClipESUConsumer" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{518AF501-674B-4095-97EB-F03D798C0524}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{518AF501-674B-4095-97EB-F03D798C0524}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessPreOrder => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Clip\ClipEsuConsumerProcessPreOrder" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A3F74F1A-D08D-4202-8FCD-7EFF379B82B2}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A3F74F1A-D08D-4202-8FCD-7EFF379B82B2}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Clip\ClipEsuConsumerProcessRefund => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Clip\ClipEsuConsumerProcessRefund" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E88D9B2C-DDEA-47B2-9582-085153004DB5}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E88D9B2C-DDEA-47B2-9582-085153004DB5}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4DC0E083-16FB-4735-B610-A39AB5F3C97D}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4DC0E083-16FB-4735-B610-A39AB5F3C97D}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FB1544C1-FB2E-4870-B6B6-8F20B40138C0}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FB1544C1-FB2E-4870-B6B6-8F20B40138C0}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E67F75A9-1405-41C5-B572-D2E4AB3F7DE5}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E67F75A9-1405-41C5-B572-D2E4AB3F7DE5}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7E4ADFE9-4C6C-4AF0-B9EA-FAA31AE86B39}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7E4ADFE9-4C6C-4AF0-B9EA-FAA31AE86B39}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BBFC2016-970B-41DE-BA6C-25B569993AD1}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBFC2016-970B-41DE-BA6C-25B569993AD1}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CA753B15-CE73-4790-AA30-8E0A4A2BD548}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA753B15-CE73-4790-AA30-8E0A4A2BD548}" => removed successfully
    C:\WINDOWS\System32\Tasks\Mozilla\Firefox Default Browser Agent 3EEC2BB1E75616D8 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Mozilla\Firefox Default Browser Agent 3EEC2BB1E75616D8" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{39C0F019-A1CB-4409-AF68-0AD12A9FC98E}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39C0F019-A1CB-4409-AF68-0AD12A9FC98E}" => removed successfully
    C:\WINDOWS\System32\Tasks\Oem\AcerJumpstartTask => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Oem\AcerJumpstartTask" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{339DE183-0AE1-4E66-89A6-ECD3EDF313AD}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{339DE183-0AE1-4E66-89A6-ECD3EDF313AD}" => removed successfully
    C:\WINDOWS\System32\Tasks\OneDrive Startup Task-S-1-5-21-1548894264-819181210-1643564009-1001 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Startup Task-S-1-5-21-1548894264-819181210-1643564009-1001" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A85B5056-9BAD-4B17-865C-9EB097C02DCF}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A85B5056-9BAD-4B17-865C-9EB097C02DCF}" => removed successfully
    C:\WINDOWS\System32\Tasks\OneDrive Startup Task-S-1-5-21-1548894264-819181210-1643564009-1003 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Startup Task-S-1-5-21-1548894264-819181210-1643564009-1003" => removed successfully
    "HKU\S-1-5-21-1548894264-819181210-1643564009-1004\Software\Microsoft\Windows\CurrentVersion\Run\\MicrosoftEdgeAutoLaunch_CB597B479230DDCF7F69B4ACCD0FB52F" => not found
    "HKU\S-1-5-21-1548894264-819181210-1643564009-1005\Software\Microsoft\Windows\CurrentVersion\Run\\MicrosoftEdgeAutoLaunch_8D6AADF2653E934432CCA87C0AED8CC3" => removed successfully
    HKLM\System\CurrentControlSet\Services\LVRS64 => removed successfully
    LVRS64 => service removed successfully
    HKLM\System\CurrentControlSet\Services\LVUVC64 => removed successfully
    LVUVC64 => service removed successfully
    HKLM\System\CurrentControlSet\Services\MpKsl93e081d8 => removed successfully
    MpKsl93e081d8 => service removed successfully
    HKLM\System\CurrentControlSet\Services\NvModuleTracker => removed successfully
    NvModuleTracker => service removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ ACloudSynced => removed successfully
    HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\PowerISO => removed successfully
    HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\PowerISO => removed successfully
    HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => removed successfully

    ========= netsh winsock reset catalog =========


    Sucessfully reset the Winsock Catalog.
    You must restart the computer in order to complete the reset.



    ========= End of CMD: =========


    ========= netsh int ip reset resetlog.txt =========

    Resetting Compartment Forwarding, OK!
    Resetting Compartment, OK!
    Resetting Control Protocol, OK!
    Resetting Echo Sequence Request, OK!
    Resetting Global, OK!
    Resetting Interface, OK!
    Resetting Anycast Address, OK!
    Resetting Multicast Address, OK!
    Resetting Unicast Address, OK!
    Resetting Neighbor, OK!
    Resetting Path, OK!
    Resetting Potential, OK!
    Resetting Prefix Policy, OK!
    Resetting Proxy Neighbor, OK!
    Resetting Route, OK!
    Resetting Site Prefix, OK!
    Resetting Subinterface, OK!
    Resetting Wakeup Pattern, OK!
    Resetting Resolve Neighbor, OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , failed.
    Access is denied.

    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Restart the computer to complete this action.



    ========= End of CMD: =========


    ========= reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg =========

    The operation completed successfully.


    ========= End of Reg: =========

    C:\Firewall.reg => moved successfully

    ========= netsh advfirewall reset =========

    Ok.



    ========= End of CMD: =========


    ========= netsh advfirewall set allprofiles state ON =========

    Ok.



    ========= End of CMD: =========


    ========= bitsadmin /reset /allusers =========


    BITSADMIN version 3.0
    BITS administration utility.
    (C) Copyright Microsoft Corp.

    {59FFDB98-0CD2-46C9-AFC2-4F456FE60D16} canceled.
    {145455E9-AC1C-46E5-9DA9-C85BBB4FA67C} canceled.
    {0E0B9A08-F3C9-4D38-8F0B-D11A723B6AD2} canceled.
    {E866C6E5-1E12-42F9-96A1-A043CE1EA483} canceled.
    {EB92E927-CC41-4EE5-8C32-76890E125470} canceled.
    {F7E3BB66-0608-476A-A1F1-5439788904F2} canceled.
    {E596100E-361B-4BB0-9B8B-DC15B8A21875} canceled.
    7 out of 7 jobs canceled.


    ========= End of CMD: =========


    ========= ipconfig /flushdns =========


    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.


    ========= End of CMD: =========


    ========= RemoveProxy: =========

    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-21-1548894264-819181210-1643564009-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-21-1548894264-819181210-1643564009-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-21-1548894264-819181210-1643564009-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-21-1548894264-819181210-1643564009-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


    ========= End of RemoveProxy: =========

    C:\Windows\System32\Drivers\etc\hosts => moved successfully
    Hosts restored successfully.

    ========= sfc /scannow =========


    Beginning system scan. This process will take some time.

    Beginning verification phase of system scan.

    Verification 0% complete.
    Verification 0% complete.
    Verification 1% complete.
    Verification 1% complete.
    Verification 2% complete.
    Verification 2% complete.
    Verification 3% complete.
    Verification 3% complete.
    Verification 4% complete.
    Verification 4% complete.
    Verification 4% complete.
    Verification 5% complete.
    Verification 5% complete.
    Verification 6% complete.
    Verification 6% complete.
    Verification 7% complete.
    Verification 7% complete.
    Verification 8% complete.
    Verification 8% complete.
    Verification 8% complete.
    Verification 9% complete.
    Verification 9% complete.
    Verification 10% complete.
    Verification 10% complete.
    Verification 11% complete.
    Verification 11% complete.
    Verification 12% complete.
    Verification 12% complete.
    Verification 13% complete.
    Verification 13% complete.
    Verification 13% complete.
    Verification 14% complete.
    Verification 14% complete.
    Verification 15% complete.
    Verification 15% complete.
    Verification 16% complete.
    Verification 16% complete.
    Verification 17% complete.
    Verification 17% complete.
    Verification 17% complete.
    Verification 18% complete.
    Verification 18% complete.
    Verification 19% complete.
    Verification 19% complete.
    Verification 20% complete.
    Verification 20% complete.
    Verification 21% complete.
    Verification 21% complete.
    Verification 22% complete.
    Verification 22% complete.
    Verification 22% complete.
    Verification 23% complete.
    Verification 23% complete.
    Verification 24% complete.
    Verification 24% complete.
    Verification 25% complete.
    Verification 25% complete.
    Verification 26% complete.
    Verification 26% complete.
    Verification 26% complete.
    Verification 27% complete.
    Verification 27% complete.
    Verification 28% complete.
    Verification 28% complete.
    Verification 29% complete.
    Verification 29% complete.
    Verification 30% complete.
    Verification 30% complete.
    Verification 31% complete.
    Verification 31% complete.
    Verification 31% complete.
    Verification 32% complete.
    Verification 32% complete.
    Verification 33% complete.
    Verification 33% complete.
    Verification 34% complete.
    Verification 34% complete.
    Verification 35% complete.
    Verification 35% complete.
    Verification 35% complete.
    Verification 36% complete.
    Verification 36% complete.
    Verification 37% complete.
    Verification 37% complete.
    Verification 38% complete.
    Verification 38% complete.
    Verification 39% complete.
    Verification 39% complete.
    Verification 39% complete.
    Verification 40% complete.
    Verification 40% complete.
    Verification 41% complete.
    Verification 41% complete.
    Verification 42% complete.
    Verification 42% complete.
    Verification 43% complete.
    Verification 43% complete.
    Verification 44% complete.
    Verification 44% complete.
    Verification 44% complete.
    Verification 45% complete.
    Verification 45% complete.
    Verification 46% complete.
    Verification 46% complete.
    Verification 47% complete.
    Verification 47% complete.
    Verification 48% complete.
    Verification 48% complete.
    Verification 48% complete.
    Verification 49% complete.
    Verification 49% complete.
    Verification 50% complete.
    Verification 50% complete.
    Verification 51% complete.
    Verification 51% complete.
    Verification 52% complete.
    Verification 52% complete.
    Verification 53% complete.
    Verification 53% complete.
    Verification 53% complete.
    Verification 54% complete.
    Verification 54% complete.
    Verification 55% complete.
    Verification 55% complete.
    Verification 56% complete.
    Verification 56% complete.
    Verification 57% complete.
    Verification 57% complete.
    Verification 57% complete.
    Verification 58% complete.
    Verification 58% complete.
    Verification 59% complete.
    Verification 59% complete.
    Verification 60% complete.
    Verification 60% complete.
    Verification 61% complete.
    Verification 61% complete.
    Verification 62% complete.
    Verification 62% complete.
    Verification 62% complete.
    Verification 63% complete.
    Verification 63% complete.
    Verification 64% complete.
    Verification 64% complete.
    Verification 65% complete.
    Verification 65% complete.
    Verification 66% complete.
    Verification 66% complete.
    Verification 66% complete.
    Verification 67% complete.
    Verification 67% complete.
    Verification 68% complete.
    Verification 68% complete.
    Verification 69% complete.
    Verification 69% complete.
    Verification 70% complete.
    Verification 70% complete.
    Verification 71% complete.
    Verification 71% complete.
    Verification 71% complete.
    Verification 72% complete.
    Verification 72% complete.
    Verification 73% complete.
    Verification 73% complete.
    Verification 74% complete.
    Verification 74% complete.
    Verification 75% complete.
    Verification 75% complete.
    Verification 75% complete.
    Verification 76% complete.
    Verification 76% complete.
    Verification 77% complete.
    Verification 77% complete.
    Verification 78% complete.
    Verification 78% complete.
    Verification 79% complete.
    Verification 79% complete.
    Verification 79% complete.
    Verification 80% complete.
    Verification 80% complete.
    Verification 81% complete.
    Verification 81% complete.
    Verification 82% complete.
    Verification 82% complete.
    Verification 83% complete.
    Verification 83% complete.
    Verification 84% complete.
    Verification 84% complete.
    Verification 84% complete.
    Verification 85% complete.
    Verification 85% complete.
    Verification 86% complete.
    Verification 86% complete.
    Verification 87% complete.
    Verification 87% complete.
    Verification 88% complete.
    Verification 88% complete.
    Verification 88% complete.
    Verification 89% complete.
    Verification 89% complete.
    Verification 90% complete.
    Verification 90% complete.
    Verification 91% complete.
    Verification 91% complete.
    Verification 92% complete.
    Verification 92% complete.
    Verification 93% complete.
    Verification 93% complete.
    Verification 93% complete.
    Verification 94% complete.
    Verification 94% complete.
    Verification 95% complete.
    Verification 95% complete.
    Verification 96% complete.
    Verification 96% complete.
    Verification 97% complete.
    Verification 97% complete.
    Verification 97% complete.
    Verification 98% complete.
    Verification 98% complete.
    Verification 99% complete.
    Verification 99% complete.
    Verification 100% complete.

    Windows Resource Protection found corrupt files and successfully repaired them.
    For online repairs, details are included in the CBS log file located at
    windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline
    repairs, details are included in the log file provided by the /OFFLOGFILE flag.


    ========= End of CMD: =========


    ========= DISM /Online /Cleanup-Image /CheckHealth =========


    Deployment Image Servicing and Management tool
    Version: 10.0.26100.8972

    Image Version: 10.0.26100.9168

    The component store is repairable.
    The operation completed successfully.


    ========= End of CMD: =========


    =========== EmptyTemp: ==========

    FlushDNS => completed
    BITS transfer queue => 7602176 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10629422 B
    Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 697933826 B
    Windows/system/drivers => 998372986 B
    Edge => 61930821 B
    Chrome => 147621456 B
    Firefox => 1022503106 B
    Opera => 0 B

    Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
    Default => 4 B
    ProgramData => 993841 B
    Public => 0 B
    systemprofile => 460788 B
    systemprofile32 => 2 B
    LocalService => 1067188 B
    NetworkService => 2532 B
    mych4 => 24128570 B
    WsiAccount => 3352050 B

    RecycleBin => 121465 B
    EmptyTemp: => 2.8 GB temporary data Removed.

    ================================


    The system needed a reboot.

    ==== End of Fixlog 15:26:43 ====
     
  6. Oh My!

    Oh My! Malware Expert Staff Member

    There are different things we addressed that can cause system slowdowns. In addition to clearing out some junk we fixed some non-malware system file corruptions but we need to do a bit more.

    Please do this.

    ===================================================

    DISM RestoreHealth from Administrator Command Prompt

    --------------------

    • Press the Windows Key, type cmd, then select Run as administrator
    • Copy and paste DISM /Online /Cleanup-Image /RestoreHealth after the command prompt then hit Enter
    • Patiently wait as the process may take a long time to complete
    • When completed report whether the process was successful or an error occurred
    ===================================================

    Things I would like to see in your next reply.
    • Results?
     
  7. vampirate

    vampirate Private E-2

    That's done, the restore operation was completed successfully
     
  8. Oh My!

    Oh My! Malware Expert Staff Member

    Great.

    Are you still experiencing this?
     
  9. vampirate

    vampirate Private E-2

    I think the black text in the youtube videos is gone, however the command prompts that pop up might take a while to figure out if they're gone because they happen early on with using the desktop after the computer boots up.

    Typically the prompts either pop up and close when a program like Steam, Discord or a web browser is starting or is just being used (I think), so I might need several days of using the computer to truly check.
     
  10. Oh My!

    Oh My! Malware Expert Staff Member

    No problem. If you are able to provide what activity the computer was involved in and the time the command prompt appears that would be helpful.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds