Thank You In Advance For Your Help! You Guys Are Great!

Discussion in 'Malware Help (A Specialist Will Reply)' started by rday22, Aug 7, 2026 at 4:50 PM.

  1. rday22

    rday22 Private E-2

    My computer is running really slow and crashing every once in a while.

    I am wondering if I have something bad on my computer.

    Thanks in advance.

    Ross
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and :welcome: to Major Geeks Malware Forum.

    My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

    ===================================================

    Ground Rules:
    • First, please keep in mind most of us at Major Geeks volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
    • It is important to not run any tools or take any steps other than those I will provide for you.
    • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
    • Please take special note in my instructions whether to copy and paste, attach, or upload reports or files requested in my instructions
    • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
    ===================================================

    Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

    Please allow me some time to review what you have posted.
     
  3. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for your patience.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool - Run Fix Using Attached File

    --------------------
    • Download the attached file and save it in the same location as FRST64.exe (example, Desktop, USB device) <<< Important
    • Right click on FRST64 and select Run as administrator
    • Click Fix and once completed your computer will reboot
    • The tool will create a log on the desktop called Fixlog.txt
    • Attach the report to your reply
    • WARNING Regarding the Emptytemp: command, please see here before running the Fixlist. If you have concerns stop and let me know.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     

    Attached Files:

  4. rday22

    rday22 Private E-2

    Fix result of Farbar Recovery Scan Tool (x64) Version: 09-08-2026
    Ran by Ross (09-08-2026 15:02:24) Run:1
    Running from C:\Users\ross\OneDrive - Day Law & Associates, P.C\Desktop
    Loaded Profiles: Ross & Heather
    Boot Mode: Normal
    ==============================================
    fixlist content:
    *****************
    CreateRestorePoint:
    CloseProcesses:
    File: C:\Users\ross\Downloads\01KYAQHCV72VWT4ZWPK
    Unlock: C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy
    C:\Users\ross\AppData\Local\Temp\bwp14a76559-dd03-4630-9891-fba0b7fffa9f
    FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi => not found
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\...\Policies\Explorer: []
    AlternateDataStreams: C:\Users\ross\Page_Index_001.xml:com.dropbox.attrs [54]
    2020-05-07 16:24 - 2020-05-07 16:24 - 000000339 ____C () C:\Users\ross\AppData\Local\LMIR0DB36001.tmp_r.bat
    SearchScopes: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107 -> DefaultScope {E89DE3B1-4351-4797-9170-FAF163B69948} URL =
    SearchScopes: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107 -> {E89DE3B1-4351-4797-9170-FAF163B69948} URL =
    CHR HKLM-x32\...\Chrome\Extension: [andadggghdadgjkmabmfhnnkafdlmohe]
    Edge HKLM-x32\...\Edge\Extension: [andadggghdadgjkmabmfhnnkafdlmohe]
    HKLM-x32\...\Run: [] => [X]
    HKLM\...\Run: [Canon DR-C225 SVC] => rundll32.exe DRC225SVC.dll, EntryPointUserMessage (No File)
    HKLM-x32\...\Run: [CentraStage] => C:\Program Files (x86)\CentraStage\Gui.exe (No File)
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\...\Run: [Toolkit] => "C:\Program Files (x86)\Toolkit\Toolkit.exe" /WinStart**ᾏ淃∀蠀C:\ProgramData\Microsoft\Windows\Start Menu\Progra (No File)
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\...\Run: [electron.app.Ooma Office] => C:\Users\ross\AppData\Local\Programs\office-desktop\Ooma Office.exe (No File)
    HKLM\Software\Microsoft\Active Setup\Installed Components: [{b1a2e791-aa02-4b5d-abe2-5c9e31b05bca}] -> "C:\ProgramData\CentraStage\AEMAgent\RMM.WebRemote\14.1.0.3358\RMM.WebRemote.exe" --init-for-user "C:\ProgramData\CentraStage\AEMAgent" (No File)
    Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
    Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
    Task: {C6213653-06B2-49B6-916D-C10CF30158F0} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe Display (No File)
    Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe RebootDialog (No File)
    Task: {ACA9C483-161E-4784-8CC9-5438A0DAC36F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
    Task: {EB6A2E10-6050-4D81-B1B0-153DF93D5E0B} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
    Task: {5921FFD1-5E78-43E7-8AD2-E8A185F31432} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe Display (No File)
    Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
    S3 btwaudio; \SystemRoot\system32\drivers\btwaudio.sys (No File)
    S3 btwl2cap; \SystemRoot\system32\DRIVERS\btwl2cap.sys (No File)
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{0137214D-10E5-F7DB-E810-A4B036876B17}\InprocServer32 -> C:\Program Files (x86)\Common Files\System\ole32.dll => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Common Files\Autodesk Shared\Inventor Interoperability 2023\Bin\TestServer.dll => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{169B5B8E-E315-41C7-9574-66FC7E530D10}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2023\acad.exe /Automation => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{345D3165-3889-4694-AB75-A91A27B217E8}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2023\acad.exe => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{8B4929F8-076F-4AEC-AFEE-8928747B7AE3}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2023\acad.exe /Automation => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Common Files\Autodesk Shared\Inventor Interoperability 2023\Bin\TestServer.dll => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{AA46BA8A-9825-40FD-8493-0BA3C4D5CEB5}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2023\acad.exe /Automation => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\ross\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> "C:\Users\ross\AppData\Local\Microsoft\Teams\current\Teams.exe" --toast => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2023\en-US\acadficn.dll => No File
    CustomCLSID: HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Common Files\Autodesk Shared\Inventor Interoperability 2023\Bin\TestServer.dll => NoHKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ATTENTION
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\...\Run: [BingWallpaperDaemon] => C:\Users\ross\AppData\Local\Temp\bwp14a76559-dd03-4630-9891-fba0b7fffa9f\UnInstDaemon.exe [110400 2026-07-27] (Microsoft Corporation -> Microsoft Corp.) <==== ATTENTION
    Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION File
    FirewallRules: [UDP Query User{F38A5EE5-1BF4-400A-95F8-D15C838394DC}C:\users\ross\appdata\local\quickbooksadvanced\app-1.24.3\quickbooks online.exe] => (Allow) C:\users\ross\appdata\local\quickbooksadvanced\app-1.24.3\quickbooks online.exe => No File
    FirewallRules: [TCP Query User{D33AB94B-9DA2-4682-B7B8-3B6A7351AF11}C:\users\ross\appdata\local\quickbooksadvanced\app-1.24.3\quickbooks online.exe] => (Allow) C:\users\ross\appdata\local\quickbooksadvanced\app-1.24.3\quickbooks online.exe => No File
    FirewallRules: [{1C5527F8-4E12-410F-AB42-18F94E36179B}] => (Block) C:\Program Files (x86)\CentraStage\UltraVNC\winvnc.exe => No File
    FirewallRules: [TCP Query User{DE34829B-9D08-47B7-B67C-18655B3F796F}C:\users\ross\appdata\local\programs\office-desktop\ooma office.exe] => (Allow) C:\users\ross\appdata\local\programs\office-desktop\ooma office.exe => No File
    FirewallRules: [UDP Query User{34E7942B-5C77-48D0-A3DF-38406CC858FA}C:\users\ross\appdata\local\programs\office-desktop\ooma office.exe] => (Allow) C:\users\ross\appdata\local\programs\office-desktop\ooma office.exe => No File
    FirewallRules: [{37A12436-4D2A-4605-A9B8-2E89C6435B09}] => (Allow) C:\ProgramData\CentraStage\AEMAgent\RMM.WebRemote\14.1.0.3358\RMM.RTC.Proxy\RMM.RTC.Proxy.exe => No File
    FirewallRules: [{1FE5AB6F-47B7-47CA-AF32-08C49F1F5146}] => (Allow) C:\ProgramData\CentraStage\AEMAgent\RMM.WebRemote\14.1.0.3358\RMM.RTC.Proxy\RMM.RTC.Proxy.exe => No File
    FirewallRules: [{15569A68-30EE-4575-8033-E67A144D1963}] => (Allow) C:\ProgramData\CentraStage\AEMAgent\AEMAgent.exe => No File
    FirewallRules: [{8C21BD0C-11CE-44E1-B184-9B16A13AFC5C}] => (Allow) C:\ProgramData\CentraStage\AEMAgent\AEMAgent.exe => No File
    FirewallRules: [{EF3600CE-B365-414D-A343-9A260CA7D35A}] => (Allow) C:\ProgramData\CentraStage\AEMAgent\RMM.WebRemote\14.1.0.3358\RMM.WebRemote.exe => No File
    FirewallRules: [{36D1A563-13A8-48F6-8D41-9A808E07B883}] => (Allow) C:\ProgramData\CentraStage\AEMAgent\RMM.WebRemote\14.1.0.3358\RMM.WebRemote.exe => No File
    FirewallRules: [{10E31F5B-AAFC-43B6-B9CC-D9BDDEC45696}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
    FirewallRules: [{3E170A42-88EF-4927-AD3D-386C110678B6}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
    FirewallRules: [TCP Query User{DB4DA18A-0C7D-40EE-B1C3-8F5248735125}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe] => (Allow) C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe => No File
    FirewallRules: [UDP Query User{BBB51A61-0839-47A8-8A23-DB8469FFD0C9}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe] => (Allow) C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe => No File
    FirewallRules: [{6FD24C68-08F9-4B1D-831A-FB4426E648AE}] => (Allow) C:\Program Files (x86)\Brother\DriverTemp\Package\BSP20A-2026-04-16-09-26-30-066\start.exe => No File
    FirewallRules: [{77BFFDF3-EBFE-4243-9181-DE622C17DAFD}] => (Allow) C:\Program Files (x86)\Brother\DriverTemp\Package\BSP20A-2026-04-16-09-26-30-066\start.exe => No File
    FirewallRules: [{87989603-65F3-4A62-9D4A-1978D552AB25}] => (Allow) C:\Program Files (x86)\Brother\DriverTemp\Package\BSP20A-2026-04-16-09-54-19-085\start.exe => No File
    FirewallRules: [{B3C68ABC-AFEC-4B7D-BD7A-7296E054D9C9}] => (Allow) C:\Program Files (x86)\Brother\DriverTemp\Package\BSP20A-2026-04-16-09-54-19-085\start.exe => No File
    FirewallRules: [{7A30F29F-6AD1-44D9-AFA8-516E8C810006}] => (Allow) C:\Program Files\LogiOptionsPlus\logivoice\logioptionsplus_logivoice.exe => No File
    FirewallRules: [{597485BC-E315-4C89-A4ED-EC29CFB0D39B}] => (Allow) C:\Program Files\LogiOptionsPlus\logivoice\logioptionsplus_logivoice.exe => No File
    cmd: bitsadmin /reset /allusers
    cmd: ipconfig /flushdns
    Removeproxy:
    hosts:
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    *****************
    Restore point was successfully created.
    Processes closed successfully.
    ========================= File: C:\Users\ross\Downloads\01KYAQHCV72VWT4ZWPK ========================
    C:\Users\ross\Downloads\01KYAQHCV72VWT4ZWPK
    File not signed
    MD5: 922338B87F2855D7987E4E81330BF000
    Creation and modification date: 2026-07-24 11:52 - 2026-07-24 11:52
    Size: 000011265
    Attributes: ----A
    Company Name:
    Internal Name:
    Original Name:
    Product:
    Description:
    File Version:
    Product Version:
    Copyright:
    Virusscan: https://virusscan.jotti.org/filescanjob/ucf4fbuucd
    ====== End of File: ======
    "C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy" => was unlocked
    "C:\Users\ross\AppData\Local\Temp\bwp14a76559-dd03-4630-9891-fba0b7fffa9f" Folder move:
    C:\Users\ross\AppData\Local\Temp\bwp14a76559-dd03-4630-9891-fba0b7fffa9f\UnInstDaemon.exe => moved successfully
    C:\Users\ross\AppData\Local\Temp\bwp14a76559-dd03-4630-9891-fba0b7fffa9f => moved successfully
    "HKLM\Software\Mozilla\Firefox\Extensions\\web2pdfextension.17@acrobat.adobe.com" => removed successfully
    "HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\" => removed successfully
    C:\Users\ross\Page_Index_001.xml => ":com.dropbox.attrs" ADS removed successfully
    C:\Users\ross\AppData\Local\LMIR0DB36001.tmp_r.bat => moved successfully
    "HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E89DE3B1-4351-4797-9170-FAF163B69948} => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\andadggghdadgjkmabmfhnnkafdlmohe => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Edge\Extensions\andadggghdadgjkmabmfhnnkafdlmohe => removed successfully
    "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Canon DR-C225 SVC" => removed successfully
    "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\CentraStage" => removed successfully
    "HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\Software\Microsoft\Windows\CurrentVersion\Run\\Toolkit" => removed successfully
    "HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\Software\Microsoft\Windows\CurrentVersion\Run\\electron.app.Ooma Office" => removed successfully
    HKLM\Software\Microsoft\Active Setup\Installed Components\{b1a2e791-aa02-4b5d-abe2-5c9e31b05bca} => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C6213653-06B2-49B6-916D-C10CF30158F0}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6213653-06B2-49B6-916D-C10CF30158F0}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ACA9C483-161E-4784-8CC9-5438A0DAC36F}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ACA9C483-161E-4784-8CC9-5438A0DAC36F}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB6A2E10-6050-4D81-B1B0-153DF93D5E0B}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB6A2E10-6050-4D81-B1B0-153DF93D5E0B}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5921FFD1-5E78-43E7-8AD2-E8A185F31432}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5921FFD1-5E78-43E7-8AD2-E8A185F31432}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
    HKLM\System\CurrentControlSet\Services\btwaudio => removed successfully
    btwaudio => service removed successfully
    HKLM\System\CurrentControlSet\Services\btwl2cap => removed successfully
    btwl2cap => service removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{0137214D-10E5-F7DB-E810-A4B036876B17} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{169B5B8E-E315-41C7-9574-66FC7E530D10} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{345D3165-3889-4694-AB75-A91A27B217E8} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{8B4929F8-076F-4AEC-AFEE-8928747B7AE3} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{AA46BA8A-9825-40FD-8493-0BA3C4D5CEB5} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005} => removed successfully
    HKU\S-1-5-21-1679037968-1235777589-3614794781-1107_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD} => removed successfully
    "HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\Software\Microsoft\Windows\CurrentVersion\Run\\BingWallpaperDaemon" => removed successfully
    C:\ProgramData\NTUSER.pol => moved successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{F38A5EE5-1BF4-400A-95F8-D15C838394DC}C:\users\ross\appdata\local\quickbooksadvanced\app-1.24.3\quickbooks online.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{D33AB94B-9DA2-4682-B7B8-3B6A7351AF11}C:\users\ross\appdata\local\quickbooksadvanced\app-1.24.3\quickbooks online.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1C5527F8-4E12-410F-AB42-18F94E36179B}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{DE34829B-9D08-47B7-B67C-18655B3F796F}C:\users\ross\appdata\local\programs\office-desktop\ooma office.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{34E7942B-5C77-48D0-A3DF-38406CC858FA}C:\users\ross\appdata\local\programs\office-desktop\ooma office.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{37A12436-4D2A-4605-A9B8-2E89C6435B09}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1FE5AB6F-47B7-47CA-AF32-08C49F1F5146}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{15569A68-30EE-4575-8033-E67A144D1963}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8C21BD0C-11CE-44E1-B184-9B16A13AFC5C}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EF3600CE-B365-414D-A343-9A260CA7D35A}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{36D1A563-13A8-48F6-8D41-9A808E07B883}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{10E31F5B-AAFC-43B6-B9CC-D9BDDEC45696}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3E170A42-88EF-4927-AD3D-386C110678B6}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{DB4DA18A-0C7D-40EE-B1C3-8F5248735125}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{BBB51A61-0839-47A8-8A23-DB8469FFD0C9}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6FD24C68-08F9-4B1D-831A-FB4426E648AE}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{77BFFDF3-EBFE-4243-9181-DE622C17DAFD}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{87989603-65F3-4A62-9D4A-1978D552AB25}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B3C68ABC-AFEC-4B7D-BD7A-7296E054D9C9}" => removed successfully
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7A30F29F-6AD1-44D9-AFA8-516E8C810006}" => not found
    "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{597485BC-E315-4C89-A4ED-EC29CFB0D39B}" => not found
    ========= bitsadmin /reset /allusers =========
    BITSADMIN version 3.0
    BITS administration utility.
    (C) Copyright Microsoft Corp.
    {C06F9B77-4AF8-4907-9412-E98FAC7C188A} canceled.
    1 out of 1 jobs canceled.
    ========= End of CMD: =========
    ========= ipconfig /flushdns =========
    Windows IP Configuration
    Successfully flushed the DNS Resolver Cache.
    ========= End of CMD: =========
    ========= RemoveProxy: =========
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-21-1679037968-1235777589-3614794781-1107\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-21-3303785369-570404562-650289642-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-21-3303785369-570404562-650289642-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    ========= End of RemoveProxy: =========
    C:\Windows\System32\Drivers\etc\hosts => moved successfully
    Hosts restored successfully.
    ========= sfc /scannow =========
    Beginning system scan. This process will take some time.
    Beginning verification phase of system scan.
    Verification 0% complete.
    Verification 1% complete.
    Verification 1% complete.
    Verification 2% complete.
    Verification 2% complete.
    Verification 3% complete.
    Verification 3% complete.
    Verification 4% complete.
    Verification 4% complete.
    Verification 5% complete.
    Verification 5% complete.
    Verification 6% complete.
    Verification 7% complete.
    Verification 7% complete.
    Verification 8% complete.
    Verification 8% complete.
    Verification 9% complete.
    Verification 9% complete.
    Verification 10% complete.
    Verification 10% complete.
    Verification 11% complete.
    Verification 11% complete.
    Verification 12% complete.
    Verification 13% complete.
    Verification 13% complete.
    Verification 14% complete.
    Verification 14% complete.
    Verification 15% complete.
    Verification 15% complete.
    Verification 16% complete.
    Verification 16% complete.
    Verification 17% complete.
    Verification 17% complete.
    Verification 18% complete.
    Verification 19% complete.
    Verification 19% complete.
    Verification 20% complete.
    Verification 20% complete.
    Verification 21% complete.
    Verification 21% complete.
    Verification 22% complete.
    Verification 22% complete.
    Verification 23% complete.
    Verification 23% complete.
    Verification 24% complete.
    Verification 25% complete.
    Verification 25% complete.
    Verification 26% complete.
    Verification 26% complete.
    Verification 27% complete.
    Verification 27% complete.
    Verification 28% complete.
    Verification 28% complete.
    Verification 29% complete.
    Verification 29% complete.
    Verification 30% complete.
    Verification 31% complete.
    Verification 31% complete.
    Verification 32% complete.
    Verification 32% complete.
    Verification 33% complete.
    Verification 33% complete.
    Verification 34% complete.
    Verification 34% complete.
    Verification 35% complete.
    Verification 35% complete.
    Verification 36% complete.
    Verification 36% complete.
    Verification 37% complete.
    Verification 38% complete.
    Verification 38% complete.
    Verification 39% complete.
    Verification 39% complete.
    Verification 40% complete.
    Verification 40% complete.
    Verification 41% complete.
    Verification 41% complete.
    Verification 42% complete.
    Verification 42% complete.
    Verification 43% complete.
    Verification 44% complete.
    Verification 44% complete.
    Verification 45% complete.
    Verification 45% complete.
    Verification 46% complete.
    Verification 46% complete.
    Verification 47% complete.
    Verification 47% complete.
    Verification 48% complete.
    Verification 48% complete.
    Verification 49% complete.
    Verification 50% complete.
    Verification 50% complete.
    Verification 51% complete.
    Verification 51% complete.
    Verification 52% complete.
    Verification 52% complete.
    Verification 53% complete.
    Verification 53% complete.
    Verification 54% complete.
    Verification 54% complete.
    Verification 55% complete.
    Verification 56% complete.
    Verification 56% complete.
    Verification 57% complete.
    Verification 57% complete.
    Verification 58% complete.
    Verification 58% complete.
    Verification 59% complete.
    Verification 59% complete.
    Verification 60% complete.
    Verification 60% complete.
    Verification 61% complete.
    Verification 62% complete.
    Verification 62% complete.
    Verification 63% complete.
    Verification 63% complete.
    Verification 64% complete.
    Verification 64% complete.
    Verification 65% complete.
    Verification 65% complete.
    Verification 66% complete.
    Verification 66% complete.
    Verification 67% complete.
    Verification 68% complete.
    Verification 68% complete.
    Verification 69% complete.
    Verification 69% complete.
    Verification 70% complete.
    Verification 70% complete.
    Verification 71% complete.
    Verification 71% complete.
    Verification 72% complete.
    Verification 72% complete.
    Verification 73% complete.
    Verification 73% complete.
    Verification 74% complete.
    Verification 75% complete.
    Verification 75% complete.
    Verification 76% complete.
    Verification 76% complete.
    Verification 77% complete.
    Verification 77% complete.
    Verification 78% complete.
    Verification 78% complete.
    Verification 79% complete.
    Verification 79% complete.
    Verification 80% complete.
    Verification 81% complete.
    Verification 81% complete.
    Verification 82% complete.
    Verification 82% complete.
    Verification 83% complete.
    Verification 83% complete.
    Verification 84% complete.
    Verification 84% complete.
    Verification 85% complete.
    Verification 85% complete.
    Verification 86% complete.
    Verification 87% complete.
    Verification 87% complete.
    Verification 88% complete.
    Verification 88% complete.
    Verification 89% complete.
    Verification 89% complete.
    Verification 90% complete.
    Verification 90% complete.
    Verification 91% complete.
    Verification 91% complete.
    Verification 92% complete.
    Verification 93% complete.
    Verification 93% complete.
    Verification 94% complete.
    Verification 94% complete.
    Verification 95% complete.
    Verification 95% complete.
    Verification 96% complete.
    Verification 96% complete.
    Verification 97% complete.
    Verification 97% complete.
    Verification 98% complete.
    Verification 99% complete.
    Verification 99% complete.
    Verification 100% complete.
    Windows Resource Protection found corrupt files and successfully repaired them.
    For online repairs, details are included in the CBS log file located at
    windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline
    repairs, details are included in the log file provided by the /OFFLOGFILE flag.
    ========= End of CMD: =========
    ========= DISM /Online /Cleanup-Image /CheckHealth =========
    Deployment Image Servicing and Management tool
    Version: 10.0.26100.8972
    Image Version: 10.0.26200.8973
    The component store is repairable.
    The operation completed successfully.
    ========= End of CMD: =========
    =========== EmptyTemp: ==========
    FlushDNS => completed
    BITS transfer queue => 3670016 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 946422055 B
    Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 894246472 B
    Windows/system/drivers => 3223761256 B
    Edge => 1889083726 B
    Chrome => 17916416260 B
    Firefox => 50736598 B
    Opera => 0 B
    Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , Caches, history, cookies, recent:
    Default => 10756 B
    ProgramData => 1000225 B
    Public => 0 B
    systemprofile => 455625 B
    systemprofile32 => 847 B
    LocalService => 3117905 B
    NetworkService => 633568 B
    ross => 14277033829 B
    Administrator => 10012 B
    Heather => 12859 B
    RecycleBin => 7272226888 B
    EmptyTemp: => 43.3 GB temporary data Removed.
    ================================
    The system needed a reboot.
    ==== End of Fixlog 15:26:01 ====
     

    Attached Files:

  5. Oh My!

    Oh My! Malware Expert Staff Member

    That looks good.

    Now this please.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    C:\Users\ross\Downloads\01KYAQHCV72VWT4ZWPK
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    HitmanPro

    --------------------
    • Download HitmanPro and save it to your Desktop
    • Close any open browsers
    • Right click on the icon and select Run as Administrator and allow the Automatic update
    • Click Next
    • Click Next
    • Select No, I only want to perform a one-time scan to check this computer then uncheck Please e-mail me... if you don't want future product notifications
    • Click Next to start the scan
    • When the process completes click click Next then Save Log
    • Save the file to your Desktop using the default file name
    • Click Next then Close
    • Copy and paste the contents of the report in your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • HitmanPro report
     
  6. rday22

    rday22 Private E-2

    Here is the Fixlog report:

    Fix result of Farbar Recovery Scan Tool (x64) Version: 09-08-2026
    Ran by Ross (09-08-2026 17:09:24) Run:3
    Running from C:\Users\ross\OneDrive - Day Law & Associates, P.C\Desktop
    Loaded Profiles: Ross
    Boot Mode: Normal
    ==============================================
    fixlist content:
    *****************
    Start::
    CreateRestorePoint:
    CloseProcesses:
    C:\Users\ross\Downloads\01KYAQHCV72VWT4ZWPK
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    End::
    *****************
    Restore point was successfully created.
    Processes closed successfully.
    "C:\Users\ross\Downloads\01KYAQHCV72VWT4ZWPK" => not found
    ========= DISM /Online /Cleanup-Image /RestoreHealth =========

    Here is the Hitman Report:

    a
    Code:
    HitmanPro 3.8.50.346
    www.hitmanpro.com
       Computer name . . . . : PC-ROSS-10
       Windows . . . . . . . : 10.0.0.26200.X64/8
       User name . . . . . . : DAYLAW\Ross
       UAC . . . . . . . . . : Enabled
       License . . . . . . . : Paid (Expired)
       Scan date . . . . . . : 2026-08-09 17:39:49
       Scan mode . . . . . . : Normal
       Scan duration . . . . : 7m 21s
       Disk access mode  . . : Direct disk access (SRB)
       Cloud . . . . . . . . : Internet
       Reboot  . . . . . . . : No
       Close Browser . . . . : No
       Close Remember  . . . : No
       Edge Sync key . . . . : Not Found
       Threats . . . . . . . : 0
       Traces  . . . . . . . : 0
       Objects scanned . . . : 8,278,075
       Files scanned . . . . : 768,131
       Remnants scanned  . . : 4,115,818 files / 3,394,126 keys
    
     
  7. Oh My!

    Oh My! Malware Expert Staff Member

    The Fixlog is incomplete. Are you able to see the results of the DISM command?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds