Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Need Help With usw9.prmsrvs.com on Chrome.exe


  • Please log in to reply
29 replies to this topic

#16 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 2,423 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:24 AM

Posted 23 September 2023 - 07:40 AM

Thanks for the new logs.
Yes I'd spotted an .opera folder in Users and had planned to remove it.
Let's run this FRST script next, to remove some items, do some maintenance and reset the firewall.
As a part of this I have included the The Emptytemp: command.
Note: This will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
Important: This script was written specifically for you, for use only on this machine. Running this on another machine may cause damage to your operating system

  • Right click on the FRST icon and select Run as administrator.
  • Highlight all of the information in the text box below then hit the Ctrl + C keys together to copy the text.
  • It is not necessary to paste the information anywhere as FRST will do this for you.
Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-951395627-451568364-1154128064-1001\...\Policies\Explorer: []
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\regfile:  <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\.reg:  =>  <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\.bat:  =>  <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\.cmd:  =>  <==== ATTENTION
Edge HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx <not found>
FF Homepage: Mozilla\Firefox\Profiles\zof674gf.default-release -> hxxps://mysearchengine.co/homepage?hp=1&bitmask=9996&pId=BT170902&iDate=2022-02-28 12:38:04&bName=
FF HKU\S-1-5-21-951395627-451568364-1154128064-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Gemilang\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Gemilang\AppData\Roaming\IDM\idmmzcc5 [2022-03-30] [Legacy] [not signed]
FF HKU\S-1-5-21-951395627-451568364-1154128064-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
CHR HKLM\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok]
CHR HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
2023-09-19 07:16 - 2023-09-19 07:16 - 000000000 ____D C:\Users\Gemilang\AppData\Local\AdvinstAnalytics
Task: {5A455BFF-AF14-4106-ABAA-616CD019E4E7} - System32\Tasks\Opera GX scheduled Autoupdate 1695082761 => C:\Users\Gemilang\AppData\Local\Programs\Opera GX\launcher.exe [2686880 2023-09-14] (Opera Norway AS -> Opera Software)
C:\Users\Gemilang\AppData\Local\Programs\Opera GX
C:\Users\Gemilang\.opera
2023-09-19 07:19 - 2023-09-19 07:21 - 000000000 ____D C:\Users\Gemilang\AppData\Local\Opera Software
2023-09-19 07:18 - 2023-09-19 07:21 - 000000000 ____D C:\Users\Gemilang\AppData\Roaming\Opera Software
Task: {0EBC74EF-D7E8-4C71-B74D-65C493746E45} - System32\Tasks\0k5gyk\uiacye\wcl32b\8061vv\ch9obp\gv6xcb\yc3dex\l2xjrq\9q8q30\t6wfja\jvcfmh\uadojg\hf6cch\b2g06o\t2hnfr\cgaqfe\5vxbl6 => %localappdata%\Catawba.exe  "tgbnhyhtgbnhyttgbnhyttgbnhyptgbnhy:tgbnhy/tgbnhy/tgbnhywtgbnhywtgbnhywtgbnhy.tgbnhyftgbnhyotgbnhyntgbnhyttgbnhyetgbnhyntgbnhyotgbnhyttgbnhystgbnhyutgbnhy.tgbnhyctgbnhyotgbnhymtgbnhy/tgbnhyle2qp0qp2qtgbnhyp3qp0c9c1ltgbnhye8leqphtmltgbnhyL2shEWR9IqtgbnhyVBHQoiukZ0" (No File) <==== ATTENTION
Task: {2088BC70-4DAA-48D0-871D-7AB65319538A} - System32\Tasks\1t8v7n\l2tjnx\7auokl\687xl3\z9jmoh\vr2uzp\0tybme\txmh4v\36hx1z\oph9d7\jl14v5\cyhl7j\16sw5m\sr3s5c\lh36mc\9s6hev\8nlq4n => %localappdata%\brooches.exe  (No File) <==== ATTENTION
Task: {D71D304C-DC3D-4144-86B6-324552FAC08E} - System32\Tasks\47qjxe\8566kz\fznvm5\dfixxe\6p62t4\ntaoqs\3gzjra\qoqley\8ci4l6\ir522d\9n8txq\afffbt\9z194s\cczhi7\pjiadh\ul6e69\n6t0xd => %PROGRAMFILES(x86)%\Botas\abed.exe  (No File) <==== ATTENTION
Task: {A4853274-B062-4A5A-875F-00E84F41BC58} - System32\Tasks\9dinme\q3ambz\itwk4j\mt5lbp\8ne09c\eooqhs\782jd2\q59wq4\1edtbb\ekdgrz\nah251\mokab1\mtnqen\zgu6wd\e3cnhb\8wyq1n\da5qye => %localappdata%\Catawba.exe  "tgbnhyhtgbnhyttgbnhyttgbnhyptgbnhy:tgbnhy/tgbnhy/tgbnhywtgbnhywtgbnhywtgbnhy.tgbnhyftgbnhyotgbnhyntgbnhyttgbnhyetgbnhyntgbnhyotgbnhyttgbnhystgbnhyutgbnhy.tgbnhyctgbnhyotgbnhymtgbnhy/tgbnhyle2qp0qp2qtgbnhyp3qp0c9c1ltgbnhye8leqphtmltgbnhyL2shEWR9IqtgbnhyVBHQoiukZ0" (No File) <==== ATTENTION
Task: {2A94F5B7-F03C-4D93-ABD7-900A6F5828AD} - System32\Tasks\ASC_SkipUac_gemil => "C:\Program Files (x86)\Advanced SystemCare Pro\ASC.exe"  /SkipUac (No File)
Task: {291F967A-2AC3-4B10-9B27-6AF378753593} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe  (No File)
Task: {70D79F22-BA6E-4466-AA74-814F3CB63E86} - System32\Tasks\Driver Booster SkipUAC (Gemilang) => C:\Program Files (x86)\Driver Booster\DriverBooster.exe [8641536 2022-02-22] (IObit) [File not signed]
Task: {D64DF579-8045-4D20-823F-39B9F1F7CE95} - System32\Tasks\m0am5a\fl0j9f\itg3t9\4cwo3d\hreyo3\ghcat5\zqt7jt\azgviq\7wj9j0\ppmvk5\vdc6it\y8awzt\87g874\057s9v\a2socn\5d9dca\yydm4m => %localappdata%\toppled.exe  "tgbnhyhtgbnhyttgbnhyttgbnhyptgbnhy:tgbnhy/tgbnhy/tgbnhywtgbnhywtgbnhywtgbnhy.tgbnhyftgbnhyotgbnhyntgbnhyttgbnhyetgbnhyntgbnhyotgbnhyttgbnhystgbnhyutgbnhy.tgbnhyctgbnhyotgbnhymtgbnhy/tgbnhyle2qp0qp2qtgbnhyp3qp0c9c1ltgbnhye8leqphtmltgbnhyL2shEWR9IqtgbnhyVBHQoiukZ0" (No File) <==== ATTENTION
Task: {97150913-4DCC-40BE-A7AE-71DE813694DA} - System32\Tasks\McAfeeTsk\OOBEUpgrader => C:\Program Files\McAfee\MSC\OOBE_Upgrader.exe  /Run (No File)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
2023-09-19 07:21 - 2023-09-19 07:50 - 000000000 ___HD C:\Program Files (x86)\Klan
2023-09-19 07:21 - 2023-09-19 07:30 - 000000000 ____D C:\Program Files (x86)\draped
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\w4agpq
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\rkn1wb
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\obs510
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\m0am5a
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\c1cupu
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\aqlv93
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\akio5d
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\9itdhj
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\9dinme
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\47qjxe
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\2r2ljl
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\1t8v7n
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\0k5gyk
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => No File
BHO: No Name -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> No File
U3 aswbdisk; no ImagePath
S3 rsDwf; \SystemRoot\system32\DRIVERS\rsDwf.sys [X]
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2021-03-03] (Tonec Inc. -> Tonec FZE)
C:\Program Files (x86)\Internet Download Manager
2023-09-21 21:06 - 2022-03-23 23:21 - 000000000 ____D C:\Program Files\Revo Uninstaller
cmd: netsh winsock reset catalog
cmd: netsh int ip reset C:\resettcpip.txt
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: Bitsadmin /Reset /Allusers
cmd: ipconfig /flushdns
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /RestoreHealth
Emptytemp:
End::
  • Click on the Fix button just once and wait.
  • If the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When it's finished FRST will generate a log in the location you ran the tool from. (Fixlog.txt).

Please copy the contents from this text file and paste into your next reply.
Also advise how your computer is running now.

 



BC AdBot (Login to Remove)

 


#17 glanko

glanko
  • Topic Starter

  •  Avatar image
  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indonesia
  • Local time:08:24 AM

Posted 23 September 2023 - 09:09 AM

okay .opera folder is still exist but the prmvs I think has gone (atleast for now). here is the log:
 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-09-2023
Ran by Gemilang (23-09-2023 20:12:23) Run:1
Running from C:\Users\Gemilang\Downloads
Loaded Profiles: Gemilang & postgres & Administrator
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-951395627-451568364-1154128064-1001\...\Policies\Explorer: []
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\regfile:  <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\.reg:  =>  <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\.bat:  =>  <==== ATTENTION
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\.cmd:  =>  <==== ATTENTION
Edge HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx <not found>
FF Homepage: Mozilla\Firefox\Profiles\zof674gf.default-release -> hxxps://mysearchengine.co/homepage?hp=1&bitmask=9996&pId=BT170902&iDate=2022-02-28 12:38:04&bName=
FF HKU\S-1-5-21-951395627-451568364-1154128064-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Gemilang\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Gemilang\AppData\Roaming\IDM\idmmzcc5 [2022-03-30] [Legacy] [not signed]
FF HKU\S-1-5-21-951395627-451568364-1154128064-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
CHR HKLM\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok]
CHR HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
2023-09-19 07:16 - 2023-09-19 07:16 - 000000000 ____D C:\Users\Gemilang\AppData\Local\AdvinstAnalytics
Task: {5A455BFF-AF14-4106-ABAA-616CD019E4E7} - System32\Tasks\Opera GX scheduled Autoupdate 1695082761 => C:\Users\Gemilang\AppData\Local\Programs\Opera GX\launcher.exe [2686880 2023-09-14] (Opera Norway AS -> Opera Software)
C:\Users\Gemilang\AppData\Local\Programs\Opera GX
C:\Users\Gemilang\.opera
2023-09-19 07:19 - 2023-09-19 07:21 - 000000000 ____D C:\Users\Gemilang\AppData\Local\Opera Software
2023-09-19 07:18 - 2023-09-19 07:21 - 000000000 ____D C:\Users\Gemilang\AppData\Roaming\Opera Software
Task: {0EBC74EF-D7E8-4C71-B74D-65C493746E45} - System32\Tasks\0k5gyk\uiacye\wcl32b\8061vv\ch9obp\gv6xcb\yc3dex\l2xjrq\9q8q30\t6wfja\jvcfmh\uadojg\hf6cch\b2g06o\t2hnfr\cgaqfe\5vxbl6 => %localappdata%\Catawba.exe  "tgbnhyhtgbnhyttgbnhyttgbnhyptgbnhy:tgbnhy/tgbnhy/tgbnhywtgbnhywtgbnhywtgbnhy.tgbnhyftgbnhyotgbnhyntgbnhyttgbnhyetgbnhyntgbnhyotgbnhyttgbnhystgbnhyutgbnhy.tgbnhyctgbnhyotgbnhymtgbnhy/tgbnhyle2qp0qp2qtgbnhyp3qp0c9c1ltgbnhye8leqphtmltgbnhyL2shEWR9IqtgbnhyVBHQoiukZ0" (No File) <==== ATTENTION
Task: {2088BC70-4DAA-48D0-871D-7AB65319538A} - System32\Tasks\1t8v7n\l2tjnx\7auokl\687xl3\z9jmoh\vr2uzp\0tybme\txmh4v\36hx1z\oph9d7\jl14v5\cyhl7j\16sw5m\sr3s5c\lh36mc\9s6hev\8nlq4n => %localappdata%\brooches.exe  (No File) <==== ATTENTION
Task: {D71D304C-DC3D-4144-86B6-324552FAC08E} - System32\Tasks\47qjxe\8566kz\fznvm5\dfixxe\6p62t4\ntaoqs\3gzjra\qoqley\8ci4l6\ir522d\9n8txq\afffbt\9z194s\cczhi7\pjiadh\ul6e69\n6t0xd => %PROGRAMFILES(x86)%\Botas\abed.exe  (No File) <==== ATTENTION
Task: {A4853274-B062-4A5A-875F-00E84F41BC58} - System32\Tasks\9dinme\q3ambz\itwk4j\mt5lbp\8ne09c\eooqhs\782jd2\q59wq4\1edtbb\ekdgrz\nah251\mokab1\mtnqen\zgu6wd\e3cnhb\8wyq1n\da5qye => %localappdata%\Catawba.exe  "tgbnhyhtgbnhyttgbnhyttgbnhyptgbnhy:tgbnhy/tgbnhy/tgbnhywtgbnhywtgbnhywtgbnhy.tgbnhyftgbnhyotgbnhyntgbnhyttgbnhyetgbnhyntgbnhyotgbnhyttgbnhystgbnhyutgbnhy.tgbnhyctgbnhyotgbnhymtgbnhy/tgbnhyle2qp0qp2qtgbnhyp3qp0c9c1ltgbnhye8leqphtmltgbnhyL2shEWR9IqtgbnhyVBHQoiukZ0" (No File) <==== ATTENTION
Task: {2A94F5B7-F03C-4D93-ABD7-900A6F5828AD} - System32\Tasks\ASC_SkipUac_gemil => "C:\Program Files (x86)\Advanced SystemCare Pro\ASC.exe"  /SkipUac (No File)
Task: {291F967A-2AC3-4B10-9B27-6AF378753593} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe  (No File)
Task: {70D79F22-BA6E-4466-AA74-814F3CB63E86} - System32\Tasks\Driver Booster SkipUAC (Gemilang) => C:\Program Files (x86)\Driver Booster\DriverBooster.exe [8641536 2022-02-22] (IObit) [File not signed]
Task: {D64DF579-8045-4D20-823F-39B9F1F7CE95} - System32\Tasks\m0am5a\fl0j9f\itg3t9\4cwo3d\hreyo3\ghcat5\zqt7jt\azgviq\7wj9j0\ppmvk5\vdc6it\y8awzt\87g874\057s9v\a2socn\5d9dca\yydm4m => %localappdata%\toppled.exe  "tgbnhyhtgbnhyttgbnhyttgbnhyptgbnhy:tgbnhy/tgbnhy/tgbnhywtgbnhywtgbnhywtgbnhy.tgbnhyftgbnhyotgbnhyntgbnhyttgbnhyetgbnhyntgbnhyotgbnhyttgbnhystgbnhyutgbnhy.tgbnhyctgbnhyotgbnhymtgbnhy/tgbnhyle2qp0qp2qtgbnhyp3qp0c9c1ltgbnhye8leqphtmltgbnhyL2shEWR9IqtgbnhyVBHQoiukZ0" (No File) <==== ATTENTION
Task: {97150913-4DCC-40BE-A7AE-71DE813694DA} - System32\Tasks\McAfeeTsk\OOBEUpgrader => C:\Program Files\McAfee\MSC\OOBE_Upgrader.exe  /Run (No File)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
2023-09-19 07:21 - 2023-09-19 07:50 - 000000000 ___HD C:\Program Files (x86)\Klan
2023-09-19 07:21 - 2023-09-19 07:30 - 000000000 ____D C:\Program Files (x86)\draped
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\w4agpq
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\rkn1wb
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\obs510
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\m0am5a
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\c1cupu
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\aqlv93
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\akio5d
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\9itdhj
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\9dinme
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\47qjxe
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\2r2ljl
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\1t8v7n
2023-09-19 07:21 - 2023-09-19 07:21 - 000000000 ____D C:\WINDOWS\system32\Tasks\0k5gyk
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => No File
BHO: No Name -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> No File
U3 aswbdisk; no ImagePath
S3 rsDwf; \SystemRoot\system32\DRIVERS\rsDwf.sys [X]
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2021-03-03] (Tonec Inc. -> Tonec FZE)
C:\Program Files (x86)\Internet Download Manager
2023-09-21 21:06 - 2022-03-23 23:21 - 000000000 ____D C:\Program Files\Revo Uninstaller
cmd: netsh winsock reset catalog
cmd: netsh int ip reset C:\resettcpip.txt
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: Bitsadmin /Reset /Allusers
cmd: ipconfig /flushdns
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /RestoreHealth
Emptytemp:
End::
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\" => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center => removed successfully
"HKLM\Software\Policies\Microsoft\Windows\System\\EnableSmartScreen" => removed successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Policies\Microsoft\Edge => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\regfile => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\.reg => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\.bat => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Classes\.cmd => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Microsoft\Edge\Extensions\llbjbkhnmlidjebalopleeepgdfgcpec => removed successfully
"Firefox homepage" => removed successfully
"HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com" => removed successfully
 
"C:\Users\Gemilang\AppData\Roaming\IDM\idmmzcc5" folder move:
 
C:\Users\Gemilang\AppData\Roaming\IDM\idmmzcc5 => moved successfully
"HKU\S-1-5-21-951395627-451568364-1154128064-1001\Software\Mozilla\SeaMonkey\Extensions\\mozilla_cc2@internetdownloadmanager.com" => removed successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\llbcnfanfmjhpedaedhbcnpgeepdnnok => removed successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Google\Chrome\Extensions\llbcnfanfmjhpedaedhbcnpgeepdnnok => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\llbcnfanfmjhpedaedhbcnpgeepdnnok => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => removed successfully
 
"C:\Users\Gemilang\AppData\Local\AdvinstAnalytics" folder move:
 
C:\Users\Gemilang\AppData\Local\AdvinstAnalytics => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5A455BFF-AF14-4106-ABAA-616CD019E4E7}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A455BFF-AF14-4106-ABAA-616CD019E4E7}" => removed successfully
C:\WINDOWS\System32\Tasks\Opera GX scheduled Autoupdate 1695082761 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera GX scheduled Autoupdate 1695082761" => removed successfully
 
"C:\Users\Gemilang\AppData\Local\Programs\Opera GX" folder move:
 
C:\Users\Gemilang\AppData\Local\Programs\Opera GX => moved successfully
 
"C:\Users\Gemilang\.opera" folder move:
 
C:\Users\Gemilang\.opera => moved successfully
 
"C:\Users\Gemilang\AppData\Local\Opera Software" folder move:
 
C:\Users\Gemilang\AppData\Local\Opera Software => moved successfully
 
"C:\Users\Gemilang\AppData\Roaming\Opera Software" folder move:
 
C:\Users\Gemilang\AppData\Roaming\Opera Software => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0EBC74EF-D7E8-4C71-B74D-65C493746E45}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0EBC74EF-D7E8-4C71-B74D-65C493746E45}" => removed successfully
C:\WINDOWS\System32\Tasks\0k5gyk\uiacye\wcl32b\8061vv\ch9obp\gv6xcb\yc3dex\l2xjrq\9q8q30\t6wfja\jvcfmh\uadojg\hf6cch\b2g06o\t2hnfr\cgaqfe\5vxbl6 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0k5gyk\uiacye\wcl32b\8061vv\ch9obp\gv6xcb\yc3dex\l2xjrq\9q8q30\t6wfja\jvcfmh\uadojg\hf6cch\b2g06o\t2hnfr\cgaqfe\5vxbl6" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2088BC70-4DAA-48D0-871D-7AB65319538A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2088BC70-4DAA-48D0-871D-7AB65319538A}" => removed successfully
C:\WINDOWS\System32\Tasks\1t8v7n\l2tjnx\7auokl\687xl3\z9jmoh\vr2uzp\0tybme\txmh4v\36hx1z\oph9d7\jl14v5\cyhl7j\16sw5m\sr3s5c\lh36mc\9s6hev\8nlq4n => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1t8v7n\l2tjnx\7auokl\687xl3\z9jmoh\vr2uzp\0tybme\txmh4v\36hx1z\oph9d7\jl14v5\cyhl7j\16sw5m\sr3s5c\lh36mc\9s6hev\8nlq4n" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D71D304C-DC3D-4144-86B6-324552FAC08E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D71D304C-DC3D-4144-86B6-324552FAC08E}" => removed successfully
C:\WINDOWS\System32\Tasks\47qjxe\8566kz\fznvm5\dfixxe\6p62t4\ntaoqs\3gzjra\qoqley\8ci4l6\ir522d\9n8txq\afffbt\9z194s\cczhi7\pjiadh\ul6e69\n6t0xd => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\47qjxe\8566kz\fznvm5\dfixxe\6p62t4\ntaoqs\3gzjra\qoqley\8ci4l6\ir522d\9n8txq\afffbt\9z194s\cczhi7\pjiadh\ul6e69\n6t0xd" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A4853274-B062-4A5A-875F-00E84F41BC58}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4853274-B062-4A5A-875F-00E84F41BC58}" => removed successfully
C:\WINDOWS\System32\Tasks\9dinme\q3ambz\itwk4j\mt5lbp\8ne09c\eooqhs\782jd2\q59wq4\1edtbb\ekdgrz\nah251\mokab1\mtnqen\zgu6wd\e3cnhb\8wyq1n\da5qye => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9dinme\q3ambz\itwk4j\mt5lbp\8ne09c\eooqhs\782jd2\q59wq4\1edtbb\ekdgrz\nah251\mokab1\mtnqen\zgu6wd\e3cnhb\8wyq1n\da5qye" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2A94F5B7-F03C-4D93-ABD7-900A6F5828AD}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A94F5B7-F03C-4D93-ABD7-900A6F5828AD}" => removed successfully
C:\WINDOWS\System32\Tasks\ASC_SkipUac_gemil => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASC_SkipUac_gemil" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{291F967A-2AC3-4B10-9B27-6AF378753593}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{291F967A-2AC3-4B10-9B27-6AF378753593}" => removed successfully
C:\WINDOWS\System32\Tasks\ASUS\P508PowerAgent_sdk => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS\P508PowerAgent_sdk" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{70D79F22-BA6E-4466-AA74-814F3CB63E86}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70D79F22-BA6E-4466-AA74-814F3CB63E86}" => removed successfully
C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Gemilang) => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Gemilang)" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D64DF579-8045-4D20-823F-39B9F1F7CE95}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D64DF579-8045-4D20-823F-39B9F1F7CE95}" => removed successfully
C:\WINDOWS\System32\Tasks\m0am5a\fl0j9f\itg3t9\4cwo3d\hreyo3\ghcat5\zqt7jt\azgviq\7wj9j0\ppmvk5\vdc6it\y8awzt\87g874\057s9v\a2socn\5d9dca\yydm4m => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\m0am5a\fl0j9f\itg3t9\4cwo3d\hreyo3\ghcat5\zqt7jt\azgviq\7wj9j0\ppmvk5\vdc6it\y8awzt\87g874\057s9v\a2socn\5d9dca\yydm4m" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{97150913-4DCC-40BE-A7AE-71DE813694DA}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{97150913-4DCC-40BE-A7AE-71DE813694DA}" => removed successfully
C:\WINDOWS\System32\Tasks\McAfeeTsk\OOBEUpgrader => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfeeTsk\OOBEUpgrader" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
 
"C:\Program Files (x86)\Klan" folder move:
 
C:\Program Files (x86)\Klan => moved successfully
 
"C:\Program Files (x86)\draped" folder move:
 
C:\Program Files (x86)\draped => moved successfully
 
"C:\WINDOWS\system32\Tasks\w4agpq" folder move:
 
C:\WINDOWS\system32\Tasks\w4agpq => moved successfully
 
"C:\WINDOWS\system32\Tasks\rkn1wb" folder move:
 
C:\WINDOWS\system32\Tasks\rkn1wb => moved successfully
 
"C:\WINDOWS\system32\Tasks\obs510" folder move:
 
C:\WINDOWS\system32\Tasks\obs510 => moved successfully
 
"C:\WINDOWS\system32\Tasks\m0am5a" folder move:
 
C:\WINDOWS\system32\Tasks\m0am5a => moved successfully
 
"C:\WINDOWS\system32\Tasks\c1cupu" folder move:
 
C:\WINDOWS\system32\Tasks\c1cupu => moved successfully
 
"C:\WINDOWS\system32\Tasks\aqlv93" folder move:
 
C:\WINDOWS\system32\Tasks\aqlv93 => moved successfully
 
"C:\WINDOWS\system32\Tasks\akio5d" folder move:
 
C:\WINDOWS\system32\Tasks\akio5d => moved successfully
 
"C:\WINDOWS\system32\Tasks\9itdhj" folder move:
 
C:\WINDOWS\system32\Tasks\9itdhj => moved successfully
 
"C:\WINDOWS\system32\Tasks\9dinme" folder move:
 
C:\WINDOWS\system32\Tasks\9dinme => moved successfully
 
"C:\WINDOWS\system32\Tasks\47qjxe" folder move:
 
C:\WINDOWS\system32\Tasks\47qjxe => moved successfully
 
"C:\WINDOWS\system32\Tasks\2r2ljl" folder move:
 
C:\WINDOWS\system32\Tasks\2r2ljl => moved successfully
 
"C:\WINDOWS\system32\Tasks\1t8v7n" folder move:
 
C:\WINDOWS\system32\Tasks\1t8v7n => moved successfully
 
"C:\WINDOWS\system32\Tasks\0k5gyk" folder move:
 
C:\WINDOWS\system32\Tasks\0k5gyk => moved successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220} => removed successfully
HKU\S-1-5-21-951395627-451568364-1154128064-1001_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1} => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8} => removed successfully
HKLM\System\CurrentControlSet\Services\aswbdisk => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\rsDwf => removed successfully
rsDwf => service removed successfully
HKLM\System\CurrentControlSet\Services\WinSetupMon => removed successfully
WinSetupMon => service removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ IDM Shell Extension => subkey with invalid name -> removed successfully
HKLM\Software\Classes\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D} => removed successfully
 
"C:\Program Files (x86)\Internet Download Manager" folder move:
 
C:\Program Files (x86)\Internet Download Manager => moved successfully
 
"C:\Program Files\Revo Uninstaller" folder move:
 
C:\Program Files\Revo Uninstaller => moved successfully
 
========= netsh winsock reset catalog =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
 
========= End of CMD: =========
 
 
========= netsh int ip reset C:\resettcpip.txt =========
 
Resetting Compartment Forwarding, OK!
Resetting Compartment, OK!
Resetting Control Protocol, OK!
Resetting Echo Sequence Request, OK!
Resetting Global, OK!
Resetting Interface, OK!
Resetting Anycast Address, OK!
Resetting Multicast Address, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting Potential, OK!
Resetting Prefix Policy, OK!
Resetting Proxy Neighbor, OK!
Resetting Route, OK!
Resetting Site Prefix, OK!
Resetting Subinterface, OK!
Resetting Wakeup Pattern, OK!
Resetting Resolve Neighbor, OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , failed.
Access is denied.
 
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.
 
 
 
========= End of CMD: =========
 
 
========= netsh advfirewall reset =========
 
Ok.
 
 
 
========= End of CMD: =========
 
 
========= netsh advfirewall set allprofiles state ON =========
 
Ok.
 
 
 
========= End of CMD: =========
 
 
========= Bitsadmin /Reset /Allusers =========
 
 
BITSADMIN version 3.0
BITS administration utility.
© Copyright Microsoft Corp.
 
0 out of 0 jobs canceled.
 
 
========= End of CMD: =========
 
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
 
========= End of CMD: =========
 
 
========= sfc /scannow =========
 
 
Beginning system scan.  This process will take some time.
 
Beginning verification phase of system scan.
 
Verification 0% complete.
Verification 1% complete.
Verification 1% complete.
Verification 2% complete.
Verification 2% complete.
Verification 3% complete.
Verification 3% complete.
Verification 4% complete.
Verification 5% complete.
Verification 5% complete.
Verification 6% complete.
Verification 6% complete.
Verification 7% complete.
Verification 7% complete.
Verification 8% complete.
Verification 8% complete.
Verification 9% complete.
Verification 10% complete.
Verification 10% complete.
Verification 11% complete.
Verification 11% complete.
Verification 12% complete.
Verification 12% complete.
Verification 13% complete.
Verification 14% complete.
Verification 14% complete.
Verification 15% complete.
Verification 15% complete.
Verification 16% complete.
Verification 16% complete.
Verification 17% complete.
Verification 17% complete.
Verification 18% complete.
Verification 19% complete.
Verification 19% complete.
Verification 20% complete.
Verification 20% complete.
Verification 21% complete.
Verification 21% complete.
Verification 22% complete.
Verification 23% complete.
Verification 23% complete.
Verification 24% complete.
Verification 24% complete.
Verification 25% complete.
Verification 25% complete.
Verification 26% complete.
Verification 26% complete.
Verification 27% complete.
Verification 28% complete.
Verification 28% complete.
Verification 29% complete.
Verification 29% complete.
Verification 30% complete.
Verification 30% complete.
Verification 31% complete.
Verification 32% complete.
Verification 32% complete.
Verification 33% complete.
Verification 33% complete.
Verification 34% complete.
Verification 34% complete.
Verification 35% complete.
Verification 35% complete.
Verification 36% complete.
Verification 37% complete.
Verification 37% complete.
Verification 38% complete.
Verification 38% complete.
Verification 39% complete.
Verification 39% complete.
Verification 40% complete.
Verification 41% complete.
Verification 41% complete.
Verification 42% complete.
Verification 42% complete.
Verification 43% complete.
Verification 43% complete.
Verification 44% complete.
Verification 44% complete.
Verification 45% complete.
Verification 46% complete.
Verification 46% complete.
Verification 47% complete.
Verification 47% complete.
Verification 48% complete.
Verification 48% complete.
Verification 49% complete.
Verification 49% complete.
Verification 50% complete.
Verification 51% complete.
Verification 51% complete.
Verification 52% complete.
Verification 52% complete.
Verification 53% complete.
Verification 53% complete.
Verification 54% complete.
Verification 55% complete.
Verification 55% complete.
Verification 56% complete.
Verification 56% complete.
Verification 57% complete.
Verification 57% complete.
Verification 58% complete.
Verification 58% complete.
Verification 59% complete.
Verification 60% complete.
Verification 60% complete.
Verification 61% complete.
Verification 61% complete.
Verification 62% complete.
Verification 62% complete.
Verification 63% complete.
Verification 64% complete.
Verification 64% complete.
Verification 65% complete.
Verification 65% complete.
Verification 66% complete.
Verification 66% complete.
Verification 67% complete.
Verification 67% complete.
Verification 68% complete.
Verification 69% complete.
Verification 69% complete.
Verification 70% complete.
Verification 70% complete.
Verification 71% complete.
Verification 71% complete.
Verification 72% complete.
Verification 73% complete.
Verification 73% complete.
Verification 74% complete.
Verification 74% complete.
Verification 75% complete.
Verification 75% complete.
Verification 76% complete.
Verification 76% complete.
Verification 77% complete.
Verification 78% complete.
Verification 78% complete.
Verification 79% complete.
Verification 79% complete.
Verification 80% complete.
Verification 80% complete.
Verification 81% complete.
Verification 82% complete.
Verification 82% complete.
Verification 83% complete.
Verification 83% complete.
Verification 84% complete.
Verification 84% complete.
Verification 85% complete.
Verification 85% complete.
Verification 86% complete.
Verification 87% complete.
Verification 87% complete.
Verification 88% complete.
Verification 88% complete.
Verification 89% complete.
Verification 89% complete.
Verification 90% complete.
Verification 90% complete.
Verification 91% complete.
Verification 92% complete.
Verification 92% complete.
Verification 93% complete.
Verification 93% complete.
Verification 94% complete.
Verification 94% complete.
Verification 95% complete.
Verification 96% complete.
Verification 96% complete.
Verification 97% complete.
Verification 97% complete.
Verification 98% complete.
Verification 98% complete.
Verification 99% complete.
Verification 99% complete.
Verification 100% complete.
 
Windows Resource Protection found corrupt files and successfully repaired them.
For online repairs, details are included in the CBS log file located at
windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline
repairs, details are included in the log file provided by the /OFFLOGFILE flag.
 
 
========= End of CMD: =========
 
 
========= DISM /Online /Cleanup-Image /RestoreHealth =========
 
 
Deployment Image Servicing and Management tool
Version: 10.0.22621.1
 
Image Version: 10.0.22621.2283
 
 
[==                         3.8%                           ] 
 
[==                         4.8%                           ] 
 
[===                        5.7%                           ] 
 
[===                        6.7%                           ] 
 
[====                       7.7%                           ] 
 
[=====                      8.7%                           ] 
 
[=====                      9.7%                           ] 
 
[======                     10.6%                          ] 
 
[======                     11.6%                          ] 
 
[=======                    12.6%                          ] 
 
[=======                    13.6%                          ] 
 
[========                   14.6%                          ] 
 
[=========                  15.5%                          ] 
 
[=========                  16.5%                          ] 
 
[==========                 17.5%                          ] 
 
[==========                 18.5%                          ] 
 
[==========                 18.6%                          ] 
 
[===========                19.6%                          ] 
 
[===========                20.6%                          ] 
 
[============               21.6%                          ] 
 
[=============              22.6%                          ] 
 
[=============              23.5%                          ] 
 
[==============             24.5%                          ] 
 
[==============             25.5%                          ] 
 
[===============            26.5%                          ] 
 
[===============            27.5%                          ] 
 
[================           28.5%                          ] 
 
[=================          29.4%                          ] 
 
[=================          30.4%                          ] 
 
[==================         31.4%                          ] 
 
[==================         31.8%                          ] 
 
[===================        32.8%                          ] 
 
[===================        33.6%                          ] 
 
[====================       34.6%                          ] 
 
[====================       35.5%                          ] 
 
[====================       35.8%                          ] 
 
[=====================      36.5%                          ] 
 
[=====================      37.1%                          ] 
 
[======================     38.1%                          ] 
 
[======================     38.4%                          ] 
 
[======================     38.9%                          ] 
 
[======================     39.5%                          ] 
 
[=======================    40.5%                          ] 
 
[========================   41.5%                          ] 
 
[========================   42.5%                          ] 
 
[=========================  43.5%                          ] 
 
[=========================  44.5%                          ] 
 
[========================== 45.4%                          ] 
 
[========================== 46.4%                          ] 
 
[===========================47.4%                          ] 
 
[===========================48.4%                          ] 
 
[===========================49.4%                          ] 
 
[===========================50.3%                          ] 
 
[===========================51.3%                          ] 
 
[===========================52.2%                          ] 
 
[===========================52.4%                          ] 
 
[===========================52.5%                          ] 
 
[===========================52.7%                          ] 
 
[===========================52.8%                          ] 
 
[===========================52.9%                          ] 
 
[===========================53.0%                          ] 
 
[===========================53.1%                          ] 
 
[===========================53.2%                          ] 
 
[===========================53.4%                          ] 
 
[===========================53.5%                          ] 
 
[===========================53.7%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.2%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.5%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.7%                          ] 
 
[===========================54.9%                          ] 
 
[===========================54.9%                          ] 
 
[===========================55.1%                          ] 
 
[===========================55.3%                          ] 
 
[===========================55.6%                          ] 
 
[===========================55.8%                          ] 
 
[===========================55.9%                          ] 
 
[===========================56.2%                          ] 
 
[===========================56.3%                          ] 
 
[===========================56.6%                          ] 
 
[===========================57.6%=                         ] 
 
[===========================58.6%=                         ] 
 
[===========================59.1%==                        ] 
 
[===========================59.1%==                        ] 
 
[===========================60.1%==                        ] 
 
[===========================62.3%====                      ] 
 
[===========================77.4%============              ] 
 
[===========================84.9%=================         ] 
 
[==========================100.0%==========================] 
The restore operation completed successfully.
The operation completed successfully.
 
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
FlushDNS => completed
BITS transfer queue => 1835008 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 26734987 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 808774147 B
Windows/system/drivers => 1019106762 B
Edge => 0 B
Chrome => 3854929242 B
Firefox => 18967992 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 679131181 B
systemprofile32 => 679131181 B
LocalService => 679170525 B
NetworkService => 689342735 B
Gemilang => 2329402541 B
defaultuser100000 => 2329409709 B
postgres => 2329409709 B
Administrator => 2329431357 B
 
RecycleBin => 324772 B
EmptyTemp: => 16.6 GB temporary data Removed.
 
================================
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 23-09-2023 21:02:06)
 
 
Result of scheduled keys to remove after reboot:
 
HKLM\System\CurrentControlSet\Services\aswbdisk => could not remove, key could be protected
 
==== End of Fixlog 21:02:06 ====


#18 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 2,423 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:24 AM

Posted 23 September 2023 - 09:24 AM

Very good.
Is the path of the .opera folder C:\Users\Gemilang\.opera or is it in Downloads, as you advised earlier?

Try and delete it again and see if it returns.
I'd now like you to run a scan with AdwCleaner.
Please download AdwCleaner.

  • Close all open programs and browsers
  • Right click on the icon and select Run as administrator
  • Click Scan Now
  • When the scan has finished AdwCleaner shows you all detected PUPs and adware.
  • If any are found, select them and click Quarantine. (I would suggest that you do not select Pre-installed applications for now, or any other items you wish to keep.)
  • AdwCleaner prompts you to save and close your work before continuing. Click Continue.
  • After cleaning, you are prompted to restart your device. Click Restart now to complete the cleanup process.

Once your computer has restarted ...

  •     If it doesn't open automatically, please start AdwCleaner.
  •     Click on View Log File button (This log can also be found in the Log Files tab).
  •     A Notepad file will open containing the results.
  •     Click Skip Basic Repair (if the option appears)
  •     Please post the contents of the file in your next reply.


#19 glanko

glanko
  • Topic Starter

  •  Avatar image
  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indonesia
  • Local time:08:24 AM

Posted 23 September 2023 - 09:38 AM

I think .opera is also gone after I deleted the folder and restarted the PC. Based on the scan, I think the adware came from "Touch VPN" " The log is as follows:
 

# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build:    08-30-2022
# Database: 2023-07-19.3 (Cloud)
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    09-23-2023
# Duration: 00:00:03
# OS:       Windows 11 (Build 22621.2283)
# Cleaned:  9
# Failed:   1
 
 
***** [ Services ] *****
 
No malicious services cleaned.
 
***** [ Folders ] *****
 
Deleted       C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
Deleted       C:\ProgramData\IObit\Advanced SystemCare
Deleted       C:\Users\Gemilang\AppData\LocalLow\IObit\Advanced SystemCare
Deleted       C:\Users\Gemilang\AppData\Roaming\IObit\Advanced SystemCare
 
***** [ Files ] *****
 
No malicious files cleaned.
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks cleaned.
 
***** [ Registry ] *****
 
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe
Deleted       HKLM\Software\Wow6432Node\IObit\Advanced SystemCare
Deleted       HKLM\Software\Wow6432Node\IObit\RealTimeProtector
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe
Not Deleted   HKCU\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D
 
***** [ Chromium (and derivatives) ] *****
 
Deleted       Touch VPN - Secure and unlimited VPN proxy - bihmplhobchoageeokmgbdihknkjbknd
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs cleaned.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries cleaned.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs cleaned.
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries cleaned.
 
***** [ Preinstalled Software ] *****
 
No Preinstalled Software cleaned.
 
 
*************************
 
[+] Delete Tracing Keys
[+] Reset Winsock
 
*************************
 
AdwCleaner[S00].txt - [2378 octets] - [23/09/2023 21:31:57]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########


#20 glanko

glanko
  • Topic Starter

  •  Avatar image
  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indonesia
  • Local time:08:24 AM

Posted 23 September 2023 - 09:40 AM

The failed one seems the adware in the registry hence I don't exactly know the details yet



#21 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 2,423 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:24 AM

Posted 23 September 2023 - 11:02 AM

Please do this next.

  • Right click on the FRST icon and select Run as administrator.
  • Highlight all of the information in the text box below then hit the Ctrl + C keys together to copy the text.
  • It is not necessary to paste the information anywhere as FRST will do this for you.
Start::
ExportKey: HKCU\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D
End::
  • Click on the Fix button just once and wait.
  • When it's finished FRST will generate a log in the location you ran the tool from. (Fixlog.txt).

Please copy the contents from this text file and paste into your next reply.


Edited by dennis_l, 23 September 2023 - 11:04 AM.


#22 glanko

glanko
  • Topic Starter

  •  Avatar image
  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indonesia
  • Local time:08:24 AM

Posted 23 September 2023 - 06:19 PM

here is the log: 
 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-09-2023
Ran by Gemilang (24-09-2023 06:18:20) Run:2
Running from C:\Users\Gemilang\Downloads
Loaded Profiles: Gemilang
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
ExportKey: HKCU\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D
End::
*****************
 
================== ExportKey: ===================
 
[HKU\S-1-5-21-951395627-451568364-1154128064-1001\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D]
"Plugin"="000201001f8b0800000000000400ccbd077c54d512387cb6976ccacd26bb69642f7d09c5140837f43420106a12d844046e924dd89064431a041517052b62c1828aa8589ebdf2ec059e154505451110053b48554144846f666ec9dd04df7bfffffbbedfef (the data entry has 66620 more characters)."
"PHNX"="0080ea006ec2eaf67ffdffe2ff5001dfde3a71d913cfedfa90889a2f801bd1b9d77e4c1d98ed5da04a902a672335a040ef489e084aef7e450d3bfe76b1cc49157433abc56b3f4eb2a10f7fd0961509c67d680ae3701f50ecc21039d60d7fca3123496d0f (the data entry has 10088054 more characters)."
 
=== End of ExportKey ===
 
==== End of Fixlog 06:18:20 ====


#23 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 2,423 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:24 AM

Posted Yesterday, 04:14 AM

Now please do this.

  • Right click on the FRST icon and select Run as administrator.
  • Highlight all of the information in the text box below then hit the Ctrl + C keys together to copy the text.
  • It is not necessary to paste the information anywhere as FRST will do this for you.
Start::
CreateRestorePoint:
CloseProcesses:
DeleteValue: HKCU\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D|Plugin
DeleteValue: HKCU\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D|PHNX
End::
  • Click on the Fix button just once and wait.
  • Make sure you let the system restart normally. After that let the tool complete its run.
  • When it's finished FRST will generate a log in the location you ran the tool from. (Fixlog.txt).

Copy the contents from this text file and paste into your next reply.
Also, please provide an update on how your computer is running now.

 



#24 glanko

glanko
  • Topic Starter

  •  Avatar image
  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indonesia
  • Local time:08:24 AM

Posted Yesterday, 04:56 AM

I think the prmvs gone and here is the latest: 
 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-09-2023
Ran by Gemilang (24-09-2023 16:18:41) Run:3
Running from C:\Users\Gemilang\Downloads
Loaded Profiles: Gemilang
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CreateRestorePoint:
CloseProcesses:
DeleteValue: HKCU\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D|Plugin
DeleteValue: HKCU\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D|PHNX
End::
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKCU\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D\\Plugin" => removed successfully
"HKCU\SOFTWARE\C8F78ABBF795D2265C74CD843832CF6D\\PHNX" => removed successfully
 
 
The system needed a reboot.
 
==== End of Fixlog 16:18:51 ====


#25 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 2,423 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:24 AM

Posted Yesterday, 11:13 AM

I'd now like you to please run a scan with Emsisoft Emergency Kit., as a final check.

  • Download and save the installation file from here
  • Double-click on the Emsisoft Emergency Kit setup file to start the installation process and then click on the Install button.
  • You may be presented with a User Account Control warning, asking you if you want to run this file. Click Yes to continue.
  • The downloaded package unpacks to “C:\EEK” by default and this folder now opens on your screen.
  • To start Emsisoft, double-click on the Start Emergency Kit Scanner icon in this folder.
  • You may get another User Account Control warning. Click Yes to continue.
  • Accept the Licence Agreement.
  • When you launch the program for the first time, Emsisoft Emergency Kit will automatically download updates. The Scan tab changes from orange to green when the update process is completed.
  • Leave the settings unchanged, which include detection of Potentially Unwanted Programs.
  • Now click on Malware Scan in the Scan button.
  • When the Emsisoft scan has finished, you will see a screen reporting details of any malicious files found on your computer.(Close the pop up inviting installation of Emsisoft protection)
  • Click Quarantine selected objects. (Note, this option is only shown if malicious objects were detected during the scan)
  • You may be asked to restart your computer.
  • When the threats have been quarantined, click the View Report button in the lower-right corner and the scan log will open in Notepad. The logs can also be accessed in the left hand menu bar.
  • Please save this log on your desktop and post the contents into your next reply.
  • When you close Emsisoft Emergency Kit it asks if you wish to sign up for a newsletter. This is optional, and does not affect the malware removal process.

 



#26 glanko

glanko
  • Topic Starter

  •  Avatar image
  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indonesia
  • Local time:08:24 AM

Posted Yesterday, 09:01 PM

ermm I tried the download link and it seems not working. I also click the "click here" button when the download doesn't start immediately and seems not to be working too. any idea?



#27 glanko

glanko
  • Topic Starter

  •  Avatar image
  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indonesia
  • Local time:08:24 AM

Posted Yesterday, 09:30 PM

Nevermind I downloaded it from the original sources and here is the result: 
 

Emsisoft Emergency Kit - Version 2023.6
Last update: N/A
My own LAPTOP-IG4RR8R0\Gemilang
 LAPTOP-IG4RR8R0
 Windows 11x64 
 
Scan settings:
 
Scan type: Malware Scan
Objects: Memory, Traces, Files
 
Detect PUPs: On
Scan archives: Off
Scan mail archives: Off
ADS Scan: On
 
Scan start: 25/09/2023 09:28:45
 
Scanned 92213
Found 0
Scanning memory... 
Scanning traces... 
Scanning files... 
 
Scan end: 25/09/2023 09:29:54
Scan time: 0:01:09


#28 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 2,423 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:24 AM

Posted Today, 02:30 AM

The link is working ok now, although there is a slight delay before the download starts.
I am pleased to see that nothing was detected and also that the original issue has been resolved.
Please advise if you have any further questions, before I post some tool/log clean up instructions and information for your future reference.



#29 glanko

glanko
  • Topic Starter

  •  Avatar image
  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indonesia
  • Local time:08:24 AM

Posted Today, 07:29 AM

I think it's safe to say that for the time being the malware is gone. If there is any malware again, I will seek for help again. Thank you so much for your corporation for the past week! 



#30 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 2,423 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:24 AM

Posted Today, 07:47 AM

You are most welcome.

This tool will remove the software we used.
KpRm by Kernel-panik

  •     Download KpRm and save it to your Desktop
  •     Right click on the icon and select Run as administrator.
  •     Click Yes on the Disclaimer.
  •     Place a check mark in Delete Tools and Create Restore Point.
  •     Under Delete Quarantine, check Delete in 7 days.
  •     Click Run.
  •     Click OK in the All operations are completed box.
  •     It will create and open a log report.
  •     KpRm will delete itself from you Desktop and you can either save or remove the report that was generated.

These articles offer good advice and information for the future.
Keep your computer secure at home
How your system gets infected.
Ransomware advice.
Choosing Secure Passwords.
Thank you for contacting us at Bleeping Computer.

Dennis






6 user(s) are reading this topic

0 members, 6 guests, 0 anonymous users