Hello, Welcome to BleepingComputer.

I’m nasdaq and will be helping you.

 

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.

===

 

Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.

Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to the a new file.

 

start
 
Comment: All processes will be force closed, System Protection will be enabled
Comment: New Restore Point will be created, All network proxies will be removed
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
RemoveProxy:
 
Comment: Items from the FRST.TXT log that will be removed from the Registry.
Task: {008A3035-9BEB-4F82-BBF0-04690BE73C3D} - System32TasksOneDrive Standalone Update Task-S-1-5-21-2336844648-3213177803-2782347618-500 => C:Usersilu-pAppDataLocalMicrosoftOneDriveOneDriveStandaloneUpdater.exe (No File)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:WindowsSystemAppsMicrosoft.MicrosoftEdge_8wekyb3d8bbweAssetsHostExtensionsAutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:WindowsSystemAppsMicrosoft.MicrosoftEdge_8wekyb3d8bbweAssetsBookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:WindowsSystemAppsMicrosoft.MicrosoftEdge_8wekyb3d8bbweAssetsHostExtensionsLearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:WindowsSystemAppsMicrosoft.MicrosoftEdge_8wekyb3d8bbweAssetsHostExtensionsPinJSAPI [not found]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.cpdf -> C:Program Files (x86)Foxit SoftwareFoxit PDF EditorpluginsnpFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:Program Files (x86)Foxit SoftwareFoxit PDF EditorpluginsnpFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:Program Files (x86)Foxit SoftwareFoxit PDF EditorpluginsnpFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:Program Files (x86)Foxit SoftwareFoxit PDF EditorpluginsnpFoxitPhantomPDFPlugin.dll [No File]
 
Comment: Items from the Addition.txt log that will be removed.
CustomCLSID: HKUS-1-5-21-2336844648-3213177803-2782347618-1001_ClassesCLSID{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}InprocServer32 -> C:Usersilu-pAppDataLocalMicrosoftTeamsMeetingAddin1.0.20244.4x64Microsoft.Teams.AddinLoader.dll => No File
CustomCLSID: HKUS-1-5-21-2336844648-3213177803-2782347618-1001_ClassesCLSID{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}localserver32 -> "C:Usersilu-pAppDataLocalMicrosoftTeamscurrentTeams.exe" --toast => No File
FirewallRules: [{D9812375-7BC9-4473-B15E-6AE8B6304BF4}] => (Allow) C:Program FilesIntelWiFibinPanDhcpDns.exe => No File
FirewallRules: [{1317FF1F-6F73-4018-816D-1CEF3E97038E}] => (Allow) C:Program Files (x86)Steambincefcef.win7steamwebhelper.exe => No File
FirewallRules: [{A09A1C24-462A-4CDF-9490-BE3291376496}] => (Allow) C:Program Files (x86)Steambincefcef.win7steamwebhelper.exe => No File
FirewallRules: [{B2368FE2-5D44-4CE3-8FBE-51751C2E527E}] => (Allow) C:Program Files (x86)SteamsteamappscommonRealm of the Mad GodRealm of the Mad God.exe => No File
FirewallRules: [{045BB8E4-8691-4FBE-B987-3F2CFCEC19D1}] => (Allow) C:Program Files (x86)SteamsteamappscommonRealm of the Mad GodRealm of the Mad God.exe => No File
 
Comment: Resetting of services and maintenance.
cmd: ECHO Y|CHKDSK C: /F
 
cmd: pushdwindowssystem32
cmd: net stop bits
cmd: net stop cryptSvc
cmd: net stop wuauserv
cmd: net stop msiserver
cmd: del /s /q C:WindowsSoftwareDistributiondownload*.*
cmd: net start cryptSvc
cmd: net start bits
cmd: net start wuauserv
cmd: net start msiserver
cmd: sfc /scannow
cmd: DISM.exe /Online /Cleanup-image /Restorehealth
cmd: sfc /scannow
StartBatch:
del /s /q "%userprofile%AppDataLocalGoogleChromeUser DataDefaultCache*.*"
del /s /q "%userprofile%AppDataLocalMicrosoftEdgeUser DataDefaultCache*.*"
"%WINDIR%SYSTEM32lodctr.exe" /R
"%WINDIR%SysWOW64lodctr.exe" /R
"%WINDIR%SYSTEM32lodctr.exe" /R
"%WINDIR%SysWOW64lodctr.exe" /R
NETSH winsock reset catalog
NETSH int ipv4 reset reset.log
NETSH int ipv6 reset reset.log
netsh interface IP delete arpcache
ipconfig /release
ipconfig /renew
ipconfig /flushdns
ipconfig /registerdns
net start sdrsvc
net start vss
net start rpcss
net start eventsystem
net start mpsdrv
net start bfe
net start MpsSvc
net start winmgmt
netsh winhttp reset proxy
Endbatch:
cmd: Bitsadmin /Reset /Allusers
cmd: winmgmt /verifyrepository
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
 
Comment: Use Farbar routine to delete temp files
C:WindowsTemp*.*
C:WINDOWSsystem32*.tmp
C:WINDOWSsyswow64*.tmp
 
Comment: The system will restart.
Reboot:
 
End

 

Save the file as fixlist.txt in the same folder where the Farbar tool is running from.

The location is listed in the 3rd line of the Farbar log you have submitted.

 

Run FRST and click Fix only once and wait.

 

The tool will create a log (Fixlog.txt) please post it to your reply.

===

 

 

Please post the Fixlog.txt and let me know what problem persists.

Source: https://www.bleepingcomputer.com/forums/t/771068/urgent-help-needed/